Secrets service: Allow decrypt through gRPC connection (#108365)

This commit is contained in:
Stephanie Hingtgen
2025-07-29 07:51:37 -05:00
committed by GitHub
parent 73d64d3e46
commit ef9f9c2d8e
15 changed files with 717 additions and 62 deletions
@@ -8,6 +8,9 @@ import (
"github.com/grafana/grafana/pkg/registry/apis/secret/xkube"
)
// HeaderGrafanaServiceIdentityName is used to pass the service identity in the gRPC request metadata.
const HeaderGrafanaServiceIdentityName = "X-Grafana-Service-Identity-Name"
var (
ErrDecryptNotFound = errors.New("not found")
ErrDecryptNotAuthorized = errors.New("not authorized")
@@ -27,6 +30,7 @@ type DecryptAuthorizer interface {
// DecryptService is the inferface for the decrypt service.
type DecryptService interface {
Decrypt(ctx context.Context, namespace string, names ...string) (map[string]DecryptResult, error)
Close() error
}
// DecryptResult is the (union) result of a decryption operation.