mirror of
https://github.com/skoelle/kctl-tui.git
synced 2026-09-17 20:10:24 +00:00
4.8 KiB
4.8 KiB
PLAN.md — Implementation Roadmap
This document tracks how kctl-tui is being built, phase by phase, and what is still open. For the full requirements, see SPEC.md.
Phase 0 — Repository setup (done)
- Go module (
github.com/skoelle/kctl-tui),.gitignore, MITLICENSE. - GitHub Actions workflow:
go vet+go teston every push/PR, plus a cross-platform build matrix (linux/darwin/windows x amd64/arm64) that attaches binaries to GitHub Releases on version tags. install.shfor Linux/macOS/WSL, downloading the latest release asset, with clear diagnostics if no release exists yet or the GitHub API is unreachable.README.md,config.example.yaml.
Phase 1 — Core logic + navigation (done, initial version)
internal/kctl: pure, unit-tested logic — template resolution (ResolveTemplate), namespace/label filtering (DistinctLabelValues,NamespacesForLabelValue), and secret diffing (DiffSecretValues,AnyMismatch).internal/config: YAML config loading with template-based context and secret name resolution (ContextTemplate,SecretNameTemplate,K8sSecretNameTemplate), with safe defaults when no config file exists yet.internal/kubeexec: thin wrappers aroundkubectl/awsCLI calls (namespaces, deployments, rollout restart/status, fetching AWS secrets by template-resolved ID, reading all fields of a Kubernetes secret, ExternalSecret annotation, AWS auth check).cmd/kctl-tui"full" mode: Bubble Tea navigation for context -> team -> namespace, withEsccorrectly popping back one level at a time, defaults pre-selected from the currently active context/namespace.- On confirming a namespace, "full" mode launches the 3-pane
tmuxsession (control pane + twok9spanes,even-verticallayout,remain-on-exitso a crashing control pane stays visible) viatea.ExecProcessand resumes at the namespace screen once the session ends. cmd/kctl-tui"panel" mode: - Redeploy: pick a deployment from a list, confirm, thenrollout restart+rollout status. - Secrets: AWS auth check with interactive SSO login fallback, then automatically resolve the AWS secret ID (fromsecret_name_template) and Kubernetes secret name (fromk8s_secret_name_template), fetch both, diff every field in one table (key / AWS value / Kubernetes value / match status). If any field differs, offer a single force-sync request for the whole secret (one ExternalSecret annotation). -Esccloses the whole tmux session (tmux kill-session).
Phase 2 — Hardening (open)
- Handle non-JSON AWS secrets and Kubernetes secrets with binary (non-UTF8) values more gracefully in the diff table (currently falls back to a single "value" key or may render oddly).
- Add integration-style tests against a local
kind/k3dcluster in CI for thekubeexecwrappers currently excluded from automated testing. - Input validation for the free-text steps in "panel" mode (empty region/secret name, invalid characters).
- Graceful handling when
tmux,k9s, orawsare not installed (currently surfaces the raw exec error). - Structured logging /
--verboseflag for troubleshooting failedkubectl/awscalls. - Paginate/scroll the secrets diff table for secrets with many fields instead of relying on terminal wrapping.
Phase 3 — Windows-native support (open, secondary priority)
- Detect OS at runtime; on native Windows (no WSL), fall back to
wt.exe split-paneinstead oftmuxfor the status panes. - Document/implement that
Esc-triggered session close is not available in the native Windows fallback — the panes must be closed manually there.
Phase 4 — Nice-to-haves (open, not committed)
- Optional direct use of
client-goinstead of shelling out tokubectl, for faster context/namespace/label queries. - Config validation command (
kctl-tui config check) that reports unknown label keys or context names not present in the current kubeconfig. - Homebrew tap /
scoopmanifest as additional install options alongsideinstall.sh.
Notes for contributors
- Keep any real organization-specific context names, namespace names,
label keys, or secret names out of the repository. Use the generic
placeholders already established in
SPEC.mdandconfig.example.yaml. - Pure/testable logic belongs in
internal/kctlandinternal/config; anything that shells out tokubectl/aws/tmuxbelongs ininternal/kubeexecor directly incmd/kctl-tui, and should stay thin enough that it does not need its own test suite.