[iac] add github organization name to proto (#54951)

* [iac] add github organization name to proto

This PR adds the github organization name to GithubConfigV1 proto
message.

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>

* add github plugin type

* add secret plugin

---------

Signed-off-by: Tiago Silva <tiago.silva@goteleport.com>
This commit is contained in:
Tiago Silva
2025-05-20 12:06:45 +00:00
committed by GitHub
parent 5fd40eba4b
commit eb7b2f5a36
4 changed files with 33 additions and 3 deletions
+2
View File
@@ -74,6 +74,8 @@ const (
PluginTypeDiscord = "discord"
// PluginTypeGitlab indicates the Gitlab access plugin
PluginTypeGitlab = "gitlab"
// PluginTypeGithub indicates the Github access plugin
PluginTypeGithub = "github"
// PluginTypeEntraID indicates the Entra ID sync plugin
PluginTypeEntraID = "entra-id"
// PluginTypeSCIM indicates a generic SCIM integration
+16
View File
@@ -44,6 +44,11 @@ type PluginStaticCredentials interface {
// GetSSHCertAuthorities will return the attached SSH CA keys.
GetSSHCertAuthorities() []*SSHKeyPair
// GetPrivateKey will return the attached private key. If it is not present, the private key will
// be empty.
GetPrivateKey() []byte
// Clone returns a copy of the credentials.
Clone() PluginStaticCredentials
}
@@ -180,6 +185,17 @@ func (p *PluginStaticCredentialsV1) GetSSHCertAuthorities() []*SSHKeyPair {
return credentials.SSHCertAuthorities.CertAuthorities
}
// GetPrivateKey will return the attached private key. If it is not present, the private key will
// be empty.
func (p *PluginStaticCredentialsV1) GetPrivateKey() []byte {
credentials, ok := p.Spec.Credentials.(*PluginStaticCredentialsSpecV1_PrivateKey)
if !ok {
return nil
}
return credentials.PrivateKey
}
// MatchSearch is a dummy value as credentials are not searchable.
func (p *PluginStaticCredentialsV1) MatchSearch(_ []string) bool {
return false
+13 -3
View File
@@ -164,7 +164,9 @@ func (x *GitHubAuditLogV1) GetCursor() *GitHubAuditLogV1Cursor {
type GitHubConfigV1 struct {
state protoimpl.MessageState `protogen:"open.v1"`
// The desired start date for exporting GitHub audit logs.
StartDate *timestamppb.Timestamp `protobuf:"bytes,1,opt,name=start_date,json=startDate,proto3" json:"start_date,omitempty"`
StartDate *timestamppb.Timestamp `protobuf:"bytes,1,opt,name=start_date,json=startDate,proto3" json:"start_date,omitempty"`
// The Github Organization name.
Organization string `protobuf:"bytes,2,opt,name=organization,proto3" json:"organization,omitempty"`
unknownFields protoimpl.UnknownFields
sizeCache protoimpl.SizeCache
}
@@ -206,6 +208,13 @@ func (x *GitHubConfigV1) GetStartDate() *timestamppb.Timestamp {
return nil
}
func (x *GitHubConfigV1) GetOrganization() string {
if x != nil {
return x.Organization
}
return ""
}
// GithubTokenV1 holds information about a GitHub access token,
// such as its ID, owner, permissions, and expiration date.
type GithubTokenV1 struct {
@@ -791,10 +800,11 @@ const file_accessgraph_v1alpha_github_proto_rawDesc = "" +
"\x0flast_event_time\x18\x03 \x01(\v2\x1a.google.protobuf.TimestampR\rlastEventTime\"\x88\x01\n" +
"\x10GitHubAuditLogV1\x12/\n" +
"\x06events\x18\x01 \x03(\v2\x17.google.protobuf.StructR\x06events\x12C\n" +
"\x06cursor\x18\x02 \x01(\v2+.accessgraph.v1alpha.GitHubAuditLogV1CursorR\x06cursor\"K\n" +
"\x06cursor\x18\x02 \x01(\v2+.accessgraph.v1alpha.GitHubAuditLogV1CursorR\x06cursor\"o\n" +
"\x0eGitHubConfigV1\x129\n" +
"\n" +
"start_date\x18\x01 \x01(\v2\x1a.google.protobuf.TimestampR\tstartDate\"\xf3\x01\n" +
"start_date\x18\x01 \x01(\v2\x1a.google.protobuf.TimestampR\tstartDate\x12\"\n" +
"\forganization\x18\x02 \x01(\tR\forganization\"\xf3\x01\n" +
"\rGithubTokenV1\x12\x0e\n" +
"\x02id\x18\x01 \x01(\x03R\x02id\x12\x12\n" +
"\x04name\x18\x02 \x01(\tR\x04name\x12\x14\n" +
+2
View File
@@ -48,6 +48,8 @@ message GitHubAuditLogV1 {
message GitHubConfigV1 {
// The desired start date for exporting GitHub audit logs.
google.protobuf.Timestamp start_date = 1;
// The Github Organization name.
string organization = 2;
}
// GithubTokenV1 holds information about a GitHub access token,