Skip to content

Commit 0c1596d

Browse files
committed
feat: change by following suggestions
1 parent a942cfe commit 0c1596d

32 files changed

Lines changed: 867 additions & 344 deletions

‎AGENTS.md‎

Lines changed: 38 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -58,8 +58,8 @@ Implemented:
5858
- `tdc db list-db-cluster-branches`
5959
- `tdc db describe-db-cluster-branch`
6060
- `tdc db delete-db-cluster-branch`
61-
- `tdc db prepare-db-query-access`
62-
- `tdc db create-db-connection-string`
61+
- `tdc db create-db-sql-users`
62+
- `tdc db format-db-connection-string`
6363
- `tdc db execute-sql-statement`
6464
- `tdc fs create-file-system`
6565
- `tdc fs delete-file-system`
@@ -115,7 +115,7 @@ Implemented:
115115
- `tdc journal search-journal-entries`
116116
- `tdc journal verify-journal`
117117
- help and version behavior at every command level
118-
- structured JSON/human rendering and JMESPath `--query`
118+
- structured JSON/text rendering and JMESPath `--query`
119119
- `--dry-run` on mutating control-plane commands
120120
- TiDB Cloud Digest-auth API client foundation and auth/authz error mapping
121121
- flat `fs_*` config/credential storage for tdc fs control-plane resources
@@ -156,7 +156,7 @@ dry-run support.
156156
- `ref/drive9/` is the filesystem reference implementation. Use it as context
157157
for filesystem commands, mount behavior, and data-plane semantics. In tdc
158158
user-facing output, this domain is always called `tdc fs`.
159-
- `ref/serverless-js/` is a reference for the HTTP SQL call shape.
159+
- `ref/serverless-js/` is a reference for the HTTPS SQL API call shape.
160160

161161
Reference directories are not product source for tdc. They exist only to give
162162
agents context and implementation examples. In main project code, behave as if
@@ -201,7 +201,8 @@ that cluster. For Starter DB branches, the live suite creates, reads, lists,
201201
and deletes only a `tdc-e2e-branch-*` branch on the cluster created by the same
202202
test run. For Starter DB SQL access, the live suite prepares tdc-managed
203203
read-only, read-write, and admin SQL users on the temporary cluster, verifies
204-
connection string output, and executes HTTP SQL with all three access modes.
204+
connection string output, and executes the HTTPS SQL API with all three access
205+
modes.
205206
For tdc fs data-plane and mount runtime, the live suite creates uniquely named
206207
remote paths, exercises real file create/read/list/copy/move/delete flows,
207208
range reads, V2-first multipart upload, efficient append, upload resume,
@@ -214,6 +215,10 @@ low-level Git workspace API CRUD, mounts with the default FUSE driver when
214215
platform prerequisites exist, verifies `tdc fs drain-file-system` against the
215216
mounted runtime control socket, and also verifies explicit WebDAV fallback on
216217
macOS when `mount_webdav` is available.
218+
If the live profile has no `fs_api_key`, the suite creates a temporary tdc fs
219+
resource named by `TDC_LIVE_FS_NAME` or `workspace`, stores the generated flat
220+
`fs_*` metadata and `fs_api_key`, and deletes that auto-created resource when
221+
the test process exits.
217222
When a service command is implemented, add its real live verification to
218223
`make live-e2e`; do not leave the target at profile, smoke-test-only, or
219224
mock-only coverage.
@@ -254,14 +259,14 @@ internal/db/ Starter DB cluster, branch, and SQL use cases
254259
internal/db/connectionstring/ DB connection string formatters
255260
internal/db/sqlaccess/ DB SQL user preparation logic
256261
internal/db/sqlcred/ cluster-scoped DB SQL credential store
257-
internal/db/sqlhttp/ HTTP SQL transport
262+
internal/db/sqlhttp/ HTTPS SQL API transport
258263
internal/db/sqlmysql/ explicit MySQL fallback transport
259264
internal/db/sqlresult/ SQL result model and decoding
260265
internal/db/sqlsingle/ one-statement validation
261266
internal/db/validate/ DB flag and request validation helpers
262267
internal/dryrun/ shared dry-run result envelope
263268
internal/fs/ tdc fs control-plane, data-plane, and mount use cases
264-
internal/output/ structured JSON/human/raw rendering
269+
internal/output/ structured JSON/text/raw rendering
265270
internal/organization/ organization project command use cases
266271
internal/query/ JMESPath query application
267272
internal/secretinput/ no-echo secret input helper
@@ -348,34 +353,35 @@ Implemented command behavior:
348353
- `tdc cli update --target-version v0.1.0 --yes`
349354
- `tdc organization list-projects`
350355
- `tdc organization list-projects --query 'projects[0].id'`
351-
- `tdc organization list-projects --output human`
356+
- `tdc organization list-projects --output text`
352357
- `tdc db create-db-cluster --db-cluster-name demo --db-cluster-type starter --project-id <project-id>`
353358
- `tdc db create-db-cluster --db-cluster-name demo --db-cluster-type starter --project-id <project-id> --dry-run`
354359
- `tdc db list-db-clusters`
355360
- `tdc db list-db-clusters --query 'clusters[].id'`
356361
- `tdc db describe-db-cluster --db-cluster-id <cluster-id>`
357362
- `tdc db update-db-cluster --db-cluster-id <cluster-id> --db-cluster-name new-name`
358363
- `tdc db update-db-cluster --db-cluster-id <cluster-id> --monthly-spending-limit-usd-cents 1000 --dry-run`
359-
- `tdc db delete-db-cluster --db-cluster-id <cluster-id> --confirm-db-cluster-name <current-name>`
360-
- `tdc db delete-db-cluster --db-cluster-id <cluster-id> --confirm-db-cluster-name <current-name> --dry-run`
364+
- `tdc db delete-db-cluster --db-cluster-id <cluster-id>`
365+
- `tdc db delete-db-cluster --db-cluster-id <cluster-id> --dry-run`
361366
- `tdc db create-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-name dev`
362367
- `tdc db create-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-name dev --dry-run`
363368
- `tdc db list-db-cluster-branches --db-cluster-id <cluster-id>`
364369
- `tdc db list-db-cluster-branches --db-cluster-id <cluster-id> --query 'branches[].id'`
365-
- `tdc db list-db-cluster-branches --db-cluster-id <cluster-id> --output human`
370+
- `tdc db list-db-cluster-branches --db-cluster-id <cluster-id> --output text`
366371
- `tdc db describe-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id>`
367-
- `tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> --confirm-db-cluster-branch-name <current-name>`
368-
- `tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> --confirm-db-cluster-branch-name <current-name> --dry-run`
369-
- `tdc db prepare-db-query-access --db-cluster-id <cluster-id>`
370-
- `tdc db prepare-db-query-access --db-cluster-id <cluster-id> --dry-run`
371-
- `tdc db create-db-connection-string --db-cluster-id <cluster-id>`
372-
- `tdc db create-db-connection-string --db-cluster-id <cluster-id> --read-write --format mysql-uri`
373-
- `tdc db create-db-connection-string --db-cluster-id <cluster-id> --read-only --format env`
374-
- `tdc db create-db-connection-string --db-cluster-id <cluster-id> --admin --format jdbc`
372+
- `tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id>`
373+
- `tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> --dry-run`
374+
- `tdc db create-db-sql-users --db-cluster-id <cluster-id>`
375+
- `tdc db create-db-sql-users --db-cluster-id <cluster-id> --dry-run`
376+
- `tdc db format-db-connection-string --db-cluster-id <cluster-id>`
377+
- `tdc db format-db-connection-string --db-cluster-id <cluster-id> --read-write --format mysql-uri`
378+
- `tdc db format-db-connection-string --db-cluster-id <cluster-id> --read-only --format env`
379+
- `tdc db format-db-connection-string --db-cluster-id <cluster-id> --admin --format jdbc`
375380
- `tdc db execute-sql-statement --db-cluster-id <cluster-id> --sql "select 1"`
376381
- `tdc db execute-sql-statement --db-cluster-id <cluster-id> --read-write --sql "select 1"`
377382
- `tdc db execute-sql-statement --db-cluster-id <cluster-id> --read-only --sql "select 1"`
378383
- `tdc db execute-sql-statement --db-cluster-id <cluster-id> --admin --sql "select 1"`
384+
- `tdc db execute-sql-statement --db-cluster-id <cluster-id> --transport https --sql "select 1"`
379385
- `tdc db execute-sql-statement --db-cluster-id <cluster-id> --transport mysql --sql "select 1"`
380386
- `tdc fs create-file-system --file-system-name workspace`
381387
- `tdc fs create-file-system --file-system-name workspace --dry-run`
@@ -396,7 +402,7 @@ Implemented command behavior:
396402
- `tdc fs copy-file --from-stdin --to-remote /workspace/stdin.txt --tag source=stdin --description "stdin upload"`
397403
- `tdc fs copy-file --from-remote /workspace/stdin.txt --to-stdout`
398404
- `tdc fs list-files --path /workspace`
399-
- `tdc fs list-files --path /workspace --output human`
405+
- `tdc fs list-files --path /workspace --output text`
400406
- `tdc fs describe-file --path /workspace/README.md`
401407
- `tdc fs move-file --from-remote /workspace/README.copy.md --to-remote /workspace/archive/README.md`
402408
- `tdc fs delete-file --path /workspace/archive/README.md`
@@ -411,7 +417,7 @@ Implemented command behavior:
411417
- `tdc fs find-files --path /workspace --file-name-pattern "*.md" --layer-id layer-1`
412418
- `tdc fs create-layer --layer-id layer-1 --base-root-path /workspace --layer-name task --durability-mode restore-safe --tag task=auth`
413419
- `tdc fs list-layers`
414-
- `tdc fs list-layers --output human`
420+
- `tdc fs list-layers --output text`
415421
- `tdc fs describe-layer --layer-id layer-1`
416422
- `tdc fs diff-layer --layer-id layer-1`
417423
- `tdc fs replay-layer --layer-id layer-1`
@@ -459,7 +465,7 @@ Implemented command behavior:
459465
- `tdc journal append-journal-entries --journal-id jrn-demo --entry-json '{"type":"task.started"}'`
460466
- `tdc journal read-journal-entries --journal-id jrn-demo --after-seq 0 --limit 100`
461467
- `tdc journal search-journal-entries --entry-type task.started --label env=dev --include-entries`
462-
- `tdc journal verify-journal --journal-id jrn-demo --output human`
468+
- `tdc journal verify-journal --journal-id jrn-demo --output text`
463469
- `tdc git clone-git-workspace --repo-url https://github.com/pingcap/tidb.git --target-path ./workspace/tidb`
464470
- `tdc git clone-git-workspace --repo-url https://github.com/pingcap/tidb.git --target-path ./workspace/tidb --blobless --hydrate sync`
465471
- `tdc git hydrate-git-workspace --target-path ./workspace/tidb --timeout 30m`
@@ -489,8 +495,8 @@ Registered command surface:
489495
- `tdc db list-db-cluster-branches`
490496
- `tdc db describe-db-cluster-branch`
491497
- `tdc db delete-db-cluster-branch`
492-
- `tdc db prepare-db-query-access`
493-
- `tdc db create-db-connection-string`
498+
- `tdc db create-db-sql-users`
499+
- `tdc db format-db-connection-string`
494500
- `tdc db execute-sql-statement`
495501
- `tdc fs create-file-system`
496502
- `tdc fs delete-file-system`
@@ -666,10 +672,11 @@ not be required by MVP usage.
666672

667673
TiDB Cloud control-plane API calls use HTTP Digest auth through
668674
`internal/api/transport`; never send `tdc_private_key` as Basic Auth for those
669-
APIs. SQL HTTP execution and tdc fs data-plane auth are separate authentication
670-
schemes. SQL HTTP uses the prepared DB SQL username/password as Basic Auth
671-
against `https://http-<cluster-host>/v1beta/sql`; TiDB Cloud API keys must not
672-
be used for SQL HTTP Basic Auth.
675+
APIs. SQL HTTPS API execution and tdc fs data-plane auth are separate
676+
authentication schemes. SQL HTTPS API execution uses the prepared DB SQL
677+
username/password as Basic Auth against
678+
`https://http-<cluster-host>/v1beta/sql`; TiDB Cloud API keys must not be used
679+
for SQL execution Basic Auth.
673680

674681
Use `internal/api/endpoints` for Starter, IAM/account, and fs endpoint
675682
selection. Do not add service URLs to user config. The default Starter host is
@@ -711,7 +718,7 @@ Generated DB SQL usernames and passwords live in
711718
`[profile.db_users."<cluster-id>".role]` TOML sections to
712719
`~/.tdc/credentials`. TiDB Cloud cluster IDs are globally unique, so DB SQL
713720
credentials are cluster-scoped rather than profile-scoped. `tdc db
714-
prepare-db-query-access` owns those credentials and must be idempotent: it
721+
create-db-sql-users` owns those credentials and must be idempotent: it
715722
creates or repairs the stable tdc-managed read-only, read-write, and admin
716723
users for a cluster instead of creating a new group every time.
717724

@@ -827,7 +834,7 @@ missing local Git state when possible, and persist dirty Git workspace changes
827834
through `/v1/git-workspaces/<id>/overlay` rather than ordinary `/v1/fs` file
828835
rows.
829836

830-
`tdc db create-db-connection-string` and `tdc db execute-sql-statement` use
837+
`tdc db format-db-connection-string` and `tdc db execute-sql-statement` use
831838
read-write credentials by default. `--read-write`, `--read-only`, and `--admin`
832839
must be mutually exclusive explicit selections. Do not add SQL-text
833840
classification or an automatic access mode.
@@ -839,7 +846,7 @@ Use structured output contracts from the start.
839846
- JSON is the default for successful structured control-plane commands.
840847
- Data-plane commands may stream bytes or plain file listings when JSON would
841848
break expected filesystem usage.
842-
- `--output json` and `--output human` are the initial output modes.
849+
- `--output json` and `--output text` are the initial output modes.
843850
- `--query` uses JMESPath semantics and is applied after command execution to
844851
the structured result.
845852
- Raw output commands must reject `--query`.

0 commit comments

Comments
 (0)