Repository navigation
refactor: adopt cinc-api data bag, policy and cookbook helpers - #264
Merged
Merged
Conversation
Point both modules at a local cinc-api checkout that carries the data
bag secret, encrypted item, PushResult and cookbook version listing
APIs this branch adopts. Swap the replace for a version bump once
cinc-api tags a release with them.
PushRevision now says which artifacts it uploaded and which the server
already held, so the separate artifact listing that counted them
(ArtifactsToUpload) is gone, and push --format json lists both. It
also uploads each cookbook under its lock name itself, so policy push
and push-archive no longer rename the cookbooks they load.
Export and push-archive name bundle directories with
CookbookLock.DottedIdentifier, and git fetches check out
CookbookLock.GitRef, which also honors a lock pinned by "ref" or "tag"
instead of failing for want of a revision or branch. The subdirectory
comes from GitSubdir ("rel" only): a lock carrying "path" is a path
source and never reaches the git fetch.
Signed-off-by: Tim Smith <tsmith84@proton.me>
Secret files are read with cinc.LoadDataBagSecret, which follows Chef's load_secret exactly, so a file that isn't UTF-8 (which knife and chef-client can't read either) is now refused. The secret commands use GetDecrypted, CreateEncrypted and UpdateEncrypted, resolve the profile once instead of twice, and explain an item that is already encrypted rather than encrypting its ciphertext again. Item checks use DataBagItem.Validate, databag show and databag item list share one RunE, and the thirteen copies of "read --file and unmarshal it" across the nouns are one generic readJSONFile. A --file whose id names a different item used to be stored under the command-line id without a word. For an edit that overwrote one item with content meant for another, so it is now refused, naming both ids, before anything is sent. The editor enforces the same rule on save, where the user can fix it. Signed-off-by: Tim Smith <tsmith84@proton.me>
cookbook download fetched the version manifest to learn the concrete version, then Download fetched it again. It now hands the first manifest to DownloadFiles. explore counted and listed versions from a bare cookbook list, which erchef answers with only the latest version, and sorted them as strings, so 1.9.0 ranked above 1.10.0. It now asks for every version and uses cinc-api's newest-first ordering. Signed-off-by: Tim Smith <tsmith84@proton.me>
…ons in show
policy diff read each group and then the revision it pins; it now asks
the group for the policy's active revision directly, one request per
side, and only looks at the group to explain a 404. Its example diffed
two version numbers as if they were group names; it now shows the
group form and the --revisions form.
clean-cookbooks fetched every policy again for the revision ids the
policy list had already returned.
policy show printed the server's {"revisions": {id: {}}} shape, whose
values are always empty. The human form now lists the revision ids;
--format json is unchanged.
Signed-off-by: Tim Smith <tsmith84@proton.me>
Signed-off-by: Tim Smith <tsmith84@proton.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Third of four cinc-api v0.15.0 adoption PRs.
Data bags
readSecretFileis a thin wrapper overcinc.LoadDataBagSecret(Chefload_secretsemantics), keeping the conversational message for an empty file.GetDecrypted,CreateEncryptedandUpdateEncrypted, and resolve the profile once instead of twice. An already-encrypted--filegets a friendly refusal where it used to be encrypted a second time.validateDataBagItemgives way toDataBagItem.Validate().databag showanddatabag item listshare one RunE.--filewhoseiddiffers from the item named on the command line is refused before anything is sent (the editor checks on save too). Before, the argument silently overwrote the id, soeditcould write one item's content over another.--filereadingreadJSONFile[T], with conversational errors ("we couldn't read X", "X isn't valid JSON").Policies
cli/policyfile/push.gois deleted.policy pushreports fromPushResult, so it no longer lists the server's artifacts a second time.--format jsonaddsuploadedandalready_present.cb.Name = namerenaming workaround in push and push-archive is gone, since the library uploads under the lock name.CookbookLock.DottedIdentifier,GitRef,GitSubdirandcinc.LatestVersion. Git locks pinned byrefortagnow fetch.policy diffbetween groups is 2 requests instead of 4 (GetPolicy).clean-cookbooksno longer callsPolicies.Getper policy.policy showlists sorted revision IDs in human format. JSON output is unchanged.policy diffexample and three misplaced doc comments are fixed.Cookbooks
cookbook downloaddoes one manifest GET instead of two (Get, thenDownloadFiles).GetVersions(name, "all"), so version counts and ordering are right on erchef.Test plan
go test ./apps/... ./cli/...(including the Ruby-backed policyfile packages),go vet ./...,gofmt,make docscleanmake test-integration(cinc-server-ng): pass.databags/item-id-from-argumentbecomesdatabags/item-id-mismatch.