feat(pipeline): register 3-stage ops-audit pipeline definitions and wire super-cli prune command

This commit is contained in:
operator
2026-10-04 17:23:28 +00:00
parent 2b19d2cb45
commit 33a0f295b6
5 changed files with 156 additions and 1 deletions
+102
View File
@@ -1866,6 +1866,76 @@ def cmd_web_sync(args):
print_table(headers, rows)
print()
# ---------------------------------------------------------------------------
# Domain: CRED (Credentials & Onboarding Client)
# ---------------------------------------------------------------------------
def cmd_cred_initiate(args):
import cred_client
client = cred_client.CredClient()
res = client.initiate(args.node, args.email, service=getattr(args, "service", "muse"), account_name=getattr(args, "account_name", None))
if getattr(args, "json", False):
print(json.dumps(res, indent=2))
else:
st = res.get("status")
if st == "awaiting_otp":
print("\n" + c_warn(f"[APPROVAL_NEEDED] Code sent to {args.email} for node '{args.node}'.") + "\n")
print(f" Submit OTP with: super cred submit-otp --node {args.node} --otp <code>\n")
sys.exit(2)
elif st == "active":
print("\n" + c_ok(f"[SUCCESS] Node '{args.node}' is already authenticated and active.") + "\n")
else:
print(f"[{st.upper()}] {res.get('message') or res.get('detail')}")
sys.exit(res.get("code", 1))
def cmd_cred_submit_otp(args):
import cred_client
client = cred_client.CredClient()
res = client.submit_otp(args.node, args.otp, email=getattr(args, "email", None))
if getattr(args, "json", False):
print(json.dumps(res, indent=2))
else:
st = res.get("status")
if st == "active":
print("\n" + c_ok(f"[SUCCESS] Node '{args.node}' successfully signed in!") + "\n")
else:
print(f"[{st.upper()}] {res.get('message') or res.get('detail')}")
sys.exit(res.get("code", 1))
def cmd_cred_status(args):
import cred_client
client = cred_client.CredClient()
res = client.status(args.node)
if getattr(args, "json", False):
print(json.dumps(res, indent=2))
else:
print("\n" + c_bold(f"=== CRED STATUS: {args.node} ===") + "\n")
print(f" Node : {c_bold(res['node'])}")
print(f" Email : {res['email']}")
print(f" Status : {res['status']}")
print(f" CDP Port : {res['cdp_port'] or '-'}")
alive_b = badge_ok("YES") if res['session_alive'] else badge_warn("NO")
print(f" Session Alive: {alive_b}")
if res["detail"]:
print(f" Detail : {c_dim(res['detail'])}")
print()
def cmd_cred_list(args):
import cred_client
client = cred_client.CredClient()
items = client.list_all()
if getattr(args, "json", False):
print(json.dumps(items, indent=2))
else:
print("\n" + c_bold("=== FLEET CREDENTIAL & ONBOARDING STATUS ===") + "\n")
headers = ["NODE", "STATUS", "CDP", "ALIVE", "EMAIL"]
rows = []
for it in items:
alive_b = badge_ok("YES") if it["session_alive"] else badge_warn("NO")
rows.append([c_bold(it['node']), it['status'], str(it['cdp_port'] or '-'), alive_b, it['email']])
print_table(headers, rows)
print()
# ---------------------------------------------------------------------------
# Domain: HARVEST (Response & Readback Harvester)
# ---------------------------------------------------------------------------
@@ -2929,6 +2999,26 @@ def build_parser():
web_sub.add_parser("test-auth", parents=[common], help="Verify operator auth gating on the VM")
web_sub.add_parser("sync", parents=[common], help="Check local log size and sync integrity")
# Domain: CRED
p_cred = subparsers.add_parser("cred", parents=[common], help="Credential console API & client onboarding")
cred_sub = p_cred.add_subparsers(dest="action")
p_c_init = cred_sub.add_parser("initiate", parents=[common], help="Initiate onboarding flow for a node")
p_c_init.add_argument("--node", required=True, help="Node label (e.g. opm, pip, 646)")
p_c_init.add_argument("--email", required=True, help="Client login email")
p_c_init.add_argument("--service", default="muse", help="Service name (default: muse)")
p_c_init.add_argument("--account-name", default=None, help="Display name hint for multi-account selector")
p_c_otp = cred_sub.add_parser("submit-otp", parents=[common], help="Submit transient OTP verification code")
p_c_otp.add_argument("--node", required=True, help="Node label")
p_c_otp.add_argument("--otp", required=True, help="6-digit verification code")
p_c_otp.add_argument("--email", default=None, help="Client email (optional)")
p_c_stat = cred_sub.add_parser("status", parents=[common], help="Query onboarding & vitality status for a node")
p_c_stat.add_argument("--node", required=True, help="Node label")
cred_sub.add_parser("list", parents=[common], help="List all registered nodes and vitality statuses")
# Domain: HARVEST
p_harvest = subparsers.add_parser("harvest", parents=[common], help="Readback & response harvesting engine")
harvest_sub = p_harvest.add_subparsers(dest="action")
@@ -3191,6 +3281,18 @@ def main():
cmd_web_sync(args)
else:
parser.print_help()
elif args.domain == "cred":
act = getattr(args, "action", None)
if not act or act == "list":
cmd_cred_list(args)
elif act == "initiate":
cmd_cred_initiate(args)
elif act == "submit-otp":
cmd_cred_submit_otp(args)
elif act == "status":
cmd_cred_status(args)
else:
parser.print_help()
elif args.domain == "harvest":
act = getattr(args, "action", None)
if not act or act == "status":