Documentation
¶
Overview ¶
Package lang holds the cli helping text
Index ¶
Constants ¶
View Source
const ( // CmdDistroCreateShort create short CmdDistroCreateShort = "Creates a Cargoship Package from a given directory or the current directory" // CmdDistroCreateLong create long CmdDistroCreateLong = "Builds an offline distro package from a definition directory -- a distro.yaml and whatever sits beside it -- producing one compressed archive that carries everything a cluster needs: the engine's packages and binaries, the OCI images, the configuration templates, and the checksums over all of them.\n\n" + "The archive is fat on purpose. One package holds every architecture it targets, and the host's own architecture selects what gets uploaded at apply time, so a mixed fleet installs from a single file.\n\n" + "Everything the definition declares is fetched while this runs, which is the one step that needs a network. --registry-override and --file-override redirect those fetches to an internal mirror or to files staged on disk ahead of time, which is how a package is built where there is no route to the upstream hosts. A declared shasum is enforced either way.\n\n" + "--signing-key signs the package as it is built. --reproducible pins the recorded build time so that identical inputs produce a byte-identical archive." // CmdDistroPublishShort publish short CmdDistroPublishShort = "Publish the Cargoship Package to an OCI registry" // CmdDistroPublishLong publish long CmdDistroPublishLong = "Pushes a built package to an OCI registry, where 'cargoship apply' and 'cargoship pull' can read it by reference instead of by path. The package is uploaded as OCI artifacts, so any registry that stores them will hold it, and --oci-concurrency sets how many layers move at once.\n\n" + "The signature a package already carries is published with it. Passing --signing-key re-signs the package under a different key on the way out, which is how one built and signed in a development environment is re-signed for a production registry." // CmdPackagePullShort pull short CmdPackagePullShort = "Pulls a Cargoship package from a remote registry and saves it to the local filesystem" // CmdPackagePullLong pull long CmdPackagePullLong = "Downloads a package from an OCI registry or an https:// URL and writes it to the local filesystem as a single archive, so that it can be carried to a machine with no route to the registry it came from. An apply reads the same references directly, so pulling first is for staging rather than something an install needs.\n\n" + "--shasum checks the downloaded archive against a checksum you already hold, which is the check to use when the package is to be trusted on the strength of something other than its signature." // CmdPackagePullFlagShasum pull shasum flag CmdPackagePullFlagShasum = "Shasum of the package to pull." // CmdDistroApplyShort apply short CmdDistroApplyShort = "Apply a config file to bootstrap and upgrade a cluster" // CmdDistroApplyLong apply long CmdDistroApplyLong = "Bootstraps a cluster from a package and a cluster configuration, or upgrades one that is already running, by stepping through the apply phases against every host the configuration names. One command does both: the engine version already on each host is what tells an upgrade apart from an install, and a downgrade is refused rather than attempted.\n\n" + "Cargoship opens every SSH connection itself, from the machine it runs on, and nothing is installed on a target host beyond what a phase uploads.\n\n" + "An apply never removes a node. A host deleted from the configuration leaves its node in the cluster and stops the run rather than having the difference reconciled, so that no machine is drained or uninstalled by a configuration edit alone. Pass --allow-unmanaged-nodes when the extra nodes were joined deliberately and cargoship should leave them alone.\n\n" + "This changes every host it is pointed at, so it needs --confirm. Pass --dry-run instead to connect to every host and run the preflight checks for real, reporting what the run would change without changing it." // CmdDistroPrepareShort prepare short CmdDistroPrepareShort = "Prepares the nodes, including restarting the node if new kernel modules are enabled" // CmdDistroPrepareLong prepare long CmdDistroPrepareLong = "Brings every host the cluster configuration names up to the prerequisites the package declares, without installing the engine: environment variables and sysctl settings, container-selinux on hosts with SELinux enabled, the fapolicyd rules the distro supplies, and the kernel modules the package asks for. A host that gained a module is rebooted, because the module has to be loaded before an apply can use it.\n\n" + "Running this is optional. An apply runs the same preparation phases itself, and this command exists so that the disruptive half can be done on its own schedule -- ahead of a maintenance window rather than inside it.\n\n" + "--hosts, --firewall and --fapolicyd each opt into rewriting a part of the host that cargoship otherwise leaves alone.\n\n" + "This changes every host it is pointed at, so it needs --confirm. Pass --dry-run to report what it would change instead." // CmdDistroResetShort reset short CmdDistroResetShort = "Reset a cluster, stopping, uninstalling, and removing all data for an engine" // CmdDistroResetLong reset long CmdDistroResetLong = "Removes the engine and the data it wrote from every host the cluster configuration names. Each node is deleted from the cluster, drained first where that is enabled, then the engine's packages or binaries are uninstalled and the service manager is reloaded.\n\n" + "This is destructive and it backs nothing up. Nothing a workload kept on a host survives it, and no command puts the cluster back: what follows a reset is an apply, which bootstraps a new one.\n\n" + "--distro names the engine to remove. A reset loads no package, so it has nothing else to read the engine's identity from.\n\n" + "This needs --confirm. Pass --dry-run to report every host it would reset, and what it would do to each, without touching one." // CmdDistroKubeConfigShort kube-config short CmdDistroKubeConfigShort = "Get the admin kube-config for a control-plane node" // CmdDistroKubeConfigLong kube-config long CmdDistroKubeConfigLong = "Fetches the engine's admin credentials from the first control-plane node the cluster configuration names and merges them into a kubeconfig file. The file is created when it does not exist, and an existing one keeps every other cluster it already holds.\n\n" + "The server address is rewritten to the control-plane address the configuration declares, rather than the node the credentials came from, so the context keeps working when that node does not. The context is named after the cluster's metadata.name.\n\n" + "This changes no host -- it connects, reads, and writes a file locally -- so it needs no --confirm. The file written to is --kubeconfig, which defaults to KUBECONFIG when that is set and to the standard location otherwise." // CmdDistroEngineConfigSyncShort engine-config-sync short CmdDistroEngineConfigSyncShort = "" /* 150-byte string literal not displayed */ // CmdDistroEngineConfigSyncLong engine-config-sync long CmdDistroEngineConfigSyncLong = "Writes the engine configuration a package and a cluster configuration describe -- registry mirrors and credentials, audit policy, and pod security -- to every host the configuration names, and restarts the engine only where what is on disk no longer matches. A node whose configuration already agrees is left running untouched.\n\n" + "This exists because those three settings are the ones that change without the engine version changing, and a full apply is a heavier way to deliver them. Where a restart is needed the node is drained first, and the nodes are worked through at the rate --work-concurrency allows, so a cluster stays serving while its configuration moves.\n\n" + "Registry credentials encrypted with Ansible Vault or age are decrypted here, and the keys for every one of them are checked before the first host is connected to.\n\n" + "This changes every host whose configuration has drifted, so it needs --confirm. Pass --dry-run to report which nodes would be restarted without restarting one." // CmdInstallFapolicydUpdate install flag fapolicyd CmdInstallFapolicydUpdate = "Whether to update every host node's fapolicyd configuration." // CmdInstallFirewallUpdate install flag firewall CmdInstallFirewallUpdate = "Whether to update every host node's firewall configuration." // CmdInstallFlagConcurrency install flag concurrency CmdInstallFlagConcurrency = "Maximum number of hosts to configure in parallel, set to 0 for unlimited." // CmdInstallFlagConfig install flag config CmdInstallFlagConfig = "Config file used to bootstrap a cluster." // CmdInstallFlagResetDistro install flag config CmdInstallFlagResetDistro = "What type of distro that will be reset. Valid options are: 'rke2', 'k3s'." // CmdInstallFlagKubeConfigDistro kube-config flag config CmdInstallFlagKubeConfigDistro = "What type of distro we will get the admin config from. Valid options are: 'rke2', 'k3s'." // CmdInstallFlagConfirm install flag confirm CmdInstallFlagConfirm = "Proceed with the run. Without it, a command that would change a host reports what it needs and stops." // CmdInstallFlagDryRun install flag dry run CmdInstallFlagDryRun = "" /* 178-byte string literal not displayed */ // CmdInstallFlagTimeout install flag timeout CmdInstallFlagTimeout = "Set the timeout for how long functions will last." // CmdInstallFlagValues install flag values CmdInstallFlagValues = "" /* 216-byte string literal not displayed */ // CmdInstallFlagVaultPasswordFile install flag vault password file CmdInstallFlagVaultPasswordFile = "" /* 201-byte string literal not displayed */ // CmdInstallFlagWorkerConcurrency install flag worker concurrency CmdInstallFlagWorkerConcurrency = "" /* 145-byte string literal not displayed */ // CmdInstallHostUpdate install flag host CmdInstallHostUpdate = "Whether to update every host node's /etc/hosts file." // CmdInstallAllowUnmanagedNodes install flag allow unmanaged nodes CmdInstallAllowUnmanagedNodes = "" /* 283-byte string literal not displayed */ // CmdInstallLabelNodes install flag label nodes CmdInstallLabelNodes = "Whether to check and add the node-role.kubernetes.io/PROFILE label on cluster nodes. Requires --update-kubeconfig." // CmdInstallKubeConfigPath install flag kubeconfig path CmdInstallKubeConfigPath = "" /* 257-byte string literal not displayed */ // CmdInstallUpdateKubeConfig install flag update kubeconfig CmdInstallUpdateKubeConfig = "Whether to write the admin creds for this cluster to a kubeconfig file at all." // CmdPackageCreateFlagFileOverride create flag file override CmdPackageCreateFlagFileOverride = "" /* 418-byte string literal not displayed */ // CmdPackageCreateFlagOutput create flag output CmdPackageCreateFlagOutput = "Specify the output (either a directory or an oci:// URL) for the created Cargoship distro package." // CmdPackageCreateFlagTag create flag tag CmdPackageCreateFlagTag = "The tag or version to override the package metadata version with." // CmdPackageFlagConcurrency deploy flag concurrency CmdPackageFlagConcurrency = "Number of concurrent layer operations when pulling or pushing images or packages to/from OCI registries." // CmdPackageFlagRetries publish flag retry CmdPackageFlagRetries = "Number of retries to perform for Cargoship's operations, such as package publishes." // CmdVersionLong version long CmdVersionLong = "Displays the version of the release that the current binary was built from." // CmdVersionShort version short CmdVersionShort = "Shows the version of the running binary" // CmdVersionOutputFormat version flag output format CmdVersionOutputFormat = "Output format. Valid options are: yaml, json." // CmdSha256SumShort sha256sum short CmdSha256SumShort = "Generates a SHA256SUM for the given file" // CmdSha256SumFlagExtractPath flag description CmdSha256SumFlagExtractPath = `The path inside of an archive to use to calculate the sha256sum (i.e. for use with "files.extractPath")` // CmdVaultShort vault short CmdVaultShort = "Encrypts and decrypts cluster configuration values with Ansible Vault or age" // CmdVaultLong vault long CmdVaultLong = "" /* 677-byte string literal not displayed */ // CmdVaultEncryptDeprecated deprecation notice for the top-level vault-encrypt spelling CmdVaultEncryptDeprecated = `use "cargoship vault encrypt" instead.` // CmdVaultEncryptShort vault encrypt short CmdVaultEncryptShort = "Encrypts a value with Ansible Vault or age, for use in a registry's user/pass/token fields" // CmdVaultEncryptLong vault encrypt long CmdVaultEncryptLong = "" /* 447-byte string literal not displayed */ // CmdVaultEncryptFlagPasswordFile flag description CmdVaultEncryptFlagPasswordFile = "" /* 148-byte string literal not displayed */ // CmdFlagAgeIdentityFile flag description CmdFlagAgeIdentityFile = "" /* 347-byte string literal not displayed */ // CmdFlagAgeRecipient flag description CmdFlagAgeRecipient = "" /* 407-byte string literal not displayed */ // CmdFlagAgeRecipientsFile flag description CmdFlagAgeRecipientsFile = "" /* 296-byte string literal not displayed */ // CmdVaultEncryptPathShort vault encrypt-path short CmdVaultEncryptPathShort = "Encrypts the values a config file already holds at one or more YAML paths, in place" // CmdVaultEncryptPathLong vault encrypt-path long CmdVaultEncryptPathLong = "" /* 784-byte string literal not displayed */ // CmdVaultEncryptPathFlagDryRun flag description CmdVaultEncryptPathFlagDryRun = "Print the resulting document to stdout instead of writing it back to FILE." // CmdVaultEncryptPathFlagForce flag description CmdVaultEncryptPathFlagForce = "Encrypt the value even though it is encrypted already, wrapping it a second time." // CmdVaultEncryptFileShort vault encrypt-file short CmdVaultEncryptFileShort = "Encrypts every registry credential in a config file, in place" // CmdVaultEncryptFileLong vault encrypt-file long CmdVaultEncryptFileLong = "" /* 765-byte string literal not displayed */ // CmdVaultEncryptFileFlagDryRun flag description CmdVaultEncryptFileFlagDryRun = "Print the resulting document to stdout instead of writing it back to FILE." // CmdVaultEncryptFileFlagForce flag description CmdVaultEncryptFileFlagForce = "Encrypt values that are encrypted already, wrapping them a second time." // CmdVaultRekeyFlagNewPasswordFile flag description CmdVaultRekeyFlagNewPasswordFile = "" /* 380-byte string literal not displayed */ // CmdVaultRekeyFlagDryRun flag description CmdVaultRekeyFlagDryRun = "Print the resulting document to stdout instead of writing it back to FILE." // CmdVaultKeygenShort vault keygen short CmdVaultKeygenShort = "Generates an age key pair, or prints the public key of one you already hold" // CmdVaultKeygenLong vault keygen long CmdVaultKeygenLong = "" /* 901-byte string literal not displayed */ // CmdVaultKeygenFlagOutput flag description CmdVaultKeygenFlagOutput = "" /* 211-byte string literal not displayed */ // CmdVaultKeygenFlagPublicKey flag description CmdVaultKeygenFlagPublicKey = "" /* 207-byte string literal not displayed */ // CmdVaultDecryptShort vault decrypt short CmdVaultDecryptShort = "Decrypts an Ansible Vault or age value, printing the plaintext" // CmdVaultDecryptLong vault decrypt long CmdVaultDecryptLong = "" /* 660-byte string literal not displayed */ // CmdVaultDecryptPathShort vault decrypt-path short CmdVaultDecryptPathShort = "Decrypts the values a config file holds at one or more YAML paths, in place" // CmdVaultDecryptPathLong vault decrypt-path long CmdVaultDecryptPathLong = "" /* 704-byte string literal not displayed */ // CmdVaultDecryptPathFlagDryRun flag description CmdVaultDecryptPathFlagDryRun = "Print the resulting document to stdout instead of writing it back to FILE." // CmdVaultDecryptFileShort vault decrypt-file short CmdVaultDecryptFileShort = "Decrypts every registry credential in a config file, in place" // CmdVaultDecryptFileLong vault decrypt-file long CmdVaultDecryptFileLong = "" /* 395-byte string literal not displayed */ // CmdVaultRekeyShort vault rekey short CmdVaultRekeyShort = "Re-wraps every encrypted registry credential in a config file, optionally under a new key" // CmdVaultRekeyLong vault rekey long CmdVaultRekeyLong = "" /* 963-byte string literal not displayed */ // CmdVaultDecryptFileFlagDryRun flag description CmdVaultDecryptFileFlagDryRun = "Print the resulting document to stdout instead of writing it back to FILE." // CmdViperErrLoadingConfigFile error text CmdViperErrLoadingConfigFile = "failed to load config file" // RootCmdFlagLogFormat log format RootCmdFlagLogFormat = "Select a logging format. Defaults to 'console'. Valid options are: 'console', 'json', 'dev'." // RootCmdFlagLogLevel log level RootCmdFlagLogLevel = "Log level when running cargoship. Valid options are: warn, info, debug, trace" // RootCmdFlagNoColor no color RootCmdFlagNoColor = "Disable terminal color codes in logging and stdout prints." // RootCmdFlagLogFile log file RootCmdFlagLogFile = "Always write a full-verbosity debug log to a file, regardless of --log-level." // RootCmdShort root short RootCmdShort = "CLI for cargoship installs" // RootCmdUse root use RootCmdUse = "cargoship COMMAND" // RootGroupInstallID subcommand for install id RootGroupInstallID = "install" // RootGroupInstallTitle subcommand for install title RootGroupInstallTitle = "Install Commands:" // RootGroupPackageID subcommand for package id RootGroupPackageID = "package" // RootGroupPackageTitle subcommand for package id RootGroupPackageTitle = "Package Commands:" // CmdPackageFlagVerify flag CmdPackageFlagVerify = "Verify the Cargoship package signature." // CmdPackageCreateFlagReproducible create flag reproducible CmdPackageCreateFlagReproducible = "" /* 135-byte string literal not displayed */ // CmdSchemaShort schema short CmdSchemaShort = "Writes out a JSON Schema for one of cargoship's own file formats" // CmdSchemaLong schema long CmdSchemaLong = "" /* 1158-byte string literal not displayed */ // CmdSchemaFlagOutput flag description CmdSchemaFlagOutput = "Path to write the schema to. Omit it to write to stdout." // CmdSchemaFlagPackage flag description CmdSchemaFlagPackage = "" /* 274-byte string literal not displayed */ // CmdInventoryShort inventory short CmdInventoryShort = "Generates a cluster inventory from another source of truth" // CmdInventoryLong inventory long CmdInventoryLong = "" /* 260-byte string literal not displayed */ // CmdInventoryFromAnsibleShort inventory from-ansible short CmdInventoryFromAnsibleShort = "Translates an Ansible inventory into a cluster inventory" // CmdInventoryFromAnsibleLong inventory from-ansible long CmdInventoryFromAnsibleLong = "Translates an inventory Ansible has already resolved into a ZarfCluster document, deriving each host's role from the Ansible groups it belongs to.\n\n" + "This does not read an Ansible inventory file. Ansible resolves the inventory -- group membership, group_vars, host_vars, dynamic inventory plugins, and the precedence rules over all of them -- and this reads the resolved result: a JSON document holding 'groups', 'hostvars', an optional 'roleGroups' mapping, and the cluster-wide settings an Ansible inventory has no way to carry. The cargoship Ansible collection produces that document; write it by hand to reproduce a translation outside a playbook run.\n\n" + "By default the Ansible group named 'controller' supplies the control-plane nodes and the group named 'worker' supplies the rest. Set 'roleGroups' to map cargoship's roles onto the group names the inventory actually uses. A host in none of the mapped groups is left out, so a play's inventory may carry hosts that are not part of the cluster; a host in groups mapped to two different roles is an error.\n\n" + "Host order is not cosmetic. Controllers are written first, and the first controller in the document becomes the cluster leader.\n\n" + "Each host's connection details come from its Ansible variables -- ansible_host, ansible_user, ansible_port, ansible_ssh_private_key_file -- and everything cargoship needs beyond those comes from variables under a 'cargoship_' prefix. A 'cargoship_' variable cargoship does not read is an error rather than a value ignored, because a misspelled variable and an unset one are indistinguishable at install time.\n\n" + "The generated document is checked against the inventory schema before it is written. The output goes to stdout, or to --output. Ansible does not connect to the fleet: cargoship opens every SSH connection itself, from the node it runs on." // CmdInventoryFlagOutput flag description CmdInventoryFlagOutput = "Path to write the generated inventory to. Omit it to write to stdout." // CmdInventoryFlagName flag description CmdInventoryFlagName = "Cluster name, overriding the one in the input. It becomes metadata.name, and the context name in the kubeconfig." // CmdInventoryFlagLoadBalancer flag description CmdInventoryFlagLoadBalancer = "Control-plane address, overriding the one in the input. Cargoship adds it to the API server's TLS subject alternative names." // CmdValidateShort validate short CmdValidateShort = "Checks a cluster inventory, package definition, or config file against its schema" // CmdValidateLong validate long CmdValidateLong = "Checks one or more files against the JSON Schema cargoship generates for that file format, " + "reporting every problem rather than the first. Cargoship parses these files without strict key checking, " + "so a misspelled key is dropped rather than reported; this catches that, along with a wrong type and a value " + "outside an enumerated list. The schema is read from the binary, so no network access is needed.\n\n" + "The schema is chosen from the document's own 'kind' field. A cargoship config file declares no kind and has " + "to be named with --kind.\n\n" + "spec.config.values is untyped in the inventory schema, because its shape belongs to whichever package is " + "being installed. Pass --package to check it as well." // CmdValidateFlagKind flag description CmdValidateFlagKind = "" /* 142-byte string literal not displayed */ // CmdValidateFlagPackage flag description CmdValidateFlagPackage = "" /* 277-byte string literal not displayed */ // CmdDistroSignShort sign short CmdDistroSignShort = "Signs an existing Cargoship distro package" // CmdDistroSignLong sign long CmdDistroSignLong = "" /* 229-byte string literal not displayed */ )
View Source
const ( // CmdDistroApplyExample apply example CmdDistroApplyExample = `` /* 968-byte string literal not displayed */ // CmdDistroPrepareExample prepare example CmdDistroPrepareExample = `` /* 642-byte string literal not displayed */ // CmdDistroResetExample reset example CmdDistroResetExample = `` /* 500-byte string literal not displayed */ // CmdDistroKubeConfigExample kube-config example CmdDistroKubeConfigExample = `` /* 344-byte string literal not displayed */ // CmdDistroEngineConfigSyncExample engine-config-sync example CmdDistroEngineConfigSyncExample = `` /* 781-byte string literal not displayed */ // CmdDistroCreateExample create example CmdDistroCreateExample = `` /* 953-byte string literal not displayed */ // CmdDistroPublishExample publish example CmdDistroPublishExample = `` /* 701-byte string literal not displayed */ // CmdPackagePullExample pull example CmdPackagePullExample = `` /* 812-byte string literal not displayed */ // CmdDistroSignExample sign example CmdDistroSignExample = `` /* 781-byte string literal not displayed */ // CmdSha256SumExample sha256sum example CmdSha256SumExample = `` /* 459-byte string literal not displayed */ // CmdVaultEncryptExample vault encrypt example CmdVaultEncryptExample = `` /* 924-byte string literal not displayed */ // CmdVaultEncryptPathExample vault encrypt-path example CmdVaultEncryptPathExample = `` /* 1029-byte string literal not displayed */ // CmdVaultEncryptFileExample vault encrypt-file example CmdVaultEncryptFileExample = `` /* 778-byte string literal not displayed */ // CmdVaultDecryptFileExample vault decrypt-file example CmdVaultDecryptFileExample = `` /* 866-byte string literal not displayed */ // CmdVaultRekeyExample vault rekey example CmdVaultRekeyExample = `` /* 1010-byte string literal not displayed */ // CmdVaultKeygenExample vault keygen example CmdVaultKeygenExample = `` /* 680-byte string literal not displayed */ // CmdVaultDecryptExample vault decrypt example CmdVaultDecryptExample = `` /* 990-byte string literal not displayed */ // CmdVaultDecryptPathExample vault decrypt-path example CmdVaultDecryptPathExample = `` /* 864-byte string literal not displayed */ // CmdInventoryFromAnsibleExample inventory from-ansible example CmdInventoryFromAnsibleExample = `` /* 542-byte string literal not displayed */ // CmdSchemaExample schema example CmdSchemaExample = `` /* 784-byte string literal not displayed */ // CmdValidateExample validate example CmdValidateExample = `` /* 499-byte string literal not displayed */ // CmdVersionExample version example CmdVersionExample = `` /* 207-byte string literal not displayed */ )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
This section is empty.
Click to show internal directories.
Click to hide internal directories.