Skip to main content

Module cloud_command

Module cloud_command 

Source
Expand description

Running the commands other tools provide for credentials: aws, a profile’s credential_process, gcloud, and az and PowerShell for Azure.

Asking a cloud’s own CLI is how SSO, assume-role and MFA work without datui reimplementing any of them. Every call here blocks, so it only ever runs on a worker, never on the thread that draws. Arguments are passed as a list, with no shell in between, and every call has a deadline.

Structs§

Expiring
Secrets by key, each kept until five minutes before it expires, so a credential command, slow to start, runs once per expiry rather than once per request. One with no known expiry is kept for the session.

Enums§

CommandError
Why a command did not produce its output.

Constants§

CREDENTIAL_TIMEOUT
How long a credential command may take. An SSO refresh is a network round trip; anything slower than this is waiting on something that is not coming.

Functions§

find_program
Where program would be run from: itself when it names a path, else the first match on path. On Windows each PATHEXT extension is tried too, which is how gcloud finds gcloud.cmd.
paged
Every item of a paged API, fetch handed each page’s token. At most max_pages pages: an API that keeps handing back a token would be a loop on a worker nobody is watching.
run
Run program with args and return what it printed.
secret
The secret a secret_command prints, run once per session: split into arguments with no shell, through env’s runner, its output trimmed and kept in memory. An error never includes what the command printed on its standard output.
split_command_line
Split a command line into a program and its arguments, the way a POSIX shell does for words and quotes, without doing anything else a shell does: no variables, no globs, no pipes. Enough for credential_process = "op read ..." --flag 'a b'.

Type Aliases§

Runner
Runs one command: the real run with a deadline, or a stand-in in tests.