123faf8bbf
Introduces the vault-tools monorepo: two Go CLIs that share a config file (~/.config/vault) and token cache (~/.cache/vault) for working with multiple Vault instances (contexts). - add shared/ library: config parsing (vctl.yaml/config.yaml, per-context overrides, slash contexts), token cache (0600/0700, atomic writes, path- traversal guards), and a small hand-rolled Vault HTTP client (login/renew) - add vctl: login/renew (single or --all), list, --method/--user overrides, no-echo password/token prompts, dynamic context completion - add vctx: resolve a context, set VAULT_ADDR/VAULT_TOKEN/VAULT_NAMESPACE and exec the vault CLI, passing remaining args through untouched - add unit tests across shared/, vctl and vctx command layers (config resolution, cache paths, vault client, --all iteration + error aggregation, vctx arg pass-through and env construction via fakeable exec/prompt seams) - add Makefile (build/test/completions/rpm, patch|minor|major version bumps), nfpm RPM packaging bundling bash/zsh/fish completions for both binaries - add Woodpecker pipelines: build/test/pre-commit on PRs, and a tag release that cross-compiles, builds+uploads the RPM to artifactapi, and cuts a Gitea release (serviceAccountName default, k8s resources on every step) - add README, per-command docs (docs/vctl.md, docs/vctx.md), AGENTS.md and an example config Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
76 lines
2.4 KiB
Makefile
76 lines
2.4 KiB
Makefile
# vault-tools: a Go monorepo of Vault token CLIs (vctl + vctx) sharing shared/.
|
|
# Each tool is a separate main package under its own subfolder.
|
|
BINARIES := vctl vctx
|
|
DIST := dist
|
|
VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo dev)
|
|
GOFLAGS := -ldflags="-s -w -X main.version=$(VERSION)"
|
|
OS ?= $(shell go env GOOS)
|
|
ARCH ?= $(shell go env GOARCH)
|
|
|
|
.PHONY: all build test lint fmt clean install completions rpm rpm-package patch minor major _tag
|
|
|
|
all: build
|
|
|
|
# Build every binary into dist/ so the nfpm packaging step
|
|
# (scripts/build-rpm.sh) can find them. Each tool is its own main package under
|
|
# ./<tool>, so they are built individually with their own -o.
|
|
build:
|
|
@for b in $(BINARIES); do \
|
|
echo "building $$b"; \
|
|
CGO_ENABLED=0 GOOS=$(OS) GOARCH=$(ARCH) go build $(GOFLAGS) -o $(DIST)/$$b ./$$b || exit 1; \
|
|
done
|
|
|
|
test:
|
|
go test -v -race ./...
|
|
|
|
lint:
|
|
golangci-lint run ./...
|
|
|
|
fmt:
|
|
gofmt -w .
|
|
|
|
clean:
|
|
rm -rf $(DIST) $(BINARIES)
|
|
|
|
install:
|
|
go install $(GOFLAGS) ./...
|
|
|
|
# Generate bash/zsh/fish completions for every binary into dist/completions.
|
|
completions: build
|
|
@mkdir -p $(DIST)/completions
|
|
@for b in $(BINARIES); do \
|
|
$(DIST)/$$b completion bash > $(DIST)/completions/$$b.bash; \
|
|
$(DIST)/$$b completion zsh > $(DIST)/completions/_$$b; \
|
|
$(DIST)/$$b completion fish > $(DIST)/completions/$$b.fish; \
|
|
done
|
|
|
|
# Build the binaries then package them (with completions) into an RPM via nfpm.
|
|
rpm: build rpm-package
|
|
|
|
# Package already-built binaries into an RPM (used by CI after the build step).
|
|
rpm-package:
|
|
./scripts/build-rpm.sh $(VERSION)
|
|
|
|
# Bump helpers — read the latest semver tag and create the next one.
|
|
# If no tag exists yet, start from v0.0.0.
|
|
_LATEST := $(shell git tag --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$$' | head -1)
|
|
_BASE := $(if $(_LATEST),$(_LATEST),v0.0.0)
|
|
_MAJ := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f1)
|
|
_MIN := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f2)
|
|
_PAT := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f3)
|
|
|
|
patch:
|
|
@NEW=v$(_MAJ).$(_MIN).$(shell expr $(_PAT) + 1); \
|
|
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
|
|
|
|
minor:
|
|
@NEW=v$(_MAJ).$(shell expr $(_MIN) + 1).0; \
|
|
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
|
|
|
|
major:
|
|
@NEW=v$(shell expr $(_MAJ) + 1).0.0; \
|
|
git tag $$NEW && echo "Tagged $$NEW" && $(MAKE) _tag TAG=$$NEW
|
|
|
|
_tag:
|
|
git push origin $(TAG)
|