lockbox_test.go 42 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091
  1. /*
  2. Copyright © 2025 ESO Maintainer Team
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. https://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package lockbox
  14. import (
  15. "context"
  16. b64 "encoding/base64"
  17. "encoding/json"
  18. "testing"
  19. "time"
  20. "github.com/google/uuid"
  21. tassert "github.com/stretchr/testify/assert"
  22. "github.com/yandex-cloud/go-genproto/yandex/cloud/lockbox/v1"
  23. "github.com/yandex-cloud/go-sdk/iamkey"
  24. corev1 "k8s.io/api/core/v1"
  25. metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  26. ctrl "sigs.k8s.io/controller-runtime"
  27. k8sclient "sigs.k8s.io/controller-runtime/pkg/client"
  28. clientfake "sigs.k8s.io/controller-runtime/pkg/client/fake"
  29. esv1 "github.com/external-secrets/external-secrets/apis/externalsecrets/v1"
  30. esmeta "github.com/external-secrets/external-secrets/apis/meta/v1"
  31. "github.com/external-secrets/external-secrets/pkg/provider/yandex/common"
  32. "github.com/external-secrets/external-secrets/pkg/provider/yandex/common/clock"
  33. "github.com/external-secrets/external-secrets/pkg/provider/yandex/lockbox/client"
  34. )
  35. const (
  36. errMissingKey = "invalid Yandex Lockbox SecretStore resource: missing AuthorizedKey Name"
  37. errSecretPayloadPermissionDenied = "unable to request secret payload to get secret: permission denied"
  38. errSecretPayloadNotFound = "unable to request secret payload to get secret: secret not found"
  39. errSecretPayloadVersionNotFound = "unable to request secret payload to get secret: version not found"
  40. )
  41. func TestNewClient(t *testing.T) {
  42. ctx := context.Background()
  43. const namespace = "namespace"
  44. const authorizedKeySecretName = "authorizedKeySecretName"
  45. const authorizedKeySecretKey = "authorizedKeySecretKey"
  46. store := &esv1.SecretStore{
  47. ObjectMeta: metav1.ObjectMeta{
  48. Namespace: namespace,
  49. },
  50. Spec: esv1.SecretStoreSpec{
  51. Provider: &esv1.SecretStoreProvider{
  52. YandexLockbox: &esv1.YandexLockboxProvider{
  53. Auth: esv1.YandexAuth{
  54. AuthorizedKey: esmeta.SecretKeySelector{
  55. Key: authorizedKeySecretKey,
  56. Name: authorizedKeySecretName,
  57. },
  58. },
  59. },
  60. },
  61. },
  62. }
  63. provider, err := esv1.GetProvider(store)
  64. tassert.Nil(t, err)
  65. k8sClient := clientfake.NewClientBuilder().Build()
  66. secretClient, err := provider.NewClient(context.Background(), store, k8sClient, namespace)
  67. tassert.EqualError(t, err, "cannot get Kubernetes secret \"authorizedKeySecretName\" from namespace \"namespace\": secrets \"authorizedKeySecretName\" not found")
  68. tassert.Nil(t, secretClient)
  69. err = createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, newFakeAuthorizedKey()))
  70. tassert.Nil(t, err)
  71. const caCertificateSecretName = "caCertificateSecretName"
  72. const caCertificateSecretKey = "caCertificateSecretKey"
  73. store.Spec.Provider.YandexLockbox.CAProvider = &esv1.YandexCAProvider{
  74. Certificate: esmeta.SecretKeySelector{
  75. Key: caCertificateSecretKey,
  76. Name: caCertificateSecretName,
  77. },
  78. }
  79. secretClient, err = provider.NewClient(context.Background(), store, k8sClient, namespace)
  80. tassert.EqualError(t, err, "cannot get Kubernetes secret \"caCertificateSecretName\" from namespace \"namespace\": secrets \"caCertificateSecretName\" not found")
  81. tassert.Nil(t, secretClient)
  82. err = createK8sSecret(ctx, t, k8sClient, namespace, caCertificateSecretName, caCertificateSecretKey, []byte("it-is-not-a-certificate"))
  83. tassert.Nil(t, err)
  84. secretClient, err = provider.NewClient(context.Background(), store, k8sClient, namespace)
  85. tassert.EqualError(t, err, "failed to create Yandex.Cloud client: unable to read trusted CA certificates")
  86. tassert.Nil(t, secretClient)
  87. }
  88. func TestGetSecretForAllEntries(t *testing.T) {
  89. ctx := context.Background()
  90. namespace := uuid.NewString()
  91. authorizedKey := newFakeAuthorizedKey()
  92. fakeClock := clock.NewFakeClock()
  93. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  94. k1, v1 := "k1", "v1"
  95. k2, v2 := "k2", []byte("v2")
  96. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  97. "folderId", "secretName",
  98. textEntry(k1, v1),
  99. binaryEntry(k2, v2),
  100. )
  101. k8sClient := clientfake.NewClientBuilder().Build()
  102. const authorizedKeySecretName = "authorizedKeySecretName"
  103. const authorizedKeySecretKey = "authorizedKeySecretKey"
  104. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  105. tassert.Nil(t, err)
  106. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  107. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  108. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  109. tassert.Nil(t, err)
  110. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID})
  111. tassert.Nil(t, err)
  112. tassert.Equal(
  113. t,
  114. map[string]string{
  115. k1: v1,
  116. k2: base64(v2),
  117. },
  118. unmarshalStringMap(t, data),
  119. )
  120. }
  121. func TestGetSecretForTextEntry(t *testing.T) {
  122. ctx := context.Background()
  123. namespace := uuid.NewString()
  124. authorizedKey := newFakeAuthorizedKey()
  125. fakeClock := clock.NewFakeClock()
  126. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  127. k1, v1 := "k1", "v1"
  128. k2, v2 := "k2", []byte("v2")
  129. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  130. "folderId", "secretName",
  131. textEntry(k1, v1),
  132. binaryEntry(k2, v2),
  133. )
  134. k8sClient := clientfake.NewClientBuilder().Build()
  135. const authorizedKeySecretName = "authorizedKeySecretName"
  136. const authorizedKeySecretKey = "authorizedKeySecretKey"
  137. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  138. tassert.Nil(t, err)
  139. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  140. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  141. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  142. tassert.Nil(t, err)
  143. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k1})
  144. tassert.Nil(t, err)
  145. tassert.Equal(t, v1, string(data))
  146. }
  147. func TestGetSecretForBinaryEntry(t *testing.T) {
  148. ctx := context.Background()
  149. namespace := uuid.NewString()
  150. authorizedKey := newFakeAuthorizedKey()
  151. fakeClock := clock.NewFakeClock()
  152. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  153. k1, v1 := "k1", "v1"
  154. k2, v2 := "k2", []byte("v2")
  155. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  156. "folderId", "secretName",
  157. textEntry(k1, v1),
  158. binaryEntry(k2, v2),
  159. )
  160. k8sClient := clientfake.NewClientBuilder().Build()
  161. const authorizedKeySecretName = "authorizedKeySecretName"
  162. const authorizedKeySecretKey = "authorizedKeySecretKey"
  163. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  164. tassert.Nil(t, err)
  165. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  166. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  167. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  168. tassert.Nil(t, err)
  169. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k2})
  170. tassert.Nil(t, err)
  171. tassert.Equal(t, v2, data)
  172. }
  173. func TestGetSecretByVersionID(t *testing.T) {
  174. ctx := context.Background()
  175. namespace := uuid.NewString()
  176. authorizedKey := newFakeAuthorizedKey()
  177. fakeClock := clock.NewFakeClock()
  178. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  179. const oldKey, oldVal = "oldKey", "oldVal"
  180. secretID, oldVersionID := fakeLockboxServer.CreateSecret(authorizedKey,
  181. "folderId", "secretName",
  182. textEntry(oldKey, oldVal),
  183. )
  184. k8sClient := clientfake.NewClientBuilder().Build()
  185. const authorizedKeySecretName = "authorizedKeySecretName"
  186. const authorizedKeySecretKey = "authorizedKeySecretKey"
  187. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  188. tassert.Nil(t, err)
  189. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  190. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  191. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  192. tassert.Nil(t, err)
  193. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: oldVersionID})
  194. tassert.Nil(t, err)
  195. tassert.Equal(t, map[string]string{oldKey: oldVal}, unmarshalStringMap(t, data))
  196. const newKey, newVal = "newKey", "newVal"
  197. newVersionID := fakeLockboxServer.AddVersion(secretID, textEntry(newKey, newVal))
  198. data, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: oldVersionID})
  199. tassert.Nil(t, err)
  200. tassert.Equal(t, map[string]string{oldKey: oldVal}, unmarshalStringMap(t, data))
  201. data, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: newVersionID})
  202. tassert.Nil(t, err)
  203. tassert.Equal(t, map[string]string{newKey: newVal}, unmarshalStringMap(t, data))
  204. }
  205. func TestGetSecretUnauthorized(t *testing.T) {
  206. ctx := context.Background()
  207. namespace := uuid.NewString()
  208. authorizedKeyA := newFakeAuthorizedKey()
  209. authorizedKeyB := newFakeAuthorizedKey()
  210. fakeClock := clock.NewFakeClock()
  211. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  212. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKeyA,
  213. "folderId", "secretName",
  214. textEntry("k1", "v1"),
  215. )
  216. k8sClient := clientfake.NewClientBuilder().Build()
  217. const authorizedKeySecretName = "authorizedKeySecretName"
  218. const authorizedKeySecretKey = "authorizedKeySecretKey"
  219. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKeyB))
  220. tassert.Nil(t, err)
  221. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  222. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  223. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  224. tassert.Nil(t, err)
  225. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID})
  226. tassert.EqualError(t, err, errSecretPayloadPermissionDenied)
  227. }
  228. func TestGetSecretNotFound(t *testing.T) {
  229. ctx := context.Background()
  230. namespace := uuid.NewString()
  231. authorizedKey := newFakeAuthorizedKey()
  232. fakeClock := clock.NewFakeClock()
  233. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  234. k8sClient := clientfake.NewClientBuilder().Build()
  235. const authorizedKeySecretName = "authorizedKeySecretName"
  236. const authorizedKeySecretKey = "authorizedKeySecretKey"
  237. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  238. tassert.Nil(t, err)
  239. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  240. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  241. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  242. tassert.Nil(t, err)
  243. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: "no-secret-with-this-id"})
  244. tassert.EqualError(t, err, errSecretPayloadNotFound)
  245. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  246. "folderId", "secretName",
  247. textEntry("k1", "v1"),
  248. )
  249. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: "no-version-with-this-id"})
  250. tassert.EqualError(t, err, errSecretPayloadVersionNotFound)
  251. }
  252. func TestGetSecretWithTwoNamespaces(t *testing.T) {
  253. ctx := context.Background()
  254. namespace1 := uuid.NewString()
  255. namespace2 := uuid.NewString()
  256. authorizedKey1 := newFakeAuthorizedKey()
  257. authorizedKey2 := newFakeAuthorizedKey()
  258. fakeClock := clock.NewFakeClock()
  259. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  260. k1, v1 := "k1", "v1"
  261. secretID1, _ := fakeLockboxServer.CreateSecret(authorizedKey1,
  262. "folderId", "secretName1",
  263. textEntry(k1, v1),
  264. )
  265. k2, v2 := "k2", "v2"
  266. secretID2, _ := fakeLockboxServer.CreateSecret(authorizedKey2,
  267. "folderId", "secretName2",
  268. textEntry(k2, v2),
  269. textEntry(k2, v2),
  270. )
  271. k8sClient := clientfake.NewClientBuilder().Build()
  272. const authorizedKeySecretName = "authorizedKeySecretName"
  273. const authorizedKeySecretKey = "authorizedKeySecretKey"
  274. err := createK8sSecret(ctx, t, k8sClient, namespace1, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey1))
  275. tassert.Nil(t, err)
  276. err = createK8sSecret(ctx, t, k8sClient, namespace2, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey2))
  277. tassert.Nil(t, err)
  278. store1 := newYandexLockboxSecretStore("", namespace1, authorizedKeySecretName, authorizedKeySecretKey)
  279. store2 := newYandexLockboxSecretStore("", namespace2, authorizedKeySecretName, authorizedKeySecretKey)
  280. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  281. secretsClient1, err := provider.NewClient(ctx, store1, k8sClient, namespace1)
  282. tassert.Nil(t, err)
  283. secretsClient2, err := provider.NewClient(ctx, store2, k8sClient, namespace2)
  284. tassert.Nil(t, err)
  285. data, err := secretsClient1.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID1, Property: k1})
  286. tassert.Equal(t, v1, string(data))
  287. tassert.Nil(t, err)
  288. data, err = secretsClient1.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID2, Property: k2})
  289. tassert.Nil(t, data)
  290. tassert.EqualError(t, err, errSecretPayloadPermissionDenied)
  291. data, err = secretsClient2.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID1, Property: k1})
  292. tassert.Nil(t, data)
  293. tassert.EqualError(t, err, errSecretPayloadPermissionDenied)
  294. data, err = secretsClient2.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID2, Property: k2})
  295. tassert.Equal(t, v2, string(data))
  296. tassert.Nil(t, err)
  297. }
  298. func TestGetSecretWithTwoApiEndpoints(t *testing.T) {
  299. ctx := context.Background()
  300. apiEndpoint1 := uuid.NewString()
  301. apiEndpoint2 := uuid.NewString()
  302. namespace := uuid.NewString()
  303. authorizedKey1 := newFakeAuthorizedKey()
  304. authorizedKey2 := newFakeAuthorizedKey()
  305. fakeClock := clock.NewFakeClock()
  306. fakeLockboxServer1 := client.NewFakeLockboxServer(fakeClock, time.Hour)
  307. k1, v1 := "k1", "v1"
  308. secretID1, _ := fakeLockboxServer1.CreateSecret(authorizedKey1,
  309. "folderId", "secretName",
  310. textEntry(k1, v1),
  311. )
  312. fakeLockboxServer2 := client.NewFakeLockboxServer(fakeClock, time.Hour)
  313. k2, v2 := "k2", "v2"
  314. secretID2, _ := fakeLockboxServer2.CreateSecret(authorizedKey2,
  315. "folderId", "secretName",
  316. textEntry(k2, v2),
  317. )
  318. k8sClient := clientfake.NewClientBuilder().Build()
  319. const authorizedKeySecretName1 = "authorizedKeySecretName1"
  320. const authorizedKeySecretKey1 = "authorizedKeySecretKey1"
  321. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName1, authorizedKeySecretKey1, toJSON(t, authorizedKey1))
  322. tassert.Nil(t, err)
  323. const authorizedKeySecretName2 = "authorizedKeySecretName2"
  324. const authorizedKeySecretKey2 = "authorizedKeySecretKey2"
  325. err = createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName2, authorizedKeySecretKey2, toJSON(t, authorizedKey2))
  326. tassert.Nil(t, err)
  327. store1 := newYandexLockboxSecretStore(apiEndpoint1, namespace, authorizedKeySecretName1, authorizedKeySecretKey1)
  328. store2 := newYandexLockboxSecretStore(apiEndpoint2, namespace, authorizedKeySecretName2, authorizedKeySecretKey2)
  329. provider1 := newLockboxProvider(fakeClock, fakeLockboxServer1)
  330. provider2 := newLockboxProvider(fakeClock, fakeLockboxServer2)
  331. secretsClient1, err := provider1.NewClient(ctx, store1, k8sClient, namespace)
  332. tassert.Nil(t, err)
  333. secretsClient2, err := provider2.NewClient(ctx, store2, k8sClient, namespace)
  334. tassert.Nil(t, err)
  335. var data []byte
  336. data, err = secretsClient1.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID1, Property: k1})
  337. tassert.Equal(t, v1, string(data))
  338. tassert.Nil(t, err)
  339. data, err = secretsClient1.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID2, Property: k2})
  340. tassert.Nil(t, data)
  341. tassert.EqualError(t, err, errSecretPayloadNotFound)
  342. data, err = secretsClient2.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID1, Property: k1})
  343. tassert.Nil(t, data)
  344. tassert.EqualError(t, err, errSecretPayloadNotFound)
  345. data, err = secretsClient2.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID2, Property: k2})
  346. tassert.Equal(t, v2, string(data))
  347. tassert.Nil(t, err)
  348. }
  349. func TestGetSecretWithIamTokenExpiration(t *testing.T) {
  350. ctx := context.Background()
  351. namespace := uuid.NewString()
  352. authorizedKey := newFakeAuthorizedKey()
  353. fakeClock := clock.NewFakeClock()
  354. tokenExpirationTime := time.Hour
  355. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, tokenExpirationTime)
  356. k1, v1 := "k1", "v1"
  357. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  358. "folderId", "secretName",
  359. textEntry(k1, v1),
  360. )
  361. k8sClient := clientfake.NewClientBuilder().Build()
  362. const authorizedKeySecretName = "authorizedKeySecretName"
  363. const authorizedKeySecretKey = "authorizedKeySecretKey"
  364. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  365. tassert.Nil(t, err)
  366. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  367. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  368. var data []byte
  369. oldSecretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  370. tassert.Nil(t, err)
  371. data, err = oldSecretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k1})
  372. tassert.Equal(t, v1, string(data))
  373. tassert.Nil(t, err)
  374. fakeClock.AddDuration(2 * tokenExpirationTime)
  375. data, err = oldSecretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k1})
  376. tassert.Nil(t, data)
  377. tassert.EqualError(t, err, "unable to request secret payload to get secret: iam token expired")
  378. newSecretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  379. tassert.Nil(t, err)
  380. data, err = newSecretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k1})
  381. tassert.Equal(t, v1, string(data))
  382. tassert.Nil(t, err)
  383. }
  384. func TestGetSecretWithIamTokenCleanup(t *testing.T) {
  385. ctx := context.Background()
  386. namespace := uuid.NewString()
  387. authorizedKey1 := newFakeAuthorizedKey()
  388. authorizedKey2 := newFakeAuthorizedKey()
  389. fakeClock := clock.NewFakeClock()
  390. tokenExpirationDuration := time.Hour
  391. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, tokenExpirationDuration)
  392. secretID1, _ := fakeLockboxServer.CreateSecret(authorizedKey1,
  393. "folderId", "secretName1",
  394. textEntry("k1", "v1"),
  395. )
  396. secretID2, _ := fakeLockboxServer.CreateSecret(authorizedKey2,
  397. "folderId", "secretName2",
  398. textEntry("k2", "v2"),
  399. )
  400. var err error
  401. k8sClient := clientfake.NewClientBuilder().Build()
  402. const authorizedKeySecretName1 = "authorizedKeySecretName1"
  403. const authorizedKeySecretKey1 = "authorizedKeySecretKey1"
  404. err = createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName1, authorizedKeySecretKey1, toJSON(t, authorizedKey1))
  405. tassert.Nil(t, err)
  406. const authorizedKeySecretName2 = "authorizedKeySecretName2"
  407. const authorizedKeySecretKey2 = "authorizedKeySecretKey2"
  408. err = createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName2, authorizedKeySecretKey2, toJSON(t, authorizedKey2))
  409. tassert.Nil(t, err)
  410. store1 := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName1, authorizedKeySecretKey1)
  411. store2 := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName2, authorizedKeySecretKey2)
  412. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  413. tassert.False(t, provider.IsIamTokenCached(authorizedKey1))
  414. tassert.False(t, provider.IsIamTokenCached(authorizedKey2))
  415. // Access secretID1 with authorizedKey1, IAM token for authorizedKey1 should be cached
  416. secretsClient, err := provider.NewClient(ctx, store1, k8sClient, namespace)
  417. tassert.Nil(t, err)
  418. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID1})
  419. tassert.Nil(t, err)
  420. tassert.True(t, provider.IsIamTokenCached(authorizedKey1))
  421. tassert.False(t, provider.IsIamTokenCached(authorizedKey2))
  422. fakeClock.AddDuration(tokenExpirationDuration * 2)
  423. // Access secretID2 with authorizedKey2, IAM token for authorizedKey2 should be cached
  424. secretsClient, err = provider.NewClient(ctx, store2, k8sClient, namespace)
  425. tassert.Nil(t, err)
  426. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID2})
  427. tassert.Nil(t, err)
  428. tassert.True(t, provider.IsIamTokenCached(authorizedKey1))
  429. tassert.True(t, provider.IsIamTokenCached(authorizedKey2))
  430. fakeClock.AddDuration(tokenExpirationDuration)
  431. tassert.True(t, provider.IsIamTokenCached(authorizedKey1))
  432. tassert.True(t, provider.IsIamTokenCached(authorizedKey2))
  433. provider.CleanUpIamTokenMap()
  434. tassert.False(t, provider.IsIamTokenCached(authorizedKey1))
  435. tassert.True(t, provider.IsIamTokenCached(authorizedKey2))
  436. fakeClock.AddDuration(tokenExpirationDuration)
  437. tassert.False(t, provider.IsIamTokenCached(authorizedKey1))
  438. tassert.True(t, provider.IsIamTokenCached(authorizedKey2))
  439. provider.CleanUpIamTokenMap()
  440. tassert.False(t, provider.IsIamTokenCached(authorizedKey1))
  441. tassert.False(t, provider.IsIamTokenCached(authorizedKey2))
  442. }
  443. func TestGetSecretMap(t *testing.T) {
  444. ctx := context.Background()
  445. namespace := uuid.NewString()
  446. authorizedKey := newFakeAuthorizedKey()
  447. fakeClock := clock.NewFakeClock()
  448. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  449. k1, v1 := "k1", "v1"
  450. k2, v2 := "k2", []byte("v2")
  451. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  452. "folderId", "secretName",
  453. textEntry(k1, v1),
  454. binaryEntry(k2, v2),
  455. )
  456. k8sClient := clientfake.NewClientBuilder().Build()
  457. const authorizedKeySecretName = "authorizedKeySecretName"
  458. const authorizedKeySecretKey = "authorizedKeySecretKey"
  459. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  460. tassert.Nil(t, err)
  461. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  462. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  463. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  464. tassert.Nil(t, err)
  465. data, err := secretsClient.GetSecretMap(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID})
  466. tassert.Nil(t, err)
  467. tassert.Equal(
  468. t,
  469. map[string][]byte{
  470. k1: []byte(v1),
  471. k2: v2,
  472. },
  473. data,
  474. )
  475. }
  476. func TestGetSecretMapByVersionID(t *testing.T) {
  477. ctx := context.Background()
  478. namespace := uuid.NewString()
  479. authorizedKey := newFakeAuthorizedKey()
  480. fakeClock := clock.NewFakeClock()
  481. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  482. oldKey, oldVal := "oldKey", "oldVal"
  483. secretID, oldVersionID := fakeLockboxServer.CreateSecret(authorizedKey,
  484. "folderId", "secretName",
  485. textEntry(oldKey, oldVal),
  486. )
  487. k8sClient := clientfake.NewClientBuilder().Build()
  488. const authorizedKeySecretName = "authorizedKeySecretName"
  489. const authorizedKeySecretKey = "authorizedKeySecretKey"
  490. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  491. tassert.Nil(t, err)
  492. store := newYandexLockboxSecretStore("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  493. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  494. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  495. tassert.Nil(t, err)
  496. data, err := secretsClient.GetSecretMap(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: oldVersionID})
  497. tassert.Nil(t, err)
  498. tassert.Equal(t, map[string][]byte{oldKey: []byte(oldVal)}, data)
  499. newKey, newVal := "newKey", "newVal"
  500. newVersionID := fakeLockboxServer.AddVersion(secretID, textEntry(newKey, newVal))
  501. data, err = secretsClient.GetSecretMap(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: oldVersionID})
  502. tassert.Nil(t, err)
  503. tassert.Equal(t, map[string][]byte{oldKey: []byte(oldVal)}, data)
  504. data, err = secretsClient.GetSecretMap(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Version: newVersionID})
  505. tassert.Nil(t, err)
  506. tassert.Equal(t, map[string][]byte{newKey: []byte(newVal)}, data)
  507. }
  508. func TestGetSecretWithByNameFetchingPolicyForAllEntries(t *testing.T) {
  509. ctx := context.Background()
  510. namespace := uuid.NewString()
  511. authorizedKey := newFakeAuthorizedKey()
  512. fakeClock := clock.NewFakeClock()
  513. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  514. folderID := uuid.NewString()
  515. const secretName = "secretName"
  516. k1, v1 := "k1", "v1"
  517. k2, v2 := "k2", []byte("v2")
  518. _, _ = fakeLockboxServer.CreateSecret(authorizedKey, folderID, secretName, textEntry(k1, v1), binaryEntry(k2, v2))
  519. k8sClient := clientfake.NewClientBuilder().Build()
  520. const authorizedKeySecretName = "authorizedKeySecretName"
  521. const authorizedKeySecretKey = "authorizedKeySecretKey"
  522. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  523. tassert.Nil(t, err)
  524. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID)
  525. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  526. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  527. tassert.Nil(t, err)
  528. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName})
  529. tassert.Nil(t, err)
  530. expected := map[string]string{
  531. k1: base64([]byte(v1)),
  532. k2: base64(v2),
  533. }
  534. tassert.Equal(t, expected, unmarshalStringMap(t, data))
  535. }
  536. func TestGetSecretWithByNameFetchingPolicyAndVersionID(t *testing.T) {
  537. ctx := context.Background()
  538. namespace := uuid.NewString()
  539. authorizedKey := newFakeAuthorizedKey()
  540. fakeClock := clock.NewFakeClock()
  541. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  542. folderID := uuid.NewString()
  543. const secretName = "secretName"
  544. oldKey, oldVal := "oldKey", "oldVal"
  545. secretID, oldVersionID := fakeLockboxServer.CreateSecret(authorizedKey, folderID, secretName, textEntry(oldKey, oldVal))
  546. k8sClient := clientfake.NewClientBuilder().Build()
  547. const authorizedKeySecretName = "authorizedKeySecretName"
  548. const authorizedKeySecretKey = "authorizedKeySecretKey"
  549. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  550. tassert.Nil(t, err)
  551. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID)
  552. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  553. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  554. tassert.Nil(t, err)
  555. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName, Version: oldVersionID})
  556. tassert.Nil(t, err)
  557. tassert.Equal(t, map[string]string{oldKey: base64([]byte(oldVal))}, unmarshalStringMap(t, data))
  558. newKey, newVal := "newKey", "newVal"
  559. newVersionID := fakeLockboxServer.AddVersion(secretID, textEntry(newKey, newVal))
  560. data, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName, Version: oldVersionID})
  561. tassert.Nil(t, err)
  562. tassert.Equal(t, map[string]string{oldKey: base64([]byte(oldVal))}, unmarshalStringMap(t, data))
  563. data, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName, Version: newVersionID})
  564. tassert.Nil(t, err)
  565. tassert.Equal(t, map[string]string{newKey: base64([]byte(newVal))}, unmarshalStringMap(t, data))
  566. }
  567. func TestGetSecretWithByNameFetchingPolicyForTextEntry(t *testing.T) {
  568. ctx := context.Background()
  569. namespace := uuid.NewString()
  570. authorizedKey := newFakeAuthorizedKey()
  571. fakeClock := clock.NewFakeClock()
  572. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  573. folderID := uuid.NewString()
  574. const secretName = "secretName"
  575. k1, v1 := "k1", "v1"
  576. k2, v2 := "k2", []byte("v2")
  577. _, _ = fakeLockboxServer.CreateSecret(authorizedKey, folderID, secretName, textEntry(k1, v1), binaryEntry(k2, v2))
  578. k8sClient := clientfake.NewClientBuilder().Build()
  579. const authorizedKeySecretName = "authorizedKeySecretName"
  580. const authorizedKeySecretKey = "authorizedKeySecretKey"
  581. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  582. tassert.Nil(t, err)
  583. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID)
  584. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  585. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  586. tassert.Nil(t, err)
  587. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName, Property: k1})
  588. tassert.Nil(t, err)
  589. tassert.Equal(t, v1, string(data))
  590. }
  591. func TestGetSecretWithByNameFetchingPolicyForBinaryEntry(t *testing.T) {
  592. ctx := context.Background()
  593. namespace := uuid.NewString()
  594. authorizedKey := newFakeAuthorizedKey()
  595. fakeClock := clock.NewFakeClock()
  596. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  597. folderID := uuid.NewString()
  598. const secretName = "secretName"
  599. k1, v1 := "k1", "v1"
  600. k2, v2 := "k2", []byte("v2")
  601. _, _ = fakeLockboxServer.CreateSecret(authorizedKey, folderID, secretName, textEntry(k1, v1), binaryEntry(k2, v2))
  602. k8sClient := clientfake.NewClientBuilder().Build()
  603. const authorizedKeySecretName = "authorizedKeySecretName"
  604. const authorizedKeySecretKey = "authorizedKeySecretKey"
  605. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  606. tassert.Nil(t, err)
  607. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID)
  608. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  609. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  610. tassert.Nil(t, err)
  611. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName, Property: k2})
  612. tassert.Nil(t, err)
  613. tassert.Equal(t, v2, data)
  614. }
  615. func TestGetSecretWithByNameFetchingPolicyNotFound(t *testing.T) {
  616. ctx := context.Background()
  617. namespace := uuid.NewString()
  618. authorizedKey := newFakeAuthorizedKey()
  619. fakeClock := clock.NewFakeClock()
  620. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  621. folderID := uuid.NewString()
  622. k8sClient := clientfake.NewClientBuilder().Build()
  623. const authorizedKeySecretName = "authorizedKeySecretName"
  624. const authorizedKeySecretKey = "authorizedKeySecretKey"
  625. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  626. tassert.Nil(t, err)
  627. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID)
  628. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  629. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  630. tassert.Nil(t, err)
  631. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: "no-secret-with-such-name"})
  632. tassert.EqualError(t, err, errSecretPayloadNotFound)
  633. secretName := "secretName"
  634. _, _ = fakeLockboxServer.CreateSecret(authorizedKey, folderID, secretName, textEntry("k1", "v1"))
  635. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName, Version: "no-version-with-such-id"})
  636. tassert.EqualError(t, err, errSecretPayloadVersionNotFound)
  637. }
  638. func TestGetSecretWithByNameFetchingPolicyUnauthorized(t *testing.T) {
  639. ctx := context.Background()
  640. namespace := uuid.NewString()
  641. authorizedKeyA := newFakeAuthorizedKey()
  642. authorizedKeyB := newFakeAuthorizedKey()
  643. fakeClock := clock.NewFakeClock()
  644. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  645. folderID := uuid.NewString()
  646. secretName := "secretName"
  647. _, _ = fakeLockboxServer.CreateSecret(authorizedKeyA, folderID, secretName, textEntry("k1", "v1"))
  648. k8sClient := clientfake.NewClientBuilder().Build()
  649. const authorizedKeySecretName = "authorizedKeySecretName"
  650. const authorizedKeySecretKey = "authorizedKeySecretKey"
  651. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKeyB))
  652. tassert.Nil(t, err)
  653. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID)
  654. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  655. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  656. tassert.Nil(t, err)
  657. _, err = secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretName})
  658. tassert.EqualError(t, err, errSecretPayloadPermissionDenied)
  659. }
  660. func TestGetSecretWithByNameFetchingPolicyWithoutFolderID(t *testing.T) {
  661. ctx := context.Background()
  662. namespace := uuid.NewString()
  663. authorizedKey := newFakeAuthorizedKey()
  664. fakeClock := clock.NewFakeClock()
  665. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  666. k8sClient := clientfake.NewClientBuilder().Build()
  667. const authorizedKeySecretName = "authorizedKeySecretName"
  668. const authorizedKeySecretKey = "authorizedKeySecretKey"
  669. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  670. tassert.Nil(t, err)
  671. store := newYandexLockboxSecretStoreWithFetchByName("", namespace, authorizedKeySecretName, authorizedKeySecretKey, "")
  672. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  673. _, err = provider.NewClient(ctx, store, k8sClient, namespace)
  674. tassert.EqualError(t, err, "folderID is required when fetching policy is 'byName'")
  675. }
  676. func TesGetSecretWithByIDFetchingPolicyForAllEntries(t *testing.T) {
  677. ctx := context.Background()
  678. namespace := uuid.NewString()
  679. authorizedKey := newFakeAuthorizedKey()
  680. fakeClock := clock.NewFakeClock()
  681. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  682. k1, v1 := "k1", "v1"
  683. k2, v2 := "k2", []byte("v2")
  684. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  685. "folderId", "secret",
  686. textEntry(k1, v1),
  687. binaryEntry(k2, v2),
  688. )
  689. k8sClient := clientfake.NewClientBuilder().Build()
  690. const authorizedKeySecretName = "authorizedKeySecretName"
  691. const authorizedKeySecretKey = "authorizedKeySecretKey"
  692. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  693. tassert.Nil(t, err)
  694. store := newYandexLockboxSecretStoreWithFetchByID("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  695. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  696. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  697. tassert.Nil(t, err)
  698. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID})
  699. tassert.Nil(t, err)
  700. expected := map[string]string{
  701. k1: v1,
  702. k2: base64(v2),
  703. }
  704. tassert.Equal(t, expected, unmarshalStringMap(t, data))
  705. }
  706. func TestGetSecretWithByIDFetchingPolicyForTextEntry(t *testing.T) {
  707. ctx := context.Background()
  708. namespace := uuid.NewString()
  709. authorizedKey := newFakeAuthorizedKey()
  710. fakeClock := clock.NewFakeClock()
  711. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  712. k1, v1 := "k1", "v1"
  713. k2, v2 := "k2", []byte("v2")
  714. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  715. "folderId", "secret",
  716. textEntry(k1, v1),
  717. binaryEntry(k2, v2),
  718. )
  719. k8sClient := clientfake.NewClientBuilder().Build()
  720. const authorizedKeySecretName = "authorizedKeySecretName"
  721. const authorizedKeySecretKey = "authorizedKeySecretKey"
  722. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  723. tassert.Nil(t, err)
  724. store := newYandexLockboxSecretStoreWithFetchByID("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  725. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  726. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  727. tassert.Nil(t, err)
  728. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k1})
  729. tassert.Nil(t, err)
  730. tassert.Equal(t, v1, string(data))
  731. }
  732. func TestGetSecretWithByIDFetchingPolicyForBinaryEntry(t *testing.T) {
  733. ctx := context.Background()
  734. namespace := uuid.NewString()
  735. authorizedKey := newFakeAuthorizedKey()
  736. fakeClock := clock.NewFakeClock()
  737. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  738. k1, v1 := "k1", "v1"
  739. k2, v2 := "k2", []byte("v2")
  740. secretID, _ := fakeLockboxServer.CreateSecret(authorizedKey,
  741. "folderId", "secret",
  742. textEntry(k1, v1),
  743. binaryEntry(k2, v2),
  744. )
  745. k8sClient := clientfake.NewClientBuilder().Build()
  746. const authorizedKeySecretName = "authorizedKeySecretName"
  747. const authorizedKeySecretKey = "authorizedKeySecretKey"
  748. err := createK8sSecret(ctx, t, k8sClient, namespace, authorizedKeySecretName, authorizedKeySecretKey, toJSON(t, authorizedKey))
  749. tassert.Nil(t, err)
  750. store := newYandexLockboxSecretStoreWithFetchByID("", namespace, authorizedKeySecretName, authorizedKeySecretKey)
  751. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  752. secretsClient, err := provider.NewClient(ctx, store, k8sClient, namespace)
  753. tassert.Nil(t, err)
  754. data, err := secretsClient.GetSecret(ctx, esv1.ExternalSecretDataRemoteRef{Key: secretID, Property: k2})
  755. tassert.Nil(t, err)
  756. tassert.Equal(t, v2, data)
  757. }
  758. func TestGetSecretWithInvalidFetchingPolicy(t *testing.T) {
  759. ctx := context.Background()
  760. namespace := uuid.NewString()
  761. authorizedKey := newFakeAuthorizedKey()
  762. fakeClock := clock.NewFakeClock()
  763. fakeLockboxServer := client.NewFakeLockboxServer(fakeClock, time.Hour)
  764. k8sClient := clientfake.NewClientBuilder().Build()
  765. const authorizedKeySecretName = "authorizedKeySecretName"
  766. const authorizedKeySecretKey = "authorizedKeySecretKey"
  767. err := createK8sSecret(
  768. ctx, t, k8sClient, namespace,
  769. authorizedKeySecretName, authorizedKeySecretKey,
  770. toJSON(t, authorizedKey),
  771. )
  772. tassert.Nil(t, err)
  773. store := &esv1.SecretStore{
  774. ObjectMeta: metav1.ObjectMeta{Namespace: namespace},
  775. Spec: esv1.SecretStoreSpec{
  776. Provider: &esv1.SecretStoreProvider{
  777. YandexLockbox: &esv1.YandexLockboxProvider{
  778. Auth: esv1.YandexAuth{
  779. AuthorizedKey: esmeta.SecretKeySelector{
  780. Name: authorizedKeySecretName,
  781. Key: authorizedKeySecretKey,
  782. },
  783. },
  784. FetchingPolicy: &esv1.FetchingPolicy{
  785. ByID: nil,
  786. ByName: nil,
  787. },
  788. },
  789. },
  790. },
  791. }
  792. provider := newLockboxProvider(fakeClock, fakeLockboxServer)
  793. _, err = provider.NewClient(ctx, store, k8sClient, namespace)
  794. tassert.EqualError(
  795. t,
  796. err,
  797. "invalid Yandex Lockbox SecretStore: requires either 'byName' or 'byID' policy",
  798. )
  799. }
  800. // helper fuxnctions
  801. func newLockboxProvider(clock clock.Clock, fakeLockboxServer *client.FakeLockboxServer) *ydxcommon.YandexCloudProvider {
  802. return ydxcommon.InitYandexCloudProvider(
  803. ctrl.Log.WithName("provider").WithName("yandex").WithName("lockbox"),
  804. clock,
  805. adaptInput,
  806. func(context.Context, string, *iamkey.Key, []byte) (ydxcommon.SecretGetter, error) {
  807. return newLockboxSecretGetter(client.NewFakeLockboxClient(fakeLockboxServer))
  808. },
  809. func(_ context.Context, _ string, authorizedKey *iamkey.Key, _ []byte) (*ydxcommon.IamToken, error) {
  810. return fakeLockboxServer.NewIamToken(authorizedKey), nil
  811. },
  812. 0,
  813. )
  814. }
  815. func newYandexLockboxSecretStore(apiEndpoint, namespace, authorizedKeySecretName, authorizedKeySecretKey string) esv1.GenericStore {
  816. return &esv1.SecretStore{
  817. ObjectMeta: metav1.ObjectMeta{
  818. Namespace: namespace,
  819. },
  820. Spec: esv1.SecretStoreSpec{
  821. Provider: &esv1.SecretStoreProvider{
  822. YandexLockbox: &esv1.YandexLockboxProvider{
  823. APIEndpoint: apiEndpoint,
  824. Auth: esv1.YandexAuth{
  825. AuthorizedKey: esmeta.SecretKeySelector{
  826. Name: authorizedKeySecretName,
  827. Key: authorizedKeySecretKey,
  828. },
  829. },
  830. },
  831. },
  832. },
  833. }
  834. }
  835. func newYandexLockboxSecretStoreWithFetchByName(apiEndpoint, namespace, authorizedKeySecretName, authorizedKeySecretKey, folderID string) esv1.GenericStore {
  836. return &esv1.SecretStore{
  837. ObjectMeta: metav1.ObjectMeta{
  838. Namespace: namespace,
  839. },
  840. Spec: esv1.SecretStoreSpec{
  841. Provider: &esv1.SecretStoreProvider{
  842. YandexLockbox: &esv1.YandexLockboxProvider{
  843. APIEndpoint: apiEndpoint,
  844. Auth: esv1.YandexAuth{
  845. AuthorizedKey: esmeta.SecretKeySelector{
  846. Name: authorizedKeySecretName,
  847. Key: authorizedKeySecretKey,
  848. },
  849. },
  850. FetchingPolicy: &esv1.FetchingPolicy{
  851. ByName: &esv1.ByName{
  852. FolderID: folderID,
  853. },
  854. },
  855. },
  856. },
  857. },
  858. }
  859. }
  860. func newYandexLockboxSecretStoreWithFetchByID(apiEndpoint, namespace, authorizedKeySecretName, authorizedKeySecretKey string) esv1.GenericStore {
  861. return &esv1.SecretStore{
  862. ObjectMeta: metav1.ObjectMeta{
  863. Namespace: namespace,
  864. },
  865. Spec: esv1.SecretStoreSpec{
  866. Provider: &esv1.SecretStoreProvider{
  867. YandexLockbox: &esv1.YandexLockboxProvider{
  868. APIEndpoint: apiEndpoint,
  869. Auth: esv1.YandexAuth{
  870. AuthorizedKey: esmeta.SecretKeySelector{
  871. Name: authorizedKeySecretName,
  872. Key: authorizedKeySecretKey,
  873. },
  874. },
  875. FetchingPolicy: &esv1.FetchingPolicy{
  876. ByID: &esv1.ByID{},
  877. },
  878. },
  879. },
  880. },
  881. }
  882. }
  883. func toJSON(t *testing.T, v any) []byte {
  884. jsonBytes, err := json.Marshal(v)
  885. tassert.Nil(t, err)
  886. return jsonBytes
  887. }
  888. func createK8sSecret(ctx context.Context, t *testing.T, k8sClient k8sclient.Client, namespace, secretName, secretKey string, secretValue []byte) error {
  889. err := k8sClient.Create(ctx, &corev1.Secret{
  890. ObjectMeta: metav1.ObjectMeta{
  891. Namespace: namespace,
  892. Name: secretName,
  893. },
  894. Data: map[string][]byte{secretKey: secretValue},
  895. })
  896. tassert.Nil(t, err)
  897. return nil
  898. }
  899. func newFakeAuthorizedKey() *iamkey.Key {
  900. uniqueLabel := uuid.NewString()
  901. return &iamkey.Key{
  902. Id: uniqueLabel,
  903. Subject: &iamkey.Key_ServiceAccountId{
  904. ServiceAccountId: uniqueLabel,
  905. },
  906. PrivateKey: uniqueLabel,
  907. }
  908. }
  909. func textEntry(key, value string) *lockbox.Payload_Entry {
  910. return &lockbox.Payload_Entry{
  911. Key: key,
  912. Value: &lockbox.Payload_Entry_TextValue{
  913. TextValue: value,
  914. },
  915. }
  916. }
  917. func binaryEntry(key string, value []byte) *lockbox.Payload_Entry {
  918. return &lockbox.Payload_Entry{
  919. Key: key,
  920. Value: &lockbox.Payload_Entry_BinaryValue{
  921. BinaryValue: value,
  922. },
  923. }
  924. }
  925. func unmarshalStringMap(t *testing.T, data []byte) map[string]string {
  926. stringMap := make(map[string]string)
  927. err := json.Unmarshal(data, &stringMap)
  928. tassert.Nil(t, err)
  929. return stringMap
  930. }
  931. func base64(data []byte) string {
  932. return b64.StdEncoding.EncodeToString(data)
  933. }