Add ssh host host ca public key endpoint

This commit is contained in:
Tuan Dang
2025-04-08 18:54:08 -07:00
parent 20ebfcefaa
commit 5a114586dc
3 changed files with 50 additions and 1 deletions
@@ -460,4 +460,25 @@ export const registerSshHostRouter = async (server: FastifyZodProvider) => {
return publicKey; return publicKey;
} }
}); });
server.route({
method: "GET",
url: "/:sshHostId/host-ca-public-key",
config: {
rateLimit: publicSshCaLimit
},
schema: {
description: "Get public key of the host SSH CA linked to the host",
params: z.object({
sshHostId: z.string().trim().describe(SSH_HOSTS.GET_USER_CA_PUBLIC_KEY.sshHostId)
}),
response: {
200: z.string()
}
},
handler: async (req) => {
const publicKey = await server.services.sshHost.getSshHostHostCaPk(req.params.sshHostId);
return publicKey;
}
});
}; };
@@ -590,6 +590,30 @@ export const sshHostServiceFactory = ({
return publicKey; return publicKey;
}; };
const getSshHostHostCaPk = async (sshHostId: string) => {
const host = await sshHostDAL.findById(sshHostId);
if (!host) {
throw new NotFoundError({
message: `SSH host with ID ${sshHostId} not found`
});
}
const sshCaSecret = await sshCertificateAuthoritySecretDAL.findOne({ sshCaId: host.hostSshCaId });
const { decryptor: secretManagerDecryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager,
projectId: host.projectId
});
const decryptedCaPrivateKey = secretManagerDecryptor({
cipherTextBlob: sshCaSecret.encryptedPrivateKey
});
const publicKey = await getSshPublicKey(decryptedCaPrivateKey.toString("utf-8"));
return publicKey;
};
return { return {
listSshHosts, listSshHosts,
createSshHost, createSshHost,
@@ -598,6 +622,7 @@ export const sshHostServiceFactory = ({
getSshHost, getSshHost,
issueSshHostUserCert, issueSshHostUserCert,
issueSshHostHostCert, issueSshHostHostCert,
getSshHostUserCaPk getSshHostUserCaPk,
getSshHostHostCaPk
}; };
}; };
+3
View File
@@ -1363,6 +1363,9 @@ export const SSH_HOSTS = {
}, },
GET_USER_CA_PUBLIC_KEY: { GET_USER_CA_PUBLIC_KEY: {
sshHostId: "The ID of the SSH host to get the user SSH CA public key for." sshHostId: "The ID of the SSH host to get the user SSH CA public key for."
},
GET_HOST_CA_PUBLIC_KEY: {
sshHostId: "The ID of the SSH host to get the host SSH CA public key for."
} }
}; };