mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 16:27:46 +00:00
improvements: add ssl options to sql connections and update ui/docs
This commit is contained in:
+14
-1
@@ -7,7 +7,20 @@ export const MSSQL_CREDENTIALS_ROTATION_LIST_OPTION: TSecretRotationV2ListItem =
|
||||
type: SecretRotation.MsSqlCredentials,
|
||||
connection: AppConnection.MsSql,
|
||||
template: {
|
||||
createUserStatement: `CREATE LOGIN [my_mssql_user] WITH PASSWORD = 'my_temporary_password'; CREATE USER [my_mssql_user] FOR LOGIN [my_mssql_user]; GRANT SELECT, INSERT, UPDATE, DELETE ON SCHEMA::dbo TO [my_mssql_user];`,
|
||||
createUserStatement: `-- Create login at the server level
|
||||
CREATE LOGIN [infisical_user] WITH PASSWORD = 'my-password';
|
||||
|
||||
-- Grant server-level connect permission
|
||||
GRANT CONNECT SQL TO [infisical_user];
|
||||
|
||||
-- Switch to the database where you want to create the user
|
||||
USE my_database;
|
||||
|
||||
-- Create the database user mapped to the login
|
||||
CREATE USER [infisical_user] FOR LOGIN [infisical_user];
|
||||
|
||||
-- Grant permissions to the user on the schema in this database
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON SCHEMA::dbo TO [infisical_user];`,
|
||||
secretsMapping: {
|
||||
username: "MSSQL_DB_USERNAME",
|
||||
password: "MSSQL_DB_PASSWORD"
|
||||
|
||||
+8
-1
@@ -7,7 +7,14 @@ export const POSTGRES_CREDENTIALS_ROTATION_LIST_OPTION: TSecretRotationV2ListIte
|
||||
type: SecretRotation.PostgresCredentials,
|
||||
connection: AppConnection.Postgres,
|
||||
template: {
|
||||
createUserStatement: `CREATE USER "my_pg_user" WITH ENCRYPTED PASSWORD 'temporary_password'; GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO "my_pg_user";`,
|
||||
createUserStatement: `-- create user role
|
||||
CREATE USER infisical_user WITH ENCRYPTED PASSWORD 'temporary_password';
|
||||
|
||||
-- grant database connection permissions
|
||||
GRANT CONNECT ON DATABASE my_database TO infisical_user;
|
||||
|
||||
-- grant relevant table permissions
|
||||
GRANT ALL PRIVILEGES ON ALL TABLES IN SCHEMA public TO infisical_user;`,
|
||||
secretsMapping: {
|
||||
username: "POSTGRES_DB_USERNAME",
|
||||
password: "POSTGRES_DB_PASSWORD"
|
||||
|
||||
@@ -1691,6 +1691,8 @@ export const AppConnections = {
|
||||
database: "The name of the database to connect to.",
|
||||
username: "The username to connect to the database with.",
|
||||
password: "The password to connect to the database with.",
|
||||
sslEnabled: "Whether or not to use SSL when connecting to the database.",
|
||||
sslRejectUnauthorized: "Whether or not to reject unauthorized SSL certificates.",
|
||||
sslCertificate: "The SSL certificate to use for connection."
|
||||
}
|
||||
}
|
||||
|
||||
@@ -59,8 +59,6 @@ const envSchema = z
|
||||
QUEUE_WORKERS_ENABLED: zodStrBool.default("true"),
|
||||
HTTPS_ENABLED: zodStrBool,
|
||||
ROTATION_DEVELOPMENT_MODE: zodStrBool.default("false").optional(),
|
||||
DB_SSL_REJECT_UNAUTHORIZED: zodStrBool.default("true"),
|
||||
DB_SSL_REQUIRED: zodStrBool.default("true"),
|
||||
// smtp options
|
||||
SMTP_HOST: zpStr(z.string().optional()),
|
||||
SMTP_IGNORE_TLS: zodStrBool.default("false"),
|
||||
|
||||
@@ -29,7 +29,9 @@ export const SanitizedMsSqlConnectionSchema = z.discriminatedUnion("method", [
|
||||
host: true,
|
||||
database: true,
|
||||
port: true,
|
||||
username: true
|
||||
username: true,
|
||||
sslEnabled: true,
|
||||
sslRejectUnauthorized: true
|
||||
})
|
||||
})
|
||||
]);
|
||||
|
||||
@@ -27,7 +27,9 @@ export const SanitizedPostgresConnectionSchema = z.discriminatedUnion("method",
|
||||
host: true,
|
||||
database: true,
|
||||
port: true,
|
||||
username: true
|
||||
username: true,
|
||||
sslEnabled: true,
|
||||
sslRejectUnauthorized: true
|
||||
})
|
||||
})
|
||||
]);
|
||||
|
||||
@@ -5,7 +5,6 @@ import {
|
||||
TSqlCredentialsRotationGeneratedCredentials,
|
||||
TSqlCredentialsRotationWithConnection
|
||||
} from "@app/ee/services/secret-rotation-v2/shared/sql-credentials/sql-credentials-rotation-types";
|
||||
import { getConfig } from "@app/lib/config/env";
|
||||
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
||||
import { alphaNumericNanoId } from "@app/lib/nanoid";
|
||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||
@@ -21,16 +20,14 @@ const SQL_CONNECTION_CLIENT_MAP = {
|
||||
|
||||
const getConnectionConfig = ({
|
||||
app,
|
||||
credentials: { sslCertificate, host }
|
||||
credentials: { host, sslCertificate, sslEnabled, sslRejectUnauthorized }
|
||||
}: Pick<TSqlConnection, "credentials" | "app">) => {
|
||||
const appCfg = getConfig();
|
||||
|
||||
switch (app) {
|
||||
case AppConnection.Postgres: {
|
||||
return {
|
||||
ssl: appCfg.DB_SSL_REQUIRED
|
||||
ssl: sslEnabled
|
||||
? {
|
||||
rejectUnauthorized: appCfg.DB_SSL_REJECT_UNAUTHORIZED,
|
||||
rejectUnauthorized: sslRejectUnauthorized,
|
||||
ca: sslCertificate,
|
||||
servername: host
|
||||
}
|
||||
@@ -39,13 +36,13 @@ const getConnectionConfig = ({
|
||||
}
|
||||
case AppConnection.MsSql: {
|
||||
return {
|
||||
options: appCfg.DB_SSL_REQUIRED
|
||||
options: sslEnabled
|
||||
? {
|
||||
trustServerCertificate: !appCfg.DB_SSL_REJECT_UNAUTHORIZED,
|
||||
trustServerCertificate: !sslRejectUnauthorized,
|
||||
encrypt: true,
|
||||
cryptoCredentialsDetails: sslCertificate ? { ca: sslCertificate } : {}
|
||||
}
|
||||
: undefined
|
||||
: { encrypt: false }
|
||||
};
|
||||
}
|
||||
default:
|
||||
|
||||
@@ -8,5 +8,12 @@ export const BaseSqlUsernameAndPasswordConnectionSchema = z.object({
|
||||
database: z.string().trim().min(1, "Database required").describe(AppConnections.CREDENTIALS.SQL_CONNECTION.database),
|
||||
username: z.string().trim().min(1, "Username required").describe(AppConnections.CREDENTIALS.SQL_CONNECTION.username),
|
||||
password: z.string().trim().min(1, "Password required").describe(AppConnections.CREDENTIALS.SQL_CONNECTION.password),
|
||||
sslCertificate: z.string().trim().optional().describe(AppConnections.CREDENTIALS.SQL_CONNECTION.sslCertificate)
|
||||
sslEnabled: z.boolean().describe(AppConnections.CREDENTIALS.SQL_CONNECTION.sslEnabled),
|
||||
sslRejectUnauthorized: z.boolean().describe(AppConnections.CREDENTIALS.SQL_CONNECTION.sslRejectUnauthorized),
|
||||
sslCertificate: z
|
||||
.string()
|
||||
.trim()
|
||||
.transform((value) => value || undefined)
|
||||
.optional()
|
||||
.describe(AppConnections.CREDENTIALS.SQL_CONNECTION.sslCertificate)
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user