main.go 1.9 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182
  1. package main
  2. import (
  3. "fmt"
  4. "log"
  5. "github.com/porter-dev/porter/api/server/shared/config/loader"
  6. "github.com/porter-dev/porter/cmd/migrate/keyrotate"
  7. adapter "github.com/porter-dev/porter/internal/adapter"
  8. lr "github.com/porter-dev/porter/internal/logger"
  9. "github.com/porter-dev/porter/internal/repository/gorm"
  10. "github.com/joeshaw/envdecode"
  11. )
  12. func main() {
  13. logger := lr.NewConsole(true)
  14. fmt.Println("running migrations...")
  15. envConf, err := loader.FromEnv()
  16. if err != nil {
  17. logger.Fatal().Err(err).Msg("")
  18. return
  19. }
  20. db, err := adapter.New(envConf.DBConf)
  21. if err != nil {
  22. logger.Fatal().Err(err).Msg("")
  23. return
  24. }
  25. err = gorm.AutoMigrate(db)
  26. if err != nil {
  27. logger.Fatal().Err(err).Msg("")
  28. return
  29. }
  30. if err := db.Raw("ALTER TABLE clusters DROP CONSTRAINT IF EXISTS fk_cluster_token_caches").Error; err != nil {
  31. logger.Fatal().Err(err).Msg("")
  32. return
  33. }
  34. if err := db.Raw("ALTER TABLE cluster_token_caches DROP CONSTRAINT IF EXISTS fk_clusters_token_cache").Error; err != nil {
  35. logger.Fatal().Err(err).Msg("")
  36. return
  37. }
  38. if shouldRotate, oldKeyStr, newKeyStr := shouldKeyRotate(); shouldRotate {
  39. oldKey := [32]byte{}
  40. newKey := [32]byte{}
  41. copy(oldKey[:], []byte(oldKeyStr))
  42. copy(newKey[:], []byte(newKeyStr))
  43. err := keyrotate.Rotate(db, &oldKey, &newKey)
  44. if err != nil {
  45. panic(err)
  46. }
  47. }
  48. }
  49. type RotateConf struct {
  50. // we add a dummy field to avoid empty struct issue with envdecode
  51. DummyField string `env:"ASDF,default=asdf"`
  52. OldEncryptionKey string `env:"OLD_ENCRYPTION_KEY"`
  53. NewEncryptionKey string `env:"NEW_ENCRYPTION_KEY"`
  54. }
  55. func shouldKeyRotate() (bool, string, string) {
  56. var c RotateConf
  57. if err := envdecode.StrictDecode(&c); err != nil {
  58. log.Fatalf("Failed to decode migration conf: %s", err)
  59. return false, "", ""
  60. }
  61. return c.OldEncryptionKey != "" && c.NewEncryptionKey != "", c.OldEncryptionKey, c.NewEncryptionKey
  62. }