mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 05:28:29 +00:00
added kms key delector for parameter store
This commit is contained in:
@@ -572,14 +572,14 @@ export const integrationAuthServiceFactory = ({
|
|||||||
const response = keys
|
const response = keys
|
||||||
.Keys!.map((key) => {
|
.Keys!.map((key) => {
|
||||||
const keyAlias = aliases.Aliases!.find((alias) => key.KeyId === alias.TargetKeyId);
|
const keyAlias = aliases.Aliases!.find((alias) => key.KeyId === alias.TargetKeyId);
|
||||||
if (!keyAlias?.AliasName?.includes("alias/aws/") || keyAlias?.AliasName?.includes("alias/aws/secretsmanager")) {
|
if (!keyAlias?.AliasName?.includes("alias/aws/")) {
|
||||||
return { id: String(key.KeyId), alias: String(keyAlias?.AliasName || key.KeyId) };
|
return { id: String(key.KeyId), alias: String(keyAlias?.AliasName || key.KeyId) };
|
||||||
}
|
}
|
||||||
return { id: "null", alias: "null" };
|
return { id: "null", alias: "null" };
|
||||||
})
|
})
|
||||||
.filter((elem) => elem.id !== "null");
|
.filter((elem) => elem.id !== "null");
|
||||||
|
|
||||||
return response;
|
return [...response, { id: "null", alias: "default" }];
|
||||||
};
|
};
|
||||||
|
|
||||||
const getQoveryProjects = async ({
|
const getQoveryProjects = async ({
|
||||||
|
|||||||
@@ -477,24 +477,29 @@ const syncSecretsAWSParameterStore = async ({
|
|||||||
}),
|
}),
|
||||||
{} as Record<string, AWS.SSM.Parameter>
|
{} as Record<string, AWS.SSM.Parameter>
|
||||||
);
|
);
|
||||||
|
|
||||||
// Identify secrets to create
|
// Identify secrets to create
|
||||||
await Promise.all(
|
await Promise.all(
|
||||||
Object.keys(secrets).map(async (key) => {
|
Object.keys(secrets).map(async (key) => {
|
||||||
if (!(key in awsParameterStoreSecretsObj)) {
|
if (!(key in awsParameterStoreSecretsObj)) {
|
||||||
// case: secret does not exist in AWS parameter store
|
// case: secret does not exist in AWS parameter store
|
||||||
// -> create secret
|
// -> create secret
|
||||||
await ssm
|
if (secrets[key].value) {
|
||||||
.putParameter({
|
await ssm
|
||||||
Name: `${integration.path}${key}`,
|
.putParameter({
|
||||||
Type: "SecureString",
|
Name: `${integration.path}${key}`,
|
||||||
Value: secrets[key].value,
|
Type: "SecureString",
|
||||||
// Overwrite: true,
|
Value: secrets[key].value,
|
||||||
Tags: metadata.secretAWSTag
|
KeyId: metadata.kmsKeyId ? metadata.kmsKeyId : undefined,
|
||||||
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({ Key: tag.key, Value: tag.value }))
|
// Overwrite: true,
|
||||||
: []
|
Tags: metadata.secretAWSTag
|
||||||
})
|
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({
|
||||||
.promise();
|
Key: tag.key,
|
||||||
|
Value: tag.value
|
||||||
|
}))
|
||||||
|
: []
|
||||||
|
})
|
||||||
|
.promise();
|
||||||
|
}
|
||||||
// case: secret exists in AWS parameter store
|
// case: secret exists in AWS parameter store
|
||||||
} else if (awsParameterStoreSecretsObj[key].Value !== secrets[key].value) {
|
} else if (awsParameterStoreSecretsObj[key].Value !== secrets[key].value) {
|
||||||
// case: secret value doesn't match one in AWS parameter store
|
// case: secret value doesn't match one in AWS parameter store
|
||||||
|
|||||||
Binary file not shown.
|
Before Width: | Height: | Size: 181 KiB After Width: | Height: | Size: 131 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 199 KiB After Width: | Height: | Size: 160 KiB |
@@ -14,6 +14,7 @@ import { motion } from "framer-motion";
|
|||||||
import queryString from "query-string";
|
import queryString from "query-string";
|
||||||
|
|
||||||
import { useCreateIntegration } from "@app/hooks/api";
|
import { useCreateIntegration } from "@app/hooks/api";
|
||||||
|
import { useGetIntegrationAuthAwsKmsKeys } from "@app/hooks/api/integrationAuth/queries";
|
||||||
|
|
||||||
import {
|
import {
|
||||||
Button,
|
Button,
|
||||||
@@ -90,6 +91,7 @@ export default function AWSParameterStoreCreateIntegrationPage() {
|
|||||||
const [shouldTag, setShouldTag] = useState(false);
|
const [shouldTag, setShouldTag] = useState(false);
|
||||||
const [tagKey, setTagKey] = useState("");
|
const [tagKey, setTagKey] = useState("");
|
||||||
const [tagValue, setTagValue] = useState("");
|
const [tagValue, setTagValue] = useState("");
|
||||||
|
const [kmsKeyId, setKmsKeyId] = useState("");
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (workspace) {
|
if (workspace) {
|
||||||
@@ -98,6 +100,19 @@ export default function AWSParameterStoreCreateIntegrationPage() {
|
|||||||
}
|
}
|
||||||
}, [workspace]);
|
}, [workspace]);
|
||||||
|
|
||||||
|
|
||||||
|
const { data: integrationAuthAwsKmsKeys, isLoading: isIntegrationAuthAwsKmsKeysLoading } =
|
||||||
|
useGetIntegrationAuthAwsKmsKeys({
|
||||||
|
integrationAuthId: String(integrationAuthId),
|
||||||
|
region: selectedAWSRegion
|
||||||
|
});
|
||||||
|
|
||||||
|
useEffect(() => {
|
||||||
|
if (integrationAuthAwsKmsKeys) {
|
||||||
|
setKmsKeyId(String(integrationAuthAwsKmsKeys?.filter(key => key.alias === "default")[0]?.id))
|
||||||
|
}
|
||||||
|
}, [integrationAuthAwsKmsKeys])
|
||||||
|
|
||||||
const isValidAWSParameterStorePath = (awsStorePath: string) => {
|
const isValidAWSParameterStorePath = (awsStorePath: string) => {
|
||||||
const pattern = /^\/([\w-]+\/)*[\w-]+\/$/;
|
const pattern = /^\/([\w-]+\/)*[\w-]+\/$/;
|
||||||
return pattern.test(awsStorePath) && awsStorePath.length <= 2048;
|
return pattern.test(awsStorePath) && awsStorePath.length <= 2048;
|
||||||
@@ -133,7 +148,11 @@ export default function AWSParameterStoreCreateIntegrationPage() {
|
|||||||
value: tagValue
|
value: tagValue
|
||||||
}]
|
}]
|
||||||
}
|
}
|
||||||
: {})
|
: {}),
|
||||||
|
...((kmsKeyId && integrationAuthAwsKmsKeys?.filter(key => key.id === kmsKeyId)[0]?.alias !== "default") ?
|
||||||
|
{
|
||||||
|
kmsKeyId
|
||||||
|
}: {})
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -146,7 +165,7 @@ export default function AWSParameterStoreCreateIntegrationPage() {
|
|||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
return integrationAuth && workspace && selectedSourceEnvironment ? (
|
return (integrationAuth && workspace && selectedSourceEnvironment && !isIntegrationAuthAwsKmsKeysLoading) ? (
|
||||||
<div className="flex h-full w-full flex-col items-center justify-center">
|
<div className="flex h-full w-full flex-col items-center justify-center">
|
||||||
<Head>
|
<Head>
|
||||||
<title>Set Up AWS Parameter Integration</title>
|
<title>Set Up AWS Parameter Integration</title>
|
||||||
@@ -286,6 +305,31 @@ export default function AWSParameterStoreCreateIntegrationPage() {
|
|||||||
</FormControl>
|
</FormControl>
|
||||||
</div>
|
</div>
|
||||||
)}
|
)}
|
||||||
|
<FormControl label="Encryption Key" className="mt-4">
|
||||||
|
<Select
|
||||||
|
value={kmsKeyId}
|
||||||
|
onValueChange={(e) => {
|
||||||
|
setKmsKeyId(e)
|
||||||
|
}}
|
||||||
|
className="w-full border border-mineshaft-500"
|
||||||
|
>
|
||||||
|
{integrationAuthAwsKmsKeys?.length ? (
|
||||||
|
integrationAuthAwsKmsKeys.map((key) => {
|
||||||
|
return (
|
||||||
|
<SelectItem
|
||||||
|
value={key.id as string}
|
||||||
|
key={`repo-id-${key.id}`}
|
||||||
|
className="w-[28.4rem] text-sm"
|
||||||
|
>
|
||||||
|
{key.alias}
|
||||||
|
</SelectItem>
|
||||||
|
);
|
||||||
|
})
|
||||||
|
) : (
|
||||||
|
<div />
|
||||||
|
)}
|
||||||
|
</Select>
|
||||||
|
</FormControl>
|
||||||
</motion.div>
|
</motion.div>
|
||||||
</TabPanel>
|
</TabPanel>
|
||||||
</Tabs>
|
</Tabs>
|
||||||
@@ -318,7 +362,7 @@ export default function AWSParameterStoreCreateIntegrationPage() {
|
|||||||
<title>Set Up AWS Parameter Store Integration</title>
|
<title>Set Up AWS Parameter Store Integration</title>
|
||||||
<link rel="icon" href="/infisical.ico" />
|
<link rel="icon" href="/infisical.ico" />
|
||||||
</Head>
|
</Head>
|
||||||
{isintegrationAuthLoading ? (
|
{(isintegrationAuthLoading || isIntegrationAuthAwsKmsKeysLoading) ? (
|
||||||
<img
|
<img
|
||||||
src="/images/loading/loading.gif"
|
src="/images/loading/loading.gif"
|
||||||
height={70}
|
height={70}
|
||||||
|
|||||||
@@ -148,7 +148,7 @@ export default function AWSSecretManagerCreateIntegrationPage() {
|
|||||||
}]
|
}]
|
||||||
}
|
}
|
||||||
: {}),
|
: {}),
|
||||||
...((kmsKeyId && integrationAuthAwsKmsKeys?.filter(key => key.id === kmsKeyId)[0]?.alias !== "alias/aws/secretsmanager") ?
|
...((kmsKeyId && integrationAuthAwsKmsKeys?.filter(key => key.id === kmsKeyId)[0]?.alias !== "default") ?
|
||||||
{
|
{
|
||||||
kmsKeyId
|
kmsKeyId
|
||||||
}: {})
|
}: {})
|
||||||
|
|||||||
+1
-1
@@ -109,7 +109,7 @@ export const CloudIntegrationSection = ({
|
|||||||
</div>
|
</div>
|
||||||
{cloudIntegration.isAvailable &&
|
{cloudIntegration.isAvailable &&
|
||||||
Boolean(integrationAuths?.[cloudIntegration.slug]) && (
|
Boolean(integrationAuths?.[cloudIntegration.slug]) && (
|
||||||
<div className="absolute top-0 right-0 z-40 h-full">
|
<div className="absolute top-0 right-0 z-30 h-full">
|
||||||
<div className="relative h-full">
|
<div className="relative h-full">
|
||||||
<div className="absolute top-0 right-0 w-24 flex-row items-center overflow-hidden whitespace-nowrap rounded-tr-md rounded-bl-md bg-primary py-0.5 px-2 text-xs text-black opacity-80 transition-all duration-300 group-hover:w-0 group-hover:p-0">
|
<div className="absolute top-0 right-0 w-24 flex-row items-center overflow-hidden whitespace-nowrap rounded-tr-md rounded-bl-md bg-primary py-0.5 px-2 text-xs text-black opacity-80 transition-all duration-300 group-hover:w-0 group-hover:p-0">
|
||||||
<FontAwesomeIcon icon={faCheck} className="mr-2 text-xs" />
|
<FontAwesomeIcon icon={faCheck} className="mr-2 text-xs" />
|
||||||
|
|||||||
+2
-1
@@ -217,11 +217,12 @@ export const IntegrationsSection = ({
|
|||||||
isOpen={popUp.deleteConfirmation.isOpen}
|
isOpen={popUp.deleteConfirmation.isOpen}
|
||||||
title={`Are you sure want to remove ${
|
title={`Are you sure want to remove ${
|
||||||
(popUp?.deleteConfirmation.data as TIntegration)?.integration || " "
|
(popUp?.deleteConfirmation.data as TIntegration)?.integration || " "
|
||||||
} integration for ${(popUp?.deleteConfirmation.data as TIntegration)?.app || " "}?`}
|
} integration for ${(popUp?.deleteConfirmation.data as TIntegration)?.app || "this project"}?`}
|
||||||
onChange={(isOpen) => handlePopUpToggle("deleteConfirmation", isOpen)}
|
onChange={(isOpen) => handlePopUpToggle("deleteConfirmation", isOpen)}
|
||||||
deleteKey={
|
deleteKey={
|
||||||
(popUp?.deleteConfirmation?.data as TIntegration)?.app ||
|
(popUp?.deleteConfirmation?.data as TIntegration)?.app ||
|
||||||
(popUp?.deleteConfirmation?.data as TIntegration)?.owner ||
|
(popUp?.deleteConfirmation?.data as TIntegration)?.owner ||
|
||||||
|
(popUp?.deleteConfirmation?.data as TIntegration)?.path ||
|
||||||
""
|
""
|
||||||
}
|
}
|
||||||
onDeleteApproved={async () =>
|
onDeleteApproved={async () =>
|
||||||
|
|||||||
Reference in New Issue
Block a user