mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: encrypt gitsshkeys.private_key at rest via dbcrypt (#25872)
Adds an optional dbcrypt wrapper around gitsshkeys.private_key. The column is encrypted on insert and update through enterprise/dbcrypt when external token encryption is configured, and decrypted on read. A new private_key_key_id column references dbcrypt_keys(active_key_digest) so revocation safety is enforced by the existing foreign key. Rows with a NULL key_id stay plaintext and remain readable. Existing plaintext rows can be backfilled by running `coder server dbcrypt rotate`. Generated with assistance from Coder Agents.
This commit is contained in:
@@ -1021,11 +1021,12 @@ func User(t testing.TB, db database.Store, orig database.User) database.User {
|
||||
|
||||
func GitSSHKey(t testing.TB, db database.Store, orig database.GitSSHKey) database.GitSSHKey {
|
||||
key, err := db.InsertGitSSHKey(genCtx, database.InsertGitSSHKeyParams{
|
||||
UserID: takeFirst(orig.UserID, uuid.New()),
|
||||
CreatedAt: takeFirst(orig.CreatedAt, dbtime.Now()),
|
||||
UpdatedAt: takeFirst(orig.UpdatedAt, dbtime.Now()),
|
||||
PrivateKey: takeFirst(orig.PrivateKey, ""),
|
||||
PublicKey: takeFirst(orig.PublicKey, ""),
|
||||
UserID: takeFirst(orig.UserID, uuid.New()),
|
||||
CreatedAt: takeFirst(orig.CreatedAt, dbtime.Now()),
|
||||
UpdatedAt: takeFirst(orig.UpdatedAt, dbtime.Now()),
|
||||
PrivateKey: takeFirst(orig.PrivateKey, ""),
|
||||
PrivateKeyKeyID: takeFirst(orig.PrivateKeyKeyID, sql.NullString{}),
|
||||
PublicKey: takeFirst(orig.PublicKey, ""),
|
||||
})
|
||||
require.NoError(t, err, "insert ssh key")
|
||||
return key
|
||||
|
||||
Reference in New Issue
Block a user