Skip to content

Name the workspace's sandbox secrets and MCP servers on the author surface - #742

Merged
czpython merged 1 commit into
mainfrom
sandbox-secrets-author-surface
Sep 27, 2026
Merged

czpython merged 1 commit into
mainfrom
sandbox-secrets-author-surface

Conversation

@czpython

Copy link
Copy Markdown
Owner

Closes #701.

A workspace gives its sandbox a custom secret through a hook that returned SecretRef, an internal ORM row. Apps had to import druks.sandbox.models. The MCP hook's type lived in the internal druks.sandbox.datastructures module.

Author surface

Before After
Workspace.get_secret_refs(subject) -> list[SecretRef] Workspace.get_secrets(subject) -> list[SandboxSecret]
Workspace.get_required_mcp_servers(subject) -> tuple[RequiredMcpServer, ...] Workspace.get_mcp_servers(subject) -> tuple[SandboxMcpServer, ...]
Workspace.get_mcp_delivery(...) Workspace.get_all_mcp_servers(...)

SandboxSecret and SandboxMcpServer are frozen dataclasses. druks.sandbox exports both. Druks maps a SandboxSecret to its SecretRef row when the agent call builds the box. This is the same way it already maps a SandboxMcpServer.

One resolution per agent call

Before, each agent call resolved every MCP server twice. The first pass got the box's secret refs and threw away the harness shapes. The second pass, in Workspace.run_agent, got the harness shapes and threw away the refs. Now the agent call resolves once. It gives the refs to the box and passes the servers to run_agent as mcp_servers. Workflow.get_secret_refs and Workspace.with_mcp_servers are gone.

Docs

"Customize the workspace" now documents get_secrets(). It covers the vault row, host, the derived variable (name.upper()), and the header the proxy sets. Both types are in the stable author imports table.

The import cycle named in the issue is not caused by the export. import druks.workspaces as the first import already fails on main, through sandbox.host, durable, harnesses, and back to sandbox.client. This PR does not change that.

@mintlify

mintlify Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
druks 🟢 Ready View Preview Sep 27, 2026, 6:55 PM

💡 Tip: Enable Automations to automatically generate PRs for you.

…rface

A workspace's custom secret hook returned SecretRef, an internal ORM row, so
apps imported druks.sandbox.models. The MCP hook's type lived in the internal
druks.sandbox.datastructures module.

- Add SandboxSecret and rename RequiredMcpServer to SandboxMcpServer. Export
  both from druks.sandbox.
- Rename the workspace hooks to get_secrets() and get_mcp_servers().
- Rename get_mcp_delivery() to get_all_mcp_servers(). The agent call now
  resolves it once and passes the servers to the workspace. Before, the box's
  secret refs and the harness config each resolved every server again.
- Document get_secrets() in the author guide and list both types as stable
  imports.
@czpython
czpython force-pushed the sandbox-secrets-author-surface branch from 2514bbd to 0daf695 Compare September 27, 2026 18:55
@czpython
czpython merged commit 3a237ef into main Sep 27, 2026
4 checks passed
@czpython
czpython deleted the sandbox-secrets-author-surface branch September 27, 2026 18:55

This branch was successfully deployed

1 active deployment
staging - docs — 0daf695e Deployed Sep 27, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Expose SecretRef on the author surface for custom sandbox secrets

1 participant