ecluse
Safe HaskellNone
LanguageGHC2021

Ecluse.Config.Resolve

Description

Hierarchical configuration resolution: the defaults, the operator document, and the ECLUSE_ environment overlay merged into one tree, strongest last.

A variable name maps to a document path rather than to a setting, so every key is reachable from the environment. The resolver inverts that mapping, which is how a refusal names the key an operator actually wrote.

Synopsis

Documentation

deepMerge :: Value -> Value -> Value Source #

Right-biased deep merge of two Aeson Values. Objects merge recursively. The right side overwrites any other type, arrays and strings included.

buildEnvAst :: [(String, String)] -> Value Source #

Convert ECLUSE_-prefixed environment variables into a nested JSON Object, prefix stripped: __ descends into an object and _ joins a camelCase word (mountKeyRef inverts it).

secretLeafKeys :: [Text] Source #

The secret-typed leaf keys, in their document spelling: token is the one under every store tag. Verbatim env values, redacted provenance, and the *_FILE indirection all read them here.

secretEnvSpellings :: [Text] Source #

secretLeafKeys in their environment spelling (authToken -> AUTH_TOKEN).

mountKeyRef :: Ecosystem -> Text -> Text Source #

The environment key a mount-scoped document path resolves from: mirrorTarget.codeArtifact.url on npm gives ECLUSE_MOUNTSNPMMIRROR_TARGETCODE_ARTIFACTURL. Every refusal builds it here.

mountDocRef :: Ecosystem -> Text -> Text Source #

mountKeyRef in the document spelling: mounts.npm.mirrorTarget.codeArtifact.url.