misc: updated proxy terminology to relay

This commit is contained in:
Sheen Capadngan
2025-09-09 01:30:45 +08:00
parent 09d179f30d
commit c9136a23bf
34 changed files with 1314 additions and 1314 deletions
+2 -2
View File
@@ -32,8 +32,8 @@ import { TPermissionServiceFactory } from "@app/ee/services/permission/permissio
import { TPitServiceFactory } from "@app/ee/services/pit/pit-service"; import { TPitServiceFactory } from "@app/ee/services/pit/pit-service";
import { TProjectTemplateServiceFactory } from "@app/ee/services/project-template/project-template-types"; import { TProjectTemplateServiceFactory } from "@app/ee/services/project-template/project-template-types";
import { TProjectUserAdditionalPrivilegeServiceFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-types"; import { TProjectUserAdditionalPrivilegeServiceFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-types";
import { TProxyServiceFactory } from "@app/ee/services/proxy/proxy-service";
import { RateLimitConfiguration, TRateLimitServiceFactory } from "@app/ee/services/rate-limit/rate-limit-types"; import { RateLimitConfiguration, TRateLimitServiceFactory } from "@app/ee/services/rate-limit/rate-limit-types";
import { TRelayServiceFactory } from "@app/ee/services/relay/relay-service";
import { TSamlConfigServiceFactory } from "@app/ee/services/saml-config/saml-config-types"; import { TSamlConfigServiceFactory } from "@app/ee/services/saml-config/saml-config-types";
import { TScimServiceFactory } from "@app/ee/services/scim/scim-types"; import { TScimServiceFactory } from "@app/ee/services/scim/scim-types";
import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service"; import { TSecretApprovalPolicyServiceFactory } from "@app/ee/services/secret-approval-policy/secret-approval-policy-service";
@@ -305,7 +305,7 @@ declare module "fastify" {
bus: TEventBusService; bus: TEventBusService;
sse: TServerSentEventsService; sse: TServerSentEventsService;
identityAuthTemplate: TIdentityAuthTemplateServiceFactory; identityAuthTemplate: TIdentityAuthTemplateServiceFactory;
proxy: TProxyServiceFactory; relay: TRelayServiceFactory;
gatewayV2: TGatewayV2ServiceFactory; gatewayV2: TGatewayV2ServiceFactory;
}; };
// this is exclusive use for middlewares in which we need to inject data // this is exclusive use for middlewares in which we need to inject data
+20 -20
View File
@@ -182,9 +182,9 @@ import {
TIncidentContacts, TIncidentContacts,
TIncidentContactsInsert, TIncidentContactsInsert,
TIncidentContactsUpdate, TIncidentContactsUpdate,
TInstanceProxyConfig, TInstanceRelayConfig,
TInstanceProxyConfigInsert, TInstanceRelayConfigInsert,
TInstanceProxyConfigUpdate, TInstanceRelayConfigUpdate,
TIntegrationAuths, TIntegrationAuths,
TIntegrationAuthsInsert, TIntegrationAuthsInsert,
TIntegrationAuthsUpdate, TIntegrationAuthsUpdate,
@@ -242,9 +242,9 @@ import {
TOrgMemberships, TOrgMemberships,
TOrgMembershipsInsert, TOrgMembershipsInsert,
TOrgMembershipsUpdate, TOrgMembershipsUpdate,
TOrgProxyConfig, TOrgRelayConfig,
TOrgProxyConfigInsert, TOrgRelayConfigInsert,
TOrgProxyConfigUpdate, TOrgRelayConfigUpdate,
TOrgRoles, TOrgRoles,
TOrgRolesInsert, TOrgRolesInsert,
TOrgRolesUpdate, TOrgRolesUpdate,
@@ -299,12 +299,12 @@ import {
TProjectUserMembershipRoles, TProjectUserMembershipRoles,
TProjectUserMembershipRolesInsert, TProjectUserMembershipRolesInsert,
TProjectUserMembershipRolesUpdate, TProjectUserMembershipRolesUpdate,
TProxies,
TProxiesInsert,
TProxiesUpdate,
TRateLimit, TRateLimit,
TRateLimitInsert, TRateLimitInsert,
TRateLimitUpdate, TRateLimitUpdate,
TRelays,
TRelaysInsert,
TRelaysUpdate,
TResourceMetadata, TResourceMetadata,
TResourceMetadataInsert, TResourceMetadataInsert,
TResourceMetadataUpdate, TResourceMetadataUpdate,
@@ -1269,22 +1269,22 @@ declare module "knex/types/tables" {
TRemindersRecipientsInsert, TRemindersRecipientsInsert,
TRemindersRecipientsUpdate TRemindersRecipientsUpdate
>; >;
[TableName.InstanceProxyConfig]: KnexOriginal.CompositeTableType<
TInstanceProxyConfig,
TInstanceProxyConfigInsert,
TInstanceProxyConfigUpdate
>;
[TableName.OrgProxyConfig]: KnexOriginal.CompositeTableType<
TOrgProxyConfig,
TOrgProxyConfigInsert,
TOrgProxyConfigUpdate
>;
[TableName.OrgGatewayConfigV2]: KnexOriginal.CompositeTableType< [TableName.OrgGatewayConfigV2]: KnexOriginal.CompositeTableType<
TOrgGatewayConfigV2, TOrgGatewayConfigV2,
TOrgGatewayConfigV2Insert, TOrgGatewayConfigV2Insert,
TOrgGatewayConfigV2Update TOrgGatewayConfigV2Update
>; >;
[TableName.Proxy]: KnexOriginal.CompositeTableType<TProxies, TProxiesInsert, TProxiesUpdate>;
[TableName.GatewayV2]: KnexOriginal.CompositeTableType<TGatewaysV2, TGatewaysV2Insert, TGatewaysV2Update>; [TableName.GatewayV2]: KnexOriginal.CompositeTableType<TGatewaysV2, TGatewaysV2Insert, TGatewaysV2Update>;
[TableName.InstanceRelayConfig]: KnexOriginal.CompositeTableType<
TInstanceRelayConfig,
TInstanceRelayConfigInsert,
TInstanceRelayConfigUpdate
>;
[TableName.OrgRelayConfig]: KnexOriginal.CompositeTableType<
TOrgRelayConfig,
TOrgRelayConfigInsert,
TOrgRelayConfigUpdate
>;
[TableName.Relay]: KnexOriginal.CompositeTableType<TRelays, TRelaysInsert, TRelaysUpdate>;
} }
} }
@@ -4,68 +4,68 @@ import { TableName } from "../schemas";
import { createOnUpdateTrigger, dropOnUpdateTrigger } from "../utils"; import { createOnUpdateTrigger, dropOnUpdateTrigger } from "../utils";
export async function up(knex: Knex): Promise<void> { export async function up(knex: Knex): Promise<void> {
if (!(await knex.schema.hasTable(TableName.InstanceProxyConfig))) { if (!(await knex.schema.hasTable(TableName.InstanceRelayConfig))) {
await knex.schema.createTable(TableName.InstanceProxyConfig, (t) => { await knex.schema.createTable(TableName.InstanceRelayConfig, (t) => {
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid()); t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
t.timestamps(true, true, true); t.timestamps(true, true, true);
// Root CA for proxy PKI // Root CA for relay PKI
t.binary("encryptedRootProxyPkiCaPrivateKey").notNullable(); t.binary("encryptedRootRelayPkiCaPrivateKey").notNullable();
t.binary("encryptedRootProxyPkiCaCertificate").notNullable(); t.binary("encryptedRootRelayPkiCaCertificate").notNullable();
// Instance CA for proxy PKI // Instance CA for relay PKI
t.binary("encryptedInstanceProxyPkiCaPrivateKey").notNullable(); t.binary("encryptedInstanceRelayPkiCaPrivateKey").notNullable();
t.binary("encryptedInstanceProxyPkiCaCertificate").notNullable(); t.binary("encryptedInstanceRelayPkiCaCertificate").notNullable();
t.binary("encryptedInstanceProxyPkiCaCertificateChain").notNullable(); t.binary("encryptedInstanceRelayPkiCaCertificateChain").notNullable();
// Instance client/server intermediates for proxy PKI // Instance client/server intermediates for relay PKI
t.binary("encryptedInstanceProxyPkiClientCaPrivateKey").notNullable(); t.binary("encryptedInstanceRelayPkiClientCaPrivateKey").notNullable();
t.binary("encryptedInstanceProxyPkiClientCaCertificate").notNullable(); t.binary("encryptedInstanceRelayPkiClientCaCertificate").notNullable();
t.binary("encryptedInstanceProxyPkiClientCaCertificateChain").notNullable(); t.binary("encryptedInstanceRelayPkiClientCaCertificateChain").notNullable();
t.binary("encryptedInstanceProxyPkiServerCaPrivateKey").notNullable(); t.binary("encryptedInstanceRelayPkiServerCaPrivateKey").notNullable();
t.binary("encryptedInstanceProxyPkiServerCaCertificate").notNullable(); t.binary("encryptedInstanceRelayPkiServerCaCertificate").notNullable();
t.binary("encryptedInstanceProxyPkiServerCaCertificateChain").notNullable(); t.binary("encryptedInstanceRelayPkiServerCaCertificateChain").notNullable();
// Org Parent CAs for proxy // Org Parent CAs for relay
t.binary("encryptedOrgProxyPkiCaPrivateKey").notNullable(); t.binary("encryptedOrgRelayPkiCaPrivateKey").notNullable();
t.binary("encryptedOrgProxyPkiCaCertificate").notNullable(); t.binary("encryptedOrgRelayPkiCaCertificate").notNullable();
t.binary("encryptedOrgProxyPkiCaCertificateChain").notNullable(); t.binary("encryptedOrgRelayPkiCaCertificateChain").notNullable();
// Instance SSH CAs for proxy // Instance SSH CAs for relay
t.binary("encryptedInstanceProxySshClientCaPrivateKey").notNullable(); t.binary("encryptedInstanceRelaySshClientCaPrivateKey").notNullable();
t.binary("encryptedInstanceProxySshClientCaPublicKey").notNullable(); t.binary("encryptedInstanceRelaySshClientCaPublicKey").notNullable();
t.binary("encryptedInstanceProxySshServerCaPrivateKey").notNullable(); t.binary("encryptedInstanceRelaySshServerCaPrivateKey").notNullable();
t.binary("encryptedInstanceProxySshServerCaPublicKey").notNullable(); t.binary("encryptedInstanceRelaySshServerCaPublicKey").notNullable();
}); });
await createOnUpdateTrigger(knex, TableName.InstanceProxyConfig); await createOnUpdateTrigger(knex, TableName.InstanceRelayConfig);
} }
// Org-level proxy configuration (one-to-one with organization) // Org-level relay configuration (one-to-one with organization)
if (!(await knex.schema.hasTable(TableName.OrgProxyConfig))) { if (!(await knex.schema.hasTable(TableName.OrgRelayConfig))) {
await knex.schema.createTable(TableName.OrgProxyConfig, (t) => { await knex.schema.createTable(TableName.OrgRelayConfig, (t) => {
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid()); t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
t.timestamps(true, true, true); t.timestamps(true, true, true);
t.uuid("orgId").notNullable().unique(); t.uuid("orgId").notNullable().unique();
t.foreign("orgId").references("id").inTable(TableName.Organization).onDelete("CASCADE"); t.foreign("orgId").references("id").inTable(TableName.Organization).onDelete("CASCADE");
// Org-scoped proxy PKI (client + server) // Org-scoped relay PKI (client + server)
t.binary("encryptedProxyPkiClientCaPrivateKey").notNullable(); t.binary("encryptedRelayPkiClientCaPrivateKey").notNullable();
t.binary("encryptedProxyPkiClientCaCertificate").notNullable(); t.binary("encryptedRelayPkiClientCaCertificate").notNullable();
t.binary("encryptedProxyPkiClientCaCertificateChain").notNullable(); t.binary("encryptedRelayPkiClientCaCertificateChain").notNullable();
t.binary("encryptedProxyPkiServerCaPrivateKey").notNullable(); t.binary("encryptedRelayPkiServerCaPrivateKey").notNullable();
t.binary("encryptedProxyPkiServerCaCertificate").notNullable(); t.binary("encryptedRelayPkiServerCaCertificate").notNullable();
t.binary("encryptedProxyPkiServerCaCertificateChain").notNullable(); t.binary("encryptedRelayPkiServerCaCertificateChain").notNullable();
// Org-scoped proxy SSH (client + server) // Org-scoped relay SSH (client + server)
t.binary("encryptedProxySshClientCaPrivateKey").notNullable(); t.binary("encryptedRelaySshClientCaPrivateKey").notNullable();
t.binary("encryptedProxySshClientCaPublicKey").notNullable(); t.binary("encryptedRelaySshClientCaPublicKey").notNullable();
t.binary("encryptedProxySshServerCaPrivateKey").notNullable(); t.binary("encryptedRelaySshServerCaPrivateKey").notNullable();
t.binary("encryptedProxySshServerCaPublicKey").notNullable(); t.binary("encryptedRelaySshServerCaPublicKey").notNullable();
}); });
await createOnUpdateTrigger(knex, TableName.OrgProxyConfig); await createOnUpdateTrigger(knex, TableName.OrgRelayConfig);
} }
if (!(await knex.schema.hasTable(TableName.OrgGatewayConfigV2))) { if (!(await knex.schema.hasTable(TableName.OrgGatewayConfigV2))) {
@@ -87,8 +87,8 @@ export async function up(knex: Knex): Promise<void> {
await createOnUpdateTrigger(knex, TableName.OrgGatewayConfigV2); await createOnUpdateTrigger(knex, TableName.OrgGatewayConfigV2);
} }
if (!(await knex.schema.hasTable(TableName.Proxy))) { if (!(await knex.schema.hasTable(TableName.Relay))) {
await knex.schema.createTable(TableName.Proxy, (t) => { await knex.schema.createTable(TableName.Relay, (t) => {
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid()); t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
t.timestamps(true, true, true); t.timestamps(true, true, true);
@@ -102,7 +102,7 @@ export async function up(knex: Knex): Promise<void> {
t.string("ip").notNullable(); t.string("ip").notNullable();
}); });
await createOnUpdateTrigger(knex, TableName.Proxy); await createOnUpdateTrigger(knex, TableName.Relay);
} }
if (!(await knex.schema.hasTable(TableName.GatewayV2))) { if (!(await knex.schema.hasTable(TableName.GatewayV2))) {
@@ -116,8 +116,8 @@ export async function up(knex: Knex): Promise<void> {
t.uuid("identityId").notNullable().unique(); t.uuid("identityId").notNullable().unique();
t.foreign("identityId").references("id").inTable(TableName.Identity).onDelete("CASCADE"); t.foreign("identityId").references("id").inTable(TableName.Identity).onDelete("CASCADE");
t.uuid("proxyId"); t.uuid("relayId");
t.foreign("proxyId").references("id").inTable(TableName.Proxy).onDelete("SET NULL"); t.foreign("relayId").references("id").inTable(TableName.Relay).onDelete("SET NULL");
t.string("name").notNullable().unique(); t.string("name").notNullable().unique();
@@ -129,11 +129,11 @@ export async function up(knex: Knex): Promise<void> {
} }
export async function down(knex: Knex): Promise<void> { export async function down(knex: Knex): Promise<void> {
await dropOnUpdateTrigger(knex, TableName.OrgProxyConfig); await dropOnUpdateTrigger(knex, TableName.OrgRelayConfig);
await knex.schema.dropTableIfExists(TableName.OrgProxyConfig); await knex.schema.dropTableIfExists(TableName.OrgRelayConfig);
await dropOnUpdateTrigger(knex, TableName.InstanceProxyConfig); await dropOnUpdateTrigger(knex, TableName.InstanceRelayConfig);
await knex.schema.dropTableIfExists(TableName.InstanceProxyConfig); await knex.schema.dropTableIfExists(TableName.InstanceRelayConfig);
await dropOnUpdateTrigger(knex, TableName.OrgGatewayConfigV2); await dropOnUpdateTrigger(knex, TableName.OrgGatewayConfigV2);
await knex.schema.dropTableIfExists(TableName.OrgGatewayConfigV2); await knex.schema.dropTableIfExists(TableName.OrgGatewayConfigV2);
@@ -141,6 +141,6 @@ export async function down(knex: Knex): Promise<void> {
await dropOnUpdateTrigger(knex, TableName.GatewayV2); await dropOnUpdateTrigger(knex, TableName.GatewayV2);
await knex.schema.dropTableIfExists(TableName.GatewayV2); await knex.schema.dropTableIfExists(TableName.GatewayV2);
await dropOnUpdateTrigger(knex, TableName.Proxy); await dropOnUpdateTrigger(knex, TableName.Relay);
await knex.schema.dropTableIfExists(TableName.Proxy); await knex.schema.dropTableIfExists(TableName.Relay);
} }
+1 -1
View File
@@ -13,7 +13,7 @@ export const GatewaysV2Schema = z.object({
updatedAt: z.date(), updatedAt: z.date(),
orgId: z.string().uuid(), orgId: z.string().uuid(),
identityId: z.string().uuid(), identityId: z.string().uuid(),
proxyId: z.string().uuid().nullable().optional(), relayId: z.string().uuid().nullable().optional(),
name: z.string(), name: z.string(),
heartbeat: z.date().nullable().optional() heartbeat: z.date().nullable().optional()
}); });
+3 -3
View File
@@ -58,7 +58,7 @@ export * from "./identity-token-auths";
export * from "./identity-ua-client-secrets"; export * from "./identity-ua-client-secrets";
export * from "./identity-universal-auths"; export * from "./identity-universal-auths";
export * from "./incident-contacts"; export * from "./incident-contacts";
export * from "./instance-proxy-config"; export * from "./instance-relay-config";
export * from "./integration-auths"; export * from "./integration-auths";
export * from "./integrations"; export * from "./integrations";
export * from "./internal-certificate-authorities"; export * from "./internal-certificate-authorities";
@@ -79,7 +79,7 @@ export * from "./org-bots";
export * from "./org-gateway-config"; export * from "./org-gateway-config";
export * from "./org-gateway-config-v2"; export * from "./org-gateway-config-v2";
export * from "./org-memberships"; export * from "./org-memberships";
export * from "./org-proxy-config"; export * from "./org-relay-config";
export * from "./org-roles"; export * from "./org-roles";
export * from "./organizations"; export * from "./organizations";
export * from "./pki-alerts"; export * from "./pki-alerts";
@@ -99,8 +99,8 @@ export * from "./project-templates";
export * from "./project-user-additional-privilege"; export * from "./project-user-additional-privilege";
export * from "./project-user-membership-roles"; export * from "./project-user-membership-roles";
export * from "./projects"; export * from "./projects";
export * from "./proxies";
export * from "./rate-limit"; export * from "./rate-limit";
export * from "./relays";
export * from "./resource-metadata"; export * from "./resource-metadata";
export * from "./saml-configs"; export * from "./saml-configs";
export * from "./scim-tokens"; export * from "./scim-tokens";
@@ -1,38 +0,0 @@
// Code generated by automation script, DO NOT EDIT.
// Automated by pulling database and generating zod schema
// To update. Just run npm run generate:schema
// Written by akhilmhdh.
import { z } from "zod";
import { zodBuffer } from "@app/lib/zod";
import { TImmutableDBKeys } from "./models";
export const InstanceProxyConfigSchema = z.object({
id: z.string().uuid(),
createdAt: z.date(),
updatedAt: z.date(),
encryptedRootProxyPkiCaPrivateKey: zodBuffer,
encryptedRootProxyPkiCaCertificate: zodBuffer,
encryptedInstanceProxyPkiCaPrivateKey: zodBuffer,
encryptedInstanceProxyPkiCaCertificate: zodBuffer,
encryptedInstanceProxyPkiCaCertificateChain: zodBuffer,
encryptedInstanceProxyPkiClientCaPrivateKey: zodBuffer,
encryptedInstanceProxyPkiClientCaCertificate: zodBuffer,
encryptedInstanceProxyPkiClientCaCertificateChain: zodBuffer,
encryptedInstanceProxyPkiServerCaPrivateKey: zodBuffer,
encryptedInstanceProxyPkiServerCaCertificate: zodBuffer,
encryptedInstanceProxyPkiServerCaCertificateChain: zodBuffer,
encryptedOrgProxyPkiCaPrivateKey: zodBuffer,
encryptedOrgProxyPkiCaCertificate: zodBuffer,
encryptedOrgProxyPkiCaCertificateChain: zodBuffer,
encryptedInstanceProxySshClientCaPrivateKey: zodBuffer,
encryptedInstanceProxySshClientCaPublicKey: zodBuffer,
encryptedInstanceProxySshServerCaPrivateKey: zodBuffer,
encryptedInstanceProxySshServerCaPublicKey: zodBuffer
});
export type TInstanceProxyConfig = z.infer<typeof InstanceProxyConfigSchema>;
export type TInstanceProxyConfigInsert = Omit<z.input<typeof InstanceProxyConfigSchema>, TImmutableDBKeys>;
export type TInstanceProxyConfigUpdate = Partial<Omit<z.input<typeof InstanceProxyConfigSchema>, TImmutableDBKeys>>;
@@ -0,0 +1,38 @@
// Code generated by automation script, DO NOT EDIT.
// Automated by pulling database and generating zod schema
// To update. Just run npm run generate:schema
// Written by akhilmhdh.
import { z } from "zod";
import { zodBuffer } from "@app/lib/zod";
import { TImmutableDBKeys } from "./models";
export const InstanceRelayConfigSchema = z.object({
id: z.string().uuid(),
createdAt: z.date(),
updatedAt: z.date(),
encryptedRootRelayPkiCaPrivateKey: zodBuffer,
encryptedRootRelayPkiCaCertificate: zodBuffer,
encryptedInstanceRelayPkiCaPrivateKey: zodBuffer,
encryptedInstanceRelayPkiCaCertificate: zodBuffer,
encryptedInstanceRelayPkiCaCertificateChain: zodBuffer,
encryptedInstanceRelayPkiClientCaPrivateKey: zodBuffer,
encryptedInstanceRelayPkiClientCaCertificate: zodBuffer,
encryptedInstanceRelayPkiClientCaCertificateChain: zodBuffer,
encryptedInstanceRelayPkiServerCaPrivateKey: zodBuffer,
encryptedInstanceRelayPkiServerCaCertificate: zodBuffer,
encryptedInstanceRelayPkiServerCaCertificateChain: zodBuffer,
encryptedOrgRelayPkiCaPrivateKey: zodBuffer,
encryptedOrgRelayPkiCaCertificate: zodBuffer,
encryptedOrgRelayPkiCaCertificateChain: zodBuffer,
encryptedInstanceRelaySshClientCaPrivateKey: zodBuffer,
encryptedInstanceRelaySshClientCaPublicKey: zodBuffer,
encryptedInstanceRelaySshServerCaPrivateKey: zodBuffer,
encryptedInstanceRelaySshServerCaPublicKey: zodBuffer
});
export type TInstanceRelayConfig = z.infer<typeof InstanceRelayConfigSchema>;
export type TInstanceRelayConfigInsert = Omit<z.input<typeof InstanceRelayConfigSchema>, TImmutableDBKeys>;
export type TInstanceRelayConfigUpdate = Partial<Omit<z.input<typeof InstanceRelayConfigSchema>, TImmutableDBKeys>>;
+3 -3
View File
@@ -181,10 +181,10 @@ export enum TableName {
ReminderRecipient = "reminders_recipients", ReminderRecipient = "reminders_recipients",
// gateway v2 // gateway v2
InstanceProxyConfig = "instance_proxy_config", InstanceRelayConfig = "instance_relay_config",
OrgProxyConfig = "org_proxy_config", OrgRelayConfig = "org_relay_config",
OrgGatewayConfigV2 = "org_gateway_config_v2", OrgGatewayConfigV2 = "org_gateway_config_v2",
Proxy = "proxies", Relay = "relays",
GatewayV2 = "gateways_v2" GatewayV2 = "gateways_v2"
} }
@@ -1,31 +0,0 @@
// Code generated by automation script, DO NOT EDIT.
// Automated by pulling database and generating zod schema
// To update. Just run npm run generate:schema
// Written by akhilmhdh.
import { z } from "zod";
import { zodBuffer } from "@app/lib/zod";
import { TImmutableDBKeys } from "./models";
export const OrgProxyConfigSchema = z.object({
id: z.string().uuid(),
createdAt: z.date(),
updatedAt: z.date(),
orgId: z.string().uuid(),
encryptedProxyPkiClientCaPrivateKey: zodBuffer,
encryptedProxyPkiClientCaCertificate: zodBuffer,
encryptedProxyPkiClientCaCertificateChain: zodBuffer,
encryptedProxyPkiServerCaPrivateKey: zodBuffer,
encryptedProxyPkiServerCaCertificate: zodBuffer,
encryptedProxyPkiServerCaCertificateChain: zodBuffer,
encryptedProxySshClientCaPrivateKey: zodBuffer,
encryptedProxySshClientCaPublicKey: zodBuffer,
encryptedProxySshServerCaPrivateKey: zodBuffer,
encryptedProxySshServerCaPublicKey: zodBuffer
});
export type TOrgProxyConfig = z.infer<typeof OrgProxyConfigSchema>;
export type TOrgProxyConfigInsert = Omit<z.input<typeof OrgProxyConfigSchema>, TImmutableDBKeys>;
export type TOrgProxyConfigUpdate = Partial<Omit<z.input<typeof OrgProxyConfigSchema>, TImmutableDBKeys>>;
@@ -0,0 +1,31 @@
// Code generated by automation script, DO NOT EDIT.
// Automated by pulling database and generating zod schema
// To update. Just run npm run generate:schema
// Written by akhilmhdh.
import { z } from "zod";
import { zodBuffer } from "@app/lib/zod";
import { TImmutableDBKeys } from "./models";
export const OrgRelayConfigSchema = z.object({
id: z.string().uuid(),
createdAt: z.date(),
updatedAt: z.date(),
orgId: z.string().uuid(),
encryptedRelayPkiClientCaPrivateKey: zodBuffer,
encryptedRelayPkiClientCaCertificate: zodBuffer,
encryptedRelayPkiClientCaCertificateChain: zodBuffer,
encryptedRelayPkiServerCaPrivateKey: zodBuffer,
encryptedRelayPkiServerCaCertificate: zodBuffer,
encryptedRelayPkiServerCaCertificateChain: zodBuffer,
encryptedRelaySshClientCaPrivateKey: zodBuffer,
encryptedRelaySshClientCaPublicKey: zodBuffer,
encryptedRelaySshServerCaPrivateKey: zodBuffer,
encryptedRelaySshServerCaPublicKey: zodBuffer
});
export type TOrgRelayConfig = z.infer<typeof OrgRelayConfigSchema>;
export type TOrgRelayConfigInsert = Omit<z.input<typeof OrgRelayConfigSchema>, TImmutableDBKeys>;
export type TOrgRelayConfigUpdate = Partial<Omit<z.input<typeof OrgRelayConfigSchema>, TImmutableDBKeys>>;
@@ -7,7 +7,7 @@ import { z } from "zod";
import { TImmutableDBKeys } from "./models"; import { TImmutableDBKeys } from "./models";
export const ProxiesSchema = z.object({ export const RelaysSchema = z.object({
id: z.string().uuid(), id: z.string().uuid(),
createdAt: z.date(), createdAt: z.date(),
updatedAt: z.date(), updatedAt: z.date(),
@@ -17,6 +17,6 @@ export const ProxiesSchema = z.object({
ip: z.string() ip: z.string()
}); });
export type TProxies = z.infer<typeof ProxiesSchema>; export type TRelays = z.infer<typeof RelaysSchema>;
export type TProxiesInsert = Omit<z.input<typeof ProxiesSchema>, TImmutableDBKeys>; export type TRelaysInsert = Omit<z.input<typeof RelaysSchema>, TImmutableDBKeys>;
export type TProxiesUpdate = Partial<Omit<z.input<typeof ProxiesSchema>, TImmutableDBKeys>>; export type TRelaysUpdate = Partial<Omit<z.input<typeof RelaysSchema>, TImmutableDBKeys>>;
+2 -2
View File
@@ -23,8 +23,8 @@ import { registerOrgRoleRouter } from "./org-role-router";
import { registerPITRouter } from "./pit-router"; import { registerPITRouter } from "./pit-router";
import { registerProjectRoleRouter } from "./project-role-router"; import { registerProjectRoleRouter } from "./project-role-router";
import { registerProjectRouter } from "./project-router"; import { registerProjectRouter } from "./project-router";
import { registerProxyRouter } from "./proxy-router";
import { registerRateLimitRouter } from "./rate-limit-router"; import { registerRateLimitRouter } from "./rate-limit-router";
import { registerRelayRouter } from "./relay-router";
import { registerSamlRouter } from "./saml-router"; import { registerSamlRouter } from "./saml-router";
import { registerScimRouter } from "./scim-router"; import { registerScimRouter } from "./scim-router";
import { registerSecretApprovalPolicyRouter } from "./secret-approval-policy-router"; import { registerSecretApprovalPolicyRouter } from "./secret-approval-policy-router";
@@ -80,7 +80,7 @@ export const registerV1EERoutes = async (server: FastifyZodProvider) => {
); );
await server.register(registerGatewayRouter, { prefix: "/gateways" }); await server.register(registerGatewayRouter, { prefix: "/gateways" });
await server.register(registerProxyRouter, { prefix: "/proxies" }); await server.register(registerRelayRouter, { prefix: "/relays" });
await server.register(registerGithubOrgSyncRouter, { prefix: "/github-org-sync-config" }); await server.register(registerGithubOrgSyncRouter, { prefix: "/github-org-sync-config" });
await server.register( await server.register(
@@ -7,12 +7,12 @@ import { writeLimit } from "@app/server/config/rateLimiter";
import { verifyAuth } from "@app/server/plugins/auth/verify-auth"; import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
import { AuthMode } from "@app/services/auth/auth-type"; import { AuthMode } from "@app/services/auth/auth-type";
export const registerProxyRouter = async (server: FastifyZodProvider) => { export const registerRelayRouter = async (server: FastifyZodProvider) => {
const appCfg = getConfig(); const appCfg = getConfig();
server.route({ server.route({
method: "POST", method: "POST",
url: "/register-instance-proxy", url: "/register-instance-relay",
config: { config: {
rateLimit: writeLimit rateLimit: writeLimit
}, },
@@ -39,8 +39,8 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
onRequest: (req, _, next) => { onRequest: (req, _, next) => {
const authHeader = req.headers.authorization; const authHeader = req.headers.authorization;
if (appCfg.PROXY_AUTH_SECRET && authHeader) { if (appCfg.RELAY_AUTH_SECRET && authHeader) {
const expectedHeader = `Bearer ${appCfg.PROXY_AUTH_SECRET}`; const expectedHeader = `Bearer ${appCfg.RELAY_AUTH_SECRET}`;
if ( if (
authHeader.length === expectedHeader.length && authHeader.length === expectedHeader.length &&
crypto.nativeCrypto.timingSafeEqual(Buffer.from(authHeader), Buffer.from(expectedHeader)) crypto.nativeCrypto.timingSafeEqual(Buffer.from(authHeader), Buffer.from(expectedHeader))
@@ -50,11 +50,11 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
} }
throw new UnauthorizedError({ throw new UnauthorizedError({
message: "Invalid proxy auth secret" message: "Invalid relay auth secret"
}); });
}, },
handler: async (req) => { handler: async (req) => {
return server.services.proxy.registerProxy({ return server.services.relay.registerRelay({
...req.body ...req.body
}); });
} }
@@ -62,7 +62,7 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
server.route({ server.route({
method: "POST", method: "POST",
url: "/register-org-proxy", url: "/register-org-relay",
config: { config: {
rateLimit: writeLimit rateLimit: writeLimit
}, },
@@ -89,10 +89,10 @@ export const registerProxyRouter = async (server: FastifyZodProvider) => {
onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]), onRequest: verifyAuth([AuthMode.IDENTITY_ACCESS_TOKEN]),
handler: async (req) => { handler: async (req) => {
throw new BadRequestError({ throw new BadRequestError({
message: "Org proxy registration is not yet supported" message: "Org relay registration is not yet supported"
}); });
return server.services.proxy.registerProxy({ return server.services.relay.registerRelay({
...req.body, ...req.body,
identityId: req.permission.id, identityId: req.permission.id,
orgId: req.permission.orgId orgId: req.permission.orgId
@@ -79,9 +79,9 @@ export const KubernetesProvider = ({
); );
}, },
{ {
proxyIp: gatewayV2ConnectionDetails.proxyIp, relayIp: gatewayV2ConnectionDetails.relayIp,
gateway: gatewayV2ConnectionDetails.gateway, gateway: gatewayV2ConnectionDetails.gateway,
proxy: gatewayV2ConnectionDetails.proxy, relay: gatewayV2ConnectionDetails.relay,
protocol: inputs.reviewTokenThroughGateway ? GatewayProxyProtocol.Http : GatewayProxyProtocol.Tcp, protocol: inputs.reviewTokenThroughGateway ? GatewayProxyProtocol.Http : GatewayProxyProtocol.Tcp,
httpsAgent: inputs.httpsAgent httpsAgent: inputs.httpsAgent
} }
@@ -201,9 +201,9 @@ export const SqlDatabaseProvider = ({
await gatewayCallback("localhost", port); await gatewayCallback("localhost", port);
}, },
{ {
proxyIp: gatewayV2ConnectionDetails.proxyIp, relayIp: gatewayV2ConnectionDetails.relayIp,
gateway: gatewayV2ConnectionDetails.gateway, gateway: gatewayV2ConnectionDetails.gateway,
proxy: gatewayV2ConnectionDetails.proxy, relay: gatewayV2ConnectionDetails.relay,
protocol: GatewayProxyProtocol.Tcp protocol: GatewayProxyProtocol.Tcp
} }
); );
@@ -3,7 +3,7 @@ import net from "node:net";
import { ForbiddenError } from "@casl/ability"; import { ForbiddenError } from "@casl/ability";
import * as x509 from "@peculiar/x509"; import * as x509 from "@peculiar/x509";
import { TProxies } from "@app/db/schemas"; import { TRelays } from "@app/db/schemas";
import { PgSqlLock } from "@app/keystore/keystore"; import { PgSqlLock } from "@app/keystore/keystore";
import { crypto } from "@app/lib/crypto"; import { crypto } from "@app/lib/crypto";
import { DatabaseErrorCode } from "@app/lib/error-codes"; import { DatabaseErrorCode } from "@app/lib/error-codes";
@@ -24,9 +24,9 @@ import { KmsDataKey } from "@app/services/kms/kms-types";
import { TLicenseServiceFactory } from "../license/license-service"; import { TLicenseServiceFactory } from "../license/license-service";
import { OrgPermissionGatewayActions, OrgPermissionSubjects } from "../permission/org-permission"; import { OrgPermissionGatewayActions, OrgPermissionSubjects } from "../permission/org-permission";
import { TPermissionServiceFactory } from "../permission/permission-service-types"; import { TPermissionServiceFactory } from "../permission/permission-service-types";
import { TProxyDALFactory } from "../proxy/proxy-dal"; import { TRelayDALFactory } from "../relay/relay-dal";
import { isInstanceProxy } from "../proxy/proxy-fns"; import { isInstanceRelay } from "../relay/relay-fns";
import { TProxyServiceFactory } from "../proxy/proxy-service"; import { TRelayServiceFactory } from "../relay/relay-service";
import { GATEWAY_ACTOR_OID, GATEWAY_ROUTING_INFO_OID } from "./gateway-v2-constants"; import { GATEWAY_ACTOR_OID, GATEWAY_ROUTING_INFO_OID } from "./gateway-v2-constants";
import { TGatewayV2DALFactory } from "./gateway-v2-dal"; import { TGatewayV2DALFactory } from "./gateway-v2-dal";
import { TOrgGatewayConfigV2DALFactory } from "./org-gateway-config-v2-dal"; import { TOrgGatewayConfigV2DALFactory } from "./org-gateway-config-v2-dal";
@@ -35,9 +35,9 @@ type TGatewayV2ServiceFactoryDep = {
orgGatewayConfigV2DAL: Pick<TOrgGatewayConfigV2DALFactory, "findOne" | "create" | "transaction" | "findById">; orgGatewayConfigV2DAL: Pick<TOrgGatewayConfigV2DALFactory, "findOne" | "create" | "transaction" | "findById">;
licenseService: Pick<TLicenseServiceFactory, "onPremFeatures" | "getPlan">; licenseService: Pick<TLicenseServiceFactory, "onPremFeatures" | "getPlan">;
kmsService: TKmsServiceFactory; kmsService: TKmsServiceFactory;
proxyService: TProxyServiceFactory; relayService: TRelayServiceFactory;
gatewayV2DAL: TGatewayV2DALFactory; gatewayV2DAL: TGatewayV2DALFactory;
proxyDAL: TProxyDALFactory; relayDAL: TRelayDALFactory;
permissionService: TPermissionServiceFactory; permissionService: TPermissionServiceFactory;
}; };
@@ -47,9 +47,9 @@ export const gatewayV2ServiceFactory = ({
orgGatewayConfigV2DAL, orgGatewayConfigV2DAL,
licenseService, licenseService,
kmsService, kmsService,
proxyService, relayService,
gatewayV2DAL, gatewayV2DAL,
proxyDAL, relayDAL,
permissionService permissionService
}: TGatewayV2ServiceFactoryDep) => { }: TGatewayV2ServiceFactoryDep) => {
const $validateIdentityAccessToGateway = async (orgId: string, actorId: string, actorAuthMethod: ActorAuthMethod) => { const $validateIdentityAccessToGateway = async (orgId: string, actorId: string, actorAuthMethod: ActorAuthMethod) => {
@@ -285,9 +285,9 @@ export const gatewayV2ServiceFactory = ({
throw new NotFoundError({ message: `Gateway Config for org ${gateway.orgId} not found.` }); throw new NotFoundError({ message: `Gateway Config for org ${gateway.orgId} not found.` });
} }
if (!gateway.proxyId) { if (!gateway.relayId) {
throw new BadRequestError({ throw new BadRequestError({
message: "Gateway is not associated with a proxy" message: "Gateway is not associated with a relay"
}); });
} }
@@ -392,23 +392,23 @@ export const gatewayV2ServiceFactory = ({
const gatewayClientCertPrivateKey = crypto.nativeCrypto.KeyObject.from(clientKeys.privateKey); const gatewayClientCertPrivateKey = crypto.nativeCrypto.KeyObject.from(clientKeys.privateKey);
const proxyCredentials = await proxyService.getCredentialsForClient({ const relayCredentials = await relayService.getCredentialsForClient({
proxyId: gateway.proxyId, relayId: gateway.relayId,
orgId: gateway.orgId, orgId: gateway.orgId,
gatewayId gatewayId
}); });
return { return {
proxyIp: proxyCredentials.proxyIp, relayIp: relayCredentials.relayIp,
gateway: { gateway: {
clientCertificate: clientCert.toString("pem"), clientCertificate: clientCert.toString("pem"),
clientPrivateKey: gatewayClientCertPrivateKey.export({ format: "pem", type: "pkcs8" }).toString(), clientPrivateKey: gatewayClientCertPrivateKey.export({ format: "pem", type: "pkcs8" }).toString(),
serverCertificateChain: constructPemChainFromCerts([gatewayServerCaCert, rootGatewayCaCert]) serverCertificateChain: constructPemChainFromCerts([gatewayServerCaCert, rootGatewayCaCert])
}, },
proxy: { relay: {
clientCertificate: proxyCredentials.clientCertificate, clientCertificate: relayCredentials.clientCertificate,
clientPrivateKey: proxyCredentials.clientPrivateKey, clientPrivateKey: relayCredentials.clientPrivateKey,
serverCertificateChain: proxyCredentials.serverCertificateChain serverCertificateChain: relayCredentials.serverCertificateChain
} }
}; };
}; };
@@ -417,27 +417,27 @@ export const gatewayV2ServiceFactory = ({
orgId, orgId,
actorId, actorId,
actorAuthMethod, actorAuthMethod,
proxyName, relayName,
name name
}: { }: {
orgId: string; orgId: string;
actorId: string; actorId: string;
actorAuthMethod: ActorAuthMethod; actorAuthMethod: ActorAuthMethod;
proxyName: string; relayName: string;
name: string; name: string;
}) => { }) => {
await $validateIdentityAccessToGateway(orgId, actorId, actorAuthMethod); await $validateIdentityAccessToGateway(orgId, actorId, actorAuthMethod);
const orgCAs = await $getOrgCAs(orgId); const orgCAs = await $getOrgCAs(orgId);
let proxy: TProxies; let relay: TRelays;
if (isInstanceProxy(proxyName)) { if (isInstanceRelay(relayName)) {
proxy = await proxyDAL.findOne({ name: proxyName }); relay = await relayDAL.findOne({ name: relayName });
} else { } else {
proxy = await proxyDAL.findOne({ orgId, name: proxyName }); relay = await relayDAL.findOne({ orgId, name: relayName });
} }
if (!proxy) { if (!relay) {
throw new NotFoundError({ message: `Proxy ${proxyName} not found` }); throw new NotFoundError({ message: `Relay ${relayName} not found` });
} }
try { try {
@@ -447,7 +447,7 @@ export const gatewayV2ServiceFactory = ({
orgId, orgId,
name, name,
identityId: actorId, identityId: actorId,
proxyId: proxy.id relayId: relay.id
} }
], ],
["identityId"] ["identityId"]
@@ -507,24 +507,24 @@ export const gatewayV2ServiceFactory = ({
extensions: gatewayServerCertExtensions extensions: gatewayServerCertExtensions
}); });
const proxyCredentials = await proxyService.getCredentialsForGateway({ const relayCredentials = await relayService.getCredentialsForGateway({
proxyName, relayName,
orgId, orgId,
gatewayId: gateway.id gatewayId: gateway.id
}); });
return { return {
gatewayId: gateway.id, gatewayId: gateway.id,
proxyIp: proxyCredentials.proxyIp, relayIp: relayCredentials.relayIp,
pki: { pki: {
serverCertificate: gatewayServerCertificate.toString("pem"), serverCertificate: gatewayServerCertificate.toString("pem"),
serverPrivateKey: gatewayServerCertPrivateKey.export({ format: "pem", type: "pkcs8" }).toString(), serverPrivateKey: gatewayServerCertPrivateKey.export({ format: "pem", type: "pkcs8" }).toString(),
clientCertificateChain: constructPemChainFromCerts([gatewayClientCaCert, rootGatewayCaCert]) clientCertificateChain: constructPemChainFromCerts([gatewayClientCaCert, rootGatewayCaCert])
}, },
ssh: { ssh: {
clientCertificate: proxyCredentials.clientSshCert, clientCertificate: relayCredentials.clientSshCert,
clientPrivateKey: proxyCredentials.clientSshPrivateKey, clientPrivateKey: relayCredentials.clientSshPrivateKey,
serverCAPublicKey: proxyCredentials.serverCAPublicKey serverCAPublicKey: relayCredentials.serverCAPublicKey
} }
}; };
} catch (err) { } catch (err) {
@@ -613,9 +613,9 @@ export const gatewayV2ServiceFactory = ({
}, },
{ {
protocol: GatewayProxyProtocol.Ping, protocol: GatewayProxyProtocol.Ping,
proxyIp: gatewayV2ConnectionDetails.proxyIp, relayIp: gatewayV2ConnectionDetails.relayIp,
gateway: gatewayV2ConnectionDetails.gateway, gateway: gatewayV2ConnectionDetails.gateway,
proxy: gatewayV2ConnectionDetails.proxy relay: gatewayV2ConnectionDetails.relay
} }
); );
@@ -1,11 +0,0 @@
import { TDbClient } from "@app/db";
import { TableName } from "@app/db/schemas";
import { ormify } from "@app/lib/knex";
export type TInstanceProxyConfigDALFactory = ReturnType<typeof instanceProxyConfigDalFactory>;
export const instanceProxyConfigDalFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.InstanceProxyConfig);
return orm;
};
@@ -1,11 +0,0 @@
import { TDbClient } from "@app/db";
import { TableName } from "@app/db/schemas";
import { ormify } from "@app/lib/knex";
export type TOrgProxyConfigDALFactory = ReturnType<typeof orgProxyConfigDalFactory>;
export const orgProxyConfigDalFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.OrgProxyConfig);
return orm;
};
@@ -1,11 +0,0 @@
import { TDbClient } from "@app/db";
import { TableName } from "@app/db/schemas";
import { ormify } from "@app/lib/knex";
export type TProxyDALFactory = ReturnType<typeof proxyDalFactory>;
export const proxyDalFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.Proxy);
return orm;
};
@@ -1,5 +0,0 @@
export const INSTANCE_PROXY_PREFIX = "infisical-";
export const isInstanceProxy = (proxyName: string) => {
return proxyName.startsWith(INSTANCE_PROXY_PREFIX);
};
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,11 @@
import { TDbClient } from "@app/db";
import { TableName } from "@app/db/schemas";
import { ormify } from "@app/lib/knex";
export type TInstanceRelayConfigDALFactory = ReturnType<typeof instanceRelayConfigDalFactory>;
export const instanceRelayConfigDalFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.InstanceRelayConfig);
return orm;
};
@@ -0,0 +1,11 @@
import { TDbClient } from "@app/db";
import { TableName } from "@app/db/schemas";
import { ormify } from "@app/lib/knex";
export type TOrgRelayConfigDALFactory = ReturnType<typeof orgRelayConfigDalFactory>;
export const orgRelayConfigDalFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.OrgRelayConfig);
return orm;
};
@@ -0,0 +1,11 @@
import { TDbClient } from "@app/db";
import { TableName } from "@app/db/schemas";
import { ormify } from "@app/lib/knex";
export type TRelayDALFactory = ReturnType<typeof relayDalFactory>;
export const relayDalFactory = (db: TDbClient) => {
const orm = ormify(db, TableName.Relay);
return orm;
};
@@ -0,0 +1,5 @@
export const INSTANCE_RELAY_PREFIX = "infisical-";
export const isInstanceRelay = (relayName: string) => {
return relayName.startsWith(INSTANCE_RELAY_PREFIX);
};
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -14,9 +14,9 @@ export const PgSqlLock = {
CreateProject: (orgId: string) => pgAdvisoryLockHashText(`create-project:${orgId}`), CreateProject: (orgId: string) => pgAdvisoryLockHashText(`create-project:${orgId}`),
CreateFolder: (envId: string, projectId: string) => pgAdvisoryLockHashText(`create-folder:${envId}-${projectId}`), CreateFolder: (envId: string, projectId: string) => pgAdvisoryLockHashText(`create-folder:${envId}-${projectId}`),
SshInit: (projectId: string) => pgAdvisoryLockHashText(`ssh-bootstrap:${projectId}`), SshInit: (projectId: string) => pgAdvisoryLockHashText(`ssh-bootstrap:${projectId}`),
InstanceProxyConfigInit: () => pgAdvisoryLockHashText("instance-proxy-config-init"), InstanceRelayConfigInit: () => pgAdvisoryLockHashText("instance-relay-config-init"),
OrgGatewayV2Init: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-v2-init:${orgId}`), OrgGatewayV2Init: (orgId: string) => pgAdvisoryLockHashText(`org-gateway-v2-init:${orgId}`),
OrgProxyConfigInit: (orgId: string) => pgAdvisoryLockHashText(`org-proxy-config-init:${orgId}`), OrgRelayConfigInit: (orgId: string) => pgAdvisoryLockHashText(`org-relay-config-init:${orgId}`),
IdentityLogin: (identityId: string, nonce: string) => pgAdvisoryLockHashText(`identity-login:${identityId}:${nonce}`) IdentityLogin: (identityId: string, nonce: string) => pgAdvisoryLockHashText(`identity-login:${identityId}:${nonce}`)
} as const; } as const;
+1 -1
View File
@@ -233,7 +233,7 @@ const envSchema = z
GATEWAY_RELAY_REALM: zpStr(z.string().optional()), GATEWAY_RELAY_REALM: zpStr(z.string().optional()),
GATEWAY_RELAY_AUTH_SECRET: zpStr(z.string().optional()), GATEWAY_RELAY_AUTH_SECRET: zpStr(z.string().optional()),
PROXY_AUTH_SECRET: zpStr(z.string().optional()), RELAY_AUTH_SECRET: zpStr(z.string().optional()),
DYNAMIC_SECRET_ALLOW_INTERNAL_IP: zodStrBool.default("false"), DYNAMIC_SECRET_ALLOW_INTERNAL_IP: zodStrBool.default("false"),
DYNAMIC_SECRET_AWS_ACCESS_KEY_ID: zpStr(z.string().optional()).default( DYNAMIC_SECRET_AWS_ACCESS_KEY_ID: zpStr(z.string().optional()).default(
+40 -40
View File
@@ -11,26 +11,26 @@ import { BadRequestError } from "../errors";
import { GatewayProxyProtocol } from "../gateway/types"; import { GatewayProxyProtocol } from "../gateway/types";
import { logger } from "../logger"; import { logger } from "../logger";
interface IGatewayProxyServer { interface IGatewayRelayServer {
server: net.Server; server: net.Server;
port: number; port: number;
cleanup: () => Promise<void>; cleanup: () => Promise<void>;
getProxyError: () => string; getRelayError: () => string;
} }
const createProxyConnection = async ({ const createRelayConnection = async ({
proxyIp, relayIp,
clientCertificate, clientCertificate,
clientPrivateKey, clientPrivateKey,
serverCertificateChain serverCertificateChain
}: { }: {
proxyIp: string; relayIp: string;
clientCertificate: string; clientCertificate: string;
clientPrivateKey: string; clientPrivateKey: string;
serverCertificateChain: string; serverCertificateChain: string;
}): Promise<net.Socket> => { }): Promise<net.Socket> => {
const [targetHost] = await verifyHostInputValidity(proxyIp); const [targetHost] = await verifyHostInputValidity(relayIp);
const [, portStr] = proxyIp.split(":"); const [, portStr] = relayIp.split(":");
const port = parseInt(portStr, 10) || 8443; const port = parseInt(portStr, 10) || 8443;
const serverCAs = splitPemChain(serverCertificateChain); const serverCAs = splitPemChain(serverCertificateChain);
@@ -47,7 +47,7 @@ const createProxyConnection = async ({
return new Promise((resolve, reject) => { return new Promise((resolve, reject) => {
try { try {
const socket = tls.connect(tlsOptions, () => { const socket = tls.connect(tlsOptions, () => {
logger.info("Proxy TLS connection established successfully"); logger.info("Relay TLS connection established successfully");
resolve(socket); resolve(socket);
}); });
@@ -75,11 +75,11 @@ const createProxyConnection = async ({
}; };
const createGatewayConnection = async ( const createGatewayConnection = async (
proxyConn: net.Socket, relayConn: net.Socket,
gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string } gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string }
): Promise<net.Socket> => { ): Promise<net.Socket> => {
const tlsOptions: tls.ConnectionOptions = { const tlsOptions: tls.ConnectionOptions = {
socket: proxyConn, socket: relayConn,
cert: gateway.clientCertificate, cert: gateway.clientCertificate,
key: gateway.clientPrivateKey, key: gateway.clientPrivateKey,
ca: splitPemChain(gateway.serverCertificateChain), ca: splitPemChain(gateway.serverCertificateChain),
@@ -119,20 +119,20 @@ const createGatewayConnection = async (
}); });
}; };
const setupProxyServer = async ({ const setupRelayServer = async ({
protocol, protocol,
proxyIp, relayIp,
gateway, gateway,
proxy, relay,
httpsAgent httpsAgent
}: { }: {
protocol: GatewayProxyProtocol; protocol: GatewayProxyProtocol;
proxyIp: string; relayIp: string;
gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string }; gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
proxy: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string }; relay: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
httpsAgent?: https.Agent; httpsAgent?: https.Agent;
}): Promise<IGatewayProxyServer> => { }): Promise<IGatewayRelayServer> => {
const proxyErrorMsg: string[] = []; const relayErrorMsg: string[] = [];
return new Promise((resolve, reject) => { return new Promise((resolve, reject) => {
const server = net.createServer(); const server = net.createServer();
@@ -143,16 +143,16 @@ const setupProxyServer = async ({
clientConn.setKeepAlive(true, 30000); clientConn.setKeepAlive(true, 30000);
clientConn.setNoDelay(true); clientConn.setNoDelay(true);
// Stage 1: Connect to proxy relay with TLS // Stage 1: Connect to relay with TLS
const proxyConn = await createProxyConnection({ const relayConn = await createRelayConnection({
proxyIp, relayIp,
clientCertificate: proxy.clientCertificate, clientCertificate: relay.clientCertificate,
clientPrivateKey: proxy.clientPrivateKey, clientPrivateKey: relay.clientPrivateKey,
serverCertificateChain: proxy.serverCertificateChain serverCertificateChain: relay.serverCertificateChain
}); });
// Stage 2: Establish mTLS connection to gateway through the proxy // Stage 2: Establish mTLS connection to gateway through the relay
const gatewayConn = await createGatewayConnection(proxyConn, gateway); const gatewayConn = await createGatewayConnection(relayConn, gateway);
let command = ""; let command = "";
@@ -191,22 +191,22 @@ const setupProxyServer = async ({
// Handle connection closure // Handle connection closure
clientConn.on("close", () => { clientConn.on("close", () => {
proxyConn.destroy(); relayConn.destroy();
gatewayConn.destroy(); gatewayConn.destroy();
}); });
proxyConn.on("close", () => { relayConn.on("close", () => {
clientConn.destroy(); clientConn.destroy();
gatewayConn.destroy(); gatewayConn.destroy();
}); });
gatewayConn.on("close", () => { gatewayConn.on("close", () => {
clientConn.destroy(); clientConn.destroy();
proxyConn.destroy(); relayConn.destroy();
}); });
} catch (err) { } catch (err) {
const errorMsg = err instanceof Error ? err.message : String(err); const errorMsg = err instanceof Error ? err.message : String(err);
proxyErrorMsg.push(errorMsg); relayErrorMsg.push(errorMsg);
clientConn.destroy(); clientConn.destroy();
} }
})(); })();
@@ -234,7 +234,7 @@ const setupProxyServer = async ({
logger.debug("Error closing server:", err instanceof Error ? err.message : String(err)); logger.debug("Error closing server:", err instanceof Error ? err.message : String(err));
} }
}, },
getProxyError: () => proxyErrorMsg.join(",") getRelayError: () => relayErrorMsg.join(",")
}); });
}); });
}); });
@@ -244,19 +244,19 @@ export const withGatewayV2Proxy = async <T>(
callback: (port: number) => Promise<T>, callback: (port: number) => Promise<T>,
options: { options: {
protocol: GatewayProxyProtocol; protocol: GatewayProxyProtocol;
proxyIp: string; relayIp: string;
gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string }; gateway: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
proxy: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string }; relay: { clientCertificate: string; clientPrivateKey: string; serverCertificateChain: string };
httpsAgent?: https.Agent; httpsAgent?: https.Agent;
} }
): Promise<T> => { ): Promise<T> => {
const { protocol, proxyIp, gateway, proxy, httpsAgent } = options; const { protocol, relayIp, gateway, relay, httpsAgent } = options;
const { port, cleanup, getProxyError } = await setupProxyServer({ const { port, cleanup, getRelayError } = await setupRelayServer({
protocol, protocol,
proxyIp, relayIp,
gateway, gateway,
proxy, relay,
httpsAgent httpsAgent
}); });
@@ -264,12 +264,12 @@ export const withGatewayV2Proxy = async <T>(
// Execute the callback with the allocated port // Execute the callback with the allocated port
return await callback(port); return await callback(port);
} catch (err) { } catch (err) {
const proxyErrorMessage = getProxyError(); const relayErrorMessage = getRelayError();
if (proxyErrorMessage) { if (relayErrorMessage) {
logger.error("Proxy error:", proxyErrorMessage); logger.error("Relay error:", relayErrorMessage);
} }
logger.error("Gateway error:", err instanceof Error ? err.message : String(err)); logger.error("Gateway error:", err instanceof Error ? err.message : String(err));
let errorMessage = proxyErrorMessage || (err instanceof Error ? err.message : String(err)); let errorMessage = relayErrorMessage || (err instanceof Error ? err.message : String(err));
if (axios.isAxiosError(err) && (err.response?.data as { message?: string })?.message) { if (axios.isAxiosError(err) && (err.response?.data as { message?: string })?.message) {
errorMessage = (err.response?.data as { message: string }).message; errorMessage = (err.response?.data as { message: string }).message;
} }
@@ -122,7 +122,7 @@ export const injectIdentity = fp(async (server: FastifyZodProvider) => {
} }
// Authentication is handled on a route-level // Authentication is handled on a route-level
if (req.url === "/api/v1/proxies/register-instance-proxy") { if (req.url === "/api/v1/proxies/register-instance-relay") {
return; return;
} }
+14 -14
View File
@@ -73,12 +73,12 @@ import { projectTemplateDALFactory } from "@app/ee/services/project-template/pro
import { projectTemplateServiceFactory } from "@app/ee/services/project-template/project-template-service"; import { projectTemplateServiceFactory } from "@app/ee/services/project-template/project-template-service";
import { projectUserAdditionalPrivilegeDALFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-dal"; import { projectUserAdditionalPrivilegeDALFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-dal";
import { projectUserAdditionalPrivilegeServiceFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-service"; import { projectUserAdditionalPrivilegeServiceFactory } from "@app/ee/services/project-user-additional-privilege/project-user-additional-privilege-service";
import { instanceProxyConfigDalFactory } from "@app/ee/services/proxy/instance-proxy-config-dal";
import { orgProxyConfigDalFactory } from "@app/ee/services/proxy/org-proxy-config-dal";
import { proxyDalFactory } from "@app/ee/services/proxy/proxy-dal";
import { proxyServiceFactory } from "@app/ee/services/proxy/proxy-service";
import { rateLimitDALFactory } from "@app/ee/services/rate-limit/rate-limit-dal"; import { rateLimitDALFactory } from "@app/ee/services/rate-limit/rate-limit-dal";
import { rateLimitServiceFactory } from "@app/ee/services/rate-limit/rate-limit-service"; import { rateLimitServiceFactory } from "@app/ee/services/rate-limit/rate-limit-service";
import { instanceRelayConfigDalFactory } from "@app/ee/services/relay/instance-relay-config-dal";
import { orgRelayConfigDalFactory } from "@app/ee/services/relay/org-relay-config-dal";
import { relayDalFactory } from "@app/ee/services/relay/relay-dal";
import { relayServiceFactory } from "@app/ee/services/relay/relay-service";
import { samlConfigDALFactory } from "@app/ee/services/saml-config/saml-config-dal"; import { samlConfigDALFactory } from "@app/ee/services/saml-config/saml-config-dal";
import { samlConfigServiceFactory } from "@app/ee/services/saml-config/saml-config-service"; import { samlConfigServiceFactory } from "@app/ee/services/saml-config/saml-config-service";
import { scimDALFactory } from "@app/ee/services/scim/scim-dal"; import { scimDALFactory } from "@app/ee/services/scim/scim-dal";
@@ -948,9 +948,9 @@ export const registerRoutes = async (
const pkiSubscriberDAL = pkiSubscriberDALFactory(db); const pkiSubscriberDAL = pkiSubscriberDALFactory(db);
const pkiTemplatesDAL = pkiTemplatesDALFactory(db); const pkiTemplatesDAL = pkiTemplatesDALFactory(db);
const instanceProxyConfigDAL = instanceProxyConfigDalFactory(db); const instanceRelayConfigDAL = instanceRelayConfigDalFactory(db);
const orgProxyConfigDAL = orgProxyConfigDalFactory(db); const orgRelayConfigDAL = orgRelayConfigDalFactory(db);
const proxyDAL = proxyDalFactory(db); const relayDAL = relayDalFactory(db);
const gatewayV2DAL = gatewayV2DalFactory(db); const gatewayV2DAL = gatewayV2DalFactory(db);
const orgGatewayConfigV2DAL = orgGatewayConfigV2DalFactory(db); const orgGatewayConfigV2DAL = orgGatewayConfigV2DalFactory(db);
@@ -1073,20 +1073,20 @@ export const registerRoutes = async (
keyStore keyStore
}); });
const proxyService = proxyServiceFactory({ const relayService = relayServiceFactory({
instanceProxyConfigDAL, instanceRelayConfigDAL,
orgProxyConfigDAL, orgRelayConfigDAL,
proxyDAL, relayDAL,
kmsService kmsService
}); });
const gatewayV2Service = gatewayV2ServiceFactory({ const gatewayV2Service = gatewayV2ServiceFactory({
kmsService, kmsService,
licenseService, licenseService,
proxyService, relayService,
orgGatewayConfigV2DAL, orgGatewayConfigV2DAL,
gatewayV2DAL, gatewayV2DAL,
proxyDAL, relayDAL,
permissionService permissionService
}); });
@@ -2138,7 +2138,7 @@ export const registerRoutes = async (
reminder: reminderService, reminder: reminderService,
bus: eventBusService, bus: eventBusService,
sse: sseService, sse: sseService,
proxy: proxyService, relay: relayService,
gatewayV2: gatewayV2Service gatewayV2: gatewayV2Service
}); });
@@ -105,9 +105,9 @@ export const requestWithGitHubGateway = async <T>(
}, },
{ {
protocol: GatewayProxyProtocol.Tcp, protocol: GatewayProxyProtocol.Tcp,
proxyIp: gatewayConnectionDetails.proxyIp, relayIp: gatewayConnectionDetails.relayIp,
gateway: gatewayConnectionDetails.gateway, gateway: gatewayConnectionDetails.gateway,
proxy: gatewayConnectionDetails.proxy relay: gatewayConnectionDetails.relay
} }
); );
} }
@@ -142,9 +142,9 @@ export const executeWithPotentialGateway = async <T>(
}, },
{ {
protocol: GatewayProxyProtocol.Tcp, protocol: GatewayProxyProtocol.Tcp,
proxyIp: platformConnectionDetails.proxyIp, relayIp: platformConnectionDetails.relayIp,
gateway: platformConnectionDetails.gateway, gateway: platformConnectionDetails.gateway,
proxy: platformConnectionDetails.proxy relay: platformConnectionDetails.relay
} }
); );
} }
@@ -114,9 +114,9 @@ export const identityKubernetesAuthServiceFactory = ({
}, },
{ {
protocol: inputs.reviewTokenThroughGateway ? GatewayProxyProtocol.Http : GatewayProxyProtocol.Tcp, protocol: inputs.reviewTokenThroughGateway ? GatewayProxyProtocol.Http : GatewayProxyProtocol.Tcp,
proxyIp: gatewayV2ConnectionDetails.proxyIp, relayIp: gatewayV2ConnectionDetails.relayIp,
gateway: gatewayV2ConnectionDetails.gateway, gateway: gatewayV2ConnectionDetails.gateway,
proxy: gatewayV2ConnectionDetails.proxy, relay: gatewayV2ConnectionDetails.relay,
httpsAgent httpsAgent
} }
); );