added base64 support for config and templates

This commit is contained in:
Maidul Islam
2024-01-06 23:43:04 -05:00
parent 12840bfdbd
commit 45d96be1ff
+72 -13
View File
@@ -5,6 +5,7 @@ package cmd
import ( import (
"bytes" "bytes"
"encoding/base64"
"fmt" "fmt"
"io/ioutil" "io/ioutil"
"os" "os"
@@ -67,8 +68,9 @@ type SinkDetails struct {
} }
type Template struct { type Template struct {
SourcePath string `yaml:"source-path"` SourcePath string `yaml:"source-path"`
DestinationPath string `yaml:"destination-path"` Base64TemplateContent string `yaml:"base64-template-content"`
DestinationPath string `yaml:"destination-path"`
} }
func ReadFile(filePath string) ([]byte, error) { func ReadFile(filePath string) ([]byte, error) {
@@ -108,12 +110,7 @@ func appendAPIEndpoint(address string) string {
return address + "/api" return address + "/api"
} }
func ParseAgentConfig(filePath string) (*Config, error) { func ParseAgentConfig(configFile []byte) (*Config, error) {
data, err := ioutil.ReadFile(filePath)
if err != nil {
return nil, err
}
var rawConfig struct { var rawConfig struct {
Infisical InfisicalConfig `yaml:"infisical"` Infisical InfisicalConfig `yaml:"infisical"`
Auth struct { Auth struct {
@@ -124,7 +121,7 @@ func ParseAgentConfig(filePath string) (*Config, error) {
Templates []Template `yaml:"templates"` Templates []Template `yaml:"templates"`
} }
if err := yaml.Unmarshal(data, &rawConfig); err != nil { if err := yaml.Unmarshal(configFile, &rawConfig); err != nil {
return nil, err return nil, err
} }
@@ -206,6 +203,35 @@ func ProcessTemplate(templatePath string, data interface{}, accessToken string)
return &buf, nil return &buf, nil
} }
func ProcessBase64Template(encodedTemplate string, data interface{}, accessToken string) (*bytes.Buffer, error) {
// custom template function to fetch secrets from Infisical
decoded, err := base64.StdEncoding.DecodeString(encodedTemplate)
if err != nil {
return nil, err
}
templateString := string(decoded)
secretFunction := secretTemplateFunction(accessToken)
funcs := template.FuncMap{
"secret": secretFunction,
}
templateName := "base64Template"
tmpl, err := template.New(templateName).Funcs(funcs).Parse(templateString)
if err != nil {
return nil, err
}
var buf bytes.Buffer
if err := tmpl.Execute(&buf, data); err != nil {
return nil, err
}
return &buf, nil
}
type TokenManager struct { type TokenManager struct {
accessToken string accessToken string
accessTokenTTL time.Duration accessTokenTTL time.Duration
@@ -403,7 +429,14 @@ func (tm *TokenManager) FetchSecrets() {
token := tm.GetToken() token := tm.GetToken()
if token != "" { if token != "" {
for _, secretTemplate := range tm.templates { for _, secretTemplate := range tm.templates {
processedTemplate, err := ProcessTemplate(secretTemplate.SourcePath, nil, token) var processedTemplate *bytes.Buffer
var err error
if secretTemplate.SourcePath != "" {
processedTemplate, err = ProcessTemplate(secretTemplate.SourcePath, nil, token)
} else {
processedTemplate, err = ProcessBase64Template(secretTemplate.Base64TemplateContent, nil, token)
}
if err != nil { if err != nil {
log.Error().Msgf("template engine: unable to render secrets because %s. Will try again on next cycle", err) log.Error().Msgf("template engine: unable to render secrets because %s. Will try again on next cycle", err)
@@ -456,12 +489,38 @@ var agentCmd = &cobra.Command{
util.HandleError(err, "Unable to parse flag config") util.HandleError(err, "Unable to parse flag config")
} }
if !FileExists(configPath) { var agentConfigInBytes []byte
log.Error().Msgf("Unable to locate %s. The provided agent config file path is either missing or incorrect", configPath)
agentConfigInBase64 := os.Getenv("INFISICAL_AGENT_CONFIG_BASE64")
if configPath != "" {
data, err := ioutil.ReadFile(configPath)
if err != nil {
if !FileExists(configPath) {
log.Error().Msgf("Unable to locate %s. The provided agent config file path is either missing or incorrect", configPath)
return
}
}
agentConfigInBytes = data
}
if agentConfigInBase64 != "" {
decodedAgentConfig, err := base64.StdEncoding.DecodeString(agentConfigInBase64)
if err != nil {
log.Error().Msgf("Unable to decode base64 config file because %v", err)
return
}
agentConfigInBytes = decodedAgentConfig
}
if !FileExists(configPath) && agentConfigInBase64 == "" {
log.Error().Msgf("No agent config file provided. Please provide a agent config file", configPath)
return return
} }
agentConfig, err := ParseAgentConfig(configPath) agentConfig, err := ParseAgentConfig(agentConfigInBytes)
if err != nil { if err != nil {
log.Error().Msgf("Unable to prase %s because %v. Please ensure that is follows the Infisical Agent config structure", configPath, err) log.Error().Msgf("Unable to prase %s because %v. Please ensure that is follows the Infisical Agent config structure", configPath, err)
return return