mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 09:26:14 +00:00
feat: review changes
This commit is contained in:
@@ -7,7 +7,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
|||||||
|
|
||||||
import { SecretKeyEncoding, TableName } from "../schemas";
|
import { SecretKeyEncoding, TableName } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { newRingBuffer } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
@@ -30,7 +30,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const projectEncryptionRingBuffer =
|
const projectEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const webhooks = await knex(TableName.Webhook)
|
const webhooks = await knex(TableName.Webhook)
|
||||||
.where({})
|
.where({})
|
||||||
@@ -47,7 +47,8 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
knex.ref("id").withSchema(TableName.Webhook),
|
knex.ref("id").withSchema(TableName.Webhook),
|
||||||
"envId"
|
"envId"
|
||||||
)
|
)
|
||||||
.select(knex.ref("projectId").withSchema(TableName.Environment));
|
.select(knex.ref("projectId").withSchema(TableName.Environment))
|
||||||
|
.orderBy(`${TableName.Environment}.projectId` as "projectId");
|
||||||
|
|
||||||
const updatedWebhooks = await Promise.all(
|
const updatedWebhooks = await Promise.all(
|
||||||
webhooks.map(async (el) => {
|
webhooks.map(async (el) => {
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
|||||||
|
|
||||||
import { SecretKeyEncoding, TableName } from "../schemas";
|
import { SecretKeyEncoding, TableName } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { newRingBuffer } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
@@ -27,12 +27,13 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const projectEncryptionRingBuffer =
|
const projectEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const secretRotations = await knex(TableName.SecretRotation)
|
const secretRotations = await knex(TableName.SecretRotation)
|
||||||
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.SecretRotation}.envId`)
|
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.SecretRotation}.envId`)
|
||||||
.select(selectAllTableCols(TableName.SecretRotation))
|
.select(selectAllTableCols(TableName.SecretRotation))
|
||||||
.select(knex.ref("projectId").withSchema(TableName.Environment));
|
.select(knex.ref("projectId").withSchema(TableName.Environment))
|
||||||
|
.orderBy(`${TableName.Environment}.projectId` as "projectId");
|
||||||
|
|
||||||
const updatedRotationData = await Promise.all(
|
const updatedRotationData = await Promise.all(
|
||||||
secretRotations.map(async ({ projectId, ...el }) => {
|
secretRotations.map(async ({ projectId, ...el }) => {
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
|||||||
|
|
||||||
import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas";
|
import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { newRingBuffer } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
@@ -58,7 +58,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const orgEncryptionRingBuffer =
|
const orgEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth)
|
const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth)
|
||||||
.join(
|
.join(
|
||||||
@@ -74,7 +74,8 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
|||||||
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot),
|
||||||
knex.ref("orgId").withSchema(TableName.OrgBot)
|
knex.ref("orgId").withSchema(TableName.OrgBot)
|
||||||
);
|
)
|
||||||
|
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
||||||
|
|
||||||
const updatedIdentityKubernetesConfigs = await Promise.all(
|
const updatedIdentityKubernetesConfigs = await Promise.all(
|
||||||
identityKubernetesConfigs.map(
|
identityKubernetesConfigs.map(
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
|||||||
|
|
||||||
import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas";
|
import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { newRingBuffer } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
@@ -38,7 +38,7 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const orgEncryptionRingBuffer =
|
const orgEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const identityOidcConfig = await knex(TableName.IdentityOidcAuth)
|
const identityOidcConfig = await knex(TableName.IdentityOidcAuth)
|
||||||
.join(
|
.join(
|
||||||
@@ -54,7 +54,8 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
|
|||||||
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot),
|
||||||
knex.ref("orgId").withSchema(TableName.OrgBot)
|
knex.ref("orgId").withSchema(TableName.OrgBot)
|
||||||
);
|
)
|
||||||
|
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
||||||
|
|
||||||
const updatedIdentityOidcConfigs = await Promise.all(
|
const updatedIdentityOidcConfigs = await Promise.all(
|
||||||
identityOidcConfig.map(
|
identityOidcConfig.map(
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
|||||||
|
|
||||||
import { SecretKeyEncoding, TableName } from "../schemas";
|
import { SecretKeyEncoding, TableName } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { newRingBuffer } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
@@ -33,13 +33,14 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const projectEncryptionRingBuffer =
|
const projectEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const dynamicSecretRootCredentials = await knex(TableName.DynamicSecret)
|
const dynamicSecretRootCredentials = await knex(TableName.DynamicSecret)
|
||||||
.join(TableName.SecretFolder, `${TableName.SecretFolder}.id`, `${TableName.DynamicSecret}.folderId`)
|
.join(TableName.SecretFolder, `${TableName.SecretFolder}.id`, `${TableName.DynamicSecret}.folderId`)
|
||||||
.join(TableName.Environment, `${TableName.SecretFolder}.envId`, `${TableName.Environment}.id`)
|
.join(TableName.Environment, `${TableName.SecretFolder}.envId`, `${TableName.Environment}.id`)
|
||||||
.select(selectAllTableCols(TableName.DynamicSecret))
|
.select(selectAllTableCols(TableName.DynamicSecret))
|
||||||
.select(knex.ref("projectId").withSchema(TableName.Environment));
|
.select(knex.ref("projectId").withSchema(TableName.Environment))
|
||||||
|
.orderBy(`${TableName.Environment}.projectId` as "projectId");
|
||||||
|
|
||||||
const updatedDynamicSecrets = await Promise.all(
|
const updatedDynamicSecrets = await Promise.all(
|
||||||
dynamicSecretRootCredentials.map(async ({ projectId, ...el }) => {
|
dynamicSecretRootCredentials.map(async ({ projectId, ...el }) => {
|
||||||
|
|||||||
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
|||||||
|
|
||||||
import { SecretKeyEncoding, TableName } from "../schemas";
|
import { SecretKeyEncoding, TableName } from "../schemas";
|
||||||
import { getMigrationEnvConfig } from "./utils/env-config";
|
import { getMigrationEnvConfig } from "./utils/env-config";
|
||||||
import { newRingBuffer } from "./utils/ring-buffer";
|
import { createCircularCache } from "./utils/ring-buffer";
|
||||||
import { getMigrationEncryptionServices } from "./utils/services";
|
import { getMigrationEncryptionServices } from "./utils/services";
|
||||||
|
|
||||||
const BATCH_SIZE = 500;
|
const BATCH_SIZE = 500;
|
||||||
@@ -31,7 +31,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const orgEncryptionRingBuffer =
|
const orgEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const samlConfigs = await knex(TableName.SamlConfig)
|
const samlConfigs = await knex(TableName.SamlConfig)
|
||||||
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.SamlConfig}.orgId`)
|
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.SamlConfig}.orgId`)
|
||||||
@@ -41,7 +41,8 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
|||||||
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
|
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
|
||||||
);
|
)
|
||||||
|
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
||||||
|
|
||||||
const updatedSamlConfigs = await Promise.all(
|
const updatedSamlConfigs = await Promise.all(
|
||||||
samlConfigs.map(
|
samlConfigs.map(
|
||||||
@@ -185,7 +186,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const orgEncryptionRingBuffer =
|
const orgEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const ldapConfigs = await knex(TableName.LdapConfig)
|
const ldapConfigs = await knex(TableName.LdapConfig)
|
||||||
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.LdapConfig}.orgId`)
|
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.LdapConfig}.orgId`)
|
||||||
@@ -195,7 +196,8 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
|||||||
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
|
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
|
||||||
);
|
)
|
||||||
|
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
||||||
|
|
||||||
const updatedLdapConfigs = await Promise.all(
|
const updatedLdapConfigs = await Promise.all(
|
||||||
ldapConfigs.map(
|
ldapConfigs.map(
|
||||||
@@ -334,7 +336,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
|||||||
const keyStore = inMemoryKeyStore();
|
const keyStore = inMemoryKeyStore();
|
||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const orgEncryptionRingBuffer =
|
const orgEncryptionRingBuffer =
|
||||||
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const oidcConfigs = await knex(TableName.OidcConfig)
|
const oidcConfigs = await knex(TableName.OidcConfig)
|
||||||
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.OidcConfig}.orgId`)
|
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.OidcConfig}.orgId`)
|
||||||
@@ -344,7 +346,8 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
|||||||
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
|
||||||
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
|
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
|
||||||
);
|
)
|
||||||
|
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
||||||
|
|
||||||
const updatedOidcConfigs = await Promise.all(
|
const updatedOidcConfigs = await Promise.all(
|
||||||
oidcConfigs.map(
|
oidcConfigs.map(
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
export const newRingBuffer = <T>(bufferSize = 10) => {
|
export const createCircularCache = <T>(bufferSize = 10) => {
|
||||||
const bufferItems: { id: string; item: T }[] = [];
|
const bufferItems: { id: string; item: T }[] = [];
|
||||||
let bufferIndex = 0;
|
let bufferIndex = 0;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user