Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

@mike/secrets #521

Merged
merged 4 commits into from
Jan 8, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 0 additions & 16 deletions .github/actions/setup-secrets/action.yml

This file was deleted.

5 changes: 0 additions & 5 deletions .github/workflows/snackager-bundle.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,11 +25,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup snackager
uses: ./.github/actions/setup-snackager

Expand Down
28 changes: 0 additions & 28 deletions .github/workflows/snackager.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,6 @@ on:
pull_request:
paths:
- .github/actions/setup-google-cloud/**
- .github/actions/setup-secrets/**
- .github/actions/setup-snackager/**
- .github/workflows/snackager.yml
- snackager/**
Expand All @@ -37,7 +36,6 @@ on:
branches: [main]
paths:
- .github/actions/setup-google-cloud/**
- .github/actions/setup-secrets/**
- .github/actions/setup-snackager/**
- .github/workflows/snackager.yml
- snackager/**
Expand All @@ -56,11 +54,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup snackager
uses: ./.github/actions/setup-snackager

Expand All @@ -81,11 +74,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup snackager
uses: ./.github/actions/setup-snackager

Expand All @@ -102,11 +90,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand All @@ -130,11 +113,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand Down Expand Up @@ -185,11 +163,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand Down Expand Up @@ -231,4 +204,3 @@ jobs:
status: ${{ job.status }}
author_name: Deploy Snackager to Production
fields: message,commit,author,job,took

22 changes: 0 additions & 22 deletions .github/workflows/snackpub.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,6 @@ on:
pull_request:
paths:
- .github/actions/setup-google-cloud/**
- .github/actions/setup-secrets/**
- .github/actions/setup-snackpub/**
- .github/workflows/snackpub.yml
- snackpub/**
Expand All @@ -34,7 +33,6 @@ on:
branches: [main]
paths:
- .github/actions/setup-google-cloud/**
- .github/actions/setup-secrets/**
- .github/actions/setup-snackpub/**
- .github/workflows/snackpub.yml
- snackpub/**
Expand All @@ -50,11 +48,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup snackpub
uses: ./.github/actions/setup-snackpub

Expand All @@ -71,11 +64,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand All @@ -98,11 +86,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand Down Expand Up @@ -148,11 +131,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand Down
22 changes: 0 additions & 22 deletions .github/workflows/website.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,6 @@ on:
pull_request:
paths:
- .github/actions/setup-google-cloud/**
- .github/actions/setup-secrets/**
- .github/actions/setup-website/**
- .github/workflows/website.yml
- website/**
Expand All @@ -36,7 +35,6 @@ on:
branches: [main]
paths:
- .github/actions/setup-google-cloud/**
- .github/actions/setup-secrets/**
- .github/actions/setup-website/**
- .github/workflows/website.yml
- website/**
Expand Down Expand Up @@ -70,11 +68,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand All @@ -94,11 +87,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud

Expand All @@ -119,11 +107,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand Down Expand Up @@ -174,11 +157,6 @@ jobs:
- name: 🏗 Setup repository
uses: actions/checkout@v3

- name: 🏗 Setup secrets
uses: ./.github/actions/setup-secrets
with:
git-crypt-key: ${{ secrets.GIT_CRYPT_KEY }}

- name: 🏗 Setup Google Cloud SDK
uses: ./.github/actions/setup-google-cloud
with:
Expand Down
30 changes: 23 additions & 7 deletions snackager/.env-cmdrc.js
Original file line number Diff line number Diff line change
@@ -1,27 +1,43 @@
const fs = require('fs');
const path = require('path');
const yaml = require('js-yaml');
const { GetEnvVars } = require('env-cmd');
const { SecretManagerServiceClient } = require('@google-cloud/secret-manager').v1;

async function getSecretEnv(name) {
const secretmanagerClient = new SecretManagerServiceClient();
try {
const response = await secretmanagerClient.accessSecretVersion({ name });
return JSON.parse(response[0].payload.data.toString());
} catch {
return {};
}
}

module.exports = (async function () {
const processArgs = process.argv.join(' ');
const baseEnv = await GetEnvVars({ envFile: { filePath: './k8s/base/snackager.env' } });
const stagingEnv = await GetEnvVars({ envFile: { filePath: './k8s/staging/snackager.env' } });
const baseSecrets = {
SENTRY_DSN: fs.readFileSync('./k8s/base/secrets/SENTRY_DSN').toString(),
REDIS_URL: 'redis://localhost:6379/0', // proxied by port-forward-redis
};
const stagingEnv = await GetEnvVars({ envFile: { filePath: './k8s/staging/snackager.env' } });
const stagingSecrets = await GetEnvVars({
envFile: { filePath: './k8s/staging/secrets/snackager.env' },
});

const externalSecret = yaml.load(fs.readFileSync(
'./k8s/staging/external-secret-env.yaml',
'utf8',
));
const secretName = externalSecret.spec.dataFrom[0].extract.key;
const secretVersion = externalSecret.spec.dataFrom[0].extract.version;
const secretResourceName = `projects/77257980902/secrets/${secretName}/versions/${secretVersion}`;
const stagingSecrets = await getSecretEnv(secretResourceName);
delete stagingSecrets['REDIS_URL']; // this is set above for the proxy

if (!stagingSecrets.GIT_SESSION_SECRET && !processArgs.includes('env-cmd -e test')) {
console.error(
'Secrets are locked, unable to start Snackager. External contributors cannot start Snackager and can ignore this error. snack-proxies will redirect traffic to the Snackager service running on the staging environment.\n'
'Cannot access secrets, unable to start Snackager. External contributors cannot start Snackager and can ignore this error. snack-proxies will redirect traffic to the Snackager service running on the staging environment.\n'
);
throw new Error('Secrets are locked.');
}

return {
development: {
NODE_ENV: 'development',
Expand Down
5 changes: 5 additions & 0 deletions snackager/k8s/base/external-secrets-config.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
nameReference:
- kind: Secret
fieldSpecs:
- kind: ExternalSecret
path: spec/target/name
6 changes: 2 additions & 4 deletions snackager/k8s/base/kustomization.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@ commonLabels:
resources:
- deployment.yaml
- service.yaml
configurations:
- external-secrets-config.yaml
configMapGenerator:
- name: snackager-config
envs:
Expand All @@ -14,8 +16,4 @@ configMapGenerator:
- NODE_ENV=production
secretGenerator:
- name: snackager-config
files:
- secrets/SENTRY_DSN
- name: git-account-credentials
files:
- id_rsa=secrets/github-key.pem
Binary file removed snackager/k8s/base/secrets/SENTRY_DSN
Binary file not shown.
Binary file removed snackager/k8s/base/secrets/github-key.pem
Binary file not shown.
17 changes: 17 additions & 0 deletions snackager/k8s/production/external-secret-env.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: snackager-config
spec:
refreshInterval: "0"
secretStoreRef:
kind: ClusterSecretStore
name: gcp-store
target:
name: snackager-config
creationPolicy: Owner
dataFrom:
- extract:
key: production__snack__snackager__env
version: "1"
17 changes: 17 additions & 0 deletions snackager/k8s/production/external-secret-private-key.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: git-account-credentials
spec:
refreshInterval: "0"
secretStoreRef:
kind: ClusterSecretStore
name: gcp-store
target:
name: snackager-config
creationPolicy: Owner
dataFrom:
- extract:
key: production__snack__snackager__gh_private_key
version: "1"
10 changes: 8 additions & 2 deletions snackager/k8s/production/kustomization.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,8 @@ namespace: production
resources:
- ../base
- vertical-pod-autoscaler.yaml
- external-secret-env.yaml
- external-secret-private-key.yaml
patchesStrategicMerge:
- deployment-increase-replicas.yaml
- service-backend.yaml
Expand All @@ -15,5 +17,9 @@ configMapGenerator:
secretGenerator:
- name: snackager-config
behavior: merge
envs:
- secrets/snackager.env
files:
- ./external-secret-env.yaml
- name: git-account-credentials
behavior: merge
files:
- ./external-secret-private-key.yaml
Binary file removed snackager/k8s/production/secrets/snackager.env
Binary file not shown.
17 changes: 17 additions & 0 deletions snackager/k8s/staging/external-secret-env.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
---
apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: snackager-config
spec:
refreshInterval: "0"
secretStoreRef:
kind: ClusterSecretStore
name: gcp-store
target:
name: snackager-config
creationPolicy: Owner
dataFrom:
- extract:
key: staging__snack__snackager__env
version: "1"
Loading
Loading