mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat: add initial sync behavior for gitlab
This commit is contained in:
@@ -2772,13 +2772,23 @@ const syncSecretsAzureDevops = async ({
|
|||||||
* Sync/push [secrets] to GitLab repo with name [integration.app]
|
* Sync/push [secrets] to GitLab repo with name [integration.app]
|
||||||
*/
|
*/
|
||||||
const syncSecretsGitLab = async ({
|
const syncSecretsGitLab = async ({
|
||||||
|
createManySecretsRawFn,
|
||||||
integrationAuth,
|
integrationAuth,
|
||||||
integration,
|
integration,
|
||||||
secrets,
|
secrets,
|
||||||
accessToken
|
accessToken
|
||||||
}: {
|
}: {
|
||||||
|
createManySecretsRawFn: (params: TCreateManySecretsRawFn) => Promise<Array<{ id: string }>>;
|
||||||
integrationAuth: TIntegrationAuths;
|
integrationAuth: TIntegrationAuths;
|
||||||
integration: TIntegrations;
|
integration: TIntegrations & {
|
||||||
|
projectId: string;
|
||||||
|
environment: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
slug: string;
|
||||||
|
};
|
||||||
|
secretPath: string;
|
||||||
|
};
|
||||||
secrets: Record<string, { value: string; comment?: string }>;
|
secrets: Record<string, { value: string; comment?: string }>;
|
||||||
accessToken: string;
|
accessToken: string;
|
||||||
}) => {
|
}) => {
|
||||||
@@ -2835,6 +2845,82 @@ const syncSecretsGitLab = async ({
|
|||||||
return isValid;
|
return isValid;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (!integration.lastUsed) {
|
||||||
|
const secretsToAddToInfisical: { [key: string]: GitLabSecret } = {};
|
||||||
|
const secretsToRemoveInGitlab: GitLabSecret[] = [];
|
||||||
|
|
||||||
|
if (!metadata.initialSyncBehavior) {
|
||||||
|
metadata.initialSyncBehavior = IntegrationInitialSyncBehavior.OVERWRITE_TARGET;
|
||||||
|
}
|
||||||
|
|
||||||
|
getSecretsRes.forEach((gitlabSecret) => {
|
||||||
|
// first time using integration
|
||||||
|
// -> apply initial sync behavior
|
||||||
|
switch (metadata.initialSyncBehavior) {
|
||||||
|
// Override all the secrets in GitLab
|
||||||
|
case IntegrationInitialSyncBehavior.OVERWRITE_TARGET: {
|
||||||
|
if (!(gitlabSecret.key in secrets)) {
|
||||||
|
secretsToRemoveInGitlab.push(gitlabSecret);
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
case IntegrationInitialSyncBehavior.PREFER_SOURCE: {
|
||||||
|
// if the secret is not in infisical, we need to add it to infisical
|
||||||
|
if (!(gitlabSecret.key in secrets)) {
|
||||||
|
secrets[gitlabSecret.key] = {
|
||||||
|
value: gitlabSecret.value
|
||||||
|
};
|
||||||
|
// need to remove prefix and suffix from what we're saving to Infisical
|
||||||
|
const prefix = metadata?.secretPrefix || "";
|
||||||
|
const suffix = metadata?.secretSuffix || "";
|
||||||
|
let processedKey = gitlabSecret.key;
|
||||||
|
|
||||||
|
// Remove prefix if it exists at the start
|
||||||
|
if (prefix && processedKey.startsWith(prefix)) {
|
||||||
|
processedKey = processedKey.slice(prefix.length);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Remove suffix if it exists at the end
|
||||||
|
if (suffix && processedKey.endsWith(suffix)) {
|
||||||
|
processedKey = processedKey.slice(0, -suffix.length);
|
||||||
|
}
|
||||||
|
|
||||||
|
secretsToAddToInfisical[processedKey] = gitlabSecret;
|
||||||
|
}
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
default: {
|
||||||
|
throw new Error(`Invalid initial sync behavior: ${metadata.initialSyncBehavior}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
if (Object.keys(secretsToAddToInfisical).length) {
|
||||||
|
await createManySecretsRawFn({
|
||||||
|
projectId: integration.projectId,
|
||||||
|
environment: integration.environment.slug,
|
||||||
|
path: integration.secretPath,
|
||||||
|
secrets: Object.keys(secretsToAddToInfisical).map((key) => ({
|
||||||
|
secretName: key,
|
||||||
|
secretValue: secretsToAddToInfisical[key].value,
|
||||||
|
type: SecretType.Shared,
|
||||||
|
secretComment: ""
|
||||||
|
}))
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
for await (const gitlabSecret of secretsToRemoveInGitlab) {
|
||||||
|
await request.delete(
|
||||||
|
`${gitLabApiUrl}/v4/projects/${integration?.appId}/variables/${gitlabSecret.key}?filter[environment_scope]=${integration.targetEnvironment}`,
|
||||||
|
{
|
||||||
|
headers: {
|
||||||
|
Authorization: `Bearer ${accessToken}`
|
||||||
|
}
|
||||||
|
}
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
for await (const key of Object.keys(secrets)) {
|
for await (const key of Object.keys(secrets)) {
|
||||||
const existingSecret = getSecretsRes.find((s) => s.key === key);
|
const existingSecret = getSecretsRes.find((s) => s.key === key);
|
||||||
if (!existingSecret) {
|
if (!existingSecret) {
|
||||||
@@ -4554,7 +4640,8 @@ export const syncIntegrationSecrets = async ({
|
|||||||
integrationAuth,
|
integrationAuth,
|
||||||
integration,
|
integration,
|
||||||
secrets,
|
secrets,
|
||||||
accessToken
|
accessToken,
|
||||||
|
createManySecretsRawFn
|
||||||
});
|
});
|
||||||
break;
|
break;
|
||||||
case Integrations.RENDER:
|
case Integrations.RENDER:
|
||||||
|
|||||||
@@ -34,6 +34,7 @@ import {
|
|||||||
useGetIntegrationAuthById,
|
useGetIntegrationAuthById,
|
||||||
useGetIntegrationAuthTeams
|
useGetIntegrationAuthTeams
|
||||||
} from "@app/hooks/api/integrationAuth";
|
} from "@app/hooks/api/integrationAuth";
|
||||||
|
import { IntegrationSyncBehavior } from "@app/hooks/api/integrations/types";
|
||||||
|
|
||||||
const gitLabEntities = [
|
const gitLabEntities = [
|
||||||
{ name: "Individual", value: "individual" },
|
{ name: "Individual", value: "individual" },
|
||||||
@@ -45,6 +46,14 @@ enum TabSections {
|
|||||||
Options = "options"
|
Options = "options"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const initialSyncBehaviors = [
|
||||||
|
{
|
||||||
|
label: "No Import - Overwrite all values in GitLab",
|
||||||
|
value: IntegrationSyncBehavior.OVERWRITE_TARGET
|
||||||
|
},
|
||||||
|
{ label: "Import - Prefer values from Infisical", value: IntegrationSyncBehavior.PREFER_SOURCE }
|
||||||
|
];
|
||||||
|
|
||||||
const schema = z.object({
|
const schema = z.object({
|
||||||
targetEntity: z.enum([gitLabEntities[0].value, gitLabEntities[1].value]),
|
targetEntity: z.enum([gitLabEntities[0].value, gitLabEntities[1].value]),
|
||||||
targetTeamId: z.string().optional(),
|
targetTeamId: z.string().optional(),
|
||||||
@@ -55,7 +64,8 @@ const schema = z.object({
|
|||||||
secretPrefix: z.string().optional(),
|
secretPrefix: z.string().optional(),
|
||||||
secretSuffix: z.string().optional(),
|
secretSuffix: z.string().optional(),
|
||||||
shouldMaskSecrets: z.boolean().optional(),
|
shouldMaskSecrets: z.boolean().optional(),
|
||||||
shouldProtectSecrets: z.boolean()
|
shouldProtectSecrets: z.boolean().default(false),
|
||||||
|
initialSyncBehavior: z.nativeEnum(IntegrationSyncBehavior)
|
||||||
});
|
});
|
||||||
|
|
||||||
type FormData = z.infer<typeof schema>;
|
type FormData = z.infer<typeof schema>;
|
||||||
@@ -74,7 +84,8 @@ export const GitlabConfigurePage = () => {
|
|||||||
secretPath: "/",
|
secretPath: "/",
|
||||||
secretPrefix: "",
|
secretPrefix: "",
|
||||||
secretSuffix: "",
|
secretSuffix: "",
|
||||||
selectedSourceEnvironment: currentWorkspace.environments[0].slug
|
selectedSourceEnvironment: currentWorkspace.environments[0].slug,
|
||||||
|
initialSyncBehavior: IntegrationSyncBehavior.PREFER_SOURCE
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
const selectedSourceEnvironment = watch("selectedSourceEnvironment");
|
const selectedSourceEnvironment = watch("selectedSourceEnvironment");
|
||||||
@@ -135,7 +146,8 @@ export const GitlabConfigurePage = () => {
|
|||||||
secretPrefix,
|
secretPrefix,
|
||||||
secretSuffix,
|
secretSuffix,
|
||||||
shouldMaskSecrets,
|
shouldMaskSecrets,
|
||||||
shouldProtectSecrets
|
shouldProtectSecrets,
|
||||||
|
initialSyncBehavior
|
||||||
}: FormData) => {
|
}: FormData) => {
|
||||||
try {
|
try {
|
||||||
setIsLoading(true);
|
setIsLoading(true);
|
||||||
@@ -155,7 +167,8 @@ export const GitlabConfigurePage = () => {
|
|||||||
secretPrefix,
|
secretPrefix,
|
||||||
secretSuffix,
|
secretSuffix,
|
||||||
shouldMaskSecrets,
|
shouldMaskSecrets,
|
||||||
shouldProtectSecrets
|
shouldProtectSecrets,
|
||||||
|
initialSyncBehavior
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
@@ -178,7 +191,11 @@ export const GitlabConfigurePage = () => {
|
|||||||
integrationAuthTeams ? (
|
integrationAuthTeams ? (
|
||||||
<form
|
<form
|
||||||
onSubmit={handleSubmit((data: FormData) => {
|
onSubmit={handleSubmit((data: FormData) => {
|
||||||
if (!data.secretPrefix && !data.secretSuffix) {
|
if (
|
||||||
|
!data.secretPrefix &&
|
||||||
|
!data.secretSuffix &&
|
||||||
|
data.initialSyncBehavior === IntegrationSyncBehavior.OVERWRITE_TARGET
|
||||||
|
) {
|
||||||
handlePopUpOpen("confirmIntegration", data);
|
handlePopUpOpen("confirmIntegration", data);
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -378,6 +395,36 @@ export const GitlabConfigurePage = () => {
|
|||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
|
<Controller
|
||||||
|
control={control}
|
||||||
|
name="initialSyncBehavior"
|
||||||
|
render={({ field: { onChange, ...field }, fieldState: { error } }) => (
|
||||||
|
<FormControl
|
||||||
|
label="Initial Sync Behavior"
|
||||||
|
errorText={error?.message}
|
||||||
|
isError={Boolean(error)}
|
||||||
|
>
|
||||||
|
<Select
|
||||||
|
defaultValue={field.value}
|
||||||
|
onValueChange={(e) => onChange(e)}
|
||||||
|
className="w-full border border-mineshaft-500"
|
||||||
|
dropdownContainerClassName="max-w-full"
|
||||||
|
>
|
||||||
|
{initialSyncBehaviors.map((b) => {
|
||||||
|
return (
|
||||||
|
<SelectItem
|
||||||
|
value={b.value}
|
||||||
|
key={`sync-behavior-${b.value}`}
|
||||||
|
className="w-full"
|
||||||
|
>
|
||||||
|
{b.label}
|
||||||
|
</SelectItem>
|
||||||
|
);
|
||||||
|
})}
|
||||||
|
</Select>
|
||||||
|
</FormControl>
|
||||||
|
)}
|
||||||
|
/>
|
||||||
</motion.div>
|
</motion.div>
|
||||||
</TabPanel>
|
</TabPanel>
|
||||||
<TabPanel value={TabSections.Options}>
|
<TabPanel value={TabSections.Options}>
|
||||||
@@ -462,11 +509,6 @@ export const GitlabConfigurePage = () => {
|
|||||||
Create Integration
|
Create Integration
|
||||||
</Button>
|
</Button>
|
||||||
</Card>
|
</Card>
|
||||||
{/* <div className="border-t border-mineshaft-800 w-full max-w-md mt-6"/>
|
|
||||||
<div className="flex flex-col bg-mineshaft-800 border border-mineshaft-600 w-full p-4 max-w-lg mt-6 rounded-md">
|
|
||||||
<div className="flex flex-row items-center"><FontAwesomeIcon icon={faCircleInfo} className="text-mineshaft-200 text-xl"/> <span className="ml-3 text-md text-mineshaft-100">Pro Tip</span></div>
|
|
||||||
<span className="text-mineshaft-300 text-sm mt-4">After creating an integration, your secrets will start syncing immediately. This might cause an unexpected override of current secrets in GitLab with secrets from Infisical.</span>
|
|
||||||
</div> */}
|
|
||||||
<Modal
|
<Modal
|
||||||
isOpen={popUp.confirmIntegration?.isOpen}
|
isOpen={popUp.confirmIntegration?.isOpen}
|
||||||
onOpenChange={(isOpen) => handlePopUpToggle("confirmIntegration", isOpen)}
|
onOpenChange={(isOpen) => handlePopUpToggle("confirmIntegration", isOpen)}
|
||||||
|
|||||||
Reference in New Issue
Block a user