Repository navigation
fix(scripts): walk folders when project-resource-graph.sh lists all projects - #22
Merged
mauritzuph merged 1 commit intoSep 10, 2026
Conversation
…rojects "project list --parent-id" answers with the children of the container it is asked for, so asking only the organizations left out every project that sits in a folder. The CLI 0.72.0 has no folder command, so the script now asks the resource manager directly with "stackit curl", which signs the request with the same subject: GET /v2/folders per container, paged, depth first, at most ten levels. Every folder found is then asked for its projects like an organization. The endpoint comes from resource_manager_custom_endpoint of the active profile and falls back to the public one, because an endpoint belongs to the environment like the region and not to the subject. A container the subject may not list answers 403, whose body carries no items, which ends that branch and not the run. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #20, which closed two defects in the project resolution of
project-resource-graph.shand left one gap open.Problem
--all-projectsasksstackit project list --parent-id <container>for every organization the subject can read.GET /v2/projectsanswers with the projects that are children of the container it is asked for, so a project that sits in a folder below the organization is never returned. Such a project was covered only when the subject happened to be a member of it, which is exactly what a role on an organization or a folder does not create.Change
GET /v2/foldersthroughstackit curl, which signs the request with the same subject as every other call: paged withlimit/offset, depth first, at most ten levels.resource_manager_custom_endpointof the active profile and falls back tohttps://resource-manager.api.stackit.cloud. It is read from the active profile and not from the key, because an endpoint belongs to the environment like the region, not to the subject.Both API operations are documented in resource-manager.json.
Tests
Against a fake CLI that answers with one organization, one folder below it, one project inside that folder and no membership anywhere:
mainwithout this commitError: no readable projects1 project: ..., lists the project inside the folderAgainst a real service account key whose role sits on an organization, region eu01: a
bash -xtrace shows the walk organization → folder → subfolder, each container asked for its projects once, and the recursion stopping where a folder has no children. The project count is unchanged there, because both folders are empty; the run takes about 1.5 s longer.shellcheckandbash -nare clean,prettier@3.1.0reportsscripts/README.mdas formatted,check_readme_tags.pypasses andgenerate_agents_md.pyproduces no diff.🤖 Generated with Claude Code