difftreelog
feat support secrets without secret data
in: trunk
4 files changed
cmds/fleet/src/cmds/secrets/mod.rsdiffbeforeafterboth70 let mut input = vec![];70 let mut input = vec![];71 io::stdin().read_to_end(&mut input)?;71 io::stdin().read_to_end(&mut input)?;727273 if input.is_empty() {74 input75 } else {73 let mut encrypted = vec![];76 let mut encrypted = vec![];74 let recipients = recipients77 let recipients = recipients75 .iter()78 .iter()81 io::copy(&mut Cursor::new(input), &mut encryptor)?;84 io::copy(&mut Cursor::new(input), &mut encryptor)?;82 encryptor.finish()?;85 encryptor.finish()?;83 encrypted86 encrypted87 }84 };88 };858986 let mut data = config.data_mut();90 let mut data = config.data_mut();cmds/fleet/src/fleetdata.rsdiffbeforeafterboth--- a/cmds/fleet/src/fleetdata.rs
+++ b/cmds/fleet/src/fleetdata.rs
@@ -39,7 +39,12 @@
pub expire_at: Option<DateTime<Utc>>,
#[serde(skip_serializing_if = "Option::is_none")]
pub public: Option<String>,
- #[serde(serialize_with = "as_z85", deserialize_with = "from_z85")]
+ #[serde(
+ default,
+ skip_serializing_if = "Vec::is_empty",
+ serialize_with = "as_z85",
+ deserialize_with = "from_z85"
+ )]
pub secret: Vec<u8>,
}
cmds/install-secrets/src/main.rsdiffbeforeafterboth--- a/cmds/install-secrets/src/main.rs
+++ b/cmds/install-secrets/src/main.rs
@@ -29,16 +29,21 @@
mode: String,
owner: String,
#[serde(deserialize_with = "from_z85")]
- secret: Vec<u8>,
+ secret: Option<Vec<u8>>,
}
-fn from_z85<'de, D>(deserializer: D) -> Result<Vec<u8>, D::Error>
+fn from_z85<'de, D>(deserializer: D) -> Result<Option<Vec<u8>>, D::Error>
where
D: Deserializer<'de>,
{
use serde::de::Error;
- String::deserialize(deserializer)
- .and_then(|string| z85::decode(&string).map_err(|err| Error::custom(err.to_string())))
+ if let Some(v) = <Option<String>>::deserialize(deserializer)? {
+ Ok(Some(
+ z85::decode(&v).map_err(|err| Error::custom(err.to_string()))?,
+ ))
+ } else {
+ Ok(None)
+ }
}
type Data = HashMap<String, DataItem>;
@@ -49,6 +54,11 @@
name: &str,
value: DataItem,
) -> Result<()> {
+ if value.secret.is_none() {
+ return Ok(());
+ }
+ let secret = value.secret.as_ref().unwrap();
+
let mut path = dir.to_path_buf();
path.push(name);
if path.strip_prefix(&dir).is_err() {
@@ -88,7 +98,7 @@
// File is owned by root, and only root can modify it
let decrypted = {
- let mut input = Cursor::new(&value.secret);
+ let mut input = Cursor::new(&secret);
let decryptor = Decryptor::new(&mut input).context("failed to init decryptor")?;
let decryptor = match decryptor {
Decryptor::Recipients(r) => r,
modules/nixos/secrets.nixdiffbeforeafterboth--- a/modules/nixos/secrets.nix
+++ b/modules/nixos/secrets.nix
@@ -3,7 +3,9 @@
sysConfig = config;
secretType = types.submodule ({ config, ... }: {
config = {
- path = mkOptionDefault "/run/secrets/${config._module.args.name}";
+ path = mkOptionDefault (if config.secret == null then (error "secret is not set") else "/run/secrets/${config._module.args.name}");
+ publicPath = mkOptionDefault (pkgs.writeText "pub-${config._module.args.name}" config.public);
+ secret = mkIf (config.public != null) "";
};
options = {
public = mkOption {
@@ -12,7 +14,7 @@
default = null;
};
secret = mkOption {
- type = types.str;
+ type = types.nullOr types.str;
description = "Encrypted secret data";
};
mode = mkOption {
@@ -36,6 +38,11 @@
readOnly = true;
description = "Path to the decrypted secret";
};
+ publicPath = mkOption {
+ type = types.package;
+ readOnly = true;
+ description = "Path to the public part of secret";
+ };
};
});
secretsFile = pkgs.writeTextFile {