Commands
coming with the provisioner’s first release.
The image registry.tinyfactory.ai/tinyblox/provision runs one command and
exits. The charts run apply on install and upgrade and delete on
uninstall; you run the others when you need them.
| Command | What it does |
|---|---|
plan |
Shows what apply would create, change and delete. Changes nothing. |
apply |
Makes the identity provider match the input and writes the Secrets. |
describe |
Shows what exists now. With --whoami, also checks the credential’s rights. |
delete |
Removes what this input created, and its Secrets. --dry-run only lists it. |
rotate <client> |
Issues a new client secret and writes it to the Secret. --overlap-hours N (TinyGuard, 1 to 24) keeps the old one valid meanwhile. |
rotate <username> |
With an access file: a new password for a local account. |
version |
Prints the version. |
| Option | Meaning |
|---|---|
--exit-code |
With plan: exit 2 when there is something to change, for a scheduled drift check. |
--verbose |
With plan: also list what is already right. |
--rotate |
With apply: issue new client secrets instead of reading the current ones back. |
--output json |
Machine-readable plan and describe output. |
Running a command yourself
Section titled “Running a command yourself”Render the input the chart gives the Job:
helm template tinyconductor oci://registry.tinyfactory.ai/tinyblox/charts/tinyconductor \ -f conductor.yaml --show-only templates/provision.yaml \ | yq 'select(.kind == "ConfigMap") | .data["provision.yaml"]' > provision.yamlPut the credential in a folder as the Secret holds it (credential for
TinyGuard; client-id and client-secret for Keycloak), then:
docker run --rm \ -v "$PWD/provision.yaml:/etc/provision/provision.yaml:ro" \ -v "$PWD/credential:/var/run/provision/credential:ro" \ -e POD_NAMESPACE=tinyblox \ registry.tinyfactory.ai/tinyblox/provision:0.1.0 planplan and describe work from any machine that can reach the identity
provider. Commands that write Secrets (apply, rotate, delete) also need
the Kubernetes API: from a Linux machine with kubectl access to the
namespace, start kubectl proxy --port 8001, and add
--network host -e PROVISION_KUBE_API=http://127.0.0.1:8001 to the
docker run above.
Reading the plan
Section titled “Reading the plan”tinyguard https://guard.example.com/auth/v1 (tenant: default) + client tinyconductor-console confidential, authorization_code, PKCE, 1 redirect URI ~ client tinyconductor-desktop redirectUris - client tinyconductor-old managed by production/tinyblox/tinyconductor ! client tinyconductor-extra exists without the managed-by marker (made by hand): not changed + secret tinyblox/tinyconductor-oidc-console (client-id, client-secret, issuer)… 2 to create, 1 to update, 1 to delete, 6 unchanged, 1 in conflict| Sign | Meaning |
|---|---|
+ |
will be created |
~ |
will be changed; the fields are listed |
- |
will be deleted (only ever something this input created) |
! |
conflict: something of that name exists that the provisioner did not create; it is left alone and the run fails |
? |
skipped: the identity provider cannot do it; the line says what to do instead |
= |
already right (shown with --verbose) |
Exit codes
Section titled “Exit codes”| Code | Meaning |
|---|---|
| 0 | Done, or nothing to do. |
| 1 | Failed, or a conflict was found. The last error log line says why. |
| 2 | plan --exit-code found changes. |
| 64 | Wrong command or option. |
Logs go to standard error, one JSON object per line, and never contain a secret. Plans and results go to standard output.
Settings
Section titled “Settings”| Variable | Default | Meaning |
|---|---|---|
PROVISION_CONFIG |
/etc/provision/provision.yaml |
The input file. |
PROVISION_CREDENTIAL_DIR |
/var/run/provision/credential |
The mounted credential. |
POD_NAMESPACE |
The namespace of the Secrets. | |
PROVISION_WAIT_TIMEOUT |
300 |
Seconds to keep retrying an identity provider that is not ready. |
PROVISION_CA_FILE |
An extra CA certificate for the identity provider’s TLS. | |
PROVISION_KUBE_API |
the in-cluster address | Another Kubernetes API address, for example kubectl proxy. |
PROVISION_LOG_LEVEL |
info |
debug, info, warn or error. |