Encrypt connector variables at rest - #837
Merged
Merged
Conversation
connectors.env_vars holds every connector's API keys, passwords and
tokens, and was stored in clear. It is now stored as
{"$enc": "<AES-256-GCM>"} with ENCRYPTION_KEY and decrypted on read.
- One choke point: a Prisma extension on PrismaService seals envVars on
connector writes and opens it on every read (findMany, include from
another model, select, transactions), so none of the ~70 call sites
changes. A test fails if a nested connector write is ever added.
- Rows written before are read as they are and encrypted by an
idempotent pass at boot; only rows unchanged since read are replaced.
- Keys an operator adds next to $enc with SQL are read (and win) and
are folded into the ciphertext at the next start.
- A row that cannot be decrypted reads as empty, so calls stop at the
placeholder guard instead of sending ciphertext to an API.
- Rollback hatch: ENV_VARS_AT_REST=plaintext decrypts every row at boot.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
connectors.env_varsholds every connector's API keys, passwords and tokens, and was stored in clear (onlyauth_configwas encrypted). It is now stored as{"$enc": "<AES-256-GCM>"}with the existingENCRYPTION_KEY(AADconnectors.env_vars) and decrypted on read.Independent of #831/#832/#834; based on main.
How
PrismaServicesealsenvVarson connector writes (create,createMany(AndReturn),update,updateMany(AndReturn),upsert) and opens it on every read through a result override. Prisma applies that at every level:findMany,includefrom another model,select,tenantTx. None of the ~70 call sites changes. A test fails if a nested connector write is added (those would bypass the query hook).Encrypted the variables of N connectors). It replaces a row only if it is unchanged since it was read, so several instances can run it at once.$enc(env_vars || '{"X":"y"}') are read, win over the encrypted value, and are folded in at the next start.ENV_VARS_AT_REST=plaintextdecrypts every row at boot. Documented indocs/operations/backup-restore.mdand passed throughdocker-compose.yml/docker-compose.cloud.yml. The quickstart compose is left as is (its file is snapshotted into the satellite repos); the doc says how to add it there.Production check (read-only)
707 rows with an object, 202 JSON
null, 136 SQLNULL; no$enckey anywhere; every value is a string. The boot pass only touches non-empty objects.Tests
PrismaService: legacy row readable, boot pass encrypts and is idempotent, writes sealed, include/select/tenantTx/findMany decrypt, SQL merge folded in, plaintext hatch and back,{}stays{}.After deploy
Raw SQL on
env_vars(analytics, ops scripts) now sees ciphertext; use the API or decrypt with the key.