mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
misc: updated proxy terminology to relay
This commit is contained in:
4
backend/src/@types/fastify.d.ts
vendored
4
backend/src/@types/fastify.d.ts
vendored
@@ -32,8 +32,8 @@ import { TPermissionServiceFactory } from "@app/ee/services/permission/permissio
|
||||
import { TPitServiceFactory } from "@app/ee/services/pit/pit-service";
|
||||
import { TProjectTemplateServiceFactory } from "@app/ee/services/project-template/project-template-types";
|
||||
import { TProjectUserAdditionalPrivilegeServiceFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-types";
|
||||
import { TProxyServiceFactory } from "@app/ee/services/proxy/proxy-service";
|
||||
import { RateLimitConfiguration, TRateLimitServiceFactory } from "@app/ee/services/rate-limit/rate-limit-types";
|
||||
import { TRelayServiceFactory } from "@app/ee/services/relay/relay-service";
|
||||
import { TSamlConfigServiceFactory } from "@app/ee/services/saml-config/saml-config-types";
|
||||
import { TScimServiceFactory } from "@app/ee/services/scim/scim-types";
|
||||
import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service";
|
||||
@@ -305,7 +305,7 @@ declare module "fastify" {
|
||||
bus: TEventBusService;
|
||||
sse: TServerSentEventsService;
|
||||
identityAuthTemplate: TIdentityAuthTemplateServiceFactory;
|
||||
proxy: TProxyServiceFactory;
|
||||
relay: TRelayServiceFactory;
|
||||
gatewayV2: TGatewayV2ServiceFactory;
|
||||
};
|
||||
// this is exclusive use for middlewares in which we need to inject data
|
||||
|
||||
40
backend/src/@types/knex.d.ts
vendored
40
backend/src/@types/knex.d.ts
vendored
@@ -182,9 +182,9 @@ import {
|
||||
TIncidentContacts,
|
||||
TIncidentContactsInsert,
|
||||
TIncidentContactsUpdate,
|
||||
TInstanceProxyConfig,
|
||||
TInstanceProxyConfigInsert,
|
||||
TInstanceProxyConfigUpdate,
|
||||
TInstanceRelayConfig,
|
||||
TInstanceRelayConfigInsert,
|
||||
TInstanceRelayConfigUpdate,
|
||||
TIntegrationAuths,
|
||||
TIntegrationAuthsInsert,
|
||||
TIntegrationAuthsUpdate,
|
||||
@@ -242,9 +242,9 @@ import {
|
||||
TOrgMemberships,
|
||||
TOrgMembershipsInsert,
|
||||
TOrgMembershipsUpdate,
|
||||
TOrgProxyConfig,
|
||||
TOrgProxyConfigInsert,
|
||||
TOrgProxyConfigUpdate,
|
||||
TOrgRelayConfig,
|
||||
TOrgRelayConfigInsert,
|
||||
TOrgRelayConfigUpdate,
|
||||
TOrgRoles,
|
||||
TOrgRolesInsert,
|
||||
TOrgRolesUpdate,
|
||||
@@ -299,12 +299,12 @@ import {
|
||||
TProjectUserMembershipRoles,
|
||||
TProjectUserMembershipRolesInsert,
|
||||
TProjectUserMembershipRolesUpdate,
|
||||
TProxies,
|
||||
TProxiesInsert,
|
||||
TProxiesUpdate,
|
||||
TRateLimit,
|
||||
TRateLimitInsert,
|
||||
TRateLimitUpdate,
|
||||
TRelays,
|
||||
TRelaysInsert,
|
||||
TRelaysUpdate,
|
||||
TResourceMetadata,
|
||||
TResourceMetadataInsert,
|
||||
TResourceMetadataUpdate,
|
||||
@@ -1269,22 +1269,22 @@ declare module "knex/types/tables" {
|
||||
TRemindersRecipientsInsert,
|
||||
TRemindersRecipientsUpdate
|
||||
>;
|
||||
[TableName.InstanceProxyConfig]: KnexOriginal.CompositeTableType<
|
||||
TInstanceProxyConfig,
|
||||
TInstanceProxyConfigInsert,
|
||||
TInstanceProxyConfigUpdate
|
||||
>;
|
||||
[TableName.OrgProxyConfig]: KnexOriginal.CompositeTableType<
|
||||
TOrgProxyConfig,
|
||||
TOrgProxyConfigInsert,
|
||||
TOrgProxyConfigUpdate
|
||||
>;
|
||||
[TableName.OrgGatewayConfigV2]: KnexOriginal.CompositeTableType<
|
||||
TOrgGatewayConfigV2,
|
||||
TOrgGatewayConfigV2Insert,
|
||||
TOrgGatewayConfigV2Update
|
||||
>;
|
||||
[TableName.Proxy]: KnexOriginal.CompositeTableType<TProxies, TProxiesInsert, TProxiesUpdate>;
|
||||
[TableName.GatewayV2]: KnexOriginal.CompositeTableType<TGatewaysV2, TGatewaysV2Insert, TGatewaysV2Update>;
|
||||
[TableName.InstanceRelayConfig]: KnexOriginal.CompositeTableType<
|
||||
TInstanceRelayConfig,
|
||||
TInstanceRelayConfigInsert,
|
||||
TInstanceRelayConfigUpdate
|
||||
>;
|
||||
[TableName.OrgRelayConfig]: KnexOriginal.CompositeTableType<
|
||||
TOrgRelayConfig,
|
||||
TOrgRelayConfigInsert,
|
||||
TOrgRelayConfigUpdate
|
||||
>;
|
||||
[TableName.Relay]: KnexOriginal.CompositeTableType<TRelays, TRelaysInsert, TRelaysUpdate>;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -4,68 +4,68 @@ import { TableName } from "../schemas";
|
||||
import { createOnUpdateTrigger, dropOnUpdateTrigger } from "../utils";
|
||||
|
||||
export async function up(knex: Knex): Promise<void> {
|
||||
if (!(await knex.schema.hasTable(TableName.InstanceProxyConfig))) {
|
||||
await knex.schema.createTable(TableName.InstanceProxyConfig, (t) => {
|
||||
if (!(await knex.schema.hasTable(TableName.InstanceRelayConfig))) {
|
||||
await knex.schema.createTable(TableName.InstanceRelayConfig, (t) => {
|
||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||
t.timestamps(true, true, true);
|
||||
|
||||
// Root CA for proxy PKI
|
||||
t.binary("encryptedRootProxyPkiCaPrivateKey").notNullable();
|
||||
t.binary("encryptedRootProxyPkiCaCertificate").notNullable();
|
||||
// Root CA for relay PKI
|
||||
t.binary("encryptedRootRelayPkiCaPrivateKey").notNullable();
|
||||
t.binary("encryptedRootRelayPkiCaCertificate").notNullable();
|
||||
|
||||
// Instance CA for proxy PKI
|
||||
t.binary("encryptedInstanceProxyPkiCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiCaCertificate").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiCaCertificateChain").notNullable();
|
||||
// Instance CA for relay PKI
|
||||
t.binary("encryptedInstanceRelayPkiCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiCaCertificate").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiCaCertificateChain").notNullable();
|
||||
|
||||
// Instance client/server intermediates for proxy PKI
|
||||
t.binary("encryptedInstanceProxyPkiClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiClientCaCertificate").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiClientCaCertificateChain").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiServerCaCertificate").notNullable();
|
||||
t.binary("encryptedInstanceProxyPkiServerCaCertificateChain").notNullable();
|
||||
// Instance client/server intermediates for relay PKI
|
||||
t.binary("encryptedInstanceRelayPkiClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiClientCaCertificate").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiClientCaCertificateChain").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiServerCaCertificate").notNullable();
|
||||
t.binary("encryptedInstanceRelayPkiServerCaCertificateChain").notNullable();
|
||||
|
||||
// Org Parent CAs for proxy
|
||||
t.binary("encryptedOrgProxyPkiCaPrivateKey").notNullable();
|
||||
t.binary("encryptedOrgProxyPkiCaCertificate").notNullable();
|
||||
t.binary("encryptedOrgProxyPkiCaCertificateChain").notNullable();
|
||||
// Org Parent CAs for relay
|
||||
t.binary("encryptedOrgRelayPkiCaPrivateKey").notNullable();
|
||||
t.binary("encryptedOrgRelayPkiCaCertificate").notNullable();
|
||||
t.binary("encryptedOrgRelayPkiCaCertificateChain").notNullable();
|
||||
|
||||
// Instance SSH CAs for proxy
|
||||
t.binary("encryptedInstanceProxySshClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceProxySshClientCaPublicKey").notNullable();
|
||||
t.binary("encryptedInstanceProxySshServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceProxySshServerCaPublicKey").notNullable();
|
||||
// Instance SSH CAs for relay
|
||||
t.binary("encryptedInstanceRelaySshClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceRelaySshClientCaPublicKey").notNullable();
|
||||
t.binary("encryptedInstanceRelaySshServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedInstanceRelaySshServerCaPublicKey").notNullable();
|
||||
});
|
||||
|
||||
await createOnUpdateTrigger(knex, TableName.InstanceProxyConfig);
|
||||
await createOnUpdateTrigger(knex, TableName.InstanceRelayConfig);
|
||||
}
|
||||
|
||||
// Org-level proxy configuration (one-to-one with organization)
|
||||
if (!(await knex.schema.hasTable(TableName.OrgProxyConfig))) {
|
||||
await knex.schema.createTable(TableName.OrgProxyConfig, (t) => {
|
||||
// Org-level relay configuration (one-to-one with organization)
|
||||
if (!(await knex.schema.hasTable(TableName.OrgRelayConfig))) {
|
||||
await knex.schema.createTable(TableName.OrgRelayConfig, (t) => {
|
||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||
t.timestamps(true, true, true);
|
||||
|
||||
t.uuid("orgId").notNullable().unique();
|
||||
t.foreign("orgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
|
||||
|
||||
// Org-scoped proxy PKI (client + server)
|
||||
t.binary("encryptedProxyPkiClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedProxyPkiClientCaCertificate").notNullable();
|
||||
t.binary("encryptedProxyPkiClientCaCertificateChain").notNullable();
|
||||
t.binary("encryptedProxyPkiServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedProxyPkiServerCaCertificate").notNullable();
|
||||
t.binary("encryptedProxyPkiServerCaCertificateChain").notNullable();
|
||||
// Org-scoped relay PKI (client + server)
|
||||
t.binary("encryptedRelayPkiClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedRelayPkiClientCaCertificate").notNullable();
|
||||
t.binary("encryptedRelayPkiClientCaCertificateChain").notNullable();
|
||||
t.binary("encryptedRelayPkiServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedRelayPkiServerCaCertificate").notNullable();
|
||||
t.binary("encryptedRelayPkiServerCaCertificateChain").notNullable();
|
||||
|
||||
// Org-scoped proxy SSH (client + server)
|
||||
t.binary("encryptedProxySshClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedProxySshClientCaPublicKey").notNullable();
|
||||
t.binary("encryptedProxySshServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedProxySshServerCaPublicKey").notNullable();
|
||||
// Org-scoped relay SSH (client + server)
|
||||
t.binary("encryptedRelaySshClientCaPrivateKey").notNullable();
|
||||
t.binary("encryptedRelaySshClientCaPublicKey").notNullable();
|
||||
t.binary("encryptedRelaySshServerCaPrivateKey").notNullable();
|
||||
t.binary("encryptedRelaySshServerCaPublicKey").notNullable();
|
||||
});
|
||||
|
||||
await createOnUpdateTrigger(knex, TableName.OrgProxyConfig);
|
||||
await createOnUpdateTrigger(knex, TableName.OrgRelayConfig);
|
||||
}
|
||||
|
||||
if (!(await knex.schema.hasTable(TableName.OrgGatewayConfigV2))) {
|
||||
@@ -87,8 +87,8 @@ export async function up(knex: Knex): Promise<void> {
|
||||
await createOnUpdateTrigger(knex, TableName.OrgGatewayConfigV2);
|
||||
}
|
||||
|
||||
if (!(await knex.schema.hasTable(TableName.Proxy))) {
|
||||
await knex.schema.createTable(TableName.Proxy, (t) => {
|
||||
if (!(await knex.schema.hasTable(TableName.Relay))) {
|
||||
await knex.schema.createTable(TableName.Relay, (t) => {
|
||||
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||
t.timestamps(true, true, true);
|
||||
|
||||
@@ -102,7 +102,7 @@ export async function up(knex: Knex): Promise<void> {
|
||||
t.string("ip").notNullable();
|
||||
});
|
||||
|
||||
await createOnUpdateTrigger(knex, TableName.Proxy);
|
||||
await createOnUpdateTrigger(knex, TableName.Relay);
|
||||
}
|
||||
|
||||
if (!(await knex.schema.hasTable(TableName.GatewayV2))) {
|
||||
@@ -116,8 +116,8 @@ export async function up(knex: Knex): Promise<void> {
|
||||
t.uuid("identityId").notNullable().unique();
|
||||
t.foreign("identityId").references("id").inTable(TableName.Identity).onDelete("CASCADE");
|
||||
|
||||
t.uuid("proxyId");
|
||||
t.foreign("proxyId").references("id").inTable(TableName.Proxy).onDelete("SET NULL");
|
||||
t.uuid("relayId");
|
||||
t.foreign("relayId").references("id").inTable(TableName.Relay).onDelete("SET NULL");
|
||||
|
||||
t.string("name").notNullable().unique();
|
||||
|
||||
@@ -129,11 +129,11 @@ export async function up(knex: Knex): Promise<void> {
|
||||
}
|
||||
|
||||
export async function down(knex: Knex): Promise<void> {
|
||||
await dropOnUpdateTrigger(knex, TableName.OrgProxyConfig);
|
||||
await knex.schema.dropTableIfExists(TableName.OrgProxyConfig);
|
||||
await dropOnUpdateTrigger(knex, TableName.OrgRelayConfig);
|
||||
await knex.schema.dropTableIfExists(TableName.OrgRelayConfig);
|
||||
|
||||
await dropOnUpdateTrigger(knex, TableName.InstanceProxyConfig);
|
||||
await knex.schema.dropTableIfExists(TableName.InstanceProxyConfig);
|
||||
await dropOnUpdateTrigger(knex, TableName.InstanceRelayConfig);
|
||||
await knex.schema.dropTableIfExists(TableName.InstanceRelayConfig);
|
||||
|
||||
await dropOnUpdateTrigger(knex, TableName.OrgGatewayConfigV2);
|
||||
await knex.schema.dropTableIfExists(TableName.OrgGatewayConfigV2);
|
||||
@@ -141,6 +141,6 @@ export async function down(knex: Knex): Promise<void> {
|
||||
await dropOnUpdateTrigger(knex, TableName.GatewayV2);
|
||||
await knex.schema.dropTableIfExists(TableName.GatewayV2);
|
||||
|
||||
await dropOnUpdateTrigger(knex, TableName.Proxy);
|
||||
await knex.schema.dropTableIfExists(TableName.Proxy);
|
||||
await dropOnUpdateTrigger(knex, TableName.Relay);
|
||||
await knex.schema.dropTableIfExists(TableName.Relay);
|
||||
}
|
||||
|
||||
@@ -13,7 +13,7 @@ export const GatewaysV2Schema = z.object({
|
||||
updatedAt: z.date(),
|
||||
orgId: z.string().uuid(),
|
||||
identityId: z.string().uuid(),
|
||||
proxyId: z.string().uuid().nullable().optional(),
|
||||
relayId: z.string().uuid().nullable().optional(),
|
||||
name: z.string(),
|
||||
heartbeat: z.date().nullable().optional()
|
||||
});
|
||||
|
||||
@@ -58,7 +58,7 @@ export * from "./identity-token-auths";
|
||||
export * from "./identity-ua-client-secrets";
|
||||
export * from "./identity-universal-auths";
|
||||
export * from "./incident-contacts";
|
||||
export * from "./instance-proxy-config";
|
||||
export * from "./instance-relay-config";
|
||||
export * from "./integration-auths";
|
||||
export * from "./integrations";
|
||||
export * from "./internal-certificate-authorities";
|
||||
@@ -79,7 +79,7 @@ export * from "./org-bots";
|
||||
export * from "./org-gateway-config";
|
||||
export * from "./org-gateway-config-v2";
|
||||
export * from "./org-memberships";
|
||||
export * from "./org-proxy-config";
|
||||
export * from "./org-relay-config";
|
||||
export * from "./org-roles";
|
||||
export * from "./organizations";
|
||||
export * from "./pki-alerts";
|
||||
@@ -99,8 +99,8 @@ export * from "./project-templates";
|
||||
export * from "./project-user-additional-privilege";
|
||||
export * from "./project-user-membership-roles";
|
||||
export * from "./projects";
|
||||
export * from "./proxies";
|
||||
export * from "./rate-limit";
|
||||
export * from "./relays";
|
||||
export * from "./resource-metadata";
|
||||
export * from "./saml-configs";
|
||||
export * from "./scim-tokens";
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
// Code generated by automation script, DO NOT EDIT.
|
||||
// Automated by pulling database and generating zod schema
|
||||
// To update. Just run npm run generate:schema
|
||||
// Written by akhilmhdh.
|
||||
|
||||
import { z } from "zod";
|
||||
|
||||
import { zodBuffer } from "@app/lib/zod";
|
||||
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const InstanceProxyConfigSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date(),
|
||||
encryptedRootProxyPkiCaPrivateKey: zodBuffer,
|
||||
encryptedRootProxyPkiCaCertificate: zodBuffer,
|
||||
encryptedInstanceProxyPkiCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceProxyPkiCaCertificate: zodBuffer,
|
||||
encryptedInstanceProxyPkiCaCertificateChain: zodBuffer,
|
||||
encryptedInstanceProxyPkiClientCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceProxyPkiClientCaCertificate: zodBuffer,
|
||||
encryptedInstanceProxyPkiClientCaCertificateChain: zodBuffer,
|
||||
encryptedInstanceProxyPkiServerCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceProxyPkiServerCaCertificate: zodBuffer,
|
||||
encryptedInstanceProxyPkiServerCaCertificateChain: zodBuffer,
|
||||
encryptedOrgProxyPkiCaPrivateKey: zodBuffer,
|
||||
encryptedOrgProxyPkiCaCertificate: zodBuffer,
|
||||
encryptedOrgProxyPkiCaCertificateChain: zodBuffer,
|
||||
encryptedInstanceProxySshClientCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceProxySshClientCaPublicKey: zodBuffer,
|
||||
encryptedInstanceProxySshServerCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceProxySshServerCaPublicKey: zodBuffer
|
||||
});
|
||||
|
||||
export type TInstanceProxyConfig = z.infer<typeof InstanceProxyConfigSchema>;
|
||||
export type TInstanceProxyConfigInsert = Omit<z.input<typeof InstanceProxyConfigSchema>, TImmutableDBKeys>;
|
||||
export type TInstanceProxyConfigUpdate = Partial<Omit<z.input<typeof InstanceProxyConfigSchema>, TImmutableDBKeys>>;
|
||||
38
backend/src/db/schemas/instance-relay-config.ts
Normal file
38
backend/src/db/schemas/instance-relay-config.ts
Normal file
@@ -0,0 +1,38 @@
|
||||
// Code generated by automation script, DO NOT EDIT.
|
||||
// Automated by pulling database and generating zod schema
|
||||
// To update. Just run npm run generate:schema
|
||||
// Written by akhilmhdh.
|
||||
|
||||
import { z } from "zod";
|
||||
|
||||
import { zodBuffer } from "@app/lib/zod";
|
||||
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const InstanceRelayConfigSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date(),
|
||||
encryptedRootRelayPkiCaPrivateKey: zodBuffer,
|
||||
encryptedRootRelayPkiCaCertificate: zodBuffer,
|
||||
encryptedInstanceRelayPkiCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceRelayPkiCaCertificate: zodBuffer,
|
||||
encryptedInstanceRelayPkiCaCertificateChain: zodBuffer,
|
||||
encryptedInstanceRelayPkiClientCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceRelayPkiClientCaCertificate: zodBuffer,
|
||||
encryptedInstanceRelayPkiClientCaCertificateChain: zodBuffer,
|
||||
encryptedInstanceRelayPkiServerCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceRelayPkiServerCaCertificate: zodBuffer,
|
||||
encryptedInstanceRelayPkiServerCaCertificateChain: zodBuffer,
|
||||
encryptedOrgRelayPkiCaPrivateKey: zodBuffer,
|
||||
encryptedOrgRelayPkiCaCertificate: zodBuffer,
|
||||
encryptedOrgRelayPkiCaCertificateChain: zodBuffer,
|
||||
encryptedInstanceRelaySshClientCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceRelaySshClientCaPublicKey: zodBuffer,
|
||||
encryptedInstanceRelaySshServerCaPrivateKey: zodBuffer,
|
||||
encryptedInstanceRelaySshServerCaPublicKey: zodBuffer
|
||||
});
|
||||
|
||||
export type TInstanceRelayConfig = z.infer<typeof InstanceRelayConfigSchema>;
|
||||
export type TInstanceRelayConfigInsert = Omit<z.input<typeof InstanceRelayConfigSchema>, TImmutableDBKeys>;
|
||||
export type TInstanceRelayConfigUpdate = Partial<Omit<z.input<typeof InstanceRelayConfigSchema>, TImmutableDBKeys>>;
|
||||
@@ -181,10 +181,10 @@ export enum TableName {
|
||||
ReminderRecipient = "reminders_recipients",
|
||||
|
||||
// gateway v2
|
||||
InstanceProxyConfig = "instance_proxy_config",
|
||||
OrgProxyConfig = "org_proxy_config",
|
||||
InstanceRelayConfig = "instance_relay_config",
|
||||
OrgRelayConfig = "org_relay_config",
|
||||
OrgGatewayConfigV2 = "org_gateway_config_v2",
|
||||
Proxy = "proxies",
|
||||
Relay = "relays",
|
||||
GatewayV2 = "gateways_v2"
|
||||
}
|
||||
|
||||
|
||||
@@ -1,31 +0,0 @@
|
||||
// Code generated by automation script, DO NOT EDIT.
|
||||
// Automated by pulling database and generating zod schema
|
||||
// To update. Just run npm run generate:schema
|
||||
// Written by akhilmhdh.
|
||||
|
||||
import { z } from "zod";
|
||||
|
||||
import { zodBuffer } from "@app/lib/zod";
|
||||
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const OrgProxyConfigSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date(),
|
||||
orgId: z.string().uuid(),
|
||||
encryptedProxyPkiClientCaPrivateKey: zodBuffer,
|
||||
encryptedProxyPkiClientCaCertificate: zodBuffer,
|
||||
encryptedProxyPkiClientCaCertificateChain: zodBuffer,
|
||||
encryptedProxyPkiServerCaPrivateKey: zodBuffer,
|
||||
encryptedProxyPkiServerCaCertificate: zodBuffer,
|
||||
encryptedProxyPkiServerCaCertificateChain: zodBuffer,
|
||||
encryptedProxySshClientCaPrivateKey: zodBuffer,
|
||||
encryptedProxySshClientCaPublicKey: zodBuffer,
|
||||
encryptedProxySshServerCaPrivateKey: zodBuffer,
|
||||
encryptedProxySshServerCaPublicKey: zodBuffer
|
||||
});
|
||||
|
||||
export type TOrgProxyConfig = z.infer<typeof OrgProxyConfigSchema>;
|
||||
export type TOrgProxyConfigInsert = Omit<z.input<typeof OrgProxyConfigSchema>, TImmutableDBKeys>;
|
||||
export type TOrgProxyConfigUpdate = Partial<Omit<z.input<typeof OrgProxyConfigSchema>, TImmutableDBKeys>>;
|
||||
31
backend/src/db/schemas/org-relay-config.ts
Normal file
31
backend/src/db/schemas/org-relay-config.ts
Normal file
@@ -0,0 +1,31 @@
|
||||
// Code generated by automation script, DO NOT EDIT.
|
||||
// Automated by pulling database and generating zod schema
|
||||
// To update. Just run npm run generate:schema
|
||||
// Written by akhilmhdh.
|
||||
|
||||
import { z } from "zod";
|
||||
|
||||
import { zodBuffer } from "@app/lib/zod";
|
||||
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const OrgRelayConfigSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date(),
|
||||
orgId: z.string().uuid(),
|
||||
encryptedRelayPkiClientCaPrivateKey: zodBuffer,
|
||||
encryptedRelayPkiClientCaCertificate: zodBuffer,
|
||||
encryptedRelayPkiClientCaCertificateChain: zodBuffer,
|
||||
encryptedRelayPkiServerCaPrivateKey: zodBuffer,
|
||||
encryptedRelayPkiServerCaCertificate: zodBuffer,
|
||||
encryptedRelayPkiServerCaCertificateChain: zodBuffer,
|
||||
encryptedRelaySshClientCaPrivateKey: zodBuffer,
|
||||
encryptedRelaySshClientCaPublicKey: zodBuffer,
|
||||
encryptedRelaySshServerCaPrivateKey: zodBuffer,
|
||||
encryptedRelaySshServerCaPublicKey: zodBuffer
|
||||
});
|
||||
|
||||
export type TOrgRelayConfig = z.infer<typeof OrgRelayConfigSchema>;
|
||||
export type TOrgRelayConfigInsert = Omit<z.input<typeof OrgRelayConfigSchema>, TImmutableDBKeys>;
|
||||
export type TOrgRelayConfigUpdate = Partial<Omit<z.input<typeof OrgRelayConfigSchema>, TImmutableDBKeys>>;
|
||||
@@ -7,7 +7,7 @@ import { z } from "zod";
|
||||
|
||||
import { TImmutableDBKeys } from "./models";
|
||||
|
||||
export const ProxiesSchema = z.object({
|
||||
export const RelaysSchema = z.object({
|
||||
id: z.string().uuid(),
|
||||
createdAt: z.date(),
|
||||
updatedAt: z.date(),
|
||||
@@ -17,6 +17,6 @@ export const ProxiesSchema = z.object({
|
||||
ip: z.string()
|
||||
});
|
||||
|
||||
export type TProxies = z.infer<typeof ProxiesSchema>;
|
||||
export type TProxiesInsert = Omit<z.input<typeof ProxiesSchema>, TImmutableDBKeys>;
|
||||
export type TProxiesUpdate = Partial<Omit<z.input<typeof ProxiesSchema>, TImmutableDBKeys>>;
|
||||
export type TRelays = z.infer<typeof RelaysSchema>;
|
||||
export type TRelaysInsert = Omit<z.input<typeof RelaysSchema>, TImmutableDBKeys>;
|
||||
export type TRelaysUpdate = Partial<Omit<z.input<typeof RelaysSchema>, TImmutableDBKeys>>;
|
||||
@@ -23,8 +23,8 @@ import { registerOrgRoleRouter } from "./org-role-router";
|
||||
import { registerPITRouter } from "./pit-router";
|
||||
import { registerProjectRoleRouter } from "./project-role-router";
|
||||
import { registerProjectRouter } from "./project-router";
|
||||
import { registerProxyRouter } from "./proxy-router";
|
||||
import { registerRateLimitRouter } from "./rate-limit-router";
|
||||
import { registerRelayRouter } from "./relay-router";
|
||||
import { registerSamlRouter } from "./saml-router";
|
||||
import { registerScimRouter } from "./scim-router";
|
||||
import { registerSecretApprovalPolicyRouter } from "./secret-approval-policy-router";
|
||||
@@ -80,7 +80,7 @@ export const registerV1EERoutes = async (server: FastifyZodProvider) => {
|
||||
);
|
||||
|
||||
await server.register(registerGatewayRouter, { prefix: "/gateways" });
|
||||
await server.register(registerProxyRouter, { prefix: "/proxies" });
|
||||
await server.register(registerRelayRouter, { prefix: "/relays" });
|
||||
await server.register(registerGithubOrgSyncRouter, { prefix: "/github-org-sync-config" });
|
||||
|
||||
await server.register(
|
||||
|
||||
@@ -7,12 +7,12 @@ import { writeLimit } from "@app/server/config/rateLimiter";
|
||||
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||
import { AuthMode } from "@app/services/auth/auth-type";
|
||||
|
||||
export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
||||
export const registerRelayRouter = async (server: FastifyZodProvider) => {
|
||||
const appCfg = getConfig();
|
||||
|
||||
server.route({
|
||||
method: "POST",
|
||||
url: "/register-instance-proxy",
|
||||
url: "/register-instance-relay",
|
||||
config: {
|
||||
rateLimit: writeLimit
|
||||
},
|
||||
@@ -39,8 +39,8 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
||||
onRequest: (req, _, next) => {
|
||||
const authHeader = req.headers.authorization;
|
||||
|
||||
if (appCfg.PROXY_AUTH_SECRET && authHeader) {
|
||||
const expectedHeader = `Bearer ${appCfg.PROXY_AUTH_SECRET}`;
|
||||
if (appCfg.RELAY_AUTH_SECRET && authHeader) {
|
||||
const expectedHeader = `Bearer ${appCfg.RELAY_AUTH_SECRET}`;
|
||||
if (
|
||||
authHeader.length === expectedHeader.length &&
|
||||
crypto.nativeCrypto.timingSafeEqual(Buffer.from(authHeader), Buffer.from(expectedHeader))
|
||||
@@ -50,11 +50,11 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
||||
}
|
||||
|
||||
throw new UnauthorizedError({
|
||||
message: "Invalid proxy auth secret"
|
||||
message: "Invalid relay auth secret"
|
||||
});
|
||||
},
|
||||
handler: async (req) => {
|
||||
return server.services.proxy.registerProxy({
|
||||
return server.services.relay.registerRelay({
|
||||
...req.body
|
||||
});
|
||||
}
|
||||
@@ -62,7 +62,7 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
||||
|
||||
server.route({
|
||||
method: "POST",
|
||||
url: "/register-org-proxy",
|
||||
url: "/register-org-relay",
|
||||
config: {
|
||||
rateLimit: writeLimit
|
||||
},
|
||||
@@ -89,10 +89,10 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
|
||||
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||
handler: async (req) => {
|
||||
throw new BadRequestError({
|
||||
message: "Org proxy registration is not yet supported"
|
||||
message: "Org relay registration is not yet supported"
|
||||
});
|
||||
|
||||
return server.services.proxy.registerProxy({
|
||||
return server.services.relay.registerRelay({
|
||||
...req.body,
|
||||
identityId: req.permission.id,
|
||||
orgId: req.permission.orgId
|
||||
@@ -79,9 +79,9 @@ export const KubernetesProvider = ({
|
||||
);
|
||||
},
|
||||
{
|
||||
proxyIp: gatewayV2ConnectionDetails.proxyIp,
|
||||
relayIp: gatewayV2ConnectionDetails.relayIp,
|
||||
gateway: gatewayV2ConnectionDetails.gateway,
|
||||
proxy: gatewayV2ConnectionDetails.proxy,
|
||||
relay: gatewayV2ConnectionDetails.relay,
|
||||
protocol: inputs.reviewTokenThroughGateway ? GatewayProxyProtocol.Http : GatewayProxyProtocol.Tcp,
|
||||
httpsAgent: inputs.httpsAgent
|
||||
}
|
||||
|
||||
@@ -201,9 +201,9 @@ export const SqlDatabaseProvider = ({
|
||||
await gatewayCallback("localhost", port);
|
||||
},
|
||||
{
|
||||
proxyIp: gatewayV2ConnectionDetails.proxyIp,
|
||||
relayIp: gatewayV2ConnectionDetails.relayIp,
|
||||
gateway: gatewayV2ConnectionDetails.gateway,
|
||||
proxy: gatewayV2ConnectionDetails.proxy,
|
||||
relay: gatewayV2ConnectionDetails.relay,
|
||||
protocol: GatewayProxyProtocol.Tcp
|
||||
}
|
||||
);
|
||||
|
||||
@@ -3,7 +3,7 @@ import net from "node:net";
|
||||
import { ForbiddenError } from "@casl/ability";
|
||||
import * as x509 from "@peculiar/x509";
|
||||
|
||||
import { TProxies } from "@app/db/schemas";
|
||||
import { TRelays } from "@app/db/schemas";
|
||||
import { PgSqlLock } from "@app/keystore/keystore";
|
||||
import { crypto } from "@app/lib/crypto";
|
||||
import { DatabaseErrorCode } from "@app/lib/error-codes";
|
||||
@@ -24,9 +24,9 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
|
||||
import { TLicenseServiceFactory } from "../license/license-service";
|
||||
import { OrgPermissionGatewayActions, OrgPermissionSubjects } from "../permission/org-permission";
|
||||
import { TPermissionServiceFactory } from "../permission/permission-service-types";
|
||||
import { TProxyDALFactory } from "../proxy/proxy-dal";
|
||||
import { isInstanceProxy } from "../proxy/proxy-fns";
|
||||
import { TProxyServiceFactory } from "../proxy/proxy-service";
|
||||
import { TRelayDALFactory } from "../relay/relay-dal";
|
||||
import { isInstanceRelay } from "../relay/relay-fns";
|
||||
import { TRelayServiceFactory } from "../relay/relay-service";
|
||||
import { GATEWAY_ACTOR_OID, GATEWAY_ROUTING_INFO_OID } from "./gateway-v2-constants";
|
||||
import { TGatewayV2DALFactory } from "./gateway-v2-dal";
|
||||
import { TOrgGatewayConfigV2DALFactory } from "./org-gateway-config-v2-dal";
|
||||
@@ -35,9 +35,9 @@ type TGatewayV2ServiceFactoryDep = {
|
||||
orgGatewayConfigV2DAL: Pick<TOrgGatewayConfigV2DALFactory, "findOne" | "create" | "transaction" | "findById">;
|
||||
licenseService: Pick<TLicenseServiceFactory, "onPremFeatures" | "getPlan">;
|
||||
kmsService: TKmsServiceFactory;
|
||||
proxyService: TProxyServiceFactory;
|
||||
relayService: TRelayServiceFactory;
|
||||
gatewayV2DAL: TGatewayV2DALFactory;
|
||||
proxyDAL: TProxyDALFactory;
|
||||
relayDAL: TRelayDALFactory;
|
||||
permissionService: TPermissionServiceFactory;
|
||||
};
|
||||
|
||||
@@ -47,9 +47,9 @@ export const gatewayV2ServiceFactory = ({
|
||||
orgGatewayConfigV2DAL,
|
||||
licenseService,
|
||||
kmsService,
|
||||
proxyService,
|
||||
relayService,
|
||||
gatewayV2DAL,
|
||||
proxyDAL,
|
||||
relayDAL,
|
||||
permissionService
|
||||
}: TGatewayV2ServiceFactoryDep) => {
|
||||
const $validateIdentityAccessToGateway = async (orgId: string, actorId: string, actorAuthMethod: ActorAuthMethod) => {
|
||||
@@ -285,9 +285,9 @@ export const gatewayV2ServiceFactory = ({
|
||||
throw new NotFoundError({ message: `Gateway Config for org ${gateway.orgId} not found.` });
|
||||
}
|
||||
|
||||
if (!gateway.proxyId) {
|
||||
if (!gateway.relayId) {
|
||||
throw new BadRequestError({
|
||||
message: "Gateway is not associated with a proxy"
|
||||
message: "Gateway is not associated with a relay"
|
||||
});
|
||||
}
|
||||
|
||||
@@ -392,23 +392,23 @@ export const gatewayV2ServiceFactory = ({
|
||||
|
||||
const gatewayClientCertPrivateKey = crypto.nativeCrypto.KeyObject.from(clientKeys.privateKey);
|
||||
|
||||
const proxyCredentials = await proxyService.getCredentialsForClient({
|
||||
proxyId: gateway.proxyId,
|
||||
const relayCredentials = await relayService.getCredentialsForClient({
|
||||
relayId: gateway.relayId,
|
||||
orgId: gateway.orgId,
|
||||
gatewayId
|
||||
});
|
||||
|
||||
return {
|
||||
proxyIp: proxyCredentials.proxyIp,
|
||||
relayIp: relayCredentials.relayIp,
|
||||
gateway: {
|
||||
clientCertificate: clientCert.toString("pem"),
|
||||
clientPrivateKey: gatewayClientCertPrivateKey.export({ format: "pem", type: "pkcs8" }).toString(),
|
||||
serverCertificateChain: constructPemChainFromCerts([gatewayServerCaCert, rootGatewayCaCert])
|
||||
},
|
||||
proxy: {
|
||||
clientCertificate: proxyCredentials.clientCertificate,
|
||||
clientPrivateKey: proxyCredentials.clientPrivateKey,
|
||||
serverCertificateChain: proxyCredentials.serverCertificateChain
|
||||
relay: {
|
||||
clientCertificate: relayCredentials.clientCertificate,
|
||||
clientPrivateKey: relayCredentials.clientPrivateKey,
|
||||
serverCertificateChain: relayCredentials.serverCertificateChain
|
||||
}
|
||||
};
|
||||
};
|
||||
@@ -417,27 +417,27 @@ export const gatewayV2ServiceFactory = ({
|
||||
orgId,
|
||||
actorId,
|
||||
actorAuthMethod,
|
||||
proxyName,
|
||||
relayName,
|
||||
name
|
||||
}: {
|
||||
orgId: string;
|
||||
actorId: string;
|
||||
actorAuthMethod: ActorAuthMethod;
|
||||
proxyName: string;
|
||||
relayName: string;
|
||||
name: string;
|
||||
}) => {
|
||||
await $validateIdentityAccessToGateway(orgId, actorId, actorAuthMethod);
|
||||
const orgCAs = await $getOrgCAs(orgId);
|
||||
|
||||
let proxy: TProxies;
|
||||
if (isInstanceProxy(proxyName)) {
|
||||
proxy = await proxyDAL.findOne({ name: proxyName });
|
||||
let relay: TRelays;
|
||||
if (isInstanceRelay(relayName)) {
|
||||
relay = await relayDAL.findOne({ name: relayName });
|
||||
} else {
|
||||
proxy = await proxyDAL.findOne({ orgId, name: proxyName });
|
||||
relay = await relayDAL.findOne({ orgId, name: relayName });
|
||||
}
|
||||
|
||||
if (!proxy) {
|
||||
throw new NotFoundError({ message: `Proxy ${proxyName} not found` });
|
||||
if (!relay) {
|
||||
throw new NotFoundError({ message: `Relay ${relayName} not found` });
|
||||
}
|
||||
|
||||
try {
|
||||
@@ -447,7 +447,7 @@ export const gatewayV2ServiceFactory = ({
|
||||
orgId,
|
||||
name,
|
||||
identityId: actorId,
|
||||
proxyId: proxy.id
|
||||
relayId: relay.id
|
||||
}
|
||||
],
|
||||
["identityId"]
|
||||
@@ -507,24 +507,24 @@ export const gatewayV2ServiceFactory = ({
|
||||
extensions: gatewayServerCertExtensions
|
||||
});
|
||||
|
||||
const proxyCredentials = await proxyService.getCredentialsForGateway({
|
||||
proxyName,
|
||||
const relayCredentials = await relayService.getCredentialsForGateway({
|
||||
relayName,
|
||||
orgId,
|
||||
gatewayId: gateway.id
|
||||
});
|
||||
|
||||
return {
|
||||
gatewayId: gateway.id,
|
||||
proxyIp: proxyCredentials.proxyIp,
|
||||
relayIp: relayCredentials.relayIp,
|
||||
pki: {
|
||||
serverCertificate: gatewayServerCertificate.toString("pem"),
|
||||
serverPrivateKey: gatewayServerCertPrivateKey.export({ format: "pem", type: "pkcs8" }).toString(),
|
||||
clientCertificateChain: constructPemChainFromCerts([gatewayClientCaCert, rootGatewayCaCert])
|
||||
},
|
||||
ssh: {
|
||||
clientCertificate: proxyCredentials.clientSshCert,
|
||||
clientPrivateKey: proxyCredentials.clientSshPrivateKey,
|
||||
serverCAPublicKey: proxyCredentials.serverCAPublicKey
|
||||
clientCertificate: relayCredentials.clientSshCert,
|
||||
clientPrivateKey: relayCredentials.clientSshPrivateKey,
|
||||
serverCAPublicKey: relayCredentials.serverCAPublicKey
|
||||
}
|
||||
};
|
||||
} catch (err) {
|
||||
@@ -613,9 +613,9 @@ export const gatewayV2ServiceFactory = ({
|
||||
},
|
||||
{
|
||||
protocol: GatewayProxyProtocol.Ping,
|
||||
proxyIp: gatewayV2ConnectionDetails.proxyIp,
|
||||
relayIp: gatewayV2ConnectionDetails.relayIp,
|
||||
gateway: gatewayV2ConnectionDetails.gateway,
|
||||
proxy: gatewayV2ConnectionDetails.proxy
|
||||
relay: gatewayV2ConnectionDetails.relay
|
||||
}
|
||||
);
|
||||
|
||||
|
||||
@@ -1,11 +0,0 @@
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { ormify } from "@app/lib/knex";
|
||||
|
||||
export type TInstanceProxyConfigDALFactory = ReturnType<typeof instanceProxyConfigDalFactory>;
|
||||
|
||||
export const instanceProxyConfigDalFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.InstanceProxyConfig);
|
||||
|
||||
return orm;
|
||||
};
|
||||
@@ -1,11 +0,0 @@
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { ormify } from "@app/lib/knex";
|
||||
|
||||
export type TOrgProxyConfigDALFactory = ReturnType<typeof orgProxyConfigDalFactory>;
|
||||
|
||||
export const orgProxyConfigDalFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.OrgProxyConfig);
|
||||
|
||||
return orm;
|
||||
};
|
||||
@@ -1,11 +0,0 @@
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { ormify } from "@app/lib/knex";
|
||||
|
||||
export type TProxyDALFactory = ReturnType<typeof proxyDalFactory>;
|
||||
|
||||
export const proxyDalFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.Proxy);
|
||||
|
||||
return orm;
|
||||
};
|
||||
@@ -1,5 +0,0 @@
|
||||
export const INSTANCE_PROXY_PREFIX = "infisical-";
|
||||
|
||||
export const isInstanceProxy = (proxyName: string) => {
|
||||
return proxyName.startsWith(INSTANCE_PROXY_PREFIX);
|
||||
};
|
||||
File diff suppressed because it is too large
Load Diff
11
backend/src/ee/services/relay/instance-relay-config-dal.ts
Normal file
11
backend/src/ee/services/relay/instance-relay-config-dal.ts
Normal file
@@ -0,0 +1,11 @@
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { ormify } from "@app/lib/knex";
|
||||
|
||||
export type TInstanceRelayConfigDALFactory = ReturnType<typeof instanceRelayConfigDalFactory>;
|
||||
|
||||
export const instanceRelayConfigDalFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.InstanceRelayConfig);
|
||||
|
||||
return orm;
|
||||
};
|
||||
11
backend/src/ee/services/relay/org-relay-config-dal.ts
Normal file
11
backend/src/ee/services/relay/org-relay-config-dal.ts
Normal file
@@ -0,0 +1,11 @@
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { ormify } from "@app/lib/knex";
|
||||
|
||||
export type TOrgRelayConfigDALFactory = ReturnType<typeof orgRelayConfigDalFactory>;
|
||||
|
||||
export const orgRelayConfigDalFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.OrgRelayConfig);
|
||||
|
||||
return orm;
|
||||
};
|
||||
11
backend/src/ee/services/relay/relay-dal.ts
Normal file
11
backend/src/ee/services/relay/relay-dal.ts
Normal file
@@ -0,0 +1,11 @@
|
||||
import { TDbClient } from "@app/db";
|
||||
import { TableName } from "@app/db/schemas";
|
||||
import { ormify } from "@app/lib/knex";
|
||||
|
||||
export type TRelayDALFactory = ReturnType<typeof relayDalFactory>;
|
||||
|
||||
export const relayDalFactory = (db: TDbClient) => {
|
||||
const orm = ormify(db, TableName.Relay);
|
||||
|
||||
return orm;
|
||||
};
|
||||
5
backend/src/ee/services/relay/relay-fns.ts
Normal file
5
backend/src/ee/services/relay/relay-fns.ts
Normal file
@@ -0,0 +1,5 @@
|
||||
export const INSTANCE_RELAY_PREFIX = "infisical-";
|
||||
|
||||
export const isInstanceRelay = (relayName: string) => {
|
||||
return relayName.startsWith(INSTANCE_RELAY_PREFIX);
|
||||
};
|
||||
1008
backend/src/ee/services/relay/relay-service.ts
Normal file
1008
backend/src/ee/services/relay/relay-service.ts
Normal file
File diff suppressed because it is too large
Load Diff
@@ -14,9 +14,9 @@ export const PgSqlLock = {
|
||||
CreateProject: (orgId: string) => pgAdvisoryLockHashText(`create-project:${orgId}`),
|
||||
CreateFolder: (envId: string, projectId: string) => pgAdvisoryLockHashText(`create-folder:${envId}-${projectId}`),
|
||||
SshInit: (projectId: string) => pgAdvisoryLockHashText(`ssh-bootstrap:${projectId}`),
|
||||
InstanceProxyConfigInit: () => pgAdvisoryLockHashText("instance-proxy-config-init"),
|
||||
InstanceRelayConfigInit: () => pgAdvisoryLockHashText("instance-relay-config-init"),
|
||||
OrgGatewayV2Init: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-v2-init:${orgId}`),
|
||||
OrgProxyConfigInit: (orgId: string) => pgAdvisoryLockHashText(`org-proxy-config-init:${orgId}`),
|
||||
OrgRelayConfigInit: (orgId: string) => pgAdvisoryLockHashText(`org-relay-config-init:${orgId}`),
|
||||
IdentityLogin: (identityId: string, nonce: string) => pgAdvisoryLockHashText(`identity-login:${identityId}:${nonce}`)
|
||||
} as const;
|
||||
|
||||
|
||||
@@ -233,7 +233,7 @@ const envSchema = z
|
||||
GATEWAY_RELAY_REALM: zpStr(z.string().optional()),
|
||||
GATEWAY_RELAY_AUTH_SECRET: zpStr(z.string().optional()),
|
||||
|
||||
PROXY_AUTH_SECRET: zpStr(z.string().optional()),
|
||||
RELAY_AUTH_SECRET: zpStr(z.string().optional()),
|
||||
|
||||
DYNAMIC_SECRET_ALLOW_INTERNAL_IP: zodStrBool.default("false"),
|
||||
DYNAMIC_SECRET_AWS_ACCESS_KEY_ID: zpStr(z.string().optional()).default(
|
||||
|
||||
@@ -11,26 +11,26 @@ import { BadRequestError } from "../errors";
|
||||
import { GatewayProxyProtocol } from "../gateway/types";
|
||||
import { logger } from "../logger";
|
||||
|
||||
interface IGatewayProxyServer {
|
||||
interface IGatewayRelayServer {
|
||||
server: net.Server;
|
||||
port: number;
|
||||
cleanup: () => Promise<void>;
|
||||
getProxyError: () => string;
|
||||
getRelayError: () => string;
|
||||
}
|
||||
|
||||
const createProxyConnection = async ({
|
||||
proxyIp,
|
||||
const createRelayConnection = async ({
|
||||
relayIp,
|
||||
clientCertificate,
|
||||
clientPrivateKey,
|
||||
serverCertificateChain
|
||||
}: {
|
||||
proxyIp: string;
|
||||
relayIp: string;
|
||||
clientCertificate: string;
|
||||
clientPrivateKey: string;
|
||||
serverCertificateChain: string;
|
||||
}): Promise<net.Socket> => {
|
||||
const [targetHost] = await verifyHostInputValidity(proxyIp);
|
||||
const [, portStr] = proxyIp.split(":");
|
||||
const [targetHost] = await verifyHostInputValidity(relayIp);
|
||||
const [, portStr] = relayIp.split(":");
|
||||
const port = parseInt(portStr, 10) || 8443;
|
||||
|
||||
const serverCAs = splitPemChain(serverCertificateChain);
|
||||
@@ -47,7 +47,7 @@ const createProxyConnection = async ({
|
||||
return new Promise((resolve, reject) => {
|
||||
try {
|
||||
const socket = tls.connect(tlsOptions, () => {
|
||||
logger.info("Proxy TLS connection established successfully");
|
||||
logger.info("Relay TLS connection established successfully");
|
||||
resolve(socket);
|
||||
});
|
||||
|
||||
@@ -75,11 +75,11 @@ const createProxyConnection = async ({
|
||||
};
|
||||
|
||||
const createGatewayConnection = async (
|
||||
proxyConn: net.Socket,
|
||||
relayConn: net.Socket,
|
||||
gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string }
|
||||
): Promise<net.Socket> => {
|
||||
const tlsOptions: tls.ConnectionOptions = {
|
||||
socket: proxyConn,
|
||||
socket: relayConn,
|
||||
cert: gateway.clientCertificate,
|
||||
key: gateway.clientPrivateKey,
|
||||
ca: splitPemChain(gateway.serverCertificateChain),
|
||||
@@ -119,20 +119,20 @@ const createGatewayConnection = async (
|
||||
});
|
||||
};
|
||||
|
||||
const setupProxyServer = async ({
|
||||
const setupRelayServer = async ({
|
||||
protocol,
|
||||
proxyIp,
|
||||
relayIp,
|
||||
gateway,
|
||||
proxy,
|
||||
relay,
|
||||
httpsAgent
|
||||
}: {
|
||||
protocol: GatewayProxyProtocol;
|
||||
proxyIp: string;
|
||||
relayIp: string;
|
||||
gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
|
||||
proxy: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
|
||||
relay: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
|
||||
httpsAgent?: https.Agent;
|
||||
}): Promise<IGatewayProxyServer> => {
|
||||
const proxyErrorMsg: string[] = [];
|
||||
}): Promise<IGatewayRelayServer> => {
|
||||
const relayErrorMsg: string[] = [];
|
||||
|
||||
return new Promise((resolve, reject) => {
|
||||
const server = net.createServer();
|
||||
@@ -143,16 +143,16 @@ const setupProxyServer = async ({
|
||||
clientConn.setKeepAlive(true, 30000);
|
||||
clientConn.setNoDelay(true);
|
||||
|
||||
// Stage 1: Connect to proxy relay with TLS
|
||||
const proxyConn = await createProxyConnection({
|
||||
proxyIp,
|
||||
clientCertificate: proxy.clientCertificate,
|
||||
clientPrivateKey: proxy.clientPrivateKey,
|
||||
serverCertificateChain: proxy.serverCertificateChain
|
||||
// Stage 1: Connect to relay with TLS
|
||||
const relayConn = await createRelayConnection({
|
||||
relayIp,
|
||||
clientCertificate: relay.clientCertificate,
|
||||
clientPrivateKey: relay.clientPrivateKey,
|
||||
serverCertificateChain: relay.serverCertificateChain
|
||||
});
|
||||
|
||||
// Stage 2: Establish mTLS connection to gateway through the proxy
|
||||
const gatewayConn = await createGatewayConnection(proxyConn, gateway);
|
||||
// Stage 2: Establish mTLS connection to gateway through the relay
|
||||
const gatewayConn = await createGatewayConnection(relayConn, gateway);
|
||||
|
||||
let command = "";
|
||||
|
||||
@@ -191,22 +191,22 @@ const setupProxyServer = async ({
|
||||
|
||||
// Handle connection closure
|
||||
clientConn.on("close", () => {
|
||||
proxyConn.destroy();
|
||||
relayConn.destroy();
|
||||
gatewayConn.destroy();
|
||||
});
|
||||
|
||||
proxyConn.on("close", () => {
|
||||
relayConn.on("close", () => {
|
||||
clientConn.destroy();
|
||||
gatewayConn.destroy();
|
||||
});
|
||||
|
||||
gatewayConn.on("close", () => {
|
||||
clientConn.destroy();
|
||||
proxyConn.destroy();
|
||||
relayConn.destroy();
|
||||
});
|
||||
} catch (err) {
|
||||
const errorMsg = err instanceof Error ? err.message : String(err);
|
||||
proxyErrorMsg.push(errorMsg);
|
||||
relayErrorMsg.push(errorMsg);
|
||||
clientConn.destroy();
|
||||
}
|
||||
})();
|
||||
@@ -234,7 +234,7 @@ const setupProxyServer = async ({
|
||||
logger.debug("Error closing server:", err instanceof Error ? err.message : String(err));
|
||||
}
|
||||
},
|
||||
getProxyError: () => proxyErrorMsg.join(",")
|
||||
getRelayError: () => relayErrorMsg.join(",")
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -244,19 +244,19 @@ export const withGatewayV2Proxy = async <T>(
|
||||
callback: (port: number) => Promise<T>,
|
||||
options: {
|
||||
protocol: GatewayProxyProtocol;
|
||||
proxyIp: string;
|
||||
relayIp: string;
|
||||
gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
|
||||
proxy: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
|
||||
relay: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
|
||||
httpsAgent?: https.Agent;
|
||||
}
|
||||
): Promise<T> => {
|
||||
const { protocol, proxyIp, gateway, proxy, httpsAgent } = options;
|
||||
const { protocol, relayIp, gateway, relay, httpsAgent } = options;
|
||||
|
||||
const { port, cleanup, getProxyError } = await setupProxyServer({
|
||||
const { port, cleanup, getRelayError } = await setupRelayServer({
|
||||
protocol,
|
||||
proxyIp,
|
||||
relayIp,
|
||||
gateway,
|
||||
proxy,
|
||||
relay,
|
||||
httpsAgent
|
||||
});
|
||||
|
||||
@@ -264,12 +264,12 @@ export const withGatewayV2Proxy = async <T>(
|
||||
// Execute the callback with the allocated port
|
||||
return await callback(port);
|
||||
} catch (err) {
|
||||
const proxyErrorMessage = getProxyError();
|
||||
if (proxyErrorMessage) {
|
||||
logger.error("Proxy error:", proxyErrorMessage);
|
||||
const relayErrorMessage = getRelayError();
|
||||
if (relayErrorMessage) {
|
||||
logger.error("Relay error:", relayErrorMessage);
|
||||
}
|
||||
logger.error("Gateway error:", err instanceof Error ? err.message : String(err));
|
||||
let errorMessage = proxyErrorMessage || (err instanceof Error ? err.message : String(err));
|
||||
let errorMessage = relayErrorMessage || (err instanceof Error ? err.message : String(err));
|
||||
if (axios.isAxiosError(err) && (err.response?.data as { message?: string })?.message) {
|
||||
errorMessage = (err.response?.data as { message: string }).message;
|
||||
}
|
||||
|
||||
@@ -122,7 +122,7 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
|
||||
}
|
||||
|
||||
// Authentication is handled on a route-level
|
||||
if (req.url === "/api/v1/proxies/register-instance-proxy") {
|
||||
if (req.url === "/api/v1/proxies/register-instance-relay") {
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -73,12 +73,12 @@ import { projectTemplateDALFactory } from "@app/ee/services/project-template/pro
|
||||
import { projectTemplateServiceFactory } from "@app/ee/services/project-template/project-template-service";
|
||||
import { projectUserAdditionalPrivilegeDALFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-dal";
|
||||
import { projectUserAdditionalPrivilegeServiceFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-service";
|
||||
import { instanceProxyConfigDalFactory } from "@app/ee/services/proxy/instance-proxy-config-dal";
|
||||
import { orgProxyConfigDalFactory } from "@app/ee/services/proxy/org-proxy-config-dal";
|
||||
import { proxyDalFactory } from "@app/ee/services/proxy/proxy-dal";
|
||||
import { proxyServiceFactory } from "@app/ee/services/proxy/proxy-service";
|
||||
import { rateLimitDALFactory } from "@app/ee/services/rate-limit/rate-limit-dal";
|
||||
import { rateLimitServiceFactory } from "@app/ee/services/rate-limit/rate-limit-service";
|
||||
import { instanceRelayConfigDalFactory } from "@app/ee/services/relay/instance-relay-config-dal";
|
||||
import { orgRelayConfigDalFactory } from "@app/ee/services/relay/org-relay-config-dal";
|
||||
import { relayDalFactory } from "@app/ee/services/relay/relay-dal";
|
||||
import { relayServiceFactory } from "@app/ee/services/relay/relay-service";
|
||||
import { samlConfigDALFactory } from "@app/ee/services/saml-config/saml-config-dal";
|
||||
import { samlConfigServiceFactory } from "@app/ee/services/saml-config/saml-config-service";
|
||||
import { scimDALFactory } from "@app/ee/services/scim/scim-dal";
|
||||
@@ -948,9 +948,9 @@ export const registerRoutes = async (
|
||||
const pkiSubscriberDAL = pkiSubscriberDALFactory(db);
|
||||
const pkiTemplatesDAL = pkiTemplatesDALFactory(db);
|
||||
|
||||
const instanceProxyConfigDAL = instanceProxyConfigDalFactory(db);
|
||||
const orgProxyConfigDAL = orgProxyConfigDalFactory(db);
|
||||
const proxyDAL = proxyDalFactory(db);
|
||||
const instanceRelayConfigDAL = instanceRelayConfigDalFactory(db);
|
||||
const orgRelayConfigDAL = orgRelayConfigDalFactory(db);
|
||||
const relayDAL = relayDalFactory(db);
|
||||
const gatewayV2DAL = gatewayV2DalFactory(db);
|
||||
|
||||
const orgGatewayConfigV2DAL = orgGatewayConfigV2DalFactory(db);
|
||||
@@ -1073,20 +1073,20 @@ export const registerRoutes = async (
|
||||
keyStore
|
||||
});
|
||||
|
||||
const proxyService = proxyServiceFactory({
|
||||
instanceProxyConfigDAL,
|
||||
orgProxyConfigDAL,
|
||||
proxyDAL,
|
||||
const relayService = relayServiceFactory({
|
||||
instanceRelayConfigDAL,
|
||||
orgRelayConfigDAL,
|
||||
relayDAL,
|
||||
kmsService
|
||||
});
|
||||
|
||||
const gatewayV2Service = gatewayV2ServiceFactory({
|
||||
kmsService,
|
||||
licenseService,
|
||||
proxyService,
|
||||
relayService,
|
||||
orgGatewayConfigV2DAL,
|
||||
gatewayV2DAL,
|
||||
proxyDAL,
|
||||
relayDAL,
|
||||
permissionService
|
||||
});
|
||||
|
||||
@@ -2138,7 +2138,7 @@ export const registerRoutes = async (
|
||||
reminder: reminderService,
|
||||
bus: eventBusService,
|
||||
sse: sseService,
|
||||
proxy: proxyService,
|
||||
relay: relayService,
|
||||
gatewayV2: gatewayV2Service
|
||||
});
|
||||
|
||||
|
||||
@@ -105,9 +105,9 @@ export const requestWithGitHubGateway = async <T>(
|
||||
},
|
||||
{
|
||||
protocol: GatewayProxyProtocol.Tcp,
|
||||
proxyIp: gatewayConnectionDetails.proxyIp,
|
||||
relayIp: gatewayConnectionDetails.relayIp,
|
||||
gateway: gatewayConnectionDetails.gateway,
|
||||
proxy: gatewayConnectionDetails.proxy
|
||||
relay: gatewayConnectionDetails.relay
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
@@ -142,9 +142,9 @@ export const executeWithPotentialGateway = async <T>(
|
||||
},
|
||||
{
|
||||
protocol: GatewayProxyProtocol.Tcp,
|
||||
proxyIp: platformConnectionDetails.proxyIp,
|
||||
relayIp: platformConnectionDetails.relayIp,
|
||||
gateway: platformConnectionDetails.gateway,
|
||||
proxy: platformConnectionDetails.proxy
|
||||
relay: platformConnectionDetails.relay
|
||||
}
|
||||
);
|
||||
}
|
||||
|
||||
@@ -114,9 +114,9 @@ export const identityKubernetesAuthServiceFactory = ({
|
||||
},
|
||||
{
|
||||
protocol: inputs.reviewTokenThroughGateway ? GatewayProxyProtocol.Http : GatewayProxyProtocol.Tcp,
|
||||
proxyIp: gatewayV2ConnectionDetails.proxyIp,
|
||||
relayIp: gatewayV2ConnectionDetails.relayIp,
|
||||
gateway: gatewayV2ConnectionDetails.gateway,
|
||||
proxy: gatewayV2ConnectionDetails.proxy,
|
||||
relay: gatewayV2ConnectionDetails.relay,
|
||||
httpsAgent
|
||||
}
|
||||
);
|
||||
|
||||
Reference in New Issue
Block a user