mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 06:26:16 +00:00
Merge pull request #1869 from Infisical/misc/made-aws-sm-mapping-plaintext-one-to-one
misc: made aws sm mapping one to one plaintext
This commit is contained in:
@@ -587,7 +587,10 @@ const syncSecretsAWSSecretManager = async ({
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
const processAwsSecret = async (secretId: string, keyValuePairs: Record<string, string | null | undefined>) => {
|
const processAwsSecret = async (
|
||||||
|
secretId: string,
|
||||||
|
secretValue: Record<string, string | null | undefined> | string
|
||||||
|
) => {
|
||||||
try {
|
try {
|
||||||
const awsSecretManagerSecret = await secretsManager.send(
|
const awsSecretManagerSecret = await secretsManager.send(
|
||||||
new GetSecretValueCommand({
|
new GetSecretValueCommand({
|
||||||
@@ -595,17 +598,20 @@ const syncSecretsAWSSecretManager = async ({
|
|||||||
})
|
})
|
||||||
);
|
);
|
||||||
|
|
||||||
let awsSecretManagerSecretObj: { [key: string]: AWS.SecretsManager } = {};
|
let secretToCompare;
|
||||||
|
|
||||||
if (awsSecretManagerSecret?.SecretString) {
|
if (awsSecretManagerSecret?.SecretString) {
|
||||||
awsSecretManagerSecretObj = JSON.parse(awsSecretManagerSecret.SecretString);
|
if (typeof secretValue === "string") {
|
||||||
|
secretToCompare = awsSecretManagerSecret.SecretString;
|
||||||
|
} else {
|
||||||
|
secretToCompare = JSON.parse(awsSecretManagerSecret.SecretString);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!isEqual(awsSecretManagerSecretObj, keyValuePairs)) {
|
if (!isEqual(secretToCompare, secretValue)) {
|
||||||
await secretsManager.send(
|
await secretsManager.send(
|
||||||
new UpdateSecretCommand({
|
new UpdateSecretCommand({
|
||||||
SecretId: secretId,
|
SecretId: secretId,
|
||||||
SecretString: JSON.stringify(keyValuePairs)
|
SecretString: typeof secretValue === "string" ? secretValue : JSON.stringify(secretValue)
|
||||||
})
|
})
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
@@ -695,7 +701,7 @@ const syncSecretsAWSSecretManager = async ({
|
|||||||
await secretsManager.send(
|
await secretsManager.send(
|
||||||
new CreateSecretCommand({
|
new CreateSecretCommand({
|
||||||
Name: secretId,
|
Name: secretId,
|
||||||
SecretString: JSON.stringify(keyValuePairs),
|
SecretString: typeof secretValue === "string" ? secretValue : JSON.stringify(secretValue),
|
||||||
...(metadata.kmsKeyId && { KmsKeyId: metadata.kmsKeyId }),
|
...(metadata.kmsKeyId && { KmsKeyId: metadata.kmsKeyId }),
|
||||||
Tags: metadata.secretAWSTag
|
Tags: metadata.secretAWSTag
|
||||||
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({ Key: tag.key, Value: tag.value }))
|
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({ Key: tag.key, Value: tag.value }))
|
||||||
@@ -708,9 +714,7 @@ const syncSecretsAWSSecretManager = async ({
|
|||||||
|
|
||||||
if (metadata.mappingBehavior === IntegrationMappingBehavior.ONE_TO_ONE) {
|
if (metadata.mappingBehavior === IntegrationMappingBehavior.ONE_TO_ONE) {
|
||||||
for await (const [key, value] of Object.entries(secrets)) {
|
for await (const [key, value] of Object.entries(secrets)) {
|
||||||
await processAwsSecret(key, {
|
await processAwsSecret(key, value.value);
|
||||||
[key]: value.value
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
await processAwsSecret(integration.app as string, getSecretKeyValuePair(secrets));
|
await processAwsSecret(integration.app as string, getSecretKeyValuePair(secrets));
|
||||||
|
|||||||
Reference in New Issue
Block a user