-
Notifications
You must be signed in to change notification settings - Fork 42
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
(PDK-1091) Implement handling Sensitive values
- Loading branch information
Showing
9 changed files
with
276 additions
and
1 deletion.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
require 'spec_helper' | ||
require 'tempfile' | ||
require 'open3' | ||
|
||
RSpec.describe 'sensitive data' do | ||
# these common_args *have* to use debug to check *all* log messages for the sensitive value | ||
let(:common_args) { '--verbose --trace --strict=error --modulepath spec/fixtures --debug' } | ||
|
||
describe 'using `puppet apply`' do | ||
it 'is not exposed by notify' do | ||
stdout_str, _status = Open3.capture2e("puppet apply #{common_args} -e \"notice(Sensitive('foo'))\"") | ||
expect(stdout_str).to match %r{redacted} | ||
expect(stdout_str).not_to match %r{foo} | ||
expect(stdout_str).not_to match %r{warn|error}i | ||
end | ||
|
||
it 'is not exposed by a provider' do | ||
stdout_str, _status = Open3.capture2e("puppet apply #{common_args} -e \"test_sensitive { bar: secret => Sensitive('foo'), optional_secret => Sensitive('optional foo'), array_secret => [Sensitive('array foo')] }\"") | ||
expect(stdout_str).to match %r{redacted} | ||
expect(stdout_str).not_to match %r{foo} | ||
expect(stdout_str).not_to match %r{warn|error}i | ||
end | ||
end | ||
|
||
describe 'using `puppet resource`' do | ||
it 'is not exposed in the output' do | ||
stdout_str, _status = Open3.capture2e("puppet resource #{common_args} test_sensitive") | ||
expect(stdout_str).to match %r{redacted} | ||
expect(stdout_str).not_to match %r{(foo|bar)secret} | ||
expect(stdout_str).not_to match %r{warn|error}i | ||
end | ||
end | ||
end |
31 changes: 31 additions & 0 deletions
31
spec/fixtures/test_module/lib/puppet/provider/test_sensitive/test_sensitive.rb
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,31 @@ | ||
require 'puppet/resource_api/simple_provider' | ||
|
||
# Implementation for the test_sensitive type using the Resource API. | ||
class Puppet::Provider::TestSensitive::TestSensitive < Puppet::ResourceApi::SimpleProvider | ||
def get(_context) | ||
[ | ||
{ | ||
name: 'foo', | ||
ensure: 'present', | ||
secret: Puppet::Pops::Types::PSensitiveType::Sensitive.new('foosecret') | ||
}, | ||
{ | ||
name: 'bar', | ||
ensure: 'present', | ||
secret: Puppet::Pops::Types::PSensitiveType::Sensitive.new('barsecret') | ||
}, | ||
] | ||
end | ||
|
||
def create(context, name, should) | ||
context.notice("Creating '#{name}' with #{should.inspect}") | ||
end | ||
|
||
def update(context, name, should) | ||
context.notice("Updating '#{name}' with #{should.inspect}") | ||
end | ||
|
||
def delete(context, name) | ||
context.notice("Deleting '#{name}'") | ||
end | ||
end |
33 changes: 33 additions & 0 deletions
33
spec/fixtures/test_module/lib/puppet/type/test_sensitive.rb
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,33 @@ | ||
require 'puppet/resource_api' | ||
|
||
Puppet::ResourceApi.register_type( | ||
name: 'test_sensitive', | ||
docs: <<-EOS, | ||
This type provides Puppet with the capabilities to manage ... | ||
EOS | ||
features: [], | ||
attributes: { | ||
ensure: { | ||
type: 'Enum[present, absent]', | ||
desc: 'Whether this resource should be present or absent on the target system.', | ||
default: 'present', | ||
}, | ||
name: { | ||
type: 'String', | ||
desc: 'The name of the resource you want to manage.', | ||
behaviour: :namevar, | ||
}, | ||
secret: { | ||
type: 'Sensitive[String]', | ||
desc: 'A secret to protect.', | ||
}, | ||
optional_secret: { | ||
type: 'Optional[Sensitive[String]]', | ||
desc: 'An optional secret to protect.', | ||
}, | ||
array_secret: { | ||
type: 'Array[Sensitive[String]]', | ||
desc: 'An array secret to protect.', | ||
}, | ||
}, | ||
) |
49 changes: 49 additions & 0 deletions
49
spec/fixtures/test_module/spec/unit/puppet/provider/test_sensitive/test_sensitive_spec.rb
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,49 @@ | ||
require 'spec_helper' | ||
|
||
ensure_module_defined('Puppet::Provider::TestSensitive') | ||
require 'puppet/provider/test_sensitive/test_sensitive' | ||
|
||
RSpec.describe Puppet::Provider::TestSensitive::TestSensitive do | ||
subject(:provider) { described_class.new } | ||
|
||
let(:context) { instance_double('Puppet::ResourceApi::BaseContext', 'context') } | ||
|
||
describe '#get' do | ||
it 'processes resources' do | ||
expect(provider.get(context)).to eq [ | ||
{ | ||
name: 'foo', | ||
ensure: 'present', | ||
}, | ||
{ | ||
name: 'bar', | ||
ensure: 'present', | ||
}, | ||
] | ||
end | ||
end | ||
|
||
describe 'create(context, name, should)' do | ||
it 'creates the resource' do | ||
expect(context).to receive(:notice).with(%r{\ACreating 'a'}) | ||
|
||
provider.create(context, 'a', name: 'a', ensure: 'present') | ||
end | ||
end | ||
|
||
describe 'update(context, name, should)' do | ||
it 'updates the resource' do | ||
expect(context).to receive(:notice).with(%r{\AUpdating 'foo'}) | ||
|
||
provider.update(context, 'foo', name: 'foo', ensure: 'present') | ||
end | ||
end | ||
|
||
describe 'delete(context, name, should)' do | ||
it 'deletes the resource' do | ||
expect(context).to receive(:notice).with(%r{\ADeleting 'foo'}) | ||
|
||
provider.delete(context, 'foo') | ||
end | ||
end | ||
end |
8 changes: 8 additions & 0 deletions
8
spec/fixtures/test_module/spec/unit/puppet/type/test_sensitive_spec.rb
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,8 @@ | ||
require 'spec_helper' | ||
require 'puppet/type/test_sensitive' | ||
|
||
RSpec.describe 'the test_sensitive type' do | ||
it 'loads' do | ||
expect(Puppet::Type.type(:test_sensitive)).not_to be_nil | ||
end | ||
end |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters