Skip to content

feat: cache non-production credentials per proxy host so staging and prod coexist - #22

Draft
alukach wants to merge 2 commits into
mainfrom
feat/per-environment-cache
Draft

alukach wants to merge 2 commits into
mainfrom
feat/per-environment-cache

Conversation

@alukach

@alukach alukach commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Cached credentials were keyed only by role ARN (source-coop-cli / _default in the keychain). Staging and prod both use _default, so logging into one overwrote the other. Worse, source-coop creds in a prod profile would then quietly return (and refresh) staging credentials.

Change

  • Production (data.source.coop) keeps the bare role ARN as its cache key (_default), so existing caches stay readable and no re-login is needed.
  • Any other proxy gets <host>/<role>, e.g. data.staging.source.coop/_default. The same key is used for the keychain entry, the fallback file and the refresh lock.
  • creds accepts --proxy-url / SOURCE_PROXY_URL (defaults to the build's proxy) to choose the environment.
  • README: new "Multiple environments" section with an AWS profile per environment.
[profile source-coop-staging]
credential_process = source-coop creds --proxy-url https://data.staging.source.coop
endpoint_url = https://data.staging.source.coop

The special case matches the production host itself, not the build's default proxy URL. That keeps a staging build and a prod build from both writing to _default. As a result, a staging-build user with a login cached under _default needs to log in again once.

Testing

  • cargo test: 22 passed, including key_separates_environments, which covers both the prod and staging keys
  • cargo clippy --all-targets: clean
  • cargo check --no-default-features --features staging: builds

Note: the first commit on this branch is titled feat! with a BREAKING CHANGE footer, which no longer applies. Please squash-merge using the PR title so release-please doesn't bump a major version.

🤖 Generated with Claude Code

alukach and others added 2 commits September 30, 2026 11:28
The cache key was the role ARN alone, and both environments default to
`_default`, so a staging login overwrote the prod entry (and `creds`
would silently serve/refresh staging credentials for a prod profile).
Key entries by `<proxy host>/<role>` and let `creds` take
`--proxy-url` / `SOURCE_PROXY_URL` to select the environment.

BREAKING CHANGE: existing cached logins are no longer found; run
`source-coop login` once after upgrading.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Existing prod caches (keyed by role ARN alone) stay readable, so upgrading
needs no re-login. Only non-production proxies get the host prefix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@alukach alukach changed the title feat!: cache credentials per proxy URL so staging and prod coexist feat: cache non-production credentials per proxy host so staging and prod coexist Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant