mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-02 20:25:47 +00:00
add missing transactions
This commit is contained in:
@@ -31,8 +31,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const projectEncryptionRingBuffer =
|
const projectEncryptionRingBuffer =
|
||||||
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
const webhooks = await knex(TableName.Webhook)
|
||||||
const webhooks = await knex(TableName.Webhook)
|
|
||||||
.where({})
|
.where({})
|
||||||
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.Webhook}.envId`)
|
.join(TableName.Environment, `${TableName.Environment}.id`, `${TableName.Webhook}.envId`)
|
||||||
.select(
|
.select(
|
||||||
@@ -57,7 +56,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
projectKmsService = await kmsService.createCipherPairWithDataKey({
|
projectKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.SecretManager,
|
type: KmsDataKey.SecretManager,
|
||||||
projectId: el.projectId
|
projectId: el.projectId
|
||||||
});
|
}, knex);
|
||||||
projectEncryptionRingBuffer.push(el.projectId, projectKmsService);
|
projectEncryptionRingBuffer.push(el.projectId, projectKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -49,7 +49,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
projectKmsService = await kmsService.createCipherPairWithDataKey({
|
projectKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.SecretManager,
|
type: KmsDataKey.SecretManager,
|
||||||
projectId
|
projectId
|
||||||
});
|
}, knex);
|
||||||
projectEncryptionRingBuffer.push(projectId, projectKmsService);
|
projectEncryptionRingBuffer.push(projectId, projectKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -42,7 +42,7 @@ export async function up(knex: Knex): Promise<void> {
|
|||||||
projectKmsService = await kmsService.createCipherPairWithDataKey({
|
projectKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.SecretManager,
|
type: KmsDataKey.SecretManager,
|
||||||
projectId
|
projectId
|
||||||
});
|
}, knex);
|
||||||
projectEncryptionRingBuffer.push(projectId, projectKmsService);
|
projectEncryptionRingBuffer.push(projectId, projectKmsService);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -59,7 +59,6 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
|||||||
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
const { kmsService } = await getMigrationEncryptionServices({ envConfig, keyStore, db: knex });
|
||||||
const orgEncryptionRingBuffer =
|
const orgEncryptionRingBuffer =
|
||||||
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
createCircularCache<Awaited<ReturnType<(typeof kmsService)["createCipherPairWithDataKey"]>>>(25);
|
||||||
|
|
||||||
const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth)
|
const identityKubernetesConfigs = await knex(TableName.IdentityKubernetesAuth)
|
||||||
.join(
|
.join(
|
||||||
TableName.IdentityOrgMembership,
|
TableName.IdentityOrgMembership,
|
||||||
@@ -77,76 +76,76 @@ const reencryptIdentityK8sAuth = async (knex: Knex) => {
|
|||||||
)
|
)
|
||||||
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
.orderBy(`${TableName.OrgBot}.orgId` as "orgId");
|
||||||
|
|
||||||
const updatedIdentityKubernetesConfigs = await Promise.all(
|
const updatedIdentityKubernetesConfigs = [];
|
||||||
identityKubernetesConfigs.map(
|
|
||||||
async ({ encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el }) => {
|
|
||||||
let orgKmsService = orgEncryptionRingBuffer.getItem(orgId);
|
|
||||||
if (!orgKmsService) {
|
|
||||||
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
|
||||||
type: KmsDataKey.Organization,
|
|
||||||
orgId
|
|
||||||
});
|
|
||||||
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
|
||||||
}
|
|
||||||
const key = infisicalSymmetricDecrypt({
|
|
||||||
ciphertext: encryptedSymmetricKey,
|
|
||||||
iv: symmetricKeyIV,
|
|
||||||
tag: symmetricKeyTag,
|
|
||||||
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
|
||||||
});
|
|
||||||
|
|
||||||
const decryptedTokenReviewerJwt =
|
for (const { encryptedSymmetricKey, symmetricKeyKeyEncoding, symmetricKeyTag, symmetricKeyIV, orgId, ...el } of identityKubernetesConfigs) {
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
let orgKmsService = orgEncryptionRingBuffer.getItem(orgId);
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
|
if (!orgKmsService) {
|
||||||
? decryptSymmetric({
|
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
key,
|
type: KmsDataKey.Organization,
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
orgId
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
}, knex);
|
||||||
iv: el.tokenReviewerJwtIV,
|
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
tag: el.tokenReviewerJwtTag,
|
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
ciphertext: el.encryptedTokenReviewerJwt
|
|
||||||
})
|
|
||||||
: "";
|
|
||||||
|
|
||||||
const decryptedCertificate =
|
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
|
||||||
? decryptSymmetric({
|
|
||||||
key,
|
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
iv: el.caCertIV,
|
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
tag: el.caCertTag,
|
|
||||||
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
|
||||||
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
|
||||||
ciphertext: el.encryptedCaCert
|
|
||||||
})
|
|
||||||
: "";
|
|
||||||
|
|
||||||
const encryptedKubernetesTokenReviewerJwt = orgKmsService.encryptor({
|
|
||||||
plainText: Buffer.from(decryptedTokenReviewerJwt)
|
|
||||||
}).cipherTextBlob;
|
|
||||||
const encryptedKubernetesCaCertificate = orgKmsService.encryptor({
|
|
||||||
plainText: Buffer.from(decryptedCertificate)
|
|
||||||
}).cipherTextBlob;
|
|
||||||
|
|
||||||
return {
|
|
||||||
...el,
|
|
||||||
accessTokenTrustedIps: JSON.stringify(el.accessTokenTrustedIps),
|
|
||||||
encryptedKubernetesCaCertificate,
|
|
||||||
encryptedKubernetesTokenReviewerJwt
|
|
||||||
};
|
|
||||||
}
|
}
|
||||||
)
|
|
||||||
);
|
const key = infisicalSymmetricDecrypt({
|
||||||
|
ciphertext: encryptedSymmetricKey,
|
||||||
|
iv: symmetricKeyIV,
|
||||||
|
tag: symmetricKeyTag,
|
||||||
|
keyEncoding: symmetricKeyKeyEncoding as SecretKeyEncoding
|
||||||
|
});
|
||||||
|
|
||||||
|
const decryptedTokenReviewerJwt =
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
el.encryptedTokenReviewerJwt && el.tokenReviewerJwtIV && el.tokenReviewerJwtTag
|
||||||
|
? decryptSymmetric({
|
||||||
|
key,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
iv: el.tokenReviewerJwtIV,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
tag: el.tokenReviewerJwtTag,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
ciphertext: el.encryptedTokenReviewerJwt
|
||||||
|
})
|
||||||
|
: "";
|
||||||
|
|
||||||
|
const decryptedCertificate =
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
el.encryptedCaCert && el.caCertIV && el.caCertTag
|
||||||
|
? decryptSymmetric({
|
||||||
|
key,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
iv: el.caCertIV,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
tag: el.caCertTag,
|
||||||
|
// eslint-disable-next-line @typescript-eslint/ban-ts-comment
|
||||||
|
// @ts-ignore This will be removed in next cycle so ignore the ts missing error
|
||||||
|
ciphertext: el.encryptedCaCert
|
||||||
|
})
|
||||||
|
: "";
|
||||||
|
|
||||||
|
const encryptedKubernetesTokenReviewerJwt = orgKmsService.encryptor({
|
||||||
|
plainText: Buffer.from(decryptedTokenReviewerJwt)
|
||||||
|
}).cipherTextBlob;
|
||||||
|
const encryptedKubernetesCaCertificate = orgKmsService.encryptor({
|
||||||
|
plainText: Buffer.from(decryptedCertificate)
|
||||||
|
}).cipherTextBlob;
|
||||||
|
|
||||||
|
updatedIdentityKubernetesConfigs.push({
|
||||||
|
...el,
|
||||||
|
accessTokenTrustedIps: JSON.stringify(el.accessTokenTrustedIps),
|
||||||
|
encryptedKubernetesCaCertificate,
|
||||||
|
encryptedKubernetesTokenReviewerJwt
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
for (let i = 0; i < updatedIdentityKubernetesConfigs.length; i += BATCH_SIZE) {
|
for (let i = 0; i < updatedIdentityKubernetesConfigs.length; i += BATCH_SIZE) {
|
||||||
// eslint-disable-next-line no-await-in-loop
|
// eslint-disable-next-line no-await-in-loop
|
||||||
|
|||||||
@@ -65,7 +65,7 @@ const reencryptIdentityOidcAuth = async (knex: Knex) => {
|
|||||||
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.Organization,
|
type: KmsDataKey.Organization,
|
||||||
orgId
|
orgId
|
||||||
});
|
}, knex);
|
||||||
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
const key = infisicalSymmetricDecrypt({
|
const key = infisicalSymmetricDecrypt({
|
||||||
|
|||||||
@@ -52,7 +52,7 @@ const reencryptSamlConfig = async (knex: Knex) => {
|
|||||||
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.Organization,
|
type: KmsDataKey.Organization,
|
||||||
orgId: el.orgId
|
orgId: el.orgId
|
||||||
});
|
}, knex);
|
||||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
const key = infisicalSymmetricDecrypt({
|
const key = infisicalSymmetricDecrypt({
|
||||||
@@ -207,7 +207,7 @@ const reencryptLdapConfig = async (knex: Knex) => {
|
|||||||
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.Organization,
|
type: KmsDataKey.Organization,
|
||||||
orgId: el.orgId
|
orgId: el.orgId
|
||||||
});
|
}, knex);
|
||||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
const key = infisicalSymmetricDecrypt({
|
const key = infisicalSymmetricDecrypt({
|
||||||
@@ -356,7 +356,7 @@ const reencryptOidcConfig = async (knex: Knex) => {
|
|||||||
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
orgKmsService = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.Organization,
|
type: KmsDataKey.Organization,
|
||||||
orgId: el.orgId
|
orgId: el.orgId
|
||||||
});
|
}, knex);
|
||||||
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
orgEncryptionRingBuffer.push(el.orgId, orgKmsService);
|
||||||
}
|
}
|
||||||
const key = infisicalSymmetricDecrypt({
|
const key = infisicalSymmetricDecrypt({
|
||||||
|
|||||||
@@ -472,7 +472,8 @@ export const kmsServiceFactory = ({
|
|||||||
}
|
}
|
||||||
|
|
||||||
const kmsDecryptor = await decryptWithKmsKey({
|
const kmsDecryptor = await decryptWithKmsKey({
|
||||||
kmsId: kmsKeyId
|
kmsId: kmsKeyId,
|
||||||
|
tx: trx
|
||||||
});
|
});
|
||||||
|
|
||||||
return kmsDecryptor({
|
return kmsDecryptor({
|
||||||
|
|||||||
Reference in New Issue
Block a user