mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Connect k8s
This commit is contained in:
@@ -2,8 +2,10 @@ import axios, { AxiosError } from "axios";
|
|||||||
import https from "https";
|
import https from "https";
|
||||||
|
|
||||||
import { BadRequestError } from "@app/lib/errors";
|
import { BadRequestError } from "@app/lib/errors";
|
||||||
import { GatewayProxyProtocol, withGatewayV2Proxy } from "@app/lib/gateway-v2/gateway-v2";
|
import { GatewayProxyProtocol } from "@app/lib/gateway/types";
|
||||||
|
import { withGatewayV2Proxy } from "@app/lib/gateway-v2/gateway-v2";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
|
|
||||||
import { verifyHostInputValidity } from "../../dynamic-secret/dynamic-secret-fns";
|
import { verifyHostInputValidity } from "../../dynamic-secret/dynamic-secret-fns";
|
||||||
import { TGatewayV2ServiceFactory } from "../../gateway-v2/gateway-v2-service";
|
import { TGatewayV2ServiceFactory } from "../../gateway-v2/gateway-v2-service";
|
||||||
import { PamResource } from "../pam-resource-enums";
|
import { PamResource } from "../pam-resource-enums";
|
||||||
@@ -29,7 +31,15 @@ export const executeWithGateway = async <T>(
|
|||||||
const { connectionDetails, gatewayId } = config;
|
const { connectionDetails, gatewayId } = config;
|
||||||
const url = new URL(connectionDetails.url);
|
const url = new URL(connectionDetails.url);
|
||||||
const [targetHost] = await verifyHostInputValidity(url.hostname, true);
|
const [targetHost] = await verifyHostInputValidity(url.hostname, true);
|
||||||
const targetPort = url.port ? Number(url.port) : url.protocol === "https:" ? 443 : 80;
|
|
||||||
|
let targetPort: number;
|
||||||
|
if (url.port) {
|
||||||
|
targetPort = Number(url.port);
|
||||||
|
} else if (url.protocol === "https:") {
|
||||||
|
targetPort = 443;
|
||||||
|
} else {
|
||||||
|
targetPort = 80;
|
||||||
|
}
|
||||||
|
|
||||||
const platformConnectionDetails = await gatewayV2Service.getPlatformConnectionDetailsByGatewayId({
|
const platformConnectionDetails = await gatewayV2Service.getPlatformConnectionDetailsByGatewayId({
|
||||||
gatewayId,
|
gatewayId,
|
||||||
@@ -60,7 +70,7 @@ export const executeWithGateway = async <T>(
|
|||||||
return operation(baseUrl, httpsAgent);
|
return operation(baseUrl, httpsAgent);
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
protocol: GatewayProxyProtocol.Tcp,
|
protocol: GatewayProxyProtocol.Http,
|
||||||
relayHost: platformConnectionDetails.relayHost,
|
relayHost: platformConnectionDetails.relayHost,
|
||||||
gateway: platformConnectionDetails.gateway,
|
gateway: platformConnectionDetails.gateway,
|
||||||
relay: platformConnectionDetails.relay,
|
relay: platformConnectionDetails.relay,
|
||||||
@@ -126,7 +136,8 @@ export const kubernetesResourceFactory: TPamResourceFactory<
|
|||||||
{ connectionDetails, gatewayId, resourceType },
|
{ connectionDetails, gatewayId, resourceType },
|
||||||
gatewayV2Service,
|
gatewayV2Service,
|
||||||
async (baseUrl, httpsAgent) => {
|
async (baseUrl, httpsAgent) => {
|
||||||
if (credentials.authMethod === KubernetesAuthMethod.ServiceAccountToken) {
|
const { authMethod } = credentials;
|
||||||
|
if (authMethod === KubernetesAuthMethod.ServiceAccountToken) {
|
||||||
// Validate service account token by making an authenticated API call
|
// Validate service account token by making an authenticated API call
|
||||||
try {
|
try {
|
||||||
await axios.get(`${baseUrl}/api/v1/namespaces/${connectionDetails.namespace}`, {
|
await axios.get(`${baseUrl}/api/v1/namespaces/${connectionDetails.namespace}`, {
|
||||||
@@ -159,7 +170,7 @@ export const kubernetesResourceFactory: TPamResourceFactory<
|
|||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `Unsupported Kubernetes auth method: ${(credentials as TKubernetesAccountCredentials).authMethod}`
|
message: `Unsupported Kubernetes auth method: ${authMethod as string}`
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -24,7 +24,7 @@ export const KubernetesResourceListItemSchema = z.object({
|
|||||||
export const KubernetesResourceConnectionDetailsSchema = z.object({
|
export const KubernetesResourceConnectionDetailsSchema = z.object({
|
||||||
url: z.string().url().trim().max(500),
|
url: z.string().url().trim().max(500),
|
||||||
namespace: z.string().trim().max(255),
|
namespace: z.string().trim().max(255),
|
||||||
skipTLSVerify: z.boolean().optional().default(false),
|
skipTLSVerify: z.boolean(),
|
||||||
caCertificate: z.string().trim().max(10000).optional()
|
caCertificate: z.string().trim().max(10000).optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user