Skip to content

cub invocation invoke get

cub invocation invoke get

Execute a non-mutating stored Invocation

Synopsis

Execute a single stored Invocation whose underlying function is non-mutating (Mutating=false), supplying values for its declared parameters.

'cub invocation invoke get' accepts only non-mutating Invocations, so an agent's permissions can be scoped to this operation class via the command.

Supply each declared parameter with a repeated --param flag:

cub invocation invoke get rbac-add-verb \ --space '*' --where "Space.Labels.Component = 'checkout'" \ --param verb=create --param role=app-reader --param namespace=prod

The supplied values are validated against the Invocation's declared Parameters (every required parameter must be present; unknown names are rejected) and become the scope for expanding the Invocation's templated argument values.

cub invocation invoke get <invocation> [--param name=value ...] [flags]

Options

      --change-desc string          change description
      --changeset string            changeset to associate units with
      --clearance stringArray       class of guarded reason this change is cleared for, as KEY, KEY=VALUE[,VALUE...], KEY!=VALUE[,VALUE...], or !KEY to refuse any path carrying KEY (repeatable). A guarded path this does not cover is not written, and the withheld change is reported as a conflict
      --dry-run                     dry run mode: execute functions but skip updating configuration data
      --filter string               Filter entity to apply to the list. Specify as 'space/filter' for cross-space filters or just 'filter' for current space. Supports both slugs and UUIDs. The filter will be combined with any --where clause using AND logic. Examples: "production-filters/security-check", "my-filter-uuid", "validation-rules"
      --guard stringArray           reason to record on the paths this change writes, as KEY=VALUE (repeatable). A later operation must be cleared for it before overwriting those paths. Adds and overwrites only; retiring a guard is cub unit set-guard --remove-guard
  -h, --help                        help for get
      --invocation strings          execute invocations by UUID, slug, or space/slug (can be repeated or comma-separated)
      --other-data-source string    additional data source to pass to functions (e.g., LastReleasedRevisionNum)
  -o, --output string               Output format. One of: json, yaml, name, wide, mutations, jq=<expr>, yq=<expr>, custom-columns=<spec>
  -O, --output-file string          Write payload to FILE. Accepts {space}, {unit}, {section} placeholders.
      --param stringArray           value for a declared parameter, as name=value (can be repeated)
      --protect                     record the paths this change writes as protected local overrides, so a later merge from upstream does not overwrite them; by default a change claims nothing and each path keeps the protection it already has
      --quiet                       No default output.
      --resource-type string        resource-type filter
      --revision string             target a specific revision (format: unit-slug/revision-number, e.g. mydeployment/3)
      --show string                 Select which part of the function response to display. One of: output, values, data
      --timeout string              completion timeout as a duration with units, such as 10s or 2m (default "10m0s")
      --toolchain string            Toolchain type for the function invocations (default "Kubernetes/YAML")
      --trigger strings             execute triggers by UUID, slug, or space/slug (can be repeated or comma-separated)
      --unit strings                target specific units by slug or UUID (can be repeated or comma-separated)
      --update-validation-results   update ValidationErrors and ValidationWarnings on units based on trigger results (requires --trigger)
      --verbose                     Detailed output, additive with default output
      --wait                        wait for completion (default true)
      --where string                Filter expression using SQL-inspired syntax. Supports conjunctions with AND. String operators: =, !=, <, >, <=, >=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*. Pattern matching with LIKE/ILIKE uses % and _ wildcards. Regex operators (~, ~*, !~, !~*) support POSIX regular expressions. A related entity is referenced by prefix, as in "UpstreamUnit.Slug = 'base'"; when the reference names a list, a * segment matches any element, as in "FromLink.*.Slug = 'upgrade-app'". Examples: "Slug LIKE 'app-%'", "DisplayName ILIKE '%backend%'", "Slug ~ '^[a-z]+-[0-9]+$'"
      --where-data string           where data filter
      --where-resource string       filter which resources the function operates on
      --worker string               worker to execute the function

Options inherited from parent commands

      --context string   The context to use for this command
      --debug            Debug output
      --space string     space to operate in, by slug or UUID. Omitted, a list or bulk operation spans the organization and a single entity is named as <space>/<slug>

SEE ALSO