fix: fill in promtool's server argument, refuse the paths that cannot authenticate - #29
Merged
Merged
Conversation
… authenticate
`promtool` was the only query wrapper that did not point itself at the cluster.
`logcli` sets `--addr` and `tempo-cli` sets `--path-prefix` from `grafana-ds`,
but `bin/promtool` only appended the two auth headers, so the bare form failed:
$ toolbox promtool query instant 'sum(up)'
promtool.real: error: required argument 'expr' not provided
The caller had to hand-build `https://grafana.<domain>/api/datasources/proxy/uid/<uid>`,
which the README already said they would not have to.
Resolve the prometheus datasource UID and insert the `<server>` positional for
`query instant` and `query range`.
Those two are also the only subcommands that can work here at all: `query series`,
`query labels` and every `debug` subcommand take no `--header`, so the old wrapper
appended a flag they reject —
$ toolbox promtool debug pprof <server>
promtool.real: error: unknown long flag '--header'
— and even without the flag their requests would arrive at the edge carrying no
credential and be redirected to the login page. Refuse those against this cluster
with a message that says why, following the precedent of `tempo-cli` refusing
`--use-grpc`. An explicit `http(s)` server is always passed through untouched, so
promtool still works against anything else.
Verified against nonprod.jupiter.onglueops.rocks: bare `query instant`/`range`
return data, the refused paths print the reason, an explicit server still works,
and `--help` plus the local subcommands (`check`, `push`, `test`, `tsdb`) are
untouched.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TrpnuCduw2KivngVRQmnG7
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found while running the CLI-SSO sweep against a freshly rebuilt
nonprod.jupiter.onglueops.rocks.The bug
promtoolis the only query wrapper that does not point itself at the cluster.logclisets--addrandtempo-clisets--path-prefix, both fromgrafana-ds— butbin/promtoolonly appended the two auth headers, so the bare form fails:The caller has to hand-build
https://grafana.<domain>/api/datasources/proxy/uid/<uid>, which the README already told them they would not have to:A second bug in the same branch
Chasing it turned up that the old wrapper applied
--headerto subcommands that do not accept it:Only two subcommands take
--headerat all:--headerquery instantquery rangequery seriesquery labelsdebug pprof/metrics/allWithout
--headera request arrives at the edge carrying no credential and oauth2-proxy redirects it to the login page — so those paths cannot work here regardless of the flag error.The change
<server>positional forquery instantandquery range.query series,query labelsanddebugagainst this cluster with a message that says why, following the precedent oftempo-clirefusing--use-grpc.http(s)server through untouched, so promtool still works against anything else.--helpand the local subcommands (check,push,test,tsdb) are unchanged.Verification
Built and run against a live cluster:
Explicit server,
query --helpandcheck --helpall still behave as before.Not included
The
logcli delete createguard discussed separately — deliberately left out, to be sorted later.🤖 Generated with Claude Code
https://claude.ai/code/session_01TrpnuCduw2KivngVRQmnG7