Skip to content

cli: attestation commands print a DBG ".chainloop.yml not found" line without --debug #3592

Description

@migmartri

Problem

Since #3518, every chainloop attestation init|add|push|status|reset run in a directory without a .chainloop.yml prints a debug line to stderr, even without --debug:

DBG failed to load repository organization error=".chainloop.yml not found"

Most repositories don't have a .chainloop.yml, so most users see this line on every attestation command. It also shows up next to real errors and makes them harder to read, for example:

DBG failed to load repository organization error=".chainloop.yml not found"
ERR you need to enable a CAS backend first. Refer to `chainloop cas-backend` command or contact your administrator.

Cause

In app/cli/cmd/attestation.go, the attestation command's PersistentPreRunE calls resolveAttestationOrganization(cmd) before it calls the root command's PersistentPreRunE:

PersistentPreRunE: func(cmd *cobra.Command, args []string) error {
    if err := resolveAttestationOrganization(cmd); err != nil { // logs here
        return err
    }
    rootCmd := cmd.Parent().Parent()
    if err := rootCmd.PersistentPreRunE(cmd, args); err != nil { // initLogger() sets the level here

The root PersistentPreRunE is where initLogger sets the log level (Info, or Debug with --debug). Before that, logger is still the seed logger from main.go, which has no level set, so logger.Debug() in resolveAttestationOrganization is printed.

Also, a missing .chainloop.yml is the normal case, not an error, so it should not be logged at any level.

Proposed fix

  1. Call resolveAttestationOrganization after rootCmd.PersistentPreRunE, so the logger (and config) are fully set up first. Check that loadAuthToken, which resolveAttestationOrganization calls, still behaves the same with the new order.
  2. In resolveAttestationOrganization, ignore errors.Is(err, repositoryconfig.ErrChainloopYMLNotFound) silently. Log other errors (e.g. a .chainloop.yml that exists but can't be parsed) at Warn, so users notice a broken config.
  3. Add a test: attestation init without --debug, in a directory with no .chainloop.yml, prints nothing on stderr for the repository config lookup.

Acceptance criteria

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions