every secondary-profile sender, #86905). The
unscoped default-profile path (`UnscopedSecretError`) and single-profile deployments keep the
`os.environ` read — there it IS the profile's own value. Never re-implement
only inventory — install kind, all
profiles, every live gateway with supervisor + running code version. Deployment kinds are
first-class: `git` updates in place; `docker`/`nix`/`apt` are NOT in-place
shell` request/spec split is the template).
- **No hardcoded tunables in plugins**: deployment-varying choices are validated `Config` fields changeable from cordis.yml; a `DEFAULT_*` constant or test hook is not configurability
expose the legacy or explicit-key methods.
- The raw AES classes stay inside `packages/core/src/encryption/`.
- **Deployment keys are never deleted** — data encrypted with a key becomes
unreadable without it. Deactivate keys
override would disable the other required proposals.
Use `resolveGitHubSessionUri` to validate and derive the deployment base; never
parse an account's display label or infer its host from
hotfix/*` branch targeting `master` for incident-speed changes (model kills, routing swaps) — CD deploys on merge. See `docs/platform/contributing/managing-llm-models.md`.
### Creating Pull Requests
- Create the PR against the `dev` branch
workflows, and RAG pipelines. This monorepo contains the backend API (`api/`), frontend application (`web/`), deployment assets (`docker/`), standalone agent backend (`dify-agent/`), CLI (`cli/`), and end-to-end suite
create the PR.
### Adopting a Fork PR
Fork PRs run without repository secrets, so deploy tests never run on them. To run those tests, a maintainer adopts
review instructions
- During code review, flag any change that newly disables, skips, or omits deploy-mode tests or assertions, including `skipDeployment: true` and `isNextDeploy` conditionals. Only allow this when
most recent successful `/scrape` flow into a permanent browser-skill (fallback browser only). |
### Release + deploy
| Skill | What it does |
|-------|-------------|
| `/ship` | Run tests, review, push, open PR. Workspace-aware version queue
ai.azure.com)
- `AZURE_OPENAI_ENDPOINT` - عنوان نقطة نهاية Azure OpenAI (نقطة موارد Foundry)
- `AZURE_OPENAI_DEPLOYMENT` - اسم نشر نموذج إكمال الدردشة (الافتراضي للدورة: `gpt-5-mini`)
- `AZURE_OPENAI_EMBEDDINGS_DEPLOYMENT` - اسم
AZURE_OPENAI_ENDPOINT` - URL на Azure OpenAI endpoint (endpoint на Foundry ресурса)
- `AZURE_OPENAI_DEPLOYMENT` - Име на deployment за чат модел (по подразбиране за курса: `gpt-5-mini`)
- `AZURE_OPENAI
OPENAI_ENDPOINT` - URL del endpoint de Azure OpenAI (endpoint del recurso Foundry)
- `AZURE_OPENAI_DEPLOYMENT` - Nombre del despliegue del modelo de chat completions (valor por defecto: `gpt-5-mini`)
- `AZURE