diff --git a/.github/copilot-instructions.md b/.github/copilot-instructions.md index a546e9f07..c4f168c9a 100644 --- a/.github/copilot-instructions.md +++ b/.github/copilot-instructions.md @@ -19,7 +19,9 @@ make doc # regenerate doc/ (see Docs below) ``` Refresh a **v1** OpenAPI schema: `make schemas UNIVERSE=` (e.g. `cloud`, `domain`, `vps`). -There is **no** automated refresh for v2 schemas (see "API schemas" below). +Refresh a **v2** one: `make schemas-v2 API= NAME=` (e.g. `API=dedicated/server NAME=baremetal_v2`). +Check one for dead paths: `make schemas-drift NAME= SOURCE=` (e.g. `NAME=baremetal SOURCE=v1/dedicated/server`). +Neither target curates — see "API schemas" below. ## Architecture — the two-file pattern @@ -102,10 +104,16 @@ or users can't drive the new/changed fields. **v1** (`cloud.json`, `me.json`, …): full spec minus `x-code-samples`, refreshed with `make schemas UNIVERSE=`. -**v2** (`cloud_v2.json`): a **hand-curated subset** — only the paths the CLI actually exposes plus -the schemas those paths reference (transitively) and OVH's standard scalar types. There is no `make` -target; it is maintained manually (only public — alpha/beta/stable — paths are curated in, never -`Internal use only` ones). +**v2** (`cloud_v2.json`, `iam.json`, `vrackservices.json`, `vmwareclouddirector*.json`): a +**hand-curated subset** — only the paths the CLI actually exposes plus the schemas those paths +reference (transitively) and OVH's standard scalar types (only public — alpha/beta/stable — paths +are curated in, never `Internal use only` ones). + +`make schemas-v2 API= NAME=` downloads one and prints its maturity breakdown, but it +does **not** curate: deciding what belongs in the subset is a judgement call. Note that the v2 +catalogue addresses APIs by path, not by universe name, and four of these files are v2 documents +stored under a name with no `_v2` suffix — `make schemas UNIVERSE=iam` cannot refresh them, the v1 +URL answers 404. **Gotcha**: in the schema, v2 paths have **no `/v2` prefix** (`/publicCloud/project/{projectId}/rancher`), but the Go HTTP calls and the `schemaPath` argument to `Create/EditResource` also omit `/v2` while the diff --git a/Makefile b/Makefile index 0ed2a2b20..aa68c3cab 100644 --- a/Makefile +++ b/Makefile @@ -30,14 +30,106 @@ release-snapshot: release: goreleaser release --clean +SCHEMAS_DIR = internal/assets/api-schemas +SCHEMAS_ROOT ?= https://eu.api.ovh.com + +# fetch-schema downloads one OpenAPI document and installs it only once it has +# been shown to be one. $(1) is the URL, $(2) the file to write under +# $(SCHEMAS_DIR). +# +# The checks are not decoration. Piping curl straight into jq hides a failure: +# an unreachable host or a proxy that answers nothing writes an empty body and +# curl's exit code is lost to the pipe, jq turns nothing into nothing and exits +# 0, and the mv then installs an empty file over a working schema. An empty +# schema embeds, builds, and ships; it surfaces much later, when a command asks +# it for an enumeration and gets "value of openapi must be a non-empty string" +# instead of a list. A 404 happens to be caught today because jq cannot iterate +# over the error document, which is luck rather than a check. +# +# So the document is downloaded to a file, where curl's own exit code is the one +# being tested, and it has to declare an openapi version and at least one path +# before it may replace anything. +define fetch-schema + @raw=$$(mktemp "$(SCHEMAS_DIR)/$(2).raw.XXXXXX"); \ + out=$$(mktemp "$(SCHEMAS_DIR)/$(2).new.XXXXXX"); \ + trap 'rm -f "$$raw" "$$out"' EXIT INT TERM; \ + curl -fsS "$(1)" -o "$$raw" && \ + jq -e '(.openapi | type) == "string" and (.paths | length) > 0' "$$raw" > /dev/null && \ + jq 'del(.paths[] | .[]["x-code-samples"])' "$$raw" > "$$out" && \ + chmod 644 "$$out" && \ + mv "$$out" "$(SCHEMAS_DIR)/$(2).json" && \ + echo "installed $(SCHEMAS_DIR)/$(2).json ($$(jq '.paths | length' "$(SCHEMAS_DIR)/$(2).json") paths)" +endef + schemas: @if [ -z "$(UNIVERSE)" ]; then echo "Usage: make schemas UNIVERSE= (e.g. cloud, domain, vps)"; exit 1; fi - @tmp=$$(mktemp internal/assets/api-schemas/$(UNIVERSE).json.XXXXXX) && \ - curl -s "https://eu.api.ovh.com/v1/$(UNIVERSE).json?format=openapi3" | jq 'del(.paths[] | .[]["x-code-samples"])' > "$$tmp" && \ - mv "$$tmp" internal/assets/api-schemas/$(UNIVERSE).json + $(call fetch-schema,$(SCHEMAS_ROOT)/v1/$(UNIVERSE).json?format=openapi3,$(UNIVERSE)) + +# schemas-v2 fetches from the other catalogue. It is a separate target because +# the two are addressed differently: v1 is one name per universe, v2 is a path, +# and two of them ("dedicated/server", "publicCloud") do not even resemble the +# file they are stored under. NAME therefore has to be given rather than +# derived, which also keeps the existing cloud_v2.json name reachable. +# +# What this target does NOT do is curate. The v2 schemas in this repository are +# a hand-picked subset of the paths the CLI exposes, and choosing what belongs +# in one is a judgement call, not a transformation. It does print what it just +# pulled in, broken down by maturity badge, because "Internal use only" is the +# one thing a curator has to look at and it is invisible in a 2 MB diff. +# +# The jq program is on one line on purpose. A backslash continuation inside the +# single quotes is not a continuation: make hands the shell a backslash-newline +# the shell will not touch, jq receives a literal backslash and dies with a +# syntax error. And it died AFTER the schema was installed, so the refresh +# succeeded, make reported failure, and the breakdown never printed once. +schemas-v2: + @if [ -z "$(API)" ] || [ -z "$(NAME)" ]; then \ + echo "Usage: make schemas-v2 API= NAME= (e.g. API=dedicated/server NAME=baremetal_v2)"; \ + exit 1; \ + fi + $(call fetch-schema,$(SCHEMAS_ROOT)/v2/$(API).json?format=openapi3,$(NAME)) + @jq -r '[.paths[] | .[] | select(type == "object") | ((.["x-badges"] // [{label: "no badge"}]) | .[] | .label)] | group_by(.) | sort_by(-length) | .[] | " \(length)\t\(.[0])"' "$(SCHEMAS_DIR)/$(NAME).json" + +# schemas-drift answers the question neither refresh target can: an embedded +# schema is a hand-picked subset, so a path present in the catalogue and absent +# from the file is normal curation. The reverse is not — a path this repository +# ships and the catalogue no longer publishes is a route that will 404. +# +# Nothing calls those paths today, so this is a contract defect rather than a +# breakage; it becomes one the day a command is built on a path that has been +# gone for a year. +# +# The `|| exit 1` on the orphan list is what stops this target from doing the +# thing it exists to prevent. A command substitution captures stdout only: with +# an unreadable NAME, jq's complaint goes to stderr, the capture is empty, and +# the recipe printed "no embedded path is missing from the catalogue" and exited +# 0. A typo in NAME bought a clean bill of health. Measured 20 August 2026: baremetal.json alone carries five, +# two of them badged "Stable production version", and every one probed against +# the live API answers 404 — including under the method it declares. +schemas-drift: + @if [ -z "$(NAME)" ] || [ -z "$(SOURCE)" ]; then \ + echo "Usage: make schemas-drift NAME= SOURCE="; \ + echo " e.g. make schemas-drift NAME=baremetal SOURCE=v1/dedicated/server"; \ + exit 1; \ + fi + @live=$$(mktemp); \ + trap 'rm -f "$$live"' EXIT INT TERM; \ + curl -fsS "$(SCHEMAS_ROOT)/$(SOURCE).json?format=openapi3" -o "$$live" && \ + jq -e '(.paths | length) > 0' "$$live" > /dev/null || { echo "the catalogue answered nothing usable"; exit 1; }; \ + echo "$(NAME).json: $$(jq '.paths | length' "$(SCHEMAS_DIR)/$(NAME).json") paths embedded, $$(jq '.paths | length' "$$live") published by $(SOURCE)"; \ + orphans=$$(jq -r -n --slurpfile a "$(SCHEMAS_DIR)/$(NAME).json" --slurpfile b "$$live" \ + '($$a[0].paths | keys) - ($$b[0].paths | keys) | .[]') \ + || { echo " could not read $(SCHEMAS_DIR)/$(NAME).json"; exit 1; }; \ + if [ -z "$$orphans" ]; then \ + echo " no embedded path is missing from the catalogue"; \ + else \ + echo " embedded but not published — these will 404:"; \ + echo "$$orphans" | sed 's/^/ /'; \ + fi + setup: curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/latest/download/prek-installer.sh | sh prek install -.PHONY: all wasm doc schemas setup +.PHONY: all wasm doc schemas schemas-v2 schemas-drift setup diff --git a/doc/ovhcloud.md b/doc/ovhcloud.md index 7d79d6150..acad5f7fc 100644 --- a/doc/ovhcloud.md +++ b/doc/ovhcloud.md @@ -1,90 +1,36 @@ -# OVHcloud CLI (`ovhcloud`) Documentation +## ovhcloud ---- +CLI to manage your OVHcloud services -## Overview +### Options -`ovhcloud` is a single, unified command‑line interface for managing the full range of OVHcloud products and account resources directly from your terminal. Whether you need to automate provisioning, perform quick look‑ups, or integrate OVHcloud operations into CI/CD pipelines, `ovhcloud` offers fine‑grained commands and consistent output formats (table, JSON, YAML, or custom gval expressions). - ---- - -## Quick Start - -```bash -# Display the top‑level help -ovhcloud --help - -# Log in and create API credentials (interactive) -ovhcloud login - -# List your VPS instances as JSON -ohvcloud vps list -o json -``` - -Check out the [authentication page](authentication.md) for further information about the authentication means. - -You can manage multiple OVHcloud accounts using [profiles](profiles.md). Create a profile with `ovhcloud login --profile `, switch between them with `ovhcloud config profile switch `, or use `--profile ` on any command. - -### Generate Shell Completion - -```bash -# Bash -eval "$(./ovhcloud completion bash)" -# Zsh -eval "$(./ovhcloud completion zsh)" -# Fish -./ovhcloud completion fish | source -# PowerShell -./ovhcloud completion powershell | Out-String | Invoke-Expression ``` - -Add the appropriate line to your shell’s startup file (`~/.bashrc`, `~/.zshrc`, etc.) to enable persistent autocompletion. - ---- - -## Global Usage - -```text -ovhcloud [command] [flags] + -d, --debug Activate debug mode (will log all HTTP requests details) + -h, --help help for ovhcloud + -e, --ignore-errors Ignore errors in API calls when it is not fatal to the execution + -o, --output string Output format: json, yaml, interactive, or a custom format expression (using https://github.com/PaesslerAG/gval syntax) + Examples: + --output json + --output yaml + --output interactive + --output 'id' (to extract a single field) + --output 'nested.field.subfield' (to extract a nested field) + --output '[id, "name"]' (to extract multiple fields as an array) + --output '{"newKey": oldKey, "otherKey": nested.field}' (to extract and rename fields in an object) + --output 'name+","+type' (to extract and concatenate fields in a string) + --output '(nbFieldA + nbFieldB) * 10' (to compute values from numeric fields) + --profile string Use a specific profile from the configuration file ``` -### Global Flags - -| Flag | Description | -| ------------------ | ---------------------------------------------------- | -| `--debug` | Activate debug mode (logs all HTTP‑request details). | -| `--ignore-errors` | Ignore errors of API calls made when listing items. | -| `--filter ` | Filter lists output with a [gval] expression. | -| `-h`, `--help` | Display help for `ovhcloud` or a specific command. | -| `-o interactive` | Produce interactive (prompt‑based) output. | -| `-o json` | Output data in JSON format. | -| `-o yaml` | Output data in YAML format. | -| `-o ` | Format output with a [gval] expression. | - -[gval]: https://github.com/PaesslerAG/gval - -#### Filtering examples - -- Strict string equality: `--filter 'name=="something"'` -- String regexp comparison: `--filter 'name=~"something"'` -- Number comparison: `--filter 'bootId > 1'` - -#### Formatting example - -- Extract only one field: `-o 'ip'` -- Extract an object: `-o '{name: ip}'` - ---- - -## Command Reference - -Below is the full list of primary sub‑commands available at the time of writing. Each can be explored in depth with `ovhcloud --help`. +### SEE ALSO * [ovhcloud account](ovhcloud_account.md) - Manage your account * [ovhcloud alldom](ovhcloud_alldom.md) - Retrieve information and manage your AllDom services * [ovhcloud baremetal](ovhcloud_baremetal.md) - Retrieve information and manage your Bare Metal services +* [ovhcloud browser](ovhcloud_browser.md) - Launch a TUI for the OVHcloud Manager - Public Cloud universe only [EXPERIMENTAL] * [ovhcloud cdn-dedicated](ovhcloud_cdn-dedicated.md) - Retrieve information and manage your dedicated CDN services * [ovhcloud cloud](ovhcloud_cloud.md) - Manage your projects and services in the Public Cloud universe (MKS, MPR, MRS, Object Storage...) +* [ovhcloud completion](ovhcloud_completion.md) - Generate shell completion scripts * [ovhcloud config](ovhcloud_config.md) - Manage your CLI configuration * [ovhcloud dedicated-ceph](ovhcloud_dedicated-ceph.md) - Retrieve information and manage your Dedicated Ceph services * [ovhcloud dedicated-cloud](ovhcloud_dedicated-cloud.md) - Retrieve information and manage your DedicatedCloud services @@ -102,6 +48,7 @@ Below is the full list of primary sub‑commands available at the time of writin * [ovhcloud ldp](ovhcloud_ldp.md) - Retrieve information and manage your LDP (Logs Data Platform) services * [ovhcloud location](ovhcloud_location.md) - Retrieve information and manage your Location services * [ovhcloud login](ovhcloud_login.md) - Login to your OVHcloud account to create API credentials +* [ovhcloud logout](ovhcloud_logout.md) - Revoke your API credentials and remove them from the configuration * [ovhcloud nutanix](ovhcloud_nutanix.md) - Retrieve information and manage your Nutanix services * [ovhcloud okms](ovhcloud_okms.md) - Retrieve information and manage your OKMS (Key Management Services) * [ovhcloud overthebox](ovhcloud_overthebox.md) - Retrieve information and manage your OverTheBox services @@ -113,6 +60,7 @@ Below is the full list of primary sub‑commands available at the time of writin * [ovhcloud storage-netapp](ovhcloud_storage-netapp.md) - Retrieve information and manage your Storage NetApp services * [ovhcloud support-tickets](ovhcloud_support-tickets.md) - Retrieve information and manage your support tickets * [ovhcloud telephony](ovhcloud_telephony.md) - Retrieve information and manage your Telephony services +* [ovhcloud upgrade](ovhcloud_upgrade.md) - Upgrade OVHcloud CLI to the latest version * [ovhcloud veeamcloudconnect](ovhcloud_veeamcloudconnect.md) - Retrieve information and manage your VeeamCloudConnect services * [ovhcloud veeamenterprise](ovhcloud_veeamenterprise.md) - Retrieve information and manage your VeeamEnterprise services * [ovhcloud version](ovhcloud_version.md) - Get OVHcloud CLI version @@ -124,30 +72,3 @@ Below is the full list of primary sub‑commands available at the time of writin * [ovhcloud webhosting](ovhcloud_webhosting.md) - Retrieve information and manage your WebHosting services * [ovhcloud xdsl](ovhcloud_xdsl.md) - Retrieve information and manage your XDSL services -> **Tip**  Use `-o json`, `-o yaml`, or `-o ` with a gval expression to integrate `ovhcloud` into scripts and automation pipelines. - ---- - -## Examples - -| Task | Command | -| ------------------------------------- | ---------------------------------------------- | -| Log in and save credentials | `ovhcloud login` | -| List VPS instances (tabular) | `ovhcloud vps list` | -| Fetch details of a single VPS in JSON | `ovhcloud vps get -o json` | -| Reinstall a baremetal interactively | `ovhcloud baremetal reinstall --editor` | - ---- - -## Troubleshooting - -* **Verbose output** — Use `--debug` to inspect raw API calls and responses. -* **Authentication issues** — Run `ovhcloud login` again to regenerate valid API keys. -* **Rate limits** — OVHcloud APIs impose rate limits; plan retries or exponential backoff in scripts. - ---- - -## Further Reading - -* OVHcloud API reference: [https://eu.api.ovh.com/console](https://eu.api.ovh.com/console) -* OVHcloud community guides and tutorials. diff --git a/doc/ovhcloud_logout.md b/doc/ovhcloud_logout.md new file mode 100644 index 000000000..c78e5c513 --- /dev/null +++ b/doc/ovhcloud_logout.md @@ -0,0 +1,46 @@ +## ovhcloud logout + +Revoke your API credentials and remove them from the configuration + +``` +ovhcloud logout [flags] +``` + +### Examples + +``` +ovhcloud logout +ovhcloud logout --yes +ovhcloud logout --profile work +``` + +### Options + +``` + -h, --help help for logout + -y, --yes Do not ask for confirmation +``` + +### Options inherited from parent commands + +``` + -d, --debug Activate debug mode (will log all HTTP requests details) + -e, --ignore-errors Ignore errors in API calls when it is not fatal to the execution + -o, --output string Output format: json, yaml, interactive, or a custom format expression (using https://github.com/PaesslerAG/gval syntax) + Examples: + --output json + --output yaml + --output interactive + --output 'id' (to extract a single field) + --output 'nested.field.subfield' (to extract a nested field) + --output '[id, "name"]' (to extract multiple fields as an array) + --output '{"newKey": oldKey, "otherKey": nested.field}' (to extract and rename fields in an object) + --output 'name+","+type' (to extract and concatenate fields in a string) + --output '(nbFieldA + nbFieldB) * 10' (to compute values from numeric fields) + --profile string Use a specific profile from the configuration file +``` + +### SEE ALSO + +* [ovhcloud](ovhcloud.md) - CLI to manage your OVHcloud services + diff --git a/internal/assets/assets_test.go b/internal/assets/assets_test.go new file mode 100644 index 000000000..fd437ad08 --- /dev/null +++ b/internal/assets/assets_test.go @@ -0,0 +1,114 @@ +// SPDX-FileCopyrightText: 2026 OVH SAS +// +// SPDX-License-Identifier: Apache-2.0 + +//go:build !(js && wasm) + +package assets + +import ( + "context" + "embed" + "io/fs" + "path" + "testing" + + "github.com/getkin/kin-openapi/openapi3" +) + +// The whole directory is embedded here, not the *.json inside it, so that a +// file which is not a schema still reaches the test. A refresh that failed +// halfway used to leave one behind, and a leftover nobody sees is a leftover +// somebody commits. +// +//go:embed api-schemas +var schemaFiles embed.FS + +// knownInvalidSchemas are the specifications the API publishes in a state the +// OpenAPI validator rejects. They are named here rather than skipped silently, +// and the test below insists they still fail: the day one is fixed upstream, +// this list goes red and asks to be shortened. +// +// telephony.json: two POST operations, on +// /telephony/{billingAccount}/easyHunting/{serviceName}/hunting/queue/{queueId}/agent +// and its ovhPabx twin, declare billingAccount and serviceName as path +// parameters and not queueId, which the specification requires. The validator +// reports the first one it meets, so fixing one alone changes nothing. The +// whole document is unusable as a result, and `ovhcloud telephony edit` fails +// at the schema-filtering step for every account — see +// internal/services/telephony. Reported upstream. +var knownInvalidSchemas = map[string]string{ + "telephony.json": "two POST .../hunting/queue/{queueId}/agent do not declare queueId", +} + +// TestEmbeddedSchemasAreSchemas reads every embedded specification the way the +// CLI reads it. +// +// Nothing else in the build looks inside these files. `go:embed` is happy with +// an empty one, `go build` is happy with an empty one, and so is `go vet`; the +// first thing that is not happy is a command asking for an enumeration at +// runtime, which answers "value of openapi must be a non-empty string" to +// somebody who typed a server name. Refreshing a schema over a broken network +// used to produce exactly that, silently and with a zero exit code. +func TestEmbeddedSchemasAreSchemas(t *testing.T) { + entries, err := fs.ReadDir(schemaFiles, "api-schemas") + if err != nil { + t.Fatalf("failed to list the embedded schemas: %s", err) + } + + if len(entries) == 0 { + t.Fatal("no schema is embedded, which cannot be right") + } + + for _, entry := range entries { + t.Run(entry.Name(), func(t *testing.T) { + if entry.IsDir() { + t.Fatalf("%s is a directory; the schemas are flat files", entry.Name()) + } + + // A refresh writes through a temporary file named after the schema + // with a random suffix. Anything that is not a .json here is either + // one of those, or something nobody meant to ship. + if path.Ext(entry.Name()) != ".json" { + t.Fatalf("%s is not a .json file; a failed schema refresh leaves one of these behind", entry.Name()) + } + + content, err := schemaFiles.ReadFile("api-schemas/" + entry.Name()) + if err != nil { + t.Fatalf("failed to read %s: %s", entry.Name(), err) + } + + if len(content) == 0 { + t.Fatalf("%s is empty", entry.Name()) + } + + doc, err := openapi3.NewLoader().LoadFromData(content) + if err != nil { + t.Fatalf("%s does not parse as an OpenAPI document: %s", entry.Name(), err) + } + + // Parsing alone accepts "{}", and an empty object embeds and builds + // exactly like a real schema. These two are what a document has to + // carry for anything to be looked up inside it. + if doc.OpenAPI == "" { + t.Fatalf("%s declares no OpenAPI version", entry.Name()) + } + if doc.Paths == nil || doc.Paths.Len() == 0 { + t.Fatalf("%s declares no path, so nothing can be looked up in it", entry.Name()) + } + + // The validation internal/openapi runs before it can read anything + // out of a schema. One document fails it today, upstream, and that + // is recorded rather than hidden. + err = doc.Validate(context.Background()) + reason, known := knownInvalidSchemas[entry.Name()] + + switch { + case err != nil && !known: + t.Fatalf("%s does not validate as an OpenAPI document: %s", entry.Name(), err) + case err == nil && known: + t.Fatalf("%s validates now (%q was the reason it did not); remove it from knownInvalidSchemas", entry.Name(), reason) + } + }) + } +} diff --git a/internal/cmd/baremetal.go b/internal/cmd/baremetal.go index 28fef787b..a8dc9bf18 100644 --- a/internal/cmd/baremetal.go +++ b/internal/cmd/baremetal.go @@ -11,7 +11,6 @@ import ( "github.com/ovh/ovhcloud-cli/internal/completion" "github.com/ovh/ovhcloud-cli/internal/flags" "github.com/ovh/ovhcloud-cli/internal/services/baremetal" - "github.com/ovh/ovhcloud-cli/internal/services/common" "github.com/ovh/ovhcloud-cli/internal/services/vrack" "github.com/spf13/cobra" ) @@ -124,7 +123,7 @@ they are not sold from the public price list, and show as "on quotation".`, ValidArgsFunction: completion.ServiceList("/v1/dedicated/server"), Run: baremetal.EditBaremetalServiceInfo, } - common.AddServiceInfoRenewFlags(baremetalServiceInfoEditCmd) + addServiceInfoRenewFlags(baremetalServiceInfoEditCmd) addInteractiveEditorFlag(baremetalServiceInfoEditCmd) baremetalServiceInfoCmd.AddCommand(baremetalServiceInfoEditCmd) diff --git a/internal/cmd/dry_run_log_test.go b/internal/cmd/dry_run_log_test.go new file mode 100644 index 000000000..fcf9f15f3 --- /dev/null +++ b/internal/cmd/dry_run_log_test.go @@ -0,0 +1,68 @@ +// SPDX-FileCopyrightText: 2025 OVH SAS +// +// SPDX-License-Identifier: Apache-2.0 + +// Ces deux tests vivent dans leur propre fichier, et non dans +// baremetal_test.go, pour une raison mecanique : 23 branches en aval ajoutent +// elles aussi des tests juste apres TestBaremetalReinstallDryRun et dans le +// meme bloc d'imports. Les y placer a fait echouer les 23 merges d'un coup, sur +// une adjacence et non sur un desaccord. Un fichier neuf ne peut entrer en +// collision qu'avec un fichier de meme nom. + +package cmd_test + +import ( + "bytes" + "log" + + "github.com/jarcoal/httpmock" + "github.com/maxatome/go-testdeep/td" + "github.com/ovh/ovhcloud-cli/internal/cmd" +) + +// A dry run prints the payload once. It used to print it twice: the message +// carries it, and a log.Println just above the --dry-run branch repeated the +// same JSON behind a Go timestamp no other command in this CLI emits. +// +// 🔍 Dry run: nothing was sent. This would have been posted to … +// { "operatingSystem": "debian12_64" } +// 2026/08/23 23:47:22 Final parameters: +// { "operatingSystem": "debian12_64" } +// +// The log line goes to stderr, so no assertion on stdout could ever have seen +// it — which is why it survived every green run. This one redirects the logger. +func (ms *MockSuite) TestBaremetalReinstallDryRunDoesNotLogTheParametersTwice(assert, require *td.T) { + httpmock.RegisterResponder("POST", "https://eu.api.ovh.com/v1/dedicated/server/fakeBaremetal/reinstall", + httpmock.NewStringResponder(200, `{"taskId": 123}`), + ) + var logged bytes.Buffer + previous := log.Writer() + log.SetOutput(&logged) + defer log.SetOutput(previous) + + out, err := cmd.Execute("baremetal", "reinstall", "fakeBaremetal", "--os", "debian12_64", "--dry-run") + + require.CmpNoError(err) + assert.Cmp(out, td.Contains(`"operatingSystem": "debian12_64"`), + "the payload is still printed, once, as the message") + assert.Cmp(logged.String(), td.Not(td.Contains("Final parameters")), + "a dry run logs nothing: it sends nothing") +} + +// The positive control of the test above: a REAL run still logs what it is +// about to send. Without it, deleting the log line altogether would pass. +func (ms *MockSuite) TestBaremetalReinstallStillLogsTheParametersItSends(assert, require *td.T) { + httpmock.RegisterResponder("POST", "https://eu.api.ovh.com/v1/dedicated/server/fakeBaremetal/reinstall", + httpmock.NewStringResponder(200, `{"taskId": 123}`), + ) + var logged bytes.Buffer + previous := log.Writer() + log.SetOutput(&logged) + defer log.SetOutput(previous) + + _, err := cmd.Execute("baremetal", "reinstall", "fakeBaremetal", "--os", "debian12_64", "--yes") + + require.CmpNoError(err) + assert.Cmp(logged.String(), td.Contains("Final parameters")) + assert.Cmp(logged.String(), td.Contains(`"operatingSystem": "debian12_64"`)) +} diff --git a/internal/cmd/ip.go b/internal/cmd/ip.go index 934850875..737f34e1f 100644 --- a/internal/cmd/ip.go +++ b/internal/cmd/ip.go @@ -7,7 +7,6 @@ package cmd import ( "github.com/ovh/ovhcloud-cli/internal/assets" "github.com/ovh/ovhcloud-cli/internal/completion" - "github.com/ovh/ovhcloud-cli/internal/services/common" "github.com/ovh/ovhcloud-cli/internal/services/ip" "github.com/spf13/cobra" ) @@ -192,7 +191,7 @@ func init() { ValidArgsFunction: completion.ServiceList("/v1/ip/service"), Run: ip.EditIpServiceInfo, } - common.AddServiceInfoRenewFlags(ipServiceInfoEditCmd) + addServiceInfoRenewFlags(ipServiceInfoEditCmd) addInteractiveEditorFlag(ipServiceInfoEditCmd) ipServiceInfoCmd.AddCommand(ipServiceInfoEditCmd) diff --git a/internal/cmd/service_info.go b/internal/cmd/service_info.go new file mode 100644 index 000000000..e08a19d1b --- /dev/null +++ b/internal/cmd/service_info.go @@ -0,0 +1,28 @@ +// SPDX-FileCopyrightText: 2025 OVH SAS +// +// SPDX-License-Identifier: Apache-2.0 + +package cmd + +import ( + "github.com/ovh/ovhcloud-cli/internal/services/common" + "github.com/spf13/cobra" +) + +// addServiceInfoRenewFlags registers the renewal flags on a `service-info edit` +// command. +// +// It sits here, beside the other shared flag helpers, rather than in the +// service package: declaring cobra flags is the command layer's job, and +// internal/services/common was the only service package doing it. The flag +// names still come from common.ServiceInfoRenewFlags, which is also what the +// payload builder reads — one table, so the two halves cannot drift. +func addServiceInfoRenewFlags(cmd *cobra.Command) { + for _, flag := range common.ServiceInfoRenewFlags { + if flag.Period { + cmd.Flags().Int(flag.Name, 0, flag.Usage) + continue + } + cmd.Flags().Bool(flag.Name, false, flag.Usage) + } +} diff --git a/internal/cmd/vps.go b/internal/cmd/vps.go index f452ef0c6..f112381a0 100644 --- a/internal/cmd/vps.go +++ b/internal/cmd/vps.go @@ -11,7 +11,6 @@ import ( "github.com/ovh/ovhcloud-cli/internal/assets" "github.com/ovh/ovhcloud-cli/internal/completion" "github.com/ovh/ovhcloud-cli/internal/flags" - "github.com/ovh/ovhcloud-cli/internal/services/common" "github.com/ovh/ovhcloud-cli/internal/services/vps" "github.com/spf13/cobra" ) @@ -221,7 +220,7 @@ func init() { ValidArgsFunction: completion.ServiceList("/v1/vps"), Run: vps.EditVpsServiceInfo, } - common.AddServiceInfoRenewFlags(serviceInfoEditCmd) + addServiceInfoRenewFlags(serviceInfoEditCmd) addInteractiveEditorFlag(serviceInfoEditCmd) serviceInfoCmd.AddCommand(serviceInfoEditCmd) diff --git a/internal/cmd/webhosting.go b/internal/cmd/webhosting.go index 7e5096d0f..e98a7e7f7 100644 --- a/internal/cmd/webhosting.go +++ b/internal/cmd/webhosting.go @@ -10,7 +10,6 @@ import ( "strings" "github.com/ovh/ovhcloud-cli/internal/completion" - "github.com/ovh/ovhcloud-cli/internal/services/common" "github.com/ovh/ovhcloud-cli/internal/services/webhosting" "github.com/spf13/cobra" ) @@ -605,7 +604,7 @@ func init() { ValidArgsFunction: completion.ServiceList("/v1/hosting/web"), Run: webhosting.UpdateExtraSqlServiceInfo, } - common.AddServiceInfoRenewFlags(extraSQLServiceInfoUpdateCmd) + addServiceInfoRenewFlags(extraSQLServiceInfoUpdateCmd) addParameterFileFlags(extraSQLServiceInfoUpdateCmd, true, nil, "", "", "", nil) addInteractiveEditorFlag(extraSQLServiceInfoUpdateCmd) extraSQLServiceInfoCmd.AddCommand(extraSQLServiceInfoUpdateCmd) @@ -1326,7 +1325,7 @@ func init() { ValidArgsFunction: completion.ServiceList("/v1/hosting/web"), Run: webhosting.UpdateCdnServiceInfo, } - common.AddServiceInfoRenewFlags(cdnServiceInfoUpdateCmd) + addServiceInfoRenewFlags(cdnServiceInfoUpdateCmd) addParameterFileFlags(cdnServiceInfoUpdateCmd, true, nil, "", "", "", nil) addInteractiveEditorFlag(cdnServiceInfoUpdateCmd) cdnServiceInfoCmd.AddCommand(cdnServiceInfoUpdateCmd) @@ -1460,7 +1459,7 @@ func init() { ValidArgsFunction: completion.ServiceList("/v1/hosting/web"), Run: webhosting.UpdateServiceInfo, } - common.AddServiceInfoRenewFlags(serviceInfoUpdateCmd) + addServiceInfoRenewFlags(serviceInfoUpdateCmd) addParameterFileFlags(serviceInfoUpdateCmd, true, nil, "", "", "", nil) addInteractiveEditorFlag(serviceInfoUpdateCmd) serviceInfoCmd.AddCommand(serviceInfoUpdateCmd) @@ -1571,7 +1570,7 @@ func init() { ValidArgsFunction: completion.ServiceList("/v1/hosting/web"), Run: webhosting.UpdateLocalSeoLocationServiceInfo, } - common.AddServiceInfoRenewFlags(localSeoLocationServiceInfoUpdateCmd) + addServiceInfoRenewFlags(localSeoLocationServiceInfoUpdateCmd) addParameterFileFlags(localSeoLocationServiceInfoUpdateCmd, true, nil, "", "", "", nil) addInteractiveEditorFlag(localSeoLocationServiceInfoUpdateCmd) localSeoLocationServiceInfoCmd.AddCommand(localSeoLocationServiceInfoUpdateCmd) diff --git a/internal/services/common/common.go b/internal/services/common/common.go index 7bf12c982..86b8db26a 100644 --- a/internal/services/common/common.go +++ b/internal/services/common/common.go @@ -201,8 +201,6 @@ func CreateResource(cmd *cobra.Command, path, endpoint, defaultExample string, return nil, fmt.Errorf("parameters cannot be marshalled: %w", err) } - log.Println("Final parameters: \n" + string(out)) - // --dry-run stops here: the caller sees exactly what would have been sent, // and nothing reaches the API. if flags.DryRun { @@ -221,6 +219,19 @@ func CreateResource(cmd *cobra.Command, path, endpoint, defaultExample string, return nil, nil } + // Logged only once the dry run is ruled out. A --dry-run already prints the + // payload as its message, so logging it here printed the same JSON twice, + // the second time behind a Go timestamp no other command in this CLI emits: + // + // 🔍 Dry run: nothing was sent. This would have been posted to … + // { "operatingSystem": "debian12_64" } + // 2026/08/23 23:47:22 Final parameters: + // { "operatingSystem": "debian12_64" } + // + // A real run still logs what it is about to send, which is what this line + // was for. + log.Println("Final parameters: \n" + string(out)) + var createdResource map[string]any if err := httpLib.Client.Post(endpoint, parameters, &createdResource); err != nil { return nil, fmt.Errorf("error creating resource: %w", err) diff --git a/internal/services/common/service_info.go b/internal/services/common/service_info.go index 9ce0b4c5b..b678696f0 100644 --- a/internal/services/common/service_info.go +++ b/internal/services/common/service_info.go @@ -6,35 +6,31 @@ package common import "github.com/spf13/cobra" -// The renewal flags shared by every `service-info edit` command, paired with -// the field each one sets in the API object. -// -// The registration and the payload builder live side by side on purpose: the -// flag name is the only thing that ties them together, so a rename that -// touches one and not the other would silently stop sending a setting rather -// than fail to compile. -var serviceInfoRenewFlags = []struct { - name string - field string - usage string -}{ - {"renew-automatic", "automatic", "Renew the service automatically"}, - {"renew-delete-at-expiration", "deleteAtExpiration", "Delete the service when it expires"}, - {"renew-forced", "forced", "Force the renewal"}, - {"renew-manual-payment", "manualPayment", "Pay the renewal manually"}, - {"renew-period", "period", "Renewal period, in months"}, +// ServiceInfoRenewFlag describes one renewal flag: what it is called on the +// command line, and which field of the API object it sets. +type ServiceInfoRenewFlag struct { + Name string + Field string + Usage string + + // Period is the one flag that carries a number rather than a yes or no. + Period bool } -// AddServiceInfoRenewFlags registers the renewal flags on a `service-info -// edit` command. -func AddServiceInfoRenewFlags(cmd *cobra.Command) { - for _, flag := range serviceInfoRenewFlags { - if flag.field == "period" { - cmd.Flags().Int(flag.name, 0, flag.usage) - continue - } - cmd.Flags().Bool(flag.name, false, flag.usage) - } +// ServiceInfoRenewFlags is the single description of the renewal flags shared +// by every `service-info edit` command. +// +// It is exported rather than kept private because the command layer registers +// the flags and this layer reads them back: the flag name is the only thing +// tying the two halves together, so they must not each hold their own copy of +// it. One table, read twice — a rename in it changes both sides at once, and a +// rename anywhere else does not compile. +var ServiceInfoRenewFlags = []ServiceInfoRenewFlag{ + {Name: "renew-automatic", Field: "automatic", Usage: "Renew the service automatically"}, + {Name: "renew-delete-at-expiration", Field: "deleteAtExpiration", Usage: "Delete the service when it expires"}, + {Name: "renew-forced", Field: "forced", Usage: "Force the renewal"}, + {Name: "renew-manual-payment", Field: "manualPayment", Usage: "Pay the renewal manually"}, + {Name: "renew-period", Field: "period", Usage: "Renewal period, in months", Period: true}, } // ServiceInfoRenewPayload returns the renewal settings the operator actually @@ -53,25 +49,25 @@ func AddServiceInfoRenewFlags(cmd *cobra.Command) { func ServiceInfoRenewPayload(cmd *cobra.Command) map[string]any { renew := map[string]any{} - for _, flag := range serviceInfoRenewFlags { - if !cmd.Flags().Changed(flag.name) { + for _, flag := range ServiceInfoRenewFlags { + if !cmd.Flags().Changed(flag.Name) { continue } - if flag.field == "period" { - period, err := cmd.Flags().GetInt(flag.name) + if flag.Period { + period, err := cmd.Flags().GetInt(flag.Name) if err != nil { continue } - renew[flag.field] = period + renew[flag.Field] = period continue } - value, err := cmd.Flags().GetBool(flag.name) + value, err := cmd.Flags().GetBool(flag.Name) if err != nil { continue } - renew[flag.field] = value + renew[flag.Field] = value } if len(renew) == 0 {