Skip to main content
← Back to list
01Issue
FeatureOpenSwamp CLIPublic
AssigneesNone

Relationships

#2461 Supported vault-write API for extension model methods (per-instance vault target)

Opened by sntxrr · 9/23/2026

Problem

An extension model method can persist a secret only through a sensitive resource field. In that path the target vault and key are fixed in the schema metadata (vaultName/vaultKey), or else derived as <type>/<modelId>/<method>/<spec>/<instance>/<field> in the repo default vault (data_writer.ts).

That's fine for secrets that only swamp consumes. It doesn't work when a method mints a credential for a consumer outside swamp, e.g. a shell script doing op read op://<vault>/<item>/<field>, or a CI secret. That consumer needs a human-chosen, per-instance address, so different model instances must write to different vaults and items.

What I did instead

@sntxrr/aws-access-key (mints IAM access keys) takes targetVault + targetItem as global arguments and calls context.vaultService.put() / .get() directly, reading the value back to verify it. That works because vaultService is on MethodContext, but it's undocumented for extensions and could change without notice. The model fails closed (refuses to mint) when vaultService is absent.

Ask

Either of these would work:

  1. Document context.vaultService (at least put/get/getVaultNames) as part of the extension API, with audit attribution to the calling model; or
  2. Allow vaultName/vaultKey on a sensitive field to be resolved per instance, e.g. from globalArguments via an expression.

While building this, a method that wrote key/current and inventory/current in one execution failed with "Duplicate data instance name 'current'". That happened after the irreversible API call had succeeded. It would help if instance-name uniqueness across specs were documented next to writeResource, or checked before the method body runs where the names are static.

02Bog Flow
◉OPEN○TRIAGED○IN PROGRESS○SHIPPED

Open

9/23/2026, 11:19:10 PM

No activity in this phase yet.

03Sludge Pulse

Sign in to post a ripple.