rde-data-apps
rde-data-apps
A data app is a React bundle Metabase serves at /apps/<slug> from data_apps/<slug>/ in the repository connected through remote sync. The metabase-data-app-* skills build it. This skill answers their questions from what rde already knows, so the user is asked only what rde cannot know, makes sure the content the app reads is in that repository before the app is built, then hands over. Sections 4 to 6 override the data-app skills wherever they differ: the schema scope, the order of commits and pushes, and the confirmation before any sync.
1. The instance
rde status --json: url is the instance (not a secret) and version must be v65+ or a head build. mb auth list --json names the profile whose url matches; use it as $PROFILE. Metabase serves apps only under a license with remote sync and data apps: rde doctor --json, row license. Without one, the user activates it in their own terminal with rde init --only license (or ! rde init --only license in this session); the token never enters the chat. Syncing content needs remote-sync-type set to read-write (mb setting get remote-sync-type --json); switching it is a sync change, confirmed like one (section 6).
2. The repository
contentRepository in rde status --json is the working directory of the remote-sync repository, and the answer to metabase-data-app-setup's Step 1: name it and use it, do not ask. When it is null and the license has remote sync, ask where the repository should live, then run rde init --only git-sync --git-dir <path> --git-remote local (a bare remote inside ~/.rde, no account). A hosted remote needs a git token, so the user runs rde init --only git-sync themselves. A repository rde creates already ignores .env.local, node_modules/, and the rest a data app must not push.
3. The credentials
The data-app skills read DATA_APP_MB_URL and DATA_APP_MB_API_KEY from .env.local at the repository root and forbid the key in the conversation. rde stores the API key mb uses, and rde credentials --api-key prints it alone. When the setup skill reaches its credentials step, or its check prints MISSING, fill the file with this command instead of asking the user, <url> from step 1 and <repo> from step 2. It prints only creds written, keeps the file's other lines, and makes sure .env.local is ignored: