pub fn deployer_secret_environment(
inputs: &[StackInputDefinition],
values: &HashMap<String, Value>,
stored_secret_input_ids: Option<&[String]>,
environment: &[EnvironmentVariable],
platform: Platform,
reports: &[DeployerSecretReport],
) -> Vec<(DeployerSecretEnv, Option<Vec<String>>)>Expand description
The environment variables workloads read from vault-native deployer
secrets, each with the resources its mapping targets (None = all).
A slot is read from the vault once Alien has a report for it, unless the deployment still stores a value from before slots were vault-native: that value keeps today’s path until the control plane drops it. The workload’s profile gains the vault read grant at the same point, so a workload never reads a slot it may not read.