🔧 AI Nachrichten KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🐧 Linux TippsPACMAN: KI-Framework steuert Fusionsplasma in Echtzeit(11.09.2026 um 10:46 Uhr)
📰 IT NachrichtenAutismus und ADHS mit früher Weichmacher-Exposition verknüpft(12.09.2026 um 09:04 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
⚠️ Malware / Trojaner / VirenNeue Android-Malware schreit Sie an, wenn Sie nicht zahlen(11.09.2026 um 10:33 Uhr)
📰 IT Nachrichten7-max: Tool bringt 10 bis 20 Prozent mehr Tempo für Programme(12.09.2026 um 09:30 Uhr)
⚠️ Malware / Trojaner / VirenHandy: Wer diese App installiert hat, sollte sein Gerät besser zurücksetzen(11.09.2026 um 16:55 Uhr)
🔧 AI Nachrichten KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🐧 Linux TippsPACMAN: KI-Framework steuert Fusionsplasma in Echtzeit(11.09.2026 um 10:46 Uhr)
📰 IT NachrichtenAutismus und ADHS mit früher Weichmacher-Exposition verknüpft(12.09.2026 um 09:04 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
⚠️ Malware / Trojaner / VirenNeue Android-Malware schreit Sie an, wenn Sie nicht zahlen(11.09.2026 um 10:33 Uhr)
📰 IT Nachrichten7-max: Tool bringt 10 bis 20 Prozent mehr Tempo für Programme(12.09.2026 um 09:30 Uhr)
⚠️ Malware / Trojaner / VirenHandy: Wer diese App installiert hat, sollte sein Gerät besser zurücksetzen(11.09.2026 um 16:55 Uhr)

🔧 Programmierung 🕛 vor 3 Monaten 3 Min Lesezeit
0

Two platforms, one missing secret: enabling dev.to and Bluesky in a content pipeline

↗ Quelle (dev.to)
🗣️ Stimme:

Two platforms, one missing secret key. That is the entire story of this session, and yet the second one ate an hour I did not expect to spend.



The setup looked trivial. My content platform engine already had valid credentials for both dev.to (via the Forem API) and Bluesky (via the AT Protocol). They lived in notes.env, already harvested under PE_ aliases. All that was left was flipping enabled = true for each adapter and running a live verification post on both. Dev.to came up on the first try.



Bluesky did not.



The publish call failed with missing AT Proto identifier. This is the kind of error that looks like a credential problem but actually points at an architectural assumption baked into the runtime.



Here is what happened. The platform engine resolves secrets by reading a descriptor.secrets list and populating a creds dict from environment variables. Adapters pull from that dict at publish time. The Bluesky adapter needs two things to authenticate: a password (the app password Bluesky generates for you) and an identifier, which is your handle or DID.



The password was in descriptor.secrets. The identifier was not.



Why? Because when the adapter was first wired up, the identifier landed in extra.identifier_secret rather than the main secrets list. The reasoning made sense at the time: the identifier is not secret in the same way a password is. Your Bluesky handle is public. But the runtime does not care about that conceptual distinction. It only resolves what is explicitly listed in descriptor.secrets. If something lives only in extra, it never reaches creds.



The fix was adding PE_BSKY_IDENTIFIER to the secrets list. One line. The runtime picks it up, the adapter gets it, the publish call goes through. Both doctor (the config validator) and missing (the environment checker) now validate it too, so this failure surfaces early rather than at publish time.



Verified live: a dev.to article posted, a Bluesky note posted.



What I would do differently: the extra field should not exist as a mechanism for passing resolved runtime values. If a value needs to be in creds at publish time, it belongs in descriptor.secrets, full stop. extra is fine for static config (timeouts, retry counts, platform specific flags) but the moment you route a secret key name through it and expect the runtime to resolve it, you have a leaky abstraction that will waste your afternoon.



The broader pattern worth internalizing: when a publish call fails with a missing error, do not reach for your credentials file first. Check whether the runtime even knows to look for that credential. Two layers can both be correctly configured while the wire between them is missing entirely. That is a harder bug to see because nothing looks obviously wrong until you actually call publish.



Two platforms live. One bug fixed. The fix was one line; the diagnosis was not.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten
1 Quelle
Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf
1 Quelle
PACMAN: KI-Framework steuert Fusionsplasma in Echtzeit
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Two platforms, one missing secret: enabling dev.to and Bluesky in a content pipeline

Thematisch verwandte Begriffe: platforms, missing, secret, enabling · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...