Skip to content

feat(cli): Postgres backup list, auth whoami, Kafka Glue schema registry, backup encryption config (#1038) - #1040

Open
sdairs wants to merge 2 commits into
claude/drift-delta-api-1027from
claude/drift-delta-cli-1038
Open

sdairs wants to merge 2 commits into
claude/drift-delta-api-1027from
claude/drift-delta-cli-1038

Conversation

@sdairs

@sdairs sdairs commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Closes #1038. Stacked on #1039 (→ #1036 → #1035 → #1028).

Exposes the library additions from #1039 in the CLI.

Commands

  • cloud postgres backup list <POSTGRES_ID> [--cursor C] [--limit 1..100]
    • New backup group under cloud postgres, built like slow-queries. It is a read.
    • --json prints {result, limit, totalCount, nextCursor}; each item is {key, lastModified}.
    • Human output is a Key / Last modified table, followed by Next cursor: … when there is one.
    • The agent context notes that a Postgres restore targets a point in time, not a backup key.
  • cloud auth whoami (Beta)
    • Shows the user and its organizations, or the API key, behind the active credentials.
    • Works with OAuth or an API key and never looks up an organization.
    • A 401 or 403 exits 4, and so do missing credentials, before any request.
    • The command goes through the normal cloud::run client path: a new AuthCommands::needs_client() routes it there, and the local auth commands keep their early return.
  • cloud clickpipe create kafka: AWS Glue Schema Registry support (also on schema discover).
    • New flags: --schema-registry-type confluent|glue (Confluent when omitted), --glue-region, --glue-registry-name and --glue-role-arn.
    • Glue requires a region and a registry name, and conflicts with the Confluent URL/credential/CA flags.
    • Glue without --glue-role-arn or --iam-role is a usage error, because the spec defaults the Glue role to the source's IAM role.
    • Existing Confluent invocations send a byte-identical request. "type":"confluent" is sent only when the type is named explicitly.
    • clickpipe update needs no change, because the patch schema has no registry.
  • cloud service create --backup-encryption-config <PATH|-> (private preview)
    • Requires --backup-id.
    • Sends the backup's encryption_config.json verbatim as backupEncryptionConfig.
    • A file that can't be read, isn't JSON, or isn't a JSON object is a usage error before any HTTP request.

Permission declarations are added for both new commands. whoami declares no named permissions, matching the spec.

Tests

  • Unit:
    • clap parsing, limits and conflicts
    • read/write classification and needs_client
    • minimal and maximal builders for both registry variants, with and without the encryption config
    • usage errors
    • table rendering
  • Wiremock:
    • backup list: cursor/limit encoding, JSON and human output, an OAuth bearer, and a 404
    • whoami: the user, API-key and unknown variants in both output modes, with no org lookup; a 401 and missing credentials both exit 4
    • the exact Glue body, with and without a role ARN; explicit versus implied Confluent
    • 7 Glue misuse cases, each exiting 2 with no request
    • clickpipe get with a Glue registry
    • service create with the encryption config from a file and from stdin, with nested content unchanged; bad input exits 2 with no request

Gates

cargo fmt and both clippy configurations are clean. cargo test -p clickhousectl passes in full, local Docker suites included. The Python classifier tests pass; no files were added, so the classifiers needed no change. The README has new examples for each command.

🤖 Generated with Claude Code

sdairs and others added 2 commits October 1, 2026 19:39
- `cloud postgres backup list <POSTGRES_ID> [--cursor] [--limit 1..100]`:
  read-only page of retained base backups; human table (Key, Last
  modified) plus a "Next cursor:" line, and --json emits
  {result, limit, totalCount, nextCursor}.
- `cloud auth whoami` (Beta): resolves the identity behind the active
  credentials. Unscoped (no organization lookup), allowed with OAuth,
  and auth failures keep the Auth kind / exit 4. Auth commands that
  need a client now take the standard client path; the local ones
  still return before credentials are resolved.
- Permission declarations for both, clap/read-write tests, wiremock
  coverage for routes, pagination encoding, both whoami variants,
  OAuth, 401 and 404, and README notes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
#1038)

`cloud clickpipe create kafka` and `clickpipe schema-discover kafka` gain
`--schema-registry-type confluent|glue` with `--glue-region`,
`--glue-registry-name` and `--glue-role-arn`. Omitting the type keeps the
existing Confluent request unchanged; Glue conflicts with the Confluent
registry flags and needs a role from `--glue-role-arn` or the source's
`--iam-role`, rejected as usage errors before any request.

`cloud service create --backup-encryption-config <PATH|->` (private preview,
requires `--backup-id`) passes a backup's encryption_config.json object
through unchanged as `backupEncryptionConfig`; unreadable or non-object
input is a usage error before any request.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CLI: expose Postgres backup list, whoami, Kafka Glue schema registry and backup encryption config (follow-up to #1027)

1 participant