## 1. Backend Enhancements - [x] 1.1 Update Config model with scope validation methods - [x] 1.2 Update Secret model with encryption verification - [x] 1.3 Enhance configs router with scope filtering and hierarchy resolution - [x] 1.4 Enhance secrets router with scope filtering and hierarchy resolution - [x] 1.5 Create apps/api/app/services/runtime_injection.py for config/secret resolution - [x] 1.6 Implement config file generation for container mounts - [x] 1.7 Implement secret env var generation for container injection - [x] 1.8 Add validation to fail spawn when referenced secrets are missing ## 2. Frontend - Config Management - [x] 2.1 Create ConfigList component at /projects/:id/configs - [x] 2.2 Implement ConfigForm for creating/updating configs - [x] 2.3 Add scope selector (project/instance/global) to config form - [x] 2.4 Implement config delete with confirmation - [x] 2.5 Add JSON formatting for config values ## 3. Frontend - Secret Management - [x] 3.1 Create SecretList component at /projects/:id/secrets - [x] 3.2 Implement SecretForm for creating/updating secrets - [x] 3.3 Add masked value display (never show decrypted) - [x] 3.4 Implement secret delete with confirmation - [x] 3.5 Add scope selector to secret form ## 4. Runtime Integration - [x] 4.1 Integrate runtime injection into tool instance spawn endpoint - [x] 4.2 Update Docker Compose generation to include config mounts - [x] 4.3 Update Docker Compose generation to include secret env vars - [x] 4.4 Test config/secret injection in local Docker environment ## 5. Testing & Verification - [x] 5.1 Write backend tests for config scope resolution - [x] 5.2 Write backend tests for secret encryption/decryption - [x] 5.3 Write backend tests for runtime injection - [x] 5.4 Write frontend tests for ConfigList and SecretList - [x] 5.5 Run full test suite: `make test` - [x] 5.6 Run linters: `make lint` ## 6. Documentation - [x] 6.1 Update docs/development.md with config/secrets workflow - [x] 6.2 Add config/secrets UI guide to docs/architecture.md - [x] 6.3 Document scope hierarchy and resolution rules