Makes the goldmane_edges east-west trail (ADR-0014) reachable during incident investigations without remembering the DB/creds/SQL. New top-level verb: homelab edges --ns <ns> edges touching <ns> (either direction) homelab edges --src/--dst <ns> directional egress / ingress peers homelab edges --peers-of <ns> distinct peer namespaces of <ns> homelab edges --new-since 24h first seen since a duration or date (YYYY-MM-DD) homelab edges --denied only action='deny' (blocked / lateral movement) homelab edges --json --limit N machine-readable / row cap (default 200) Filters render to a single read-only SELECT against the `edge` table, run via the dbaas CNPG primary pod (same exec path as `k8s db`). Namespace values are validated to the k8s name charset (injection guard) before they reach SQL. TDD: edges_test.go covers flag parsing, query building (each filter, AND combination, peers-of shape, JSON wrapper), the new-since duration/date parser, and namespace-validation / injection rejection. Smoke-tested live: --peers-of, --new-since 24h, --denied, and --json all return correct rows. Docs: runbook query section now leads with the CLI; cli/README gains a v0.9 section. VERSION v0.8.2 -> v0.9.0. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
99 lines
2.6 KiB
Go
99 lines
2.6 KiB
Go
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"strings"
|
|
)
|
|
|
|
// version is stamped at build time via -ldflags "-X main.version=vX.Y.Z".
|
|
var version = "dev"
|
|
|
|
// buildRegistry returns every homelab verb. New verb-groups append here.
|
|
func buildRegistry() []Command {
|
|
var reg []Command
|
|
reg = append(reg, claimCommands()...)
|
|
reg = append(reg, tfCommands()...)
|
|
reg = append(reg, workCommands()...)
|
|
reg = append(reg, k8sCommands()...)
|
|
reg = append(reg, memoryCommands()...)
|
|
reg = append(reg, ciCommands()...)
|
|
reg = append(reg, deployCommands()...)
|
|
reg = append(reg, netCommands()...)
|
|
reg = append(reg, obsCommands()...)
|
|
reg = append(reg, edgesCommands()...)
|
|
reg = append(reg, usageCommands()...)
|
|
reg = append(reg, haCommands()...)
|
|
reg = append(reg, browserCommands()...)
|
|
reg = append(reg, vaultCommands()...)
|
|
return reg
|
|
}
|
|
|
|
// dispatchTop handles the homelab verb surface. handled=false means the args are
|
|
// not a homelab verb, so main() falls back to the legacy -use-case path.
|
|
func dispatchTop(args []string) (handled bool, err error) {
|
|
if len(args) == 0 {
|
|
fmt.Print(usage())
|
|
return true, nil
|
|
}
|
|
switch args[0] {
|
|
case "help", "-h", "--help":
|
|
fmt.Print(usage())
|
|
return true, nil
|
|
case "version", "--version":
|
|
fmt.Println("homelab " + version)
|
|
return true, nil
|
|
case "manifest":
|
|
reg := buildRegistry()
|
|
if containsArg(args[1:], "--json") {
|
|
out, err := manifestJSON(reg)
|
|
if err != nil {
|
|
return true, err
|
|
}
|
|
fmt.Println(out)
|
|
return true, nil
|
|
}
|
|
fmt.Print(manifestText(reg))
|
|
return true, nil
|
|
}
|
|
if strings.HasPrefix(args[0], "-") {
|
|
return false, nil
|
|
}
|
|
reg := buildRegistry()
|
|
if !isCommandGroup(reg, args[0]) {
|
|
return false, nil
|
|
}
|
|
return true, dispatch(reg, args)
|
|
}
|
|
|
|
func isCommandGroup(reg []Command, group string) bool {
|
|
for _, c := range reg {
|
|
if len(c.Path) > 0 && c.Path[0] == group {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func containsArg(args []string, want string) bool {
|
|
for _, a := range args {
|
|
if a == want {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func usage() string {
|
|
var b strings.Builder
|
|
fmt.Fprintf(&b, "homelab %s — unified homelab operations CLI\n\n", version)
|
|
b.WriteString("Usage:\n homelab <command> [args]\n\nCommands:\n")
|
|
for _, line := range strings.Split(strings.TrimRight(manifestText(buildRegistry()), "\n"), "\n") {
|
|
if line != "" {
|
|
b.WriteString(" " + line + "\n")
|
|
}
|
|
}
|
|
b.WriteString("\n manifest [--json] list all commands (machine-readable with --json)\n")
|
|
b.WriteString(" version print version\n")
|
|
b.WriteString("\nLegacy webhook use-cases remain available via -use-case=<name>.\n")
|
|
return b.String()
|
|
}
|