Kubernetes ConfigMap sensitive value diagnostics
Summary
- Implemented OpenSpec 6.4 on branch
codex/6-4-configmap-secret-diagnostics. - Added warning diagnostic
OctopusImport.Action.Kubernetes.SensitiveConfigMapValuefor suspicious sensitive entries in Kubernetes ConfigMap values in OctopusKubernetesDeployContainersActionMapper.cs. - Reused the central
OctopusImportRedactiondetection helper and expanded it for underscore names likeapi_key,client_secret, andprivate_key. - Preserved existing ConfigMap import behavior: values are still normalized/imported unchanged; diagnostics report only count/context and do not include detected sensitive values.
- Added focused tests for suspicious ConfigMap diagnostics, normal ConfigMap behavior, SecretValues behavior, and diagnostic non-leakage in OctopusKubernetesActionMapperTests.cs.
- Updated OpenSpec task 6.4 and
SESSION_MEMORY.md; did not implement 6.2, 6.3, 6.5, 6.6, or unrelated Kubernetes mapping work.
Test plan
-
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~OctopusKubernetesActionMapperTests --no-restore -p:UseSharedCompilation=false -m:1 -v quietpassed 6/6. -
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~OctopusImportRedactionTests --no-restore -p:UseSharedCompilation=false -m:1 -v quietpassed 6/6. -
dotnet test tests/Squid.UnitTests/Squid.UnitTests.csproj --filter FullyQualifiedName~Services.OctopusImport.Mapping.Actions --no-restore -p:UseSharedCompilation=false -m:1 -v quietpassed 21/21. -
git diff --checkpassed. -
OpenSpec CLI validation was not run because local openspecstill fails due the Homebrew Node/macOS libc++ symbol mismatch. Tests required escalated permissions because sandboxed MSBuild named-pipe creation fails withSocketException (13): Permission denied.