mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add awsiamrds db auth driver (#12566)
This commit is contained in:
@@ -12,6 +12,8 @@ import (
|
||||
"cdr.dev/slog/sloggers/sloghuman"
|
||||
"github.com/coder/coder/v2/cli"
|
||||
"github.com/coder/coder/v2/cli/cliui"
|
||||
"github.com/coder/coder/v2/coderd/database/awsiamrds"
|
||||
"github.com/coder/coder/v2/codersdk"
|
||||
"github.com/coder/coder/v2/enterprise/dbcrypt"
|
||||
"github.com/coder/serpent"
|
||||
|
||||
@@ -88,7 +90,15 @@ func (*RootCmd) dbcryptRotateCmd() *serpent.Command {
|
||||
return err
|
||||
}
|
||||
|
||||
sqlDB, err := cli.ConnectToPostgres(inv.Context(), logger, "postgres", flags.PostgresURL)
|
||||
sqlDriver := "postgres"
|
||||
if codersdk.PostgresAuth(flags.PostgresAuth) == codersdk.PostgresAuthAWSIAMRDS {
|
||||
sqlDriver, err = awsiamrds.Register(inv.Context(), sqlDriver)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("register aws rds iam auth: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
sqlDB, err := cli.ConnectToPostgres(inv.Context(), logger, sqlDriver, flags.PostgresURL)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("connect to postgres: %w", err)
|
||||
}
|
||||
@@ -145,7 +155,15 @@ func (*RootCmd) dbcryptDecryptCmd() *serpent.Command {
|
||||
return err
|
||||
}
|
||||
|
||||
sqlDB, err := cli.ConnectToPostgres(inv.Context(), logger, "postgres", flags.PostgresURL)
|
||||
sqlDriver := "postgres"
|
||||
if codersdk.PostgresAuth(flags.PostgresAuth) == codersdk.PostgresAuthAWSIAMRDS {
|
||||
sqlDriver, err = awsiamrds.Register(inv.Context(), sqlDriver)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("register aws rds iam auth: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
sqlDB, err := cli.ConnectToPostgres(inv.Context(), logger, sqlDriver, flags.PostgresURL)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("connect to postgres: %w", err)
|
||||
}
|
||||
@@ -192,7 +210,16 @@ Are you sure you want to continue?`
|
||||
return err
|
||||
}
|
||||
|
||||
sqlDB, err := cli.ConnectToPostgres(inv.Context(), logger, "postgres", flags.PostgresURL)
|
||||
var err error
|
||||
sqlDriver := "postgres"
|
||||
if codersdk.PostgresAuth(flags.PostgresAuth) == codersdk.PostgresAuthAWSIAMRDS {
|
||||
sqlDriver, err = awsiamrds.Register(inv.Context(), sqlDriver)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("register aws rds iam auth: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
sqlDB, err := cli.ConnectToPostgres(inv.Context(), logger, sqlDriver, flags.PostgresURL)
|
||||
if err != nil {
|
||||
return xerrors.Errorf("connect to postgres: %w", err)
|
||||
}
|
||||
@@ -212,9 +239,10 @@ Are you sure you want to continue?`
|
||||
}
|
||||
|
||||
type rotateFlags struct {
|
||||
PostgresURL string
|
||||
New string
|
||||
Old []string
|
||||
PostgresURL string
|
||||
PostgresAuth string
|
||||
New string
|
||||
Old []string
|
||||
}
|
||||
|
||||
func (f *rotateFlags) attach(opts *serpent.OptionSet) {
|
||||
@@ -226,6 +254,14 @@ func (f *rotateFlags) attach(opts *serpent.OptionSet) {
|
||||
Description: "The connection URL for the Postgres database.",
|
||||
Value: serpent.StringOf(&f.PostgresURL),
|
||||
},
|
||||
serpent.Option{
|
||||
Name: "Postgres Connection Auth",
|
||||
Description: "Type of auth to use when connecting to postgres.",
|
||||
Flag: "postgres-connection-auth",
|
||||
Env: "CODER_PG_CONNECTION_AUTH",
|
||||
Default: "password",
|
||||
Value: serpent.EnumOf(&f.PostgresAuth, codersdk.PostgresAuthDrivers...),
|
||||
},
|
||||
serpent.Option{
|
||||
Flag: "new-key",
|
||||
Env: "CODER_EXTERNAL_TOKEN_ENCRYPTION_ENCRYPT_NEW_KEY",
|
||||
@@ -274,8 +310,9 @@ func (f *rotateFlags) valid() error {
|
||||
}
|
||||
|
||||
type decryptFlags struct {
|
||||
PostgresURL string
|
||||
Keys []string
|
||||
PostgresURL string
|
||||
PostgresAuth string
|
||||
Keys []string
|
||||
}
|
||||
|
||||
func (f *decryptFlags) attach(opts *serpent.OptionSet) {
|
||||
@@ -287,6 +324,14 @@ func (f *decryptFlags) attach(opts *serpent.OptionSet) {
|
||||
Description: "The connection URL for the Postgres database.",
|
||||
Value: serpent.StringOf(&f.PostgresURL),
|
||||
},
|
||||
serpent.Option{
|
||||
Name: "Postgres Connection Auth",
|
||||
Description: "Type of auth to use when connecting to postgres.",
|
||||
Flag: "postgres-connection-auth",
|
||||
Env: "CODER_PG_CONNECTION_AUTH",
|
||||
Default: "password",
|
||||
Value: serpent.EnumOf(&f.PostgresAuth, codersdk.PostgresAuthDrivers...),
|
||||
},
|
||||
serpent.Option{
|
||||
Flag: "keys",
|
||||
Env: "CODER_EXTERNAL_TOKEN_ENCRYPTION_DECRYPT_KEYS",
|
||||
@@ -318,8 +363,9 @@ func (f *decryptFlags) valid() error {
|
||||
}
|
||||
|
||||
type deleteFlags struct {
|
||||
PostgresURL string
|
||||
Confirm bool
|
||||
PostgresURL string
|
||||
PostgresAuth string
|
||||
Confirm bool
|
||||
}
|
||||
|
||||
func (f *deleteFlags) attach(opts *serpent.OptionSet) {
|
||||
@@ -331,6 +377,14 @@ func (f *deleteFlags) attach(opts *serpent.OptionSet) {
|
||||
Description: "The connection URL for the Postgres database.",
|
||||
Value: serpent.StringOf(&f.PostgresURL),
|
||||
},
|
||||
serpent.Option{
|
||||
Name: "Postgres Connection Auth",
|
||||
Description: "Type of auth to use when connecting to postgres.",
|
||||
Flag: "postgres-connection-auth",
|
||||
Env: "CODER_PG_CONNECTION_AUTH",
|
||||
Default: "password",
|
||||
Value: serpent.EnumOf(&f.PostgresAuth, codersdk.PostgresAuthDrivers...),
|
||||
},
|
||||
cliui.SkipPromptOption(),
|
||||
)
|
||||
}
|
||||
|
||||
@@ -45,6 +45,9 @@ OPTIONS:
|
||||
Separate multiple experiments with commas, or enter '*' to opt-in to
|
||||
all available experiments.
|
||||
|
||||
--postgres-auth password|awsiamrds, $CODER_PG_AUTH (default: password)
|
||||
Type of auth to use when connecting to postgres.
|
||||
|
||||
--postgres-url string, $CODER_PG_CONNECTION_URL
|
||||
URL of a PostgreSQL database. If empty, PostgreSQL binaries will be
|
||||
downloaded from Maven (https://repo1.maven.org/maven2) and store all
|
||||
|
||||
@@ -7,6 +7,9 @@ USAGE:
|
||||
it to every organization.
|
||||
|
||||
OPTIONS:
|
||||
--postgres-connection-auth password|awsiamrds, $CODER_PG_CONNECTION_AUTH (default: password)
|
||||
Type of auth to use when connecting to postgres.
|
||||
|
||||
--email string, $CODER_EMAIL
|
||||
The email of the new user. If not specified, you will be prompted via
|
||||
stdin.
|
||||
|
||||
@@ -6,6 +6,9 @@ USAGE:
|
||||
Decrypt a previously encrypted database.
|
||||
|
||||
OPTIONS:
|
||||
--postgres-connection-auth password|awsiamrds, $CODER_PG_CONNECTION_AUTH (default: password)
|
||||
Type of auth to use when connecting to postgres.
|
||||
|
||||
--keys string-array, $CODER_EXTERNAL_TOKEN_ENCRYPTION_DECRYPT_KEYS
|
||||
Keys required to decrypt existing data. Must be a comma-separated list
|
||||
of base64-encoded keys.
|
||||
|
||||
@@ -8,6 +8,9 @@ USAGE:
|
||||
Aliases: rm
|
||||
|
||||
OPTIONS:
|
||||
--postgres-connection-auth password|awsiamrds, $CODER_PG_CONNECTION_AUTH (default: password)
|
||||
Type of auth to use when connecting to postgres.
|
||||
|
||||
--postgres-url string, $CODER_EXTERNAL_TOKEN_ENCRYPTION_POSTGRES_URL
|
||||
The connection URL for the Postgres database.
|
||||
|
||||
|
||||
@@ -6,6 +6,9 @@ USAGE:
|
||||
Rotate database encryption keys.
|
||||
|
||||
OPTIONS:
|
||||
--postgres-connection-auth password|awsiamrds, $CODER_PG_CONNECTION_AUTH (default: password)
|
||||
Type of auth to use when connecting to postgres.
|
||||
|
||||
--new-key string, $CODER_EXTERNAL_TOKEN_ENCRYPTION_ENCRYPT_NEW_KEY
|
||||
The new external token encryption key. Must be base64-encoded.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user