feat: add initial sync behavior for gitlab

This commit is contained in:
Sheen Capadngan
2025-01-09 20:43:14 +08:00
parent 5d8f32b774
commit 858e569d4d
2 changed files with 141 additions and 12 deletions

View File

@@ -2772,13 +2772,23 @@ const syncSecretsAzureDevops = async ({
* Sync/push [secrets] to GitLab repo with name [integration.app] * Sync/push [secrets] to GitLab repo with name [integration.app]
*/ */
const syncSecretsGitLab = async ({ const syncSecretsGitLab = async ({
createManySecretsRawFn,
integrationAuth, integrationAuth,
integration, integration,
secrets, secrets,
accessToken accessToken
}: { }: {
createManySecretsRawFn: (params: TCreateManySecretsRawFn) => Promise<Array<{ id: string }>>;
integrationAuth: TIntegrationAuths; integrationAuth: TIntegrationAuths;
integration: TIntegrations; integration: TIntegrations & {
projectId: string;
environment: {
id: string;
name: string;
slug: string;
};
secretPath: string;
};
secrets: Record<string, { value: string; comment?: string }>; secrets: Record<string, { value: string; comment?: string }>;
accessToken: string; accessToken: string;
}) => { }) => {
@@ -2835,6 +2845,82 @@ const syncSecretsGitLab = async ({
return isValid; return isValid;
}); });
if (!integration.lastUsed) {
const secretsToAddToInfisical: { [key: string]: GitLabSecret } = {};
const secretsToRemoveInGitlab: GitLabSecret[] = [];
if (!metadata.initialSyncBehavior) {
metadata.initialSyncBehavior = IntegrationInitialSyncBehavior.OVERWRITE_TARGET;
}
getSecretsRes.forEach((gitlabSecret) => {
// first time using integration
// -> apply initial sync behavior
switch (metadata.initialSyncBehavior) {
// Override all the secrets in GitLab
case IntegrationInitialSyncBehavior.OVERWRITE_TARGET: {
if (!(gitlabSecret.key in secrets)) {
secretsToRemoveInGitlab.push(gitlabSecret);
}
break;
}
case IntegrationInitialSyncBehavior.PREFER_SOURCE: {
// if the secret is not in infisical, we need to add it to infisical
if (!(gitlabSecret.key in secrets)) {
secrets[gitlabSecret.key] = {
value: gitlabSecret.value
};
// need to remove prefix and suffix from what we're saving to Infisical
const prefix = metadata?.secretPrefix || "";
const suffix = metadata?.secretSuffix || "";
let processedKey = gitlabSecret.key;
// Remove prefix if it exists at the start
if (prefix && processedKey.startsWith(prefix)) {
processedKey = processedKey.slice(prefix.length);
}
// Remove suffix if it exists at the end
if (suffix && processedKey.endsWith(suffix)) {
processedKey = processedKey.slice(0, -suffix.length);
}
secretsToAddToInfisical[processedKey] = gitlabSecret;
}
break;
}
default: {
throw new Error(`Invalid initial sync behavior: ${metadata.initialSyncBehavior}`);
}
}
});
if (Object.keys(secretsToAddToInfisical).length) {
await createManySecretsRawFn({
projectId: integration.projectId,
environment: integration.environment.slug,
path: integration.secretPath,
secrets: Object.keys(secretsToAddToInfisical).map((key) => ({
secretName: key,
secretValue: secretsToAddToInfisical[key].value,
type: SecretType.Shared,
secretComment: ""
}))
});
}
for await (const gitlabSecret of secretsToRemoveInGitlab) {
await request.delete(
`${gitLabApiUrl}/v4/projects/${integration?.appId}/variables/${gitlabSecret.key}?filter[environment_scope]=${integration.targetEnvironment}`,
{
headers: {
Authorization: `Bearer ${accessToken}`
}
}
);
}
}
for await (const key of Object.keys(secrets)) { for await (const key of Object.keys(secrets)) {
const existingSecret = getSecretsRes.find((s) => s.key === key); const existingSecret = getSecretsRes.find((s) => s.key === key);
if (!existingSecret) { if (!existingSecret) {
@@ -4554,7 +4640,8 @@ export const syncIntegrationSecrets = async ({
integrationAuth, integrationAuth,
integration, integration,
secrets, secrets,
accessToken accessToken,
createManySecretsRawFn
}); });
break; break;
case Integrations.RENDER: case Integrations.RENDER:

View File

@@ -34,6 +34,7 @@ import {
useGetIntegrationAuthById, useGetIntegrationAuthById,
useGetIntegrationAuthTeams useGetIntegrationAuthTeams
} from "@app/hooks/api/integrationAuth"; } from "@app/hooks/api/integrationAuth";
import { IntegrationSyncBehavior } from "@app/hooks/api/integrations/types";
const gitLabEntities = [ const gitLabEntities = [
{ name: "Individual", value: "individual" }, { name: "Individual", value: "individual" },
@@ -45,6 +46,14 @@ enum TabSections {
Options = "options" Options = "options"
} }
const initialSyncBehaviors = [
{
label: "No Import - Overwrite all values in GitLab",
value: IntegrationSyncBehavior.OVERWRITE_TARGET
},
{ label: "Import - Prefer values from Infisical", value: IntegrationSyncBehavior.PREFER_SOURCE }
];
const schema = z.object({ const schema = z.object({
targetEntity: z.enum([gitLabEntities[0].value, gitLabEntities[1].value]), targetEntity: z.enum([gitLabEntities[0].value, gitLabEntities[1].value]),
targetTeamId: z.string().optional(), targetTeamId: z.string().optional(),
@@ -55,7 +64,8 @@ const schema = z.object({
secretPrefix: z.string().optional(), secretPrefix: z.string().optional(),
secretSuffix: z.string().optional(), secretSuffix: z.string().optional(),
shouldMaskSecrets: z.boolean().optional(), shouldMaskSecrets: z.boolean().optional(),
shouldProtectSecrets: z.boolean() shouldProtectSecrets: z.boolean().default(false),
initialSyncBehavior: z.nativeEnum(IntegrationSyncBehavior)
}); });
type FormData = z.infer<typeof schema>; type FormData = z.infer<typeof schema>;
@@ -74,7 +84,8 @@ export const GitlabConfigurePage = () => {
secretPath: "/", secretPath: "/",
secretPrefix: "", secretPrefix: "",
secretSuffix: "", secretSuffix: "",
selectedSourceEnvironment: currentWorkspace.environments[0].slug selectedSourceEnvironment: currentWorkspace.environments[0].slug,
initialSyncBehavior: IntegrationSyncBehavior.PREFER_SOURCE
} }
}); });
const selectedSourceEnvironment = watch("selectedSourceEnvironment"); const selectedSourceEnvironment = watch("selectedSourceEnvironment");
@@ -135,7 +146,8 @@ export const GitlabConfigurePage = () => {
secretPrefix, secretPrefix,
secretSuffix, secretSuffix,
shouldMaskSecrets, shouldMaskSecrets,
shouldProtectSecrets shouldProtectSecrets,
initialSyncBehavior
}: FormData) => { }: FormData) => {
try { try {
setIsLoading(true); setIsLoading(true);
@@ -155,7 +167,8 @@ export const GitlabConfigurePage = () => {
secretPrefix, secretPrefix,
secretSuffix, secretSuffix,
shouldMaskSecrets, shouldMaskSecrets,
shouldProtectSecrets shouldProtectSecrets,
initialSyncBehavior
} }
}); });
@@ -178,7 +191,11 @@ export const GitlabConfigurePage = () => {
integrationAuthTeams ? ( integrationAuthTeams ? (
<form <form
onSubmit={handleSubmit((data: FormData) => { onSubmit={handleSubmit((data: FormData) => {
if (!data.secretPrefix && !data.secretSuffix) { if (
!data.secretPrefix &&
!data.secretSuffix &&
data.initialSyncBehavior === IntegrationSyncBehavior.OVERWRITE_TARGET
) {
handlePopUpOpen("confirmIntegration", data); handlePopUpOpen("confirmIntegration", data);
return; return;
} }
@@ -378,6 +395,36 @@ export const GitlabConfigurePage = () => {
</FormControl> </FormControl>
)} )}
/> />
<Controller
control={control}
name="initialSyncBehavior"
render={({ field: { onChange, ...field }, fieldState: { error } }) => (
<FormControl
label="Initial Sync Behavior"
errorText={error?.message}
isError={Boolean(error)}
>
<Select
defaultValue={field.value}
onValueChange={(e) => onChange(e)}
className="w-full border border-mineshaft-500"
dropdownContainerClassName="max-w-full"
>
{initialSyncBehaviors.map((b) => {
return (
<SelectItem
value={b.value}
key={`sync-behavior-${b.value}`}
className="w-full"
>
{b.label}
</SelectItem>
);
})}
</Select>
</FormControl>
)}
/>
</motion.div> </motion.div>
</TabPanel> </TabPanel>
<TabPanel value={TabSections.Options}> <TabPanel value={TabSections.Options}>
@@ -462,11 +509,6 @@ export const GitlabConfigurePage = () => {
Create Integration Create Integration
</Button> </Button>
</Card> </Card>
{/* <div className="border-t border-mineshaft-800 w-full max-w-md mt-6"/>
<div className="flex flex-col bg-mineshaft-800 border border-mineshaft-600 w-full p-4 max-w-lg mt-6 rounded-md">
<div className="flex flex-row items-center"><FontAwesomeIcon icon={faCircleInfo} className="text-mineshaft-200 text-xl"/> <span className="ml-3 text-md text-mineshaft-100">Pro Tip</span></div>
<span className="text-mineshaft-300 text-sm mt-4">After creating an integration, your secrets will start syncing immediately. This might cause an unexpected override of current secrets in GitLab with secrets from Infisical.</span>
</div> */}
<Modal <Modal
isOpen={popUp.confirmIntegration?.isOpen} isOpen={popUp.confirmIntegration?.isOpen}
onOpenChange={(isOpen) => handlePopUpToggle("confirmIntegration", isOpen)} onOpenChange={(isOpen) => handlePopUpToggle("confirmIntegration", isOpen)}