Skip to content

docs: document deferred values and credentials as targets - #109

Merged
raphaelvigee merged 3 commits into
mainfrom
claude/eager-galileo-qdl8hr
Sep 19, 2026
Merged

raphaelvigee merged 3 commits into
mainfrom
claude/eager-galileo-qdl8hr

Conversation

@raphaelvigee

@raphaelvigee raphaelvigee commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Summary

Covers the last three commits on hephbuild/heph master, which landed together as one feature train:

  • hephbuild/heph#455 (4ba6266) — credential as a target driver.
  • hephbuild/heph#456 (780af6f) — the deferred-values mechanism (${read://pkg:name}) a driver option reads from another target, which credentials build on top of.
  • hephbuild/heph#458 (d21817d) — ${src://pkg:name}, the sandbox-path form of a deferred value.

None of this was documented on the site before this PR.

  • Adds Deferred values (website/docs/concepts/deferred-values.md): the two forms (${read://…}/${src://…}), the output-group selector, where an option can/can't accept one, failure behavior, and the substitution-not-quoting caveat for bash.
  • Adds Credentials (website/docs/concepts/credentials.md): the credential driver and its contract (never hashed, never an input), the source chain and when vocabulary, the three presentation shapes and the heph.auth.* presentation presets (AWS/GCP/Azure/GitHub/Docker/git/netrc), consuming a credential with credentials = [...], the heph auth CLI, and log redaction. Cross-links to Deferred values, since a credential's present values accept ${read://…} (e.g. role = "${read://infra/aws:role-arn}").
  • Registers both pages in website/sidebars.ts, under "Concepts".
  • Cross-links Deferred values from website/docs/plugins/exec.md (run's config-key row plus a short section), since run is the only currently-documented driver option outside credentials that accepts one.
  • Fixed a bug in my own first draft: the copy-version example's run wrote to a different filename than its declared out — thanks for catching that.

Content is sourced directly from hephbuild/heph's docs/DEFERRED_VALUES.md, docs/CREDENTIALS.md, example/deferred/, example/credential/, and the plugincredential/core::template source on master (I read the actual Starlark builtin definitions to get exact function signatures — heph.auth.oidc, heph.auth.exec, the presentation presets, etc. — rather than guessing from the prose docs alone), rewritten in the site's user-facing style (no internal architecture/hashing/security-boundary mechanics, no source-code paths in the rendered text).

Not built locally (no build environment available in this session) — content-only change, both pages registered in sidebars.ts per the checklist in .claude/writing-docs.md.

Test plan

  • lint (ESLint, zero warnings)
  • build (Docusaurus production build)
  • Spot-check both new pages and the exec page render correctly, and both sidebar entries appear under "Concepts"

🤖 Generated with Claude Code

https://claude.ai/code/session_01JVc3xVtpWa7kPVKKweR5Dc

hephbuild/heph#458 added ${src://pkg:name} — the sandbox path of
another target's output — alongside the existing ${read://pkg:name}
contents form. Neither was documented on the site; add a Deferred
values concept page and cross-link it from the exec/bash driver docs.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JVc3xVtpWa7kPVKKweR5Dc
cp's destination argument didn't match the declared out path.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JVc3xVtpWa7kPVKKweR5Dc
@github-actions

github-actions Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

⚡ Cloudflare Pages preview

Preview https://e0ad707b.hephbuild.pages.dev
Commit 67dcd13

hephbuild/heph#455 introduced the credential driver, hephbuild/heph#456
the underlying deferred-values mechanism it and #458's ${src://…} both
build on. Only the deferred-values half was covered so far; add a
Credentials concept page covering the driver, source chain, when
vocabulary, presentation shapes and presets, the CLI, and redaction —
sourced from heph's docs/CREDENTIALS.md and the plugincredential
builtins on master. Cross-link it from the deferred-values page, which
already noted a credential's present block as a consumer.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JVc3xVtpWa7kPVKKweR5Dc
@raphaelvigee raphaelvigee changed the title docs: document deferred values (${read://…} and ${src://…}) docs: document deferred values and credentials as targets Sep 19, 2026
@raphaelvigee
raphaelvigee merged commit f5d0ddf into main Sep 19, 2026
3 checks passed
@raphaelvigee
raphaelvigee deleted the claude/eager-galileo-qdl8hr branch September 19, 2026 15:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants