Files
George Karr a25ae3ddfc Adding initial tool - dibble the tapir for seeding data (#46122)
## Overview

`dibble` is a one-stop CLI for seeding a Fleet server with test data —
users, teams, policies, reports, labels, scripts, MDM profiles,
software, secrets, CAs, and vulns — replacing ~8 ad-hoc seeding tools
with a single binary.

It makes it easy to:
- **Spin up a populated dev/test server in one command** — `dibble all`
plants everything with sensible, idempotent defaults.
- **Skip the flag-memorization** — running `dibble` with no args
launches an interactive wizard that prompts for Fleet URL, API token,
theme, and which entities to seed, and offers to save the config to
`~/.dibble.yaml`.
- **Seed individual entity types** — `dibble users`, `dibble teams`,
`dibble policies`, etc., when you only need one slice.
- **Get themed, recognizable test data** — pick a theme (hitchhikers,
tng, lotr, ghibli, parksrec, …) so seeded names are easy to eyeball in
the UI.

Hosts are intentionally out of scope — `cmd/osquery-perf` still owns
that. `dibble hosts` is a thin convenience wrapper that picks a fleet,
fetches its enroll secret, and prints/runs the osquery-perf invocation
for you.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Dibble: a CLI tool to seed realistic test data, including an
interactive wizard and subcommands for
teams/users/software/policies/scripts/reports/profiles/labels/activities/enroll-secrets/hosts/vulns,
plus theme-driven “cas” and “ping”.
* Theme system: multiple curated themes to generate consistent seeded
identities, policies, software, labels, and scripts.
* **Chores**
* Ignored the built dibble binary and added a Makefile build target to
compile the dibble tool.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-17 11:07:05 -05:00

50 lines
1.8 KiB
Go

package command
import (
"context"
"github.com/spf13/cobra"
"github.com/fleetdm/fleet/v4/tools/dibble/pkg/seed"
)
func newVulnsCmd() *cobra.Command {
cmd := &cobra.Command{
Use: "vulns",
Short: "Seed software rows directly into MySQL for the vuln scanner to chew on",
Long: `Writes rows directly into the software table so Fleet's background
vulnerability scanner has inventory to process. Each row gets a
fleet-compatible checksum, so re-runs are idempotent against the unique
software-checksum index.
NOTE: this only writes the software table. It does NOT create hosts,
host_software entries, or software_cpe associations — vulnerabilities won't
surface against any host until those rows exist (via real ingest or a
follow-up seeder). Use this when you need plausible inventory volume; use
osquery-perf or the legacy seed_vuln_data tool when you need end-to-end
vulnerable-host scenarios.
Requires direct access to the Fleet MySQL instance. The default DSN matches
the local docker-compose dev environment.`,
RunE: func(cmd *cobra.Command, args []string) error {
dsn, _ := cmd.Flags().GetString("dsn")
macos, _ := cmd.Flags().GetInt("macos")
ubuntu, _ := cmd.Flags().GetInt("ubuntu")
windows, _ := cmd.Flags().GetInt("windows")
res := seed.Vulns(context.Background(), seederLogger{}, seed.VulnsOptions{
DSN: dsn,
MacOS: macos,
Ubuntu: ubuntu,
Windows: windows,
})
printf("%s", res.Summary())
return reportErrors(res.Errors)
},
}
cmd.Flags().String("dsn", "fleet:insecure@tcp(localhost:3306)/fleet", "MySQL DSN")
cmd.Flags().Int("macos", 0, "Number of macOS software rows to insert")
cmd.Flags().Int("ubuntu", 0, "Number of Ubuntu software rows to insert")
cmd.Flags().Int("windows", 0, "Number of Windows software rows to insert")
return cmd
}