mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 05:28:51 +00:00
add try catch
This commit is contained in:
@@ -42,85 +42,109 @@ export const RailwaySyncFns = {
|
|||||||
|
|
||||||
/**
|
/**
|
||||||
* Syncs secrets to Railway and redeploys the service if needed.
|
* Syncs secrets to Railway and redeploys the service if needed.
|
||||||
*
|
*
|
||||||
* Gets existing Railway vars, merges with new secrets (keeping Railway vars if deletion is disabled),
|
* Gets existing Railway vars, merges with new secrets (keeping Railway vars if deletion is disabled),
|
||||||
* then replaces every variable with the new values, if variable is not in the secretMap, it is deleted.
|
* then replaces every variable with the new values, if variable is not in the secretMap, it is deleted.
|
||||||
* If there's a service, triggers a redeploy to pick up the changes.
|
* If there's a service, triggers a redeploy to pick up the changes.
|
||||||
*/
|
*/
|
||||||
async syncSecrets(secretSync: TRailwaySyncWithCredentials, secretMap: TSecretMap) {
|
async syncSecrets(secretSync: TRailwaySyncWithCredentials, secretMap: TSecretMap) {
|
||||||
const {
|
try {
|
||||||
syncOptions: { disableSecretDeletion }
|
const {
|
||||||
} = secretSync;
|
syncOptions: { disableSecretDeletion }
|
||||||
const railwaySecrets = await this.getSecrets(secretSync);
|
} = secretSync;
|
||||||
const config = secretSync.destinationConfig;
|
const railwaySecrets = await this.getSecrets(secretSync);
|
||||||
|
const config = secretSync.destinationConfig;
|
||||||
|
|
||||||
const railwaySecretsMap = Object.fromEntries(Object.entries(railwaySecrets).map(([key, secret]) => [key, secret.value]));
|
const railwaySecretsMap = Object.fromEntries(
|
||||||
const secretMapMap = Object.fromEntries(Object.entries(secretMap).map(([key, secret]) => [key, secret.value]));
|
Object.entries(railwaySecrets).map(([key, secret]) => [key, secret.value])
|
||||||
|
);
|
||||||
|
const secretMapMap = Object.fromEntries(Object.entries(secretMap).map(([key, secret]) => [key, secret.value]));
|
||||||
|
|
||||||
const toReplace = disableSecretDeletion
|
const toReplace = disableSecretDeletion ? { ...railwaySecretsMap, ...secretMapMap } : secretMapMap;
|
||||||
? { ...railwaySecretsMap, ...secretMapMap }
|
|
||||||
: secretMapMap;
|
|
||||||
|
|
||||||
const upserted = await RailwayPublicAPI.upsertCollection(secretSync.connection, {
|
const upserted = await RailwayPublicAPI.upsertCollection(secretSync.connection, {
|
||||||
input: {
|
input: {
|
||||||
projectId: config.projectId,
|
projectId: config.projectId,
|
||||||
environmentId: config.environmentId,
|
environmentId: config.environmentId,
|
||||||
serviceId: config.serviceId || undefined,
|
serviceId: config.serviceId || undefined,
|
||||||
skipDeploys: true,
|
skipDeploys: true,
|
||||||
variables: toReplace,
|
variables: toReplace,
|
||||||
replace: true,
|
replace: true
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!upserted) throw new SecretSyncError({
|
if (!upserted)
|
||||||
message: "Failed to upsert secrets to Railway",
|
throw new SecretSyncError({
|
||||||
})
|
message: "Failed to upsert secrets to Railway"
|
||||||
|
});
|
||||||
|
|
||||||
if (!config.serviceId) return;
|
if (!config.serviceId) return;
|
||||||
|
|
||||||
const latestDeployment = await RailwayPublicAPI.getDeployments(secretSync.connection, {
|
const latestDeployment = await RailwayPublicAPI.getDeployments(secretSync.connection, {
|
||||||
input: {
|
input: {
|
||||||
serviceId: config.serviceId,
|
serviceId: config.serviceId,
|
||||||
environmentId: config.environmentId
|
environmentId: config.environmentId
|
||||||
},
|
},
|
||||||
first: 1,
|
first: 1
|
||||||
});
|
});
|
||||||
|
|
||||||
const latestDeploymentId = latestDeployment?.deployments.edges[0].node.id;
|
const latestDeploymentId = latestDeployment?.deployments.edges[0].node.id;
|
||||||
|
|
||||||
if (!latestDeploymentId) throw new SecretSyncError({
|
if (!latestDeploymentId)
|
||||||
message: "Failed to get latest deployment from Railway",
|
throw new SecretSyncError({
|
||||||
})
|
message: "Failed to get latest deployment from Railway"
|
||||||
|
});
|
||||||
|
|
||||||
await RailwayPublicAPI.redeployDeployment(secretSync.connection, {
|
await RailwayPublicAPI.redeployDeployment(secretSync.connection, {
|
||||||
input: {
|
input: {
|
||||||
deploymentId: latestDeploymentId
|
deploymentId: latestDeploymentId
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
} catch (error) {
|
||||||
|
if (error instanceof SecretSyncError) throw error;
|
||||||
|
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
message: "Failed to sync secrets to Railway"
|
||||||
|
});
|
||||||
|
}
|
||||||
},
|
},
|
||||||
|
|
||||||
async removeSecrets(secretSync: TRailwaySyncWithCredentials, secretMap: TSecretMap) {
|
async removeSecrets(secretSync: TRailwaySyncWithCredentials, secretMap: TSecretMap) {
|
||||||
const existing = await this.getSecrets(secretSync);
|
const existing = await this.getSecrets(secretSync);
|
||||||
const config = secretSync.destinationConfig;
|
const config = secretSync.destinationConfig;
|
||||||
|
|
||||||
for await (const secret of Object.keys(existing)) {
|
// Create a new variables object excluding secrets that exist in secretMap
|
||||||
try {
|
const remainingVariables = Object.fromEntries(
|
||||||
if (secret in secretMap) {
|
Object.entries(existing)
|
||||||
await RailwayPublicAPI.deleteVariable(secretSync.connection, {
|
.filter(([key]) => !(key in secretMap))
|
||||||
input: {
|
.map(([key, secret]) => [key, secret.value])
|
||||||
projectId: config.projectId,
|
);
|
||||||
environmentId: config.environmentId,
|
|
||||||
serviceId: config.serviceId || undefined,
|
try {
|
||||||
name: secret
|
const upserted = await RailwayPublicAPI.upsertCollection(secretSync.connection, {
|
||||||
}
|
input: {
|
||||||
});
|
projectId: config.projectId,
|
||||||
|
environmentId: config.environmentId,
|
||||||
|
serviceId: config.serviceId || undefined,
|
||||||
|
skipDeploys: true,
|
||||||
|
variables: remainingVariables,
|
||||||
|
replace: true
|
||||||
}
|
}
|
||||||
} catch (error) {
|
});
|
||||||
|
|
||||||
|
if (!upserted) {
|
||||||
throw new SecretSyncError({
|
throw new SecretSyncError({
|
||||||
error,
|
message: "Failed to remove secrets from Railway"
|
||||||
secretKey: secret
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
} catch (error) {
|
||||||
|
if (error instanceof SecretSyncError) throw error;
|
||||||
|
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
message: "Failed to remove secrets from Railway"
|
||||||
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user