oap spicedb
Apply schema and check permissions against the system SpiceDB.
oap spicedb apply-schema
Apply the canonical agentprimitives schema (pkg/authz/spicedb/schema) to the SpiceDB endpoint via WriteSchema (idempotent).
Flags:
--endpoint string SpiceDB gRPC endpoint (default: $SPICEDB_ENDPOINT)
--insecure Use insecure gRPC (no TLS) (default "true")
--token-file string Path to a file holding the SpiceDB bearer token (default: $SPICEDB_TOKEN_FILE)
oap spicedb check <object_type>:<object_id>#<permission>@<subject_type>:<subject_id>[#<rel>]
One-shot CheckPermission query for debugging.
Flags:
--endpoint string SpiceDB gRPC endpoint (default: $SPICEDB_ENDPOINT)
--insecure Use insecure gRPC (default "true")
--token-file string Path to bearer token file (default: $SPICEDB_TOKEN_FILE)
oap spicedb expose
Wraps kubectl port-forward against the spicebox-spicedb Service. It lives in the platform's system namespace, which is where this looks unless -n says otherwise. Useful for pointing an external SpiceDB client at the operator's SpiceDB.
Foreground process; Ctrl-C kills the forward.
Example: in another terminal, run SPICEDB_ENDPOINT=localhost:50051 ./run.sh in a client checkout to write permissions into the same SpiceDB this operator manages.
Flags:
--local-port int Local port to forward from (default "50051")
--remote-port int Remote port on the SpiceDB Service (50051 = gRPC, 8443 = HTTP) (default "50051")
oap spicedb proxy
Opens a long-running port-forward from 127.0.0.1:<port> to the spicebox-spicedb Service, writes a zed context (default name "agentprimitives") pointing at it, and switches to that context. Blocks until Ctrl-C / SIGTERM, then removes the zed context entry and tears down the forward.
After it's running, in another terminal:
zed schema read zed relationship read agentsession:abc zed permission check agentsession:abc interact user:alice
Flags:
--port uint16 Local TCP port to bind (default "60061")
--zed-context string zed context name to create / use (default "agentprimitives")