feat(cli): import provider profiles from HTTP URLs (#3706)

* feat(cli): import provider profiles from HTTP URLs

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(cli): initialize crypto provider for remote profiles

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
This commit is contained in:
Drew Newberry
2026-09-25 06:12:18 +00:00
committed by GitHub
parent 7a50c0899f
commit c93fd94a5f
6 changed files with 332 additions and 39 deletions
+13
View File
@@ -277,6 +277,19 @@ Import one profile file at platform scope:
openshell profile import -f providers/github.yaml --global
```
Import a published YAML or JSON profile directly from an HTTP or HTTPS URL:
```shell
openshell profile lint --url https://example.com/profiles/github.yaml
openshell profile import --url https://example.com/profiles/github.yaml --global
```
Review profiles from remote sources before importing them. A profile can grant
network access and bind credentials to the endpoints and binaries it declares.
The URL path must end in `.yaml`, `.yml`, or `.json`; query parameters are allowed.
Remote downloads have a 1 MiB size limit and a 15 second timeout. `--url` is
mutually exclusive with `-f` and `--from`.
Import all non-recursive `*.yaml`, `*.yml`, and `*.json` files from a directory:
```shell