Workspace workflow

Repo config stays commit-safe. Secrets live in the vault; each developer picks one local environment.

Authsia resolves refs in the child process, not the parent shell.

Preview

Review env files before anything is written.

Apply

Store selected secrets and write refs.

Run

Resolve at the Authsia boundary.

Applying selected workspace secrets asks for one Workspace Secret Migration approval covering the selected items, destination folder, environment tags, and rollback backups. It grants no reusable CLI session. If approval is denied or storage fails, env files remain unchanged. The app's local preview and rules-only updates need no vault approval.

Select one environment

List Default, workspace tags, and env bindings, then select one. Named envs use exact-tagged and All items; Default stays inactive until you use Default or clear.

Remove a stale binding with authsia workspace env remove NAME authsia://.... Removal works even when unrelated MCP configuration is invalid; it preserves vault items, other bindings, and MCP settings. Normal workspace operations still require valid configuration.

Override one run

Does not change the saved workspace environment.

Resolution order

Searches upward for the nearest .authsia/workspace.json. Conflicts fail closed.

Guarded shims reuse this order on every command after you change the active environment.

Metadata without interrupting for approval

workspace env use, workspace env list, workspace env validate, and secret-bearing workspace run planning stays metadata-only for configured CLI-enabled refs. At the secret boundary, direct-human runs batch every supported requested item into one approval before creating the normal terminal session. Secret values never appear in either view.