summaryrefslogtreecommitdiff
path: root/cmd/rotate-credentials/main.go
blob: 598035ddb16f97de979b92a58c487db8254c1f68 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
package main

import (
	"context"
	"fmt"
	"os"
	"strings"
	"time"

	"aigw/internal/controlplane"
)

func main() {
	databaseURL := strings.TrimSpace(os.Getenv("AIGW_DATABASE_URL"))
	current := strings.TrimSpace(os.Getenv("AIGW_CREDENTIAL_KEY"))
	previousRaw := os.Getenv("AIGW_CREDENTIAL_PREVIOUS_KEYS")
	if databaseURL == "" || current == "" || strings.TrimSpace(previousRaw) == "" {
		fmt.Fprintln(os.Stderr, "AIGW_DATABASE_URL, AIGW_CREDENTIAL_KEY, and AIGW_CREDENTIAL_PREVIOUS_KEYS are required")
		os.Exit(2)
	}
	previous := []string{}
	for _, value := range strings.Split(previousRaw, ",") {
		if value = strings.TrimSpace(value); value != "" {
			previous = append(previous, value)
		}
	}
	ctx, cancel := context.WithTimeout(context.Background(), 10*time.Minute)
	defer cancel()
	store, err := controlplane.NewStore(ctx, controlplane.Options{DatabaseURL: databaseURL, CredentialKey: current, PreviousCredentialKeys: previous})
	if err != nil {
		fmt.Fprintln(os.Stderr, err)
		os.Exit(1)
	}
	defer store.Close()
	count, err := store.RotateCredentials(ctx)
	if err != nil {
		fmt.Fprintln(os.Stderr, err)
		os.Exit(1)
	}
	fmt.Printf("re-encrypted %d credential records\n", count)
}