mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 09:28:52 +00:00
Merge pull request #4667 from Infisical/feat/in-platform-vault-migration-tooling
feat: in-platform migration tooling for Vault policies + scaffolding
This commit is contained in:
Vendored
+8
@@ -518,6 +518,9 @@ import {
|
||||
TUsers,
|
||||
TUsersInsert,
|
||||
TUsersUpdate,
|
||||
TVaultExternalMigrationConfigs,
|
||||
TVaultExternalMigrationConfigsInsert,
|
||||
TVaultExternalMigrationConfigsUpdate,
|
||||
TWebhooks,
|
||||
TWebhooksInsert,
|
||||
TWebhooksUpdate,
|
||||
@@ -1345,5 +1348,10 @@ declare module "knex/types/tables" {
|
||||
TAdditionalPrivilegesInsert,
|
||||
TAdditionalPrivilegesUpdate
|
||||
>;
|
||||
[TableName.VaultExternalMigrationConfig]: KnexOriginal.CompositeTableType<
|
||||
TVaultExternalMigrationConfigs,
|
||||
TVaultExternalMigrationConfigsInsert,
|
||||
TVaultExternalMigrationConfigsUpdate
|
||||
>;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
import { Knex } from "knex";
|
||||
|
||||
import { TableName } from "../schemas";
|
||||
import { createOnUpdateTrigger, dropOnUpdateTrigger } from "../utils";
|
||||
|
||||
export async function up(knex: Knex): Promise<void> {
|
||||
if (!(await knex.schema.hasTable(TableName.VaultExternalMigrationConfig))) {
|
||||
await knex.schema.createTable(TableName.VaultExternalMigrationConfig, (t) => {
|
||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||
t.uuid("orgId").notNullable();
|
||||
t.foreign("orgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
|
||||
|
||||
t.string("namespace").notNullable();
|
||||
|
||||
t.uuid("connectionId");
|
||||
t.foreign("connectionId").references("id").inTable(TableName.AppConnection);
|
||||
|
||||
t.timestamps(true, true, true);
|
||||
t.unique(["orgId", "namespace"]);
|
||||
});
|
||||
|
||||
await createOnUpdateTrigger(knex, TableName.VaultExternalMigrationConfig);
|
||||
}
|
||||
}
|
||||
|
||||
export async function down(knex: Knex): Promise<void> {
|
||||
await knex.schema.dropTableIfExists(TableName.VaultExternalMigrationConfig);
|
||||
await dropOnUpdateTrigger(knex, TableName.VaultExternalMigrationConfig);
|
||||
}
|
||||
@@ -176,5 +176,6 @@ export * from "./user-aliases";
|
||||
export * from "./user-encryption-keys";
|
||||
export * from "./user-group-membership";
|
||||
export * from "./users";
|
||||
export * from "./vault-external-migration-configs";
|
||||
export * from "./webhooks";
|
||||
export * from "./workflow-integrations";
|
||||
|
||||
@@ -203,7 +203,9 @@ export enum TableName {
|
||||
PamFolder = "pam_folders",
|
||||
PamResource = "pam_resources",
|
||||
PamAccount = "pam_accounts",
|
||||
PamSession = "pam_sessions"
|
||||
PamSession = "pam_sessions",
|
||||
|
||||
VaultExternalMigrationConfig = "vault_external_migration_configs"
|
||||
}
|
||||
|
||||
export type TImmutableDBKeys = "id" | "createdAt" | "updatedAt" | "commitId";
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
// Code generated by automation script, DO NOT EDIT.
|
||||
// Automated by pulling database and generating zod schema
|
||||
// To update. Just run npm run generate:schema
|
||||
// Written by akhilmhdh.
|
||||
|
||||
import { z } from "zod";
|
||||
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const VaultExternalMigrationConfigsSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
orgId: z.string().uuid(),
|
||||
namespace: z.string(),
|
||||
connectionId: z.string().uuid().nullable().optional(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date()
|
||||
});
|
||||
|
||||
export type TVaultExternalMigrationConfigs = z.infer<typeof VaultExternalMigrationConfigsSchema>;
|
||||
export type TVaultExternalMigrationConfigsInsert = Omit<
|
||||
z.input<typeof VaultExternalMigrationConfigsSchema>,
|
||||
TImmutableDBKeys
|
||||
>;
|
||||
export type TVaultExternalMigrationConfigsUpdate = Partial<
|
||||
Omit<z.input<typeof VaultExternalMigrationConfigsSchema>, TImmutableDBKeys>
|
||||
>;
|
||||
@@ -176,6 +176,7 @@ import { externalGroupOrgRoleMappingDALFactory } from "@app/services/external-gr
|
||||
import { externalGroupOrgRoleMappingServiceFactory } from "@app/services/external-group-org-role-mapping/external-group-org-role-mapping-service";
|
||||
import { externalMigrationQueueFactory } from "@app/services/external-migration/external-migration-queue";
|
||||
import { externalMigrationServiceFactory } from "@app/services/external-migration/external-migration-service";
|
||||
import { vaultExternalMigrationConfigDALFactory } from "@app/services/external-migration/vault-external-migration-config-dal";
|
||||
import { folderCheckpointDALFactory } from "@app/services/folder-checkpoint/folder-checkpoint-dal";
|
||||
import { folderCheckpointResourcesDALFactory } from "@app/services/folder-checkpoint-resources/folder-checkpoint-resources-dal";
|
||||
import { folderCommitDALFactory } from "@app/services/folder-commit/folder-commit-dal";
|
||||
@@ -534,6 +535,8 @@ export const registerRoutes = async (
|
||||
const membershipRoleDAL = membershipRoleDALFactory(db);
|
||||
const roleDAL = roleDALFactory(db);
|
||||
|
||||
const vaultExternalMigrationConfigDAL = vaultExternalMigrationConfigDALFactory(db);
|
||||
|
||||
const eventBusService = eventBusFactory(server.redis);
|
||||
const sseService = sseServiceFactory(eventBusService, server.redis);
|
||||
|
||||
@@ -1882,13 +1885,6 @@ export const registerRoutes = async (
|
||||
notificationService
|
||||
});
|
||||
|
||||
const migrationService = externalMigrationServiceFactory({
|
||||
externalMigrationQueue,
|
||||
userDAL,
|
||||
permissionService,
|
||||
gatewayService
|
||||
});
|
||||
|
||||
const externalGroupOrgRoleMappingService = externalGroupOrgRoleMappingServiceFactory({
|
||||
permissionService,
|
||||
licenseService,
|
||||
@@ -2205,6 +2201,18 @@ export const registerRoutes = async (
|
||||
kmsService
|
||||
});
|
||||
|
||||
const migrationService = externalMigrationServiceFactory({
|
||||
externalMigrationQueue,
|
||||
userDAL,
|
||||
permissionService,
|
||||
gatewayService,
|
||||
kmsService,
|
||||
appConnectionService,
|
||||
vaultExternalMigrationConfigDAL,
|
||||
secretService,
|
||||
auditLogService
|
||||
});
|
||||
|
||||
// setup the communication with license key server
|
||||
await licenseService.init();
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@ import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
import {
|
||||
ExternalMigrationProviders,
|
||||
VaultImportStatus,
|
||||
VaultMappingType
|
||||
} from "@app/services/external-migration/external-migration-types";
|
||||
|
||||
@@ -113,4 +114,366 @@ export const registerExternalMigrationRouter = async (server: FastifyZodProvider
|
||||
return { enabled };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/configs",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
response: {
|
||||
200: z.object({
|
||||
configs: z
|
||||
.object({
|
||||
id: z.string(),
|
||||
orgId: z.string(),
|
||||
namespace: z.string(),
|
||||
connectionId: z.string().nullish(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date()
|
||||
})
|
||||
.array()
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const configs = await server.services.migration.getVaultExternalMigrationConfigs({
|
||||
actor: req.permission
|
||||
});
|
||||
|
||||
return { configs };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "POST",
|
||||
url: "/vault/configs",
|
||||
config: {
|
||||
rateLimit: writeLimit
|
||||
},
|
||||
schema: {
|
||||
body: z.object({
|
||||
connectionId: z.string(),
|
||||
namespace: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
config: z.object({
|
||||
id: z.string(),
|
||||
orgId: z.string(),
|
||||
namespace: z.string(),
|
||||
connectionId: z.string().nullable().optional(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date()
|
||||
})
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const config = await server.services.migration.createVaultExternalMigration({
|
||||
...req.body,
|
||||
actor: req.permission
|
||||
});
|
||||
|
||||
return { config };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "PUT",
|
||||
url: "/vault/configs/:id",
|
||||
config: {
|
||||
rateLimit: writeLimit
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
id: z.string()
|
||||
}),
|
||||
body: z.object({
|
||||
connectionId: z.string(),
|
||||
namespace: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
config: z.object({
|
||||
id: z.string(),
|
||||
orgId: z.string(),
|
||||
namespace: z.string(),
|
||||
connectionId: z.string().nullable().optional(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date()
|
||||
})
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const config = await server.services.migration.updateVaultExternalMigration({
|
||||
id: req.params.id,
|
||||
...req.body,
|
||||
actor: req.permission
|
||||
});
|
||||
|
||||
return { config };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "DELETE",
|
||||
url: "/vault/configs/:id",
|
||||
config: {
|
||||
rateLimit: writeLimit
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
id: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
config: z.object({
|
||||
id: z.string(),
|
||||
orgId: z.string(),
|
||||
namespace: z.string(),
|
||||
connectionId: z.string().nullable().optional(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date()
|
||||
})
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const config = await server.services.migration.deleteVaultExternalMigration({
|
||||
id: req.params.id,
|
||||
actor: req.permission
|
||||
});
|
||||
|
||||
return { config };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/namespaces",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
response: {
|
||||
200: z.object({
|
||||
namespaces: z.array(z.object({ id: z.string(), name: z.string() }))
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const namespaces = await server.services.migration.getVaultNamespaces({
|
||||
actor: req.permission
|
||||
});
|
||||
|
||||
return { namespaces };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/policies",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
querystring: z.object({
|
||||
namespace: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
policies: z.array(z.object({ name: z.string(), rules: z.string() }))
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const policies = await server.services.migration.getVaultPolicies({
|
||||
actor: req.permission,
|
||||
namespace: req.query.namespace
|
||||
});
|
||||
|
||||
return { policies };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/mounts",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
querystring: z.object({
|
||||
namespace: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
mounts: z.array(z.object({ path: z.string(), type: z.string(), version: z.string().nullish() }))
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const mounts = await server.services.migration.getVaultMounts({
|
||||
actor: req.permission,
|
||||
namespace: req.query.namespace
|
||||
});
|
||||
|
||||
return { mounts };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/auth-mounts",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
querystring: z.object({
|
||||
namespace: z.string(),
|
||||
authType: z.string().optional()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
mounts: z.array(z.object({ path: z.string(), type: z.string() }))
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const mounts = await server.services.migration.getVaultAuthMounts({
|
||||
actor: req.permission,
|
||||
namespace: req.query.namespace,
|
||||
authType: req.query.authType
|
||||
});
|
||||
|
||||
return { mounts };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "POST",
|
||||
url: "/vault/import-secrets",
|
||||
config: {
|
||||
rateLimit: writeLimit
|
||||
},
|
||||
schema: {
|
||||
body: z.object({
|
||||
projectId: z.string(),
|
||||
environment: z.string(),
|
||||
secretPath: z.string(),
|
||||
vaultNamespace: z.string(),
|
||||
vaultSecretPath: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
status: z.nativeEnum(VaultImportStatus)
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const result = await server.services.migration.importVaultSecrets({
|
||||
actor: req.permission,
|
||||
auditLogInfo: req.auditLogInfo,
|
||||
...req.body
|
||||
});
|
||||
|
||||
return result;
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/secret-paths",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
querystring: z.object({
|
||||
namespace: z.string(),
|
||||
mountPath: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z.object({
|
||||
secretPaths: z.string().array()
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const secretPaths = await server.services.migration.getVaultSecretPaths({
|
||||
actor: req.permission,
|
||||
namespace: req.query.namespace,
|
||||
mountPath: req.query.mountPath
|
||||
});
|
||||
|
||||
return { secretPaths };
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: "/vault/auth-roles/kubernetes",
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
querystring: z.object({
|
||||
namespace: z.string(),
|
||||
mountPath: z.string()
|
||||
}),
|
||||
|
||||
response: {
|
||||
200: z.object({
|
||||
roles: z.array(
|
||||
z.object({
|
||||
name: z.string(),
|
||||
mountPath: z.string(),
|
||||
bound_service_account_names: z.array(z.string()),
|
||||
bound_service_account_namespaces: z.array(z.string()),
|
||||
token_ttl: z.number().optional(),
|
||||
token_max_ttl: z.number().optional(),
|
||||
token_policies: z.array(z.string()).optional(),
|
||||
token_bound_cidrs: z.array(z.string()).optional(),
|
||||
token_explicit_max_ttl: z.number().optional(),
|
||||
token_no_default_policy: z.boolean().optional(),
|
||||
token_num_uses: z.number().optional(),
|
||||
token_period: z.number().optional(),
|
||||
token_type: z.string().optional(),
|
||||
audience: z.string().optional(),
|
||||
alias_name_source: z.string().optional(),
|
||||
config: z.object({
|
||||
kubernetes_host: z.string(),
|
||||
kubernetes_ca_cert: z.string().optional(),
|
||||
issuer: z.string().optional(),
|
||||
disable_iss_validation: z.boolean().optional(),
|
||||
disable_local_ca_jwt: z.boolean().optional()
|
||||
})
|
||||
})
|
||||
)
|
||||
})
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const roles = await server.services.migration.getVaultKubernetesAuthRoles({
|
||||
actor: req.permission,
|
||||
namespace: req.query.namespace,
|
||||
mountPath: req.query.mountPath
|
||||
});
|
||||
|
||||
return { roles };
|
||||
}
|
||||
});
|
||||
};
|
||||
|
||||
@@ -2,3 +2,7 @@ export enum HCVaultConnectionMethod {
|
||||
AccessToken = "access-token",
|
||||
AppRole = "app-role"
|
||||
}
|
||||
|
||||
export enum HCVaultAuthType {
|
||||
Kubernetes = "kubernetes"
|
||||
}
|
||||
|
||||
@@ -12,8 +12,56 @@ import { logger } from "@app/lib/logger";
|
||||
import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator";
|
||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||
|
||||
import { HCVaultConnectionMethod } from "./hc-vault-connection-enums";
|
||||
import { THCVaultConnection, THCVaultConnectionConfig, THCVaultMountResponse } from "./hc-vault-connection-types";
|
||||
import { HCVaultAuthType, HCVaultConnectionMethod } from "./hc-vault-connection-enums";
|
||||
import {
|
||||
THCVaultAuthMount,
|
||||
THCVaultAuthMountResponse,
|
||||
THCVaultConnection,
|
||||
THCVaultConnectionConfig,
|
||||
THCVaultKubernetesAuthConfig,
|
||||
THCVaultKubernetesAuthRole,
|
||||
THCVaultKubernetesAuthRoleWithConfig,
|
||||
THCVaultMount,
|
||||
THCVaultMountResponse
|
||||
} from "./hc-vault-connection-types";
|
||||
|
||||
// Concurrency limit for HC Vault API requests to avoid rate limiting
|
||||
const HC_VAULT_CONCURRENCY_LIMIT = 20;
|
||||
|
||||
/**
|
||||
* Creates a concurrency limiter that restricts the number of concurrent async operations
|
||||
* @param limit - Maximum number of concurrent operations
|
||||
* @returns A function that takes an async function and executes it with concurrency control
|
||||
*/
|
||||
const createConcurrencyLimiter = (limit: number) => {
|
||||
let activeCount = 0;
|
||||
const queue: Array<() => void> = [];
|
||||
|
||||
const next = () => {
|
||||
activeCount -= 1;
|
||||
if (queue.length > 0) {
|
||||
const resolve = queue.shift();
|
||||
resolve?.();
|
||||
}
|
||||
};
|
||||
|
||||
return async <T>(fn: () => Promise<T>): Promise<T> => {
|
||||
// If we're at the limit, wait in queue
|
||||
if (activeCount >= limit) {
|
||||
await new Promise<void>((resolve) => {
|
||||
queue.push(resolve);
|
||||
});
|
||||
}
|
||||
|
||||
activeCount += 1;
|
||||
|
||||
try {
|
||||
return await fn();
|
||||
} finally {
|
||||
next();
|
||||
}
|
||||
};
|
||||
};
|
||||
|
||||
export const getHCVaultInstanceUrl = async (config: THCVaultConnectionConfig) => {
|
||||
const instanceUrl = removeTrailingSlash(config.credentials.instanceUrl);
|
||||
@@ -181,30 +229,573 @@ export const validateHCVaultConnectionCredentials = async (
|
||||
}
|
||||
};
|
||||
|
||||
export const listHCVaultMounts = async (
|
||||
export const listHCVaultPolicies = async (
|
||||
namespace: string,
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">
|
||||
) => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
try {
|
||||
const { data: listData } = await requestWithHCVaultGateway<{
|
||||
data: {
|
||||
policies: string[];
|
||||
};
|
||||
}>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/sys/policy`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
});
|
||||
|
||||
const policyNames = listData.data.policies || [];
|
||||
|
||||
const limiter = createConcurrencyLimiter(HC_VAULT_CONCURRENCY_LIMIT);
|
||||
|
||||
const policies = await Promise.all(
|
||||
policyNames.map((policyName) =>
|
||||
limiter(async () => {
|
||||
try {
|
||||
const { data: policyData } = await requestWithHCVaultGateway<{
|
||||
data: {
|
||||
name: string;
|
||||
rules: string;
|
||||
};
|
||||
}>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/sys/policy/${policyName}`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
});
|
||||
|
||||
return {
|
||||
name: policyData.data.name,
|
||||
rules: policyData.data.rules
|
||||
};
|
||||
} catch (error: unknown) {
|
||||
logger.error(error, `Unable to fetch policy details for ${policyName}`);
|
||||
return {
|
||||
name: policyName,
|
||||
rules: ""
|
||||
};
|
||||
}
|
||||
})
|
||||
)
|
||||
);
|
||||
|
||||
return policies;
|
||||
} catch (error: unknown) {
|
||||
logger.error(error, "Unable to list HC Vault policies");
|
||||
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to list policies: ${error.message || "Unknown error"}`
|
||||
});
|
||||
}
|
||||
|
||||
throw new BadRequestError({
|
||||
message: "Unable to list policies from HashiCorp Vault"
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
export const listHCVaultNamespaces = async (
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">
|
||||
) => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
const currentNamespace = connection.credentials.namespace || "/";
|
||||
|
||||
// Helper function to fetch namespaces at a specific path
|
||||
const fetchNamespacesAtPath = async (namespacePath: string): Promise<string[] | null> => {
|
||||
try {
|
||||
const { data } = await requestWithHCVaultGateway<{
|
||||
data: {
|
||||
keys: string[];
|
||||
key_info?: {
|
||||
[key: string]: {
|
||||
id: string;
|
||||
path: string;
|
||||
custom_metadata?: Record<string, unknown>;
|
||||
};
|
||||
};
|
||||
};
|
||||
}>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/sys/namespaces?list=true`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespacePath
|
||||
}
|
||||
});
|
||||
|
||||
return data.data.keys || [];
|
||||
} catch (error: unknown) {
|
||||
if (error instanceof AxiosError && error.response?.status === 404) {
|
||||
// No child namespaces at this path
|
||||
return null;
|
||||
}
|
||||
throw error;
|
||||
}
|
||||
};
|
||||
|
||||
// Recursive function to get all namespaces at all depths with controlled parallelization
|
||||
const recursivelyGetAllNamespaces = async (
|
||||
parentPath: string,
|
||||
limiter: ReturnType<typeof createConcurrencyLimiter>
|
||||
): Promise<string[]> => {
|
||||
const childKeys = await fetchNamespacesAtPath(parentPath);
|
||||
|
||||
if (childKeys === null || childKeys.length === 0) {
|
||||
return [];
|
||||
}
|
||||
|
||||
// Process namespaces in parallel with concurrency control
|
||||
const namespacesArrays = await Promise.all(
|
||||
childKeys.map((namespaceKey) =>
|
||||
limiter(async () => {
|
||||
// Remove trailing slash from the key
|
||||
const cleanNamespaceKey = namespaceKey.replace(/\/$/, "");
|
||||
|
||||
// Build the full path
|
||||
let fullNamespacePath: string;
|
||||
if (parentPath === "/") {
|
||||
fullNamespacePath = cleanNamespaceKey;
|
||||
} else {
|
||||
fullNamespacePath = `${parentPath}/${cleanNamespaceKey}`;
|
||||
}
|
||||
|
||||
// Recursively fetch child namespaces
|
||||
const childNamespaces = await recursivelyGetAllNamespaces(fullNamespacePath, limiter);
|
||||
|
||||
// Return this namespace and all its children
|
||||
return [fullNamespacePath, ...childNamespaces];
|
||||
})
|
||||
)
|
||||
);
|
||||
|
||||
// Flatten the arrays into a single array
|
||||
return namespacesArrays.flat();
|
||||
};
|
||||
|
||||
try {
|
||||
// Create concurrency limiter to avoid overwhelming the Vault instance
|
||||
const limiter = createConcurrencyLimiter(HC_VAULT_CONCURRENCY_LIMIT);
|
||||
|
||||
// Get all namespaces starting from currentNamespace
|
||||
const childNamespaces = await recursivelyGetAllNamespaces(currentNamespace, limiter);
|
||||
|
||||
// Build the result array with full paths
|
||||
const namespaces = childNamespaces.map((path) => ({
|
||||
id: path,
|
||||
name: path
|
||||
}));
|
||||
|
||||
// Always include the current/root namespace
|
||||
namespaces.unshift({
|
||||
id: currentNamespace,
|
||||
name: currentNamespace
|
||||
});
|
||||
|
||||
return namespaces;
|
||||
} catch (error: unknown) {
|
||||
logger.error(error, "Unable to list HC Vault namespaces");
|
||||
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to list namespaces: ${error.message || "Unknown error"}`
|
||||
});
|
||||
}
|
||||
|
||||
throw new BadRequestError({
|
||||
message: "Unable to list namespaces from HashiCorp Vault"
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
export const listHCVaultMounts = async (
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">,
|
||||
namespace?: string
|
||||
) => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
const targetNamespace = namespace || connection.credentials.namespace;
|
||||
|
||||
const { data } = await requestWithHCVaultGateway<THCVaultMountResponse>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/sys/mounts`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
...(connection.credentials.namespace ? { "X-Vault-Namespace": connection.credentials.namespace } : {})
|
||||
...(targetNamespace ? { "X-Vault-Namespace": targetNamespace } : {})
|
||||
}
|
||||
});
|
||||
|
||||
const mounts: string[] = [];
|
||||
const mounts: THCVaultMount[] = [];
|
||||
|
||||
// Filter for "kv" version 2 type only
|
||||
Object.entries(data.data).forEach(([path, mount]) => {
|
||||
if (mount.type === "kv" && mount.options?.version === "2") {
|
||||
mounts.push(path);
|
||||
}
|
||||
mounts.push({
|
||||
path,
|
||||
type: mount.type,
|
||||
version: mount.options?.version
|
||||
});
|
||||
});
|
||||
|
||||
return mounts;
|
||||
};
|
||||
|
||||
export const listHCVaultSecretPaths = async (
|
||||
namespace: string,
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">,
|
||||
filterMountPath?: string
|
||||
) => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
const getPaths = async (mountPath: string, secretPath: string, kvVersion: "1" | "2"): Promise<string[] | null> => {
|
||||
try {
|
||||
let path: string;
|
||||
if (kvVersion === "2") {
|
||||
// For KV v2: /v1/{mount}/metadata/{path}?list=true
|
||||
path = secretPath ? `${mountPath}/metadata/${secretPath}` : `${mountPath}/metadata`;
|
||||
} else {
|
||||
// For KV v1: /v1/{mount}/{path}?list=true
|
||||
path = secretPath ? `${mountPath}/${secretPath}` : mountPath;
|
||||
}
|
||||
|
||||
const { data } = await requestWithHCVaultGateway<{
|
||||
data: {
|
||||
keys: string[];
|
||||
};
|
||||
}>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/${path}?list=true`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
});
|
||||
|
||||
return data.data.keys;
|
||||
} catch (error) {
|
||||
if (error instanceof AxiosError && error.response?.status === 404) {
|
||||
return null;
|
||||
}
|
||||
|
||||
throw error;
|
||||
}
|
||||
};
|
||||
|
||||
// Recursive function to get all secret paths in a mount with controlled parallelization
|
||||
const recursivelyGetAllPaths = async (
|
||||
mountPath: string,
|
||||
kvVersion: "1" | "2",
|
||||
limiter: ReturnType<typeof createConcurrencyLimiter>,
|
||||
currentPath: string = ""
|
||||
): Promise<string[]> => {
|
||||
const paths = await getPaths(mountPath, currentPath, kvVersion);
|
||||
|
||||
if (paths === null || paths.length === 0) {
|
||||
return [];
|
||||
}
|
||||
|
||||
// Process paths in parallel with concurrency control
|
||||
const secretPathsArrays = await Promise.all(
|
||||
paths.map((path) =>
|
||||
limiter(async () => {
|
||||
const cleanPath = path.endsWith("/") ? path.slice(0, -1) : path;
|
||||
const fullItemPath = currentPath ? `${currentPath}/${cleanPath}` : cleanPath;
|
||||
|
||||
if (path.endsWith("/")) {
|
||||
// it's a folder so we recurse into it
|
||||
return recursivelyGetAllPaths(mountPath, kvVersion, limiter, fullItemPath);
|
||||
}
|
||||
// it's a secret so we return it
|
||||
return [`${mountPath}/${fullItemPath}`];
|
||||
})
|
||||
)
|
||||
);
|
||||
|
||||
// Flatten the arrays into a single array
|
||||
return secretPathsArrays.flat();
|
||||
};
|
||||
|
||||
// Get all mounts
|
||||
const mounts = await listHCVaultMounts(connection, gatewayService, namespace);
|
||||
|
||||
// Filter for KV mounts (kv, kv-v1, kv-v2)
|
||||
let kvMounts = mounts.filter((mount) => mount.type === "kv" || mount.type.startsWith("kv"));
|
||||
|
||||
// If filterMountPath is provided, filter to only that mount
|
||||
if (filterMountPath) {
|
||||
const normalizedFilterPath = filterMountPath.replace(/\/$/, ""); // Remove trailing slash
|
||||
kvMounts = kvMounts.filter((mount) => mount.path.replace(/\/$/, "") === normalizedFilterPath);
|
||||
}
|
||||
|
||||
// Create concurrency limiter to avoid overwhelming the Vault instance
|
||||
const limiter = createConcurrencyLimiter(HC_VAULT_CONCURRENCY_LIMIT);
|
||||
|
||||
// Collect all secret paths from all KV mounts in parallel
|
||||
const allSecretPathsArrays = await Promise.all(
|
||||
kvMounts.map(async (mount) => {
|
||||
const kvVersion = mount.version === "2" ? "2" : "1";
|
||||
const cleanMountPath = mount.path.replace(/\/$/, ""); // Remove trailing slash
|
||||
return recursivelyGetAllPaths(cleanMountPath, kvVersion, limiter);
|
||||
})
|
||||
);
|
||||
|
||||
// Flatten the arrays into a single array
|
||||
const allSecretPaths = allSecretPathsArrays.flat();
|
||||
|
||||
return allSecretPaths;
|
||||
};
|
||||
|
||||
export const getHCVaultSecretsForPath = async (
|
||||
namespace: string,
|
||||
secretPath: string,
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">
|
||||
) => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
try {
|
||||
// Extract mount and path from the secretPath
|
||||
// secretPath format: {mount}/{path}
|
||||
const pathParts = secretPath.split("/");
|
||||
const mountPath = pathParts[0];
|
||||
const actualPath = pathParts.slice(1).join("/");
|
||||
|
||||
if (!mountPath || !actualPath) {
|
||||
throw new BadRequestError({
|
||||
message: "Invalid secret path format. Expected format: {mount}/{path}"
|
||||
});
|
||||
}
|
||||
|
||||
// Get mounts to determine KV version
|
||||
const mounts = await listHCVaultMounts(connection, gatewayService, namespace);
|
||||
const mount = mounts.find((m) => m.path.replace(/\/$/, "") === mountPath);
|
||||
|
||||
if (!mount) {
|
||||
throw new BadRequestError({
|
||||
message: `Mount '${mountPath}' not found in HashiCorp Vault`
|
||||
});
|
||||
}
|
||||
|
||||
const kvVersion = mount.version === "2" ? "2" : "1";
|
||||
|
||||
// Fetch secrets based on KV version
|
||||
if (kvVersion === "2") {
|
||||
// For KV v2: /v1/{mount}/data/{path}
|
||||
const { data } = await requestWithHCVaultGateway<{
|
||||
data: {
|
||||
data: Record<string, string>; // KV v2 has nested data structure
|
||||
metadata: {
|
||||
created_time: string;
|
||||
deletion_time: string;
|
||||
destroyed: boolean;
|
||||
version: number;
|
||||
};
|
||||
};
|
||||
}>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/${mountPath}/data/${actualPath}`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
});
|
||||
|
||||
return data.data.data;
|
||||
}
|
||||
|
||||
// For KV v1: /v1/{mount}/{path}
|
||||
const { data } = await requestWithHCVaultGateway<{
|
||||
data: Record<string, string>; // KV v1 has flat data structure
|
||||
lease_duration: number;
|
||||
lease_id: string;
|
||||
renewable: boolean;
|
||||
}>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/${mountPath}/${actualPath}`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
});
|
||||
|
||||
return data.data;
|
||||
} catch (error: unknown) {
|
||||
logger.error(error, "Unable to fetch secrets from HC Vault path");
|
||||
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to fetch secrets: ${error.message || "Unknown error"}`
|
||||
});
|
||||
}
|
||||
|
||||
if (error instanceof BadRequestError) {
|
||||
throw error;
|
||||
}
|
||||
|
||||
throw new BadRequestError({
|
||||
message: "Unable to fetch secrets from HashiCorp Vault"
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
export const getHCVaultAuthMounts = async (
|
||||
namespace: string,
|
||||
authType: HCVaultAuthType | undefined,
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">
|
||||
): Promise<THCVaultAuthMount[]> => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
try {
|
||||
const { data } = await requestWithHCVaultGateway<THCVaultAuthMountResponse>(connection, gatewayService, {
|
||||
url: `${instanceUrl}/v1/sys/auth`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
});
|
||||
|
||||
const authMounts: THCVaultAuthMount[] = [];
|
||||
|
||||
Object.entries(data.data).forEach(([path, authMethod]) => {
|
||||
// If authType is specified, filter by it; otherwise, include all
|
||||
if (!authType || authMethod.type === authType) {
|
||||
authMounts.push({
|
||||
path,
|
||||
type: authMethod.type,
|
||||
description: authMethod.description,
|
||||
accessor: authMethod.accessor
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
return authMounts;
|
||||
} catch (error: unknown) {
|
||||
const authTypeStr = authType || "all";
|
||||
logger.error(error, `Unable to list HC Vault ${authTypeStr} auth mounts`);
|
||||
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to list ${authTypeStr} auth mounts: ${error.message || "Unknown error"}`
|
||||
});
|
||||
}
|
||||
|
||||
throw new BadRequestError({
|
||||
message: `Unable to list ${authTypeStr} auth mounts from HashiCorp Vault`
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
export const getHCVaultKubernetesAuthRoles = async (
|
||||
namespace: string,
|
||||
mountPath: string,
|
||||
connection: THCVaultConnection,
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">
|
||||
): Promise<THCVaultKubernetesAuthRoleWithConfig[]> => {
|
||||
const instanceUrl = await getHCVaultInstanceUrl(connection);
|
||||
const accessToken = await getHCVaultAccessToken(connection, gatewayService);
|
||||
|
||||
// Remove trailing slash from mount path
|
||||
const cleanMountPath = mountPath.endsWith("/") ? mountPath.slice(0, -1) : mountPath;
|
||||
|
||||
try {
|
||||
// 1. Get the Kubernetes auth configuration for this mount
|
||||
const { data: configResponse } = await requestWithHCVaultGateway<{ data: THCVaultKubernetesAuthConfig }>(
|
||||
connection,
|
||||
gatewayService,
|
||||
{
|
||||
url: `${instanceUrl}/v1/auth/${cleanMountPath}/config`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
}
|
||||
);
|
||||
|
||||
const kubernetesConfig = configResponse.data;
|
||||
|
||||
// 2. List all roles in this mount
|
||||
const { data: roleListResponse } = await requestWithHCVaultGateway<{ data: { keys: string[] } }>(
|
||||
connection,
|
||||
gatewayService,
|
||||
{
|
||||
url: `${instanceUrl}/v1/auth/${cleanMountPath}/role`,
|
||||
method: "LIST",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
}
|
||||
);
|
||||
|
||||
const roleNames = roleListResponse.data.keys;
|
||||
|
||||
if (!roleNames || roleNames.length === 0) {
|
||||
return [];
|
||||
}
|
||||
|
||||
// 3. Fetch details for each role with concurrency control
|
||||
const limiter = createConcurrencyLimiter(HC_VAULT_CONCURRENCY_LIMIT);
|
||||
|
||||
const roleDetailsPromises = roleNames.map((roleName) =>
|
||||
limiter(async () => {
|
||||
const { data: roleResponse } = await requestWithHCVaultGateway<{ data: THCVaultKubernetesAuthRole }>(
|
||||
connection,
|
||||
gatewayService,
|
||||
{
|
||||
url: `${instanceUrl}/v1/auth/${cleanMountPath}/role/${roleName}`,
|
||||
method: "GET",
|
||||
headers: {
|
||||
"X-Vault-Token": accessToken,
|
||||
"X-Vault-Namespace": namespace
|
||||
}
|
||||
}
|
||||
);
|
||||
|
||||
// 4. Merge the role with the config
|
||||
return {
|
||||
...roleResponse.data,
|
||||
name: roleName,
|
||||
config: kubernetesConfig,
|
||||
mountPath: cleanMountPath
|
||||
} as THCVaultKubernetesAuthRoleWithConfig;
|
||||
})
|
||||
);
|
||||
|
||||
const roles = await Promise.all(roleDetailsPromises);
|
||||
|
||||
return roles;
|
||||
} catch (error: unknown) {
|
||||
logger.error(error, "Unable to list HC Vault Kubernetes auth roles");
|
||||
|
||||
if (error instanceof AxiosError) {
|
||||
const errorMessage =
|
||||
(error.response?.data as { errors?: string[] })?.errors?.[0] || error.message || "Unknown error";
|
||||
throw new BadRequestError({
|
||||
message: `Failed to list Kubernetes auth roles: ${errorMessage}`
|
||||
});
|
||||
}
|
||||
|
||||
throw new BadRequestError({
|
||||
message: "Unable to list Kubernetes auth roles from HashiCorp Vault"
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
@@ -21,7 +21,8 @@ export const hcVaultConnectionService = (
|
||||
|
||||
try {
|
||||
const mounts = await listHCVaultMounts(appConnection, gatewayService);
|
||||
return mounts;
|
||||
// Filter for KV version 2 mounts only and extract just the paths
|
||||
return mounts.filter((mount) => mount.type === "kv" && mount.version === "2").map((mount) => mount.path);
|
||||
} catch (error) {
|
||||
logger.error(error, "Failed to establish connection with Hashicorp Vault");
|
||||
return [];
|
||||
|
||||
@@ -33,3 +33,65 @@ export type THCVaultMountResponse = {
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
export type THCVaultMount = {
|
||||
path: string;
|
||||
type: string;
|
||||
version?: string | null;
|
||||
};
|
||||
|
||||
export type THCVaultAuthMountResponse = {
|
||||
data: {
|
||||
[key: string]: {
|
||||
type: string;
|
||||
description: string;
|
||||
accessor: string;
|
||||
config: {
|
||||
default_lease_ttl: number;
|
||||
max_lease_ttl: number;
|
||||
force_no_cache: boolean;
|
||||
};
|
||||
local: boolean;
|
||||
seal_wrap: boolean;
|
||||
external_entropy_access: boolean;
|
||||
options: Record<string, string> | null;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
export type THCVaultAuthMount = {
|
||||
path: string;
|
||||
type: string;
|
||||
description: string;
|
||||
accessor: string;
|
||||
};
|
||||
|
||||
export type THCVaultKubernetesAuthConfig = {
|
||||
kubernetes_host: string;
|
||||
kubernetes_ca_cert?: string;
|
||||
issuer?: string;
|
||||
disable_iss_validation?: boolean;
|
||||
disable_local_ca_jwt?: boolean;
|
||||
};
|
||||
|
||||
export type THCVaultKubernetesAuthRole = {
|
||||
name: string;
|
||||
bound_service_account_names: string[];
|
||||
bound_service_account_namespaces: string[];
|
||||
token_ttl?: number;
|
||||
token_max_ttl?: number;
|
||||
token_policies?: string[];
|
||||
token_bound_cidrs?: string[];
|
||||
token_explicit_max_ttl?: number;
|
||||
token_no_default_policy?: boolean;
|
||||
token_num_uses?: number;
|
||||
token_period?: number;
|
||||
token_type?: string;
|
||||
audience?: string;
|
||||
alias_name_source?: string;
|
||||
};
|
||||
|
||||
export type THCVaultKubernetesAuthRoleWithConfig = THCVaultKubernetesAuthRole & {
|
||||
config: THCVaultKubernetesAuthConfig;
|
||||
mountPath: string;
|
||||
};
|
||||
|
||||
@@ -1,9 +1,33 @@
|
||||
import { OrgMembershipRole } from "@app/db/schemas";
|
||||
import {
|
||||
AuditLogInfo,
|
||||
EventType,
|
||||
SecretApprovalEvent,
|
||||
TAuditLogServiceFactory
|
||||
} from "@app/ee/services/audit-log/audit-log-types";
|
||||
import { TGatewayServiceFactory } from "@app/ee/services/gateway/gateway-service";
|
||||
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service-types";
|
||||
import { crypto } from "@app/lib/crypto/cryptography";
|
||||
import { BadRequestError, ForbiddenRequestError } from "@app/lib/errors";
|
||||
import { DatabaseErrorCode } from "@app/lib/error-codes";
|
||||
import { BadRequestError, DatabaseError, ForbiddenRequestError, NotFoundError } from "@app/lib/errors";
|
||||
import { OrgServiceActor } from "@app/lib/types";
|
||||
|
||||
import { AppConnection } from "../app-connection/app-connection-enums";
|
||||
import { decryptAppConnectionCredentials } from "../app-connection/app-connection-fns";
|
||||
import { TAppConnectionServiceFactory } from "../app-connection/app-connection-service";
|
||||
import {
|
||||
getHCVaultAuthMounts,
|
||||
getHCVaultKubernetesAuthRoles,
|
||||
getHCVaultSecretsForPath,
|
||||
HCVaultAuthType,
|
||||
listHCVaultMounts,
|
||||
listHCVaultPolicies,
|
||||
listHCVaultSecretPaths,
|
||||
THCVaultConnection
|
||||
} from "../app-connection/hc-vault";
|
||||
import { TKmsServiceFactory } from "../kms/kms-service";
|
||||
import { TSecretServiceFactory } from "../secret/secret-service";
|
||||
import { SecretProtectionType } from "../secret/secret-types";
|
||||
import { TUserDALFactory } from "../user/user-dal";
|
||||
import {
|
||||
decryptEnvKeyDataFn,
|
||||
@@ -15,16 +39,29 @@ import { TExternalMigrationQueueFactory } from "./external-migration-queue";
|
||||
import {
|
||||
ExternalMigrationProviders,
|
||||
ExternalPlatforms,
|
||||
TCreateVaultExternalMigrationDTO,
|
||||
TDeleteVaultExternalMigrationDTO,
|
||||
THasCustomVaultMigrationDTO,
|
||||
TImportEnvKeyDataDTO,
|
||||
TImportVaultDataDTO
|
||||
TImportVaultDataDTO,
|
||||
TUpdateVaultExternalMigrationDTO,
|
||||
VaultImportStatus
|
||||
} from "./external-migration-types";
|
||||
import { TVaultExternalMigrationConfigDALFactory } from "./vault-external-migration-config-dal";
|
||||
|
||||
type TExternalMigrationServiceFactoryDep = {
|
||||
permissionService: TPermissionServiceFactory;
|
||||
secretService: TSecretServiceFactory;
|
||||
auditLogService: Pick<TAuditLogServiceFactory, "createAuditLog">;
|
||||
externalMigrationQueue: TExternalMigrationQueueFactory;
|
||||
appConnectionService: Pick<TAppConnectionServiceFactory, "connectAppConnectionById">;
|
||||
vaultExternalMigrationConfigDAL: Pick<
|
||||
TVaultExternalMigrationConfigDALFactory,
|
||||
"create" | "findOne" | "transaction" | "find" | "updateById" | "deleteById" | "findById"
|
||||
>;
|
||||
userDAL: Pick<TUserDALFactory, "findById">;
|
||||
gatewayService: Pick<TGatewayServiceFactory, "fnGetGatewayClientTlsByGatewayId">;
|
||||
kmsService: Pick<TKmsServiceFactory, "createCipherPairWithDataKey">;
|
||||
};
|
||||
|
||||
export type TExternalMigrationServiceFactory = ReturnType<typeof externalMigrationServiceFactory>;
|
||||
@@ -33,7 +70,12 @@ export const externalMigrationServiceFactory = ({
|
||||
permissionService,
|
||||
externalMigrationQueue,
|
||||
userDAL,
|
||||
gatewayService
|
||||
gatewayService,
|
||||
secretService,
|
||||
auditLogService,
|
||||
appConnectionService,
|
||||
vaultExternalMigrationConfigDAL,
|
||||
kmsService
|
||||
}: TExternalMigrationServiceFactoryDep) => {
|
||||
const importEnvKeyData = async ({
|
||||
decryptionKey,
|
||||
@@ -171,9 +213,554 @@ export const externalMigrationServiceFactory = ({
|
||||
return actorOrgId in vaultMigrationTransformMappings;
|
||||
};
|
||||
|
||||
const validateVaultExternalMigrationConnection = async ({
|
||||
connection,
|
||||
namespace
|
||||
}: {
|
||||
connection: THCVaultConnection;
|
||||
namespace: string;
|
||||
}) => {
|
||||
// Allow root namespace access when no namespace is configured on the connection
|
||||
const isRootAccess = namespace === "root" || namespace === "/";
|
||||
const hasNoNamespace = connection.credentials.namespace === undefined;
|
||||
|
||||
if (hasNoNamespace && isRootAccess) {
|
||||
// Skip validation for root access with no configured namespace
|
||||
} else if (connection.credentials.namespace !== namespace) {
|
||||
throw new BadRequestError({ message: "Namespace value does not match the namespace of the connection" });
|
||||
}
|
||||
|
||||
try {
|
||||
await listHCVaultPolicies(namespace, connection, gatewayService);
|
||||
await getHCVaultAuthMounts(namespace, HCVaultAuthType.Kubernetes, connection, gatewayService);
|
||||
|
||||
const mounts = await listHCVaultMounts(connection, gatewayService);
|
||||
const sampleKvMount = mounts.find((mount) => mount.type === "kv");
|
||||
if (sampleKvMount) {
|
||||
await listHCVaultSecretPaths(namespace, connection, gatewayService, sampleKvMount.path);
|
||||
}
|
||||
} catch (error) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to establish namespace confiugration. ${error instanceof Error ? error.message : "Unknown error"}`
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
const createVaultExternalMigration = async ({ namespace, connectionId, actor }: TCreateVaultExternalMigrationDTO) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can configure vault external migration" });
|
||||
}
|
||||
|
||||
const connection = await appConnectionService.connectAppConnectionById<THCVaultConnection>(
|
||||
AppConnection.HCVault,
|
||||
connectionId,
|
||||
actor
|
||||
);
|
||||
|
||||
await validateVaultExternalMigrationConnection({
|
||||
connection,
|
||||
namespace
|
||||
});
|
||||
|
||||
try {
|
||||
const config = await vaultExternalMigrationConfigDAL.create({
|
||||
namespace,
|
||||
connectionId,
|
||||
orgId: actor.orgId
|
||||
});
|
||||
|
||||
return config;
|
||||
} catch (error) {
|
||||
if (
|
||||
error instanceof DatabaseError &&
|
||||
(error.error as { code: string })?.code === DatabaseErrorCode.UniqueViolation
|
||||
) {
|
||||
throw new BadRequestError({
|
||||
message: `Vault external migration already exists for this namespace`
|
||||
});
|
||||
}
|
||||
|
||||
throw error;
|
||||
}
|
||||
};
|
||||
|
||||
const updateVaultExternalMigration = async ({
|
||||
id,
|
||||
namespace,
|
||||
connectionId,
|
||||
actor
|
||||
}: TUpdateVaultExternalMigrationDTO) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can update vault external migration" });
|
||||
}
|
||||
|
||||
if (connectionId) {
|
||||
const connection = await appConnectionService.connectAppConnectionById<THCVaultConnection>(
|
||||
AppConnection.HCVault,
|
||||
connectionId,
|
||||
actor
|
||||
);
|
||||
|
||||
await validateVaultExternalMigrationConnection({
|
||||
connection,
|
||||
namespace
|
||||
});
|
||||
}
|
||||
|
||||
const config = await vaultExternalMigrationConfigDAL.updateById(id, {
|
||||
namespace,
|
||||
connectionId
|
||||
});
|
||||
|
||||
return config;
|
||||
};
|
||||
|
||||
const getVaultExternalMigrationConfigs = async ({ actor }: { actor: OrgServiceActor }) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault external migration configs" });
|
||||
}
|
||||
|
||||
const configs = await vaultExternalMigrationConfigDAL.find({
|
||||
orgId: actor.orgId
|
||||
});
|
||||
|
||||
return configs;
|
||||
};
|
||||
|
||||
const getVaultNamespaces = async ({ actor }: { actor: OrgServiceActor }) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault namespaces" });
|
||||
}
|
||||
|
||||
// Get all configured namespaces for this org
|
||||
const vaultConfigs = await vaultExternalMigrationConfigDAL.find({
|
||||
orgId: actor.orgId
|
||||
});
|
||||
|
||||
// Return the configured namespaces as an array of objects with id and name
|
||||
// where both id and name are the namespace path
|
||||
const namespaces = vaultConfigs.map((config) => ({
|
||||
id: config.namespace,
|
||||
name: config.namespace
|
||||
}));
|
||||
|
||||
return namespaces;
|
||||
};
|
||||
|
||||
const getVaultPolicies = async ({ actor, namespace }: { actor: OrgServiceActor; namespace: string }) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault policies" });
|
||||
}
|
||||
|
||||
const vaultConfig = await vaultExternalMigrationConfigDAL.findOne({
|
||||
orgId: actor.orgId,
|
||||
namespace
|
||||
});
|
||||
|
||||
if (!vaultConfig) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found for this namespace" });
|
||||
}
|
||||
|
||||
if (!vaultConfig.connection) {
|
||||
throw new BadRequestError({ message: "Vault migration connection is not configured for this namespace" });
|
||||
}
|
||||
|
||||
const credentials = await decryptAppConnectionCredentials({
|
||||
orgId: vaultConfig.orgId,
|
||||
encryptedCredentials: vaultConfig.connection.encryptedCredentials,
|
||||
kmsService,
|
||||
projectId: null
|
||||
});
|
||||
|
||||
const connection = {
|
||||
...vaultConfig.connection,
|
||||
credentials
|
||||
} as THCVaultConnection;
|
||||
|
||||
const policies = await listHCVaultPolicies(namespace, connection, gatewayService);
|
||||
return policies;
|
||||
};
|
||||
|
||||
const getVaultMounts = async ({ actor, namespace }: { actor: OrgServiceActor; namespace: string }) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault mounts" });
|
||||
}
|
||||
|
||||
const vaultConfig = await vaultExternalMigrationConfigDAL.findOne({
|
||||
orgId: actor.orgId,
|
||||
namespace
|
||||
});
|
||||
|
||||
if (!vaultConfig) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found for this namespace" });
|
||||
}
|
||||
|
||||
if (!vaultConfig.connection) {
|
||||
throw new BadRequestError({ message: "Vault migration connection is not configured for this namespace" });
|
||||
}
|
||||
|
||||
const credentials = await decryptAppConnectionCredentials({
|
||||
orgId: vaultConfig.orgId,
|
||||
encryptedCredentials: vaultConfig.connection.encryptedCredentials,
|
||||
kmsService,
|
||||
projectId: null
|
||||
});
|
||||
|
||||
const connection = {
|
||||
...vaultConfig.connection,
|
||||
credentials
|
||||
} as THCVaultConnection;
|
||||
|
||||
const mounts = await listHCVaultMounts(connection, gatewayService, namespace);
|
||||
return mounts;
|
||||
};
|
||||
|
||||
const getVaultSecretPaths = async ({
|
||||
actor,
|
||||
namespace,
|
||||
mountPath
|
||||
}: {
|
||||
actor: OrgServiceActor;
|
||||
namespace: string;
|
||||
mountPath: string;
|
||||
}) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault secret paths" });
|
||||
}
|
||||
|
||||
const vaultConfig = await vaultExternalMigrationConfigDAL.findOne({
|
||||
orgId: actor.orgId,
|
||||
namespace
|
||||
});
|
||||
|
||||
if (!vaultConfig) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found for this namespace" });
|
||||
}
|
||||
|
||||
if (!vaultConfig.connection) {
|
||||
throw new BadRequestError({ message: "Vault migration connection is not configured for this namespace" });
|
||||
}
|
||||
|
||||
const credentials = await decryptAppConnectionCredentials({
|
||||
orgId: vaultConfig.orgId,
|
||||
encryptedCredentials: vaultConfig.connection.encryptedCredentials,
|
||||
kmsService,
|
||||
projectId: null
|
||||
});
|
||||
|
||||
const connection = {
|
||||
...vaultConfig.connection,
|
||||
credentials
|
||||
} as THCVaultConnection;
|
||||
|
||||
const secretPaths = await listHCVaultSecretPaths(namespace, connection, gatewayService, mountPath);
|
||||
|
||||
return secretPaths;
|
||||
};
|
||||
|
||||
const importVaultSecrets = async ({
|
||||
actor,
|
||||
projectId,
|
||||
environment,
|
||||
secretPath,
|
||||
vaultNamespace,
|
||||
vaultSecretPath,
|
||||
auditLogInfo
|
||||
}: {
|
||||
actor: OrgServiceActor;
|
||||
projectId: string;
|
||||
environment: string;
|
||||
secretPath: string;
|
||||
vaultNamespace: string;
|
||||
vaultSecretPath: string;
|
||||
auditLogInfo: AuditLogInfo;
|
||||
}) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can import vault secrets" });
|
||||
}
|
||||
|
||||
const vaultConfig = await vaultExternalMigrationConfigDAL.findOne({
|
||||
orgId: actor.orgId,
|
||||
namespace: vaultNamespace
|
||||
});
|
||||
|
||||
if (!vaultConfig) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found for this namespace" });
|
||||
}
|
||||
|
||||
if (!vaultConfig.connection) {
|
||||
throw new BadRequestError({ message: "Vault migration connection is not configured for this namespace" });
|
||||
}
|
||||
|
||||
const credentials = await decryptAppConnectionCredentials({
|
||||
orgId: vaultConfig.orgId,
|
||||
encryptedCredentials: vaultConfig.connection.encryptedCredentials,
|
||||
kmsService,
|
||||
projectId: null
|
||||
});
|
||||
|
||||
const connection = {
|
||||
...vaultConfig.connection,
|
||||
credentials
|
||||
} as THCVaultConnection;
|
||||
|
||||
const vaultSecrets = await getHCVaultSecretsForPath(vaultNamespace, vaultSecretPath, connection, gatewayService);
|
||||
|
||||
try {
|
||||
const secretOperation = await secretService.createManySecretsRaw({
|
||||
actorId: actor.id,
|
||||
actor: actor.type,
|
||||
actorAuthMethod: actor.authMethod,
|
||||
actorOrgId: actor.orgId,
|
||||
secretPath,
|
||||
environment,
|
||||
projectId,
|
||||
secrets: Object.entries(vaultSecrets).map(([secretKey, secretValue]) => ({
|
||||
secretKey,
|
||||
secretValue
|
||||
}))
|
||||
});
|
||||
|
||||
if (secretOperation.type === SecretProtectionType.Approval) {
|
||||
await auditLogService.createAuditLog({
|
||||
projectId,
|
||||
...auditLogInfo,
|
||||
event: {
|
||||
type: EventType.SECRET_APPROVAL_REQUEST,
|
||||
metadata: {
|
||||
committedBy: secretOperation.approval.committerUserId,
|
||||
secretApprovalRequestId: secretOperation.approval.id,
|
||||
secretApprovalRequestSlug: secretOperation.approval.slug,
|
||||
secretPath,
|
||||
environment,
|
||||
secrets: Object.entries(vaultSecrets).map(([secretKey]) => ({
|
||||
secretKey
|
||||
})),
|
||||
eventType: SecretApprovalEvent.CreateMany
|
||||
}
|
||||
}
|
||||
});
|
||||
|
||||
return { status: VaultImportStatus.ApprovalRequired };
|
||||
}
|
||||
|
||||
return { status: VaultImportStatus.Imported };
|
||||
} catch (error) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to import Vault secrets. ${error instanceof Error ? error.message : "Unknown error"}`
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
const deleteVaultExternalMigration = async ({ id, actor }: TDeleteVaultExternalMigrationDTO) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can delete vault external migration configs" });
|
||||
}
|
||||
|
||||
const config = await vaultExternalMigrationConfigDAL.findById(id);
|
||||
|
||||
if (!config) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found" });
|
||||
}
|
||||
|
||||
if (config.orgId !== actor.orgId) {
|
||||
throw new ForbiddenRequestError({ message: "Config does not belong to this organization" });
|
||||
}
|
||||
|
||||
const deletedConfig = await vaultExternalMigrationConfigDAL.deleteById(id);
|
||||
|
||||
return deletedConfig;
|
||||
};
|
||||
|
||||
const getVaultAuthMounts = async ({
|
||||
actor,
|
||||
namespace,
|
||||
authType
|
||||
}: {
|
||||
actor: OrgServiceActor;
|
||||
namespace: string;
|
||||
authType?: string;
|
||||
}) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault auth mounts" });
|
||||
}
|
||||
|
||||
const vaultConfig = await vaultExternalMigrationConfigDAL.findOne({
|
||||
orgId: actor.orgId,
|
||||
namespace
|
||||
});
|
||||
|
||||
if (!vaultConfig) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found for this namespace" });
|
||||
}
|
||||
|
||||
if (!vaultConfig.connection) {
|
||||
throw new BadRequestError({ message: "Vault migration connection is not configured for this namespace" });
|
||||
}
|
||||
|
||||
const credentials = await decryptAppConnectionCredentials({
|
||||
orgId: vaultConfig.orgId,
|
||||
encryptedCredentials: vaultConfig.connection.encryptedCredentials,
|
||||
kmsService,
|
||||
projectId: null
|
||||
});
|
||||
|
||||
const connection = {
|
||||
...vaultConfig.connection,
|
||||
credentials
|
||||
} as THCVaultConnection;
|
||||
|
||||
const authMounts = await getHCVaultAuthMounts(namespace, authType as HCVaultAuthType, connection, gatewayService);
|
||||
|
||||
return authMounts;
|
||||
};
|
||||
|
||||
const getVaultKubernetesAuthRoles = async ({
|
||||
actor,
|
||||
namespace,
|
||||
mountPath
|
||||
}: {
|
||||
actor: OrgServiceActor;
|
||||
namespace: string;
|
||||
mountPath: string;
|
||||
}) => {
|
||||
const { hasRole } = await permissionService.getOrgPermission(
|
||||
actor.type,
|
||||
actor.id,
|
||||
actor.orgId,
|
||||
actor.authMethod,
|
||||
actor.orgId
|
||||
);
|
||||
|
||||
if (!hasRole(OrgMembershipRole.Admin)) {
|
||||
throw new ForbiddenRequestError({ message: "Only admins can view vault Kubernetes auth roles" });
|
||||
}
|
||||
|
||||
const vaultConfig = await vaultExternalMigrationConfigDAL.findOne({
|
||||
orgId: actor.orgId,
|
||||
namespace
|
||||
});
|
||||
|
||||
if (!vaultConfig) {
|
||||
throw new NotFoundError({ message: "Vault migration config not found for this namespace" });
|
||||
}
|
||||
|
||||
if (!vaultConfig.connection) {
|
||||
throw new BadRequestError({ message: "Vault migration connection is not configured for this namespace" });
|
||||
}
|
||||
|
||||
const credentials = await decryptAppConnectionCredentials({
|
||||
orgId: vaultConfig.orgId,
|
||||
encryptedCredentials: vaultConfig.connection.encryptedCredentials,
|
||||
kmsService,
|
||||
projectId: null
|
||||
});
|
||||
|
||||
const connection = {
|
||||
...vaultConfig.connection,
|
||||
credentials
|
||||
} as THCVaultConnection;
|
||||
|
||||
// Get roles for the specified mount path only
|
||||
const roles = await getHCVaultKubernetesAuthRoles(namespace, mountPath, connection, gatewayService);
|
||||
|
||||
return roles;
|
||||
};
|
||||
|
||||
return {
|
||||
importEnvKeyData,
|
||||
importVaultData,
|
||||
hasCustomVaultMigration
|
||||
hasCustomVaultMigration,
|
||||
createVaultExternalMigration,
|
||||
getVaultExternalMigrationConfigs,
|
||||
updateVaultExternalMigration,
|
||||
deleteVaultExternalMigration,
|
||||
getVaultNamespaces,
|
||||
getVaultPolicies,
|
||||
getVaultMounts,
|
||||
getVaultAuthMounts,
|
||||
getVaultSecretPaths,
|
||||
importVaultSecrets,
|
||||
getVaultKubernetesAuthRoles
|
||||
};
|
||||
};
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { TOrgPermission } from "@app/lib/types";
|
||||
import { OrgServiceActor, TOrgPermission } from "@app/lib/types";
|
||||
|
||||
import { ActorAuthMethod, ActorType } from "../auth/auth-type";
|
||||
|
||||
@@ -121,3 +121,26 @@ export enum ExternalMigrationProviders {
|
||||
Vault = "vault",
|
||||
EnvKey = "env-key"
|
||||
}
|
||||
|
||||
export enum VaultImportStatus {
|
||||
Imported = "imported",
|
||||
ApprovalRequired = "approval-required"
|
||||
}
|
||||
|
||||
export type TCreateVaultExternalMigrationDTO = {
|
||||
namespace: string;
|
||||
connectionId: string;
|
||||
actor: OrgServiceActor;
|
||||
};
|
||||
|
||||
export type TUpdateVaultExternalMigrationDTO = {
|
||||
id: string;
|
||||
namespace: string;
|
||||
connectionId: string | null;
|
||||
actor: OrgServiceActor;
|
||||
};
|
||||
|
||||
export type TDeleteVaultExternalMigrationDTO = {
|
||||
id: string;
|
||||
actor: OrgServiceActor;
|
||||
};
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
import { Knex } from "knex";
|
||||
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { DatabaseError } from "@app/lib/errors";
|
||||
import { buildFindFilter, ormify, prependTableNameToFindFilter, selectAllTableCols } from "@app/lib/knex";
|
||||
|
||||
export type TVaultExternalMigrationConfigDALFactory = ReturnType<typeof vaultExternalMigrationConfigDALFactory>;
|
||||
|
||||
export const vaultExternalMigrationConfigDALFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.VaultExternalMigrationConfig);
|
||||
|
||||
const findOne = async (filter: { orgId: string; namespace: string }, tx?: Knex) => {
|
||||
try {
|
||||
const result = await (tx || db?.replicaNode?.() || db)(TableName.VaultExternalMigrationConfig)
|
||||
.leftJoin(
|
||||
TableName.AppConnection,
|
||||
`${TableName.AppConnection}.id`,
|
||||
`${TableName.VaultExternalMigrationConfig}.connectionId`
|
||||
)
|
||||
/* eslint-disable @typescript-eslint/no-misused-promises */
|
||||
.where(buildFindFilter(prependTableNameToFindFilter(TableName.VaultExternalMigrationConfig, filter)))
|
||||
.select(selectAllTableCols(TableName.VaultExternalMigrationConfig))
|
||||
.select(
|
||||
db.ref("id").withSchema(TableName.AppConnection).as("appConnectionId"),
|
||||
db.ref("name").withSchema(TableName.AppConnection).as("appConnectionName"),
|
||||
db.ref("app").withSchema(TableName.AppConnection).as("appConnectionApp"),
|
||||
db.ref("encryptedCredentials").withSchema(TableName.AppConnection).as("appConnectionEncryptedCredentials"),
|
||||
db.ref("orgId").withSchema(TableName.AppConnection).as("appConnectionOrgId"),
|
||||
db.ref("method").withSchema(TableName.AppConnection).as("appConnectionMethod"),
|
||||
db.ref("description").withSchema(TableName.AppConnection).as("appConnectionDescription"),
|
||||
db.ref("version").withSchema(TableName.AppConnection).as("appConnectionVersion"),
|
||||
db.ref("gatewayId").withSchema(TableName.AppConnection).as("appConnectionGatewayId"),
|
||||
db.ref("projectId").withSchema(TableName.AppConnection).as("appConnectionProjectId"),
|
||||
db.ref("createdAt").withSchema(TableName.AppConnection).as("appConnectionCreatedAt"),
|
||||
db.ref("updatedAt").withSchema(TableName.AppConnection).as("appConnectionUpdatedAt")
|
||||
)
|
||||
.first();
|
||||
|
||||
if (!result) return undefined;
|
||||
|
||||
return {
|
||||
...result,
|
||||
connection: result.appConnectionId
|
||||
? {
|
||||
id: result.appConnectionId,
|
||||
name: result.appConnectionName,
|
||||
app: result.appConnectionApp,
|
||||
encryptedCredentials: result.appConnectionEncryptedCredentials,
|
||||
orgId: result.appConnectionOrgId,
|
||||
method: result.appConnectionMethod,
|
||||
description: result.appConnectionDescription,
|
||||
version: result.appConnectionVersion,
|
||||
gatewayId: result.appConnectionGatewayId,
|
||||
projectId: result.appConnectionProjectId,
|
||||
createdAt: result.appConnectionCreatedAt,
|
||||
updatedAt: result.appConnectionUpdatedAt
|
||||
}
|
||||
: undefined
|
||||
};
|
||||
} catch (error) {
|
||||
throw new DatabaseError({ error, name: "Find one" });
|
||||
}
|
||||
};
|
||||
|
||||
return { ...orm, findOne };
|
||||
};
|
||||
Reference in New Issue
Block a user