Add missing k8s stuff

# Conflicts:
#	frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx
This commit is contained in:
Fang-Pen Lin
2025-12-03 14:08:38 -08:00
parent 2140956ba8
commit e62705a81d
5 changed files with 20 additions and 7 deletions

View File

@@ -2,6 +2,7 @@ import { z } from "zod";
import { PamSessionsSchema } from "@app/db/schemas";
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
import { KubernetesSessionCredentialsSchema } from "@app/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas";
import { MySQLSessionCredentialsSchema } from "@app/ee/services/pam-resource/mysql/mysql-resource-schemas";
import { PostgresSessionCredentialsSchema } from "@app/ee/services/pam-resource/postgres/postgres-resource-schemas";
import { SSHSessionCredentialsSchema } from "@app/ee/services/pam-resource/ssh/ssh-resource-schemas";
@@ -17,7 +18,8 @@ import { AuthMode } from "@app/services/auth/auth-type";
const SessionCredentialsSchema = z.union([
SSHSessionCredentialsSchema,
PostgresSessionCredentialsSchema,
MySQLSessionCredentialsSchema
MySQLSessionCredentialsSchema,
KubernetesSessionCredentialsSchema
]);
export const registerPamSessionRouter = async (server: FastifyZodProvider) => {

View File

@@ -626,6 +626,11 @@ export const pamAccountServiceFactory = ({
};
}
break;
case PamResource.Kubernetes:
{
// TODO: provide metadata for Kubernetes if we need it
}
break;
default:
break;
}

View File

@@ -24,8 +24,12 @@ export const KubernetesResourceListItemSchema = z.object({
export const KubernetesResourceConnectionDetailsSchema = z.object({
url: z.string().url().trim().max(500),
namespace: z.string().trim().max(255),
skipTLSVerify: z.boolean(),
caCertificate: z.string().trim().max(10000).optional()
sslRejectUnauthorized: z.boolean(),
sslCertificate: z
.string()
.trim()
.transform((value) => value || undefined)
.optional()
});
export const KubernetesServiceAccountTokenCredentialsSchema = z.object({

View File

@@ -86,6 +86,8 @@ export const PamAccessAccountModal = ({
return `infisical pam db access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`;
case PamResourceType.SSH:
return `infisical pam ssh access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`;
case PamResourceType.Kubernetes:
return `infisical pam kubernetes access-account ${account.id} --duration ${cliDuration} --domain ${siteURL}`;
default:
return "";
}

View File

@@ -17,8 +17,8 @@ type Props = {
const KubernetesConnectionDetailsSchema = z.object({
url: z.string().url().trim().max(500),
namespace: z.string().trim().max(255),
skipTLSVerify: z.boolean(),
caCertificate: z.string().trim().max(10000).optional()
sslRejectUnauthorized: z.boolean(),
sslCertificate: z.string().trim().max(10000).optional()
});
const KubernetesServiceAccountTokenCredentialsSchema = z.object({
@@ -54,8 +54,8 @@ export const KubernetesResourceForm = ({ resource, onSubmit }: Props) => {
connectionDetails: {
url: "",
namespace: "default",
skipTLSVerify: false,
caCertificate: undefined
sslRejectUnauthorized: true,
sslCertificate: undefined
}
}
});