Skip to content

refactor: restructure package to mirror vct-cribl-cli's API-endpoint framework - #81

Merged
JacobPEvans-personal merged 4 commits into
mainfrom
refactor/api-endpoint-framework
Aug 18, 2026
Merged

JacobPEvans-personal merged 4 commits into
mainfrom
refactor/api-endpoint-framework

Conversation

@werd-drew

Copy link
Copy Markdown
Contributor

Summary

Reorganizes the package from a core/ + commands/ split into the same layered layout as vct-cribl-cli, so both CLIs expose a consistent API surface. Behavior is unchanged.

What changed

  • api/client.py — layered httpx transport stack (AuthTransport → RetryTransport → HTTPTransport). Auth is now resolved and injected per request by AuthTransport instead of set once at client construction, so a long-running embedder re-authenticates transparently when a session key expires.
  • api/endpoint_factory.py — generic CRUD engine renamed to EndpointConfig / Field / Endpoints (was Spec / CrudResource); a scope field ("global"/"namespaced") replaces the namespaced boolean.
  • api/endpoints/ — hand-written endpoint modules; api/acs/ — Splunk Cloud ACS client.
  • auth/session.py — credential resolution + login with lazy session-key caching.
  • config/ (loader.py, types.py) — profile/env/flag merging; SplunkConfig carries token/session_key/username/password separately.
  • utils/, output/formatter.py, commands/command_factory.py — the remaining cribl-parallel packages.
  • Adds docs/architecture.md; updates the AGENTS.md architecture section. .envrc now loads a local .env via direnv's dotenv_if_exists.

Verification

  • 1023 unit tests pass; ruff and pyright clean.
  • Verified live against Splunk Enterprise 10.4 (server info, index list, bounded search run, namespaced saved-search list, health check, raw api get).

🤖 Generated with Claude Code

werd-drew and others added 2 commits August 17, 2026 10:43
…framework

Reorganize the package from a core/ + commands/ split into the same layered
layout as vct-cribl-cli, so both CLIs expose a consistent API surface:

- api/client.py: layered httpx transport stack (AuthTransport -> RetryTransport
  -> HTTPTransport). Auth is now resolved and injected per request by
  AuthTransport instead of set once at client construction, so a long-running
  embedder re-authenticates transparently when a session key expires.
- api/endpoint_factory.py: generic CRUD engine renamed to EndpointConfig /
  Field / Endpoints (was Spec / CrudResource); scope replaces the namespaced
  flag.
- api/endpoints/: hand-written endpoint modules; api/acs/: Cloud ACS client.
- auth/session.py: credential resolution + login with lazy session-key caching.
- config/ (loader.py, types.py): profile/env/flag merging; SplunkConfig carries
  token/session_key/username/password separately.
- utils/, output/formatter.py, commands/command_factory.py: remaining packages.

Behavior is unchanged: 1023 unit tests pass, ruff/pyright clean, and the CLI is
verified live against Splunk Enterprise 10.4. Adds docs/architecture.md and
updates the AGENTS.md architecture section. .envrc now loads a local .env via
direnv's dotenv_if_exists.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Bring in config read commands (#79) and the Splunk Cloud validation
runbook (#78), adapting imports to the api/endpoints layout.

Co-authored-by: Cursor <cursoragent@cursor.com>
werd-drew and others added 2 commits August 17, 2026 20:10
markdownlint MD040 requires a language on fenced code blocks; the three
plain fences (project tree, transport diagram, config chain) now use ```text.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The per-request session-key cache (added with the transport-stack auth) held a
stale key across a Splunk restart: a restart invalidates session keys
server-side, but the client kept sending the cached one, so every request 401'd
until the 55-minute TTL expired. This broke server-info reconnect polling after
'server restart' (caught by the live enterprise integration suite) and would
break any long-running embedder on username/password auth.

AuthTransport now treats a 401 as a possibly-stale session when the credential
is a username/password (re-mintable): it drops the cache, logs in again, and
retries the request once. A static token or session key is not refreshable, so
its 401 still surfaces immediately.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

@JacobPEvans-personal JacobPEvans-personal left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great, thank you @werd-drew

@JacobPEvans-personal
JacobPEvans-personal merged commit 6012b13 into main Aug 18, 2026
12 checks passed
@JacobPEvans-personal
JacobPEvans-personal deleted the refactor/api-endpoint-framework branch August 18, 2026 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants