Encryption: Fix multiple data keys migration (#49848)

* Add migration

* Migrator: Extend support to rename columns

* Fix getting current key

* Fix column name in migration

* Fix deks reencryption

* Fix caching

* Add back separate caches for byName and byPrefix

* Do not concatenate prefix with uid

* Rename DataKey struc fields

* SQLStore: Add deprecation comments for breaking migrations

* Add comment

* Minor corrections

Co-authored-by: Joan López de la Franca Beltran <joanjan14@gmail.com>
This commit is contained in:
Tania
2022-06-04 12:55:49 +02:00
committed by GitHub
co-authored by Joan López de la Franca Beltran
parent 8de4ffe61f
commit 4f8111e24e
9 changed files with 85 additions and 55 deletions
+11 -10
View File
@@ -14,8 +14,9 @@ var (
type dataKeyCacheEntry struct {
id string
name string
label string
dataKey []byte
active bool
expiration time.Time
}
@@ -26,14 +27,14 @@ func (e dataKeyCacheEntry) expired() bool {
type dataKeyCache struct {
mtx sync.RWMutex
byId map[string]*dataKeyCacheEntry
byName map[string]*dataKeyCacheEntry
byLabel map[string]*dataKeyCacheEntry
cacheTTL time.Duration
}
func newDataKeyCache(ttl time.Duration) *dataKeyCache {
return &dataKeyCache{
byId: make(map[string]*dataKeyCacheEntry),
byName: make(map[string]*dataKeyCacheEntry),
byLabel: make(map[string]*dataKeyCacheEntry),
cacheTTL: ttl,
}
}
@@ -56,15 +57,15 @@ func (c *dataKeyCache) getById(id string) (*dataKeyCacheEntry, bool) {
return entry, true
}
func (c *dataKeyCache) getByName(name string) (*dataKeyCacheEntry, bool) {
func (c *dataKeyCache) getByLabel(label string) (*dataKeyCacheEntry, bool) {
c.mtx.RLock()
defer c.mtx.RUnlock()
entry, exists := c.byName[name]
entry, exists := c.byLabel[label]
cacheReadsCounter.With(prometheus.Labels{
"hit": strconv.FormatBool(exists),
"method": "byName",
"method": "byLabel",
}).Inc()
if !exists || entry.expired() {
@@ -81,7 +82,7 @@ func (c *dataKeyCache) add(entry *dataKeyCacheEntry) {
entry.expiration = now().Add(c.cacheTTL)
c.byId[entry.id] = entry
c.byName[entry.name] = entry
c.byLabel[entry.label] = entry
}
func (c *dataKeyCache) removeExpired() {
@@ -94,9 +95,9 @@ func (c *dataKeyCache) removeExpired() {
}
}
for name, entry := range c.byName {
for label, entry := range c.byLabel {
if entry.expired() {
delete(c.byName, name)
delete(c.byLabel, label)
}
}
}
@@ -104,6 +105,6 @@ func (c *dataKeyCache) removeExpired() {
func (c *dataKeyCache) flush() {
c.mtx.Lock()
c.byId = make(map[string]*dataKeyCacheEntry)
c.byName = make(map[string]*dataKeyCacheEntry)
c.byLabel = make(map[string]*dataKeyCacheEntry)
c.mtx.Unlock()
}