mirror of
https://github.com/Unleash/unleash.git
synced 2025-09-05 17:53:12 +02:00
chore: AWS IAM DB auth migrator, logs (#10617)
https://linear.app/unleash/issue/2-3860/aws-iam-db-auth-migrator-logs AWS IAM DB auth migrator, logs.
This commit is contained in:
parent
4a00792f1e
commit
07f6970eed
31
src/lib/db/aws-iam.ts
Normal file
31
src/lib/db/aws-iam.ts
Normal file
@ -0,0 +1,31 @@
|
|||||||
|
import { Signer } from '@aws-sdk/rds-signer';
|
||||||
|
import type { IDBOption } from '../types/option.js';
|
||||||
|
|
||||||
|
type PasswordResolver = () => Promise<string>;
|
||||||
|
|
||||||
|
export const getDBPasswordResolver = (db: IDBOption): PasswordResolver => {
|
||||||
|
if (db.awsIamAuth) {
|
||||||
|
if (!db.awsRegion)
|
||||||
|
throw new Error(
|
||||||
|
'AWS_REGION is required when DATABASE_AWS_IAM=true',
|
||||||
|
);
|
||||||
|
|
||||||
|
const signer = new Signer({
|
||||||
|
region: db.awsRegion,
|
||||||
|
hostname: db.host,
|
||||||
|
port: db.port,
|
||||||
|
username: db.user,
|
||||||
|
});
|
||||||
|
return async () => {
|
||||||
|
console.log('[AWS RDS SIGNER] Getting token...');
|
||||||
|
const token = await signer.getAuthToken();
|
||||||
|
console.log(`[AWS RDS SIGNER] Got token: ${token}`);
|
||||||
|
return token;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
return async () => db.password;
|
||||||
|
};
|
||||||
|
|
||||||
|
export const getDBPassword = (db: IDBOption): Promise<string> =>
|
||||||
|
getDBPasswordResolver(db)();
|
@ -2,8 +2,7 @@ import type { Knex } from 'knex';
|
|||||||
import knexpkg from 'knex';
|
import knexpkg from 'knex';
|
||||||
const { knex } = knexpkg;
|
const { knex } = knexpkg;
|
||||||
import type { IUnleashConfig } from '../types/option.js';
|
import type { IUnleashConfig } from '../types/option.js';
|
||||||
|
import { getDBPasswordResolver } from './aws-iam.js';
|
||||||
import { Signer } from '@aws-sdk/rds-signer';
|
|
||||||
|
|
||||||
export function createDb({
|
export function createDb({
|
||||||
db,
|
db,
|
||||||
@ -11,53 +10,19 @@ export function createDb({
|
|||||||
}: Pick<IUnleashConfig, 'db' | 'getLogger'>): Knex {
|
}: Pick<IUnleashConfig, 'db' | 'getLogger'>): Knex {
|
||||||
const logger = getLogger('db-pool.js');
|
const logger = getLogger('db-pool.js');
|
||||||
|
|
||||||
const {
|
logger.info(
|
||||||
host,
|
`createDb: iam=${Boolean(db.awsIamAuth)} host=${db.host} port=${db.port} db=${db.database} user=${db.user} ssl=${Boolean(db.ssl)}`,
|
||||||
port,
|
);
|
||||||
user,
|
|
||||||
database,
|
|
||||||
ssl,
|
|
||||||
applicationName,
|
|
||||||
password,
|
|
||||||
awsIamAuth,
|
|
||||||
awsRegion,
|
|
||||||
pool,
|
|
||||||
} = db;
|
|
||||||
|
|
||||||
let resolvedPassword: string | (() => Promise<string>) | undefined =
|
|
||||||
password;
|
|
||||||
|
|
||||||
if (awsIamAuth) {
|
|
||||||
if (!awsRegion) {
|
|
||||||
throw new Error(
|
|
||||||
'AWS_REGION is required when DATABASE_AWS_IAM=true',
|
|
||||||
);
|
|
||||||
}
|
|
||||||
const signer = new Signer({
|
|
||||||
region: awsRegion,
|
|
||||||
hostname: host,
|
|
||||||
port,
|
|
||||||
username: user,
|
|
||||||
});
|
|
||||||
|
|
||||||
resolvedPassword = async () => signer.getAuthToken();
|
|
||||||
}
|
|
||||||
|
|
||||||
const connection = {
|
|
||||||
host,
|
|
||||||
port,
|
|
||||||
user,
|
|
||||||
database,
|
|
||||||
ssl,
|
|
||||||
application_name: applicationName,
|
|
||||||
password: resolvedPassword,
|
|
||||||
};
|
|
||||||
|
|
||||||
return knex({
|
return knex({
|
||||||
client: 'pg',
|
client: 'pg',
|
||||||
version: db.version,
|
version: db.version,
|
||||||
connection,
|
connection: {
|
||||||
pool,
|
...db,
|
||||||
|
application_name: db.applicationName,
|
||||||
|
password: getDBPasswordResolver(db),
|
||||||
|
},
|
||||||
|
pool: db.pool,
|
||||||
searchPath: db.schema,
|
searchPath: db.schema,
|
||||||
asyncStackTraces: true,
|
asyncStackTraces: true,
|
||||||
log: {
|
log: {
|
||||||
|
@ -20,7 +20,7 @@ export interface ISSLOption {
|
|||||||
|
|
||||||
export interface IDBOption {
|
export interface IDBOption {
|
||||||
user: string;
|
user: string;
|
||||||
password?: string;
|
password: string;
|
||||||
host: string;
|
host: string;
|
||||||
port: number;
|
port: number;
|
||||||
database: string;
|
database: string;
|
||||||
|
Loading…
Reference in New Issue
Block a user