rotate_test.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610
  1. package keyrotate_test
  2. import (
  3. "testing"
  4. "github.com/porter-dev/porter/cmd/migrate/keyrotate"
  5. "github.com/porter-dev/porter/internal/models"
  6. ints "github.com/porter-dev/porter/internal/models/integrations"
  7. gorm "github.com/porter-dev/porter/internal/repository/gorm"
  8. )
  9. func TestClusterModelRotation(t *testing.T) {
  10. var newKey [32]byte
  11. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  12. newKey[i] = b
  13. }
  14. tester := &tester{
  15. dbFileName: "./porter_cluster_rotate.db",
  16. }
  17. setupTestEnv(tester, t)
  18. for i := 0; i < 128; i++ {
  19. initCluster(tester, t)
  20. }
  21. defer cleanup(tester, t)
  22. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  23. if err != nil {
  24. t.Fatalf("error rotating: %v\n", err)
  25. }
  26. // very all clusters decoded properly
  27. repo := gorm.NewClusterRepository(tester.DB, &newKey).(*gorm.ClusterRepository)
  28. clusters := []*models.Cluster{}
  29. if err := tester.DB.Find(&clusters).Error; err != nil {
  30. t.Fatalf("%v\n", err)
  31. }
  32. // decrypt with the old key
  33. for _, c := range clusters {
  34. cluster, err := repo.ReadCluster(c.ProjectID, c.ID)
  35. if err != nil {
  36. t.Fatalf("error reading cluster: %v\n", err)
  37. }
  38. if string(cluster.CertificateAuthorityData) != "-----BEGIN" {
  39. t.Errorf("%s\n", string(cluster.CertificateAuthorityData))
  40. }
  41. if string(cluster.TokenCache.Token) != "token-1" {
  42. t.Errorf("%s\n", string(cluster.TokenCache.Token))
  43. }
  44. }
  45. }
  46. func TestClusterCandidateModelRotation(t *testing.T) {
  47. var newKey [32]byte
  48. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  49. newKey[i] = b
  50. }
  51. tester := &tester{
  52. dbFileName: "./porter_cluster_candidate_rotate.db",
  53. }
  54. setupTestEnv(tester, t)
  55. for i := 0; i < 256; i++ {
  56. initClusterCandidate(tester, t)
  57. }
  58. defer cleanup(tester, t)
  59. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  60. if err != nil {
  61. t.Fatalf("error rotating: %v\n", err)
  62. }
  63. // very all clusters decoded properly
  64. repo := gorm.NewClusterRepository(tester.DB, &newKey).(*gorm.ClusterRepository)
  65. ccs := []*models.ClusterCandidate{}
  66. if err := tester.DB.Find(&ccs).Error; err != nil {
  67. t.Fatalf("%v\n", err)
  68. }
  69. // decrypt with the old key
  70. for _, c := range ccs {
  71. cc, err := repo.ReadClusterCandidate(c.ProjectID, c.ID)
  72. if err != nil {
  73. t.Fatalf("error reading cluster: %v\n", err)
  74. }
  75. if string(cc.AWSClusterIDGuess) != "example-cluster-0" {
  76. t.Errorf("%s\n", string(cc.AWSClusterIDGuess))
  77. }
  78. if string(cc.Kubeconfig) != "current-context: testing\n" {
  79. t.Errorf("%s\n", string(cc.Kubeconfig))
  80. }
  81. }
  82. }
  83. func TestRegistryModelRotation(t *testing.T) {
  84. var newKey [32]byte
  85. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  86. newKey[i] = b
  87. }
  88. tester := &tester{
  89. dbFileName: "./porter_registry_rotate.db",
  90. }
  91. setupTestEnv(tester, t)
  92. for i := 0; i < 144; i++ {
  93. initRegistry(tester, t)
  94. }
  95. defer cleanup(tester, t)
  96. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  97. if err != nil {
  98. t.Fatalf("error rotating: %v\n", err)
  99. }
  100. // very all registries decoded properly
  101. repo := gorm.NewRegistryRepository(tester.DB, &newKey).(*gorm.RegistryRepository)
  102. regs := []*models.Registry{}
  103. if err := tester.DB.Preload("TokenCache").Find(&regs).Error; err != nil {
  104. t.Fatalf("%v\n", err)
  105. }
  106. // decrypt with the old key
  107. for _, r := range regs {
  108. registry, err := repo.ReadRegistry(r.ProjectID, r.ID)
  109. if err != nil {
  110. t.Fatalf("error reading registry: %v\n", err)
  111. }
  112. if string(registry.TokenCache.Token) != "token-1" {
  113. t.Errorf("%s\n", string(registry.TokenCache.Token))
  114. }
  115. }
  116. }
  117. func TestHelmRepoModelRotation(t *testing.T) {
  118. var newKey [32]byte
  119. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  120. newKey[i] = b
  121. }
  122. tester := &tester{
  123. dbFileName: "./porter_hr_rotate.db",
  124. }
  125. setupTestEnv(tester, t)
  126. for i := 0; i < 169; i++ {
  127. initHelmRepo(tester, t)
  128. }
  129. defer cleanup(tester, t)
  130. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  131. if err != nil {
  132. t.Fatalf("error rotating: %v\n", err)
  133. }
  134. // very all helm repos decoded properly
  135. repo := gorm.NewHelmRepoRepository(tester.DB, &newKey).(*gorm.HelmRepoRepository)
  136. hrs := []*models.HelmRepo{}
  137. if err := tester.DB.Preload("TokenCache").Find(&hrs).Error; err != nil {
  138. t.Fatalf("%v\n", err)
  139. }
  140. // decrypt with the old key
  141. for _, h := range hrs {
  142. hr, err := repo.ReadHelmRepo(h.ProjectID, h.ID)
  143. if err != nil {
  144. t.Fatalf("error reading helm repo: %v\n", err)
  145. }
  146. if string(hr.TokenCache.Token) != "token-1" {
  147. t.Errorf("%s\n", string(hr.TokenCache.Token))
  148. }
  149. }
  150. }
  151. func TestInfraModelRotation(t *testing.T) {
  152. var newKey [32]byte
  153. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  154. newKey[i] = b
  155. }
  156. tester := &tester{
  157. dbFileName: "./porter_infra_rotate.db",
  158. }
  159. setupTestEnv(tester, t)
  160. for i := 0; i < 128; i++ {
  161. initInfra(tester, t)
  162. }
  163. defer cleanup(tester, t)
  164. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  165. if err != nil {
  166. t.Fatalf("error rotating: %v\n", err)
  167. }
  168. // very all infras decoded properly
  169. repo := gorm.NewInfraRepository(tester.DB, &newKey).(*gorm.InfraRepository)
  170. infras := []*models.Infra{}
  171. if err := tester.DB.Find(&infras).Error; err != nil {
  172. t.Fatalf("%v\n", err)
  173. }
  174. // decrypt with the old key
  175. for _, i := range infras {
  176. infra, err := repo.ReadInfra(i.ProjectID, i.ID)
  177. if err != nil {
  178. t.Fatalf("error reading infra: %v\n", err)
  179. }
  180. if string(infra.LastApplied) != "testing" {
  181. t.Errorf("%s\n", string(infra.LastApplied))
  182. }
  183. }
  184. }
  185. func TestKubeIntegrationModelRotation(t *testing.T) {
  186. var newKey [32]byte
  187. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  188. newKey[i] = b
  189. }
  190. tester := &tester{
  191. dbFileName: "./porter_ki_rotate.db",
  192. }
  193. setupTestEnv(tester, t)
  194. for i := 0; i < 128; i++ {
  195. initKubeIntegration(tester, t)
  196. }
  197. defer cleanup(tester, t)
  198. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  199. if err != nil {
  200. t.Fatalf("error rotating: %v\n", err)
  201. }
  202. // very all kis decoded properly
  203. repo := gorm.NewKubeIntegrationRepository(tester.DB, &newKey).(*gorm.KubeIntegrationRepository)
  204. kis := []*ints.KubeIntegration{}
  205. if err := tester.DB.Find(&kis).Error; err != nil {
  206. t.Fatalf("%v\n", err)
  207. }
  208. // decrypt with the old key
  209. for _, k := range kis {
  210. ki, err := repo.ReadKubeIntegration(k.ProjectID, k.ID)
  211. if err != nil {
  212. t.Fatalf("error reading infra: %v\n", err)
  213. }
  214. if string(ki.Kubeconfig) != "current-context: testing\n" {
  215. t.Errorf("%s\n", string(ki.Kubeconfig))
  216. }
  217. if string(ki.ClientCertificateData) != "clientcertdata" {
  218. t.Errorf("%s\n", string(ki.ClientCertificateData))
  219. }
  220. if string(ki.ClientKeyData) != "clientkeydata" {
  221. t.Errorf("%s\n", string(ki.ClientKeyData))
  222. }
  223. if string(ki.Token) != "token" {
  224. t.Errorf("%s\n", string(ki.Token))
  225. }
  226. if string(ki.Username) != "username" {
  227. t.Errorf("%s\n", string(ki.Username))
  228. }
  229. if string(ki.Password) != "password" {
  230. t.Errorf("%s\n", string(ki.Password))
  231. }
  232. }
  233. }
  234. func TestBasicIntegrationModelRotation(t *testing.T) {
  235. var newKey [32]byte
  236. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  237. newKey[i] = b
  238. }
  239. tester := &tester{
  240. dbFileName: "./porter_basic_rotate.db",
  241. }
  242. setupTestEnv(tester, t)
  243. for i := 0; i < 128; i++ {
  244. initBasicIntegration(tester, t)
  245. }
  246. defer cleanup(tester, t)
  247. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  248. if err != nil {
  249. t.Fatalf("error rotating: %v\n", err)
  250. }
  251. // very all basics decoded properly
  252. repo := gorm.NewBasicIntegrationRepository(tester.DB, &newKey).(*gorm.BasicIntegrationRepository)
  253. basics := []*ints.BasicIntegration{}
  254. if err := tester.DB.Find(&basics).Error; err != nil {
  255. t.Fatalf("%v\n", err)
  256. }
  257. // decrypt with the old key
  258. for _, k := range basics {
  259. basic, err := repo.ReadBasicIntegration(k.ProjectID, k.ID)
  260. if err != nil {
  261. t.Fatalf("error reading infra: %v\n", err)
  262. }
  263. if string(basic.Username) != "username" {
  264. t.Errorf("%s\n", string(basic.Username))
  265. }
  266. if string(basic.Password) != "password" {
  267. t.Errorf("%s\n", string(basic.Password))
  268. }
  269. }
  270. }
  271. func TestOIDCIntegrationModelRotation(t *testing.T) {
  272. var newKey [32]byte
  273. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  274. newKey[i] = b
  275. }
  276. tester := &tester{
  277. dbFileName: "./porter_oidc_rotate.db",
  278. }
  279. setupTestEnv(tester, t)
  280. for i := 0; i < 128; i++ {
  281. initOIDCIntegration(tester, t)
  282. }
  283. defer cleanup(tester, t)
  284. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  285. if err != nil {
  286. t.Fatalf("error rotating: %v\n", err)
  287. }
  288. // very all oidcs decoded properly
  289. repo := gorm.NewOIDCIntegrationRepository(tester.DB, &newKey).(*gorm.OIDCIntegrationRepository)
  290. oidcs := []*ints.OIDCIntegration{}
  291. if err := tester.DB.Find(&oidcs).Error; err != nil {
  292. t.Fatalf("%v\n", err)
  293. }
  294. // decrypt with the old key
  295. for _, k := range oidcs {
  296. oidc, err := repo.ReadOIDCIntegration(k.ProjectID, k.ID)
  297. if err != nil {
  298. t.Fatalf("error reading infra: %v\n", err)
  299. }
  300. if string(oidc.IssuerURL) != "https://oidc.example.com" {
  301. t.Errorf("%s\n", string(oidc.IssuerURL))
  302. }
  303. if string(oidc.ClientID) != "exampleclientid" {
  304. t.Errorf("%s\n", string(oidc.ClientID))
  305. }
  306. if string(oidc.ClientSecret) != "exampleclientsecret" {
  307. t.Errorf("%s\n", string(oidc.ClientSecret))
  308. }
  309. if string(oidc.CertificateAuthorityData) != "cadata" {
  310. t.Errorf("%s\n", string(oidc.CertificateAuthorityData))
  311. }
  312. if string(oidc.IDToken) != "idtoken" {
  313. t.Errorf("%s\n", string(oidc.IDToken))
  314. }
  315. if string(oidc.RefreshToken) != "refreshtoken" {
  316. t.Errorf("%s\n", string(oidc.RefreshToken))
  317. }
  318. }
  319. }
  320. func TestOAuthIntegrationModelRotation(t *testing.T) {
  321. var newKey [32]byte
  322. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  323. newKey[i] = b
  324. }
  325. tester := &tester{
  326. dbFileName: "./porter_oauth_rotate.db",
  327. }
  328. setupTestEnv(tester, t)
  329. for i := 0; i < 128; i++ {
  330. initOAuthIntegration(tester, t)
  331. }
  332. defer cleanup(tester, t)
  333. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  334. if err != nil {
  335. t.Fatalf("error rotating: %v\n", err)
  336. }
  337. // very all oauths decoded properly
  338. repo := gorm.NewOAuthIntegrationRepository(tester.DB, &newKey, nil).(*gorm.OAuthIntegrationRepository)
  339. oauths := []*ints.OAuthIntegration{}
  340. if err := tester.DB.Find(&oauths).Error; err != nil {
  341. t.Fatalf("%v\n", err)
  342. }
  343. // decrypt with the old key
  344. for _, k := range oauths {
  345. oauth, err := repo.ReadOAuthIntegration(k.ProjectID, k.ID)
  346. if err != nil {
  347. t.Fatalf("error reading infra: %v\n", err)
  348. }
  349. if string(oauth.ClientID) != "exampleclientid" {
  350. t.Errorf("%s\n", string(oauth.ClientID))
  351. }
  352. if string(oauth.AccessToken) != "idtoken" {
  353. t.Errorf("%s\n", string(oauth.AccessToken))
  354. }
  355. if string(oauth.RefreshToken) != "refreshtoken" {
  356. t.Errorf("%s\n", string(oauth.RefreshToken))
  357. }
  358. }
  359. }
  360. func TestGCPIntegrationModelRotation(t *testing.T) {
  361. var newKey [32]byte
  362. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  363. newKey[i] = b
  364. }
  365. tester := &tester{
  366. dbFileName: "./porter_gcp_rotate.db",
  367. }
  368. setupTestEnv(tester, t)
  369. for i := 0; i < 128; i++ {
  370. initGCPIntegration(tester, t)
  371. }
  372. defer cleanup(tester, t)
  373. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  374. if err != nil {
  375. t.Fatalf("error rotating: %v\n", err)
  376. }
  377. // very all gcps decoded properly
  378. repo := gorm.NewGCPIntegrationRepository(tester.DB, &newKey, nil).(*gorm.GCPIntegrationRepository)
  379. gcps := []*ints.GCPIntegration{}
  380. if err := tester.DB.Find(&gcps).Error; err != nil {
  381. t.Fatalf("%v\n", err)
  382. }
  383. // decrypt with the old key
  384. for _, k := range gcps {
  385. gcp, err := repo.ReadGCPIntegration(k.ProjectID, k.ID)
  386. if err != nil {
  387. t.Fatalf("error reading infra: %v\n", err)
  388. }
  389. if string(gcp.GCPKeyData) != "{\"test\":\"key\"}" {
  390. t.Errorf("%s\n", string(gcp.GCPKeyData))
  391. }
  392. }
  393. }
  394. func TestAWSIntegrationModelRotation(t *testing.T) {
  395. var newKey [32]byte
  396. for i, b := range []byte("__r3n3o3_s3r3n3_3n3r3p3i3n_k3y__") {
  397. newKey[i] = b
  398. }
  399. tester := &tester{
  400. dbFileName: "./porter_aws_rotate.db",
  401. }
  402. setupTestEnv(tester, t)
  403. for i := 0; i < 128; i++ {
  404. initAWSIntegration(tester, t)
  405. }
  406. defer cleanup(tester, t)
  407. err := keyrotate.Rotate(tester.DB, tester.Key, &newKey)
  408. if err != nil {
  409. t.Fatalf("error rotating: %v\n", err)
  410. }
  411. // very all awss decoded properly
  412. repo := gorm.NewAWSIntegrationRepository(tester.DB, &newKey, nil).(*gorm.AWSIntegrationRepository)
  413. awss := []*ints.AWSIntegration{}
  414. if err := tester.DB.Find(&awss).Error; err != nil {
  415. t.Fatalf("%v\n", err)
  416. }
  417. // decrypt with the old key
  418. for _, k := range awss {
  419. aws, err := repo.ReadAWSIntegration(k.ProjectID, k.ID)
  420. if err != nil {
  421. t.Fatalf("error reading infra: %v\n", err)
  422. }
  423. if string(aws.AWSClusterID) != "example-cluster-0" {
  424. t.Errorf("%s\n", string(aws.AWSClusterID))
  425. }
  426. if string(aws.AWSAccessKeyID) != "accesskey" {
  427. t.Errorf("%s\n", string(aws.AWSAccessKeyID))
  428. }
  429. if string(aws.AWSSecretAccessKey) != "secret" {
  430. t.Errorf("%s\n", string(aws.AWSSecretAccessKey))
  431. }
  432. if string(aws.AWSSessionToken) != "optional" {
  433. t.Errorf("%s\n", string(aws.AWSSessionToken))
  434. }
  435. }
  436. }