pub fn default_adapters() -> Vec<Arc<dyn EnvoyAdapter>>Expand description
Construct the tier-S adapters this process can source live credentials for from ambient env/vault state alone — no camp-scoped config needed.
R409-T9: this is the “host” half of the classification process W144
describes — rather than every call site (the yah-mcp binary, tests,
future hosts) re-deriving “which providers do we have tokens for,” the
policy lives once here. A provider with no credentials present is
silently absent from the result (possibly empty) rather than an error —
same graceful-degradation convention as cloud.yubaba_status and
friends: the KgToolRegistry ends up simply not offering that provider’s
verbs rather than every session erroring at startup for lack of a
Hetzner token.
Excluded on purpose:
- Cloudflare (
dns.*/cloud.object.*) —CloudflareEnvoyneeds anaccount_id, which today is camp-scoped config (.yah/infra/providers/cloudflare.toml), not ambient env/vault state. A caller with acamp_rootcan build one directly (CloudflareEnvoy::new(token, account_id)) and register it alongside this function’s output viaKgToolRegistry::with_envoy_adapters. - LocalDocker — needs a live containerd socket and sits behind the
local-dockercargo feature; wiring it in by default would make every consumer of this function require a reachable containerd, which most don’t have. Same opt-in path as Cloudflare.
Both are natural follow-ups once a caller has the extra context to build them; nothing about the verb-tool wiring itself is Hetzner/DO- specific.