mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
added base64 support for config and templates
This commit is contained in:
+72
-13
@@ -5,6 +5,7 @@ package cmd
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"bytes"
|
"bytes"
|
||||||
|
"encoding/base64"
|
||||||
"fmt"
|
"fmt"
|
||||||
"io/ioutil"
|
"io/ioutil"
|
||||||
"os"
|
"os"
|
||||||
@@ -67,8 +68,9 @@ type SinkDetails struct {
|
|||||||
}
|
}
|
||||||
|
|
||||||
type Template struct {
|
type Template struct {
|
||||||
SourcePath string `yaml:"source-path"`
|
SourcePath string `yaml:"source-path"`
|
||||||
DestinationPath string `yaml:"destination-path"`
|
Base64TemplateContent string `yaml:"base64-template-content"`
|
||||||
|
DestinationPath string `yaml:"destination-path"`
|
||||||
}
|
}
|
||||||
|
|
||||||
func ReadFile(filePath string) ([]byte, error) {
|
func ReadFile(filePath string) ([]byte, error) {
|
||||||
@@ -108,12 +110,7 @@ func appendAPIEndpoint(address string) string {
|
|||||||
return address + "/api"
|
return address + "/api"
|
||||||
}
|
}
|
||||||
|
|
||||||
func ParseAgentConfig(filePath string) (*Config, error) {
|
func ParseAgentConfig(configFile []byte) (*Config, error) {
|
||||||
data, err := ioutil.ReadFile(filePath)
|
|
||||||
if err != nil {
|
|
||||||
return nil, err
|
|
||||||
}
|
|
||||||
|
|
||||||
var rawConfig struct {
|
var rawConfig struct {
|
||||||
Infisical InfisicalConfig `yaml:"infisical"`
|
Infisical InfisicalConfig `yaml:"infisical"`
|
||||||
Auth struct {
|
Auth struct {
|
||||||
@@ -124,7 +121,7 @@ func ParseAgentConfig(filePath string) (*Config, error) {
|
|||||||
Templates []Template `yaml:"templates"`
|
Templates []Template `yaml:"templates"`
|
||||||
}
|
}
|
||||||
|
|
||||||
if err := yaml.Unmarshal(data, &rawConfig); err != nil {
|
if err := yaml.Unmarshal(configFile, &rawConfig); err != nil {
|
||||||
return nil, err
|
return nil, err
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -206,6 +203,35 @@ func ProcessTemplate(templatePath string, data interface{}, accessToken string)
|
|||||||
return &buf, nil
|
return &buf, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func ProcessBase64Template(encodedTemplate string, data interface{}, accessToken string) (*bytes.Buffer, error) {
|
||||||
|
// custom template function to fetch secrets from Infisical
|
||||||
|
decoded, err := base64.StdEncoding.DecodeString(encodedTemplate)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
templateString := string(decoded)
|
||||||
|
|
||||||
|
secretFunction := secretTemplateFunction(accessToken)
|
||||||
|
funcs := template.FuncMap{
|
||||||
|
"secret": secretFunction,
|
||||||
|
}
|
||||||
|
|
||||||
|
templateName := "base64Template"
|
||||||
|
|
||||||
|
tmpl, err := template.New(templateName).Funcs(funcs).Parse(templateString)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
var buf bytes.Buffer
|
||||||
|
if err := tmpl.Execute(&buf, data); err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
return &buf, nil
|
||||||
|
}
|
||||||
|
|
||||||
type TokenManager struct {
|
type TokenManager struct {
|
||||||
accessToken string
|
accessToken string
|
||||||
accessTokenTTL time.Duration
|
accessTokenTTL time.Duration
|
||||||
@@ -403,7 +429,14 @@ func (tm *TokenManager) FetchSecrets() {
|
|||||||
token := tm.GetToken()
|
token := tm.GetToken()
|
||||||
if token != "" {
|
if token != "" {
|
||||||
for _, secretTemplate := range tm.templates {
|
for _, secretTemplate := range tm.templates {
|
||||||
processedTemplate, err := ProcessTemplate(secretTemplate.SourcePath, nil, token)
|
var processedTemplate *bytes.Buffer
|
||||||
|
var err error
|
||||||
|
if secretTemplate.SourcePath != "" {
|
||||||
|
processedTemplate, err = ProcessTemplate(secretTemplate.SourcePath, nil, token)
|
||||||
|
} else {
|
||||||
|
processedTemplate, err = ProcessBase64Template(secretTemplate.Base64TemplateContent, nil, token)
|
||||||
|
}
|
||||||
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Error().Msgf("template engine: unable to render secrets because %s. Will try again on next cycle", err)
|
log.Error().Msgf("template engine: unable to render secrets because %s. Will try again on next cycle", err)
|
||||||
|
|
||||||
@@ -456,12 +489,38 @@ var agentCmd = &cobra.Command{
|
|||||||
util.HandleError(err, "Unable to parse flag config")
|
util.HandleError(err, "Unable to parse flag config")
|
||||||
}
|
}
|
||||||
|
|
||||||
if !FileExists(configPath) {
|
var agentConfigInBytes []byte
|
||||||
log.Error().Msgf("Unable to locate %s. The provided agent config file path is either missing or incorrect", configPath)
|
|
||||||
|
agentConfigInBase64 := os.Getenv("INFISICAL_AGENT_CONFIG_BASE64")
|
||||||
|
|
||||||
|
if configPath != "" {
|
||||||
|
data, err := ioutil.ReadFile(configPath)
|
||||||
|
if err != nil {
|
||||||
|
if !FileExists(configPath) {
|
||||||
|
log.Error().Msgf("Unable to locate %s. The provided agent config file path is either missing or incorrect", configPath)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
agentConfigInBytes = data
|
||||||
|
}
|
||||||
|
|
||||||
|
if agentConfigInBase64 != "" {
|
||||||
|
decodedAgentConfig, err := base64.StdEncoding.DecodeString(agentConfigInBase64)
|
||||||
|
if err != nil {
|
||||||
|
log.Error().Msgf("Unable to decode base64 config file because %v", err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
|
||||||
|
agentConfigInBytes = decodedAgentConfig
|
||||||
|
}
|
||||||
|
|
||||||
|
if !FileExists(configPath) && agentConfigInBase64 == "" {
|
||||||
|
log.Error().Msgf("No agent config file provided. Please provide a agent config file", configPath)
|
||||||
return
|
return
|
||||||
}
|
}
|
||||||
|
|
||||||
agentConfig, err := ParseAgentConfig(configPath)
|
agentConfig, err := ParseAgentConfig(agentConfigInBytes)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
log.Error().Msgf("Unable to prase %s because %v. Please ensure that is follows the Infisical Agent config structure", configPath, err)
|
log.Error().Msgf("Unable to prase %s because %v. Please ensure that is follows the Infisical Agent config structure", configPath, err)
|
||||||
return
|
return
|
||||||
|
|||||||
Reference in New Issue
Block a user