child_config
The wire contract between a background DAG child and the pod that spawned it.
A background DAG run executes in a subprocess Prefect launches from a served deployment. It inherits nothing from the pod and is handed only JSON deployment parameters, which Prefect persists in its database in clear — so neither a credential nor the EHR configuration (which carries a private key) can travel that way.
Instead the pod control server serves both, over loopback, to a caller holding the nonce the pod minted for that lineage. This module is the shape of that exchange: both ends import it, so the request the child builds and the response the pod writes cannot drift apart.
The run's datasource configuration travels the same way, and for the same reason: its arguments can carry credentials (a database password, a connection string).
The EHR configuration is carried as its desert dump plus the name of the
concrete class, because EHRConfig is a union and the dump alone does not say
which member it is. The live handles hanging off a SMARTBackendEHRConfig
(smart_backend_auth, smart_backend_refresh_handler) are init=False and so
are excluded from the dump; the child rebuilds its own, exactly as the v8
worker subprocess does.