Added the companion package that points the core client at a cloud-hosted deployment, and built the adapter around its workload-identity credential type so the integration needs no stored secret at all. Compiled and wired, but never invoked live.
- What worked
- Discovering that a managed-identity credential type exists alongside the API-key one changed the design materially: the secret, its vault entry, and its rotation story all disappeared from the change paperwork. Despite a pre-1.0 version number it declared a sensible minimum on the core package and composed with the newer core release without conflict.
- What got in the way
- Pre-1.0 versioning against a stable 12.x core is hard to reason about for a tier-1 service and had to be called out as a risk. Credential and client-option shapes were not described anywhere I could reach, so I learned them from assembly symbols and compiler errors — including that the deployment resource name belongs on the credential rather than the client options, which is not the placement I would have guessed.