feat: enhance AWS IAM resource handling with new gateway access schema and improved project ID management

- Introduced GatewayAccessResponseSchema for consistent response structures across Postgres, MySQL, and SSH resources.
- Updated PAM account router to utilize the new schema, streamlining response validation.
- Refactored AWS IAM service to improve project ID handling during role assumption and credential management.
- Enhanced AWS IAM resource schemas to support gateway-specific configurations, improving flexibility and type safety.
This commit is contained in:
Victor Santos
2025-12-07 20:32:59 -03:00
parent 69fd05bc1e
commit 3e77c33532
11 changed files with 198 additions and 185 deletions
@@ -18,7 +18,7 @@ import { CopyButton } from "@app/components/v2/CopyButton";
import { useProject } from "@app/context";
import { PamResourceType, TAwsIamAccount } from "@app/hooks/api/pam";
import { GenericAccountFields } from "./GenericAccountFields";
import { GenericAccountFields, genericAccountFieldsSchema } from "./GenericAccountFields";
type Props = {
account?: TAwsIamAccount;
@@ -45,12 +45,7 @@ const AwsIamCredentialsSchema = z.object({
.default(3600)
});
const genericAwsIamAccountFieldsSchema = z.object({
name: z.string().min(1, "Name is required").max(64, "Name must be at most 64 characters"),
description: z.string().max(512).optional().nullable()
});
const formSchema = genericAwsIamAccountFieldsSchema.extend({
const formSchema = genericAccountFieldsSchema.extend({
credentials: AwsIamCredentialsSchema
});
@@ -153,8 +148,8 @@ export const AwsIamAccountForm = ({ account, onSubmit }: Props) => {
</AccordionTrigger>
<AccordionContent className="px-4 pb-2.5">
<p className="mb-3 text-sm text-mineshaft-300">
The target role must have a trust policy that allows the Infisical PAM role to
assume it. If you used the{" "}
The target role must have a trust policy that allows the Infisical PAM role you
created and used in the &quot;Resources&quot; tab to assume it. If you used the{" "}
<code className="rounded bg-mineshaft-700 px-1 text-xs">infisical-pam-*</code>{" "}
naming convention, no additional changes are needed to the PAM role.
</p>
@@ -66,7 +66,7 @@ export const AwsIamResourceForm = ({ resource, onSubmit }: Props) => {
"Statement": [{
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::${INFISICAL_AWS_ACCOUNT_US}:root"
"AWS": "arn:aws:iam::<INFISICAL_AWS_ACCOUNT_ID>:root"
},
"Action": "sts:AssumeRole",
"Condition": {
@@ -186,7 +186,11 @@ export const AwsIamResourceForm = ({ resource, onSubmit }: Props) => {
<code className="rounded bg-mineshaft-700 px-1 font-bold">
{INFISICAL_AWS_ACCOUNT_EU}
</code>{" "}
for EU region. The External ID{" "}
for EU region. Replace{" "}
<code className="rounded bg-mineshaft-700 px-1 font-bold">
&lt;INFISICAL_AWS_ACCOUNT_ID&gt;
</code>{" "}
with the appropriate Infisical AWS account ID for your region. The External ID{" "}
<code className="rounded bg-mineshaft-700 px-1 font-bold">{projectId}</code> is your
current project ID.
</p>