|
|
@ -7,100 +7,83 @@ import (
|
|
|
|
|
|
|
|
|
|
|
|
const SecretsEncryptCommand = "secrets-encrypt"
|
|
|
|
const SecretsEncryptCommand = "secrets-encrypt"
|
|
|
|
|
|
|
|
|
|
|
|
var EncryptFlags = []cli.Flag{
|
|
|
|
var (
|
|
|
|
DataDirFlag,
|
|
|
|
forceFlag = cli.BoolFlag{
|
|
|
|
ServerToken,
|
|
|
|
Name: "f,force",
|
|
|
|
cli.StringFlag{
|
|
|
|
Usage: "Force this stage.",
|
|
|
|
Name: "server, s",
|
|
|
|
Destination: &ServerConfig.EncryptForce,
|
|
|
|
Usage: "(cluster) Server to connect to",
|
|
|
|
|
|
|
|
EnvVar: version.ProgramUpper + "_URL",
|
|
|
|
|
|
|
|
Value: "https://127.0.0.1:6443",
|
|
|
|
|
|
|
|
Destination: &ServerConfig.ServerURL,
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
func NewSecretsEncryptCommand(action func(*cli.Context) error, subcommands []cli.Command) cli.Command {
|
|
|
|
|
|
|
|
return cli.Command{
|
|
|
|
|
|
|
|
Name: SecretsEncryptCommand,
|
|
|
|
|
|
|
|
Usage: "Control secrets encryption and keys rotation",
|
|
|
|
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: action,
|
|
|
|
|
|
|
|
Subcommands: subcommands,
|
|
|
|
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
EncryptFlags = []cli.Flag{
|
|
|
|
|
|
|
|
DataDirFlag,
|
|
|
|
func NewSecretsEncryptSubcommands(status, enable, disable, prepare, rotate, reencrypt func(ctx *cli.Context) error) []cli.Command {
|
|
|
|
ServerToken,
|
|
|
|
return []cli.Command{
|
|
|
|
cli.StringFlag{
|
|
|
|
{
|
|
|
|
Name: "server, s",
|
|
|
|
Name: "status",
|
|
|
|
Usage: "(cluster) Server to connect to",
|
|
|
|
Usage: "Print current status of secrets encryption",
|
|
|
|
EnvVar: version.ProgramUpper + "_URL",
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
Value: "https://127.0.0.1:6443",
|
|
|
|
SkipArgReorder: true,
|
|
|
|
Destination: &ServerConfig.ServerURL,
|
|
|
|
Action: status,
|
|
|
|
|
|
|
|
Flags: append(EncryptFlags, &cli.StringFlag{
|
|
|
|
|
|
|
|
Name: "output,o",
|
|
|
|
|
|
|
|
Usage: "Status format. Default: text. Optional: json",
|
|
|
|
|
|
|
|
Destination: &ServerConfig.EncryptOutput,
|
|
|
|
|
|
|
|
}),
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "enable",
|
|
|
|
|
|
|
|
Usage: "Enable secrets encryption",
|
|
|
|
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: enable,
|
|
|
|
|
|
|
|
Flags: EncryptFlags,
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "disable",
|
|
|
|
|
|
|
|
Usage: "Disable secrets encryption",
|
|
|
|
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: disable,
|
|
|
|
|
|
|
|
Flags: EncryptFlags,
|
|
|
|
|
|
|
|
},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
}
|
|
|
|
Name: "prepare",
|
|
|
|
)
|
|
|
|
Usage: "Prepare for encryption keys rotation",
|
|
|
|
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
func NewSecretsEncryptCommands(status, enable, disable, prepare, rotate, reencrypt func(ctx *cli.Context) error) cli.Command {
|
|
|
|
SkipArgReorder: true,
|
|
|
|
return cli.Command{
|
|
|
|
Action: prepare,
|
|
|
|
Name: SecretsEncryptCommand,
|
|
|
|
Flags: append(EncryptFlags, &cli.BoolFlag{
|
|
|
|
Usage: "Control secrets encryption and keys rotation",
|
|
|
|
Name: "f,force",
|
|
|
|
SkipArgReorder: true,
|
|
|
|
Usage: "Force preparation.",
|
|
|
|
Subcommands: []cli.Command{
|
|
|
|
Destination: &ServerConfig.EncryptForce,
|
|
|
|
{
|
|
|
|
}),
|
|
|
|
Name: "status",
|
|
|
|
},
|
|
|
|
Usage: "Print current status of secrets encryption",
|
|
|
|
{
|
|
|
|
SkipArgReorder: true,
|
|
|
|
Name: "rotate",
|
|
|
|
Action: status,
|
|
|
|
Usage: "Rotate secrets encryption keys",
|
|
|
|
Flags: append(EncryptFlags, &cli.StringFlag{
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
Name: "output,o",
|
|
|
|
SkipArgReorder: true,
|
|
|
|
Usage: "Status format. Default: text. Optional: json",
|
|
|
|
Action: rotate,
|
|
|
|
Destination: &ServerConfig.EncryptOutput,
|
|
|
|
Flags: append(EncryptFlags, &cli.BoolFlag{
|
|
|
|
|
|
|
|
Name: "f,force",
|
|
|
|
|
|
|
|
Usage: "Force key rotation.",
|
|
|
|
|
|
|
|
Destination: &ServerConfig.EncryptForce,
|
|
|
|
|
|
|
|
}),
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "reencrypt",
|
|
|
|
|
|
|
|
Usage: "Reencrypt all data with new encryption key",
|
|
|
|
|
|
|
|
SkipFlagParsing: false,
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: reencrypt,
|
|
|
|
|
|
|
|
Flags: append(EncryptFlags,
|
|
|
|
|
|
|
|
&cli.BoolFlag{
|
|
|
|
|
|
|
|
Name: "f,force",
|
|
|
|
|
|
|
|
Usage: "Force secrets reencryption.",
|
|
|
|
|
|
|
|
Destination: &ServerConfig.EncryptForce,
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
&cli.BoolFlag{
|
|
|
|
|
|
|
|
Name: "skip",
|
|
|
|
|
|
|
|
Usage: "Skip removing old key",
|
|
|
|
|
|
|
|
Destination: &ServerConfig.EncryptSkip,
|
|
|
|
|
|
|
|
}),
|
|
|
|
}),
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "enable",
|
|
|
|
|
|
|
|
Usage: "Enable secrets encryption",
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: enable,
|
|
|
|
|
|
|
|
Flags: EncryptFlags,
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "disable",
|
|
|
|
|
|
|
|
Usage: "Disable secrets encryption",
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: disable,
|
|
|
|
|
|
|
|
Flags: EncryptFlags,
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "prepare",
|
|
|
|
|
|
|
|
Usage: "Prepare for encryption keys rotation",
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: prepare,
|
|
|
|
|
|
|
|
Flags: append(EncryptFlags, &forceFlag),
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "rotate",
|
|
|
|
|
|
|
|
Usage: "Rotate secrets encryption keys",
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: rotate,
|
|
|
|
|
|
|
|
Flags: append(EncryptFlags, &forceFlag),
|
|
|
|
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
Name: "reencrypt",
|
|
|
|
|
|
|
|
Usage: "Reencrypt all data with new encryption key",
|
|
|
|
|
|
|
|
SkipArgReorder: true,
|
|
|
|
|
|
|
|
Action: reencrypt,
|
|
|
|
|
|
|
|
Flags: append(EncryptFlags,
|
|
|
|
|
|
|
|
&forceFlag,
|
|
|
|
|
|
|
|
&cli.BoolFlag{
|
|
|
|
|
|
|
|
Name: "skip",
|
|
|
|
|
|
|
|
Usage: "Skip removing old key",
|
|
|
|
|
|
|
|
Destination: &ServerConfig.EncryptSkip,
|
|
|
|
|
|
|
|
}),
|
|
|
|
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|