feat: added one to one support for aws SM integration

This commit is contained in:
Sheen Capadngan
2024-05-23 20:30:55 +08:00
parent 663f8abc51
commit de2a5b4255
8 changed files with 217 additions and 140 deletions
+1
View File
@@ -662,6 +662,7 @@ export const INTEGRATION = {
secretPrefix: "The prefix for the saved secret. Used by GCP.", secretPrefix: "The prefix for the saved secret. Used by GCP.",
secretSuffix: "The suffix for the saved secret. Used by GCP.", secretSuffix: "The suffix for the saved secret. Used by GCP.",
initialSyncBehavoir: "Type of syncing behavoir with the integration.", initialSyncBehavoir: "Type of syncing behavoir with the integration.",
mappingBehavior: "The mapping behavior of the integration.",
shouldAutoRedeploy: "Used by Render to trigger auto deploy.", shouldAutoRedeploy: "Used by Render to trigger auto deploy.",
secretGCPLabel: "The label for GCP secrets.", secretGCPLabel: "The label for GCP secrets.",
secretAWSTag: "The tags for AWS secrets.", secretAWSTag: "The tags for AWS secrets.",
@@ -49,6 +49,7 @@ export const registerIntegrationRouter = async (server: FastifyZodProvider) => {
secretPrefix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretPrefix), secretPrefix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretPrefix),
secretSuffix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretSuffix), secretSuffix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretSuffix),
initialSyncBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.initialSyncBehavoir), initialSyncBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.initialSyncBehavoir),
mappingBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.mappingBehavior),
shouldAutoRedeploy: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldAutoRedeploy), shouldAutoRedeploy: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldAutoRedeploy),
secretGCPLabel: z secretGCPLabel: z
.object({ .object({
@@ -160,6 +161,7 @@ export const registerIntegrationRouter = async (server: FastifyZodProvider) => {
secretPrefix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretPrefix), secretPrefix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretPrefix),
secretSuffix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretSuffix), secretSuffix: z.string().optional().describe(INTEGRATION.CREATE.metadata.secretSuffix),
initialSyncBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.initialSyncBehavoir), initialSyncBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.initialSyncBehavoir),
mappingBehavior: z.string().optional().describe(INTEGRATION.CREATE.metadata.mappingBehavior),
shouldAutoRedeploy: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldAutoRedeploy), shouldAutoRedeploy: z.boolean().optional().describe(INTEGRATION.CREATE.metadata.shouldAutoRedeploy),
secretGCPLabel: z secretGCPLabel: z
.object({ .object({
@@ -43,6 +43,11 @@ export enum IntegrationInitialSyncBehavior {
PREFER_SOURCE = "prefer-source" PREFER_SOURCE = "prefer-source"
} }
export enum IntegrationMappingBehavior {
ONE_TO_ONE = "one-to-one",
MANY_TO_ONE = "many-to-one"
}
export enum IntegrationUrls { export enum IntegrationUrls {
// integration oauth endpoints // integration oauth endpoints
GCP_TOKEN_URL = "https://oauth2.googleapis.com/token", GCP_TOKEN_URL = "https://oauth2.googleapis.com/token",
@@ -30,7 +30,12 @@ import { BadRequestError } from "@app/lib/errors";
import { TCreateManySecretsRawFn, TUpdateManySecretsRawFn } from "@app/services/secret/secret-types"; import { TCreateManySecretsRawFn, TUpdateManySecretsRawFn } from "@app/services/secret/secret-types";
import { TIntegrationDALFactory } from "../integration/integration-dal"; import { TIntegrationDALFactory } from "../integration/integration-dal";
import { IntegrationInitialSyncBehavior, Integrations, IntegrationUrls } from "./integration-list"; import {
IntegrationInitialSyncBehavior,
IntegrationMappingBehavior,
Integrations,
IntegrationUrls
} from "./integration-list";
const getSecretKeyValuePair = (secrets: Record<string, { value: string | null; comment?: string } | null>) => const getSecretKeyValuePair = (secrets: Record<string, { value: string | null; comment?: string } | null>) =>
Object.keys(secrets).reduce<Record<string, string | null | undefined>>((prev, key) => { Object.keys(secrets).reduce<Record<string, string | null | undefined>>((prev, key) => {
@@ -570,134 +575,145 @@ const syncSecretsAWSSecretManager = async ({
accessId: string | null; accessId: string | null;
accessToken: string; accessToken: string;
}) => { }) => {
let secretsManager;
const secKeyVal = getSecretKeyValuePair(secrets);
const metadata = z.record(z.any()).parse(integration.metadata || {}); const metadata = z.record(z.any()).parse(integration.metadata || {});
try {
if (!accessId) return;
secretsManager = new SecretsManagerClient({ if (!accessId) return;
region: integration.region as string,
credentials: { const secretsManager = new SecretsManagerClient({
accessKeyId: accessId, region: integration.region as string,
secretAccessKey: accessToken credentials: {
accessKeyId: accessId,
secretAccessKey: accessToken
}
});
const processAwsSecret = async (secretId: string, keyValuePairs: Record<string, string | null | undefined>) => {
try {
const awsSecretManagerSecret = await secretsManager.send(
new GetSecretValueCommand({
SecretId: secretId
})
);
let awsSecretManagerSecretObj: { [key: string]: AWS.SecretsManager } = {};
if (awsSecretManagerSecret?.SecretString) {
awsSecretManagerSecretObj = JSON.parse(awsSecretManagerSecret.SecretString);
} }
});
const awsSecretManagerSecret = await secretsManager.send( if (!isEqual(awsSecretManagerSecretObj, keyValuePairs)) {
new GetSecretValueCommand({ await secretsManager.send(
SecretId: integration.app as string new UpdateSecretCommand({
}) SecretId: secretId,
); SecretString: JSON.stringify(keyValuePairs)
})
);
}
let awsSecretManagerSecretObj: { [key: string]: AWS.SecretsManager } = {}; const secretAWSTag = metadata.secretAWSTag as { key: string; value: string }[] | undefined;
if (awsSecretManagerSecret?.SecretString) { if (secretAWSTag && secretAWSTag.length) {
awsSecretManagerSecretObj = JSON.parse(awsSecretManagerSecret.SecretString); const describedSecret = await secretsManager.send(
} // requires secretsmanager:DescribeSecret policy
new DescribeSecretCommand({
SecretId: secretId
})
);
if (!isEqual(awsSecretManagerSecretObj, secKeyVal)) { if (!describedSecret.Tags) return;
await secretsManager.send(
new UpdateSecretCommand({
SecretId: integration.app as string,
SecretString: JSON.stringify(secKeyVal)
})
);
}
const secretAWSTag = metadata.secretAWSTag as { key: string; value: string }[] | undefined; const integrationTagObj = secretAWSTag.reduce(
(acc, item) => {
acc[item.key] = item.value;
return acc;
},
{} as Record<string, string>
);
if (secretAWSTag && secretAWSTag.length) { const awsTagObj = (describedSecret.Tags || []).reduce(
const describedSecret = await secretsManager.send( (acc, item) => {
// requires secretsmanager:DescribeSecret policy if (item.Key && item.Value) {
new DescribeSecretCommand({ acc[item.Key] = item.Value;
SecretId: integration.app as string }
}) return acc;
); },
{} as Record<string, string>
);
if (!describedSecret.Tags) return; const tagsToUpdate: { Key: string; Value: string }[] = [];
const tagsToDelete: { Key: string; Value: string }[] = [];
const integrationTagObj = secretAWSTag.reduce( describedSecret.Tags?.forEach((tag) => {
(acc, item) => { if (tag.Key && tag.Value) {
acc[item.key] = item.value; if (!(tag.Key in integrationTagObj)) {
return acc; // delete tag from AWS secret manager
}, tagsToDelete.push({
{} as Record<string, string> Key: tag.Key,
); Value: tag.Value
});
const awsTagObj = (describedSecret.Tags || []).reduce( } else if (tag.Value !== integrationTagObj[tag.Key]) {
(acc, item) => { // update tag in AWS secret manager
if (item.Key && item.Value) { tagsToUpdate.push({
acc[item.Key] = item.Value; Key: tag.Key,
Value: integrationTagObj[tag.Key]
});
}
} }
return acc; });
},
{} as Record<string, string>
);
const tagsToUpdate: { Key: string; Value: string }[] = []; secretAWSTag?.forEach((tag) => {
const tagsToDelete: { Key: string; Value: string }[] = []; if (!(tag.key in awsTagObj)) {
// create tag in AWS secret manager
describedSecret.Tags?.forEach((tag) => {
if (tag.Key && tag.Value) {
if (!(tag.Key in integrationTagObj)) {
// delete tag from AWS secret manager
tagsToDelete.push({
Key: tag.Key,
Value: tag.Value
});
} else if (tag.Value !== integrationTagObj[tag.Key]) {
// update tag in AWS secret manager
tagsToUpdate.push({ tagsToUpdate.push({
Key: tag.Key, Key: tag.key,
Value: integrationTagObj[tag.Key] Value: tag.value
}); });
} }
} });
});
secretAWSTag?.forEach((tag) => { if (tagsToUpdate.length) {
if (!(tag.key in awsTagObj)) { await secretsManager.send(
// create tag in AWS secret manager new TagResourceCommand({
tagsToUpdate.push({ SecretId: secretId,
Key: tag.key, Tags: tagsToUpdate
Value: tag.value })
}); );
} }
});
if (tagsToUpdate.length) { if (tagsToDelete.length) {
await secretsManager.send( await secretsManager.send(
new TagResourceCommand({ new UntagResourceCommand({
SecretId: integration.app as string, SecretId: secretId,
Tags: tagsToUpdate TagKeys: tagsToDelete.map((tag) => tag.Key)
}) })
); );
}
} }
} catch (err) {
if (tagsToDelete.length) { // case when AWS manager can't find the specified secret
if (err instanceof ResourceNotFoundException && secretsManager) {
await secretsManager.send( await secretsManager.send(
new UntagResourceCommand({ new CreateSecretCommand({
SecretId: integration.app as string, Name: secretId,
TagKeys: tagsToDelete.map((tag) => tag.Key) SecretString: JSON.stringify(keyValuePairs),
...(metadata.kmsKeyId && { KmsKeyId: metadata.kmsKeyId }),
Tags: metadata.secretAWSTag
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({ Key: tag.key, Value: tag.value }))
: []
}) })
); );
} }
} }
} catch (err) { };
// case when AWS manager can't find the specified secret
if (err instanceof ResourceNotFoundException && secretsManager) { if (metadata.mappingBehavior === IntegrationMappingBehavior.ONE_TO_ONE) {
await secretsManager.send( for await (const [key, value] of Object.entries(secrets)) {
new CreateSecretCommand({ await processAwsSecret(key, {
Name: integration.app as string, [key]: value.value
SecretString: JSON.stringify(secKeyVal), });
...(metadata.kmsKeyId && { KmsKeyId: metadata.kmsKeyId }),
Tags: metadata.secretAWSTag
? metadata.secretAWSTag.map((tag: { key: string; value: string }) => ({ Key: tag.key, Value: tag.value }))
: []
})
);
} }
} else {
await processAwsSecret(integration.app as string, getSecretKeyValuePair(secrets));
} }
}; };
@@ -64,6 +64,7 @@ export const useCreateIntegration = () => {
secretSuffix?: string; secretSuffix?: string;
initialSyncBehavior?: string; initialSyncBehavior?: string;
shouldAutoRedeploy?: boolean; shouldAutoRedeploy?: boolean;
mappingBehavior?: string;
secretAWSTag?: { secretAWSTag?: {
key: string; key: string;
value: string; value: string;
@@ -36,6 +36,7 @@ export type TIntegration = {
metadata?: { metadata?: {
secretSuffix?: string; secretSuffix?: string;
syncBehavior?: IntegrationSyncBehavior; syncBehavior?: IntegrationSyncBehavior;
mappingBehavior?: IntegrationMappingBehavior;
scope: string; scope: string;
org: string; org: string;
project: string; project: string;
@@ -48,3 +49,8 @@ export enum IntegrationSyncBehavior {
PREFER_TARGET = "prefer-target", PREFER_TARGET = "prefer-target",
PREFER_SOURCE = "prefer-source" PREFER_SOURCE = "prefer-source"
} }
export enum IntegrationMappingBehavior {
ONE_TO_ONE = "one-to-one",
MANY_TO_ONE = "many-to-one"
}
@@ -15,6 +15,7 @@ import queryString from "query-string";
import { useCreateIntegration } from "@app/hooks/api"; import { useCreateIntegration } from "@app/hooks/api";
import { useGetIntegrationAuthAwsKmsKeys } from "@app/hooks/api/integrationAuth/queries"; import { useGetIntegrationAuthAwsKmsKeys } from "@app/hooks/api/integrationAuth/queries";
import { IntegrationMappingBehavior } from "@app/hooks/api/integrations/types";
import { import {
Button, Button,
@@ -70,6 +71,17 @@ const awsRegions = [
{ name: "AWS GovCloud (US-West)", slug: "us-gov-west-1" } { name: "AWS GovCloud (US-West)", slug: "us-gov-west-1" }
]; ];
const mappingBehaviors = [
{
label: "Many to One - secrets will be mapped to one AWS Secret",
value: IntegrationMappingBehavior.MANY_TO_ONE
},
{
label: "One to One - secrets will be mapped to individual AWS secrets",
value: IntegrationMappingBehavior.ONE_TO_ONE
}
];
export default function AWSSecretManagerCreateIntegrationPage() { export default function AWSSecretManagerCreateIntegrationPage() {
const router = useRouter(); const router = useRouter();
const { mutateAsync } = useCreateIntegration(); const { mutateAsync } = useCreateIntegration();
@@ -84,6 +96,9 @@ export default function AWSSecretManagerCreateIntegrationPage() {
const [selectedSourceEnvironment, setSelectedSourceEnvironment] = useState(""); const [selectedSourceEnvironment, setSelectedSourceEnvironment] = useState("");
const [secretPath, setSecretPath] = useState("/"); const [secretPath, setSecretPath] = useState("/");
const [selectedAWSRegion, setSelectedAWSRegion] = useState(""); const [selectedAWSRegion, setSelectedAWSRegion] = useState("");
const [selectedMappingBehavior, setSelectedMappingBehavior] = useState(
IntegrationMappingBehavior.MANY_TO_ONE
);
const [targetSecretName, setTargetSecretName] = useState(""); const [targetSecretName, setTargetSecretName] = useState("");
const [targetSecretNameErrorText, setTargetSecretNameErrorText] = useState(""); const [targetSecretNameErrorText, setTargetSecretNameErrorText] = useState("");
const [tagKey, setTagKey] = useState(""); const [tagKey, setTagKey] = useState("");
@@ -116,7 +131,14 @@ export default function AWSSecretManagerCreateIntegrationPage() {
const handleButtonClick = async () => { const handleButtonClick = async () => {
try { try {
if (targetSecretName.trim() === "") { if (!selectedMappingBehavior) {
return;
}
if (
selectedMappingBehavior === IntegrationMappingBehavior.MANY_TO_ONE &&
targetSecretName.trim() === ""
) {
setTargetSecretName("Secret name cannot be blank"); setTargetSecretName("Secret name cannot be blank");
return; return;
} }
@@ -143,7 +165,8 @@ export default function AWSSecretManagerCreateIntegrationPage() {
] ]
} }
: {}), : {}),
...(kmsKeyId && { kmsKeyId }) ...(kmsKeyId && { kmsKeyId }),
mappingBehavior: selectedMappingBehavior
} }
}); });
@@ -248,19 +271,36 @@ export default function AWSSecretManagerCreateIntegrationPage() {
))} ))}
</Select> </Select>
</FormControl> </FormControl>
<FormControl <FormControl label="Mapping Behavior">
label="AWS SM Secret Name" <Select
errorText={targetSecretNameErrorText} value={selectedMappingBehavior}
isError={targetSecretNameErrorText !== "" ?? false} onValueChange={(val) => {
> setSelectedMappingBehavior(val as IntegrationMappingBehavior);
<Input }}
placeholder={`${workspace.name className="w-full border border-mineshaft-500"
.toLowerCase() >
.replace(/ /g, "-")}/${selectedSourceEnvironment}`} {mappingBehaviors.map((option) => (
value={targetSecretName} <SelectItem value={option.value} key={`aws-environment-${option.value}`}>
onChange={(e) => setTargetSecretName(e.target.value)} {option.label}
/> </SelectItem>
))}
</Select>
</FormControl> </FormControl>
{selectedMappingBehavior === IntegrationMappingBehavior.MANY_TO_ONE && (
<FormControl
label="AWS SM Secret Name"
errorText={targetSecretNameErrorText}
isError={targetSecretNameErrorText !== "" ?? false}
>
<Input
placeholder={`${workspace.name
.toLowerCase()
.replace(/ /g, "-")}/${selectedSourceEnvironment}`}
value={targetSecretName}
onChange={(e) => setTargetSecretName(e.target.value)}
/>
</FormControl>
)}
</motion.div> </motion.div>
</TabPanel> </TabPanel>
<TabPanel value={TabSections.Options}> <TabPanel value={TabSections.Options}>
@@ -21,6 +21,7 @@ import {
import { ProjectPermissionActions, ProjectPermissionSub } from "@app/context"; import { ProjectPermissionActions, ProjectPermissionSub } from "@app/context";
import { usePopUp } from "@app/hooks"; import { usePopUp } from "@app/hooks";
import { useSyncIntegration } from "@app/hooks/api/integrations/queries"; import { useSyncIntegration } from "@app/hooks/api/integrations/queries";
import { IntegrationMappingBehavior } from "@app/hooks/api/integrations/types";
import { TIntegration } from "@app/hooks/api/types"; import { TIntegration } from "@app/hooks/api/types";
type Props = { type Props = {
@@ -131,30 +132,35 @@ export const IntegrationsSection = ({
</div> </div>
</div> </div>
)} )}
<div className="ml-2 flex flex-col"> {!(
<FormLabel integration.integration === "aws-secret-manager" &&
label={ integration.metadata?.mappingBehavior === IntegrationMappingBehavior.ONE_TO_ONE
(integration.integration === "qovery" && integration?.scope) || ) && (
(integration.integration === "aws-secret-manager" && "Secret") || <div className="ml-2 flex flex-col">
(integration.integration === "aws-parameter-store" && "Path") || <FormLabel
(integration?.integration === "terraform-cloud" && "Project") || label={
(integration?.scope === "github-org" && "Organization") || (integration.integration === "qovery" && integration?.scope) ||
(["github-repo", "github-env"].includes(integration?.scope as string) && (integration.integration === "aws-secret-manager" && "Secret") ||
"Repository") || (integration.integration === "aws-parameter-store" && "Path") ||
"App" (integration?.integration === "terraform-cloud" && "Project") ||
} (integration?.scope === "github-org" && "Organization") ||
/> (["github-repo", "github-env"].includes(integration?.scope as string) &&
<div className="no-scrollbar::-webkit-scrollbar min-w-[8rem] max-w-[12rem] overflow-scroll whitespace-nowrap rounded-md border border-mineshaft-700 bg-mineshaft-900 px-3 py-2 font-inter text-sm text-bunker-200 no-scrollbar"> "Repository") ||
{(integration.integration === "hashicorp-vault" && "App"
`${integration.app} - path: ${integration.path}`) || }
(integration.scope === "github-org" && `${integration.owner}`) || />
(integration.integration === "aws-parameter-store" && <div className="no-scrollbar::-webkit-scrollbar min-w-[8rem] max-w-[12rem] overflow-scroll whitespace-nowrap rounded-md border border-mineshaft-700 bg-mineshaft-900 px-3 py-2 font-inter text-sm text-bunker-200 no-scrollbar">
`${integration.path}`) || {(integration.integration === "hashicorp-vault" &&
(integration.scope?.startsWith("github-") && `${integration.app} - path: ${integration.path}`) ||
`${integration.owner}/${integration.app}`) || (integration.scope === "github-org" && `${integration.owner}`) ||
integration.app} (integration.integration === "aws-parameter-store" &&
`${integration.path}`) ||
(integration.scope?.startsWith("github-") &&
`${integration.owner}/${integration.app}`) ||
integration.app}
</div>
</div> </div>
</div> )}
{(integration.integration === "vercel" || {(integration.integration === "vercel" ||
integration.integration === "netlify" || integration.integration === "netlify" ||
integration.integration === "railway" || integration.integration === "railway" ||