Skip to main content

heddle_cli_args/cli/cli_args/
commands_env.rs

1// SPDX-License-Identifier: Apache-2.0
2//! `heddle env` — confidential-runtime profiles (ADR 0051 / heddle#999).
3//!
4//! `run` is the product path: the policy broker unwraps named slots and
5//! injects them into a child process. Values never land in the worktree,
6//! the store, or command JSON. `create` / `list` are metadata and
7//! ciphertext only.
8
9use clap::{Args, Subcommand};
10
11#[derive(Clone, Debug, Subcommand)]
12pub enum EnvCommands {
13    /// Create a runtime profile from current environment values.
14    ///
15    /// `--from-env SLOT` copies `SLOT` from this process into ciphertext.
16    /// The value is not printed.
17    Create(EnvCreateArgs),
18    /// List runtime profiles and slot names. Never prints values.
19    List(EnvListArgs),
20    /// Run a child with profile slots injected as environment variables.
21    ///
22    /// Plaintext lives in the child only. Same-UID callers are cooperative;
23    /// OS process isolation is a later slice.
24    #[command(after_help = "\
25Examples:
26  heddle env run --profile production -- printenv DATABASE_URL
27  heddle env run --profile local --slot TOKEN -- env
28")]
29    Run(EnvRunArgs),
30}
31
32#[derive(Clone, Debug, Args)]
33pub struct EnvCreateArgs {
34    /// Profile name (`[A-Za-z0-9._-]`, 1..=64).
35    #[arg(long)]
36    pub name: String,
37
38    /// Copy this environment variable into a slot of the same name.
39    /// Repeat for multiple slots.
40    #[arg(long = "from-env", value_name = "SLOT", required = true)]
41    pub from_env: Vec<String>,
42}
43
44#[derive(Clone, Debug, Args)]
45pub struct EnvListArgs {}
46
47#[derive(Clone, Debug, Args)]
48pub struct EnvRunArgs {
49    /// Runtime profile name.
50    #[arg(long)]
51    pub profile: String,
52
53    /// Slot names to inject. Default: every slot on the current head.
54    #[arg(long = "slot", value_name = "SLOT")]
55    pub slots: Vec<String>,
56
57    /// Child command. Use `--` to separate it from Heddle flags.
58    #[arg(required = true, trailing_var_arg = true, allow_hyphen_values = true)]
59    pub command: Vec<String>,
60}