mirror of
https://github.com/immich-app/devtools.git
synced 2026-09-30 21:27:48 +08:00
fix: replace null_resource + local_file with external data source for cert conversion (#1455)
This commit is contained in:
@@ -24,6 +24,23 @@ provider "registry.opentofu.org/1password/onepassword" {
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.opentofu.org/hashicorp/external" {
|
||||
version = "2.3.5"
|
||||
hashes = [
|
||||
"h1:jcVmeuuz74tdRt2kj0MpUG9AORdlAlRRQ3k61y0r5Vc=",
|
||||
"zh:1fb9aca1f068374a09d438dba84c9d8ba5915d24934a72b6ef66ef6818329151",
|
||||
"zh:3eab30e4fcc76369deffb185b4d225999fc82d2eaaa6484d3b3164a4ed0f7c49",
|
||||
"zh:4f8b7a4832a68080f0bf4f155b56a691832d8a91ce8096dac0f13a90081abc50",
|
||||
"zh:5ff1935612db62e48e4fe6cfb83dfac401b506a5b7b38342217616fbcab70ce0",
|
||||
"zh:993192234d327ec86726041eb6d1efb001e41f32e4518ad8b9b162130b65ee9a",
|
||||
"zh:ce445e68282a2c4b2d1f994a2730406df4ea47914c0932fb4a7eb040a7ec7061",
|
||||
"zh:e305e17216840c54194141fb852839c2cedd6b41abd70cf8d606d6e88ed40e64",
|
||||
"zh:edba65fb241d663c09aa2cbf75026c840e963d5195f27000f216829e49811437",
|
||||
"zh:f306cc6f6ec9beaf75bdcefaadb7b77af320b1f9b56d8f50df5ebd2189a93148",
|
||||
"zh:fb2ff9e1f86796fda87e1f122d40568912a904da51d477461b850d81a0105f3d",
|
||||
]
|
||||
}
|
||||
|
||||
provider "registry.opentofu.org/hashicorp/local" {
|
||||
version = "2.7.0"
|
||||
hashes = [
|
||||
|
||||
+29
@@ -0,0 +1,29 @@
|
||||
#!/usr/bin/env bash
|
||||
set -euo pipefail
|
||||
|
||||
INPUT=$(cat)
|
||||
PEM_VALUE=$(echo "$INPUT" | jq -r '.pem_value')
|
||||
|
||||
if [ -z "$PEM_VALUE" ] || [ "$PEM_VALUE" = "CHANGE_ME" ]; then
|
||||
jq -n '{"pkcs1": "CHANGE_ME", "pkcs8": "CHANGE_ME"}'
|
||||
else
|
||||
PKCS1=$(printf "%b" "$PEM_VALUE")
|
||||
|
||||
# Validate PKCS#1 format
|
||||
echo "$PKCS1" | openssl rsa -check -noout >/dev/null 2>&1
|
||||
if [ $? -ne 0 ]; then
|
||||
echo "Input PEM does not appear to be valid PKCS#1 format" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Convert to PKCS#8
|
||||
PKCS8=$(echo "$PKCS1" | openssl pkcs8 -topk8 -inform PEM -outform PEM -nocrypt 2>/dev/null)
|
||||
if [ $? -ne 0 ] || [ -z "$PKCS8" ]; then
|
||||
echo "PKCS8 conversion failed" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
jq -n --arg pkcs1 "$PKCS1
|
||||
" --arg pkcs8 "$PKCS8
|
||||
" '{"pkcs1": $pkcs1, "pkcs8": $pkcs8}'
|
||||
fi
|
||||
@@ -41,76 +41,14 @@ resource "onepassword_item" "manual" {
|
||||
}
|
||||
}
|
||||
|
||||
resource "null_resource" "convert_certificates" {
|
||||
data "external" "convert_certificate" {
|
||||
for_each = onepassword_item.manual
|
||||
|
||||
triggers = {
|
||||
program = ["bash", "${path.module}/convert_cert.sh"]
|
||||
|
||||
query = {
|
||||
pem_value = each.value.section[0].field[0].value
|
||||
}
|
||||
|
||||
provisioner "local-exec" {
|
||||
environment = {
|
||||
PEM_VALUE = each.value.section[0].field[0].value
|
||||
}
|
||||
command = <<-EOT
|
||||
# Create cert directory if it doesn't exist
|
||||
mkdir -p /tmp/tf-certs
|
||||
|
||||
if [ -z "$PEM_VALUE" ] || [ "$PEM_VALUE" = "CHANGE_ME" ]; then
|
||||
echo "PEM value not set or is still the default value. Using CHANGE_ME as certificate values."
|
||||
|
||||
# Create certificate files with CHANGE_ME content
|
||||
echo "CHANGE_ME" > /tmp/tf-certs/${each.key}_pkcs1.pem
|
||||
echo "CHANGE_ME" > /tmp/tf-certs/${each.key}_pkcs8.pem
|
||||
else
|
||||
echo "Processing PEM value to handle newlines"
|
||||
|
||||
# Convert literal \n to actual newlines and create PKCS#1 PEM file (original format)
|
||||
printf "%b" "$PEM_VALUE" > /tmp/tf-certs/${each.key}_pkcs1.pem
|
||||
|
||||
cat /tmp/tf-certs/${each.key}_pkcs1.pem
|
||||
|
||||
# Validate PKCS#1 format
|
||||
openssl rsa -in /tmp/tf-certs/${each.key}_pkcs1.pem -check -noout
|
||||
PKCS1_VALID=$?
|
||||
|
||||
if [ $PKCS1_VALID -ne 0 ]; then
|
||||
echo "Input PEM does not appear to be valid PKCS#1 format"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Convert to PKCS8
|
||||
openssl pkcs8 -topk8 -inform PEM -in /tmp/tf-certs/${each.key}_pkcs1.pem -outform PEM -nocrypt > /tmp/tf-certs/${each.key}_pkcs8.pem
|
||||
PKCS8_SUCCESS=$?
|
||||
|
||||
# Verify files were created with content
|
||||
if [ ! -s /tmp/tf-certs/${each.key}_pkcs1.pem ]; then
|
||||
echo "PKCS1 file is empty"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
if [ $PKCS8_SUCCESS -ne 0 ] || [ ! -s /tmp/tf-certs/${each.key}_pkcs8.pem ]; then
|
||||
echo "PKCS8 conversion failed or file is empty"
|
||||
exit 1
|
||||
fi
|
||||
fi
|
||||
EOT
|
||||
}
|
||||
|
||||
depends_on = [onepassword_item.manual]
|
||||
}
|
||||
|
||||
# Read the converted certificate files
|
||||
data "local_file" "pkcs1_cert" {
|
||||
for_each = onepassword_item.manual
|
||||
filename = "/tmp/tf-certs/${each.key}_pkcs1.pem"
|
||||
depends_on = [null_resource.convert_certificates]
|
||||
}
|
||||
|
||||
data "local_file" "pkcs8_cert" {
|
||||
for_each = onepassword_item.manual
|
||||
filename = "/tmp/tf-certs/${each.key}_pkcs8.pem"
|
||||
depends_on = [null_resource.convert_certificates]
|
||||
}
|
||||
|
||||
# Create new 1Password items with all certificate formats
|
||||
@@ -127,12 +65,12 @@ resource "onepassword_item" "converted" {
|
||||
label = "GitHub App"
|
||||
field {
|
||||
label = "pkcs1"
|
||||
value = data.local_file.pkcs1_cert[each.key].content
|
||||
value = data.external.convert_certificate[each.key].result.pkcs1
|
||||
type = "CONCEALED"
|
||||
}
|
||||
field {
|
||||
label = "pkcs8"
|
||||
value = data.local_file.pkcs8_cert[each.key].content
|
||||
value = data.external.convert_certificate[each.key].result.pkcs8
|
||||
type = "CONCEALED"
|
||||
}
|
||||
field {
|
||||
@@ -150,8 +88,6 @@ resource "onepassword_item" "converted" {
|
||||
}
|
||||
|
||||
depends_on = [
|
||||
data.local_file.pkcs1_cert,
|
||||
data.local_file.pkcs8_cert,
|
||||
null_resource.convert_certificates
|
||||
data.external.convert_certificate,
|
||||
]
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user