File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -92,6 +92,21 @@ Four properties of runs and run records that mislead diagnosis when unknown:
9292 in-workflow logs block reports the same run's cost in credits. Never compare or store the two as
9393 one number.
9494
95+ ## ` {{KEY}} ` in run output is usually a mask, not a failure
96+
97+ Only ` workflows runs get ` and ` logs get ` return the masked copy, where a resolved secret is written
98+ back as ` {{KEY}} ` - or ` [REDACTED_SECRET] ` when it cannot be pinned to one name. Live run output is
99+ never masked: a plain run and a ` --follow ` stream hit the same endpoint and both carry real values,
100+ so never quote either back.
101+
102+ So a ` {{KEY}} ` in a masked log is usually a resolved secret rather than a broken reference - but it
103+ is not proof. An unresolved name survives too: JavaScript and Python leave it literal, shell
104+ resolves it to the empty string, and a secret shorter than 8 characters is never masked at all, so
105+ its ` {{KEY}} ` is always unresolved. ` sim --output json secrets list ` proves only that a name exists,
106+ not that it resolved in this run. When a block behaves as though the credential were literal text,
107+ check the spelling there first - but never "fix" a working reference by rewriting it into
108+ ` environmentVariables.KEY ` or hardcoding a literal.
109+
95110Report which mode ran, the terminal status, and the relevant output or error. Include the run id when
96111the selected execution mode returns one; ` --follow ` streams omit it. Never print profile credentials
97112or raw secrets from block inputs.
You can’t perform that action at this time.
0 commit comments