mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #2368 from akhilmhdh/fix/audit-log-loop
Audit log queue looping
This commit is contained in:
@@ -5,6 +5,7 @@ import { TableName } from "@app/db/schemas";
|
|||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, stripUndefinedInWhere } from "@app/lib/knex";
|
import { ormify, stripUndefinedInWhere } from "@app/lib/knex";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TAuditLogDALFactory = ReturnType<typeof auditLogDALFactory>;
|
export type TAuditLogDALFactory = ReturnType<typeof auditLogDALFactory>;
|
||||||
|
|
||||||
@@ -62,7 +63,9 @@ export const auditLogDALFactory = (db: TDbClient) => {
|
|||||||
const today = new Date();
|
const today = new Date();
|
||||||
let deletedAuditLogIds: { id: string }[] = [];
|
let deletedAuditLogIds: { id: string }[] = [];
|
||||||
let numberOfRetryOnFailure = 0;
|
let numberOfRetryOnFailure = 0;
|
||||||
|
let isRetrying = false;
|
||||||
|
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: audit log started`);
|
||||||
do {
|
do {
|
||||||
try {
|
try {
|
||||||
const findExpiredLogSubQuery = (tx || db)(TableName.AuditLog)
|
const findExpiredLogSubQuery = (tx || db)(TableName.AuditLog)
|
||||||
@@ -84,7 +87,9 @@ export const auditLogDALFactory = (db: TDbClient) => {
|
|||||||
setTimeout(resolve, 10); // time to breathe for db
|
setTimeout(resolve, 10); // time to breathe for db
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
} while (deletedAuditLogIds.length > 0 || numberOfRetryOnFailure < MAX_RETRY_ON_FAILURE);
|
isRetrying = numberOfRetryOnFailure > 0;
|
||||||
|
} while (deletedAuditLogIds.length > 0 || (isRetrying && numberOfRetryOnFailure < MAX_RETRY_ON_FAILURE));
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: audit log completed`);
|
||||||
};
|
};
|
||||||
|
|
||||||
return { ...auditLogOrm, pruneAuditLog, find };
|
return { ...auditLogOrm, pruneAuditLog, find };
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ import {
|
|||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
|
import { ormify, selectAllTableCols, sqlNestRelationships } from "@app/lib/knex";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TSnapshotDALFactory = ReturnType<typeof snapshotDALFactory>;
|
export type TSnapshotDALFactory = ReturnType<typeof snapshotDALFactory>;
|
||||||
|
|
||||||
@@ -599,6 +600,7 @@ export const snapshotDALFactory = (db: TDbClient) => {
|
|||||||
const pruneExcessSnapshots = async () => {
|
const pruneExcessSnapshots = async () => {
|
||||||
const PRUNE_FOLDER_BATCH_SIZE = 10000;
|
const PRUNE_FOLDER_BATCH_SIZE = 10000;
|
||||||
|
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret snapshots started`);
|
||||||
try {
|
try {
|
||||||
let uuidOffset = "00000000-0000-0000-0000-000000000000";
|
let uuidOffset = "00000000-0000-0000-0000-000000000000";
|
||||||
// cleanup snapshots from current folders
|
// cleanup snapshots from current folders
|
||||||
@@ -714,6 +716,7 @@ export const snapshotDALFactory = (db: TDbClient) => {
|
|||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new DatabaseError({ error, name: "SnapshotPrune" });
|
throw new DatabaseError({ error, name: "SnapshotPrune" });
|
||||||
}
|
}
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret snapshots completed`);
|
||||||
};
|
};
|
||||||
|
|
||||||
// special query for migration for secret v2
|
// special query for migration for secret v2
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ import { TDbClient } from "@app/db";
|
|||||||
import { IdentityAuthMethod, TableName, TIdentityAccessTokens } from "@app/db/schemas";
|
import { IdentityAuthMethod, TableName, TIdentityAccessTokens } from "@app/db/schemas";
|
||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TIdentityAccessTokenDALFactory = ReturnType<typeof identityAccessTokenDALFactory>;
|
export type TIdentityAccessTokenDALFactory = ReturnType<typeof identityAccessTokenDALFactory>;
|
||||||
|
|
||||||
@@ -95,6 +97,7 @@ export const identityAccessTokenDALFactory = (db: TDbClient) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const removeExpiredTokens = async (tx?: Knex) => {
|
const removeExpiredTokens = async (tx?: Knex) => {
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: remove expired access token started`);
|
||||||
try {
|
try {
|
||||||
const docs = (tx || db)(TableName.IdentityAccessToken)
|
const docs = (tx || db)(TableName.IdentityAccessToken)
|
||||||
.where({
|
.where({
|
||||||
@@ -131,7 +134,8 @@ export const identityAccessTokenDALFactory = (db: TDbClient) => {
|
|||||||
});
|
});
|
||||||
})
|
})
|
||||||
.delete();
|
.delete();
|
||||||
return await docs;
|
await docs;
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: remove expired access token completed`);
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new DatabaseError({ error, name: "IdentityAccessTokenPrune" });
|
throw new DatabaseError({ error, name: "IdentityAccessTokenPrune" });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -5,6 +5,7 @@ import { TableName } from "@app/db/schemas";
|
|||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify } from "@app/lib/knex";
|
import { ormify } from "@app/lib/knex";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TIdentityUaClientSecretDALFactory = ReturnType<typeof identityUaClientSecretDALFactory>;
|
export type TIdentityUaClientSecretDALFactory = ReturnType<typeof identityUaClientSecretDALFactory>;
|
||||||
|
|
||||||
@@ -30,7 +31,9 @@ export const identityUaClientSecretDALFactory = (db: TDbClient) => {
|
|||||||
|
|
||||||
let deletedClientSecret: { id: string }[] = [];
|
let deletedClientSecret: { id: string }[] = [];
|
||||||
let numberOfRetryOnFailure = 0;
|
let numberOfRetryOnFailure = 0;
|
||||||
|
let isRetrying = false;
|
||||||
|
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: remove expired univesal auth client secret started`);
|
||||||
do {
|
do {
|
||||||
try {
|
try {
|
||||||
const findExpiredClientSecretQuery = (tx || db)(TableName.IdentityUaClientSecret)
|
const findExpiredClientSecretQuery = (tx || db)(TableName.IdentityUaClientSecret)
|
||||||
@@ -71,7 +74,9 @@ export const identityUaClientSecretDALFactory = (db: TDbClient) => {
|
|||||||
setTimeout(resolve, 10); // time to breathe for db
|
setTimeout(resolve, 10); // time to breathe for db
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
} while (deletedClientSecret.length > 0 || numberOfRetryOnFailure < MAX_RETRY_ON_FAILURE);
|
isRetrying = numberOfRetryOnFailure > 0;
|
||||||
|
} while (deletedClientSecret.length > 0 || (isRetrying && numberOfRetryOnFailure < MAX_RETRY_ON_FAILURE));
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: remove expired univesal auth client secret completed`);
|
||||||
};
|
};
|
||||||
|
|
||||||
return { ...uaClientSecretOrm, incrementUsage, removeExpiredClientSecrets };
|
return { ...uaClientSecretOrm, incrementUsage, removeExpiredClientSecrets };
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ import { TDbClient } from "@app/db";
|
|||||||
import { TableName, TSecretFolderVersions } from "@app/db/schemas";
|
import { TableName, TSecretFolderVersions } from "@app/db/schemas";
|
||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TSecretFolderVersionDALFactory = ReturnType<typeof secretFolderVersionDALFactory>;
|
export type TSecretFolderVersionDALFactory = ReturnType<typeof secretFolderVersionDALFactory>;
|
||||||
|
|
||||||
@@ -65,6 +67,7 @@ export const secretFolderVersionDALFactory = (db: TDbClient) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const pruneExcessVersions = async () => {
|
const pruneExcessVersions = async () => {
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret folder versions started`);
|
||||||
try {
|
try {
|
||||||
await db(TableName.SecretFolderVersion)
|
await db(TableName.SecretFolderVersion)
|
||||||
.with("folder_cte", (qb) => {
|
.with("folder_cte", (qb) => {
|
||||||
@@ -89,6 +92,7 @@ export const secretFolderVersionDALFactory = (db: TDbClient) => {
|
|||||||
name: "Secret Folder Version Prune"
|
name: "Secret Folder Version Prune"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret folder versions completed`);
|
||||||
};
|
};
|
||||||
|
|
||||||
return { ...secretFolderVerOrm, findLatestFolderVersions, findLatestVersionByFolderId, pruneExcessVersions };
|
return { ...secretFolderVerOrm, findLatestFolderVersions, findLatestVersionByFolderId, pruneExcessVersions };
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ import { TDbClient } from "@app/db";
|
|||||||
import { TableName, TSecretSharing } from "@app/db/schemas";
|
import { TableName, TSecretSharing } from "@app/db/schemas";
|
||||||
import { DatabaseError } from "@app/lib/errors";
|
import { DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TSecretSharingDALFactory = ReturnType<typeof secretSharingDALFactory>;
|
export type TSecretSharingDALFactory = ReturnType<typeof secretSharingDALFactory>;
|
||||||
|
|
||||||
@@ -30,6 +32,7 @@ export const secretSharingDALFactory = (db: TDbClient) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const pruneExpiredSharedSecrets = async (tx?: Knex) => {
|
const pruneExpiredSharedSecrets = async (tx?: Knex) => {
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning expired shared secret started`);
|
||||||
try {
|
try {
|
||||||
const today = new Date();
|
const today = new Date();
|
||||||
const docs = await (tx || db)(TableName.SecretSharing)
|
const docs = await (tx || db)(TableName.SecretSharing)
|
||||||
@@ -40,6 +43,7 @@ export const secretSharingDALFactory = (db: TDbClient) => {
|
|||||||
tag: "",
|
tag: "",
|
||||||
iv: ""
|
iv: ""
|
||||||
});
|
});
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning expired shared secret completed`);
|
||||||
return docs;
|
return docs;
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new DatabaseError({ error, name: "pruneExpiredSharedSecrets" });
|
throw new DatabaseError({ error, name: "pruneExpiredSharedSecrets" });
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ import { TDbClient } from "@app/db";
|
|||||||
import { TableName, TSecretVersionsV2, TSecretVersionsV2Update } from "@app/db/schemas";
|
import { TableName, TSecretVersionsV2, TSecretVersionsV2Update } from "@app/db/schemas";
|
||||||
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TSecretVersionV2DALFactory = ReturnType<typeof secretVersionV2BridgeDALFactory>;
|
export type TSecretVersionV2DALFactory = ReturnType<typeof secretVersionV2BridgeDALFactory>;
|
||||||
|
|
||||||
@@ -87,6 +89,7 @@ export const secretVersionV2BridgeDALFactory = (db: TDbClient) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const pruneExcessVersions = async () => {
|
const pruneExcessVersions = async () => {
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret version v2 started`);
|
||||||
try {
|
try {
|
||||||
await db(TableName.SecretVersionV2)
|
await db(TableName.SecretVersionV2)
|
||||||
.with("version_cte", (qb) => {
|
.with("version_cte", (qb) => {
|
||||||
@@ -112,6 +115,7 @@ export const secretVersionV2BridgeDALFactory = (db: TDbClient) => {
|
|||||||
name: "Secret Version Prune"
|
name: "Secret Version Prune"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret version v2 completed`);
|
||||||
};
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
|
|||||||
@@ -4,6 +4,8 @@ import { TDbClient } from "@app/db";
|
|||||||
import { TableName, TSecretVersions, TSecretVersionsUpdate } from "@app/db/schemas";
|
import { TableName, TSecretVersions, TSecretVersionsUpdate } from "@app/db/schemas";
|
||||||
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
import { BadRequestError, DatabaseError } from "@app/lib/errors";
|
||||||
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
import { ormify, selectAllTableCols } from "@app/lib/knex";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
import { QueueName } from "@app/queue";
|
||||||
|
|
||||||
export type TSecretVersionDALFactory = ReturnType<typeof secretVersionDALFactory>;
|
export type TSecretVersionDALFactory = ReturnType<typeof secretVersionDALFactory>;
|
||||||
|
|
||||||
@@ -112,6 +114,7 @@ export const secretVersionDALFactory = (db: TDbClient) => {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const pruneExcessVersions = async () => {
|
const pruneExcessVersions = async () => {
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret version v1 started`);
|
||||||
try {
|
try {
|
||||||
await db(TableName.SecretVersion)
|
await db(TableName.SecretVersion)
|
||||||
.with("version_cte", (qb) => {
|
.with("version_cte", (qb) => {
|
||||||
@@ -137,6 +140,7 @@ export const secretVersionDALFactory = (db: TDbClient) => {
|
|||||||
name: "Secret Version Prune"
|
name: "Secret Version Prune"
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
logger.info(`${QueueName.DailyResourceCleanUp}: pruning secret version v1 completed`);
|
||||||
};
|
};
|
||||||
|
|
||||||
return {
|
return {
|
||||||
|
|||||||
Reference in New Issue
Block a user