Skip to content

feat(cli): generate hsctl and its terminal UI with the rh-trex-ai generators - #477

Merged
rh-amarin merged 4 commits into
openshift-online:mainfrom
rh-amarin:tui
Oct 8, 2026
Merged

rh-amarin merged 4 commits into
openshift-online:mainfrom
rh-amarin:tui

Conversation

@rh-amarin

Copy link
Copy Markdown
Collaborator

Summary

Generate the hsctl commands and the hsctl tui terminal UI from the OpenAPI description with the rh-trex-ai generators (pinned to the merged PR 58, ff48c56), replacing the hand-written code they supersede.

Changes

  • Generation: scripts/generate-cli.sh and generate-tui.sh run the pinned generators from a cached checkout. make check, the hooks and CI fail on stale generated output and on orphaned commands. The vendored cli-generator is removed.
  • CLI: list/get/create/update/delete per resource, OIDC login (browser and device flow), logout with revocation, whoami and token refresh are generated. Existing saved logins keep working (same config location and keys).
  • Hand-written, by design: apply, service-account and gateway connection commands, the six ext/ extension kinds (the generator supports a single API prefix), the tui wrapper, main.go, go.mod.
  • TUI: built on rh-trex-ai tuicmd, reusing the saved login; the bespoke hsctl ui is removed.
  • Dependency age policy: also covers the pinned generators' module graphs; age exception for ff48c56 (remove after 2026-10-21).
  • make build-cli now runs generate-cli first.
  • components/api-server stays on e2ff9d8: the merged trex commit lacks RegisterPrefixedRoutes, which the extension plugins use.

Test plan

  • make generate-cli: no drift after rebase on main
  • make check passes
  • go vet / go test ./... in components/cli
  • make unit-test-all: all pass except scripts/skillspector-scan_test.sh (macOS bash 3.2 printf --; also fails on clean main)
  • CI

🤖 Generated with Claude Code

rh-amarin and others added 3 commits October 8, 2026 13:37
…erators

Generate the hsctl commands and the terminal UI from the OpenAPI description
with the rh-trex-ai generators, pinned to PR 58 (scripts/rh-trex-ai.ref, the
go.mod replace and a temporary dependency age exception), and replace the
hand-written code they supersede.

Generation
- scripts/generate-cli.sh and generate-tui.sh run the pinned generators from a
  cached checkout (scripts/lib/trex-checkout.sh), passing --config-name
  hypershell and --oidc-client-id hypershell-cli. make check, the hooks and CI
  fail on a stale CLI or descriptor and on commands the generator no longer
  emits. The vendored cli-generator is removed.
- The dependency age policy now also covers the pinned generators' module
  graphs, checks version replacements whether or not they are cached, and
  retries truncated registry responses.

CLI
- list, get, create, update and delete per resource, OIDC login (browser and
  device flow), logout with revocation, whoami and token refresh are generated.
  Delete confirms and refuses without a terminal unless --yes is given.
- Logins saved by earlier versions keep working: same config location and keys.
- Hand-written code is limited to apply, the scoped service account and
  gateway connection commands, the tui wrapper, main.go and go.mod.

Terminal UI
- hsctl tui is built on the rh-trex-ai tuicmd package and reuses the saved
  login and its token refresh; the bespoke hsctl ui is removed.

Docs and specs describe the workflow, the pin and the hand-maintained files.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…rk replace

PR 58 merged to rh-trex-ai main as ff48c56. Point rh-trex-ai.ref and the CLI
go.mod at that upstream commit, remove the replace to the fork, and move the
dependency age exception to the upstream module path (the commit is under the
14 day minimum age until 2026-10-21). The merged tree equals the previously
pinned commit, so the generated CLI and terminal UI are unchanged.

components/api-server stays on e2ff9d8: ff48c56 no longer contains
RegisterPrefixedRoutes (added by rh-trex-ai openshift-online#62 and used by the extension kind
plugins), so it does not build against it.

Document the pin process without the fork, and why the extension kinds are
hand-written: the generator handles a single API prefix.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
make build-cli now depends on generate-cli (which also regenerates the terminal
UI descriptor the binary embeds), so the binary always matches the OpenAPI
description and the pinned rh-trex-ai generators. The first run needs network
access to fetch the pinned generators.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Repository YAML (base), Central YAML (inherited)
  • Review profile: CHILL
  • Plan: Enterprise
  • Run ID: ab069c17-81a4-48cb-a8fb-096f299cdaa0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

@hypershell-delivery

hypershell-delivery Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Amber review: comment

Amber review

Status: Complete

View the submitted review.

hypershell-delivery[bot]

This comment was marked as outdated.

…d nil config in tui

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>

@hypershell-delivery hypershell-delivery Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict

The head commit resolves both prior actionable findings: the Makefile no longer defaults the generator source to a personal fork, and the hand-written tui wrapper now guards against a nil config before calling cfg.Armed(). The only remaining items are an informational, upstream-owned convention gap in generator output and a cross-PR coordination decision on the CLI's generated-vs-hand-written boundary.

Summary

This PR replaces the hand-written hsctl CLI and TUI with output from the SHA-pinned rh-trex-ai generators, keeping a small hand-maintained surface (main.go, the tui wrapper, apply, revoke, scoped service-account and ext/ extension commands, and the generation scripts). The generator-driven model is well guarded: generate-cli.sh/generate-tui.sh run from a checkout that refuses dirty or SHA-mismatched trees, make check fails on drift and on orphaned resource commands, and the dependency-age exception is time-bounded and justified. Hand-written code avoids panic(), propagates errors, validates the issuer, and keeps secrets out of logs.

Findings

[Minor, informational] Generated resource commands wrap errors with %v, not %w. For example components/cli/cmd/hsctl/delete/gateway/cmd.go:61 uses fmt.Errorf("can't delete gateway: %v", err), which drops the error chain and deviates from the repo convention. These files are generator output (replaced by make generate-cli and drift-checked), so the fix belongs in the rh-trex-ai templates rather than in this repo; raising an upstream issue would let the convention hold once the pin advances. Confidence: High.

Previous concerns

  • [Major] Generator source defaults to a personal fork - Addressed. The head commit removes the TREX_REPO?=https://github.com/rh-amarin/rh-trex-ai override and its export from the Makefile (see git show 0c175e5), and the checkout now defaults to upstream at scripts/lib/trex-checkout.sh:19 (TREX_REPO="${TREX_REPO:-https://github.com/openshift-online/rh-trex-ai}"). make build-cli/make check/hooks no longer depend on an individual's fork.
  • [Minor] Hand-written tui wrapper dereferences a possibly-nil config - Addressed. components/cli/cmd/hsctl/tui/cmd.go:29-31 now returns an error when config.Load() yields (nil, nil) before calling cfg.Armed(), mirroring the login guard and keeping the newly exported config.SetStore extension point safe.
  • [Minor, informational] Generated resource commands wrap errors with %v - Still present at components/cli/cmd/hsctl/delete/gateway/cmd.go:61, but this is generator/upstream output (see the finding above); not a HyperShell-owned fix.

Cross-PR coordination

A gateway-access management pull request adds a new gatewayAccess resource to the CLI by hand-editing the parent command files that this PR converts to generator output, which forces a maintainer decision on merge order and on the generated-vs-hand-written boundary.

  • PR #447: It adds gatewayAccess CLI commands and, to register them, hand-edits components/cli/cmd/hsctl/{create,delete,list}/cmd.go, rewrites main.go, and introduces a new hand-written cmd/hsctl/update/cmd.go parent that registers only gatewayAccess. This PR instead makes those parent files generator output: create/delete/list/cmd.go and update/cmd.go are copied from the generator and drift-checked by make check (scripts/generate-cli.sh), and update/cmd.go is the generated parent registering gateway and managedCluster. After this PR merges, #447's hand edits to the generated parents are overwritten and would fail check-cli-drift, and its new update/cmd.go collides structurally with the generated one. #447 also gives gatewayAccess custom verbs (grant/change-role/revoke) that the resource generator does not emit. Maintainers need to decide whether gatewayAccess is a generated core command or a hand-written one (and, if hand-written, register it via the extgroup/HAND_MAINTAINED_COMMANDS mechanism this PR establishes), and to sequence the two PRs so the later one rebases onto the chosen CLI model.

Findings Summary (ordered by severity, highest first)

  1. [Minor] Generated resource commands wrap errors with %v instead of %w - Convention (generated/upstream) (delete/gateway/cmd.go L61)

Convention Checklist

Convention Result
No panic() in production code Pass
Errors wrapped with fmt.Errorf("...: %w", err) Fail (generated commands use %v)
No secrets in logs or error messages Pass
Input validated (issuer URL, token file) Pass
Proper context propagation (no context.TODO()) Pass
OpenAPI/generated client not manually edited Pass (drift-checked by make check)
Conventional commit messages Pass
Dependency age / pins policy honored Pass (time-bounded, justified exception)

@rh-amarin
rh-amarin added this pull request to the merge queue Oct 8, 2026
Merged via the queue into openshift-online:main with commit 18bb3cd Oct 8, 2026
31 checks passed
@rh-amarin
rh-amarin deleted the tui branch October 8, 2026 13:10
bsquizz added a commit that referenced this pull request Oct 9, 2026
Resolve conflicts between the user_management (gateway access management)
work and main's placement-availability, CLI-generator overhaul (#477), and
SDK relative-path changes:

- sdk-generator (parser.go): keep HEAD's scoped-resource capability flags +
  TS import ordering and adopt main's relativeAPIPath for collection/item
  paths; make the directory-search path relative too, for consistency.
- gateways plugin (handler.go/plugin.go): union of enforceRBAC + caller
  capability checks (HEAD) and placement/availability resolver (main).
- hsctl: take main's generated-command architecture (ui -> tui, generated
  update/version/whoami via addGeneratedCommands); re-wire the hand-written
  gatewayAccess scoped commands like service accounts and declare them in
  generate-cli.sh HAND_MAINTAINED_COMMANDS.
- openapi_embed_test.go: merged operation count is 60.
- Regenerated sdk-go, sdk-typescript, and hsctl from the merged OpenAPI spec.
- RECONCILE.md / gateway-create.test.tsx: union both sides.

Verified: all Go components build+vet; api-server embed test; sdk-generator
tests; gateway-management-ui 220 tests; sdk-typescript tsc; make check
(no CLI drift, no forbidden terms).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant