-
Notifications
You must be signed in to change notification settings - Fork 187
Make decryption an explicit opt-in for o11y tooling #1000
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: nate/wire-encryption
Are you sure you want to change the base?
Conversation
🧪 E2E Test Results❌ Some tests failed Summary
❌ Failed Tests▲ Vercel Production (1 failed)nextjs-turbopack (1 failed):
🌍 Community Worlds (42 failed)mongodb (1 failed):
turso (41 failed):
Details by Category❌ ▲ Vercel Production
✅ 💻 Local Development
✅ 📦 Local Production
✅ 🐘 Local Postgres
✅ 🪟 Windows
❌ 🌍 Community Worlds
✅ 📋 Other
❌ Some E2E test jobs failed:
Check the workflow run for details. |
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
🦋 Changeset detectedLatest commit: cfa8bb9 The changes in this PR will be included in the next version bump. This PR includes changesets to release 15 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
7142697 to
cfa8bb9
Compare

Make decryption of encrypted values an explicit opt-in for observability tooling to prevent unnecessary audit-logged key retrieval.
What changed?
--decryptflag toworkflow inspectcommands to explicitly request decryptionhydrateResourceIOnow acceptsnullas theEncryptorResolverto skip decryptionENCRYPTED_PLACEHOLDERconstant to represent encrypted values when decryption is not requestedHow to test?
workflow inspectto view the run - encrypted values should show as "🔒 Encrypted"workflow inspect --decryptto verify decryption works properlyWhy make this change?
Decryption of encrypted values triggers audit-logged key retrieval from the Vercel API. Making decryption an explicit opt-in ensures that these API calls only happen when the user specifically requests to see the decrypted values, improving security and reducing unnecessary API calls.