Repository navigation
Commit 2149b6f
authored
feat: request time-boxed operation access from the CLI (#540)
## Summary
- Adds `alien access-requests create/get/wait` so CLI/API callers
(customers running their own AI agent, or a human) can request
time-boxed operation access without Slack.
- `create` supports both exact (`--operation <plugin>/<operation>`) and
wildcard (`--operation <plugin>/*` + `--max-risk`) requests through a
single `--operation` flag.
- `get`/`wait` fetch and print the customer's actual `kubectl patch ...`
approve command once the operator materializes the grant CR, polling
briefly so it's available right after creation rather than requiring a
follow-up call.
- `operations invoke --request-access` creates an access request, waits
for approval, then re-invokes the operation.
- Approval always happens on the customer's side, in-cluster — there is
deliberately no CLI action that approves a request.
## Test plan
- [x] `cargo check -p alien-cli` and `cargo test -p alien-cli --lib
access_requests` pass
- [x] Manually exercised end-to-end against a local kind cluster: create
→ operator materializes grant CR → `kubectl patch` approve →
`wait`/`invoke` dispatches → verified pod restart via `kubectl get pods`
- [x] Manually exercised the wildcard path (`--operation 'kubernetes/*'
--max-risk mutating`)
🤖 Generated with [Claude Code](https://claude.com/claude-code)1 parent e583edf commit 2149b6f
7 files changed
Lines changed: 1076 additions & 81 deletions
File tree
- client-sdks/platform
- rust
- crates/alien-cli/src
- commands
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments