Skip to content

Configuration and provider access

Configuration records intent and ownership. Authentication remains the provider adapter's responsibility; configuration loading does not read a credential file, resolve environment secrets, or contact a cloud account.

Explicit identity

A foundation configuration such as intent.toml uses schema version 1:

schema_version = 1
profile = "secure-gateway"

[identity]
project = "example-project"
stack = "example-stack"
provider = "yandex-cloud"
scope_id = "example-folder"
owner_id = "example-owner"

[[resources]]
logical_id = "gateway"
kind = "instance"
name = "example-gateway"

These are synthetic identifiers. Substitute your own intended folder and ownership identity before provider calls. Core names use lowercase letters, digits and hyphens, starting with a letter; the opaque scope ID is validated separately. Unknown fields, duplicate logical IDs and unsupported schema versions fail closed.

Validate locally through the configuration API:

from flayer.core.config import LoadConfig

config = LoadConfig("intent.toml")
print(config.identity.project, config.profile)

This basic model describes resource identities. The lifecycle deployment plan adds explicit dependencies and provider parameters; it is a separate loader. A gateway profile compiles its security settings into that plan. See first deployment for the second-wave path.

Existing Yandex CLI authentication

Install the official Yandex Cloud CLI and configure a named account/profile using the vendor's instructions. Select the intended folder yourself. F-Layer does not initialize profiles, export access tokens, or fall back to a profile's default folder.

yc --version

Constructing the adapter is local; its read operations access the chosen account:

from flayer.providers.contracts import ResourceKind
from flayer.providers.yandex import YandexCloudProvider, YandexCloudSettings

provider = YandexCloudProvider(
    YandexCloudSettings(folder_id="example-folder", profile="example")
)
status = provider.CheckAuthentication()

if status.authenticated:
    instances = provider.ListResources(ResourceKind.INSTANCE)
    print(len(instances))

Use actual scope/profile values for an authorized account. Each cloud command supplies an explicit folder and profile; returned scope IDs must match. Read authentication success does not establish mutation permissions or access to every resource kind. The adapter never includes raw vendor stdout/stderr in public errors. See the provider contract and generated API reference for exact result types.

Credentials and durable state

Optional foundation credential entries hold references, never inline values:

[[credentials]]
name = "provider-auth"
source = "env"
reference = "EXAMPLE_PROVIDER_AUTH"

The foundation loader preserves that reference without resolving it. The current Yandex adapter uses existing yc authentication instead; this entry does not configure that adapter or inject a token into its commands.

Runtime state stores the minimum external IDs and exact owned stack identity. Keep it in an operator-controlled directory; do not commit it. Reusing another owner's state or changing identity to adopt arbitrary resources is rejected.