Skip to content

Plan / Interface: mecatui remote endpoints and first-use connect sign-in - #2049

Merged
tgrunnagle merged 3 commits into
mainfrom
plan/mecatui-remote-endpoints
Oct 1, 2026
Merged

tgrunnagle merged 3 commits into
mainfrom
plan/mecatui-remote-endpoints

Conversation

@tgrunnagle

Copy link
Copy Markdown
Contributor

Stage: Plan / Interface

Acceptance plan: docs/acceptance/mecatui-remote-endpoints.md (status: draft). Tracking: none (no issue yet).

Goal

Connect to the OIDC-protected deploy/mecak8s-kind Keycloak fixture with one command, task mecak8s:kind-connect. The first interactive mecatui connect uses the server's RFC 9728 metadata the same way mecatui login HOST does: it confirms the discovered tuple, runs the browser login, and continues into the TUI.

Scope (5 scenarios)

  1. Named endpoints. A remote: block in operator-owned settings resolves targets for connect, login, and logout.
  2. First-use sign-in from connect. Allowed only when all six gates hold. The trigger is a pre-TUI, credential-free, read-only ListSessions probe. Saved targets keep ADR 0277's no-browser rule.
  3. Private discovery. Allowed only when an operator pins it on an endpoint, using the ADR 0286 private issuer transport. A command-line address or server metadata can never select it.
  4. Reconnect and drift. Saved endpoints reconnect without flags, and restart and picker paths keep the endpoint. A drifted entry or a legacy enrollment row fails closed.
  5. Kind fixture changes:
    • the Keycloak overlay publishes oidc.resource, clientID, and scopes;
    • kind-connect writes the endpoint under an absolute, fixture-owned XDG root;
    • destroy and reset log out first.

Review notes

  • Classification. This is Bounded with no ADR, as the directing human chose. The plan narrows ADR 0277 (connect never opens a browser) and ADR 0305 (public-only discovery) without amending them. This risk is recorded under Human decisions.
  • Open Human decisions. Three need a choice before the plan can move to proposed:
    • where the settings live (recommended: the client-owned ~/.config/mecatui/settings.yaml);
    • how the kind fixture provides its endpoint (recommended: a fixture-owned XDG root);
    • the endpoint name grammar.
  • A devils-advocate pass ran, and its findings are folded in: probe RPC, restart and picker CA loss, legacy-row lookup, relative XDG root, grammar compatibility, and the fixture cleanup root.

Checks

  • check-acceptance-plan.sh: passed
  • check-acceptance-plan-test.sh: passed
  • task docs: passed

🤖 Generated with Claude Code

tgrunnagle and others added 2 commits October 1, 2026 14:12
… sign-in

Draft acceptance plan for operator-owned named remote endpoints, interactive
first-use discovered sign-in from `mecatui connect`, operator-pinned private
discovery, and a one-command connect to the mecak8s kind Keycloak fixture.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
The connection profile (gRPC target, gRPC CA, private discovery and its
CA) now comes from connect flags, all-or-none, falling back to a named
client-settings endpoint only when no profile flag is given. Kind tasks
pass the flags instead of writing a fixture-owned settings root.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@tgrunnagle

Copy link
Copy Markdown
Contributor Author

Amended per review: connect now takes the connection profile as flags (--grpc-target, --tls-ca, --private-issuer, --discovery-ca). When no profile flag is given, it falls back to a named remote: endpoint in client settings. The two sources are all-or-none: any profile flag means settings aren't read, and an endpoint name plus a flag is a usage error. Within the flags, --private-issuer and --discovery-ca must come together. The kind tasks now pass the flags and use the normal client root, with a best-effort logout on destroy and reset. A new Human decision records the all-or-none reading, and the private-discovery decision now also allows explicit flags.

@tgrunnagle
tgrunnagle merged commit 92683cb into main Oct 1, 2026
29 checks passed
@tgrunnagle
tgrunnagle deleted the plan/mecatui-remote-endpoints branch October 1, 2026 12:40
@toolhive-release-app toolhive-release-app Bot mentioned this pull request Oct 7, 2026
2 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants