SecretsManager: Add base encryption manager (#107562)
Co-authored-by: Michael Mandrus <michael.mandrus@grafana.com> Co-authored-by: Matheus Macabu <macabu@users.noreply.github.com>
This commit is contained in:
co-authored by
Michael Mandrus
Matheus Macabu
parent
93c14c52da
commit
4d8678c7f2
@@ -0,0 +1,28 @@
|
||||
package defaultprovider
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption/cipher"
|
||||
)
|
||||
|
||||
type grafanaProvider struct {
|
||||
sk string
|
||||
encryption cipher.Cipher
|
||||
}
|
||||
|
||||
func New(sk string, encryption cipher.Cipher) encryption.Provider {
|
||||
return grafanaProvider{
|
||||
sk: sk,
|
||||
encryption: encryption,
|
||||
}
|
||||
}
|
||||
|
||||
func (p grafanaProvider) Encrypt(ctx context.Context, blob []byte) ([]byte, error) {
|
||||
return p.encryption.Encrypt(ctx, blob, p.sk)
|
||||
}
|
||||
|
||||
func (p grafanaProvider) Decrypt(ctx context.Context, blob []byte) ([]byte, error) {
|
||||
return p.encryption.Decrypt(ctx, blob, p.sk)
|
||||
}
|
||||
@@ -0,0 +1,19 @@
|
||||
package kmsproviders
|
||||
|
||||
import (
|
||||
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption/cipher"
|
||||
"github.com/grafana/grafana/pkg/registry/apis/secret/encryption/kmsproviders/defaultprovider"
|
||||
"github.com/grafana/grafana/pkg/setting"
|
||||
)
|
||||
|
||||
const (
|
||||
// Default is the identifier of the default kms provider which fallbacks to the configured secret_key
|
||||
Default = "secretKey.v1"
|
||||
)
|
||||
|
||||
func GetOSSKMSProviders(cfg *setting.Cfg, enc cipher.Cipher) encryption.ProviderMap {
|
||||
return encryption.ProviderMap{
|
||||
Default: defaultprovider.New(cfg.SecretsManagement.SecretKey, enc),
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user