Add triggershell run/scripts - execute configured scripts from the CLI
`run <scriptId>` auto-detects whether the web server is already reachable (a quick /api/healthz check): - If it is, the run goes through the existing POST /api/scripts/:id/runs endpoint (token-authenticated, same as any other API client) and the CLI subscribes over /ws/runs exactly like a browser tab - so the run shows up live in Run History and any open browser watching it, with zero server-side changes, since the broadcast path has no idea a run was triggered by a click vs a CLI invocation. - If nothing's reachable, it calls startRun() directly in its own process (after its own migrateOnBoot/reconcileOrphanedRuns, so a from-scratch .triggershell/ works standalone) and streams output by listening on the same in-process runEvents emitter a WS client would otherwise be fed from - read-log-then-listen, the same ordering ws/server.ts's subscribe() already uses, so a fast script finishing before the listener attaches still gets its output printed. Both modes support --var name=value (repeatable; repeat a name for multiselect), --no-wait, and Ctrl-C cancellation through the same mechanism the web UI's Cancel button uses (a WS cancel message remotely, cancelRun() directly locally). `scripts list`/`scripts show` are local-only, no network - same direct-config-read pattern as `validate`/`doctor`. Extracts defaultValuesForScript() out of dynamic-form.tsx into src/lib/config/defaults.ts so the CLI's --var handling and the web form fill in a script's configured defaults identically instead of duplicating that logic. Verified live end-to-end: a CLI-triggered remote run was observed streaming to both the triggering CLI process and an independent WS client (simulating a browser tab) simultaneously; local-mode Ctrl-C confirmed to actually kill the spawned child process, not just the CLI; token, wrong-token, and TRIGGERSHELL_API_TOKEN auth paths all verified against a running auth-enabled server. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -105,12 +105,34 @@ the script — always as a discrete argv element or env var, never interpolated
|
||||
| `triggershell validate [-c CONFIG]` | Validate a config file against the full schema |
|
||||
| `triggershell start [-c CONFIG] [--port] [--host] [--no-browser]` | Run the web app |
|
||||
| `triggershell doctor [-c CONFIG]` | Print environment/config diagnostics |
|
||||
| `triggershell scripts list [-c CONFIG]` | List configured scripts |
|
||||
| `triggershell scripts show <scriptId> [-c CONFIG]` | Show a script's command and variables |
|
||||
| `triggershell run <scriptId> [--var name=value...] [--token] [--local\|--remote] [--no-wait]` | Run a configured script - through an already-running server's API if one is reachable (so any open browser tab sees it live), otherwise standalone. See [Running scripts from the CLI](#running-scripts-from-the-cli). |
|
||||
| `triggershell users add <username> [-c CONFIG] [--inline]` | Hash a password, store it in `.env`, and print a `${VAR}` snippet for `auth.users` (`--inline` prints the raw hash instead) |
|
||||
| `triggershell users add-token <name> [-c CONFIG] [--inline]` | Generate an API token, store its hash in `.env`, and print a `${VAR}` snippet for `auth.tokens` (`--inline` prints the raw hash instead) |
|
||||
| `triggershell service install [--system]` | Install a systemd unit that runs `triggershell start` (per-user by default, Linux only) |
|
||||
| `triggershell service uninstall [--system]` | Stop, disable, and remove the systemd unit |
|
||||
| `triggershell service status [--system]` | Show the systemd unit's status |
|
||||
|
||||
### Running scripts from the CLI
|
||||
|
||||
`triggershell run <scriptId>` auto-detects whether the web app is already running (a quick
|
||||
`/api/healthz` check against `server.host`/`server.port`, overridable with `--host`/`--port`):
|
||||
|
||||
- **Server reachable** — the run goes through the same `POST /api/scripts/:id/runs` endpoint the
|
||||
web UI uses, authenticated with `--token`/`TRIGGERSHELL_API_TOKEN` if `auth.enabled`. It's a
|
||||
completely normal run from the server's point of view: it shows up in Run History, and any
|
||||
browser tab open on `/runs/:id` streams its output live, exactly as if it had been started from
|
||||
the UI.
|
||||
- **No server reachable** — `run` executes the script itself, in its own process, using the same
|
||||
runner the web app uses. The run and its log are still persisted, just without a browser to watch it.
|
||||
|
||||
Force one or the other with `--local`/`--remote` (the latter fails instead of falling back if
|
||||
nothing's reachable). Pass variables with repeated `--var name=value` flags (repeat the same name
|
||||
for a `multiselect` variable); `--no-wait` prints the run ID and returns immediately instead of
|
||||
streaming output and blocking until it finishes. Exit code is `0` for a succeeded run, `1`
|
||||
otherwise. `Ctrl-C` while waiting cancels the run, the same as the UI's Cancel button.
|
||||
|
||||
## Web App Guide
|
||||
|
||||
- **Scripts** (`/`) — every configured script as a card; click through to its run form.
|
||||
|
||||
Reference in New Issue
Block a user