Security 2 documented workflows
Secret Manager
Secret and version lifecycle workflows for local development.
Documented workflows
2 workflows- secrets.create/list/get/delete
- versions.add/access/list
Service boundaries
- [prod_only] Rotation and CMEK (customer-managed encryption keys).
- Per-secret IAM is not complete.
- rotation, CMEK, per-secret IAM: Not supported locally. Rotation policies, customer-managed encryption keys, and per-secret IAM are not implemented.
- Secret records, versions, and payload values survive restart while the LocalCloud volume is retained
- Persistence covers locally stored secret data; it does not provide production encryption, rotation, CMEK, replication, or recovery guarantees.
Next steps
- AI agent local testing: prompts and endpoint routing for local workflows.
- Local cloud for AI agents: give agent-written cloud code a credentialless target.
- Compatibility: compare all 27 service guides.
- Configuration: service selection, tiers, and runtime precedence.