import { REMOTE_PATH_PREAMBLE } from "../generated/shell-scripts.js"; export { REMOTE_PATH_PREAMBLE }; /** * Build the remote argv for a shell program. * * The program is passed as a single quoted `sh -c` argument rather than on * stdin, which keeps the child's stdin free for callers that pipe a request * body through it. Programs are module constants, never user input; supplied * `args` become the program's positional parameters and must each be a single * bare word, which the caller is responsible for validating. */ export declare function remoteShellArgv(script: string, args?: readonly string[]): string[]; export type SshCommandResult = { stdout: string; stderr: string; exitCode: number; }; export type SshCommandOptions = { timeoutMs?: number; signal?: AbortSignal | null; stdin?: string; }; /** SSH failure classes RouteKit can act on, ordered most to least specific. */ export type SshFailureCode = "unauthorized" | "not_found" | "unavailable"; export type SshFailure = { code: SshFailureCode; /** Redacted, human-readable cause, or an empty string when none is known. */ detail: string; /** True when the local `ssh` executable itself is missing. */ missingSshClient: boolean; }; /** Every string reachable under a sensitive-looking key in `value`. */ export declare function requestSecrets(value: unknown): Set; export declare function redactSensitiveText(text: string, secrets?: Iterable): string; /** * SSH's own `ConnectTimeout` is bounded well below the overall command budget: * a provisioning step may legitimately run for minutes, but an unreachable * host must fail fast rather than hold the budget open. */ export declare function connectTimeoutSeconds(timeoutMs?: number): number; export declare function sshArgv(host: string, argv: readonly string[], timeoutMs?: number): string[]; /** * Classify a rejected SSH invocation. Callers own the surrounding sentence; * this decides the failure class and produces a redacted cause. */ export declare function classifySshFailure(error: unknown, secrets?: Iterable): SshFailure; /** * Run one command on `host` and capture its output. A non-zero exit resolves * rather than rejects: callers that treat a failing status as fatal inspect * `exitCode` themselves, and provisioning probes expect failing statuses. * Rejections mean the invocation never produced a usable result: no `ssh` * binary, a timeout, an abort, or oversized output. */ export declare function runSshCommand(host: string, argv: readonly string[], options?: SshCommandOptions): Promise; /** A rejected `runSshCommand` carrying the remote stderr for classification. */ export declare function sshExitError(result: SshCommandResult, host: string): Error; export type SshLocalForward = { readonly localPort: number; readonly gatewayUrl: string; close(): Promise; }; export type SshLocalForwardOptions = { remoteHost?: string; remotePort?: number; timeoutMs?: number; signal?: AbortSignal | null; }; /** argv for `ssh -N -o ExitOnForwardFailure=yes -L :127.0.0.1:8080 host`. */ export declare function sshLocalForwardArgv(host: string, localPort: number, options?: SshLocalForwardOptions): string[]; /** * Data-plane hop: `ssh -N -L :127.0.0.1: `. * Invoke against `http://127.0.0.1:`, never remotes.json or the Tailscale IP. */ export declare function openSshLocalForward(host: string, options?: SshLocalForwardOptions): Promise;