Encryption: Extend secrets service to support registering key providers (#40626)

* Draft adding kms providers

* Rename defaultProvider to currentProvider

* Add getting current provider from config

* Remove comments

* Make current provider service struct field

* Add methods to secrets service

* Test getting current provider

* Implements missing methods for fake secrets service

* Remove accidental changes

* Fix linter issue

* Update configuration examples

* Rename CurrentProvider method

* Split service interface

* Update wire

Co-authored-by: spinillos <selenepinillos@gmail.com>
This commit is contained in:
Tania B
2021-11-04 19:25:01 +02:00
committed by GitHub
co-authored by spinillos
parent 9f205cf1d7
commit e81d434edf
7 changed files with 81 additions and 2 deletions
+44 -1
View File
@@ -4,15 +4,19 @@ import (
"context"
"testing"
"github.com/grafana/grafana/pkg/bus"
"github.com/grafana/grafana/pkg/services/encryption/ossencryption"
"github.com/grafana/grafana/pkg/services/secrets"
"github.com/grafana/grafana/pkg/services/secrets/database"
"github.com/grafana/grafana/pkg/services/sqlstore"
"github.com/grafana/grafana/pkg/setting"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
"gopkg.in/ini.v1"
)
func TestSecrets_EnvelopeEncryption(t *testing.T) {
func TestSecretsService_EnvelopeEncryption(t *testing.T) {
store := database.ProvideSecretsStore(sqlstore.InitTestDB(t))
svc := SetupTestService(t, store)
ctx := context.Background()
@@ -141,3 +145,42 @@ func TestSecretsService_DataKeys(t *testing.T) {
assert.Nil(t, res)
})
}
func TestSecretsService_GetCurrentProvider(t *testing.T) {
t.Run("When encryption_provider is not specified explicitly, should use 'secretKey' as a current provider", func(t *testing.T) {
cfg := `[security]
secret_key = sdDkslslld`
raw, err := ini.Load([]byte(cfg))
require.NoError(t, err)
settings := &setting.OSSImpl{Cfg: &setting.Cfg{Raw: raw}}
svc := ProvideSecretsService(
database.ProvideSecretsStore(sqlstore.InitTestDB(t)),
bus.New(),
ossencryption.ProvideService(),
settings,
)
assert.Equal(t, "secretKey", svc.currentProvider)
})
t.Run("When encryption_provider value is set, should use it as a current provider", func(t *testing.T) {
cfg := `[security]
secret_key = sdDkslslld
encryption_provider = awskms.second_key`
raw, err := ini.Load([]byte(cfg))
require.NoError(t, err)
settings := &setting.OSSImpl{Cfg: &setting.Cfg{Raw: raw}}
svc := ProvideSecretsService(
database.ProvideSecretsStore(sqlstore.InitTestDB(t)),
bus.New(),
ossencryption.ProvideService(),
settings,
)
assert.Equal(t, "awskms.second_key", svc.currentProvider)
})
}