Add opt-in decryption for CLI and web observability#1000
Closed
TooTallNate wants to merge 46 commits intonate/wire-encryptionfrom
Closed
Add opt-in decryption for CLI and web observability#1000TooTallNate wants to merge 46 commits intonate/wire-encryptionfrom
TooTallNate wants to merge 46 commits intonate/wire-encryptionfrom
Conversation
Contributor
This was referenced Feb 11, 2026
Contributor
🧪 E2E Test Results❌ Some tests failed Summary
❌ Failed Tests🌍 Community Worlds (46 failed)mongodb (1 failed):
turso (45 failed):
Details by Category✅ ▲ Vercel Production
✅ 💻 Local Development
✅ 📦 Local Production
✅ 🐘 Local Postgres
✅ 🪟 Windows
❌ 🌍 Community Worlds
✅ 📋 Other
|
Member
Author
|
Warning This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
This stack of pull requests is managed by Graphite. Learn more about stacking. |
🦋 Changeset detectedLatest commit: 9ef7740 The changes in this PR will be included in the next version bump. This PR includes changesets to release 15 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
7142697 to
cfa8bb9
Compare
…sts, fix stale comments
…step/hook/sleep callbacks
…ks from step/hook/sleep callbacks" This reverts commit 1ec73ba.
…ent race condition
…ompletion corruption check - Scan-forward consume loop skips past out-of-order events to find ones current subscribers can match, fixing deadlocks from async DB writes - Replace aggressive setTimeout(0) unconsumed check with 1s watchdog timer that only fires on true deadlock (no progress for 1 second) - Add onEventConsumed callback for passive timestamp observation without participating in event matching (replaces timestamp subscriber) - Add post-completion check in runWorkflow: if events remain unconsumed after workflow completes, throw WorkflowRuntimeError (catches duplicate/orphaned events that scan-forward skipped past) - Update all tests for new mechanics (splice-based, watchdog timing, corruption detection via post-completion check)
… collapsed preview
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Summary
Adds encryption-aware observability so users can view encrypted workflow data in the CLI and web UI:
CLI
--decryptflag forworkflow inspectcommandsEncryptedDataRefwithutil.inspect.customfor styled encrypted data displayWorkflowRunfor key resolution, caches perrunIdWeb UI
getEncryptionKeyForRunRPC endpoint with client-sideimportKey()decryptionShared
hydrateResourceIOWithKey()for browser-side decryption