Sign inSign up

reflexi/cih

By reflexi

•Updated over 1 year ago

!! LAB Tool !! CI helper tool.

Image
Developer tools
0

660

reflexi/cih repository overview

⁠CI Helper CLI tool

A namespace aware key/value store and logging tool. Built for Gitlab CI, GitHub Actions and any tool supporting JWT job tokens authentication.

⁠Why???

We built this tool because CI Job caches, artifacts shared between jobs, state storage between jobs and pipelines are all very difficult. For years we stood up Redis for our runners. We decided to make it more user friendly and add better controls around permissions and namespacing.

⁠Namespace

For commands like:

cih kv <get/set/delete> <namespace> <key> ...
cih log <debug/info/warn/error> <namespace> <message>

We support the following namespaces:

  • project
  • group
  • pipeline
  • job
  • branch
  • commit
  • env
  • org

⁠Example Gitlab CI

stages:
  - deploy-dev

deploy dev:
  id_tokens:
    CIH_ID_TOKEN:
      aud: https://lab.synci.cloud
  image: reflexi/cih:latest
  stage: deploy-dev
  environment:
    name: dev
  script:
    - cih log info pipeline "job starting"
    - cih whoami
    - cih kv pipeline set foo '{"key":"val"}'
    - cih kv pipeline get foo
    - cih kv pipeline list
    - cih kv pipeline delete foo
    - cih kv pipeline list
    - cih exec whoami
    - cih exec cih:///test
    - cih log info pipeline "job complete"

or set default Gitlab CI ID tokens for all jobs in the pipeline:

default:
  id_tokens:
    CIH_ID_TOKEN:
      aud: https://lab.synci.cloud

job 1:
  image: reflexi/cih:latest
  script:
    - cih whoami

job 2:
  image: reflexi/cih:latest
  script:
    - cih whoami

⁠Environment Variables

  • CIH_SERVER_URL (Default: https://lab.synci.cloud⁠)
  • CIH_SERVER_TOKEN - Required in multi tenant environments
  • CIH_ID_TOKEN - Job ID token as a JWT with required claims

⁠Other useful commands

Validate your job id token with the CIH server

cih kv whoami # provide the claims from your JWT
cih kv health # exit 0 if server is healthy

⁠Exec

Execute local commands and log to the CIH server as well as local.

cih exec ./test.sh

You can also specify a script which is pulled from the CIH server. This is very useful when testing pipelines as the script can be updated and you can simply rerun a job.

cih exec cih:///some/path/to/a/script

⁠Expand

Replace variables with KV values pulled from the server. This function reads stdin or the first argument. Note the single quotes to avoid shell expansion of the variables!

cih expand 'Hello ${kv branch foo}, ${kv org a} ${kv org b}'
echo 'Hello ${kv branch foo}, ${kv org a} ${kv org b}' | cih expand

⁠Help

Run local in docker

docker run -it --rm docker.io/reflexi/cih:latest

All commands and sub commands have a --help and -h option.

$ docker run -it --rm docker.io/reflexi/cih:latest
# cih -h
NAME:
   cih - ci helper tool 

USAGE:
   cih [global options] [command [command options]]

VERSION:
   v0.0.0

COMMANDS:
   health, h  run health check
   log, l     log to a namespace
   whoami     validate job token with cih server
   env        dump env
   exec       exec a script
   expand     expand stdin to stdout
   kv         key / value functions
   help, h    Shows a list of commands or help for one command

GLOBAL OPTIONS:
   --server value  cih server url (default: "https://lab.synci.cloud")
   --type value    input and output data type (json, yaml, raw, xml, toml) (default: "json")
   --debug         enable debug logging (default: false)
   --help, -h      show help
   --version, -v   print the version

⁠Add CIH to your own Docker Images

FROM ubuntu:latest # or whatever....

COPY --from=reflexi/cih:latest /bin/cih /bin/cih

# my image stuff...

⁠Gitlab Token Auth

You can also use a personal token to execute operations locally. You must set the CI_PROJECT_PATH variable and also have maintainer privileges on the target project.

export CI_PROJECT_PATH=some/repo/path
export GITLAB_TOKEN=... 
cih whoami | jq

Tag summary

Content type

Image

Digest

sha256:1acfcaa04…

Size

75.8 MB

Last updated

over 1 year ago

docker pull reflexi/cih