config-db is developer first, JSON based configuration management database (CMDB)
make buildStarting the server will run the migrations and start scraping in background (The default-schedule configuration will run scraping every 60 minutes if configuration is not explicitly specified).
DB_URL=postgres://<username>:<password>@localhost:5432/<db_name> ./.bin/config-db serve --db-migrationsTo explicitly run scraping with a particular configuration:
./.bin/config-db run <scrapper-config.yaml> -vvvSee fixtures/ for example scraping configurations.
Run read-only doctor checks for a local scrape configuration:
./.bin/config-db doctor fixtures/github-doctor.yamlPass a persisted scraper UUID instead when a database is configured:
DB_URL=postgres://<username>:<password>@localhost:5432/<db_name> ./.bin/config-db doctor <scraper-id>The GitHub doctor checks only the endpoint families enabled by the scraper configuration. It reports GitHub's accepted fine-grained permissions and OAuth scopes, any OAuth scopes explicitly reported for the token, and whether each request succeeded, was denied, or was skipped because the feature is disabled. A successful authenticated request is evidence that the configured token can perform that operation; it is not presented as a complete list of fine-grained token grants.
Organization rulesets are checked only when organizations[].rulesets is enabled. GitHub requires the fine-grained organization_administration=write permission to read organization repository rulesets, so the doctor reports that documented requirement even when a denied response omits the permission header. App installation checks use GET /orgs/{org}/installations, which requires organization_administration=read; selected repository grants are not inferred because that organization endpoint does not expose them.
Use Clicky output flags for machine-readable or alternate output:
./.bin/config-db doctor fixtures/github-doctor.yaml --json
./.bin/config-db doctor fixtures/github-doctor.yaml --format markdown- JSON Based - Configuration is stored in JSON, with changes recorded as JSON patches that enables highly structured search.
- SPAM Free - Not all configuration data is useful, and overly verbose change histories are difficult to navigate.
- GitOps Ready - Configuration should be stored in Git, config-db enables the extraction of configuration out of Git repositories with branch/environment awareness.
- Topology Aware - Configuration can often have an inheritance or override hierarchy.
- View and search change history in any dimension (node, zone, environment, application, technology)
- Compare and diff configuration across environments.
- AWS
- EC2 (including trusted advisor, compliance and patch reporting)
- VPC
- IAM
- Azure
- Kubernetes
- Pods
- Secrets / ConfigMaps
- LoadBalancers / Ingress
- Nodes
- Configuration Files
- YAML/JSON
- Properties files
- Dependency Graphs
- pom.xml
- package.json
- go.mod
- Infrastructure as Code
- Terraform
- CloudFormation
- Ansible
See CONTRIBUTING.md