Skip to content

refactor: adopt cinc-api data bag, policy and cookbook helpers - #264

Merged
tas50 merged 5 commits into
mainfrom
refactor/adopt-cinc-api-databags-policies
Sep 24, 2026
Merged

tas50 merged 5 commits into
mainfrom
refactor/adopt-cinc-api-databags-policies

Conversation

@tas50

@tas50 tas50 commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Third of four cinc-api v0.15.0 adoption PRs.

Data bags

  • readSecretFile is a thin wrapper over cinc.LoadDataBagSecret (Chef load_secret semantics), keeping the conversational message for an empty file.
  • The secret commands use GetDecrypted, CreateEncrypted and UpdateEncrypted, and resolve the profile once instead of twice. An already-encrypted --file gets a friendly refusal where it used to be encrypted a second time.
  • validateDataBagItem gives way to DataBagItem.Validate(). databag show and databag item list share one RunE.
  • Behavior change: a --file whose id differs from the item named on the command line is refused before anything is sent (the editor checks on save too). Before, the argument silently overwrote the id, so edit could write one item's content over another.

--file reading

  • 13 copies of "read the file, unmarshal it, wrap the error" across every noun are now one generic readJSONFile[T], with conversational errors ("we couldn't read X", "X isn't valid JSON").

Policies

  • cli/policyfile/push.go is deleted. policy push reports from PushResult, so it no longer lists the server's artifacts a second time. --format json adds uploaded and already_present.
  • The cb.Name = name renaming workaround in push and push-archive is gone, since the library uploads under the lock name.
  • Uses CookbookLock.DottedIdentifier, GitRef, GitSubdir and cinc.LatestVersion. Git locks pinned by ref or tag now fetch.
  • policy diff between groups is 2 requests instead of 4 (GetPolicy). clean-cookbooks no longer calls Policies.Get per policy.
  • policy show lists sorted revision IDs in human format. JSON output is unchanged.
  • The policy diff example and three misplaced doc comments are fixed.

Cookbooks

  • cookbook download does one manifest GET instead of two (Get, then DownloadFiles).
  • Explore's version drilldown and summary use GetVersions(name, "all"), so version counts and ordering are right on erchef.

Test plan

  • go test ./apps/... ./cli/... (including the Ruby-backed policyfile packages), go vet ./..., gofmt, make docs clean
  • make test-integration (cinc-server-ng): pass. databags/item-id-from-argument becomes databags/item-id-mismatch.

Point both modules at a local cinc-api checkout that carries the data
bag secret, encrypted item, PushResult and cookbook version listing
APIs this branch adopts. Swap the replace for a version bump once
cinc-api tags a release with them.

PushRevision now says which artifacts it uploaded and which the server
already held, so the separate artifact listing that counted them
(ArtifactsToUpload) is gone, and push --format json lists both. It
also uploads each cookbook under its lock name itself, so policy push
and push-archive no longer rename the cookbooks they load.

Export and push-archive name bundle directories with
CookbookLock.DottedIdentifier, and git fetches check out
CookbookLock.GitRef, which also honors a lock pinned by "ref" or "tag"
instead of failing for want of a revision or branch. The subdirectory
comes from GitSubdir ("rel" only): a lock carrying "path" is a path
source and never reaches the git fetch.

Signed-off-by: Tim Smith <tsmith84@proton.me>
Secret files are read with cinc.LoadDataBagSecret, which follows Chef's
load_secret exactly, so a file that isn't UTF-8 (which knife and
chef-client can't read either) is now refused. The secret commands use
GetDecrypted, CreateEncrypted and UpdateEncrypted, resolve the profile
once instead of twice, and explain an item that is already encrypted
rather than encrypting its ciphertext again. Item checks use
DataBagItem.Validate, databag show and databag item list share one
RunE, and the thirteen copies of "read --file and unmarshal it" across
the nouns are one generic readJSONFile.

A --file whose id names a different item used to be stored under the
command-line id without a word. For an edit that overwrote one item
with content meant for another, so it is now refused, naming both ids,
before anything is sent. The editor enforces the same rule on save,
where the user can fix it.

Signed-off-by: Tim Smith <tsmith84@proton.me>
cookbook download fetched the version manifest to learn the concrete
version, then Download fetched it again. It now hands the first
manifest to DownloadFiles.

explore counted and listed versions from a bare cookbook list, which
erchef answers with only the latest version, and sorted them as
strings, so 1.9.0 ranked above 1.10.0. It now asks for every version
and uses cinc-api's newest-first ordering.

Signed-off-by: Tim Smith <tsmith84@proton.me>
…ons in show

policy diff read each group and then the revision it pins; it now asks
the group for the policy's active revision directly, one request per
side, and only looks at the group to explain a 404. Its example diffed
two version numbers as if they were group names; it now shows the
group form and the --revisions form.

clean-cookbooks fetched every policy again for the revision ids the
policy list had already returned.

policy show printed the server's {"revisions": {id: {}}} shape, whose
values are always empty. The human form now lists the revision ids;
--format json is unchanged.

Signed-off-by: Tim Smith <tsmith84@proton.me>
Signed-off-by: Tim Smith <tsmith84@proton.me>
@tas50
tas50 enabled auto-merge (squash) September 24, 2026 09:56
@tas50
tas50 merged commit d716c3c into main Sep 24, 2026
6 checks passed
@tas50
tas50 deleted the refactor/adopt-cinc-api-databags-policies branch September 24, 2026 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant