61bb464e32
Interactive agents are classifier-blocked from plumbing credentials through a shell, so seeding an Authentik outpost token into Vault KV needs to happen inside one binary invocation that never exposes the secret. - Add cmd/agentvault, a fourth CLI sharing the agentpr Vault AppRole login (role_id only, VAULT_ADDR/AGENT_APPROLE_ROLE_ID defaults unchanged). - Add `agentvault seed-outpost`: read the Authentik API token from kv/service/authentik/agent-api-token (field `token`, falling back to `api_token`), exact-match the outpost by name via the instances search, fetch its key from /api/v3/core/tokens/<identifier>/view_key/ and write it to --dest-path under --dest-key. - Print only the outpost name, token identifier, dest path and new KV version; keep secret material out of results, errors and logs. - Distinguish the failure stages (login, KV read denied, outpost missing, view_key, KV write denied) with ErrVaultDenied/ErrVaultNotFound/ ErrOutpostNotFound sentinels and actionable messages. - Add internal/agent vaultkv.go (AppRole-authenticated KV-v2 client) and authentik.go (outpost search + view_key) for reuse by future flows. - Cover the happy path, idempotent re-run, field fallback and every failure mode with httptest servers, including a leak check on error strings. - Wire agentvault into the Makefile, build-rpm.sh, nfpm contents, release cross-builds/assets, README and AGENTS.md.
80 lines
2.5 KiB
Makefile
80 lines
2.5 KiB
Makefile
# All shipped binaries and the package path each is built from. Both tools live
|
|
# under cmd/; the module root ships no binary of its own.
|
|
BINARIES := agentpr watchpr agentws agentvault
|
|
DIST := dist
|
|
VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo dev)
|
|
GOFLAGS := -ldflags="-s -w -X main.version=$(VERSION)"
|
|
OS ?= $(shell go env GOOS)
|
|
ARCH ?= $(shell go env GOARCH)
|
|
|
|
# The Go package path for a binary. Both tools live under cmd/. Usable inside a
|
|
# shell for-loop over $(BINARIES).
|
|
pkgpath = ./cmd/$$b
|
|
|
|
.PHONY: all build test lint fmt clean install completions rpm rpm-package patch minor major _tag
|
|
|
|
all: build
|
|
|
|
# Build every binary into dist/ so the nfpm packaging step
|
|
# (scripts/build-rpm.sh) can find them. Each main package needs its own -o, so
|
|
# they are built individually rather than with a single ./... invocation.
|
|
build:
|
|
@for b in $(BINARIES); do \
|
|
echo "building $$b"; \
|
|
CGO_ENABLED=0 GOOS=$(OS) GOARCH=$(ARCH) go build $(GOFLAGS) -o $(DIST)/$$b $(pkgpath) || exit 1; \
|
|
done
|
|
|
|
test:
|
|
go test -v -race ./...
|
|
|
|
lint:
|
|
golangci-lint run ./...
|
|
|
|
fmt:
|
|
gofmt -w .
|
|
|
|
clean:
|
|
rm -rf $(DIST) $(BINARIES)
|
|
|
|
install:
|
|
go install $(GOFLAGS) ./...
|
|
|
|
# Generate bash/zsh/fish completions for every binary into dist/completions.
|
|
completions: build
|
|
@mkdir -p $(DIST)/completions
|
|
@for b in $(BINARIES); do \
|
|
$(DIST)/$$b completion bash > $(DIST)/completions/$$b.bash; \
|
|
$(DIST)/$$b completion zsh > $(DIST)/completions/_$$b; \
|
|
$(DIST)/$$b completion fish > $(DIST)/completions/$$b.fish; \
|
|
done
|
|
|
|
# Build the binaries then package them (with completions) into an RPM via nfpm.
|
|
rpm: build rpm-package
|
|
|
|
# Package already-built binaries into an RPM (used by CI after the build step).
|
|
rpm-package:
|
|
./scripts/build-rpm.sh $(VERSION)
|
|
|
|
# Bump helpers — reads the latest semver tag and creates the next one.
|
|
# If no tag exists yet, starts from v0.0.0.
|
|
_LATEST := $(shell git tag --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$$' | head -1)
|
|
_BASE := $(if $(_LATEST),$(_LATEST),v0.0.0)
|
|
_MAJ := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f1)
|
|
_MIN := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f2)
|
|
_PAT := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f3)
|
|
|
|
patch:
|
|
@NEW=v$(_MAJ).$(_MIN).$(shell expr $(_PAT) + 1); \
|
|
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
|
|
|
|
minor:
|
|
@NEW=v$(_MAJ).$(shell expr $(_MIN) + 1).0; \
|
|
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
|
|
|
|
major:
|
|
@NEW=v$(shell expr $(_MAJ) + 1).0.0; \
|
|
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
|
|
|
|
_tag:
|
|
git push origin $(TAG)
|