Conversation
- `cloud postgres backup list <POSTGRES_ID> [--cursor] [--limit 1..100]`:
read-only page of retained base backups; human table (Key, Last
modified) plus a "Next cursor:" line, and --json emits
{result, limit, totalCount, nextCursor}.
- `cloud auth whoami` (Beta): resolves the identity behind the active
credentials. Unscoped (no organization lookup), allowed with OAuth,
and auth failures keep the Auth kind / exit 4. Auth commands that
need a client now take the standard client path; the local ones
still return before credentials are resolved.
- Permission declarations for both, clap/read-write tests, wiremock
coverage for routes, pagination encoding, both whoami variants,
OAuth, 401 and 404, and README notes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#1038) `cloud clickpipe create kafka` and `clickpipe schema-discover kafka` gain `--schema-registry-type confluent|glue` with `--glue-region`, `--glue-registry-name` and `--glue-role-arn`. Omitting the type keeps the existing Confluent request unchanged; Glue conflicts with the Confluent registry flags and needs a role from `--glue-role-arn` or the source's `--iam-role`, rejected as usage errors before any request. `cloud service create --backup-encryption-config <PATH|->` (private preview, requires `--backup-id`) passes a backup's encryption_config.json object through unchanged as `backupEncryptionConfig`; unreadable or non-object input is a usage error before any request. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
sdairs
added this pull request to stack #1001
October 1, 2026 19:02
This was referenced Oct 1, 2026
cloud service query: bind the caller's own API key (via whoami) instead of minting a query key
#1043
Open
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #1038. Stacked on #1039 (→ #1036 → #1035 → #1028).
Exposes the library additions from #1039 in the CLI.
Commands
cloud postgres backup list <POSTGRES_ID> [--cursor C] [--limit 1..100]backupgroup undercloud postgres, built likeslow-queries. It is a read.--jsonprints{result, limit, totalCount, nextCursor}; each item is{key, lastModified}.Key/Last modifiedtable, followed byNext cursor: …when there is one.cloud auth whoami(Beta)cloud::runclient path: a newAuthCommands::needs_client()routes it there, and the local auth commands keep their early return.cloud clickpipe create kafka: AWS Glue Schema Registry support (also onschema discover).--schema-registry-type confluent|glue(Confluent when omitted),--glue-region,--glue-registry-nameand--glue-role-arn.--glue-role-arnor--iam-roleis a usage error, because the spec defaults the Glue role to the source's IAM role."type":"confluent"is sent only when the type is named explicitly.clickpipe updateneeds no change, because the patch schema has no registry.cloud service create --backup-encryption-config <PATH|->(private preview)--backup-id.encryption_config.jsonverbatim asbackupEncryptionConfig.Permission declarations are added for both new commands.
whoamideclares no named permissions, matching the spec.Tests
needs_clientclickpipe getwith a Glue registryGates
cargo fmtand both clippy configurations are clean.cargo test -p clickhousectlpasses in full, local Docker suites included. The Python classifier tests pass; no files were added, so the classifiers needed no change. The README has new examples for each command.🤖 Generated with Claude Code