Improvements to cert-syncs

This commit is contained in:
Carlos Monastyrski
2025-09-22 11:45:45 -03:00
parent 27dbe5b013
commit 3587fbf98b
26 changed files with 180 additions and 190 deletions

View File

@@ -130,11 +130,10 @@ export const CreatePkiSyncForm = ({ destination, onComplete, onCancel }: Props)
Certificate Sync Behavior
</div>
<p className="mt-1 text-sm text-bunker-200">
Certificate Syncs manage certificates that are prefixed with &quot;Infisical-&quot; in
the destination. Only certificates managed by Infisical will be affected during sync
operations. Certificates not created or managed by Infisical will remain untouched, and
changes made to Infisical-managed certificates directly in the destination service may
be overwritten by future syncs.
Only certificates managed by Infisical will be affected during sync operations.
Certificates not created or managed by Infisical will remain untouched, and changes made
to Infisical-managed certificates directly in the destination service may be overwritten
by future syncs.
</p>
</div>
<div className="mt-4 flex gap-4">

View File

@@ -104,8 +104,8 @@ export const PkiSyncOptionsFields = ({ destination }: Props) => {
tooltipText={
<div className="flex flex-col gap-3">
<span>
When a certificate is synced, values will be injected into the certificate name
schema before it reaches the destination. This is useful for organization.
When a certificate is synced, the certificate name schema will be applied before
it reaches the destination.
</span>
<div className="flex flex-col">
@@ -114,10 +114,6 @@ export const PkiSyncOptionsFields = ({ destination }: Props) => {
<li>
<code>{"{{certificateId}}"}</code> - The unique ID of the certificate
</li>
<li>
<code>{"{{environment}}"}</code> - The environment which the certificate is in
(e.g. dev, staging, prod)
</li>
</ul>
</div>
{syncOption?.forbiddenCharacters && syncOption.forbiddenCharacters.length > 0 && (
@@ -129,11 +125,6 @@ export const PkiSyncOptionsFields = ({ destination }: Props) => {
The following characters are not allowed:{" "}
{syncOption.forbiddenCharacters.split("").join(" ")}
</div>
{syncOption.allowedCharacterPattern && (
<div className="mt-1 text-xs text-bunker-300">
Only alphanumeric characters and hyphens are allowed (a-z, A-Z, 0-9, -)
</div>
)}
</div>
)}
</div>
@@ -142,7 +133,7 @@ export const PkiSyncOptionsFields = ({ destination }: Props) => {
isOptional
errorText={error?.message}
label="Certificate Name Schema"
helperText="Infisical strongly advises setting a Certificate Name Schema to ensure that Infisical only manages the specific certificates you intend, keeping everything else untouched."
helperText="Infisical strongly advises setting a Certificate Name Schema to ensure that Infisical only manages the specific certificates you intend to manage, keeping everything else untouched."
>
<Input
value={value || ""}

View File

@@ -97,7 +97,9 @@ export const useTriggerPkiSyncRemoveCertificates = () => {
const queryClient = useQueryClient();
return useMutation({
mutationFn: async ({ syncId, destination }: TTriggerPkiSyncRemoveCertificatesDTO) => {
const { data } = await apiRequest.post(`/api/v1/pki/syncs/${destination}/${syncId}/remove`);
const { data } = await apiRequest.post(
`/api/v1/pki/syncs/${destination}/${syncId}/remove-certificates`
);
return data;
},

View File

@@ -8,8 +8,7 @@ type Props = {
type:
| ProjectPermissionSub.SecretFolders
| ProjectPermissionSub.SecretImports
| ProjectPermissionSub.SecretRotation
| ProjectPermissionSub.PkiSyncs;
| ProjectPermissionSub.SecretRotation;
};
export const GeneralPermissionConditions = ({ position = 0, isDisabled, type }: Props) => {

View File

@@ -0,0 +1,19 @@
import { ProjectPermissionSub } from "@app/context/ProjectPermissionContext/types";
import { ConditionsFields } from "./ConditionsFields";
type Props = {
position?: number;
isDisabled?: boolean;
};
export const PkiSyncPermissionConditions = ({ position = 0, isDisabled }: Props) => {
return (
<ConditionsFields
isDisabled={isDisabled}
subject={ProjectPermissionSub.PkiSyncs}
position={position}
selectOptions={[{ value: "subscriberName", label: "Subscriber Name" }]}
/>
);
};

View File

@@ -23,6 +23,7 @@ import { GeneralPermissionPolicies } from "./GeneralPermissionPolicies";
import { IdentityManagementPermissionConditions } from "./IdentityManagementPermissionConditions";
import { PermissionEmptyState } from "./PermissionEmptyState";
import { PkiSubscriberPermissionConditions } from "./PkiSubscriberPermissionConditions";
import { PkiSyncPermissionConditions } from "./PkiSyncPermissionConditions";
import { PkiTemplatePermissionConditions } from "./PkiTemplatePermissionConditions";
import {
EXCLUDED_PERMISSION_SUBS,
@@ -74,6 +75,10 @@ export const renderConditionalComponents = (
return <SecretSyncPermissionConditions isDisabled={isDisabled} />;
}
if (subject === ProjectPermissionSub.PkiSyncs) {
return <PkiSyncPermissionConditions isDisabled={isDisabled} />;
}
if (subject === ProjectPermissionSub.SecretEvents) {
return <SecretEventPermissionConditions isDisabled={isDisabled} />;
}