fake.go 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237
  1. /*
  2. Copyright © The ESO Authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. https://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package fake
  14. import (
  15. "context"
  16. "maps"
  17. "sync"
  18. corev1 "k8s.io/api/core/v1"
  19. "sigs.k8s.io/controller-runtime/pkg/client"
  20. "sigs.k8s.io/controller-runtime/pkg/webhook/admission"
  21. esv1 "github.com/external-secrets/external-secrets/apis/externalsecrets/v1"
  22. "github.com/external-secrets/external-secrets/runtime/esutils"
  23. )
  24. var _ esv1.Provider = &Client{}
  25. type SetSecretCallArgs struct {
  26. Value []byte
  27. RemoteRef esv1.PushSecretRemoteRef
  28. }
  29. // Client is a fake client for testing.
  30. type Client struct {
  31. mu sync.RWMutex
  32. pushSecretData map[string]SetSecretCallArgs
  33. NewFn func(context.Context, esv1.GenericStore, client.Client, string) (esv1.SecretsClient, error)
  34. GetSecretFn func(context.Context, esv1.ExternalSecretDataRemoteRef) ([]byte, error)
  35. GetSecretMapFn func(context.Context, esv1.ExternalSecretDataRemoteRef) (map[string][]byte, error)
  36. GetAllSecretsFn func(context.Context, esv1.ExternalSecretFind) (map[string][]byte, error)
  37. SecretExistsFn func(context.Context, esv1.PushSecretRemoteRef) (bool, error)
  38. SetSecretFn func() error
  39. DeleteSecretFn func() error
  40. }
  41. // New returns a fake provider/client with default no-op behavior.
  42. func New() *Client {
  43. v := &Client{}
  44. v.Reset()
  45. return v
  46. }
  47. // RegisterAs registers the fake client in the schema.
  48. func (v *Client) RegisterAs(provider *esv1.SecretStoreProvider) {
  49. esv1.ForceRegister(v, provider, esv1.MaintenanceStatusMaintained)
  50. }
  51. // GetAllSecrets implements the provider.Provider interface.
  52. func (v *Client) GetAllSecrets(ctx context.Context, ref esv1.ExternalSecretFind) (map[string][]byte, error) {
  53. v.mu.RLock()
  54. fn := v.GetAllSecretsFn
  55. v.mu.RUnlock()
  56. return fn(ctx, ref)
  57. }
  58. func (v *Client) PushSecret(_ context.Context, secret *corev1.Secret, data esv1.PushSecretData) error {
  59. v.mu.Lock()
  60. value, _ := esutils.ExtractSecretData(data, secret)
  61. v.pushSecretData[data.GetRemoteKey()] = SetSecretCallArgs{
  62. Value: value,
  63. RemoteRef: data,
  64. }
  65. fn := v.SetSecretFn
  66. v.mu.Unlock()
  67. return fn()
  68. }
  69. // GetPushSecretData safely retrieves the push secret data map for reading.
  70. func (v *Client) GetPushSecretData() map[string]SetSecretCallArgs {
  71. v.mu.RLock()
  72. defer v.mu.RUnlock()
  73. result := make(map[string]SetSecretCallArgs, len(v.pushSecretData))
  74. maps.Copy(result, v.pushSecretData)
  75. return result
  76. }
  77. func (v *Client) DeleteSecret(_ context.Context, _ esv1.PushSecretRemoteRef) error {
  78. v.mu.RLock()
  79. fn := v.DeleteSecretFn
  80. v.mu.RUnlock()
  81. return fn()
  82. }
  83. func (v *Client) SecretExists(ctx context.Context, ref esv1.PushSecretRemoteRef) (bool, error) {
  84. v.mu.RLock()
  85. fn := v.SecretExistsFn
  86. v.mu.RUnlock()
  87. return fn(ctx, ref)
  88. }
  89. // GetSecret implements the provider.Provider interface.
  90. func (v *Client) GetSecret(ctx context.Context, ref esv1.ExternalSecretDataRemoteRef) ([]byte, error) {
  91. v.mu.RLock()
  92. fn := v.GetSecretFn
  93. v.mu.RUnlock()
  94. return fn(ctx, ref)
  95. }
  96. // WithGetSecret wraps secret data returned by this provider.
  97. func (v *Client) WithGetSecret(secData []byte, err error) *Client {
  98. v.mu.Lock()
  99. v.GetSecretFn = func(context.Context, esv1.ExternalSecretDataRemoteRef) ([]byte, error) {
  100. return secData, err
  101. }
  102. v.mu.Unlock()
  103. return v
  104. }
  105. // GetSecretMap implements the provider.Provider interface.
  106. func (v *Client) GetSecretMap(ctx context.Context, ref esv1.ExternalSecretDataRemoteRef) (map[string][]byte, error) {
  107. v.mu.RLock()
  108. fn := v.GetSecretMapFn
  109. v.mu.RUnlock()
  110. return fn(ctx, ref)
  111. }
  112. func (v *Client) Close(_ context.Context) error {
  113. return nil
  114. }
  115. func (v *Client) Validate() (esv1.ValidationResult, error) {
  116. return esv1.ValidationResultReady, nil
  117. }
  118. func (v *Client) ValidateStore(_ esv1.GenericStore) (admission.Warnings, error) {
  119. return nil, nil
  120. }
  121. // WithGetSecretMap wraps the secret data map returned by this fake provider.
  122. func (v *Client) WithGetSecretMap(secData map[string][]byte, err error) *Client {
  123. v.mu.Lock()
  124. v.GetSecretMapFn = func(context.Context, esv1.ExternalSecretDataRemoteRef) (map[string][]byte, error) {
  125. return secData, err
  126. }
  127. v.mu.Unlock()
  128. return v
  129. }
  130. // WithGetAllSecrets wraps the secret data map returned by this fake provider.
  131. func (v *Client) WithGetAllSecrets(secData map[string][]byte, err error) *Client {
  132. v.mu.Lock()
  133. v.GetAllSecretsFn = func(context.Context, esv1.ExternalSecretFind) (map[string][]byte, error) {
  134. return secData, err
  135. }
  136. v.mu.Unlock()
  137. return v
  138. }
  139. // WithSetSecretFn installs a custom SetSecret function under the client lock.
  140. func (v *Client) WithSetSecretFn(fn func() error) *Client {
  141. v.mu.Lock()
  142. v.SetSecretFn = fn
  143. v.mu.Unlock()
  144. return v
  145. }
  146. // WithDeleteSecretFn installs a custom DeleteSecret function under the client lock.
  147. func (v *Client) WithDeleteSecretFn(fn func() error) *Client {
  148. v.mu.Lock()
  149. v.DeleteSecretFn = fn
  150. v.mu.Unlock()
  151. return v
  152. }
  153. // WithSecretExistsFn installs a custom SecretExists function under the client lock.
  154. func (v *Client) WithSecretExistsFn(fn func(context.Context, esv1.PushSecretRemoteRef) (bool, error)) *Client {
  155. v.mu.Lock()
  156. v.SecretExistsFn = fn
  157. v.mu.Unlock()
  158. return v
  159. }
  160. // WithNew wraps the fake provider factory function.
  161. func (v *Client) WithNew(f func(context.Context, esv1.GenericStore, client.Client,
  162. string) (esv1.SecretsClient, error)) *Client {
  163. v.mu.Lock()
  164. v.NewFn = f
  165. v.mu.Unlock()
  166. return v
  167. }
  168. // Capabilities return the provider supported capabilities (ReadOnly, WriteOnly, ReadWrite).
  169. func (v *Client) Capabilities() esv1.SecretStoreCapabilities {
  170. return esv1.SecretStoreReadOnly
  171. }
  172. // NewClient returns a new fake provider.
  173. func (v *Client) NewClient(ctx context.Context, store esv1.GenericStore, kube client.Client, namespace string) (esv1.SecretsClient, error) {
  174. v.mu.RLock()
  175. fn := v.NewFn
  176. v.mu.RUnlock()
  177. return fn(ctx, store, kube, namespace)
  178. }
  179. // Reset restores all functions to their default no-op behavior and clears recorded push data.
  180. func (v *Client) Reset() {
  181. v.mu.Lock()
  182. defer v.mu.Unlock()
  183. v.NewFn = func(context.Context, esv1.GenericStore, client.Client, string) (esv1.SecretsClient, error) {
  184. return v, nil
  185. }
  186. v.GetSecretFn = func(context.Context, esv1.ExternalSecretDataRemoteRef) ([]byte, error) {
  187. return nil, nil
  188. }
  189. v.GetSecretMapFn = func(context.Context, esv1.ExternalSecretDataRemoteRef) (map[string][]byte, error) {
  190. return nil, nil
  191. }
  192. v.GetAllSecretsFn = func(context.Context, esv1.ExternalSecretFind) (map[string][]byte, error) {
  193. return nil, nil
  194. }
  195. v.SecretExistsFn = func(context.Context, esv1.PushSecretRemoteRef) (bool, error) {
  196. return false, nil
  197. }
  198. v.SetSecretFn = func() error {
  199. return nil
  200. }
  201. v.DeleteSecretFn = func() error {
  202. return nil
  203. }
  204. v.pushSecretData = map[string]SetSecretCallArgs{}
  205. }