Repository navigation
feat(cli): generate hsctl and its terminal UI with the rh-trex-ai generators - #477
Conversation
…erators Generate the hsctl commands and the terminal UI from the OpenAPI description with the rh-trex-ai generators, pinned to PR 58 (scripts/rh-trex-ai.ref, the go.mod replace and a temporary dependency age exception), and replace the hand-written code they supersede. Generation - scripts/generate-cli.sh and generate-tui.sh run the pinned generators from a cached checkout (scripts/lib/trex-checkout.sh), passing --config-name hypershell and --oidc-client-id hypershell-cli. make check, the hooks and CI fail on a stale CLI or descriptor and on commands the generator no longer emits. The vendored cli-generator is removed. - The dependency age policy now also covers the pinned generators' module graphs, checks version replacements whether or not they are cached, and retries truncated registry responses. CLI - list, get, create, update and delete per resource, OIDC login (browser and device flow), logout with revocation, whoami and token refresh are generated. Delete confirms and refuses without a terminal unless --yes is given. - Logins saved by earlier versions keep working: same config location and keys. - Hand-written code is limited to apply, the scoped service account and gateway connection commands, the tui wrapper, main.go and go.mod. Terminal UI - hsctl tui is built on the rh-trex-ai tuicmd package and reuses the saved login and its token refresh; the bespoke hsctl ui is removed. Docs and specs describe the workflow, the pin and the hand-maintained files. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…rk replace PR 58 merged to rh-trex-ai main as ff48c56. Point rh-trex-ai.ref and the CLI go.mod at that upstream commit, remove the replace to the fork, and move the dependency age exception to the upstream module path (the commit is under the 14 day minimum age until 2026-10-21). The merged tree equals the previously pinned commit, so the generated CLI and terminal UI are unchanged. components/api-server stays on e2ff9d8: ff48c56 no longer contains RegisterPrefixedRoutes (added by rh-trex-ai openshift-online#62 and used by the extension kind plugins), so it does not build against it. Document the pin process without the fork, and why the extension kinds are hand-written: the generator handles a single API prefix. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
make build-cli now depends on generate-cli (which also regenerates the terminal UI descriptor the binary embeds), so the binary always matches the OpenAPI description and the pinned rh-trex-ai generators. The first run needs network access to fetch the pinned generators. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Amber reviewStatus: Complete |
…d nil config in tui Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Verdict
The head commit resolves both prior actionable findings: the Makefile no longer defaults the generator source to a personal fork, and the hand-written tui wrapper now guards against a nil config before calling cfg.Armed(). The only remaining items are an informational, upstream-owned convention gap in generator output and a cross-PR coordination decision on the CLI's generated-vs-hand-written boundary.
Summary
This PR replaces the hand-written hsctl CLI and TUI with output from the SHA-pinned rh-trex-ai generators, keeping a small hand-maintained surface (main.go, the tui wrapper, apply, revoke, scoped service-account and ext/ extension commands, and the generation scripts). The generator-driven model is well guarded: generate-cli.sh/generate-tui.sh run from a checkout that refuses dirty or SHA-mismatched trees, make check fails on drift and on orphaned resource commands, and the dependency-age exception is time-bounded and justified. Hand-written code avoids panic(), propagates errors, validates the issuer, and keeps secrets out of logs.
Findings
[Minor, informational] Generated resource commands wrap errors with %v, not %w. For example components/cli/cmd/hsctl/delete/gateway/cmd.go:61 uses fmt.Errorf("can't delete gateway: %v", err), which drops the error chain and deviates from the repo convention. These files are generator output (replaced by make generate-cli and drift-checked), so the fix belongs in the rh-trex-ai templates rather than in this repo; raising an upstream issue would let the convention hold once the pin advances. Confidence: High.
Previous concerns
- [Major] Generator source defaults to a personal fork - Addressed. The head commit removes the
TREX_REPO?=https://github.com/rh-amarin/rh-trex-aioverride and itsexportfrom theMakefile(seegit show 0c175e5), and the checkout now defaults to upstream atscripts/lib/trex-checkout.sh:19(TREX_REPO="${TREX_REPO:-https://github.com/openshift-online/rh-trex-ai}").make build-cli/make check/hooks no longer depend on an individual's fork. - [Minor] Hand-written
tuiwrapper dereferences a possibly-nil config - Addressed.components/cli/cmd/hsctl/tui/cmd.go:29-31now returns an error whenconfig.Load()yields(nil, nil)before callingcfg.Armed(), mirroring theloginguard and keeping the newly exportedconfig.SetStoreextension point safe. - [Minor, informational] Generated resource commands wrap errors with
%v- Still present atcomponents/cli/cmd/hsctl/delete/gateway/cmd.go:61, but this is generator/upstream output (see the finding above); not a HyperShell-owned fix.
Cross-PR coordination
A gateway-access management pull request adds a new gatewayAccess resource to the CLI by hand-editing the parent command files that this PR converts to generator output, which forces a maintainer decision on merge order and on the generated-vs-hand-written boundary.
- PR #447: It adds
gatewayAccessCLI commands and, to register them, hand-editscomponents/cli/cmd/hsctl/{create,delete,list}/cmd.go, rewritesmain.go, and introduces a new hand-writtencmd/hsctl/update/cmd.goparent that registers onlygatewayAccess. This PR instead makes those parent files generator output:create/delete/list/cmd.goandupdate/cmd.goare copied from the generator and drift-checked bymake check(scripts/generate-cli.sh), andupdate/cmd.gois the generated parent registeringgatewayandmanagedCluster. After this PR merges, #447's hand edits to the generated parents are overwritten and would failcheck-cli-drift, and its newupdate/cmd.gocollides structurally with the generated one. #447 also givesgatewayAccesscustom verbs (grant/change-role/revoke) that the resource generator does not emit. Maintainers need to decide whethergatewayAccessis a generated core command or a hand-written one (and, if hand-written, register it via theextgroup/HAND_MAINTAINED_COMMANDSmechanism this PR establishes), and to sequence the two PRs so the later one rebases onto the chosen CLI model.
Findings Summary (ordered by severity, highest first)
- [Minor] Generated resource commands wrap errors with
%vinstead of%w- Convention (generated/upstream) (delete/gateway/cmd.go L61)
Convention Checklist
| Convention | Result |
|---|---|
No panic() in production code |
Pass |
Errors wrapped with fmt.Errorf("...: %w", err) |
Fail (generated commands use %v) |
| No secrets in logs or error messages | Pass |
| Input validated (issuer URL, token file) | Pass |
Proper context propagation (no context.TODO()) |
Pass |
| OpenAPI/generated client not manually edited | Pass (drift-checked by make check) |
| Conventional commit messages | Pass |
| Dependency age / pins policy honored | Pass (time-bounded, justified exception) |
Resolve conflicts between the user_management (gateway access management) work and main's placement-availability, CLI-generator overhaul (#477), and SDK relative-path changes: - sdk-generator (parser.go): keep HEAD's scoped-resource capability flags + TS import ordering and adopt main's relativeAPIPath for collection/item paths; make the directory-search path relative too, for consistency. - gateways plugin (handler.go/plugin.go): union of enforceRBAC + caller capability checks (HEAD) and placement/availability resolver (main). - hsctl: take main's generated-command architecture (ui -> tui, generated update/version/whoami via addGeneratedCommands); re-wire the hand-written gatewayAccess scoped commands like service accounts and declare them in generate-cli.sh HAND_MAINTAINED_COMMANDS. - openapi_embed_test.go: merged operation count is 60. - Regenerated sdk-go, sdk-typescript, and hsctl from the merged OpenAPI spec. - RECONCILE.md / gateway-create.test.tsx: union both sides. Verified: all Go components build+vet; api-server embed test; sdk-generator tests; gateway-management-ui 220 tests; sdk-typescript tsc; make check (no CLI drift, no forbidden terms). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

Summary
Generate the
hsctlcommands and thehsctl tuiterminal UI from the OpenAPI description with the rh-trex-ai generators (pinned to the merged PR 58,ff48c56), replacing the hand-written code they supersede.Changes
scripts/generate-cli.shandgenerate-tui.shrun the pinned generators from a cached checkout.make check, the hooks and CI fail on stale generated output and on orphaned commands. The vendored cli-generator is removed.apply, service-account and gateway connection commands, the sixext/extension kinds (the generator supports a single API prefix), thetuiwrapper,main.go,go.mod.tuicmd, reusing the saved login; the bespokehsctl uiis removed.ff48c56(remove after 2026-10-21).make build-clinow runsgenerate-clifirst.components/api-serverstays one2ff9d8: the merged trex commit lacksRegisterPrefixedRoutes, which the extension plugins use.Test plan
make generate-cli: no drift after rebase on mainmake checkpassesgo vet/go test ./...incomponents/climake unit-test-all: all pass exceptscripts/skillspector-scan_test.sh(macOS bash 3.2printf --; also fails on clean main)🤖 Generated with Claude Code