mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 00:27:30 +00:00
improvement: address feedback
This commit is contained in:
+4
-2
@@ -317,11 +317,13 @@ export const AwsParameterStoreSyncFns = {
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const keyId = syncOptions.keyId ?? "alias/aws/ssm";
|
||||||
|
|
||||||
// create parameter or update if changed
|
// create parameter or update if changed
|
||||||
if (
|
if (
|
||||||
!(key in awsParameterStoreSecretsRecord) ||
|
!(key in awsParameterStoreSecretsRecord) ||
|
||||||
value !== awsParameterStoreSecretsRecord[key].Value ||
|
value !== awsParameterStoreSecretsRecord[key].Value ||
|
||||||
(syncOptions.keyId ?? "alias/aws/ssm") !== awsParameterStoreMetadataRecord[key]?.KeyId
|
keyId !== awsParameterStoreMetadataRecord[key]?.KeyId
|
||||||
) {
|
) {
|
||||||
try {
|
try {
|
||||||
await putParameter(ssm, {
|
await putParameter(ssm, {
|
||||||
@@ -329,7 +331,7 @@ export const AwsParameterStoreSyncFns = {
|
|||||||
Type: "SecureString",
|
Type: "SecureString",
|
||||||
Value: value,
|
Value: value,
|
||||||
Overwrite: true,
|
Overwrite: true,
|
||||||
KeyId: syncOptions.keyId
|
KeyId: keyId
|
||||||
});
|
});
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new SecretSyncError({
|
throw new SecretSyncError({
|
||||||
|
|||||||
+8
-25
@@ -318,6 +318,8 @@ export const AwsSecretsManagerSyncFns = {
|
|||||||
|
|
||||||
const syncTagsRecord = Object.fromEntries(syncOptions.tags?.map((tag) => [tag.key, tag.value]) ?? []);
|
const syncTagsRecord = Object.fromEntries(syncOptions.tags?.map((tag) => [tag.key, tag.value]) ?? []);
|
||||||
|
|
||||||
|
const keyId = syncOptions.keyId ?? "alias/aws/secretsmanager";
|
||||||
|
|
||||||
if (destinationConfig.mappingBehavior === AwsSecretsManagerSyncMappingBehavior.OneToOne) {
|
if (destinationConfig.mappingBehavior === AwsSecretsManagerSyncMappingBehavior.OneToOne) {
|
||||||
for await (const entry of Object.entries(secretMap)) {
|
for await (const entry of Object.entries(secretMap)) {
|
||||||
const [key, { value, secretMetadata }] = entry;
|
const [key, { value, secretMetadata }] = entry;
|
||||||
@@ -330,15 +332,12 @@ export const AwsSecretsManagerSyncFns = {
|
|||||||
|
|
||||||
if (awsSecretsRecord[key]) {
|
if (awsSecretsRecord[key]) {
|
||||||
// skip secrets that haven't changed
|
// skip secrets that haven't changed
|
||||||
if (
|
if (awsValuesRecord[key]?.SecretString !== value || keyId !== awsDescriptionsRecord[key]?.KmsKeyId) {
|
||||||
awsValuesRecord[key]?.SecretString !== value ||
|
|
||||||
(syncOptions.keyId ?? "alias/aws/secretsmanager") !== awsDescriptionsRecord[key]?.KmsKeyId
|
|
||||||
) {
|
|
||||||
try {
|
try {
|
||||||
await updateSecret(client, {
|
await updateSecret(client, {
|
||||||
SecretId: key,
|
SecretId: key,
|
||||||
SecretString: value,
|
SecretString: value,
|
||||||
KmsKeyId: syncOptions.keyId
|
KmsKeyId: keyId
|
||||||
});
|
});
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new SecretSyncError({
|
throw new SecretSyncError({
|
||||||
@@ -352,7 +351,7 @@ export const AwsSecretsManagerSyncFns = {
|
|||||||
await createSecret(client, {
|
await createSecret(client, {
|
||||||
Name: key,
|
Name: key,
|
||||||
SecretString: value,
|
SecretString: value,
|
||||||
KmsKeyId: syncOptions.keyId
|
KmsKeyId: keyId
|
||||||
});
|
});
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
throw new SecretSyncError({
|
throw new SecretSyncError({
|
||||||
@@ -416,17 +415,17 @@ export const AwsSecretsManagerSyncFns = {
|
|||||||
Object.fromEntries(Object.entries(secretMap).map(([key, secretData]) => [key, secretData.value]))
|
Object.fromEntries(Object.entries(secretMap).map(([key, secretData]) => [key, secretData.value]))
|
||||||
);
|
);
|
||||||
|
|
||||||
if (awsValuesRecord[destinationConfig.secretName]) {
|
if (awsSecretsRecord[destinationConfig.secretName]) {
|
||||||
await updateSecret(client, {
|
await updateSecret(client, {
|
||||||
SecretId: destinationConfig.secretName,
|
SecretId: destinationConfig.secretName,
|
||||||
SecretString: secretValue,
|
SecretString: secretValue,
|
||||||
KmsKeyId: syncOptions.keyId
|
KmsKeyId: keyId
|
||||||
});
|
});
|
||||||
} else {
|
} else {
|
||||||
await createSecret(client, {
|
await createSecret(client, {
|
||||||
Name: destinationConfig.secretName,
|
Name: destinationConfig.secretName,
|
||||||
SecretString: secretValue,
|
SecretString: secretValue,
|
||||||
KmsKeyId: syncOptions.keyId
|
KmsKeyId: keyId
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -458,22 +457,6 @@ export const AwsSecretsManagerSyncFns = {
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
for await (const secretKey of Object.keys(awsSecretsRecord)) {
|
|
||||||
if (secretKey === destinationConfig.secretName) {
|
|
||||||
// eslint-disable-next-line no-continue
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
|
|
||||||
try {
|
|
||||||
await deleteSecret(client, secretKey);
|
|
||||||
} catch (error) {
|
|
||||||
throw new SecretSyncError({
|
|
||||||
error,
|
|
||||||
secretKey
|
|
||||||
});
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
getSecrets: async (secretSync: TAwsSecretsManagerSyncWithCredentials): Promise<TSecretMap> => {
|
getSecrets: async (secretSync: TAwsSecretsManagerSyncWithCredentials): Promise<TSecretMap> => {
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 492 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 306 KiB After Width: | Height: | Size: 500 KiB |
Binary file not shown.
|
Before Width: | Height: | Size: 311 KiB After Width: | Height: | Size: 523 KiB |
@@ -82,22 +82,26 @@ Infisical supports two methods for connecting to AWS.
|
|||||||
"Sid": "AllowSecretsManagerAccess",
|
"Sid": "AllowSecretsManagerAccess",
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": [
|
"Action": [
|
||||||
"secretsmanager:GetSecretValue",
|
"secretsmanager:ListSecrets",
|
||||||
"secretsmanager:CreateSecret",
|
"secretsmanager:GetSecretValue",
|
||||||
"secretsmanager:UpdateSecret",
|
"secretsmanager:BatchGetSecretValue",
|
||||||
"secretsmanager:DescribeSecret",
|
"secretsmanager:CreateSecret",
|
||||||
"secretsmanager:TagResource",
|
"secretsmanager:UpdateSecret",
|
||||||
"secretsmanager:UntagResource",
|
"secretsmanager:DeleteSecret",
|
||||||
"kms:ListKeys", // if you need to specify the KMS key
|
"secretsmanager:DescribeSecret",
|
||||||
"kms:ListAliases", // if you need to specify the KMS key
|
"secretsmanager:TagResource",
|
||||||
"kms:Encrypt", // if you need to specify the KMS key
|
"secretsmanager:UntagResource",
|
||||||
"kms:Decrypt" // if you need to specify the KMS key
|
"kms:ListAliases", // if you need to specify the KMS key
|
||||||
|
"kms:Encrypt", // if you need to specify the KMS key
|
||||||
|
"kms:Decrypt", // if you need to specify the KMS key
|
||||||
|
"kms:DescribeKey" // if you need to specify the KMS key
|
||||||
],
|
],
|
||||||
"Resource": "*"
|
"Resource": "*"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. </Note>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="AWS Parameter Store">
|
<Accordion title="AWS Parameter Store">
|
||||||
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
|
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
|
||||||
@@ -112,25 +116,25 @@ Infisical supports two methods for connecting to AWS.
|
|||||||
"Sid": "AllowSSMAccess",
|
"Sid": "AllowSSMAccess",
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": [
|
"Action": [
|
||||||
"ssm:PutParameter",
|
"ssm:PutParameter",
|
||||||
"ssm:DeleteParameter",
|
"ssm:GetParameters",
|
||||||
"ssm:GetParameters",
|
"ssm:GetParametersByPath",
|
||||||
"ssm:GetParametersByPath",
|
"ssm:DescribeParameters",
|
||||||
"ssm:DescribeParameters",
|
"ssm:DeleteParameters",
|
||||||
"ssm:DeleteParameters",
|
"ssm:ListTagsForResource", // if you need to add tags to secrets
|
||||||
"ssm:ListTagsForResource", // if you need to add tags to secrets
|
"ssm:AddTagsToResource", // if you need to add tags to secrets
|
||||||
"ssm:AddTagsToResource", // if you need to add tags to secrets
|
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets
|
||||||
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets
|
"kms:ListAliases", // if you need to specify the KMS key
|
||||||
"kms:ListKeys", // if you need to specify the KMS key
|
"kms:Encrypt", // if you need to specify the KMS key
|
||||||
"kms:ListAliases", // if you need to specify the KMS key
|
"kms:Decrypt", // if you need to specify the KMS key
|
||||||
"kms:Encrypt", // if you need to specify the KMS key
|
"kms:DescribeKey" // if you need to specify the KMS key
|
||||||
"kms:Decrypt" // if you need to specify the KMS key
|
|
||||||
],
|
],
|
||||||
"Resource": "*"
|
"Resource": "*"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. </Note>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
</Tab>
|
</Tab>
|
||||||
@@ -225,22 +229,26 @@ Infisical supports two methods for connecting to AWS.
|
|||||||
"Sid": "AllowSecretsManagerAccess",
|
"Sid": "AllowSecretsManagerAccess",
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": [
|
"Action": [
|
||||||
"secretsmanager:GetSecretValue",
|
"secretsmanager:ListSecrets",
|
||||||
"secretsmanager:CreateSecret",
|
"secretsmanager:GetSecretValue",
|
||||||
"secretsmanager:UpdateSecret",
|
"secretsmanager:BatchGetSecretValue",
|
||||||
"secretsmanager:DescribeSecret",
|
"secretsmanager:CreateSecret",
|
||||||
"secretsmanager:TagResource",
|
"secretsmanager:UpdateSecret",
|
||||||
"secretsmanager:UntagResource",
|
"secretsmanager:DeleteSecret",
|
||||||
"kms:ListKeys", // if you need to specify the KMS key
|
"secretsmanager:DescribeSecret",
|
||||||
"kms:ListAliases", // if you need to specify the KMS key
|
"secretsmanager:TagResource",
|
||||||
"kms:Encrypt", // if you need to specify the KMS key
|
"secretsmanager:UntagResource",
|
||||||
"kms:Decrypt" // if you need to specify the KMS key
|
"kms:ListAliases", // if you need to specify the KMS key
|
||||||
|
"kms:Encrypt", // if you need to specify the KMS key
|
||||||
|
"kms:Decrypt", // if you need to specify the KMS key
|
||||||
|
"kms:DescribeKey" // if you need to specify the KMS key
|
||||||
],
|
],
|
||||||
"Resource": "*"
|
"Resource": "*"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. </Note>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
<Accordion title="AWS Parameter Store">
|
<Accordion title="AWS Parameter Store">
|
||||||
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
|
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
|
||||||
@@ -255,25 +263,25 @@ Infisical supports two methods for connecting to AWS.
|
|||||||
"Sid": "AllowSSMAccess",
|
"Sid": "AllowSSMAccess",
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Action": [
|
"Action": [
|
||||||
"ssm:PutParameter",
|
"ssm:PutParameter",
|
||||||
"ssm:DeleteParameter",
|
"ssm:GetParameters",
|
||||||
"ssm:GetParameters",
|
"ssm:GetParametersByPath",
|
||||||
"ssm:GetParametersByPath",
|
"ssm:DescribeParameters",
|
||||||
"ssm:DescribeParameters",
|
"ssm:DeleteParameters",
|
||||||
"ssm:DeleteParameters",
|
"ssm:ListTagsForResource", // if you need to add tags to secrets
|
||||||
"ssm:ListTagsForResource", // if you need to add tags to secrets
|
"ssm:AddTagsToResource", // if you need to add tags to secrets
|
||||||
"ssm:AddTagsToResource", // if you need to add tags to secrets
|
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets
|
||||||
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets
|
"kms:ListAliases", // if you need to specify the KMS key
|
||||||
"kms:ListKeys", // if you need to specify the KMS key
|
"kms:Encrypt", // if you need to specify the KMS key
|
||||||
"kms:ListAliases", // if you need to specify the KMS key
|
"kms:Decrypt", // if you need to specify the KMS key
|
||||||
"kms:Encrypt", // if you need to specify the KMS key
|
"kms:DescribeKey" // if you need to specify the KMS key
|
||||||
"kms:Decrypt" // if you need to specify the KMS key
|
|
||||||
],
|
],
|
||||||
"Resource": "*"
|
"Resource": "*"
|
||||||
}
|
}
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
```
|
```
|
||||||
|
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. </Note>
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
</Tab>
|
</Tab>
|
||||||
|
|||||||
@@ -80,7 +80,7 @@ via the UI or API for the third-party service you intend to sync secrets to.
|
|||||||
<Note>
|
<Note>
|
||||||
Secret Syncs are the source of truth for connected third-party services. Any secret,
|
Secret Syncs are the source of truth for connected third-party services. Any secret,
|
||||||
including associated data, not present or imported in Infisical before syncing will be
|
including associated data, not present or imported in Infisical before syncing will be
|
||||||
overwritten, and changes directly in the connected service outside of infisical may also
|
overwritten, and changes made directly in the connected service outside of infisical may also
|
||||||
be overwritten by future syncs.
|
be overwritten by future syncs.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
|
|||||||
@@ -138,8 +138,8 @@ export const CreateSecretSyncForm = ({ destination, onComplete, onCancel }: Prop
|
|||||||
<p className="mt-1 text-sm text-bunker-200">
|
<p className="mt-1 text-sm text-bunker-200">
|
||||||
Secret Syncs are the source of truth for connected third-party services. Any secret,
|
Secret Syncs are the source of truth for connected third-party services. Any secret,
|
||||||
including associated data, not present or imported in Infisical before syncing will be
|
including associated data, not present or imported in Infisical before syncing will be
|
||||||
overwritten, and changes directly in the connected service outside of infisical may also
|
overwritten, and changes made directly in the connected service outside of infisical may
|
||||||
be overwritten by future syncs.
|
also be overwritten by future syncs.
|
||||||
</p>
|
</p>
|
||||||
</div>
|
</div>
|
||||||
<div className="mt-4 flex gap-4">
|
<div className="mt-4 flex gap-4">
|
||||||
|
|||||||
+2
-2
@@ -70,11 +70,11 @@ export const AwsParameterStoreSyncOptionsFields = () => {
|
|||||||
To configure a KMS key, ensure the following permissions are present on the
|
To configure a KMS key, ensure the following permissions are present on the
|
||||||
selected IAM role:{" "}
|
selected IAM role:{" "}
|
||||||
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
||||||
"kms:ListKeys"
|
"kms:ListAliases"
|
||||||
</span>
|
</span>
|
||||||
,{" "}
|
,{" "}
|
||||||
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
||||||
"kms:ListAliases"
|
"kms:DescribeKey"
|
||||||
</span>
|
</span>
|
||||||
,{" "}
|
,{" "}
|
||||||
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
||||||
|
|||||||
+2
-2
@@ -72,11 +72,11 @@ export const AwsSecretsManagerSyncOptionsFields = () => {
|
|||||||
To configure a KMS key, ensure the following permissions are present on the
|
To configure a KMS key, ensure the following permissions are present on the
|
||||||
selected IAM role:{" "}
|
selected IAM role:{" "}
|
||||||
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
||||||
"kms:ListKeys"
|
"kms:ListAliases"
|
||||||
</span>
|
</span>
|
||||||
,{" "}
|
,{" "}
|
||||||
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
||||||
"kms:ListAliases"
|
"kms:DescribeKey"
|
||||||
</span>
|
</span>
|
||||||
,{" "}
|
,{" "}
|
||||||
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
<span className="rounded bg-mineshaft-600 text-mineshaft-300">
|
||||||
|
|||||||
Reference in New Issue
Block a user