Skip to content

cwp settings pull

shipped 1.0.0
cwp settings pull [env] [flags]

This name is an alias. The work moved to cwp pull --only settings, and that page documents it. This spelling still runs for one minor cycle.

Acts on the local site. Name an environment to act there instead.

tree ← site

ArgumentWhat it isDefault
[env]environment to read (default: default_environment in cwp.yml)
FlagWhat it doesDefault
--with-agentwith —dry-run on a host with no shell: install and remove the PHP agent so the plan is realoff

Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.

What it does

Reads the options each settings: group declares from a site into the tree, as settings/<group>.yml.

Two round trips per group, deliberately. The matching option names come back first. cwp applies the refusals to them here and reads only the survivors for their values. A credential’s value never crosses the wire, so this is safe to run against production.

The output names a key a glob matched and the deny list refuses. The file holds it in a refused: map: names and reasons only, never the value. The refusal judges the value as well as the name. An option holding a credential under a nested key, or an IP address anywhere inside it, fails whole. Half an option is not a value.

The way past that is a decision in cwp.yml, not a flag. A group’s hold: names the path the target keeps for itself. The pull leaves it out before it judges the value, and the file records the path under held::

– settings/stats.yml — 1 option(s) — updated
  held on the target: stats_settings.geoip_license_key

A group’s classify: says the same thing with a word per path. The file records the word under withheld:. The report prints one line per class:

– settings/smtp.yml — 1 option(s) — updated
  environment, on the target: custom_smtp_settings.smtp_host
  secret, on the target: custom_smtp_settings.smtp_password
  attachment, as identity: custom_smtp_settings.logo

A path classified attachment, post or term lands in the file as the identity the site describes for the id. A push resolves it on the target.

What it does not do

  • It does not write when nothing changed. An unchanged file keeps its mtime, so a pull that found nothing new leaves the git tree clean.
  • It does not decide what to carry. The block in cwp.yml does, and cwp coverage proposes one.
  • It does not touch the site. Reading is all it does; there is nothing to confirm and nothing to guard.