A namespace aware key/value store and logging tool. Built for Gitlab CI, GitHub Actions and any tool supporting JWT job tokens authentication.
We built this tool because CI Job caches, artifacts shared between jobs, state storage between jobs and pipelines are all very difficult. For years we stood up Redis for our runners. We decided to make it more user friendly and add better controls around permissions and namespacing.
For commands like:
cih kv <get/set/delete> <namespace> <key> ...
cih log <debug/info/warn/error> <namespace> <message>
We support the following namespaces:
stages:
- deploy-dev
deploy dev:
id_tokens:
CIH_ID_TOKEN:
aud: https://lab.synci.cloud
image: reflexi/cih:latest
stage: deploy-dev
environment:
name: dev
script:
- cih log info pipeline "job starting"
- cih whoami
- cih kv pipeline set foo '{"key":"val"}'
- cih kv pipeline get foo
- cih kv pipeline list
- cih kv pipeline delete foo
- cih kv pipeline list
- cih exec whoami
- cih exec cih:///test
- cih log info pipeline "job complete"
or set default Gitlab CI ID tokens for all jobs in the pipeline:
default:
id_tokens:
CIH_ID_TOKEN:
aud: https://lab.synci.cloud
job 1:
image: reflexi/cih:latest
script:
- cih whoami
job 2:
image: reflexi/cih:latest
script:
- cih whoami
Validate your job id token with the CIH server
cih kv whoami # provide the claims from your JWT
cih kv health # exit 0 if server is healthy
Execute local commands and log to the CIH server as well as local.
cih exec ./test.sh
You can also specify a script which is pulled from the CIH server. This is very useful when testing pipelines as the script can be updated and you can simply rerun a job.
cih exec cih:///some/path/to/a/script
Replace variables with KV values pulled from the server. This function reads stdin or the first argument. Note the single quotes to avoid shell expansion of the variables!
cih expand 'Hello ${kv branch foo}, ${kv org a} ${kv org b}'
echo 'Hello ${kv branch foo}, ${kv org a} ${kv org b}' | cih expand
Run local in docker
docker run -it --rm docker.io/reflexi/cih:latest
All commands and sub commands have a --help and -h option.
$ docker run -it --rm docker.io/reflexi/cih:latest
# cih -h
NAME:
cih - ci helper tool
USAGE:
cih [global options] [command [command options]]
VERSION:
v0.0.0
COMMANDS:
health, h run health check
log, l log to a namespace
whoami validate job token with cih server
env dump env
exec exec a script
expand expand stdin to stdout
kv key / value functions
help, h Shows a list of commands or help for one command
GLOBAL OPTIONS:
--server value cih server url (default: "https://lab.synci.cloud")
--type value input and output data type (json, yaml, raw, xml, toml) (default: "json")
--debug enable debug logging (default: false)
--help, -h show help
--version, -v print the version
FROM ubuntu:latest # or whatever....
COPY --from=reflexi/cih:latest /bin/cih /bin/cih
# my image stuff...
You can also use a personal token to execute operations locally. You must set the CI_PROJECT_PATH variable and also have maintainer privileges on the target project.
export CI_PROJECT_PATH=some/repo/path
export GITLAB_TOKEN=...
cih whoami | jq
Content type
Image
Digest
sha256:1acfcaa04…
Size
75.8 MB
Last updated
over 1 year ago
docker pull reflexi/cih