/** * GCP Secret Manager implementation of EnvConfigStore. * * Each environment is persisted as its own secret resource: * * projects/${project}/secrets/log10x-env-config-${env_id} * * Secret Manager does not allow in-place mutation — writes always create a * new SecretVersion under the secret. Reads always access `/versions/latest`, * so the most recent write wins. The first write for a given env_id creates * the secret itself (idempotently — an existing secret is reused). * * Discovery (`list`) uses `listSecrets` with a `name~` regex filter so we * only walk our own resources, not every secret in the project. * * Auth is ambient: the `@google-cloud/secret-manager` SDK picks up * `GOOGLE_APPLICATION_CREDENTIALS` (service-account key file) or workload * identity in-cluster. The project is read from `LOG10X_GCP_PROJECT` first * (so a customer can pin a non-default project) and falls back to * `GOOGLE_CLOUD_PROJECT`. * * `isAvailable` is intentionally cheap: it only checks that the SDK is * importable and that the basic credential + project signals are present. * It does NOT issue an API call — the resolver tries every store on every * read, so an RPC on each availability check would be a per-tool tax. */ import type { EnvConfigStore, StoreKind } from './store-interface.js'; import { type EnvironmentConfig } from './types.js'; export declare class GcpSecretManagerStore implements EnvConfigStore { private readonly opts; readonly kind: StoreKind; /** * Optional injected client (for tests). Production callers leave this * undefined; the store lazily constructs a `SecretManagerServiceClient` on * first use. */ private clientPromise; private cachedProject; constructor(opts?: { project?: string; clientFactory?: () => Promise; }); private getClient; private getProject; isAvailable(): Promise<{ available: boolean; reason: string; }>; read(envIdOrNickname: string): Promise; private readByEnvId; write(config: EnvironmentConfig): Promise; list(): Promise; delete(envId: string): Promise; }