Skip to content

fix(scripts): walk folders when project-resource-graph.sh lists all projects - #22

Merged
mauritzuph merged 1 commit into
stackitcloud:mainfrom
devpie:fix/project-resource-graph-folder-walk
Sep 10, 2026
Merged

mauritzuph merged 1 commit into
stackitcloud:mainfrom
devpie:fix/project-resource-graph-folder-walk

Conversation

@devpie

@devpie devpie commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Follow-up to #20, which closed two defects in the project resolution of project-resource-graph.sh and left one gap open.

Problem

--all-projects asks stackit project list --parent-id <container> for every organization the subject can read. GET /v2/projects answers with the projects that are children of the container it is asked for, so a project that sits in a folder below the organization is never returned. Such a project was covered only when the subject happened to be a member of it, which is exactly what a role on an organization or a folder does not create.

Change

  • Every folder below a readable organization is now asked for its projects like an organization. The CLI 0.72.0 has no folder command, so the folders come from GET /v2/folders through stackit curl, which signs the request with the same subject as every other call: paged with limit/offset, depth first, at most ten levels.
  • The endpoint is taken from resource_manager_custom_endpoint of the active profile and falls back to https://resource-manager.api.stackit.cloud. It is read from the active profile and not from the key, because an endpoint belongs to the environment like the region, not to the subject.
  • A container the subject may not list answers 403, whose body carries no items. That ends the branch and not the run, the same way an unavailable service does.

Both API operations are documented in resource-manager.json.

Tests

Against a fake CLI that answers with one organization, one folder below it, one project inside that folder and no membership anywhere:

Script Result
main without this commit Error: no readable projects
this branch 1 project: ..., lists the project inside the folder

Against a real service account key whose role sits on an organization, region eu01: a bash -x trace shows the walk organization → folder → subfolder, each container asked for its projects once, and the recursion stopping where a folder has no children. The project count is unchanged there, because both folders are empty; the run takes about 1.5 s longer.

shellcheck and bash -n are clean, prettier@3.1.0 reports scripts/README.md as formatted, check_readme_tags.py passes and generate_agents_md.py produces no diff.

🤖 Generated with Claude Code

…rojects

"project list --parent-id" answers with the children of the container it is
asked for, so asking only the organizations left out every project that sits
in a folder. The CLI 0.72.0 has no folder command, so the script now asks the
resource manager directly with "stackit curl", which signs the request with
the same subject: GET /v2/folders per container, paged, depth first, at most
ten levels. Every folder found is then asked for its projects like an
organization.

The endpoint comes from resource_manager_custom_endpoint of the active
profile and falls back to the public one, because an endpoint belongs to the
environment like the region and not to the subject. A container the subject
may not list answers 403, whose body carries no items, which ends that branch
and not the run.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@mauritzuph
mauritzuph merged commit d7ea030 into stackitcloud:main Sep 10, 2026
5 checks passed
@devpie
devpie deleted the fix/project-resource-graph-folder-walk branch September 10, 2026 18:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants