changedInput schema / properties / auth_config / anyOf
Previous value: -[
- {
- "additionalProperties": false,
- "properties": {
- "aws_access_key_id": {
- "description": "AWS access key ID; required when aws_auth_type is accessKey",
- "minLength": 1,
- "type": "string"
- },
- "aws_auth_type": {
- "const": "accessKey",
- "description": "Use an AWS access key ID and secret access key",
- "type": "string"
- },
- "aws_region": {
- "description": "AWS region containing the secret, for example us-east-1",
- "minLength": 1,
- "type": "string"
- },
- "aws_secret_access_key": {
- "description": "AWS secret access key; required when aws_auth_type is accessKey and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- }
- },
- "required": [
- "aws_auth_type",
- "aws_access_key_id",
- "aws_secret_access_key",
- "aws_region"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "aws_auth_type": {
- "const": "assumedRole",
- "description": "Assume the specified AWS IAM role",
- "type": "string"
- },
- "aws_external_id": {
- "anyOf": [
- {
- "type": "string"
- },
- {
- "type": "null"
- }
- ],
- "description": "Optional external ID required by the target IAM role"
- },
- "aws_region": {
- "description": "AWS region containing the secret, for example us-east-1",
- "minLength": 1,
- "type": "string"
- },
- "aws_role_arn": {
- "description": "IAM role ARN to assume; required when aws_auth_type is assumedRole",
- "minLength": 1,
- "type": "string"
- }
- },
- "required": [
- "aws_auth_type",
- "aws_role_arn",
- "aws_region"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "aws_auth_type": {
- "const": "serviceRole",
- "description": "Use the AWS workload or service role available at runtime",
- "type": "string"
- },
- "aws_region": {
- "description": "Optional AWS region containing the secret, for example us-east-1",
- "type": "string"
- }
- },
- "required": [
- "aws_auth_type"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "azure_auth_mode": {
- "const": "entra",
- "description": "Authenticate with a Microsoft Entra application client secret",
- "type": "string"
- },
- "azure_entra_client_id": {
- "description": "Microsoft Entra application client ID; required for entra authentication",
- "minLength": 1,
- "type": "string"
- },
- "azure_entra_client_secret": {
- "description": "Microsoft Entra client secret; required for entra authentication and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- },
- "azure_entra_tenant_id": {
- "description": "Microsoft Entra tenant ID; required for entra authentication",
- "minLength": 1,
- "type": "string"
- },
- "azure_vault_url": {
- "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
- "format": "uri",
- "type": "string"
- }
- },
- "required": [
- "azure_auth_mode",
- "azure_entra_tenant_id",
- "azure_entra_client_id",
- "azure_entra_client_secret",
- "azure_vault_url"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "azure_auth_mode": {
- "const": "managed",
- "description": "Authenticate with an Azure managed identity",
- "type": "string"
- },
- "azure_managed_client_id": {
- "description": "Optional client ID of a user-assigned managed identity; omit for the system-assigned identity",
- "minLength": 1,
- "type": "string"
- },
- "azure_vault_url": {
- "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
- "format": "uri",
- "type": "string"
- }
- },
- "required": [
- "azure_auth_mode",
- "azure_vault_url"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "azure_auth_mode": {
- "const": "default",
- "description": "Use Azure's default runtime credential chain",
- "type": "string"
- },
- "azure_vault_url": {
- "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
- "format": "uri",
- "type": "string"
- }
- },
- "required": [
- "azure_auth_mode",
- "azure_vault_url"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "vault_addr": {
- "description": "Base URL of the HashiCorp Vault server",
- "format": "uri",
- "type": "string"
- },
- "vault_auth_type": {
- "const": "token",
- "description": "Authenticate to HashiCorp Vault with a token",
- "type": "string"
- },
- "vault_namespace": {
- "description": "Optional HashiCorp Vault Enterprise namespace",
- "minLength": 1,
- "type": "string"
- },
- "vault_token": {
- "description": "HashiCorp Vault token; required for token authentication and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- }
- },
- "required": [
- "vault_auth_type",
- "vault_addr",
- "vault_token"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "vault_addr": {
- "description": "Base URL of the HashiCorp Vault server",
- "format": "uri",
- "type": "string"
- },
- "vault_auth_type": {
- "const": "approle",
- "description": "Authenticate to HashiCorp Vault with AppRole credentials",
- "type": "string"
- },
- "vault_namespace": {
- "description": "Optional HashiCorp Vault Enterprise namespace",
- "minLength": 1,
- "type": "string"
- },
- "vault_role_id": {
- "description": "HashiCorp Vault AppRole role ID; required for approle authentication",
- "minLength": 1,
- "type": "string"
- },
- "vault_secret_id": {
- "description": "HashiCorp Vault AppRole secret ID; required for approle authentication and exposed to the MCP transcript",
- "minLength": 1,
- "type": "string"
- }
- },
- "required": [
- "vault_auth_type",
- "vault_addr",
- "vault_role_id",
- "vault_secret_id"
- ],
- "type": "object"
- },
- {
- "additionalProperties": false,
- "properties": {
- "vault_addr": {
- "description": "Base URL of the HashiCorp Vault server",
- "format": "uri",
- "type": "string"
- },
- "vault_auth_type": {
- "const": "kubernetes",
- "description": "Authenticate to HashiCorp Vault with a Kubernetes service account",
- "type": "string"
- },
- "vault_namespace": {
- "description": "Optional HashiCorp Vault Enterprise namespace",
- "minLength": 1,
- "type": "string"
- },
- "vault_role": {
- "description": "HashiCorp Vault Kubernetes auth role name",
- "minLength": 1,
- "type": "string"
- }
- },
- "required": [
- "vault_auth_type",
- "vault_addr",
- "vault_role"
- ],
- "type": "object"
- }
-]New value: +[
+ {
+ "additionalProperties": false,
+ "properties": {
+ "aws_access_key_id": {
+ "description": "AWS access key ID; required when aws_auth_type is accessKey",
+ "minLength": 1,
+ "type": "string"
+ },
+ "aws_auth_type": {
+ "const": "accessKey",
+ "description": "Use an AWS access key ID and secret access key",
+ "type": "string"
+ },
+ "aws_region": {
+ "description": "AWS region containing the secret, for example us-east-1",
+ "minLength": 1,
+ "type": "string"
+ },
+ "aws_secret_access_key": {
+ "description": "AWS secret access key; required when aws_auth_type is accessKey and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "aws_auth_type",
+ "aws_access_key_id",
+ "aws_secret_access_key",
+ "aws_region"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "aws_auth_type": {
+ "const": "assumedRole",
+ "description": "Assume the specified AWS IAM role",
+ "type": "string"
+ },
+ "aws_external_id": {
+ "description": "Optional external ID required by the target IAM role",
+ "type": [
+ "string",
+ "null"
+ ]
+ },
+ "aws_region": {
+ "description": "AWS region containing the secret, for example us-east-1",
+ "minLength": 1,
+ "type": "string"
+ },
+ "aws_role_arn": {
+ "description": "IAM role ARN to assume; required when aws_auth_type is assumedRole",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "aws_auth_type",
+ "aws_role_arn",
+ "aws_region"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "aws_auth_type": {
+ "const": "serviceRole",
+ "description": "Use the AWS workload or service role available at runtime",
+ "type": "string"
+ },
+ "aws_region": {
+ "description": "Optional AWS region containing the secret, for example us-east-1",
+ "type": "string"
+ }
+ },
+ "required": [
+ "aws_auth_type"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "azure_auth_mode": {
+ "const": "entra",
+ "description": "Authenticate with a Microsoft Entra application client secret",
+ "type": "string"
+ },
+ "azure_entra_client_id": {
+ "description": "Microsoft Entra application client ID; required for entra authentication",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_entra_client_secret": {
+ "description": "Microsoft Entra client secret; required for entra authentication and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_entra_tenant_id": {
+ "description": "Microsoft Entra tenant ID; required for entra authentication",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_vault_url": {
+ "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
+ "format": "uri",
+ "type": "string"
+ }
+ },
+ "required": [
+ "azure_auth_mode",
+ "azure_entra_tenant_id",
+ "azure_entra_client_id",
+ "azure_entra_client_secret",
+ "azure_vault_url"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "azure_auth_mode": {
+ "const": "managed",
+ "description": "Authenticate with an Azure managed identity",
+ "type": "string"
+ },
+ "azure_managed_client_id": {
+ "description": "Optional client ID of a user-assigned managed identity; omit for the system-assigned identity",
+ "minLength": 1,
+ "type": "string"
+ },
+ "azure_vault_url": {
+ "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
+ "format": "uri",
+ "type": "string"
+ }
+ },
+ "required": [
+ "azure_auth_mode",
+ "azure_vault_url"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "azure_auth_mode": {
+ "const": "default",
+ "description": "Use Azure's default runtime credential chain",
+ "type": "string"
+ },
+ "azure_vault_url": {
+ "description": "Azure Key Vault URL, for example https://example.vault.azure.net",
+ "format": "uri",
+ "type": "string"
+ }
+ },
+ "required": [
+ "azure_auth_mode",
+ "azure_vault_url"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "vault_addr": {
+ "description": "Base URL of the HashiCorp Vault server",
+ "format": "uri",
+ "type": "string"
+ },
+ "vault_auth_type": {
+ "const": "token",
+ "description": "Authenticate to HashiCorp Vault with a token",
+ "type": "string"
+ },
+ "vault_namespace": {
+ "description": "Optional HashiCorp Vault Enterprise namespace",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_token": {
+ "description": "HashiCorp Vault token; required for token authentication and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "vault_auth_type",
+ "vault_addr",
+ "vault_token"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "vault_addr": {
+ "description": "Base URL of the HashiCorp Vault server",
+ "format": "uri",
+ "type": "string"
+ },
+ "vault_auth_type": {
+ "const": "approle",
+ "description": "Authenticate to HashiCorp Vault with AppRole credentials",
+ "type": "string"
+ },
+ "vault_namespace": {
+ "description": "Optional HashiCorp Vault Enterprise namespace",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_role_id": {
+ "description": "HashiCorp Vault AppRole role ID; required for approle authentication",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_secret_id": {
+ "description": "HashiCorp Vault AppRole secret ID; required for approle authentication and exposed to the MCP transcript",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "vault_auth_type",
+ "vault_addr",
+ "vault_role_id",
+ "vault_secret_id"
+ ],
+ "type": "object"
+ },
+ {
+ "additionalProperties": false,
+ "properties": {
+ "vault_addr": {
+ "description": "Base URL of the HashiCorp Vault server",
+ "format": "uri",
+ "type": "string"
+ },
+ "vault_auth_type": {
+ "const": "kubernetes",
+ "description": "Authenticate to HashiCorp Vault with a Kubernetes service account",
+ "type": "string"
+ },
+ "vault_namespace": {
+ "description": "Optional HashiCorp Vault Enterprise namespace",
+ "minLength": 1,
+ "type": "string"
+ },
+ "vault_role": {
+ "description": "HashiCorp Vault Kubernetes auth role name",
+ "minLength": 1,
+ "type": "string"
+ }
+ },
+ "required": [
+ "vault_auth_type",
+ "vault_addr",
+ "vault_role"
+ ],
+ "type": "object"
+ }
+]