feat: review changes

This commit is contained in:
=
2025-02-10 15:46:38 +05:30
parent 9eed67c21b
commit 648fde8f37
7 changed files with 31 additions and 23 deletions
@@ -7,7 +7,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { SecretKeyEncoding, TableName } from "../schemas"; import { SecretKeyEncoding, TableName } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config"; import { getMigrationEnvConfig } from "./utils/env-config";
import { newRingBuffer } from "./utils/ring-buffer"; import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services"; import { getMigrationEncryptionServices } from "./utils/services";
const BATCH_SIZE = 500; const BATCH_SIZE = 500;
@@ -30,7 +30,7 @@ export async function up(knex: Knex): Promise<void> {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const projectEncryptionRingBuffer = const projectEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const webhooks = await knex(TableName.Webhook) const webhooks = await knex(TableName.Webhook)
.where({}) .where({})
@@ -47,7 +47,8 @@ export async function up(knex: Knex): Promise<void> {
knex.ref("id").withSchema(TableName.Webhook), knex.ref("id").withSchema(TableName.Webhook),
"envId" "envId"
) )
.select(knex.ref("projectId").withSchema(TableName.Environment)); .select(knex.ref("projectId").withSchema(TableName.Environment))
.orderBy(`${TableName.Environment}.projectId` as "projectId");
const updatedWebhooks = await Promise.all( const updatedWebhooks = await Promise.all(
webhooks.map(async (el) => { webhooks.map(async (el) => {
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { SecretKeyEncoding, TableName } from "../schemas"; import { SecretKeyEncoding, TableName } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config"; import { getMigrationEnvConfig } from "./utils/env-config";
import { newRingBuffer } from "./utils/ring-buffer"; import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services"; import { getMigrationEncryptionServices } from "./utils/services";
const BATCH_SIZE = 500; const BATCH_SIZE = 500;
@@ -27,12 +27,13 @@ export async function up(knex: Knex): Promise<void> {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const projectEncryptionRingBuffer = const projectEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const secretRotations = await knex(TableName.SecretRotation) const secretRotations = await knex(TableName.SecretRotation)
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.SecretRotation}.envId`) .join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.SecretRotation}.envId`)
.select(selectAllTableCols(TableName.SecretRotation)) .select(selectAllTableCols(TableName.SecretRotation))
.select(knex.ref("projectId").withSchema(TableName.Environment)); .select(knex.ref("projectId").withSchema(TableName.Environment))
.orderBy(`${TableName.Environment}.projectId` as "projectId");
const updatedRotationData = await Promise.all( const updatedRotationData = await Promise.all(
secretRotations.map(async ({ projectId, ...el }) => { secretRotations.map(async ({ projectId, ...el }) => {
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas"; import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config"; import { getMigrationEnvConfig } from "./utils/env-config";
import { newRingBuffer } from "./utils/ring-buffer"; import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services"; import { getMigrationEncryptionServices } from "./utils/services";
const BATCH_SIZE = 500; const BATCH_SIZE = 500;
@@ -58,7 +58,7 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const orgEncryptionRingBuffer = const orgEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth) const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth)
.join( .join(
@@ -74,7 +74,8 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot), knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot), knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot),
knex.ref("orgId").withSchema(TableName.OrgBot) knex.ref("orgId").withSchema(TableName.OrgBot)
); )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedIdentityKubernetesConfigs = await Promise.all( const updatedIdentityKubernetesConfigs = await Promise.all(
identityKubernetesConfigs.map( identityKubernetesConfigs.map(
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas"; import { SecretKeyEncoding, TableName, TOrgBots } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config"; import { getMigrationEnvConfig } from "./utils/env-config";
import { newRingBuffer } from "./utils/ring-buffer"; import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services"; import { getMigrationEncryptionServices } from "./utils/services";
const BATCH_SIZE = 500; const BATCH_SIZE = 500;
@@ -38,7 +38,7 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const orgEncryptionRingBuffer = const orgEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const identityOidcConfig = await knex(TableName.IdentityOidcAuth) const identityOidcConfig = await knex(TableName.IdentityOidcAuth)
.join( .join(
@@ -54,7 +54,8 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot), knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot), knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot),
knex.ref("orgId").withSchema(TableName.OrgBot) knex.ref("orgId").withSchema(TableName.OrgBot)
); )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedIdentityOidcConfigs = await Promise.all( const updatedIdentityOidcConfigs = await Promise.all(
identityOidcConfig.map( identityOidcConfig.map(
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { SecretKeyEncoding, TableName } from "../schemas"; import { SecretKeyEncoding, TableName } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config"; import { getMigrationEnvConfig } from "./utils/env-config";
import { newRingBuffer } from "./utils/ring-buffer"; import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services"; import { getMigrationEncryptionServices } from "./utils/services";
const BATCH_SIZE = 500; const BATCH_SIZE = 500;
@@ -33,13 +33,14 @@ export async function up(knex: Knex): Promise<void> {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const projectEncryptionRingBuffer = const projectEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const dynamicSecretRootCredentials = await knex(TableName.DynamicSecret) const dynamicSecretRootCredentials = await knex(TableName.DynamicSecret)
.join(TableName.SecretFolder, `${TableName.SecretFolder}.id`, `${TableName.DynamicSecret}.folderId`) .join(TableName.SecretFolder, `${TableName.SecretFolder}.id`, `${TableName.DynamicSecret}.folderId`)
.join(TableName.Environment, `${TableName.SecretFolder}.envId`, `${TableName.Environment}.id`) .join(TableName.Environment, `${TableName.SecretFolder}.envId`, `${TableName.Environment}.id`)
.select(selectAllTableCols(TableName.DynamicSecret)) .select(selectAllTableCols(TableName.DynamicSecret))
.select(knex.ref("projectId").withSchema(TableName.Environment)); .select(knex.ref("projectId").withSchema(TableName.Environment))
.orderBy(`${TableName.Environment}.projectId` as "projectId");
const updatedDynamicSecrets = await Promise.all( const updatedDynamicSecrets = await Promise.all(
dynamicSecretRootCredentials.map(async ({ projectId, ...el }) => { dynamicSecretRootCredentials.map(async ({ projectId, ...el }) => {
@@ -8,7 +8,7 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { SecretKeyEncoding, TableName } from "../schemas"; import { SecretKeyEncoding, TableName } from "../schemas";
import { getMigrationEnvConfig } from "./utils/env-config"; import { getMigrationEnvConfig } from "./utils/env-config";
import { newRingBuffer } from "./utils/ring-buffer"; import { createCircularCache } from "./utils/ring-buffer";
import { getMigrationEncryptionServices } from "./utils/services"; import { getMigrationEncryptionServices } from "./utils/services";
const BATCH_SIZE = 500; const BATCH_SIZE = 500;
@@ -31,7 +31,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const orgEncryptionRingBuffer = const orgEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const samlConfigs = await knex(TableName.SamlConfig) const samlConfigs = await knex(TableName.SamlConfig)
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.SamlConfig}.orgId`) .join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.SamlConfig}.orgId`)
@@ -41,7 +41,8 @@ const reencryptSamlConfig = async (knex: Knex) => {
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot), knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot), knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot) knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
); )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedSamlConfigs = await Promise.all( const updatedSamlConfigs = await Promise.all(
samlConfigs.map( samlConfigs.map(
@@ -185,7 +186,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const orgEncryptionRingBuffer = const orgEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const ldapConfigs = await knex(TableName.LdapConfig) const ldapConfigs = await knex(TableName.LdapConfig)
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.LdapConfig}.orgId`) .join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.LdapConfig}.orgId`)
@@ -195,7 +196,8 @@ const reencryptLdapConfig = async (knex: Knex) => {
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot), knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot), knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot) knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
); )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedLdapConfigs = await Promise.all( const updatedLdapConfigs = await Promise.all(
ldapConfigs.map( ldapConfigs.map(
@@ -334,7 +336,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
const keyStore = inMemoryKeyStore(); const keyStore = inMemoryKeyStore();
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex }); const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
const orgEncryptionRingBuffer = const orgEncryptionRingBuffer =
newRingBuffer<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25); createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
const oidcConfigs = await knex(TableName.OidcConfig) const oidcConfigs = await knex(TableName.OidcConfig)
.join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.OidcConfig}.orgId`) .join(TableName.OrgBot, `${TableName.OrgBot}.orgId`, `${TableName.OidcConfig}.orgId`)
@@ -344,7 +346,8 @@ const reencryptOidcConfig = async (knex: Knex) => {
knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot), knex.ref("symmetricKeyIV").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot), knex.ref("symmetricKeyTag").withSchema(TableName.OrgBot),
knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot) knex.ref("symmetricKeyKeyEncoding").withSchema(TableName.OrgBot)
); )
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
const updatedOidcConfigs = await Promise.all( const updatedOidcConfigs = await Promise.all(
oidcConfigs.map( oidcConfigs.map(
@@ -1,4 +1,4 @@
export const newRingBuffer = <T>(bufferSize = 10) => { export const createCircularCache = <T>(bufferSize = 10) => {
const bufferItems: { id: string; item: T }[] = []; const bufferItems: { id: string; item: T }[] = [];
let bufferIndex = 0; let bufferIndex = 0;