Secrets: remove unused SecureValueMetadataStorage.ReadForDecrypt method (#108181)
* Secrets: remove unused SecureValueMetadataStorage.ReadForDecrypt method * remove unused struct: secureValueForDecrypt
This commit is contained in:
@@ -36,7 +36,6 @@ type SecureValueMetadataStorage interface {
|
|||||||
SetVersionToActive(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
SetVersionToActive(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
||||||
SetVersionToInactive(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
SetVersionToInactive(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
||||||
SetExternalID(ctx context.Context, namespace xkube.Namespace, name string, version int64, externalID ExternalID) error
|
SetExternalID(ctx context.Context, namespace xkube.Namespace, name string, version int64, externalID ExternalID) error
|
||||||
ReadForDecrypt(ctx context.Context, namespace xkube.Namespace, name string) (*DecryptSecureValue, error)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
type SecureValueService interface {
|
type SecureValueService interface {
|
||||||
|
|||||||
@@ -1,13 +0,0 @@
|
|||||||
SELECT
|
|
||||||
{{ .Ident "keeper" }},
|
|
||||||
{{ .Ident "decrypters" }},
|
|
||||||
{{ .Ident "ref" }},
|
|
||||||
{{ .Ident "external_id" }},
|
|
||||||
{{ .Ident "active" }}
|
|
||||||
FROM
|
|
||||||
{{ .Ident "secret_secure_value" }}
|
|
||||||
WHERE
|
|
||||||
{{ .Ident "namespace" }} = {{ .Arg .Namespace }} AND
|
|
||||||
{{ .Ident "name" }} = {{ .Arg .Name }} AND
|
|
||||||
{{ .Ident "active" }} = true
|
|
||||||
;
|
|
||||||
@@ -28,7 +28,6 @@ var (
|
|||||||
sqlSecureValueList = mustTemplate("secure_value_list.sql")
|
sqlSecureValueList = mustTemplate("secure_value_list.sql")
|
||||||
sqlSecureValueCreate = mustTemplate("secure_value_create.sql")
|
sqlSecureValueCreate = mustTemplate("secure_value_create.sql")
|
||||||
sqlSecureValueUpdateExternalId = mustTemplate("secure_value_updateExternalId.sql")
|
sqlSecureValueUpdateExternalId = mustTemplate("secure_value_updateExternalId.sql")
|
||||||
sqlSecureValueReadForDecrypt = mustTemplate("secure_value_read_for_decrypt.sql")
|
|
||||||
|
|
||||||
sqlGetLatestSecureValueVersion = mustTemplate("secure_value_get_latest_version.sql")
|
sqlGetLatestSecureValueVersion = mustTemplate("secure_value_get_latest_version.sql")
|
||||||
sqlSecureValueSetVersionToActive = mustTemplate("secure_value_set_version_to_active.sql")
|
sqlSecureValueSetVersionToActive = mustTemplate("secure_value_set_version_to_active.sql")
|
||||||
@@ -209,11 +208,3 @@ type updateExternalIdSecureValue struct {
|
|||||||
func (r updateExternalIdSecureValue) Validate() error {
|
func (r updateExternalIdSecureValue) Validate() error {
|
||||||
return nil // TODO
|
return nil // TODO
|
||||||
}
|
}
|
||||||
|
|
||||||
type readSecureValueForDecrypt struct {
|
|
||||||
sqltemplate.SQLTemplate
|
|
||||||
Namespace string
|
|
||||||
Name string
|
|
||||||
}
|
|
||||||
|
|
||||||
func (r readSecureValueForDecrypt) Validate() error { return nil }
|
|
||||||
|
|||||||
@@ -230,16 +230,6 @@ func TestSecureValueQueries(t *testing.T) {
|
|||||||
},
|
},
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
sqlSecureValueReadForDecrypt: {
|
|
||||||
{
|
|
||||||
Name: "read-for-decrypt",
|
|
||||||
Data: &readSecureValueForDecrypt{
|
|
||||||
SQLTemplate: mocks.NewTestingSQLTemplate(),
|
|
||||||
Name: "name",
|
|
||||||
Namespace: "ns",
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
|
||||||
},
|
},
|
||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -9,7 +9,6 @@ import (
|
|||||||
"github.com/google/uuid"
|
"github.com/google/uuid"
|
||||||
secretv1beta1 "github.com/grafana/grafana/apps/secret/pkg/apis/secret/v1beta1"
|
secretv1beta1 "github.com/grafana/grafana/apps/secret/pkg/apis/secret/v1beta1"
|
||||||
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
"github.com/grafana/grafana/pkg/apimachinery/utils"
|
||||||
"github.com/grafana/grafana/pkg/registry/apis/secret/contracts"
|
|
||||||
"github.com/grafana/grafana/pkg/registry/apis/secret/xkube"
|
"github.com/grafana/grafana/pkg/registry/apis/secret/xkube"
|
||||||
"github.com/grafana/grafana/pkg/storage/secret/migrator"
|
"github.com/grafana/grafana/pkg/storage/secret/migrator"
|
||||||
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
|
||||||
@@ -201,39 +200,6 @@ func toRow(sv *secretv1beta1.SecureValue, externalID string) (*secureValueDB, er
|
|||||||
}, nil
|
}, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// DTO for `secureValueForDecrypt` query result, only what we need.
|
|
||||||
type secureValueForDecrypt struct {
|
|
||||||
Keeper sql.NullString
|
|
||||||
Decrypters sql.NullString
|
|
||||||
Ref sql.NullString
|
|
||||||
Active bool
|
|
||||||
ExternalID string
|
|
||||||
}
|
|
||||||
|
|
||||||
// to Decrypt maps a DB row into a DecryptSecureValue object needed for decryption.
|
|
||||||
func (sv *secureValueForDecrypt) toDecrypt() (*contracts.DecryptSecureValue, error) {
|
|
||||||
decrypters := make([]string, 0)
|
|
||||||
if sv.Decrypters.Valid && sv.Decrypters.String != "" {
|
|
||||||
if err := json.Unmarshal([]byte(sv.Decrypters.String), &decrypters); err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to unmarshal decrypters: %w", err)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
decryptSecureValue := &contracts.DecryptSecureValue{
|
|
||||||
Decrypters: decrypters,
|
|
||||||
ExternalID: sv.ExternalID,
|
|
||||||
}
|
|
||||||
|
|
||||||
if sv.Keeper.Valid && sv.Keeper.String != "" {
|
|
||||||
decryptSecureValue.Keeper = &sv.Keeper.String
|
|
||||||
}
|
|
||||||
if sv.Ref.Valid && sv.Ref.String != "" {
|
|
||||||
decryptSecureValue.Ref = sv.Ref.String
|
|
||||||
}
|
|
||||||
|
|
||||||
return decryptSecureValue, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
// toNullString returns a sql.NullString struct given a *string
|
// toNullString returns a sql.NullString struct given a *string
|
||||||
// assumes that "" (empty string) is a valid string
|
// assumes that "" (empty string) is a valid string
|
||||||
func toNullString(s *string) sql.NullString {
|
func toNullString(s *string) sql.NullString {
|
||||||
|
|||||||
@@ -191,60 +191,6 @@ func (s *secureValueMetadataStorage) getLatestVersion(ctx context.Context, names
|
|||||||
return &version, nil
|
return &version, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// TODO: can this method + queries be removed?
|
|
||||||
func (s *secureValueMetadataStorage) ReadForDecrypt(ctx context.Context, namespace xkube.Namespace, name string) (*contracts.DecryptSecureValue, error) {
|
|
||||||
start := time.Now()
|
|
||||||
ctx, span := s.tracer.Start(ctx, "SecureValueMetadataStorage.ReadForDecrypt", trace.WithAttributes(
|
|
||||||
attribute.String("name", name),
|
|
||||||
attribute.String("namespace", namespace.String()),
|
|
||||||
))
|
|
||||||
defer span.End()
|
|
||||||
|
|
||||||
req := readSecureValueForDecrypt{
|
|
||||||
SQLTemplate: sqltemplate.New(s.dialect),
|
|
||||||
Namespace: namespace.String(),
|
|
||||||
Name: name,
|
|
||||||
}
|
|
||||||
|
|
||||||
query, err := sqltemplate.Execute(sqlSecureValueReadForDecrypt, req)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("execute template %q: %w", sqlSecureValueReadForDecrypt.Name(), err)
|
|
||||||
}
|
|
||||||
|
|
||||||
res, err := s.db.QueryContext(ctx, query, req.GetArgs()...)
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("reading row: %w", err)
|
|
||||||
}
|
|
||||||
defer func() { _ = res.Close() }()
|
|
||||||
|
|
||||||
var row secureValueForDecrypt
|
|
||||||
if !res.Next() {
|
|
||||||
return nil, contracts.ErrSecureValueNotFound
|
|
||||||
}
|
|
||||||
if err := res.Scan(
|
|
||||||
&row.Keeper, &row.Decrypters,
|
|
||||||
&row.Ref, &row.ExternalID, &row.Active); err != nil {
|
|
||||||
return nil, fmt.Errorf("failed to scan secure value row: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if err := res.Err(); err != nil {
|
|
||||||
return nil, fmt.Errorf("read rows error: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if !row.Active {
|
|
||||||
return nil, fmt.Errorf("bug: read an inactive version: row=%+v", row)
|
|
||||||
}
|
|
||||||
|
|
||||||
secureValue, err := row.toDecrypt()
|
|
||||||
if err != nil {
|
|
||||||
return nil, fmt.Errorf("convert to kubernetes object: %w", err)
|
|
||||||
}
|
|
||||||
|
|
||||||
s.metrics.SecureValueGetForDecryptDuration.Observe(time.Since(start).Seconds())
|
|
||||||
|
|
||||||
return secureValue, nil
|
|
||||||
}
|
|
||||||
|
|
||||||
func (s *secureValueMetadataStorage) readActiveVersion(ctx context.Context, namespace xkube.Namespace, name string, opts contracts.ReadOpts) (secureValueDB, error) {
|
func (s *secureValueMetadataStorage) readActiveVersion(ctx context.Context, namespace xkube.Namespace, name string, opts contracts.ReadOpts) (secureValueDB, error) {
|
||||||
req := readSecureValue{
|
req := readSecureValue{
|
||||||
SQLTemplate: sqltemplate.New(s.dialect),
|
SQLTemplate: sqltemplate.New(s.dialect),
|
||||||
|
|||||||
Vendored
-13
@@ -1,13 +0,0 @@
|
|||||||
SELECT
|
|
||||||
`keeper`,
|
|
||||||
`decrypters`,
|
|
||||||
`ref`,
|
|
||||||
`external_id`,
|
|
||||||
`active`
|
|
||||||
FROM
|
|
||||||
`secret_secure_value`
|
|
||||||
WHERE
|
|
||||||
`namespace` = 'ns' AND
|
|
||||||
`name` = 'name' AND
|
|
||||||
`active` = true
|
|
||||||
;
|
|
||||||
Vendored
-13
@@ -1,13 +0,0 @@
|
|||||||
SELECT
|
|
||||||
"keeper",
|
|
||||||
"decrypters",
|
|
||||||
"ref",
|
|
||||||
"external_id",
|
|
||||||
"active"
|
|
||||||
FROM
|
|
||||||
"secret_secure_value"
|
|
||||||
WHERE
|
|
||||||
"namespace" = 'ns' AND
|
|
||||||
"name" = 'name' AND
|
|
||||||
"active" = true
|
|
||||||
;
|
|
||||||
Vendored
-13
@@ -1,13 +0,0 @@
|
|||||||
SELECT
|
|
||||||
"keeper",
|
|
||||||
"decrypters",
|
|
||||||
"ref",
|
|
||||||
"external_id",
|
|
||||||
"active"
|
|
||||||
FROM
|
|
||||||
"secret_secure_value"
|
|
||||||
WHERE
|
|
||||||
"namespace" = 'ns' AND
|
|
||||||
"name" = 'name' AND
|
|
||||||
"active" = true
|
|
||||||
;
|
|
||||||
Reference in New Issue
Block a user