diff --git a/CHANGELOG.md b/CHANGELOG.md index 21fd05b6a..3e5100355 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## [Unreleased] +### Added +- Added `file` and `azureKeyVaultSecret` token sources, so rotated credentials (e.g., GitHub App installation tokens) are picked up without restarting Sourcebot. [#1705](https://github.com/sourcebot-dev/sourcebot/pull/1705) + ### Fixed - Silenced a false-positive `MaxListenersExceededWarning` logged on every request proxied through an external rewrite. [#1697](https://github.com/sourcebot-dev/sourcebot/pull/1697) diff --git a/docs/docs/configuration/config-file.mdx b/docs/docs/configuration/config-file.mdx index 37b6b689b..abc150892 100644 --- a/docs/docs/configuration/config-file.mdx +++ b/docs/docs/configuration/config-file.mdx @@ -58,7 +58,9 @@ The following are settings that can be provided in your config file to modify So # Tokens -Tokens are used to securely pass secrets to Sourcebot in a config file. They are used in various places, including connections, language model providers, auth providers, etc. Tokens can be passed as either environment variables or Google Cloud secrets: +Tokens are used to securely pass secrets to Sourcebot in a config file. They are used in various places, including connections, language model providers, auth providers, etc. Tokens can be passed as environment variables, files, Google Cloud secrets, or Azure Key Vault secrets. + +Environment variables are fixed when the container starts. File, Google Cloud, and Azure Key Vault tokens are read each time Sourcebot resolves them. For connection tokens, this happens on every sync, so you can rotate short-lived credentials (e.g., GitHub App installation tokens) without restarting Sourcebot. Tokens used in `environmentOverrides` are resolved once at startup. @@ -79,11 +81,41 @@ Tokens are used to securely pass secrets to Sourcebot in a config file. They are } ``` + + ```json + { + "token": { + "file": "/var/run/secrets/sourcebot/token" + } + } + ``` + + The path is resolved inside the Sourcebot container. Use an absolute path. Leading and trailing whitespace is trimmed. + + This works with Kubernetes Secret volumes, Docker secrets, the [Secrets Store CSI driver](https://secrets-store-csi-driver.sigs.k8s.io/), or a sidecar that writes refreshed tokens to a shared volume. + + + Kubernetes does not update Secrets mounted with `subPath`. Mount the whole volume if you want rotated values to be picked up. + + + + ```json + { + "token": { + "azureKeyVaultSecret": "https://.vault.azure.net/secrets/" + } + } + ``` + + To pin a specific version, append it to the identifier: `https://.vault.azure.net/secrets//`. If you omit the version, Sourcebot reads the latest version each time. + + Sourcebot authenticates with [`DefaultAzureCredential`](https://learn.microsoft.com/en-us/azure/developer/javascript/sdk/authentication/credential-chains#use-defaultazurecredential-for-flexibility). This supports AKS Workload Identity, managed identity, and the `AZURE_CLIENT_ID`, `AZURE_TENANT_ID`, and `AZURE_CLIENT_SECRET` environment variables. The identity needs the **Key Vault Secrets User** role, or a `get` secret access policy, on the vault. + # Overriding environment variables from the config -You can override / set environment variables from the config file by using the `environmentOverrides` property. Overrides can be of type `string`, `number`, `boolean`, or a [token](/docs/configuration/config-file#tokens). Tokens are useful when you want to configure a environment variable using a Google Cloud Secret or other supported secret management service. +You can override / set environment variables from the config file by using the `environmentOverrides` property. Overrides can be of type `string`, `number`, `boolean`, or a [token](/docs/configuration/config-file#tokens). Tokens are useful when you want to configure a environment variable using a Google Cloud secret, an Azure Key Vault secret, or other supported secret management service. diff --git a/docs/snippets/schemas/v3/app.schema.mdx b/docs/snippets/schemas/v3/app.schema.mdx index 07fd910c9..e92e3047e 100644 --- a/docs/snippets/schemas/v3/app.schema.mdx +++ b/docs/snippets/schemas/v3/app.schema.mdx @@ -53,6 +53,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -115,6 +141,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/docs/snippets/schemas/v3/azuredevops.schema.mdx b/docs/snippets/schemas/v3/azuredevops.schema.mdx index b3b3d282c..5b5a12285 100644 --- a/docs/snippets/schemas/v3/azuredevops.schema.mdx +++ b/docs/snippets/schemas/v3/azuredevops.schema.mdx @@ -37,6 +37,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/bitbucket.schema.mdx b/docs/snippets/schemas/v3/bitbucket.schema.mdx index 56895a892..193e9b792 100644 --- a/docs/snippets/schemas/v3/bitbucket.schema.mdx +++ b/docs/snippets/schemas/v3/bitbucket.schema.mdx @@ -45,6 +45,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/connection.schema.mdx b/docs/snippets/schemas/v3/connection.schema.mdx index 2d4607b9d..39a38b30f 100644 --- a/docs/snippets/schemas/v3/connection.schema.mdx +++ b/docs/snippets/schemas/v3/connection.schema.mdx @@ -41,6 +41,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -258,6 +284,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -478,6 +530,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -767,6 +845,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -949,6 +1053,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/environmentOverrides.schema.mdx b/docs/snippets/schemas/v3/environmentOverrides.schema.mdx index bca6ec083..e3ec6626c 100644 --- a/docs/snippets/schemas/v3/environmentOverrides.schema.mdx +++ b/docs/snippets/schemas/v3/environmentOverrides.schema.mdx @@ -50,6 +50,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/docs/snippets/schemas/v3/gitea.schema.mdx b/docs/snippets/schemas/v3/gitea.schema.mdx index 45e034744..6eb3ca42a 100644 --- a/docs/snippets/schemas/v3/gitea.schema.mdx +++ b/docs/snippets/schemas/v3/gitea.schema.mdx @@ -37,6 +37,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/github.schema.mdx b/docs/snippets/schemas/v3/github.schema.mdx index 7d731cdc5..e4864551f 100644 --- a/docs/snippets/schemas/v3/github.schema.mdx +++ b/docs/snippets/schemas/v3/github.schema.mdx @@ -37,6 +37,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/gitlab.schema.mdx b/docs/snippets/schemas/v3/gitlab.schema.mdx index 017e5fc5e..ab3ee3417 100644 --- a/docs/snippets/schemas/v3/gitlab.schema.mdx +++ b/docs/snippets/schemas/v3/gitlab.schema.mdx @@ -37,6 +37,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/identityProvider.schema.mdx b/docs/snippets/schemas/v3/identityProvider.schema.mdx index 0be1f8f6d..c6090184c 100644 --- a/docs/snippets/schemas/v3/identityProvider.schema.mdx +++ b/docs/snippets/schemas/v3/identityProvider.schema.mdx @@ -48,6 +48,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -78,6 +104,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -148,6 +200,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -178,6 +256,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -245,6 +349,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -275,6 +405,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -327,6 +483,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -357,6 +539,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -387,6 +595,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -440,40 +674,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -500,63 +730,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "MicrosoftEntraIDIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "microsoft-entra-id" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -583,34 +786,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -625,21 +824,21 @@ "issuer" ] }, - "GCPIAPIdentityProviderConfig": { + "MicrosoftEntraIDIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -666,26 +865,1261 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "GCPIAPIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gcp-iap" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + }, + "purpose": { + "const": "sso" + }, + "audience": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "audience" + ] + }, + "BitbucketCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-cloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "AuthentikIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "authentik" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "JumpCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "jumpcloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "IdiraIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "idira" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "BitbucketServerIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-server" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "description": "The URL of the Bitbucket Server/Data Center host.", + "examples": [ + "https://bitbucket.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "baseUrl" + ] + } + }, + "oneOf": [ + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "github" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ "provider", "purpose", - "audience" + "clientId", + "clientSecret" ] }, - "BitbucketCloudIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-cloud" + "const": "gitlab" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." }, "purpose": { "enum": [ @@ -720,6 +2154,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -750,9 +2210,46 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, "accountLinkingRequired": { "type": "boolean", "default": false @@ -765,16 +2262,16 @@ "clientSecret" ] }, - "AuthentikIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "authentik" + "const": "google" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." }, "purpose": { "const": "sso" @@ -806,6 +2303,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -836,34 +2359,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -874,20 +2393,19 @@ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, - "JumpCloudIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "okta" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." }, "purpose": { "const": "sso" @@ -919,6 +2437,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -949,6 +2493,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -979,6 +2549,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -991,16 +2587,16 @@ "issuer" ] }, - "IdiraIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "idira" + "const": "keycloak" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." }, "purpose": { "const": "sso" @@ -1010,32 +2606,114 @@ { "type": "object", "properties": { - "env": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -1062,34 +2740,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1104,22 +2778,19 @@ "issuer" ] }, - "BitbucketServerIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-server" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -1148,80 +2819,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "baseUrl" - ] - } - }, - "oneOf": [ - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "github" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -1248,80 +2875,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "gitlab" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -1348,60 +2931,42 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", - "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -1409,16 +2974,16 @@ "additionalProperties": false, "properties": { "provider": { - "const": "google" + "const": "gcp-iap" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." }, "purpose": { "const": "sso" }, - "clientId": { + "audience": { "anyOf": [ { "type": "object", @@ -1445,34 +3010,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1482,8 +3043,7 @@ "required": [ "provider", "purpose", - "clientId", - "clientSecret" + "audience" ] }, { @@ -1491,11 +3051,11 @@ "additionalProperties": false, "properties": { "provider": { - "const": "okta" + "const": "authentik" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." }, "purpose": { "const": "sso" @@ -1527,40 +3087,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -1587,63 +3143,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "keycloak" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -1670,34 +3199,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1717,14 +3242,17 @@ "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "bitbucket-cloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -1753,6 +3281,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1783,46 +3337,45 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -1830,16 +3383,16 @@ "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -1866,55 +3419,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1947,66 +3475,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-cloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -2033,49 +3531,42 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -2083,11 +3574,11 @@ "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "idira" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." }, "purpose": { "const": "sso" @@ -2119,40 +3610,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -2179,63 +3666,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "idira" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -2262,34 +3722,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -2348,6 +3804,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -2378,6 +3860,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/index.schema.mdx b/docs/snippets/schemas/v3/index.schema.mdx index 60f08e149..efd24250a 100644 --- a/docs/snippets/schemas/v3/index.schema.mdx +++ b/docs/snippets/schemas/v3/index.schema.mdx @@ -431,6 +431,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -537,6 +563,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "A Personal Access Token (PAT)." @@ -754,6 +806,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "An authentication token." @@ -974,6 +1052,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "A Personal Access Token (PAT)." @@ -1263,6 +1367,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "An authentication token." @@ -1445,6 +1575,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "A Personal Access Token (PAT)." @@ -1747,6 +1903,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional access key ID to use with the model. Defaults to the `AWS_ACCESS_KEY_ID` environment variable." @@ -1778,6 +1960,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional secret access key to use with the model. Defaults to the `AWS_SECRET_ACCESS_KEY` environment variable." @@ -1809,6 +2017,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable." @@ -1868,6 +2102,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1925,6 +2185,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -1956,6 +2242,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -2006,22 +2318,48 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - ] - } - }, - "additionalProperties": false - } - }, - "required": [ - "provider", - "model" - ], - "additionalProperties": false - }, - "AzureLanguageModel": { + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + ] + } + }, + "additionalProperties": false + } + }, + "required": [ + "provider", + "model" + ], + "additionalProperties": false + }, + "AzureLanguageModel": { "type": "object", "properties": { "provider": { @@ -2067,6 +2405,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -2141,6 +2505,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2198,6 +2588,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -2248,6 +2664,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2305,6 +2747,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -2369,6 +2837,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2442,6 +2936,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -2492,6 +3012,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2567,6 +3113,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -2631,6 +3203,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2688,6 +3286,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -2738,6 +3362,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2801,6 +3451,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -2871,6 +3547,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2928,6 +3630,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -2977,6 +3705,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3021,6 +3775,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3093,6 +3873,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -3143,6 +3949,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3204,6 +4036,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." @@ -3254,6 +4112,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3313,6 +4197,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional access key ID to use with the model. Defaults to the `AWS_ACCESS_KEY_ID` environment variable." @@ -3344,6 +4254,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional secret access key to use with the model. Defaults to the `AWS_SECRET_ACCESS_KEY` environment variable." @@ -3375,22 +4311,48 @@ "googleCloudSecret" ], "additionalProperties": false - } - ], - "description": "Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable." - }, - "region": { - "type": "string", - "description": "The AWS region. Defaults to the `AWS_REGION` environment variable.", - "examples": [ - "us-east-1", - "us-west-2", - "eu-west-1" - ] - }, - "baseUrl": { - "type": "string", - "format": "url", + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ], + "description": "Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable." + }, + "region": { + "type": "string", + "description": "The AWS region. Defaults to the `AWS_REGION` environment variable.", + "examples": [ + "us-east-1", + "us-west-2", + "eu-west-1" + ] + }, + "baseUrl": { + "type": "string", + "format": "url", "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$", "description": "Optional base URL." }, @@ -3434,6 +4396,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3491,6 +4479,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -3522,6 +4536,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -3572,6 +4612,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3633,6 +4699,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -3707,6 +4799,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3764,6 +4882,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -3814,6 +4958,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3871,6 +5041,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -3935,6 +5131,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4008,6 +5230,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -4058,6 +5306,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4133,6 +5407,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -4197,6 +5497,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4254,6 +5580,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -4304,6 +5656,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4367,6 +5745,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -4437,6 +5841,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4494,6 +5924,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -4543,6 +5999,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4587,6 +6069,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4659,6 +6167,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -4709,6 +6243,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4770,22 +6330,48 @@ "googleCloudSecret" ], "additionalProperties": false - } - ], - "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." - }, - "baseUrl": { - "type": "string", - "format": "url", - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$", - "description": "Optional base URL." - }, - "temperature": { - "type": "number", - "description": "Optional temperature setting to use with the model." - }, - "headers": { - "type": "object", + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ], + "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." + }, + "baseUrl": { + "type": "string", + "format": "url", + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$", + "description": "Optional base URL." + }, + "temperature": { + "type": "number", + "description": "Optional temperature setting to use with the model." + }, + "headers": { + "type": "object", "description": "Optional headers to use with the model.", "patternProperties": { "^[!#$%&'*+\\-.^_`|~0-9A-Za-z]+$": { @@ -4820,6 +6406,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4893,6 +6505,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "The private key of the GitHub App." @@ -4955,6 +6593,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "The private key of the GitHub App." @@ -5025,6 +6689,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5055,6 +6745,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5125,6 +6841,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5155,6 +6897,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5222,6 +6990,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5252,6 +7046,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5304,6 +7124,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5334,6 +7180,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5364,6 +7236,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5417,6 +7315,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5447,6 +7371,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5477,6 +7427,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5530,6 +7506,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5560,6 +7562,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5590,6 +7618,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5643,6 +7697,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5697,6 +7777,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5727,6 +7833,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5783,40 +7915,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -5843,63 +7971,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "JumpCloudIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "jumpcloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -5926,34 +8027,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -5968,16 +8065,16 @@ "issuer" ] }, - "IdiraIdentityProviderConfig": { + "JumpCloudIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "idira" + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { "const": "sso" @@ -6009,6 +8106,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -6039,66 +8162,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "BitbucketServerIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-server" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -6125,50 +8218,34 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ @@ -6176,27 +8253,22 @@ "purpose", "clientId", "clientSecret", - "baseUrl" + "issuer" ] - } - }, - "oneOf": [ - { + }, + "IdiraIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "github" + "const": "idira" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -6225,80 +8297,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "gitlab" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -6325,77 +8353,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", - "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "google" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -6422,34 +8409,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -6460,22 +8443,26 @@ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, - { + "BitbucketServerIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "okta" + "const": "bitbucket-server" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -6504,40 +8491,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -6564,8 +8547,46 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "description": "The URL of the Bitbucket Server/Data Center host.", + "examples": [ + "https://bitbucket.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ @@ -6573,22 +8594,27 @@ "purpose", "clientId", "clientSecret", - "issuer" + "baseUrl" ] - }, + } + }, + "oneOf": [ { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "keycloak" + "const": "github" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -6617,6 +8643,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -6647,46 +8699,56 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -6694,14 +8756,17 @@ "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "gitlab" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -6730,6 +8795,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -6760,46 +8851,56 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -6807,16 +8908,16 @@ "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "google" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -6843,55 +8944,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -6924,34 +9000,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -6962,8 +9034,7 @@ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -6971,17 +9042,14 @@ "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-cloud" + "const": "okta" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -7010,6 +9078,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7040,31 +9134,110 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] }, { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "keycloak" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." }, "purpose": { "const": "sso" @@ -7096,6 +9269,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7126,6 +9325,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7156,6 +9381,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -7173,11 +9424,11 @@ "additionalProperties": false, "properties": { "provider": { - "const": "idira" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { "const": "sso" @@ -7209,6 +9460,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7239,6 +9516,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7269,6 +9572,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -7286,19 +9615,16 @@ "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-server" + "const": "gcp-iap" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, - "clientId": { + "audience": { "anyOf": [ { "type": "object", @@ -7325,67 +9651,913 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", - "clientId", - "clientSecret", - "baseUrl" + "audience" ] - } - ] - } - }, - "additionalProperties": false - }, - { - "type": "array", + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "authentik" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-cloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "jumpcloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "idira" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-server" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "description": "The URL of the Bitbucket Server/Data Center host.", + "examples": [ + "https://bitbucket.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "baseUrl" + ] + } + ] + } + }, + "additionalProperties": false + }, + { + "type": "array", "items": { "$schema": "http://json-schema.org/draft-07/schema#", "title": "IdentityProviderConfig", @@ -7395,19 +10567,1683 @@ "additionalProperties": false, "properties": { "provider": { - "const": "github" + "const": "github" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "GitLabIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gitlab" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "GoogleIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "google" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "OktaIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "okta" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "KeycloakIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "keycloak" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "MicrosoftEntraIDIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "microsoft-entra-id" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "GCPIAPIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gcp-iap" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + }, + "purpose": { + "const": "sso" + }, + "audience": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "audience" + ] + }, + "BitbucketCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-cloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "AuthentikIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "authentik" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "JumpCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { - "enum": [ - "sso", - "account_linking" + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "IdiraIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "idira" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } ] }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -7434,10 +12270,36 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -7464,42 +12326,54 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, - "GitLabIdentityProviderConfig": { + "BitbucketServerIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "gitlab" + "const": "bitbucket-server" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." }, "purpose": { "enum": [ @@ -7534,6 +12408,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7564,17 +12464,40 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, "baseUrl": { "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "description": "The URL of the Bitbucket Server/Data Center host.", "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" + "https://bitbucket.example.com" ], "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" }, @@ -7587,22 +12510,28 @@ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "baseUrl" ] - }, - "GoogleIdentityProviderConfig": { + } + }, + "oneOf": [ + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "google" + "const": "github" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -7631,62 +12560,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - "OktaIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "okta" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." - }, - "purpose": { - "const": "sso" }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -7713,40 +12616,76 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gitlab" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { "anyOf": [ { "type": "object", @@ -7773,57 +12712,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "KeycloakIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "keycloak" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -7856,58 +12768,68 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, - "MicrosoftEntraIDIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "google" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." }, "purpose": { "const": "sso" @@ -7939,6 +12861,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7969,34 +12917,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8007,25 +12951,24 @@ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, - "GCPIAPIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "okta" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -8052,58 +12995,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - "BitbucketCloudIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-cloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8136,66 +13051,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - "AuthentikIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -8222,34 +13107,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8264,16 +13145,16 @@ "issuer" ] }, - "JumpCloudIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "keycloak" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." }, "purpose": { "const": "sso" @@ -8305,40 +13186,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -8364,64 +13241,37 @@ "required": [ "googleCloudSecret" ], - "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "IdiraIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "idira" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + "additionalProperties": false + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -8448,34 +13298,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8490,22 +13336,19 @@ "issuer" ] }, - "BitbucketServerIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-server" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -8534,80 +13377,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "baseUrl" - ] - } - }, - "oneOf": [ - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "github" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -8634,80 +13433,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "gitlab" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -8734,60 +13489,42 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", - "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -8795,16 +13532,16 @@ "additionalProperties": false, "properties": { "provider": { - "const": "google" + "const": "gcp-iap" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." }, "purpose": { "const": "sso" }, - "clientId": { + "audience": { "anyOf": [ { "type": "object", @@ -8831,34 +13568,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8868,8 +13601,7 @@ "required": [ "provider", "purpose", - "clientId", - "clientSecret" + "audience" ] }, { @@ -8877,11 +13609,11 @@ "additionalProperties": false, "properties": { "provider": { - "const": "okta" + "const": "authentik" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." }, "purpose": { "const": "sso" @@ -8913,40 +13645,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -8973,63 +13701,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "keycloak" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -9056,34 +13757,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -9103,14 +13800,17 @@ "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "bitbucket-cloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -9139,6 +13839,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -9169,46 +13895,45 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -9216,16 +13941,16 @@ "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -9252,55 +13977,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -9333,66 +14033,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-cloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -9419,49 +14089,42 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -9469,11 +14132,11 @@ "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "idira" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." }, "purpose": { "const": "sso" @@ -9505,40 +14168,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -9565,63 +14224,36 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "idira" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -9648,34 +14280,30 @@ "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -9734,6 +14362,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -9764,6 +14418,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/docs/snippets/schemas/v3/languageModel.schema.mdx b/docs/snippets/schemas/v3/languageModel.schema.mdx index 90aee08af..09c9d9201 100644 --- a/docs/snippets/schemas/v3/languageModel.schema.mdx +++ b/docs/snippets/schemas/v3/languageModel.schema.mdx @@ -47,6 +47,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -78,6 +104,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -109,6 +161,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -167,6 +245,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -224,6 +328,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -255,6 +385,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -305,6 +461,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -366,6 +548,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -440,6 +648,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -497,6 +731,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -547,6 +807,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -604,6 +890,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -668,6 +980,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -741,6 +1079,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -791,6 +1155,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -866,6 +1256,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -930,6 +1346,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -987,6 +1429,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -1015,26 +1483,52 @@ { "type": "object", "properties": { - "env": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1100,6 +1594,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -1170,6 +1690,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1227,6 +1773,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -1276,6 +1848,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1320,6 +1918,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1392,6 +2016,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -1442,6 +2092,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1503,6 +2179,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." @@ -1553,6 +2255,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1613,6 +2341,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1644,6 +2398,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1675,6 +2455,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1733,6 +2539,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1790,6 +2622,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -1821,6 +2679,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -1871,6 +2755,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1932,6 +2842,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -2006,6 +2942,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2063,6 +3025,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -2113,6 +3101,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2170,6 +3184,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -2234,6 +3274,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2307,6 +3373,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -2357,6 +3449,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2410,26 +3528,52 @@ { "type": "object", "properties": { - "env": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -2496,6 +3640,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2553,6 +3723,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -2603,6 +3799,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2666,6 +3888,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -2736,6 +3984,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2793,6 +4067,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -2842,6 +4142,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2886,6 +4212,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2958,6 +4310,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -3008,6 +4386,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3069,6 +4473,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." @@ -3119,6 +4549,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/docs/snippets/schemas/v3/shared.schema.mdx b/docs/snippets/schemas/v3/shared.schema.mdx index 270d85b4b..4a3f0724b 100644 --- a/docs/snippets/schemas/v3/shared.schema.mdx +++ b/docs/snippets/schemas/v3/shared.schema.mdx @@ -31,6 +31,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -111,6 +137,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -155,6 +207,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/packages/schemas/src/v3/app.schema.ts b/packages/schemas/src/v3/app.schema.ts index b46bd72a3..49e877b52 100644 --- a/packages/schemas/src/v3/app.schema.ts +++ b/packages/schemas/src/v3/app.schema.ts @@ -52,6 +52,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -114,6 +140,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/packages/schemas/src/v3/app.type.ts b/packages/schemas/src/v3/app.type.ts index 325084a8f..00ae45917 100644 --- a/packages/schemas/src/v3/app.type.ts +++ b/packages/schemas/src/v3/app.type.ts @@ -30,5 +30,17 @@ export interface GitHubAppConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } diff --git a/packages/schemas/src/v3/azuredevops.schema.ts b/packages/schemas/src/v3/azuredevops.schema.ts index 8b730bda5..f925a77aa 100644 --- a/packages/schemas/src/v3/azuredevops.schema.ts +++ b/packages/schemas/src/v3/azuredevops.schema.ts @@ -36,6 +36,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/azuredevops.type.ts b/packages/schemas/src/v3/azuredevops.type.ts index 28f35f1ad..3545ca089 100644 --- a/packages/schemas/src/v3/azuredevops.type.ts +++ b/packages/schemas/src/v3/azuredevops.type.ts @@ -20,6 +20,18 @@ export interface AzureDevOpsConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Azure DevOps host. For Azure DevOps Cloud, use https://dev.azure.com. For Azure DevOps Server, use your server URL. diff --git a/packages/schemas/src/v3/bitbucket.schema.ts b/packages/schemas/src/v3/bitbucket.schema.ts index 11bbb3221..6381069be 100644 --- a/packages/schemas/src/v3/bitbucket.schema.ts +++ b/packages/schemas/src/v3/bitbucket.schema.ts @@ -44,6 +44,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/bitbucket.type.ts b/packages/schemas/src/v3/bitbucket.type.ts index ee5647064..c19457a9c 100644 --- a/packages/schemas/src/v3/bitbucket.type.ts +++ b/packages/schemas/src/v3/bitbucket.type.ts @@ -28,6 +28,18 @@ export interface BitbucketConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Bitbucket URL diff --git a/packages/schemas/src/v3/connection.schema.ts b/packages/schemas/src/v3/connection.schema.ts index 15d80600d..27b783f6b 100644 --- a/packages/schemas/src/v3/connection.schema.ts +++ b/packages/schemas/src/v3/connection.schema.ts @@ -40,6 +40,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -257,6 +283,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -477,6 +529,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -766,6 +844,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -948,6 +1052,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/connection.type.ts b/packages/schemas/src/v3/connection.type.ts index 7d85e86e7..b3b220bc4 100644 --- a/packages/schemas/src/v3/connection.type.ts +++ b/packages/schemas/src/v3/connection.type.ts @@ -29,6 +29,18 @@ export interface GithubConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitHub host. Defaults to https://github.com @@ -126,6 +138,18 @@ export interface GitlabConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitLab host. Defaults to https://gitlab.com @@ -209,6 +233,18 @@ export interface GiteaConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Gitea host. Defaults to https://gitea.com @@ -315,6 +351,18 @@ export interface BitbucketConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Bitbucket URL @@ -384,6 +432,18 @@ export interface AzureDevOpsConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Azure DevOps host. For Azure DevOps Cloud, use https://dev.azure.com. For Azure DevOps Server, use your server URL. diff --git a/packages/schemas/src/v3/environmentOverrides.schema.ts b/packages/schemas/src/v3/environmentOverrides.schema.ts index 49742827c..5c07c280e 100644 --- a/packages/schemas/src/v3/environmentOverrides.schema.ts +++ b/packages/schemas/src/v3/environmentOverrides.schema.ts @@ -49,6 +49,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/packages/schemas/src/v3/environmentOverrides.type.ts b/packages/schemas/src/v3/environmentOverrides.type.ts index e9adfaec8..4ebe3b508 100644 --- a/packages/schemas/src/v3/environmentOverrides.type.ts +++ b/packages/schemas/src/v3/environmentOverrides.type.ts @@ -23,6 +23,18 @@ export interface EnvironmentOverrides { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } | { diff --git a/packages/schemas/src/v3/gitea.schema.ts b/packages/schemas/src/v3/gitea.schema.ts index 6626b1992..868e34807 100644 --- a/packages/schemas/src/v3/gitea.schema.ts +++ b/packages/schemas/src/v3/gitea.schema.ts @@ -36,6 +36,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/gitea.type.ts b/packages/schemas/src/v3/gitea.type.ts index dbdeeb8c5..8e04e9397 100644 --- a/packages/schemas/src/v3/gitea.type.ts +++ b/packages/schemas/src/v3/gitea.type.ts @@ -20,6 +20,18 @@ export interface GiteaConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Gitea host. Defaults to https://gitea.com diff --git a/packages/schemas/src/v3/github.schema.ts b/packages/schemas/src/v3/github.schema.ts index 93c61ba90..7874693b9 100644 --- a/packages/schemas/src/v3/github.schema.ts +++ b/packages/schemas/src/v3/github.schema.ts @@ -36,6 +36,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/github.type.ts b/packages/schemas/src/v3/github.type.ts index f7cdf4a2d..9ee5fff00 100644 --- a/packages/schemas/src/v3/github.type.ts +++ b/packages/schemas/src/v3/github.type.ts @@ -20,6 +20,18 @@ export interface GithubConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitHub host. Defaults to https://github.com diff --git a/packages/schemas/src/v3/gitlab.schema.ts b/packages/schemas/src/v3/gitlab.schema.ts index 1c5819c90..de322022a 100644 --- a/packages/schemas/src/v3/gitlab.schema.ts +++ b/packages/schemas/src/v3/gitlab.schema.ts @@ -36,6 +36,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/gitlab.type.ts b/packages/schemas/src/v3/gitlab.type.ts index 63eea72b5..be971c724 100644 --- a/packages/schemas/src/v3/gitlab.type.ts +++ b/packages/schemas/src/v3/gitlab.type.ts @@ -20,6 +20,18 @@ export interface GitlabConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitLab host. Defaults to https://gitlab.com diff --git a/packages/schemas/src/v3/identityProvider.schema.ts b/packages/schemas/src/v3/identityProvider.schema.ts index a95db0c1a..bc9b73a3e 100644 --- a/packages/schemas/src/v3/identityProvider.schema.ts +++ b/packages/schemas/src/v3/identityProvider.schema.ts @@ -47,6 +47,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -77,6 +103,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -147,6 +199,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -177,6 +255,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -244,6 +348,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -274,6 +404,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -326,6 +482,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -356,6 +538,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -386,6 +594,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -439,40 +673,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -499,63 +729,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "MicrosoftEntraIDIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "microsoft-entra-id" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -582,34 +785,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -624,21 +823,21 @@ const schema = { "issuer" ] }, - "GCPIAPIdentityProviderConfig": { + "MicrosoftEntraIDIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -665,26 +864,1261 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "GCPIAPIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gcp-iap" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + }, + "purpose": { + "const": "sso" + }, + "audience": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "audience" + ] + }, + "BitbucketCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-cloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "AuthentikIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "authentik" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "JumpCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "jumpcloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "IdiraIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "idira" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "BitbucketServerIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-server" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "description": "The URL of the Bitbucket Server/Data Center host.", + "examples": [ + "https://bitbucket.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "baseUrl" + ] + } + }, + "oneOf": [ + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "github" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ "provider", "purpose", - "audience" + "clientId", + "clientSecret" ] }, - "BitbucketCloudIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-cloud" + "const": "gitlab" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." }, "purpose": { "enum": [ @@ -719,6 +2153,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -749,9 +2209,46 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, "accountLinkingRequired": { "type": "boolean", "default": false @@ -764,16 +2261,16 @@ const schema = { "clientSecret" ] }, - "AuthentikIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "authentik" + "const": "google" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." }, "purpose": { "const": "sso" @@ -805,6 +2302,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -835,34 +2358,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -873,20 +2392,19 @@ const schema = { "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, - "JumpCloudIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "okta" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." }, "purpose": { "const": "sso" @@ -918,6 +2436,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -948,6 +2492,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -978,6 +2548,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -990,16 +2586,16 @@ const schema = { "issuer" ] }, - "IdiraIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "idira" + "const": "keycloak" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." }, "purpose": { "const": "sso" @@ -1009,32 +2605,114 @@ const schema = { { "type": "object", "properties": { - "env": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -1061,34 +2739,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1103,22 +2777,19 @@ const schema = { "issuer" ] }, - "BitbucketServerIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-server" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -1147,80 +2818,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "baseUrl" - ] - } - }, - "oneOf": [ - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "github" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -1247,80 +2874,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "gitlab" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -1347,60 +2930,42 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", - "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -1408,16 +2973,16 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "google" + "const": "gcp-iap" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." }, "purpose": { "const": "sso" }, - "clientId": { + "audience": { "anyOf": [ { "type": "object", @@ -1444,34 +3009,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1481,8 +3042,7 @@ const schema = { "required": [ "provider", "purpose", - "clientId", - "clientSecret" + "audience" ] }, { @@ -1490,11 +3050,11 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "okta" + "const": "authentik" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." }, "purpose": { "const": "sso" @@ -1526,40 +3086,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -1586,63 +3142,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "keycloak" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -1669,34 +3198,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1716,14 +3241,17 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "bitbucket-cloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -1752,6 +3280,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1782,46 +3336,45 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -1829,16 +3382,16 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -1865,55 +3418,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1946,66 +3474,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-cloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -2032,49 +3530,42 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -2082,11 +3573,11 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "idira" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." }, "purpose": { "const": "sso" @@ -2118,40 +3609,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -2178,63 +3665,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "idira" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -2261,34 +3721,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -2347,6 +3803,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -2377,6 +3859,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/identityProvider.type.ts b/packages/schemas/src/v3/identityProvider.type.ts index 936bdb72b..859f73df1 100644 --- a/packages/schemas/src/v3/identityProvider.type.ts +++ b/packages/schemas/src/v3/identityProvider.type.ts @@ -33,6 +33,18 @@ export interface GitHubIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -46,6 +58,18 @@ export interface GitHubIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitHub host. Defaults to https://github.com @@ -72,6 +96,18 @@ export interface GitLabIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -85,6 +121,18 @@ export interface GitLabIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitLab host. Defaults to https://gitlab.com @@ -111,6 +159,18 @@ export interface GoogleIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -124,6 +184,18 @@ export interface GoogleIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface OktaIdentityProviderConfig { @@ -145,6 +217,18 @@ export interface OktaIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -158,6 +242,18 @@ export interface OktaIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -171,6 +267,18 @@ export interface OktaIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface KeycloakIdentityProviderConfig { @@ -192,6 +300,18 @@ export interface KeycloakIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -205,6 +325,18 @@ export interface KeycloakIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -218,6 +350,18 @@ export interface KeycloakIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface MicrosoftEntraIDIdentityProviderConfig { @@ -239,6 +383,18 @@ export interface MicrosoftEntraIDIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -252,6 +408,18 @@ export interface MicrosoftEntraIDIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -265,6 +433,18 @@ export interface MicrosoftEntraIDIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface GCPIAPIdentityProviderConfig { @@ -286,6 +466,18 @@ export interface GCPIAPIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface AuthentikIdentityProviderConfig { @@ -307,6 +499,18 @@ export interface AuthentikIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -320,6 +524,18 @@ export interface AuthentikIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -333,6 +549,18 @@ export interface AuthentikIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface BitbucketCloudIdentityProviderConfig { @@ -354,6 +582,18 @@ export interface BitbucketCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -367,6 +607,18 @@ export interface BitbucketCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; accountLinkingRequired?: boolean; } @@ -389,6 +641,18 @@ export interface JumpCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -402,6 +666,18 @@ export interface JumpCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -415,6 +691,18 @@ export interface JumpCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface IdiraIdentityProviderConfig { @@ -436,6 +724,18 @@ export interface IdiraIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -449,6 +749,18 @@ export interface IdiraIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -462,6 +774,18 @@ export interface IdiraIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface BitbucketServerIdentityProviderConfig { @@ -483,6 +807,18 @@ export interface BitbucketServerIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -496,6 +832,18 @@ export interface BitbucketServerIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Bitbucket Server/Data Center host. diff --git a/packages/schemas/src/v3/index.schema.ts b/packages/schemas/src/v3/index.schema.ts index 0d7a76d92..34d1a554c 100644 --- a/packages/schemas/src/v3/index.schema.ts +++ b/packages/schemas/src/v3/index.schema.ts @@ -430,6 +430,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -536,6 +562,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "A Personal Access Token (PAT)." @@ -753,6 +805,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "An authentication token." @@ -973,6 +1051,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "A Personal Access Token (PAT)." @@ -1262,6 +1366,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "An authentication token." @@ -1444,6 +1574,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "A Personal Access Token (PAT)." @@ -1746,6 +1902,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional access key ID to use with the model. Defaults to the `AWS_ACCESS_KEY_ID` environment variable." @@ -1777,6 +1959,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional secret access key to use with the model. Defaults to the `AWS_SECRET_ACCESS_KEY` environment variable." @@ -1808,6 +2016,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable." @@ -1867,6 +2101,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1924,6 +2184,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -1955,6 +2241,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -2005,22 +2317,48 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - ] - } - }, - "additionalProperties": false - } - }, - "required": [ - "provider", - "model" - ], - "additionalProperties": false - }, - "AzureLanguageModel": { + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + ] + } + }, + "additionalProperties": false + } + }, + "required": [ + "provider", + "model" + ], + "additionalProperties": false + }, + "AzureLanguageModel": { "type": "object", "properties": { "provider": { @@ -2066,6 +2404,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -2140,6 +2504,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2197,6 +2587,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -2247,6 +2663,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2304,6 +2746,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -2368,6 +2836,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2441,6 +2935,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -2491,6 +3011,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2566,6 +3112,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -2630,6 +3202,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2687,6 +3285,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -2737,6 +3361,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2800,6 +3450,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -2870,6 +3546,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2927,6 +3629,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -2976,6 +3704,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3020,6 +3774,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3092,6 +3872,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -3142,6 +3948,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3203,6 +4035,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." @@ -3253,6 +4111,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3312,6 +4196,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional access key ID to use with the model. Defaults to the `AWS_ACCESS_KEY_ID` environment variable." @@ -3343,6 +4253,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional secret access key to use with the model. Defaults to the `AWS_SECRET_ACCESS_KEY` environment variable." @@ -3374,22 +4310,48 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ], - "description": "Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable." - }, - "region": { - "type": "string", - "description": "The AWS region. Defaults to the `AWS_REGION` environment variable.", - "examples": [ - "us-east-1", - "us-west-2", - "eu-west-1" - ] - }, - "baseUrl": { - "type": "string", - "format": "url", + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ], + "description": "Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable." + }, + "region": { + "type": "string", + "description": "The AWS region. Defaults to the `AWS_REGION` environment variable.", + "examples": [ + "us-east-1", + "us-west-2", + "eu-west-1" + ] + }, + "baseUrl": { + "type": "string", + "format": "url", "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$", "description": "Optional base URL." }, @@ -3433,6 +4395,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3490,6 +4478,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -3521,6 +4535,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -3571,6 +4611,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3632,6 +4698,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -3706,6 +4798,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3763,6 +4881,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -3813,6 +4957,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3870,6 +5040,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -3934,6 +5130,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4007,6 +5229,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -4057,6 +5305,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4132,6 +5406,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -4196,6 +5496,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4253,6 +5579,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -4303,6 +5655,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4366,6 +5744,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -4436,6 +5840,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4493,6 +5923,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -4542,6 +5998,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4586,6 +6068,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4658,6 +6166,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -4708,6 +6242,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4769,22 +6329,48 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ], - "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." - }, - "baseUrl": { - "type": "string", - "format": "url", - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$", - "description": "Optional base URL." - }, - "temperature": { - "type": "number", - "description": "Optional temperature setting to use with the model." - }, - "headers": { - "type": "object", + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ], + "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." + }, + "baseUrl": { + "type": "string", + "format": "url", + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$", + "description": "Optional base URL." + }, + "temperature": { + "type": "number", + "description": "Optional temperature setting to use with the model." + }, + "headers": { + "type": "object", "description": "Optional headers to use with the model.", "patternProperties": { "^[!#$%&'*+\\-.^_`|~0-9A-Za-z]+$": { @@ -4819,6 +6405,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -4892,6 +6504,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "The private key of the GitHub App." @@ -4954,6 +6592,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "The private key of the GitHub App." @@ -5024,6 +6688,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5054,6 +6744,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5124,6 +6840,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5154,6 +6896,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5221,6 +6989,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5251,6 +7045,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5303,6 +7123,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5333,6 +7179,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5363,6 +7235,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5416,6 +7314,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5446,6 +7370,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5476,6 +7426,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5529,6 +7505,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5559,6 +7561,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5589,6 +7617,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5642,6 +7696,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -5696,6 +7776,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5726,6 +7832,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -5782,40 +7914,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -5842,63 +7970,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "JumpCloudIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "jumpcloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -5925,34 +8026,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -5967,16 +8064,16 @@ const schema = { "issuer" ] }, - "IdiraIdentityProviderConfig": { + "JumpCloudIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "idira" + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { "const": "sso" @@ -6008,6 +8105,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -6038,66 +8161,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "BitbucketServerIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-server" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -6124,50 +8217,34 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ @@ -6175,27 +8252,22 @@ const schema = { "purpose", "clientId", "clientSecret", - "baseUrl" + "issuer" ] - } - }, - "oneOf": [ - { + }, + "IdiraIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "github" + "const": "idira" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -6224,80 +8296,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "gitlab" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -6324,77 +8352,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", - "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "google" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -6421,34 +8408,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -6459,22 +8442,26 @@ const schema = { "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, - { + "BitbucketServerIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "okta" + "const": "bitbucket-server" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -6503,40 +8490,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -6563,8 +8546,46 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "description": "The URL of the Bitbucket Server/Data Center host.", + "examples": [ + "https://bitbucket.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ @@ -6572,22 +8593,27 @@ const schema = { "purpose", "clientId", "clientSecret", - "issuer" + "baseUrl" ] - }, + } + }, + "oneOf": [ { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "keycloak" + "const": "github" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -6616,6 +8642,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -6646,46 +8698,56 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -6693,14 +8755,17 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "gitlab" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -6729,6 +8794,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -6759,46 +8850,56 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -6806,16 +8907,16 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "google" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -6842,55 +8943,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -6923,34 +8999,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -6961,8 +9033,7 @@ const schema = { "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -6970,17 +9041,14 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-cloud" + "const": "okta" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -7009,6 +9077,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7039,31 +9133,110 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] }, { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "keycloak" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." }, "purpose": { "const": "sso" @@ -7095,6 +9268,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7125,6 +9324,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7155,6 +9380,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -7172,11 +9423,11 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "idira" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { "const": "sso" @@ -7208,6 +9459,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7238,6 +9515,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7268,6 +9571,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -7285,19 +9614,16 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-server" + "const": "gcp-iap" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, - "clientId": { + "audience": { "anyOf": [ { "type": "object", @@ -7324,67 +9650,913 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", - "clientId", - "clientSecret", - "baseUrl" + "audience" ] - } - ] - } - }, - "additionalProperties": false - }, - { - "type": "array", + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "authentik" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-cloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "jumpcloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "idira" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-server" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "description": "The URL of the Bitbucket Server/Data Center host.", + "examples": [ + "https://bitbucket.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "baseUrl" + ] + } + ] + } + }, + "additionalProperties": false + }, + { + "type": "array", "items": { "$schema": "http://json-schema.org/draft-07/schema#", "title": "IdentityProviderConfig", @@ -7394,19 +10566,1683 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "github" + "const": "github" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "GitLabIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gitlab" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "GoogleIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "google" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "OktaIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "okta" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "KeycloakIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "keycloak" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "MicrosoftEntraIDIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "microsoft-entra-id" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "GCPIAPIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gcp-iap" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + }, + "purpose": { + "const": "sso" + }, + "audience": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "audience" + ] + }, + "BitbucketCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "bitbucket-cloud" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + "AuthentikIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "authentik" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "JumpCloudIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { - "enum": [ - "sso", - "account_linking" + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "clientSecret": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + }, + "issuer": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } + ] + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret", + "issuer" + ] + }, + "IdiraIdentityProviderConfig": { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "idira" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." + }, + "purpose": { + "const": "sso" + }, + "clientId": { + "anyOf": [ + { + "type": "object", + "properties": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false + } ] }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -7433,10 +12269,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -7463,42 +12325,54 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, - "GitLabIdentityProviderConfig": { + "BitbucketServerIdentityProviderConfig": { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "gitlab" + "const": "bitbucket-server" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." }, "purpose": { "enum": [ @@ -7533,6 +12407,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7563,17 +12463,40 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, "baseUrl": { "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "description": "The URL of the Bitbucket Server/Data Center host.", "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" + "https://bitbucket.example.com" ], "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" }, @@ -7586,22 +12509,28 @@ const schema = { "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "baseUrl" ] - }, - "GoogleIdentityProviderConfig": { + } + }, + "oneOf": [ + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "google" + "const": "github" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -7630,62 +12559,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - "OktaIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "okta" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." - }, - "purpose": { - "const": "sso" }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -7712,40 +12615,76 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://github.com", + "description": "The URL of the GitHub host. Defaults to https://github.com", + "examples": [ + "https://github.com", + "https://github.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false + } + }, + "required": [ + "provider", + "purpose", + "clientId", + "clientSecret" + ] + }, + { + "type": "object", + "additionalProperties": false, + "properties": { + "provider": { + "const": "gitlab" + }, + "displayName": { + "type": "string", + "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." + }, + "purpose": { + "enum": [ + "sso", + "account_linking" + ] + }, + "clientId": { "anyOf": [ { "type": "object", @@ -7772,57 +12711,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "KeycloakIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "keycloak" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -7855,58 +12767,68 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "baseUrl": { + "type": "string", + "format": "url", + "default": "https://gitlab.com", + "description": "The URL of the GitLab host. Defaults to https://gitlab.com", + "examples": [ + "https://gitlab.com", + "https://gitlab.example.com" + ], + "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, - "MicrosoftEntraIDIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "google" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." }, "purpose": { "const": "sso" @@ -7938,6 +12860,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -7968,34 +12916,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8006,25 +12950,24 @@ const schema = { "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, - "GCPIAPIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "okta" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -8051,58 +12994,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - "BitbucketCloudIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-cloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8135,66 +13050,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - "AuthentikIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -8221,34 +13106,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8263,16 +13144,16 @@ const schema = { "issuer" ] }, - "JumpCloudIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "keycloak" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." }, "purpose": { "const": "sso" @@ -8304,40 +13185,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -8363,64 +13240,37 @@ const schema = { "required": [ "googleCloudSecret" ], - "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - "IdiraIdentityProviderConfig": { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "idira" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + "additionalProperties": false + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -8447,34 +13297,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8489,22 +13335,19 @@ const schema = { "issuer" ] }, - "BitbucketServerIdentityProviderConfig": { + { "type": "object", "additionalProperties": false, "properties": { "provider": { - "const": "bitbucket-server" + "const": "microsoft-entra-id" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Server'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." }, "purpose": { - "enum": [ - "sso", - "account_linking" - ] + "const": "sso" }, "clientId": { "anyOf": [ @@ -8533,80 +13376,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "description": "The URL of the Bitbucket Server/Data Center host.", - "examples": [ - "https://bitbucket.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "baseUrl" - ] - } - }, - "oneOf": [ - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "github" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitHub'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -8633,80 +13432,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://github.com", - "description": "The URL of the GitHub host. Defaults to https://github.com", - "examples": [ - "https://github.com", - "https://github.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "gitlab" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'GitLab'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] - }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -8733,60 +13488,42 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "baseUrl": { - "type": "string", - "format": "url", - "default": "https://gitlab.com", - "description": "The URL of the GitLab host. Defaults to https://gitlab.com", - "examples": [ - "https://gitlab.com", - "https://gitlab.example.com" - ], - "pattern": "^https?:\\/\\/[^\\s/$.?#].[^\\s]*$" - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -8794,16 +13531,16 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "google" + "const": "gcp-iap" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." }, "purpose": { "const": "sso" }, - "clientId": { + "audience": { "anyOf": [ { "type": "object", @@ -8830,34 +13567,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -8867,8 +13600,7 @@ const schema = { "required": [ "provider", "purpose", - "clientId", - "clientSecret" + "audience" ] }, { @@ -8876,11 +13608,11 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "okta" + "const": "authentik" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Okta'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." }, "purpose": { "const": "sso" @@ -8912,40 +13644,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -8972,63 +13700,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "keycloak" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Keycloak'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -9055,34 +13756,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -9102,14 +13799,17 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "microsoft-entra-id" + "const": "bitbucket-cloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Microsoft Entra ID'." + "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." }, "purpose": { - "const": "sso" + "enum": [ + "sso", + "account_linking" + ] }, "clientId": { "anyOf": [ @@ -9138,6 +13838,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -9168,46 +13894,45 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] + }, + "accountLinkingRequired": { + "type": "boolean", + "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret", - "issuer" + "clientSecret" ] }, { @@ -9215,16 +13940,16 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "gcp-iap" + "const": "jumpcloud" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Google Cloud IAP'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." }, "purpose": { "const": "sso" }, - "audience": { + "clientId": { "anyOf": [ { "type": "object", @@ -9251,55 +13976,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "audience" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "authentik" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Authentik'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -9332,66 +14032,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "bitbucket-cloud" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen and account settings. Defaults to 'Bitbucket Cloud'." - }, - "purpose": { - "enum": [ - "sso", - "account_linking" - ] }, - "clientId": { + "issuer": { "anyOf": [ { "type": "object", @@ -9418,49 +14088,42 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] - }, - "accountLinkingRequired": { - "type": "boolean", - "default": false } }, "required": [ "provider", "purpose", "clientId", - "clientSecret" + "clientSecret", + "issuer" ] }, { @@ -9468,11 +14131,11 @@ const schema = { "additionalProperties": false, "properties": { "provider": { - "const": "jumpcloud" + "const": "idira" }, "displayName": { "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'JumpCloud'." + "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." }, "purpose": { "const": "sso" @@ -9504,40 +14167,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "clientSecret": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "issuer": { + "clientSecret": { "anyOf": [ { "type": "object", @@ -9564,63 +14223,36 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - } - }, - "required": [ - "provider", - "purpose", - "clientId", - "clientSecret", - "issuer" - ] - }, - { - "type": "object", - "additionalProperties": false, - "properties": { - "provider": { - "const": "idira" - }, - "displayName": { - "type": "string", - "description": "Optional human-readable label shown on the login screen. Defaults to 'Idira'." - }, - "purpose": { - "const": "sso" - }, - "clientId": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } ] }, - "clientSecret": { + "issuer": { "anyOf": [ { "type": "object", @@ -9647,34 +14279,30 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false - } - ] - }, - "issuer": { - "anyOf": [ + }, { "type": "object", "properties": { - "env": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -9733,6 +14361,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -9763,6 +14417,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/packages/schemas/src/v3/index.type.ts b/packages/schemas/src/v3/index.type.ts index 13027d9ff..1ffeff673 100644 --- a/packages/schemas/src/v3/index.type.ts +++ b/packages/schemas/src/v3/index.type.ts @@ -225,6 +225,18 @@ export interface EnvironmentOverrides { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } | { @@ -260,6 +272,18 @@ export interface GithubConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitHub host. Defaults to https://github.com @@ -357,6 +381,18 @@ export interface GitlabConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitLab host. Defaults to https://gitlab.com @@ -440,6 +476,18 @@ export interface GiteaConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Gitea host. Defaults to https://gitea.com @@ -546,6 +594,18 @@ export interface BitbucketConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Bitbucket URL @@ -615,6 +675,18 @@ export interface AzureDevOpsConnectionConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Azure DevOps host. For Azure DevOps Cloud, use https://dev.azure.com. For Azure DevOps Server, use your server URL. @@ -724,6 +796,18 @@ export interface AmazonBedrockLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional secret access key to use with the model. Defaults to the `AWS_SECRET_ACCESS_KEY` environment variable. @@ -740,6 +824,18 @@ export interface AmazonBedrockLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable. @@ -756,6 +852,18 @@ export interface AmazonBedrockLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The AWS region. Defaults to the `AWS_REGION` environment variable. @@ -794,6 +902,18 @@ export interface LanguageModelHeaders { */ googleCloudSecret: string; } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; + } ); } export interface AnthropicLanguageModel { @@ -824,6 +944,18 @@ export interface AnthropicLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable. @@ -840,6 +972,18 @@ export interface AnthropicLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -883,6 +1027,18 @@ export interface AzureLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Sets a custom api version. Defaults to `preview`. @@ -934,6 +1090,18 @@ export interface DeepSeekLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -973,6 +1141,18 @@ export interface GoogleGenerativeAILanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1028,6 +1208,18 @@ export interface GoogleVertexAnthropicLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1075,6 +1267,18 @@ export interface GoogleVertexLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1122,6 +1326,18 @@ export interface MistralLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1161,6 +1377,18 @@ export interface OpenAILanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1208,6 +1436,18 @@ export interface OpenAICompatibleLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Base URL of the OpenAI-compatible chat completions API endpoint. @@ -1247,6 +1487,18 @@ export interface LanguageModelQueryParams { */ googleCloudSecret: string; } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; + } ); } export interface OpenRouterLanguageModel { @@ -1277,6 +1529,18 @@ export interface OpenRouterLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1316,6 +1580,18 @@ export interface XaiLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -1355,6 +1631,18 @@ export interface GitHubAppConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface GitHubIdentityProviderConfig { @@ -1376,6 +1664,18 @@ export interface GitHubIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1389,6 +1689,18 @@ export interface GitHubIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitHub host. Defaults to https://github.com @@ -1415,6 +1727,18 @@ export interface GitLabIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1428,6 +1752,18 @@ export interface GitLabIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the GitLab host. Defaults to https://gitlab.com @@ -1454,6 +1790,18 @@ export interface GoogleIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1467,6 +1815,18 @@ export interface GoogleIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface OktaIdentityProviderConfig { @@ -1488,6 +1848,18 @@ export interface OktaIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1501,6 +1873,18 @@ export interface OktaIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -1514,6 +1898,18 @@ export interface OktaIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface KeycloakIdentityProviderConfig { @@ -1535,6 +1931,18 @@ export interface KeycloakIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1548,6 +1956,18 @@ export interface KeycloakIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -1561,6 +1981,18 @@ export interface KeycloakIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface MicrosoftEntraIDIdentityProviderConfig { @@ -1582,6 +2014,18 @@ export interface MicrosoftEntraIDIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1595,6 +2039,18 @@ export interface MicrosoftEntraIDIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -1608,6 +2064,18 @@ export interface MicrosoftEntraIDIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface GCPIAPIdentityProviderConfig { @@ -1629,6 +2097,18 @@ export interface GCPIAPIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface AuthentikIdentityProviderConfig { @@ -1650,6 +2130,18 @@ export interface AuthentikIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1663,6 +2155,18 @@ export interface AuthentikIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -1676,6 +2180,18 @@ export interface AuthentikIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface BitbucketCloudIdentityProviderConfig { @@ -1697,6 +2213,18 @@ export interface BitbucketCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1710,6 +2238,18 @@ export interface BitbucketCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; accountLinkingRequired?: boolean; } @@ -1732,6 +2272,18 @@ export interface JumpCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1745,6 +2297,18 @@ export interface JumpCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -1758,6 +2322,18 @@ export interface JumpCloudIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface IdiraIdentityProviderConfig { @@ -1779,6 +2355,18 @@ export interface IdiraIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1792,6 +2380,18 @@ export interface IdiraIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; issuer: | { @@ -1805,6 +2405,18 @@ export interface IdiraIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; } export interface BitbucketServerIdentityProviderConfig { @@ -1826,6 +2438,18 @@ export interface BitbucketServerIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; clientSecret: | { @@ -1839,6 +2463,18 @@ export interface BitbucketServerIdentityProviderConfig { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The URL of the Bitbucket Server/Data Center host. diff --git a/packages/schemas/src/v3/languageModel.schema.ts b/packages/schemas/src/v3/languageModel.schema.ts index ab418ce79..39f3f8a74 100644 --- a/packages/schemas/src/v3/languageModel.schema.ts +++ b/packages/schemas/src/v3/languageModel.schema.ts @@ -46,6 +46,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -77,6 +103,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -108,6 +160,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -166,6 +244,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -223,6 +327,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -254,6 +384,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -304,6 +460,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -365,6 +547,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -439,6 +647,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -496,6 +730,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -546,6 +806,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -603,6 +889,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -667,6 +979,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -740,6 +1078,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -790,6 +1154,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -865,6 +1255,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -929,6 +1345,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -986,6 +1428,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -1014,26 +1482,52 @@ const schema = { { "type": "object", "properties": { - "env": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -1099,6 +1593,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -1169,6 +1689,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1226,6 +1772,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -1275,6 +1847,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1319,6 +1917,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1391,6 +2015,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -1441,6 +2091,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1502,6 +2178,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." @@ -1552,6 +2254,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1612,6 +2340,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1643,6 +2397,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1674,6 +2454,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -1732,6 +2538,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1789,6 +2621,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model, sent as the `x-api-key` header. Defaults to the `ANTHROPIC_API_KEY` environment variable." @@ -1820,6 +2678,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable." @@ -1870,6 +2754,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -1931,6 +2841,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `AZURE_API_KEY` environment variable." @@ -2005,6 +2941,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2062,6 +3024,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `DEEPSEEK_API_KEY` environment variable." @@ -2112,6 +3100,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2169,6 +3183,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `GOOGLE_GENERATIVE_AI_API_KEY` environment variable." @@ -2233,6 +3273,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2306,6 +3372,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional file path to service account credentials JSON. Defaults to the `GOOGLE_APPLICATION_CREDENTIALS` environment variable or application default credentials." @@ -2356,6 +3448,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2409,26 +3527,52 @@ const schema = { { "type": "object", "properties": { - "env": { + "env": { + "type": "string", + "description": "The name of the environment variable that contains the token." + } + }, + "required": [ + "env" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "googleCloudSecret": { + "type": "string", + "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + } + }, + "required": [ + "googleCloudSecret" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { "type": "string", - "description": "The name of the environment variable that contains the token." + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." } }, "required": [ - "env" + "file" ], "additionalProperties": false }, { "type": "object", "properties": { - "googleCloudSecret": { + "azureKeyVaultSecret": { "type": "string", - "description": "The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets" + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" } }, "required": [ - "googleCloudSecret" + "azureKeyVaultSecret" ], "additionalProperties": false } @@ -2495,6 +3639,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2552,6 +3722,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `MISTRAL_API_KEY` environment variable." @@ -2602,6 +3798,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2665,6 +3887,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENAI_API_KEY` environment variable." @@ -2735,6 +3983,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2792,6 +4066,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key. If specified, adds an `Authorization` header to request headers with the value Bearer ." @@ -2841,6 +4141,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2885,6 +4211,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -2957,6 +4309,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `OPENROUTER_API_KEY` environment variable." @@ -3007,6 +4385,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -3068,6 +4472,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ], "description": "Optional API key to use with the model. Defaults to the `XAI_API_KEY` environment variable." @@ -3118,6 +4548,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/packages/schemas/src/v3/languageModel.type.ts b/packages/schemas/src/v3/languageModel.type.ts index 5c3b25668..f1e0dfac7 100644 --- a/packages/schemas/src/v3/languageModel.type.ts +++ b/packages/schemas/src/v3/languageModel.type.ts @@ -42,6 +42,18 @@ export interface AmazonBedrockLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional secret access key to use with the model. Defaults to the `AWS_SECRET_ACCESS_KEY` environment variable. @@ -58,6 +70,18 @@ export interface AmazonBedrockLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional session token to use with the model. Defaults to the `AWS_SESSION_TOKEN` environment variable. @@ -74,6 +98,18 @@ export interface AmazonBedrockLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * The AWS region. Defaults to the `AWS_REGION` environment variable. @@ -112,6 +148,18 @@ export interface LanguageModelHeaders { */ googleCloudSecret: string; } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; + } ); } export interface AnthropicLanguageModel { @@ -142,6 +190,18 @@ export interface AnthropicLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional auth token to use with the model, sent as the `Authorization: Bearer` header. Defaults to the `ANTHROPIC_AUTH_TOKEN` environment variable. @@ -158,6 +218,18 @@ export interface AnthropicLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -201,6 +273,18 @@ export interface AzureLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Sets a custom api version. Defaults to `preview`. @@ -252,6 +336,18 @@ export interface DeepSeekLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -291,6 +387,18 @@ export interface GoogleGenerativeAILanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -346,6 +454,18 @@ export interface GoogleVertexAnthropicLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -393,6 +513,18 @@ export interface GoogleVertexLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -440,6 +572,18 @@ export interface MistralLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -479,6 +623,18 @@ export interface OpenAILanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -526,6 +682,18 @@ export interface OpenAICompatibleLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Base URL of the OpenAI-compatible chat completions API endpoint. @@ -565,6 +733,18 @@ export interface LanguageModelQueryParams { */ googleCloudSecret: string; } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; + } ); } export interface OpenRouterLanguageModel { @@ -595,6 +775,18 @@ export interface OpenRouterLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. @@ -634,6 +826,18 @@ export interface XaiLanguageModel { * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; /** * Optional base URL. diff --git a/packages/schemas/src/v3/shared.schema.ts b/packages/schemas/src/v3/shared.schema.ts index 91a34529b..7945a38f2 100644 --- a/packages/schemas/src/v3/shared.schema.ts +++ b/packages/schemas/src/v3/shared.schema.ts @@ -30,6 +30,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, @@ -110,6 +136,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } @@ -154,6 +206,32 @@ const schema = { "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] } diff --git a/packages/schemas/src/v3/shared.type.ts b/packages/schemas/src/v3/shared.type.ts index 043d1c80c..2186c042b 100644 --- a/packages/schemas/src/v3/shared.type.ts +++ b/packages/schemas/src/v3/shared.type.ts @@ -16,6 +16,18 @@ export type Token = * The resource name of a Google Cloud secret. Must be in the format `projects//secrets//versions/`. See https://cloud.google.com/secret-manager/docs/creating-and-accessing-secrets */ googleCloudSecret: string; + } + | { + /** + * The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret). + */ + file: string; + } + | { + /** + * The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets + */ + azureKeyVaultSecret: string; }; export interface Shared { diff --git a/packages/shared/package.json b/packages/shared/package.json index bda6b8ebc..6d40c8dec 100644 --- a/packages/shared/package.json +++ b/packages/shared/package.json @@ -11,6 +11,8 @@ "tool:resolve-env-overrides": "tsx tools/resolveEnvOverrides.ts" }, "dependencies": { + "@azure/identity": "^4.13.3", + "@azure/keyvault-secrets": "^4.11.2", "@google-cloud/secret-manager": "^6.1.1", "@logtail/node": "^0.5.2", "@logtail/winston": "^0.5.2", diff --git a/packages/shared/src/crypto.test.ts b/packages/shared/src/crypto.test.ts new file mode 100644 index 000000000..62dbf3409 --- /dev/null +++ b/packages/shared/src/crypto.test.ts @@ -0,0 +1,163 @@ +import { describe, test, expect, vi, beforeEach, afterEach } from 'vitest'; +import fs from 'fs'; +import os from 'os'; +import path from 'path'; + +const mocks = vi.hoisted(() => ({ + getSecret: vi.fn(), + secretClientConstructor: vi.fn(), + defaultAzureCredentialConstructor: vi.fn(), +})); + +// env.server.js imports crypto.js and loads the config at import time. +vi.mock('./env.server.js', () => ({ + env: {}, +})); + +vi.mock('@azure/identity', () => ({ + DefaultAzureCredential: class { + constructor() { + mocks.defaultAzureCredentialConstructor(); + } + }, +})); + +vi.mock('@azure/keyvault-secrets', async (importOriginal) => { + const actual = await importOriginal(); + return { + parseKeyVaultSecretIdentifier: actual.parseKeyVaultSecretIdentifier, + SecretClient: class { + constructor(vaultUrl: string) { + mocks.secretClientConstructor(vaultUrl); + } + getSecret = mocks.getSecret; + }, + }; +}); + +import type { Token } from '@sourcebot/schemas/v3/shared.type'; +import { getTokenFromConfig } from './crypto.js'; + +describe('getTokenFromConfig', () => { + describe('env', () => { + afterEach(() => { + delete process.env.TEST_TOKEN; + }); + + test('returns the trimmed value of the environment variable', async () => { + process.env.TEST_TOKEN = ' env-token\n'; + await expect(getTokenFromConfig({ env: 'TEST_TOKEN' })).resolves.toBe('env-token'); + }); + + test('throws when the environment variable is not set', async () => { + await expect(getTokenFromConfig({ env: 'TEST_TOKEN' })).rejects.toThrow('Environment variable TEST_TOKEN not found.'); + }); + }); + + describe('file', () => { + let tmpDir: string; + + beforeEach(() => { + tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'sourcebot-token-')); + }); + + afterEach(() => { + fs.rmSync(tmpDir, { recursive: true, force: true }); + }); + + test('returns the trimmed contents of the file', async () => { + const tokenPath = path.join(tmpDir, 'token'); + fs.writeFileSync(tokenPath, 'ghs_file-token\n'); + + await expect(getTokenFromConfig({ file: tokenPath })).resolves.toBe('ghs_file-token'); + }); + + test('re-reads the file on every call so rotated tokens are picked up', async () => { + const tokenPath = path.join(tmpDir, 'token'); + fs.writeFileSync(tokenPath, 'ghs_first'); + await expect(getTokenFromConfig({ file: tokenPath })).resolves.toBe('ghs_first'); + + fs.writeFileSync(tokenPath, 'ghs_second'); + await expect(getTokenFromConfig({ file: tokenPath })).resolves.toBe('ghs_second'); + }); + + test('throws when the file does not exist', async () => { + const tokenPath = path.join(tmpDir, 'missing'); + + await expect(getTokenFromConfig({ file: tokenPath })).rejects.toThrow(`Failed to read token file ${tokenPath}`); + }); + + test('throws when the file is empty', async () => { + const tokenPath = path.join(tmpDir, 'token'); + fs.writeFileSync(tokenPath, ' \n'); + + await expect(getTokenFromConfig({ file: tokenPath })).rejects.toThrow(`Token file ${tokenPath} is empty.`); + }); + }); + + describe('azureKeyVaultSecret', () => { + beforeEach(() => { + mocks.getSecret.mockReset(); + mocks.secretClientConstructor.mockReset(); + }); + + test('fetches the latest version when no version is given', async () => { + mocks.getSecret.mockResolvedValue({ value: 'kv-token\n' }); + + const result = await getTokenFromConfig({ azureKeyVaultSecret: 'https://latest-vault.vault.azure.net/secrets/github-token' }); + + expect(result).toBe('kv-token'); + expect(mocks.secretClientConstructor).toHaveBeenCalledWith('https://latest-vault.vault.azure.net'); + expect(mocks.getSecret).toHaveBeenCalledWith('github-token', { version: undefined }); + }); + + test('fetches a specific version when one is given', async () => { + mocks.getSecret.mockResolvedValue({ value: 'kv-token' }); + + await getTokenFromConfig({ azureKeyVaultSecret: 'https://versioned-vault.vault.azure.net/secrets/github-token/0123abcd' }); + + expect(mocks.getSecret).toHaveBeenCalledWith('github-token', { version: '0123abcd' }); + }); + + test('reuses the client for the same vault and does not cache the secret value', async () => { + mocks.getSecret + .mockResolvedValueOnce({ value: 'kv-first' }) + .mockResolvedValueOnce({ value: 'kv-second' }); + const token = { azureKeyVaultSecret: 'https://cached-vault.vault.azure.net/secrets/github-token' }; + + await expect(getTokenFromConfig(token)).resolves.toBe('kv-first'); + await expect(getTokenFromConfig(token)).resolves.toBe('kv-second'); + + expect(mocks.secretClientConstructor).toHaveBeenCalledTimes(1); + expect(mocks.getSecret).toHaveBeenCalledTimes(2); + }); + + test('throws when the secret has no value', async () => { + mocks.getSecret.mockResolvedValue({ value: undefined }); + const id = 'https://empty-vault.vault.azure.net/secrets/github-token'; + + await expect(getTokenFromConfig({ azureKeyVaultSecret: id })).rejects.toThrow(`Failed to access Azure Key Vault secret ${id}: Secret ${id} has no value.`); + }); + + test('wraps errors from Key Vault', async () => { + mocks.getSecret.mockRejectedValue(new Error('Forbidden')); + const id = 'https://forbidden-vault.vault.azure.net/secrets/github-token'; + + await expect(getTokenFromConfig({ azureKeyVaultSecret: id })).rejects.toThrow(`Failed to access Azure Key Vault secret ${id}: Forbidden`); + }); + + test.each([ + 'not-a-url', + 'https://my-vault.vault.azure.net/keys/github-token', + 'https://my-vault.vault.azure.net/secrets/', + 'http://my-vault.vault.azure.net/secrets/github-token', + ])('rejects malformed identifier %s without calling Key Vault', async (id) => { + await expect(getTokenFromConfig({ azureKeyVaultSecret: id })).rejects.toThrow('Expected the format'); + expect(mocks.getSecret).not.toHaveBeenCalled(); + }); + }); + + test('throws on an unknown token shape', async () => { + await expect(getTokenFromConfig({ unknown: 'value' } as unknown as Token)).rejects.toThrow('Invalid token configuration'); + }); +}); diff --git a/packages/shared/src/crypto.ts b/packages/shared/src/crypto.ts index b04e65d3b..cdd9e6d4d 100644 --- a/packages/shared/src/crypto.ts +++ b/packages/shared/src/crypto.ts @@ -4,6 +4,8 @@ import { z } from 'zod'; import { env } from './env.server.js'; import { Token } from '@sourcebot/schemas/v3/shared.type'; import { SecretManagerServiceClient } from "@google-cloud/secret-manager"; +import { DefaultAzureCredential } from "@azure/identity"; +import { parseKeyVaultSecretIdentifier, SecretClient } from "@azure/keyvault-secrets"; import { API_KEY_PREFIX, OAUTH_ACCESS_TOKEN_PREFIX, OAUTH_REFRESH_TOKEN_PREFIX, SCIM_TOKEN_PREFIX, SCOPED_ACCESS_TOKEN_PREFIX } from './constants.js'; const algorithm = 'aes-256-cbc'; @@ -121,6 +123,22 @@ export function verifySignature(data: string, signature: string, publicKeyPath: } } +// Clients (and the shared credential) are cached so that the credential's +// access token is reused across lookups. Secret values themselves are not cached. +let azureCredential: DefaultAzureCredential | undefined; +const azureKeyVaultSecretClients = new Map(); + +const getAzureKeyVaultSecretClient = (vaultUrl: string): SecretClient => { + let client = azureKeyVaultSecretClients.get(vaultUrl); + if (!client) { + azureCredential ??= new DefaultAzureCredential(); + client = new SecretClient(vaultUrl, azureCredential); + azureKeyVaultSecretClients.set(vaultUrl, client); + } + + return client; +}; + export const getTokenFromConfig = async (token: Token): Promise => { if ('env' in token) { const envToken = process.env[token.env]; @@ -144,6 +162,41 @@ export const getTokenFromConfig = async (token: Token): Promise => { } catch (error) { throw new Error(`Failed to access Google Cloud secret ${token.googleCloudSecret}: ${error instanceof Error ? error.message : String(error)}`); } + } else if ('file' in token) { + // Read on every call (no caching) so that rotated secrets + // (e.g., mounted Kubernetes secrets) are picked up without a restart. + let contents: string; + try { + contents = await fs.promises.readFile(token.file, 'utf8'); + } catch (error) { + throw new Error(`Failed to read token file ${token.file}: ${error instanceof Error ? error.message : String(error)}`); + } + + const fileToken = contents.trim(); + if (!fileToken) { + throw new Error(`Token file ${token.file} is empty.`); + } + + return fileToken; + } else if ('azureKeyVaultSecret' in token) { + try { + // parseKeyVaultSecretIdentifier does not check the collection, so a + // key or certificate URL would otherwise resolve to a same-named secret. + if (!/^https:\/\/[^/]+\/secrets\/[^/]+(\/[^/]+)?$/.test(token.azureKeyVaultSecret)) { + throw new Error('Expected the format https://.vault.azure.net/secrets/[/].'); + } + + const { vaultUrl, name, version } = parseKeyVaultSecretIdentifier(token.azureKeyVaultSecret); + const secret = await getAzureKeyVaultSecretClient(vaultUrl).getSecret(name, { version }); + + if (!secret.value) { + throw new Error(`Secret ${token.azureKeyVaultSecret} has no value.`); + } + + return secret.value.trim(); + } catch (error) { + throw new Error(`Failed to access Azure Key Vault secret ${token.azureKeyVaultSecret}: ${error instanceof Error ? error.message : String(error)}`); + } } else { throw new Error('Invalid token configuration'); } diff --git a/schemas/v3/shared.json b/schemas/v3/shared.json index c45c834f0..a7aaf6e80 100644 --- a/schemas/v3/shared.json +++ b/schemas/v3/shared.json @@ -29,6 +29,32 @@ "googleCloudSecret" ], "additionalProperties": false + }, + { + "type": "object", + "properties": { + "file": { + "type": "string", + "description": "The path to a file that contains the token. The file is re-read each time the token is used, so its contents can be rotated without restarting Sourcebot (e.g., a mounted Kubernetes secret)." + } + }, + "required": [ + "file" + ], + "additionalProperties": false + }, + { + "type": "object", + "properties": { + "azureKeyVaultSecret": { + "type": "string", + "description": "The identifier of an Azure Key Vault secret. Must be in the format `https://.vault.azure.net/secrets/` or `https://.vault.azure.net/secrets//`. If the version is omitted, the latest version is used. Authenticates using DefaultAzureCredential. See https://learn.microsoft.com/en-us/azure/key-vault/secrets/about-secrets" + } + }, + "required": [ + "azureKeyVaultSecret" + ], + "additionalProperties": false } ] }, diff --git a/yarn.lock b/yarn.lock index 16aa3ddd3..c3481f4b0 100644 --- a/yarn.lock +++ b/yarn.lock @@ -957,6 +957,209 @@ __metadata: languageName: node linkType: hard +"@azure-rest/core-client@npm:^2.3.3": + version: 2.9.0 + resolution: "@azure-rest/core-client@npm:2.9.0" + dependencies: + "@azure/abort-controller": "npm:^2.1.2" + "@azure/core-auth": "npm:^1.10.0" + "@azure/core-rest-pipeline": "npm:^1.24.0" + "@azure/core-tracing": "npm:^1.3.0" + "@typespec/ts-http-runtime": "npm:^0.3.8" + tslib: "npm:^2.6.2" + checksum: 10c0/14c7f8b6e6071c9e54f11b40120bd4b5cf63a994da2e3d06a871f3690c0023edc5149c32874317548161f0051efd4622032e4324f441ecc2a7cb270d5060610f + languageName: node + linkType: hard + +"@azure/abort-controller@npm:^2.0.0, @azure/abort-controller@npm:^2.1.2": + version: 2.2.0 + resolution: "@azure/abort-controller@npm:2.2.0" + dependencies: + tslib: "npm:^2.6.2" + checksum: 10c0/8de5bfe64802b6a57e9567eaec789dfd46774b5a6d1420345788f0879c229a48c8ff3c8c6eedb3dc7c0d8d9fb7651bf83a5fb496d8323f65917be8c02c2b7268 + languageName: node + linkType: hard + +"@azure/core-auth@npm:^1.10.0, @azure/core-auth@npm:^1.3.0, @azure/core-auth@npm:^1.9.0": + version: 1.11.0 + resolution: "@azure/core-auth@npm:1.11.0" + dependencies: + "@azure/abort-controller": "npm:^2.1.2" + "@azure/core-util": "npm:^1.13.0" + tslib: "npm:^2.6.2" + checksum: 10c0/40e5ee735bf40ba0e99807ae5771238212ee97552574a59e17e18795e2c28fcdb58912057003337a5f066cf7acb7fa65eb3d9f8b2b613fe98e449e940aef3f59 + languageName: node + linkType: hard + +"@azure/core-client@npm:^1.9.2": + version: 1.11.1 + resolution: "@azure/core-client@npm:1.11.1" + dependencies: + "@azure/abort-controller": "npm:^2.1.2" + "@azure/core-auth": "npm:^1.10.0" + "@azure/core-rest-pipeline": "npm:^1.22.0" + "@azure/core-tracing": "npm:^1.3.0" + "@azure/core-util": "npm:^1.13.0" + "@azure/logger": "npm:^1.3.0" + tslib: "npm:^2.6.2" + checksum: 10c0/1478c8ccf24eb850c11dd7d54379610d6878237a3c08ff870e03cf5977452314e2f692dccb1e229a22a578dcccb9b300dd9492042853504a70032f06c443837f + languageName: node + linkType: hard + +"@azure/core-lro@npm:^2.7.2": + version: 2.7.2 + resolution: "@azure/core-lro@npm:2.7.2" + dependencies: + "@azure/abort-controller": "npm:^2.0.0" + "@azure/core-util": "npm:^1.2.0" + "@azure/logger": "npm:^1.0.0" + tslib: "npm:^2.6.2" + checksum: 10c0/bee809e47661b40021bbbedf88de54019715fdfcc95ac552b1d901719c29d78e293eeab51257b8f5155aac768eb4ea420715004d00d6e32109f5f97db5960d39 + languageName: node + linkType: hard + +"@azure/core-paging@npm:^1.6.2": + version: 1.7.0 + resolution: "@azure/core-paging@npm:1.7.0" + dependencies: + tslib: "npm:^2.6.2" + checksum: 10c0/d477e32d6235709a2206d8e95c131056766ff39054efb4ec7e8c773d0ef9dd3ad26d2e9e9a7e2f045895166ecd1867a81561ab553a6b57973232f2571ed738ff + languageName: node + linkType: hard + +"@azure/core-process@npm:^1.0.0": + version: 1.0.0 + resolution: "@azure/core-process@npm:1.0.0" + checksum: 10c0/351283f1a9214a68ba6b6b2c0ce38fb42edc5adb861c350b1308b6bca6a790fc6d57f7aba3aa4fbaacbb2ae6dd095b0e014c0a5cf83e5e2e5c742813e17ce687 + languageName: node + linkType: hard + +"@azure/core-rest-pipeline@npm:^1.17.0, @azure/core-rest-pipeline@npm:^1.19.0, @azure/core-rest-pipeline@npm:^1.22.0, @azure/core-rest-pipeline@npm:^1.24.0, @azure/core-rest-pipeline@npm:^1.8.0": + version: 1.25.0 + resolution: "@azure/core-rest-pipeline@npm:1.25.0" + dependencies: + "@azure/abort-controller": "npm:^2.1.2" + "@azure/core-auth": "npm:^1.10.0" + "@azure/core-tracing": "npm:^1.3.0" + "@azure/core-util": "npm:^1.13.0" + "@azure/logger": "npm:^1.3.0" + "@typespec/ts-http-runtime": "npm:^0.3.4" + tslib: "npm:^2.6.2" + checksum: 10c0/240ccb463ae6fafe78268871514440eed927147872dc64dd82be9956abe3be1b19bb2f0be2ec9a458f1a9f8613b9532c1be7a798d8d1fc965dcf9fd721a9e0c8 + languageName: node + linkType: hard + +"@azure/core-tracing@npm:^1.0.0, @azure/core-tracing@npm:^1.2.0, @azure/core-tracing@npm:^1.3.0": + version: 1.4.0 + resolution: "@azure/core-tracing@npm:1.4.0" + dependencies: + tslib: "npm:^2.6.2" + checksum: 10c0/10401c0c38714585456258bc0540aa99dfa626272c3e96c5a331ad3d522c01dd930c0ed16a6ea024957ab97a8a241c7ae4ae5a8759ba293d08001eac8046722d + languageName: node + linkType: hard + +"@azure/core-util@npm:^1.10.0, @azure/core-util@npm:^1.11.0, @azure/core-util@npm:^1.13.0, @azure/core-util@npm:^1.2.0": + version: 1.14.0 + resolution: "@azure/core-util@npm:1.14.0" + dependencies: + "@azure/abort-controller": "npm:^2.1.2" + "@typespec/ts-http-runtime": "npm:^0.3.0" + tslib: "npm:^2.6.2" + checksum: 10c0/f4885a0b98d169ee169369f362ea84b7298b83477c3a35f0ad6a5bc31c008a9d0f21f6b068cee71c71f86a6ac6030489b1b3b0d250c7ed8d7b1c34b335ad7e32 + languageName: node + linkType: hard + +"@azure/identity@npm:^4.13.3": + version: 4.13.3 + resolution: "@azure/identity@npm:4.13.3" + dependencies: + "@azure/abort-controller": "npm:^2.0.0" + "@azure/core-auth": "npm:^1.9.0" + "@azure/core-client": "npm:^1.9.2" + "@azure/core-process": "npm:^1.0.0" + "@azure/core-rest-pipeline": "npm:^1.17.0" + "@azure/core-tracing": "npm:^1.0.0" + "@azure/core-util": "npm:^1.11.0" + "@azure/logger": "npm:^1.0.0" + "@azure/msal-browser": "npm:^5.5.0" + "@azure/msal-node": "npm:^6.0.0" + open: "npm:^10.1.0" + tslib: "npm:^2.2.0" + checksum: 10c0/bea0ecdea2bce865cdae468bd90df300b0874980302d315b754257684be3048eb225d15ddae32cde40cad3afcd30c39c35ed0458b6ebec32bfff9b28f82fd762 + languageName: node + linkType: hard + +"@azure/keyvault-common@npm:^2.1.0": + version: 2.1.0 + resolution: "@azure/keyvault-common@npm:2.1.0" + dependencies: + "@azure-rest/core-client": "npm:^2.3.3" + "@azure/abort-controller": "npm:^2.0.0" + "@azure/core-auth": "npm:^1.3.0" + "@azure/core-rest-pipeline": "npm:^1.8.0" + "@azure/core-tracing": "npm:^1.0.0" + "@azure/core-util": "npm:^1.10.0" + "@azure/logger": "npm:^1.1.4" + tslib: "npm:^2.2.0" + checksum: 10c0/5cd2019f363f0d25fef4eb85402a89c32dd41a4627bc7186437ba3aeb4d4454d117d72a07c1580372932a1d3822d05f20d804eada9507e1b098c1b7f8ab17382 + languageName: node + linkType: hard + +"@azure/keyvault-secrets@npm:^4.11.2": + version: 4.11.2 + resolution: "@azure/keyvault-secrets@npm:4.11.2" + dependencies: + "@azure-rest/core-client": "npm:^2.3.3" + "@azure/abort-controller": "npm:^2.1.2" + "@azure/core-auth": "npm:^1.9.0" + "@azure/core-lro": "npm:^2.7.2" + "@azure/core-paging": "npm:^1.6.2" + "@azure/core-rest-pipeline": "npm:^1.19.0" + "@azure/core-tracing": "npm:^1.2.0" + "@azure/core-util": "npm:^1.11.0" + "@azure/keyvault-common": "npm:^2.1.0" + "@azure/logger": "npm:^1.1.4" + tslib: "npm:^2.8.1" + checksum: 10c0/a3f1cc6b2c9892bebfeaa534959d0a5fd5180b303795263e6aa1aa753a2c8b040995a57aeb7496c570a43fa7b7e22fc4fa1d330045c451d3778a548614b359ef + languageName: node + linkType: hard + +"@azure/logger@npm:^1.0.0, @azure/logger@npm:^1.1.4, @azure/logger@npm:^1.3.0": + version: 1.4.0 + resolution: "@azure/logger@npm:1.4.0" + dependencies: + "@typespec/ts-http-runtime": "npm:^0.3.0" + tslib: "npm:^2.6.2" + checksum: 10c0/7f8497623cb5fcdeba87debfc60e8a53684ee8ba9f93a9cf32c7238d51072bbfbc6a7abb270ade965fea96b277c96ff070e548f0758fe26a470b8e193b94e317 + languageName: node + linkType: hard + +"@azure/msal-browser@npm:^5.5.0": + version: 5.23.0 + resolution: "@azure/msal-browser@npm:5.23.0" + dependencies: + "@azure/msal-common": "npm:16.14.1" + checksum: 10c0/b0d654ea83deeb21009533439011583039d782f095d3129020a629db1fc947790d48249087a87902f2b6e99aaf8132741dd1b4047e85f4af132c47a86b313977 + languageName: node + linkType: hard + +"@azure/msal-common@npm:16.14.1": + version: 16.14.1 + resolution: "@azure/msal-common@npm:16.14.1" + checksum: 10c0/99abadb8ce40cf234e534776806e17a76904d9f99af069e20e6e7513cb3956428809672cb7fc2e1bde6ab0684b7027225514fe0d11671017b985ce7db8886087 + languageName: node + linkType: hard + +"@azure/msal-node@npm:^6.0.0": + version: 6.0.1 + resolution: "@azure/msal-node@npm:6.0.1" + dependencies: + "@azure/msal-common": "npm:16.14.1" + jsonwebtoken: "npm:^9.0.0" + checksum: 10c0/feab144530e708b3d9c7e50a30e3339a460fc4d9879c8841795ffea49bab78395963c0740235a9e585d8c81587291ed286ff6b99fdd5236748ff662e2aea75c8 + languageName: node + linkType: hard + "@babel/code-frame@npm:^7.10.4": version: 7.27.1 resolution: "@babel/code-frame@npm:7.27.1" @@ -8976,6 +9179,8 @@ __metadata: version: 0.0.0-use.local resolution: "@sourcebot/shared@workspace:packages/shared" dependencies: + "@azure/identity": "npm:^4.13.3" + "@azure/keyvault-secrets": "npm:^4.11.2" "@google-cloud/secret-manager": "npm:^6.1.1" "@logtail/node": "npm:^0.5.2" "@logtail/winston": "npm:^0.5.2" @@ -10527,6 +10732,17 @@ __metadata: languageName: node linkType: hard +"@typespec/ts-http-runtime@npm:^0.3.0, @typespec/ts-http-runtime@npm:^0.3.4, @typespec/ts-http-runtime@npm:^0.3.8": + version: 0.3.9 + resolution: "@typespec/ts-http-runtime@npm:0.3.9" + dependencies: + http-proxy-agent: "npm:^7.0.0" + https-proxy-agent: "npm:^7.0.0" + tslib: "npm:^2.6.2" + checksum: 10c0/a07e2ea0054d15c71b9b18eb6c3bee005e97a60b3a2dda78c81c73c1a77845f40665838e1cc80d1bae388a1facac8ef36ad367d1e8bfd360534a815a8e43da8c + languageName: node + linkType: hard + "@uidotdev/usehooks@npm:^2.4.1": version: 2.4.1 resolution: "@uidotdev/usehooks@npm:2.4.1" @@ -11590,6 +11806,15 @@ __metadata: languageName: node linkType: hard +"bundle-name@npm:^4.1.0": + version: 4.1.1 + resolution: "bundle-name@npm:4.1.1" + dependencies: + run-applescript: "npm:^7.0.0" + checksum: 10c0/1d059a934a80af73db5bf52d4b932a631fc9724451e4082c900e947c433668f0569017c185ac8245bae84ada97a2c7048bd7eeeb288d2ebac8840c4a388a2d09 + languageName: node + linkType: hard + "bytes@npm:3.1.2, bytes@npm:^3.1.2, bytes@npm:~3.1.2": version: 3.1.2 resolution: "bytes@npm:3.1.2" @@ -13140,6 +13365,23 @@ __metadata: languageName: node linkType: hard +"default-browser-id@npm:^5.0.0": + version: 5.0.1 + resolution: "default-browser-id@npm:5.0.1" + checksum: 10c0/5288b3094c740ef3a86df9b999b04ff5ba4dee6b64e7b355c0fff5217752c8c86908d67f32f6cba9bb4f9b7b61a1b640c0a4f9e34c57e0ff3493559a625245ee + languageName: node + linkType: hard + +"default-browser@npm:^5.2.1": + version: 5.5.1 + resolution: "default-browser@npm:5.5.1" + dependencies: + bundle-name: "npm:^4.1.0" + default-browser-id: "npm:^5.0.0" + checksum: 10c0/feb5e7a6a6f2fcbc7a6c5c78e071a4f7a3ab136e6244b9637e58fe6170f6e1254ae099cbe2ebc2b2823c387ed50fda176ce31d386f4f2ebbd43d8fb1cb6aacf7 + languageName: node + linkType: hard + "define-data-property@npm:^1.0.1, define-data-property@npm:^1.1.4": version: 1.1.4 resolution: "define-data-property@npm:1.1.4" @@ -13151,6 +13393,13 @@ __metadata: languageName: node linkType: hard +"define-lazy-prop@npm:^3.0.0": + version: 3.0.0 + resolution: "define-lazy-prop@npm:3.0.0" + checksum: 10c0/5ab0b2bf3fa58b3a443140bbd4cd3db1f91b985cc8a246d330b9ac3fc0b6a325a6d82bddc0b055123d745b3f9931afeea74a5ec545439a1630b9c8512b0eeb49 + languageName: node + linkType: hard + "define-properties@npm:^1.1.3, define-properties@npm:^1.2.1": version: 1.2.1 resolution: "define-properties@npm:1.2.1" @@ -15764,7 +16013,7 @@ __metadata: languageName: node linkType: hard -"https-proxy-agent@npm:^7.0.1, https-proxy-agent@npm:^7.0.5": +"https-proxy-agent@npm:^7.0.0, https-proxy-agent@npm:^7.0.1, https-proxy-agent@npm:^7.0.5": version: 7.0.6 resolution: "https-proxy-agent@npm:7.0.6" dependencies: @@ -16133,6 +16382,15 @@ __metadata: languageName: node linkType: hard +"is-docker@npm:^3.0.0": + version: 3.0.0 + resolution: "is-docker@npm:3.0.0" + bin: + is-docker: cli.js + checksum: 10c0/d2c4f8e6d3e34df75a5defd44991b6068afad4835bb783b902fa12d13ebdb8f41b2a199dcb0b5ed2cb78bfee9e4c0bbdb69c2d9646f4106464674d3e697a5856 + languageName: node + linkType: hard + "is-extglob@npm:^2.1.1": version: 2.1.1 resolution: "is-extglob@npm:2.1.1" @@ -16191,6 +16449,17 @@ __metadata: languageName: node linkType: hard +"is-inside-container@npm:^1.0.0": + version: 1.0.0 + resolution: "is-inside-container@npm:1.0.0" + dependencies: + is-docker: "npm:^3.0.0" + bin: + is-inside-container: cli.js + checksum: 10c0/a8efb0e84f6197e6ff5c64c52890fa9acb49b7b74fed4da7c95383965da6f0fa592b4dbd5e38a79f87fc108196937acdbcd758fcefc9b140e479b39ce1fcd1cd + languageName: node + linkType: hard + "is-interactive@npm:^2.0.0": version: 2.0.0 resolution: "is-interactive@npm:2.0.0" @@ -16394,6 +16663,15 @@ __metadata: languageName: node linkType: hard +"is-wsl@npm:^3.1.0": + version: 3.1.1 + resolution: "is-wsl@npm:3.1.1" + dependencies: + is-inside-container: "npm:^1.0.0" + checksum: 10c0/7e5023522bfb8f27de4de960b0d82c4a8146c0bddb186529a3616d78b5bbbfc19ef0c5fc60d0b3a3cc0bf95a415fbdedc18454310ea3049587c879b07ace5107 + languageName: node + linkType: hard + "isarray@npm:^2.0.5": version: 2.0.5 resolution: "isarray@npm:2.0.5" @@ -16689,6 +16967,24 @@ __metadata: languageName: node linkType: hard +"jsonwebtoken@npm:^9.0.0": + version: 9.0.3 + resolution: "jsonwebtoken@npm:9.0.3" + dependencies: + jws: "npm:^4.0.1" + lodash.includes: "npm:^4.3.0" + lodash.isboolean: "npm:^3.0.3" + lodash.isinteger: "npm:^4.0.4" + lodash.isnumber: "npm:^3.0.3" + lodash.isplainobject: "npm:^4.0.6" + lodash.isstring: "npm:^4.0.1" + lodash.once: "npm:^4.0.0" + ms: "npm:^2.1.1" + semver: "npm:^7.5.4" + checksum: 10c0/6ca7f1e54886ea3bde7146a5a22b53847c46e25453c7f7307a69818b9a6ad48c390b2e59d5690fcfd03c529b01960060cc4bb0c686991d6edae2285dfd30f4ba + languageName: node + linkType: hard + "jsx-ast-utils@npm:^2.4.1 || ^3.0.0, jsx-ast-utils@npm:^3.3.5": version: 3.3.5 resolution: "jsx-ast-utils@npm:3.3.5" @@ -16712,7 +17008,7 @@ __metadata: languageName: node linkType: hard -"jws@npm:^4.0.0": +"jws@npm:^4.0.0, jws@npm:^4.0.1": version: 4.0.1 resolution: "jws@npm:4.0.1" dependencies: @@ -17090,6 +17386,34 @@ __metadata: languageName: node linkType: hard +"lodash.includes@npm:^4.3.0": + version: 4.3.0 + resolution: "lodash.includes@npm:4.3.0" + checksum: 10c0/7ca498b9b75bf602d04e48c0adb842dfc7d90f77bcb2a91a2b2be34a723ad24bc1c8b3683ec6b2552a90f216c723cdea530ddb11a3320e08fa38265703978f4b + languageName: node + linkType: hard + +"lodash.isboolean@npm:^3.0.3": + version: 3.0.3 + resolution: "lodash.isboolean@npm:3.0.3" + checksum: 10c0/0aac604c1ef7e72f9a6b798e5b676606042401dd58e49f051df3cc1e3adb497b3d7695635a5cbec4ae5f66456b951fdabe7d6b387055f13267cde521f10ec7f7 + languageName: node + linkType: hard + +"lodash.isinteger@npm:^4.0.4": + version: 4.0.4 + resolution: "lodash.isinteger@npm:4.0.4" + checksum: 10c0/4c3e023a2373bf65bf366d3b8605b97ec830bca702a926939bcaa53f8e02789b6a176e7f166b082f9365bfec4121bfeb52e86e9040cb8d450e64c858583f61b7 + languageName: node + linkType: hard + +"lodash.isnumber@npm:^3.0.3": + version: 3.0.3 + resolution: "lodash.isnumber@npm:3.0.3" + checksum: 10c0/2d01530513a1ee4f72dd79528444db4e6360588adcb0e2ff663db2b3f642d4bb3d687051ae1115751ca9082db4fdef675160071226ca6bbf5f0c123dbf0aa12d + languageName: node + linkType: hard + "lodash.isplainobject@npm:^4.0.6": version: 4.0.6 resolution: "lodash.isplainobject@npm:4.0.6" @@ -17097,6 +17421,13 @@ __metadata: languageName: node linkType: hard +"lodash.isstring@npm:^4.0.1": + version: 4.0.1 + resolution: "lodash.isstring@npm:4.0.1" + checksum: 10c0/09eaf980a283f9eef58ef95b30ec7fee61df4d6bf4aba3b5f096869cc58f24c9da17900febc8ffd67819b4e29de29793190e88dc96983db92d84c95fa85d1c92 + languageName: node + linkType: hard + "lodash.merge@npm:^4.6.2": version: 4.6.2 resolution: "lodash.merge@npm:4.6.2" @@ -17104,6 +17435,13 @@ __metadata: languageName: node linkType: hard +"lodash.once@npm:^4.0.0": + version: 4.1.1 + resolution: "lodash.once@npm:4.1.1" + checksum: 10c0/46a9a0a66c45dd812fcc016e46605d85ad599fe87d71a02f6736220554b52ffbe82e79a483ad40f52a8a95755b0d1077fba259da8bfb6694a7abbf4a48f1fc04 + languageName: node + linkType: hard + "lodash@npm:^4.17.11, lodash@npm:^4.17.21": version: 4.18.1 resolution: "lodash@npm:4.18.1" @@ -18887,6 +19225,18 @@ __metadata: languageName: node linkType: hard +"open@npm:^10.1.0": + version: 10.2.0 + resolution: "open@npm:10.2.0" + dependencies: + default-browser: "npm:^5.2.1" + define-lazy-prop: "npm:^3.0.0" + is-inside-container: "npm:^1.0.0" + wsl-utils: "npm:^0.1.0" + checksum: 10c0/5a36d0c1fd2f74ce553beb427ca8b8494b623fc22c6132d0c1688f246a375e24584ea0b44c67133d9ab774fa69be8e12fbe1ff12504b1142bd960fb09671948f + languageName: node + linkType: hard + "openai@npm:^4.98.0": version: 4.98.0 resolution: "openai@npm:4.98.0" @@ -20975,6 +21325,13 @@ __metadata: languageName: node linkType: hard +"run-applescript@npm:^7.0.0": + version: 7.1.0 + resolution: "run-applescript@npm:7.1.0" + checksum: 10c0/ab826c57c20f244b2ee807704b1ef4ba7f566aa766481ae5922aac785e2570809e297c69afcccc3593095b538a8a77d26f2b2e9a1d9dffee24e0e039502d1a03 + languageName: node + linkType: hard + "run-parallel@npm:^1.1.9": version: 1.2.0 resolution: "run-parallel@npm:1.2.0" @@ -21116,7 +21473,7 @@ __metadata: languageName: node linkType: hard -"semver@npm:7.8.5, semver@npm:^7.8.5": +"semver@npm:7.8.5, semver@npm:^7.5.4, semver@npm:^7.8.5": version: 7.8.5 resolution: "semver@npm:7.8.5" bin: @@ -22746,7 +23103,7 @@ __metadata: languageName: node linkType: hard -"tslib@npm:2.8.1, tslib@npm:^2.0.0, tslib@npm:^2.1.0, tslib@npm:^2.4.0, tslib@npm:^2.6.2, tslib@npm:^2.7.0, tslib@npm:^2.8.0, tslib@npm:^2.8.1": +"tslib@npm:2.8.1, tslib@npm:^2.0.0, tslib@npm:^2.1.0, tslib@npm:^2.2.0, tslib@npm:^2.4.0, tslib@npm:^2.6.2, tslib@npm:^2.7.0, tslib@npm:^2.8.0, tslib@npm:^2.8.1": version: 2.8.1 resolution: "tslib@npm:2.8.1" checksum: 10c0/9c4759110a19c53f992d9aae23aac5ced636e99887b51b9e61def52611732872ff7668757d4e4c61f19691e36f4da981cd9485e869b4a7408d689f6bf1f14e62 @@ -23808,6 +24165,15 @@ __metadata: languageName: node linkType: hard +"wsl-utils@npm:^0.1.0": + version: 0.1.0 + resolution: "wsl-utils@npm:0.1.0" + dependencies: + is-wsl: "npm:^3.1.0" + checksum: 10c0/44318f3585eb97be994fc21a20ddab2649feaf1fbe893f1f866d936eea3d5f8c743bec6dc02e49fbdd3c0e69e9b36f449d90a0b165a4f47dd089747af4cf2377 + languageName: node + linkType: hard + "xcase@npm:^2.0.1": version: 2.0.1 resolution: "xcase@npm:2.0.1"