Aidp Credentials

作者 oracle-samples90b42d6c24d4无许可证收录于 2026年10月8日更新于 2026年10月8日

Manage the AIDP credential store (secrets) — list, get, create, update, delete credentials used by AIDP workflows. Use when the user wants to store/rotate a secret centrally instead of embedding it, or manage connection credentials. Primary engine is the official `aidp` CLI (`aidp credentials …`); the same Preview REST API via `oci raw-request` is the no-CLI fallback. Verify the endpoint live before relying on it.

AI 生成的概览

通过 aidp CLI 或 REST 备用方式管理 AIDP 集中存储的凭据与密钥。

功能
列出、获取、创建、更新和删除 AIDP 凭据存储中的凭据,以 aidp CLI 为主要方式,OCI raw-request REST 调用作为无 CLI 时的备用方式。文档说明了 SECRET_TOKEN、VAULT_REFERENCE 和 SERVICE_ACCOUNT 三种凭据类型的创建请求体结构,并要求在执行写入前先做实时验证。其产出是凭据记录和持久化的请求负载,而不是在输出中显示密钥值。
适用场景
适用于用户希望将密钥集中存储在 AIDP 中而不是嵌入代码,或需要管理连接凭据的场景。也适用于在依赖凭据存储端点之前需要先验证该端点的情况。
运行要求
需要 aidp CLI,并配置实例 ID、api_key 认证、配置文件和区域;或使用 oci CLI 作为 raw-request 备用方式;需要访问 AIDP 端点的网络连接。该技能不附带脚本,仅为说明文档。

aidp-credentials — credential store (Preview)

Manage centrally-stored AIDP credentials/secrets.

CLI (preferred): aidp credentials <command> --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region <r>

  • aidp credentials list | get | create | update | delete

Fallback (no CLI): same credentialStore REST API via oci raw-request (identical endpoint + auth; see references/oci-raw-request.md).

Preview + verify-first (no-fabrication): credentialStore is Preview and the route exists, but its GET/response shape is TBD. Confirm the working path (default 20240831/dataLakes) with a live aidp credentials list (or GET …/credentials) before asserting success or doing writes; record it in references/rest-endpoint-map.md. Treat the path as UNVERIFIED until a live 2xx returns.

When to use

  • "Store/rotate a secret in AIDP", "manage connection credentials", "stop embedding this secret in code".

Workflow

  1. Verify first: aidp credentials list (CLI) — or a GET …/credentials (REST fallback) — returns 2xx; record the version/prefix.
  2. Read/create/update as asked. Never print secret values; pass secret material in the request body only, never echo it back. Confirm before delete/rotate.
  3. Handle async 202 + etag/if-match per the shared conventions.

Mutating ops (create, update/rotate, delete): persist the body to .aidp/payloads/ and confirm first (references/payloads.md).

Create body — CreateDataLakeCredentialDetails

CLI: aidp credentials create <DATALAKE_OCID> --body <JSON> (CLI README "credentials create"). Top-level envelope (SDK create_data_lake_credential_details.py:51-63):

Field (wire)ReqNotes
displayName✅start with a letter; letters/digits/_ only — no secrets in the name
credentialDescription–purpose summary
type✅discriminator — SECRET_TOKEN | VAULT_REFERENCE | SERVICE_ACCOUNT (…:18-26)
credentialDetails✅nested object whose credentialType must match type (credential_details.py:52-73)

credentialDetails shape per type (subclass models + CLI README "credentials create"):

credentialTypeFields (wire)Source
SECRET_TOKENsecretTokenPair: array of {secretKey, secretValue}secret_token_credential_details.py:38-41, secret_pair.py:35-38
VAULT_REFERENCEsecretId (OCID of an external Vault secret)vault_reference_credential_details.py:38-41
SERVICE_ACCOUNTuserId, fingerprint, tenancy, region, isReadOnly, privateKeyservice_account_credential_details.py:63-71

Example (SECRET_TOKEN) — persist to .aidp/payloads/create-<name>-credential.json and confirm first; the secretValue is the only secret material — pass it in the body, never echo it back:

json
{  "displayName": "github_pat",  "credentialDescription": "GitHub PAT for workspace git",  "type": "SECRET_TOKEN",  "credentialDetails": {    "credentialType": "SECRET_TOKEN",    "secretTokenPair": [ { "secretKey": "token", "secretValue": "<PAT>" } ]  }}

Field names are confirmed (SDK attribute_map + CLI README). The full create round-trip is verify-first: …/credentials GET returned 400 here (Preview, list-shape TBD — references/rest-endpoint-map.md), so confirm a 2xx before relying on the POST.

Fallback (no CLI) — REST endpoints (lake-scoped, Preview)

Live-probed 2026-06-10: GET …/dataLakes/<ocid>/credentials → 400 (route exists, list-shape TBD — needs a param/body); …/workspaces/<ws>/credentials → 404 (so credentials are lake-scoped, not workspace-scoped).

  • GET /dataLakes/<ocid>/credentials — list (400 until the required param/shape is supplied — verify live)
  • POST /dataLakes/<ocid>/credentials — create
  • GET|PUT|DELETE /dataLakes/<ocid>/credentials/{key} — get / update / delete

Base URL: https://aidp.<region>.oci.oraclecloud.com/20240831/dataLakes/<dataLakeOcid>/…

Guardrails

  • Secrets never go into logs, the transcript, or committed files.
  • Destructive ops (delete/rotate) require explicit confirmation.

References

  • references/aidp-cli-map.md · references/payloads.md · references/oci-raw-request.md · references/rest-endpoint-map.md

来源与署名

来源:oracle-samples/oracle-aidp-samples位于ai/claude-code-plugins/oracle-ai-data-platform-workbench-engineer-agent/skills/aidp-credentials提交90b42d6

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 oracle-samples/oracle-aidp-samples 的技能

Aidp Workspace Admin

oracle-samples

Provision and inspect AIDP DataLake instances and workspaces, including private-network workspaces attached to a customer VCN/subnet. Use when the user wants to create/list/get a workspace or DataLake instance, set up a new (e.g. private) AIDP environment, or replicate a customer setup. Create/delete are guarded — confirm before any provisioning.

待分类2026年10月8日

Aidp Volumes

oracle-samples

Work with AIDP volumes — list volumes, browse files inside a volume, upload/download via the PAR flow, and create directories. Use when the user mentions volumes, needs to stage large/binary files, or move data in/out of a volume (distinct from the workspace filesystem). Control-plane via the official `aidp` CLI.

待分类2026年10月8日

Aidp Verified Queries

oracle-samples

维护经过验证的问题到 Spark SQL 配对库,让智能体在生成新 SQL 前优先复用可信查询。

Data & Analytics2026年10月8日

Aidp User Settings

oracle-samples

通过 aidp CLI 或 oci raw-request 备用方式管理 AIDP DataLake 用户设置与偏好。

Productivity & Workflow2026年10月8日

Aidp Spark Optimization

oracle-samples

指导 Apache Spark 3.5.0 性能调优:分区、shuffle、连接、倾斜、内存、文件布局、AQE 与 Delta Lake。

Data & Analytics2026年10月8日

Aidp Semantic Model

oracle-samples

维护 .aidp/semantic.md 业务语义层,定义指标、连接、同义词和值字典,为自然语言转 SQL 提供依据。

Data & Analytics2026年10月8日