drpcli delegations¶
drpcli delegations¶
Manage DRP delegations (grants letting a trigger use your parameters)
Synopsis¶
Delegations let an unattended trigger use a bounded set of your parameters on your behalf.
A trigger normally runs with no user authority at all, so it cannot read parameters stored on a user. A delegation is how you grant it that access deliberately and narrowly:
- User - whose parameters are being granted. You may only create a delegation naming yourself, and only while logged in - a token an administrator minted for you will not do.
- Trigger - the single trigger authorized to read them. No other trigger is covered, even for the same user.
- Params - the parameter globs in scope, such as
email-triage/*. A glob made up entirely of wildcard characters (*,**,?*, ...) is refused. - ExpiresAt - optional. When unset, the delegation does not expire.
A delegation stores no password or token. It is a permission record, so deleting it stops access immediately, including for a run already in flight. Anyone able to manage delegations may delete yours; only you can create one.
When a trigger fires, one work order is created per delegation naming it, so each grant produces its own run against its own user's parameters.
Common operations:
drpcli delegations list- list delegationsdrpcli delegations show <name>- display one delegationdrpcli delegations create <json>- grant accessdrpcli delegations destroy <name>- revoke access
Examples¶
# List all delegations
drpcli delegations list
# Show a specific delegation
drpcli delegations show greg-email-triage
# Grant the email-triage cron trigger access to your Gmail parameters
drpcli delegations create '{"Name":"greg-email-triage","User":"greg","Trigger":"email-triage-cron","Params":["email-triage/*"]}'
# Grant access from a JSON file
drpcli delegations create - < delegation.json
# Narrow an existing grant to two specific parameters
drpcli delegations update greg-email-triage '{"Params":["email-triage/gmail-client-id","email-triage/gmail-refresh-token"]}'
# Revoke access
drpcli delegations destroy greg-email-triage
Options¶
Options inherited from parent commands¶
--ca-cert string CA certificate used to verify the server certs (with the system set)
-c, --catalog string The catalog file to use to get product information (default "https://repo.rackn.io")
--catalog-path string The path to where the catalog file exists on the drp server. By default and historically this has been /files/rebar-catalog. For example, if no catalog urls are provided, the complete path will be https://drp-ip:8090/files/rebar-catalog (default "/files/rebar-catalog")
-S, --catalog-source string A location from which catalog items can be downloaded. For example, in airgapped mode it would be the local catalog
--client-cert string Client certificate to use for communicating to the server - replaces RS_KEY, RS_TOKEN, RS_USERNAME, RS_PASSWORD
--client-key string Client key to use for communicating to the server - replaces RS_KEY, RS_TOKEN, RS_USERNAME, RS_PASSWORD
-C, --colors string The colors for JSON and Table/Text colorization. 8 values in the for 0=val,val;1=val,val2... (default "0=32;1=33;2=36;3=90;4=34,1;5=35;6=95;7=32;8=92")
-d, --debug Whether the CLI should run in debug mode
-D, --download-proxy string HTTP Proxy to use for downloading catalog and content
-E, --endpoint string The Digital Rebar Provision API endpoint to talk to (default "https://127.0.0.1:8092")
-X, --exit-early Cause drpcli to exit if a command results in an object that has errors
--fetch-catalogs all Determines which catalog urls to use to fetch the catalog. If set to all, all the catalog urls defined with catalog_url and catalog_urls as well as the default catalog will be used. If set to server, only the catalog urls defined on the server will be used. If set to cli, then the specific url specified with the -c flag will be used. It defaults to `all`. Allowed values `all, `server`, `cli`. (default "all")
-f, --force When needed, attempt to force the operation - used on some update/patch calls
--force-new-session Should the client always create a new session
-F, --format string The serialization we expect for output. Can be "json" or "yaml" or "text" or "table" (default "json")
--http-request-retry-count int Specifies the number of retries for downloads in case of failure
--http-request-retry-delay-max int Specifies the maximum delay (in seconds) between HTTP/HTTPS retry attempts (default 60)
--ignore-unix-proxy Should the client ignore unix proxies
-N, --no-color Whether the CLI should output colorized strings
-H, --no-header Should header be shown in "text" or "table" mode
-x, --no-token Do not use token auth or token cache
-P, --password string password of the Digital Rebar Provision user (default "r0cketsk8ts")
-p, --platform string Platform to filter details by. Defaults to current system. Format: arch/os
-J, --print-fields string The fields of the object to display in "text" or "table" mode. Comma separated
-r, --ref string A reference object for update commands that can be a file name, yaml, or json blob
--server-verify Should the client verify the server cert
-G, --show-global-help-flags Show global flags in help message
-T, --token string token of the Digital Rebar Provision access
-t, --trace string The log level API requests should be logged at on the server side
-Z, --trace-token string A token that individual traced requests should report in the server logs
-j, --truncate-length int Truncate columns at this length (default 40)
-u, --url-proxy string URL Proxy for passing actions through another DRP
-U, --username string Name of the Digital Rebar Provision user to talk to (default "rocketskates")
SEE ALSO¶
- drpcli - A CLI application for interacting with the DigitalRebar Provision API
- drpcli delegations await - Wait for a delegation's field to become a value within a number of seconds
- drpcli delegations count - Count all delegations
- drpcli delegations create - Create a new delegation with the passed-in JSON or string key
- drpcli delegations destroy - Destroy delegation by id
- drpcli delegations etag - Get the etag for a delegations by id
- drpcli delegations exists - See if a delegations exists by id
- drpcli delegations fieldinfo - Return the documentation for all the fields or the provided field
- drpcli delegations generate - Generate an object of delegations type in the content directory
- drpcli delegations indexes - Get indexes for delegations
- drpcli delegations list - List all delegations
- drpcli delegations meta - Get all metadata key/value pairs for a delegation
- drpcli delegations patch - Patch delegation by ID using the passed-in JSON Patch
- drpcli delegations show - Show a single delegations by id
- drpcli delegations update - Unsafely update delegation by id with the passed-in JSON
- drpcli delegations wait - Wait for a delegation's field to become a value within a number of seconds