mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 09:28:52 +00:00
Merge remote-tracking branch 'origin/main' into pki-revamp
This commit is contained in:
@@ -2,7 +2,9 @@ import knex, { Knex } from "knex";
|
||||
|
||||
const parseSslConfig = (dbConnectionUri: string, dbRootCert?: string) => {
|
||||
let modifiedDbConnectionUri = dbConnectionUri;
|
||||
let sslConfig: { rejectUnauthorized: boolean; ca: string } | boolean = false;
|
||||
let sslConfig: { rejectUnauthorized: boolean; ca: string } | boolean = dbRootCert
|
||||
? { rejectUnauthorized: true, ca: Buffer.from(dbRootCert, "base64").toString("ascii") }
|
||||
: false;
|
||||
|
||||
if (dbRootCert) {
|
||||
const url = new URL(dbConnectionUri);
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
import { Knex } from "knex";
|
||||
|
||||
import { TableName } from "../schemas";
|
||||
|
||||
export async function up(knex: Knex): Promise<void> {
|
||||
const hasScopeColumn = await knex.schema.hasColumn(TableName.Membership, "scope");
|
||||
const hasActorIdentityColumn = await knex.schema.hasColumn(TableName.Membership, "actorIdentityId");
|
||||
if (hasScopeColumn && hasActorIdentityColumn) {
|
||||
await knex.schema.alterTable(TableName.Membership, (t) => {
|
||||
t.index(["scope", "actorIdentityId"]);
|
||||
});
|
||||
}
|
||||
}
|
||||
|
||||
export async function down(knex: Knex): Promise<void> {
|
||||
const hasScopeColumn = await knex.schema.hasColumn(TableName.Membership, "scope");
|
||||
const hasActorIdentityColumn = await knex.schema.hasColumn(TableName.Membership, "actorIdentityId");
|
||||
if (hasScopeColumn && hasActorIdentityColumn) {
|
||||
await knex.schema.alterTable(TableName.Membership, (t) => {
|
||||
t.dropIndex(["scope", "actorIdentityId"]);
|
||||
});
|
||||
}
|
||||
}
|
||||
@@ -2,7 +2,6 @@ import net from "node:net";
|
||||
|
||||
import { ForbiddenError } from "@casl/ability";
|
||||
import * as x509 from "@peculiar/x509";
|
||||
import { CronJob } from "cron";
|
||||
|
||||
import { OrgMembershipRole, TRelays } from "@app/db/schemas";
|
||||
import { PgSqlLock } from "@app/keystore/keystore";
|
||||
@@ -891,7 +890,7 @@ export const gatewayV2ServiceFactory = ({
|
||||
});
|
||||
};
|
||||
|
||||
const $healthcheckNotify = async () => {
|
||||
const healthcheckNotify = async () => {
|
||||
const unhealthyGateways = await gatewayV2DAL.find({
|
||||
isHeartbeatStale: true
|
||||
});
|
||||
@@ -945,18 +944,6 @@ export const gatewayV2ServiceFactory = ({
|
||||
}
|
||||
};
|
||||
|
||||
const initializeHealthcheckNotify = async () => {
|
||||
logger.info("Setting up background notification process for gateway v2 health-checks");
|
||||
|
||||
await $healthcheckNotify();
|
||||
|
||||
// run every 5 minutes
|
||||
const job = new CronJob("*/5 * * * *", $healthcheckNotify);
|
||||
job.start();
|
||||
|
||||
return job;
|
||||
};
|
||||
|
||||
return {
|
||||
listGateways,
|
||||
registerGateway,
|
||||
@@ -965,6 +952,6 @@ export const gatewayV2ServiceFactory = ({
|
||||
deleteGatewayById,
|
||||
heartbeat,
|
||||
getPamSessionKey,
|
||||
initializeHealthcheckNotify
|
||||
healthcheckNotify
|
||||
};
|
||||
};
|
||||
|
||||
@@ -25,7 +25,9 @@ export const initializeHsmModule = (envConfig: Pick<TEnvConfig, "isHsmConfigured
|
||||
|
||||
logger.info("PKCS#11 module initialized");
|
||||
} catch (error) {
|
||||
if (error instanceof pkcs11js.Pkcs11Error && error.code === pkcs11js.CKR_CRYPTOKI_ALREADY_INITIALIZED) {
|
||||
logger.error(error, "Failed to initialize PKCS#11 module");
|
||||
|
||||
if ((error as { message?: string })?.message === "CKR_CRYPTOKI_ALREADY_INITIALIZED") {
|
||||
logger.info("Skipping HSM initialization because it's already initialized.");
|
||||
} else {
|
||||
logger.error(error, "Failed to initialize PKCS#11 module");
|
||||
|
||||
@@ -44,7 +44,7 @@ export const licenseDALFactory = (db: TDbClient) => {
|
||||
|
||||
// count org identities
|
||||
const identityDoc = await (tx || db.replicaNode())(TableName.Membership)
|
||||
.where({ status: OrgMembershipStatus.Accepted, scope: AccessScope.Organization })
|
||||
.where({ scope: AccessScope.Organization })
|
||||
.whereNotNull(`${TableName.Membership}.actorIdentityId`)
|
||||
.where((bd) => {
|
||||
if (orgId) {
|
||||
|
||||
@@ -2,7 +2,6 @@ import { isIP } from "node:net";
|
||||
|
||||
import { ForbiddenError } from "@casl/ability";
|
||||
import * as x509 from "@peculiar/x509";
|
||||
import { CronJob } from "cron";
|
||||
|
||||
import { OrgMembershipRole, TRelays } from "@app/db/schemas";
|
||||
import { PgSqlLock } from "@app/keystore/keystore";
|
||||
@@ -1209,7 +1208,7 @@ export const relayServiceFactory = ({
|
||||
return deletedRelay;
|
||||
};
|
||||
|
||||
const $healthcheckNotify = async () => {
|
||||
const healthcheckNotify = async () => {
|
||||
const unhealthyRelays = await relayDAL.find({
|
||||
isHeartbeatStale: true
|
||||
});
|
||||
@@ -1283,18 +1282,6 @@ export const relayServiceFactory = ({
|
||||
}
|
||||
};
|
||||
|
||||
const initializeHealthcheckNotify = async () => {
|
||||
logger.info("Setting up background notification process for relay health-checks");
|
||||
|
||||
await $healthcheckNotify();
|
||||
|
||||
// run every 5 minutes
|
||||
const job = new CronJob("*/5 * * * *", $healthcheckNotify);
|
||||
job.start();
|
||||
|
||||
return job;
|
||||
};
|
||||
|
||||
return {
|
||||
registerRelay,
|
||||
getCredentialsForGateway,
|
||||
@@ -1302,6 +1289,6 @@ export const relayServiceFactory = ({
|
||||
getRelays,
|
||||
deleteRelay,
|
||||
heartbeat,
|
||||
initializeHealthcheckNotify
|
||||
healthcheckNotify
|
||||
};
|
||||
};
|
||||
|
||||
@@ -2356,6 +2356,9 @@ export const AppConnections = {
|
||||
sslRejectUnauthorized:
|
||||
"Whether or not to reject unauthorized SSL certificates (true/false). Set to false only in test environments with self-signed certificates.",
|
||||
sslCertificate: "The SSL certificate (PEM format) to use for secure connection."
|
||||
},
|
||||
LARAVEL_FORGE: {
|
||||
apiToken: "The API token used to authenticate with Laravel Forge."
|
||||
}
|
||||
}
|
||||
};
|
||||
@@ -2508,6 +2511,14 @@ export const SecretSyncs = {
|
||||
branch: "The branch to sync preview secrets to.",
|
||||
teamId: "The ID of the Vercel team to sync secrets to."
|
||||
},
|
||||
LARAVEL_FORGE: {
|
||||
orgSlug: "The slug of the Laravel Forge org to sync secrets to.",
|
||||
orgName: "The name of the Laravel Forge org to sync secrets to.",
|
||||
serverId: "The ID of the Laravel Forge server to sync secrets to.",
|
||||
serverName: "The name of the Laravel Forge server to sync secrets to.",
|
||||
siteId: "The ID of the Laravel Forge site to sync secrets to.",
|
||||
siteName: "The name of the Laravel Forge site to sync secrets to."
|
||||
},
|
||||
WINDMILL: {
|
||||
workspace: "The Windmill workspace to sync secrets to.",
|
||||
path: "The Windmill workspace path to sync secrets to."
|
||||
|
||||
@@ -76,7 +76,8 @@ export enum QueueName {
|
||||
TelemetryAggregatedEvents = "telemetry-aggregated-events",
|
||||
DailyReminders = "daily-reminders",
|
||||
SecretReminderMigration = "secret-reminder-migration",
|
||||
UserNotification = "user-notification"
|
||||
UserNotification = "user-notification",
|
||||
HealthAlert = "health-alert"
|
||||
}
|
||||
|
||||
export enum QueueJobs {
|
||||
@@ -124,7 +125,8 @@ export enum QueueJobs {
|
||||
TelemetryAggregatedEvents = "telemetry-aggregated-events",
|
||||
DailyReminders = "daily-reminders",
|
||||
SecretReminderMigration = "secret-reminder-migration",
|
||||
UserNotification = "user-notification-job"
|
||||
UserNotification = "user-notification-job",
|
||||
HealthAlert = "health-alert"
|
||||
}
|
||||
|
||||
export type TQueueJobTypes = {
|
||||
@@ -351,6 +353,10 @@ export type TQueueJobTypes = {
|
||||
name: QueueJobs.UserNotification;
|
||||
payload: { notifications: TCreateUserNotificationDTO[] };
|
||||
};
|
||||
[QueueName.HealthAlert]: {
|
||||
name: QueueJobs.HealthAlert;
|
||||
payload: undefined;
|
||||
};
|
||||
};
|
||||
|
||||
const SECRET_SCANNING_JOBS = [
|
||||
|
||||
@@ -194,6 +194,7 @@ import { folderTreeCheckpointDALFactory } from "@app/services/folder-tree-checkp
|
||||
import { folderTreeCheckpointResourcesDALFactory } from "@app/services/folder-tree-checkpoint-resources/folder-tree-checkpoint-resources-dal";
|
||||
import { groupProjectDALFactory } from "@app/services/group-project/group-project-dal";
|
||||
import { groupProjectServiceFactory } from "@app/services/group-project/group-project-service";
|
||||
import { healthAlertServiceFactory } from "@app/services/health-alert/health-alert-queue";
|
||||
import { identityDALFactory } from "@app/services/identity/identity-dal";
|
||||
import { identityMetadataDALFactory } from "@app/services/identity/identity-metadata-dal";
|
||||
import { identityOrgDALFactory } from "@app/services/identity/identity-org-dal";
|
||||
@@ -1619,9 +1620,9 @@ export const registerRoutes = async (
|
||||
|
||||
const identityAccessTokenService = identityAccessTokenServiceFactory({
|
||||
identityAccessTokenDAL,
|
||||
identityOrgMembershipDAL,
|
||||
accessTokenQueue,
|
||||
identityDAL
|
||||
identityDAL,
|
||||
membershipIdentityDAL
|
||||
});
|
||||
|
||||
const identityTokenAuthService = identityTokenAuthServiceFactory({
|
||||
@@ -1807,6 +1808,7 @@ export const registerRoutes = async (
|
||||
identityDAL
|
||||
});
|
||||
|
||||
// DAILY
|
||||
const dailyResourceCleanUp = dailyResourceCleanUpQueueServiceFactory({
|
||||
auditLogDAL,
|
||||
queueService,
|
||||
@@ -1823,6 +1825,12 @@ export const registerRoutes = async (
|
||||
keyValueStoreDAL
|
||||
});
|
||||
|
||||
const healthAlert = healthAlertServiceFactory({
|
||||
gatewayV2Service,
|
||||
queueService,
|
||||
relayService
|
||||
});
|
||||
|
||||
const dailyReminderQueueService = dailyReminderQueueServiceFactory({
|
||||
reminderService,
|
||||
queueService,
|
||||
@@ -2256,6 +2264,7 @@ export const registerRoutes = async (
|
||||
await telemetryQueue.startTelemetryCheck();
|
||||
await telemetryQueue.startAggregatedEventsJob();
|
||||
await dailyResourceCleanUp.init();
|
||||
await healthAlert.init();
|
||||
await pkiSyncCleanup.init();
|
||||
await dailyReminderQueueService.startDailyRemindersJob();
|
||||
await dailyReminderQueueService.startSecretReminderMigrationJob();
|
||||
@@ -2420,16 +2429,6 @@ export const registerRoutes = async (
|
||||
cronJobs.push(configSyncJob);
|
||||
}
|
||||
|
||||
const gatewayHealthcheckNotifyJob = await gatewayV2Service.initializeHealthcheckNotify();
|
||||
if (gatewayHealthcheckNotifyJob) {
|
||||
cronJobs.push(gatewayHealthcheckNotifyJob);
|
||||
}
|
||||
|
||||
const relayHealthcheckNotifyJob = await relayService.initializeHealthcheckNotify();
|
||||
if (relayHealthcheckNotifyJob) {
|
||||
cronJobs.push(relayHealthcheckNotifyJob);
|
||||
}
|
||||
|
||||
const oauthConfigSyncJob = await initializeOauthConfigSync();
|
||||
if (oauthConfigSyncJob) {
|
||||
cronJobs.push(oauthConfigSyncJob);
|
||||
|
||||
@@ -77,6 +77,10 @@ import {
|
||||
HumanitecConnectionListItemSchema,
|
||||
SanitizedHumanitecConnectionSchema
|
||||
} from "@app/services/app-connection/humanitec";
|
||||
import {
|
||||
LaravelForgeConnectionListItemSchema,
|
||||
SanitizedLaravelForgeConnectionSchema
|
||||
} from "@app/services/app-connection/laravel-forge";
|
||||
import { LdapConnectionListItemSchema, SanitizedLdapConnectionSchema } from "@app/services/app-connection/ldap";
|
||||
import { MsSqlConnectionListItemSchema, SanitizedMsSqlConnectionSchema } from "@app/services/app-connection/mssql";
|
||||
import { MySqlConnectionListItemSchema, SanitizedMySqlConnectionSchema } from "@app/services/app-connection/mysql";
|
||||
@@ -158,7 +162,8 @@ const SanitizedAppConnectionSchema = z.union([
|
||||
...SanitizedNetlifyConnectionSchema.options,
|
||||
...SanitizedOktaConnectionSchema.options,
|
||||
...SanitizedAzureADCSConnectionSchema.options,
|
||||
...SanitizedRedisConnectionSchema.options
|
||||
...SanitizedRedisConnectionSchema.options,
|
||||
...SanitizedLaravelForgeConnectionSchema.options
|
||||
]);
|
||||
|
||||
const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
||||
@@ -200,7 +205,8 @@ const AppConnectionOptionsSchema = z.discriminatedUnion("app", [
|
||||
NetlifyConnectionListItemSchema,
|
||||
OktaConnectionListItemSchema,
|
||||
AzureADCSConnectionListItemSchema,
|
||||
RedisConnectionListItemSchema
|
||||
RedisConnectionListItemSchema,
|
||||
LaravelForgeConnectionListItemSchema
|
||||
]);
|
||||
|
||||
export const registerAppConnectionRouter = async (server: FastifyZodProvider) => {
|
||||
|
||||
@@ -24,6 +24,7 @@ import { registerGitLabConnectionRouter } from "./gitlab-connection-router";
|
||||
import { registerHCVaultConnectionRouter } from "./hc-vault-connection-router";
|
||||
import { registerHerokuConnectionRouter } from "./heroku-connection-router";
|
||||
import { registerHumanitecConnectionRouter } from "./humanitec-connection-router";
|
||||
import { registerLaravelForgeConnectionRouter } from "./laravel-forge-connection-router";
|
||||
import { registerLdapConnectionRouter } from "./ldap-connection-router";
|
||||
import { registerMsSqlConnectionRouter } from "./mssql-connection-router";
|
||||
import { registerMySqlConnectionRouter } from "./mysql-connection-router";
|
||||
@@ -71,6 +72,7 @@ export const APP_CONNECTION_REGISTER_ROUTER_MAP: Record<AppConnection, (server:
|
||||
[AppConnection.OnePass]: registerOnePassConnectionRouter,
|
||||
[AppConnection.Heroku]: registerHerokuConnectionRouter,
|
||||
[AppConnection.Render]: registerRenderConnectionRouter,
|
||||
[AppConnection.LaravelForge]: registerLaravelForgeConnectionRouter,
|
||||
[AppConnection.Flyio]: registerFlyioConnectionRouter,
|
||||
[AppConnection.GitLab]: registerGitLabConnectionRouter,
|
||||
[AppConnection.Cloudflare]: registerCloudflareConnectionRouter,
|
||||
|
||||
+128
@@ -0,0 +1,128 @@
|
||||
import z from "zod";
|
||||
|
||||
import { readLimit } from "@app/server/config/rateLimiter";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||
import {
|
||||
CreateLaravelForgeConnectionSchema,
|
||||
SanitizedLaravelForgeConnectionSchema,
|
||||
UpdateLaravelForgeConnectionSchema
|
||||
} from "@app/services/app-connection/laravel-forge";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
|
||||
import { registerAppConnectionEndpoints } from "./app-connection-endpoints";
|
||||
|
||||
export const registerLaravelForgeConnectionRouter = async (server: FastifyZodProvider) => {
|
||||
registerAppConnectionEndpoints({
|
||||
app: AppConnection.LaravelForge,
|
||||
server,
|
||||
sanitizedResponseSchema: SanitizedLaravelForgeConnectionSchema,
|
||||
createSchema: CreateLaravelForgeConnectionSchema,
|
||||
updateSchema: UpdateLaravelForgeConnectionSchema
|
||||
});
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: `/:connectionId/organizations`,
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
connectionId: z.string().uuid()
|
||||
}),
|
||||
response: {
|
||||
200: z
|
||||
.object({
|
||||
id: z.string(),
|
||||
name: z.string(),
|
||||
slug: z.string()
|
||||
})
|
||||
.array()
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const { connectionId } = req.params;
|
||||
const organizations = await server.services.appConnection.laravelForge.listOrganizations(
|
||||
connectionId,
|
||||
req.permission
|
||||
);
|
||||
|
||||
return organizations;
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: `/:connectionId/servers`,
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
connectionId: z.string().uuid()
|
||||
}),
|
||||
querystring: z.object({
|
||||
organizationSlug: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z
|
||||
.object({
|
||||
id: z.string(),
|
||||
name: z.string()
|
||||
})
|
||||
.array()
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const { connectionId } = req.params;
|
||||
const { organizationSlug } = req.query;
|
||||
const servers = await server.services.appConnection.laravelForge.listServers(
|
||||
connectionId,
|
||||
req.permission,
|
||||
organizationSlug
|
||||
);
|
||||
|
||||
return servers;
|
||||
}
|
||||
});
|
||||
|
||||
server.route({
|
||||
method: "GET",
|
||||
url: `/:connectionId/sites`,
|
||||
config: {
|
||||
rateLimit: readLimit
|
||||
},
|
||||
schema: {
|
||||
params: z.object({
|
||||
connectionId: z.string().uuid()
|
||||
}),
|
||||
querystring: z.object({
|
||||
organizationSlug: z.string(),
|
||||
serverId: z.string()
|
||||
}),
|
||||
response: {
|
||||
200: z
|
||||
.object({
|
||||
id: z.string(),
|
||||
name: z.string()
|
||||
})
|
||||
.array()
|
||||
}
|
||||
},
|
||||
onRequest: verifyAuth([AuthMode.JWT]),
|
||||
handler: async (req) => {
|
||||
const { connectionId } = req.params;
|
||||
const { organizationSlug, serverId } = req.query;
|
||||
const sites = await server.services.appConnection.laravelForge.listSites(
|
||||
connectionId,
|
||||
req.permission,
|
||||
organizationSlug,
|
||||
serverId
|
||||
);
|
||||
|
||||
return sites;
|
||||
}
|
||||
});
|
||||
};
|
||||
@@ -21,6 +21,7 @@ import { registerGitLabSyncRouter } from "./gitlab-sync-router";
|
||||
import { registerHCVaultSyncRouter } from "./hc-vault-sync-router";
|
||||
import { registerHerokuSyncRouter } from "./heroku-sync-router";
|
||||
import { registerHumanitecSyncRouter } from "./humanitec-sync-router";
|
||||
import { registerLaravelForgeSyncRouter } from "./laravel-forge-sync-router";
|
||||
import { registerNetlifySyncRouter } from "./netlify-sync-router";
|
||||
import { registerRailwaySyncRouter } from "./railway-sync-router";
|
||||
import { registerRenderSyncRouter } from "./render-sync-router";
|
||||
@@ -63,5 +64,6 @@ export const SECRET_SYNC_REGISTER_ROUTER_MAP: Record<SecretSync, (server: Fastif
|
||||
[SecretSync.Checkly]: registerChecklySyncRouter,
|
||||
[SecretSync.DigitalOceanAppPlatform]: registerDigitalOceanAppPlatformSyncRouter,
|
||||
[SecretSync.Netlify]: registerNetlifySyncRouter,
|
||||
[SecretSync.Bitbucket]: registerBitbucketSyncRouter
|
||||
[SecretSync.Bitbucket]: registerBitbucketSyncRouter,
|
||||
[SecretSync.LaravelForge]: registerLaravelForgeSyncRouter
|
||||
};
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
import {
|
||||
CreateLaravelForgeSyncSchema,
|
||||
LaravelForgeSyncSchema,
|
||||
UpdateLaravelForgeSyncSchema
|
||||
} from "@app/services/secret-sync/laravel-forge";
|
||||
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||
|
||||
import { registerSyncSecretsEndpoints } from "./secret-sync-endpoints";
|
||||
|
||||
export const registerLaravelForgeSyncRouter = async (server: FastifyZodProvider) =>
|
||||
registerSyncSecretsEndpoints({
|
||||
destination: SecretSync.LaravelForge,
|
||||
server,
|
||||
responseSchema: LaravelForgeSyncSchema,
|
||||
createSchema: CreateLaravelForgeSyncSchema,
|
||||
updateSchema: UpdateLaravelForgeSyncSchema
|
||||
});
|
||||
@@ -44,6 +44,7 @@ import { GitLabSyncListItemSchema, GitLabSyncSchema } from "@app/services/secret
|
||||
import { HCVaultSyncListItemSchema, HCVaultSyncSchema } from "@app/services/secret-sync/hc-vault";
|
||||
import { HerokuSyncListItemSchema, HerokuSyncSchema } from "@app/services/secret-sync/heroku";
|
||||
import { HumanitecSyncListItemSchema, HumanitecSyncSchema } from "@app/services/secret-sync/humanitec";
|
||||
import { LaravelForgeSyncListItemSchema, LaravelForgeSyncSchema } from "@app/services/secret-sync/laravel-forge";
|
||||
import { NetlifySyncListItemSchema, NetlifySyncSchema } from "@app/services/secret-sync/netlify";
|
||||
import { RailwaySyncListItemSchema, RailwaySyncSchema } from "@app/services/secret-sync/railway/railway-sync-schemas";
|
||||
import { RenderSyncListItemSchema, RenderSyncSchema } from "@app/services/secret-sync/render/render-sync-schemas";
|
||||
@@ -84,7 +85,8 @@ const SecretSyncSchema = z.discriminatedUnion("destination", [
|
||||
ChecklySyncSchema,
|
||||
DigitalOceanAppPlatformSyncSchema,
|
||||
NetlifySyncSchema,
|
||||
BitbucketSyncSchema
|
||||
BitbucketSyncSchema,
|
||||
LaravelForgeSyncSchema
|
||||
]);
|
||||
|
||||
const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
||||
@@ -117,7 +119,8 @@ const SecretSyncOptionsSchema = z.discriminatedUnion("destination", [
|
||||
ChecklySyncListItemSchema,
|
||||
SupabaseSyncListItemSchema,
|
||||
NetlifySyncListItemSchema,
|
||||
BitbucketSyncListItemSchema
|
||||
BitbucketSyncListItemSchema,
|
||||
LaravelForgeSyncListItemSchema
|
||||
]);
|
||||
|
||||
export const registerSecretSyncRouter = async (server: FastifyZodProvider) => {
|
||||
|
||||
@@ -37,7 +37,8 @@ export enum AppConnection {
|
||||
DigitalOcean = "digital-ocean",
|
||||
Netlify = "netlify",
|
||||
Okta = "okta",
|
||||
Redis = "redis"
|
||||
Redis = "redis",
|
||||
LaravelForge = "laravel-forge"
|
||||
}
|
||||
|
||||
export enum AWSRegion {
|
||||
|
||||
@@ -103,6 +103,11 @@ import {
|
||||
HumanitecConnectionMethod,
|
||||
validateHumanitecConnectionCredentials
|
||||
} from "./humanitec";
|
||||
import {
|
||||
getLaravelForgeConnectionListItem,
|
||||
LaravelForgeConnectionMethod,
|
||||
validateLaravelForgeConnectionCredentials
|
||||
} from "./laravel-forge";
|
||||
import { getLdapConnectionListItem, LdapConnectionMethod, validateLdapConnectionCredentials } from "./ldap";
|
||||
import { getMsSqlConnectionListItem, MsSqlConnectionMethod } from "./mssql";
|
||||
import { MySqlConnectionMethod } from "./mysql/mysql-connection-enums";
|
||||
@@ -187,6 +192,7 @@ export const listAppConnectionOptions = (projectType?: ProjectType) => {
|
||||
getOnePassConnectionListItem(),
|
||||
getHerokuConnectionListItem(),
|
||||
getRenderConnectionListItem(),
|
||||
getLaravelForgeConnectionListItem(),
|
||||
getFlyioConnectionListItem(),
|
||||
getGitLabConnectionListItem(),
|
||||
getCloudflareConnectionListItem(),
|
||||
@@ -316,6 +322,7 @@ export const validateAppConnectionCredentials = async (
|
||||
[AppConnection.OnePass]: validateOnePassConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
[AppConnection.Heroku]: validateHerokuConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
[AppConnection.Render]: validateRenderConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
[AppConnection.LaravelForge]: validateLaravelForgeConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
[AppConnection.Flyio]: validateFlyioConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
[AppConnection.GitLab]: validateGitLabConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
[AppConnection.Cloudflare]: validateCloudflareConnectionCredentials as TAppConnectionCredentialsValidator,
|
||||
@@ -368,6 +375,7 @@ export const getAppConnectionMethodName = (method: TAppConnection["method"]) =>
|
||||
case ZabbixConnectionMethod.ApiToken:
|
||||
case DigitalOceanConnectionMethod.ApiToken:
|
||||
case OktaConnectionMethod.ApiToken:
|
||||
case LaravelForgeConnectionMethod.ApiToken:
|
||||
return "API Token";
|
||||
case PostgresConnectionMethod.UsernameAndPassword:
|
||||
case MsSqlConnectionMethod.UsernameAndPassword:
|
||||
@@ -463,7 +471,8 @@ export const TRANSITION_CONNECTION_CREDENTIALS_TO_PLATFORM: Record<
|
||||
[AppConnection.DigitalOcean]: platformManagedCredentialsNotSupported,
|
||||
[AppConnection.Netlify]: platformManagedCredentialsNotSupported,
|
||||
[AppConnection.Okta]: platformManagedCredentialsNotSupported,
|
||||
[AppConnection.Redis]: platformManagedCredentialsNotSupported
|
||||
[AppConnection.Redis]: platformManagedCredentialsNotSupported,
|
||||
[AppConnection.LaravelForge]: platformManagedCredentialsNotSupported
|
||||
};
|
||||
|
||||
export const enterpriseAppCheck = async (
|
||||
|
||||
@@ -28,6 +28,7 @@ export const APP_CONNECTION_NAME_MAP: Record<AppConnection, string> = {
|
||||
[AppConnection.OnePass]: "1Password",
|
||||
[AppConnection.Heroku]: "Heroku",
|
||||
[AppConnection.Render]: "Render",
|
||||
[AppConnection.LaravelForge]: "Laravel Forge",
|
||||
[AppConnection.Flyio]: "Fly.io",
|
||||
[AppConnection.GitLab]: "GitLab",
|
||||
[AppConnection.Cloudflare]: "Cloudflare",
|
||||
@@ -70,6 +71,7 @@ export const APP_CONNECTION_PLAN_MAP: Record<AppConnection, AppConnectionPlanTyp
|
||||
[AppConnection.MySql]: AppConnectionPlanType.Regular,
|
||||
[AppConnection.Heroku]: AppConnectionPlanType.Regular,
|
||||
[AppConnection.Render]: AppConnectionPlanType.Regular,
|
||||
[AppConnection.LaravelForge]: AppConnectionPlanType.Regular,
|
||||
[AppConnection.Flyio]: AppConnectionPlanType.Regular,
|
||||
[AppConnection.GitLab]: AppConnectionPlanType.Regular,
|
||||
[AppConnection.Cloudflare]: AppConnectionPlanType.Regular,
|
||||
|
||||
@@ -89,6 +89,8 @@ import { ValidateHerokuConnectionCredentialsSchema } from "./heroku";
|
||||
import { herokuConnectionService } from "./heroku/heroku-connection-service";
|
||||
import { ValidateHumanitecConnectionCredentialsSchema } from "./humanitec";
|
||||
import { humanitecConnectionService } from "./humanitec/humanitec-connection-service";
|
||||
import { ValidateLaravelForgeConnectionCredentialsSchema } from "./laravel-forge";
|
||||
import { laravelForgeConnectionService } from "./laravel-forge/laravel-forge-connection-service";
|
||||
import { ValidateLdapConnectionCredentialsSchema } from "./ldap";
|
||||
import { ValidateMsSqlConnectionCredentialsSchema } from "./mssql";
|
||||
import { ValidateMySqlConnectionCredentialsSchema } from "./mysql";
|
||||
@@ -157,6 +159,7 @@ const VALIDATE_APP_CONNECTION_CREDENTIALS_MAP: Record<AppConnection, TValidateAp
|
||||
[AppConnection.OnePass]: ValidateOnePassConnectionCredentialsSchema,
|
||||
[AppConnection.Heroku]: ValidateHerokuConnectionCredentialsSchema,
|
||||
[AppConnection.Render]: ValidateRenderConnectionCredentialsSchema,
|
||||
[AppConnection.LaravelForge]: ValidateLaravelForgeConnectionCredentialsSchema,
|
||||
[AppConnection.Flyio]: ValidateFlyioConnectionCredentialsSchema,
|
||||
[AppConnection.GitLab]: ValidateGitLabConnectionCredentialsSchema,
|
||||
[AppConnection.Cloudflare]: ValidateCloudflareConnectionCredentialsSchema,
|
||||
@@ -864,6 +867,7 @@ export const appConnectionServiceFactory = ({
|
||||
supabase: supabaseConnectionService(connectAppConnectionById),
|
||||
digitalOcean: digitalOceanAppPlatformConnectionService(connectAppConnectionById),
|
||||
netlify: netlifyConnectionService(connectAppConnectionById),
|
||||
okta: oktaConnectionService(connectAppConnectionById)
|
||||
okta: oktaConnectionService(connectAppConnectionById),
|
||||
laravelForge: laravelForgeConnectionService(connectAppConnectionById)
|
||||
};
|
||||
};
|
||||
|
||||
@@ -148,6 +148,12 @@ import {
|
||||
THumanitecConnectionInput,
|
||||
TValidateHumanitecConnectionCredentialsSchema
|
||||
} from "./humanitec";
|
||||
import {
|
||||
TLaravelForgeConnection,
|
||||
TLaravelForgeConnectionConfig,
|
||||
TLaravelForgeConnectionInput,
|
||||
TValidateLaravelForgeConnectionCredentialsSchema
|
||||
} from "./laravel-forge";
|
||||
import {
|
||||
TLdapConnection,
|
||||
TLdapConnectionConfig,
|
||||
@@ -256,6 +262,7 @@ export type TAppConnection = { id: string } & (
|
||||
| TOnePassConnection
|
||||
| THerokuConnection
|
||||
| TRenderConnection
|
||||
| TLaravelForgeConnection
|
||||
| TFlyioConnection
|
||||
| TGitLabConnection
|
||||
| TCloudflareConnection
|
||||
@@ -302,6 +309,7 @@ export type TAppConnectionInput = { id: string } & (
|
||||
| TOnePassConnectionInput
|
||||
| THerokuConnectionInput
|
||||
| TRenderConnectionInput
|
||||
| TLaravelForgeConnectionInput
|
||||
| TFlyioConnectionInput
|
||||
| TGitLabConnectionInput
|
||||
| TCloudflareConnectionInput
|
||||
@@ -366,6 +374,7 @@ export type TAppConnectionConfig =
|
||||
| TOnePassConnectionConfig
|
||||
| THerokuConnectionConfig
|
||||
| TRenderConnectionConfig
|
||||
| TLaravelForgeConnectionConfig
|
||||
| TFlyioConnectionConfig
|
||||
| TGitLabConnectionConfig
|
||||
| TCloudflareConnectionConfig
|
||||
@@ -407,6 +416,7 @@ export type TValidateAppConnectionCredentialsSchema =
|
||||
| TValidateOnePassConnectionCredentialsSchema
|
||||
| TValidateHerokuConnectionCredentialsSchema
|
||||
| TValidateRenderConnectionCredentialsSchema
|
||||
| TValidateLaravelForgeConnectionCredentialsSchema
|
||||
| TValidateFlyioConnectionCredentialsSchema
|
||||
| TValidateGitLabConnectionCredentialsSchema
|
||||
| TValidateCloudflareConnectionCredentialsSchema
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
export * from "./laravel-forge-connection-enums";
|
||||
export * from "./laravel-forge-connection-fns";
|
||||
export * from "./laravel-forge-connection-schemas";
|
||||
export * from "./laravel-forge-connection-types";
|
||||
@@ -0,0 +1,3 @@
|
||||
export enum LaravelForgeConnectionMethod {
|
||||
ApiToken = "api-token"
|
||||
}
|
||||
@@ -0,0 +1,165 @@
|
||||
/* eslint-disable no-await-in-loop */
|
||||
import { AxiosError } from "axios";
|
||||
|
||||
import { request } from "@app/lib/config/request";
|
||||
import { BadRequestError, InternalServerError } from "@app/lib/errors";
|
||||
import { IntegrationUrls } from "@app/services/integration-auth/integration-list";
|
||||
|
||||
import { AppConnection } from "../app-connection-enums";
|
||||
import { LaravelForgeConnectionMethod } from "./laravel-forge-connection-enums";
|
||||
import {
|
||||
TLaravelForgeConnection,
|
||||
TLaravelForgeConnectionConfig,
|
||||
TLaravelForgeOrganization,
|
||||
TLaravelForgeServer,
|
||||
TLaravelForgeSite,
|
||||
TRawLaravelForgeOrganization,
|
||||
TRawLaravelForgeServer,
|
||||
TRawLaravelForgeSite
|
||||
} from "./laravel-forge-connection-types";
|
||||
|
||||
export const getLaravelForgeConnectionListItem = () => {
|
||||
return {
|
||||
name: "Laravel Forge" as const,
|
||||
app: AppConnection.LaravelForge as const,
|
||||
methods: Object.values(LaravelForgeConnectionMethod) as [LaravelForgeConnectionMethod.ApiToken]
|
||||
};
|
||||
};
|
||||
|
||||
export const validateLaravelForgeConnectionCredentials = async (config: TLaravelForgeConnectionConfig) => {
|
||||
const { credentials: inputCredentials } = config;
|
||||
|
||||
try {
|
||||
// Using the /api/me endpoint to validate the API token
|
||||
await request.get(`${IntegrationUrls.LARAVELFORGE_API_URL}/api/me`, {
|
||||
headers: {
|
||||
Authorization: `Bearer ${inputCredentials.apiToken}`,
|
||||
Accept: "application/json",
|
||||
"Content-Type": "application/json"
|
||||
}
|
||||
});
|
||||
} catch (error) {
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to validate credentials: ${error.message || "Unknown error"}`
|
||||
});
|
||||
}
|
||||
throw new BadRequestError({
|
||||
message: "Unable to validate connection: verify credentials"
|
||||
});
|
||||
}
|
||||
|
||||
return inputCredentials;
|
||||
};
|
||||
|
||||
type TLaravelForgeApiResponse<T> = {
|
||||
data: T[];
|
||||
links?: {
|
||||
next?: string;
|
||||
};
|
||||
meta?: {
|
||||
next_cursor?: string;
|
||||
prev_cursor?: string | null;
|
||||
};
|
||||
};
|
||||
|
||||
const fetchAllPages = async <T>(
|
||||
apiToken: string,
|
||||
url: string,
|
||||
params?: Record<string, string | number>
|
||||
): Promise<T[]> => {
|
||||
const allItems: T[] = [];
|
||||
let nextUrl: string | null = url;
|
||||
const queryParams = params || {};
|
||||
|
||||
while (nextUrl) {
|
||||
try {
|
||||
const response: { data: TLaravelForgeApiResponse<T> } = await request.get<TLaravelForgeApiResponse<T>>(nextUrl, {
|
||||
params: queryParams,
|
||||
headers: {
|
||||
Authorization: `Bearer ${apiToken}`,
|
||||
Accept: "application/json",
|
||||
"Content-Type": "application/json"
|
||||
}
|
||||
});
|
||||
|
||||
if (!response?.data?.data) {
|
||||
throw new InternalServerError({
|
||||
message: `Failed to fetch data from ${url}: Response was empty or malformed`
|
||||
});
|
||||
}
|
||||
|
||||
allItems.push(...response.data.data);
|
||||
|
||||
if (response.data.links?.next) {
|
||||
nextUrl = response.data.links.next;
|
||||
} else {
|
||||
nextUrl = null;
|
||||
}
|
||||
} catch (error) {
|
||||
if (error instanceof AxiosError) {
|
||||
throw new BadRequestError({
|
||||
message: `Failed to fetch data from ${url}: ${error.message || "Unknown error"}`
|
||||
});
|
||||
}
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
return allItems;
|
||||
};
|
||||
|
||||
export const listLaravelForgeOrganizations = async (
|
||||
appConnection: TLaravelForgeConnection
|
||||
): Promise<TLaravelForgeOrganization[]> => {
|
||||
const { credentials } = appConnection;
|
||||
const { apiToken } = credentials;
|
||||
|
||||
const rawOrganizations = await fetchAllPages<TRawLaravelForgeOrganization>(
|
||||
apiToken,
|
||||
`${IntegrationUrls.LARAVELFORGE_API_URL}/api/orgs`
|
||||
);
|
||||
|
||||
return rawOrganizations.map((org: TRawLaravelForgeOrganization) => ({
|
||||
id: org.id,
|
||||
name: org.attributes.name,
|
||||
slug: org.attributes.slug
|
||||
}));
|
||||
};
|
||||
|
||||
export const listLaravelForgeServers = async (
|
||||
appConnection: TLaravelForgeConnection,
|
||||
organizationSlug: string
|
||||
): Promise<TLaravelForgeServer[]> => {
|
||||
const { credentials } = appConnection;
|
||||
const { apiToken } = credentials;
|
||||
|
||||
const rawServers = await fetchAllPages<TRawLaravelForgeServer>(
|
||||
apiToken,
|
||||
`${IntegrationUrls.LARAVELFORGE_API_URL}/api/orgs/${organizationSlug}/servers`
|
||||
);
|
||||
|
||||
return rawServers.map((server: TRawLaravelForgeServer) => ({
|
||||
id: server.id,
|
||||
name: server.attributes.name
|
||||
}));
|
||||
};
|
||||
|
||||
export const listLaravelForgeSites = async (
|
||||
appConnection: TLaravelForgeConnection,
|
||||
organizationSlug: string,
|
||||
serverId: string
|
||||
): Promise<TLaravelForgeSite[]> => {
|
||||
const { credentials } = appConnection;
|
||||
const { apiToken } = credentials;
|
||||
|
||||
const rawSites = await fetchAllPages<TRawLaravelForgeSite>(
|
||||
apiToken,
|
||||
`${IntegrationUrls.LARAVELFORGE_API_URL}/api/orgs/${organizationSlug}/servers/${serverId}/sites`
|
||||
);
|
||||
|
||||
return rawSites.map((site: TRawLaravelForgeSite) => ({
|
||||
id: site.id,
|
||||
name: site.attributes.name
|
||||
}));
|
||||
};
|
||||
@@ -0,0 +1,58 @@
|
||||
import z from "zod";
|
||||
|
||||
import { AppConnections } from "@app/lib/api-docs";
|
||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||
import {
|
||||
BaseAppConnectionSchema,
|
||||
GenericCreateAppConnectionFieldsSchema,
|
||||
GenericUpdateAppConnectionFieldsSchema
|
||||
} from "@app/services/app-connection/app-connection-schemas";
|
||||
|
||||
import { LaravelForgeConnectionMethod } from "./laravel-forge-connection-enums";
|
||||
|
||||
export const LaravelForgeConnectionApiTokenCredentialsSchema = z.object({
|
||||
apiToken: z.string().trim().min(1, "API token required").describe(AppConnections.CREDENTIALS.LARAVEL_FORGE.apiToken)
|
||||
});
|
||||
|
||||
const BaseLaravelForgeConnectionSchema = BaseAppConnectionSchema.extend({ app: z.literal(AppConnection.LaravelForge) });
|
||||
|
||||
export const LaravelForgeConnectionSchema = BaseLaravelForgeConnectionSchema.extend({
|
||||
method: z.literal(LaravelForgeConnectionMethod.ApiToken),
|
||||
credentials: LaravelForgeConnectionApiTokenCredentialsSchema
|
||||
});
|
||||
|
||||
export const SanitizedLaravelForgeConnectionSchema = z.discriminatedUnion("method", [
|
||||
BaseLaravelForgeConnectionSchema.extend({
|
||||
method: z.literal(LaravelForgeConnectionMethod.ApiToken),
|
||||
credentials: LaravelForgeConnectionApiTokenCredentialsSchema.pick({})
|
||||
})
|
||||
]);
|
||||
|
||||
export const ValidateLaravelForgeConnectionCredentialsSchema = z.discriminatedUnion("method", [
|
||||
z.object({
|
||||
method: z
|
||||
.literal(LaravelForgeConnectionMethod.ApiToken)
|
||||
.describe(AppConnections.CREATE(AppConnection.LaravelForge).method),
|
||||
credentials: LaravelForgeConnectionApiTokenCredentialsSchema.describe(
|
||||
AppConnections.CREATE(AppConnection.LaravelForge).credentials
|
||||
)
|
||||
})
|
||||
]);
|
||||
|
||||
export const CreateLaravelForgeConnectionSchema = ValidateLaravelForgeConnectionCredentialsSchema.and(
|
||||
GenericCreateAppConnectionFieldsSchema(AppConnection.LaravelForge)
|
||||
);
|
||||
|
||||
export const UpdateLaravelForgeConnectionSchema = z
|
||||
.object({
|
||||
credentials: LaravelForgeConnectionApiTokenCredentialsSchema.optional().describe(
|
||||
AppConnections.UPDATE(AppConnection.LaravelForge).credentials
|
||||
)
|
||||
})
|
||||
.and(GenericUpdateAppConnectionFieldsSchema(AppConnection.LaravelForge));
|
||||
|
||||
export const LaravelForgeConnectionListItemSchema = z.object({
|
||||
name: z.literal("Laravel Forge"),
|
||||
app: z.literal(AppConnection.LaravelForge),
|
||||
methods: z.nativeEnum(LaravelForgeConnectionMethod).array()
|
||||
});
|
||||
@@ -0,0 +1,74 @@
|
||||
import { logger } from "@app/lib/logger";
|
||||
import { OrgServiceActor } from "@app/lib/types";
|
||||
|
||||
import { AppConnection } from "../app-connection-enums";
|
||||
import {
|
||||
listLaravelForgeOrganizations,
|
||||
listLaravelForgeServers,
|
||||
listLaravelForgeSites
|
||||
} from "./laravel-forge-connection-fns";
|
||||
import {
|
||||
TLaravelForgeConnection,
|
||||
TLaravelForgeOrganization,
|
||||
TLaravelForgeServer,
|
||||
TLaravelForgeSite
|
||||
} from "./laravel-forge-connection-types";
|
||||
|
||||
type TGetAppConnectionFunc = (
|
||||
app: AppConnection,
|
||||
connectionId: string,
|
||||
actor: OrgServiceActor
|
||||
) => Promise<TLaravelForgeConnection>;
|
||||
|
||||
export const laravelForgeConnectionService = (getAppConnection: TGetAppConnectionFunc) => {
|
||||
const listOrganizations = async (
|
||||
connectionId: string,
|
||||
actor: OrgServiceActor
|
||||
): Promise<TLaravelForgeOrganization[]> => {
|
||||
const appConnection = await getAppConnection(AppConnection.LaravelForge, connectionId, actor);
|
||||
try {
|
||||
const organizations = await listLaravelForgeOrganizations(appConnection);
|
||||
return organizations;
|
||||
} catch (error) {
|
||||
logger.error(error, "Failed to list organizations for Laravel Forge connection");
|
||||
return [];
|
||||
}
|
||||
};
|
||||
|
||||
const listServers = async (
|
||||
connectionId: string,
|
||||
actor: OrgServiceActor,
|
||||
organizationSlug: string
|
||||
): Promise<TLaravelForgeServer[]> => {
|
||||
const appConnection = await getAppConnection(AppConnection.LaravelForge, connectionId, actor);
|
||||
try {
|
||||
const servers = await listLaravelForgeServers(appConnection, organizationSlug);
|
||||
return servers;
|
||||
} catch (error) {
|
||||
logger.error(error, "Failed to list servers for Laravel Forge connection");
|
||||
return [];
|
||||
}
|
||||
};
|
||||
|
||||
const listSites = async (
|
||||
connectionId: string,
|
||||
actor: OrgServiceActor,
|
||||
organizationSlug: string,
|
||||
serverId: string
|
||||
): Promise<TLaravelForgeSite[]> => {
|
||||
const appConnection = await getAppConnection(AppConnection.LaravelForge, connectionId, actor);
|
||||
try {
|
||||
const sites = await listLaravelForgeSites(appConnection, organizationSlug, serverId);
|
||||
return sites;
|
||||
} catch (error) {
|
||||
logger.error(error, "Failed to list sites for Laravel Forge connection");
|
||||
return [];
|
||||
}
|
||||
};
|
||||
|
||||
return {
|
||||
listOrganizations,
|
||||
listServers,
|
||||
listSites
|
||||
};
|
||||
};
|
||||
@@ -0,0 +1,63 @@
|
||||
import z from "zod";
|
||||
|
||||
import { DiscriminativePick } from "@app/lib/types";
|
||||
|
||||
import { AppConnection } from "../app-connection-enums";
|
||||
import {
|
||||
CreateLaravelForgeConnectionSchema,
|
||||
LaravelForgeConnectionSchema,
|
||||
ValidateLaravelForgeConnectionCredentialsSchema
|
||||
} from "./laravel-forge-connection-schemas";
|
||||
|
||||
export type TLaravelForgeConnection = z.infer<typeof LaravelForgeConnectionSchema>;
|
||||
|
||||
export type TLaravelForgeConnectionInput = z.infer<typeof CreateLaravelForgeConnectionSchema> & {
|
||||
app: AppConnection.LaravelForge;
|
||||
};
|
||||
|
||||
export type TValidateLaravelForgeConnectionCredentialsSchema = typeof ValidateLaravelForgeConnectionCredentialsSchema;
|
||||
|
||||
export type TLaravelForgeConnectionConfig = DiscriminativePick<
|
||||
TLaravelForgeConnectionInput,
|
||||
"method" | "app" | "credentials"
|
||||
> & {
|
||||
orgSlug: string;
|
||||
};
|
||||
|
||||
export type TLaravelForgeOrganization = {
|
||||
id: string;
|
||||
name: string;
|
||||
slug: string;
|
||||
};
|
||||
|
||||
export type TLaravelForgeServer = {
|
||||
id: string;
|
||||
name: string;
|
||||
};
|
||||
|
||||
export type TLaravelForgeSite = {
|
||||
id: string;
|
||||
name: string;
|
||||
};
|
||||
|
||||
export type TRawLaravelForgeOrganization = {
|
||||
id: string;
|
||||
attributes: {
|
||||
name: string;
|
||||
slug: string;
|
||||
};
|
||||
};
|
||||
|
||||
export type TRawLaravelForgeServer = {
|
||||
id: string;
|
||||
attributes: {
|
||||
name: string;
|
||||
};
|
||||
};
|
||||
|
||||
export type TRawLaravelForgeSite = {
|
||||
id: string;
|
||||
attributes: {
|
||||
name: string;
|
||||
};
|
||||
};
|
||||
@@ -0,0 +1,65 @@
|
||||
import { TGatewayV2ServiceFactory } from "@app/ee/services/gateway-v2/gateway-v2-service";
|
||||
import { TRelayServiceFactory } from "@app/ee/services/relay/relay-service";
|
||||
import { getConfig } from "@app/lib/config/env";
|
||||
import { logger } from "@app/lib/logger";
|
||||
import { QueueJobs, QueueName, TQueueServiceFactory } from "@app/queue";
|
||||
|
||||
type THealthAlertServiceFactoryDep = {
|
||||
queueService: TQueueServiceFactory;
|
||||
gatewayV2Service: Pick<TGatewayV2ServiceFactory, "healthcheckNotify">;
|
||||
relayService: Pick<TRelayServiceFactory, "healthcheckNotify">;
|
||||
};
|
||||
|
||||
export type THealthAlertServiceFactory = ReturnType<typeof healthAlertServiceFactory>;
|
||||
|
||||
export const healthAlertServiceFactory = ({
|
||||
queueService,
|
||||
gatewayV2Service,
|
||||
relayService
|
||||
}: THealthAlertServiceFactoryDep) => {
|
||||
const appCfg = getConfig();
|
||||
|
||||
const init = async () => {
|
||||
if (appCfg.isSecondaryInstance) {
|
||||
return;
|
||||
}
|
||||
|
||||
await queueService.stopRepeatableJob(
|
||||
QueueName.HealthAlert,
|
||||
QueueJobs.HealthAlert,
|
||||
{ pattern: "*/5 * * * *", utc: true },
|
||||
QueueName.HealthAlert // job id
|
||||
);
|
||||
|
||||
await queueService.startPg<QueueName.HealthAlert>(
|
||||
QueueJobs.HealthAlert,
|
||||
async () => {
|
||||
try {
|
||||
logger.info(`${QueueName.HealthAlert}: health check alert task started`);
|
||||
await gatewayV2Service.healthcheckNotify();
|
||||
await relayService.healthcheckNotify();
|
||||
logger.info(`${QueueName.HealthAlert}: health check alert task completed`);
|
||||
} catch (error) {
|
||||
logger.error(error, `${QueueName.HealthAlert}: health check alert failed`);
|
||||
throw error;
|
||||
}
|
||||
},
|
||||
{
|
||||
batchSize: 1,
|
||||
workerCount: 1,
|
||||
pollingIntervalSeconds: 60
|
||||
}
|
||||
);
|
||||
|
||||
await queueService.schedulePg(
|
||||
QueueJobs.HealthAlert,
|
||||
"*/5 * * * *", // Schedule to run every 5 minutes
|
||||
undefined,
|
||||
{ tz: "UTC" }
|
||||
);
|
||||
};
|
||||
|
||||
return {
|
||||
init
|
||||
};
|
||||
};
|
||||
@@ -1,4 +1,4 @@
|
||||
import { IdentityAuthMethod, TableName, TIdentityAccessTokens } from "@app/db/schemas";
|
||||
import { AccessScope, IdentityAuthMethod, TableName, TIdentityAccessTokens } from "@app/db/schemas";
|
||||
import { getConfig } from "@app/lib/config/env";
|
||||
import { crypto } from "@app/lib/crypto";
|
||||
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||
@@ -7,27 +7,27 @@ import { checkIPAgainstBlocklist, TIp } from "@app/lib/ip";
|
||||
import { TAccessTokenQueueServiceFactory } from "../access-token-queue/access-token-queue";
|
||||
import { AuthTokenType } from "../auth/auth-type";
|
||||
import { TIdentityDALFactory } from "../identity/identity-dal";
|
||||
import { TIdentityOrgDALFactory } from "../identity/identity-org-dal";
|
||||
import { TMembershipIdentityDALFactory } from "../membership-identity/membership-identity-dal";
|
||||
import { TIdentityAccessTokenDALFactory } from "./identity-access-token-dal";
|
||||
import { TIdentityAccessTokenJwtPayload, TRenewAccessTokenDTO } from "./identity-access-token-types";
|
||||
|
||||
type TIdentityAccessTokenServiceFactoryDep = {
|
||||
identityAccessTokenDAL: TIdentityAccessTokenDALFactory;
|
||||
identityDAL: Pick<TIdentityDALFactory, "getTrustedIpsByAuthMethod">;
|
||||
identityOrgMembershipDAL: TIdentityOrgDALFactory;
|
||||
accessTokenQueue: Pick<
|
||||
TAccessTokenQueueServiceFactory,
|
||||
"updateIdentityAccessTokenStatus" | "getIdentityTokenDetailsInCache"
|
||||
>;
|
||||
membershipIdentityDAL: Pick<TMembershipIdentityDALFactory, "findOne">;
|
||||
};
|
||||
|
||||
export type TIdentityAccessTokenServiceFactory = ReturnType<typeof identityAccessTokenServiceFactory>;
|
||||
|
||||
export const identityAccessTokenServiceFactory = ({
|
||||
identityAccessTokenDAL,
|
||||
identityOrgMembershipDAL,
|
||||
accessTokenQueue,
|
||||
identityDAL
|
||||
identityDAL,
|
||||
membershipIdentityDAL
|
||||
}: TIdentityAccessTokenServiceFactoryDep) => {
|
||||
const validateAccessTokenExp = async (identityAccessToken: TIdentityAccessTokens) => {
|
||||
const {
|
||||
@@ -202,8 +202,8 @@ export const identityAccessTokenServiceFactory = ({
|
||||
trustedIps: trustedIps as TIp[]
|
||||
});
|
||||
}
|
||||
|
||||
const identityOrgMembership = await identityOrgMembershipDAL.findOne({
|
||||
const identityOrgMembership = await membershipIdentityDAL.findOne({
|
||||
scope: AccessScope.Organization,
|
||||
actorIdentityId: identityAccessToken.identityId
|
||||
});
|
||||
|
||||
|
||||
@@ -742,23 +742,27 @@ export const kmsServiceFactory = ({
|
||||
if (!project.kmsSecretManagerEncryptedDataKey) {
|
||||
const lock = await keyStore
|
||||
.acquireLock([KeyStorePrefixes.KmsProjectDataKeyCreation, projectId], 3000, { retryCount: 0 })
|
||||
.catch(() => null);
|
||||
.catch((err) => {
|
||||
logger.error(err, "KMS. Failed to acquire lock.");
|
||||
return null;
|
||||
});
|
||||
|
||||
try {
|
||||
if (!lock) {
|
||||
await keyStore.waitTillReady({
|
||||
key: `${KeyStorePrefixes.WaitUntilReadyKmsProjectDataKeyCreation}${projectId}`,
|
||||
keyCheckCb: (val) => val === "true",
|
||||
waitingCb: () => logger.debug("KMS. Waiting for secret manager data key to be created"),
|
||||
waitingCb: () => logger.info("KMS. Waiting for secret manager data key to be created"),
|
||||
delay: 500
|
||||
});
|
||||
|
||||
project = await projectDAL.findById(projectId, trx);
|
||||
} else {
|
||||
logger.info(`KMS. Generating KMS key for project ${projectId}`);
|
||||
const projectDataKey = await (trx || projectDAL).transaction(async (tx) => {
|
||||
project = await projectDAL.findById(projectId, tx);
|
||||
if (project.kmsSecretManagerEncryptedDataKey) {
|
||||
return;
|
||||
return project.kmsSecretManagerEncryptedDataKey;
|
||||
}
|
||||
|
||||
const dataKey = crypto.randomBytes(32);
|
||||
|
||||
@@ -5,6 +5,7 @@ import {
|
||||
AccessScope,
|
||||
OrganizationsSchema,
|
||||
OrgMembershipRole,
|
||||
OrgMembershipStatus,
|
||||
TableName,
|
||||
TMemberships,
|
||||
TMembershipsInsert,
|
||||
@@ -346,6 +347,7 @@ export const orgDALFactory = (db: TDbClient) => {
|
||||
.replicaNode()(TableName.Membership)
|
||||
.where(`${TableName.Membership}.scopeOrgId`, orgId)
|
||||
.where(`${TableName.Membership}.scope`, AccessScope.Organization)
|
||||
.where(`${TableName.Membership}.status`, OrgMembershipStatus.Accepted)
|
||||
.whereNotNull(`${TableName.Membership}.actorUserId`)
|
||||
.count("*")
|
||||
.join(TableName.Users, `${TableName.Membership}.actorUserId`, `${TableName.Users}.id`)
|
||||
|
||||
@@ -258,10 +258,6 @@ export const fnSecretsV2FromImports = async ({
|
||||
})[];
|
||||
}[] = [{ secretImports: rootSecretImports, depth: 0, parentImportedSecrets: [] }];
|
||||
|
||||
const processedSecretImports = await processReservedImports(rootSecretImports, secretImportDAL);
|
||||
|
||||
stack[0] = { secretImports: processedSecretImports, depth: 0, parentImportedSecrets: [] };
|
||||
|
||||
const processedImports: TSecretImportSecretsV2[] = [];
|
||||
|
||||
while (stack.length) {
|
||||
@@ -299,7 +295,9 @@ export const fnSecretsV2FromImports = async ({
|
||||
);
|
||||
const importedSecretsGroupByFolderId = groupBy(importedSecrets, (i) => i.folderId);
|
||||
|
||||
sanitizedImports.forEach(({ importPath, importEnv }) => {
|
||||
const processedBatchImports = await processReservedImports(sanitizedImports, secretImportDAL);
|
||||
|
||||
processedBatchImports.forEach(({ importPath, importEnv }) => {
|
||||
cyclicDetector.add(getImportUniqKey(importEnv.slug, importPath));
|
||||
});
|
||||
// now we need to check recursively deeper imports made inside other imports
|
||||
@@ -308,7 +306,7 @@ export const fnSecretsV2FromImports = async ({
|
||||
const deeperImportsGroupByFolderId = groupBy(deeperImports, (i) => i.folderId);
|
||||
|
||||
const isFirstIteration = !processedImports.length;
|
||||
sanitizedImports.forEach(({ importPath, importEnv, id, folderId }, i) => {
|
||||
processedBatchImports.forEach(({ importPath, importEnv, id, folderId }, i) => {
|
||||
const sourceImportFolder = importedFolderGroupBySourceImport[`${importEnv.id}-${importPath}`]?.[0];
|
||||
const secretsWithDuplicate = (importedSecretsGroupByFolderId?.[importedFolders?.[i]?.id as string] || [])
|
||||
.filter((item) =>
|
||||
|
||||
@@ -0,0 +1,4 @@
|
||||
export * from "./laravel-forge-sync-constants";
|
||||
export * from "./laravel-forge-sync-fns";
|
||||
export * from "./laravel-forge-sync-schemas";
|
||||
export * from "./laravel-forge-sync-types";
|
||||
@@ -0,0 +1,10 @@
|
||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||
import { TSecretSyncListItem } from "@app/services/secret-sync/secret-sync-types";
|
||||
|
||||
export const LARAVEL_FORGE_SYNC_LIST_OPTION: TSecretSyncListItem = {
|
||||
name: "Laravel Forge",
|
||||
destination: SecretSync.LaravelForge,
|
||||
connection: AppConnection.LaravelForge,
|
||||
canImportSecrets: true
|
||||
};
|
||||
@@ -0,0 +1,207 @@
|
||||
import { request } from "@app/lib/config/request";
|
||||
import { IntegrationUrls } from "@app/services/integration-auth/integration-list";
|
||||
import { matchesSchema } from "@app/services/secret-sync/secret-sync-fns";
|
||||
import { TSecretMap } from "@app/services/secret-sync/secret-sync-types";
|
||||
|
||||
import {
|
||||
LaravelForgeSecret,
|
||||
TGetLaravelForgeSecrets,
|
||||
TLaravelForgeSecrets,
|
||||
TLaravelForgeSyncWithCredentials
|
||||
} from "./laravel-forge-sync-types";
|
||||
|
||||
const getLaravelForgeSecretsRaw = async ({ apiToken, orgSlug, serverId, siteId }: TGetLaravelForgeSecrets) => {
|
||||
const { data } = await request.get<TLaravelForgeSecrets>(
|
||||
`${IntegrationUrls.LARAVELFORGE_API_URL}/api/orgs/${orgSlug}/servers/${serverId}/sites/${siteId}/environment`,
|
||||
{
|
||||
headers: {
|
||||
Authorization: `Bearer ${apiToken}`,
|
||||
Accept: "application/json",
|
||||
"Content-Type": "application/json"
|
||||
}
|
||||
}
|
||||
);
|
||||
|
||||
return data.data.attributes.content;
|
||||
};
|
||||
|
||||
const parseEnv = (str: string) => {
|
||||
const lines = str.split("\n");
|
||||
const parsed: { key: string; value: string }[] = [];
|
||||
|
||||
let i = 0;
|
||||
while (i < lines.length) {
|
||||
const trimmed = lines[i].trim();
|
||||
|
||||
// Skip empty lines and comments
|
||||
if (trimmed === "" || trimmed.startsWith("#")) {
|
||||
i += 1;
|
||||
// eslint-disable-next-line no-continue
|
||||
continue;
|
||||
}
|
||||
|
||||
if (trimmed.includes("=")) {
|
||||
const equalIndex = trimmed.indexOf("=");
|
||||
const key = trimmed.substring(0, equalIndex).trim();
|
||||
const valueRaw = trimmed.substring(equalIndex + 1).trim();
|
||||
|
||||
// Check if value starts with a quote
|
||||
const startsWithDoubleQuote = valueRaw.startsWith('"');
|
||||
const startsWithSingleQuote = valueRaw.startsWith("'");
|
||||
|
||||
if (startsWithDoubleQuote || startsWithSingleQuote) {
|
||||
const quoteChar = startsWithDoubleQuote ? '"' : "'";
|
||||
|
||||
const closingQuoteIndex = valueRaw.indexOf(quoteChar, 1);
|
||||
|
||||
if (closingQuoteIndex !== -1) {
|
||||
// Single-line quoted value
|
||||
const value = valueRaw.slice(1, closingQuoteIndex);
|
||||
parsed.push({ key, value });
|
||||
i += 1;
|
||||
} else {
|
||||
// Multiline quoted value - collect lines until closing quote
|
||||
let value = valueRaw.slice(1);
|
||||
i += 1;
|
||||
|
||||
while (i < lines.length) {
|
||||
const nextLine = lines[i];
|
||||
const closingIndex = nextLine.indexOf(quoteChar);
|
||||
|
||||
if (closingIndex !== -1) {
|
||||
value += `\n${nextLine.substring(0, closingIndex)}`;
|
||||
parsed.push({ key, value });
|
||||
i += 1;
|
||||
break;
|
||||
} else {
|
||||
value += `\n${nextLine}`;
|
||||
i += 1;
|
||||
}
|
||||
}
|
||||
}
|
||||
} else {
|
||||
// Unquoted value
|
||||
parsed.push({ key, value: valueRaw });
|
||||
i += 1;
|
||||
}
|
||||
} else {
|
||||
i += 1;
|
||||
}
|
||||
}
|
||||
|
||||
return parsed;
|
||||
};
|
||||
|
||||
const getLaravelForgeSecrets = async (secretSync: TLaravelForgeSyncWithCredentials): Promise<LaravelForgeSecret[]> => {
|
||||
const {
|
||||
connection,
|
||||
destinationConfig: { orgSlug, serverId, siteId }
|
||||
} = secretSync;
|
||||
|
||||
const { apiToken } = connection.credentials;
|
||||
|
||||
const secrets = await getLaravelForgeSecretsRaw({ apiToken, orgSlug, serverId, siteId });
|
||||
|
||||
const parsedSecrets = parseEnv(secrets);
|
||||
|
||||
return parsedSecrets;
|
||||
};
|
||||
|
||||
const buildEnvString = (secrets: LaravelForgeSecret[]) => {
|
||||
if (secrets.length === 0) {
|
||||
return "# .env";
|
||||
}
|
||||
|
||||
return secrets
|
||||
.map((secret) => {
|
||||
const { value } = secret;
|
||||
|
||||
if (value.includes(`"`)) {
|
||||
return `${secret.key}='${value}'`;
|
||||
}
|
||||
|
||||
if (value.includes(" ") || value.includes("\n") || value.includes(`'`)) {
|
||||
return `${secret.key}="${value}"`;
|
||||
}
|
||||
return `${secret.key}=${value}`;
|
||||
})
|
||||
.join("\n");
|
||||
};
|
||||
|
||||
const updateLaravelForgeSecrets = async (secretSync: TLaravelForgeSyncWithCredentials, envString: string) => {
|
||||
const {
|
||||
connection,
|
||||
destinationConfig: { orgSlug, serverId, siteId }
|
||||
} = secretSync;
|
||||
|
||||
const { apiToken } = connection.credentials;
|
||||
|
||||
await request.put(
|
||||
`${IntegrationUrls.LARAVELFORGE_API_URL}/api/orgs/${orgSlug}/servers/${serverId}/sites/${siteId}/environment`,
|
||||
{
|
||||
environment: envString
|
||||
},
|
||||
|
||||
{
|
||||
headers: {
|
||||
Authorization: `Bearer ${apiToken}`,
|
||||
Accept: "application/json",
|
||||
"Content-Type": "application/json"
|
||||
}
|
||||
}
|
||||
);
|
||||
};
|
||||
|
||||
export const LaravelForgeSyncFns = {
|
||||
async syncSecrets(secretSync: TLaravelForgeSyncWithCredentials, secretMap: TSecretMap) {
|
||||
const {
|
||||
environment,
|
||||
syncOptions: { disableSecretDeletion, keySchema }
|
||||
} = secretSync;
|
||||
|
||||
const secrets = await getLaravelForgeSecrets(secretSync);
|
||||
|
||||
// Create a map of the existing secrets
|
||||
const updatedSecretsMap = new Map(secrets.map((secret) => [secret.key, secret.value]));
|
||||
|
||||
for (const [key, { value }] of Object.entries(secretMap)) {
|
||||
// Add the new secrets to the map
|
||||
updatedSecretsMap.set(key, value);
|
||||
}
|
||||
|
||||
if (!disableSecretDeletion) {
|
||||
secrets.forEach((secret) => {
|
||||
if (!matchesSchema(secret.key, environment?.slug || "", keySchema)) return;
|
||||
|
||||
if (!secretMap[secret.key]) {
|
||||
updatedSecretsMap.delete(secret.key);
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
const updatedSecrets = Array.from(updatedSecretsMap.entries()).map(([key, value]) => ({ key, value }));
|
||||
|
||||
const envString = buildEnvString(updatedSecrets);
|
||||
|
||||
await updateLaravelForgeSecrets(secretSync, envString);
|
||||
},
|
||||
|
||||
async getSecrets(secretSync: TLaravelForgeSyncWithCredentials): Promise<TSecretMap> {
|
||||
const secrets = await getLaravelForgeSecrets(secretSync);
|
||||
return Object.fromEntries(secrets.map((secret) => [secret.key, { value: secret.value }]));
|
||||
},
|
||||
|
||||
async removeSecrets(secretSync: TLaravelForgeSyncWithCredentials, secretMap: TSecretMap) {
|
||||
const existingSecrets = await getLaravelForgeSecrets(secretSync);
|
||||
|
||||
const newSecrets = existingSecrets.filter((secret) => !Object.hasOwn(secretMap, secret.key));
|
||||
|
||||
if (newSecrets.length === existingSecrets.length) {
|
||||
return;
|
||||
}
|
||||
|
||||
const envString = buildEnvString(newSecrets);
|
||||
|
||||
await updateLaravelForgeSecrets(secretSync, envString);
|
||||
}
|
||||
};
|
||||
@@ -0,0 +1,68 @@
|
||||
import RE2 from "re2";
|
||||
import { z } from "zod";
|
||||
|
||||
import { SecretSyncs } from "@app/lib/api-docs";
|
||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||
import { SecretSync } from "@app/services/secret-sync/secret-sync-enums";
|
||||
import {
|
||||
BaseSecretSyncSchema,
|
||||
GenericCreateSecretSyncFieldsSchema,
|
||||
GenericUpdateSecretSyncFieldsSchema
|
||||
} from "@app/services/secret-sync/secret-sync-schemas";
|
||||
import { TSyncOptionsConfig } from "@app/services/secret-sync/secret-sync-types";
|
||||
|
||||
const slugValidator = (val: string) => {
|
||||
return new RE2("^[a-z0-9.-]+$").test(val) && !new RE2(".[-]$").test(val);
|
||||
};
|
||||
|
||||
const LaravelForgeSyncDestinationConfigSchema = z.object({
|
||||
orgSlug: z
|
||||
.string()
|
||||
.min(1, "Org Slug is required")
|
||||
.max(512, "Org Slug cannot exceed 512 characters")
|
||||
.refine(
|
||||
(val) => slugValidator(val),
|
||||
"Org Slug can only contain lowercase letters, numbers, dots, and dashes, and cannot end with a dot or dash."
|
||||
)
|
||||
.describe(SecretSyncs.DESTINATION_CONFIG.LARAVEL_FORGE.orgSlug),
|
||||
orgName: z.string().optional().describe(SecretSyncs.DESTINATION_CONFIG.LARAVEL_FORGE.orgName),
|
||||
serverId: z
|
||||
.string()
|
||||
.min(1, "Server ID is required")
|
||||
.refine((val) => !Number.isNaN(Number(val)), "Server ID must be a valid integer")
|
||||
.describe(SecretSyncs.DESTINATION_CONFIG.LARAVEL_FORGE.serverId),
|
||||
serverName: z.string().optional().describe(SecretSyncs.DESTINATION_CONFIG.LARAVEL_FORGE.serverName),
|
||||
siteId: z.string().min(1, "Site ID is required").describe(SecretSyncs.DESTINATION_CONFIG.LARAVEL_FORGE.siteId),
|
||||
siteName: z.string().optional().describe(SecretSyncs.DESTINATION_CONFIG.LARAVEL_FORGE.siteName)
|
||||
});
|
||||
|
||||
const LaravelForgeSyncOptionsConfig: TSyncOptionsConfig = { canImportSecrets: true };
|
||||
|
||||
export const LaravelForgeSyncSchema = BaseSecretSyncSchema(
|
||||
SecretSync.LaravelForge,
|
||||
LaravelForgeSyncOptionsConfig
|
||||
).extend({
|
||||
destination: z.literal(SecretSync.LaravelForge),
|
||||
destinationConfig: LaravelForgeSyncDestinationConfigSchema
|
||||
});
|
||||
|
||||
export const CreateLaravelForgeSyncSchema = GenericCreateSecretSyncFieldsSchema(
|
||||
SecretSync.LaravelForge,
|
||||
LaravelForgeSyncOptionsConfig
|
||||
).extend({
|
||||
destinationConfig: LaravelForgeSyncDestinationConfigSchema
|
||||
});
|
||||
|
||||
export const UpdateLaravelForgeSyncSchema = GenericUpdateSecretSyncFieldsSchema(
|
||||
SecretSync.LaravelForge,
|
||||
LaravelForgeSyncOptionsConfig
|
||||
).extend({
|
||||
destinationConfig: LaravelForgeSyncDestinationConfigSchema.optional()
|
||||
});
|
||||
|
||||
export const LaravelForgeSyncListItemSchema = z.object({
|
||||
name: z.literal("Laravel Forge"),
|
||||
connection: z.literal(AppConnection.LaravelForge),
|
||||
destination: z.literal(SecretSync.LaravelForge),
|
||||
canImportSecrets: z.literal(true)
|
||||
});
|
||||
@@ -0,0 +1,41 @@
|
||||
import z from "zod";
|
||||
|
||||
import { TLaravelForgeConnection } from "@app/services/app-connection/laravel-forge";
|
||||
|
||||
import {
|
||||
CreateLaravelForgeSyncSchema,
|
||||
LaravelForgeSyncListItemSchema,
|
||||
LaravelForgeSyncSchema
|
||||
} from "./laravel-forge-sync-schemas";
|
||||
|
||||
export type TLaravelForgeSyncListItem = z.infer<typeof LaravelForgeSyncListItemSchema>;
|
||||
|
||||
export type TLaravelForgeSync = z.infer<typeof LaravelForgeSyncSchema>;
|
||||
|
||||
export type TLaravelForgeSyncInput = z.infer<typeof CreateLaravelForgeSyncSchema>;
|
||||
|
||||
export type TLaravelForgeSyncWithCredentials = TLaravelForgeSync & {
|
||||
connection: TLaravelForgeConnection;
|
||||
};
|
||||
|
||||
export type TGetLaravelForgeSecrets = {
|
||||
apiToken: string;
|
||||
orgSlug: string;
|
||||
serverId: string;
|
||||
siteId: string;
|
||||
};
|
||||
|
||||
export type TLaravelForgeSecrets = {
|
||||
data: {
|
||||
id: string;
|
||||
type: string;
|
||||
attributes: {
|
||||
content: string;
|
||||
};
|
||||
};
|
||||
};
|
||||
|
||||
export type LaravelForgeSecret = {
|
||||
key: string;
|
||||
value: string;
|
||||
};
|
||||
@@ -28,7 +28,8 @@ export enum SecretSync {
|
||||
Checkly = "checkly",
|
||||
DigitalOceanAppPlatform = "digital-ocean-app-platform",
|
||||
Netlify = "netlify",
|
||||
Bitbucket = "bitbucket"
|
||||
Bitbucket = "bitbucket",
|
||||
LaravelForge = "laravel-forge"
|
||||
}
|
||||
|
||||
export enum SecretSyncInitialSyncBehavior {
|
||||
|
||||
@@ -49,6 +49,8 @@ import { HC_VAULT_SYNC_LIST_OPTION, HCVaultSyncFns } from "./hc-vault";
|
||||
import { HEROKU_SYNC_LIST_OPTION, HerokuSyncFns } from "./heroku";
|
||||
import { HUMANITEC_SYNC_LIST_OPTION } from "./humanitec";
|
||||
import { HumanitecSyncFns } from "./humanitec/humanitec-sync-fns";
|
||||
import { LARAVEL_FORGE_SYNC_LIST_OPTION } from "./laravel-forge";
|
||||
import { LaravelForgeSyncFns } from "./laravel-forge/laravel-forge-sync-fns";
|
||||
import { NETLIFY_SYNC_LIST_OPTION, NetlifySyncFns } from "./netlify";
|
||||
import { RAILWAY_SYNC_LIST_OPTION } from "./railway/railway-sync-constants";
|
||||
import { RailwaySyncFns } from "./railway/railway-sync-fns";
|
||||
@@ -91,7 +93,8 @@ const SECRET_SYNC_LIST_OPTIONS: Record<SecretSync, TSecretSyncListItem> = {
|
||||
[SecretSync.Checkly]: CHECKLY_SYNC_LIST_OPTION,
|
||||
[SecretSync.DigitalOceanAppPlatform]: DIGITAL_OCEAN_APP_PLATFORM_SYNC_LIST_OPTION,
|
||||
[SecretSync.Netlify]: NETLIFY_SYNC_LIST_OPTION,
|
||||
[SecretSync.Bitbucket]: BITBUCKET_SYNC_LIST_OPTION
|
||||
[SecretSync.Bitbucket]: BITBUCKET_SYNC_LIST_OPTION,
|
||||
[SecretSync.LaravelForge]: LARAVEL_FORGE_SYNC_LIST_OPTION
|
||||
};
|
||||
|
||||
export const listSecretSyncOptions = () => {
|
||||
@@ -277,6 +280,8 @@ export const SecretSyncFns = {
|
||||
return NetlifySyncFns.syncSecrets(secretSync, schemaSecretMap);
|
||||
case SecretSync.Bitbucket:
|
||||
return BitbucketSyncFns.syncSecrets(secretSync, schemaSecretMap);
|
||||
case SecretSync.LaravelForge:
|
||||
return LaravelForgeSyncFns.syncSecrets(secretSync, schemaSecretMap);
|
||||
default:
|
||||
throw new Error(
|
||||
`Unhandled sync destination for sync secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||
@@ -393,6 +398,9 @@ export const SecretSyncFns = {
|
||||
case SecretSync.Bitbucket:
|
||||
secretMap = await BitbucketSyncFns.getSecrets(secretSync);
|
||||
break;
|
||||
case SecretSync.LaravelForge:
|
||||
secretMap = await LaravelForgeSyncFns.getSecrets(secretSync);
|
||||
break;
|
||||
default:
|
||||
throw new Error(
|
||||
`Unhandled sync destination for get secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||
@@ -486,6 +494,8 @@ export const SecretSyncFns = {
|
||||
return NetlifySyncFns.removeSecrets(secretSync, schemaSecretMap);
|
||||
case SecretSync.Bitbucket:
|
||||
return BitbucketSyncFns.removeSecrets(secretSync, schemaSecretMap);
|
||||
case SecretSync.LaravelForge:
|
||||
return LaravelForgeSyncFns.removeSecrets(secretSync, schemaSecretMap);
|
||||
default:
|
||||
throw new Error(
|
||||
`Unhandled sync destination for remove secrets fns: ${(secretSync as TSecretSyncWithCredentials).destination}`
|
||||
|
||||
@@ -32,7 +32,8 @@ export const SECRET_SYNC_NAME_MAP: Record<SecretSync, string> = {
|
||||
[SecretSync.Checkly]: "Checkly",
|
||||
[SecretSync.DigitalOceanAppPlatform]: "Digital Ocean App Platform",
|
||||
[SecretSync.Netlify]: "Netlify",
|
||||
[SecretSync.Bitbucket]: "Bitbucket"
|
||||
[SecretSync.Bitbucket]: "Bitbucket",
|
||||
[SecretSync.LaravelForge]: "Laravel Forge"
|
||||
};
|
||||
|
||||
export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
||||
@@ -65,7 +66,8 @@ export const SECRET_SYNC_CONNECTION_MAP: Record<SecretSync, AppConnection> = {
|
||||
[SecretSync.Checkly]: AppConnection.Checkly,
|
||||
[SecretSync.DigitalOceanAppPlatform]: AppConnection.DigitalOcean,
|
||||
[SecretSync.Netlify]: AppConnection.Netlify,
|
||||
[SecretSync.Bitbucket]: AppConnection.Bitbucket
|
||||
[SecretSync.Bitbucket]: AppConnection.Bitbucket,
|
||||
[SecretSync.LaravelForge]: AppConnection.LaravelForge
|
||||
};
|
||||
|
||||
export const SECRET_SYNC_PLAN_MAP: Record<SecretSync, SecretSyncPlanType> = {
|
||||
@@ -98,7 +100,8 @@ export const SECRET_SYNC_PLAN_MAP: Record<SecretSync, SecretSyncPlanType> = {
|
||||
[SecretSync.Checkly]: SecretSyncPlanType.Regular,
|
||||
[SecretSync.DigitalOceanAppPlatform]: SecretSyncPlanType.Regular,
|
||||
[SecretSync.Netlify]: SecretSyncPlanType.Regular,
|
||||
[SecretSync.Bitbucket]: SecretSyncPlanType.Regular
|
||||
[SecretSync.Bitbucket]: SecretSyncPlanType.Regular,
|
||||
[SecretSync.LaravelForge]: SecretSyncPlanType.Regular
|
||||
};
|
||||
|
||||
export const SECRET_SYNC_SKIP_FIELDS_MAP: Record<SecretSync, string[]> = {
|
||||
@@ -140,7 +143,8 @@ export const SECRET_SYNC_SKIP_FIELDS_MAP: Record<SecretSync, string[]> = {
|
||||
[SecretSync.Checkly]: ["groupName", "accountName"],
|
||||
[SecretSync.DigitalOceanAppPlatform]: ["appName"],
|
||||
[SecretSync.Netlify]: ["accountName", "siteName"],
|
||||
[SecretSync.Bitbucket]: []
|
||||
[SecretSync.Bitbucket]: [],
|
||||
[SecretSync.LaravelForge]: []
|
||||
};
|
||||
|
||||
const defaultDuplicateCheck: DestinationDuplicateCheckFn = () => true;
|
||||
@@ -199,5 +203,6 @@ export const DESTINATION_DUPLICATE_CHECK_MAP: Record<SecretSync, DestinationDupl
|
||||
[SecretSync.Checkly]: defaultDuplicateCheck,
|
||||
[SecretSync.DigitalOceanAppPlatform]: defaultDuplicateCheck,
|
||||
[SecretSync.Netlify]: defaultDuplicateCheck,
|
||||
[SecretSync.Bitbucket]: defaultDuplicateCheck
|
||||
[SecretSync.Bitbucket]: defaultDuplicateCheck,
|
||||
[SecretSync.LaravelForge]: defaultDuplicateCheck
|
||||
};
|
||||
|
||||
@@ -117,6 +117,12 @@ import {
|
||||
THumanitecSyncListItem,
|
||||
THumanitecSyncWithCredentials
|
||||
} from "./humanitec";
|
||||
import {
|
||||
TLaravelForgeSync,
|
||||
TLaravelForgeSyncInput,
|
||||
TLaravelForgeSyncListItem,
|
||||
TLaravelForgeSyncWithCredentials
|
||||
} from "./laravel-forge";
|
||||
import { TNetlifySync, TNetlifySyncInput, TNetlifySyncListItem, TNetlifySyncWithCredentials } from "./netlify";
|
||||
import {
|
||||
TRailwaySync,
|
||||
@@ -164,6 +170,7 @@ export type TSecretSync =
|
||||
| TTerraformCloudSync
|
||||
| TCamundaSync
|
||||
| TVercelSync
|
||||
| TLaravelForgeSync
|
||||
| TWindmillSync
|
||||
| THCVaultSync
|
||||
| TTeamCitySync
|
||||
@@ -212,7 +219,8 @@ export type TSecretSyncWithCredentials =
|
||||
| TSupabaseSyncWithCredentials
|
||||
| TDigitalOceanAppPlatformSyncWithCredentials
|
||||
| TNetlifySyncWithCredentials
|
||||
| TBitbucketSyncWithCredentials;
|
||||
| TBitbucketSyncWithCredentials
|
||||
| TLaravelForgeSyncWithCredentials;
|
||||
|
||||
export type TSecretSyncInput =
|
||||
| TAwsParameterStoreSyncInput
|
||||
@@ -244,7 +252,8 @@ export type TSecretSyncInput =
|
||||
| TSupabaseSyncInput
|
||||
| TDigitalOceanAppPlatformSyncInput
|
||||
| TNetlifySyncInput
|
||||
| TBitbucketSyncInput;
|
||||
| TBitbucketSyncInput
|
||||
| TLaravelForgeSyncInput;
|
||||
|
||||
export type TSecretSyncListItem =
|
||||
| TAwsParameterStoreSyncListItem
|
||||
@@ -259,6 +268,7 @@ export type TSecretSyncListItem =
|
||||
| TTerraformCloudSyncListItem
|
||||
| TCamundaSyncListItem
|
||||
| TVercelSyncListItem
|
||||
| TLaravelForgeSyncListItem
|
||||
| TWindmillSyncListItem
|
||||
| THCVaultSyncListItem
|
||||
| TTeamCitySyncListItem
|
||||
|
||||
Reference in New Issue
Block a user