Files
cairnobs/cli/cmd/sentryctl/main.go
T
jcoffey-dev 4b5dae5879 Add local login, agent extra log paths, IPv4/IPv6 metrics; remediate security audit findings
This is a large squashed commit covering two batches of prior uncommitted
work plus a full security-audit remediation pass, kept together because
go.mod/go.sum and several shared files (main.go, handler.go) were touched
by both and splitting risked non-building intermediate commits.

Features (built earlier, previously uncommitted):
- Local username/password login for single-tenant deployments with no
  SSO configured (api/localauth, alerting/internal/sessioncheck,
  sentryctl users, web/src/routes/login, metadata migrations 0040/0041).
- Remotely-editable additional log file paths for agents, on top of
  their existing primary source (api/agents, agent/sentry-agent
  extra-file-path diffing, web agent config UI).
- IPv4/IPv6 addresses reported alongside other host system metrics.

Security audit remediation (this pass, all live-verified in production):
- Critical: block ClickHouse SSRF table functions (url/remote/file/s3/...)
  in the raw-SQL query escape hatch.
- High: deny sensitive paths and require Admin to add agent
  extra_file_paths (Editor could previously point an agent at /etc/shadow
  or an SSH key); alerting webhook targets now validate against
  internal/metadata/loopback addresses, both at creation and send time;
  alerting's session middleware now enforces an Editor+ floor on
  mutating requests instead of "any authenticated session"; bumped
  goxmldsig to close a SAML signature-verification bypass (GO-2026-4753).
- Medium: per-IP login rate limiting; security response headers
  (HSTS/CSP/nosniff/X-Frame-Options/Referrer-Policy/Permissions-Policy)
  on web/nginx.conf; a DevCredentialWarnings check in every Go service's
  config loader, logging loudly at startup if a deployment is still on
  docker-compose.yml's literal dev-only credentials; dependency bumps
  (golang.org/x/text, grpc, x/net, quick-xml, h2) across every affected
  Go module and both Rust crates, including a previously-uncovered x/net
  vulnerability in deploy/operator; a new security-scan.yml CI workflow
  running cargo-deny/govulncheck/npm-audit, mirroring the existing
  license-compliance.yml matrix shape.
- Low: removed sentryctl's plaintext --password flag (shell
  history/`ps` exposure) in favor of stdin and a --password-stdin flag
  for reset-password's optional specific-password path; a dummy bcrypt
  comparison closes a login response-time username-enumeration
  side-channel.
2026-08-18 23:53:20 -07:00

182 lines
6.8 KiB
Go

// Command sentryctl is Sentry's control CLI. Six subcommands now
// (ping, query, dashboards, alerts) clearly justify splitting dispatch
// across files -- see cli/README.md's "revisit once there's a real
// command tree" note -- while keeping the same hand-rolled switch on
// os.Args, no CLI framework, per that same README.
package main
import (
"encoding/json"
"fmt"
"io"
"os"
"strings"
"text/tabwriter"
)
const (
defaultAPIURL = "http://localhost:8080"
defaultAlertingURL = "http://localhost:8081"
)
func main() {
os.Exit(run(os.Args[1:], os.Stdout, os.Stderr))
}
func run(args []string, stdout, stderr io.Writer) int {
if len(args) == 0 {
usage(stderr)
return 1
}
switch args[0] {
case "ping":
return cmdPing(args[1:], stdout, stderr)
case "query":
return cmdQuery(args[1:], stdout, stderr)
case "dashboards":
return cmdDashboards(args[1:], stdout, stderr)
case "alerts":
return cmdAlerts(args[1:], stdout, stderr)
case "agents":
return cmdAgents(args[1:], stdout, stderr)
case "users":
return cmdUsers(args[1:], os.Stdin, stdout, stderr)
case "-h", "--help", "help":
usage(stdout)
return 0
default:
fmt.Fprintf(stderr, "sentryctl: unknown command %q\n", args[0])
usage(stderr)
return 1
}
}
func usage(w io.Writer) {
fmt.Fprintln(w, `sentryctl: Sentry control CLI
Usage:
sentryctl ping [--api <url>]
sentryctl query "<query>" [--api <url>] [--language sql|spl] [--json]
sentryctl dashboards list|get <id>|apply <file> [--api <url>]
sentryctl dashboards permissions list <dashboard-id> [--api <url>]
sentryctl dashboards permissions grant <dashboard-id> <user-id> viewer|editor [--api <url>]
sentryctl dashboards permissions revoke <dashboard-id> <user-id> [--api <url>]
sentryctl alerts list|get <id>|apply <file> [--alerting-api <url>]
sentryctl agents list|get <host> [--api <url>]
sentryctl agents config get <host>|clear <host> [--api <url>]
sentryctl agents config set <host> [--batch-max-size N] [--batch-flush-interval-ms N]
[--heartbeat-enabled true|false] [--heartbeat-interval-ms N]
[--journald-unit UNIT] [--api <url>]
sentryctl agents restart <host> [--yes] [--api <url>]
sentryctl users login <username> [--password <pw>] [--api <url>]
sentryctl users list [--api <url>]
sentryctl users create <username> [--password <pw>] [--role viewer|editor|admin|owner] [--api <url>]
sentryctl users delete <id> [--api <url>]
sentryctl users reset-password <id> [--password <pw>] [--api <url>]
Commands:
ping Checks that the api service is reachable via GET /healthz.
query Runs a query (pipe syntax or SQL) against POST /query and
prints the result as a table, or as JSON with --json. Quote
the query in your shell -- pipe syntax uses "|", which your
shell will otherwise interpret itself.
dashboards list/get/apply against api's dashboard CRUD endpoints.
"apply <file>" imports a dashboard exported via the web
UI's Export JSON button or GET /dashboards/{id}/export --
the same JSON shape both places, Terraform-friendly.
"permissions" grants/revokes/lists per-resource dashboard
access (a Phase 4, enterprise-api-only feature -- a 501 on
plain api means no enterprise permission service is wired
in on this deployment, not a client error). A grant only
ever raises someone to viewer or editor on one dashboard;
Admin/Owner already have tenant-wide access.
alerts list/get/apply against alerting's rule CRUD endpoints.
"apply <file>" creates a rule from a JSON file with the
same shape POST /rules accepts.
agents Agent inventory, remote config, and lifecycle commands
(see /docs/agent-management-design.md). "config set" reads
the agent's current effective config first and PUTs back
the complete merged override -- only the fields you pass
change, everything else carries forward unchanged, same
as the web UI's edit form. "restart" briefly interrupts
log collection on that host and prompts for confirmation
unless --yes is given.
users Local username/password login and user management (see
api/localauth -- only meaningful on a deployment with
LOCAL_AUTH_ENABLED set; a 404 on any of these means it
isn't). "login" is the only command that works with no
$SENTRYCTL_TOKEN set yet -- it prints just the raw token
to stdout: `+"`export SENTRYCTL_TOKEN=$(sentryctl users login admin)`"+`.
--password (on any users subcommand) is read from stdin
if omitted -- same shell-history/ps caveat as typing a
credential in any flag, prefer piping it in.
"create"/"list"/"delete"/"reset-password" require an
owner-role token (see RegisterRoutes in api/localauth).
--api defaults to $SENTRYCTL_API_URL, or `+defaultAPIURL+` if unset.
--alerting-api defaults to $SENTRYCTL_ALERTING_API_URL, or `+defaultAlertingURL+` if unset.
--language overrides auto-detection; omit it for the common case.
$SENTRYCTL_TOKEN, if set, is sent as "Authorization: Bearer <token>" on
every request -- required once a deployment configures enterprise-auth
(see /docs/phase-4-rbac-design.md). No flag equivalent, deliberately:
unlike --api, a credential shouldn't be typed where shell history or
`+"`ps`"+` output can capture it.`)
}
func resolveAPIURL(env func(string) string) string {
if v := env("SENTRYCTL_API_URL"); v != "" {
return v
}
return defaultAPIURL
}
func resolveAlertingURL(env func(string) string) string {
if v := env("SENTRYCTL_ALERTING_API_URL"); v != "" {
return v
}
return defaultAlertingURL
}
// resolveToken reads the RoleService/human bearer credential sentryctl
// presents to api/alerting once enterprise-auth enforcement is turned
// on (api/internal/authz.RequireRole*) -- empty by default, matching
// every other Phase 0-3 client's nil-authorizer no-op behavior.
func resolveToken(env func(string) string) string {
return env("SENTRYCTL_TOKEN")
}
type errorResponseBody struct {
Error string `json:"error"`
}
func printTable(w io.Writer, columns []string, rows [][]any) {
tw := tabwriter.NewWriter(w, 0, 4, 2, ' ', 0)
fmt.Fprintln(tw, strings.Join(columns, "\t"))
for _, row := range rows {
cells := make([]string, len(row))
for i, v := range row {
cells[i] = formatCell(v)
}
fmt.Fprintln(tw, strings.Join(cells, "\t"))
}
_ = tw.Flush()
fmt.Fprintf(w, "(%d row(s))\n", len(rows))
}
func formatCell(v any) string {
switch t := v.(type) {
case nil:
return ""
case map[string]any, []any:
b, err := json.Marshal(t)
if err != nil {
return fmt.Sprintf("%v", t)
}
return string(b)
default:
return fmt.Sprintf("%v", t)
}
}