diff options
Diffstat (limited to 'cmd/rotate-credentials')
| -rw-r--r-- | cmd/rotate-credentials/main.go | 41 |
1 files changed, 41 insertions, 0 deletions
diff --git a/cmd/rotate-credentials/main.go b/cmd/rotate-credentials/main.go new file mode 100644 index 0000000..598035d --- /dev/null +++ b/cmd/rotate-credentials/main.go @@ -0,0 +1,41 @@ +package main + +import ( + "context" + "fmt" + "os" + "strings" + "time" + + "aigw/internal/controlplane" +) + +func main() { + databaseURL := strings.TrimSpace(os.Getenv("AIGW_DATABASE_URL")) + current := strings.TrimSpace(os.Getenv("AIGW_CREDENTIAL_KEY")) + previousRaw := os.Getenv("AIGW_CREDENTIAL_PREVIOUS_KEYS") + if databaseURL == "" || current == "" || strings.TrimSpace(previousRaw) == "" { + fmt.Fprintln(os.Stderr, "AIGW_DATABASE_URL, AIGW_CREDENTIAL_KEY, and AIGW_CREDENTIAL_PREVIOUS_KEYS are required") + os.Exit(2) + } + previous := []string{} + for _, value := range strings.Split(previousRaw, ",") { + if value = strings.TrimSpace(value); value != "" { + previous = append(previous, value) + } + } + ctx, cancel := context.WithTimeout(context.Background(), 10*time.Minute) + defer cancel() + store, err := controlplane.NewStore(ctx, controlplane.Options{DatabaseURL: databaseURL, CredentialKey: current, PreviousCredentialKeys: previous}) + if err != nil { + fmt.Fprintln(os.Stderr, err) + os.Exit(1) + } + defer store.Close() + count, err := store.RotateCredentials(ctx) + if err != nil { + fmt.Fprintln(os.Stderr, err) + os.Exit(1) + } + fmt.Printf("re-encrypted %d credential records\n", count) +} |
