Rename the `rails/` directory to `tools/` for agent discoverability — agents frequently failed to locate helper scripts due to the non-intuitive directory name. Add backward-compat symlink `rails/ → tools/`. New tool suites: - Authentik: auth-token, user-list, user-create, group-list, app-list, flow-list, admin-status (8 scripts) - Coolify: team-list, project-list, service-list, service-status, deploy, env-set (7 scripts) - Woodpecker: pipeline-list, pipeline-status, pipeline-trigger (3 stubs) - GLPI: session-init, computer-list, ticket-list, ticket-create, user-list (6 scripts) - Health: stack-health.sh — stack-wide connectivity check Infrastructure: - Shared credential loader at tools/_lib/credentials.sh - install.sh creates symlink + chmod on tool scripts - All ~253 rails/ path references updated across 68+ files Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
94 lines
2.9 KiB
Bash
Executable File
94 lines
2.9 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
#
|
|
# user-create.sh — Create an Authentik user
|
|
#
|
|
# Usage: user-create.sh -u <username> -n <name> -e <email> [-p password] [-g group]
|
|
#
|
|
# Options:
|
|
# -u username Username (required)
|
|
# -n name Display name (required)
|
|
# -e email Email address (required)
|
|
# -p password Initial password (optional — user gets set-password flow if omitted)
|
|
# -g group Group name to add user to (optional)
|
|
# -f format Output format: table (default), json
|
|
# -h Show this help
|
|
#
|
|
# Environment variables (or credentials.json):
|
|
# AUTHENTIK_URL — Authentik instance URL
|
|
set -euo pipefail
|
|
|
|
MOSAIC_HOME="${MOSAIC_HOME:-$HOME/.config/mosaic}"
|
|
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
|
|
source "$MOSAIC_HOME/tools/_lib/credentials.sh"
|
|
load_credentials authentik
|
|
|
|
USERNAME="" NAME="" EMAIL="" PASSWORD="" GROUP="" FORMAT="table"
|
|
|
|
while getopts "u:n:e:p:g:f:h" opt; do
|
|
case $opt in
|
|
u) USERNAME="$OPTARG" ;;
|
|
n) NAME="$OPTARG" ;;
|
|
e) EMAIL="$OPTARG" ;;
|
|
p) PASSWORD="$OPTARG" ;;
|
|
g) GROUP="$OPTARG" ;;
|
|
f) FORMAT="$OPTARG" ;;
|
|
h) head -18 "$0" | grep "^#" | sed 's/^# \?//'; exit 0 ;;
|
|
*) echo "Usage: $0 -u <username> -n <name> -e <email> [-p password] [-g group]" >&2; exit 1 ;;
|
|
esac
|
|
done
|
|
|
|
if [[ -z "$USERNAME" || -z "$NAME" || -z "$EMAIL" ]]; then
|
|
echo "Error: -u username, -n name, and -e email are required" >&2
|
|
exit 1
|
|
fi
|
|
|
|
TOKEN=$("$SCRIPT_DIR/auth-token.sh" -q)
|
|
|
|
# Build user payload
|
|
payload=$(jq -n \
|
|
--arg username "$USERNAME" \
|
|
--arg name "$NAME" \
|
|
--arg email "$EMAIL" \
|
|
'{username: $username, name: $name, email: $email, is_active: true}')
|
|
|
|
# Add password if provided
|
|
if [[ -n "$PASSWORD" ]]; then
|
|
payload=$(echo "$payload" | jq --arg pw "$PASSWORD" '. + {password: $pw}')
|
|
fi
|
|
|
|
# Add to group if provided
|
|
if [[ -n "$GROUP" ]]; then
|
|
# Look up group PK by name
|
|
group_response=$(curl -sk \
|
|
-H "Authorization: Bearer $TOKEN" \
|
|
"${AUTHENTIK_URL}/api/v3/core/groups/?search=${GROUP}")
|
|
group_pk=$(echo "$group_response" | jq -r ".results[] | select(.name == \"$GROUP\") | .pk" | head -1)
|
|
if [[ -n "$group_pk" ]]; then
|
|
payload=$(echo "$payload" | jq --arg gk "$group_pk" '. + {groups: [$gk]}')
|
|
else
|
|
echo "Warning: Group '$GROUP' not found — creating user without group" >&2
|
|
fi
|
|
fi
|
|
|
|
response=$(curl -sk -w "\n%{http_code}" -X POST \
|
|
-H "Authorization: Bearer $TOKEN" \
|
|
-H "Content-Type: application/json" \
|
|
-d "$payload" \
|
|
"${AUTHENTIK_URL}/api/v3/core/users/")
|
|
|
|
http_code=$(echo "$response" | tail -n1)
|
|
body=$(echo "$response" | sed '$d')
|
|
|
|
if [[ "$http_code" != "201" ]]; then
|
|
echo "Error: Failed to create user (HTTP $http_code)" >&2
|
|
echo "$body" | jq -r '.' 2>/dev/null >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ "$FORMAT" == "json" ]]; then
|
|
echo "$body" | jq '.'
|
|
else
|
|
echo "User created successfully:"
|
|
echo "$body" | jq -r '" Username: \(.username)\n Name: \(.name)\n Email: \(.email)\n PK: \(.pk)"'
|
|
fi
|