diff --git a/backend/src/services/secret-sync/hc-vault/hc-vault-sync-fns.ts b/backend/src/services/secret-sync/hc-vault/hc-vault-sync-fns.ts index 9a4c6aa15..db35df292 100644 --- a/backend/src/services/secret-sync/hc-vault/hc-vault-sync-fns.ts +++ b/backend/src/services/secret-sync/hc-vault/hc-vault-sync-fns.ts @@ -1,3 +1,5 @@ +import { isAxiosError } from "axios"; + import { request } from "@app/lib/config/request"; import { removeTrailingSlash } from "@app/lib/fn"; import { blockLocalAndPrivateIpAddresses } from "@app/lib/validator"; @@ -14,17 +16,25 @@ import { TSecretMap } from "@app/services/secret-sync/secret-sync-types"; const listHCVaultVariables = async ({ instanceUrl, namespace, mount, accessToken, path }: THCVaultListVariables) => { await blockLocalAndPrivateIpAddresses(instanceUrl); - const { data } = await request.get( - `${instanceUrl}/v1/${removeTrailingSlash(mount)}/data/${path}`, - { - headers: { - "X-Vault-Token": accessToken, - ...(namespace ? { "X-Vault-Namespace": namespace } : {}) + try { + const { data } = await request.get( + `${instanceUrl}/v1/${removeTrailingSlash(mount)}/data/${path}`, + { + headers: { + "X-Vault-Token": accessToken, + ...(namespace ? { "X-Vault-Namespace": namespace } : {}) + } } - } - ); + ); - return data.data.data; + return data.data.data; + } catch (error: unknown) { + // Returning an empty set when a path isn't found allows that path to be created by a later POST request + if (isAxiosError(error) && error.response?.status === 404) { + return {}; + } + throw error; + } }; // Hashicorp Vault updates all variables in one batch. This is to respect their versioning diff --git a/docs/integrations/secret-syncs/hashicorp-vault.mdx b/docs/integrations/secret-syncs/hashicorp-vault.mdx index 8f2b73357..0d6c0d644 100644 --- a/docs/integrations/secret-syncs/hashicorp-vault.mdx +++ b/docs/integrations/secret-syncs/hashicorp-vault.mdx @@ -40,6 +40,10 @@ description: "Learn how to configure a Hashicorp Vault Sync for Infisical." - **Path**: The specific path within the secrets engine where secrets will be stored. After configuring these parameters, click the **Next** button to continue to the Sync Options step. + + + If the **path** you provide does not exist in Vault, it will be created. + Configure the **Sync Options** to specify how secrets should be synced, then click **Next**. diff --git a/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/HCVaultSyncFields.tsx b/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/HCVaultSyncFields.tsx index 0865b81f3..76e14b6d7 100644 --- a/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/HCVaultSyncFields.tsx +++ b/frontend/src/components/secret-syncs/forms/SecretSyncDestinationFields/HCVaultSyncFields.tsx @@ -44,7 +44,7 @@ export const HCVaultSyncFields = () => { helperText={
Don't see the mount you're looking for?{" "} @@ -72,7 +72,7 @@ export const HCVaultSyncFields = () => { render={({ field: { value, onChange }, fieldState: { error } }) => (