mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 03:26:46 +00:00
Merge pull request #1383 from Grraahaam/feat/cli-secret-plain-output
feat(cli): plain secret value output
This commit is contained in:
+38
-14
@@ -73,6 +73,11 @@ var secretsCmd = &cobra.Command{
|
|||||||
util.HandleError(err, "Unable to parse flag")
|
util.HandleError(err, "Unable to parse flag")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
plainOutput, err := cmd.Flags().GetBool("plain")
|
||||||
|
if err != nil {
|
||||||
|
util.HandleError(err, "Unable to parse flag")
|
||||||
|
}
|
||||||
|
|
||||||
request := models.GetAllSecretsParameters{
|
request := models.GetAllSecretsParameters{
|
||||||
Environment: environmentName,
|
Environment: environmentName,
|
||||||
WorkspaceId: projectId,
|
WorkspaceId: projectId,
|
||||||
@@ -100,7 +105,6 @@ var secretsCmd = &cobra.Command{
|
|||||||
}
|
}
|
||||||
|
|
||||||
if shouldExpandSecrets {
|
if shouldExpandSecrets {
|
||||||
|
|
||||||
authParams := models.ExpandSecretsAuthentication{}
|
authParams := models.ExpandSecretsAuthentication{}
|
||||||
if token != nil && token.Type == util.SERVICE_TOKEN_IDENTIFIER {
|
if token != nil && token.Type == util.SERVICE_TOKEN_IDENTIFIER {
|
||||||
authParams.InfisicalToken = token.Token
|
authParams.InfisicalToken = token.Token
|
||||||
@@ -114,7 +118,14 @@ var secretsCmd = &cobra.Command{
|
|||||||
// Sort the secrets by key so we can create a consistent output
|
// Sort the secrets by key so we can create a consistent output
|
||||||
secrets = util.SortSecretsByKeys(secrets)
|
secrets = util.SortSecretsByKeys(secrets)
|
||||||
|
|
||||||
visualize.PrintAllSecretDetails(secrets)
|
if plainOutput {
|
||||||
|
for _, secret := range secrets {
|
||||||
|
fmt.Println(secret.Value)
|
||||||
|
}
|
||||||
|
} else {
|
||||||
|
visualize.PrintAllSecretDetails(secrets)
|
||||||
|
}
|
||||||
|
|
||||||
Telemetry.CaptureEvent("cli-command:secrets", posthog.NewProperties().Set("secretCount", len(secrets)).Set("version", util.CLI_VERSION))
|
Telemetry.CaptureEvent("cli-command:secrets", posthog.NewProperties().Set("secretCount", len(secrets)).Set("version", util.CLI_VERSION))
|
||||||
},
|
},
|
||||||
}
|
}
|
||||||
@@ -325,9 +336,20 @@ func getSecretsByNames(cmd *cobra.Command, args []string) {
|
|||||||
util.HandleError(err, "Unable to parse recursive flag")
|
util.HandleError(err, "Unable to parse recursive flag")
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// deprecated, in favor of --plain
|
||||||
showOnlyValue, err := cmd.Flags().GetBool("raw-value")
|
showOnlyValue, err := cmd.Flags().GetBool("raw-value")
|
||||||
if err != nil {
|
if err != nil {
|
||||||
util.HandleError(err, "Unable to parse path flag")
|
util.HandleError(err, "Unable to parse flag")
|
||||||
|
}
|
||||||
|
|
||||||
|
plainOutput, err := cmd.Flags().GetBool("plain")
|
||||||
|
if err != nil {
|
||||||
|
util.HandleError(err, "Unable to parse flag")
|
||||||
|
}
|
||||||
|
|
||||||
|
includeImports, err := cmd.Flags().GetBool("include-imports")
|
||||||
|
if err != nil {
|
||||||
|
util.HandleError(err, "Unable to parse flag")
|
||||||
}
|
}
|
||||||
|
|
||||||
request := models.GetAllSecretsParameters{
|
request := models.GetAllSecretsParameters{
|
||||||
@@ -335,7 +357,7 @@ func getSecretsByNames(cmd *cobra.Command, args []string) {
|
|||||||
WorkspaceId: projectId,
|
WorkspaceId: projectId,
|
||||||
TagSlugs: tagSlugs,
|
TagSlugs: tagSlugs,
|
||||||
SecretsPath: secretsPath,
|
SecretsPath: secretsPath,
|
||||||
IncludeImport: true,
|
IncludeImport: includeImports,
|
||||||
Recursive: recursive,
|
Recursive: recursive,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -377,15 +399,15 @@ func getSecretsByNames(cmd *cobra.Command, args []string) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if showOnlyValue && len(requestedSecrets) > 1 {
|
// showOnlyValue deprecated in favor of --plain, below only for backward compatibility
|
||||||
util.PrintErrorMessageAndExit("--raw-value only works with one secret.")
|
if plainOutput || showOnlyValue {
|
||||||
}
|
for _, secret := range requestedSecrets {
|
||||||
|
fmt.Println(secret.Value)
|
||||||
if showOnlyValue {
|
}
|
||||||
fmt.Printf(requestedSecrets[0].Value)
|
|
||||||
} else {
|
} else {
|
||||||
visualize.PrintAllSecretDetails(requestedSecrets)
|
visualize.PrintAllSecretDetails(requestedSecrets)
|
||||||
}
|
}
|
||||||
|
|
||||||
Telemetry.CaptureEvent("cli-command:secrets get", posthog.NewProperties().Set("secretCount", len(secrets)).Set("version", util.CLI_VERSION))
|
Telemetry.CaptureEvent("cli-command:secrets get", posthog.NewProperties().Set("secretCount", len(secrets)).Set("version", util.CLI_VERSION))
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -639,11 +661,12 @@ func init() {
|
|||||||
secretsGetCmd.Flags().String("token", "", "Fetch secrets using service token or machine identity access token")
|
secretsGetCmd.Flags().String("token", "", "Fetch secrets using service token or machine identity access token")
|
||||||
secretsGetCmd.Flags().String("projectId", "", "manually set the project ID to fetch secrets from when using machine identity based auth")
|
secretsGetCmd.Flags().String("projectId", "", "manually set the project ID to fetch secrets from when using machine identity based auth")
|
||||||
secretsGetCmd.Flags().String("path", "/", "get secrets within a folder path")
|
secretsGetCmd.Flags().String("path", "/", "get secrets within a folder path")
|
||||||
secretsGetCmd.Flags().Bool("expand", true, "Parse shell parameter expansions in your secrets")
|
secretsGetCmd.Flags().Bool("plain", false, "print values without formatting, one per line")
|
||||||
secretsGetCmd.Flags().Bool("raw-value", false, "Returns only the value of secret, only works with one secret")
|
secretsGetCmd.Flags().Bool("raw-value", false, "deprecated. Returns only the value of secret, only works with one secret. Use --plain instead")
|
||||||
|
secretsGetCmd.Flags().Bool("include-imports", true, "Imported linked secrets ")
|
||||||
|
secretsGetCmd.Flags().Bool("expand", true, "Parse shell parameter expansions in your secrets, and process your referenced secrets")
|
||||||
secretsGetCmd.Flags().Bool("recursive", false, "Fetch secrets from all sub-folders")
|
secretsGetCmd.Flags().Bool("recursive", false, "Fetch secrets from all sub-folders")
|
||||||
secretsCmd.AddCommand(secretsGetCmd)
|
secretsCmd.AddCommand(secretsGetCmd)
|
||||||
|
|
||||||
secretsCmd.Flags().Bool("secret-overriding", true, "Prioritizes personal secrets, if any, with the same name over shared secrets")
|
secretsCmd.Flags().Bool("secret-overriding", true, "Prioritizes personal secrets, if any, with the same name over shared secrets")
|
||||||
secretsCmd.AddCommand(secretsSetCmd)
|
secretsCmd.AddCommand(secretsSetCmd)
|
||||||
secretsSetCmd.Flags().String("token", "", "Fetch secrets using service token or machine identity access token")
|
secretsSetCmd.Flags().String("token", "", "Fetch secrets using service token or machine identity access token")
|
||||||
@@ -687,10 +710,11 @@ func init() {
|
|||||||
secretsCmd.Flags().String("token", "", "Fetch secrets using service token or machine identity access token")
|
secretsCmd.Flags().String("token", "", "Fetch secrets using service token or machine identity access token")
|
||||||
secretsCmd.Flags().String("projectId", "", "manually set the projectId to fetch secrets when using machine identity based auth")
|
secretsCmd.Flags().String("projectId", "", "manually set the projectId to fetch secrets when using machine identity based auth")
|
||||||
secretsCmd.PersistentFlags().String("env", "dev", "Used to select the environment name on which actions should be taken on")
|
secretsCmd.PersistentFlags().String("env", "dev", "Used to select the environment name on which actions should be taken on")
|
||||||
secretsCmd.Flags().Bool("expand", true, "Parse shell parameter expansions in your secrets")
|
secretsCmd.Flags().Bool("expand", true, "Parse shell parameter expansions in your secrets, and process your referenced secrets")
|
||||||
secretsCmd.Flags().Bool("include-imports", true, "Imported linked secrets ")
|
secretsCmd.Flags().Bool("include-imports", true, "Imported linked secrets ")
|
||||||
secretsCmd.Flags().Bool("recursive", false, "Fetch secrets from all sub-folders")
|
secretsCmd.Flags().Bool("recursive", false, "Fetch secrets from all sub-folders")
|
||||||
secretsCmd.PersistentFlags().StringP("tags", "t", "", "filter secrets by tag slugs")
|
secretsCmd.PersistentFlags().StringP("tags", "t", "", "filter secrets by tag slugs")
|
||||||
secretsCmd.Flags().String("path", "/", "get secrets within a folder path")
|
secretsCmd.Flags().String("path", "/", "get secrets within a folder path")
|
||||||
|
secretsCmd.Flags().Bool("plain", false, "print values without formatting, one per line")
|
||||||
rootCmd.AddCommand(secretsCmd)
|
rootCmd.AddCommand(secretsCmd)
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -88,6 +88,27 @@ $ infisical secrets
|
|||||||
```
|
```
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
<Accordion title="--plain">
|
||||||
|
The `--plain` flag will output all your secret values without formatting, one per line.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Example
|
||||||
|
infisical secrets --plain --silent
|
||||||
|
```
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="--silent">
|
||||||
|
The `--silent` flag disables output of tip/info messages. Useful when running in scripts or CI/CD pipelines.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Example
|
||||||
|
infisical secrets --silent
|
||||||
|
```
|
||||||
|
|
||||||
|
Can be used inline to replace `INFISICAL_DISABLE_UPDATE_CHECK`
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
@@ -99,6 +120,7 @@ $ infisical secrets get <secret-name-a> <secret-name-b> ...
|
|||||||
|
|
||||||
# Example
|
# Example
|
||||||
$ infisical secrets get DOMAIN
|
$ infisical secrets get DOMAIN
|
||||||
|
$ infisical secrets get DOMAIN PORT
|
||||||
|
|
||||||
```
|
```
|
||||||
|
|
||||||
@@ -111,7 +133,41 @@ $ infisical secrets get DOMAIN
|
|||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="--raw-value">
|
<Accordion title="--plain">
|
||||||
|
The `--plain` flag will output all your requested secret values without formatting, one per line.
|
||||||
|
|
||||||
|
Default value: `false`
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Example
|
||||||
|
infisical secrets get FOO --plain
|
||||||
|
infisical secrets get FOO BAR --plain
|
||||||
|
|
||||||
|
# Fetch a single value and assign it to a variable
|
||||||
|
API_KEY=$(infisical secrets get FOO --plain --silent)
|
||||||
|
```
|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
When running in CI/CD environments or in a script, set `INFISICAL_DISABLE_UPDATE_CHECK=true` or add the `--silent` flag. This will help hide any CLI info/debug output and only show the secret value.
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="--silent">
|
||||||
|
The `--silent` flag disables output of tip/info messages. Useful when running in scripts or CI/CD pipelines.
|
||||||
|
|
||||||
|
```bash
|
||||||
|
# Example
|
||||||
|
infisical secrets get FOO --plain --silent
|
||||||
|
```
|
||||||
|
|
||||||
|
Can be used inline to replace `INFISICAL_DISABLE_UPDATE_CHECK`
|
||||||
|
|
||||||
|
</Accordion>
|
||||||
|
|
||||||
|
<Accordion title="--raw-value (deprecated)">
|
||||||
|
Use `--plain` instead, as it supports single and multiple secrets.
|
||||||
|
|
||||||
Used to print the plain value of a single requested secret without any table style.
|
Used to print the plain value of a single requested secret without any table style.
|
||||||
|
|
||||||
Default value: `false`
|
Default value: `false`
|
||||||
@@ -119,10 +175,11 @@ $ infisical secrets get DOMAIN
|
|||||||
Example: `infisical secrets get DOMAIN --raw-value`
|
Example: `infisical secrets get DOMAIN --raw-value`
|
||||||
|
|
||||||
<Tip>
|
<Tip>
|
||||||
When running in CI/CD environments or in a script, set `INFISICAL_DISABLE_UPDATE_CHECK` env to `true`. This will help hide any CLI update messages and only show the secret value.
|
When running in CI/CD environments or in a script, set `INFISICAL_DISABLE_UPDATE_CHECK=true` or add the `--silent` flag. This will help hide any CLI info/debug output and only show the secret value.
|
||||||
</Tip>
|
</Tip>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
|
|
||||||
<Accordion title="infisical secrets set">
|
<Accordion title="infisical secrets set">
|
||||||
|
|||||||
Reference in New Issue
Block a user