Conversation
|
If you're new to commit signing, there are different ways to set it up: Sign commits with
|
6122e82 to
24adb36
Compare
Marton6
left a comment
There was a problem hiding this comment.
Looks good! Thank you for your contribution
|
Neat-o. Perhaps 1 more reviewer. 👁️ @mrjones2014 if you have the time |
|
Semi-yearly vibe check for 1 more review to get this merged. Perhaps @bertrmz @RyanPrussin |
24adb36 to
51aadf7
Compare
| "COCKROACH_HOST": fieldname.Host, | ||
| "COCKROACH_PORT": fieldname.Port, | ||
| "COCKROACH_USER": fieldname.User, | ||
| "COCKROACH_PASSWORD": fieldname.Password, |
There was a problem hiding this comment.
| "COCKROACH_PASSWORD": fieldname.Password, | |
| "PGPASSWORD": fieldname.Password, |
I tested a real CockroachDB v26.3.1 cluster with COCKROACH_PASSWORD set, cockroach sql still drops to an interactive Enter password: prompt instead of connecting. cockroach's SQL client is libpq-compatible and reads the standard PGPASSWORD env var and I was able to confirm that it worked with this locally.
@syndbg Thanks so much for fixing that so quickly, I have left some comments with some of my other findings, if you address them I would be more than happy to approve and merge. |
|
Cheers. Will re-check over the next few days and get it again in shape. |
Adds the ability to read Database Credentials and inject for `cockroach sql`. Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
The names were updated upstream. Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
51aadf7 to
d7853bd
Compare
1Password rejects URL fields on Database items, which prevents importing CockroachDB credentials. Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
The SQL CLI ignores COCKROACH_PASSWORD and prompts for a password. Use PGPASSWORD so provisioned credentials authenticate correctly. Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
Run the importer and provisioner against CockroachDB in Docker. Check insecure and TLS connections, password failures, and the environment variable the SQL CLI accepts. Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
Signed-off-by: Anton Antonov <anton.synd.antonov@gmail.com>
|
Okay, had more time than I expected. It's working and verified now. And a user test. I re-checked with the same cockroachdb I had previously tested with This is what I put in my OP Vault
Full gif showcasing the user flow. From an
@rr3khan ready for re-review. 🍻 |


Overview
This PR adds a new shell plugin for CockroachDB that enables secure credential management for the
cockroach sqlcommand. The plugin supports both local development (insecure mode) and production environments (secure TLS connections) through environment variable configuration.Type of change
Related Issue(s)
How To Test
tl;dr There's a demo. https://streamable.com/btqzp5. It goes from a clean DB credential creation, renaming fields to match the expected format, etc.
Apologies for the streamable link, but GitHub has a 10mb file size limit and the mp4 demo video was already 58 or so mb.
Set up database credentials in 1Password with the following fields:
localhost26257rootdefaultdb1(for local development)Test with local CockroachDB instance:
Test environment variable import:
Run plugin validation:
Changelog
The CockroachDB plugin enables authentication for the
cockroach sqlcommand using Touch ID and other unlock options with 1Password Shell Plugins.