Skip to content

Manual configuration markers for external resource secrets

Summary

  • Implemented OpenSpec 6.3 on branch codex/octopus-import-external-secret-shells.
  • Added import-only manual configuration markers and shell mapping for Feed, Account, Certificate, and Target resources in OctopusImportManualConfigurationMarker.cs and OctopusImportExternalResourceShellMapper.cs.
  • Extended Feed mapping so credentials remain omitted, safe manual configuration marker properties are added, and markers are returned from mapping results.
  • Extended preview planning so Feed/Account/Certificate/Target secret omissions emit redacted manual-configuration diagnostics without changing public import DTO contracts.
  • Added focused tests for feed markers, account empty credential shells, certificate manual shells, target endpoint secret omission, preview diagnostics, and non-leakage.
  • Updated SESSION_MEMORY.md and marked OpenSpec task 6.3 complete; did not implement 6.2, 6.4, 6.5, 6.6, or confirmation orchestration.

Test plan

  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter "FullyQualifiedName~OctopusImportFeedMapperTests|FullyQualifiedName~OctopusImportExternalResourceShellMapperTests|FullyQualifiedName~OctopusImportPreviewPlannerTests|FullyQualifiedName~OctopusImportRedactionTests" --no-restore passed 30/30.
  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~Services.OctopusImport --no-restore -p:UseSharedCompilation=false -m:1 -v quiet passed 222/222.
  • git diff --check passed.

Merge request reports

Loading