Relationships
↔ sibling #18#3030 digitalocean codegen: app-platform and database spec secret fields are not marked sensitive
Opened by skunk-ape · 10/5/2026
Problem
The generated @swamp/digitalocean models carry real secret fields typed as plain z.string() with no .meta({ sensitive: true }). Found by running the swamp credentials-sensitive-field review rule over the extension (swamp-club#3019 triage):
- model/digitalocean/extensions/models/app_platform.ts: log_destinations basic_auth.password (84), logtail.token (43), datadog.api_key (41), image.registry_credentials (32), plus secret, access_key, private_key, oauth_client_secret
- database_cluster.ts, database_pool.ts, database_replica.ts, database_user.ts: connection password (20+)
- action_gateway_mcp_server.ts, insight_notification_channel.ts, database_logsink.ts: api_key, datadog_api_key, token
Only the top-level API token injected by codegen/digitalocean/extensionModelGenerator.ts is marked sensitive today. The rest are whole-identifier secret names, so the review rule is right to warn on them, and swamp-club#3019 (whole-identifier matching) does not clear them: about 215 of the extension's 244 credentials-sensitive-field warnings remain after that fix.
Expected
The digitalocean generator emits .meta({ sensitive: true }) on spec fields whose identifier is a whole secret name (password, token, api_key, secret, access_key, private_key, registry_credentials, oauth_client_secret and their datadog_ prefixed forms), so swamp vaults and redacts them and extension push --dry-run emits no credentials-sensitive-field warning for the extension.
Notes
The lifecycle for this issue runs in swamp-extensions (codegen/digitalocean). Generated files are not edited by hand; re-generate with deno task generate:digitalocean.
In Progress
Click a lifecycle step above to view its details.
system commented 10/5/2026, 3:33:18 PM
Classified automatically when this issue was filed.
- Source: Extensions
If you feel this classification is incorrect, add a ripple to tell us so.
Sign in to post a ripple.