Skip to content

Kubernetes ConfigMap sensitive value diagnostics

Summary

  • Implemented OpenSpec 6.4 on branch codex/6-4-configmap-secret-diagnostics.
  • Added warning diagnostic OctopusImport.Action.Kubernetes.SensitiveConfigMapValue for suspicious sensitive entries in Kubernetes ConfigMap values in OctopusKubernetesDeployContainersActionMapper.cs.
  • Reused the central OctopusImportRedaction detection helper and expanded it for underscore names like api_key, client_secret, and private_key.
  • Preserved existing ConfigMap import behavior: values are still normalized/imported unchanged; diagnostics report only count/context and do not include detected sensitive values.
  • Added focused tests for suspicious ConfigMap diagnostics, normal ConfigMap behavior, SecretValues behavior, and diagnostic non-leakage in OctopusKubernetesActionMapperTests.cs.
  • Updated OpenSpec task 6.4 and SESSION_MEMORY.md; did not implement 6.2, 6.3, 6.5, 6.6, or unrelated Kubernetes mapping work.

Test plan

  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~OctopusKubernetesActionMapperTests --no-restore -p:UseSharedCompilation=false -m:1 -v quiet passed 6/6.
  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~OctopusImportRedactionTests --no-restore -p:UseSharedCompilation=false -m:1 -v quiet passed 6/6.
  • dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~Services.OctopusImport.Mapping.Actions --no-restore -p:UseSharedCompilation=false -m:1 -v quiet passed 21/21.
  • git diff --check passed.
  • OpenSpec CLI validation was not run because local openspec still fails due the Homebrew Node/macOS libc++ symbol mismatch. Tests required escalated permissions because sandboxed MSBuild named-pipe creation fails with SocketException (13): Permission denied.

Merge request reports

Loading