ChatCRS
ChatCRS 是 ChatArch 的 CRS 管理 CLI。外部管理面优先使用 CRS HTTP/Admin API;service 域是 server-local surface,只在 CRS 服务器本机 shell 里操作本机 CRS checkout / Node runtime / crs executable。
Images 验收、debug runtime、Nginx/edge、release/cutover 等花哨/任务型能力不作为当前包内命令暴露;这些属于代理站维护、专项验收或运维 runbook,后续需要时单独设计。
安装与开发
python -m pip install -e '.[dev,docs]'
chatcrs --help
chatcrs --version
python -m pytest -q
python -m mkdocs build --strict
python -m build
完整文档使用 MkDocs,本地预览:
python -m mkdocs serve
线上文档:https://arch.gh.wzhecnu.cn/ChatCRS/
配置测试
安装后用 chatenv paste --stdin --profile smoke -I --yes 导入 CRS_API_BASE(服务根 URL)与 CRS_API_KEY,再 chatenv use smoke -t crs -I、chatenv test -t crs -I。
默认只验证 Key 鉴权,明确不证明上游可用;显式配置可选 CRS_API_MODEL 后才发起同 Key 的 Codex Responses 流式文本请求(会产生用量)。失败非零,不打印凭据或原始错误。详见配置文档。
CLI 树
chatcrs
├── --help # Show this message and exit.
├── --version # Show the version and exit.
├── --tree # Print the registered CLI tree and exit.
├── --tree-brief # Print the registered CLI tree without parameter signatures and exit.
├── admin # Remote CRS administrator operations via HTTPS Admin API.
│ ├── accounts # Inspect or refresh remote CRS account state via HTTP Admin API.
│ │ ├── refresh-status [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] <ACCOUNT-ID> [--execute] [--json-output] # Reset a CRS OpenAI account status after transient failures.
│ │ └── usage [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] [--json-output] # List OpenAI/Codex account usage and scheduling metadata.
│ ├── keys # Inspect remote CRS API keys with admin privileges.
│ │ ├── list [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] [--include-stats] [--time-range TIME-RANGE] [--json-output] # List CRS API key metadata, optionally including usage stats.
│ │ └── show [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] <KEY-ID> [--include-stats] [--time-range TIME-RANGE] [--json-output] # Show one CRS API key by id or name.
│ ├── login [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] [--save-token] [--json-output] # Verify CRS admin login without printing the session token.
│ └── token # Manage cached CRS admin session tokens in the ChatArch token store.
│ ├── clear [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] [--execute] [--json-output] # Clear the cached CRS admin session token.
│ ├── refresh [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] [--json-output] # Login and save a fresh CRS admin session token.
│ └── status [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--username USERNAME] [--password PASSWORD] [--admin-token ADMIN-TOKEN] [--timeout TIMEOUT] [--json-output] # Show cached CRS admin token metadata without printing the token.
├── codex # Direct OpenAI Codex account token and usage helpers.
│ ├── account [--profile PROFILE] [--access-token ACCESS-TOKEN] [--refresh] [--client-id CLIENT-ID] [--timeout TIMEOUT] [--json-output] # Read a safe OpenAI Codex account summary from token claims and API probe.
│ ├── quota [--profile PROFILE] [--account-id ACCOUNT-ID] [--access-token ACCESS-TOKEN] [--refresh] [--client-id CLIENT-ID] [--model MODEL] [--timeout TIMEOUT] [--json-output] # Run a profile-only Codex responses smoke and show quota headers.
│ ├── token # Manage OpenAI OAuth tokens through the ChatEnv Codex token store.
│ │ ├── refresh [--profile PROFILE] [--refresh-token REFRESH-TOKEN] [--client-id CLIENT-ID] [--timeout TIMEOUT] [--json-output] # Refresh an OpenAI OAuth access token without printing token values.
│ │ └── status [--profile PROFILE] [--json-output] # Show cached OpenAI OAuth token metadata without printing tokens.
│ └── usage [--profile PROFILE] [--account-id ACCOUNT-ID] [--access-token ACCESS-TOKEN] [--refresh] [--client-id CLIENT-ID] [--timeout TIMEOUT] [--json-output] # Read Codex usage and quota metadata directly from OpenAI.
├── health [--base-url BASE-URL] [--json-output] # Verify the CRS /health endpoint.
├── key # CRS API-key-only operations that do not require admin login.
│ └── info [--profile PROFILE] [--base-url BASE-URL] [--api-key API-KEY] [--timeout TIMEOUT] [--path INFO-PATH] [--json-output] # Query CRS key-info using only a CRS API key.
└── service # Local CRS service lifecycle commands for the current server.
├── install [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs install` on this server.
├── restart [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs restart` on this server.
├── start [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs start` on this server.
├── status [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--json-output] # Execute local `crs status` on this server.
├── stop [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs stop` on this server.
├── switch-branch <BRANCH> [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs switch-branch <branch>` on this server.
├── update [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs update` on this server.
└── update-pricing [--app-dir APP-DIR] [--crs-command CRS-COMMAND] [--timeout TIMEOUT] [--execute] [--json-output] # Plan or execute local `crs update-pricing` on this server.
运行 chatcrs --tree 可从实际 Click 注册表回读带参数签名的命令树;chatcrs --tree-brief 保留命令节点和描述,但省略参数签名。两种模式都固定使用 canonical 根名 chatcrs。
HTTP/Admin 与 API key
chatcrs health --base-url https://crs.example.com --json-output
chatcrs admin login --profile admin --json-output
chatcrs admin login --profile admin --save-token --json-output
chatcrs admin token status --profile admin --json-output
chatcrs admin token refresh --profile admin --json-output
chatcrs admin token clear --profile admin --json-output
chatcrs admin token clear --profile admin --execute --json-output
chatcrs admin accounts usage --profile admin --json-output
chatcrs admin accounts refresh-status <account_id> --profile admin --json-output
chatcrs admin accounts refresh-status <account_id> --profile admin --execute --json-output
chatcrs admin keys list --profile admin --include-stats --json-output
chatcrs admin keys show <key_id_or_name> --profile admin --json-output
chatcrs key info --profile admin --json-output
chatcrs codex token status --profile default --json-output
chatenv token refresh Codex default
chatcrs codex account --profile default --json-output
chatcrs codex quota --profile default --json-output
chatcrs codex usage --profile default --json-output
Server-local service
这些命令应安装在目标 CRS 服务器上,并在该服务器本机执行:
chatcrs service status --app-dir /path/to/crs --json-output
chatcrs service update --app-dir /path/to/crs --json-output
chatcrs service update --app-dir /path/to/crs --execute --json-output
chatcrs service restart --app-dir /path/to/crs --execute --json-output
status 默认执行本机只读 crs status。其它 service mutation 默认 dry-run,需要 --execute 才执行。
配置
ChatCRS 使用 CRS ChatEnv profile 管理 CRS Admin/API 配置,并为 OpenAI 注册 OAuth token refresher 供 Codex direct 使用。Codex direct 的稳定 OAuth profile 来自 envs/Codex/<profile>.env,runtime token 来自 tokens/Codex/<profile>.json,持久刷新用 chatenv token refresh Codex <profile>。Codex profile 可设置非敏感 relay 字段:OPENAI_OAUTH_BASE_URL 覆盖 OAuth token/accounts upstream,CHATGPT_BACKEND_BASE_URL 覆盖 ChatGPT backend upstream。公开文档只描述字段类别,不写具体 secret 文件路径或 secret-bearing env key 名。
Canonical 字段类别:
HTTP base URL
caller API key
admin username
admin password
admin bearer/session token
Service-local 目标不进入第二套 ChatEnv namespace;用当前工作目录或 --app-dir / --crs-command 指定本机 checkout 和 executable。
敏感字段只应存在于 ChatEnv 或进程环境中,不进入命令行参数、文档、PR body 或日志输出。Profile 文件应使用 0600 权限。
生产安全
外部管理只能使用 HTTP/Admin API;没有 HTTP lifecycle 接口时,不用远端执行补洞。要么新增 CRS API/host-agent,要么在目标服务器本机运行 chatcrs service ...。
更多内容见:
docs/cli.mddocs/interfaces.mddocs/configuration.mddocs/production-maintenance.md
Metadata
Release files for ChatCRS 0.3.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| chatcrs-0.3.2.tar.gz | 72.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| chatcrs-0.3.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 104.5 kB
Release files / chatcrs-0.3.2.tar.gz
| Download URL | chatcrs-0.3.2.tar.gz |
|---|---|
| Size | 72.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1624e8ee889f3381ff9626f53469abc7db4738488a2e02d3d90f2e929fb53565
|
|
BLAKE2b-256 checksum How to use checksums |
9eea2c8b82b8ebc99481ad7d7078794cb4a914f5a50cd56d47137ef26c9c627f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.
Transparency logRelease files / chatcrs-0.3.2-py3-none-any.whl
| Download URL | chatcrs-0.3.2-py3-none-any.whl |
|---|---|
| Size | 31.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6cba1f75f7d0fdadbc22f186d059b9c1cb1510d7f145f807a410e31f53d9c89e
|
|
BLAKE2b-256 checksum How to use checksums |
c5c3d2f49a13f97216cc5972d6d4a538bf00ef741c562bc416559420c3913051
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 8, 2026.
Transparency log