cwp settings pull
shipped 1.0.0cwp settings pull [env] [flags]
This name is an alias. The work moved to cwp pull --only settings, and that page documents it. This spelling still runs for one minor cycle.
Acts on the local site. Name an environment to act there instead.
| Argument | What it is | Default |
|---|---|---|
[env] | environment to read (default: default_environment in cwp.yml) |
| Flag | What it does | Default |
|---|---|---|
--with-agent | with —dry-run on a host with no shell: install and remove the PHP agent so the plan is real | off |
Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.
What it does
Reads the options each settings: group declares from a site into the tree, as
settings/<group>.yml.
Two round trips per group, deliberately. The matching option names come back first. cwp applies the refusals to them here and reads only the survivors for their values. A credential’s value never crosses the wire, so this is safe to run against production.
The output names a key a glob matched and the deny list refuses. The file holds
it in a refused: map: names and reasons only, never the value. The refusal
judges the value as well as the name. An option holding a credential under a
nested key, or an IP address anywhere inside it, fails whole. Half an option is
not a value.
The way past that is a decision in cwp.yml, not a flag. A group’s hold:
names the path the target keeps for itself. The pull leaves it out before it
judges the value, and the file records the path under held::
– settings/stats.yml — 1 option(s) — updated
held on the target: stats_settings.geoip_license_key
A group’s classify: says the same thing with a word per path. The file
records the word under withheld:. The report prints one line per class:
– settings/smtp.yml — 1 option(s) — updated
environment, on the target: custom_smtp_settings.smtp_host
secret, on the target: custom_smtp_settings.smtp_password
attachment, as identity: custom_smtp_settings.logo
A path classified attachment, post or term lands in the file as the
identity the site describes for the id. A push resolves it on the target.
What it does not do
- It does not write when nothing changed. An unchanged file keeps its mtime, so a pull that found nothing new leaves the git tree clean.
- It does not decide what to carry. The block in
cwp.ymldoes, andcwp coverageproposes one. - It does not touch the site. Reading is all it does; there is nothing to confirm and nothing to guard.