Metadata-Version: 2.4
Name: gnetcli_adapter
Version: 2.8.5
Summary: Gnetcli-server adapter for Annet
Author-email: Aleksandr Balezin <gescheit12@gmail.com>
Requires-Python: >=3.10
Description-Content-Type: text/markdown
Classifier: Development Status :: 3 - Alpha
Classifier: Intended Audience :: Developers
Classifier: License :: OSI Approved :: MIT License
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Programming Language :: Python :: 3.10
Classifier: Programming Language :: Python :: 3.11
License-File: LICENSE
Requires-Dist: exceptiongroup>=1.1.3; python_version<'3.11'
Requires-Dist: annet>=4.6.10
Requires-Dist: gnetclisdk>=1.3.5
Requires-Dist: pydantic_settings
Requires-Dist: pydantic
Requires-Dist: bandit[toml]==1.7.5 ; extra == "test"
Requires-Dist: black==23.3.0 ; extra == "test"
Requires-Dist: check-manifest==0.49 ; extra == "test"
Requires-Dist: flake8-bugbear==23.5.9 ; extra == "test"
Requires-Dist: flake8-docstrings ; extra == "test"
Requires-Dist: flake8-formatter_junit_xml ; extra == "test"
Requires-Dist: flake8 ; extra == "test"
Requires-Dist: flake8-pyproject ; extra == "test"
Requires-Dist: pre-commit==3.3.1 ; extra == "test"
Requires-Dist: pylint==2.17.4 ; extra == "test"
Requires-Dist: pylint_junit ; extra == "test"
Requires-Dist: pytest-cov==4.0.0 ; extra == "test"
Requires-Dist: pytest-mock<3.10.1 ; extra == "test"
Requires-Dist: pytest-runner ; extra == "test"
Requires-Dist: pytest==7.3.1 ; extra == "test"
Requires-Dist: pytest-github-actions-annotate-failures ; extra == "test"
Requires-Dist: shellcheck-py==0.9.0.2 ; extra == "test"
Project-URL: Documentation, https://github.com/annetutil/gnetcli_adapter
Project-URL: Source, https://github.com/annetutil/gnetcli_adapter
Project-URL: Tracker, https://github.com/annetutil/gnetcli_adapter/issues
Provides-Extra: test

# gnetcli_adapter
This package provides deployer and fetcher adapters for Annet

# Examples

## Using specified login and password

cat ~/.annet/context.yml
```yaml
fetcher:
  default:
    adapter: gnetcli
    params: &gnetcli
      dev_login: mylogin
      dev_password: mypassword
deployer:
  default:
    adapter: gnetcli
    params:
      <<: *gnetcli
...
context:
  default:
    fetcher: default
    deployer: default
selected_context: default
```

## Using tunnel through master SSH-connection

https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Multiplexing

cat ~/.ssh/config
```
Host myhost*
    ProxyJump mybastion

Host mybastion
    ControlMaster auto
    ControlPath ~/.ssh/mastersockets/%r@%h:%p
    ControlPersist 120m
```

`~/.annet/context.yml` the same because gnetcli read .ssh/config by default.

## Enforcing minimum command timeouts

`min_cmd_timeout` and `min_read_timeout` set lower bounds, in seconds, for
timeouts sent to `gnetcli_server`. Values configured on individual Annet
commands are preserved when they are larger.

```yaml
fetcher:
  default:
    adapter: gnetcli
    params: &gnetcli
      min_cmd_timeout: 120
      min_read_timeout: 60
deployer:
  default:
    adapter: gnetcli
    params:
      <<: *gnetcli
```

With this configuration, a command timeout of 30 seconds is raised to 120,
while a command timeout of 180 seconds remains unchanged. Omit either setting
to leave that timeout unchanged.

## Connecting to an externally-running gnetcli_server

If `gnetcli_server` is already running on a bastion host, set `url` and the
adapter will connect to it instead of spawning a local server binary. `login`
and `password` authenticate to the gnetcli server itself (Basic auth);
`dev_login`/`dev_password` are still the network device credentials.

```yaml
fetcher:
  default:
    adapter: gnetcli
    params: &gnetcli
      url: 192.0.2.10:50051
      login: gnetcli-user
      password: gnetcli-secret
      dev_login: mylogin
      dev_password: mypassword
deployer:
  default:
    adapter: gnetcli
    params:
      <<: *gnetcli
```

When `url` is unset, the adapter starts a local `gnetcli_server` subprocess
(`server_path` defaults to `gnetcli_server` on `$PATH`).

The default `insecure_grpc: true` means the external-server example does not
use TLS. Basic authentication over plaintext is only appropriate on a trusted
local/tunnelled connection. Do not expose it directly to an untrusted network.
For local key-only server credentials, omit both `dev_login` and `dev_password`;
explicit per-device credentials override the server defaults.

