From e62705a81dc27eacf65e8afa4bb0540bce7fe1ef Mon Sep 17 00:00:00 2001 From: Fang-Pen Lin Date: Wed, 3 Dec 2025 14:08:38 -0800 Subject: [PATCH] Add missing k8s stuff # Conflicts: # frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx --- backend/src/ee/routes/v1/pam-session-router.ts | 4 +++- .../src/ee/services/pam-account/pam-account-service.ts | 5 +++++ .../kubernetes/kubernetes-resource-schemas.ts | 8 ++++++-- .../PamAccountsPage/components/PamAccessAccountModal.tsx | 2 ++ .../components/PamResourceForm/KubernetesResourceForm.tsx | 8 ++++---- 5 files changed, 20 insertions(+), 7 deletions(-) diff --git a/backend/src/ee/routes/v1/pam-session-router.ts b/backend/src/ee/routes/v1/pam-session-router.ts index 3c39a9516..542fff2f4 100644 --- a/backend/src/ee/routes/v1/pam-session-router.ts +++ b/backend/src/ee/routes/v1/pam-session-router.ts @@ -2,6 +2,7 @@ import { z } from "zod"; import { PamSessionsSchema } from "@app/db/schemas"; import { EventType } from "@app/ee/services/audit-log/audit-log-types"; +import { KubernetesSessionCredentialsSchema } from "@app/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas"; import { MySQLSessionCredentialsSchema } from "@app/ee/services/pam-resource/mysql/mysql-resource-schemas"; import { PostgresSessionCredentialsSchema } from "@app/ee/services/pam-resource/postgres/postgres-resource-schemas"; import { SSHSessionCredentialsSchema } from "@app/ee/services/pam-resource/ssh/ssh-resource-schemas"; @@ -17,7 +18,8 @@ import { AuthMode } from "@app/services/auth/auth-type"; const SessionCredentialsSchema = z.union([ SSHSessionCredentialsSchema, PostgresSessionCredentialsSchema, - MySQLSessionCredentialsSchema + MySQLSessionCredentialsSchema, + KubernetesSessionCredentialsSchema ]); export const registerPamSessionRouter = async (server: FastifyZodProvider) => { diff --git a/backend/src/ee/services/pam-account/pam-account-service.ts b/backend/src/ee/services/pam-account/pam-account-service.ts index 019df00ec..d03c00d1a 100644 --- a/backend/src/ee/services/pam-account/pam-account-service.ts +++ b/backend/src/ee/services/pam-account/pam-account-service.ts @@ -626,6 +626,11 @@ export const pamAccountServiceFactory = ({ }; } break; + case PamResource.Kubernetes: + { + // TODO: provide metadata for Kubernetes if we need it + } + break; default: break; } diff --git a/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas.ts b/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas.ts index 19da74823..7f86328f7 100644 --- a/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas.ts +++ b/backend/src/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas.ts @@ -24,8 +24,12 @@ export const KubernetesResourceListItemSchema = z.object({ export const KubernetesResourceConnectionDetailsSchema = z.object({ url: z.string().url().trim().max(500), namespace: z.string().trim().max(255), - skipTLSVerify: z.boolean(), - caCertificate: z.string().trim().max(10000).optional() + sslRejectUnauthorized: z.boolean(), + sslCertificate: z + .string() + .trim() + .transform((value) => value || undefined) + .optional() }); export const KubernetesServiceAccountTokenCredentialsSchema = z.object({ diff --git a/frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx b/frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx index 262900182..fb1dcb17f 100644 --- a/frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx +++ b/frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx @@ -86,6 +86,8 @@ export const PamAccessAccountModal = ({ return `infisical pam db access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`; case PamResourceType.SSH: return `infisical pam ssh access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`; + case PamResourceType.Kubernetes: + return `infisical pam kubernetes access-account ${account.id} --duration ${cliDuration} --domain ${siteURL}`; default: return ""; } diff --git a/frontend/src/pages/pam/PamResourcesPage/components/PamResourceForm/KubernetesResourceForm.tsx b/frontend/src/pages/pam/PamResourcesPage/components/PamResourceForm/KubernetesResourceForm.tsx index 651e83a6a..9d81318e3 100644 --- a/frontend/src/pages/pam/PamResourcesPage/components/PamResourceForm/KubernetesResourceForm.tsx +++ b/frontend/src/pages/pam/PamResourcesPage/components/PamResourceForm/KubernetesResourceForm.tsx @@ -17,8 +17,8 @@ type Props = { const KubernetesConnectionDetailsSchema = z.object({ url: z.string().url().trim().max(500), namespace: z.string().trim().max(255), - skipTLSVerify: z.boolean(), - caCertificate: z.string().trim().max(10000).optional() + sslRejectUnauthorized: z.boolean(), + sslCertificate: z.string().trim().max(10000).optional() }); const KubernetesServiceAccountTokenCredentialsSchema = z.object({ @@ -54,8 +54,8 @@ export const KubernetesResourceForm = ({ resource, onSubmit }: Props) => { connectionDetails: { url: "", namespace: "default", - skipTLSVerify: false, - caCertificate: undefined + sslRejectUnauthorized: true, + sslCertificate: undefined } } });