Problem
Since #3518, every chainloop attestation init|add|push|status|reset run in a directory without a .chainloop.yml prints a debug line to stderr, even without --debug:
DBG failed to load repository organization error=".chainloop.yml not found"
Most repositories don't have a .chainloop.yml, so most users see this line on every attestation command. It also shows up next to real errors and makes them harder to read, for example:
DBG failed to load repository organization error=".chainloop.yml not found"
ERR you need to enable a CAS backend first. Refer to `chainloop cas-backend` command or contact your administrator.
Cause
In app/cli/cmd/attestation.go, the attestation command's PersistentPreRunE calls resolveAttestationOrganization(cmd) before it calls the root command's PersistentPreRunE:
PersistentPreRunE: func(cmd *cobra.Command, args []string) error {
if err := resolveAttestationOrganization(cmd); err != nil { // logs here
return err
}
rootCmd := cmd.Parent().Parent()
if err := rootCmd.PersistentPreRunE(cmd, args); err != nil { // initLogger() sets the level here
The root PersistentPreRunE is where initLogger sets the log level (Info, or Debug with --debug). Before that, logger is still the seed logger from main.go, which has no level set, so logger.Debug() in resolveAttestationOrganization is printed.
Also, a missing .chainloop.yml is the normal case, not an error, so it should not be logged at any level.
Proposed fix
- Call
resolveAttestationOrganization after rootCmd.PersistentPreRunE, so the logger (and config) are fully set up first. Check that loadAuthToken, which resolveAttestationOrganization calls, still behaves the same with the new order.
- In
resolveAttestationOrganization, ignore errors.Is(err, repositoryconfig.ErrChainloopYMLNotFound) silently. Log other errors (e.g. a .chainloop.yml that exists but can't be parsed) at Warn, so users notice a broken config.
- Add a test:
attestation init without --debug, in a directory with no .chainloop.yml, prints nothing on stderr for the repository config lookup.
Acceptance criteria
Problem
Since #3518, every
chainloop attestation init|add|push|status|resetrun in a directory without a.chainloop.ymlprints a debug line to stderr, even without--debug:Most repositories don't have a
.chainloop.yml, so most users see this line on every attestation command. It also shows up next to real errors and makes them harder to read, for example:Cause
In
app/cli/cmd/attestation.go, the attestation command'sPersistentPreRunEcallsresolveAttestationOrganization(cmd)before it calls the root command'sPersistentPreRunE:The root
PersistentPreRunEis whereinitLoggersets the log level (Info, or Debug with--debug). Before that,loggeris still the seed logger frommain.go, which has no level set, sologger.Debug()inresolveAttestationOrganizationis printed.Also, a missing
.chainloop.ymlis the normal case, not an error, so it should not be logged at any level.Proposed fix
resolveAttestationOrganizationafterrootCmd.PersistentPreRunE, so the logger (and config) are fully set up first. Check thatloadAuthToken, whichresolveAttestationOrganizationcalls, still behaves the same with the new order.resolveAttestationOrganization, ignoreerrors.Is(err, repositoryconfig.ErrChainloopYMLNotFound)silently. Log other errors (e.g. a.chainloop.ymlthat exists but can't be parsed) at Warn, so users notice a broken config.attestation initwithout--debug, in a directory with no.chainloop.yml, prints nothing on stderr for the repository config lookup.Acceptance criteria
DBGlines are printed by attestation commands unless--debugis set.chainloop.ymlprints nothing, even with--debug.chainloop.ymlprints a warning.chainloop.yml(feat(cli): use repository organization for attestations #3518) works as before