Skip to content

Commit 8970dd3

Browse files
authored
Merge pull request #10 from tidbcloud/feat-updater-update
feat: make tdc updates user-owned and password-free
2 parents 0c894cc + be20356 commit 8970dd3

16 files changed

Lines changed: 415 additions & 214 deletions

‎AGENTS.md‎

Lines changed: 14 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -335,13 +335,19 @@ Follow these rules unless `docs/priciples.md` is updated:
335335
- `tdc update` may replace only tdc-owned archive/script installs. It must
336336
refuse local, unknown, Homebrew, Scoop, Winget, or other package-manager
337337
installs with actionable guidance.
338-
- Installer scripts prefer upgrading the active `tdc`/`tdc.exe` found on
339-
`PATH` unless `--install-dir` or `TDC_INSTALL_DIR` overrides it. On
340-
macOS/Linux, no active binary means defaulting to `/usr/local/bin` and using
341-
`sudo` for directory creation or binary replacement when needed.
338+
- `tdc update` is itself explicit update intent and must not require `--yes`.
339+
It downloads, extracts, verifies, stages, and replaces artifacts as the
340+
current user and must never invoke sudo or another privilege escalation
341+
mechanism.
342+
- Installer scripts default to the stable user-owned `~/.tdc/bin` directory on
343+
macOS, Linux, and Windows unless `--install-dir`/`-InstallDir` or
344+
`TDC_INSTALL_DIR` overrides it. They must not prefer or overwrite an active
345+
system-level tdc found on PATH, invoke sudo, create system-directory
346+
symlinks, or modify shell profile files automatically.
342347
- Installer scripts must detect PATH shadowing, bootstrap `~/.tdc/config` only
343-
when missing, print DB and tdc fs region lists, and show clear next steps.
344-
They must never write `~/.tdc/credentials`.
348+
when missing, print the exact command that prepends `~/.tdc/bin` to PATH,
349+
print DB and tdc fs region lists, and show clear next steps. They must never
350+
write `~/.tdc/credentials`.
345351

346352
## Commands
347353

@@ -358,8 +364,8 @@ Implemented command behavior:
358364
- `tdc update --check`
359365
- `tdc update --check --fail-if-update-available`
360366
- `tdc update --dry-run`
361-
- `tdc update --yes`
362-
- `tdc update --target-version v0.1.0 --yes`
367+
- `tdc update`
368+
- `tdc update --target-version v0.1.1`
363369
- `tdc organization list-projects`
364370
- `tdc organization list-projects --query 'projects[0].id'`
365371
- `tdc organization list-projects --output text`

‎README.md‎

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11,14 +11,20 @@ macOS and Linux users:
1111

1212
```bash
1313
curl -fsSL https://github.com/tidbcloud/tdc/releases/latest/download/install.sh | sh -s -- --yes
14+
export PATH="$HOME/.tdc/bin:$PATH"
15+
tdc --version
1416
```
1517

18+
The installer writes `tdc` and `tdc-drive9` to `~/.tdc/bin` without sudo. Add the `export PATH=...` line to your shell profile to make it persistent.
19+
1620
Windows users:
1721

1822
```powershell
1923
$script = "$env:TEMP\install-tdc.ps1"
2024
iwr https://github.com/tidbcloud/tdc/releases/latest/download/install.ps1 -OutFile $script
21-
powershell -ExecutionPolicy Bypass -File $script -InstallDir "$HOME\bin" -Yes
25+
powershell -ExecutionPolicy Bypass -File $script -Yes
26+
$env:Path = "$HOME\.tdc\bin;$env:Path"
27+
tdc --version
2228
```
2329

2430
## Quick Start Guide
@@ -109,10 +115,12 @@ Each project includes a `type`: `tidbx` identifies a regular project and `tidbx_
109115
```bash
110116
tdc update --check
111117
tdc update --dry-run
112-
tdc update --yes
113-
tdc update --target-version v0.1.0 --yes
118+
tdc update
119+
tdc update --target-version v0.1.1
114120
```
115121

122+
`tdc update` downloads and verifies both `tdc` and its `tdc-drive9` companion before replacing either binary in the user-writable install directory. It never requests sudo. Legacy installations under `/usr/local/bin` must run the installer once to migrate to `~/.tdc/bin`.
123+
116124
## Build from source
117125

118126
Requirements:

‎docs/priciples.md‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -162,9 +162,13 @@ CLI v2 for TiDB Cloud \| Init Date: 2026\-05\-18 \|@Todd Bao
162162

163163
- Update checks are explicit, for example `tdc update --check`\.
164164

165-
- Self\-update is explicit, for example `tdc update --yes`, and must
165+
- Self\-update is explicit, for example `tdc update`, and must
166166
refuse package\-manager installs with actionable instructions\.
167167

168+
- Direct installers place binaries in the user\-owned `~/.tdc/bin`
169+
directory\. Installation and update must not require sudo; users add
170+
`export PATH="$HOME/.tdc/bin:$PATH"` to their shell environment\.
171+
168172
5. `--output`
169173

170174
6. `--query` / JMESPath** ** — Even with JSON, there is no way to extract a single field \(e\.g\., cluster ID from a create response\)\. The dev/agent must parse the entire response\. Provide `--query` to remove noisy output and save tokens\. For `db` command, if SQL executions are designed in the future, it will use `--sql`, no conflicts here\.

‎docs/release-notes/v0.1.1.md‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# tdc v0.1.1
22

3-
This release adds configuration-free tdc fs access for ephemeral agent sandboxes. An existing file system can now be used without running `tdc configure` or providing TiDB Cloud API keys: supply `TDC_FS_TOKEN`, `TDC_REGION_CODE`, and `TDC_FS_FILE_SYSTEM_NAME`, then use the normal `tdc fs`, `tdc fs-git`, `tdc fs-journal`, and `tdc fs-vault` commands.
3+
This release adds configuration-free tdc fs access for ephemeral agent sandboxes and makes tdc installation and updates fully user-owned. An existing file system can be used without running `tdc configure` or providing TiDB Cloud API keys: supply `TDC_FS_TOKEN`, `TDC_REGION_CODE`, and `TDC_FS_FILE_SYSTEM_NAME`, then use the normal `tdc fs`, `tdc fs-git`, `tdc fs-journal`, and `tdc fs-vault` commands.
44

55
```bash
66
export TDC_FS_TOKEN="drive9_..."
@@ -13,10 +13,17 @@ tdc fs mount-file-system --file-system-name workspace --mount-path ./workspace
1313

1414
The release keeps environment-provided credentials in memory, preserves configured profile workflows, isolates companion runtime state per file system, and allows drain and unmount operations to locate a configuration-free mount without storing its FS token.
1515

16-
Upgrade an existing archive or installer-managed `v0.1.0` installation with:
16+
On macOS and Linux, the installer now places `tdc` and `tdc-drive9` in `~/.tdc/bin`; Windows uses `%USERPROFILE%\.tdc\bin`. It does not use `sudo`, write to `/usr/local/bin`, or create system-level links. Add the user-owned directory to `PATH` after installation:
1717

1818
```bash
19-
tdc update --check
20-
tdc update --yes
19+
curl -fsSL https://github.com/tidbcloud/tdc/releases/latest/download/install.sh | sh -s -- --yes
20+
export PATH="$HOME/.tdc/bin:$PATH"
2121
tdc --version
2222
```
23+
24+
Once installed in the user-owned directory, `tdc update` verifies and replaces both bundled binaries without `--yes` or elevated privileges:
25+
26+
```bash
27+
tdc update --check
28+
tdc update
29+
```

‎docs/spec/0020-homebrew-and-scoop-distribution.md‎

Lines changed: 8 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ Existing `tdc` commands keep the same behavior:
2626
```bash
2727
tdc update --check
2828
tdc update --dry-run
29-
tdc update --yes
29+
tdc update
3030
```
3131

3232
For Homebrew and Scoop installs, `tdc update` must not replace the binary. It returns `update.managed_install` with the correct package-manager command.
@@ -59,13 +59,13 @@ No user `~/.tdc/` config or credentials are required for package-manager install
5959

6060
## Output And Errors
6161

62-
`tdc update --yes` from a Homebrew install:
62+
`tdc update` from a Homebrew install:
6363

6464
```text
6565
tdc [ERROR]: tdc is managed by homebrew; update it with `brew upgrade tidbcloud/tap/tdc`
6666
```
6767

68-
`tdc update --yes` from a Scoop install:
68+
`tdc update` from a Scoop install:
6969

7070
```text
7171
tdc [ERROR]: tdc is managed by scoop; update it with `scoop update tdc`
@@ -78,15 +78,17 @@ The structured error code remains `update.managed_install`.
7878
Users can choose between direct GitHub Releases installers and package-manager installs:
7979

8080
```bash
81-
curl -fsSL https://github.com/tidbcloud/tdc/releases/latest/download/install.sh | sh -s -- --install-dir "$HOME/.local/bin" --yes
81+
curl -fsSL https://github.com/tidbcloud/tdc/releases/latest/download/install.sh | sh -s -- --yes
82+
export PATH="$HOME/.tdc/bin:$PATH"
8283
brew install tidbcloud/tap/tdc
8384
```
8485

8586
Windows users can choose between the PowerShell installer and Scoop:
8687

8788
```powershell
8889
iwr https://github.com/tidbcloud/tdc/releases/latest/download/install.ps1 -OutFile $env:TEMP\install-tdc.ps1
89-
powershell -ExecutionPolicy Bypass -File $env:TEMP\install-tdc.ps1 -InstallDir "$HOME\bin" -Yes
90+
powershell -ExecutionPolicy Bypass -File $env:TEMP\install-tdc.ps1 -Yes
91+
$env:Path = "$HOME\.tdc\bin;$env:Path"
9092
scoop bucket add icemap https://github.com/tidbcloud/scoop-bucket
9193
scoop install tdc
9294
```
@@ -153,7 +155,7 @@ Runtime update call chain from package-managed installs:
153155
- `scoop bucket add icemap https://github.com/tidbcloud/scoop-bucket` and `scoop install tdc` install `tdc.exe` on Windows.
154156
- `scoop update tdc` upgrades to a newer release.
155157
- `tdc update --check` works from Homebrew and Scoop installs.
156-
- `tdc update --yes` refuses Homebrew and Scoop installs with `update.managed_install`.
158+
- `tdc update` refuses Homebrew and Scoop installs with `update.managed_install`.
157159
- README documents Homebrew and Scoop as optional package-manager channels.
158160

159161
## Out Of Scope

0 commit comments

Comments
 (0)