feature: windmill connection and sync
@@ -1801,6 +1801,10 @@ export const AppConnections = {
|
|||||||
CAMUNDA: {
|
CAMUNDA: {
|
||||||
clientId: "The client ID used to authenticate with Camunda.",
|
clientId: "The client ID used to authenticate with Camunda.",
|
||||||
clientSecret: "The client secret used to authenticate with Camunda."
|
clientSecret: "The client secret used to authenticate with Camunda."
|
||||||
|
},
|
||||||
|
WINDMILL: {
|
||||||
|
instanceUrl: "The Windmill instance URL to connect with (defaults to https://dev.windmill.app).",
|
||||||
|
accessToken: "The access token to use to connect with Windmill."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
@@ -1936,6 +1940,10 @@ export const SecretSyncs = {
|
|||||||
env: "The ID of the Vercel environment to sync secrets to.",
|
env: "The ID of the Vercel environment to sync secrets to.",
|
||||||
branch: "The branch to sync preview secrets to.",
|
branch: "The branch to sync preview secrets to.",
|
||||||
teamId: "The ID of the Vercel team to sync secrets to."
|
teamId: "The ID of the Vercel team to sync secrets to."
|
||||||
|
},
|
||||||
|
WINDMILL: {
|
||||||
|
workspace: "The Windmill workspace to sync secrets to.",
|
||||||
|
path: "The Windmill workspace path to sync secrets to."
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -36,6 +36,10 @@ import {
|
|||||||
TerraformCloudConnectionListItemSchema
|
TerraformCloudConnectionListItemSchema
|
||||||
} from "@app/services/app-connection/terraform-cloud";
|
} from "@app/services/app-connection/terraform-cloud";
|
||||||
import { SanitizedVercelConnectionSchema, VercelConnectionListItemSchema } from "@app/services/app-connection/vercel";
|
import { SanitizedVercelConnectionSchema, VercelConnectionListItemSchema } from "@app/services/app-connection/vercel";
|
||||||
|
import {
|
||||||
|
SanitizedWindmillConnectionSchema,
|
||||||
|
WindmillConnectionListItemSchema
|
||||||
|
} from "@app/services/app-connection/windmill";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
// can't use discriminated due to multiple schemas for certain apps
|
// can't use discriminated due to multiple schemas for certain apps
|
||||||
@@ -51,7 +55,8 @@ const SanitizedAppConnectionSchema = z.union([
|
|||||||
...SanitizedVercelConnectionSchema.options,
|
...SanitizedVercelConnectionSchema.options,
|
||||||
...SanitizedPostgresConnectionSchema.options,
|
...SanitizedPostgresConnectionSchema.options,
|
||||||
...SanitizedMsSqlConnectionSchema.options,
|
...SanitizedMsSqlConnectionSchema.options,
|
||||||
...SanitizedCamundaConnectionSchema.options
|
...SanitizedCamundaConnectionSchema.options,
|
||||||
|
...SanitizedWindmillConnectionSchema.options
|
||||||
]);
|
]);
|
||||||
|
|
||||||
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
||||||
@@ -66,7 +71,8 @@ const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
|||||||
VercelConnectionListItemSchema,
|
VercelConnectionListItemSchema,
|
||||||
PostgresConnectionListItemSchema,
|
PostgresConnectionListItemSchema,
|
||||||
MsSqlConnectionListItemSchema,
|
MsSqlConnectionListItemSchema,
|
||||||
CamundaConnectionListItemSchema
|
CamundaConnectionListItemSchema,
|
||||||
|
WindmillConnectionListItemSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import { registerMsSqlConnectionRouter } from "./mssql-connection-router";
|
|||||||
import { registerPostgresConnectionRouter } from "./postgres-connection-router";
|
import { registerPostgresConnectionRouter } from "./postgres-connection-router";
|
||||||
import { registerTerraformCloudConnectionRouter } from "./terraform-cloud-router";
|
import { registerTerraformCloudConnectionRouter } from "./terraform-cloud-router";
|
||||||
import { registerVercelConnectionRouter } from "./vercel-connection-router";
|
import { registerVercelConnectionRouter } from "./vercel-connection-router";
|
||||||
|
import { registerWindmillConnectionRouter } from "./windmill-connection-router";
|
||||||
|
|
||||||
export * from "./app-connection-router";
|
export * from "./app-connection-router";
|
||||||
|
|
||||||
@@ -28,5 +29,6 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record<AppConnection, (server:
|
|||||||
[AppConnection.Vercel]: registerVercelConnectionRouter,
|
[AppConnection.Vercel]: registerVercelConnectionRouter,
|
||||||
[AppConnection.Postgres]: registerPostgresConnectionRouter,
|
[AppConnection.Postgres]: registerPostgresConnectionRouter,
|
||||||
[AppConnection.MsSql]: registerMsSqlConnectionRouter,
|
[AppConnection.MsSql]: registerMsSqlConnectionRouter,
|
||||||
[AppConnection.Camunda]: registerCamundaConnectionRouter
|
[AppConnection.Camunda]: registerCamundaConnectionRouter,
|
||||||
|
[AppConnection.Windmill]: registerWindmillConnectionRouter
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,53 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { readLimit } from "@app/server/config/rateLimiter";
|
||||||
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import {
|
||||||
|
CreateWindmillConnectionSchema,
|
||||||
|
SanitizedWindmillConnectionSchema,
|
||||||
|
UpdateWindmillConnectionSchema
|
||||||
|
} from "@app/services/app-connection/windmill";
|
||||||
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
|
import { registerAppConnectionEndpoints } from "./app-connection-endpoints";
|
||||||
|
|
||||||
|
export const registerWindmillConnectionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
registerAppConnectionEndpoints({
|
||||||
|
app: AppConnection.Windmill,
|
||||||
|
server,
|
||||||
|
sanitizedResponseSchema: SanitizedWindmillConnectionSchema,
|
||||||
|
createSchema: CreateWindmillConnectionSchema,
|
||||||
|
updateSchema: UpdateWindmillConnectionSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
// The below endpoints are not exposed and for Infisical App use
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: `/:connectionId/workspaces`,
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
params: z.object({
|
||||||
|
connectionId: z.string().uuid()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z
|
||||||
|
.object({
|
||||||
|
id: z.string(),
|
||||||
|
name: z.string()
|
||||||
|
})
|
||||||
|
.array()
|
||||||
|
}
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT]),
|
||||||
|
handler: async (req) => {
|
||||||
|
const { connectionId } = req.params;
|
||||||
|
|
||||||
|
const workspaces = await server.services.appConnection.windmill.listWorkspaces(connectionId, req.permission);
|
||||||
|
|
||||||
|
return workspaces;
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -11,6 +11,7 @@ import { registerGitHubSyncRouter } from "./github-sync-router";
|
|||||||
import { registerHumanitecSyncRouter } from "./humanitec-sync-router";
|
import { registerHumanitecSyncRouter } from "./humanitec-sync-router";
|
||||||
import { registerTerraformCloudSyncRouter } from "./terraform-cloud-sync-router";
|
import { registerTerraformCloudSyncRouter } from "./terraform-cloud-sync-router";
|
||||||
import { registerVercelSyncRouter } from "./vercel-sync-router";
|
import { registerVercelSyncRouter } from "./vercel-sync-router";
|
||||||
|
import { registerWindmillSyncRouter } from "./windmill-sync-router";
|
||||||
|
|
||||||
export * from "./secret-sync-router";
|
export * from "./secret-sync-router";
|
||||||
|
|
||||||
@@ -25,5 +26,6 @@ export const SECRET_SYNC_REGISTER_ROUTER_MAP: Record<SecretSync, (server: Fastif
|
|||||||
[SecretSync.Humanitec]: registerHumanitecSyncRouter,
|
[SecretSync.Humanitec]: registerHumanitecSyncRouter,
|
||||||
[SecretSync.TerraformCloud]: registerTerraformCloudSyncRouter,
|
[SecretSync.TerraformCloud]: registerTerraformCloudSyncRouter,
|
||||||
[SecretSync.Camunda]: registerCamundaSyncRouter,
|
[SecretSync.Camunda]: registerCamundaSyncRouter,
|
||||||
[SecretSync.Vercel]: registerVercelSyncRouter
|
[SecretSync.Vercel]: registerVercelSyncRouter,
|
||||||
|
[SecretSync.Windmill]: registerWindmillSyncRouter
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ import { GitHubSyncListItemSchema, GitHubSyncSchema } from "@app/services/secret
|
|||||||
import { HumanitecSyncListItemSchema, HumanitecSyncSchema } from "@app/services/secret-sync/humanitec";
|
import { HumanitecSyncListItemSchema, HumanitecSyncSchema } from "@app/services/secret-sync/humanitec";
|
||||||
import { TerraformCloudSyncListItemSchema, TerraformCloudSyncSchema } from "@app/services/secret-sync/terraform-cloud";
|
import { TerraformCloudSyncListItemSchema, TerraformCloudSyncSchema } from "@app/services/secret-sync/terraform-cloud";
|
||||||
import { VercelSyncListItemSchema, VercelSyncSchema } from "@app/services/secret-sync/vercel";
|
import { VercelSyncListItemSchema, VercelSyncSchema } from "@app/services/secret-sync/vercel";
|
||||||
|
import { WindmillSyncListItemSchema, WindmillSyncSchema } from "@app/services/secret-sync/windmill";
|
||||||
|
|
||||||
const SecretSyncSchema = z.discriminatedUnion("destination", [
|
const SecretSyncSchema = z.discriminatedUnion("destination", [
|
||||||
AwsParameterStoreSyncSchema,
|
AwsParameterStoreSyncSchema,
|
||||||
@@ -37,7 +38,8 @@ const SecretSyncSchema = z.discriminatedUnion("destination", [
|
|||||||
HumanitecSyncSchema,
|
HumanitecSyncSchema,
|
||||||
TerraformCloudSyncSchema,
|
TerraformCloudSyncSchema,
|
||||||
CamundaSyncSchema,
|
CamundaSyncSchema,
|
||||||
VercelSyncSchema
|
VercelSyncSchema,
|
||||||
|
WindmillSyncSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
||||||
@@ -51,7 +53,8 @@ const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
|||||||
HumanitecSyncListItemSchema,
|
HumanitecSyncListItemSchema,
|
||||||
TerraformCloudSyncListItemSchema,
|
TerraformCloudSyncListItemSchema,
|
||||||
CamundaSyncListItemSchema,
|
CamundaSyncListItemSchema,
|
||||||
VercelSyncListItemSchema
|
VercelSyncListItemSchema,
|
||||||
|
WindmillSyncListItemSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerSecretSyncRouter = async (server: FastifyZodProvider) => {
|
export const registerSecretSyncRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -0,0 +1,17 @@
|
|||||||
|
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
import {
|
||||||
|
CreateWindmillSyncSchema,
|
||||||
|
UpdateWindmillSyncSchema,
|
||||||
|
WindmillSyncSchema
|
||||||
|
} from "@app/services/secret-sync/windmill";
|
||||||
|
|
||||||
|
import { registerSyncSecretsEndpoints } from "./secret-sync-endpoints";
|
||||||
|
|
||||||
|
export const registerWindmillSyncRouter = async (server: FastifyZodProvider) =>
|
||||||
|
registerSyncSecretsEndpoints({
|
||||||
|
destination: SecretSync.Windmill,
|
||||||
|
server,
|
||||||
|
responseSchema: WindmillSyncSchema,
|
||||||
|
createSchema: CreateWindmillSyncSchema,
|
||||||
|
updateSchema: UpdateWindmillSyncSchema
|
||||||
|
});
|
||||||
@@ -10,7 +10,8 @@ export enum AppConnection {
|
|||||||
Vercel = "vercel",
|
Vercel = "vercel",
|
||||||
Postgres = "postgres",
|
Postgres = "postgres",
|
||||||
MsSql = "mssql",
|
MsSql = "mssql",
|
||||||
Camunda = "camunda"
|
Camunda = "camunda",
|
||||||
|
Windmill = "windmill"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum AWSRegion {
|
export enum AWSRegion {
|
||||||
|
|||||||
@@ -49,6 +49,11 @@ import {
|
|||||||
} from "./terraform-cloud";
|
} from "./terraform-cloud";
|
||||||
import { VercelConnectionMethod } from "./vercel";
|
import { VercelConnectionMethod } from "./vercel";
|
||||||
import { getVercelConnectionListItem, validateVercelConnectionCredentials } from "./vercel/vercel-connection-fns";
|
import { getVercelConnectionListItem, validateVercelConnectionCredentials } from "./vercel/vercel-connection-fns";
|
||||||
|
import {
|
||||||
|
getWindmillConnectionListItem,
|
||||||
|
validateWindmillConnectionCredentials,
|
||||||
|
WindmillConnectionMethod
|
||||||
|
} from "./windmill";
|
||||||
|
|
||||||
export const listAppConnectionOptions = () => {
|
export const listAppConnectionOptions = () => {
|
||||||
return [
|
return [
|
||||||
@@ -63,7 +68,8 @@ export const listAppConnectionOptions = () => {
|
|||||||
getVercelConnectionListItem(),
|
getVercelConnectionListItem(),
|
||||||
getPostgresConnectionListItem(),
|
getPostgresConnectionListItem(),
|
||||||
getMsSqlConnectionListItem(),
|
getMsSqlConnectionListItem(),
|
||||||
getCamundaConnectionListItem()
|
getCamundaConnectionListItem(),
|
||||||
|
getWindmillConnectionListItem()
|
||||||
].sort((a, b) => a.name.localeCompare(b.name));
|
].sort((a, b) => a.name.localeCompare(b.name));
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -122,7 +128,8 @@ const VALIDATE_APP_CONNECTION_CREDENTIALS_MAP: Record<AppConnection, TAppConnect
|
|||||||
[AppConnection.MsSql]: validateSqlConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.MsSql]: validateSqlConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.TerraformCloud]: validateTerraformCloudConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.TerraformCloud]: validateTerraformCloudConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Camunda]: validateCamundaConnectionCredentials as TAppConnectionCredentialsValidator,
|
[AppConnection.Camunda]: validateCamundaConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
[AppConnection.Vercel]: validateVercelConnectionCredentials as TAppConnectionCredentialsValidator
|
[AppConnection.Vercel]: validateVercelConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||||
|
[AppConnection.Windmill]: validateWindmillConnectionCredentials as TAppConnectionCredentialsValidator
|
||||||
};
|
};
|
||||||
|
|
||||||
export const validateAppConnectionCredentials = async (
|
export const validateAppConnectionCredentials = async (
|
||||||
@@ -154,6 +161,8 @@ export const getAppConnectionMethodName = (method: TAppConnection["method"]) =>
|
|||||||
case PostgresConnectionMethod.UsernameAndPassword:
|
case PostgresConnectionMethod.UsernameAndPassword:
|
||||||
case MsSqlConnectionMethod.UsernameAndPassword:
|
case MsSqlConnectionMethod.UsernameAndPassword:
|
||||||
return "Username & Password";
|
return "Username & Password";
|
||||||
|
case WindmillConnectionMethod.AccessToken:
|
||||||
|
return "Access Token";
|
||||||
default:
|
default:
|
||||||
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions
|
// eslint-disable-next-line @typescript-eslint/restrict-template-expressions
|
||||||
throw new Error(`Unhandled App Connection Method: ${method}`);
|
throw new Error(`Unhandled App Connection Method: ${method}`);
|
||||||
@@ -196,5 +205,6 @@ export const TRANSITION_CONNECTION_CREDENTIALS_TO_PLATFORM: Record<
|
|||||||
[AppConnection.MsSql]: transferSqlConnectionCredentialsToPlatform as TAppConnectionTransitionCredentialsToPlatform,
|
[AppConnection.MsSql]: transferSqlConnectionCredentialsToPlatform as TAppConnectionTransitionCredentialsToPlatform,
|
||||||
[AppConnection.TerraformCloud]: platformManagedCredentialsNotSupported,
|
[AppConnection.TerraformCloud]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Camunda]: platformManagedCredentialsNotSupported,
|
[AppConnection.Camunda]: platformManagedCredentialsNotSupported,
|
||||||
[AppConnection.Vercel]: platformManagedCredentialsNotSupported
|
[AppConnection.Vercel]: platformManagedCredentialsNotSupported,
|
||||||
|
[AppConnection.Windmill]: platformManagedCredentialsNotSupported
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -12,5 +12,6 @@ export const APP_CONNECTION_NAME_MAP: Record<AppConnection, string> = {
|
|||||||
[AppConnection.Vercel]: "Vercel",
|
[AppConnection.Vercel]: "Vercel",
|
||||||
[AppConnection.Postgres]: "PostgreSQL",
|
[AppConnection.Postgres]: "PostgreSQL",
|
||||||
[AppConnection.MsSql]: "Microsoft SQL Server",
|
[AppConnection.MsSql]: "Microsoft SQL Server",
|
||||||
[AppConnection.Camunda]: "Camunda"
|
[AppConnection.Camunda]: "Camunda",
|
||||||
|
[AppConnection.Windmill]: "Windmill"
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -47,6 +47,8 @@ import { ValidateTerraformCloudConnectionCredentialsSchema } from "./terraform-c
|
|||||||
import { terraformCloudConnectionService } from "./terraform-cloud/terraform-cloud-connection-service";
|
import { terraformCloudConnectionService } from "./terraform-cloud/terraform-cloud-connection-service";
|
||||||
import { ValidateVercelConnectionCredentialsSchema } from "./vercel";
|
import { ValidateVercelConnectionCredentialsSchema } from "./vercel";
|
||||||
import { vercelConnectionService } from "./vercel/vercel-connection-service";
|
import { vercelConnectionService } from "./vercel/vercel-connection-service";
|
||||||
|
import { ValidateWindmillConnectionCredentialsSchema } from "./windmill";
|
||||||
|
import { windmillConnectionService } from "./windmill/windmill-connection-service";
|
||||||
|
|
||||||
export type TAppConnectionServiceFactoryDep = {
|
export type TAppConnectionServiceFactoryDep = {
|
||||||
appConnectionDAL: TAppConnectionDALFactory;
|
appConnectionDAL: TAppConnectionDALFactory;
|
||||||
@@ -68,7 +70,8 @@ const VALIDATE_APP_CONNECTION_CREDENTIALS_MAP: Record<AppConnection, TValidateAp
|
|||||||
[AppConnection.Vercel]: ValidateVercelConnectionCredentialsSchema,
|
[AppConnection.Vercel]: ValidateVercelConnectionCredentialsSchema,
|
||||||
[AppConnection.Postgres]: ValidatePostgresConnectionCredentialsSchema,
|
[AppConnection.Postgres]: ValidatePostgresConnectionCredentialsSchema,
|
||||||
[AppConnection.MsSql]: ValidateMsSqlConnectionCredentialsSchema,
|
[AppConnection.MsSql]: ValidateMsSqlConnectionCredentialsSchema,
|
||||||
[AppConnection.Camunda]: ValidateCamundaConnectionCredentialsSchema
|
[AppConnection.Camunda]: ValidateCamundaConnectionCredentialsSchema,
|
||||||
|
[AppConnection.Windmill]: ValidateWindmillConnectionCredentialsSchema
|
||||||
};
|
};
|
||||||
|
|
||||||
export const appConnectionServiceFactory = ({
|
export const appConnectionServiceFactory = ({
|
||||||
@@ -442,6 +445,7 @@ export const appConnectionServiceFactory = ({
|
|||||||
humanitec: humanitecConnectionService(connectAppConnectionById),
|
humanitec: humanitecConnectionService(connectAppConnectionById),
|
||||||
terraformCloud: terraformCloudConnectionService(connectAppConnectionById),
|
terraformCloud: terraformCloudConnectionService(connectAppConnectionById),
|
||||||
camunda: camundaConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
camunda: camundaConnectionService(connectAppConnectionById, appConnectionDAL, kmsService),
|
||||||
vercel: vercelConnectionService(connectAppConnectionById)
|
vercel: vercelConnectionService(connectAppConnectionById),
|
||||||
|
windmill: windmillConnectionService(connectAppConnectionById)
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -69,6 +69,12 @@ import {
|
|||||||
TVercelConnectionConfig,
|
TVercelConnectionConfig,
|
||||||
TVercelConnectionInput
|
TVercelConnectionInput
|
||||||
} from "./vercel";
|
} from "./vercel";
|
||||||
|
import {
|
||||||
|
TValidateWindmillConnectionCredentialsSchema,
|
||||||
|
TWindmillConnection,
|
||||||
|
TWindmillConnectionConfig,
|
||||||
|
TWindmillConnectionInput
|
||||||
|
} from "./windmill";
|
||||||
|
|
||||||
export type TAppConnection = { id: string } & (
|
export type TAppConnection = { id: string } & (
|
||||||
| TAwsConnection
|
| TAwsConnection
|
||||||
@@ -83,6 +89,7 @@ export type TAppConnection = { id: string } & (
|
|||||||
| TPostgresConnection
|
| TPostgresConnection
|
||||||
| TMsSqlConnection
|
| TMsSqlConnection
|
||||||
| TCamundaConnection
|
| TCamundaConnection
|
||||||
|
| TWindmillConnection
|
||||||
);
|
);
|
||||||
|
|
||||||
export type TAppConnectionRaw = NonNullable<Awaited<ReturnType<TAppConnectionDALFactory["findById"]>>>;
|
export type TAppConnectionRaw = NonNullable<Awaited<ReturnType<TAppConnectionDALFactory["findById"]>>>;
|
||||||
@@ -102,6 +109,7 @@ export type TAppConnectionInput = { id: string } & (
|
|||||||
| TPostgresConnectionInput
|
| TPostgresConnectionInput
|
||||||
| TMsSqlConnectionInput
|
| TMsSqlConnectionInput
|
||||||
| TCamundaConnectionInput
|
| TCamundaConnectionInput
|
||||||
|
| TWindmillConnectionInput
|
||||||
);
|
);
|
||||||
|
|
||||||
export type TSqlConnectionInput = TPostgresConnectionInput | TMsSqlConnectionInput;
|
export type TSqlConnectionInput = TPostgresConnectionInput | TMsSqlConnectionInput;
|
||||||
@@ -126,7 +134,8 @@ export type TAppConnectionConfig =
|
|||||||
| TTerraformCloudConnectionConfig
|
| TTerraformCloudConnectionConfig
|
||||||
| TVercelConnectionConfig
|
| TVercelConnectionConfig
|
||||||
| TSqlConnectionConfig
|
| TSqlConnectionConfig
|
||||||
| TCamundaConnectionConfig;
|
| TCamundaConnectionConfig
|
||||||
|
| TWindmillConnectionConfig;
|
||||||
|
|
||||||
export type TValidateAppConnectionCredentialsSchema =
|
export type TValidateAppConnectionCredentialsSchema =
|
||||||
| TValidateAwsConnectionCredentialsSchema
|
| TValidateAwsConnectionCredentialsSchema
|
||||||
@@ -140,7 +149,8 @@ export type TValidateAppConnectionCredentialsSchema =
|
|||||||
| TValidateMsSqlConnectionCredentialsSchema
|
| TValidateMsSqlConnectionCredentialsSchema
|
||||||
| TValidateCamundaConnectionCredentialsSchema
|
| TValidateCamundaConnectionCredentialsSchema
|
||||||
| TValidateTerraformCloudConnectionCredentialsSchema
|
| TValidateTerraformCloudConnectionCredentialsSchema
|
||||||
| TValidateVercelConnectionCredentialsSchema;
|
| TValidateVercelConnectionCredentialsSchema
|
||||||
|
| TValidateWindmillConnectionCredentialsSchema;
|
||||||
|
|
||||||
export type TListAwsConnectionKmsKeys = {
|
export type TListAwsConnectionKmsKeys = {
|
||||||
connectionId: string;
|
connectionId: string;
|
||||||
|
|||||||
@@ -44,7 +44,7 @@ export const validateTerraformCloudConnectionCredentials = async (config: TTerra
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Unable to validate connection - verify credentials"
|
message: "Unable to validate connection: verify credentials"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -42,7 +42,7 @@ export const validateVercelConnectionCredentials = async (config: TVercelConnect
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: "Unable to validate connection - verify credentials"
|
message: "Unable to validate connection: verify credentials"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export * from "./windmill-connection-enums";
|
||||||
|
export * from "./windmill-connection-fns";
|
||||||
|
export * from "./windmill-connection-schemas";
|
||||||
|
export * from "./windmill-connection-types";
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
export enum WindmillConnectionMethod {
|
||||||
|
AccessToken = "access-token"
|
||||||
|
}
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
import { AxiosError } from "axios";
|
||||||
|
|
||||||
|
import { request } from "@app/lib/config/request";
|
||||||
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
|
import { removeTrailingSlash } from "@app/lib/fn";
|
||||||
|
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
|
||||||
|
import { WindmillConnectionMethod } from "./windmill-connection-enums";
|
||||||
|
import { TWindmillConnection, TWindmillConnectionConfig, TWindmillWorkspace } from "./windmill-connection-types";
|
||||||
|
|
||||||
|
export const getWindmillInstanceUrl = async (config: TWindmillConnectionConfig) => {
|
||||||
|
const instanceUrl = config.credentials.instanceUrl
|
||||||
|
? removeTrailingSlash(config.credentials.instanceUrl)
|
||||||
|
: "https://app.windmill.dev";
|
||||||
|
|
||||||
|
await blockLocalAndPrivateIpAddresses(instanceUrl);
|
||||||
|
|
||||||
|
return instanceUrl;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const getWindmillConnectionListItem = () => {
|
||||||
|
return {
|
||||||
|
name: "Windmill" as const,
|
||||||
|
app: AppConnection.Windmill as const,
|
||||||
|
methods: Object.values(WindmillConnectionMethod) as [WindmillConnectionMethod.AccessToken]
|
||||||
|
};
|
||||||
|
};
|
||||||
|
|
||||||
|
export const validateWindmillConnectionCredentials = async (config: TWindmillConnectionConfig) => {
|
||||||
|
const instanceUrl = await getWindmillInstanceUrl(config);
|
||||||
|
const { accessToken } = config.credentials;
|
||||||
|
|
||||||
|
try {
|
||||||
|
await request.get(`${instanceUrl}/api/workspaces/list`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`
|
||||||
|
}
|
||||||
|
});
|
||||||
|
} catch (error: unknown) {
|
||||||
|
if (error instanceof AxiosError) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Failed to validate credentials: ${error.message || "Unknown error"}`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Unable to validate connection: verify credentials"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return config.credentials;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const listWindmillWorkspaces = async (appConnection: TWindmillConnection) => {
|
||||||
|
const instanceUrl = await getWindmillInstanceUrl(appConnection);
|
||||||
|
const { accessToken } = appConnection.credentials;
|
||||||
|
|
||||||
|
const resp = await request.get<TWindmillWorkspace[]>(`${instanceUrl}/api/workspaces/list`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return resp.data.filter((workspace) => !workspace.deleted);
|
||||||
|
};
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { AppConnections } from "@app/lib/api-docs";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import {
|
||||||
|
BaseAppConnectionSchema,
|
||||||
|
GenericCreateAppConnectionFieldsSchema,
|
||||||
|
GenericUpdateAppConnectionFieldsSchema
|
||||||
|
} from "@app/services/app-connection/app-connection-schemas";
|
||||||
|
|
||||||
|
import { WindmillConnectionMethod } from "./windmill-connection-enums";
|
||||||
|
|
||||||
|
export const WindmillConnectionAccessTokenCredentialsSchema = z.object({
|
||||||
|
accessToken: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Access Token required")
|
||||||
|
.describe(AppConnections.CREDENTIALS.WINDMILL.accessToken),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.url("Invalid Instance URL")
|
||||||
|
.optional()
|
||||||
|
.describe(AppConnections.CREDENTIALS.WINDMILL.instanceUrl)
|
||||||
|
});
|
||||||
|
|
||||||
|
const BaseWindmillConnectionSchema = BaseAppConnectionSchema.extend({ app: z.literal(AppConnection.Windmill) });
|
||||||
|
|
||||||
|
export const WindmillConnectionSchema = BaseWindmillConnectionSchema.extend({
|
||||||
|
method: z.literal(WindmillConnectionMethod.AccessToken),
|
||||||
|
credentials: WindmillConnectionAccessTokenCredentialsSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const SanitizedWindmillConnectionSchema = z.discriminatedUnion("method", [
|
||||||
|
BaseWindmillConnectionSchema.extend({
|
||||||
|
method: z.literal(WindmillConnectionMethod.AccessToken),
|
||||||
|
credentials: WindmillConnectionAccessTokenCredentialsSchema.pick({
|
||||||
|
instanceUrl: true
|
||||||
|
})
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
export const ValidateWindmillConnectionCredentialsSchema = z.discriminatedUnion("method", [
|
||||||
|
z.object({
|
||||||
|
method: z
|
||||||
|
.literal(WindmillConnectionMethod.AccessToken)
|
||||||
|
.describe(AppConnections?.CREATE(AppConnection.Windmill).method),
|
||||||
|
credentials: WindmillConnectionAccessTokenCredentialsSchema.describe(
|
||||||
|
AppConnections.CREATE(AppConnection.Windmill).credentials
|
||||||
|
)
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
export const CreateWindmillConnectionSchema = ValidateWindmillConnectionCredentialsSchema.and(
|
||||||
|
GenericCreateAppConnectionFieldsSchema(AppConnection.Windmill)
|
||||||
|
);
|
||||||
|
|
||||||
|
export const UpdateWindmillConnectionSchema = z
|
||||||
|
.object({
|
||||||
|
credentials: WindmillConnectionAccessTokenCredentialsSchema.optional().describe(
|
||||||
|
AppConnections.UPDATE(AppConnection.Windmill).credentials
|
||||||
|
)
|
||||||
|
})
|
||||||
|
.and(GenericUpdateAppConnectionFieldsSchema(AppConnection.Windmill));
|
||||||
|
|
||||||
|
export const WindmillConnectionListItemSchema = z.object({
|
||||||
|
name: z.literal("Windmill"),
|
||||||
|
app: z.literal(AppConnection.Windmill),
|
||||||
|
methods: z.nativeEnum(WindmillConnectionMethod).array()
|
||||||
|
});
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
import { OrgServiceActor } from "@app/lib/types";
|
||||||
|
|
||||||
|
import { AppConnection } from "../app-connection-enums";
|
||||||
|
import { listWindmillWorkspaces } from "./windmill-connection-fns";
|
||||||
|
import { TWindmillConnection } from "./windmill-connection-types";
|
||||||
|
|
||||||
|
type TGetAppConnectionFunc = (
|
||||||
|
app: AppConnection,
|
||||||
|
connectionId: string,
|
||||||
|
actor: OrgServiceActor
|
||||||
|
) => Promise<TWindmillConnection>;
|
||||||
|
|
||||||
|
export const windmillConnectionService = (getAppConnection: TGetAppConnectionFunc) => {
|
||||||
|
const listWorkspaces = async (connectionId: string, actor: OrgServiceActor) => {
|
||||||
|
const appConnection = await getAppConnection(AppConnection.Windmill, connectionId, actor);
|
||||||
|
|
||||||
|
try {
|
||||||
|
const workspaces = await listWindmillWorkspaces(appConnection);
|
||||||
|
return workspaces;
|
||||||
|
} catch (error) {
|
||||||
|
return [];
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
return {
|
||||||
|
listWorkspaces
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,27 @@
|
|||||||
|
import z from "zod";
|
||||||
|
|
||||||
|
import { DiscriminativePick } from "@app/lib/types";
|
||||||
|
|
||||||
|
import { AppConnection } from "../app-connection-enums";
|
||||||
|
import {
|
||||||
|
CreateWindmillConnectionSchema,
|
||||||
|
ValidateWindmillConnectionCredentialsSchema,
|
||||||
|
WindmillConnectionSchema
|
||||||
|
} from "./windmill-connection-schemas";
|
||||||
|
|
||||||
|
export type TWindmillConnection = z.infer<typeof WindmillConnectionSchema>;
|
||||||
|
|
||||||
|
export type TWindmillConnectionInput = z.infer<typeof CreateWindmillConnectionSchema> & {
|
||||||
|
app: AppConnection.Windmill;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TValidateWindmillConnectionCredentialsSchema = typeof ValidateWindmillConnectionCredentialsSchema;
|
||||||
|
|
||||||
|
export type TWindmillConnectionConfig = DiscriminativePick<
|
||||||
|
TWindmillConnectionInput,
|
||||||
|
"method" | "app" | "credentials"
|
||||||
|
> & {
|
||||||
|
orgId: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TWindmillWorkspace = { id: string; name: string; deleted: boolean };
|
||||||
@@ -9,7 +9,8 @@ export enum SecretSync {
|
|||||||
Humanitec = "humanitec",
|
Humanitec = "humanitec",
|
||||||
TerraformCloud = "terraform-cloud",
|
TerraformCloud = "terraform-cloud",
|
||||||
Camunda = "camunda",
|
Camunda = "camunda",
|
||||||
Vercel = "vercel"
|
Vercel = "vercel",
|
||||||
|
Windmill = "windmill"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum SecretSyncInitialSyncBehavior {
|
export enum SecretSyncInitialSyncBehavior {
|
||||||
|
|||||||
@@ -29,6 +29,7 @@ import { HUMANITEC_SYNC_LIST_OPTION } from "./humanitec";
|
|||||||
import { HumanitecSyncFns } from "./humanitec/humanitec-sync-fns";
|
import { HumanitecSyncFns } from "./humanitec/humanitec-sync-fns";
|
||||||
import { TERRAFORM_CLOUD_SYNC_LIST_OPTION, TerraformCloudSyncFns } from "./terraform-cloud";
|
import { TERRAFORM_CLOUD_SYNC_LIST_OPTION, TerraformCloudSyncFns } from "./terraform-cloud";
|
||||||
import { VERCEL_SYNC_LIST_OPTION, VercelSyncFns } from "./vercel";
|
import { VERCEL_SYNC_LIST_OPTION, VercelSyncFns } from "./vercel";
|
||||||
|
import { WINDMILL_SYNC_LIST_OPTION, WindmillSyncFns } from "./windmill";
|
||||||
|
|
||||||
const SECRET_SYNC_LIST_OPTIONS: Record<SecretSync, TSecretSyncListItem> = {
|
const SECRET_SYNC_LIST_OPTIONS: Record<SecretSync, TSecretSyncListItem> = {
|
||||||
[SecretSync.AWSParameterStore]: AWS_PARAMETER_STORE_SYNC_LIST_OPTION,
|
[SecretSync.AWSParameterStore]: AWS_PARAMETER_STORE_SYNC_LIST_OPTION,
|
||||||
@@ -41,7 +42,8 @@ const SECRET_SYNC_LIST_OPTIONS: Record<SecretSync, TSecretSyncListItem> = {
|
|||||||
[SecretSync.Humanitec]: HUMANITEC_SYNC_LIST_OPTION,
|
[SecretSync.Humanitec]: HUMANITEC_SYNC_LIST_OPTION,
|
||||||
[SecretSync.TerraformCloud]: TERRAFORM_CLOUD_SYNC_LIST_OPTION,
|
[SecretSync.TerraformCloud]: TERRAFORM_CLOUD_SYNC_LIST_OPTION,
|
||||||
[SecretSync.Camunda]: CAMUNDA_SYNC_LIST_OPTION,
|
[SecretSync.Camunda]: CAMUNDA_SYNC_LIST_OPTION,
|
||||||
[SecretSync.Vercel]: VERCEL_SYNC_LIST_OPTION
|
[SecretSync.Vercel]: VERCEL_SYNC_LIST_OPTION,
|
||||||
|
[SecretSync.Windmill]: WINDMILL_SYNC_LIST_OPTION
|
||||||
};
|
};
|
||||||
|
|
||||||
export const listSecretSyncOptions = () => {
|
export const listSecretSyncOptions = () => {
|
||||||
@@ -136,6 +138,8 @@ export const SecretSyncFns = {
|
|||||||
}).syncSecrets(secretSync, secretMap);
|
}).syncSecrets(secretSync, secretMap);
|
||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
return VercelSyncFns.syncSecrets(secretSync, secretMap);
|
return VercelSyncFns.syncSecrets(secretSync, secretMap);
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
return WindmillSyncFns.syncSecrets(secretSync, secretMap);
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled sync destination for sync secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
`Unhandled sync destination for sync secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||||
@@ -192,6 +196,9 @@ export const SecretSyncFns = {
|
|||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
secretMap = await VercelSyncFns.getSecrets(secretSync);
|
secretMap = await VercelSyncFns.getSecrets(secretSync);
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
secretMap = await WindmillSyncFns.getSecrets(secretSync);
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled sync destination for get secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
`Unhandled sync destination for get secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||||
@@ -243,6 +250,8 @@ export const SecretSyncFns = {
|
|||||||
}).removeSecrets(secretSync, secretMap);
|
}).removeSecrets(secretSync, secretMap);
|
||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
return VercelSyncFns.removeSecrets(secretSync, secretMap);
|
return VercelSyncFns.removeSecrets(secretSync, secretMap);
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
return WindmillSyncFns.removeSecrets(secretSync, secretMap);
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled sync destination for remove secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
`Unhandled sync destination for remove secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||||
|
|||||||
@@ -12,7 +12,8 @@ export const SECRET_SYNC_NAME_MAP: Record<SecretSync, string> = {
|
|||||||
[SecretSync.Humanitec]: "Humanitec",
|
[SecretSync.Humanitec]: "Humanitec",
|
||||||
[SecretSync.TerraformCloud]: "Terraform Cloud",
|
[SecretSync.TerraformCloud]: "Terraform Cloud",
|
||||||
[SecretSync.Camunda]: "Camunda",
|
[SecretSync.Camunda]: "Camunda",
|
||||||
[SecretSync.Vercel]: "Vercel"
|
[SecretSync.Vercel]: "Vercel",
|
||||||
|
[SecretSync.Windmill]: "Windmill"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
||||||
@@ -26,5 +27,6 @@ export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
|||||||
[SecretSync.Humanitec]: AppConnection.Humanitec,
|
[SecretSync.Humanitec]: AppConnection.Humanitec,
|
||||||
[SecretSync.TerraformCloud]: AppConnection.TerraformCloud,
|
[SecretSync.TerraformCloud]: AppConnection.TerraformCloud,
|
||||||
[SecretSync.Camunda]: AppConnection.Camunda,
|
[SecretSync.Camunda]: AppConnection.Camunda,
|
||||||
[SecretSync.Vercel]: AppConnection.Vercel
|
[SecretSync.Vercel]: AppConnection.Vercel,
|
||||||
|
[SecretSync.Windmill]: AppConnection.Windmill
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -76,6 +76,7 @@ type TSecretSyncQueueFactoryDep = {
|
|||||||
| "findBySecretKeys"
|
| "findBySecretKeys"
|
||||||
| "bulkUpdate"
|
| "bulkUpdate"
|
||||||
| "deleteMany"
|
| "deleteMany"
|
||||||
|
| "invalidateSecretCacheByProjectId"
|
||||||
>;
|
>;
|
||||||
secretImportDAL: Pick<TSecretImportDALFactory, "find" | "findByFolderIds">;
|
secretImportDAL: Pick<TSecretImportDALFactory, "find" | "findByFolderIds">;
|
||||||
secretSyncDAL: Pick<TSecretSyncDALFactory, "findById" | "find" | "updateById" | "deleteById">;
|
secretSyncDAL: Pick<TSecretSyncDALFactory, "findById" | "find" | "updateById" | "deleteById">;
|
||||||
@@ -382,6 +383,9 @@ export const secretSyncQueueFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (secretsToUpdate.length || secretsToCreate.length)
|
||||||
|
await secretV2BridgeDAL.invalidateSecretCacheByProjectId(projectId);
|
||||||
|
|
||||||
return importedSecretMap;
|
return importedSecretMap;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -29,6 +29,12 @@ import {
|
|||||||
} from "@app/services/secret-sync/github";
|
} from "@app/services/secret-sync/github";
|
||||||
import { TSecretSyncDALFactory } from "@app/services/secret-sync/secret-sync-dal";
|
import { TSecretSyncDALFactory } from "@app/services/secret-sync/secret-sync-dal";
|
||||||
import { SecretSync, SecretSyncImportBehavior } from "@app/services/secret-sync/secret-sync-enums";
|
import { SecretSync, SecretSyncImportBehavior } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
import {
|
||||||
|
TWindmillSync,
|
||||||
|
TWindmillSyncInput,
|
||||||
|
TWindmillSyncListItem,
|
||||||
|
TWindmillSyncWithCredentials
|
||||||
|
} from "@app/services/secret-sync/windmill";
|
||||||
|
|
||||||
import {
|
import {
|
||||||
TAwsParameterStoreSync,
|
TAwsParameterStoreSync,
|
||||||
@@ -74,7 +80,8 @@ export type TSecretSync =
|
|||||||
| THumanitecSync
|
| THumanitecSync
|
||||||
| TTerraformCloudSync
|
| TTerraformCloudSync
|
||||||
| TCamundaSync
|
| TCamundaSync
|
||||||
| TVercelSync;
|
| TVercelSync
|
||||||
|
| TWindmillSync;
|
||||||
|
|
||||||
export type TSecretSyncWithCredentials =
|
export type TSecretSyncWithCredentials =
|
||||||
| TAwsParameterStoreSyncWithCredentials
|
| TAwsParameterStoreSyncWithCredentials
|
||||||
@@ -87,7 +94,8 @@ export type TSecretSyncWithCredentials =
|
|||||||
| THumanitecSyncWithCredentials
|
| THumanitecSyncWithCredentials
|
||||||
| TTerraformCloudSyncWithCredentials
|
| TTerraformCloudSyncWithCredentials
|
||||||
| TCamundaSyncWithCredentials
|
| TCamundaSyncWithCredentials
|
||||||
| TVercelSyncWithCredentials;
|
| TVercelSyncWithCredentials
|
||||||
|
| TWindmillSyncWithCredentials;
|
||||||
|
|
||||||
export type TSecretSyncInput =
|
export type TSecretSyncInput =
|
||||||
| TAwsParameterStoreSyncInput
|
| TAwsParameterStoreSyncInput
|
||||||
@@ -100,7 +108,8 @@ export type TSecretSyncInput =
|
|||||||
| THumanitecSyncInput
|
| THumanitecSyncInput
|
||||||
| TTerraformCloudSyncInput
|
| TTerraformCloudSyncInput
|
||||||
| TCamundaSyncInput
|
| TCamundaSyncInput
|
||||||
| TVercelSyncInput;
|
| TVercelSyncInput
|
||||||
|
| TWindmillSyncInput;
|
||||||
|
|
||||||
export type TSecretSyncListItem =
|
export type TSecretSyncListItem =
|
||||||
| TAwsParameterStoreSyncListItem
|
| TAwsParameterStoreSyncListItem
|
||||||
@@ -113,7 +122,8 @@ export type TSecretSyncListItem =
|
|||||||
| THumanitecSyncListItem
|
| THumanitecSyncListItem
|
||||||
| TTerraformCloudSyncListItem
|
| TTerraformCloudSyncListItem
|
||||||
| TCamundaSyncListItem
|
| TCamundaSyncListItem
|
||||||
| TVercelSyncListItem;
|
| TVercelSyncListItem
|
||||||
|
| TWindmillSyncListItem;
|
||||||
|
|
||||||
export type TSyncOptionsConfig = {
|
export type TSyncOptionsConfig = {
|
||||||
canImportSecrets: boolean;
|
canImportSecrets: boolean;
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export * from "./windmill-sync-constants";
|
||||||
|
export * from "./windmill-sync-fns";
|
||||||
|
export * from "./windmill-sync-schemas";
|
||||||
|
export * from "./windmill-sync-types";
|
||||||
@@ -0,0 +1,10 @@
|
|||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
import { TSecretSyncListItem } from "@app/services/secret-sync/secret-sync-types";
|
||||||
|
|
||||||
|
export const WINDMILL_SYNC_LIST_OPTION: TSecretSyncListItem = {
|
||||||
|
name: "Windmill",
|
||||||
|
destination: SecretSync.Windmill,
|
||||||
|
connection: AppConnection.Windmill,
|
||||||
|
canImportSecrets: true
|
||||||
|
};
|
||||||
@@ -0,0 +1,232 @@
|
|||||||
|
import { request } from "@app/lib/config/request";
|
||||||
|
import { getWindmillInstanceUrl } from "@app/services/app-connection/windmill";
|
||||||
|
import { SecretSyncError } from "@app/services/secret-sync/secret-sync-errors";
|
||||||
|
import {
|
||||||
|
TDeleteWindmillVariable,
|
||||||
|
TPostWindmillVariable,
|
||||||
|
TWindmillListVariables,
|
||||||
|
TWindmillListVariablesResponse,
|
||||||
|
TWindmillSyncWithCredentials,
|
||||||
|
TWindmillVariable
|
||||||
|
} from "@app/services/secret-sync/windmill/windmill-sync-types";
|
||||||
|
|
||||||
|
import { TSecretMap } from "../secret-sync-types";
|
||||||
|
|
||||||
|
const PAGE_LIMIT = 100;
|
||||||
|
|
||||||
|
const listWindmillVariables = async ({ instanceUrl, workspace, accessToken, path }: TWindmillListVariables) => {
|
||||||
|
const variables: Record<string, TWindmillVariable> = {};
|
||||||
|
|
||||||
|
// windmill paginates but doesn't return if there's more pages so we need to check if page size full
|
||||||
|
let page: number | null = 1;
|
||||||
|
|
||||||
|
while (page) {
|
||||||
|
// eslint-disable-next-line no-await-in-loop
|
||||||
|
const { data: variablesPage } = await request.get<TWindmillListVariablesResponse>(
|
||||||
|
`${instanceUrl}/api/w/${workspace}/variables/list`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`
|
||||||
|
},
|
||||||
|
params: {
|
||||||
|
page,
|
||||||
|
limit: PAGE_LIMIT,
|
||||||
|
path_start: path
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
// eslint-disable-next-line no-await-in-loop
|
||||||
|
for await (const variable of variablesPage) {
|
||||||
|
const variableName = variable.path.replace(path, "");
|
||||||
|
|
||||||
|
if (variable.is_secret) {
|
||||||
|
const { data: variableValue } = await request.get<string>(
|
||||||
|
`${instanceUrl}/api/w/${workspace}/variables/get_value/${variable.path}`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
variables[variableName] = {
|
||||||
|
...variable,
|
||||||
|
value: variableValue
|
||||||
|
};
|
||||||
|
} else {
|
||||||
|
variables[variableName] = variable;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (variablesPage.length >= PAGE_LIMIT) {
|
||||||
|
page += 1;
|
||||||
|
} else {
|
||||||
|
page = null;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return variables;
|
||||||
|
};
|
||||||
|
|
||||||
|
const createWindmillVariable = async ({
|
||||||
|
path,
|
||||||
|
value,
|
||||||
|
instanceUrl,
|
||||||
|
accessToken,
|
||||||
|
workspace,
|
||||||
|
description
|
||||||
|
}: TPostWindmillVariable) =>
|
||||||
|
request.post(
|
||||||
|
`${instanceUrl}/api/w/${workspace}/variables/create`,
|
||||||
|
{
|
||||||
|
path,
|
||||||
|
value,
|
||||||
|
is_secret: true,
|
||||||
|
description
|
||||||
|
},
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
const updateWindmillVariable = async ({
|
||||||
|
path,
|
||||||
|
value,
|
||||||
|
instanceUrl,
|
||||||
|
accessToken,
|
||||||
|
workspace,
|
||||||
|
description
|
||||||
|
}: TPostWindmillVariable) =>
|
||||||
|
request.post(
|
||||||
|
`${instanceUrl}/api/w/${workspace}/variables/update/${path}`,
|
||||||
|
{
|
||||||
|
value,
|
||||||
|
is_secret: true,
|
||||||
|
description
|
||||||
|
},
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`,
|
||||||
|
"Content-Type": "application/json"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
const deleteWindmillVariable = async ({ path, instanceUrl, accessToken, workspace }: TDeleteWindmillVariable) =>
|
||||||
|
request.delete(`${instanceUrl}/api/w/${workspace}/variables/delete/${path}`, {
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
export const WindmillSyncFns = {
|
||||||
|
syncSecrets: async (secretSync: TWindmillSyncWithCredentials, secretMap: TSecretMap) => {
|
||||||
|
const {
|
||||||
|
connection,
|
||||||
|
destinationConfig: { workspace, path },
|
||||||
|
syncOptions: { disableSecretDeletion }
|
||||||
|
} = secretSync;
|
||||||
|
|
||||||
|
const instanceUrl = await getWindmillInstanceUrl(connection);
|
||||||
|
|
||||||
|
const { accessToken } = connection.credentials;
|
||||||
|
|
||||||
|
const variables = await listWindmillVariables({ instanceUrl, accessToken, workspace, path });
|
||||||
|
|
||||||
|
for await (const entry of Object.entries(secretMap)) {
|
||||||
|
const [key, { value, comment = "" }] = entry;
|
||||||
|
|
||||||
|
try {
|
||||||
|
const payload = {
|
||||||
|
instanceUrl,
|
||||||
|
workspace,
|
||||||
|
path: path + key,
|
||||||
|
value,
|
||||||
|
accessToken,
|
||||||
|
description: comment
|
||||||
|
};
|
||||||
|
if (key in variables) {
|
||||||
|
if (variables[key].value !== value || variables[key].description !== comment)
|
||||||
|
await updateWindmillVariable(payload);
|
||||||
|
} else {
|
||||||
|
await createWindmillVariable(payload);
|
||||||
|
}
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: key
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if (disableSecretDeletion) return;
|
||||||
|
|
||||||
|
for await (const [key, variable] of Object.entries(variables)) {
|
||||||
|
if (!(key in secretMap)) {
|
||||||
|
try {
|
||||||
|
await deleteWindmillVariable({
|
||||||
|
instanceUrl,
|
||||||
|
workspace,
|
||||||
|
path: variable.path,
|
||||||
|
accessToken
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: key
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
removeSecrets: async (secretSync: TWindmillSyncWithCredentials, secretMap: TSecretMap) => {
|
||||||
|
const {
|
||||||
|
connection,
|
||||||
|
destinationConfig: { workspace, path }
|
||||||
|
} = secretSync;
|
||||||
|
|
||||||
|
const instanceUrl = await getWindmillInstanceUrl(connection);
|
||||||
|
|
||||||
|
const { accessToken } = connection.credentials;
|
||||||
|
|
||||||
|
const variables = await listWindmillVariables({ instanceUrl, accessToken, workspace, path });
|
||||||
|
|
||||||
|
for await (const [key, variable] of Object.entries(variables)) {
|
||||||
|
if (key in secretMap) {
|
||||||
|
try {
|
||||||
|
await deleteWindmillVariable({
|
||||||
|
path: variable.path,
|
||||||
|
instanceUrl,
|
||||||
|
workspace,
|
||||||
|
accessToken
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
throw new SecretSyncError({
|
||||||
|
error,
|
||||||
|
secretKey: key
|
||||||
|
});
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
},
|
||||||
|
getSecrets: async (secretSync: TWindmillSyncWithCredentials) => {
|
||||||
|
const {
|
||||||
|
connection,
|
||||||
|
destinationConfig: { workspace, path }
|
||||||
|
} = secretSync;
|
||||||
|
|
||||||
|
const instanceUrl = await getWindmillInstanceUrl(connection);
|
||||||
|
|
||||||
|
const { accessToken } = connection.credentials;
|
||||||
|
|
||||||
|
const variables = await listWindmillVariables({ instanceUrl, accessToken, workspace, path });
|
||||||
|
|
||||||
|
return Object.fromEntries(
|
||||||
|
Object.entries(variables).map(([key, variable]) => [key, { value: variable.value ?? "" }])
|
||||||
|
);
|
||||||
|
}
|
||||||
|
};
|
||||||
@@ -0,0 +1,66 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { SecretSyncs } from "@app/lib/api-docs";
|
||||||
|
import { CharacterType, characterValidator } from "@app/lib/validator/validate-string";
|
||||||
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
|
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||||
|
import {
|
||||||
|
BaseSecretSyncSchema,
|
||||||
|
GenericCreateSecretSyncFieldsSchema,
|
||||||
|
GenericUpdateSecretSyncFieldsSchema
|
||||||
|
} from "@app/services/secret-sync/secret-sync-schemas";
|
||||||
|
import { TSyncOptionsConfig } from "@app/services/secret-sync/secret-sync-types";
|
||||||
|
|
||||||
|
const pathCharacterValidator = characterValidator([
|
||||||
|
CharacterType.AlphaNumeric,
|
||||||
|
CharacterType.Underscore,
|
||||||
|
CharacterType.Hyphen
|
||||||
|
]);
|
||||||
|
|
||||||
|
const WindmillSyncDestinationConfigSchema = z.object({
|
||||||
|
workspace: z.string().trim().min(1, "Workspace required").describe(SecretSyncs.DESTINATION_CONFIG.WINDMILL.workspace),
|
||||||
|
path: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Path required")
|
||||||
|
.refine(
|
||||||
|
(val) =>
|
||||||
|
(val.startsWith("u/") || val.startsWith("f/")) &&
|
||||||
|
val.endsWith("/") &&
|
||||||
|
val.split("/").length >= 3 &&
|
||||||
|
val
|
||||||
|
.split("/")
|
||||||
|
.filter(Boolean)
|
||||||
|
.every((segment) => pathCharacterValidator(segment)),
|
||||||
|
'Invalid path - must follow Windmill path format. ex: "/f/folder/path/"'
|
||||||
|
)
|
||||||
|
.describe(SecretSyncs.DESTINATION_CONFIG.WINDMILL.path)
|
||||||
|
});
|
||||||
|
|
||||||
|
const WindmillSyncOptionsConfig: TSyncOptionsConfig = { canImportSecrets: true };
|
||||||
|
|
||||||
|
export const WindmillSyncSchema = BaseSecretSyncSchema(SecretSync.Windmill, WindmillSyncOptionsConfig).extend({
|
||||||
|
destination: z.literal(SecretSync.Windmill),
|
||||||
|
destinationConfig: WindmillSyncDestinationConfigSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const CreateWindmillSyncSchema = GenericCreateSecretSyncFieldsSchema(
|
||||||
|
SecretSync.Windmill,
|
||||||
|
WindmillSyncOptionsConfig
|
||||||
|
).extend({
|
||||||
|
destinationConfig: WindmillSyncDestinationConfigSchema
|
||||||
|
});
|
||||||
|
|
||||||
|
export const UpdateWindmillSyncSchema = GenericUpdateSecretSyncFieldsSchema(
|
||||||
|
SecretSync.Windmill,
|
||||||
|
WindmillSyncOptionsConfig
|
||||||
|
).extend({
|
||||||
|
destinationConfig: WindmillSyncDestinationConfigSchema.optional()
|
||||||
|
});
|
||||||
|
|
||||||
|
export const WindmillSyncListItemSchema = z.object({
|
||||||
|
name: z.literal("Windmill"),
|
||||||
|
connection: z.literal(AppConnection.Windmill),
|
||||||
|
destination: z.literal(SecretSync.Windmill),
|
||||||
|
canImportSecrets: z.literal(true)
|
||||||
|
});
|
||||||
@@ -0,0 +1,39 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TWindmillConnection } from "@app/services/app-connection/windmill";
|
||||||
|
|
||||||
|
import { CreateWindmillSyncSchema, WindmillSyncListItemSchema, WindmillSyncSchema } from "./windmill-sync-schemas";
|
||||||
|
|
||||||
|
export type TWindmillSync = z.infer<typeof WindmillSyncSchema>;
|
||||||
|
|
||||||
|
export type TWindmillSyncInput = z.infer<typeof CreateWindmillSyncSchema>;
|
||||||
|
|
||||||
|
export type TWindmillSyncListItem = z.infer<typeof WindmillSyncListItemSchema>;
|
||||||
|
|
||||||
|
export type TWindmillSyncWithCredentials = TWindmillSync & {
|
||||||
|
connection: TWindmillConnection;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TWindmillVariable = {
|
||||||
|
path: string;
|
||||||
|
value: string;
|
||||||
|
is_secret: boolean;
|
||||||
|
is_oauth: boolean;
|
||||||
|
description: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TWindmillListVariablesResponse = TWindmillVariable[];
|
||||||
|
|
||||||
|
export type TWindmillListVariables = {
|
||||||
|
accessToken: string;
|
||||||
|
instanceUrl: string;
|
||||||
|
path: string;
|
||||||
|
workspace: string;
|
||||||
|
description?: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TPostWindmillVariable = TWindmillListVariables & {
|
||||||
|
value: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TDeleteWindmillVariable = TWindmillListVariables;
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Available"
|
||||||
|
openapi: "GET /api/v1/app-connections/windmill/available"
|
||||||
|
---
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
title: "Create"
|
||||||
|
openapi: "POST /api/v1/app-connections/windmill"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Check out the configuration docs for [Windmill Connections](/integrations/app-connections/windmill) to learn how to obtain
|
||||||
|
the required credentials.
|
||||||
|
</Note>
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Delete"
|
||||||
|
openapi: "DELETE /api/v1/app-connections/windmill/{connectionId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by ID"
|
||||||
|
openapi: "GET /api/v1/app-connections/windmill/{connectionId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by Name"
|
||||||
|
openapi: "GET /api/v1/app-connections/windmill/connection-name/{connectionName}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "List"
|
||||||
|
openapi: "GET /api/v1/app-connections/windmill"
|
||||||
|
---
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
---
|
||||||
|
title: "Update"
|
||||||
|
openapi: "PATCH /api/v1/app-connections/windmill/{connectionId}"
|
||||||
|
---
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Check out the configuration docs for [Windmill Connections](/integrations/app-connections/windmill) to learn how to obtain
|
||||||
|
the required credentials.
|
||||||
|
</Note>
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Create"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/windmill"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Delete"
|
||||||
|
openapi: "DELETE /api/v1/secret-syncs/windmill/{syncId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by ID"
|
||||||
|
openapi: "GET /api/v1/secret-syncs/windmill/{syncId}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Get by Name"
|
||||||
|
openapi: "GET /api/v1/secret-syncs/windmill/sync-name/{syncName}"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Import Secrets"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/windmill/{syncId}/import-secrets"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "List"
|
||||||
|
openapi: "GET /api/v1/secret-syncs/windmill"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Remove Secrets"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/windmill/{syncId}/remove-secrets"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Sync Secrets"
|
||||||
|
openapi: "POST /api/v1/secret-syncs/windmill/{syncId}/sync-secrets"
|
||||||
|
---
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
title: "Update"
|
||||||
|
openapi: "PATCH /api/v1/secret-syncs/windmill/{syncId}"
|
||||||
|
---
|
||||||
|
After Width: | Height: | Size: 752 KiB |
|
After Width: | Height: | Size: 807 KiB |
|
After Width: | Height: | Size: 1.2 MiB |
|
After Width: | Height: | Size: 322 KiB |
|
After Width: | Height: | Size: 378 KiB |
|
After Width: | Height: | Size: 336 KiB |
|
After Width: | Height: | Size: 373 KiB |
|
After Width: | Height: | Size: 775 KiB |
|
After Width: | Height: | Size: 1.2 MiB |
|
After Width: | Height: | Size: 752 KiB |
|
After Width: | Height: | Size: 741 KiB |
|
After Width: | Height: | Size: 758 KiB |
|
After Width: | Height: | Size: 764 KiB |
|
After Width: | Height: | Size: 725 KiB |
@@ -0,0 +1,102 @@
|
|||||||
|
---
|
||||||
|
title: "Windmill Connection"
|
||||||
|
description: "Learn how to configure a Windmill Connection for Infisical."
|
||||||
|
---
|
||||||
|
|
||||||
|
Infisical supports connecting to Windmill using an **Access Token** to securely sync your secrets to Windmill.
|
||||||
|
|
||||||
|
## Get a Windmill Access Token
|
||||||
|
|
||||||
|
<Steps>
|
||||||
|
<Step title="Navigate to Account Setting">
|
||||||
|
In Windmill, click on your user in the sidebar and select **Account Settings**.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Access Token Section">
|
||||||
|
In the **Tokens** section on the drawer, click **Create token**.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Create Access Token">
|
||||||
|
Give your token a name and click **New token**.
|
||||||
|
<Note>
|
||||||
|
If you configure an expiry date for your access token, you must manually rotate to a new token before the expiration date to prevent service interruption.
|
||||||
|
</Note>
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Copy Access Token">
|
||||||
|
Copy your new access token and save it for the steps below.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
|
||||||
|
|
||||||
|
## Setup a Windmill Connection in Infisical
|
||||||
|
|
||||||
|
|
||||||
|
<Tabs>
|
||||||
|
<Tab title="Infisical UI">
|
||||||
|
<Steps>
|
||||||
|
<Step title="Navigate to App Connections">
|
||||||
|
In your Infisical dashboard, go to **Organization Settings** and select the **App Connections** tab.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Add Connection">
|
||||||
|
Click the **+ Add Connection** button and select the **Windmill Connection** option.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
<Step title="Configure Connection">
|
||||||
|
Configure your Windmill Connection using the access token generated in the steps above. Then click **Connect to Windmill**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Name**: The name of the connection to be created. Must be slug-friendly.
|
||||||
|
- **Description**: An optional description to provide details about this connection.
|
||||||
|
- **Instance URL**: The URL of your Windmill instance. If you are not self-hosting Windmill you can leave this field blank.
|
||||||
|
- **Access Token**: The access token generated in the steps above.
|
||||||
|
</Step>
|
||||||
|
<Step title="Connection Created">
|
||||||
|
Your Windmill Connection is now available for use.
|
||||||
|

|
||||||
|
</Step>
|
||||||
|
</Steps>
|
||||||
|
</Tab>
|
||||||
|
<Tab title="API">
|
||||||
|
To create a Windmill Connection, make an API request to the [Create Windmill
|
||||||
|
Connection](/api-reference/endpoints/app-connections/windmill/create) API endpoint.
|
||||||
|
|
||||||
|
### Sample request
|
||||||
|
|
||||||
|
```bash Request
|
||||||
|
curl --request POST \
|
||||||
|
--url https://app.infisical.com/api/v1/app-connections/windmill \
|
||||||
|
--header 'Content-Type: application/json' \
|
||||||
|
--data '{
|
||||||
|
"name": "my-windmill-connection",
|
||||||
|
"method": "access-token",
|
||||||
|
"credentials": {
|
||||||
|
"token": "...",
|
||||||
|
"instanceUrl": "https://app.windmill.dev"
|
||||||
|
}
|
||||||
|
}'
|
||||||
|
```
|
||||||
|
|
||||||
|
### Sample response
|
||||||
|
|
||||||
|
```bash Response
|
||||||
|
{
|
||||||
|
"appConnection": {
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"name": "my-windmill-connection",
|
||||||
|
"version": 123,
|
||||||
|
"orgId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"createdAt": "2025-04-01T05:31:56Z",
|
||||||
|
"updatedAt": "2025-04-01T05:31:56Z",
|
||||||
|
"app": "windmill",
|
||||||
|
"method": "access-token",
|
||||||
|
"credentials": {
|
||||||
|
"instanceUrl": "https://app.windmill.dev"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
</Tab>
|
||||||
|
</Tabs>
|
||||||
@@ -0,0 +1,147 @@
|
|||||||
|
---
|
||||||
|
title: "Windmill Sync"
|
||||||
|
description: "Learn how to configure a Windmill Sync for Infisical."
|
||||||
|
---
|
||||||
|
|
||||||
|
**Prerequisites:**
|
||||||
|
|
||||||
|
- Set up and add secrets to [Infisical Cloud](https://app.infisical.com)
|
||||||
|
- Create a [Windmill Connection](/integrations/app-connections/windmill)
|
||||||
|
|
||||||
|
<Tabs>
|
||||||
|
<Tab title="Infisical UI">
|
||||||
|
1. Navigate to **Project** > **Integrations** and select the **Secret Syncs** tab. Click on the **Add Sync** button.
|
||||||
|

|
||||||
|
|
||||||
|
2. Select the **Windmill** option.
|
||||||
|

|
||||||
|
|
||||||
|
3. Configure the **Source** from where secrets should be retrieved, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Environment**: The project environment to retrieve secrets from.
|
||||||
|
- **Secret Path**: The folder path to retrieve secrets from.
|
||||||
|
|
||||||
|
<Tip>
|
||||||
|
If you need to sync secrets from multiple folder locations, check out [secret imports](/documentation/platform/secret-reference#secret-imports).
|
||||||
|
</Tip>
|
||||||
|
|
||||||
|
4. Configure the **Destination** to where secrets should be deployed, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Windmill Connection**: The Windmill Connection to authenticate with.
|
||||||
|
- **Workspace**: The Windmill workspace to sync secrets to.
|
||||||
|
- **Path**: The workspace path to sync secrets to.
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Workspace path must conform to Windmill's [owner path convention](https://www.windmill.dev/docs/core_concepts/roles_and_permissions#path).
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
5. Configure the **Sync Options** to specify how secrets should be synced, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Initial Sync Behavior**: Determines how Infisical should resolve the initial sync.
|
||||||
|
- **Overwrite Destination Secrets**: Removes any secrets at the destination endpoint not present in Infisical.
|
||||||
|
- **Import Secrets (Prioritize Infisical)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Infisical over Vercel when keys conflict.
|
||||||
|
- **Import Secrets (Prioritize Windmill)**: Imports secrets from the destination endpoint before syncing, prioritizing values from Windmill over Infisical when keys conflict.
|
||||||
|
- **Auto-Sync Enabled**: If enabled, secrets will automatically be synced from the source location when changes occur. Disable to enforce manual syncing only.
|
||||||
|
- **Disable Secret Deletion**: If enabled, Infisical will not remove secrets from the sync destination. Enable this option if you intend to manage some secrets manually outside of Infisical.
|
||||||
|
|
||||||
|
6. Configure the **Details** of your Windmill Sync, then click **Next**.
|
||||||
|

|
||||||
|
|
||||||
|
- **Name**: The name of your sync. Must be slug-friendly.
|
||||||
|
- **Description**: An optional description for your sync.
|
||||||
|
|
||||||
|
7. Review your Windmill Sync configuration, then click **Create Sync**.
|
||||||
|

|
||||||
|
|
||||||
|
8. If enabled, your Windmill Sync will begin syncing your secrets to the destination endpoint.
|
||||||
|

|
||||||
|
|
||||||
|
</Tab>
|
||||||
|
<Tab title="API">
|
||||||
|
To create an **Windmill Sync**, make an API request to the [Create Windmill Sync](/api-reference/endpoints/secret-syncs/windmill/create) API endpoint.
|
||||||
|
|
||||||
|
### Sample request
|
||||||
|
|
||||||
|
```bash Request
|
||||||
|
curl --request POST \
|
||||||
|
--url https://app.infisical.com/api/v1/secret-syncs/windmill \
|
||||||
|
--header 'Content-Type: application/json' \
|
||||||
|
--data '{
|
||||||
|
"name": "my-windmill-sync",
|
||||||
|
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"description": "an example sync",
|
||||||
|
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"environment": "dev",
|
||||||
|
"secretPath": "/my-secrets",
|
||||||
|
"isEnabled": true,
|
||||||
|
"syncOptions": {
|
||||||
|
"initialSyncBehavior": "overwrite-destination"
|
||||||
|
},
|
||||||
|
"destinationConfig": {
|
||||||
|
"workspace": "my-workspace",
|
||||||
|
"path": "f/folder/path/"
|
||||||
|
}
|
||||||
|
}'
|
||||||
|
```
|
||||||
|
|
||||||
|
<Note>
|
||||||
|
Workspace path must conform to Windmill's [owner path convention](https://www.windmill.dev/docs/core_concepts/roles_and_permissions#path).
|
||||||
|
</Note>
|
||||||
|
|
||||||
|
### Sample response
|
||||||
|
|
||||||
|
```bash Response
|
||||||
|
{
|
||||||
|
"secretSync": {
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"name": "my-windmill-sync",
|
||||||
|
"description": "an example sync",
|
||||||
|
"isEnabled": true,
|
||||||
|
"version": 1,
|
||||||
|
"folderId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"connectionId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"createdAt": "2023-11-07T05:31:56Z",
|
||||||
|
"updatedAt": "2023-11-07T05:31:56Z",
|
||||||
|
"syncStatus": "succeeded",
|
||||||
|
"lastSyncJobId": "123",
|
||||||
|
"lastSyncMessage": null,
|
||||||
|
"lastSyncedAt": "2023-11-07T05:31:56Z",
|
||||||
|
"importStatus": null,
|
||||||
|
"lastImportJobId": null,
|
||||||
|
"lastImportMessage": null,
|
||||||
|
"lastImportedAt": null,
|
||||||
|
"removeStatus": null,
|
||||||
|
"lastRemoveJobId": null,
|
||||||
|
"lastRemoveMessage": null,
|
||||||
|
"lastRemovedAt": null,
|
||||||
|
"syncOptions": {
|
||||||
|
"initialSyncBehavior": "overwrite-destination"
|
||||||
|
},
|
||||||
|
"projectId": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"connection": {
|
||||||
|
"app": "windmill",
|
||||||
|
"name": "my-windmill-connection",
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||||
|
},
|
||||||
|
"environment": {
|
||||||
|
"slug": "dev",
|
||||||
|
"name": "Development",
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a"
|
||||||
|
},
|
||||||
|
"folder": {
|
||||||
|
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
|
||||||
|
"path": "/my-secrets"
|
||||||
|
},
|
||||||
|
"destination": "windmill",
|
||||||
|
"destinationConfig": {
|
||||||
|
"workspace": "my-workspace",
|
||||||
|
"path": "f/folder/path/"
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
```
|
||||||
|
</Tab>
|
||||||
|
</Tabs>
|
||||||
@@ -425,7 +425,8 @@
|
|||||||
"integrations/app-connections/mssql",
|
"integrations/app-connections/mssql",
|
||||||
"integrations/app-connections/postgres",
|
"integrations/app-connections/postgres",
|
||||||
"integrations/app-connections/terraform-cloud",
|
"integrations/app-connections/terraform-cloud",
|
||||||
"integrations/app-connections/vercel"
|
"integrations/app-connections/vercel",
|
||||||
|
"integrations/app-connections/windmill"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
@@ -447,7 +448,8 @@
|
|||||||
"integrations/secret-syncs/github",
|
"integrations/secret-syncs/github",
|
||||||
"integrations/secret-syncs/humanitec",
|
"integrations/secret-syncs/humanitec",
|
||||||
"integrations/secret-syncs/terraform-cloud",
|
"integrations/secret-syncs/terraform-cloud",
|
||||||
"integrations/secret-syncs/vercel"
|
"integrations/secret-syncs/vercel",
|
||||||
|
"integrations/secret-syncs/windmill"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
@@ -1031,6 +1033,18 @@
|
|||||||
"api-reference/endpoints/app-connections/vercel/update",
|
"api-reference/endpoints/app-connections/vercel/update",
|
||||||
"api-reference/endpoints/app-connections/vercel/delete"
|
"api-reference/endpoints/app-connections/vercel/delete"
|
||||||
]
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"group": "Windmill",
|
||||||
|
"pages": [
|
||||||
|
"api-reference/endpoints/app-connections/windmill/list",
|
||||||
|
"api-reference/endpoints/app-connections/windmill/available",
|
||||||
|
"api-reference/endpoints/app-connections/windmill/get-by-id",
|
||||||
|
"api-reference/endpoints/app-connections/windmill/get-by-name",
|
||||||
|
"api-reference/endpoints/app-connections/windmill/create",
|
||||||
|
"api-reference/endpoints/app-connections/windmill/update",
|
||||||
|
"api-reference/endpoints/app-connections/windmill/delete"
|
||||||
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
},
|
},
|
||||||
@@ -1184,8 +1198,22 @@
|
|||||||
"api-reference/endpoints/secret-syncs/vercel/update",
|
"api-reference/endpoints/secret-syncs/vercel/update",
|
||||||
"api-reference/endpoints/secret-syncs/vercel/delete",
|
"api-reference/endpoints/secret-syncs/vercel/delete",
|
||||||
"api-reference/endpoints/secret-syncs/vercel/sync-secrets",
|
"api-reference/endpoints/secret-syncs/vercel/sync-secrets",
|
||||||
"api-reference/endpoints/secret-syncs/vercel/remove-secrets",
|
"api-reference/endpoints/secret-syncs/vercel/import-secrets",
|
||||||
"api-reference/endpoints/secret-syncs/vercel/import-secrets"
|
"api-reference/endpoints/secret-syncs/vercel/remove-secrets"
|
||||||
|
]
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"group": "Windmill",
|
||||||
|
"pages": [
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/list",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/get-by-id",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/get-by-name",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/create",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/update",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/delete",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/sync-secrets",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/import-secrets",
|
||||||
|
"api-reference/endpoints/secret-syncs/windmill/remove-secrets"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
|
|||||||
@@ -14,6 +14,7 @@ import { GitHubSyncFields } from "./GitHubSyncFields";
|
|||||||
import { HumanitecSyncFields } from "./HumanitecSyncFields";
|
import { HumanitecSyncFields } from "./HumanitecSyncFields";
|
||||||
import { TerraformCloudSyncFields } from "./TerraformCloudSyncFields";
|
import { TerraformCloudSyncFields } from "./TerraformCloudSyncFields";
|
||||||
import { VercelSyncFields } from "./VercelSyncFields";
|
import { VercelSyncFields } from "./VercelSyncFields";
|
||||||
|
import { WindmillSyncFields } from "./WindmillSyncFields";
|
||||||
|
|
||||||
export const SecretSyncDestinationFields = () => {
|
export const SecretSyncDestinationFields = () => {
|
||||||
const { watch } = useFormContext<TSecretSyncForm>();
|
const { watch } = useFormContext<TSecretSyncForm>();
|
||||||
@@ -43,6 +44,8 @@ export const SecretSyncDestinationFields = () => {
|
|||||||
return <CamundaSyncFields />;
|
return <CamundaSyncFields />;
|
||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
return <VercelSyncFields />;
|
return <VercelSyncFields />;
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
return <WindmillSyncFields />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Config Field: ${destination}`);
|
throw new Error(`Unhandled Destination Config Field: ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,105 @@
|
|||||||
|
import { Controller, useFormContext, useWatch } from "react-hook-form";
|
||||||
|
import { SingleValue } from "react-select";
|
||||||
|
import { faCircleInfo } from "@fortawesome/free-solid-svg-icons";
|
||||||
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
|
||||||
|
import { SecretSyncConnectionField } from "@app/components/secret-syncs/forms/SecretSyncConnectionField";
|
||||||
|
import { FilterableSelect, FormControl, Input, Tooltip } from "@app/components/v2";
|
||||||
|
import {
|
||||||
|
TWindmillWorkspace,
|
||||||
|
useWindmillConnectionListWorkspaces
|
||||||
|
} from "@app/hooks/api/appConnections/windmill";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
|
||||||
|
import { TSecretSyncForm } from "../schemas";
|
||||||
|
|
||||||
|
export const WindmillSyncFields = () => {
|
||||||
|
const { control, setValue } = useFormContext<
|
||||||
|
TSecretSyncForm & { destination: SecretSync.Windmill }
|
||||||
|
>();
|
||||||
|
|
||||||
|
const connectionId = useWatch({ name: "connection.id", control });
|
||||||
|
|
||||||
|
const { data: workspaces, isLoading: isWorkspacesLoading } = useWindmillConnectionListWorkspaces(
|
||||||
|
connectionId,
|
||||||
|
{
|
||||||
|
enabled: Boolean(connectionId)
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<SecretSyncConnectionField
|
||||||
|
onChange={() => {
|
||||||
|
setValue("destinationConfig.workspace", "");
|
||||||
|
}}
|
||||||
|
/>
|
||||||
|
|
||||||
|
<Controller
|
||||||
|
name="destinationConfig.workspace"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
label="Workspace"
|
||||||
|
helperText={
|
||||||
|
<Tooltip
|
||||||
|
className="max-w-md"
|
||||||
|
content="Ensure the workspace exists in the connection's Windmill instance URL."
|
||||||
|
>
|
||||||
|
<div>
|
||||||
|
<span>Don't see the workspace you're looking for?</span>{" "}
|
||||||
|
<FontAwesomeIcon icon={faCircleInfo} className="text-mineshaft-400" />
|
||||||
|
</div>
|
||||||
|
</Tooltip>
|
||||||
|
}
|
||||||
|
>
|
||||||
|
<FilterableSelect
|
||||||
|
menuPlacement="top"
|
||||||
|
isLoading={isWorkspacesLoading && Boolean(connectionId)}
|
||||||
|
isDisabled={!connectionId}
|
||||||
|
value={workspaces?.find((workspace) => workspace.name === value) ?? null}
|
||||||
|
onChange={(option) =>
|
||||||
|
onChange((option as SingleValue<TWindmillWorkspace>)?.name ?? null)
|
||||||
|
}
|
||||||
|
options={workspaces}
|
||||||
|
placeholder="Select a workspace..."
|
||||||
|
getOptionLabel={(option) => option.name}
|
||||||
|
getOptionValue={(option) => option.name}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
tooltipClassName="max-w-sm"
|
||||||
|
tooltipText={
|
||||||
|
<>
|
||||||
|
The workspace path where secrets should be synced to. Path must follow Windmill{" "}
|
||||||
|
<a
|
||||||
|
target="_blank"
|
||||||
|
rel="noopener noreferrer"
|
||||||
|
href="https://www.windmill.dev/docs/core_concepts/roles_and_permissions#path"
|
||||||
|
>
|
||||||
|
<span className="cursor-pointer underline decoration-primary underline-offset-2 hover:text-mineshaft-200">
|
||||||
|
owner path convention
|
||||||
|
</span>
|
||||||
|
.
|
||||||
|
</a>
|
||||||
|
</>
|
||||||
|
}
|
||||||
|
isError={Boolean(error)}
|
||||||
|
errorText={error?.message}
|
||||||
|
label="Path"
|
||||||
|
>
|
||||||
|
<Input value={value} onChange={onChange} placeholder="f/folder-name/" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
control={control}
|
||||||
|
name="destinationConfig.path"
|
||||||
|
/>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -42,6 +42,7 @@ export const SecretSyncOptionsFields = ({ hideInitialSync }: Props) => {
|
|||||||
case SecretSync.TerraformCloud:
|
case SecretSync.TerraformCloud:
|
||||||
case SecretSync.Camunda:
|
case SecretSync.Camunda:
|
||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
|
case SecretSync.Windmill:
|
||||||
AdditionalSyncOptionsFieldsComponent = null;
|
AdditionalSyncOptionsFieldsComponent = null;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
|
|||||||
@@ -24,6 +24,7 @@ import { GitHubSyncReviewFields } from "./GitHubSyncReviewFields";
|
|||||||
import { HumanitecSyncReviewFields } from "./HumanitecSyncReviewFields";
|
import { HumanitecSyncReviewFields } from "./HumanitecSyncReviewFields";
|
||||||
import { TerraformCloudSyncReviewFields } from "./TerraformCloudSyncReviewFields";
|
import { TerraformCloudSyncReviewFields } from "./TerraformCloudSyncReviewFields";
|
||||||
import { VercelSyncReviewFields } from "./VercelSyncReviewFields";
|
import { VercelSyncReviewFields } from "./VercelSyncReviewFields";
|
||||||
|
import { WindmillSyncReviewFields } from "./WindmillSyncReviewFields";
|
||||||
|
|
||||||
export const SecretSyncReviewFields = () => {
|
export const SecretSyncReviewFields = () => {
|
||||||
const { watch } = useFormContext<TSecretSyncForm>();
|
const { watch } = useFormContext<TSecretSyncForm>();
|
||||||
@@ -84,6 +85,9 @@ export const SecretSyncReviewFields = () => {
|
|||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
DestinationFieldsComponent = <VercelSyncReviewFields />;
|
DestinationFieldsComponent = <VercelSyncReviewFields />;
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
DestinationFieldsComponent = <WindmillSyncReviewFields />;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Review Fields: ${destination}`);
|
throw new Error(`Unhandled Destination Review Fields: ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
import { useFormContext } from "react-hook-form";
|
||||||
|
|
||||||
|
import { TSecretSyncForm } from "@app/components/secret-syncs/forms/schemas";
|
||||||
|
import { GenericFieldLabel } from "@app/components/v2";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
|
||||||
|
export const WindmillSyncReviewFields = () => {
|
||||||
|
const { watch } = useFormContext<TSecretSyncForm & { destination: SecretSync.Windmill }>();
|
||||||
|
const workspace = watch("destinationConfig.workspace");
|
||||||
|
const path = watch("destinationConfig.path");
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<GenericFieldLabel label="Workspace">{workspace}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Path">{path}</GenericFieldLabel>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -1,17 +1,17 @@
|
|||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { AwsSecretsManagerSyncDestinationSchema } from "@app/components/secret-syncs/forms/schemas/aws-secrets-manager-sync-destination-schema";
|
|
||||||
import { DatabricksSyncDestinationSchema } from "@app/components/secret-syncs/forms/schemas/databricks-sync-destination-schema";
|
|
||||||
import { GitHubSyncDestinationSchema } from "@app/components/secret-syncs/forms/schemas/github-sync-destination-schema";
|
|
||||||
|
|
||||||
import { AwsParameterStoreSyncDestinationSchema } from "./aws-parameter-store-sync-destination-schema";
|
import { AwsParameterStoreSyncDestinationSchema } from "./aws-parameter-store-sync-destination-schema";
|
||||||
|
import { AwsSecretsManagerSyncDestinationSchema } from "./aws-secrets-manager-sync-destination-schema";
|
||||||
import { AzureAppConfigurationSyncDestinationSchema } from "./azure-app-configuration-sync-destination-schema";
|
import { AzureAppConfigurationSyncDestinationSchema } from "./azure-app-configuration-sync-destination-schema";
|
||||||
import { AzureKeyVaultSyncDestinationSchema } from "./azure-key-vault-sync-destination-schema";
|
import { AzureKeyVaultSyncDestinationSchema } from "./azure-key-vault-sync-destination-schema";
|
||||||
import { CamundaSyncDestinationSchema } from "./camunda-sync-destination-schema";
|
import { CamundaSyncDestinationSchema } from "./camunda-sync-destination-schema";
|
||||||
|
import { DatabricksSyncDestinationSchema } from "./databricks-sync-destination-schema";
|
||||||
import { GcpSyncDestinationSchema } from "./gcp-sync-destination-schema";
|
import { GcpSyncDestinationSchema } from "./gcp-sync-destination-schema";
|
||||||
|
import { GitHubSyncDestinationSchema } from "./github-sync-destination-schema";
|
||||||
import { HumanitecSyncDestinationSchema } from "./humanitec-sync-destination-schema";
|
import { HumanitecSyncDestinationSchema } from "./humanitec-sync-destination-schema";
|
||||||
import { TerraformCloudSyncDestinationSchema } from "./terraform-cloud-destination-schema";
|
import { TerraformCloudSyncDestinationSchema } from "./terraform-cloud-destination-schema";
|
||||||
import { VercelSyncDestinationSchema } from "./vercel-sync-destination-schema";
|
import { VercelSyncDestinationSchema } from "./vercel-sync-destination-schema";
|
||||||
|
import { WindmillSyncDestinationSchema } from "./windmill-sync-destination-schema";
|
||||||
|
|
||||||
const SecretSyncUnionSchema = z.discriminatedUnion("destination", [
|
const SecretSyncUnionSchema = z.discriminatedUnion("destination", [
|
||||||
AwsParameterStoreSyncDestinationSchema,
|
AwsParameterStoreSyncDestinationSchema,
|
||||||
@@ -24,7 +24,8 @@ const SecretSyncUnionSchema = z.discriminatedUnion("destination", [
|
|||||||
HumanitecSyncDestinationSchema,
|
HumanitecSyncDestinationSchema,
|
||||||
TerraformCloudSyncDestinationSchema,
|
TerraformCloudSyncDestinationSchema,
|
||||||
CamundaSyncDestinationSchema,
|
CamundaSyncDestinationSchema,
|
||||||
VercelSyncDestinationSchema
|
VercelSyncDestinationSchema,
|
||||||
|
WindmillSyncDestinationSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const SecretSyncFormSchema = SecretSyncUnionSchema;
|
export const SecretSyncFormSchema = SecretSyncUnionSchema;
|
||||||
|
|||||||
@@ -0,0 +1,21 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { BaseSecretSyncSchema } from "@app/components/secret-syncs/forms/schemas/base-secret-sync-schema";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
|
||||||
|
export const WindmillSyncDestinationSchema = BaseSecretSyncSchema().merge(
|
||||||
|
z.object({
|
||||||
|
destination: z.literal(SecretSync.Windmill),
|
||||||
|
destinationConfig: z.object({
|
||||||
|
workspace: z.string().trim().min(1, "Project required"),
|
||||||
|
path: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1, "Project required")
|
||||||
|
.regex(
|
||||||
|
/^([uf])\/([a-zA-Z0-9_-]+)(\/[a-zA-Z0-9_-]+)*\/$/,
|
||||||
|
'Invalid path - must follow Windmill path format. ex: "/f/folder/path/"'
|
||||||
|
)
|
||||||
|
})
|
||||||
|
})
|
||||||
|
);
|
||||||
@@ -15,7 +15,8 @@ import {
|
|||||||
PostgresConnectionMethod,
|
PostgresConnectionMethod,
|
||||||
TAppConnection,
|
TAppConnection,
|
||||||
TerraformCloudConnectionMethod,
|
TerraformCloudConnectionMethod,
|
||||||
VercelConnectionMethod
|
VercelConnectionMethod,
|
||||||
|
WindmillConnectionMethod
|
||||||
} from "@app/hooks/api/appConnections/types";
|
} from "@app/hooks/api/appConnections/types";
|
||||||
|
|
||||||
export const APP_CONNECTION_MAP: Record<AppConnection, { name: string; image: string }> = {
|
export const APP_CONNECTION_MAP: Record<AppConnection, { name: string; image: string }> = {
|
||||||
@@ -36,7 +37,8 @@ export const APP_CONNECTION_MAP: Record<AppConnection, { name: string; image: st
|
|||||||
[AppConnection.Vercel]: { name: "Vercel", image: "Vercel.png" },
|
[AppConnection.Vercel]: { name: "Vercel", image: "Vercel.png" },
|
||||||
[AppConnection.Postgres]: { name: "PostgreSQL", image: "Postgres.png" },
|
[AppConnection.Postgres]: { name: "PostgreSQL", image: "Postgres.png" },
|
||||||
[AppConnection.MsSql]: { name: "Microsoft SQL Server", image: "MsSql.png" },
|
[AppConnection.MsSql]: { name: "Microsoft SQL Server", image: "MsSql.png" },
|
||||||
[AppConnection.Camunda]: { name: "Camunda", image: "Camunda.png" }
|
[AppConnection.Camunda]: { name: "Camunda", image: "Camunda.png" },
|
||||||
|
[AppConnection.Windmill]: { name: "Windmill", image: "Windmill.png" }
|
||||||
};
|
};
|
||||||
|
|
||||||
export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => {
|
export const getAppConnectionMethodDetails = (method: TAppConnection["method"]) => {
|
||||||
@@ -64,6 +66,8 @@ export const getAppConnectionMethodDetails = (method: TAppConnection["method"])
|
|||||||
case PostgresConnectionMethod.UsernameAndPassword:
|
case PostgresConnectionMethod.UsernameAndPassword:
|
||||||
case MsSqlConnectionMethod.UsernameAndPassword:
|
case MsSqlConnectionMethod.UsernameAndPassword:
|
||||||
return { name: "Username & Password", icon: faLock };
|
return { name: "Username & Password", icon: faLock };
|
||||||
|
case WindmillConnectionMethod.AccessToken:
|
||||||
|
return { name: "Access Token", icon: faKey };
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App Connection Method: ${method}`);
|
throw new Error(`Unhandled App Connection Method: ${method}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -35,6 +35,10 @@ export const SECRET_SYNC_MAP: Record<SecretSync, { name: string; image: string }
|
|||||||
[SecretSync.Vercel]: {
|
[SecretSync.Vercel]: {
|
||||||
name: "Vercel",
|
name: "Vercel",
|
||||||
image: "Vercel.png"
|
image: "Vercel.png"
|
||||||
|
},
|
||||||
|
[SecretSync.Windmill]: {
|
||||||
|
name: "Windmill",
|
||||||
|
image: "Windmill.png"
|
||||||
}
|
}
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -49,7 +53,8 @@ export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
|||||||
[SecretSync.Humanitec]: AppConnection.Humanitec,
|
[SecretSync.Humanitec]: AppConnection.Humanitec,
|
||||||
[SecretSync.TerraformCloud]: AppConnection.TerraformCloud,
|
[SecretSync.TerraformCloud]: AppConnection.TerraformCloud,
|
||||||
[SecretSync.Camunda]: AppConnection.Camunda,
|
[SecretSync.Camunda]: AppConnection.Camunda,
|
||||||
[SecretSync.Vercel]: AppConnection.Vercel
|
[SecretSync.Vercel]: AppConnection.Vercel,
|
||||||
|
[SecretSync.Windmill]: AppConnection.Windmill
|
||||||
};
|
};
|
||||||
|
|
||||||
export const SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP: Record<
|
export const SECRET_SYNC_INITIAL_SYNC_BEHAVIOR_MAP: Record<
|
||||||
|
|||||||
@@ -10,5 +10,6 @@ export enum AppConnection {
|
|||||||
Vercel = "vercel",
|
Vercel = "vercel",
|
||||||
Postgres = "postgres",
|
Postgres = "postgres",
|
||||||
MsSql = "mssql",
|
MsSql = "mssql",
|
||||||
Camunda = "camunda"
|
Camunda = "camunda",
|
||||||
|
Windmill = "windmill"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -59,6 +59,10 @@ export type TCamundaConnectionOption = TAppConnectionOptionBase & {
|
|||||||
app: AppConnection.Camunda;
|
app: AppConnection.Camunda;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
export type TWindmillConnectionOption = TAppConnectionOptionBase & {
|
||||||
|
app: AppConnection.Windmill;
|
||||||
|
};
|
||||||
|
|
||||||
export type TAppConnectionOption =
|
export type TAppConnectionOption =
|
||||||
| TAwsConnectionOption
|
| TAwsConnectionOption
|
||||||
| TGitHubConnectionOption
|
| TGitHubConnectionOption
|
||||||
@@ -71,7 +75,8 @@ export type TAppConnectionOption =
|
|||||||
| TVercelConnectionOption
|
| TVercelConnectionOption
|
||||||
| TPostgresConnectionOption
|
| TPostgresConnectionOption
|
||||||
| TMsSqlConnectionOption
|
| TMsSqlConnectionOption
|
||||||
| TCamundaConnectionOption;
|
| TCamundaConnectionOption
|
||||||
|
| TWindmillConnectionOption;
|
||||||
|
|
||||||
export type TAppConnectionOptionMap = {
|
export type TAppConnectionOptionMap = {
|
||||||
[AppConnection.AWS]: TAwsConnectionOption;
|
[AppConnection.AWS]: TAwsConnectionOption;
|
||||||
@@ -86,4 +91,5 @@ export type TAppConnectionOptionMap = {
|
|||||||
[AppConnection.Postgres]: TPostgresConnectionOption;
|
[AppConnection.Postgres]: TPostgresConnectionOption;
|
||||||
[AppConnection.MsSql]: TMsSqlConnectionOption;
|
[AppConnection.MsSql]: TMsSqlConnectionOption;
|
||||||
[AppConnection.Camunda]: TCamundaConnectionOption;
|
[AppConnection.Camunda]: TCamundaConnectionOption;
|
||||||
|
[AppConnection.Windmill]: TWindmillConnectionOption;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import { TMsSqlConnection } from "./mssql-connection";
|
|||||||
import { TPostgresConnection } from "./postgres-connection";
|
import { TPostgresConnection } from "./postgres-connection";
|
||||||
import { TTerraformCloudConnection } from "./terraform-cloud-connection";
|
import { TTerraformCloudConnection } from "./terraform-cloud-connection";
|
||||||
import { TVercelConnection } from "./vercel-connection";
|
import { TVercelConnection } from "./vercel-connection";
|
||||||
|
import { TWindmillConnection } from "./windmill-connection";
|
||||||
|
|
||||||
export * from "./aws-connection";
|
export * from "./aws-connection";
|
||||||
export * from "./azure-app-configuration-connection";
|
export * from "./azure-app-configuration-connection";
|
||||||
@@ -25,6 +26,7 @@ export * from "./mssql-connection";
|
|||||||
export * from "./postgres-connection";
|
export * from "./postgres-connection";
|
||||||
export * from "./terraform-cloud-connection";
|
export * from "./terraform-cloud-connection";
|
||||||
export * from "./vercel-connection";
|
export * from "./vercel-connection";
|
||||||
|
export * from "./windmill-connection";
|
||||||
|
|
||||||
export type TAppConnection =
|
export type TAppConnection =
|
||||||
| TAwsConnection
|
| TAwsConnection
|
||||||
@@ -38,7 +40,8 @@ export type TAppConnection =
|
|||||||
| TVercelConnection
|
| TVercelConnection
|
||||||
| TPostgresConnection
|
| TPostgresConnection
|
||||||
| TMsSqlConnection
|
| TMsSqlConnection
|
||||||
| TCamundaConnection;
|
| TCamundaConnection
|
||||||
|
| TWindmillConnection;
|
||||||
|
|
||||||
export type TAvailableAppConnection = Pick<TAppConnection, "name" | "id">;
|
export type TAvailableAppConnection = Pick<TAppConnection, "name" | "id">;
|
||||||
|
|
||||||
@@ -78,4 +81,5 @@ export type TAppConnectionMap = {
|
|||||||
[AppConnection.Postgres]: TPostgresConnection;
|
[AppConnection.Postgres]: TPostgresConnection;
|
||||||
[AppConnection.MsSql]: TMsSqlConnection;
|
[AppConnection.MsSql]: TMsSqlConnection;
|
||||||
[AppConnection.Camunda]: TCamundaConnection;
|
[AppConnection.Camunda]: TCamundaConnection;
|
||||||
|
[AppConnection.Windmill]: TWindmillConnection;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import { TRootAppConnection } from "@app/hooks/api/appConnections/types/root-connection";
|
||||||
|
|
||||||
|
export enum WindmillConnectionMethod {
|
||||||
|
AccessToken = "access-token"
|
||||||
|
}
|
||||||
|
|
||||||
|
export type TWindmillConnection = TRootAppConnection & { app: AppConnection.Windmill } & {
|
||||||
|
method: WindmillConnectionMethod.AccessToken;
|
||||||
|
credentials: {
|
||||||
|
accessToken: string;
|
||||||
|
instanceUrl?: string;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,2 @@
|
|||||||
|
export * from "./queries";
|
||||||
|
export * from "./types";
|
||||||
@@ -0,0 +1,37 @@
|
|||||||
|
import { useQuery, UseQueryOptions } from "@tanstack/react-query";
|
||||||
|
|
||||||
|
import { apiRequest } from "@app/config/request";
|
||||||
|
|
||||||
|
import { appConnectionKeys } from "../queries";
|
||||||
|
import { TWindmillWorkspace } from "./types";
|
||||||
|
|
||||||
|
const windmillConnectionKeys = {
|
||||||
|
all: [...appConnectionKeys.all, "windmill"] as const,
|
||||||
|
listWorkspaces: (connectionId: string) =>
|
||||||
|
[...windmillConnectionKeys.all, "workspaces", connectionId] as const
|
||||||
|
};
|
||||||
|
|
||||||
|
export const useWindmillConnectionListWorkspaces = (
|
||||||
|
connectionId: string,
|
||||||
|
options?: Omit<
|
||||||
|
UseQueryOptions<
|
||||||
|
TWindmillWorkspace[],
|
||||||
|
unknown,
|
||||||
|
TWindmillWorkspace[],
|
||||||
|
ReturnType<typeof windmillConnectionKeys.listWorkspaces>
|
||||||
|
>,
|
||||||
|
"queryKey" | "queryFn"
|
||||||
|
>
|
||||||
|
) => {
|
||||||
|
return useQuery({
|
||||||
|
queryKey: windmillConnectionKeys.listWorkspaces(connectionId),
|
||||||
|
queryFn: async () => {
|
||||||
|
const { data } = await apiRequest.get<TWindmillWorkspace[]>(
|
||||||
|
`/api/v1/app-connections/windmill/${connectionId}/workspaces`
|
||||||
|
);
|
||||||
|
|
||||||
|
return data;
|
||||||
|
},
|
||||||
|
...options
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
export type TWindmillWorkspace = {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
};
|
||||||
@@ -9,7 +9,8 @@ export enum SecretSync {
|
|||||||
Humanitec = "humanitec",
|
Humanitec = "humanitec",
|
||||||
TerraformCloud = "terraform-cloud",
|
TerraformCloud = "terraform-cloud",
|
||||||
Camunda = "camunda",
|
Camunda = "camunda",
|
||||||
Vercel = "vercel"
|
Vercel = "vercel",
|
||||||
|
Windmill = "windmill"
|
||||||
}
|
}
|
||||||
|
|
||||||
export enum SecretSyncStatus {
|
export enum SecretSyncStatus {
|
||||||
|
|||||||
@@ -1,17 +1,18 @@
|
|||||||
import { SecretSync, SecretSyncImportBehavior } from "@app/hooks/api/secretSyncs";
|
import { SecretSync, SecretSyncImportBehavior } from "@app/hooks/api/secretSyncs";
|
||||||
import { TAwsParameterStoreSync } from "@app/hooks/api/secretSyncs/types/aws-parameter-store-sync";
|
|
||||||
import { TDatabricksSync } from "@app/hooks/api/secretSyncs/types/databricks-sync";
|
|
||||||
import { TGitHubSync } from "@app/hooks/api/secretSyncs/types/github-sync";
|
|
||||||
import { DiscriminativePick } from "@app/types";
|
import { DiscriminativePick } from "@app/types";
|
||||||
|
|
||||||
|
import { TAwsParameterStoreSync } from "./aws-parameter-store-sync";
|
||||||
import { TAwsSecretsManagerSync } from "./aws-secrets-manager-sync";
|
import { TAwsSecretsManagerSync } from "./aws-secrets-manager-sync";
|
||||||
import { TAzureAppConfigurationSync } from "./azure-app-configuration-sync";
|
import { TAzureAppConfigurationSync } from "./azure-app-configuration-sync";
|
||||||
import { TAzureKeyVaultSync } from "./azure-key-vault-sync";
|
import { TAzureKeyVaultSync } from "./azure-key-vault-sync";
|
||||||
import { TCamundaSync } from "./camunda-sync";
|
import { TCamundaSync } from "./camunda-sync";
|
||||||
|
import { TDatabricksSync } from "./databricks-sync";
|
||||||
import { TGcpSync } from "./gcp-sync";
|
import { TGcpSync } from "./gcp-sync";
|
||||||
|
import { TGitHubSync } from "./github-sync";
|
||||||
import { THumanitecSync } from "./humanitec-sync";
|
import { THumanitecSync } from "./humanitec-sync";
|
||||||
import { TTerraformCloudSync } from "./terraform-cloud-sync";
|
import { TTerraformCloudSync } from "./terraform-cloud-sync";
|
||||||
import { TVercelSync } from "./vercel-sync";
|
import { TVercelSync } from "./vercel-sync";
|
||||||
|
import { TWindmillSync } from "./windmill-sync";
|
||||||
|
|
||||||
export type TSecretSyncOption = {
|
export type TSecretSyncOption = {
|
||||||
name: string;
|
name: string;
|
||||||
@@ -30,7 +31,8 @@ export type TSecretSync =
|
|||||||
| THumanitecSync
|
| THumanitecSync
|
||||||
| TTerraformCloudSync
|
| TTerraformCloudSync
|
||||||
| TCamundaSync
|
| TCamundaSync
|
||||||
| TVercelSync;
|
| TVercelSync
|
||||||
|
| TWindmillSync;
|
||||||
|
|
||||||
export type TListSecretSyncs = { secretSyncs: TSecretSync[] };
|
export type TListSecretSyncs = { secretSyncs: TSecretSync[] };
|
||||||
|
|
||||||
|
|||||||
@@ -0,0 +1,16 @@
|
|||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
import { SecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
|
import { TRootSecretSync } from "@app/hooks/api/secretSyncs/types/root-sync";
|
||||||
|
|
||||||
|
export type TWindmillSync = TRootSecretSync & {
|
||||||
|
destination: SecretSync.Windmill;
|
||||||
|
destinationConfig: {
|
||||||
|
workspace: string;
|
||||||
|
path: string;
|
||||||
|
};
|
||||||
|
connection: {
|
||||||
|
app: AppConnection.Windmill;
|
||||||
|
name: string;
|
||||||
|
id: string;
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -21,6 +21,7 @@ import { MsSqlConnectionForm } from "./MsSqlConnectionForm";
|
|||||||
import { PostgresConnectionForm } from "./PostgresConnectionForm";
|
import { PostgresConnectionForm } from "./PostgresConnectionForm";
|
||||||
import { TerraformCloudConnectionForm } from "./TerraformCloudConnectionForm";
|
import { TerraformCloudConnectionForm } from "./TerraformCloudConnectionForm";
|
||||||
import { VercelConnectionForm } from "./VercelConnectionForm";
|
import { VercelConnectionForm } from "./VercelConnectionForm";
|
||||||
|
import { WindmillConnectionForm } from "./WindmillConnectionForm";
|
||||||
|
|
||||||
type FormProps = {
|
type FormProps = {
|
||||||
onComplete: (appConnection: TAppConnection) => void;
|
onComplete: (appConnection: TAppConnection) => void;
|
||||||
@@ -83,6 +84,8 @@ const CreateForm = ({ app, onComplete }: CreateFormProps) => {
|
|||||||
return <MsSqlConnectionForm onSubmit={onSubmit} />;
|
return <MsSqlConnectionForm onSubmit={onSubmit} />;
|
||||||
case AppConnection.Camunda:
|
case AppConnection.Camunda:
|
||||||
return <CamundaConnectionForm onSubmit={onSubmit} />;
|
return <CamundaConnectionForm onSubmit={onSubmit} />;
|
||||||
|
case AppConnection.Windmill:
|
||||||
|
return <WindmillConnectionForm onSubmit={onSubmit} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App ${app}`);
|
throw new Error(`Unhandled App ${app}`);
|
||||||
}
|
}
|
||||||
@@ -143,6 +146,8 @@ const UpdateForm = ({ appConnection, onComplete }: UpdateFormProps) => {
|
|||||||
return <MsSqlConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
return <MsSqlConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
case AppConnection.Camunda:
|
case AppConnection.Camunda:
|
||||||
return <CamundaConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
return <CamundaConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
|
case AppConnection.Windmill:
|
||||||
|
return <WindmillConnectionForm onSubmit={onSubmit} appConnection={appConnection} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`);
|
throw new Error(`Unhandled App ${(appConnection as TAppConnection).app}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,158 @@
|
|||||||
|
import { Controller, FormProvider, useForm } from "react-hook-form";
|
||||||
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import {
|
||||||
|
Button,
|
||||||
|
FormControl,
|
||||||
|
Input,
|
||||||
|
ModalClose,
|
||||||
|
SecretInput,
|
||||||
|
Select,
|
||||||
|
SelectItem
|
||||||
|
} from "@app/components/v2";
|
||||||
|
import { APP_CONNECTION_MAP, getAppConnectionMethodDetails } from "@app/helpers/appConnections";
|
||||||
|
import { TWindmillConnection, WindmillConnectionMethod } from "@app/hooks/api/appConnections";
|
||||||
|
import { AppConnection } from "@app/hooks/api/appConnections/enums";
|
||||||
|
|
||||||
|
import {
|
||||||
|
genericAppConnectionFieldsSchema,
|
||||||
|
GenericAppConnectionsFields
|
||||||
|
} from "./GenericAppConnectionFields";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
appConnection?: TWindmillConnection;
|
||||||
|
onSubmit: (formData: FormData) => void;
|
||||||
|
};
|
||||||
|
|
||||||
|
const rootSchema = genericAppConnectionFieldsSchema.extend({
|
||||||
|
app: z.literal(AppConnection.Windmill)
|
||||||
|
});
|
||||||
|
|
||||||
|
const formSchema = z.discriminatedUnion("method", [
|
||||||
|
rootSchema.extend({
|
||||||
|
method: z.literal(WindmillConnectionMethod.AccessToken),
|
||||||
|
credentials: z.object({
|
||||||
|
accessToken: z.string().trim().min(1, "Access Token required"),
|
||||||
|
instanceUrl: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.transform((value) => value || undefined)
|
||||||
|
.refine((value) => (!value ? true : z.string().url().safeParse(value).success), {
|
||||||
|
message: "Invalid instance URL"
|
||||||
|
})
|
||||||
|
.optional()
|
||||||
|
})
|
||||||
|
})
|
||||||
|
]);
|
||||||
|
|
||||||
|
type FormData = z.infer<typeof formSchema>;
|
||||||
|
|
||||||
|
export const WindmillConnectionForm = ({ appConnection, onSubmit }: Props) => {
|
||||||
|
const isUpdate = Boolean(appConnection);
|
||||||
|
|
||||||
|
const form = useForm<FormData>({
|
||||||
|
resolver: zodResolver(formSchema),
|
||||||
|
defaultValues: appConnection ?? {
|
||||||
|
app: AppConnection.Windmill,
|
||||||
|
method: WindmillConnectionMethod.AccessToken
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
const {
|
||||||
|
handleSubmit,
|
||||||
|
control,
|
||||||
|
formState: { isSubmitting, isDirty }
|
||||||
|
} = form;
|
||||||
|
|
||||||
|
return (
|
||||||
|
<FormProvider {...form}>
|
||||||
|
<form onSubmit={handleSubmit(onSubmit)}>
|
||||||
|
{!isUpdate && <GenericAppConnectionsFields />}
|
||||||
|
<Controller
|
||||||
|
name="method"
|
||||||
|
control={control}
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
tooltipText={`The method you would like to use to connect with ${
|
||||||
|
APP_CONNECTION_MAP[AppConnection.Windmill].name
|
||||||
|
}. This field cannot be changed after creation.`}
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Method"
|
||||||
|
>
|
||||||
|
<Select
|
||||||
|
isDisabled={isUpdate}
|
||||||
|
value={value}
|
||||||
|
onValueChange={(val) => onChange(val)}
|
||||||
|
className="w-full border border-mineshaft-500"
|
||||||
|
position="popper"
|
||||||
|
dropdownContainerClassName="max-w-none"
|
||||||
|
>
|
||||||
|
{Object.values(WindmillConnectionMethod).map((method) => {
|
||||||
|
return (
|
||||||
|
<SelectItem value={method} key={method}>
|
||||||
|
{getAppConnectionMethodDetails(method).name}{" "}
|
||||||
|
</SelectItem>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</Select>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
name="credentials.instanceUrl"
|
||||||
|
control={control}
|
||||||
|
shouldUnregister
|
||||||
|
render={({ field, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Instance URL"
|
||||||
|
isOptional
|
||||||
|
tooltipClassName="max-w-sm"
|
||||||
|
tooltipText="Will default to Windmill Cloud if not specified."
|
||||||
|
>
|
||||||
|
<Input {...field} placeholder="https://app.windmill.dev" />
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<Controller
|
||||||
|
name="credentials.accessToken"
|
||||||
|
control={control}
|
||||||
|
shouldUnregister
|
||||||
|
render={({ field: { value, onChange }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error?.message)}
|
||||||
|
label="Access Token"
|
||||||
|
>
|
||||||
|
<SecretInput
|
||||||
|
containerClassName="text-gray-400 group-focus-within:!border-primary-400/50 border border-mineshaft-500 bg-mineshaft-900 px-2.5 py-1.5"
|
||||||
|
value={value}
|
||||||
|
onChange={(e) => onChange(e.target.value)}
|
||||||
|
/>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
|
<div className="mt-8 flex items-center">
|
||||||
|
<Button
|
||||||
|
className="mr-4"
|
||||||
|
size="sm"
|
||||||
|
type="submit"
|
||||||
|
colorSchema="secondary"
|
||||||
|
isLoading={isSubmitting}
|
||||||
|
isDisabled={isSubmitting || !isDirty}
|
||||||
|
>
|
||||||
|
{isUpdate ? "Update Credentials" : "Connect to Windmill"}
|
||||||
|
</Button>
|
||||||
|
<ModalClose asChild>
|
||||||
|
<Button colorSchema="secondary" variant="plain">
|
||||||
|
Cancel
|
||||||
|
</Button>
|
||||||
|
</ModalClose>
|
||||||
|
</div>
|
||||||
|
</form>
|
||||||
|
</FormProvider>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -11,6 +11,7 @@ import { GitHubSyncDestinationCol } from "./GitHubSyncDestinationCol";
|
|||||||
import { HumanitecSyncDestinationCol } from "./HumanitecSyncDestinationCol";
|
import { HumanitecSyncDestinationCol } from "./HumanitecSyncDestinationCol";
|
||||||
import { TerraformCloudSyncDestinationCol } from "./TerraformCloudSyncDestinationCol";
|
import { TerraformCloudSyncDestinationCol } from "./TerraformCloudSyncDestinationCol";
|
||||||
import { VercelSyncDestinationCol } from "./VercelSyncDestinationCol";
|
import { VercelSyncDestinationCol } from "./VercelSyncDestinationCol";
|
||||||
|
import { WindmillSyncDestinationCol } from "./WindmillSyncDestinationCol";
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
secretSync: TSecretSync;
|
secretSync: TSecretSync;
|
||||||
@@ -40,6 +41,8 @@ export const SecretSyncDestinationCol = ({ secretSync }: Props) => {
|
|||||||
return <CamundaSyncDestinationCol secretSync={secretSync} />;
|
return <CamundaSyncDestinationCol secretSync={secretSync} />;
|
||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
return <VercelSyncDestinationCol secretSync={secretSync} />;
|
return <VercelSyncDestinationCol secretSync={secretSync} />;
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
return <WindmillSyncDestinationCol secretSync={secretSync} />;
|
||||||
default:
|
default:
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`Unhandled Secret Sync Destination Col: ${(secretSync as TSecretSync).destination}`
|
`Unhandled Secret Sync Destination Col: ${(secretSync as TSecretSync).destination}`
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
import { TWindmillSync } from "@app/hooks/api/secretSyncs/types/windmill-sync";
|
||||||
|
|
||||||
|
import { getSecretSyncDestinationColValues } from "../helpers";
|
||||||
|
import { SecretSyncTableCell } from "../SecretSyncTableCell";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
secretSync: TWindmillSync;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const WindmillSyncDestinationCol = ({ secretSync }: Props) => {
|
||||||
|
const { primaryText, secondaryText } = getSecretSyncDestinationColValues(secretSync);
|
||||||
|
|
||||||
|
return <SecretSyncTableCell primaryText={primaryText} secondaryText={secondaryText} />;
|
||||||
|
};
|
||||||
@@ -90,6 +90,10 @@ export const getSecretSyncDestinationColValues = (secretSync: TSecretSync) => {
|
|||||||
primaryText = destinationConfig.appName || destinationConfig.app;
|
primaryText = destinationConfig.appName || destinationConfig.app;
|
||||||
secondaryText = destinationConfig.env;
|
secondaryText = destinationConfig.env;
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
primaryText = destinationConfig.workspace;
|
||||||
|
secondaryText = destinationConfig.path;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Col Values ${destination}`);
|
throw new Error(`Unhandled Destination Col Values ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,18 +9,19 @@ import { ProjectPermissionSub } from "@app/context";
|
|||||||
import { ProjectPermissionSecretSyncActions } from "@app/context/ProjectPermissionContext/types";
|
import { ProjectPermissionSecretSyncActions } from "@app/context/ProjectPermissionContext/types";
|
||||||
import { APP_CONNECTION_MAP } from "@app/helpers/appConnections";
|
import { APP_CONNECTION_MAP } from "@app/helpers/appConnections";
|
||||||
import { SecretSync, TSecretSync } from "@app/hooks/api/secretSyncs";
|
import { SecretSync, TSecretSync } from "@app/hooks/api/secretSyncs";
|
||||||
import { AwsParameterStoreSyncDestinationSection } from "@app/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/AwsParameterStoreSyncDestinationSection";
|
|
||||||
import { AwsSecretsManagerSyncDestinationSection } from "@app/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/AwsSecretsManagerSyncDestinationSection";
|
|
||||||
import { DatabricksSyncDestinationSection } from "@app/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/DatabricksSyncDestinationSection";
|
|
||||||
import { GitHubSyncDestinationSection } from "@app/pages/secret-manager/SecretSyncDetailsByIDPage/components/SecretSyncDestinationSection/GitHubSyncDestinationSection";
|
|
||||||
|
|
||||||
|
import { AwsParameterStoreSyncDestinationSection } from "./AwsParameterStoreSyncDestinationSection";
|
||||||
|
import { AwsSecretsManagerSyncDestinationSection } from "./AwsSecretsManagerSyncDestinationSection";
|
||||||
import { AzureAppConfigurationSyncDestinationSection } from "./AzureAppConfigurationSyncDestinationSection";
|
import { AzureAppConfigurationSyncDestinationSection } from "./AzureAppConfigurationSyncDestinationSection";
|
||||||
import { AzureKeyVaultSyncDestinationSection } from "./AzureKeyVaultSyncDestinationSection";
|
import { AzureKeyVaultSyncDestinationSection } from "./AzureKeyVaultSyncDestinationSection";
|
||||||
import { CamundaSyncDestinationSection } from "./CamundaSyncDestinationSection";
|
import { CamundaSyncDestinationSection } from "./CamundaSyncDestinationSection";
|
||||||
|
import { DatabricksSyncDestinationSection } from "./DatabricksSyncDestinationSection";
|
||||||
import { GcpSyncDestinationSection } from "./GcpSyncDestinationSection";
|
import { GcpSyncDestinationSection } from "./GcpSyncDestinationSection";
|
||||||
|
import { GitHubSyncDestinationSection } from "./GitHubSyncDestinationSection";
|
||||||
import { HumanitecSyncDestinationSection } from "./HumanitecSyncDestinationSection";
|
import { HumanitecSyncDestinationSection } from "./HumanitecSyncDestinationSection";
|
||||||
import { TerraformCloudSyncDestinationSection } from "./TerraformCloudSyncDestinationSection";
|
import { TerraformCloudSyncDestinationSection } from "./TerraformCloudSyncDestinationSection";
|
||||||
import { VercelSyncDestinationSection } from "./VercelSyncDestinationSection";
|
import { VercelSyncDestinationSection } from "./VercelSyncDestinationSection";
|
||||||
|
import { WindmillSyncDestinationSection } from "./WindmillSyncDestinationSection";
|
||||||
|
|
||||||
type Props = {
|
type Props = {
|
||||||
secretSync: TSecretSync;
|
secretSync: TSecretSync;
|
||||||
@@ -69,6 +70,9 @@ export const SecretSyncDestinationSection = ({ secretSync, onEditDestination }:
|
|||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
DestinationComponents = <VercelSyncDestinationSection secretSync={secretSync} />;
|
DestinationComponents = <VercelSyncDestinationSection secretSync={secretSync} />;
|
||||||
break;
|
break;
|
||||||
|
case SecretSync.Windmill:
|
||||||
|
DestinationComponents = <WindmillSyncDestinationSection secretSync={secretSync} />;
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
throw new Error(`Unhandled Destination Section components: ${destination}`);
|
throw new Error(`Unhandled Destination Section components: ${destination}`);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,19 @@
|
|||||||
|
import { GenericFieldLabel } from "@app/components/secret-syncs";
|
||||||
|
import { TWindmillSync } from "@app/hooks/api/secretSyncs/types/windmill-sync";
|
||||||
|
|
||||||
|
type Props = {
|
||||||
|
secretSync: TWindmillSync;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const WindmillSyncDestinationSection = ({ secretSync }: Props) => {
|
||||||
|
const {
|
||||||
|
destinationConfig: { path, workspace }
|
||||||
|
} = secretSync;
|
||||||
|
|
||||||
|
return (
|
||||||
|
<>
|
||||||
|
<GenericFieldLabel label="Workspace">{workspace}</GenericFieldLabel>
|
||||||
|
<GenericFieldLabel label="Path">{path}</GenericFieldLabel>
|
||||||
|
</>
|
||||||
|
);
|
||||||
|
};
|
||||||
@@ -51,6 +51,7 @@ export const SecretSyncOptionsSection = ({ secretSync, onEditOptions }: Props) =
|
|||||||
case SecretSync.TerraformCloud:
|
case SecretSync.TerraformCloud:
|
||||||
case SecretSync.Camunda:
|
case SecretSync.Camunda:
|
||||||
case SecretSync.Vercel:
|
case SecretSync.Vercel:
|
||||||
|
case SecretSync.Windmill:
|
||||||
AdditionalSyncOptionsComponent = null;
|
AdditionalSyncOptionsComponent = null;
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
|
|||||||