Skip to content

Commands

coming with the provisioner’s first release.

The image registry.tinyfactory.ai/tinyblox/provision runs one command and exits. The charts run apply on install and upgrade and delete on uninstall; you run the others when you need them.

Command What it does
plan Shows what apply would create, change and delete. Changes nothing.
apply Makes the identity provider match the input and writes the Secrets.
describe Shows what exists now. With --whoami, also checks the credential’s rights.
delete Removes what this input created, and its Secrets. --dry-run only lists it.
rotate <client> Issues a new client secret and writes it to the Secret. --overlap-hours N (TinyGuard, 1 to 24) keeps the old one valid meanwhile.
rotate <username> With an access file: a new password for a local account.
version Prints the version.
Option Meaning
--exit-code With plan: exit 2 when there is something to change, for a scheduled drift check.
--verbose With plan: also list what is already right.
--rotate With apply: issue new client secrets instead of reading the current ones back.
--output json Machine-readable plan and describe output.

Render the input the chart gives the Job:

Terminal window
helm template tinyconductor oci://registry.tinyfactory.ai/tinyblox/charts/tinyconductor \
-f conductor.yaml --show-only templates/provision.yaml \
| yq 'select(.kind == "ConfigMap") | .data["provision.yaml"]' > provision.yaml

Put the credential in a folder as the Secret holds it (credential for TinyGuard; client-id and client-secret for Keycloak), then:

Terminal window
docker run --rm \
-v "$PWD/provision.yaml:/etc/provision/provision.yaml:ro" \
-v "$PWD/credential:/var/run/provision/credential:ro" \
-e POD_NAMESPACE=tinyblox \
registry.tinyfactory.ai/tinyblox/provision:0.1.0 plan

plan and describe work from any machine that can reach the identity provider. Commands that write Secrets (apply, rotate, delete) also need the Kubernetes API: from a Linux machine with kubectl access to the namespace, start kubectl proxy --port 8001, and add --network host -e PROVISION_KUBE_API=http://127.0.0.1:8001 to the docker run above.

tinyguard https://guard.example.com/auth/v1 (tenant: default)
+ client tinyconductor-console confidential, authorization_code, PKCE, 1 redirect URI
~ client tinyconductor-desktop redirectUris
- client tinyconductor-old managed by production/tinyblox/tinyconductor
! client tinyconductor-extra exists without the managed-by marker (made by hand): not changed
+ secret tinyblox/tinyconductor-oidc-console (client-id, client-secret, issuer)
… 2 to create, 1 to update, 1 to delete, 6 unchanged, 1 in conflict
Sign Meaning
+ will be created
~ will be changed; the fields are listed
- will be deleted (only ever something this input created)
! conflict: something of that name exists that the provisioner did not create; it is left alone and the run fails
? skipped: the identity provider cannot do it; the line says what to do instead
= already right (shown with --verbose)
Code Meaning
0 Done, or nothing to do.
1 Failed, or a conflict was found. The last error log line says why.
2 plan --exit-code found changes.
64 Wrong command or option.

Logs go to standard error, one JSON object per line, and never contain a secret. Plans and results go to standard output.

Variable Default Meaning
PROVISION_CONFIG /etc/provision/provision.yaml The input file.
PROVISION_CREDENTIAL_DIR /var/run/provision/credential The mounted credential.
POD_NAMESPACE The namespace of the Secrets.
PROVISION_WAIT_TIMEOUT 300 Seconds to keep retrying an identity provider that is not ready.
PROVISION_CA_FILE An extra CA certificate for the identity provider’s TLS.
PROVISION_KUBE_API the in-cluster address Another Kubernetes API address, for example kubectl proxy.
PROVISION_LOG_LEVEL info debug, info, warn or error.