Merge pull request 'Scaffold vault-plugin-secrets-ghp secrets engine' (#1) from benvin/scaffold-ghp-engine into main
ci/woodpecker/tag/release Pipeline was successful
ci/woodpecker/tag/release Pipeline was successful
Reviewed-on: #1
This commit was merged in pull request #1.
This commit is contained in:
@@ -0,0 +1,7 @@
|
||||
/dist/
|
||||
/vault-plugin-secrets-ghp
|
||||
*.out
|
||||
*.test
|
||||
.env
|
||||
test/plugins/
|
||||
/mockghp
|
||||
@@ -0,0 +1,15 @@
|
||||
repos:
|
||||
- repo: https://github.com/pre-commit/pre-commit-hooks
|
||||
rev: v5.0.0
|
||||
hooks:
|
||||
- id: trailing-whitespace
|
||||
- id: end-of-file-fixer
|
||||
- id: check-yaml
|
||||
- id: check-added-large-files
|
||||
|
||||
- repo: https://github.com/dnephin/pre-commit-golang
|
||||
rev: v0.5.1
|
||||
hooks:
|
||||
- id: go-fmt
|
||||
- id: go-vet
|
||||
- id: go-mod-tidy
|
||||
@@ -0,0 +1,18 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: build
|
||||
image: golang:1.25
|
||||
commands:
|
||||
- make build
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,18 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: pre-commit
|
||||
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
|
||||
commands:
|
||||
- uvx pre-commit run --all-files
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,47 @@
|
||||
when:
|
||||
- event: tag
|
||||
|
||||
steps:
|
||||
- name: build
|
||||
image: git.unkin.net/unkin/almalinux9-gobuilder:20260606
|
||||
commands:
|
||||
- make build VERSION=${CI_COMMIT_TAG}
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests: {memory: 512Mi, cpu: 1}
|
||||
limits: {memory: 2Gi, cpu: 2}
|
||||
|
||||
- name: package
|
||||
image: git.unkin.net/unkin/almalinux9-rpmbuilder:latest
|
||||
commands:
|
||||
- ./scripts/build-rpm.sh ${CI_COMMIT_TAG}
|
||||
depends_on: [build]
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests: {memory: 512Mi, cpu: 1}
|
||||
limits: {memory: 2Gi, cpu: 2}
|
||||
|
||||
- name: upload
|
||||
image: git.unkin.net/unkin/almalinux9-base:20260606
|
||||
commands:
|
||||
- |
|
||||
HOST="https://artifactapi.k8s.syd1.au.unkin.net"
|
||||
REPO="rpm-internal"
|
||||
for rpm in dist/*.rpm; do
|
||||
FILE=$$(basename "$$rpm")
|
||||
code=$$(curl -s -o /dev/null -w '%{http_code}' "$$HOST/api/v2/remotes/$$REPO/files/Packages/$$FILE" || true)
|
||||
if [ "$$code" = "200" ]; then echo "$$FILE exists; skipping"; continue; fi
|
||||
echo "Uploading $$FILE (probe $$code)"
|
||||
curl -f -X PUT "$$HOST/api/v2/remotes/$$REPO/files/$$FILE" -H "Content-Type: application/x-rpm" --data-binary @"$$rpm"
|
||||
done
|
||||
depends_on: [package]
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests: {memory: 128Mi, cpu: 100m}
|
||||
limits: {memory: 512Mi, cpu: 500m}
|
||||
@@ -0,0 +1,33 @@
|
||||
when:
|
||||
- event: pull_request
|
||||
|
||||
steps:
|
||||
- name: lint
|
||||
image: golang:1.25
|
||||
commands:
|
||||
- make lint
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
|
||||
- name: test
|
||||
image: golang:1.25
|
||||
commands:
|
||||
- make test
|
||||
backend_options:
|
||||
kubernetes:
|
||||
serviceAccountName: default
|
||||
resources:
|
||||
requests:
|
||||
memory: 512Mi
|
||||
cpu: 1
|
||||
limits:
|
||||
memory: 2Gi
|
||||
cpu: 2
|
||||
@@ -0,0 +1,77 @@
|
||||
.PHONY: build install test lint fmt clean tidy rpm rpm-package patch minor major check-go e2e e2e-vault e2e-openbao e2e-up e2e-down
|
||||
|
||||
BINARY := vault-plugin-secrets-ghp
|
||||
PKG := ./cmd/vault-plugin-secrets-ghp
|
||||
VERSION ?= $(shell git describe --tags --always --dirty 2>/dev/null || echo "0.0.0-dev")
|
||||
OS ?= $(shell go env GOOS)
|
||||
ARCH ?= $(shell go env GOARCH)
|
||||
PLUGIN_DIR ?= ./dist
|
||||
|
||||
GO_VERSION_REQUIRED := 1.25
|
||||
GO_VERSION_ACTUAL := $(shell go version | sed 's/go version go\([0-9]*\.[0-9]*\).*/\1/')
|
||||
|
||||
check-go:
|
||||
@if [ "$$(printf '%s\n%s' "$(GO_VERSION_REQUIRED)" "$(GO_VERSION_ACTUAL)" | sort -V | head -1)" != "$(GO_VERSION_REQUIRED)" ]; then \
|
||||
echo "ERROR: Go >= $(GO_VERSION_REQUIRED) required, found $(GO_VERSION_ACTUAL)"; exit 1; \
|
||||
fi
|
||||
|
||||
build: check-go tidy
|
||||
CGO_ENABLED=0 GOOS=$(OS) GOARCH=$(ARCH) go build -ldflags="-s -w -X main.version=$(VERSION)" -o $(PLUGIN_DIR)/$(BINARY) $(PKG)
|
||||
|
||||
install: build
|
||||
@echo "Built $(PLUGIN_DIR)/$(BINARY) (register it with: vault plugin register -sha256=<sha> secret $(BINARY))"
|
||||
|
||||
test: check-go
|
||||
go test -race -count=1 ./...
|
||||
|
||||
lint: check-go
|
||||
go vet ./...
|
||||
|
||||
fmt: check-go
|
||||
gofmt -w .
|
||||
|
||||
tidy:
|
||||
go mod tidy
|
||||
|
||||
clean:
|
||||
rm -rf $(PLUGIN_DIR)
|
||||
|
||||
rpm: build rpm-package
|
||||
|
||||
rpm-package:
|
||||
./scripts/build-rpm.sh $(VERSION)
|
||||
|
||||
# End-to-end tests bring up a mock ghp API plus Vault and OpenBao in Docker and
|
||||
# drive the full lifecycle against each with the same plugin binary.
|
||||
e2e:
|
||||
./scripts/e2e.sh
|
||||
|
||||
e2e-vault:
|
||||
ENGINES=vault ./scripts/e2e.sh
|
||||
|
||||
e2e-openbao:
|
||||
ENGINES=openbao ./scripts/e2e.sh
|
||||
|
||||
e2e-up:
|
||||
docker compose -f test/docker-compose.yml up -d --build
|
||||
|
||||
e2e-down:
|
||||
docker compose -f test/docker-compose.yml down -v
|
||||
|
||||
_LATEST := $(shell git tag --sort=-v:refname | grep -E '^v[0-9]+\.[0-9]+\.[0-9]+$$' | head -1)
|
||||
_BASE := $(if $(_LATEST),$(_LATEST),v0.0.0)
|
||||
_MAJ := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f1)
|
||||
_MIN := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f2)
|
||||
_PAT := $(shell echo $(_BASE) | sed 's/^v//' | cut -d. -f3)
|
||||
|
||||
patch:
|
||||
@NEW=v$(_MAJ).$(_MIN).$(shell expr $(_PAT) + 1); \
|
||||
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
||||
|
||||
minor:
|
||||
@NEW=v$(_MAJ).$(shell expr $(_MIN) + 1).0; \
|
||||
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
||||
|
||||
major:
|
||||
@NEW=v$(shell expr $(_MAJ) + 1).0.0; \
|
||||
git tag $$NEW && echo "Tagged $$NEW" && git push origin $$NEW
|
||||
@@ -1,3 +1,114 @@
|
||||
# vault-plugin-secrets-ghp
|
||||
|
||||
HashiCorp Vault / OpenBao secrets engine for ghp: mints ephemeral, scoped access tokens via the ghp admin API, authenticating as a static admin service token
|
||||
A Vault / OpenBao secrets engine that mints **ephemeral, scoped ghp access
|
||||
tokens** on demand.
|
||||
|
||||
## Why
|
||||
|
||||
Machine callers of [ghp](https://git.unkin.net/unkin/ghp) (the GitHub proxy) —
|
||||
CI identities, agents, ... — should never hold standing ghp tokens: a leaked
|
||||
token is valid until someone notices and revokes it. This engine removes standing
|
||||
tokens entirely:
|
||||
|
||||
- You seed it once with a single ghp **service token** (`ghpsvc_...`) that ghp
|
||||
treats as a synthetic site admin.
|
||||
- A **role** binds a ghp App installation (and optional scopes/repositories) to a
|
||||
set of TTLs.
|
||||
- Each read of `creds/<role>` mints a fresh token via `POST /api/tokens`, bound
|
||||
to a Vault lease, and **deletes it from ghp when the lease is revoked or
|
||||
expires** (`DELETE /api/tokens/{id}`).
|
||||
|
||||
### Why a static service token, not a rotated root credential
|
||||
|
||||
ghp service tokens are configured on the ghp server (`auth.service_tokens` /
|
||||
`GHP_AUTH_SERVICE_TOKENS`) and authenticate as a synthetic admin with no database
|
||||
row. There is nothing for the engine to rotate in place, so — unlike the sibling
|
||||
`vault-plugin-secrets-gitea` engine — this backend deliberately has **no
|
||||
`config/rotate-root` path**. The service token is supplied and rotated through
|
||||
Vault config by the operator.
|
||||
|
||||
### Server-side expiry *and* the Vault lease
|
||||
|
||||
Unlike Gitea tokens, ghp tokens **do** expire server-side. Each mint sets a
|
||||
`duration` equal to the lease ceiling (`max_ttl`), so the token self-expires even
|
||||
if lease revocation never reaches ghp. The Vault lease remains the primary
|
||||
expiry: on revoke or `max_ttl`, the engine issues `DELETE /api/tokens/{id}`. A
|
||||
delete that returns 404 (token already gone) is treated as success, so revocation
|
||||
is idempotent and Vault's retries converge.
|
||||
|
||||
## Paths
|
||||
|
||||
| Path | Description |
|
||||
|------|-------------|
|
||||
| `config` | ghp `base_url` + TLS settings + seeded `admin_token` service token. Verifies the token is a ghp admin on write. |
|
||||
| `roles/<name>` | Mint policy: `token_type`, `installation_id`, `app_record_id`, `repositories`, `scopes`, `session_prefix`, `ttl`, `max_ttl`. |
|
||||
| `roles` | List roles. |
|
||||
| `creds/<role>` | Read to mint a short-lived, lease-bound ghp token for the role. |
|
||||
|
||||
## Token types
|
||||
|
||||
- **agent** (default) — backed by a ghp App installation. Requires
|
||||
`installation_id`; `app_record_id` optionally pins a specific ghp App record
|
||||
(UUID). This is the natural fit for a service credential and works with the
|
||||
synthetic-admin service token.
|
||||
- **proxy** — OAuth-backed. Included for completeness; note a service-token
|
||||
identity generally has no linked GitHub OAuth token, so proxy mints require ghp
|
||||
to be configured accordingly.
|
||||
|
||||
## Scopes
|
||||
|
||||
`scopes` is a comma-separated list of `permission:level` entries (matching ghp's
|
||||
`token.ParseScopeString`), where `level` is `read` or `write` and `permission` is
|
||||
a GitHub App permission key (`contents`, `pull_requests`, `issues`, ...). An
|
||||
empty `scopes` is **open-scoped**. Likewise an empty `repositories` grants all
|
||||
repositories in the installation.
|
||||
|
||||
## Usage
|
||||
|
||||
```sh
|
||||
vault secrets enable -path=ghp vault-plugin-secrets-ghp
|
||||
|
||||
# Seed with a ghp service token (ghpsvc_...).
|
||||
vault write ghp/config \
|
||||
base_url=https://ghp.unkin.net \
|
||||
admin_token='ghpsvc_...' \
|
||||
ca_cert=@ghp-ca.pem
|
||||
|
||||
# A role that mints 1h agent tokens for App installation 4242, scoped to
|
||||
# repo contents + PRs.
|
||||
vault write ghp/roles/agent token_type=agent installation_id=4242 \
|
||||
scopes=contents:read,pull_requests:write ttl=1h max_ttl=24h
|
||||
|
||||
# Mint one. The token is deleted from ghp when the lease is revoked.
|
||||
vault read ghp/creds/agent
|
||||
```
|
||||
|
||||
## Development
|
||||
|
||||
```sh
|
||||
make build # build the plugin binary into ./dist
|
||||
make test # unit tests (race)
|
||||
make e2e # full lifecycle vs mock ghp on Vault + OpenBao (Docker)
|
||||
make rpm # build Vault + OpenBao RPMs via nfpm
|
||||
```
|
||||
|
||||
Releases are tag-driven (`make patch|minor|major`): a Woodpecker pipeline builds
|
||||
the Vault and OpenBao RPMs and uploads them to the internal artifactapi yum repo.
|
||||
|
||||
## Deployment (out of scope for this repo; documented for the operator)
|
||||
|
||||
Live registration mirrors the sibling `vault-plugin-secrets-gitea` /
|
||||
`vault-plugin-secrets-rancher` engines:
|
||||
|
||||
1. **Release**: tag `v0.1.0` (`make minor` from `v0.0.0`). CI publishes
|
||||
`rpm-internal/files/Packages/{vault,openbao}-plugin-secrets-ghp-<ver>-1.x86_64.rpm`.
|
||||
2. **terraform-vault**: plugin catalog entry with the release `sha256`, engine
|
||||
policies, and `ghp_secret_backend` + `ghp_secret_backend_role` module
|
||||
instances (via the companion terraform provider).
|
||||
3. **Seed the service token in KV** before the backend module applies, e.g.
|
||||
`kv/service/vault/au/syd1/secret_backend/ghp/config` with `admin_token` set to
|
||||
a ghp service token configured in `GHP_AUTH_SERVICE_TOKENS`.
|
||||
4. **Reload after a binary upgrade**:
|
||||
`vault write sys/plugins/reload/backend plugin=vault-plugin-secrets-ghp`.
|
||||
Bump the RPM version in puppet-prod and the catalog `sha256` in terraform-vault
|
||||
*together* so the on-disk binary stays in lockstep with the catalog.
|
||||
|
||||
+101
@@ -0,0 +1,101 @@
|
||||
// Package ghp implements a Vault / OpenBao secrets engine that mints ephemeral,
|
||||
// scoped ghp access tokens on demand.
|
||||
//
|
||||
// ghp (the GitHub proxy) issues short-lived tokens that front GitHub App
|
||||
// installations. Machine callers (CI identities, agents, ...) should never hold
|
||||
// standing ghp tokens. The engine is seeded with a single ghp *service token*
|
||||
// (ghpsvc_...) that ghp treats as a synthetic site admin, and on each read of
|
||||
// creds/<role> it calls ghp's admin token API (POST /api/tokens) to mint a fresh
|
||||
// scoped token for the role. Each minted token is bound to a Vault lease and
|
||||
// revoked from ghp (DELETE /api/tokens/{id}) when the lease expires or is revoked.
|
||||
//
|
||||
// Why a static service token and not a rotated root credential: ghp service
|
||||
// tokens are configured out-of-band on the ghp server (auth.service_tokens /
|
||||
// GHP_AUTH_SERVICE_TOKENS) and authenticate as a synthetic admin with no
|
||||
// database row. There is nothing for the engine to rotate in place, so unlike
|
||||
// the sibling gitea engine this backend deliberately has no config/rotate-root
|
||||
// path; the service token is supplied and rotated by Vault/operator config.
|
||||
//
|
||||
// Unlike Gitea, ghp tokens *do* expire server-side: each mint sets a duration so
|
||||
// the token self-expires around the lease ceiling as defence in depth, while the
|
||||
// Vault lease remains the primary expiry — lease revocation deletes the token.
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"strings"
|
||||
|
||||
"github.com/hashicorp/vault/sdk/framework"
|
||||
"github.com/hashicorp/vault/sdk/logical"
|
||||
)
|
||||
|
||||
// errBackendNotConfigured is returned when a credential is requested before the
|
||||
// ghp connection has been configured.
|
||||
var errBackendNotConfigured = errors.New("ghp backend not configured; write config first")
|
||||
|
||||
type ghpBackend struct {
|
||||
*framework.Backend
|
||||
}
|
||||
|
||||
// Factory returns a configured ghp secrets backend.
|
||||
func Factory(ctx context.Context, conf *logical.BackendConfig) (logical.Backend, error) {
|
||||
b := backend()
|
||||
if err := b.Setup(ctx, conf); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return b, nil
|
||||
}
|
||||
|
||||
func backend() *ghpBackend {
|
||||
b := &ghpBackend{}
|
||||
|
||||
b.Backend = &framework.Backend{
|
||||
Help: strings.TrimSpace(backendHelp),
|
||||
BackendType: logical.TypeLogical,
|
||||
PathsSpecial: &logical.Paths{
|
||||
SealWrapStorage: []string{configStoragePath},
|
||||
},
|
||||
Paths: framework.PathAppend(
|
||||
[]*framework.Path{
|
||||
pathConfig(b),
|
||||
pathRole(b),
|
||||
pathRolesList(b),
|
||||
pathCredentials(b),
|
||||
},
|
||||
),
|
||||
Secrets: []*framework.Secret{
|
||||
b.ghpTokenSecret(),
|
||||
},
|
||||
}
|
||||
|
||||
return b
|
||||
}
|
||||
|
||||
// clientFor builds a ghp client from the stored config, authenticated with the
|
||||
// seeded service token.
|
||||
func (b *ghpBackend) clientFor(ctx context.Context, s logical.Storage) (*ghpClient, error) {
|
||||
config, err := getConfig(ctx, s)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if config == nil {
|
||||
return nil, errBackendNotConfigured
|
||||
}
|
||||
return newClient(config)
|
||||
}
|
||||
|
||||
const backendHelp = `
|
||||
The ghp secrets engine mints ephemeral, scoped ghp access tokens.
|
||||
|
||||
Seed the engine with a ghp service token (ghpsvc_...) that ghp accepts as a
|
||||
synthetic site admin. Roles bind a ghp App installation and a set of GitHub App
|
||||
permission scopes to TTLs; each read of creds/<role> mints a fresh token via
|
||||
POST /api/tokens, bound to a Vault lease and deleted from ghp (DELETE
|
||||
/api/tokens/{id}) on revocation. ghp tokens expire server-side too, so each mint
|
||||
sets a duration bounded by the lease ceiling.
|
||||
|
||||
There is no config/rotate-root: the ghp service token is a static credential
|
||||
managed on the ghp server and supplied through Vault config, not rotated by this
|
||||
engine.
|
||||
`
|
||||
+432
@@ -0,0 +1,432 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strconv"
|
||||
"strings"
|
||||
"sync"
|
||||
"testing"
|
||||
|
||||
"github.com/hashicorp/vault/sdk/logical"
|
||||
)
|
||||
|
||||
// fakeGHP is an in-memory stand-in for the subset of ghp's admin API the plugin
|
||||
// uses: admin check (GET /api/users), token create (POST /api/tokens) and token
|
||||
// revoke (DELETE /api/tokens/{id}). Bearer auth is validated against the seeded
|
||||
// service token, and non-admin behaviour can be simulated by rejecting it.
|
||||
type fakeGHP struct {
|
||||
mu sync.Mutex
|
||||
adminTok string
|
||||
nextID int64
|
||||
tokens map[string]createdToken // key: id
|
||||
minted int
|
||||
forbidden bool // when true, a valid token is treated as non-admin (403)
|
||||
}
|
||||
|
||||
type createdToken struct {
|
||||
id string
|
||||
tokenType string
|
||||
repositories []string
|
||||
scopes map[string]string
|
||||
sessionID string
|
||||
}
|
||||
|
||||
func newFakeGHP(adminTok string) *fakeGHP {
|
||||
return &fakeGHP{adminTok: adminTok, tokens: map[string]createdToken{}}
|
||||
}
|
||||
|
||||
func (f *fakeGHP) authOK(r *http.Request) bool {
|
||||
tok, ok := strings.CutPrefix(r.Header.Get("Authorization"), "Bearer ")
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
return ok && tok == f.adminTok
|
||||
}
|
||||
|
||||
func (f *fakeGHP) server(t *testing.T) *httptest.Server {
|
||||
t.Helper()
|
||||
return httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if !f.authOK(r) {
|
||||
w.WriteHeader(http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
f.mu.Lock()
|
||||
forbidden := f.forbidden
|
||||
f.mu.Unlock()
|
||||
|
||||
switch {
|
||||
case r.Method == http.MethodGet && r.URL.Path == "/api/users":
|
||||
if forbidden {
|
||||
w.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, []map[string]interface{}{{"id": "svc-admin"}})
|
||||
|
||||
case r.Method == http.MethodPost && r.URL.Path == "/api/tokens":
|
||||
var in createTokenRequest
|
||||
_ = json.NewDecoder(r.Body).Decode(&in)
|
||||
scopes := map[string]string{}
|
||||
if in.Scopes != "" {
|
||||
for _, part := range strings.Split(in.Scopes, ",") {
|
||||
kv := strings.SplitN(part, ":", 2)
|
||||
if len(kv) == 2 {
|
||||
scopes[kv[0]] = kv[1]
|
||||
}
|
||||
}
|
||||
}
|
||||
f.mu.Lock()
|
||||
f.nextID++
|
||||
id := "tok-" + strconv.FormatInt(f.nextID, 10)
|
||||
f.minted++
|
||||
tt := in.Type
|
||||
if tt == "" {
|
||||
tt = tokenTypeProxy
|
||||
}
|
||||
f.tokens[id] = createdToken{id: id, tokenType: tt, repositories: in.Repositories, scopes: scopes, sessionID: in.SessionID}
|
||||
f.mu.Unlock()
|
||||
writeJSON(w, http.StatusCreated, map[string]interface{}{
|
||||
"token": "gha_" + id,
|
||||
"id": id,
|
||||
"type": tt,
|
||||
"repositories": in.Repositories,
|
||||
"scopes": scopes,
|
||||
"expires_at": "2030-01-01T00:00:00Z",
|
||||
"session_id": in.SessionID,
|
||||
})
|
||||
|
||||
case r.Method == http.MethodDelete && strings.HasPrefix(r.URL.Path, "/api/tokens/"):
|
||||
id := strings.TrimPrefix(r.URL.Path, "/api/tokens/")
|
||||
f.mu.Lock()
|
||||
_, exists := f.tokens[id]
|
||||
delete(f.tokens, id)
|
||||
f.mu.Unlock()
|
||||
if !exists {
|
||||
writeJSON(w, http.StatusNotFound, map[string]string{"message": "Token not found"})
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]string{"message": "Token revoked"})
|
||||
|
||||
default:
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}))
|
||||
}
|
||||
|
||||
func (f *fakeGHP) has(id string) bool {
|
||||
f.mu.Lock()
|
||||
defer f.mu.Unlock()
|
||||
_, ok := f.tokens[id]
|
||||
return ok
|
||||
}
|
||||
|
||||
func writeJSON(w http.ResponseWriter, code int, v interface{}) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(code)
|
||||
_ = json.NewEncoder(w).Encode(v)
|
||||
}
|
||||
|
||||
func newTestBackend(t *testing.T) (*ghpBackend, logical.Storage) {
|
||||
t.Helper()
|
||||
config := logical.TestBackendConfig()
|
||||
config.StorageView = &logical.InmemStorage{}
|
||||
b, err := Factory(context.Background(), config)
|
||||
if err != nil {
|
||||
t.Fatalf("Factory: %v", err)
|
||||
}
|
||||
return b.(*ghpBackend), config.StorageView
|
||||
}
|
||||
|
||||
func req(t *testing.T, b *ghpBackend, s logical.Storage, op logical.Operation, path string, data map[string]interface{}) *logical.Response {
|
||||
t.Helper()
|
||||
resp, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: op,
|
||||
Path: path,
|
||||
Data: data,
|
||||
Storage: s,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("%s %s: %v", op, path, err)
|
||||
}
|
||||
if resp != nil && resp.IsError() {
|
||||
t.Fatalf("%s %s: %v", op, path, resp.Error())
|
||||
}
|
||||
return resp
|
||||
}
|
||||
|
||||
func configure(t *testing.T, b *ghpBackend, s logical.Storage, url, token string) {
|
||||
t.Helper()
|
||||
req(t, b, s, logical.CreateOperation, "config", map[string]interface{}{
|
||||
"base_url": url,
|
||||
"admin_token": token,
|
||||
})
|
||||
}
|
||||
|
||||
func TestLifecycle(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
|
||||
req(t, b, s, logical.CreateOperation, "roles/agent", map[string]interface{}{
|
||||
"token_type": "agent",
|
||||
"installation_id": 4242,
|
||||
"scopes": "contents:read,pull_requests:write",
|
||||
"repositories": "unkin/ghp,unkin/teabot",
|
||||
"ttl": "1h",
|
||||
"max_ttl": "24h",
|
||||
})
|
||||
|
||||
creds := req(t, b, s, logical.ReadOperation, "creds/agent", nil)
|
||||
if creds.Secret == nil {
|
||||
t.Fatal("creds returned no secret")
|
||||
}
|
||||
tokenID, _ := creds.Data["token_id"].(string)
|
||||
tokenVal, _ := creds.Data["token"].(string)
|
||||
if tokenID == "" || tokenVal == "" {
|
||||
t.Fatalf("creds missing token/token_id: %#v", creds.Data)
|
||||
}
|
||||
if !strings.HasPrefix(tokenVal, "gha_") {
|
||||
t.Errorf("token = %q, want gha_ prefix", tokenVal)
|
||||
}
|
||||
if creds.Data["token_type"].(string) != "agent" {
|
||||
t.Errorf("token_type = %q, want agent", creds.Data["token_type"])
|
||||
}
|
||||
if creds.Data["base_url"].(string) != srv.URL {
|
||||
t.Errorf("base_url = %q, want %q", creds.Data["base_url"], srv.URL)
|
||||
}
|
||||
if !fake.has(tokenID) {
|
||||
t.Error("minted token not present in ghp")
|
||||
}
|
||||
|
||||
// Renew keeps the same secret.
|
||||
if _, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.RenewOperation,
|
||||
Secret: creds.Secret,
|
||||
Storage: s,
|
||||
}); err != nil {
|
||||
t.Fatalf("renew: %v", err)
|
||||
}
|
||||
|
||||
// Revoke deletes the token from ghp.
|
||||
if _, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.RevokeOperation,
|
||||
Secret: creds.Secret,
|
||||
Storage: s,
|
||||
}); err != nil {
|
||||
t.Fatalf("revoke: %v", err)
|
||||
}
|
||||
if fake.has(tokenID) {
|
||||
t.Error("token still present after revoke")
|
||||
}
|
||||
}
|
||||
|
||||
func TestRevokeIsIdempotent(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
req(t, b, s, logical.CreateOperation, "roles/agent", map[string]interface{}{
|
||||
"token_type": "agent", "installation_id": 7,
|
||||
})
|
||||
creds := req(t, b, s, logical.ReadOperation, "creds/agent", nil)
|
||||
|
||||
revoke := func() error {
|
||||
_, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.RevokeOperation,
|
||||
Secret: creds.Secret,
|
||||
Storage: s,
|
||||
})
|
||||
return err
|
||||
}
|
||||
if err := revoke(); err != nil {
|
||||
t.Fatalf("first revoke: %v", err)
|
||||
}
|
||||
// A second revoke (token already gone → 404) must still succeed.
|
||||
if err := revoke(); err != nil {
|
||||
t.Fatalf("second revoke should be idempotent, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAgentRoleRequiresInstallationID(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
|
||||
resp, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.CreateOperation,
|
||||
Path: "roles/bad",
|
||||
Data: map[string]interface{}{"token_type": "agent"},
|
||||
Storage: s,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected err: %v", err)
|
||||
}
|
||||
if resp == nil || !resp.IsError() {
|
||||
t.Fatal("expected error for agent role without installation_id")
|
||||
}
|
||||
}
|
||||
|
||||
func TestScopeValidationOnRole(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
|
||||
// Bad level rejected.
|
||||
resp, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.CreateOperation,
|
||||
Path: "roles/bad",
|
||||
Data: map[string]interface{}{"token_type": "agent", "installation_id": 1, "scopes": "contents:admin"},
|
||||
Storage: s,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected err: %v", err)
|
||||
}
|
||||
if resp == nil || !resp.IsError() {
|
||||
t.Fatal("expected error for invalid scope level")
|
||||
}
|
||||
|
||||
// Valid scopes normalise (level lower-cased, duplicates dropped) and read back.
|
||||
req(t, b, s, logical.CreateOperation, "roles/ok", map[string]interface{}{
|
||||
"token_type": "agent", "installation_id": 1,
|
||||
"scopes": " contents:Read , contents:read, pull_requests:write",
|
||||
})
|
||||
role := req(t, b, s, logical.ReadOperation, "roles/ok", nil)
|
||||
got, _ := role.Data["scopes"].([]string)
|
||||
if len(got) != 2 || got[0] != "contents:read" || got[1] != "pull_requests:write" {
|
||||
t.Errorf("normalised scopes = %v, want [contents:read pull_requests:write]", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestProxyRoleAllowedWithoutInstallation(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
|
||||
req(t, b, s, logical.CreateOperation, "roles/proxy", map[string]interface{}{
|
||||
"token_type": "proxy", "repositories": "unkin/ghp",
|
||||
})
|
||||
creds := req(t, b, s, logical.ReadOperation, "creds/proxy", nil)
|
||||
if creds.Secret == nil {
|
||||
t.Fatal("proxy mint returned no secret")
|
||||
}
|
||||
if creds.Data["token_type"].(string) != "proxy" {
|
||||
t.Errorf("token_type = %q, want proxy", creds.Data["token_type"])
|
||||
}
|
||||
}
|
||||
|
||||
func TestConfigRequiresTokenAndVerifies(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
|
||||
// Missing admin_token.
|
||||
resp, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.CreateOperation,
|
||||
Path: "config",
|
||||
Data: map[string]interface{}{"base_url": srv.URL},
|
||||
Storage: s,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected err: %v", err)
|
||||
}
|
||||
if resp == nil || !resp.IsError() {
|
||||
t.Fatal("expected error when admin_token missing")
|
||||
}
|
||||
|
||||
// Wrong token fails verification against the fake (401).
|
||||
resp, err = b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.CreateOperation,
|
||||
Path: "config",
|
||||
Data: map[string]interface{}{"base_url": srv.URL, "admin_token": "wrong"},
|
||||
Storage: s,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected err: %v", err)
|
||||
}
|
||||
if resp == nil || !resp.IsError() {
|
||||
t.Fatal("expected error when admin_token fails verification")
|
||||
}
|
||||
|
||||
// config read must never leak the token.
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
read := req(t, b, s, logical.ReadOperation, "config", nil)
|
||||
if _, leaked := read.Data["admin_token"]; leaked {
|
||||
t.Fatal("config read leaked admin_token")
|
||||
}
|
||||
if read.Data["base_url"].(string) != srv.URL {
|
||||
t.Errorf("base_url = %q, want %q", read.Data["base_url"], srv.URL)
|
||||
}
|
||||
}
|
||||
|
||||
func TestConfigRejectsNonAdminToken(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
fake.forbidden = true
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
resp, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.CreateOperation,
|
||||
Path: "config",
|
||||
Data: map[string]interface{}{"base_url": srv.URL, "admin_token": "ghpsvc_seed"},
|
||||
Storage: s,
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected err: %v", err)
|
||||
}
|
||||
if resp == nil || !resp.IsError() {
|
||||
t.Fatal("expected error when token authenticates but is not admin")
|
||||
}
|
||||
if !strings.Contains(resp.Error().Error(), "not a ghp admin") {
|
||||
t.Errorf("unexpected error: %v", resp.Error())
|
||||
}
|
||||
}
|
||||
|
||||
func TestCredsBeforeConfig(t *testing.T) {
|
||||
b, s := newTestBackend(t)
|
||||
req(t, b, s, logical.CreateOperation, "roles/x", map[string]interface{}{
|
||||
"token_type": "agent", "installation_id": 1,
|
||||
})
|
||||
_, err := b.HandleRequest(context.Background(), &logical.Request{
|
||||
Operation: logical.ReadOperation,
|
||||
Path: "creds/x",
|
||||
Storage: s,
|
||||
})
|
||||
if err == nil {
|
||||
t.Fatal("expected creds read to fail without config")
|
||||
}
|
||||
}
|
||||
|
||||
func TestRolesList(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
b, s := newTestBackend(t)
|
||||
configure(t, b, s, srv.URL, "ghpsvc_seed")
|
||||
req(t, b, s, logical.CreateOperation, "roles/a", map[string]interface{}{"token_type": "agent", "installation_id": 1})
|
||||
req(t, b, s, logical.CreateOperation, "roles/b", map[string]interface{}{"token_type": "agent", "installation_id": 2})
|
||||
|
||||
list := req(t, b, s, logical.ListOperation, "roles/", nil)
|
||||
keys, _ := list.Data["keys"].([]string)
|
||||
if len(keys) != 2 {
|
||||
t.Fatalf("roles list = %v, want 2 entries", keys)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,189 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"crypto/tls"
|
||||
"crypto/x509"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"strings"
|
||||
"time"
|
||||
)
|
||||
|
||||
const defaultHTTPTimeout = 30 * time.Second
|
||||
|
||||
// ghpClient talks to the ghp admin API using the seeded service token as a
|
||||
// bearer credential. ghp matches the token against its configured service-token
|
||||
// set and grants a synthetic admin session, which is required to mint agent
|
||||
// tokens and to revoke any user's token.
|
||||
type ghpClient struct {
|
||||
baseURL string
|
||||
token string
|
||||
httpClient *http.Client
|
||||
}
|
||||
|
||||
// createTokenRequest is ghp's POST /api/tokens body. Only the fields the engine
|
||||
// sets are included; omitempty keeps the wire payload minimal.
|
||||
type createTokenRequest struct {
|
||||
Type string `json:"type,omitempty"`
|
||||
AppRecordID string `json:"app_record_id,omitempty"`
|
||||
Repositories []string `json:"repositories,omitempty"`
|
||||
InstallationID int64 `json:"installation_id,omitempty"`
|
||||
Scopes string `json:"scopes,omitempty"`
|
||||
Duration string `json:"duration,omitempty"`
|
||||
SessionID string `json:"session_id,omitempty"`
|
||||
}
|
||||
|
||||
// createTokenResponse mirrors the subset of ghp's 201 response the engine reads.
|
||||
// The token value is only ever returned here, at creation.
|
||||
type createTokenResponse struct {
|
||||
Token string `json:"token"`
|
||||
ID string `json:"id"`
|
||||
Type string `json:"type"`
|
||||
Repositories []string `json:"repositories"`
|
||||
Scopes map[string]string `json:"scopes"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
SessionID string `json:"session_id"`
|
||||
}
|
||||
|
||||
func newClient(cfg *ghpConfig) (*ghpClient, error) {
|
||||
if cfg == nil {
|
||||
return nil, errors.New("ghp client configuration is nil")
|
||||
}
|
||||
if cfg.BaseURL == "" {
|
||||
return nil, errors.New("base_url is required")
|
||||
}
|
||||
if cfg.AdminToken == "" {
|
||||
return nil, errors.New("admin_token is required")
|
||||
}
|
||||
|
||||
timeout := defaultHTTPTimeout
|
||||
if cfg.RequestTimeoutSeconds > 0 {
|
||||
timeout = time.Duration(cfg.RequestTimeoutSeconds) * time.Second
|
||||
}
|
||||
|
||||
tlsConfig := &tls.Config{InsecureSkipVerify: cfg.TLSSkipVerify} //nolint:gosec // opt-in via config
|
||||
if cfg.CACert != "" {
|
||||
pool := x509.NewCertPool()
|
||||
if !pool.AppendCertsFromPEM([]byte(cfg.CACert)) {
|
||||
return nil, errors.New("ca_cert is not a valid PEM certificate")
|
||||
}
|
||||
tlsConfig.RootCAs = pool
|
||||
}
|
||||
|
||||
return &ghpClient{
|
||||
baseURL: strings.TrimRight(cfg.BaseURL, "/"),
|
||||
token: cfg.AdminToken,
|
||||
httpClient: &http.Client{
|
||||
Timeout: timeout,
|
||||
Transport: &http.Transport{TLSClientConfig: tlsConfig},
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
|
||||
// errNotFound flags a 404 so callers can treat absence as non-fatal.
|
||||
var errNotFound = errors.New("not found")
|
||||
|
||||
// CreateToken mints a new ghp token and returns the full response. The service
|
||||
// token's synthetic-admin session authorises agent-token creation and any scope.
|
||||
func (c *ghpClient) CreateToken(ctx context.Context, req createTokenRequest) (*createTokenResponse, error) {
|
||||
var out createTokenResponse
|
||||
if err := c.do(ctx, http.MethodPost, "/api/tokens", req, &out); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if out.Token == "" {
|
||||
return nil, errors.New("ghp returned an empty token value")
|
||||
}
|
||||
if out.ID == "" {
|
||||
return nil, errors.New("ghp returned an empty token id")
|
||||
}
|
||||
return &out, nil
|
||||
}
|
||||
|
||||
// RevokeToken deletes a ghp token by its id. A missing token (404) is treated as
|
||||
// success so revocation is idempotent and Vault's retries converge.
|
||||
func (c *ghpClient) RevokeToken(ctx context.Context, id string) error {
|
||||
if id == "" {
|
||||
return nil
|
||||
}
|
||||
err := c.do(ctx, http.MethodDelete, "/api/tokens/"+id, nil, nil)
|
||||
if errors.Is(err, errNotFound) {
|
||||
return nil
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
// VerifyAdmin confirms the seeded service token authenticates as a ghp admin by
|
||||
// calling an admin-only endpoint. 401 means the token is invalid; 403 means it
|
||||
// authenticated but is not an admin. Used to fail config writes fast.
|
||||
func (c *ghpClient) VerifyAdmin(ctx context.Context) error {
|
||||
err := c.do(ctx, http.MethodGet, "/api/users", nil, nil)
|
||||
if err == nil {
|
||||
return nil
|
||||
}
|
||||
if errors.Is(err, errUnauthorized) {
|
||||
return errors.New("ghp rejected the admin_token (401); it is not a configured service token")
|
||||
}
|
||||
if errors.Is(err, errForbidden) {
|
||||
return errors.New("the admin_token authenticated but is not a ghp admin (403); a service token is required")
|
||||
}
|
||||
return err
|
||||
}
|
||||
|
||||
var (
|
||||
errUnauthorized = errors.New("unauthorized")
|
||||
errForbidden = errors.New("forbidden")
|
||||
)
|
||||
|
||||
func (c *ghpClient) do(ctx context.Context, method, path string, payload, out interface{}) error {
|
||||
var body io.Reader
|
||||
if payload != nil {
|
||||
raw, err := json.Marshal(payload)
|
||||
if err != nil {
|
||||
return fmt.Errorf("encoding request body: %w", err)
|
||||
}
|
||||
body = bytes.NewReader(raw)
|
||||
}
|
||||
|
||||
req, err := http.NewRequestWithContext(ctx, method, c.baseURL+path, body)
|
||||
if err != nil {
|
||||
return fmt.Errorf("building request: %w", err)
|
||||
}
|
||||
req.Header.Set("Authorization", "Bearer "+c.token)
|
||||
req.Header.Set("Accept", "application/json")
|
||||
if body != nil {
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
}
|
||||
|
||||
resp, err := c.httpClient.Do(req)
|
||||
if err != nil {
|
||||
return fmt.Errorf("calling ghp %s %s: %w", method, path, err)
|
||||
}
|
||||
defer func() { _ = resp.Body.Close() }()
|
||||
|
||||
respBody, _ := io.ReadAll(io.LimitReader(resp.Body, 1<<20))
|
||||
|
||||
switch resp.StatusCode {
|
||||
case http.StatusNotFound:
|
||||
return errNotFound
|
||||
case http.StatusUnauthorized:
|
||||
return errUnauthorized
|
||||
case http.StatusForbidden:
|
||||
return errForbidden
|
||||
}
|
||||
if resp.StatusCode < 200 || resp.StatusCode >= 300 {
|
||||
return fmt.Errorf("ghp %s %s returned %d: %s", method, path, resp.StatusCode, strings.TrimSpace(string(respBody)))
|
||||
}
|
||||
|
||||
if out == nil {
|
||||
return nil
|
||||
}
|
||||
if err := json.Unmarshal(respBody, out); err != nil {
|
||||
return fmt.Errorf("decoding ghp response: %w", err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
+108
@@ -0,0 +1,108 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func testClient(t *testing.T, url, token string) *ghpClient {
|
||||
t.Helper()
|
||||
c, err := newClient(&ghpConfig{BaseURL: url, AdminToken: token})
|
||||
if err != nil {
|
||||
t.Fatalf("newClient: %v", err)
|
||||
}
|
||||
return c
|
||||
}
|
||||
|
||||
func TestClientCreateAndRevokeToken(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
c := testClient(t, srv.URL, "ghpsvc_seed")
|
||||
ctx := context.Background()
|
||||
|
||||
out, err := c.CreateToken(ctx, createTokenRequest{
|
||||
Type: tokenTypeAgent, InstallationID: 42, Scopes: "contents:read", SessionID: "vault-x",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("CreateToken: %v", err)
|
||||
}
|
||||
if out.Token == "" || out.ID == "" {
|
||||
t.Fatalf("CreateToken returned empty value/id: %#v", out)
|
||||
}
|
||||
if !fake.has(out.ID) {
|
||||
t.Fatal("token not stored in fake")
|
||||
}
|
||||
|
||||
if err := c.RevokeToken(ctx, out.ID); err != nil {
|
||||
t.Fatalf("RevokeToken: %v", err)
|
||||
}
|
||||
if fake.has(out.ID) {
|
||||
t.Fatal("token still present after revoke")
|
||||
}
|
||||
|
||||
// Revoking a non-existent token (404) is treated as success.
|
||||
if err := c.RevokeToken(ctx, "tok-999999"); err != nil {
|
||||
t.Fatalf("RevokeToken of missing token should succeed, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientUnauthorized(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_correct")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
c := testClient(t, srv.URL, "ghpsvc_wrong")
|
||||
_, err := c.CreateToken(context.Background(), createTokenRequest{Type: tokenTypeAgent, InstallationID: 1})
|
||||
if err == nil {
|
||||
t.Fatal("expected unauthorized error with wrong token")
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientVerifyAdmin(t *testing.T) {
|
||||
fake := newFakeGHP("ghpsvc_seed")
|
||||
srv := fake.server(t)
|
||||
defer srv.Close()
|
||||
|
||||
if err := testClient(t, srv.URL, "ghpsvc_seed").VerifyAdmin(context.Background()); err != nil {
|
||||
t.Fatalf("VerifyAdmin with valid admin token: %v", err)
|
||||
}
|
||||
|
||||
// Invalid token → 401 → clear message.
|
||||
err := testClient(t, srv.URL, "nope").VerifyAdmin(context.Background())
|
||||
if err == nil || !strings.Contains(err.Error(), "not a configured service token") {
|
||||
t.Errorf("expected 401 message, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientVerifyAdminNonAdmin(t *testing.T) {
|
||||
srv := httptest.NewServer(http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
||||
if r.URL.Path == "/api/users" {
|
||||
w.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}))
|
||||
defer srv.Close()
|
||||
|
||||
err := testClient(t, srv.URL, "ghpsvc_seed").VerifyAdmin(context.Background())
|
||||
if err == nil || !strings.Contains(err.Error(), "not a ghp admin") {
|
||||
t.Errorf("expected non-admin error, got: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestClientRequiresConfig(t *testing.T) {
|
||||
if _, err := newClient(&ghpConfig{BaseURL: "https://ghp.example.com"}); err == nil {
|
||||
t.Fatal("expected error when admin_token missing")
|
||||
}
|
||||
if _, err := newClient(&ghpConfig{AdminToken: "t"}); err == nil {
|
||||
t.Fatal("expected error when base_url missing")
|
||||
}
|
||||
if _, err := newClient(&ghpConfig{BaseURL: "x", AdminToken: "t", CACert: "not-a-pem"}); err == nil {
|
||||
t.Fatal("expected error for invalid ca_cert")
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,34 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"os"
|
||||
|
||||
hclog "github.com/hashicorp/go-hclog"
|
||||
"github.com/hashicorp/vault/api"
|
||||
"github.com/hashicorp/vault/sdk/plugin"
|
||||
|
||||
ghp "git.unkin.net/unkin/vault-plugin-secrets-ghp"
|
||||
)
|
||||
|
||||
func main() {
|
||||
apiClientMeta := &api.PluginAPIClientMeta{}
|
||||
flags := apiClientMeta.FlagSet()
|
||||
if err := flags.Parse(os.Args[1:]); err != nil {
|
||||
logger := hclog.New(&hclog.LoggerOptions{})
|
||||
logger.Error("failed to parse flags", "error", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
tlsConfig := apiClientMeta.GetTLSConfig()
|
||||
tlsProviderFunc := api.VaultPluginTLSProvider(tlsConfig)
|
||||
|
||||
err := plugin.ServeMultiplex(&plugin.ServeOpts{
|
||||
BackendFactoryFunc: ghp.Factory,
|
||||
TLSProviderFunc: tlsProviderFunc,
|
||||
})
|
||||
if err != nil {
|
||||
logger := hclog.New(&hclog.LoggerOptions{})
|
||||
logger.Error("plugin shutting down", "error", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,90 @@
|
||||
module git.unkin.net/unkin/vault-plugin-secrets-ghp
|
||||
|
||||
go 1.25.0
|
||||
|
||||
require (
|
||||
github.com/hashicorp/go-hclog v1.6.3
|
||||
github.com/hashicorp/go-uuid v1.0.3
|
||||
github.com/hashicorp/vault/api v1.15.0
|
||||
github.com/hashicorp/vault/sdk v0.14.0
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/Microsoft/go-winio v0.6.1 // indirect
|
||||
github.com/armon/go-metrics v0.4.1 // indirect
|
||||
github.com/armon/go-radix v1.0.0 // indirect
|
||||
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
|
||||
github.com/cespare/xxhash/v2 v2.3.0 // indirect
|
||||
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc // indirect
|
||||
github.com/distribution/reference v0.6.0 // indirect
|
||||
github.com/docker/docker v26.1.5+incompatible // indirect
|
||||
github.com/docker/go-connections v0.4.0 // indirect
|
||||
github.com/docker/go-units v0.5.0 // indirect
|
||||
github.com/evanphx/json-patch/v5 v5.6.0 // indirect
|
||||
github.com/fatih/color v1.16.0 // indirect
|
||||
github.com/felixge/httpsnoop v1.0.4 // indirect
|
||||
github.com/go-jose/go-jose/v4 v4.1.4 // indirect
|
||||
github.com/go-logr/logr v1.4.3 // indirect
|
||||
github.com/go-logr/stdr v1.2.2 // indirect
|
||||
github.com/gogo/protobuf v1.3.2 // indirect
|
||||
github.com/golang/protobuf v1.5.4 // indirect
|
||||
github.com/golang/snappy v0.0.4 // indirect
|
||||
github.com/hashicorp/errwrap v1.1.0 // indirect
|
||||
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
|
||||
github.com/hashicorp/go-immutable-radix v1.3.1 // indirect
|
||||
github.com/hashicorp/go-kms-wrapping/entropy/v2 v2.0.0 // indirect
|
||||
github.com/hashicorp/go-kms-wrapping/v2 v2.0.8 // indirect
|
||||
github.com/hashicorp/go-multierror v1.1.1 // indirect
|
||||
github.com/hashicorp/go-plugin v1.6.1 // indirect
|
||||
github.com/hashicorp/go-retryablehttp v0.7.7 // indirect
|
||||
github.com/hashicorp/go-rootcerts v1.0.2 // indirect
|
||||
github.com/hashicorp/go-secure-stdlib/mlock v0.1.2 // indirect
|
||||
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.8 // indirect
|
||||
github.com/hashicorp/go-secure-stdlib/plugincontainer v0.4.0 // indirect
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 // indirect
|
||||
github.com/hashicorp/go-sockaddr v1.0.6 // indirect
|
||||
github.com/hashicorp/go-version v1.6.0 // indirect
|
||||
github.com/hashicorp/golang-lru v0.5.4 // indirect
|
||||
github.com/hashicorp/hcl v1.0.1-vault-5 // indirect
|
||||
github.com/hashicorp/yamux v0.1.1 // indirect
|
||||
github.com/joshlf/go-acl v0.0.0-20200411065538-eae00ae38531 // indirect
|
||||
github.com/mattn/go-colorable v0.1.13 // indirect
|
||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||
github.com/mitchellh/copystructure v1.2.0 // indirect
|
||||
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
||||
github.com/mitchellh/go-testing-interface v1.14.1 // indirect
|
||||
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
||||
github.com/mitchellh/reflectwalk v1.0.2 // indirect
|
||||
github.com/moby/docker-image-spec v1.3.1 // indirect
|
||||
github.com/oklog/run v1.1.0 // indirect
|
||||
github.com/opencontainers/go-digest v1.0.0 // indirect
|
||||
github.com/opencontainers/image-spec v1.1.0-rc2.0.20221005185240-3a7f492d3f1b // indirect
|
||||
github.com/petermattis/goid v0.0.0-20180202154549-b0b1615b78e5 // indirect
|
||||
github.com/pierrec/lz4 v2.6.1+incompatible // indirect
|
||||
github.com/pkg/errors v0.9.1 // indirect
|
||||
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
|
||||
github.com/ryanuber/go-glob v1.0.0 // indirect
|
||||
github.com/sasha-s/go-deadlock v0.2.0 // indirect
|
||||
github.com/stretchr/testify v1.11.1 // indirect
|
||||
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
|
||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.51.0 // indirect
|
||||
go.opentelemetry.io/otel v1.44.0 // indirect
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 // indirect
|
||||
go.opentelemetry.io/otel/metric v1.44.0 // indirect
|
||||
go.opentelemetry.io/otel/sdk/metric v1.44.0 // indirect
|
||||
go.opentelemetry.io/otel/trace v1.44.0 // indirect
|
||||
go.opentelemetry.io/proto/otlp v1.11.0 // indirect
|
||||
go.uber.org/atomic v1.9.0 // indirect
|
||||
golang.org/x/crypto v0.54.0 // indirect
|
||||
golang.org/x/mod v0.37.0 // indirect
|
||||
golang.org/x/net v0.57.0 // indirect
|
||||
golang.org/x/sync v0.22.0 // indirect
|
||||
golang.org/x/sys v0.47.0 // indirect
|
||||
golang.org/x/text v0.40.0 // indirect
|
||||
golang.org/x/time v0.5.0 // indirect
|
||||
golang.org/x/tools v0.47.0 // indirect
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a // indirect
|
||||
google.golang.org/grpc v1.82.1 // indirect
|
||||
google.golang.org/protobuf v1.36.11 // indirect
|
||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||
)
|
||||
@@ -0,0 +1,340 @@
|
||||
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 h1:UQHMgLO+TxOElx5B5HZ4hJQsoJ/PvUvKRhJHDQXO8P8=
|
||||
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1/go.mod h1:xomTg63KZ2rFqZQzSB4Vz2SUXa1BpHTVz9L5PTmPC4E=
|
||||
github.com/DataDog/datadog-go v3.2.0+incompatible/go.mod h1:LButxg5PwREeZtORoXG3tL4fMGNddJ+vMq1mwgfaqoQ=
|
||||
github.com/Microsoft/go-winio v0.6.1 h1:9/kr64B9VUZrLm5YYwbGtUJnMgqWVOdUAXu6Migciow=
|
||||
github.com/Microsoft/go-winio v0.6.1/go.mod h1:LRdKpFKfdobln8UmuiYcKPot9D2v6svN5+sAH+4kjUM=
|
||||
github.com/alecthomas/template v0.0.0-20160405071501-a0175ee3bccc/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
|
||||
github.com/alecthomas/template v0.0.0-20190718012654-fb15b899a751/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
|
||||
github.com/alecthomas/units v0.0.0-20151022065526-2efee857e7cf/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
|
||||
github.com/alecthomas/units v0.0.0-20190717042225-c3de453c63f4/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
|
||||
github.com/armon/go-metrics v0.4.1 h1:hR91U9KYmb6bLBYLQjyM+3j+rcd/UhE+G78SFnF8gJA=
|
||||
github.com/armon/go-metrics v0.4.1/go.mod h1:E6amYzXo6aW1tqzoZGT755KkbgrJsSdpwZ+3JqfkOG4=
|
||||
github.com/armon/go-radix v1.0.0 h1:F4z6KzEeeQIMeLFa97iZU6vupzoecKdU5TX24SNppXI=
|
||||
github.com/armon/go-radix v1.0.0/go.mod h1:ufUuZ+zHj4x4TnLV4JWEpy2hxWSpsRywHrMgIH9cCH8=
|
||||
github.com/beorn7/perks v0.0.0-20180321164747-3a771d992973/go.mod h1:Dwedo/Wpr24TaqPxmxbtue+5NUziq4I4S80YR8gNf3Q=
|
||||
github.com/beorn7/perks v1.0.0/go.mod h1:KWe93zE9D1o94FZ5RNwFwVgaQK1VOXiVxmqh+CedLV8=
|
||||
github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6rlkpw=
|
||||
github.com/bufbuild/protocompile v0.4.0 h1:LbFKd2XowZvQ/kajzguUp2DC9UEIQhIq77fZZlaQsNA=
|
||||
github.com/bufbuild/protocompile v0.4.0/go.mod h1:3v93+mbWn/v3xzN+31nwkJfrEpAUwp+BagBSZWx+TP8=
|
||||
github.com/cenkalti/backoff/v4 v4.3.0 h1:MyRJ/UdXutAwSAT+s3wNd7MfTIcy71VQueUuFK343L8=
|
||||
github.com/cenkalti/backoff/v4 v4.3.0/go.mod h1:Y3VNntkOUPxTVeUxJ/G5vcM//AlwfmyYozVcomhLiZE=
|
||||
github.com/cespare/xxhash/v2 v2.1.1/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
||||
github.com/cespare/xxhash/v2 v2.3.0 h1:UL815xU9SqsFlibzuggzjXhog7bL6oX9BbNZnL2UFvs=
|
||||
github.com/cespare/xxhash/v2 v2.3.0/go.mod h1:VGX0DQ3Q6kWi7AoAeZDth3/j3BFtOZR5XLFGgcrjCOs=
|
||||
github.com/circonus-labs/circonus-gometrics v2.3.1+incompatible/go.mod h1:nmEj6Dob7S7YxXgwXpfOuvO54S+tGdZdw9fuRZt25Ag=
|
||||
github.com/circonus-labs/circonusllhist v0.1.3/go.mod h1:kMXHVDlOchFAehlya5ePtbp5jckzBHf4XRpQvBOLI+I=
|
||||
github.com/containerd/log v0.1.0 h1:TCJt7ioM2cr/tfR8GPbGf9/VRAX8D2B4PjzCpfX540I=
|
||||
github.com/containerd/log v0.1.0/go.mod h1:VRRf09a7mHDIRezVKTRCrOq78v577GXq3bSa3EhrzVo=
|
||||
github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc h1:U9qPSI2PIWSS1VwoXQT9A3Wy9MM3WgvqSxFWenqJduM=
|
||||
github.com/davecgh/go-spew v1.1.2-0.20180830191138-d8f796af33cc/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5QvfrDyIgxBk=
|
||||
github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E=
|
||||
github.com/docker/docker v26.1.5+incompatible h1:NEAxTwEjxV6VbBMBoGG3zPqbiJosIApZjxlbrG9q3/g=
|
||||
github.com/docker/docker v26.1.5+incompatible/go.mod h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk=
|
||||
github.com/docker/go-connections v0.4.0 h1:El9xVISelRB7BuFusrZozjnkIM5YnzCViNKohAFqRJQ=
|
||||
github.com/docker/go-connections v0.4.0/go.mod h1:Gbd7IOopHjR8Iph03tsViu4nIes5XhDvyHbTtUxmeec=
|
||||
github.com/docker/go-units v0.5.0 h1:69rxXcBk27SvSaaxTtLh/8llcHD8vYHT7WSdRZ/jvr4=
|
||||
github.com/docker/go-units v0.5.0/go.mod h1:fgPhTUdO+D/Jk86RDLlptpiXQzgHJF7gydDDbaIK4Dk=
|
||||
github.com/evanphx/json-patch/v5 v5.6.0 h1:b91NhWfaz02IuVxO9faSllyAtNXHMPkC5J8sJCLunww=
|
||||
github.com/evanphx/json-patch/v5 v5.6.0/go.mod h1:G79N1coSVB93tBe7j6PhzjmR3/2VvlbKOFpnXhI9Bw4=
|
||||
github.com/fatih/color v1.13.0/go.mod h1:kLAiJbzzSOZDVNGyDpeOxJ47H46qBXwg5ILebYFFOfk=
|
||||
github.com/fatih/color v1.16.0 h1:zmkK9Ngbjj+K0yRhTVONQh1p/HknKYSlNT+vZCzyokM=
|
||||
github.com/fatih/color v1.16.0/go.mod h1:fL2Sau1YI5c0pdGEVCbKQbLXB6edEj1ZgiY4NijnWvE=
|
||||
github.com/fatih/structs v1.1.0 h1:Q7juDM0QtcnhCpeyLGQKyg4TOIghuNXrkL32pHAUMxo=
|
||||
github.com/fatih/structs v1.1.0/go.mod h1:9NiDSp5zOcgEDl+j00MP/WkGVPOlPRLejGD8Ga6PJ7M=
|
||||
github.com/felixge/httpsnoop v1.0.4 h1:NFTV2Zj1bL4mc9sqWACXbQFVBBg2W3GPvqp8/ESS2Wg=
|
||||
github.com/felixge/httpsnoop v1.0.4/go.mod h1:m8KPJKqk1gH5J9DgRY2ASl2lWCfGKXixSwevea8zH2U=
|
||||
github.com/frankban/quicktest v1.14.0 h1:+cqqvzZV87b4adx/5ayVOaYZ2CrvM4ejQvUdBzPPUss=
|
||||
github.com/frankban/quicktest v1.14.0/go.mod h1:NeW+ay9A/U67EYXNFA1nPE8e/tnQv/09mUdL/ijj8og=
|
||||
github.com/go-jose/go-jose/v4 v4.1.4 h1:moDMcTHmvE6Groj34emNPLs/qtYXRVcd6S7NHbHz3kA=
|
||||
github.com/go-jose/go-jose/v4 v4.1.4/go.mod h1:x4oUasVrzR7071A4TnHLGSPpNOm2a21K9Kf04k1rs08=
|
||||
github.com/go-kit/kit v0.8.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
|
||||
github.com/go-kit/kit v0.9.0/go.mod h1:xBxKIO96dXMWWy0MnWVtmwkA9/13aqxPnvrjFYMA2as=
|
||||
github.com/go-logfmt/logfmt v0.3.0/go.mod h1:Qt1PoO58o5twSAckw1HlFXLmHsOX5/0LbT9GBnD5lWE=
|
||||
github.com/go-logfmt/logfmt v0.4.0/go.mod h1:3RMwSq7FuexP4Kalkev3ejPJsZTpXXBr9+V4qmtdjCk=
|
||||
github.com/go-logr/logr v1.2.2/go.mod h1:jdQByPbusPIv2/zmleS9BjJVeZ6kBagPoEUsqbVz/1A=
|
||||
github.com/go-logr/logr v1.4.3 h1:CjnDlHq8ikf6E492q6eKboGOC0T8CDaOvkHCIg8idEI=
|
||||
github.com/go-logr/logr v1.4.3/go.mod h1:9T104GzyrTigFIr8wt5mBrctHMim0Nb2HLGrmQ40KvY=
|
||||
github.com/go-logr/stdr v1.2.2 h1:hSWxHoqTgW2S2qGc0LTAI563KZ5YKYRhT3MFKZMbjag=
|
||||
github.com/go-logr/stdr v1.2.2/go.mod h1:mMo/vtBO5dYbehREoey6XUKy/eSumjCCveDpRre4VKE=
|
||||
github.com/go-stack/stack v1.8.0/go.mod h1:v0f6uXyyMGvRgIKkXu+yp6POWl0qKG85gN/melR3HDY=
|
||||
github.com/go-test/deep v1.1.0 h1:WOcxcdHcvdgThNXjw0t76K42FXTU7HpNQWHpA2HHNlg=
|
||||
github.com/go-test/deep v1.1.0/go.mod h1:5C2ZWiW0ErCdrYzpqxLbTX7MG14M9iiw8DgHncVwcsE=
|
||||
github.com/gogo/protobuf v1.1.1/go.mod h1:r8qH/GZQm5c6nD/R0oafs1akxWv10x8SbQlK7atdtwQ=
|
||||
github.com/gogo/protobuf v1.3.2 h1:Ov1cvc58UF3b5XjBnZv7+opcTcQFZebYjWzi34vdm4Q=
|
||||
github.com/gogo/protobuf v1.3.2/go.mod h1:P1XiOD3dCwIKUDQYPy72D8LYyHL2YPYrpS2s69NZV8Q=
|
||||
github.com/golang/protobuf v1.2.0/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
|
||||
github.com/golang/protobuf v1.3.1/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
|
||||
github.com/golang/protobuf v1.3.2/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
|
||||
github.com/golang/protobuf v1.5.4 h1:i7eJL8qZTpSEXOPTxNKhASYpMn+8e5Q6AdndVa1dWek=
|
||||
github.com/golang/protobuf v1.5.4/go.mod h1:lnTiLA8Wa4RWRcIUkrtSVa5nRhsEGBg48fD6rSs7xps=
|
||||
github.com/golang/snappy v0.0.4 h1:yAGX7huGHXlcLOEtBnF4w7FQwA26wojNCwOYAEhLjQM=
|
||||
github.com/golang/snappy v0.0.4/go.mod h1:/XxbfmMg8lxefKM7IXC3fBNl/7bRcc72aCRzEWrmP2Q=
|
||||
github.com/google/go-cmp v0.3.1/go.mod h1:8QqcDgzrUqlUb/G2PQTWiueGozuR1884gddMywk6iLU=
|
||||
github.com/google/go-cmp v0.4.0/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
|
||||
github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
|
||||
github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
|
||||
github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg=
|
||||
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
|
||||
github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
|
||||
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0 h1:5VipnvEpbqr2gA2VbM+nYVbkIF28c5ZQfqCBQ5g2xfk=
|
||||
github.com/grpc-ecosystem/grpc-gateway/v2 v2.29.0/go.mod h1:Hyl3n6Twe1hvtd9XUXDec4pTvgMSEixRuQKPTMH2bNs=
|
||||
github.com/hashicorp/errwrap v1.0.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
||||
github.com/hashicorp/errwrap v1.1.0 h1:OxrOeh75EUXMY8TBjag2fzXGZ40LB6IKw45YeGUDY2I=
|
||||
github.com/hashicorp/errwrap v1.1.0/go.mod h1:YH+1FKiLXxHSkmPseP+kNlulaMuP3n2brvKWEqk/Jc4=
|
||||
github.com/hashicorp/go-cleanhttp v0.5.0/go.mod h1:JpRdi6/HCYpAwUzNwuwqhbovhLtngrth3wmdIIUrZ80=
|
||||
github.com/hashicorp/go-cleanhttp v0.5.2 h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ=
|
||||
github.com/hashicorp/go-cleanhttp v0.5.2/go.mod h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48=
|
||||
github.com/hashicorp/go-hclog v1.6.3 h1:Qr2kF+eVWjTiYmU7Y31tYlP1h0q/X3Nl3tPGdaB11/k=
|
||||
github.com/hashicorp/go-hclog v1.6.3/go.mod h1:W4Qnvbt70Wk/zYJryRzDRU/4r0kIg0PVHBcfoyhpF5M=
|
||||
github.com/hashicorp/go-immutable-radix v1.0.0/go.mod h1:0y9vanUI8NX6FsYoO3zeMjhV/C5i9g4Q3DwcSNZ4P60=
|
||||
github.com/hashicorp/go-immutable-radix v1.3.1 h1:DKHmCUm2hRBK510BaiZlwvpD40f8bJFeZnpfm2KLowc=
|
||||
github.com/hashicorp/go-immutable-radix v1.3.1/go.mod h1:0y9vanUI8NX6FsYoO3zeMjhV/C5i9g4Q3DwcSNZ4P60=
|
||||
github.com/hashicorp/go-kms-wrapping/entropy/v2 v2.0.0 h1:pSjQfW3vPtrOTcasTUKgCTQT7OGPPTTMVRrOfU6FJD8=
|
||||
github.com/hashicorp/go-kms-wrapping/entropy/v2 v2.0.0/go.mod h1:xvb32K2keAc+R8DSFG2IwDcydK9DBQE+fGA5fsw6hSk=
|
||||
github.com/hashicorp/go-kms-wrapping/v2 v2.0.8 h1:9Q2lu1YbbmiAgvYZ7Pr31RdlVonUpX+mmDL7Z7qTA2U=
|
||||
github.com/hashicorp/go-kms-wrapping/v2 v2.0.8/go.mod h1:qTCjxGig/kjuj3hk1z8pOUrzbse/GxB1tGfbrq8tGJg=
|
||||
github.com/hashicorp/go-multierror v1.1.1 h1:H5DkEtf6CXdFp0N0Em5UCwQpXMWke8IA0+lD48awMYo=
|
||||
github.com/hashicorp/go-multierror v1.1.1/go.mod h1:iw975J/qwKPdAO1clOe2L8331t/9/fmwbPZ6JB6eMoM=
|
||||
github.com/hashicorp/go-plugin v1.6.1 h1:P7MR2UP6gNKGPp+y7EZw2kOiq4IR9WiqLvp0XOsVdwI=
|
||||
github.com/hashicorp/go-plugin v1.6.1/go.mod h1:XPHFku2tFo3o3QKFgSYo+cghcUhw1NA1hZyMK0PWAw0=
|
||||
github.com/hashicorp/go-retryablehttp v0.5.3/go.mod h1:9B5zBasrRhHXnJnui7y6sL7es7NDiJgTc6Er0maI1Xs=
|
||||
github.com/hashicorp/go-retryablehttp v0.7.7 h1:C8hUCYzor8PIfXHa4UrZkU4VvK8o9ISHxT2Q8+VepXU=
|
||||
github.com/hashicorp/go-retryablehttp v0.7.7/go.mod h1:pkQpWZeYWskR+D1tR2O5OcBFOxfA7DoAO6xtkuQnHTk=
|
||||
github.com/hashicorp/go-rootcerts v1.0.2 h1:jzhAVGtqPKbwpyCPELlgNWhE1znq+qwJtW5Oi2viEzc=
|
||||
github.com/hashicorp/go-rootcerts v1.0.2/go.mod h1:pqUvnprVnM5bf7AOirdbb01K4ccR319Vf4pU3K5EGc8=
|
||||
github.com/hashicorp/go-secure-stdlib/mlock v0.1.2 h1:p4AKXPPS24tO8Wc8i1gLvSKdmkiSY5xuju57czJ/IJQ=
|
||||
github.com/hashicorp/go-secure-stdlib/mlock v0.1.2/go.mod h1:zq93CJChV6L9QTfGKtfBxKqD7BqqXx5O04A/ns2p5+I=
|
||||
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.8 h1:iBt4Ew4XEGLfh6/bPk4rSYmuZJGizr6/x/AEizP0CQc=
|
||||
github.com/hashicorp/go-secure-stdlib/parseutil v0.1.8/go.mod h1:aiJI+PIApBRQG7FZTEBx5GiiX+HbOHilUdNxUZi4eV0=
|
||||
github.com/hashicorp/go-secure-stdlib/plugincontainer v0.4.0 h1:7Yran48kl6X7jfUg3sfYDrFot1gD3LvzdC3oPu5l/qo=
|
||||
github.com/hashicorp/go-secure-stdlib/plugincontainer v0.4.0/go.mod h1:9WJFu7L3d+Z4ViZmwUf+6/73/Uy7YMY1NXrB9wdElYE=
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2 h1:kes8mmyCpxJsI7FTwtzRqEy9CdjCtrXrXGuOpxEA7Ts=
|
||||
github.com/hashicorp/go-secure-stdlib/strutil v0.1.2/go.mod h1:Gou2R9+il93BqX25LAKCLuM+y9U2T4hlwvT1yprcna4=
|
||||
github.com/hashicorp/go-sockaddr v1.0.6 h1:RSG8rKU28VTUTvEKghe5gIhIQpv8evvNpnDEyqO4u9I=
|
||||
github.com/hashicorp/go-sockaddr v1.0.6/go.mod h1:uoUUmtwU7n9Dv3O4SNLeFvg0SxQ3lyjsj6+CCykpaxI=
|
||||
github.com/hashicorp/go-uuid v1.0.0/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro=
|
||||
github.com/hashicorp/go-uuid v1.0.3 h1:2gKiV6YVmrJ1i2CKKa9obLvRieoRGviZFL26PcT/Co8=
|
||||
github.com/hashicorp/go-uuid v1.0.3/go.mod h1:6SBZvOh/SIDV7/2o3Jml5SYk/TvGqwFJ/bN7x4byOro=
|
||||
github.com/hashicorp/go-version v1.6.0 h1:feTTfFNnjP967rlCxM/I9g701jU+RN74YKx2mOkIeek=
|
||||
github.com/hashicorp/go-version v1.6.0/go.mod h1:fltr4n8CU8Ke44wwGCBoEymUuxUHl09ZGVZPK5anwXA=
|
||||
github.com/hashicorp/golang-lru v0.5.0/go.mod h1:/m3WP610KZHVQ1SGc6re/UDhFvYD7pJ4Ao+sR/qLZy8=
|
||||
github.com/hashicorp/golang-lru v0.5.4 h1:YDjusn29QI/Das2iO9M0BHnIbxPeyuCHsjMW+lJfyTc=
|
||||
github.com/hashicorp/golang-lru v0.5.4/go.mod h1:iADmTwqILo4mZ8BN3D2Q6+9jd8WM5uGBxy+E8yxSoD4=
|
||||
github.com/hashicorp/hcl v1.0.1-vault-5 h1:kI3hhbbyzr4dldA8UdTb7ZlVVlI2DACdCfz31RPDgJM=
|
||||
github.com/hashicorp/hcl v1.0.1-vault-5/go.mod h1:XYhtn6ijBSAj6n4YqAaf7RBPS4I06AItNorpy+MoQNM=
|
||||
github.com/hashicorp/vault/api v1.15.0 h1:O24FYQCWwhwKnF7CuSqP30S51rTV7vz1iACXE/pj5DA=
|
||||
github.com/hashicorp/vault/api v1.15.0/go.mod h1:+5YTO09JGn0u+b6ySD/LLVf8WkJCPLAL2Vkmrn2+CM8=
|
||||
github.com/hashicorp/vault/sdk v0.14.0 h1:8vagjlpLurkFTnKT9aFSGs4U1XnK2IFytnWSxgFrDo0=
|
||||
github.com/hashicorp/vault/sdk v0.14.0/go.mod h1:3hnGK5yjx3CW2hFyk+Dw1jDgKxdBvUvjyxMHhq0oUFc=
|
||||
github.com/hashicorp/yamux v0.1.1 h1:yrQxtgseBDrq9Y652vSRDvsKCJKOUD+GzTS4Y0Y8pvE=
|
||||
github.com/hashicorp/yamux v0.1.1/go.mod h1:CtWFDAQgb7dxtzFs4tWbplKIe2jSi3+5vKbgIO0SLnQ=
|
||||
github.com/jessevdk/go-flags v1.4.0/go.mod h1:4FA24M0QyGHXBuZZK/XkWh8h0e1EYbRYJSGM75WSRxI=
|
||||
github.com/jhump/protoreflect v1.15.1 h1:HUMERORf3I3ZdX05WaQ6MIpd/NJ434hTp5YiKgfCL6c=
|
||||
github.com/jhump/protoreflect v1.15.1/go.mod h1:jD/2GMKKE6OqX8qTjhADU1e6DShO+gavG9e0Q693nKo=
|
||||
github.com/joshlf/go-acl v0.0.0-20200411065538-eae00ae38531 h1:hgVxRoDDPtQE68PT4LFvNlPz2nBKd3OMlGKIQ69OmR4=
|
||||
github.com/joshlf/go-acl v0.0.0-20200411065538-eae00ae38531/go.mod h1:fqTUQpVYBvhCNIsMXGl2GE9q6z94DIP6NtFKXCSTVbg=
|
||||
github.com/joshlf/testutil v0.0.0-20170608050642-b5d8aa79d93d h1:J8tJzRyiddAFF65YVgxli+TyWBi0f79Sld6rJP6CBcY=
|
||||
github.com/joshlf/testutil v0.0.0-20170608050642-b5d8aa79d93d/go.mod h1:b+Q3v8Yrg5o15d71PSUraUzYb+jWl6wQMSBXSGS/hv0=
|
||||
github.com/json-iterator/go v1.1.6/go.mod h1:+SdeFBvtyEkXs7REEP0seUULqWtbJapLOCVDaaPEHmU=
|
||||
github.com/json-iterator/go v1.1.9/go.mod h1:KdQUCv79m/52Kvf8AW2vK1V8akMuk1QjK/uOdHXbAo4=
|
||||
github.com/julienschmidt/httprouter v1.2.0/go.mod h1:SYymIcj16QtmaHHD7aYtjjsJG7VTCxuUUipMqKk8s4w=
|
||||
github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8=
|
||||
github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
|
||||
github.com/konsorten/go-windows-terminal-sequences v1.0.1/go.mod h1:T0+1ngSBFLxvqU3pZ+m/2kptfBszLMUkC4ZK/EgS/cQ=
|
||||
github.com/kr/logfmt v0.0.0-20140226030751-b84e30acd515/go.mod h1:+0opPa2QZZtGFBFZlji/RkVcI2GknAs/DXo4wKdlNEc=
|
||||
github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo=
|
||||
github.com/kr/pretty v0.3.1 h1:flRD4NNwYAUpkphVc1HcthR4KEIFJ65n8Mw5qdRn3LE=
|
||||
github.com/kr/pretty v0.3.1/go.mod h1:hoEshYVHaxMs3cyo3Yncou5ZscifuDolrwPKZanG3xk=
|
||||
github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ=
|
||||
github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI=
|
||||
github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY=
|
||||
github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE=
|
||||
github.com/mattn/go-colorable v0.1.9/go.mod h1:u6P/XSegPjTcexA+o6vUJrdnUu04hMope9wVRipJSqc=
|
||||
github.com/mattn/go-colorable v0.1.12/go.mod h1:u5H1YNBxpqRaxsYJYSkiCWKzEfiAb1Gb520KVy5xxl4=
|
||||
github.com/mattn/go-colorable v0.1.13 h1:fFA4WZxdEF4tXPZVKMLwD8oUnCTTo08duU7wxecdEvA=
|
||||
github.com/mattn/go-colorable v0.1.13/go.mod h1:7S9/ev0klgBDR4GtXTXX8a3vIGJpMovkB8vQcUbaXHg=
|
||||
github.com/mattn/go-isatty v0.0.12/go.mod h1:cbi8OIDigv2wuxKPP5vlRcQ1OAZbq2CE4Kysco4FUpU=
|
||||
github.com/mattn/go-isatty v0.0.14/go.mod h1:7GGIvUiUoEMVVmxf/4nioHXj79iQHKdU27kJ6hsGG94=
|
||||
github.com/mattn/go-isatty v0.0.16/go.mod h1:kYGgaQfpe5nmfYZH+SKPsOc2e4SrIfOl2e/yFXSvRLM=
|
||||
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
|
||||
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
|
||||
github.com/matttproud/golang_protobuf_extensions v1.0.1/go.mod h1:D8He9yQNgCq6Z5Ld7szi9bcBfOoFv/3dc6xSMkL2PC0=
|
||||
github.com/mitchellh/copystructure v1.2.0 h1:vpKXTN4ewci03Vljg/q9QvCGUDttBOGBIa15WveJJGw=
|
||||
github.com/mitchellh/copystructure v1.2.0/go.mod h1:qLl+cE2AmVv+CoeAwDPye/v+N2HKCj9FbZEVFJRxO9s=
|
||||
github.com/mitchellh/go-homedir v1.1.0 h1:lukF9ziXFxDFPkA1vsr5zpc1XuPDn/wFntq5mG+4E0Y=
|
||||
github.com/mitchellh/go-homedir v1.1.0/go.mod h1:SfyaCUpYCn1Vlf4IUYiD9fPX4A5wJrkLzIz1N1q0pr0=
|
||||
github.com/mitchellh/go-testing-interface v1.14.1 h1:jrgshOhYAUVNMAJiKbEu7EqAwgJJ2JqpQmpLJOu07cU=
|
||||
github.com/mitchellh/go-testing-interface v1.14.1/go.mod h1:gfgS7OtZj6MA4U1UrDRp04twqAjfvlZyCfX3sDjEym8=
|
||||
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
|
||||
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
|
||||
github.com/mitchellh/reflectwalk v1.0.2 h1:G2LzWKi524PWgd3mLHV8Y5k7s6XUvT0Gef6zxSIeXaQ=
|
||||
github.com/mitchellh/reflectwalk v1.0.2/go.mod h1:mSTlrgnPZtwu0c4WaC2kGObEpuNDbx0jmZXqmk4esnw=
|
||||
github.com/moby/docker-image-spec v1.3.1 h1:jMKff3w6PgbfSa69GfNg+zN/XLhfXJGnEx3Nl2EsFP0=
|
||||
github.com/moby/docker-image-spec v1.3.1/go.mod h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo=
|
||||
github.com/moby/term v0.5.0 h1:xt8Q1nalod/v7BqbG21f8mQPqH+xAaC9C3N3wfWbVP0=
|
||||
github.com/moby/term v0.5.0/go.mod h1:8FzsFHVUBGZdbDsJw/ot+X+d5HLUbvklYLJ9uGfcI3Y=
|
||||
github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
|
||||
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
|
||||
github.com/modern-go/reflect2 v0.0.0-20180701023420-4b7aa43c6742/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
|
||||
github.com/modern-go/reflect2 v1.0.1/go.mod h1:bx2lNnkwVCuqBIxFjflWJWanXIb3RllmbCylyMrvgv0=
|
||||
github.com/morikuni/aec v1.0.0 h1:nP9CBfwrvYnBRgY6qfDQkygYDmYwOilePFkwzv4dU8A=
|
||||
github.com/morikuni/aec v1.0.0/go.mod h1:BbKIizmSmc5MMPqRYbxO4ZU0S0+P200+tUnFx7PXmsc=
|
||||
github.com/mwitkow/go-conntrack v0.0.0-20161129095857-cc309e4a2223/go.mod h1:qRWi+5nqEBWmkhHvq77mSJWrCKwh8bxhgT7d/eI7P4U=
|
||||
github.com/oklog/run v1.1.0 h1:GEenZ1cK0+q0+wsJew9qUg/DyD8k3JzYsZAi5gYi2mA=
|
||||
github.com/oklog/run v1.1.0/go.mod h1:sVPdnTZT1zYwAJeCMu2Th4T21pA3FPOQRfWjQlk7DVU=
|
||||
github.com/opencontainers/go-digest v1.0.0 h1:apOUWs51W5PlhuyGyz9FCeeBIOUDA/6nW8Oi/yOhh5U=
|
||||
github.com/opencontainers/go-digest v1.0.0/go.mod h1:0JzlMkj0TRzQZfJkVvzbP0HBR3IKzErnv2BNG4W4MAM=
|
||||
github.com/opencontainers/image-spec v1.1.0-rc2.0.20221005185240-3a7f492d3f1b h1:YWuSjZCQAPM8UUBLkYUk1e+rZcvWHJmFb6i6rM44Xs8=
|
||||
github.com/opencontainers/image-spec v1.1.0-rc2.0.20221005185240-3a7f492d3f1b/go.mod h1:3OVijpioIKYWTqjiG0zfF6wvoJ4fAXGbjdZuI2NgsRQ=
|
||||
github.com/pascaldekloe/goe v0.1.0 h1:cBOtyMzM9HTpWjXfbbunk26uA6nG3a8n06Wieeh0MwY=
|
||||
github.com/pascaldekloe/goe v0.1.0/go.mod h1:lzWF7FIEvWOWxwDKqyGYQf6ZUaNfKdP144TG7ZOy1lc=
|
||||
github.com/petermattis/goid v0.0.0-20180202154549-b0b1615b78e5 h1:q2e307iGHPdTGp0hoxKjt1H5pDo6utceo3dQVK3I5XQ=
|
||||
github.com/petermattis/goid v0.0.0-20180202154549-b0b1615b78e5/go.mod h1:jvVRKCrJTQWu0XVbaOlby/2lO20uSCHEMzzplHXte1o=
|
||||
github.com/pierrec/lz4 v2.6.1+incompatible h1:9UY3+iC23yxF0UfGaYrGplQ+79Rg+h/q9FV9ix19jjM=
|
||||
github.com/pierrec/lz4 v2.6.1+incompatible/go.mod h1:pdkljMzZIN41W+lC3N2tnIh5sFi+IEE17M5jbnwPHcY=
|
||||
github.com/pkg/errors v0.8.0/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
github.com/pkg/errors v0.8.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
github.com/pkg/errors v0.9.1 h1:FEBLx1zS214owpjy7qsBeixbURkuhQAwrK5UwLGTwt4=
|
||||
github.com/pkg/errors v0.9.1/go.mod h1:bwawxfHBFNV+L2hUp1rHADufV3IMtnDRdf1r5NINEl0=
|
||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 h1:Jamvg5psRIccs7FGNTlIRMkT8wgtp5eCXdBlqhYGL6U=
|
||||
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||
github.com/prometheus/client_golang v0.9.1/go.mod h1:7SWBe2y4D6OKWSNQJUaRYU/AaXPKyh/dDVn+NZz0KFw=
|
||||
github.com/prometheus/client_golang v1.0.0/go.mod h1:db9x61etRT2tGnBNRi70OPL5FsnadC4Ky3P0J6CfImo=
|
||||
github.com/prometheus/client_golang v1.4.0/go.mod h1:e9GMxYsXl05ICDXkRhurwBS4Q3OK1iX/F2sw+iXX5zU=
|
||||
github.com/prometheus/client_model v0.0.0-20180712105110-5c3871d89910/go.mod h1:MbSGuTsp3dbXC40dX6PRTWyKYBIrTGTE9sqQNg2J8bo=
|
||||
github.com/prometheus/client_model v0.0.0-20190129233127-fd36f4220a90/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
|
||||
github.com/prometheus/client_model v0.2.0/go.mod h1:xMI15A0UPsDsEKsMN9yxemIoYk6Tm2C1GtYGdfGttqA=
|
||||
github.com/prometheus/common v0.4.1/go.mod h1:TNfzLD0ON7rHzMJeJkieUDPYmFC7Snx/y86RQel1bk4=
|
||||
github.com/prometheus/common v0.9.1/go.mod h1:yhUN8i9wzaXS3w1O07YhxHEBxD+W35wd8bs7vj7HSQ4=
|
||||
github.com/prometheus/procfs v0.0.0-20181005140218-185b4288413d/go.mod h1:c3At6R/oaqEKCNdg8wHV1ftS6bRYblBhIjjI8uT2IGk=
|
||||
github.com/prometheus/procfs v0.0.2/go.mod h1:TjEm7ze935MbeOT/UhFTIMYKhuLP4wbCsTZCD3I8kEA=
|
||||
github.com/prometheus/procfs v0.0.8/go.mod h1:7Qr8sr6344vo1JqZ6HhLceV9o3AJ1Ff+GxbHq6oeK9A=
|
||||
github.com/rogpeppe/go-internal v1.14.1 h1:UQB4HGPB6osV0SQTLymcB4TgvyWu6ZyliaW0tI/otEQ=
|
||||
github.com/rogpeppe/go-internal v1.14.1/go.mod h1:MaRKkUm5W0goXpeCfT7UZI6fk/L7L7so1lCWt35ZSgc=
|
||||
github.com/ryanuber/go-glob v1.0.0 h1:iQh3xXAumdQ+4Ufa5b25cRpC5TYKlno6hsv6Cb3pkBk=
|
||||
github.com/ryanuber/go-glob v1.0.0/go.mod h1:807d1WSdnB0XRJzKNil9Om6lcp/3a0v4qIHxIXzX/Yc=
|
||||
github.com/sasha-s/go-deadlock v0.2.0 h1:lMqc+fUb7RrFS3gQLtoQsJ7/6TV/pAIFvBsqX73DK8Y=
|
||||
github.com/sasha-s/go-deadlock v0.2.0/go.mod h1:StQn567HiB1fF2yJ44N9au7wOhrPS3iZqiDbRupzT10=
|
||||
github.com/sirupsen/logrus v1.2.0/go.mod h1:LxeOpSwHxABJmUn/MG1IvRgCAasNZTLOkJPxbbu5VWo=
|
||||
github.com/sirupsen/logrus v1.4.2/go.mod h1:tLMulIdttU9McNUspp0xgXVQah82FyeX6MwdIuYE2rE=
|
||||
github.com/sirupsen/logrus v1.9.3 h1:dueUQJ1C2q9oE3F7wvmSGAaVtTmUizReu6fjN8uqzbQ=
|
||||
github.com/sirupsen/logrus v1.9.3/go.mod h1:naHLuLoDiP4jHNo9R0sCBMtWGeIprob74mVsIT4qYEQ=
|
||||
github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||
github.com/stretchr/objx v0.1.1/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME=
|
||||
github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY=
|
||||
github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
|
||||
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
||||
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
|
||||
github.com/stretchr/testify v1.4.0/go.mod h1:j7eGeouHqKxXV5pUuKE4zz7dFj8WfuZ+81PSLYec5m4=
|
||||
github.com/stretchr/testify v1.7.2/go.mod h1:R6va5+xMeoiuVRoj+gSkQ7d3FALtqAAGI1FQKckRals=
|
||||
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
|
||||
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
|
||||
github.com/tv42/httpunix v0.0.0-20150427012821-b75d8614f926/go.mod h1:9ESjWnEqriFuLhtthL60Sar/7RFoluCcXsuvEwTV5KM=
|
||||
github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||
github.com/yuin/goldmark v1.2.1/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
|
||||
go.opentelemetry.io/auto/sdk v1.2.1 h1:jXsnJ4Lmnqd11kwkBV2LgLoFMZKizbCi5fNZ/ipaZ64=
|
||||
go.opentelemetry.io/auto/sdk v1.2.1/go.mod h1:KRTj+aOaElaLi+wW1kO/DZRXwkF4C5xPbEe3ZiIhN7Y=
|
||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.51.0 h1:Xs2Ncz0gNihqu9iosIZ5SkBbWo5T8JhhLJFMQL1qmLI=
|
||||
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.51.0/go.mod h1:vy+2G/6NvVMpwGX/NyLqcC41fxepnuKHk16E6IZUcJc=
|
||||
go.opentelemetry.io/otel v1.44.0 h1:JjwHmHpA4iZ3wBxluu2fbbE7j4kqlE8jXyAyPXH7HqU=
|
||||
go.opentelemetry.io/otel v1.44.0/go.mod h1:BMgjTHL9WPRlRjL2oZCBTL4whCGtXch2H4BhOPIAyYc=
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0 h1:4YsVu3B8+3qtWYYrsUYgn0OG78pN0rnNPRGX4SbokQI=
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.44.0/go.mod h1:+wnlSn0mD1ADVMe3v9Z/WIaiz6q6gL2J/ejaAmdmv80=
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.28.0 h1:j9+03ymgYhPKmeXGk5Zu+cIZOlVzd9Zv7QIiyItjFBU=
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.28.0/go.mod h1:Y5+XiUG4Emn1hTfciPzGPJaSI+RpDts6BnCIir0SLqk=
|
||||
go.opentelemetry.io/otel/metric v1.44.0 h1:1w0gILTcHdr3YI+ixLyjemwrVnsMURbTZFrSYCdDdmc=
|
||||
go.opentelemetry.io/otel/metric v1.44.0/go.mod h1:8O7hanEPBNgEMmybD3s2VBKcgWOCsA6tzHBPODAiquo=
|
||||
go.opentelemetry.io/otel/sdk v1.44.0 h1:nHYwb9lK+fJPU/dnT6s7W7Z8itMWyqrnVfbheVYrZ58=
|
||||
go.opentelemetry.io/otel/sdk v1.44.0/go.mod h1:Osuydd3Se74nqjAKxid74N5eC+jfEqfTegHRnq58oK0=
|
||||
go.opentelemetry.io/otel/sdk/metric v1.44.0 h1:3LlKgI+VjbVsjNRFZJZAJ30WjXC5VkNRks6si09iEfI=
|
||||
go.opentelemetry.io/otel/sdk/metric v1.44.0/go.mod h1:5B5pMARnXxKhltooO4xUuCBorl65a4EpnTalObqOigA=
|
||||
go.opentelemetry.io/otel/trace v1.44.0 h1:jxF5CsGYCe74MCRx2X4g7WsY/VBKRqqpNvXlX/6gtIk=
|
||||
go.opentelemetry.io/otel/trace v1.44.0/go.mod h1:oLl1jrMQAVo6v3GAggN+1VH9VIz9iUSvW53sW1Q8PIE=
|
||||
go.opentelemetry.io/proto/otlp v1.11.0 h1:5rrYs0Ykyj50sdU/JU0x8etU+LubXWb+gED6TbEdMIk=
|
||||
go.opentelemetry.io/proto/otlp v1.11.0/go.mod h1:SmVizdCOAm3XBtG1g1NnOdhW6jtddT72hLMhv8VwA8E=
|
||||
go.uber.org/atomic v1.9.0 h1:ECmE8Bn/WFTYwEW/bpKD3M8VtR/zQVbavAoalC1PYyE=
|
||||
go.uber.org/atomic v1.9.0/go.mod h1:fEN4uk6kAWBTFdckzkM89CLk9XfWZrxpCo0nPH17wJc=
|
||||
golang.org/x/crypto v0.0.0-20180904163835-0709b304e793/go.mod h1:6SG95UA2DQfeDnfUPMdvaQW0Q7yPrPDi9nlGo2tz2b4=
|
||||
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
|
||||
golang.org/x/crypto v0.0.0-20191011191535-87dc89f01550/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
|
||||
golang.org/x/crypto v0.0.0-20200622213623-75b288015ac9/go.mod h1:LzIPMQfyMNhhGPhUkYOs5KpL4U8rLKemX1yGLhDgUto=
|
||||
golang.org/x/crypto v0.54.0 h1:YLIA59K4fiNzHzjnZt2tUJQjQtUWfWbeHBqKtk3eScw=
|
||||
golang.org/x/crypto v0.54.0/go.mod h1:KWL8ny2AZdGR2cWmzeHrp2azQPGogOv+HeQaVEXC2dk=
|
||||
golang.org/x/mod v0.2.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||
golang.org/x/mod v0.3.0/go.mod h1:s0Qsj1ACt9ePp/hMypM3fl4fZqREWJwdYDEqhRiZZUA=
|
||||
golang.org/x/mod v0.37.0 h1:vF1DjpVEshcIqoEaauuHebaLk1O1forxjxBaVn884JQ=
|
||||
golang.org/x/mod v0.37.0/go.mod h1:m8S8VeM9r4dzDwjrKO0a1sZP3YjeMamRRlD+fmR2Q/0=
|
||||
golang.org/x/net v0.0.0-20181114220301-adae6a3d119a/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
|
||||
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
|
||||
golang.org/x/net v0.0.0-20190613194153-d28f0bde5980/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||
golang.org/x/net v0.0.0-20190620200207-3b0461eec859/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||
golang.org/x/net v0.0.0-20200226121028-0de0cce0169b/go.mod h1:z5CRVTTTmAJ677TzLLGU+0bjPO0LkuOLi4/5GtJWs/s=
|
||||
golang.org/x/net v0.0.0-20201021035429-f5854403a974/go.mod h1:sp8m0HH+o8qH0wwXwYZr8TS3Oi6o0r6Gce1SSxlDquU=
|
||||
golang.org/x/net v0.57.0 h1:K5+3DljvIuDG9/Jv9rvyMywYNFCQ9RSUY6OOTTkT+tE=
|
||||
golang.org/x/net v0.57.0/go.mod h1:KpXc8iv+r3XplLAG/f7Jsf9RPszJzdR0f58q9vGOuEU=
|
||||
golang.org/x/sync v0.0.0-20181108010431-42b317875d0f/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20181221193216-37e7f081c4d4/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20190423024810-112230192c58/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20190911185100-cd5d95a43a6e/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.0.0-20201020160332-67f06af15bc9/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
|
||||
golang.org/x/sync v0.22.0 h1:SZjpbeLmrCk4xhRSZFNZW5gFUeCeFgjekvI/+gfScek=
|
||||
golang.org/x/sync v0.22.0/go.mod h1:9xrNwdLfx4jkKbNva9FpL6vEN7evnE43NNNJQ2LF3+0=
|
||||
golang.org/x/sys v0.0.0-20180905080454-ebe1bf3edb33/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20181116152217-5ac8a444bdc5/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
|
||||
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20190422165155-953cdadca894/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20200116001909-b77594299b42/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20200122134326-e047566fdf82/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20200223170610-d5e6a3e2c0ae/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20200930185726-fdedc70b468f/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
|
||||
golang.org/x/sys v0.0.0-20210630005230-0f9fa26af87c/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20210927094055-39ccf1dd6fa6/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20220503163025-988cb79eb6c6/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
|
||||
golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
|
||||
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
|
||||
golang.org/x/text v0.3.3/go.mod h1:5Zoc/QRtKVWzQhOtBMvqHzDpF6irO9z98xDceosuGiQ=
|
||||
golang.org/x/text v0.40.0 h1:Ub2Z6/xjgF1WrYQz2nuITOEegKFtiIy+rieRJ5lHZKs=
|
||||
golang.org/x/text v0.40.0/go.mod h1:hpnzDAfGV753zIKo+wk3u1bVKCGPbrnF7+7LBF/UHVY=
|
||||
golang.org/x/time v0.5.0 h1:o7cqy6amK/52YcAKIPlM3a+Fpj35zvRj2TP+e1xFSfk=
|
||||
golang.org/x/time v0.5.0/go.mod h1:3BpzKBy/shNhVucY/MWOyx10tF3SFh9QdLuxbVysPQM=
|
||||
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
|
||||
golang.org/x/tools v0.0.0-20191119224855-298f0cb1881e/go.mod h1:b+2E5dAYhXwXZwtnZ6UAqBI28+e2cm9otk0dWdXHAEo=
|
||||
golang.org/x/tools v0.0.0-20200619180055-7c47624df98f/go.mod h1:EkVYQZoAsY45+roYkvgYkIh4xh/qjgUK9TdY2XT94GE=
|
||||
golang.org/x/tools v0.0.0-20210106214847-113979e3529a/go.mod h1:emZCQorbCU4vsT4fOWvOPXz4eW1wZW4PmDk9uLelYpA=
|
||||
golang.org/x/tools v0.47.0 h1:7Kn5x/d1svx/PzryTsqeoZN4TZwqeH5pGWjefhLi/1Q=
|
||||
golang.org/x/tools v0.47.0/go.mod h1:dFHnyTvFWY212G+h7ZY4Vsp/K3U4/7W9TyVaAul8uCA=
|
||||
golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
|
||||
gonum.org/v1/gonum v0.17.0 h1:VbpOemQlsSMrYmn7T2OUvQ4dqxQXU+ouZFQsZOx50z4=
|
||||
gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E=
|
||||
google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a h1:97PfJ4tCxY5C7NzzgGqQEMZmXbISdvSArNNEOoUGKBg=
|
||||
google.golang.org/genproto/googleapis/api v0.0.0-20260720211330-0afa2a65878a/go.mod h1:1brfde68Npq6+WA75c1EHWPijZEG1kMus61ygPZfn4A=
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a h1:qI/YMH1ep2qQtqcp00gMQyoU7mjvbhg88GJKCvfoLj0=
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20260720211330-0afa2a65878a/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
|
||||
google.golang.org/grpc v1.82.1 h1:NnAxzGRA0677vCa4BUkOAnO5+FfQqVl9iUXeD0IqcGE=
|
||||
google.golang.org/grpc v1.82.1/go.mod h1:yzTZ1TB1Z3SG+LIYaI+WiE8D5+PZ3ArnrSp8zF3+/ZA=
|
||||
google.golang.org/protobuf v1.36.11 h1:fV6ZwhNocDyBLK0dj+fg8ektcVegBBuEolpbTQyBNVE=
|
||||
google.golang.org/protobuf v1.36.11/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
|
||||
gopkg.in/alecthomas/kingpin.v2 v2.2.6/go.mod h1:FMv+mEhP44yOT+4EoQTLFTRgOQ1FBLkstjWtayDeSgw=
|
||||
gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||
gopkg.in/check.v1 v1.0.0-20190902080502-41f04d3bba15/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
|
||||
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk=
|
||||
gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q=
|
||||
gopkg.in/yaml.v2 v2.2.1/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
||||
gopkg.in/yaml.v2 v2.2.2/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
||||
gopkg.in/yaml.v2 v2.2.4/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
||||
gopkg.in/yaml.v2 v2.2.5/go.mod h1:hI93XBmqTisBFMUTm0b8Fm+jr3Dg1NNxqwp+5A1VGuI=
|
||||
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
||||
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||
gotest.tools/v3 v3.5.0 h1:Ljk6PdHdOhAb5aDMWXjDLMMhph+BpztA4v1QdqEW2eY=
|
||||
gotest.tools/v3 v3.5.0/go.mod h1:isy3WKz7GK6uNw/sbHzfKBLvlvXwUyV06n6brMxxopU=
|
||||
@@ -0,0 +1,35 @@
|
||||
---
|
||||
# nfpm config for the vault-plugin-secrets-ghp RPM. Rendered through envsubst
|
||||
# (see scripts/build-rpm.sh) then fed to `nfpm pkg`. Built once per target server
|
||||
# (Vault, OpenBao); PACKAGE_NAME and PACKAGE_PLUGIN_DIR vary.
|
||||
|
||||
name: ${PACKAGE_NAME}
|
||||
version: ${PACKAGE_VERSION}
|
||||
release: ${PACKAGE_RELEASE}
|
||||
arch: ${PACKAGE_ARCH}
|
||||
platform: ${PACKAGE_PLATFORM}
|
||||
section: default
|
||||
priority: extra
|
||||
description: "${PACKAGE_DESCRIPTION}"
|
||||
|
||||
maintainer: ${PACKAGE_MAINTAINER}
|
||||
homepage: ${PACKAGE_HOMEPAGE}
|
||||
license: ${PACKAGE_LICENSE}
|
||||
|
||||
disable_globbing: false
|
||||
|
||||
replaces:
|
||||
- ${PACKAGE_NAME}
|
||||
provides:
|
||||
- ${PACKAGE_NAME}
|
||||
|
||||
contents:
|
||||
- src: dist/vault-plugin-secrets-ghp
|
||||
dst: ${PACKAGE_PLUGIN_DIR}/vault-plugin-secrets-ghp
|
||||
file_info:
|
||||
mode: 0755
|
||||
owner: root
|
||||
group: root
|
||||
|
||||
scripts:
|
||||
preinstall: ${PACKAGE_PREINSTALL}
|
||||
Executable
+4
@@ -0,0 +1,4 @@
|
||||
#!/usr/bin/env bash
|
||||
# Ensure the plugin directory exists before the binary is laid down.
|
||||
# Rendered per flavour via envsubst (see scripts/build-rpm.sh).
|
||||
mkdir -p ${PACKAGE_PLUGIN_DIR}
|
||||
+177
@@ -0,0 +1,177 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
|
||||
"github.com/hashicorp/vault/sdk/framework"
|
||||
"github.com/hashicorp/vault/sdk/logical"
|
||||
)
|
||||
|
||||
const configStoragePath = "config"
|
||||
|
||||
const defaultBaseURL = "https://ghp.unkin.net"
|
||||
|
||||
// ghpConfig is the connection to ghp plus the seeded service token the engine
|
||||
// authenticates with to mint and revoke tokens.
|
||||
type ghpConfig struct {
|
||||
BaseURL string `json:"base_url"`
|
||||
AdminToken string `json:"admin_token"`
|
||||
CACert string `json:"ca_cert"`
|
||||
TLSSkipVerify bool `json:"tls_skip_verify"`
|
||||
RequestTimeoutSeconds int `json:"request_timeout_seconds"`
|
||||
}
|
||||
|
||||
func pathConfig(b *ghpBackend) *framework.Path {
|
||||
return &framework.Path{
|
||||
Pattern: "config",
|
||||
DisplayAttrs: &framework.DisplayAttributes{
|
||||
OperationPrefix: "ghp",
|
||||
OperationSuffix: "config",
|
||||
},
|
||||
Fields: map[string]*framework.FieldSchema{
|
||||
"base_url": {
|
||||
Type: framework.TypeString,
|
||||
Description: "Base URL of the ghp server (default https://ghp.unkin.net).",
|
||||
Default: defaultBaseURL,
|
||||
},
|
||||
"admin_token": {
|
||||
Type: framework.TypeString,
|
||||
Description: "ghp service token (ghpsvc_...) sent as a bearer credential; ghp treats it as a synthetic admin. Write-only, never returned.",
|
||||
DisplayAttrs: &framework.DisplayAttributes{
|
||||
Name: "Admin Token",
|
||||
Sensitive: true,
|
||||
},
|
||||
},
|
||||
"ca_cert": {
|
||||
Type: framework.TypeString,
|
||||
Description: "PEM CA certificate that signed the ghp server's TLS certificate.",
|
||||
},
|
||||
"tls_skip_verify": {
|
||||
Type: framework.TypeBool,
|
||||
Description: "Skip TLS verification of the ghp server (not recommended).",
|
||||
Default: false,
|
||||
},
|
||||
"request_timeout_seconds": {
|
||||
Type: framework.TypeInt,
|
||||
Description: "HTTP timeout in seconds for calls to ghp (default 30).",
|
||||
Default: 30,
|
||||
},
|
||||
},
|
||||
Operations: map[logical.Operation]framework.OperationHandler{
|
||||
logical.ReadOperation: &framework.PathOperation{Callback: b.pathConfigRead},
|
||||
logical.CreateOperation: &framework.PathOperation{Callback: b.pathConfigWrite},
|
||||
logical.UpdateOperation: &framework.PathOperation{Callback: b.pathConfigWrite},
|
||||
logical.DeleteOperation: &framework.PathOperation{Callback: b.pathConfigDelete},
|
||||
},
|
||||
ExistenceCheck: b.pathConfigExistenceCheck,
|
||||
HelpSynopsis: "Configure the connection to ghp and the seeded service token.",
|
||||
HelpDescription: "Configure the ghp URL, TLS settings, and the service token the engine authenticates with. Roles then mint scoped tokens with this credential.",
|
||||
}
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathConfigExistenceCheck(ctx context.Context, req *logical.Request, _ *framework.FieldData) (bool, error) {
|
||||
config, err := getConfig(ctx, req.Storage)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
return config != nil, nil
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathConfigRead(ctx context.Context, req *logical.Request, _ *framework.FieldData) (*logical.Response, error) {
|
||||
config, err := getConfig(ctx, req.Storage)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if config == nil {
|
||||
return nil, nil
|
||||
}
|
||||
// admin_token is deliberately never returned.
|
||||
return &logical.Response{
|
||||
Data: map[string]interface{}{
|
||||
"base_url": config.BaseURL,
|
||||
"tls_skip_verify": config.TLSSkipVerify,
|
||||
"request_timeout_seconds": config.RequestTimeoutSeconds,
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathConfigWrite(ctx context.Context, req *logical.Request, data *framework.FieldData) (*logical.Response, error) {
|
||||
config, err := getConfig(ctx, req.Storage)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if config == nil {
|
||||
if req.Operation == logical.UpdateOperation {
|
||||
return nil, errors.New("config not found during update operation")
|
||||
}
|
||||
config = &ghpConfig{}
|
||||
}
|
||||
|
||||
if v, ok := data.GetOk("base_url"); ok {
|
||||
config.BaseURL = v.(string)
|
||||
} else if config.BaseURL == "" {
|
||||
config.BaseURL = defaultBaseURL
|
||||
}
|
||||
if v, ok := data.GetOk("admin_token"); ok {
|
||||
config.AdminToken = v.(string)
|
||||
}
|
||||
if v, ok := data.GetOk("ca_cert"); ok {
|
||||
config.CACert = v.(string)
|
||||
}
|
||||
if v, ok := data.GetOk("tls_skip_verify"); ok {
|
||||
config.TLSSkipVerify = v.(bool)
|
||||
}
|
||||
if v, ok := data.GetOk("request_timeout_seconds"); ok {
|
||||
config.RequestTimeoutSeconds = v.(int)
|
||||
} else if req.Operation == logical.CreateOperation {
|
||||
config.RequestTimeoutSeconds = data.Get("request_timeout_seconds").(int)
|
||||
}
|
||||
|
||||
if config.BaseURL == "" {
|
||||
return logical.ErrorResponse("base_url is required"), nil
|
||||
}
|
||||
if config.AdminToken == "" {
|
||||
return logical.ErrorResponse("admin_token is required"), nil
|
||||
}
|
||||
|
||||
// Verify the seeded token authenticates as a ghp admin before storing it, so
|
||||
// misconfiguration fails fast rather than at first mint.
|
||||
client, err := newClient(config)
|
||||
if err != nil {
|
||||
return logical.ErrorResponse(err.Error()), nil
|
||||
}
|
||||
if err := client.VerifyAdmin(ctx); err != nil {
|
||||
return logical.ErrorResponse("verifying ghp admin_token: %s", err), nil
|
||||
}
|
||||
|
||||
return nil, setJSON(ctx, req.Storage, configStoragePath, config)
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathConfigDelete(ctx context.Context, req *logical.Request, _ *framework.FieldData) (*logical.Response, error) {
|
||||
return nil, req.Storage.Delete(ctx, configStoragePath)
|
||||
}
|
||||
|
||||
func getConfig(ctx context.Context, s logical.Storage) (*ghpConfig, error) {
|
||||
entry, err := s.Get(ctx, configStoragePath)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if entry == nil {
|
||||
return nil, nil
|
||||
}
|
||||
config := &ghpConfig{}
|
||||
if err := entry.DecodeJSON(config); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return config, nil
|
||||
}
|
||||
|
||||
// setJSON stores a value as a JSON storage entry.
|
||||
func setJSON(ctx context.Context, s logical.Storage, key string, value interface{}) error {
|
||||
entry, err := logical.StorageEntryJSON(key, value)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
return s.Put(ctx, entry)
|
||||
}
|
||||
+123
@@ -0,0 +1,123 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"time"
|
||||
|
||||
"github.com/hashicorp/go-uuid"
|
||||
"github.com/hashicorp/vault/sdk/framework"
|
||||
"github.com/hashicorp/vault/sdk/logical"
|
||||
)
|
||||
|
||||
func pathCredentials(b *ghpBackend) *framework.Path {
|
||||
return &framework.Path{
|
||||
Pattern: "creds/" + framework.GenericNameRegex("name"),
|
||||
DisplayAttrs: &framework.DisplayAttributes{
|
||||
OperationPrefix: "ghp",
|
||||
OperationSuffix: "credentials",
|
||||
},
|
||||
Fields: map[string]*framework.FieldSchema{
|
||||
"name": {
|
||||
Type: framework.TypeLowerCaseString,
|
||||
Description: "Name of the role to mint a token for.",
|
||||
Required: true,
|
||||
},
|
||||
},
|
||||
Operations: map[logical.Operation]framework.OperationHandler{
|
||||
logical.ReadOperation: &framework.PathOperation{Callback: b.pathCredentialsRead},
|
||||
logical.UpdateOperation: &framework.PathOperation{Callback: b.pathCredentialsRead},
|
||||
},
|
||||
HelpSynopsis: "Mint a short-lived ghp token from a role.",
|
||||
HelpDescription: "Reading this path mints a new, lease-bound ghp token for the role; the token is deleted from ghp when the lease is revoked.",
|
||||
}
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathCredentialsRead(ctx context.Context, req *logical.Request, data *framework.FieldData) (*logical.Response, error) {
|
||||
roleName := data.Get("name").(string)
|
||||
|
||||
role, err := b.getRole(ctx, req.Storage, roleName)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if role == nil {
|
||||
return logical.ErrorResponse("role %q does not exist", roleName), nil
|
||||
}
|
||||
|
||||
config, err := getConfig(ctx, req.Storage)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if config == nil {
|
||||
return nil, errBackendNotConfigured
|
||||
}
|
||||
|
||||
client, err := newClient(config)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
ttl, maxTTL := b.resolveTTLs(role.TTL, role.MaxTTL)
|
||||
|
||||
suffix, err := uuid.GenerateUUID()
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("generating session id suffix: %w", err)
|
||||
}
|
||||
sessionID := fmt.Sprintf("%s-%s-%s", role.sessionPrefix(), roleName, suffix[:8])
|
||||
|
||||
createReq := createTokenRequest{
|
||||
Type: role.tokenType(),
|
||||
Repositories: role.Repositories,
|
||||
Scopes: scopeString(role.Scopes),
|
||||
// Bound the ghp-side expiry to the lease ceiling so the token self-expires
|
||||
// even if lease revocation never reaches ghp; the lease remains primary.
|
||||
Duration: maxTTL.String(),
|
||||
SessionID: sessionID,
|
||||
}
|
||||
if role.tokenType() == tokenTypeAgent {
|
||||
createReq.InstallationID = role.InstallationID
|
||||
createReq.AppRecordID = role.AppRecordID
|
||||
}
|
||||
|
||||
out, err := client.CreateToken(ctx, createReq)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("minting ghp token: %w", err)
|
||||
}
|
||||
|
||||
internal := map[string]interface{}{
|
||||
"token_id": out.ID,
|
||||
}
|
||||
external := map[string]interface{}{
|
||||
"token": out.Token,
|
||||
"token_id": out.ID,
|
||||
"token_type": out.Type,
|
||||
"repositories": out.Repositories,
|
||||
"scopes": out.Scopes,
|
||||
"expires_at": out.ExpiresAt,
|
||||
"session_id": out.SessionID,
|
||||
"base_url": config.BaseURL,
|
||||
}
|
||||
|
||||
resp := b.Secret(ghpTokenType).Response(external, internal)
|
||||
resp.Secret.TTL = ttl
|
||||
resp.Secret.MaxTTL = maxTTL
|
||||
resp.Secret.Renewable = true
|
||||
return resp, nil
|
||||
}
|
||||
|
||||
// resolveTTLs clamps a role's TTL/MaxTTL against the mount and system limits.
|
||||
func (b *ghpBackend) resolveTTLs(roleTTL, roleMaxTTL time.Duration) (ttl, maxTTL time.Duration) {
|
||||
sysMaxTTL := b.System().MaxLeaseTTL()
|
||||
maxTTL = roleMaxTTL
|
||||
if maxTTL <= 0 || maxTTL > sysMaxTTL {
|
||||
maxTTL = sysMaxTTL
|
||||
}
|
||||
ttl = roleTTL
|
||||
if ttl <= 0 {
|
||||
ttl = b.System().DefaultLeaseTTL()
|
||||
}
|
||||
if ttl > maxTTL {
|
||||
ttl = maxTTL
|
||||
}
|
||||
return ttl, maxTTL
|
||||
}
|
||||
+249
@@ -0,0 +1,249 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"time"
|
||||
|
||||
"github.com/hashicorp/vault/sdk/framework"
|
||||
"github.com/hashicorp/vault/sdk/logical"
|
||||
)
|
||||
|
||||
const roleStoragePrefix = "role/"
|
||||
|
||||
const (
|
||||
tokenTypeAgent = "agent"
|
||||
tokenTypeProxy = "proxy"
|
||||
)
|
||||
|
||||
// defaultSessionPrefix labels each minted token's ghp session id so leaked or
|
||||
// orphaned tokens are recognisable in ghp's UI/audit log.
|
||||
const defaultSessionPrefix = "vault"
|
||||
|
||||
// ghpRole binds a ghp token type, App installation and scope set to a TTL
|
||||
// policy. Each read of creds/<name> mints a unique, lease-bound token for it.
|
||||
type ghpRole struct {
|
||||
// TokenType is "agent" (default) or "proxy". Agent tokens are backed by a
|
||||
// ghp App installation and are the natural fit for a service credential.
|
||||
TokenType string `json:"token_type"`
|
||||
// InstallationID is the ghp/GitHub App installation id (required for agent
|
||||
// tokens; ghp rejects agent tokens without one).
|
||||
InstallationID int64 `json:"installation_id"`
|
||||
// AppRecordID optionally pins an agent token to a specific ghp App record
|
||||
// (UUID); empty selects ghp's default/only app.
|
||||
AppRecordID string `json:"app_record_id"`
|
||||
// Repositories optionally restricts the token to named repositories; empty
|
||||
// is open-scoped (all repositories in the installation).
|
||||
Repositories []string `json:"repositories"`
|
||||
// Scopes are ghp permission:level entries; empty is open-scoped.
|
||||
Scopes []string `json:"scopes"`
|
||||
// SessionPrefix prefixes each minted token's ghp session id.
|
||||
SessionPrefix string `json:"session_prefix"`
|
||||
TTL time.Duration `json:"ttl"`
|
||||
MaxTTL time.Duration `json:"max_ttl"`
|
||||
}
|
||||
|
||||
func (r *ghpRole) sessionPrefix() string {
|
||||
if r.SessionPrefix != "" {
|
||||
return r.SessionPrefix
|
||||
}
|
||||
return defaultSessionPrefix
|
||||
}
|
||||
|
||||
func (r *ghpRole) tokenType() string {
|
||||
if r.TokenType != "" {
|
||||
return r.TokenType
|
||||
}
|
||||
return tokenTypeAgent
|
||||
}
|
||||
|
||||
func pathRole(b *ghpBackend) *framework.Path {
|
||||
return &framework.Path{
|
||||
Pattern: "roles/" + framework.GenericNameRegex("name"),
|
||||
DisplayAttrs: &framework.DisplayAttributes{
|
||||
OperationPrefix: "ghp",
|
||||
OperationSuffix: "role",
|
||||
},
|
||||
Fields: map[string]*framework.FieldSchema{
|
||||
"name": {
|
||||
Type: framework.TypeLowerCaseString,
|
||||
Description: "Name of the role.",
|
||||
Required: true,
|
||||
},
|
||||
"token_type": {
|
||||
Type: framework.TypeString,
|
||||
Description: "ghp token type to mint: \"agent\" (default) or \"proxy\".",
|
||||
Default: tokenTypeAgent,
|
||||
},
|
||||
"installation_id": {
|
||||
Type: framework.TypeInt64,
|
||||
Description: "ghp App installation id the minted agent token is bound to (required for agent tokens).",
|
||||
},
|
||||
"app_record_id": {
|
||||
Type: framework.TypeString,
|
||||
Description: "Optional ghp App record id (UUID) to pin agent tokens to; empty selects ghp's default app.",
|
||||
},
|
||||
"repositories": {
|
||||
Type: framework.TypeCommaStringSlice,
|
||||
Description: "Optional repositories the token is restricted to; empty is open-scoped (all repositories).",
|
||||
},
|
||||
"scopes": {
|
||||
Type: framework.TypeCommaStringSlice,
|
||||
Description: "Optional ghp permission:level scopes (e.g. contents:read,pull_requests:write); empty is open-scoped.",
|
||||
},
|
||||
"session_prefix": {
|
||||
Type: framework.TypeString,
|
||||
Description: "Prefix for the ghp session id of each minted token (default \"vault\").",
|
||||
Default: defaultSessionPrefix,
|
||||
},
|
||||
"ttl": {
|
||||
Type: framework.TypeDurationSecond,
|
||||
Description: "Default lease TTL for tokens minted from this role.",
|
||||
},
|
||||
"max_ttl": {
|
||||
Type: framework.TypeDurationSecond,
|
||||
Description: "Maximum lease TTL for tokens minted from this role.",
|
||||
},
|
||||
},
|
||||
Operations: map[logical.Operation]framework.OperationHandler{
|
||||
logical.ReadOperation: &framework.PathOperation{Callback: b.pathRoleRead},
|
||||
logical.CreateOperation: &framework.PathOperation{Callback: b.pathRoleWrite},
|
||||
logical.UpdateOperation: &framework.PathOperation{Callback: b.pathRoleWrite},
|
||||
logical.DeleteOperation: &framework.PathOperation{Callback: b.pathRoleDelete},
|
||||
},
|
||||
ExistenceCheck: b.pathRoleExistenceCheck,
|
||||
HelpSynopsis: "Manage roles that mint short-lived ghp tokens.",
|
||||
HelpDescription: "Each read of creds/<name> mints a unique, lease-bound ghp token for the role's installation with the role's scopes.",
|
||||
}
|
||||
}
|
||||
|
||||
func pathRolesList(b *ghpBackend) *framework.Path {
|
||||
return &framework.Path{
|
||||
Pattern: "roles/?$",
|
||||
DisplayAttrs: &framework.DisplayAttributes{
|
||||
OperationPrefix: "ghp",
|
||||
OperationSuffix: "roles",
|
||||
},
|
||||
Operations: map[logical.Operation]framework.OperationHandler{
|
||||
logical.ListOperation: &framework.PathOperation{Callback: b.pathRolesList},
|
||||
},
|
||||
HelpSynopsis: "List roles.",
|
||||
HelpDescription: "List the token-minting roles configured on this backend.",
|
||||
}
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathRoleExistenceCheck(ctx context.Context, req *logical.Request, data *framework.FieldData) (bool, error) {
|
||||
role, err := b.getRole(ctx, req.Storage, data.Get("name").(string))
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
return role != nil, nil
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathRoleRead(ctx context.Context, req *logical.Request, data *framework.FieldData) (*logical.Response, error) {
|
||||
role, err := b.getRole(ctx, req.Storage, data.Get("name").(string))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if role == nil {
|
||||
return nil, nil
|
||||
}
|
||||
return &logical.Response{
|
||||
Data: map[string]interface{}{
|
||||
"token_type": role.tokenType(),
|
||||
"installation_id": role.InstallationID,
|
||||
"app_record_id": role.AppRecordID,
|
||||
"repositories": role.Repositories,
|
||||
"scopes": role.Scopes,
|
||||
"session_prefix": role.sessionPrefix(),
|
||||
"ttl": int64(role.TTL.Seconds()),
|
||||
"max_ttl": int64(role.MaxTTL.Seconds()),
|
||||
},
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathRoleWrite(ctx context.Context, req *logical.Request, data *framework.FieldData) (*logical.Response, error) {
|
||||
name := data.Get("name").(string)
|
||||
role, err := b.getRole(ctx, req.Storage, name)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if role == nil {
|
||||
role = &ghpRole{}
|
||||
}
|
||||
|
||||
if v, ok := data.GetOk("token_type"); ok {
|
||||
role.TokenType = v.(string)
|
||||
}
|
||||
if v, ok := data.GetOk("installation_id"); ok {
|
||||
role.InstallationID = v.(int64)
|
||||
}
|
||||
if v, ok := data.GetOk("app_record_id"); ok {
|
||||
role.AppRecordID = v.(string)
|
||||
}
|
||||
if v, ok := data.GetOk("repositories"); ok {
|
||||
role.Repositories = v.([]string)
|
||||
}
|
||||
if v, ok := data.GetOk("scopes"); ok {
|
||||
scopes, serr := normalizeScopes(v.([]string))
|
||||
if serr != nil {
|
||||
return logical.ErrorResponse(serr.Error()), nil
|
||||
}
|
||||
role.Scopes = scopes
|
||||
}
|
||||
if v, ok := data.GetOk("session_prefix"); ok {
|
||||
role.SessionPrefix = v.(string)
|
||||
}
|
||||
if v, ok := data.GetOk("ttl"); ok {
|
||||
role.TTL = time.Duration(v.(int)) * time.Second
|
||||
}
|
||||
if v, ok := data.GetOk("max_ttl"); ok {
|
||||
role.MaxTTL = time.Duration(v.(int)) * time.Second
|
||||
}
|
||||
|
||||
switch role.tokenType() {
|
||||
case tokenTypeAgent:
|
||||
if role.InstallationID == 0 {
|
||||
return logical.ErrorResponse("installation_id is required for agent tokens"), nil
|
||||
}
|
||||
case tokenTypeProxy:
|
||||
// proxy tokens are OAuth-backed; installation_id/app_record_id do not apply.
|
||||
default:
|
||||
return logical.ErrorResponse("token_type must be %q or %q", tokenTypeAgent, tokenTypeProxy), nil
|
||||
}
|
||||
if role.MaxTTL > 0 && role.TTL > role.MaxTTL {
|
||||
return logical.ErrorResponse("ttl must not exceed max_ttl"), nil
|
||||
}
|
||||
|
||||
return nil, setJSON(ctx, req.Storage, roleStoragePrefix+name, role)
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathRoleDelete(ctx context.Context, req *logical.Request, data *framework.FieldData) (*logical.Response, error) {
|
||||
return nil, req.Storage.Delete(ctx, roleStoragePrefix+data.Get("name").(string))
|
||||
}
|
||||
|
||||
func (b *ghpBackend) pathRolesList(ctx context.Context, req *logical.Request, _ *framework.FieldData) (*logical.Response, error) {
|
||||
entries, err := req.Storage.List(ctx, roleStoragePrefix)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return logical.ListResponse(entries), nil
|
||||
}
|
||||
|
||||
func (b *ghpBackend) getRole(ctx context.Context, s logical.Storage, name string) (*ghpRole, error) {
|
||||
if name == "" {
|
||||
return nil, errors.New("missing role name")
|
||||
}
|
||||
entry, err := s.Get(ctx, roleStoragePrefix+name)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if entry == nil {
|
||||
return nil, nil
|
||||
}
|
||||
role := &ghpRole{}
|
||||
if err := entry.DecodeJSON(role); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return role, nil
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// normalizeScopes validates ghp scope entries of the form "permission:level"
|
||||
// (matching ghp's token.ParseScopeString), where level is read or write and
|
||||
// permission is a GitHub App permission key. It trims, lower-cases the level,
|
||||
// de-duplicates identical entries and rejects a permission requested at two
|
||||
// different levels. Order is preserved (first occurrence wins). An empty input
|
||||
// is valid and yields no scopes: ghp treats an open-scoped token as all-repos.
|
||||
func normalizeScopes(scopes []string) ([]string, error) {
|
||||
seen := make(map[string]string, len(scopes))
|
||||
out := make([]string, 0, len(scopes))
|
||||
for _, raw := range scopes {
|
||||
s := strings.TrimSpace(raw)
|
||||
if s == "" {
|
||||
continue
|
||||
}
|
||||
kv := strings.SplitN(s, ":", 2)
|
||||
if len(kv) != 2 {
|
||||
return nil, fmt.Errorf("invalid scope %q; expected permission:level (e.g. contents:read)", raw)
|
||||
}
|
||||
perm := strings.TrimSpace(kv[0])
|
||||
level := strings.ToLower(strings.TrimSpace(kv[1]))
|
||||
if perm == "" {
|
||||
return nil, fmt.Errorf("invalid scope %q; permission must not be empty", raw)
|
||||
}
|
||||
if level != "read" && level != "write" {
|
||||
return nil, fmt.Errorf("invalid scope level %q in %q; must be read or write", kv[1], raw)
|
||||
}
|
||||
if prev, ok := seen[perm]; ok {
|
||||
if prev != level {
|
||||
return nil, fmt.Errorf("permission %q requested at conflicting levels %q and %q", perm, prev, level)
|
||||
}
|
||||
continue
|
||||
}
|
||||
seen[perm] = level
|
||||
out = append(out, perm+":"+level)
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// scopeString joins normalized scopes into the comma-separated form ghp's
|
||||
// POST /api/tokens expects; an empty slice yields an empty (open-scoped) string.
|
||||
func scopeString(scopes []string) string {
|
||||
return strings.Join(scopes, ",")
|
||||
}
|
||||
@@ -0,0 +1,52 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestNormalizeScopes(t *testing.T) {
|
||||
cases := []struct {
|
||||
name string
|
||||
in []string
|
||||
want []string
|
||||
wantErr bool
|
||||
}{
|
||||
{"single", []string{"contents:read"}, []string{"contents:read"}, false},
|
||||
{"trim+level-case", []string{" pull_requests:Write "}, []string{"pull_requests:write"}, false},
|
||||
{"dedupe-identical", []string{"contents:read", "contents:read"}, []string{"contents:read"}, false},
|
||||
{"multi", []string{"contents:read", "issues:write"}, []string{"contents:read", "issues:write"}, false},
|
||||
{"empty-input", nil, []string{}, false},
|
||||
{"blank-entries", []string{"", " "}, []string{}, false},
|
||||
{"no-level", []string{"contents"}, nil, true},
|
||||
{"bad-level", []string{"contents:admin"}, nil, true},
|
||||
{"empty-perm", []string{":read"}, nil, true},
|
||||
{"conflict", []string{"contents:read", "contents:write"}, nil, true},
|
||||
}
|
||||
for _, c := range cases {
|
||||
t.Run(c.name, func(t *testing.T) {
|
||||
got, err := normalizeScopes(c.in)
|
||||
if c.wantErr {
|
||||
if err == nil {
|
||||
t.Fatalf("expected error, got %v", got)
|
||||
}
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if strings.Join(got, ",") != strings.Join(c.want, ",") {
|
||||
t.Errorf("normalizeScopes(%v) = %v, want %v", c.in, got, c.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestScopeString(t *testing.T) {
|
||||
if got := scopeString(nil); got != "" {
|
||||
t.Errorf("scopeString(nil) = %q, want empty", got)
|
||||
}
|
||||
if got := scopeString([]string{"contents:read", "issues:write"}); got != "contents:read,issues:write" {
|
||||
t.Errorf("scopeString = %q", got)
|
||||
}
|
||||
}
|
||||
Executable
+44
@@ -0,0 +1,44 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# Package the (already built) plugin binary into RPMs with nfpm. Builds one RPM
|
||||
# per target server: Vault (/opt/vault-plugins) and OpenBao (/opt/openbao-plugins).
|
||||
# Usage: scripts/build-rpm.sh [version] (version defaults to $CI_COMMIT_TAG)
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
cd "${ROOT_DIR}"
|
||||
|
||||
VERSION="${1:-${CI_COMMIT_TAG:-0.0.0-dev}}"
|
||||
VERSION="${VERSION#v}"
|
||||
BINARY="vault-plugin-secrets-ghp"
|
||||
DIST="dist"
|
||||
|
||||
if [ ! -f "${DIST}/${BINARY}" ]; then
|
||||
echo "ERROR: ${DIST}/${BINARY} not found; run 'make build' first" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
export PACKAGE_VERSION="${VERSION}"
|
||||
export PACKAGE_RELEASE="1"
|
||||
export PACKAGE_ARCH="amd64"
|
||||
export PACKAGE_PLATFORM="linux"
|
||||
export PACKAGE_DESCRIPTION="Vault/OpenBao secrets engine for ephemeral, scoped ghp access tokens"
|
||||
export PACKAGE_MAINTAINER="Ben Vincent <ben@unkin.net>"
|
||||
export PACKAGE_HOMEPAGE="https://git.unkin.net/unkin/vault-plugin-secrets-ghp"
|
||||
export PACKAGE_LICENSE="MIT"
|
||||
|
||||
build_flavor() {
|
||||
export PACKAGE_NAME="$1"
|
||||
export PACKAGE_PLUGIN_DIR="$2"
|
||||
export PACKAGE_PREINSTALL="${DIST}/preinstall-${PACKAGE_NAME}.sh"
|
||||
envsubst '${PACKAGE_PLUGIN_DIR}' < packaging/scripts/preinstall.sh.tmpl > "${PACKAGE_PREINSTALL}"
|
||||
envsubst < packaging/nfpm.yaml > "${DIST}/nfpm-${PACKAGE_NAME}.yaml"
|
||||
nfpm pkg --config "${DIST}/nfpm-${PACKAGE_NAME}.yaml" --target "${DIST}" --packager rpm
|
||||
}
|
||||
|
||||
build_flavor "vault-plugin-secrets-ghp" "/opt/vault-plugins"
|
||||
build_flavor "openbao-plugin-secrets-ghp" "/opt/openbao-plugins"
|
||||
|
||||
echo "Built:"
|
||||
ls -1 "${DIST}"/*.rpm
|
||||
Executable
+94
@@ -0,0 +1,94 @@
|
||||
#!/usr/bin/env bash
|
||||
#
|
||||
# End-to-end test for vault-plugin-secrets-ghp.
|
||||
#
|
||||
# Builds the plugin, brings up a mock ghp admin API plus both Vault and OpenBao,
|
||||
# then drives the identical lifecycle against each engine to prove the same
|
||||
# binary works on both:
|
||||
# configure -> role -> creds (mint) -> revoke.
|
||||
#
|
||||
# Select engines with ENGINES (default "vault openbao"), e.g. ENGINES=openbao.
|
||||
#
|
||||
set -euo pipefail
|
||||
|
||||
ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)"
|
||||
COMPOSE_FILE="${ROOT_DIR}/test/docker-compose.yml"
|
||||
COMPOSE="docker compose -f ${COMPOSE_FILE}"
|
||||
BINARY="vault-plugin-secrets-ghp"
|
||||
|
||||
ADMIN_TOKEN="ghpsvc_seed"
|
||||
MOUNT="ghp"
|
||||
ENGINES="${ENGINES:-vault openbao}"
|
||||
|
||||
red() { printf '\033[31m%s\033[0m\n' "$*"; }
|
||||
green() { printf '\033[32m%s\033[0m\n' "$*"; }
|
||||
blue() { printf '\033[34m==> %s\033[0m\n' "$*"; }
|
||||
|
||||
cleanup() { blue "Tearing down containers"; ${COMPOSE} down -v >/dev/null 2>&1 || true; }
|
||||
trap cleanup EXIT
|
||||
fail() { red "FAIL: $*"; exit 1; }
|
||||
|
||||
wait_for() {
|
||||
local desc="$1"; shift
|
||||
local i=0
|
||||
until "$@" >/dev/null 2>&1; do
|
||||
i=$((i + 1))
|
||||
[ "$i" -ge "${WAIT_RETRIES:-90}" ] && fail "timed out waiting for ${desc}"
|
||||
sleep 2
|
||||
done
|
||||
green "ready: ${desc}"
|
||||
}
|
||||
|
||||
jq_field() { python3 -c "import sys,json;print(json.load(sys.stdin)$1)"; }
|
||||
|
||||
run_engine() {
|
||||
local engine="$1" container="$2" cli="$3"
|
||||
blue "[${engine}] exercising the plugin"
|
||||
ex() { ${COMPOSE} exec -T "${container}" "${cli}" "$@"; }
|
||||
|
||||
local sha; sha="$(sha256sum "${ROOT_DIR}/dist/${BINARY}" | awk '{print $1}')"
|
||||
ex plugin register -sha256="${sha}" secret "${BINARY}" >/dev/null || true
|
||||
ex secrets disable "${MOUNT}" >/dev/null 2>&1 || true
|
||||
ex secrets enable -path="${MOUNT}" "${BINARY}" >/dev/null
|
||||
green "[${engine}] plugin registered and mounted"
|
||||
|
||||
# The plugin runs inside the engine container, so it reaches ghp by name.
|
||||
ex write "${MOUNT}/config" base_url="http://ghp:3000" admin_token="${ADMIN_TOKEN}" >/dev/null
|
||||
green "[${engine}] configured"
|
||||
|
||||
# --- role + dynamic creds ---
|
||||
ex write "${MOUNT}/roles/agent" token_type="agent" installation_id=4242 \
|
||||
scopes="contents:read,pull_requests:write" ttl=1h max_ttl=24h >/dev/null
|
||||
local json id lease tok
|
||||
json="$(ex read -format=json "${MOUNT}/creds/agent")"
|
||||
id="$(printf '%s' "${json}" | jq_field '["data"]["token_id"]')"
|
||||
lease="$(printf '%s' "${json}" | jq_field '["lease_id"]')"
|
||||
tok="$(printf '%s' "${json}" | jq_field '["data"]["token"]')"
|
||||
[ -n "${id}" ] || fail "[${engine}] no dynamic token id returned"
|
||||
[ -n "${tok}" ] || fail "[${engine}] dynamic creds returned empty token value"
|
||||
green "[${engine}] dynamic token id=${id} issued (lease ${lease})"
|
||||
|
||||
# revoke -> token deleted from ghp (idempotent: a second revoke is a no-op)
|
||||
ex lease revoke "${lease}" >/dev/null
|
||||
green "[${engine}] revoked lease ${lease}"
|
||||
|
||||
green "[${engine}] PASSED"
|
||||
}
|
||||
|
||||
blue "Building plugin for linux/amd64"
|
||||
OS=linux ARCH=amd64 PLUGIN_DIR="${ROOT_DIR}/dist" make -C "${ROOT_DIR}" build
|
||||
|
||||
blue "Starting Docker stack (ghp + vault + openbao)"
|
||||
${COMPOSE} up -d --build
|
||||
|
||||
wait_for "ghp" curl -fsS "http://127.0.0.1:3000/healthz"
|
||||
|
||||
for engine in ${ENGINES}; do
|
||||
case "${engine}" in
|
||||
vault) wait_for "vault" ${COMPOSE} exec -T vault vault status -address=http://127.0.0.1:8200; run_engine vault vault vault ;;
|
||||
openbao) wait_for "openbao" ${COMPOSE} exec -T openbao bao status -address=http://127.0.0.1:8200; run_engine openbao openbao bao ;;
|
||||
*) fail "unknown engine: ${engine}" ;;
|
||||
esac
|
||||
done
|
||||
|
||||
green "ALL END-TO-END CHECKS PASSED (${ENGINES})"
|
||||
@@ -0,0 +1,92 @@
|
||||
package ghp
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
|
||||
"github.com/hashicorp/vault/sdk/framework"
|
||||
"github.com/hashicorp/vault/sdk/logical"
|
||||
)
|
||||
|
||||
const ghpTokenType = "ghp_token"
|
||||
|
||||
func (b *ghpBackend) ghpTokenSecret() *framework.Secret {
|
||||
return &framework.Secret{
|
||||
Type: ghpTokenType,
|
||||
Fields: map[string]*framework.FieldSchema{
|
||||
"token": {
|
||||
Type: framework.TypeString,
|
||||
Description: "The ghp access token value.",
|
||||
},
|
||||
"token_id": {
|
||||
Type: framework.TypeString,
|
||||
Description: "The ghp token id (used for revocation).",
|
||||
},
|
||||
"token_type": {
|
||||
Type: framework.TypeString,
|
||||
Description: "The ghp token type (agent or proxy).",
|
||||
},
|
||||
"repositories": {
|
||||
Type: framework.TypeCommaStringSlice,
|
||||
Description: "Repositories the token is scoped to.",
|
||||
},
|
||||
"scopes": {
|
||||
Type: framework.TypeKVPairs,
|
||||
Description: "Permission:level scopes granted to the token.",
|
||||
},
|
||||
"expires_at": {
|
||||
Type: framework.TypeString,
|
||||
Description: "The ghp server-side expiry timestamp (RFC3339), if any.",
|
||||
},
|
||||
"session_id": {
|
||||
Type: framework.TypeString,
|
||||
Description: "The ghp session id assigned to the token.",
|
||||
},
|
||||
"base_url": {
|
||||
Type: framework.TypeString,
|
||||
Description: "The ghp base URL the token authenticates against.",
|
||||
},
|
||||
},
|
||||
Revoke: b.secretRevoke,
|
||||
Renew: b.secretRenew,
|
||||
}
|
||||
}
|
||||
|
||||
// secretRevoke deletes the minted ghp token via the admin API. Returning an
|
||||
// error lets Vault retry; a token already gone (404) is treated as success
|
||||
// inside RevokeToken so retries converge.
|
||||
func (b *ghpBackend) secretRevoke(ctx context.Context, req *logical.Request, _ *framework.FieldData) (*logical.Response, error) {
|
||||
tokenID, err := internalString(req.Secret.InternalData, "token_id")
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
client, err := b.clientFor(ctx, req.Storage)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if err := client.RevokeToken(ctx, tokenID); err != nil {
|
||||
return nil, fmt.Errorf("revoking ghp token %q: %w", tokenID, err)
|
||||
}
|
||||
return nil, nil
|
||||
}
|
||||
|
||||
// secretRenew extends the Vault lease; the token material is unchanged. The
|
||||
// ghp-side duration was set to the lease ceiling at mint time, so a renew within
|
||||
// max_ttl simply postpones deletion without outliving the server-side expiry.
|
||||
func (b *ghpBackend) secretRenew(_ context.Context, req *logical.Request, _ *framework.FieldData) (*logical.Response, error) {
|
||||
return &logical.Response{Secret: req.Secret}, nil
|
||||
}
|
||||
|
||||
func internalString(data map[string]interface{}, key string) (string, error) {
|
||||
raw, ok := data[key]
|
||||
if !ok {
|
||||
return "", fmt.Errorf("secret is missing internal %s data", key)
|
||||
}
|
||||
s, ok := raw.(string)
|
||||
if !ok {
|
||||
return "", errors.New("secret internal " + key + " data is not a string")
|
||||
}
|
||||
return s, nil
|
||||
}
|
||||
@@ -0,0 +1,63 @@
|
||||
# End-to-end test stack. A mock ghp admin API (in-memory, no db/GitHub) plus two
|
||||
# secrets-engine hosts running the exact same plugin binary: HashiCorp Vault and
|
||||
# OpenBao. Bind mounts use ":z" so they work under SELinux.
|
||||
services:
|
||||
ghp:
|
||||
image: golang:1.25-alpine
|
||||
working_dir: /src
|
||||
environment:
|
||||
MOCKGHP_ADDR: ":3000"
|
||||
MOCKGHP_ADMIN_TOKEN: "ghpsvc_seed"
|
||||
GOFLAGS: "-mod=mod"
|
||||
command: ["go", "run", "./test/mockghp"]
|
||||
volumes:
|
||||
- ..:/src:ro,z
|
||||
ports:
|
||||
- "3000:3000"
|
||||
healthcheck:
|
||||
test: ["CMD", "wget", "-qO-", "http://localhost:3000/healthz"]
|
||||
interval: 3s
|
||||
timeout: 3s
|
||||
retries: 40
|
||||
|
||||
vault:
|
||||
image: hashicorp/vault:1.18
|
||||
depends_on:
|
||||
ghp:
|
||||
condition: service_healthy
|
||||
cap_add: [IPC_LOCK]
|
||||
environment:
|
||||
VAULT_DEV_ROOT_TOKEN_ID: root
|
||||
VAULT_ADDR: http://127.0.0.1:8200
|
||||
VAULT_TOKEN: root
|
||||
command: ["server", "-dev", "-dev-listen-address=0.0.0.0:8200", "-config=/vault/vault.hcl"]
|
||||
volumes:
|
||||
- ../dist:/vault/plugins:ro,z
|
||||
- ./vault/vault.hcl:/vault/vault.hcl:ro,z
|
||||
ports: ["8200:8200"]
|
||||
healthcheck:
|
||||
test: ["CMD", "vault", "status", "-address=http://127.0.0.1:8200"]
|
||||
interval: 3s
|
||||
timeout: 3s
|
||||
retries: 20
|
||||
|
||||
openbao:
|
||||
image: openbao/openbao:latest
|
||||
depends_on:
|
||||
ghp:
|
||||
condition: service_healthy
|
||||
cap_add: [IPC_LOCK]
|
||||
environment:
|
||||
BAO_DEV_ROOT_TOKEN_ID: root
|
||||
BAO_ADDR: http://127.0.0.1:8200
|
||||
BAO_TOKEN: root
|
||||
command: ["server", "-dev", "-dev-listen-address=0.0.0.0:8200", "-config=/openbao/bao.hcl"]
|
||||
volumes:
|
||||
- ../dist:/openbao/plugins:ro,z
|
||||
- ./openbao/bao.hcl:/openbao/bao.hcl:ro,z
|
||||
ports: ["8300:8200"]
|
||||
healthcheck:
|
||||
test: ["CMD", "bao", "status", "-address=http://127.0.0.1:8200"]
|
||||
interval: 3s
|
||||
timeout: 3s
|
||||
retries: 20
|
||||
@@ -0,0 +1,139 @@
|
||||
// Command mockghp is an in-memory stand-in for the subset of the ghp admin API
|
||||
// that vault-plugin-secrets-ghp uses: admin check (GET /api/users), token
|
||||
// create (POST /api/tokens) and token revoke (DELETE /api/tokens/{id}). It is
|
||||
// used by the e2e tests — no real ghp, database, or GitHub App required. Not for
|
||||
// production use.
|
||||
//
|
||||
// Authentication is a bearer service token (MOCKGHP_ADMIN_TOKEN) matched exactly;
|
||||
// a valid token is treated as a synthetic admin, exactly as real ghp treats its
|
||||
// configured service tokens.
|
||||
package main
|
||||
|
||||
import (
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"encoding/json"
|
||||
"log"
|
||||
"net/http"
|
||||
"os"
|
||||
"strconv"
|
||||
"strings"
|
||||
"sync"
|
||||
)
|
||||
|
||||
type createTokenRequest struct {
|
||||
Type string `json:"type"`
|
||||
AppRecordID string `json:"app_record_id"`
|
||||
Repositories []string `json:"repositories"`
|
||||
InstallationID int64 `json:"installation_id"`
|
||||
Scopes string `json:"scopes"`
|
||||
Duration string `json:"duration"`
|
||||
SessionID string `json:"session_id"`
|
||||
}
|
||||
|
||||
type store struct {
|
||||
mu sync.Mutex
|
||||
adminTok string
|
||||
nextID int64
|
||||
tokens map[string]bool // key: id
|
||||
}
|
||||
|
||||
func randHex(n int) string {
|
||||
buf := make([]byte, n)
|
||||
_, _ = rand.Read(buf)
|
||||
return hex.EncodeToString(buf)
|
||||
}
|
||||
|
||||
func (s *store) authOK(r *http.Request) bool {
|
||||
tok, ok := strings.CutPrefix(r.Header.Get("Authorization"), "Bearer ")
|
||||
s.mu.Lock()
|
||||
defer s.mu.Unlock()
|
||||
return ok && tok == s.adminTok
|
||||
}
|
||||
|
||||
func writeJSON(w http.ResponseWriter, code int, v interface{}) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(code)
|
||||
_ = json.NewEncoder(w).Encode(v)
|
||||
}
|
||||
|
||||
func (s *store) handleUsers(w http.ResponseWriter, r *http.Request) {
|
||||
if !s.authOK(r) {
|
||||
w.WriteHeader(http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, []map[string]interface{}{{"id": "svc-admin", "role": "admin"}})
|
||||
}
|
||||
|
||||
func (s *store) handleTokens(w http.ResponseWriter, r *http.Request) {
|
||||
if !s.authOK(r) {
|
||||
w.WriteHeader(http.StatusUnauthorized)
|
||||
return
|
||||
}
|
||||
switch {
|
||||
case r.Method == http.MethodPost && r.URL.Path == "/api/tokens":
|
||||
var in createTokenRequest
|
||||
if err := json.NewDecoder(r.Body).Decode(&in); err != nil {
|
||||
w.WriteHeader(http.StatusBadRequest)
|
||||
return
|
||||
}
|
||||
tt := in.Type
|
||||
if tt == "" {
|
||||
tt = "proxy"
|
||||
}
|
||||
s.mu.Lock()
|
||||
s.nextID++
|
||||
id := "tok-" + strconv.FormatInt(s.nextID, 10)
|
||||
s.tokens[id] = true
|
||||
s.mu.Unlock()
|
||||
scopes := map[string]string{}
|
||||
for _, part := range strings.Split(in.Scopes, ",") {
|
||||
kv := strings.SplitN(part, ":", 2)
|
||||
if len(kv) == 2 {
|
||||
scopes[kv[0]] = kv[1]
|
||||
}
|
||||
}
|
||||
writeJSON(w, http.StatusCreated, map[string]interface{}{
|
||||
"token": "gha_" + randHex(16),
|
||||
"id": id,
|
||||
"type": tt,
|
||||
"repositories": in.Repositories,
|
||||
"scopes": scopes,
|
||||
"expires_at": "2030-01-01T00:00:00Z",
|
||||
"session_id": in.SessionID,
|
||||
})
|
||||
case r.Method == http.MethodDelete && strings.HasPrefix(r.URL.Path, "/api/tokens/"):
|
||||
id := strings.TrimPrefix(r.URL.Path, "/api/tokens/")
|
||||
s.mu.Lock()
|
||||
exists := s.tokens[id]
|
||||
delete(s.tokens, id)
|
||||
s.mu.Unlock()
|
||||
if !exists {
|
||||
writeJSON(w, http.StatusNotFound, map[string]string{"message": "Token not found"})
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, map[string]string{"message": "Token revoked"})
|
||||
default:
|
||||
w.WriteHeader(http.StatusNotFound)
|
||||
}
|
||||
}
|
||||
|
||||
func main() {
|
||||
addr := os.Getenv("MOCKGHP_ADDR")
|
||||
if addr == "" {
|
||||
addr = ":3000"
|
||||
}
|
||||
adminTok := os.Getenv("MOCKGHP_ADMIN_TOKEN")
|
||||
if adminTok == "" {
|
||||
adminTok = "ghpsvc_seed"
|
||||
}
|
||||
s := &store{adminTok: adminTok, tokens: map[string]bool{}}
|
||||
|
||||
mux := http.NewServeMux()
|
||||
mux.HandleFunc("/api/users", s.handleUsers)
|
||||
mux.HandleFunc("/api/tokens", s.handleTokens)
|
||||
mux.HandleFunc("/api/tokens/", s.handleTokens)
|
||||
mux.HandleFunc("/healthz", func(w http.ResponseWriter, _ *http.Request) { _, _ = w.Write([]byte("ok")) })
|
||||
log.Printf("mock ghp API listening on %s", addr)
|
||||
log.Fatal(http.ListenAndServe(addr, mux)) //nolint:gosec // test-only mock
|
||||
}
|
||||
@@ -0,0 +1,4 @@
|
||||
# OpenBao is plugin-protocol compatible with Vault, so the very same plugin
|
||||
# binary registers and runs here unchanged. Combined with `-dev` at runtime.
|
||||
plugin_directory = "/openbao/plugins"
|
||||
api_addr = "http://127.0.0.1:8200"
|
||||
@@ -0,0 +1,4 @@
|
||||
# Combined with `-dev` at runtime; supplies the plugin_directory the dev server
|
||||
# would otherwise leave unset, so the plugin binary in ../dist can be registered.
|
||||
plugin_directory = "/vault/plugins"
|
||||
api_addr = "http://127.0.0.1:8200"
|
||||
Reference in New Issue
Block a user