Name the workspace's sandbox secrets and MCP servers on the author surface - #742
Merged
Merged
Conversation
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
…rface A workspace's custom secret hook returned SecretRef, an internal ORM row, so apps imported druks.sandbox.models. The MCP hook's type lived in the internal druks.sandbox.datastructures module. - Add SandboxSecret and rename RequiredMcpServer to SandboxMcpServer. Export both from druks.sandbox. - Rename the workspace hooks to get_secrets() and get_mcp_servers(). - Rename get_mcp_delivery() to get_all_mcp_servers(). The agent call now resolves it once and passes the servers to the workspace. Before, the box's secret refs and the harness config each resolved every server again. - Document get_secrets() in the author guide and list both types as stable imports.
czpython
force-pushed
the
sandbox-secrets-author-surface
branch
from
September 27, 2026 18:55
2514bbd to
0daf695
Compare
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #701.
A workspace gives its sandbox a custom secret through a hook that returned
SecretRef, an internal ORM row. Apps had to importdruks.sandbox.models. The MCP hook's type lived in the internaldruks.sandbox.datastructuresmodule.Author surface
Workspace.get_secret_refs(subject) -> list[SecretRef]Workspace.get_secrets(subject) -> list[SandboxSecret]Workspace.get_required_mcp_servers(subject) -> tuple[RequiredMcpServer, ...]Workspace.get_mcp_servers(subject) -> tuple[SandboxMcpServer, ...]Workspace.get_mcp_delivery(...)Workspace.get_all_mcp_servers(...)SandboxSecretandSandboxMcpServerare frozen dataclasses.druks.sandboxexports both. Druks maps aSandboxSecretto itsSecretRefrow when the agent call builds the box. This is the same way it already maps aSandboxMcpServer.One resolution per agent call
Before, each agent call resolved every MCP server twice. The first pass got the box's secret refs and threw away the harness shapes. The second pass, in
Workspace.run_agent, got the harness shapes and threw away the refs. Now the agent call resolves once. It gives the refs to the box and passes the servers torun_agentasmcp_servers.Workflow.get_secret_refsandWorkspace.with_mcp_serversare gone.Docs
"Customize the workspace" now documents
get_secrets(). It covers the vault row,host, the derived variable (name.upper()), and the header the proxy sets. Both types are in the stable author imports table.The import cycle named in the issue is not caused by the export.
import druks.workspacesas the first import already fails on main, throughsandbox.host,durable,harnesses, and back tosandbox.client. This PR does not change that.