## Overview `dibble` is a one-stop CLI for seeding a Fleet server with test data — users, teams, policies, reports, labels, scripts, MDM profiles, software, secrets, CAs, and vulns — replacing ~8 ad-hoc seeding tools with a single binary. It makes it easy to: - **Spin up a populated dev/test server in one command** — `dibble all` plants everything with sensible, idempotent defaults. - **Skip the flag-memorization** — running `dibble` with no args launches an interactive wizard that prompts for Fleet URL, API token, theme, and which entities to seed, and offers to save the config to `~/.dibble.yaml`. - **Seed individual entity types** — `dibble users`, `dibble teams`, `dibble policies`, etc., when you only need one slice. - **Get themed, recognizable test data** — pick a theme (hitchhikers, tng, lotr, ghibli, parksrec, …) so seeded names are easy to eyeball in the UI. Hosts are intentionally out of scope — `cmd/osquery-perf` still owns that. `dibble hosts` is a thin convenience wrapper that picks a fleet, fetches its enroll secret, and prints/runs the osquery-perf invocation for you. <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Dibble: a CLI tool to seed realistic test data, including an interactive wizard and subcommands for teams/users/software/policies/scripts/reports/profiles/labels/activities/enroll-secrets/hosts/vulns, plus theme-driven “cas” and “ping”. * Theme system: multiple curated themes to generate consistent seeded identities, policies, software, labels, and scripts. * **Chores** * Ignored the built dibble binary and added a Makefile build target to compile the dibble tool. <!-- end of auto-generated comment: release notes by coderabbit.ai -->
51 lines
1.6 KiB
Go
51 lines
1.6 KiB
Go
package seed
|
|
|
|
import (
|
|
"github.com/fleetdm/fleet/v4/tools/dibble/pkg/themes"
|
|
)
|
|
|
|
// SeedUsers creates `count` users on the Fleet server using names drawn from
|
|
// the given theme. Roles cycle through observer / observer_plus / maintainer /
|
|
// admin / gitops so the seeded set covers every permission level.
|
|
//
|
|
// All users share a known dev password so tests can sign in as them; production
|
|
// Fleets should never run this against a real deployment.
|
|
const SeededUserPassword = "DibbleSeed123!"
|
|
|
|
var seededRoles = []string{
|
|
"observer", "observer_plus", "maintainer", "admin", "gitops",
|
|
}
|
|
|
|
func Users(c Client, log Logger, theme themes.Theme, count int) Result {
|
|
res := Result{Entity: "users"}
|
|
for i := 0; i < count; i++ {
|
|
name := themes.FullName(theme, i)
|
|
email := themes.Email(theme, i)
|
|
role := seededRoles[i%len(seededRoles)]
|
|
body := map[string]any{
|
|
"name": name,
|
|
"email": email,
|
|
"global_role": role,
|
|
"admin_forced_password_reset": false,
|
|
"password": SeededUserPassword,
|
|
}
|
|
// GitOps users authenticate via API token only, but Fleet's
|
|
// /users/admin endpoint still requires a password be set on the
|
|
// record (only SSO-enabled creates waive that requirement).
|
|
if role == "gitops" {
|
|
body["api_only"] = true
|
|
}
|
|
err := c.Post("/api/latest/fleet/users/admin", body, nil)
|
|
switch {
|
|
case err == nil:
|
|
res.Created++
|
|
log.Printf("user %s <%s> [%s]", name, email, role)
|
|
case IsAlreadyExists(err):
|
|
res.Skipped++
|
|
default:
|
|
res.Errors = append(res.Errors, err)
|
|
}
|
|
}
|
|
return res
|
|
}
|