Docs Cloud Platform Connectors

Cloud platform connectors

Cloud operators manage outbound email, sign-in providers, payment and fiscal adapters, and the internal support-board destination under Operator console → Email, payment and fiscal connectors. Connector settings are central product configuration and survive an application restart.

Each connector has a revision and an immutable credential version. Updates require a recent step-up verification, the current revision, and a stable idempotency key. A concurrent update returns a conflict; reload the connector list and review the newer revision before retrying.

Secret values are write-only. The API, operator UI, CLI output, audit events, and SDK response models return only safe metadata such as secret_configured, secret_fields, and secret_revoked. They never return the credential value.

Legacy CLOUD_API_SMTP_* and CLOUD_API_COMMERCIAL_PROVIDERS_JSON settings are no longer runtime authorities. An upgraded process fails at startup when they remain non-empty, instead of silently ignoring credentials. Configure the matching connector through the operator API or CLI, verify it, and then remove the legacy variables before restarting Cloud. CLOUD_API_COMMERCIAL_PROVIDER_TIMEOUT_MS remains supported as the outbound payment-provider timeout during this transition.

Supported connectors

Connector Connector key Public settings Write-only secret fields
Outbound email smtp default host, port, username, implicit_tls password
Yandex ID oauth yandex client_id client_secret
VK ID oauth vk client_id client_secret
GitHub oauth github client_id client_secret
YooKassa payment yookassa main account, market, currency, channel, and mode settings secret_key, webhook_hmac
Stripe payment stripe main account, market, currency, channel, and mode settings secret_key, webhook_secret
ATOL Online fiscal atol main receipt identity, tax, account, market, currency, channel, and mode settings login, password
Internal support boards saas mockarty internal base_url, namespace, project_id, issue_type api_token

Internal support board destination

Configure this connector in the operator UI. For a deployed destination, base_url must be an HTTPS hostname without a path, query, fragment, embedded credentials, or raw IP address. The local Compose topology may use only the fixed internal address http://mockarty-saas-runtime-lb:5770. Set namespace to the dedicated internal support tenant, project_id to the exact project UUID, and issue_type to bug, task, or story.

The API token is write-only and should be limited to creating and reading issues in that one internal project. Changing base_url, namespace, or project_id requires entering the API token again; Cloud never redirects a previously stored write-only credential to a new authority. Saving a new connector version does not move already queued routes: each route stays pinned to the exact immutable credential version selected when it was created. Revoking that version stops its pending work fail-closed.

Configure through the CLI

Pass only the environment variable name through --secret-env; the raw value does not enter the command line. The variable must exist in the environment of the CLI process.

export MOCKARTY_SMTP_PASSWORD='replace-in-your-secure-shell'
mockarty cloud-connectors configure smtp default \
  --config host=smtp.example.internal \
  --config port=465 \
  --config username=mailer \
  --config implicit_tls=true \
  --secret-env password=MOCKARTY_SMTP_PASSWORD \
  --expected-revision 1 \
  --enabled \
  --idempotency-key smtp-config-20260830-1

List safe metadata before and after the update:

mockarty cloud-connectors list

Every connector that can be checked safely has a Check connection action in the cabinet (Operator → Connectors) and the same command in the CLI. The check is read-only: it never creates a payment, a refund or a receipt.

  • SMTP sends one test letter, only to the verified email address of the current operator.
  • YooKassa reads the shop record (GET /me) with the stored shop id and secret key.
  • Stripe reads the account balance (GET /balance) with the stored secret key.
  • ATOL Online requests an API token (POST /getToken) with the stored login and password for the configured cash-register group.
mockarty cloud-connectors test smtp default --idempotency-key smtp-test-20260830-1
mockarty cloud-connectors test payment yookassa main --idempotency-key yookassa-probe-20260830-1
mockarty cloud-connectors test fiscal atol main --idempotency-key atol-probe-20260830-1

The answer names the next step instead of echoing the provider: provider_ok (the credentials work), provider_rejected_credentials (the provider answered and refused them — check the identifiers and the secret), provider_unreachable (the provider did not answer — check the base address and outbound network access). A connector does not have to be the default one to be checked, so a freshly entered test account can be verified before it is promoted. The result is recorded on the connector version and shown as its last test status.

Revoke a compromised immutable version by the version_id returned in safe metadata:

mockarty cloud-connectors revoke VERSION_ID --idempotency-key connector-revoke-20260830-1

Revocation is fail-closed: runtime adapters cannot continue using the revoked version. Configure and review a new version before re-enabling delivery or payments.

Saving configuration or receiving a successful HTTP response is not proof that an external provider works. Run the connection check, then complete one full test payment (and, for ATOL, one test receipt) against the provider’s own sandbox before production use. OAuth connectors are verified by signing in through them.