Merge pull request #1182 from Allex1/secret

Make secret type field configurable
This commit is contained in:
Maidul Islam
2023-12-07 19:31:39 -05:00
committed by GitHub
9 changed files with 76 additions and 11 deletions
+1 -1
View File
@@ -13,7 +13,7 @@ type: application
# This is the chart version. This version number should be incremented each time you make changes # This is the chart version. This version number should be incremented each time you make changes
# to the chart and its templates, including the app version. # to the chart and its templates, including the app version.
# Versions are expected to follow Semantic Versioning (https://semver.org/) # Versions are expected to follow Semantic Versioning (https://semver.org/)
version: 0.2.1 version: 0.3.0
# This is the version number of the application being deployed. This version number should be # This is the version number of the application being deployed. This version number should be
# incremented each time you make changes to the application. Versions are not expected to # incremented each time you make changes to the application. Versions are not expected to
# follow Semantic Versioning. They should reflect the version the application is using. # follow Semantic Versioning. They should reflect the version the application is using.
@@ -102,6 +102,11 @@ spec:
secretNamespace: secretNamespace:
description: The name space where the Kubernetes Secret is located description: The name space where the Kubernetes Secret is located
type: string type: string
secretType:
default: Opaque
description: 'The Kubernetes Secret type (experimental feature).
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
type: string
required: required:
- secretName - secretName
- secretNamespace - secretNamespace
@@ -43,6 +43,21 @@ type KubeSecretReference struct {
SecretNamespace string `json:"secretNamespace"` SecretNamespace string `json:"secretNamespace"`
} }
type MangedKubeSecretConfig struct {
// The name of the Kubernetes Secret
// +kubebuilder:validation:Required
SecretName string `json:"secretName"`
// The name space where the Kubernetes Secret is located
// +kubebuilder:validation:Required
SecretNamespace string `json:"secretNamespace"`
// The Kubernetes Secret type (experimental feature). More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types
// +kubebuilder:validation:Optional
// +kubebuilder:default:=Opaque
SecretType string `json:"secretType"`
}
// InfisicalSecretSpec defines the desired state of InfisicalSecret // InfisicalSecretSpec defines the desired state of InfisicalSecret
type InfisicalSecretSpec struct { type InfisicalSecretSpec struct {
// +kubebuilder:validation:Optional // +kubebuilder:validation:Optional
@@ -52,7 +67,7 @@ type InfisicalSecretSpec struct {
Authentication Authentication `json:"authentication"` Authentication Authentication `json:"authentication"`
// +kubebuilder:validation:Required // +kubebuilder:validation:Required
ManagedSecretReference KubeSecretReference `json:"managedSecretReference"` ManagedSecretReference MangedKubeSecretConfig `json:"managedSecretReference"`
// +kubebuilder:default:=60 // +kubebuilder:default:=60
ResyncInterval int `json:"resyncInterval"` ResyncInterval int `json:"resyncInterval"`
@@ -157,6 +157,21 @@ func (in *KubeSecretReference) DeepCopy() *KubeSecretReference {
return out return out
} }
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (in *MangedKubeSecretConfig) DeepCopyInto(out *MangedKubeSecretConfig) {
*out = *in
}
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new MangedKubeSecretConfig.
func (in *MangedKubeSecretConfig) DeepCopy() *MangedKubeSecretConfig {
if in == nil {
return nil
}
out := new(MangedKubeSecretConfig)
in.DeepCopyInto(out)
return out
}
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil. // DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
func (in *SecretScopeInWorkspace) DeepCopyInto(out *SecretScopeInWorkspace) { func (in *SecretScopeInWorkspace) DeepCopyInto(out *SecretScopeInWorkspace) {
*out = *in *out = *in
@@ -102,6 +102,11 @@ spec:
secretNamespace: secretNamespace:
description: The name space where the Kubernetes Secret is located description: The name space where the Kubernetes Secret is located
type: string type: string
secretType:
default: Opaque
description: 'The Kubernetes Secret type (experimental feature).
More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
type: string
required: required:
- secretName - secretName
- secretNamespace - secretNamespace
+7 -1
View File
@@ -2,8 +2,12 @@ apiVersion: secrets.infisical.com/v1alpha1
kind: InfisicalSecret kind: InfisicalSecret
metadata: metadata:
name: infisicalsecret-sample name: infisicalsecret-sample
labels:
label-to-be-passed-to-managed-secret: sample-value
annotations:
example.com/annotation-to-be-passed-to-managed-secret: "sample-value"
spec: spec:
hostAPI: http://localhost:8764/api hostAPI: https://app.infisical.com/api
resyncInterval: 10 resyncInterval: 10
authentication: authentication:
serviceAccount: serviceAccount:
@@ -22,6 +26,8 @@ spec:
managedSecretReference: managedSecretReference:
secretName: managed-secret secretName: managed-secret
secretNamespace: default secretNamespace: default
# secretType: kubernetes.io/dockerconfigjson
# # To be depreciated soon # # To be depreciated soon
# tokenSecretReference: # tokenSecretReference:
# secretName: service-token # secretName: service-token
@@ -36,6 +36,8 @@ func (r *InfisicalSecretReconciler) ReconcileDeploymentsWithManagedSecrets(ctx c
var wg sync.WaitGroup var wg sync.WaitGroup
// Iterate over the deployments and check if they use the managed secret // Iterate over the deployments and check if they use the managed secret
for _, deployment := range listOfDeployments.Items { for _, deployment := range listOfDeployments.Items {
// Adding bc of https://github.com/golang/go/issues/16520
deployment := deployment
if deployment.Annotations[AUTO_RELOAD_DEPLOYMENT_ANNOTATION] == "true" && r.IsDeploymentUsingManagedSecret(deployment, infisicalSecret) { if deployment.Annotations[AUTO_RELOAD_DEPLOYMENT_ANNOTATION] == "true" && r.IsDeploymentUsingManagedSecret(deployment, infisicalSecret) {
// Start a goroutine to reconcile the deployment // Start a goroutine to reconcile the deployment
wg.Add(1) wg.Add(1)
@@ -72,7 +72,6 @@ func (r *InfisicalSecretReconciler) GetInfisicalTokenFromKubeSecret(ctx context.
// default to new secret ref structure // default to new secret ref structure
secretName := infisicalSecret.Spec.Authentication.ServiceToken.ServiceTokenSecretReference.SecretName secretName := infisicalSecret.Spec.Authentication.ServiceToken.ServiceTokenSecretReference.SecretName
secretNamespace := infisicalSecret.Spec.Authentication.ServiceToken.ServiceTokenSecretReference.SecretNamespace secretNamespace := infisicalSecret.Spec.Authentication.ServiceToken.ServiceTokenSecretReference.SecretNamespace
// fall back to previous secret ref // fall back to previous secret ref
if secretName == "" { if secretName == "" {
secretName = infisicalSecret.Spec.TokenSecretReference.SecretName secretName = infisicalSecret.Spec.TokenSecretReference.SecretName
@@ -129,20 +128,34 @@ func (r *InfisicalSecretReconciler) GetInfisicalServiceAccountCredentialsFromKub
func (r *InfisicalSecretReconciler) CreateInfisicalManagedKubeSecret(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret, secretsFromAPI []model.SingleEnvironmentVariable, encryptedSecretsResponse api.GetEncryptedSecretsV3Response) error { func (r *InfisicalSecretReconciler) CreateInfisicalManagedKubeSecret(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret, secretsFromAPI []model.SingleEnvironmentVariable, encryptedSecretsResponse api.GetEncryptedSecretsV3Response) error {
plainProcessedSecrets := make(map[string][]byte) plainProcessedSecrets := make(map[string][]byte)
secretType := infisicalSecret.Spec.ManagedSecretReference.SecretType
for _, secret := range secretsFromAPI { for _, secret := range secretsFromAPI {
plainProcessedSecrets[secret.Key] = []byte(secret.Value) // plain process plainProcessedSecrets[secret.Key] = []byte(secret.Value) // plain process
} }
// copy labels and annotations from InfisicalSecret CRD
labels := map[string]string{}
for k, v := range infisicalSecret.Labels {
labels[k] = v
}
annotations := map[string]string{}
for k, v := range infisicalSecret.Annotations {
annotations[k] = v
}
annotations[SECRET_VERSION_ANNOTATION] = encryptedSecretsResponse.ETag
// create a new secret as specified by the managed secret spec of CRD // create a new secret as specified by the managed secret spec of CRD
newKubeSecretInstance := &corev1.Secret{ newKubeSecretInstance := &corev1.Secret{
ObjectMeta: metav1.ObjectMeta{ ObjectMeta: metav1.ObjectMeta{
Name: infisicalSecret.Spec.ManagedSecretReference.SecretName, Name: infisicalSecret.Spec.ManagedSecretReference.SecretName,
Namespace: infisicalSecret.Spec.ManagedSecretReference.SecretNamespace, Namespace: infisicalSecret.Spec.ManagedSecretReference.SecretNamespace,
Annotations: map[string]string{ Annotations: annotations,
SECRET_VERSION_ANNOTATION: encryptedSecretsResponse.ETag, Labels: labels,
},
}, },
Type: "Opaque", Type: corev1.SecretType(secretType),
Data: plainProcessedSecrets, Data: plainProcessedSecrets,
} }
@@ -151,7 +164,7 @@ func (r *InfisicalSecretReconciler) CreateInfisicalManagedKubeSecret(ctx context
return fmt.Errorf("unable to create the managed Kubernetes secret : %w", err) return fmt.Errorf("unable to create the managed Kubernetes secret : %w", err)
} }
fmt.Println("Successfully created a managed Kubernetes secret with your Infisical secrets") fmt.Printf("Successfully created a managed Kubernetes secret with your Infisical secrets. Type: %s\n", secretType)
return nil return nil
} }
@@ -108,6 +108,10 @@ spec:
secretNamespace: secretNamespace:
description: The name space where the Kubernetes Secret is located description: The name space where the Kubernetes Secret is located
type: string type: string
secretType:
default: Opaque
description: 'The Kubernetes Secret type (experimental feature). More info: https://kubernetes.io/docs/concepts/configuration/secret/#secret-types'
type: string
required: required:
- secretName - secretName
- secretNamespace - secretNamespace