-
Notifications
You must be signed in to change notification settings - Fork 0
/
store.ts
71 lines (64 loc) · 1.98 KB
/
store.ts
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
import makeDebug from 'debug'
import type { SecretManagerServiceClient } from '@google-cloud/secret-manager'
import { accessSecretVersion } from './access-secret-version.js'
import { addSecretVersion } from './add-secret-version.js'
import { disableSecretVersionsMatchingFilter } from './disable-secret-versions.js'
export interface Store<T> {
persist: (data: T) => Promise<void>
retrieve: () => Promise<T>
}
const debug = makeDebug('secret-manager-utils/store')
export interface Config {
secret_manager: SecretManagerServiceClient
secret_name: string
should_disable_older_enabled_versions?: boolean
}
/**
* Store that retrieves data from, and persists data to, Secret Manager.
*/
export const secretManagerStore = <T>({
secret_manager,
secret_name,
should_disable_older_enabled_versions
}: Config): Store<T> => {
//
const retrieve = async () => {
debug(`trying to retrieve, from Secret Manager, secret ${secret_name}`)
const secret = await accessSecretVersion({
secret_manager,
secret_name,
version: 'latest'
})
debug(`retrieved secret ${secret_name} from Secret Manager`)
try {
const obj = JSON.parse(secret)
return obj as T
} catch (err: any) {
return secret as unknown as T
}
}
const persist = async (data: T) => {
debug(`trying to persist data to Secret Manager, in secret ${secret_name}`)
const new_version = await addSecretVersion({
secret_manager,
secret_name,
payload: JSON.stringify(data, null, 2)
})
debug(`data persisted to Secret Manager, in secret ${secret_name}`)
if (should_disable_older_enabled_versions) {
debug(
`trying to disable all older, enabled versions of secret ${secret_name}`
)
const { message } = await disableSecretVersionsMatchingFilter({
secret_manager,
secret_name,
filter: `state:ENABLED AND NOT name:${new_version.name}`
})
debug(message)
}
}
return {
persist,
retrieve
}
}