@manta-eu/codegen
v0.1.7
Published
CLI that generates LDkit schemas from a realm's SHACL shapes, read from its datastore
Downloads
2,011
Maintainers
Keywords
Readme
@manta-eu/codegen
A CLI that generates LDkit schemas for one realm, from the SHACL shapes that realm's datastore
holds. @manta-eu/ldo builds the same types from local files in this repository. An app outside this
repository has neither the files nor Nix, so this package reads the shapes over HTTP instead.
Use
pnpm manta-codegen generate --datastore your-datastore --out ./.ldkitThe run targets hiremanta.com production unless flags name another deployment:
pnpm manta-codegen generate \
--api-url https://app.example \
--datastore your-datastore \
--keycloak-url https://keycloak.example \
--keycloak-realm your-realm \
--out ./.ldkitThe run writes one .ts file per namespace (manta.ts, meta.ts, google.ts and so on),
namespaces.ts for the vocabulary constants, and an index.ts that re-exports every file. It writes
nothing else: the directory holds generated code, and the CLI keeps no copy of either graph it read.
A run removes the .ts files of the run before it, so a class the shapes no longer describe loses
its file. It leaves every other file in the directory alone.
Only namespaces.ts holds the realm IRIs.
Log in
MANTA_CLIENT_SECRET decides the path. Login itself is @manta-eu/auth's job — see
its README for how the browser login works, where
the login is stored and how long it lasts. @manta-eu/upload reads and writes the same store, so
one login serves both CLIs.
No secret — a person. Log in once:
pnpm manta-codegen login| Command | What it does |
| -------- | ------------------------------------------------------------------- |
| login | Logs in and stores the login. |
| status | Says whether a login is stored, and for whom. Exits 1 when none is. |
| logout | Revokes the login at Keycloak and deletes the stored copy. |
Each takes the same --keycloak-url and --keycloak-realm as generate, because a login belongs to
one Keycloak, realm and client. The client defaults to the realm's <realm>-cli, a public client
made for this, so --client-id is only needed for another one. generate logs in by itself when
nothing is stored and a terminal is attached; without one it fails and names login instead of
waiting for a browser.
A secret — a machine. Set MANTA_CLIENT_SECRET to the secret of the realm's manta-codegen
client, which the CLI then uses by default. The CLI asks for a service account token. Add --scope to ask for a narrow token.
export MANTA_CLIENT_SECRET=... # never a flag: an argument list is public on the machineTwo traps:
- The API grants a datastore to a person, or to a service account holding the
operatorrealm role.manta-codegenholds it; a service account without it is refused the datastore. - The API can compare the token's
azpagainst its ownVITE_KEYCLOAK_CLIENT_IDand answer 401 for any other client. That check is off today (authorizedPartyCheckEnabled). Turning it on 401s both<realm>-cliandmanta-codegenunless it learns to accept them.
What the datastore does not hold
observed-entities.ttl reaches no graph. It describes 35 classes, among them meta:Body,
meta:Title and google:Headline. A consumer generates without them.
This is a decision, not an oversight. kgc/kgc/realms/lib/term_structure.py writes that file from
the instance data of a live datastore. A new realm therefore has none, and the shapes move with the
data. See WEB-1536.
The CLI prints the class count for each namespace, so a thin result is visible at once.
