Skip to content

Configure S3 profile credentials in Witan - #357

Merged
feoh merged 3 commits into
mainfrom
feat/witan-s3-profile-credentials
Sep 18, 2026
Merged

feoh merged 3 commits into
mainfrom
feat/witan-s3-profile-credentials

Conversation

@feoh

@feoh feoh commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

What are the relevant tickets?

N/A

Description (What does it do?)

  • Adds global and per-target s3_profile / s3_region settings, with environment overrides.
  • Exports AWS profile credentials into each omnigraph child process so Witan no longer needs an external credential shim.
  • Keeps local and HTTP graph behavior unchanged.
Implementation details
  • Delegates credential resolution to aws configure export-credentials --format process instead of persisting credentials in Witan's configuration.
  • Clears ambient session tokens before applying the selected profile and supplies both AWS region variable spellings.
  • Propagates the settings through serving, context injection, maintenance, actor clients, and merge store clients.
  • Bumps witan-core to 0.37.0 and raises Witan's dependency floor.

How can this be tested?

  • Configure an S3 target with s3_profile and optional s3_region, then run a read-only Witan command without the wrapper script.
  • just test-all (2,777 passed, 4 skipped)
  • Changed-file prek hooks passed.
  • just check-versions
  • just check-core-floor

Additional Context

The repository-wide prek run remains blocked by pre-existing unrelated shebang-mode and shellcheck failures in skills/process/renovate-security-triage/ and skills/process/screenshot-pr/; every hook passed for this PR's changed files.

Copilot AI balanced review requested due to automatic review settings September 17, 2026 21:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Named S3 merge endpoints can receive the wrong profile, and the new environment selectors are not hermetically cleared.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds AWS profile-based authentication for Witan S3 graph stores.

Changes:

  • Adds global, per-target, and environment S3 settings.
  • Exports AWS CLI credentials to omnigraph subprocesses.
  • Updates tests, documentation, dependency floors, and release metadata.
File summaries
File Description
uv.lock Locks witan-core 0.37.0.
packages/witan-core/witan_core/omnigraph.py Resolves and forwards AWS credentials.
packages/witan-core/tests/test_omnigraph.py Tests credential export behavior.
packages/witan-core/pyproject.toml Bumps witan-core to 0.37.0.
packages/witan-core/CHANGELOG.md Documents the new API.
mcp/servers/witan/witan/server.py Propagates S3 settings to server clients.
mcp/servers/witan/witan/context.py Supports S3-authenticated context reads.
mcp/servers/witan/witan/config.py Loads S3 profile and region settings.
mcp/servers/witan/witan/cli/maintenance.py Propagates settings to maintenance clients.
mcp/servers/witan/witan/cli/hooks.py Propagates settings during context injection.
mcp/servers/witan/tests/test_config.py Tests configuration precedence.
mcp/servers/witan/tests/test_actor_client.py Updates actor-client test doubles.
mcp/servers/witan/README.md Documents S3 profile configuration.
mcp/servers/witan/pyproject.toml Raises the witan-core dependency floor.
mcp/servers/witan/CHANGELOG.md Records the Witan feature.
Review details
  • Files reviewed: 16/17 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread mcp/servers/witan/witan/server.py Outdated
Comment thread mcp/servers/witan/witan/config.py
@feoh
feoh merged commit a9e3c62 into main Sep 18, 2026
17 checks passed
@feoh
feoh deleted the feat/witan-s3-profile-credentials branch September 18, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants