* Secrets: changes to allow a 3rd party keeper / secret references * fix test * make gofmt * lint * fix tests * assign aws secrets manager to @grafana/grafana-operator-experience-squad * rename Keeper.Reference to Keeper.RetrieveReference * rename ModelSecretsManager to ModelAWSSecretsManager * validator: ensure that only one of keeper.Spec.Aws.AccessKey or keeper.Spec.Aws.AssumeRole are set * move secrets manager dep / go mod tidy * move secrets manager dep * keeper validator: move 3rd party secret stores validation to their own functions * add github.com/aws/aws-sdk-go-v2/service/secretsmanager pkg/extensions/enterprise_imports * make update-workspace * undo go.mod changes in /apps * make update-workspace * fix test * add github.com/aws/aws-sdk-go-v2/service/secretsmanager to enterprise_imports * make update-workspace * gcworker: handle refs * make update-workspace * create toggle: FeatureStageExperimental * allow features.IsEnabled for now * format
57 lines
2.6 KiB
Go
57 lines
2.6 KiB
Go
package contracts
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
|
|
"k8s.io/client-go/dynamic"
|
|
|
|
secretv1beta1 "github.com/grafana/grafana/apps/secret/pkg/apis/secret/v1beta1"
|
|
"github.com/grafana/grafana/pkg/registry/apis/secret/xkube"
|
|
)
|
|
|
|
// The maximum size of a secure value in bytes when written as raw input.
|
|
const SecureValueRawInputMaxSizeBytes = 24 << 10 // 24 KiB
|
|
|
|
type DecryptSecureValue struct {
|
|
Keeper *string
|
|
Ref string
|
|
ExternalID string
|
|
Decrypters []string
|
|
}
|
|
|
|
var (
|
|
ErrSecureValueNotFound = errors.New("secure value not found")
|
|
ErrSecureValueAlreadyExists = errors.New("secure value already exists")
|
|
ErrReferenceWithSystemKeeper = errors.New("tried to create secure value using reference with system keeper, references can only be used with 3rd party keepers")
|
|
ErrSecureValueMissingSecretAndRef = errors.New("secure value spec doesn't have neither a secret or reference")
|
|
)
|
|
|
|
type ReadOpts struct {
|
|
ForUpdate bool
|
|
}
|
|
|
|
// SecureValueMetadataStorage is the interface for wiring and dependency injection.
|
|
type SecureValueMetadataStorage interface {
|
|
Create(ctx context.Context, keeper string, sv *secretv1beta1.SecureValue, actorUID string) (*secretv1beta1.SecureValue, error)
|
|
Read(ctx context.Context, namespace xkube.Namespace, name string, opts ReadOpts) (*secretv1beta1.SecureValue, error)
|
|
List(ctx context.Context, namespace xkube.Namespace) ([]secretv1beta1.SecureValue, error)
|
|
SetVersionToActive(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
|
SetVersionToInactive(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
|
SetExternalID(ctx context.Context, namespace xkube.Namespace, name string, version int64, externalID ExternalID) error
|
|
Delete(ctx context.Context, namespace xkube.Namespace, name string, version int64) error
|
|
LeaseInactiveSecureValues(ctx context.Context, maxBatchSize uint16) ([]secretv1beta1.SecureValue, error)
|
|
}
|
|
|
|
type SecureValueService interface {
|
|
Create(ctx context.Context, sv *secretv1beta1.SecureValue, actorUID string) (*secretv1beta1.SecureValue, error)
|
|
Read(ctx context.Context, namespace xkube.Namespace, name string) (*secretv1beta1.SecureValue, error)
|
|
List(ctx context.Context, namespace xkube.Namespace) (*secretv1beta1.SecureValueList, error)
|
|
Update(ctx context.Context, newSecureValue *secretv1beta1.SecureValue, actorUID string) (*secretv1beta1.SecureValue, bool, error)
|
|
Delete(ctx context.Context, namespace xkube.Namespace, name string) (*secretv1beta1.SecureValue, error)
|
|
}
|
|
|
|
type SecureValueClient interface {
|
|
Client(ctx context.Context, namespace string) (dynamic.ResourceInterface, error)
|
|
}
|