mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 17:28:26 +00:00
Fix: Kubernetes native auth
This commit is contained in:
@@ -33,13 +33,20 @@ type UniversalAuthDetails struct {
|
|||||||
type KubernetesAuthDetails struct {
|
type KubernetesAuthDetails struct {
|
||||||
// +kubebuilder:validation:Required
|
// +kubebuilder:validation:Required
|
||||||
IdentityID string `json:"identityId"`
|
IdentityID string `json:"identityId"`
|
||||||
// +kubebuilder:validation:Optional
|
// +kubebuilder:validation:Required
|
||||||
ServiceAccountTokenPath string `json:"serviceAccountTokenPath"`
|
ServiceAccountRef KubernetesServiceAccountRef `json:"serviceAccountRef"`
|
||||||
|
|
||||||
// +kubebuilder:validation:Required
|
// +kubebuilder:validation:Required
|
||||||
SecretsScope MachineIdentityScopeInWorkspace `json:"secretsScope"`
|
SecretsScope MachineIdentityScopeInWorkspace `json:"secretsScope"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type KubernetesServiceAccountRef struct {
|
||||||
|
// +kubebuilder:validation:Required
|
||||||
|
Name string `json:"name"`
|
||||||
|
// +kubebuilder:validation:Required
|
||||||
|
Namespace string `json:"namespace"`
|
||||||
|
}
|
||||||
|
|
||||||
type AWSIamAuthDetails struct {
|
type AWSIamAuthDetails struct {
|
||||||
// +kubebuilder:validation:Required
|
// +kubebuilder:validation:Required
|
||||||
IdentityID string `json:"identityId"`
|
IdentityID string `json:"identityId"`
|
||||||
|
|||||||
@@ -6,6 +6,7 @@ import (
|
|||||||
"fmt"
|
"fmt"
|
||||||
|
|
||||||
"github.com/Infisical/infisical/k8-operator/api/v1alpha1"
|
"github.com/Infisical/infisical/k8-operator/api/v1alpha1"
|
||||||
|
"github.com/Infisical/infisical/k8-operator/packages/util"
|
||||||
infisicalSdk "github.com/infisical/go-sdk"
|
infisicalSdk "github.com/infisical/go-sdk"
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -31,6 +32,12 @@ var AuthStrategy = struct {
|
|||||||
GCP_IAM_MACHINE_IDENTITY: "GCP_IAM_MACHINE_IDENTITY",
|
GCP_IAM_MACHINE_IDENTITY: "GCP_IAM_MACHINE_IDENTITY",
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type AuthenticationDetails struct {
|
||||||
|
authStrategy AuthStrategyType
|
||||||
|
machineIdentityScope v1alpha1.MachineIdentityScopeInWorkspace // This will only be set if a machine identity auth method is used (e.g. UniversalAuth or KubernetesAuth, etc.)
|
||||||
|
isMachineIdentityAuth bool
|
||||||
|
}
|
||||||
|
|
||||||
var ErrAuthNotApplicable = errors.New("authentication not applicable")
|
var ErrAuthNotApplicable = errors.New("authentication not applicable")
|
||||||
|
|
||||||
func (r *InfisicalSecretReconciler) handleUniversalAuth(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret, infisicalClient infisicalSdk.InfisicalClientInterface) (AuthenticationDetails, error) {
|
func (r *InfisicalSecretReconciler) handleUniversalAuth(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret, infisicalClient infisicalSdk.InfisicalClientInterface) (AuthenticationDetails, error) {
|
||||||
@@ -65,7 +72,12 @@ func (r *InfisicalSecretReconciler) handleKubernetesAuth(ctx context.Context, in
|
|||||||
return AuthenticationDetails{}, ErrAuthNotApplicable
|
return AuthenticationDetails{}, ErrAuthNotApplicable
|
||||||
}
|
}
|
||||||
|
|
||||||
_, err := infisicalClient.Auth().KubernetesAuthLogin(kubernetesAuthSpec.IdentityID, kubernetesAuthSpec.ServiceAccountTokenPath)
|
serviceAccountToken, err := util.GetServiceAccountToken(r.Client, kubernetesAuthSpec.ServiceAccountRef.Namespace, kubernetesAuthSpec.ServiceAccountRef.Name)
|
||||||
|
if err != nil {
|
||||||
|
return AuthenticationDetails{}, fmt.Errorf("unable to get service account token [err=%s]", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
_, err = infisicalClient.Auth().KubernetesRawServiceAccountTokenLogin(kubernetesAuthSpec.IdentityID, serviceAccountToken)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return AuthenticationDetails{}, fmt.Errorf("unable to login with Kubernetes native auth [err=%s]", err)
|
return AuthenticationDetails{}, fmt.Errorf("unable to login with Kubernetes native auth [err=%s]", err)
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user