docs(FN-007): add repository connection documentation
- Update development.md with Repository Connections section - Document SSH key generation and provider adapter usage
This commit is contained in:
+54
-1
@@ -217,7 +217,7 @@ and local CLI operations evolve independently:
|
||||
Security rules for the package:
|
||||
- Credential models store **only** `encrypted_payload` — no plaintext `token` or `private_key` fields.
|
||||
- SSH private keys are encrypted before storage; the field uses `repr=False`.
|
||||
- Real encryption of the payload is deferred to FN-009; the current placeholder is base64-only.
|
||||
- SSH private keys are encrypted with Fernet before storage.
|
||||
|
||||
## Tool Spawn Workflow
|
||||
|
||||
@@ -324,6 +324,59 @@ When a tool instance is spawned:
|
||||
|
||||
Before spawning, the system validates that all required secrets exist. If any are missing, the spawn fails with an error message listing the missing secrets.
|
||||
|
||||
## Repository Connections
|
||||
|
||||
### Overview
|
||||
|
||||
The platform supports connecting Git repositories to projects with provider-independent authentication.
|
||||
|
||||
### Architecture
|
||||
|
||||
1. **Repository** (`apps/api/app/models/repository.py`):
|
||||
- Stores repository metadata (name, git_url, provider_type, default_branch)
|
||||
- Belongs to a project
|
||||
|
||||
2. **Repository Connection** (`apps/api/app/models/repository_connection.py`):
|
||||
- Links a repository to a Git provider with credentials
|
||||
- Tracks connection status (pending, connected, error, disconnected)
|
||||
- Supports SSH key authentication
|
||||
|
||||
3. **Credential Storage** (`apps/api/app/git/credential_storage.py`):
|
||||
- Database-backed storage for encrypted credentials
|
||||
- Uses Fernet encryption for payload
|
||||
- Supports access tokens and SSH keys
|
||||
|
||||
4. **Provider Adapters** (`apps/api/app/git/providers/`):
|
||||
- GitHubAdapter and GitLabAdapter with URL parsing
|
||||
- Extensible for other providers (Gitea, Forgejo)
|
||||
|
||||
5. **SSH Key Lifecycle** (`apps/api/app/git/ssh_key.py`):
|
||||
- Ed25519 key pair generation
|
||||
- Fernet-encrypted private key storage
|
||||
- Public key available for deploy key registration
|
||||
|
||||
### API Endpoints
|
||||
|
||||
- `POST /projects/{id}/repositories` — Add repository
|
||||
- `GET /projects/{id}/repositories` — List repositories
|
||||
- `DELETE /projects/{id}/repositories/{id}` — Remove repository
|
||||
- `POST /projects/{id}/repository-connections` — Create connection
|
||||
- `GET /projects/{id}/repository-connections` — List connections
|
||||
- `DELETE /projects/{id}/repository-connections/{id}` — Remove connection
|
||||
- `POST /projects/{id}/repository-connections/{id}/ssh-key` — Generate SSH key
|
||||
- `POST /projects/{id}/repository-connections/{id}/validate` — Validate connection
|
||||
|
||||
### Frontend
|
||||
|
||||
- `/repositories` — Repository list and creation
|
||||
- `/projects/{id}/repositories/{id}` — Repository detail with connections
|
||||
|
||||
### Git Operations
|
||||
|
||||
Local Git operations are supported via subprocess:
|
||||
- Clone, fetch, push with credential-aware subprocess
|
||||
- Working tree status (branch, clean, untracked, modified, staged, deleted)
|
||||
|
||||
## OpenCode Tool
|
||||
|
||||
### Overview
|
||||
|
||||
Reference in New Issue
Block a user