Configuring sloctl
Using sloctl for SLO management requires authentication,
this guide will walk you through configuring sloctl.
Access keys
In order to start using sloctl, you'll need access keys, which consist of a Client ID and Client Secret.
There are two kinds of keys you can utilize, each fitting a different use case:
- use user access keys if you want to have the same level of access as your user account
- use API keys if you want granular control over the permissions, this a recommended approach for automations, like your CI/CD pipeline
Configuration
Once you create the keys, you can setup configuration for sloctl through:
- ready to use
config.tomlfile downloaded when creating the keys sloctl config add-contextcommand, it will create theconfig.tomlfile for you but you still need to create and save the access keys in the Nobl9 web application- environment variables
Interactive setup
Run the interactive setup command:
sloctl config add-context
Enter a new context name, your client ID and client secret, your default Project and finally select your Nobl9 instance.
The command saves the context in ~/.config/nobl9/config.toml and creates the file if it does not exist.
See Configuration file if you use a custom path.
If prompted, confirm Set context as default? so subsequent commands use the new context.
Verify authentication with the default context:
sloctl get slos
See Verifying configuration for the possible responses.
config.toml
The minimal config.toml file and required fields are presented below,
before you proceed, make sure you
choose your Nobl9 instance
defaultContext = "default"
[contexts.default]
clientId = "YOUR_CLIENT_ID"
clientSecret = "YOUR_CLIENT_SECRET"
project = "default"
| Field | Description |
|---|---|
defaultContext | The default context to use if none is specified when running sloctl commands |
clientId | The client ID for API authorization with your sloctl access key |
clientSecret | The client secret for API authorization with your sloctl access key |
project | The default project to use if none is specified when running sloctl commands |
For configuration precedence, every supported field, and all environment variables, see Nobl9 tools configuration.
With your authentication prerequisites in place,
you can now authenticate sloctl either directly on your local system or using a Docker container.
Verifying configuration
To verify successful authentication, run sloctl get slos. You will receive one of these responses:
| Response | Result |
|---|---|
No resources found in default project | Authentication succeeded. No SLOs exist or you don't have access to view them. |
| List of SLOs | Authentication succeeded. |
| Error 401 | Authentication failed. Ensure your credentials are correct and config.toml is in the expected configuration location. |
Customizing timeout and file prompts
Set timeout in a context to change the HTTP request timeout.
Set the global [sloctl] fields to control file confirmation prompts for
sloctl apply and sloctl delete.
[sloctl]
filesPromptEnabled = false # Disable confirmation prompts for `sloctl apply` and `sloctl delete` commands.
filesPromptThreshold = 30 # Used only when file confirmation prompts are enabled.
[contexts.production]
clientId = "YOUR_CLIENT_ID"
clientSecret = "YOUR_CLIENT_SECRET"
project = "default"
timeout = "1m" # HTTP request timeout for this context.
Docker authentication
You can provide access keys to sloctl Docker image in either of the following ways:
- pass your
config.tomlfile through a volume mount - provide access keys directly through environment variables
- config.toml mount
- environment variables
Mount the directory that contains your config.toml file into the container.
This example uses the default local configuration directory, ~/.config/nobl9.
Replace $HOME/.config/nobl9 with the absolute path to your local configuration directory if it differs.
To fetch all the SLOs from web-app project, run the following command:
docker run --rm \
-v "$HOME/.config/nobl9:/nobl9-config" \
-e SLOCTL_CONFIG_FILE_PATH=/nobl9-config/config.toml \
nobl9/sloctl:latest get slos --project web-app
SLOCTL_CONFIG_FILE_PATH selects the file at its mounted path inside the container.
You can pass your sloctl credentials with environment variables instead of using config.toml.
The complete list is available in Nobl9 tools configuration.
Choose your Nobl9 instance:
| Variable name | Description |
|---|---|
SLOCTL_CLIENT_ID | Nobl9 client ID. |
SLOCTL_CLIENT_SECRET | Nobl9 client secret. |
SLOCTL_NO_CONFIG_FILE | Set to true to prevent config.toml reads and creation. |
Set SLOCTL_CLIENT_ID and SLOCTL_CLIENT_SECRET in your local shell before running the command.
To fetch all the SLOs from web-app project, run the following command:
docker run \
-e SLOCTL_CLIENT_ID \
-e SLOCTL_CLIENT_SECRET \
-e SLOCTL_NO_CONFIG_FILE=true \
nobl9/sloctl:latest get slos --project web-app
sloctl is the image's entrypoint so there's no need to invoke it. Put its flags and subcommands after the image name:
docker run --rm nobl9/sloctl:latest get project