From db55cf75833814db9fc51ce66807e99e8e6c71bb Mon Sep 17 00:00:00 2001 From: Andrea Luzzardi Date: Wed, 24 Nov 2021 16:24:29 -0800 Subject: [PATCH] runtime: context: support secret environment variables Signed-off-by: Andrea Luzzardi --- plan/task/secretenv.go | 48 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 plan/task/secretenv.go diff --git a/plan/task/secretenv.go b/plan/task/secretenv.go new file mode 100644 index 00000000..11ee5d71 --- /dev/null +++ b/plan/task/secretenv.go @@ -0,0 +1,48 @@ +package task + +import ( + "context" + "fmt" + "os" + + "cuelang.org/go/cue" + "github.com/rs/zerolog/log" + "go.dagger.io/dagger/compiler" + "go.dagger.io/dagger/plancontext" + "go.dagger.io/dagger/solver" +) + +func init() { + Register("SecretEnv", func() Task { return &secretEnvTask{} }) +} + +type secretEnvTask struct { +} + +func (c secretEnvTask) Run(ctx context.Context, pctx *plancontext.Context, _ solver.Solver, v *compiler.Value) (*compiler.Value, error) { + lg := log.Ctx(ctx) + + var secretEnv struct { + Envvar string + } + + if err := v.Decode(&secretEnv); err != nil { + return nil, err + } + + lg.Debug().Str("envvar", secretEnv.Envvar).Msg("loading secret") + + env := os.Getenv(secretEnv.Envvar) + if env == "" { + return nil, fmt.Errorf("environment variable %q not set", secretEnv.Envvar) + } + id := pctx.Secrets.Register(&plancontext.Secret{ + PlainText: env, + }) + + out := compiler.NewValue() + if err := out.FillPath(cue.ParsePath("contents.id"), id); err != nil { + return nil, err + } + return out, nil +}