python create_secrets, update_secrets and delete_secrets docs

This commit is contained in:
Aashish-Upadhyay-101
2023-03-10 22:45:58 +05:45
parent 42374a775d
commit 1090a61162
4 changed files with 236 additions and 27 deletions

View File

@@ -113,9 +113,10 @@ getSecrets();
```Python
import requests
import base64
from Cryptodome.Cipher import AES
from Cryptodome.Cipher import AES
BASE_URL = "http://app.infisical.com"
BASE_URL = "http://app.infisical.com"
def decrypt(ciphertext, iv, tag, secret):
@@ -126,20 +127,18 @@ def decrypt(ciphertext, iv, tag, secret):
cipher = AES.new(secret, AES.MODE_GCM, iv)
cipher.update(tag)
cleartext = cipher.decrypt(ciphertext).decode('utf-8')
cleartext = cipher.decrypt(ciphertext).decode("utf-8")
return cleartext
def get_secrets():
service_token = "<your_service_token>"
service_token_secret = service_token[service_token.rindex(".") + 1:]
service_token = "your_service_token"
service_token_secret = service_token[service_token.rindex(".") + 1 :]
# 1. Get your Infisical Token data
service_token_data = requests.get(
f"{BASE_URL}/api/v2/service-token",
headers={
"Authorization": f"Bearer {service_token}"
}
headers={"Authorization": f"Bearer {service_token}"},
).json()
# 2. Get secrets for your project and environment
@@ -147,21 +146,19 @@ def get_secrets():
f"{BASE_URL}/api/v2/secrets",
params={
"environment": service_token_data["environment"],
"workspaceId": service_token_data["workspace"]
"workspaceId": service_token_data["workspace"],
},
headers={
"Authorization": f"Bearer {service_token}"
}
headers={"Authorization": f"Bearer {service_token}"},
).json()
encrypted_secrets = data.get("secrets")
encrypted_secrets = data["secrets"]
# 3. Decrypt the (encrypted) project key with the key from your Infisical Token
project_key = decrypt(
ciphertext=service_token_data.get("encryptedKey"),
iv=service_token_data.get("iv"),
tag=service_token_data.get("tag"),
secret=service_token_secret
ciphertext=service_token_data["encryptedKey"],
iv=service_token_data["iv"],
tag=service_token_data["tag"],
secret=service_token_secret,
)
# 4. Decrypt the (encrypted) secrets
@@ -171,25 +168,28 @@ def get_secrets():
ciphertext=secret["secretKeyCiphertext"],
iv=secret["secretKeyIV"],
tag=secret["secretKeyTag"],
secret=project_key
secret=project_key,
)
secret_value = decrypt(
ciphertext=secret["secretValueCiphertext"],
iv=secret["secretValueIV"],
tag=secret["secretValueTag"],
secret=project_key
secret=project_key,
)
secrets.append(
{
"secret_key": secret_key,
"secret_value": secret_value,
}
)
secrets.append({
"secret_key": secret_key,
"secret_value": secret_value,
})
print("secrets:", secrets)
get_secrets()
```
</Tab>
</Tabs>