mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 00:27:30 +00:00
misc: updated to use new proxy action
This commit is contained in:
@@ -125,13 +125,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
// 2. Create a test role binding
|
// 2. Create a test role binding
|
||||||
@@ -166,13 +170,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
// 3. Request a token for the test service account
|
// 3. Request a token for the test service account
|
||||||
@@ -188,13 +196,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
// 4. Cleanup: delete role binding and service account
|
// 4. Cleanup: delete role binding and service account
|
||||||
@@ -205,25 +217,33 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
} else {
|
} else {
|
||||||
await axios.delete(`${baseUrl}/apis/rbac.authorization.k8s.io/v1/clusterrolebindings/${roleBindingName}`, {
|
await axios.delete(`${baseUrl}/apis/rbac.authorization.k8s.io/v1/clusterrolebindings/${roleBindingName}`, {
|
||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -231,12 +251,16 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
});
|
});
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
const cleanupInfo = `You may need to manually clean up the following resources in namespace "${namespace}": Service Account - ${serviceAccountName}, ${providerInputs.roleType === KubernetesRoleType.Role ? "Role" : "Cluster Role"} Binding - ${roleBindingName}.`;
|
const cleanupInfo = `You may need to manually clean up the following resources in namespace "${namespace}": Service Account - ${serviceAccountName}, ${providerInputs.roleType === KubernetesRoleType.Role ? "Role" : "Cluster Role"} Binding - ${roleBindingName}.`;
|
||||||
@@ -265,13 +289,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -381,13 +409,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
// 2. Create the role binding
|
// 2. Create the role binding
|
||||||
@@ -422,13 +454,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
// 3. Request a token for the service account
|
// 3. Request a token for the service account
|
||||||
@@ -444,13 +480,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
return { ...res.data, serviceAccountName };
|
return { ...res.data, serviceAccountName };
|
||||||
@@ -481,13 +521,17 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
return { ...res.data, serviceAccountName: providerInputs.serviceAccountName };
|
return { ...res.data, serviceAccountName: providerInputs.serviceAccountName };
|
||||||
@@ -581,25 +625,33 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
}
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
|
}
|
||||||
);
|
);
|
||||||
} else {
|
} else {
|
||||||
await axios.delete(`${baseUrl}/apis/rbac.authorization.k8s.io/v1/clusterrolebindings/${roleBindingName}`, {
|
await axios.delete(`${baseUrl}/apis/rbac.authorization.k8s.io/v1/clusterrolebindings/${roleBindingName}`, {
|
||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -608,12 +660,16 @@ export const KubernetesProvider = ({ gatewayService }: TKubernetesProviderDTO):
|
|||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
...(providerInputs.authMethod === KubernetesAuthMethod.Gateway
|
||||||
? { "x-infisical-action": GatewayHttpProxyActions.InjectGatewayK8sServiceAccountToken }
|
? { "x-infisical-action": GatewayHttpProxyActions.UseGatewayK8sServiceAccount }
|
||||||
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
: { Authorization: `Bearer ${providerInputs.clusterToken}` })
|
||||||
},
|
},
|
||||||
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
...(providerInputs.authMethod === KubernetesAuthMethod.Api
|
||||||
timeout: EXTERNAL_REQUEST_TIMEOUT,
|
? {
|
||||||
httpsAgent
|
httpsAgent
|
||||||
|
}
|
||||||
|
: {}),
|
||||||
|
signal: AbortSignal.timeout(EXTERNAL_REQUEST_TIMEOUT),
|
||||||
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
});
|
});
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user