feat: added option for choosing encryption method

This commit is contained in:
Daniel Hougaard
2024-11-11 21:45:05 +04:00
parent cfc0b2fb8d
commit a807f0cf6c
5 changed files with 109 additions and 54 deletions
+8
View File
@@ -1,6 +1,8 @@
import { Logger } from "pino";
import { z } from "zod";
import { RootKeyEncryptionStrategy } from "@app/services/kms/kms-types";
import { removeTrailingSlash } from "../fn";
import { zpStr } from "../zod";
@@ -165,6 +167,9 @@ const envSchema = z
WORKFLOW_SLACK_CLIENT_SECRET: zpStr(z.string().optional()),
ENABLE_MSSQL_SECRET_ROTATION_ENCRYPT: zodStrBool.default("true"),
// KMS ENCRYPTION
ROOT_KEY_ENCRYPTION_STRATEGY: z.nativeEnum(RootKeyEncryptionStrategy).default(RootKeyEncryptionStrategy.Basic),
// HSM
HSM_LIB_PATH: zpStr(
z
@@ -198,6 +203,9 @@ const envSchema = z
})
.transform((data) => ({
...data,
// ROOT_KEY_ENCRYPTION_STRATEGY: "HSM",
DB_READ_REPLICAS: data.DB_READ_REPLICAS
? databaseReadReplicaSchema.parse(JSON.parse(data.DB_READ_REPLICAS))
: undefined,