improvement: address feedback

This commit is contained in:
Scott Wilson
2025-02-20 11:48:47 -08:00
parent f8ab2bcdfd
commit f23ea0991c
10 changed files with 73 additions and 80 deletions
@@ -317,11 +317,13 @@ export const AwsParameterStoreSyncFns = {
continue; continue;
} }
const keyId = syncOptions.keyId ?? "alias/aws/ssm";
// create parameter or update if changed // create parameter or update if changed
if ( if (
!(key in awsParameterStoreSecretsRecord) || !(key in awsParameterStoreSecretsRecord) ||
value !== awsParameterStoreSecretsRecord[key].Value || value !== awsParameterStoreSecretsRecord[key].Value ||
(syncOptions.keyId ?? "alias/aws/ssm") !== awsParameterStoreMetadataRecord[key]?.KeyId keyId !== awsParameterStoreMetadataRecord[key]?.KeyId
) { ) {
try { try {
await putParameter(ssm, { await putParameter(ssm, {
@@ -329,7 +331,7 @@ export const AwsParameterStoreSyncFns = {
Type: "SecureString", Type: "SecureString",
Value: value, Value: value,
Overwrite: true, Overwrite: true,
KeyId: syncOptions.keyId KeyId: keyId
}); });
} catch (error) { } catch (error) {
throw new SecretSyncError({ throw new SecretSyncError({
@@ -318,6 +318,8 @@ export const AwsSecretsManagerSyncFns = {
const syncTagsRecord = Object.fromEntries(syncOptions.tags?.map((tag) => [tag.key, tag.value]) ?? []); const syncTagsRecord = Object.fromEntries(syncOptions.tags?.map((tag) => [tag.key, tag.value]) ?? []);
const keyId = syncOptions.keyId ?? "alias/aws/secretsmanager";
if (destinationConfig.mappingBehavior === AwsSecretsManagerSyncMappingBehavior.OneToOne) { if (destinationConfig.mappingBehavior === AwsSecretsManagerSyncMappingBehavior.OneToOne) {
for await (const entry of Object.entries(secretMap)) { for await (const entry of Object.entries(secretMap)) {
const [key, { value, secretMetadata }] = entry; const [key, { value, secretMetadata }] = entry;
@@ -330,15 +332,12 @@ export const AwsSecretsManagerSyncFns = {
if (awsSecretsRecord[key]) { if (awsSecretsRecord[key]) {
// skip secrets that haven't changed // skip secrets that haven't changed
if ( if (awsValuesRecord[key]?.SecretString !== value || keyId !== awsDescriptionsRecord[key]?.KmsKeyId) {
awsValuesRecord[key]?.SecretString !== value ||
(syncOptions.keyId ?? "alias/aws/secretsmanager") !== awsDescriptionsRecord[key]?.KmsKeyId
) {
try { try {
await updateSecret(client, { await updateSecret(client, {
SecretId: key, SecretId: key,
SecretString: value, SecretString: value,
KmsKeyId: syncOptions.keyId KmsKeyId: keyId
}); });
} catch (error) { } catch (error) {
throw new SecretSyncError({ throw new SecretSyncError({
@@ -352,7 +351,7 @@ export const AwsSecretsManagerSyncFns = {
await createSecret(client, { await createSecret(client, {
Name: key, Name: key,
SecretString: value, SecretString: value,
KmsKeyId: syncOptions.keyId KmsKeyId: keyId
}); });
} catch (error) { } catch (error) {
throw new SecretSyncError({ throw new SecretSyncError({
@@ -416,17 +415,17 @@ export const AwsSecretsManagerSyncFns = {
Object.fromEntries(Object.entries(secretMap).map(([key, secretData]) => [key, secretData.value])) Object.fromEntries(Object.entries(secretMap).map(([key, secretData]) => [key, secretData.value]))
); );
if (awsValuesRecord[destinationConfig.secretName]) { if (awsSecretsRecord[destinationConfig.secretName]) {
await updateSecret(client, { await updateSecret(client, {
SecretId: destinationConfig.secretName, SecretId: destinationConfig.secretName,
SecretString: secretValue, SecretString: secretValue,
KmsKeyId: syncOptions.keyId KmsKeyId: keyId
}); });
} else { } else {
await createSecret(client, { await createSecret(client, {
Name: destinationConfig.secretName, Name: destinationConfig.secretName,
SecretString: secretValue, SecretString: secretValue,
KmsKeyId: syncOptions.keyId KmsKeyId: keyId
}); });
} }
@@ -458,22 +457,6 @@ export const AwsSecretsManagerSyncFns = {
}); });
} }
} }
for await (const secretKey of Object.keys(awsSecretsRecord)) {
if (secretKey === destinationConfig.secretName) {
// eslint-disable-next-line no-continue
continue;
}
try {
await deleteSecret(client, secretKey);
} catch (error) {
throw new SecretSyncError({
error,
secretKey
});
}
}
} }
}, },
getSecrets: async (secretSync: TAwsSecretsManagerSyncWithCredentials): Promise<TSecretMap> => { getSecrets: async (secretSync: TAwsSecretsManagerSyncWithCredentials): Promise<TSecretMap> => {
Binary file not shown.

After

Width:  |  Height:  |  Size: 492 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 306 KiB

After

Width:  |  Height:  |  Size: 500 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 311 KiB

After

Width:  |  Height:  |  Size: 523 KiB

+54 -46
View File
@@ -82,22 +82,26 @@ Infisical supports two methods for connecting to AWS.
"Sid": "AllowSecretsManagerAccess", "Sid": "AllowSecretsManagerAccess",
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"secretsmanager:GetSecretValue", "secretsmanager:ListSecrets",
"secretsmanager:CreateSecret", "secretsmanager:GetSecretValue",
"secretsmanager:UpdateSecret", "secretsmanager:BatchGetSecretValue",
"secretsmanager:DescribeSecret", "secretsmanager:CreateSecret",
"secretsmanager:TagResource", "secretsmanager:UpdateSecret",
"secretsmanager:UntagResource", "secretsmanager:DeleteSecret",
"kms:ListKeys", // if you need to specify the KMS key "secretsmanager:DescribeSecret",
"kms:ListAliases", // if you need to specify the KMS key "secretsmanager:TagResource",
"kms:Encrypt", // if you need to specify the KMS key "secretsmanager:UntagResource",
"kms:Decrypt" // if you need to specify the KMS key "kms:ListAliases", // if you need to specify the KMS key
"kms:Encrypt", // if you need to specify the KMS key
"kms:Decrypt", // if you need to specify the KMS key
"kms:DescribeKey" // if you need to specify the KMS key
], ],
"Resource": "*" "Resource": "*"
} }
] ]
} }
``` ```
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png)</Note>
</Accordion> </Accordion>
<Accordion title="AWS Parameter Store"> <Accordion title="AWS Parameter Store">
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store: Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
@@ -112,25 +116,25 @@ Infisical supports two methods for connecting to AWS.
"Sid": "AllowSSMAccess", "Sid": "AllowSSMAccess",
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ssm:PutParameter", "ssm:PutParameter",
"ssm:DeleteParameter", "ssm:GetParameters",
"ssm:GetParameters", "ssm:GetParametersByPath",
"ssm:GetParametersByPath", "ssm:DescribeParameters",
"ssm:DescribeParameters", "ssm:DeleteParameters",
"ssm:DeleteParameters", "ssm:ListTagsForResource", // if you need to add tags to secrets
"ssm:ListTagsForResource", // if you need to add tags to secrets "ssm:AddTagsToResource", // if you need to add tags to secrets
"ssm:AddTagsToResource", // if you need to add tags to secrets "ssm:RemoveTagsFromResource", // if you need to add tags to secrets
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets "kms:ListAliases", // if you need to specify the KMS key
"kms:ListKeys", // if you need to specify the KMS key "kms:Encrypt", // if you need to specify the KMS key
"kms:ListAliases", // if you need to specify the KMS key "kms:Decrypt", // if you need to specify the KMS key
"kms:Encrypt", // if you need to specify the KMS key "kms:DescribeKey" // if you need to specify the KMS key
"kms:Decrypt" // if you need to specify the KMS key
], ],
"Resource": "*" "Resource": "*"
} }
] ]
} }
``` ```
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png)</Note>
</Accordion> </Accordion>
</AccordionGroup> </AccordionGroup>
</Tab> </Tab>
@@ -225,22 +229,26 @@ Infisical supports two methods for connecting to AWS.
"Sid": "AllowSecretsManagerAccess", "Sid": "AllowSecretsManagerAccess",
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"secretsmanager:GetSecretValue", "secretsmanager:ListSecrets",
"secretsmanager:CreateSecret", "secretsmanager:GetSecretValue",
"secretsmanager:UpdateSecret", "secretsmanager:BatchGetSecretValue",
"secretsmanager:DescribeSecret", "secretsmanager:CreateSecret",
"secretsmanager:TagResource", "secretsmanager:UpdateSecret",
"secretsmanager:UntagResource", "secretsmanager:DeleteSecret",
"kms:ListKeys", // if you need to specify the KMS key "secretsmanager:DescribeSecret",
"kms:ListAliases", // if you need to specify the KMS key "secretsmanager:TagResource",
"kms:Encrypt", // if you need to specify the KMS key "secretsmanager:UntagResource",
"kms:Decrypt" // if you need to specify the KMS key "kms:ListAliases", // if you need to specify the KMS key
"kms:Encrypt", // if you need to specify the KMS key
"kms:Decrypt", // if you need to specify the KMS key
"kms:DescribeKey" // if you need to specify the KMS key
], ],
"Resource": "*" "Resource": "*"
} }
] ]
} }
``` ```
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png)</Note>
</Accordion> </Accordion>
<Accordion title="AWS Parameter Store"> <Accordion title="AWS Parameter Store">
Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store: Use the following custom policy to grant the minimum permissions required by Infisical to sync secrets to AWS Parameter Store:
@@ -255,25 +263,25 @@ Infisical supports two methods for connecting to AWS.
"Sid": "AllowSSMAccess", "Sid": "AllowSSMAccess",
"Effect": "Allow", "Effect": "Allow",
"Action": [ "Action": [
"ssm:PutParameter", "ssm:PutParameter",
"ssm:DeleteParameter", "ssm:GetParameters",
"ssm:GetParameters", "ssm:GetParametersByPath",
"ssm:GetParametersByPath", "ssm:DescribeParameters",
"ssm:DescribeParameters", "ssm:DeleteParameters",
"ssm:DeleteParameters", "ssm:ListTagsForResource", // if you need to add tags to secrets
"ssm:ListTagsForResource", // if you need to add tags to secrets "ssm:AddTagsToResource", // if you need to add tags to secrets
"ssm:AddTagsToResource", // if you need to add tags to secrets "ssm:RemoveTagsFromResource", // if you need to add tags to secrets
"ssm:RemoveTagsFromResource", // if you need to add tags to secrets "kms:ListAliases", // if you need to specify the KMS key
"kms:ListKeys", // if you need to specify the KMS key "kms:Encrypt", // if you need to specify the KMS key
"kms:ListAliases", // if you need to specify the KMS key "kms:Decrypt", // if you need to specify the KMS key
"kms:Encrypt", // if you need to specify the KMS key "kms:DescribeKey" // if you need to specify the KMS key
"kms:Decrypt" // if you need to specify the KMS key
], ],
"Resource": "*" "Resource": "*"
} }
] ]
} }
``` ```
<Note>If using a custom KMS key, be sure to add the IAM role as a key user. ![KMS Key IAM Role User](/images/app-connections/aws/kms-key-user.png)</Note>
</Accordion> </Accordion>
</AccordionGroup> </AccordionGroup>
</Tab> </Tab>
+1 -1
View File
@@ -80,7 +80,7 @@ via the UI or API for the third-party service you intend to sync secrets to.
<Note> <Note>
Secret Syncs are the source of truth for connected third-party services. Any secret, Secret Syncs are the source of truth for connected third-party services. Any secret,
including associated data, not present or imported in Infisical before syncing will be including associated data, not present or imported in Infisical before syncing will be
overwritten, and changes directly in the connected service outside of infisical may also overwritten, and changes made directly in the connected service outside of infisical may also
be overwritten by future syncs. be overwritten by future syncs.
</Note> </Note>
@@ -138,8 +138,8 @@ export const CreateSecretSyncForm = ({ destination, onComplete, onCancel }: Prop
<p className="mt-1 text-sm text-bunker-200"> <p className="mt-1 text-sm text-bunker-200">
Secret Syncs are the source of truth for connected third-party services. Any secret, Secret Syncs are the source of truth for connected third-party services. Any secret,
including associated data, not present or imported in Infisical before syncing will be including associated data, not present or imported in Infisical before syncing will be
overwritten, and changes directly in the connected service outside of infisical may also overwritten, and changes made directly in the connected service outside of infisical may
be overwritten by future syncs. also be overwritten by future syncs.
</p> </p>
</div> </div>
<div className="mt-4 flex gap-4"> <div className="mt-4 flex gap-4">
@@ -70,11 +70,11 @@ export const AwsParameterStoreSyncOptionsFields = () => {
To configure a KMS key, ensure the following permissions are present on the To configure a KMS key, ensure the following permissions are present on the
selected IAM role:{" "} selected IAM role:{" "}
<span className="rounded bg-mineshaft-600 text-mineshaft-300"> <span className="rounded bg-mineshaft-600 text-mineshaft-300">
&#34;kms:ListKeys&#34; &#34;kms:ListAliases&#34;
</span> </span>
,{" "} ,{" "}
<span className="rounded bg-mineshaft-600 text-mineshaft-300"> <span className="rounded bg-mineshaft-600 text-mineshaft-300">
&#34;kms:ListAliases&#34; &#34;kms:DescribeKey&#34;
</span> </span>
,{" "} ,{" "}
<span className="rounded bg-mineshaft-600 text-mineshaft-300"> <span className="rounded bg-mineshaft-600 text-mineshaft-300">
@@ -72,11 +72,11 @@ export const AwsSecretsManagerSyncOptionsFields = () => {
To configure a KMS key, ensure the following permissions are present on the To configure a KMS key, ensure the following permissions are present on the
selected IAM role:{" "} selected IAM role:{" "}
<span className="rounded bg-mineshaft-600 text-mineshaft-300"> <span className="rounded bg-mineshaft-600 text-mineshaft-300">
&#34;kms:ListKeys&#34; &#34;kms:ListAliases&#34;
</span> </span>
,{" "} ,{" "}
<span className="rounded bg-mineshaft-600 text-mineshaft-300"> <span className="rounded bg-mineshaft-600 text-mineshaft-300">
&#34;kms:ListAliases&#34; &#34;kms:DescribeKey&#34;
</span> </span>
,{" "} ,{" "}
<span className="rounded bg-mineshaft-600 text-mineshaft-300"> <span className="rounded bg-mineshaft-600 text-mineshaft-300">