Resources
Resources displays real server state with a next action, not placeholder statistics.
Served by the core studio
Software records (sources, programs, runs, releases, components, environments, media, verification and exports) live in the core engine and are edited in its studio. When a connected engine answers through this workspace, the panels above render its own records as returned; without a connection the shell states that and shows nothing rather than an invented row. The surface contract below names each action and the setup it needs.
Surface contract
Primary object: provider resources: the reference the engine resolves, whether a secret is present, and the scopes it was granted.
Actions
- AddCore studioAdding a resource records a reference to a secret held by the deployment (for example an environment variable or managed secret); the value never enters this page.
- TestCore studioA test performs one provider call with the granted scope and reports the provider’s own answer; success is never assumed and no result is fabricated.
- RotateCore studioRotation points the engine at a new secret version and re-runs the capability check; the old value is not echoed anywhere.
- RevokeCore studioRevoking stops the engine from using the reference and records who revoked it; dependent runs then fail honestly with the missing reference.
Required states and how this surface reaches them
- loading
- the session probe and each list show Loading… until the control plane answers.
- ready
- the server’s own records render as returned; the primary object is named before its details.
- empty
- no resource is bound; bindings are created in the core studio, which stores the secret outside this shell (reference only, never the value).
- error
- the control plane’s status and detail are shown; no placeholder row replaces them.
- offline
- no control plane is reachable; nothing is rendered rather than invented.
- permission_denied
- a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
- not_configured
- a credential reference that resolves to no environment value is shown as not configured with the reference name, never as a working provider.
- budget_paused
- a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
- requires_approval
- mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.
Scope: workspace membership. Resource references and their secret presence are engine records; this hosted shell never receives or displays a secret value, and grants no scope on its own.