Skip to content

Expose consumed secret version for read-only snapshot provenance - #638

Merged
Pigbibi merged 1 commit into
mainfrom
codex/r10-snapshot-secret-source-20260928
Sep 27, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
codex/r10-snapshot-secret-source-20260928

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Asset snapshots need to identify the token version actually consumed, so a later rotation cannot silently join observations from different sources. Add optional GcpSecretStore.get_secret_with_metadata() returning the value and concrete version from one SDK response; unavailable or invalid version metadata stays None.

The value is excluded from repr. Existing secret interfaces, read-write access and trading authentication are unchanged. The LongBridge snapshot consumer will adopt this separately; this PR does not enable sampling or authenticate broker account identity.

Validation: 79 tests and 21 subtests passed in the focused cloud/LongBridge auth suite; targeted Ruff and diff checks passed. Independent review found no material issues. All SDK calls in validation were mocked.

@Pigbibi
Pigbibi merged commit d386270 into main Sep 27, 2026
1 check passed
@Pigbibi
Pigbibi deleted the codex/r10-snapshot-secret-source-20260928 branch September 27, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant