[FR] Support file-based and Azure Key Vault token sources alongside env and googleCloudSecret
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
- #1705 de @simmi-tdh — cerrado sin fusionar
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 64/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bien especificado
- Estado de actividad
- Activo
- Stack tecnológico
- azure, typescript
Línea de trabajo
Start with schemas/v3/shared.json and packages/shared/src/crypto.ts:124-149, then inspect the existing env and googleCloudSecret handling. Update the schema, regenerated schemas, implementation, unit tests, and docs/docs/configuration/config-file.mdx for both file and Azure Key Vault sources. Done means both configurations validate, missing or empty files fail clearly, and values are resolved on each use.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Describe the feature you'd like
Add two new token sources alongside env and googleCloudSecret: a file source and an
Azure Key Vault source.
{ "token": { "file": "/var/run/secrets/sourcebot/github-token" } }
{ "token": { "azureKeyVaultSecret": "https://<vault>.vault.azure.net/secrets/<name>[/<version>]" } }
Motivation
A Token in the config can only come from an environment variable or from Google Cloud
Secret Manager. schemas/v3/shared.json defines exactly two shapes, { "env": ... } and
{ "googleCloudSecret": ... }, and getTokenFromConfig throws Invalid token configuration
for anything else (packages/shared/src/crypto.ts:124-149).
That makes short-lived credentials impractical outside GCP. GitHub App installation tokens
(ghs_, accepted as connection tokens once #1662 lands) expire after one hour. Environment
variables are fixed when the container starts, so the only way to hand Sourcebot a fresh
token is to restart the whole service every hour. That restart takes the web app down and
interrupts in-flight indexing.
The rest of the code already supports rotation. Nothing caches the resolved value:
getGitHubReposFromConfig calls getTokenFromConfig on every sync
(packages/backend/src/github.ts:172), and getRepoAuth calls it on every clone and fetch
(packages/backend/src/utils.ts:167). A source whose value can change at runtime would be
picked up on the next sync with no other changes. Only the source types are missing.
Note - this is not specific to GitHub. Token is shared, so connection tokens, SSO client
secrets, LLM API keys and environmentOverrides values (DATABASE_URL, REDIS_URL) have the
same limit. On Azure there is currently no supported way to keep any of them in Key Vault.
Proposed design
Both are additive anyOf branches in Token, so existing configs are unaffected.
1. file (no new dependencies)
{ "token": { "file": "/var/run/secrets/sourcebot/github-token" } }
- Read the file each time the token is resolved and trim whitespace, matching
envand
googleCloudSecret. Fail with a clear error if it is missing or empty. - Works on any platform: Kubernetes Secret volumes (refreshed in place), Docker/Compose
secrets, the Secrets Store CSI driver for Azure Key Vault/AWS/Vault, and sidecars that mint
tokens, such as a GitHub App token refresher writing to a sharedemptyDir. - On its own, this solves the rotation problem above.
2. azureKeyVaultSecret
{ "token": { "azureKeyVaultSecret": "https://<vault>.vault.azure.net/secrets/<name>" } }
{ "token": { "azureKeyVaultSecret": "https://<vault>.vault.azure.net/secrets/<name>/<version>" } }
- Uses
@azure/keyvault-secretswithDefaultAzureCredential(@azure/identity), covering
AKS Workload Identity, managed identity andAZURE_CLIENT_*environment variables. This
mirrors how the GCP source relies on Application Default Credentials. - Leaving out the version fetches the latest one, so rotating the secret in Key Vault is
enough.
Example use case
- Register a GitHub App, install it on an organisation, grant
Contents: readand
Metadata: read. - Run a sidecar (or CronJob) that mints an installation token every ~50 minutes via
POST /app/installations/{installation_id}/access_tokensand writes it to a shared volume. - Point the connector at that file:
{ "type": "github", "token": { "file": "/var/run/secrets/github-token" }, "orgs": ["my-org"] } - Sourcebot reads the current token on every sync, clone and fetch. No restarts.
Today, step 3 is rejected by schema validation at startup, and the env equivalent stops
working with 401 Bad credentials after an hour.
Alternatives considered
- Restarting the container every hour: causes downtime and interrupts indexing.
- The native
appsGitHub App integration: requires a license key, and itsprivateKey
is itself aToken(schemas/v3/app.json), so on Azure the App's private key still has to
sit in an environment variable. - Going through GCP Secret Manager: brings a second cloud into an Azure-only deployment.
Additional information
Sourcebot version: v5.1.12 (docker.sourcebot.dev/sourcebot-dev/sourcebot), also applies to
main at the time of writing. Running on AKS (Azure); no GCP.
I'm happy to send the PR: schemas/v3/shared.json (plus regenerated schemas and docs),
getTokenFromConfig, unit tests, and the Tokens section of
docs/docs/configuration/config-file.mdx. If you'd prefer it smaller, I can send file
first and Azure Key Vault in a follow-up.
- Lenguaje dominante
- TypeScript
- Estrellas
- 3.9k
- Forks
- 374
- Merge medio
- 2 d 13 h
- PR fusionados (30 d)
- 48
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de sourcebot-dev/sourcebot
-
[bug] Search result hydration performs duplicate repository lookups within the same chunkPosiblemente ocupada @dipeshbabu la tomó hace 16 días. Abiertobug triage needed
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
sourcebot-dev/sourcebot#1681 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Linux ctags build instructions in CONTRIBUTING.md are missing build dependenciesPosiblemente ocupada @The-AarushiSingh la tomó hace 23 días. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 84/100
sourcebot-dev/sourcebot#1633 ·
Los mantenedores suelen responder en 1 día
-
MCP ask_codebase rejects explicit languageModel: getLanguageModelKey includes displayName which the MCP schema doesn't exposePosiblemente ocupada @pranav718 la tomó hace 40 días. Abiertoask_sb bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 76/100
sourcebot-dev/sourcebot#1137 · 4 comentarios ·
Los mantenedores suelen responder en 1 día
-
[bug] Local repositories with a space or non-ASCII character in the path cannot be indexedQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 35/100
sourcebot-dev/sourcebot#1689 ·
Los mantenedores suelen responder en 1 día
-
[bug] Escaped quotes in a quoted keyword search are searched with the backslashesQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 35/100
sourcebot-dev/sourcebot#1687 ·
Los mantenedores suelen responder en 1 día
Todos los issues de sourcebot-dev/sourcebot
Issues similares
-
area: desktop area: website priority: P2 type: feature
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
appandflow/stim#3411 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
needs triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
rjsf-team/react-jsonschema-form#5485 ·
Los mantenedores suelen responder en 2 días
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Dificultad 1/5 Menos de una hora Aptitud para principiantes 65/100
lingdojo/kana-dojo#32090 · 1 comentario · 5 reacciones ·
Los mantenedores suelen responder en 1 día
-
Friction: Org home and org switcher copy still say repositories and connected agents live in the personal accountPosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abiertofriction
Dificultad 2/5 1-3 horas Aptitud para principiantes 80/100
kentcdodds/kody#3265 ·
Los mantenedores suelen responder en 1 día