Elinpf/dsh-ops-plugins--packages-ops-access-prometheus ↗★ 1
@elinpf/dsh-ops-access-prometheus
Ops access provider for Prometheus — validates prometheus registry entries (server URL + optional bearer-token file) and expands the token path. 适合需要在运维流程中安全解析和验证 Prometheus 凭据的运维人员。
インストール
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:Elinpf/dsh-ops-plugins#64b1d76649bf24155173c74254d0fb61d12815d5&path:packages/ops-access/prometheusドキュメント
README 全文を読む ↗@elinpf/dsh-ops-access-prometheus
The Prometheus credential provider for DeepSeek Harness ops mode — validates prometheus registry entries (server URL + optional bearer token) and expands the token path.
What it does
One provider per credential kind, per the ops-access three-role split: core owns the registry and the ctx.opsAccess service; this package supplies only the prometheus kind — a zod entry schema plus field processing.
- Entry schema:
{ url, token? }—urlis the Prometheus server's base URL (http(s) only).tokenis optional bearer-token CONTENT: the admin UI /register_accessaccept the pasted token, core writes it to a managed file under~/.dsh-ops/credentials/and stores the path — the token never sits in the registry. - process: strips trailing slashes from the URL and expands a leading
~in the token path. - validateContent: save-time paste guard — a token must be a single line (it is sent verbatim in the
Authorizationheader; an interior newline would fail at request time). Structural only, no connectivity checks. - No capability probe: the Prometheus HTTP API is read-only by nature (
query/query_range), so there is no ro/rw distinction to verify.knownLimitssays so and points at pairing with the same cluster's k8s profile.
Installation
Provider row of the ops preset's agent.cordis.yml:
- id: ops-access-prometheus
name: '@elinpf/dsh-ops-access-prometheus'
Registration goes through registerAccessProvider (deferred ctx.inject + effect lifecycle, so HMR unloads it) — never a static inject on opsAccess, which deadlocks the loader.
Testing
npm run build # tsc → lib/
npx vitest run # schema, process, paste guard, registration/HMR disposal
No server needed: all tests run against the pure provider object and a mock mount.