mirror of
https://github.com/safedep/pmg.git
synced 2026-08-03 07:24:09 +02:00
feat: add macOS setup script for Jamf deployment (#258)
* feat: add macOS setup script for Jamf deployment Adds scripts/pmg_setup_install.sh that installs/updates pmg (via Homebrew or GitHub releases), runs pmg setup install, and optionally enables cloud sync with credentials stored in macOS Keychain. * feat: add --from-env flag to pmg cloud login Allows non-interactive credential import from SAFEDEP_API_KEY and SAFEDEP_TENANT_ID environment variables. Fails explicitly if either is missing. Used by the setup script for Jamf deployments. * refactor: use cloud.NewEnvCredentialResolver for --from-env Use the dry library's env credential resolver instead of reading env vars directly, keeping env var ownership in the shared library. * update DRY * update go to 1.25 back
This commit is contained in:
+67
-24
@@ -8,41 +8,84 @@ import (
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
var loginFromEnv bool
|
||||
|
||||
func newLoginCommand() *cobra.Command {
|
||||
return &cobra.Command{
|
||||
cmd := &cobra.Command{
|
||||
Use: "login",
|
||||
Short: "Store SafeDep Cloud credentials securely",
|
||||
RunE: runLogin,
|
||||
}
|
||||
|
||||
cmd.Flags().BoolVar(&loginFromEnv, "from-env", false,
|
||||
"Read credentials from SAFEDEP_API_KEY and SAFEDEP_TENANT_ID environment variables")
|
||||
|
||||
return cmd
|
||||
}
|
||||
|
||||
func runLogin(cmd *cobra.Command, args []string) error {
|
||||
tenantID, err := ui.PromptInput("Tenant ID: ")
|
||||
if err != nil {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
Wrap(err).
|
||||
WithCode(usefulerror.ErrCodeLifecycle).
|
||||
WithHumanError("Failed to read Tenant ID"))
|
||||
}
|
||||
var tenantID, apiKey string
|
||||
|
||||
if tenantID == "" {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("Tenant ID cannot be empty"))
|
||||
}
|
||||
if loginFromEnv {
|
||||
resolver, err := cloud.NewEnvCredentialResolver()
|
||||
if err != nil {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
Wrap(err).
|
||||
WithCode(usefulerror.ErrCodeLifecycle).
|
||||
WithHumanError("Failed to create environment credential resolver"))
|
||||
}
|
||||
|
||||
apiKey, err := ui.PromptSecret("API Key: ")
|
||||
if err != nil {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
Wrap(err).
|
||||
WithCode(usefulerror.ErrCodeLifecycle).
|
||||
WithHumanError("Failed to read API Key"))
|
||||
}
|
||||
creds, err := resolver.Resolve()
|
||||
if err != nil {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
Wrap(err).
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("Failed to resolve credentials from environment").
|
||||
WithHelp("Set SAFEDEP_API_KEY and SAFEDEP_TENANT_ID environment variables"))
|
||||
}
|
||||
|
||||
if apiKey == "" {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("API Key cannot be empty"))
|
||||
apiKey, err = creds.GetAPIKey()
|
||||
if err != nil || apiKey == "" {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("SAFEDEP_API_KEY environment variable is not set"))
|
||||
}
|
||||
|
||||
tenantID, err = creds.GetTenantDomain()
|
||||
if err != nil || tenantID == "" {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("SAFEDEP_TENANT_ID environment variable is not set"))
|
||||
}
|
||||
} else {
|
||||
var err error
|
||||
tenantID, err = ui.PromptInput("Tenant ID: ")
|
||||
if err != nil {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
Wrap(err).
|
||||
WithCode(usefulerror.ErrCodeLifecycle).
|
||||
WithHumanError("Failed to read Tenant ID"))
|
||||
}
|
||||
|
||||
if tenantID == "" {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("Tenant ID cannot be empty"))
|
||||
}
|
||||
|
||||
apiKey, err = ui.PromptSecret("API Key: ")
|
||||
if err != nil {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
Wrap(err).
|
||||
WithCode(usefulerror.ErrCodeLifecycle).
|
||||
WithHumanError("Failed to read API Key"))
|
||||
}
|
||||
|
||||
if apiKey == "" {
|
||||
ui.ErrorExit(usefulerror.Useful().
|
||||
WithCode(usefulerror.ErrCodeInvalidArgument).
|
||||
WithHumanError("API Key cannot be empty"))
|
||||
}
|
||||
}
|
||||
|
||||
store, err := cloud.NewKeychainCredentialStore()
|
||||
|
||||
Reference in New Issue
Block a user