SecretsManager: Add base encryption manager (#107562)

Co-authored-by: Michael Mandrus <michael.mandrus@grafana.com>
Co-authored-by: Matheus Macabu <macabu@users.noreply.github.com>
This commit is contained in:
Dana Axinte
2025-07-03 11:29:14 +01:00
committed by GitHub
co-authored by Michael Mandrus Matheus Macabu
parent 93c14c52da
commit 4d8678c7f2
28 changed files with 1173 additions and 431 deletions
@@ -0,0 +1,28 @@
package defaultprovider
import (
"context"
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption"
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption/cipher"
)
type grafanaProvider struct {
sk string
encryption cipher.Cipher
}
func New(sk string, encryption cipher.Cipher) encryption.Provider {
return grafanaProvider{
sk: sk,
encryption: encryption,
}
}
func (p grafanaProvider) Encrypt(ctx context.Context, blob []byte) ([]byte, error) {
return p.encryption.Encrypt(ctx, blob, p.sk)
}
func (p grafanaProvider) Decrypt(ctx context.Context, blob []byte) ([]byte, error) {
return p.encryption.Decrypt(ctx, blob, p.sk)
}
@@ -0,0 +1,19 @@
package kmsproviders
import (
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption"
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption/cipher"
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption/kmsproviders/defaultprovider"
"github.com/grafana/grafana/pkg/setting"
)
const (
// Default is the identifier of the default kms provider which fallbacks to the configured secret_key
Default = "secretKey.v1"
)
func GetOSSKMSProviders(cfg *setting.Cfg, enc cipher.Cipher) encryption.ProviderMap {
return encryption.ProviderMap{
Default: defaultprovider.New(cfg.SecretsManagement.SecretKey, enc),
}
}