diff --git a/sunbeam-python/sunbeam/storage/backends/dellpowerstore/backend.py b/sunbeam-python/sunbeam/storage/backends/dellpowerstore/backend.py index 4ca2a6f77..0fa25924e 100644 --- a/sunbeam-python/sunbeam/storage/backends/dellpowerstore/backend.py +++ b/sunbeam-python/sunbeam/storage/backends/dellpowerstore/backend.py @@ -28,6 +28,7 @@ class DellPowerstoreConfig(StorageBackendConfig): san_ip: Annotated[ str, Field(description="Dell PowerStore management IP"), + SecretDictField(field="san-ip"), ] san_login: Annotated[ str, diff --git a/sunbeam-python/tests/unit/sunbeam/storage/backends/test_dellpowerstore.py b/sunbeam-python/tests/unit/sunbeam/storage/backends/test_dellpowerstore.py index 1cd8bb040..c6d346901 100644 --- a/sunbeam-python/tests/unit/sunbeam/storage/backends/test_dellpowerstore.py +++ b/sunbeam-python/tests/unit/sunbeam/storage/backends/test_dellpowerstore.py @@ -92,6 +92,15 @@ def test_dellpowerstore_san_credentials_are_secret(self, backend): config_class = backend.config_type() + # Check san_ip is marked as secret + ip_field = config_class.model_fields.get("san_ip") + assert ip_field is not None + has_secret_marker = any( + isinstance(m, SecretDictField) for m in ip_field.metadata + ) + + assert has_secret_marker, "san_ip` should be marked as secret" + # Check san_login is marked as secret username_field = config_class.model_fields.get("san_login") assert username_field is not None