feat(maintenance): support insecure TLS mode

This commit is contained in:
2026-09-10 13:46:11 +03:00
parent 9d2e856e3f
commit fc8a9bf45d
2 changed files with 30 additions and 6 deletions

View File

@@ -163,6 +163,7 @@ API_KEY="${SS_TOOLS_API_KEY:-}"
# Pass `--auto-end` to `start`: the banner is removed automatically at end_time.
# Without it, end_time is informational only and maintenance must be ended manually.
AUTO_END=0
INSECURE=0
# Color helpers (disabled in non-TTY)
if [[ -t 1 ]]; then
@@ -209,6 +210,10 @@ api_call() {
-H "Content-Type: application/json"
)
if [[ "$INSECURE" -eq 1 ]]; then
curl_args+=(-k)
fi
if [[ -n "$data" ]]; then
curl_args+=(-d "$data")
fi
@@ -407,11 +412,13 @@ EOF
# Main
# Filter the --auto-end flag out of the positional args
# Filter global flags out of the positional args
ARGS=()
for arg in "$@"; do
if [[ "$arg" == "--auto-end" ]]; then
AUTO_END=1
elif [[ "$arg" == "--insecure" ]]; then
INSECURE=1
else
ARGS+=("$arg")
fi
@@ -422,7 +429,7 @@ case "${1:-help}" in
start)
check_auth
if [[ $# -lt 2 ]]; then
echo "Usage: $0 start <tables> [duration_hours] [environment|-] [message] [--auto-end]"
echo "Usage: $0 start <tables> [duration_hours] [environment|-] [message] [--auto-end] [--insecure]"
echo ""
echo "Examples:"
echo " $0 start public.messages 4 dev"
@@ -438,6 +445,7 @@ case "${1:-help}" in
echo ""
echo "--auto-end: also pass auto_end=true so the banner is removed automatically"
echo " at end_time. Without it, end_time is informational only."
echo "--insecure: disable TLS certificate verification (use for self-signed certs)"
exit 1
fi
cmd_start "$2" "${3:-4}" "${4:-}" "${5:-}"
@@ -459,11 +467,12 @@ case "${1:-help}" in
superset-tools Maintenance CLI
Usage:
$0 start <tables> [hours=4] [environment|-] [message] [--auto-end]
$0 start <tables> [hours=4] [environment|-] [message] [--auto-end] [--insecure]
Start maintenance on tables (comma-separated).
environment is OPTIONAL: omit it (or pass '-') to start in ALL PROD
environments (fan-out) the response is a batch { status, events[] }.
--auto-end also removes the banner automatically at end_time (API param auto_end=true).
--insecure disables TLS certificate verification (use for self-signed certs).
$0 end <event-id>
End a specific maintenance event
@@ -481,6 +490,7 @@ Examples:
Environment:
SS_TOOLS_URL superset-tools base URL, no trailing '/' (default: http://localhost:8000)
SS_TOOLS_API_KEY API key with required permissions (required)
--insecure disable TLS certificate verification (use for self-signed certs)
Notes:
Exact environment ids: GET \${SS_TOOLS_URL}/api/environments (unknown id -> 404).

View File

@@ -186,7 +186,7 @@ API_KEY_HEADER = "X-API-Key"
def start_maintenance(base_url: str, api_key: str, tables: list[str],
environment_id: str | None, duration_hours: int = 4,
message: str | None = None, auto_end: bool = False,
timeout: int = 30) -> dict:
timeout: int = 30, insecure: bool = False) -> dict:
"""
Start a maintenance event.
@@ -202,6 +202,7 @@ def start_maintenance(base_url: str, api_key: str, tables: list[str],
auto_end: When True, sends auto_end=true so the scheduler removes the banner
automatically at end_time. When False (default), end_time is informational
only and maintenance must be ended manually via `end`.
insecure: Disable TLS certificate verification for self-signed certificates.
timeout: Request timeout in seconds
Returns:
@@ -248,6 +249,7 @@ def start_maintenance(base_url: str, api_key: str, tables: list[str],
f"{base_url}/api/maintenance/start",
json=payload,
headers={API_KEY_HEADER: api_key},
verify=not insecure,
timeout=timeout,
)
@@ -297,7 +299,7 @@ def start_maintenance(base_url: str, api_key: str, tables: list[str],
def end_maintenance(base_url: str, api_key: str, event_id: str,
timeout: int = 30) -> dict:
timeout: int = 30, insecure: bool = False) -> dict:
"""
End a specific maintenance event and remove its banners.
@@ -305,6 +307,7 @@ def end_maintenance(base_url: str, api_key: str, event_id: str,
base_url: superset-tools base URL
api_key: API key with 'maintenance:end' permission
event_id: The event ID returned by start_maintenance
insecure: Disable TLS certificate verification for self-signed certificates.
timeout: Request timeout in seconds
Returns:
@@ -318,6 +321,7 @@ def end_maintenance(base_url: str, api_key: str, event_id: str,
response = requests.post(
f"{base_url}/api/maintenance/{event_id}/end",
headers={API_KEY_HEADER: api_key},
verify=not insecure,
timeout=timeout,
)
@@ -344,7 +348,7 @@ def end_maintenance(base_url: str, api_key: str, event_id: str,
def end_all_maintenance(base_url: str, api_key: str,
environment_id: str | None = None,
timeout: int = 30) -> dict:
timeout: int = 30, insecure: bool = False) -> dict:
"""
End ALL active maintenance events in the given environment.
USE WITH CAUTION this removes banners from all dashboards.
@@ -354,6 +358,7 @@ def end_all_maintenance(base_url: str, api_key: str,
api_key: API key with 'maintenance:end_all' permission
environment_id: If set, only end events in this environment.
If None, uses the API key's default scope.
insecure: Disable TLS certificate verification for self-signed certificates.
timeout: Request timeout in seconds
Returns:
@@ -374,6 +379,7 @@ def end_all_maintenance(base_url: str, api_key: str,
f"{base_url}/api/maintenance/end-all",
json=payload,
headers={API_KEY_HEADER: api_key},
verify=not insecure,
timeout=timeout,
)
@@ -444,6 +450,11 @@ Examples:
required=True,
help="API key with required permissions",
)
common_opts.add_argument(
"--insecure",
action="store_true",
help="Disable TLS certificate verification (use for self-signed certificates)",
)
subparsers = parser.add_subparsers(dest="command", required=True)
@@ -512,18 +523,21 @@ Examples:
duration_hours=args.duration_hours,
message=args.message,
auto_end=args.auto_end,
insecure=args.insecure,
)
elif args.command == "end":
end_maintenance(
base_url=args.base_url,
api_key=args.api_key,
event_id=args.event_id,
insecure=args.insecure,
)
elif args.command == "end-all":
end_all_maintenance(
base_url=args.base_url,
api_key=args.api_key,
environment_id=args.environment_id,
insecure=args.insecure,
)
except requests.HTTPError:
# Specific error message was already printed by the command function.