Files
George Karr a25ae3ddfc Adding initial tool - dibble the tapir for seeding data (#46122)
## Overview

`dibble` is a one-stop CLI for seeding a Fleet server with test data —
users, teams, policies, reports, labels, scripts, MDM profiles,
software, secrets, CAs, and vulns — replacing ~8 ad-hoc seeding tools
with a single binary.

It makes it easy to:
- **Spin up a populated dev/test server in one command** — `dibble all`
plants everything with sensible, idempotent defaults.
- **Skip the flag-memorization** — running `dibble` with no args
launches an interactive wizard that prompts for Fleet URL, API token,
theme, and which entities to seed, and offers to save the config to
`~/.dibble.yaml`.
- **Seed individual entity types** — `dibble users`, `dibble teams`,
`dibble policies`, etc., when you only need one slice.
- **Get themed, recognizable test data** — pick a theme (hitchhikers,
tng, lotr, ghibli, parksrec, …) so seeded names are easy to eyeball in
the UI.

Hosts are intentionally out of scope — `cmd/osquery-perf` still owns
that. `dibble hosts` is a thin convenience wrapper that picks a fleet,
fetches its enroll secret, and prints/runs the osquery-perf invocation
for you.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Dibble: a CLI tool to seed realistic test data, including an
interactive wizard and subcommands for
teams/users/software/policies/scripts/reports/profiles/labels/activities/enroll-secrets/hosts/vulns,
plus theme-driven “cas” and “ping”.
* Theme system: multiple curated themes to generate consistent seeded
identities, policies, software, labels, and scripts.
* **Chores**
* Ignored the built dibble binary and added a Makefile build target to
compile the dibble tool.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-17 11:07:05 -05:00

51 lines
1.6 KiB
Go

package seed
import (
"github.com/fleetdm/fleet/v4/tools/dibble/pkg/themes"
)
// SeedUsers creates `count` users on the Fleet server using names drawn from
// the given theme. Roles cycle through observer / observer_plus / maintainer /
// admin / gitops so the seeded set covers every permission level.
//
// All users share a known dev password so tests can sign in as them; production
// Fleets should never run this against a real deployment.
const SeededUserPassword = "DibbleSeed123!"
var seededRoles = []string{
"observer", "observer_plus", "maintainer", "admin", "gitops",
}
func Users(c Client, log Logger, theme themes.Theme, count int) Result {
res := Result{Entity: "users"}
for i := 0; i < count; i++ {
name := themes.FullName(theme, i)
email := themes.Email(theme, i)
role := seededRoles[i%len(seededRoles)]
body := map[string]any{
"name": name,
"email": email,
"global_role": role,
"admin_forced_password_reset": false,
"password": SeededUserPassword,
}
// GitOps users authenticate via API token only, but Fleet's
// /users/admin endpoint still requires a password be set on the
// record (only SSO-enabled creates waive that requirement).
if role == "gitops" {
body["api_only"] = true
}
err := c.Post("/api/latest/fleet/users/admin", body, nil)
switch {
case err == nil:
res.Created++
log.Printf("user %s <%s> [%s]", name, email, role)
case IsAlreadyExists(err):
res.Skipped++
default:
res.Errors = append(res.Errors, err)
}
}
return res
}