@@ -58,8 +58,8 @@ Implemented:
5858- ` tdc db list-db-cluster-branches `
5959- ` tdc db describe-db-cluster-branch `
6060- ` tdc db delete-db-cluster-branch `
61- - ` tdc db prepare -db-query-access `
62- - ` tdc db create -db-connection-string `
61+ - ` tdc db create -db-sql-users `
62+ - ` tdc db format -db-connection-string `
6363- ` tdc db execute-sql-statement `
6464- ` tdc fs create-file-system `
6565- ` tdc fs delete-file-system `
@@ -115,7 +115,7 @@ Implemented:
115115- ` tdc journal search-journal-entries `
116116- ` tdc journal verify-journal `
117117- help and version behavior at every command level
118- - structured JSON/human rendering and JMESPath ` --query `
118+ - structured JSON/text rendering and JMESPath ` --query `
119119- ` --dry-run ` on mutating control-plane commands
120120- TiDB Cloud Digest-auth API client foundation and auth/authz error mapping
121121- flat ` fs_* ` config/credential storage for tdc fs control-plane resources
@@ -156,7 +156,7 @@ dry-run support.
156156- ` ref/drive9/ ` is the filesystem reference implementation. Use it as context
157157 for filesystem commands, mount behavior, and data-plane semantics. In tdc
158158 user-facing output, this domain is always called ` tdc fs ` .
159- - ` ref/serverless-js/ ` is a reference for the HTTP SQL call shape.
159+ - ` ref/serverless-js/ ` is a reference for the HTTPS SQL API call shape.
160160
161161Reference directories are not product source for tdc. They exist only to give
162162agents context and implementation examples. In main project code, behave as if
@@ -201,7 +201,8 @@ that cluster. For Starter DB branches, the live suite creates, reads, lists,
201201and deletes only a ` tdc-e2e-branch-* ` branch on the cluster created by the same
202202test run. For Starter DB SQL access, the live suite prepares tdc-managed
203203read-only, read-write, and admin SQL users on the temporary cluster, verifies
204- connection string output, and executes HTTP SQL with all three access modes.
204+ connection string output, and executes the HTTPS SQL API with all three access
205+ modes.
205206For tdc fs data-plane and mount runtime, the live suite creates uniquely named
206207remote paths, exercises real file create/read/list/copy/move/delete flows,
207208range reads, V2-first multipart upload, efficient append, upload resume,
@@ -214,6 +215,10 @@ low-level Git workspace API CRUD, mounts with the default FUSE driver when
214215platform prerequisites exist, verifies ` tdc fs drain-file-system ` against the
215216mounted runtime control socket, and also verifies explicit WebDAV fallback on
216217macOS when ` mount_webdav ` is available.
218+ If the live profile has no ` fs_api_key ` , the suite creates a temporary tdc fs
219+ resource named by ` TDC_LIVE_FS_NAME ` or ` workspace ` , stores the generated flat
220+ ` fs_* ` metadata and ` fs_api_key ` , and deletes that auto-created resource when
221+ the test process exits.
217222When a service command is implemented, add its real live verification to
218223` make live-e2e ` ; do not leave the target at profile, smoke-test-only, or
219224mock-only coverage.
@@ -254,14 +259,14 @@ internal/db/ Starter DB cluster, branch, and SQL use cases
254259internal/db/connectionstring/ DB connection string formatters
255260internal/db/sqlaccess/ DB SQL user preparation logic
256261internal/db/sqlcred/ cluster-scoped DB SQL credential store
257- internal/db/sqlhttp/ HTTP SQL transport
262+ internal/db/sqlhttp/ HTTPS SQL API transport
258263internal/db/sqlmysql/ explicit MySQL fallback transport
259264internal/db/sqlresult/ SQL result model and decoding
260265internal/db/sqlsingle/ one-statement validation
261266internal/db/validate/ DB flag and request validation helpers
262267internal/dryrun/ shared dry-run result envelope
263268internal/fs/ tdc fs control-plane, data-plane, and mount use cases
264- internal/output/ structured JSON/human /raw rendering
269+ internal/output/ structured JSON/text /raw rendering
265270internal/organization/ organization project command use cases
266271internal/query/ JMESPath query application
267272internal/secretinput/ no-echo secret input helper
@@ -348,34 +353,35 @@ Implemented command behavior:
348353- ` tdc cli update --target-version v0.1.0 --yes `
349354- ` tdc organization list-projects `
350355- ` tdc organization list-projects --query 'projects[0].id' `
351- - ` tdc organization list-projects --output human `
356+ - ` tdc organization list-projects --output text `
352357- ` tdc db create-db-cluster --db-cluster-name demo --db-cluster-type starter --project-id <project-id> `
353358- ` tdc db create-db-cluster --db-cluster-name demo --db-cluster-type starter --project-id <project-id> --dry-run `
354359- ` tdc db list-db-clusters `
355360- ` tdc db list-db-clusters --query 'clusters[].id' `
356361- ` tdc db describe-db-cluster --db-cluster-id <cluster-id> `
357362- ` tdc db update-db-cluster --db-cluster-id <cluster-id> --db-cluster-name new-name `
358363- ` tdc db update-db-cluster --db-cluster-id <cluster-id> --monthly-spending-limit-usd-cents 1000 --dry-run `
359- - ` tdc db delete-db-cluster --db-cluster-id <cluster-id> --confirm-db-cluster-name <current-name> `
360- - ` tdc db delete-db-cluster --db-cluster-id <cluster-id> --confirm-db-cluster-name <current-name> -- dry-run `
364+ - ` tdc db delete-db-cluster --db-cluster-id <cluster-id> `
365+ - ` tdc db delete-db-cluster --db-cluster-id <cluster-id> --dry-run `
361366- ` tdc db create-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-name dev `
362367- ` tdc db create-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-name dev --dry-run `
363368- ` tdc db list-db-cluster-branches --db-cluster-id <cluster-id> `
364369- ` tdc db list-db-cluster-branches --db-cluster-id <cluster-id> --query 'branches[].id' `
365- - ` tdc db list-db-cluster-branches --db-cluster-id <cluster-id> --output human `
370+ - ` tdc db list-db-cluster-branches --db-cluster-id <cluster-id> --output text `
366371- ` tdc db describe-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> `
367- - ` tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> --confirm-db-cluster-branch-name <current-name> `
368- - ` tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> --confirm-db-cluster-branch-name <current-name> -- dry-run `
369- - ` tdc db prepare -db-query-access --db-cluster-id <cluster-id> `
370- - ` tdc db prepare -db-query-access --db-cluster-id <cluster-id> --dry-run `
371- - ` tdc db create -db-connection-string --db-cluster-id <cluster-id> `
372- - ` tdc db create -db-connection-string --db-cluster-id <cluster-id> --read-write --format mysql-uri `
373- - ` tdc db create -db-connection-string --db-cluster-id <cluster-id> --read-only --format env `
374- - ` tdc db create -db-connection-string --db-cluster-id <cluster-id> --admin --format jdbc `
372+ - ` tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> `
373+ - ` tdc db delete-db-cluster-branch --db-cluster-id <cluster-id> --db-cluster-branch-id <branch-id> --dry-run `
374+ - ` tdc db create -db-sql-users --db-cluster-id <cluster-id> `
375+ - ` tdc db create -db-sql-users --db-cluster-id <cluster-id> --dry-run `
376+ - ` tdc db format -db-connection-string --db-cluster-id <cluster-id> `
377+ - ` tdc db format -db-connection-string --db-cluster-id <cluster-id> --read-write --format mysql-uri `
378+ - ` tdc db format -db-connection-string --db-cluster-id <cluster-id> --read-only --format env `
379+ - ` tdc db format -db-connection-string --db-cluster-id <cluster-id> --admin --format jdbc `
375380- ` tdc db execute-sql-statement --db-cluster-id <cluster-id> --sql "select 1" `
376381- ` tdc db execute-sql-statement --db-cluster-id <cluster-id> --read-write --sql "select 1" `
377382- ` tdc db execute-sql-statement --db-cluster-id <cluster-id> --read-only --sql "select 1" `
378383- ` tdc db execute-sql-statement --db-cluster-id <cluster-id> --admin --sql "select 1" `
384+ - ` tdc db execute-sql-statement --db-cluster-id <cluster-id> --transport https --sql "select 1" `
379385- ` tdc db execute-sql-statement --db-cluster-id <cluster-id> --transport mysql --sql "select 1" `
380386- ` tdc fs create-file-system --file-system-name workspace `
381387- ` tdc fs create-file-system --file-system-name workspace --dry-run `
@@ -396,7 +402,7 @@ Implemented command behavior:
396402- ` tdc fs copy-file --from-stdin --to-remote /workspace/stdin.txt --tag source=stdin --description "stdin upload" `
397403- ` tdc fs copy-file --from-remote /workspace/stdin.txt --to-stdout `
398404- ` tdc fs list-files --path /workspace `
399- - ` tdc fs list-files --path /workspace --output human `
405+ - ` tdc fs list-files --path /workspace --output text `
400406- ` tdc fs describe-file --path /workspace/README.md `
401407- ` tdc fs move-file --from-remote /workspace/README.copy.md --to-remote /workspace/archive/README.md `
402408- ` tdc fs delete-file --path /workspace/archive/README.md `
@@ -411,7 +417,7 @@ Implemented command behavior:
411417- ` tdc fs find-files --path /workspace --file-name-pattern "*.md" --layer-id layer-1 `
412418- ` tdc fs create-layer --layer-id layer-1 --base-root-path /workspace --layer-name task --durability-mode restore-safe --tag task=auth `
413419- ` tdc fs list-layers `
414- - ` tdc fs list-layers --output human `
420+ - ` tdc fs list-layers --output text `
415421- ` tdc fs describe-layer --layer-id layer-1 `
416422- ` tdc fs diff-layer --layer-id layer-1 `
417423- ` tdc fs replay-layer --layer-id layer-1 `
@@ -459,7 +465,7 @@ Implemented command behavior:
459465- ` tdc journal append-journal-entries --journal-id jrn-demo --entry-json '{"type":"task.started"}' `
460466- ` tdc journal read-journal-entries --journal-id jrn-demo --after-seq 0 --limit 100 `
461467- ` tdc journal search-journal-entries --entry-type task.started --label env=dev --include-entries `
462- - ` tdc journal verify-journal --journal-id jrn-demo --output human `
468+ - ` tdc journal verify-journal --journal-id jrn-demo --output text `
463469- ` tdc git clone-git-workspace --repo-url https://github.com/pingcap/tidb.git --target-path ./workspace/tidb `
464470- ` tdc git clone-git-workspace --repo-url https://github.com/pingcap/tidb.git --target-path ./workspace/tidb --blobless --hydrate sync `
465471- ` tdc git hydrate-git-workspace --target-path ./workspace/tidb --timeout 30m `
@@ -489,8 +495,8 @@ Registered command surface:
489495- ` tdc db list-db-cluster-branches `
490496- ` tdc db describe-db-cluster-branch `
491497- ` tdc db delete-db-cluster-branch `
492- - ` tdc db prepare -db-query-access `
493- - ` tdc db create -db-connection-string `
498+ - ` tdc db create -db-sql-users `
499+ - ` tdc db format -db-connection-string `
494500- ` tdc db execute-sql-statement `
495501- ` tdc fs create-file-system `
496502- ` tdc fs delete-file-system `
@@ -666,10 +672,11 @@ not be required by MVP usage.
666672
667673TiDB Cloud control-plane API calls use HTTP Digest auth through
668674` internal/api/transport ` ; never send ` tdc_private_key ` as Basic Auth for those
669- APIs. SQL HTTP execution and tdc fs data-plane auth are separate authentication
670- schemes. SQL HTTP uses the prepared DB SQL username/password as Basic Auth
671- against ` https://http-<cluster-host>/v1beta/sql ` ; TiDB Cloud API keys must not
672- be used for SQL HTTP Basic Auth.
675+ APIs. SQL HTTPS API execution and tdc fs data-plane auth are separate
676+ authentication schemes. SQL HTTPS API execution uses the prepared DB SQL
677+ username/password as Basic Auth against
678+ ` https://http-<cluster-host>/v1beta/sql ` ; TiDB Cloud API keys must not be used
679+ for SQL execution Basic Auth.
673680
674681Use ` internal/api/endpoints ` for Starter, IAM/account, and fs endpoint
675682selection. Do not add service URLs to user config. The default Starter host is
@@ -711,7 +718,7 @@ Generated DB SQL usernames and passwords live in
711718` [profile.db_users."<cluster-id>".role] ` TOML sections to
712719` ~/.tdc/credentials ` . TiDB Cloud cluster IDs are globally unique, so DB SQL
713720credentials are cluster-scoped rather than profile-scoped. `tdc db
714- prepare -db-query-access ` owns those credentials and must be idempotent: it
721+ create -db-sql-users ` owns those credentials and must be idempotent: it
715722creates or repairs the stable tdc-managed read-only, read-write, and admin
716723users for a cluster instead of creating a new group every time.
717724
@@ -827,7 +834,7 @@ missing local Git state when possible, and persist dirty Git workspace changes
827834through ` /v1/git-workspaces/<id>/overlay ` rather than ordinary ` /v1/fs ` file
828835rows.
829836
830- ` tdc db create -db-connection-string ` and ` tdc db execute-sql-statement ` use
837+ ` tdc db format -db-connection-string ` and ` tdc db execute-sql-statement ` use
831838read-write credentials by default. ` --read-write ` , ` --read-only ` , and ` --admin `
832839must be mutually exclusive explicit selections. Do not add SQL-text
833840classification or an automatic access mode.
@@ -839,7 +846,7 @@ Use structured output contracts from the start.
839846- JSON is the default for successful structured control-plane commands.
840847- Data-plane commands may stream bytes or plain file listings when JSON would
841848 break expected filesystem usage.
842- - ` --output json ` and ` --output human ` are the initial output modes.
849+ - ` --output json ` and ` --output text ` are the initial output modes.
843850- ` --query ` uses JMESPath semantics and is applied after command execution to
844851 the structured result.
845852- Raw output commands must reject ` --query ` .
0 commit comments