fix: resolved ssm failing for empty secret in 1-1 mapping

This commit is contained in:
=
2024-10-09 16:06:48 +05:30
parent b482a9cda7
commit 4aaba3ef9f
@@ -9,6 +9,7 @@
import { import {
CreateSecretCommand, CreateSecretCommand,
DeleteSecretCommand,
DescribeSecretCommand, DescribeSecretCommand,
GetSecretValueCommand, GetSecretValueCommand,
ResourceNotFoundException, ResourceNotFoundException,
@@ -899,12 +900,21 @@ const syncSecretsAWSSecretManager = async ({
} }
if (!isEqual(secretToCompare, secretValue)) { if (!isEqual(secretToCompare, secretValue)) {
if (secretValue) {
await secretsManager.send( await secretsManager.send(
new UpdateSecretCommand({ new UpdateSecretCommand({
SecretId: secretId, SecretId: secretId,
SecretString: typeof secretValue === "string" ? secretValue : JSON.stringify(secretValue) SecretString: typeof secretValue === "string" ? secretValue : JSON.stringify(secretValue)
}) })
); );
// delete it
} else {
await secretsManager.send(
new DeleteSecretCommand({
SecretId: secretId
})
);
}
} }
const secretAWSTag = metadata.secretAWSTag as { key: string; value: string }[] | undefined; const secretAWSTag = metadata.secretAWSTag as { key: string; value: string }[] | undefined;
@@ -989,16 +999,21 @@ const syncSecretsAWSSecretManager = async ({
} catch (err) { } catch (err) {
// case 1: when AWS manager can't find the specified secret // case 1: when AWS manager can't find the specified secret
if (err instanceof ResourceNotFoundException && secretsManager) { if (err instanceof ResourceNotFoundException && secretsManager) {
if (secretValue) {
await secretsManager.send( await secretsManager.send(
new CreateSecretCommand({ new CreateSecretCommand({
Name: secretId, Name: secretId,
SecretString: typeof secretValue === "string" ? secretValue : JSON.stringify(secretValue), SecretString: typeof secretValue === "string" ? secretValue : JSON.stringify(secretValue),
...(metadata.kmsKeyId && { KmsKeyId: metadata.kmsKeyId }), ...(metadata.kmsKeyId && { KmsKeyId: metadata.kmsKeyId }),
Tags: metadata.secretAWSTag Tags: metadata.secretAWSTag
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({ Key: tag.key, Value: tag.value })) ? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({
Key: tag.key,
Value: tag.value
}))
: [] : []
}) })
); );
}
// case 2: something unexpected went wrong, so we'll throw the error to reflect the error in the integration sync status // case 2: something unexpected went wrong, so we'll throw the error to reflect the error in the integration sync status
} else { } else {
throw err; throw err;