Expand description
Command-line surface for cairn (§F9 + §5.3).
Sub-modules land incrementally:
session— on-disk session file (§5.3 storage format + 0600 + owner checks + atomic write-rename).
Future sessions add:
pds— client forcom.atproto.server.{createSession, refreshSession, deleteSession, getServiceAuth}.login/logout— session lifecycle.report—cairn report create.output— human vs--jsonformatting.
Modules§
- audit
cairn audit list(#6) andcairn audit show <id>(#26) — admin-side audit log queries.- audit_
rebuild cairn audit-rebuild(#40, v1.3) — one-shot operator command for backfillingprev_hash+row_hashon pre-v1.3 audit_log rows.- audit_
verify cairn audit verify(#41 / v1.3; #88 / v1.7 unified-chain extension) — operator command for verifying the audit hash chain.- auth
- Shared CLI auth helpers (#28).
- error
- Unified error taxonomy for the CLI handlers + the exit-code contract (criterion G / §F9’s “specific exit codes per error class”).
- login
cairn login— §5.3 interactive auth, no password flag.- logout
cairn logout— revoke at PDS, then remove local file.- moderator
cairn moderator {add, remove, list}— orchestrators (#24).- moderator_
action cairn moderator {action, warn, note, revoke}(#51) — HTTP-routed moderator-tier CLIs that hittools.cairn.admin.recordActionandtools.cairn.admin.revokeAction.- moderator_
events cairn moderator events(#99, Phase E) — operator-tier audit-events view.- moderator_
pending cairn moderator pending {list, view, confirm, dismiss}(#78) — HTTP-routed moderator-tier CLIs that wrap thetools.cairn.admin.{listPendingActions, getPendingAction, confirmPendingAction, dismissPendingAction}admin XRPC endpoints from #74 / #75 / #77.- operator_
login cairn operator-login— interactive app-password exchange for the operator’s PDS account (§F1).- operator_
session - Operator PDS session file (§F1).
- output
- Shared CLI output helpers (#28).
- pds
- Client for the four PDS endpoints the CLI depends on (§5.3).
- pds_
admin cairn pds-admin {takedown, suspend, restore}(#99, Phase E) — manual escape hatch for the PDS-admin bridge (#87).- publish_
service_ record cairn publish-service-record— emit theapp.bsky.labeler.servicerecord to the operator’s PDS (§F1).- report
cairn report {create, list, view, resolve, flag, unflag}— thin wrappers over the moderation + admin XRPC endpoints Cairn exposes (#7 + #16).- retention
cairn retention sweep— admin-side trigger for the §F4 retention sweep (#12).- session
- CLI session file — §5.3.
- trust_
chain cairn trust-chain show— admin-side trust-chain transparency query (#37).- unpublish_
service_ record cairn unpublish-service-record(#34) — inverse ofcrate::cli::publish_service_record. Removes the publishedapp.bsky.labeler.servicerecord from the operator’s PDS and clears the locallabeler_configstate that tracks it.