fix: harden thothctl diagnostics

This commit is contained in:
2026-08-04 17:00:05 +02:00
parent 853a151796
commit 4158990c10
7 changed files with 351 additions and 12 deletions
+17 -7
View File
@@ -47,6 +47,16 @@ func run(ctx context.Context, args []string, stdout, stderr io.Writer) int {
fmt.Fprintf(stderr, "thothctl: %s\n", output.Sanitize(err.Error(), nil))
return 2
}
secretFiles, err := installation.SecretFiles()
if err != nil {
fmt.Fprintln(stderr, "thothctl: installation secret declarations could not be read")
return 2
}
secretValues, err := output.SecretValuesFromFiles(secretFiles)
if err != nil {
fmt.Fprintln(stderr, "thothctl: declared secret file could not be read")
return 2
}
runner := compose.NewRunner("")
var result compose.Result
@@ -81,11 +91,11 @@ func run(ctx context.Context, args []string, stdout, stderr io.Writer) int {
if len(commandArgs) != 0 {
return commandUsageError(stderr, "doctor does not accept arguments")
}
return doctor(ctx, installation, runner, stdout, stderr)
return doctor(ctx, installation, runner, secretValues, stdout, stderr)
default:
return commandUsageError(stderr, fmt.Sprintf("unknown command %q", command))
}
return writeResult(result, err, stdout, stderr)
return writeResult(result, err, secretValues, stdout, stderr)
}
func parseArgs(args []string) (string, string, []string, error) {
@@ -113,12 +123,12 @@ func commandUsageError(stderr io.Writer, message string) int {
return 2
}
func writeResult(result compose.Result, err error, stdout, stderr io.Writer) int {
func writeResult(result compose.Result, err error, secretValues []string, stdout, stderr io.Writer) int {
if result.Stdout != "" {
fmt.Fprint(stdout, output.Sanitize(result.Stdout, nil))
fmt.Fprint(stdout, output.Sanitize(result.Stdout, secretValues))
}
if result.Stderr != "" {
fmt.Fprint(stderr, output.Sanitize(result.Stderr, nil))
fmt.Fprint(stderr, output.Sanitize(result.Stderr, secretValues))
}
if err == nil {
return 0
@@ -132,7 +142,7 @@ func writeResult(result compose.Result, err error, stdout, stderr io.Writer) int
return 1
}
func doctor(ctx context.Context, installation config.Installation, runner compose.Runner, stdout, stderr io.Writer) int {
func doctor(ctx context.Context, installation config.Installation, runner compose.Runner, secretValues []string, stdout, stderr io.Writer) int {
checks := [][]string{
{"version", "--format", "{{.Client.Version}}"},
{"compose", "version", "--short"},
@@ -144,7 +154,7 @@ func doctor(ctx context.Context, installation config.Installation, runner compos
for index, args := range checks {
result, err := runner.Run(ctx, args, nil)
if err != nil {
return writeResult(result, err, stdout, stderr)
return writeResult(result, err, secretValues, stdout, stderr)
}
if index == 3 {
renderedConfig = result.Stdout