[package] name = "tidalctl" version = "0.1.0" edition.workspace = true # Higher than the workspace floor: aws-config -> aws-types 1.3.16 declares # rustc 1.91.1, and resolution fails workspace-wide below it. Declared here so # the requirement is visible where it originates rather than only in a lockfile # error. rust-version = "1.91.1" description = "Command-line inspector for embedded tidalDB instances" license.workspace = true # ── tidal-crate lint posture (single source of truth) ────────────────────── # IDENTICAL block across tidaldb / tidal-net / tidal-server / tidalctl. These # crates deliberately DO NOT inherit `[workspace.lints]`; they hold the embedded # recommendation DB + its transport/server/CLI to a stricter correctness bar # (`unsafe_code = forbid`, `clippy::all = deny`, `unwrap_used = deny`). # `unwrap_used = "deny"` is kept per-crate rather than in `[workspace.lints]` # because the workspace also hosts the example/consumer crates under # `applications/` (not held to the engine's bar). Keep these four blocks BYTE-IDENTICAL. [lints.rust] unsafe_code = "forbid" [lints.clippy] all = { level = "deny", priority = -1 } pedantic = { level = "warn", priority = -1 } nursery = { level = "warn", priority = -1 } # Justified allows (lossy numeric casts are pervasive + intentional in the # ranking/scoring math; module_name_repetitions is idiomatic for the flat # module layout documented in CLAUDE.md): cast_possible_truncation = "allow" module_name_repetitions = "allow" unwrap_used = "deny" [dependencies] tidaldb = { path = "../tidal" } serde = { version = "1", features = ["derive"] } serde_json = "1" # Backup/restore manifest integrity (m11p8) — the same hash the engine verifies # WAL segments and snapshot artifacts with, so a tidalctl-written manifest and an # engine-verified one agree. blake3 = "1" # Object-store (S3-compatible) export/import for the DR gate (m11p8 R2). Chosen # over `rust-s3` because the AWS SDK shares the workspace's existing # hyper/rustls/tokio tree (no native-tls / second TLS stack), and R2 is handled # with `.endpoint_url(.r2.cloudflarestorage.com)` + `.force_path_style`. # `default-features = false` + `rustls` keeps the TLS stack aligned with the rest # of the workspace (reqwest is already `rustls-tls`); `behavior-version-latest` # pins the SDK behavior contract so an SDK minor bump can't silently change it. aws-config = { version = "1.8", default-features = false, features = ["behavior-version-latest", "rustls"] } # `rt-tokio` exposes `ByteStream::from_path` (stream a file body straight off # disk on `put_object` — no whole-file read into memory). aws-sdk-s3 = { version = "1.137", default-features = false, features = ["behavior-version-latest", "rustls", "rt-tokio"] } # `hardcoded-credentials` exposes `Credentials::from_keys` so the env-var creds # (AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY) become a static SigV4 provider. aws-credential-types = { version = "1.2", features = ["hardcoded-credentials"] } # S3 transfers run on a locally-built current-thread runtime ONLY when an --s3-* # flag is given; the local-dir backup/restore path stays fully synchronous. tokio = { version = "1", default-features = false, features = ["rt", "macros"] } # Fresh staging dir for an S3 import (downloaded prefix -> temp dir -> the # UNCHANGED verified restore reads it). Reaped when the restore returns. tempfile = "3" # Live-server commands (`search`, `feed`, `cluster-status`, `watch`) talk HTTP to # a RUNNING node. Blocking client: this is a CLI, so a runtime would buy nothing. # `rustls-tls` keeps the TLS stack aligned with the rest of the workspace, and # matters here because a cluster's client port is served with the INTERNAL # cluster CA — hence `--ca` / `--insecure`. reqwest = { version = "0.12", default-features = false, features = ["json", "rustls-tls", "blocking"] } [dev-dependencies] tidaldb = { path = "../tidal", features = ["test-utils"] } [[test]] name = "cli"