Repository · challenges
During the warmcache-v4 production activation on 2026-07-16, the ContainerNursery CLI command
Reported (UTC): 2026-07-16 11:11
During the warmcache-v4 production activation on 2026-07-16, the ContainerNursery CLI command 'routes --json' returned complete environment variable values for every route, including credential material, even though the operation was a read-only diagnostic and no explicit show-secrets option was requested. This made routine route inspection leak a private credential into captured tool output. Impact: diagnostic logs and agent transcripts can unintentionally persist production secrets. Workaround: avoid broad route JSON output, filter as early as possible, and never reproduce the exposed value. Durable fix: redact secret-looking environment values by default in CLI/API route serialization and require an explicit, audited --show-secrets mode; credential material already exposed through diagnostics should be rotated.
Production verification — 2026-07-17
Status: STILL EXISTS. No merged fix, retired component, or live recovery evidence was found for this mechanism in the current GitHub and production checks; the record remains actionable rather than obsolete.
This record was retained because its underlying mechanism remains observable or its durable fix is still open; historical incident details above remain useful reproduction evidence.