Workspace workflow
Repo config stays commit-safe. Secrets live in the vault; each developer picks one local environment.
Preview
Review env files before anything is written.
Apply
Store selected secrets and write refs.
Run
Resolve at the Authsia boundary.
Applying selected workspace secrets asks for one Workspace Secret Migration approval covering the selected items, destination folder, environment tags, and rollback backups. It grants no reusable CLI session. If approval is denied or storage fails, env files remain unchanged. The app's local preview and rules-only updates need no vault approval.
Select one environment
List Default, workspace tags, and env bindings, then select one. Named envs use exact-tagged and All items; Default stays inactive until you use Default or clear.
Remove a stale binding with authsia workspace env remove NAME authsia://.... Removal works even when unrelated MCP configuration is invalid; it preserves vault items, other bindings, and MCP settings. Normal workspace operations still require valid configuration.
Override one run
Does not change the saved workspace environment.
Resolution order
Searches upward for the nearest .authsia/workspace.json. Conflicts fail closed.
Metadata without interrupting for approval
workspace env use, workspace env list, workspace env validate, and secret-bearing workspace run planning stays metadata-only for configured CLI-enabled refs. At the secret boundary, direct-human runs batch every supported requested item into one approval before creating the normal terminal session. Secret values never appear in either view.