mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 08:26:00 +00:00
feat: npm CLI
This commit is contained in:
@@ -1,12 +1,15 @@
|
|||||||
name: Build and release CLI
|
name: Build and release CLI
|
||||||
|
|
||||||
on:
|
on:
|
||||||
|
pull_request:
|
||||||
|
types: [opened, synchronize]
|
||||||
|
|
||||||
workflow_dispatch:
|
workflow_dispatch:
|
||||||
|
|
||||||
push:
|
# push:
|
||||||
# run only against tags
|
# run only against tags
|
||||||
tags:
|
# tags:
|
||||||
- "infisical-cli/v*.*.*"
|
# - "infisical-cli/v*.*.*"
|
||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: write
|
contents: write
|
||||||
@@ -26,6 +29,63 @@ jobs:
|
|||||||
CLI_TESTS_USER_PASSWORD: ${{ secrets.CLI_TESTS_USER_PASSWORD }}
|
CLI_TESTS_USER_PASSWORD: ${{ secrets.CLI_TESTS_USER_PASSWORD }}
|
||||||
CLI_TESTS_INFISICAL_VAULT_FILE_PASSPHRASE: ${{ secrets.CLI_TESTS_INFISICAL_VAULT_FILE_PASSPHRASE }}
|
CLI_TESTS_INFISICAL_VAULT_FILE_PASSPHRASE: ${{ secrets.CLI_TESTS_INFISICAL_VAULT_FILE_PASSPHRASE }}
|
||||||
|
|
||||||
|
npm-release:
|
||||||
|
runs-on: ubuntu-20.04
|
||||||
|
env:
|
||||||
|
working-directory: ./npm
|
||||||
|
CLI_VERSION: 1.1.1
|
||||||
|
needs:
|
||||||
|
- cli-integration-tests
|
||||||
|
# - goreleaser
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v3
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
# - name: Extract version
|
||||||
|
# run: |
|
||||||
|
# VERSION=$(echo ${{ github.ref_name }} | sed 's/infisical-cli\/v//')
|
||||||
|
# echo "Version extracted: $VERSION"
|
||||||
|
# echo "CLI_VERSION=$VERSION" >> $GITHUB_ENV
|
||||||
|
|
||||||
|
- name: Print version
|
||||||
|
run: echo ${{ env.CLI_VERSION }}
|
||||||
|
|
||||||
|
- name: Setup Node
|
||||||
|
uses: actions/setup-node@8f152de45cc393bb48ce5d89d36b731f54556e65 # v4.0.0
|
||||||
|
with:
|
||||||
|
node-version: 20
|
||||||
|
cache: "npm"
|
||||||
|
cache-dependency-path: ./npm/package-lock.json
|
||||||
|
- name: Install dependencies
|
||||||
|
working-directory: ${{ env.working-directory }}
|
||||||
|
run: npm install
|
||||||
|
|
||||||
|
- name: Set NPM version
|
||||||
|
working-directory: ${{ env.working-directory }}
|
||||||
|
run: npm version ${{ env.CLI_VERSION }} --allow-same-version --no-git-tag-version
|
||||||
|
|
||||||
|
- name: Setup NPM
|
||||||
|
working-directory: ${{ env.working-directory }}
|
||||||
|
run: |
|
||||||
|
echo 'registry="https://registry.npmjs.org/"' > ./.npmrc
|
||||||
|
echo "//registry.npmjs.org/:_authToken=$NPM_TOKEN" >> ./.npmrc
|
||||||
|
|
||||||
|
echo 'registry="https://registry.npmjs.org/"' > ~/.npmrc
|
||||||
|
echo "//registry.npmjs.org/:_authToken=$NPM_TOKEN" >> ~/.npmrc
|
||||||
|
env:
|
||||||
|
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||||
|
|
||||||
|
- name: Pack NPM
|
||||||
|
working-directory: ${{ env.working-directory }}
|
||||||
|
run: npm pack
|
||||||
|
|
||||||
|
- name: Publish NPM
|
||||||
|
run: npm publish --tarball=./infisical-sdk-${{github.ref_name}} --access public --registry=https://registry.npmjs.org/ --dry-run
|
||||||
|
env:
|
||||||
|
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||||
|
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
|
||||||
|
|
||||||
goreleaser:
|
goreleaser:
|
||||||
runs-on: ubuntu-20.04
|
runs-on: ubuntu-20.04
|
||||||
needs: [cli-integration-tests]
|
needs: [cli-integration-tests]
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
{
|
||||||
|
"env": {
|
||||||
|
"es6": true,
|
||||||
|
"node": true
|
||||||
|
},
|
||||||
|
"parserOptions": {
|
||||||
|
"ecmaVersion": "latest"
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,45 @@
|
|||||||
|
<h1 align="center">Infisical</h1>
|
||||||
|
<p align="center">
|
||||||
|
<p align="center"><b>The open-source secret management platform</b>: Sync secrets/configs across your team/infrastructure and prevent secret leaks.</p>
|
||||||
|
</p>
|
||||||
|
|
||||||
|
<h4 align="center">
|
||||||
|
<a href="https://infisical.com/slack">Slack</a> |
|
||||||
|
<a href="https://infisical.com/">Infisical Cloud</a> |
|
||||||
|
<a href="https://infisical.com/docs/self-hosting/overview">Self-Hosting</a> |
|
||||||
|
<a href="https://infisical.com/docs/documentation/getting-started/introduction">Docs</a> |
|
||||||
|
<a href="https://www.infisical.com">Website</a> |
|
||||||
|
<a href="https://infisical.com/careers">Hiring (Remote/SF)</a>
|
||||||
|
</h4>
|
||||||
|
|
||||||
|
|
||||||
|
<h4 align="center">
|
||||||
|
<a href="https://github.com/Infisical/infisical/blob/main/LICENSE">
|
||||||
|
<img src="https://img.shields.io/badge/license-MIT-blue.svg" alt="Infisical is released under the MIT license." />
|
||||||
|
</a>
|
||||||
|
<a href="https://github.com/infisical/infisical/blob/main/CONTRIBUTING.md">
|
||||||
|
<img src="https://img.shields.io/badge/PRs-Welcome-brightgreen" alt="PRs welcome!" />
|
||||||
|
</a>
|
||||||
|
<a href="https://github.com/Infisical/infisical/issues">
|
||||||
|
<img src="https://img.shields.io/github/commit-activity/m/infisical/infisical" alt="git commit activity" />
|
||||||
|
</a>
|
||||||
|
<a href="https://cloudsmith.io/~infisical/repos/">
|
||||||
|
<img src="https://img.shields.io/badge/Downloads-6.95M-orange" alt="Cloudsmith downloads" />
|
||||||
|
</a>
|
||||||
|
<a href="https://infisical.com/slack">
|
||||||
|
<img src="https://img.shields.io/badge/chat-on%20Slack-blueviolet" alt="Slack community channel" />
|
||||||
|
</a>
|
||||||
|
<a href="https://twitter.com/infisical">
|
||||||
|
<img src="https://img.shields.io/twitter/follow/infisical?label=Follow" alt="Infisical Twitter" />
|
||||||
|
</a>
|
||||||
|
</h4>
|
||||||
|
|
||||||
|
## Introduction
|
||||||
|
|
||||||
|
**[Infisical](https://infisical.com)** is the open source secret management platform that teams use to centralize their application configuration and secrets like API keys and database credentials as well as manage their internal PKI.
|
||||||
|
|
||||||
|
We're on a mission to make security tooling more accessible to everyone, not just security teams, and that means redesigning the entire developer experience from ground up.
|
||||||
|
|
||||||
|
## [CLI Documentation](https://infisical.com/docs/cli/usage)
|
||||||
|
|
||||||
|
|
||||||
Generated
+4
-4
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "infisical-cli",
|
"name": "@infisical/cli",
|
||||||
"version": "0.14.2",
|
"version": "0.14.3",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "infisical-cli",
|
"name": "@infisical/cli",
|
||||||
"version": "0.14.2",
|
"version": "0.14.3",
|
||||||
"hasInstallScript": true,
|
"hasInstallScript": true,
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tar": "^6.2.0"
|
"tar": "^6.2.0"
|
||||||
|
|||||||
+14
-2
@@ -1,9 +1,21 @@
|
|||||||
{
|
{
|
||||||
"name": "infisical-cli",
|
"name": "@infisical/cli",
|
||||||
"version": "0.14.2",
|
"private": false,
|
||||||
|
"version": "0.0.0",
|
||||||
|
"keywords": [
|
||||||
|
"infisical",
|
||||||
|
"cli",
|
||||||
|
"command-line"
|
||||||
|
],
|
||||||
"bin": {
|
"bin": {
|
||||||
"infisical": "./bin/infisical"
|
"infisical": "./bin/infisical"
|
||||||
},
|
},
|
||||||
|
"repository": {
|
||||||
|
"type": "git",
|
||||||
|
"url": "https://github.com/Infisical/infisical.git"
|
||||||
|
},
|
||||||
|
"author": "Infisical Inc, <[email protected]>",
|
||||||
|
|
||||||
"scripts": {
|
"scripts": {
|
||||||
"postinstall": "node src/index.cjs"
|
"postinstall": "node src/index.cjs"
|
||||||
},
|
},
|
||||||
|
|||||||
+64
-67
@@ -1,4 +1,4 @@
|
|||||||
const { execSync } = require("child_process");
|
const childProcess = require("child_process");
|
||||||
const fs = require("fs");
|
const fs = require("fs");
|
||||||
const stream = require("node:stream");
|
const stream = require("node:stream");
|
||||||
const tar = require("tar");
|
const tar = require("tar");
|
||||||
@@ -10,79 +10,76 @@ const supportedPlatforms = ["linux", "darwin", "win32", "freebsd"];
|
|||||||
const outputDir = "bin";
|
const outputDir = "bin";
|
||||||
|
|
||||||
const getPlatform = () => {
|
const getPlatform = () => {
|
||||||
const platform = process.platform;
|
const platform = process.platform;
|
||||||
if (!supportedPlatforms.includes(platform)) {
|
if (!supportedPlatforms.includes(platform)) {
|
||||||
console.error(
|
console.error("Your platform doesn't seem to be of type darwin, linux or windows");
|
||||||
"Your platform doesn't seem to be of type darwin, linux or windows"
|
process.exit(1);
|
||||||
);
|
}
|
||||||
process.exit(1);
|
return platform;
|
||||||
}
|
|
||||||
return platform;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
const getArchitecture = () => {
|
const getArchitecture = () => {
|
||||||
const architecture = execSync("uname -m").toString().trim();
|
const architecture = childProcess.execSync("uname -m").toString().trim();
|
||||||
let arch = "";
|
let arch = "";
|
||||||
if (architecture === "x86_64" || architecture === "amd64") {
|
if (architecture === "x86_64" || architecture === "amd64") {
|
||||||
arch = "amd64";
|
arch = "amd64";
|
||||||
} else if (architecture === "arm64" || architecture === "aarch64") {
|
} else if (architecture === "arm64" || architecture === "aarch64") {
|
||||||
arch = "arm64";
|
arch = "arm64";
|
||||||
} else if (architecture.startsWith("armv5")) {
|
} else if (architecture.startsWith("armv5")) {
|
||||||
arch = "armv5";
|
arch = "armv5";
|
||||||
} else if (architecture.startsWith("armv6")) {
|
} else if (architecture.startsWith("armv6")) {
|
||||||
arch = "armv6";
|
arch = "armv6";
|
||||||
} else if (architecture.startsWith("armv7")) {
|
} else if (architecture.startsWith("armv7")) {
|
||||||
arch = "armv7";
|
arch = "armv7";
|
||||||
} else if (architecture === "i386" || architecture === "i686") {
|
} else if (architecture === "i386" || architecture === "i686") {
|
||||||
arch = "i386";
|
arch = "i386";
|
||||||
} else {
|
} else {
|
||||||
console.error(
|
console.error("Your architecture doesn't seem to be supported. Your architecture is", architecture);
|
||||||
"Your architecture doesn't seem to be supported. Your architecture is",
|
process.exit(1);
|
||||||
architecture
|
}
|
||||||
);
|
return arch;
|
||||||
process.exit(1);
|
|
||||||
}
|
|
||||||
return arch;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
function main() {
|
async function main() {
|
||||||
const PLATFORM = getPlatform();
|
const PLATFORM = getPlatform();
|
||||||
const ARCH = getArchitecture();
|
const ARCH = getArchitecture();
|
||||||
const NUMERIC_RELEASE_VERSION = packageJSON.version;
|
const NUMERIC_RELEASE_VERSION = packageJSON.version;
|
||||||
const LATEST_RELEASE_VERSION = `v${NUMERIC_RELEASE_VERSION}`;
|
const LATEST_RELEASE_VERSION = `v${NUMERIC_RELEASE_VERSION}`;
|
||||||
const downloadLink = `https://github.com/Infisical/infisical/releases/download/infisical-cli/${LATEST_RELEASE_VERSION}/infisical_${NUMERIC_RELEASE_VERSION}_${PLATFORM}_${ARCH}.tar.gz`;
|
const downloadLink = `https://github.com/Infisical/infisical/releases/download/infisical-cli/${LATEST_RELEASE_VERSION}/infisical_${NUMERIC_RELEASE_VERSION}_${PLATFORM}_${ARCH}.tar.gz`;
|
||||||
|
|
||||||
if (!fs.existsSync(outputDir)) {
|
// Ensure the output directory exists
|
||||||
fs.mkdirSync(outputDir);
|
if (!fs.existsSync(outputDir)) {
|
||||||
fetch(downloadLink, {
|
fs.mkdirSync(outputDir);
|
||||||
headers: {
|
}
|
||||||
Accept: "application/octet-stream",
|
|
||||||
},
|
|
||||||
})
|
|
||||||
.then(async (response) => {
|
|
||||||
if (!response.ok) {
|
|
||||||
throw new Error(
|
|
||||||
`Failed to fetch: ${response.status} - ${response.statusText}`
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
return new Promise((resolve, reject) => {
|
// Download the latest CLI binary
|
||||||
const outStream = stream.Readable.fromWeb(response.body)
|
try {
|
||||||
.pipe(zlib.createGunzip())
|
const response = await fetch(downloadLink, {
|
||||||
.pipe(
|
headers: {
|
||||||
tar.x({
|
Accept: "application/octet-stream"
|
||||||
C: path.join(outputDir),
|
}
|
||||||
filter: (path) => path === "infisical",
|
});
|
||||||
})
|
|
||||||
);
|
|
||||||
|
|
||||||
outStream.on("error", reject);
|
if (!response.ok) {
|
||||||
outStream.on("close", resolve);
|
throw new Error(`Failed to fetch: ${response.status} - ${response.statusText}`);
|
||||||
});
|
}
|
||||||
})
|
|
||||||
.catch((error) => {
|
return await new Promise((resolve, reject) => {
|
||||||
console.error("Error downloading or extracting the asset:", error);
|
const outStream = stream.Readable.fromWeb(response.body)
|
||||||
});
|
.pipe(zlib.createGunzip())
|
||||||
}
|
.pipe(
|
||||||
|
tar.x({
|
||||||
|
C: path.join(outputDir),
|
||||||
|
filter: path => path === "infisical"
|
||||||
|
})
|
||||||
|
);
|
||||||
|
|
||||||
|
outStream.on("error", reject);
|
||||||
|
outStream.on("close", resolve);
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
console.error("Error downloading or extracting the asset:", error);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
main();
|
main();
|
||||||
|
|||||||
Reference in New Issue
Block a user