Encryption: Add support for multiple data keys per day (#47765)
* Add database migrations * Use short uids as data key ids * Add support for manual data key rotation * Fix duplicated mutex unlocks * Fix migration * Manage current data keys per name * Adjust key re-encryption and test * Modify rename column migration for MySQL compatibility * Refactor secrets manager and data keys cache * Multiple o11y adjustments * Fix stats query * Apply suggestions from code review Co-authored-by: Tania <yalyna.ts@gmail.com> * Fix linter * Docs: Rotate data encryption keys API endpoint Co-authored-by: Tania <yalyna.ts@gmail.com>
This commit is contained in:
co-authored by
Tania
parent
ae8c11bfa4
commit
e43879e55d
@@ -4,6 +4,7 @@ import (
|
||||
"context"
|
||||
"fmt"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"xorm.io/xorm"
|
||||
)
|
||||
@@ -25,16 +26,19 @@ type Service interface {
|
||||
|
||||
GetDecryptedValue(ctx context.Context, sjd map[string][]byte, key, fallback string) string
|
||||
|
||||
RotateDataKeys(ctx context.Context) error
|
||||
ReEncryptDataKeys(ctx context.Context) error
|
||||
}
|
||||
|
||||
// Store defines methods to interact with secrets storage
|
||||
type Store interface {
|
||||
GetDataKey(ctx context.Context, name string) (*DataKey, error)
|
||||
GetDataKey(ctx context.Context, id string) (*DataKey, error)
|
||||
GetCurrentDataKey(ctx context.Context, name string) (*DataKey, error)
|
||||
GetAllDataKeys(ctx context.Context) ([]*DataKey, error)
|
||||
CreateDataKey(ctx context.Context, dataKey DataKey) error
|
||||
CreateDataKeyWithDBSession(ctx context.Context, dataKey DataKey, sess *xorm.Session) error
|
||||
DeleteDataKey(ctx context.Context, name string) error
|
||||
CreateDataKey(ctx context.Context, dataKey *DataKey) error
|
||||
CreateDataKeyWithDBSession(ctx context.Context, dataKey *DataKey, sess *xorm.Session) error
|
||||
DisableDataKeys(ctx context.Context) error
|
||||
DeleteDataKey(ctx context.Context, id string) error
|
||||
ReEncryptDataKeys(ctx context.Context, providers map[ProviderID]Provider, currProvider ProviderID) error
|
||||
}
|
||||
|
||||
@@ -57,6 +61,10 @@ func (id ProviderID) Kind() (string, error) {
|
||||
return parts[0], nil
|
||||
}
|
||||
|
||||
func KeyName(scope string, providerID ProviderID) string {
|
||||
return fmt.Sprintf("%s/%s@%s", time.Now().Format("2006-01-02"), scope, providerID)
|
||||
}
|
||||
|
||||
// BackgroundProvider should be implemented for a provider that has a task that needs to be run in the background.
|
||||
type BackgroundProvider interface {
|
||||
Run(ctx context.Context) error
|
||||
|
||||
Reference in New Issue
Block a user