Repository navigation
fix(scripts): resolve projects per identity in project-resource-graph.sh - #20
Merged
mauritzuph merged 1 commit intoSep 9, 2026
Conversation
A run with --key took the project from the CLI configuration, which belongs to the logged-in session. The key is another subject and usually sits in another organization, so every service answered 403. The configuration is now read for the project only when no --key is given. A key run without --project-id or --all-projects stops and says why. --all-projects missed the projects of such a key too. "stackit project list" returns the projects the subject is a member of, and a role on an organization creates no membership there. The script now also runs "stackit project list --parent-id" for every organization of "stackit organization list" and takes the union, each project once. A project inside a folder is still covered only by the membership list, because the API returns the children of the container it is asked for and the CLI has no folder command. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Collaborator
|
Ty! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
project-resource-graph.shresolved the project independently of the identity it ran as.--keystill took the project from the CLI configuration. That project belongs to the logged-in session; the key is another subject and usually sits in another organization, so every service answered 403 and the run produced a table ofunavailablerows.load_cli_defaultsran beforeresolve_identityand used the barestackit, so the default profile always won.--all-projectsdid not help such a key either.stackit project listreturns the projects the subject is a member of, and a role on an organization creates no membership. A service account with an organization role got an empty list and the run died withno readable projects, although the same key can read the projects of its organization.The two defects compound: fixing only the first would leave a key with an organization role without any working way to select a project.
Change
--keyis given. The region is still inherited, because every subject uses the same regions while a project belongs to one. A key run without--project-idor--all-projectsstops and says why.--all-projectsnow takes the union of both sources, each project once:stackit project listfor the memberships, plusstackit project list --parent-id <organization>for every organization ofstackit organization list. Aninfoline names the resulting count, since the meaning of the option widened.--helpandscripts/README.mddescribe both rules, including the remaining gap.Limitation
A project inside a folder is covered by the membership list only.
GET /v2/projectsreturns the projects that are children of the container it is asked for (resource-manager.json), and the CLI 0.72.0 has no command that lists folders. Walking the tree would needstackit curlagainst a hardcoded endpoint thatresource_manager_custom_endpointcan override, so it is left out. Closed in a follow-up.Tests
Run against a service account key whose role sits on an organization, region eu01:
--key <org key>without a project--key <org key> --all-projects --services networkunavailable: ... 403--key, profile withproject_id--key, profile withoutproject_idstackit config sethint--all-projects --delete network/<name>--delete needs exactly one project, 6 are selected, before any query or promptshellcheckandbash -nare clean,prettier@3.1.0changes nothing inscripts/README.md,check_readme_tags.pypasses andgenerate_agents_md.pyproduces no diff.🤖 Generated with Claude Code