Merge pull request #1806 from Infisical/aws-non-delete

Add option to not delete secrets in parameter store
This commit is contained in:
Akhil Mohan
2024-05-09 21:56:48 +05:30
committed by GitHub
7 changed files with 35 additions and 17 deletions

View File

@@ -627,7 +627,8 @@ export const INTEGRATION = {
shouldAutoRedeploy: "Used by Render to trigger auto deploy.", shouldAutoRedeploy: "Used by Render to trigger auto deploy.",
secretGCPLabel: "The label for GCP secrets.", secretGCPLabel: "The label for GCP secrets.",
secretAWSTag: "The tags for AWS secrets.", secretAWSTag: "The tags for AWS secrets.",
kmsKeyId: "The ID of the encryption key from AWS KMS." kmsKeyId: "The ID of the encryption key from AWS KMS.",
shouldDisableDelete: "The flag to disable deletion of secrets in AWS Parameter Store."
} }
}, },
UPDATE: { UPDATE: {

View File

@@ -66,7 +66,8 @@ export const registerIntegrationRouter = async (server: FastifyZodProvider) => {
) )
.optional() .optional()
.describe(INTEGRATION.CREATE.metadata.secretAWSTag), .describe(INTEGRATION.CREATE.metadata.secretAWSTag),
kmsKeyId: z.string().optional().describe(INTEGRATION.CREATE.metadata.kmsKeyId) kmsKeyId: z.string().optional().describe(INTEGRATION.CREATE.metadata.kmsKeyId),
shouldDisableDelete: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldDisableDelete)
}) })
.default({}) .default({})
}), }),

View File

@@ -517,20 +517,22 @@ const syncSecretsAWSParameterStore = async ({
}) })
); );
// Identify secrets to delete if (!metadata.shouldDisableDelete) {
await Promise.all( // Identify secrets to delete
Object.keys(awsParameterStoreSecretsObj).map(async (key) => { await Promise.all(
if (!(key in secrets)) { Object.keys(awsParameterStoreSecretsObj).map(async (key) => {
// case: if (!(key in secrets)) {
// -> delete secret // case:
await ssm // -> delete secret
.deleteParameter({ await ssm
Name: awsParameterStoreSecretsObj[key].Name as string .deleteParameter({
}) Name: awsParameterStoreSecretsObj[key].Name as string
.promise(); })
} .promise();
}) }
); })
);
}
}; };
/** /**

View File

@@ -27,6 +27,7 @@ export type TCreateIntegrationDTO = {
value: string; value: string;
}[]; }[];
kmsKeyId?: string; kmsKeyId?: string;
shouldDisableDelete?: boolean;
}; };
} & Omit<TProjectPermission, "projectId">; } & Omit<TProjectPermission, "projectId">;

View File

@@ -68,6 +68,7 @@ export const useCreateIntegration = () => {
value: string; value: string;
}[]; }[];
kmsKeyId?: string; kmsKeyId?: string;
shouldDisableDelete?: boolean;
}; };
}) => { }) => {
const { const {

View File

@@ -89,6 +89,7 @@ export default function AWSParameterStoreCreateIntegrationPage() {
const [isLoading, setIsLoading] = useState(false); const [isLoading, setIsLoading] = useState(false);
const [shouldTag, setShouldTag] = useState(false); const [shouldTag, setShouldTag] = useState(false);
const [shouldDisableDelete, setShouldDisableDelete] = useState(false);
const [tagKey, setTagKey] = useState(""); const [tagKey, setTagKey] = useState("");
const [tagValue, setTagValue] = useState(""); const [tagValue, setTagValue] = useState("");
const [kmsKeyId, setKmsKeyId] = useState(""); const [kmsKeyId, setKmsKeyId] = useState("");
@@ -144,7 +145,8 @@ export default function AWSParameterStoreCreateIntegrationPage() {
] ]
} }
: {}), : {}),
...(kmsKeyId && { kmsKeyId }) ...(kmsKeyId && { kmsKeyId }),
...(shouldDisableDelete && { shouldDisableDelete })
} }
}); });
@@ -273,6 +275,15 @@ export default function AWSParameterStoreCreateIntegrationPage() {
exit={{ opacity: 0, translateX: 30 }} exit={{ opacity: 0, translateX: 30 }}
> >
<div className="mt-2 ml-1"> <div className="mt-2 ml-1">
<Switch
id="delete-aws"
onCheckedChange={() => setShouldDisableDelete(!shouldDisableDelete)}
isChecked={shouldDisableDelete}
>
Disable deleting secrets in AWS Parameter Store
</Switch>
</div>
<div className="mt-4 ml-1">
<Switch <Switch
id="tag-aws" id="tag-aws"
onCheckedChange={() => setShouldTag(!shouldTag)} onCheckedChange={() => setShouldTag(!shouldTag)}

View File

@@ -10,4 +10,5 @@ export type Metadata = {
value: string; value: string;
}[] }[]
kmsKeyId?: string; kmsKeyId?: string;
shouldDisableDelete?: boolean;
} }