mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat(coderd): connect dbcrypt package implementation (#9523)
See also: https://github.com/coder/coder/pull/9522 - Adds commands `server dbcrypt {rotate,decrypt,delete}` to re-encrypt, decrypt, or delete encrypted data, respectively. - Plumbs through dbcrypt in enterprise/coderd (including unit tests). - Adds documentation in admin/encryption.md. This enables dbcrypt by default, but the feature is soft-enforced on supplying external token encryption keys. Without specifying any keys, encryption/decryption is a no-op.
This commit is contained in:
@@ -6,6 +6,7 @@ Start a Coder server
|
||||
create-admin-user Create a new admin user with the given username,
|
||||
email and password and adds it to every
|
||||
organization.
|
||||
dbcrypt Manage database encryption.
|
||||
postgres-builtin-serve Run the built-in PostgreSQL deployment.
|
||||
postgres-builtin-url Output the connection URL for the built-in
|
||||
PostgreSQL deployment.
|
||||
@@ -458,6 +459,16 @@ These options are only available in the Enterprise Edition.
|
||||
An HTTP URL that is accessible by other replicas to relay DERP
|
||||
traffic. Required for high availability.
|
||||
|
||||
--external-token-encryption-keys string-array, $CODER_EXTERNAL_TOKEN_ENCRYPTION_KEYS
|
||||
Encrypt OIDC and Git authentication tokens with AES-256-GCM in the
|
||||
database. The value must be a comma-separated list of base64-encoded
|
||||
keys. Each key, when base64-decoded, must be exactly 32 bytes in
|
||||
length. The first key will be used to encrypt new values. Subsequent
|
||||
keys will be used as a fallback when decrypting. During normal
|
||||
operation it is recommended to only set one key unless you are in the
|
||||
process of rotating keys with the `coder server dbcrypt rotate`
|
||||
command.
|
||||
|
||||
--scim-auth-header string, $CODER_SCIM_AUTH_HEADER
|
||||
Enables SCIM and sets the authentication header for the built-in SCIM
|
||||
server. New users are automatically created with OIDC authentication.
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
Usage: coder server dbcrypt
|
||||
|
||||
Manage database encryption.
|
||||
|
||||
[1mSubcommands[0m
|
||||
decrypt Decrypt a previously encrypted database.
|
||||
delete Delete all encrypted data from the database. THIS IS A
|
||||
DESTRUCTIVE OPERATION.
|
||||
rotate Rotate database encryption keys.
|
||||
|
||||
---
|
||||
Run `coder --help` for a list of global options.
|
||||
@@ -0,0 +1,17 @@
|
||||
Usage: coder server dbcrypt decrypt [flags]
|
||||
|
||||
Decrypt a previously encrypted database.
|
||||
|
||||
[1mOptions[0m
|
||||
--keys string-array, $CODER_EXTERNAL_TOKEN_ENCRYPTION_DECRYPT_KEYS
|
||||
Keys required to decrypt existing data. Must be a comma-separated list
|
||||
of base64-encoded keys.
|
||||
|
||||
--postgres-url string, $CODER_PG_CONNECTION_URL
|
||||
The connection URL for the Postgres database.
|
||||
|
||||
-y, --yes bool
|
||||
Bypass prompts.
|
||||
|
||||
---
|
||||
Run `coder --help` for a list of global options.
|
||||
@@ -0,0 +1,15 @@
|
||||
Usage: coder server dbcrypt delete [flags]
|
||||
|
||||
Delete all encrypted data from the database. THIS IS A DESTRUCTIVE OPERATION.
|
||||
|
||||
Aliases: rm
|
||||
|
||||
[1mOptions[0m
|
||||
--postgres-url string, $CODER_EXTERNAL_TOKEN_ENCRYPTION_POSTGRES_URL
|
||||
The connection URL for the Postgres database.
|
||||
|
||||
-y, --yes bool
|
||||
Bypass prompts.
|
||||
|
||||
---
|
||||
Run `coder --help` for a list of global options.
|
||||
@@ -0,0 +1,20 @@
|
||||
Usage: coder server dbcrypt rotate [flags]
|
||||
|
||||
Rotate database encryption keys.
|
||||
|
||||
[1mOptions[0m
|
||||
--new-key string, $CODER_EXTERNAL_TOKEN_ENCRYPTION_ENCRYPT_NEW_KEY
|
||||
The new external token encryption key. Must be base64-encoded.
|
||||
|
||||
--old-keys string-array, $CODER_EXTERNAL_TOKEN_ENCRYPTION_ENCRYPT_OLD_KEYS
|
||||
The old external token encryption keys. Must be a comma-separated list
|
||||
of base64-encoded keys.
|
||||
|
||||
--postgres-url string, $CODER_PG_CONNECTION_URL
|
||||
The connection URL for the Postgres database.
|
||||
|
||||
-y, --yes bool
|
||||
Bypass prompts.
|
||||
|
||||
---
|
||||
Run `coder --help` for a list of global options.
|
||||
Reference in New Issue
Block a user