Synchronize UK private-data and Cloud Run runtime credentials
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
Direzione di ricerca
Start with the deployment workflows and the manually dispatched synchronization workflow entry point, then trace the existing Secret Manager and Cloud Run credential handling. Add coverage for idempotency, environment separation, value verification, and IAM checks without exposing secrets. Done means deployments bind the specified Hugging Face resource, documentation describes ownership and synchronization, and staging retains its distinct database password.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Problem
Cloud Run deployments need an unambiguous, read-only Hugging Face credential for the private UK datasets. GitHub-owned runtime credentials also need to be copied to Google Secret Manager and have their Cloud Run access bindings verified before deployment.
Required behavior
- Use
PE_UK_PRIVATE_HF_READ_TOKENas the GitHub secret andpe-uk-private-hf-read-tokenas the Google Secret Manager resource. - Verify that the Hugging Face credential is read-only and can access both required private UK repositories.
- Synchronize shared GitHub-owned runtime secrets before staging and production deployments.
- Synchronize the production database password only for production; preserve the distinct GCP-managed staging database password.
- Avoid creating redundant Secret Manager versions when values have not changed.
- Verify stored values and Cloud Run service-account permissions without printing secret values.
- Provide a manually dispatched synchronization workflow for credential rotation and recovery.
Acceptance criteria
- Deployment and manual workflows synchronize the correct environment-specific secret set.
- Tests cover idempotency, environment separation, value verification, and IAM verification.
- Deployment validation confirms the expected Hugging Face Secret Manager binding.
- Documentation states the credential ownership and synchronization path.
- Lingua principale
- Python
- Stelle
- 18
- Fork
- 33
- Merge medio
- 1g 7h
- PR unite (30g)
- 22
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di PolicyEngine/policyengine-api
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
PolicyEngine/policyengine-api#3864 ·
I maintainer di solito rispondono entro 1 giorno
-
Replace rich SPM provenance with compact typed receiptsForse già presa @anth-volk l’ha presa 4 giorni fa. Aperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 42/100
PolicyEngine/policyengine-api#3862 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 38/100
PolicyEngine/policyengine-api#3860 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 38/100
PolicyEngine/policyengine-api#3823 ·
I maintainer di solito rispondono entro 1 giorno
-
API v2: report validations as an append-only, provenance-keyed resource on reportsForse già presa @anth-volk l’ha presa 27 giorni fa. Aperta
PolicyEngine/policyengine-api#3818 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di PolicyEngine/policyengine-api
Issue simili
-
needs triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno
-
json_params_matcher fails on falsy top-level JSON primitives (0, False, "")Forse già presa @mayureshsonawane17 l’ha presa oggi. ApertaWaiting for: Product Owner
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
I maintainer di solito rispondono entro 5 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
Add .devin pluginAperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
ayghri/i-have-adhd#249 ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
modelscope/FunASR#3762 ·
I maintainer di solito rispondono entro 1 giorno