heddle_cli_args/cli/cli_args/commands_env.rs
1// SPDX-License-Identifier: Apache-2.0
2//! `heddle env` — confidential-runtime profiles (ADR 0051 / heddle#999).
3//!
4//! `run` is the product path: the policy broker unwraps named slots and
5//! injects them into a child process. Values never land in the worktree,
6//! the store, or command JSON. `create` / `list` are metadata and
7//! ciphertext only.
8
9use clap::{Args, Subcommand};
10
11#[derive(Clone, Debug, Subcommand)]
12pub enum EnvCommands {
13 /// Create a runtime profile from current environment values.
14 ///
15 /// `--from-env SLOT` copies `SLOT` from this process into ciphertext.
16 /// The value is not printed.
17 Create(EnvCreateArgs),
18 /// List runtime profiles and slot names. Never prints values.
19 List(EnvListArgs),
20 /// Run a child with profile slots injected as environment variables.
21 ///
22 /// Plaintext lives in the child only. Same-UID callers are cooperative;
23 /// OS process isolation is a later slice.
24 #[command(after_help = "\
25Examples:
26 heddle env run --profile production -- printenv DATABASE_URL
27 heddle env run --profile local --slot TOKEN -- env
28")]
29 Run(EnvRunArgs),
30}
31
32#[derive(Clone, Debug, Args)]
33pub struct EnvCreateArgs {
34 /// Profile name (`[A-Za-z0-9._-]`, 1..=64).
35 #[arg(long)]
36 pub name: String,
37
38 /// Copy this environment variable into a slot of the same name.
39 /// Repeat for multiple slots.
40 #[arg(long = "from-env", value_name = "SLOT", required = true)]
41 pub from_env: Vec<String>,
42}
43
44#[derive(Clone, Debug, Args)]
45pub struct EnvListArgs {}
46
47#[derive(Clone, Debug, Args)]
48pub struct EnvRunArgs {
49 /// Runtime profile name.
50 #[arg(long)]
51 pub profile: String,
52
53 /// Slot names to inject. Default: every slot on the current head.
54 #[arg(long = "slot", value_name = "SLOT")]
55 pub slots: Vec<String>,
56
57 /// Child command. Use `--` to separate it from Heddle flags.
58 #[arg(required = true, trailing_var_arg = true, allow_hyphen_values = true)]
59 pub command: Vec<String>,
60}