Expand description
Running the commands other tools provide for credentials: aws, a profile’s
credential_process, gcloud, and az and PowerShell for Azure.
Asking a cloud’s own CLI is how SSO, assume-role and MFA work without datui reimplementing any of them. Every call here blocks, so it only ever runs on a worker, never on the thread that draws. Arguments are passed as a list, with no shell in between, and every call has a deadline.
Structs§
- Expiring
- Secrets by key, each kept until five minutes before it expires, so a credential command, slow to start, runs once per expiry rather than once per request. One with no known expiry is kept for the session.
Enums§
- Command
Error - Why a command did not produce its output.
Constants§
- CREDENTIAL_
TIMEOUT - How long a credential command may take. An SSO refresh is a network round trip; anything slower than this is waiting on something that is not coming.
Functions§
- find_
program - Where
programwould be run from: itself when it names a path, else the first match onpath. On Windows eachPATHEXTextension is tried too, which is howgcloudfindsgcloud.cmd. - paged
- Every item of a paged API,
fetchhanded each page’s token. At mostmax_pagespages: an API that keeps handing back a token would be a loop on a worker nobody is watching. - run
- Run
programwithargsand return what it printed. - secret
- The secret a
secret_commandprints, run once per session: split into arguments with no shell, throughenv’s runner, its output trimmed and kept in memory. An error never includes what the command printed on its standard output. - split_
command_ line - Split a command line into a program and its arguments, the way a POSIX shell does
for words and quotes, without doing anything else a shell does: no variables, no
globs, no pipes. Enough for
credential_process = "op read ..." --flag 'a b'.