mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 00:28:12 +00:00
feat: add support for custom ca in k8 operator
This commit is contained in:
@@ -149,6 +149,26 @@ type MangedKubeSecretConfig struct {
|
|||||||
CreationPolicy string `json:"creationPolicy"`
|
CreationPolicy string `json:"creationPolicy"`
|
||||||
}
|
}
|
||||||
|
|
||||||
|
type CaReference struct {
|
||||||
|
// The name of the Kubernetes Secret
|
||||||
|
// +kubebuilder:validation:Required
|
||||||
|
SecretName string `json:"secretName"`
|
||||||
|
|
||||||
|
// The namespace where the Kubernetes Secret is located
|
||||||
|
// +kubebuilder:validation:Required
|
||||||
|
SecretNamespace string `json:"secretNamespace"`
|
||||||
|
|
||||||
|
// +kubebuilder:validation:Required
|
||||||
|
// The name of the secret property with the CA certificate value
|
||||||
|
SecretKey string `json:"key"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type TLSConfig struct {
|
||||||
|
// Reference to secret containing CA cert
|
||||||
|
// +kubebuilder:validation:Optional
|
||||||
|
CaRef CaReference `json:"caRef,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
// InfisicalSecretSpec defines the desired state of InfisicalSecret
|
// InfisicalSecretSpec defines the desired state of InfisicalSecret
|
||||||
type InfisicalSecretSpec struct {
|
type InfisicalSecretSpec struct {
|
||||||
// +kubebuilder:validation:Optional
|
// +kubebuilder:validation:Optional
|
||||||
@@ -166,6 +186,9 @@ type InfisicalSecretSpec struct {
|
|||||||
// Infisical host to pull secrets from
|
// Infisical host to pull secrets from
|
||||||
// +kubebuilder:validation:Optional
|
// +kubebuilder:validation:Optional
|
||||||
HostAPI string `json:"hostAPI"`
|
HostAPI string `json:"hostAPI"`
|
||||||
|
|
||||||
|
// +kubebuilder:validation:Optional
|
||||||
|
TLS TLSConfig `json:"tls"`
|
||||||
}
|
}
|
||||||
|
|
||||||
// InfisicalSecretStatus defines the observed state of InfisicalSecret
|
// InfisicalSecretStatus defines the observed state of InfisicalSecret
|
||||||
|
|||||||
@@ -81,6 +81,21 @@ func (in *AzureAuthDetails) DeepCopy() *AzureAuthDetails {
|
|||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||||
|
func (in *CaReference) DeepCopyInto(out *CaReference) {
|
||||||
|
*out = *in
|
||||||
|
}
|
||||||
|
|
||||||
|
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new CaReference.
|
||||||
|
func (in *CaReference) DeepCopy() *CaReference {
|
||||||
|
if in == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
out := new(CaReference)
|
||||||
|
in.DeepCopyInto(out)
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||||
func (in *GCPIdTokenAuthDetails) DeepCopyInto(out *GCPIdTokenAuthDetails) {
|
func (in *GCPIdTokenAuthDetails) DeepCopyInto(out *GCPIdTokenAuthDetails) {
|
||||||
*out = *in
|
*out = *in
|
||||||
@@ -178,6 +193,7 @@ func (in *InfisicalSecretSpec) DeepCopyInto(out *InfisicalSecretSpec) {
|
|||||||
out.TokenSecretReference = in.TokenSecretReference
|
out.TokenSecretReference = in.TokenSecretReference
|
||||||
out.Authentication = in.Authentication
|
out.Authentication = in.Authentication
|
||||||
out.ManagedSecretReference = in.ManagedSecretReference
|
out.ManagedSecretReference = in.ManagedSecretReference
|
||||||
|
out.TLS = in.TLS
|
||||||
}
|
}
|
||||||
|
|
||||||
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InfisicalSecretSpec.
|
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new InfisicalSecretSpec.
|
||||||
@@ -337,6 +353,22 @@ func (in *ServiceTokenDetails) DeepCopy() *ServiceTokenDetails {
|
|||||||
return out
|
return out
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||||
|
func (in *TLSConfig) DeepCopyInto(out *TLSConfig) {
|
||||||
|
*out = *in
|
||||||
|
out.CaRef = in.CaRef
|
||||||
|
}
|
||||||
|
|
||||||
|
// DeepCopy is an autogenerated deepcopy function, copying the receiver, creating a new TLSConfig.
|
||||||
|
func (in *TLSConfig) DeepCopy() *TLSConfig {
|
||||||
|
if in == nil {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
out := new(TLSConfig)
|
||||||
|
in.DeepCopyInto(out)
|
||||||
|
return out
|
||||||
|
}
|
||||||
|
|
||||||
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
// DeepCopyInto is an autogenerated deepcopy function, copying the receiver, writing into out. in must be non-nil.
|
||||||
func (in *UniversalAuthDetails) DeepCopyInto(out *UniversalAuthDetails) {
|
func (in *UniversalAuthDetails) DeepCopyInto(out *UniversalAuthDetails) {
|
||||||
*out = *in
|
*out = *in
|
||||||
|
|||||||
@@ -290,6 +290,28 @@ spec:
|
|||||||
resyncInterval:
|
resyncInterval:
|
||||||
default: 60
|
default: 60
|
||||||
type: integer
|
type: integer
|
||||||
|
tls:
|
||||||
|
properties:
|
||||||
|
caRef:
|
||||||
|
description: Reference to secret containing CA cert
|
||||||
|
properties:
|
||||||
|
key:
|
||||||
|
description: The name of the secret property with the CA certificate
|
||||||
|
value
|
||||||
|
type: string
|
||||||
|
secretName:
|
||||||
|
description: The name of the Kubernetes Secret
|
||||||
|
type: string
|
||||||
|
secretNamespace:
|
||||||
|
description: The namespace where the Kubernetes Secret is
|
||||||
|
located
|
||||||
|
type: string
|
||||||
|
required:
|
||||||
|
- key
|
||||||
|
- secretName
|
||||||
|
- secretNamespace
|
||||||
|
type: object
|
||||||
|
type: object
|
||||||
tokenSecretReference:
|
tokenSecretReference:
|
||||||
properties:
|
properties:
|
||||||
secretName:
|
secretName:
|
||||||
|
|||||||
@@ -107,6 +107,18 @@ func (r *InfisicalSecretReconciler) Reconcile(ctx context.Context, req ctrl.Requ
|
|||||||
api.API_HOST_URL = infisicalSecretCR.Spec.HostAPI
|
api.API_HOST_URL = infisicalSecretCR.Spec.HostAPI
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if infisicalSecretCR.Spec.TLS.CaRef.SecretName != "" {
|
||||||
|
api.API_CA_CERTIFICATE, err = r.GetInfisicalCaCertificateFromKubeSecret(ctx, infisicalSecretCR)
|
||||||
|
if err != nil {
|
||||||
|
fmt.Printf("unable to fetch CA certificate [err=%s]. Will requeue after [requeueTime=%v]\n", err, requeueTime)
|
||||||
|
return ctrl.Result{
|
||||||
|
RequeueAfter: requeueTime,
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
fmt.Println("Using custom CA certificate...")
|
||||||
|
}
|
||||||
|
|
||||||
err = r.ReconcileInfisicalSecret(ctx, infisicalSecretCR)
|
err = r.ReconcileInfisicalSecret(ctx, infisicalSecretCR)
|
||||||
r.SetReadyToSyncSecretsConditions(ctx, &infisicalSecretCR, err)
|
r.SetReadyToSyncSecretsConditions(ctx, &infisicalSecretCR, err)
|
||||||
|
|
||||||
|
|||||||
@@ -177,6 +177,27 @@ func (r *InfisicalSecretReconciler) GetInfisicalUniversalAuthFromKubeSecret(ctx
|
|||||||
|
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func (r *InfisicalSecretReconciler) GetInfisicalCaCertificateFromKubeSecret(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret) (caCertificate string, err error) {
|
||||||
|
|
||||||
|
caCertificateFromKubeSecret, err := r.GetKubeSecretByNamespacedName(ctx, types.NamespacedName{
|
||||||
|
Namespace: infisicalSecret.Spec.TLS.CaRef.SecretNamespace,
|
||||||
|
Name: infisicalSecret.Spec.TLS.CaRef.SecretName,
|
||||||
|
})
|
||||||
|
|
||||||
|
if k8Errors.IsNotFound(err) {
|
||||||
|
return "", fmt.Errorf("kubernetes secret containing custom CA certificate cannot be found. [err=%s]", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
return "", fmt.Errorf("something went wrong when fetching your CA certificate [err=%s]", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
caCertificateFromSecret := string(caCertificateFromKubeSecret.Data[infisicalSecret.Spec.TLS.CaRef.SecretKey])
|
||||||
|
|
||||||
|
return caCertificateFromSecret, nil
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
// Fetches service account credentials from a Kubernetes secret specified in the infisicalSecret object, extracts the access key, public key, and private key from the secret, and returns them as a ServiceAccountCredentials object.
|
// Fetches service account credentials from a Kubernetes secret specified in the infisicalSecret object, extracts the access key, public key, and private key from the secret, and returns them as a ServiceAccountCredentials object.
|
||||||
// If any keys are missing or an error occurs, returns an empty object or an error object, respectively.
|
// If any keys are missing or an error occurs, returns an empty object or an error object, respectively.
|
||||||
func (r *InfisicalSecretReconciler) GetInfisicalServiceAccountCredentialsFromKubeSecret(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret) (serviceAccountDetails model.ServiceAccountDetails, err error) {
|
func (r *InfisicalSecretReconciler) GetInfisicalServiceAccountCredentialsFromKubeSecret(ctx context.Context, infisicalSecret v1alpha1.InfisicalSecret) (serviceAccountDetails model.ServiceAccountDetails, err error) {
|
||||||
@@ -296,8 +317,9 @@ func (r *InfisicalSecretReconciler) GetResourceVariables(infisicalSecret v1alpha
|
|||||||
ctx, cancel := context.WithCancel(context.Background())
|
ctx, cancel := context.WithCancel(context.Background())
|
||||||
|
|
||||||
client := infisicalSdk.NewInfisicalClient(ctx, infisicalSdk.Config{
|
client := infisicalSdk.NewInfisicalClient(ctx, infisicalSdk.Config{
|
||||||
SiteUrl: api.API_HOST_URL,
|
SiteUrl: api.API_HOST_URL,
|
||||||
UserAgent: api.USER_AGENT_NAME,
|
CaCertificate: api.API_CA_CERTIFICATE,
|
||||||
|
UserAgent: api.USER_AGENT_NAME,
|
||||||
})
|
})
|
||||||
|
|
||||||
resourceVariablesMap[string(infisicalSecret.UID)] = ResourceVariables{
|
resourceVariablesMap[string(infisicalSecret.UID)] = ResourceVariables{
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
package api
|
package api
|
||||||
|
|
||||||
var API_HOST_URL string = "https://app.infisical.com/api"
|
var API_HOST_URL string = "https://app.infisical.com/api"
|
||||||
|
var API_CA_CERTIFICATE string = ""
|
||||||
|
|||||||
Reference in New Issue
Block a user