Merge pull request #4290 from Infisical/daniel/fix-vault-migration

fix(external-migration/vault): fix vault parsing
This commit is contained in:
Daniel Hougaard
2025-07-31 21:28:58 +04:00
committed by GitHub
5 changed files with 18 additions and 29 deletions
+2
View File
@@ -22,6 +22,7 @@ import { crypto } from "@app/lib/crypto";
import { logger } from "@app/lib/logger"; import { logger } from "@app/lib/logger";
import { QueueWorkerProfile } from "@app/lib/types"; import { QueueWorkerProfile } from "@app/lib/types";
import { CaType } from "@app/services/certificate-authority/certificate-authority-enums"; import { CaType } from "@app/services/certificate-authority/certificate-authority-enums";
import { ExternalPlatforms } from "@app/services/external-migration/external-migration-types";
import { import {
TFailedIntegrationSyncEmailsPayload, TFailedIntegrationSyncEmailsPayload,
TIntegrationSyncPayload, TIntegrationSyncPayload,
@@ -228,6 +229,7 @@ export type TQueueJobTypes = {
name: QueueJobs.ImportSecretsFromExternalSource; name: QueueJobs.ImportSecretsFromExternalSource;
payload: { payload: {
actorEmail: string; actorEmail: string;
importType: ExternalPlatforms;
data: { data: {
iv: string; iv: string;
tag: string; tag: string;
@@ -17,25 +17,16 @@ type VaultData = {
const vaultFactory = () => { const vaultFactory = () => {
const getMounts = async (request: AxiosInstance) => { const getMounts = async (request: AxiosInstance) => {
const response = await request const response = await request
.get< .get<{
Record< data: Record<string, { accessor: string; options: { version?: string } | null; type: string }>;
string, }>("/v1/sys/mounts")
{
accessor: string;
options: {
version?: string;
} | null;
type: string;
}
>
>("/v1/sys/mounts")
.catch((err) => { .catch((err) => {
if (axios.isAxiosError(err)) { if (axios.isAxiosError(err)) {
logger.error(err.response?.data, "External migration: Failed to get Vault mounts"); logger.error(err.response?.data, "External migration: Failed to get Vault mounts");
} }
throw err; throw err;
}); });
return response.data; return response.data.data;
}; };
const getPaths = async ( const getPaths = async (
@@ -19,7 +19,7 @@ import { TSecretVersionV2DALFactory } from "../secret-v2-bridge/secret-version-d
import { TSecretVersionV2TagDALFactory } from "../secret-v2-bridge/secret-version-tag-dal"; import { TSecretVersionV2TagDALFactory } from "../secret-v2-bridge/secret-version-tag-dal";
import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service"; import { SmtpTemplates, TSmtpService } from "../smtp/smtp-service";
import { importDataIntoInfisicalFn } from "./external-migration-fns"; import { importDataIntoInfisicalFn } from "./external-migration-fns";
import { ExternalPlatforms, ImportType, TImportInfisicalDataCreate } from "./external-migration-types"; import { ExternalPlatforms, TImportInfisicalDataCreate } from "./external-migration-types";
export type TExternalMigrationQueueFactoryDep = { export type TExternalMigrationQueueFactoryDep = {
smtpService: TSmtpService; smtpService: TSmtpService;
@@ -66,8 +66,8 @@ export const externalMigrationQueueFactory = ({
}: TExternalMigrationQueueFactoryDep) => { }: TExternalMigrationQueueFactoryDep) => {
const startImport = async (dto: { const startImport = async (dto: {
actorEmail: string; actorEmail: string;
importType: ExternalPlatforms;
data: { data: {
importType: ImportType;
iv: string; iv: string;
tag: string; tag: string;
ciphertext: string; ciphertext: string;
@@ -87,14 +87,14 @@ export const externalMigrationQueueFactory = ({
}; };
queueService.start(QueueName.ImportSecretsFromExternalSource, async (job) => { queueService.start(QueueName.ImportSecretsFromExternalSource, async (job) => {
try { const { data, actorEmail, importType } = job.data;
const { data, actorEmail } = job.data;
try {
await smtpService.sendMail({ await smtpService.sendMail({
recipients: [actorEmail], recipients: [actorEmail],
subjectLine: "Infisical import started", subjectLine: "Infisical import started",
substitutions: { substitutions: {
provider: ExternalPlatforms.EnvKey provider: importType
}, },
template: SmtpTemplates.ExternalImportStarted template: SmtpTemplates.ExternalImportStarted
}); });
@@ -141,7 +141,7 @@ export const externalMigrationQueueFactory = ({
recipients: [actorEmail], recipients: [actorEmail],
subjectLine: "Infisical import successful", subjectLine: "Infisical import successful",
substitutions: { substitutions: {
provider: ExternalPlatforms.EnvKey provider: importType
}, },
template: SmtpTemplates.ExternalImportSuccessful template: SmtpTemplates.ExternalImportSuccessful
}); });
@@ -150,7 +150,7 @@ export const externalMigrationQueueFactory = ({
recipients: [job.data.actorEmail], recipients: [job.data.actorEmail],
subjectLine: "Infisical import failed", subjectLine: "Infisical import failed",
substitutions: { substitutions: {
provider: ExternalPlatforms.EnvKey, provider: importType,
// eslint-disable-next-line @typescript-eslint/no-unsafe-member-access, @typescript-eslint/no-explicit-any, @typescript-eslint/no-unsafe-assignment // eslint-disable-next-line @typescript-eslint/no-unsafe-member-access, @typescript-eslint/no-explicit-any, @typescript-eslint/no-unsafe-assignment
error: (err as any)?.message || "Unknown error" error: (err as any)?.message || "Unknown error"
}, },
@@ -6,7 +6,7 @@ import { BadRequestError, ForbiddenRequestError } from "@app/lib/errors";
import { TUserDALFactory } from "../user/user-dal"; import { TUserDALFactory } from "../user/user-dal";
import { decryptEnvKeyDataFn, importVaultDataFn, parseEnvKeyDataFn } from "./external-migration-fns"; import { decryptEnvKeyDataFn, importVaultDataFn, parseEnvKeyDataFn } from "./external-migration-fns";
import { TExternalMigrationQueueFactory } from "./external-migration-queue"; import { TExternalMigrationQueueFactory } from "./external-migration-queue";
import { ImportType, TImportEnvKeyDataDTO, TImportVaultDataDTO } from "./external-migration-types"; import { ExternalPlatforms, TImportEnvKeyDataDTO, TImportVaultDataDTO } from "./external-migration-types";
type TExternalMigrationServiceFactoryDep = { type TExternalMigrationServiceFactoryDep = {
permissionService: TPermissionServiceFactory; permissionService: TPermissionServiceFactory;
@@ -60,8 +60,8 @@ export const externalMigrationServiceFactory = ({
await externalMigrationQueue.startImport({ await externalMigrationQueue.startImport({
actorEmail: user.email!, actorEmail: user.email!,
importType: ExternalPlatforms.EnvKey,
data: { data: {
importType: ImportType.EnvKey,
...encrypted ...encrypted
} }
}); });
@@ -110,8 +110,8 @@ export const externalMigrationServiceFactory = ({
await externalMigrationQueue.startImport({ await externalMigrationQueue.startImport({
actorEmail: user.email!, actorEmail: user.email!,
importType: ExternalPlatforms.Vault,
data: { data: {
importType: ImportType.Vault,
...encrypted ...encrypted
} }
}); });
@@ -2,11 +2,6 @@ import { TOrgPermission } from "@app/lib/types";
import { ActorAuthMethod, ActorType } from "../auth/auth-type"; import { ActorAuthMethod, ActorType } from "../auth/auth-type";
export enum ImportType {
EnvKey = "envkey",
Vault = "vault"
}
export enum VaultMappingType { export enum VaultMappingType {
Namespace = "namespace", Namespace = "namespace",
KeyVault = "key-vault" KeyVault = "key-vault"
@@ -112,5 +107,6 @@ export type TEnvKeyExportJSON = {
}; };
export enum ExternalPlatforms { export enum ExternalPlatforms {
EnvKey = "EnvKey" EnvKey = "EnvKey",
Vault = "Vault"
} }