mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 06:28:11 +00:00
requested changes
This commit is contained in:
@@ -3,6 +3,7 @@ import { z } from "zod";
|
|||||||
import { IdentityKubernetesAuthsSchema } from "@app/db/schemas";
|
import { IdentityKubernetesAuthsSchema } from "@app/db/schemas";
|
||||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
import { ApiDocsTags, KUBERNETES_AUTH } from "@app/lib/api-docs";
|
import { ApiDocsTags, KUBERNETES_AUTH } from "@app/lib/api-docs";
|
||||||
|
import { CharacterType, characterValidator } from "@app/lib/validator/validate-string";
|
||||||
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
import { AuthMode } from "@app/services/auth/auth-type";
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
@@ -101,7 +102,24 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
|
|||||||
}),
|
}),
|
||||||
body: z
|
body: z
|
||||||
.object({
|
.object({
|
||||||
kubernetesHost: z.string().trim().min(1).describe(KUBERNETES_AUTH.ATTACH.kubernetesHost),
|
kubernetesHost: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1)
|
||||||
|
.describe(KUBERNETES_AUTH.ATTACH.kubernetesHost)
|
||||||
|
.refine(
|
||||||
|
(val) =>
|
||||||
|
characterValidator([
|
||||||
|
CharacterType.Alphabets,
|
||||||
|
CharacterType.Numbers,
|
||||||
|
CharacterType.Colon,
|
||||||
|
CharacterType.Period,
|
||||||
|
CharacterType.ForwardSlash
|
||||||
|
])(val),
|
||||||
|
{
|
||||||
|
message: "Kubernetes host must only contain alphabets, numbers, colons, periods, and forward slashes."
|
||||||
|
}
|
||||||
|
),
|
||||||
caCert: z.string().trim().default("").describe(KUBERNETES_AUTH.ATTACH.caCert),
|
caCert: z.string().trim().default("").describe(KUBERNETES_AUTH.ATTACH.caCert),
|
||||||
tokenReviewerJwt: z.string().trim().optional().describe(KUBERNETES_AUTH.ATTACH.tokenReviewerJwt),
|
tokenReviewerJwt: z.string().trim().optional().describe(KUBERNETES_AUTH.ATTACH.tokenReviewerJwt),
|
||||||
allowedNamespaces: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNamespaces), // TODO: validation
|
allowedNamespaces: z.string().describe(KUBERNETES_AUTH.ATTACH.allowedNamespaces), // TODO: validation
|
||||||
@@ -201,7 +219,28 @@ export const registerIdentityKubernetesRouter = async (server: FastifyZodProvide
|
|||||||
}),
|
}),
|
||||||
body: z
|
body: z
|
||||||
.object({
|
.object({
|
||||||
kubernetesHost: z.string().trim().min(1).optional().describe(KUBERNETES_AUTH.UPDATE.kubernetesHost),
|
kubernetesHost: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.min(1)
|
||||||
|
.optional()
|
||||||
|
.describe(KUBERNETES_AUTH.UPDATE.kubernetesHost)
|
||||||
|
.refine(
|
||||||
|
(val) => {
|
||||||
|
if (!val) return true;
|
||||||
|
|
||||||
|
return characterValidator([
|
||||||
|
CharacterType.Alphabets,
|
||||||
|
CharacterType.Numbers,
|
||||||
|
CharacterType.Colon,
|
||||||
|
CharacterType.Period,
|
||||||
|
CharacterType.ForwardSlash
|
||||||
|
])(val);
|
||||||
|
},
|
||||||
|
{
|
||||||
|
message: "Kubernetes host must only contain alphabets, numbers, colons, periods, and forward slashes."
|
||||||
|
}
|
||||||
|
),
|
||||||
caCert: z.string().trim().optional().describe(KUBERNETES_AUTH.UPDATE.caCert),
|
caCert: z.string().trim().optional().describe(KUBERNETES_AUTH.UPDATE.caCert),
|
||||||
tokenReviewerJwt: z.string().trim().nullable().optional().describe(KUBERNETES_AUTH.UPDATE.tokenReviewerJwt),
|
tokenReviewerJwt: z.string().trim().nullable().optional().describe(KUBERNETES_AUTH.UPDATE.tokenReviewerJwt),
|
||||||
allowedNamespaces: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNamespaces), // TODO: validation
|
allowedNamespaces: z.string().optional().describe(KUBERNETES_AUTH.UPDATE.allowedNamespaces), // TODO: validation
|
||||||
|
|||||||
@@ -158,14 +158,4 @@ Once authenticated, the Gateway establishes a secure connection with Infisical t
|
|||||||
To confirm your Gateway is working, check the deployment status by looking for the message **"Gateway started successfully"** in the Gateway logs. This indicates the Gateway is running properly. Next, verify its registration by opening your Infisical dashboard, navigating to **Organization Access Control**, and selecting the **Gateways** tab. Your newly deployed Gateway should appear in the list.
|
To confirm your Gateway is working, check the deployment status by looking for the message **"Gateway started successfully"** in the Gateway logs. This indicates the Gateway is running properly. Next, verify its registration by opening your Infisical dashboard, navigating to **Organization Access Control**, and selecting the **Gateways** tab. Your newly deployed Gateway should appear in the list.
|
||||||

|

|
||||||
</Step>
|
</Step>
|
||||||
|
|
||||||
<Step title="Link Gateway to Projects">
|
|
||||||
To enable Infisical features like dynamic secrets or secret rotation to access private resources through the Gateway, you need to link the Gateway to the relevant projects.
|
|
||||||
|
|
||||||
Start by accessing the **Gateway settings** then locate the Gateway in the list, click the options menu (**:**), and select **Edit Details**.
|
|
||||||

|
|
||||||
In the edit modal that appears, choose the projects you want the Gateway to access and click **Save** to confirm your selections.
|
|
||||||

|
|
||||||
Once added to a project, the Gateway becomes available for use by any feature that supports Gateways within that project.
|
|
||||||
</Step>
|
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|||||||
+1
-1
@@ -332,7 +332,7 @@ export const IdentityKubernetesAuthForm = ({
|
|||||||
className="w-full border border-mineshaft-500"
|
className="w-full border border-mineshaft-500"
|
||||||
dropdownContainerClassName="max-w-none"
|
dropdownContainerClassName="max-w-none"
|
||||||
isLoading={isGatewayLoading}
|
isLoading={isGatewayLoading}
|
||||||
placeholder="Select Gateway"
|
placeholder="Default: Internet Gateway"
|
||||||
position="popper"
|
position="popper"
|
||||||
>
|
>
|
||||||
<SelectItem
|
<SelectItem
|
||||||
|
|||||||
+11
@@ -4,6 +4,7 @@ import { z } from "zod";
|
|||||||
|
|
||||||
import { createNotification } from "@app/components/notifications";
|
import { createNotification } from "@app/components/notifications";
|
||||||
import { Button, FormControl, Input } from "@app/components/v2";
|
import { Button, FormControl, Input } from "@app/components/v2";
|
||||||
|
import { NoticeBannerV2 } from "@app/components/v2/NoticeBannerV2/NoticeBannerV2";
|
||||||
import { useUpdateGatewayById } from "@app/hooks/api";
|
import { useUpdateGatewayById } from "@app/hooks/api";
|
||||||
import { TGateway } from "@app/hooks/api/gateways/types";
|
import { TGateway } from "@app/hooks/api/gateways/types";
|
||||||
|
|
||||||
@@ -53,6 +54,16 @@ export const EditGatewayDetailsModal = ({ gatewayDetails, onClose }: Props) => {
|
|||||||
|
|
||||||
return (
|
return (
|
||||||
<form onSubmit={handleSubmit(onFormSubmit)}>
|
<form onSubmit={handleSubmit(onFormSubmit)}>
|
||||||
|
<NoticeBannerV2 className="mx-auto mb-4" title="Project Linking">
|
||||||
|
<p className="mt-1 text-xs text-mineshaft-300">
|
||||||
|
Since the 15th May 2025, all gateways are automatically available for use in all projects
|
||||||
|
and you no longer need to link them.
|
||||||
|
<br />
|
||||||
|
Organization members with the "Attach Gateways" permission can use gateways
|
||||||
|
anywhere within the organization.
|
||||||
|
</p>
|
||||||
|
</NoticeBannerV2>
|
||||||
|
|
||||||
<Controller
|
<Controller
|
||||||
control={control}
|
control={control}
|
||||||
name="name"
|
name="name"
|
||||||
|
|||||||
+10
-1
@@ -1,8 +1,10 @@
|
|||||||
|
import { useMemo } from "react";
|
||||||
import { faBan, faEye } from "@fortawesome/free-solid-svg-icons";
|
import { faBan, faEye } from "@fortawesome/free-solid-svg-icons";
|
||||||
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
import { FontAwesomeIcon } from "@fortawesome/react-fontawesome";
|
||||||
|
import { useQuery } from "@tanstack/react-query";
|
||||||
|
|
||||||
import { Badge, EmptyState, Spinner, Tooltip } from "@app/components/v2";
|
import { Badge, EmptyState, Spinner, Tooltip } from "@app/components/v2";
|
||||||
import { useGetIdentityKubernetesAuth } from "@app/hooks/api";
|
import { gatewaysQueryKeys, useGetIdentityKubernetesAuth } from "@app/hooks/api";
|
||||||
import { IdentityKubernetesAuthForm } from "@app/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityKubernetesAuthForm";
|
import { IdentityKubernetesAuthForm } from "@app/pages/organization/AccessManagementPage/components/OrgIdentityTab/components/IdentitySection/IdentityKubernetesAuthForm";
|
||||||
|
|
||||||
import { IdentityAuthFieldDisplay } from "./IdentityAuthFieldDisplay";
|
import { IdentityAuthFieldDisplay } from "./IdentityAuthFieldDisplay";
|
||||||
@@ -16,8 +18,14 @@ export const ViewIdentityKubernetesAuthContent = ({
|
|||||||
onDelete,
|
onDelete,
|
||||||
popUp
|
popUp
|
||||||
}: ViewAuthMethodProps) => {
|
}: ViewAuthMethodProps) => {
|
||||||
|
const { data: gateways } = useQuery(gatewaysQueryKeys.list());
|
||||||
|
|
||||||
const { data, isPending } = useGetIdentityKubernetesAuth(identityId);
|
const { data, isPending } = useGetIdentityKubernetesAuth(identityId);
|
||||||
|
|
||||||
|
const selectedGateway = useMemo(() => {
|
||||||
|
return gateways?.find((gateway) => gateway.id === data?.gatewayId) || null;
|
||||||
|
}, [gateways, data?.gatewayId]);
|
||||||
|
|
||||||
if (isPending) {
|
if (isPending) {
|
||||||
return (
|
return (
|
||||||
<div className="flex w-full items-center justify-center">
|
<div className="flex w-full items-center justify-center">
|
||||||
@@ -69,6 +77,7 @@ export const ViewIdentityKubernetesAuthContent = ({
|
|||||||
>
|
>
|
||||||
{data.kubernetesHost}
|
{data.kubernetesHost}
|
||||||
</IdentityAuthFieldDisplay>
|
</IdentityAuthFieldDisplay>
|
||||||
|
<IdentityAuthFieldDisplay label="Gateway">{selectedGateway?.name}</IdentityAuthFieldDisplay>
|
||||||
<IdentityAuthFieldDisplay className="col-span-2" label="Token Reviewer JWT">
|
<IdentityAuthFieldDisplay className="col-span-2" label="Token Reviewer JWT">
|
||||||
{data.tokenReviewerJwt ? (
|
{data.tokenReviewerJwt ? (
|
||||||
<Tooltip
|
<Tooltip
|
||||||
|
|||||||
+1
-1
@@ -329,7 +329,7 @@ export const SqlDatabaseInputForm = ({
|
|||||||
className="w-full border border-mineshaft-500"
|
className="w-full border border-mineshaft-500"
|
||||||
dropdownContainerClassName="max-w-none"
|
dropdownContainerClassName="max-w-none"
|
||||||
isLoading={isGatewaysLoading}
|
isLoading={isGatewaysLoading}
|
||||||
placeholder="Internet gateway"
|
placeholder="Default: Internet Gateway"
|
||||||
position="popper"
|
position="popper"
|
||||||
>
|
>
|
||||||
<SelectItem
|
<SelectItem
|
||||||
|
|||||||
+1
-1
@@ -281,7 +281,7 @@ export const EditDynamicSecretSqlProviderForm = ({
|
|||||||
className="w-full border border-mineshaft-500"
|
className="w-full border border-mineshaft-500"
|
||||||
dropdownContainerClassName="max-w-none"
|
dropdownContainerClassName="max-w-none"
|
||||||
isLoading={isGatewaysLoading}
|
isLoading={isGatewaysLoading}
|
||||||
placeholder="Internet Gateway"
|
placeholder="Default: Internet Gateway"
|
||||||
position="popper"
|
position="popper"
|
||||||
>
|
>
|
||||||
<SelectItem
|
<SelectItem
|
||||||
|
|||||||
Reference in New Issue
Block a user