config

package
v0.1.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: MIT Imports: 16 Imported by: 0

Documentation

Overview

Package config loads the chcli configuration file and resolves the effective connection settings from profiles, environment variables and command-line flags.

Index

Constants

View Source
const (
	AuthPassword = "password"
	AuthJWT      = "jwt"
	AuthOIDC     = "oidc"
	AuthGoogle   = "google"
)

Authentication types.

View Source
const (
	ProtocolNative = "native"
	ProtocolHTTP   = "http"
)

Transport protocols.

View Source
const (
	FlowBrowser = "browser"
	FlowDevice  = "device"
)

OAuth login flows.

View Source
const (
	TokenTypeID     = "id_token"
	TokenTypeAccess = "access_token"
)

Which OAuth token is presented to ClickHouse.

View Source
const (
	KeyHost               = "host"
	KeyPort               = "port"
	KeyDatabase           = "database"
	KeyProtocol           = "protocol"
	KeySecure             = "secure"
	KeyInsecureSkipVerify = "insecure-skip-verify"
	KeyCACert             = "ca-cert"
	KeyAuth               = "auth"
	KeyGoogleOAuth        = "google-oauth"
	KeyUser               = "user"
	KeyPassword           = "password"
	KeyJWTToken           = "jwt-token"
	KeyClientID           = "oauth-client-id"
	KeyClientSecret       = "oauth-client-secret"
	KeyIssuer             = "oauth-issuer"
	KeyAuthEndpoint       = "oauth-authorization-endpoint"
	KeyTokenEndpoint      = "oauth-token-endpoint"
	KeyDeviceEndpoint     = "oauth-device-endpoint"
	KeyAudience           = "oauth-audience"
	KeyRedirectURI        = "oauth-redirect-uri"
	KeyUsernameClaim      = "oauth-username-claim"
	KeyScope              = "oauth-scope"
	KeyFlow               = "oauth-flow"
	KeyTokenType          = "oauth-token-type"
)

Setting keys. Each key is the name of a command-line flag (--host) and, upper-cased with a CHCLI_ prefix, of an environment variable (CHCLI_HOST).

View Source
const DefaultHistoryEntries = 10000

DefaultHistoryEntries is used when history.max_entries is not set.

View Source
const GoogleIssuer = "https://accounts.google.com"

GoogleIssuer is the OpenID Connect issuer of Google accounts.

View Source
const Redacted = "***"

Redacted is what a non-empty Secret looks like anywhere it is printed.

Variables

This section is empty.

Functions

func DefaultPath

func DefaultPath() string

DefaultPath returns the configuration file location: $CHCLI_CONFIG if set, otherwise $XDG_CONFIG_HOME/chcli/config.yaml (~/.config/chcli/config.yaml) on Unix-like systems and %AppData%\chcli\config.yaml on Windows.

func EnvName

func EnvName(key string) string

EnvName returns the environment variable for a setting key.

func StateDir

func StateDir() string

StateDir returns the directory for history and the fallback token cache: $XDG_STATE_HOME/chcli (~/.local/state/chcli) on Unix-like systems and %LocalAppData%\chcli on Windows.

func ValidateRedirectURI

func ValidateRedirectURI(redirect string) error

ValidateRedirectURI checks that an OAuth redirect URI points at a local loopback HTTP listener, the only kind this client can serve.

Types

type Auth

type Auth struct {
	Type string `yaml:"type"`

	// Password authentication.
	Username string `yaml:"username,omitempty"`
	Password Secret `yaml:"password,omitempty"`

	// Static JWT / bearer token authentication.
	Token Secret `yaml:"token,omitempty"`

	// OAuth 2.0 / OpenID Connect (types "oidc" and "google").
	ClientID              string   `yaml:"client_id,omitempty"`
	ClientSecret          Secret   `yaml:"client_secret,omitempty"`
	Issuer                string   `yaml:"issuer,omitempty"`
	AuthorizationEndpoint string   `yaml:"authorization_endpoint,omitempty"`
	TokenEndpoint         string   `yaml:"token_endpoint,omitempty"`
	DeviceEndpoint        string   `yaml:"device_endpoint,omitempty"`
	Audience              string   `yaml:"audience,omitempty"`
	Scopes                []string `yaml:"scopes,omitempty"`
	UsernameClaim         string   `yaml:"username_claim,omitempty"`
	RedirectURI           string   `yaml:"redirect_uri,omitempty"`
	Flow                  string   `yaml:"flow,omitempty"`
	TokenType             string   `yaml:"token_type,omitempty"`
}

Auth holds the authentication settings of a connection. Which fields are meaningful depends on Type.

type File

type File struct {
	Connections map[string]Profile `yaml:"connections"`
	History     History            `yaml:"history"`
	Output      Output             `yaml:"output"`

	// Warnings collects non-fatal problems found while loading.
	Warnings []string `yaml:"-"`
}

File is the on-disk configuration.

func Load

func Load(path string) (*File, error)

Load reads the configuration file at path. A missing file is not an error: profiles are optional, so an empty configuration is returned.

func (*File) ProfileNames

func (f *File) ProfileNames() []string

ProfileNames returns the configured profile names in sorted order.

type History

type History struct {
	Enabled    *bool `yaml:"enabled"`
	MaxEntries int   `yaml:"max_entries"`
}

History configures the persistent REPL history.

func (History) IsEnabled

func (h History) IsEnabled() bool

IsEnabled reports whether history is enabled (the default).

func (History) Limit

func (h History) Limit() int

Limit returns the maximum number of history entries to keep.

type Output

type Output struct {
	// Format is the default output format for interactive sessions.
	Format string `yaml:"format"`
	// Pager is a command (for example "less -FRSX") that interactive table
	// output is piped through. Empty disables paging.
	Pager string `yaml:"pager"`
}

Output configures result rendering.

type Profile

type Profile struct {
	Host               string `yaml:"host"`
	Port               int    `yaml:"port"`
	Database           string `yaml:"database"`
	Protocol           string `yaml:"protocol"`
	Secure             *bool  `yaml:"secure"`
	InsecureSkipVerify bool   `yaml:"insecure_skip_verify"`
	CACert             string `yaml:"ca_cert"`
	Auth               Auth   `yaml:"auth"`
}

Profile is a named connection in the configuration file.

type Resolved

type Resolved struct {
	Profile            string `yaml:"profile,omitempty"`
	Host               string `yaml:"host"`
	Port               int    `yaml:"port"`
	Database           string `yaml:"database"`
	Protocol           string `yaml:"protocol"`
	Secure             bool   `yaml:"secure"`
	InsecureSkipVerify bool   `yaml:"insecure_skip_verify,omitempty"`
	CACert             string `yaml:"ca_cert,omitempty"`
	Auth               Auth   `yaml:"auth"`
	// contains filtered or unexported fields
}

Resolved is the effective configuration of one connection after merging built-in defaults, the selected profile, environment variables and flags.

func Resolve

func Resolve(file *File, profileName string, env, flags Source) (*Resolved, error)

Resolve computes the effective configuration. Precedence, highest first: flags, environment, the selected profile, built-in defaults. The stored profile is never modified.

func (*Resolved) Addr

func (r *Resolved) Addr() string

Addr returns host:port.

func (*Resolved) Label

func (r *Resolved) Label() string

Label names the connection for prompts and messages: the profile name when a profile is in use, the host otherwise.

type Secret

type Secret string

Secret is a string that refuses to reveal itself by accident. Formatting it with fmt, logging it with slog, or marshalling it to YAML or JSON all yield the redaction placeholder. Call Reveal where the real value is needed.

func (Secret) GoString

func (s Secret) GoString() string

func (Secret) LogValue

func (s Secret) LogValue() slog.Value

func (Secret) MarshalJSON

func (s Secret) MarshalJSON() ([]byte, error)

func (Secret) MarshalText

func (s Secret) MarshalText() ([]byte, error)

func (Secret) MarshalYAML

func (s Secret) MarshalYAML() (any, error)

func (Secret) Reveal

func (s Secret) Reveal() string

Reveal returns the underlying secret value.

func (Secret) String

func (s Secret) String() string

type Source

type Source struct {
	// Lookup returns the value for a setting key and whether it is set.
	Lookup func(key string) (string, bool)
	// Name returns how the key is spelled in this source, for error messages.
	Name func(key string) string
}

Source is one layer of overrides (environment or command-line flags).

func EnvSource

func EnvSource(lookupEnv func(string) (string, bool)) Source

EnvSource builds a Source over an environment lookup function such as os.LookupEnv. Empty variables count as unset.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL