Skip to content

Commit 6d4afaa

Browse files
committed
docs(drivers): a plugin driver's config is its author's to keep free of credentials
Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6
1 parent faf8dce commit 6d4afaa

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

‎content/docs/data-modeling/drivers.mdx‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -154,7 +154,10 @@ Two things live **outside** `config`, because they are not driver-specific:
154154

155155
A plugin-contributed driver (`com.vendor.snowflake`) has no contract in this
156156
repo, so its `config` is left unvalidated rather than judged against a shape the
157-
platform does not have.
157+
platform does not have. The platform also does not guess which of its keys hold
158+
credentials: `config` is stored and served to administrators as written. Keeping
159+
secrets out of it is the plugin author's responsibility; put the credential in
160+
the bound secret (`external.credentialsRef`) instead.
158161

159162
<Callout type="info">
160163
The same schemas are projected to JSON Schema for

0 commit comments

Comments
 (0)