Skip to content

Commit 9dce635

Browse files
docs(drivers): a plugin driver's config is its author's to keep free of credentials (#21927)
Refs #21840 Clause-②: no ## What One paragraph in `content/docs/data-modeling/drivers.mdx`, after the note that a plugin-contributed driver's `config` is left unvalidated. It adds that the platform does not guess which keys of that `config` hold credentials, that the `config` is stored and served to administrators as written, and that keeping secrets out of it is the plugin author's responsibility, with the credential going in the bound secret (`external.credentialsRef`). This is the one change the maintainer kept when #21840 was closed as not planned (ruling on #21921). ## Checks - `node scripts/check-doc-authoring.mjs`: exit 0. - Docs only, so nothing is published and no changeset is needed. 🤖 Generated with [Claude Code](https://claude.com/claude-code) https://claude.ai/code/session_018zT8d8NpiQ1ExhuNd5TxY6 Co-authored-by: Claude <noreply@anthropic.com>
1 parent 7b6c652 commit 9dce635

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

‎content/docs/data-modeling/drivers.mdx‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -154,7 +154,10 @@ Two things live **outside** `config`, because they are not driver-specific:
154154

155155
A plugin-contributed driver (`com.vendor.snowflake`) has no contract in this
156156
repo, so its `config` is left unvalidated rather than judged against a shape the
157-
platform does not have.
157+
platform does not have. The platform also does not guess which of its keys hold
158+
credentials: `config` is stored and served to administrators as written. Keeping
159+
secrets out of it is the plugin author's responsibility; put the credential in
160+
the bound secret (`external.credentialsRef`) instead.
158161

159162
<Callout type="info">
160163
The same schemas are projected to JSON Schema for

0 commit comments

Comments
 (0)