use anyhow::{Context, Result};
use crate::config::{Config, GitlabTargetConfig, ResolvedTarget};
use crate::targets::{
check_command, resolve_env_flags, CommandOpts, CommandRunner, DeployMode, DeployTarget,
};
pub struct GitlabTarget<'a> {
pub config: &'a Config,
pub target_config: &'a GitlabTargetConfig,
pub runner: &'a dyn CommandRunner,
}
impl DeployTarget for GitlabTarget<'_> {
fn name(&self) -> &'static str {
"gitlab"
}
fn deploy_mode(&self) -> DeployMode {
DeployMode::Individual
}
fn preflight(&self) -> Result<()> {
check_command(self.runner, "glab").map_err(|_| {
anyhow::anyhow!(
"glab is not installed or not in PATH. Install it from: https://gitlab.com/gitlab-org/cli"
)
})?;
let output = self
.runner
.run("glab", &["auth", "status"], CommandOpts::default())
.context("failed to run glab auth status")?;
if !output.success {
anyhow::bail!("glab is not authenticated. Run: glab auth login");
}
Ok(())
}
fn deploy_secret(&self, key: &str, value: &str, target: &ResolvedTarget) -> Result<()> {
let flag_parts = resolve_env_flags(&self.target_config.env_flags, &target.environment);
let mut args: Vec<&str> = vec!["variable", "set", key, "--scope", &target.environment];
args.extend(flag_parts.iter().map(String::as_str));
self.runner
.run(
"glab",
&args,
CommandOpts {
stdin: Some(value.as_bytes().to_vec()),
..Default::default()
},
)
.with_context(|| format!("failed to run glab variable set for {key}"))?
.check("glab variable set", key)
}
fn delete_secret(&self, key: &str, target: &ResolvedTarget) -> Result<()> {
let flag_parts = resolve_env_flags(&self.target_config.env_flags, &target.environment);
let mut args: Vec<&str> = vec!["variable", "delete", key, "--scope", &target.environment];
args.extend(flag_parts.iter().map(String::as_str));
self.runner
.run("glab", &args, CommandOpts::default())
.with_context(|| format!("failed to run glab variable delete for {key}"))?
.check("glab variable delete", key)
}
}
#[cfg(test)]
mod tests {
use super::*;
use crate::targets::CommandOutput;
use crate::test_support::{ConfigFixture, ErrorCommandRunner, MockCommandRunner};
fn make_config() -> ConfigFixture {
let yaml = r#"
project: x
environments: [dev, prod]
targets:
gitlab:
env_flags:
prod: "--masked"
"#;
ConfigFixture::new(yaml).expect("fixture")
}
fn make_target(env: &str) -> ResolvedTarget {
ResolvedTarget {
service: "gitlab".to_string(),
app: None,
environment: env.to_string(),
}
}
#[test]
fn gitlab_preflight_success() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![
CommandOutput {
success: true,
stdout: b"1.0.0".to_vec(),
stderr: vec![],
},
CommandOutput {
success: true,
stdout: b"Logged in".to_vec(),
stderr: vec![],
},
]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
assert!(target.preflight().is_ok());
let calls = runner.take_calls();
assert_eq!(calls[1].args, vec!["auth", "status"]);
}
#[test]
fn gitlab_preflight_auth_failure() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![
CommandOutput {
success: true,
stdout: b"1.0.0".to_vec(),
stderr: vec![],
},
CommandOutput {
success: false,
stdout: vec![],
stderr: b"not logged in".to_vec(),
},
]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
let err = target.preflight().unwrap_err();
assert!(err.to_string().contains("glab is not authenticated"));
}
#[test]
fn gitlab_preflight_missing_cli() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = ErrorCommandRunner::missing_command();
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
let err = target.preflight().unwrap_err();
assert!(err.to_string().contains("glab is not installed"));
}
#[test]
fn gitlab_deploy_uses_stdin() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![CommandOutput {
success: true,
stdout: vec![],
stderr: vec![],
}]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
target
.deploy_secret("MY_KEY", "secret_val", &make_target("dev"))
.unwrap();
let calls = runner.take_calls();
assert_eq!(calls[0].program, "glab");
assert_eq!(
calls[0].args,
vec!["variable", "set", "MY_KEY", "--scope", "dev"]
);
assert_eq!(calls[0].stdin.as_deref(), Some(b"secret_val".as_slice()));
assert!(!calls[0].args.iter().any(|a| a.contains("secret_val")));
}
#[test]
fn gitlab_deploy_with_env_flags() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![CommandOutput {
success: true,
stdout: vec![],
stderr: vec![],
}]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
target
.deploy_secret("KEY", "val", &make_target("prod"))
.unwrap();
let calls = runner.take_calls();
assert_eq!(
calls[0].args,
vec!["variable", "set", "KEY", "--scope", "prod", "--masked"]
);
assert_eq!(calls[0].stdin.as_deref(), Some(b"val".as_slice()));
}
#[test]
fn gitlab_delete_correct_args() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![CommandOutput {
success: true,
stdout: vec![],
stderr: vec![],
}]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
target.delete_secret("MY_KEY", &make_target("dev")).unwrap();
let calls = runner.take_calls();
assert_eq!(
calls[0].args,
vec!["variable", "delete", "MY_KEY", "--scope", "dev"]
);
}
#[test]
fn gitlab_delete_with_env_flags() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![CommandOutput {
success: true,
stdout: vec![],
stderr: vec![],
}]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
target.delete_secret("KEY", &make_target("prod")).unwrap();
let calls = runner.take_calls();
assert_eq!(
calls[0].args,
vec!["variable", "delete", "KEY", "--scope", "prod", "--masked"]
);
}
#[test]
fn gitlab_delete_failure() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![CommandOutput {
success: false,
stdout: vec![],
stderr: b"not found".to_vec(),
}]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
let err = target
.delete_secret("KEY", &make_target("dev"))
.unwrap_err();
assert!(err.to_string().contains("not found"));
}
#[test]
fn gitlab_nonzero_exit() {
let fixture = make_config();
let config = fixture.config();
let target_config = config.targets.gitlab.as_ref().unwrap();
let runner = MockCommandRunner::from_outputs(vec![CommandOutput {
success: false,
stdout: vec![],
stderr: b"api error".to_vec(),
}]);
let target = GitlabTarget {
config,
target_config,
runner: &runner,
};
let err = target
.deploy_secret("KEY", "val", &make_target("dev"))
.unwrap_err();
assert!(err.to_string().contains("api error"));
}
}