mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 14:27:59 +00:00
Add missing k8s stuff
# Conflicts: # frontend/src/pages/pam/PamAccountsPage/components/PamAccessAccountModal.tsx
This commit is contained in:
@@ -2,6 +2,7 @@ import { z } from "zod";
|
|||||||
|
|
||||||
import { PamSessionsSchema } from "@app/db/schemas";
|
import { PamSessionsSchema } from "@app/db/schemas";
|
||||||
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
|
import { KubernetesSessionCredentialsSchema } from "@app/ee/services/pam-resource/kubernetes/kubernetes-resource-schemas";
|
||||||
import { MySQLSessionCredentialsSchema } from "@app/ee/services/pam-resource/mysql/mysql-resource-schemas";
|
import { MySQLSessionCredentialsSchema } from "@app/ee/services/pam-resource/mysql/mysql-resource-schemas";
|
||||||
import { PostgresSessionCredentialsSchema } from "@app/ee/services/pam-resource/postgres/postgres-resource-schemas";
|
import { PostgresSessionCredentialsSchema } from "@app/ee/services/pam-resource/postgres/postgres-resource-schemas";
|
||||||
import { SSHSessionCredentialsSchema } from "@app/ee/services/pam-resource/ssh/ssh-resource-schemas";
|
import { SSHSessionCredentialsSchema } from "@app/ee/services/pam-resource/ssh/ssh-resource-schemas";
|
||||||
@@ -17,7 +18,8 @@ import { AuthMode } from "@app/services/auth/auth-type";
|
|||||||
const SessionCredentialsSchema = z.union([
|
const SessionCredentialsSchema = z.union([
|
||||||
SSHSessionCredentialsSchema,
|
SSHSessionCredentialsSchema,
|
||||||
PostgresSessionCredentialsSchema,
|
PostgresSessionCredentialsSchema,
|
||||||
MySQLSessionCredentialsSchema
|
MySQLSessionCredentialsSchema,
|
||||||
|
KubernetesSessionCredentialsSchema
|
||||||
]);
|
]);
|
||||||
|
|
||||||
export const registerPamSessionRouter = async (server: FastifyZodProvider) => {
|
export const registerPamSessionRouter = async (server: FastifyZodProvider) => {
|
||||||
|
|||||||
@@ -626,6 +626,11 @@ export const pamAccountServiceFactory = ({
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
break;
|
break;
|
||||||
|
case PamResource.Kubernetes:
|
||||||
|
{
|
||||||
|
// TODO: provide metadata for Kubernetes if we need it
|
||||||
|
}
|
||||||
|
break;
|
||||||
default:
|
default:
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -24,8 +24,12 @@ export const KubernetesResourceListItemSchema = z.object({
|
|||||||
export const KubernetesResourceConnectionDetailsSchema = z.object({
|
export const KubernetesResourceConnectionDetailsSchema = z.object({
|
||||||
url: z.string().url().trim().max(500),
|
url: z.string().url().trim().max(500),
|
||||||
namespace: z.string().trim().max(255),
|
namespace: z.string().trim().max(255),
|
||||||
skipTLSVerify: z.boolean(),
|
sslRejectUnauthorized: z.boolean(),
|
||||||
caCertificate: z.string().trim().max(10000).optional()
|
sslCertificate: z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.transform((value) => value || undefined)
|
||||||
|
.optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
export const KubernetesServiceAccountTokenCredentialsSchema = z.object({
|
export const KubernetesServiceAccountTokenCredentialsSchema = z.object({
|
||||||
|
|||||||
@@ -86,6 +86,8 @@ export const PamAccessAccountModal = ({
|
|||||||
return `infisical pam db access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`;
|
return `infisical pam db access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`;
|
||||||
case PamResourceType.SSH:
|
case PamResourceType.SSH:
|
||||||
return `infisical pam ssh access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`;
|
return `infisical pam ssh access-account ${fullAccountPath} --project-id ${projectId} --duration ${cliDuration} --domain ${siteURL}`;
|
||||||
|
case PamResourceType.Kubernetes:
|
||||||
|
return `infisical pam kubernetes access-account ${account.id} --duration ${cliDuration} --domain ${siteURL}`;
|
||||||
default:
|
default:
|
||||||
return "";
|
return "";
|
||||||
}
|
}
|
||||||
|
|||||||
+4
-4
@@ -17,8 +17,8 @@ type Props = {
|
|||||||
const KubernetesConnectionDetailsSchema = z.object({
|
const KubernetesConnectionDetailsSchema = z.object({
|
||||||
url: z.string().url().trim().max(500),
|
url: z.string().url().trim().max(500),
|
||||||
namespace: z.string().trim().max(255),
|
namespace: z.string().trim().max(255),
|
||||||
skipTLSVerify: z.boolean(),
|
sslRejectUnauthorized: z.boolean(),
|
||||||
caCertificate: z.string().trim().max(10000).optional()
|
sslCertificate: z.string().trim().max(10000).optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
const KubernetesServiceAccountTokenCredentialsSchema = z.object({
|
const KubernetesServiceAccountTokenCredentialsSchema = z.object({
|
||||||
@@ -54,8 +54,8 @@ export const KubernetesResourceForm = ({ resource, onSubmit }: Props) => {
|
|||||||
connectionDetails: {
|
connectionDetails: {
|
||||||
url: "",
|
url: "",
|
||||||
namespace: "default",
|
namespace: "default",
|
||||||
skipTLSVerify: false,
|
sslRejectUnauthorized: true,
|
||||||
caCertificate: undefined
|
sslCertificate: undefined
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
Reference in New Issue
Block a user