Expand description
Command-line surface for cairn (§F9 + §5.3).
Sub-modules land incrementally:
session— on-disk session file (§5.3 storage format + 0600 + owner checks + atomic write-rename).
Future sessions add:
pds— client forcom.atproto.server.{createSession, refreshSession, deleteSession, getServiceAuth}.login/logout— session lifecycle.report—cairn report create.output— human vs--jsonformatting.
Modules§
- audit
cairn audit list(#6) andcairn audit show <id>(#26) — admin-side audit log queries.- auth
- Shared CLI auth helpers (#28).
- error
- Unified error taxonomy for the CLI handlers + the exit-code contract (criterion G / §F9’s “specific exit codes per error class”).
- login
cairn login— §5.3 interactive auth, no password flag.- logout
cairn logout— revoke at PDS, then remove local file.- moderator
cairn moderator {add, remove, list}— orchestrators (#24).- operator_
login cairn operator-login— interactive app-password exchange for the operator’s PDS account (§F1).- operator_
session - Operator PDS session file (§F1).
- output
- Shared CLI output helpers (#28).
- pds
- Client for the four PDS endpoints the CLI depends on (§5.3).
- publish_
service_ record cairn publish-service-record— emit theapp.bsky.labeler.servicerecord to the operator’s PDS (§F1).- report
cairn report {create, list, view, resolve, flag, unflag}— thin wrappers over the moderation + admin XRPC endpoints Cairn exposes (#7 + #16).- retention
cairn retention sweep— admin-side trigger for the §F4 retention sweep (#12).- session
- CLI session file — §5.3.
- trust_
chain cairn trust-chain show— admin-side trust-chain transparency query (#37).- unpublish_
service_ record cairn unpublish-service-record(#34) — inverse ofcrate::cli::publish_service_record. Removes the publishedapp.bsky.labeler.servicerecord from the operator’s PDS and clears the locallabeler_configstate that tracks it.