Secrets service: Allow decrypt through gRPC connection (#108365)

This commit is contained in:
Stephanie Hingtgen
2025-07-29 07:51:37 -05:00
committed by GitHub
parent 73d64d3e46
commit ef9f9c2d8e
15 changed files with 717 additions and 62 deletions
@@ -0,0 +1,39 @@
package decrypt
import (
"context"
"github.com/grafana/grafana/pkg/registry/apis/secret/contracts"
"github.com/grafana/grafana/pkg/registry/apis/secret/xkube"
)
type LocalDecryptClient struct {
decryptStorage contracts.DecryptStorage
}
var _ contracts.DecryptService = &LocalDecryptClient{}
func NewLocalDecryptClient(decryptStorage contracts.DecryptStorage) (*LocalDecryptClient, error) {
return &LocalDecryptClient{
decryptStorage: decryptStorage,
}, nil
}
func (c *LocalDecryptClient) Decrypt(ctx context.Context, namespace string, names ...string) (map[string]contracts.DecryptResult, error) {
results := make(map[string]contracts.DecryptResult, len(names))
for _, name := range names {
exposedSecureValue, err := c.decryptStorage.Decrypt(ctx, xkube.Namespace(namespace), name)
if err != nil {
results[name] = contracts.NewDecryptResultErr(err)
} else {
results[name] = contracts.NewDecryptResultValue(&exposedSecureValue)
}
}
return results, nil
}
func (c *LocalDecryptClient) Close() error {
return nil
}