Documentation
¶
Overview ¶
Package config loads the chcli configuration file and resolves the effective connection settings from profiles, environment variables and command-line flags.
Index ¶
Constants ¶
const ( AuthPassword = "password" AuthJWT = "jwt" AuthOIDC = "oidc" AuthGoogle = "google" )
Authentication types.
const ( ProtocolNative = "native" ProtocolHTTP = "http" )
Transport protocols.
const ( FlowBrowser = "browser" FlowDevice = "device" )
OAuth login flows.
const ( TokenTypeID = "id_token" TokenTypeAccess = "access_token" )
Which OAuth token is presented to ClickHouse.
const ( KeyHost = "host" KeyPort = "port" KeyDatabase = "database" KeyProtocol = "protocol" KeySecure = "secure" KeyInsecureSkipVerify = "insecure-skip-verify" KeyCACert = "ca-cert" KeyAuth = "auth" KeyGoogleOAuth = "google-oauth" KeyUser = "user" KeyPassword = "password" KeyJWTToken = "jwt-token" KeyClientID = "oauth-client-id" KeyClientSecret = "oauth-client-secret" KeyIssuer = "oauth-issuer" KeyAuthEndpoint = "oauth-authorization-endpoint" KeyTokenEndpoint = "oauth-token-endpoint" KeyDeviceEndpoint = "oauth-device-endpoint" KeyAudience = "oauth-audience" KeyRedirectURI = "oauth-redirect-uri" KeyUsernameClaim = "oauth-username-claim" KeyScope = "oauth-scope" KeyFlow = "oauth-flow" KeyTokenType = "oauth-token-type" )
Setting keys. Each key is the name of a command-line flag (--host) and, upper-cased with a CHCLI_ prefix, of an environment variable (CHCLI_HOST).
const DefaultHistoryEntries = 10000
DefaultHistoryEntries is used when history.max_entries is not set.
const GoogleIssuer = "https://accounts.google.com"
GoogleIssuer is the OpenID Connect issuer of Google accounts.
const Redacted = "***"
Redacted is what a non-empty Secret looks like anywhere it is printed.
Variables ¶
var SecretKeys = []string{KeyPassword, KeyJWTToken, KeyClientSecret}
SecretKeys lists the settings that hold secrets and so have a command companion.
Functions ¶
func CommandKey ¶ added in v0.2.0
CommandKey returns the key of the command companion of a secret setting: "password" -> "password-command" (--password-command, CHCLI_PASSWORD_COMMAND).
func DefaultPath ¶
func DefaultPath() string
DefaultPath returns the configuration file location: $CHCLI_CONFIG if set, otherwise $XDG_CONFIG_HOME/chcli/config.yaml (~/.config/chcli/config.yaml) on Unix-like systems and %AppData%\chcli\config.yaml on Windows.
func StateDir ¶
func StateDir() string
StateDir returns the directory for history and the fallback token cache: $XDG_STATE_HOME/chcli (~/.local/state/chcli) on Unix-like systems and %LocalAppData%\chcli on Windows.
func ValidateRedirectURI ¶
ValidateRedirectURI checks that an OAuth redirect URI points at a local loopback HTTP listener, the only kind this client can serve.
Types ¶
type Auth ¶
type Auth struct {
Type string `yaml:"type"`
// Password authentication.
Username string `yaml:"username,omitempty"`
Password Secret `yaml:"password,omitempty"`
PasswordCommand Command `yaml:"password_command,omitempty"`
// Static JWT / bearer token authentication.
Token Secret `yaml:"token,omitempty"`
TokenCommand Command `yaml:"token_command,omitempty"`
// OAuth 2.0 / OpenID Connect (types "oidc" and "google").
ClientID string `yaml:"client_id,omitempty"`
ClientSecret Secret `yaml:"client_secret,omitempty"`
ClientSecretCommand Command `yaml:"client_secret_command,omitempty"`
Issuer string `yaml:"issuer,omitempty"`
AuthorizationEndpoint string `yaml:"authorization_endpoint,omitempty"`
TokenEndpoint string `yaml:"token_endpoint,omitempty"`
DeviceEndpoint string `yaml:"device_endpoint,omitempty"`
Audience string `yaml:"audience,omitempty"`
Scopes []string `yaml:"scopes,omitempty"`
UsernameClaim string `yaml:"username_claim,omitempty"`
RedirectURI string `yaml:"redirect_uri,omitempty"`
Flow string `yaml:"flow,omitempty"`
TokenType string `yaml:"token_type,omitempty"`
}
Auth holds the authentication settings of a connection. Which fields are meaningful depends on Type.
type Command ¶ added in v0.2.0
Command is an external program that prints a secret, in the spirit of kubeconfig's exec credential plugins. Every secret setting X has a companion X_command (--X-command, CHCLI_X_COMMAND). In YAML a command is either a string, which is run through the shell ("sh -c" / "cmd /C"), or a list of program and arguments, which is run directly.
func (Command) IsZero ¶ added in v0.2.0
IsZero lets "omitempty" leave an unset command out of config show.
func (Command) MarshalYAML ¶ added in v0.2.0
type File ¶
type File struct {
Connections map[string]Profile `yaml:"connections"`
History History `yaml:"history"`
Output Output `yaml:"output"`
// Warnings collects non-fatal problems found while loading.
Warnings []string `yaml:"-"`
}
File is the on-disk configuration.
func Load ¶
Load reads the configuration file at path. A missing file is not an error: profiles are optional, so an empty configuration is returned.
func (*File) ProfileNames ¶
ProfileNames returns the configured profile names in sorted order.
type History ¶
History configures the persistent REPL history.
type Output ¶
type Output struct {
// Format is the default output format for interactive sessions.
Format string `yaml:"format"`
// Pager is a command (for example "less -FRSX") that interactive table
// output is piped through. Empty disables paging.
Pager string `yaml:"pager"`
}
Output configures result rendering.
type Profile ¶
type Profile struct {
Host string `yaml:"host"`
Port int `yaml:"port"`
Database string `yaml:"database"`
Protocol string `yaml:"protocol"`
Secure *bool `yaml:"secure"`
InsecureSkipVerify bool `yaml:"insecure_skip_verify"`
CACert string `yaml:"ca_cert"`
Auth Auth `yaml:"auth"`
}
Profile is a named connection in the configuration file.
type Resolved ¶
type Resolved struct {
Profile string `yaml:"profile,omitempty"`
Host string `yaml:"host"`
Port int `yaml:"port"`
Database string `yaml:"database"`
Protocol string `yaml:"protocol"`
Secure bool `yaml:"secure"`
InsecureSkipVerify bool `yaml:"insecure_skip_verify,omitempty"`
CACert string `yaml:"ca_cert,omitempty"`
Auth Auth `yaml:"auth"`
// contains filtered or unexported fields
}
Resolved is the effective configuration of one connection after merging built-in defaults, the selected profile, environment variables and flags.
type Secret ¶
type Secret string
Secret is a string that refuses to reveal itself by accident. Formatting it with fmt, logging it with slog, or marshalling it to YAML or JSON all yield the redaction placeholder. Call Reveal where the real value is needed.
func (Secret) MarshalJSON ¶
func (Secret) MarshalText ¶
func (Secret) MarshalYAML ¶
type Source ¶
type Source struct {
// Lookup returns the value for a setting key and whether it is set.
Lookup func(key string) (string, bool)
// Name returns how the key is spelled in this source, for error messages.
Name func(key string) string
}
Source is one layer of overrides (environment or command-line flags).