thomas
No lore recorded.
click a wedge to zoom · center to return
Show full breakdown
- cli_invocation100.0%18kaudit52%9.1k
- record9.1k
model22%3.9k- method3.2k
- type358
- search121
- get93
- create50
- validate24
- delete22
- output11
- list5
- evaluate2
vault11%1.9k- read-secret1.6k
- list-keys93
- put71
- list32
- get13
- create10
- type7
- search7
data10%1.8k- get1.3k
- delete243
- list214
- query18
- versions4
- search1
extension2%293- fmt71
- quality71
- push47
- search42
- version24
- list11
- info8
- pull6
- source6
- rm5
- yank1
- trust1
workflow1%201- run114
- validate28
- history22
- create9
- get8
- search7
- list6
- evaluate5
- schema1
- delete1
completions1%142- zsh142
help1%121- model59
- vault30
- extension10
- data8
- issue2
- serve2
- workflow1
- doctor1
- repo1
doctor0%49- extensions47
auth0%18- whoami14
- login2
update0%7repo0%4- upgrade4
issue0%2- bug2
summarise0%1
Technitium
Management of a Technitium DNS Server via its HTTP API — built-in ad-blocking control (enable/disable, temporary disable, allow/block list URLs), authoritative zone + record lifecycle, allowed/blocked custom domains, dashboard stats, DNS client + query-log debugging, cache flush, and settings backup/restore.
Postgres Admin
Non-destructive PostgreSQL administration over a direct TCP connection (node-postgres). Read/audit of databases, roles, permissions, tables, connections, and extensions; plus data-safe admin DDL — create database/role, grant/revoke, rotate passwords, and an idempotent app_provision composite. Never reads or writes table rows; never DROP/TRUNCATE; no arbitrary-SQL passthrough.
Arcane
Management of an Arcane Docker instance via its REST API — GitOps sync setup, compose project lifecycle with validated mode-aware deploy, swarm stack deploy (render-validated, convergence-polled) + secret/config rotation, and volume/prune cleanup.
Zitadel
Careful, non-destructive administration of a Zitadel instance over its Management API (v1 REST), authenticated with a JWT private-key service account. Read/audit of orgs, projects, applications, users and managers; idempotent provisioning of OIDC/API applications and machine (service) users; project-role and user-grant authorization (roles, grants, and the role-assertion flag that surfaces roles in tokens); rotation of client secrets, PATs, machine keys and secrets; and reversible deactivate/reactivate. Machine identities only. The only hard delete is a single, verify-first project-role removal (roles have no deactivate state); secrets are emitted once and marked sensitive.
Woodpecker
Careful administration of a Woodpecker CI server over its REST API, authenticated with a personal access token. Onboard and configure repositories (enable, mark trusted, set timeout/visibility/approval), promote shared CI credentials to org- or repo-scoped secrets idempotently, inspect recent pipelines, and trigger runs. Mutations are additive or reversible (disable/secret-delete undo by re-running enable/set); secret values are write-only — supplied via a vault reference, sent once, and never read back or emitted.