mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 16:28:40 +00:00
feat: add AWS IAM resource support with console access functionality
- Introduced AWS IAM resource type in the system, allowing users to create and manage AWS IAM accounts. - Implemented AWS IAM resource forms and account forms for creating and updating IAM resources and accounts. - Added functionality to generate AWS Console URLs for IAM accounts, enabling direct access to the AWS Console. - Updated various components and hooks to handle AWS IAM-specific logic, including session expiration and access management. - Enhanced the UI to reflect AWS IAM integration, including new modals and forms for user interaction.
This commit is contained in:
@@ -0,0 +1,111 @@
|
||||
import { BadRequestError } from "@app/lib/errors";
|
||||
import { logger } from "@app/lib/logger";
|
||||
|
||||
import { PamResource } from "../pam-resource-enums";
|
||||
import {
|
||||
TPamResourceFactory,
|
||||
TPamResourceFactoryRotateAccountCredentials,
|
||||
TPamResourceFactoryValidateAccountCredentials
|
||||
} from "../pam-resource-types";
|
||||
import { validatePamRoleConnection, validateTargetRoleAssumption } from "./aws-iam-federation";
|
||||
import { TAwsIamAccountCredentials, TAwsIamResourceConnectionDetails } from "./aws-iam-resource-types";
|
||||
|
||||
export const awsIamResourceFactory: TPamResourceFactory<TAwsIamResourceConnectionDetails, TAwsIamAccountCredentials> = (
|
||||
resourceType: PamResource,
|
||||
connectionDetails: TAwsIamResourceConnectionDetails,
|
||||
// AWS IAM doesn't use gateway
|
||||
// eslint-disable-next-line @typescript-eslint/no-unused-vars
|
||||
_gatewayId,
|
||||
// eslint-disable-next-line @typescript-eslint/no-unused-vars
|
||||
_gatewayV2Service,
|
||||
projectId
|
||||
) => {
|
||||
const validateConnection = async () => {
|
||||
try {
|
||||
const isValid = await validatePamRoleConnection(connectionDetails, projectId ?? "");
|
||||
|
||||
if (!isValid) {
|
||||
throw new BadRequestError({
|
||||
message:
|
||||
"Unable to assume the PAM role. Verify the role ARN and ensure the trust policy allows Infisical to assume the role."
|
||||
});
|
||||
}
|
||||
|
||||
logger.info(
|
||||
{ roleArn: connectionDetails.roleArn, region: connectionDetails.region },
|
||||
"[AWS IAM Resource Factory] PAM role connection validated successfully"
|
||||
);
|
||||
|
||||
return connectionDetails;
|
||||
} catch (error) {
|
||||
if (error instanceof BadRequestError) {
|
||||
throw error;
|
||||
}
|
||||
|
||||
logger.error(error, "[AWS IAM Resource Factory] Failed to validate PAM role connection");
|
||||
|
||||
throw new BadRequestError({
|
||||
message: `Unable to validate connection to ${resourceType}: ${(error as Error).message || String(error)}`
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
const validateAccountCredentials: TPamResourceFactoryValidateAccountCredentials<TAwsIamAccountCredentials> = async (
|
||||
credentials
|
||||
) => {
|
||||
try {
|
||||
const isValid = await validateTargetRoleAssumption({
|
||||
connectionDetails,
|
||||
targetRoleArn: credentials.targetRoleArn,
|
||||
projectId: projectId ?? ""
|
||||
});
|
||||
|
||||
if (!isValid) {
|
||||
throw new BadRequestError({
|
||||
message:
|
||||
"Unable to assume the target role. Verify the target role ARN and ensure the PAM role has permission to assume it."
|
||||
});
|
||||
}
|
||||
|
||||
logger.info(
|
||||
{ targetRoleArn: credentials.targetRoleArn },
|
||||
"[AWS IAM Resource Factory] Target role credentials validated successfully"
|
||||
);
|
||||
|
||||
return credentials;
|
||||
} catch (error) {
|
||||
if (error instanceof BadRequestError) {
|
||||
throw error;
|
||||
}
|
||||
|
||||
logger.error(error, "[AWS IAM Resource Factory] Failed to validate target role credentials");
|
||||
|
||||
throw new BadRequestError({
|
||||
message: `Unable to validate account credentials for ${resourceType}: ${(error as Error).message || String(error)}`
|
||||
});
|
||||
}
|
||||
};
|
||||
|
||||
const rotateAccountCredentials: TPamResourceFactoryRotateAccountCredentials<TAwsIamAccountCredentials> = async (
|
||||
_rotationAccountCredentials,
|
||||
currentCredentials
|
||||
) => {
|
||||
return currentCredentials;
|
||||
};
|
||||
|
||||
const handleOverwritePreventionForCensoredValues = async (
|
||||
updatedAccountCredentials: TAwsIamAccountCredentials,
|
||||
// AWS IAM has no censored credential values - role ARNs are not secrets
|
||||
// eslint-disable-next-line @typescript-eslint/no-unused-vars
|
||||
_currentCredentials: TAwsIamAccountCredentials
|
||||
) => {
|
||||
return updatedAccountCredentials;
|
||||
};
|
||||
|
||||
return {
|
||||
validateConnection,
|
||||
validateAccountCredentials,
|
||||
rotateAccountCredentials,
|
||||
handleOverwritePreventionForCensoredValues
|
||||
};
|
||||
};
|
||||
Reference in New Issue
Block a user