mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 12:27:28 +00:00
feat(integrations): visibility support for github integration
This commit is contained in:
@@ -964,6 +964,10 @@ export const INTEGRATION = {
|
|||||||
shouldAutoRedeploy: "Used by Render to trigger auto deploy.",
|
shouldAutoRedeploy: "Used by Render to trigger auto deploy.",
|
||||||
secretGCPLabel: "The label for GCP secrets.",
|
secretGCPLabel: "The label for GCP secrets.",
|
||||||
secretAWSTag: "The tags for AWS secrets.",
|
secretAWSTag: "The tags for AWS secrets.",
|
||||||
|
githubVisibility:
|
||||||
|
"Define where the secrets from the Github Integration should be visible. Option 'selected' lets you directly define which repositories to sync secrets to.",
|
||||||
|
githubVisibilityRepoIds:
|
||||||
|
"The repository IDs to sync secrets to when using the Github Integration. Only applicable when using Organization scope, and visibility is set to 'selected'",
|
||||||
kmsKeyId: "The ID of the encryption key from AWS KMS.",
|
kmsKeyId: "The ID of the encryption key from AWS KMS.",
|
||||||
shouldDisableDelete: "The flag to disable deletion of secrets in AWS Parameter Store.",
|
shouldDisableDelete: "The flag to disable deletion of secrets in AWS Parameter Store.",
|
||||||
shouldMaskSecrets: "Specifies if the secrets synced from Infisical to Gitlab should be marked as 'Masked'.",
|
shouldMaskSecrets: "Specifies if the secrets synced from Infisical to Gitlab should be marked as 'Masked'.",
|
||||||
|
|||||||
@@ -1625,7 +1625,11 @@ const syncSecretsGitHub = async ({
|
|||||||
await octokit.request("PUT /orgs/{org}/actions/secrets/{secret_name}", {
|
await octokit.request("PUT /orgs/{org}/actions/secrets/{secret_name}", {
|
||||||
org: integration.owner as string,
|
org: integration.owner as string,
|
||||||
secret_name: key,
|
secret_name: key,
|
||||||
visibility: "all",
|
visibility: metadata.githubVisibility ?? "all",
|
||||||
|
...(metadata.githubVisibility === "selected" && {
|
||||||
|
// we need to map the githubVisibilityRepoIds to numbers
|
||||||
|
selected_repository_ids: metadata.githubVisibilityRepoIds?.map(Number) ?? []
|
||||||
|
}),
|
||||||
encrypted_value: encryptedSecret,
|
encrypted_value: encryptedSecret,
|
||||||
key_id: repoPublicKey.key_id
|
key_id: repoPublicKey.key_id
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -5,14 +5,18 @@ import { INTEGRATION } from "@app/lib/api-docs";
|
|||||||
import { IntegrationMappingBehavior } from "../integration-auth/integration-list";
|
import { IntegrationMappingBehavior } from "../integration-auth/integration-list";
|
||||||
|
|
||||||
export const IntegrationMetadataSchema = z.object({
|
export const IntegrationMetadataSchema = z.object({
|
||||||
|
initialSyncBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.initialSyncBehavoir),
|
||||||
|
|
||||||
secretPrefix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretPrefix),
|
secretPrefix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretPrefix),
|
||||||
secretSuffix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretSuffix),
|
secretSuffix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretSuffix),
|
||||||
initialSyncBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.initialSyncBehavoir),
|
|
||||||
mappingBehavior: z
|
mappingBehavior: z
|
||||||
.nativeEnum(IntegrationMappingBehavior)
|
.nativeEnum(IntegrationMappingBehavior)
|
||||||
.optional()
|
.optional()
|
||||||
.describe(INTEGRATION.CREATE.metadata.mappingBehavior),
|
.describe(INTEGRATION.CREATE.metadata.mappingBehavior),
|
||||||
|
|
||||||
shouldAutoRedeploy: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldAutoRedeploy),
|
shouldAutoRedeploy: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldAutoRedeploy),
|
||||||
|
|
||||||
secretGCPLabel: z
|
secretGCPLabel: z
|
||||||
.object({
|
.object({
|
||||||
labelName: z.string(),
|
labelName: z.string(),
|
||||||
@@ -20,6 +24,7 @@ export const IntegrationMetadataSchema = z.object({
|
|||||||
})
|
})
|
||||||
.optional()
|
.optional()
|
||||||
.describe(INTEGRATION.CREATE.metadata.secretGCPLabel),
|
.describe(INTEGRATION.CREATE.metadata.secretGCPLabel),
|
||||||
|
|
||||||
secretAWSTag: z
|
secretAWSTag: z
|
||||||
.array(
|
.array(
|
||||||
z.object({
|
z.object({
|
||||||
@@ -29,7 +34,15 @@ export const IntegrationMetadataSchema = z.object({
|
|||||||
)
|
)
|
||||||
.optional()
|
.optional()
|
||||||
.describe(INTEGRATION.CREATE.metadata.secretAWSTag),
|
.describe(INTEGRATION.CREATE.metadata.secretAWSTag),
|
||||||
|
|
||||||
|
githubVisibility: z
|
||||||
|
.union([z.literal("selected"), z.literal("private"), z.literal("all")])
|
||||||
|
.optional()
|
||||||
|
.describe(INTEGRATION.CREATE.metadata.githubVisibility),
|
||||||
|
githubVisibilityRepoIds: z.array(z.string()).optional().describe(INTEGRATION.CREATE.metadata.githubVisibilityRepoIds),
|
||||||
|
|
||||||
kmsKeyId: z.string().optional().describe(INTEGRATION.CREATE.metadata.kmsKeyId),
|
kmsKeyId: z.string().optional().describe(INTEGRATION.CREATE.metadata.kmsKeyId),
|
||||||
|
|
||||||
shouldDisableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldDisableDelete),
|
shouldDisableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldDisableDelete),
|
||||||
shouldEnableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldEnableDelete),
|
shouldEnableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldEnableDelete),
|
||||||
shouldMaskSecrets: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldMaskSecrets),
|
shouldMaskSecrets: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldMaskSecrets),
|
||||||
|
|||||||
@@ -27,6 +27,10 @@ export type TCreateIntegrationDTO = {
|
|||||||
key: string;
|
key: string;
|
||||||
value: string;
|
value: string;
|
||||||
}[];
|
}[];
|
||||||
|
|
||||||
|
githubVisibility?: string;
|
||||||
|
githubVisibilityRepoIds?: string[];
|
||||||
|
|
||||||
kmsKeyId?: string;
|
kmsKeyId?: string;
|
||||||
shouldDisableDelete?: boolean;
|
shouldDisableDelete?: boolean;
|
||||||
shouldMaskSecrets?: boolean;
|
shouldMaskSecrets?: boolean;
|
||||||
|
|||||||
Reference in New Issue
Block a user