Aidp Credentials

作者 oracle-samples90b42d6c24d4無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Manage the AIDP credential store (secrets) — list, get, create, update, delete credentials used by AIDP workflows. Use when the user wants to store/rotate a secret centrally instead of embedding it, or manage connection credentials. Primary engine is the official `aidp` CLI (`aidp credentials …`); the same Preview REST API via `oci raw-request` is the no-CLI fallback. Verify the endpoint live before relying on it.

AI 產生的概覽

透過 aidp CLI 或 REST 備援方式管理 AIDP 集中儲存的認證與密鑰。

功能
列出、取得、建立、更新與刪除 AIDP 認證存放區中的認證,以 aidp CLI 為主要方式,OCI raw-request REST 呼叫作為無 CLI 時的備援方式。文件說明了 SECRET_TOKEN、VAULT_REFERENCE 與 SERVICE_ACCOUNT 三種認證型別的建立請求內容結構,並要求在執行寫入前先做即時驗證。其產出是認證記錄與持久化的請求內容,而不是在輸出中顯示密鑰值。
適用情境
適用於使用者希望將密鑰集中儲存在 AIDP 中而非嵌入程式碼,或需要管理連線認證的情境。也適用於在依賴認證存放區端點之前需要先驗證該端點的情況。
執行需求
需要 aidp CLI,並設定執行個體 ID、api_key 驗證、設定檔與區域;或使用 oci CLI 作為 raw-request 備援方式;需要連線至 AIDP 端點的網路存取。此技能不附帶指令碼,僅為說明文件。

aidp-credentials — credential store (Preview)

Manage centrally-stored AIDP credentials/secrets.

CLI (preferred): aidp credentials <command> --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region <r>

  • aidp credentials list | get | create | update | delete

Fallback (no CLI): same credentialStore REST API via oci raw-request (identical endpoint + auth; see references/oci-raw-request.md).

Preview + verify-first (no-fabrication): credentialStore is Preview and the route exists, but its GET/response shape is TBD. Confirm the working path (default 20240831/dataLakes) with a live aidp credentials list (or GET …/credentials) before asserting success or doing writes; record it in references/rest-endpoint-map.md. Treat the path as UNVERIFIED until a live 2xx returns.

When to use

  • "Store/rotate a secret in AIDP", "manage connection credentials", "stop embedding this secret in code".

Workflow

  1. Verify first: aidp credentials list (CLI) — or a GET …/credentials (REST fallback) — returns 2xx; record the version/prefix.
  2. Read/create/update as asked. Never print secret values; pass secret material in the request body only, never echo it back. Confirm before delete/rotate.
  3. Handle async 202 + etag/if-match per the shared conventions.

Mutating ops (create, update/rotate, delete): persist the body to .aidp/payloads/ and confirm first (references/payloads.md).

Create body — CreateDataLakeCredentialDetails

CLI: aidp credentials create <DATALAKE_OCID> --body <JSON> (CLI README "credentials create"). Top-level envelope (SDK create_data_lake_credential_details.py:51-63):

Field (wire)ReqNotes
displayName✅start with a letter; letters/digits/_ only — no secrets in the name
credentialDescription–purpose summary
type✅discriminator — SECRET_TOKEN | VAULT_REFERENCE | SERVICE_ACCOUNT (…:18-26)
credentialDetails✅nested object whose credentialType must match type (credential_details.py:52-73)

credentialDetails shape per type (subclass models + CLI README "credentials create"):

credentialTypeFields (wire)Source
SECRET_TOKENsecretTokenPair: array of {secretKey, secretValue}secret_token_credential_details.py:38-41, secret_pair.py:35-38
VAULT_REFERENCEsecretId (OCID of an external Vault secret)vault_reference_credential_details.py:38-41
SERVICE_ACCOUNTuserId, fingerprint, tenancy, region, isReadOnly, privateKeyservice_account_credential_details.py:63-71

Example (SECRET_TOKEN) — persist to .aidp/payloads/create-<name>-credential.json and confirm first; the secretValue is the only secret material — pass it in the body, never echo it back:

json
{  "displayName": "github_pat",  "credentialDescription": "GitHub PAT for workspace git",  "type": "SECRET_TOKEN",  "credentialDetails": {    "credentialType": "SECRET_TOKEN",    "secretTokenPair": [ { "secretKey": "token", "secretValue": "<PAT>" } ]  }}

Field names are confirmed (SDK attribute_map + CLI README). The full create round-trip is verify-first: …/credentials GET returned 400 here (Preview, list-shape TBD — references/rest-endpoint-map.md), so confirm a 2xx before relying on the POST.

Fallback (no CLI) — REST endpoints (lake-scoped, Preview)

Live-probed 2026-06-10: GET …/dataLakes/<ocid>/credentials → 400 (route exists, list-shape TBD — needs a param/body); …/workspaces/<ws>/credentials → 404 (so credentials are lake-scoped, not workspace-scoped).

  • GET /dataLakes/<ocid>/credentials — list (400 until the required param/shape is supplied — verify live)
  • POST /dataLakes/<ocid>/credentials — create
  • GET|PUT|DELETE /dataLakes/<ocid>/credentials/{key} — get / update / delete

Base URL: https://aidp.<region>.oci.oraclecloud.com/20240831/dataLakes/<dataLakeOcid>/…

Guardrails

  • Secrets never go into logs, the transcript, or committed files.
  • Destructive ops (delete/rotate) require explicit confirmation.

References

  • references/aidp-cli-map.md · references/payloads.md · references/oci-raw-request.md · references/rest-endpoint-map.md

來源與署名

來源:oracle-samples/oracle-aidp-samples位於ai/claude-code-plugins/oracle-ai-data-platform-workbench-engineer-agent/skills/aidp-credentials提交90b42d6

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 oracle-samples/oracle-aidp-samples 的技能

Aidp Workspace Admin

oracle-samples

Provision and inspect AIDP DataLake instances and workspaces, including private-network workspaces attached to a customer VCN/subnet. Use when the user wants to create/list/get a workspace or DataLake instance, set up a new (e.g. private) AIDP environment, or replicate a customer setup. Create/delete are guarded — confirm before any provisioning.

待分類2026年10月8日

Aidp Volumes

oracle-samples

Work with AIDP volumes — list volumes, browse files inside a volume, upload/download via the PAR flow, and create directories. Use when the user mentions volumes, needs to stage large/binary files, or move data in/out of a volume (distinct from the workspace filesystem). Control-plane via the official `aidp` CLI.

待分類2026年10月8日

Aidp Verified Queries

oracle-samples

維護經過驗證的問題到 Spark SQL 配對庫,讓代理在產生新 SQL 前優先重用可信查詢。

Data & Analytics2026年10月8日

Aidp User Settings

oracle-samples

透過 aidp CLI 或 oci raw-request 備援方式管理 AIDP DataLake 使用者設定與偏好。

Productivity & Workflow2026年10月8日

Aidp Spark Optimization

oracle-samples

指導 Apache Spark 3.5.0 效能調校:分割區、shuffle、join、資料傾斜、記憶體、檔案配置、AQE 與 Delta Lake。

Data & Analytics2026年10月8日

Aidp Semantic Model

oracle-samples

維護 .aidp/semantic.md 業務語意層,定義指標、連接、同義詞與值字典,為自然語言轉 SQL 提供依據。

Data & Analytics2026年10月8日