improvements: address feedback

This commit is contained in:
Scott Wilson
2025-08-14 16:25:00 -07:00
parent 48e5f550e9
commit a7847f177c
@@ -1,4 +1,5 @@
import AWS, { AWSError } from "aws-sdk"; import AWS, { AWSError } from "aws-sdk";
import handlebars from "handlebars";
import { getAwsConnectionConfig } from "@app/services/app-connection/aws/aws-connection-fns"; import { getAwsConnectionConfig } from "@app/services/app-connection/aws/aws-connection-fns";
import { SecretSyncError } from "@app/services/secret-sync/secret-sync-errors"; import { SecretSyncError } from "@app/services/secret-sync/secret-sync-errors";
@@ -34,16 +35,21 @@ const sleep = async () =>
setTimeout(resolve, 1000); setTimeout(resolve, 1000);
}); });
const getFullPath = ({ path, keySchema }: { path: string; keySchema?: string }) => { const getFullPath = ({ path, keySchema, environment }: { path: string; keySchema?: string; environment: string }) => {
if (!keySchema || !keySchema.includes("/")) return path; if (!keySchema || !keySchema.includes("/")) return path;
const keySchemaSegments = keySchema.split("/"); const keySchemaSegments = handlebars
.compile(keySchema)({
environment,
secretKey: "{{secretKey}}"
})
.split("/");
const pathSegments = keySchemaSegments.slice(0, keySchemaSegments.length - 1); const pathSegments = keySchemaSegments.slice(0, keySchemaSegments.length - 1);
if (pathSegments.some((segment) => segment.includes("{{"))) { if (pathSegments.some((segment) => segment.includes("{{secretKey}}"))) {
throw new SecretSyncError({ throw new SecretSyncError({
message: "Key schema cannot contain '/' after keys: ie {{secretKey}} or {{environment}}", message: "Key schema cannot contain '/' after {{secretKey}}",
shouldRetry: false shouldRetry: false
}); });
} }
@@ -54,14 +60,15 @@ const getFullPath = ({ path, keySchema }: { path: string; keySchema?: string })
const getParametersByPath = async ( const getParametersByPath = async (
ssm: AWS.SSM, ssm: AWS.SSM,
path: string, path: string,
keySchema: string | undefined keySchema: string | undefined,
environment: string
): Promise<TAWSParameterStoreRecord> => { ): Promise<TAWSParameterStoreRecord> => {
const awsParameterStoreSecretsRecord: TAWSParameterStoreRecord = {}; const awsParameterStoreSecretsRecord: TAWSParameterStoreRecord = {};
let hasNext = true; let hasNext = true;
let nextToken: string | undefined; let nextToken: string | undefined;
let attempt = 0; let attempt = 0;
const fullPath = getFullPath({ path, keySchema }); const fullPath = getFullPath({ path, keySchema, environment });
while (hasNext) { while (hasNext) {
try { try {
@@ -109,14 +116,15 @@ const getParametersByPath = async (
const getParameterMetadataByPath = async ( const getParameterMetadataByPath = async (
ssm: AWS.SSM, ssm: AWS.SSM,
path: string, path: string,
keySchema: string | undefined keySchema: string | undefined,
environment: string
): Promise<TAWSParameterStoreMetadataRecord> => { ): Promise<TAWSParameterStoreMetadataRecord> => {
const awsParameterStoreMetadataRecord: TAWSParameterStoreMetadataRecord = {}; const awsParameterStoreMetadataRecord: TAWSParameterStoreMetadataRecord = {};
let hasNext = true; let hasNext = true;
let nextToken: string | undefined; let nextToken: string | undefined;
let attempt = 0; let attempt = 0;
const fullPath = getFullPath({ path, keySchema }); const fullPath = getFullPath({ path, keySchema, environment });
while (hasNext) { while (hasNext) {
try { try {
@@ -330,13 +338,15 @@ export const AwsParameterStoreSyncFns = {
const awsParameterStoreSecretsRecord = await getParametersByPath( const awsParameterStoreSecretsRecord = await getParametersByPath(
ssm, ssm,
destinationConfig.path, destinationConfig.path,
syncOptions.keySchema syncOptions.keySchema,
environment!.slug
); );
const awsParameterStoreMetadataRecord = await getParameterMetadataByPath( const awsParameterStoreMetadataRecord = await getParameterMetadataByPath(
ssm, ssm,
destinationConfig.path, destinationConfig.path,
syncOptions.keySchema syncOptions.keySchema,
environment!.slug
); );
const { shouldManageTags, awsParameterStoreTagsRecord } = await getParameterStoreTagsRecord( const { shouldManageTags, awsParameterStoreTagsRecord } = await getParameterStoreTagsRecord(
@@ -437,14 +447,15 @@ export const AwsParameterStoreSyncFns = {
await deleteParametersBatch(ssm, parametersToDelete); await deleteParametersBatch(ssm, parametersToDelete);
}, },
getSecrets: async (secretSync: TAwsParameterStoreSyncWithCredentials): Promise<TSecretMap> => { getSecrets: async (secretSync: TAwsParameterStoreSyncWithCredentials): Promise<TSecretMap> => {
const { destinationConfig, syncOptions } = secretSync; const { destinationConfig, syncOptions, environment } = secretSync;
const ssm = await getSSM(secretSync); const ssm = await getSSM(secretSync);
const awsParameterStoreSecretsRecord = await getParametersByPath( const awsParameterStoreSecretsRecord = await getParametersByPath(
ssm, ssm,
destinationConfig.path, destinationConfig.path,
syncOptions.keySchema syncOptions.keySchema,
environment!.slug
); );
return Object.fromEntries( return Object.fromEntries(
@@ -452,14 +463,15 @@ export const AwsParameterStoreSyncFns = {
); );
}, },
removeSecrets: async (secretSync: TAwsParameterStoreSyncWithCredentials, secretMap: TSecretMap) => { removeSecrets: async (secretSync: TAwsParameterStoreSyncWithCredentials, secretMap: TSecretMap) => {
const { destinationConfig, syncOptions } = secretSync; const { destinationConfig, syncOptions, environment } = secretSync;
const ssm = await getSSM(secretSync); const ssm = await getSSM(secretSync);
const awsParameterStoreSecretsRecord = await getParametersByPath( const awsParameterStoreSecretsRecord = await getParametersByPath(
ssm, ssm,
destinationConfig.path, destinationConfig.path,
syncOptions.keySchema syncOptions.keySchema,
environment!.slug
); );
const parametersToDelete: AWS.SSM.Parameter[] = []; const parametersToDelete: AWS.SSM.Parameter[] = [];