Skip to main content

alien_core/bindings/
key.rs

1use super::BindingValue;
2use serde::{Deserialize, Serialize};
3
4/// Provider key reference used for native encrypt and decrypt operations.
5#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
6#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
7#[cfg_attr(feature = "jsonschema", derive(schemars::JsonSchema))]
8#[serde(tag = "service")]
9pub enum KeyBinding {
10    /// AWS Key Management Service.
11    #[serde(rename = "kms")]
12    AwsKms(AwsKmsKeyBinding),
13    /// GCP Cloud Key Management Service.
14    #[serde(rename = "cloud-kms")]
15    GcpCloudKms(GcpCloudKmsKeyBinding),
16    /// Azure Key Vault Keys.
17    #[serde(rename = "key-vault-key")]
18    AzureKeyVault(AzureKeyVaultKeyBinding),
19}
20
21#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
22#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
23#[cfg_attr(feature = "jsonschema", derive(schemars::JsonSchema))]
24#[serde(rename_all = "camelCase")]
25pub struct AwsKmsKeyBinding {
26    pub key_arn: BindingValue<String>,
27    pub region: Option<BindingValue<String>>,
28}
29
30#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
31#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
32#[cfg_attr(feature = "jsonschema", derive(schemars::JsonSchema))]
33#[serde(rename_all = "camelCase")]
34pub struct GcpCloudKmsKeyBinding {
35    pub crypto_key_name: BindingValue<String>,
36}
37
38#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
39#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
40#[cfg_attr(feature = "jsonschema", derive(schemars::JsonSchema))]
41#[serde(rename_all = "camelCase")]
42pub struct AzureKeyVaultKeyBinding {
43    pub key_id: BindingValue<String>,
44}
45
46impl KeyBinding {
47    pub fn aws_kms(key_arn: impl Into<String>, region: Option<impl Into<String>>) -> Self {
48        Self::AwsKms(AwsKmsKeyBinding {
49            key_arn: key_arn.into().into(),
50            region: region.map(|value| value.into().into()),
51        })
52    }
53
54    pub fn gcp_cloud_kms(crypto_key_name: impl Into<String>) -> Self {
55        Self::GcpCloudKms(GcpCloudKmsKeyBinding {
56            crypto_key_name: crypto_key_name.into().into(),
57        })
58    }
59
60    pub fn azure_key_vault(key_id: impl Into<String>) -> Self {
61        Self::AzureKeyVault(AzureKeyVaultKeyBinding {
62            key_id: key_id.into().into(),
63        })
64    }
65}
66
67#[cfg(test)]
68mod tests {
69    use super::*;
70
71    #[test]
72    fn provider_tags_round_trip_without_ambiguity() {
73        let bindings = [
74            KeyBinding::aws_kms("arn:aws:kms:us-east-1:123:key/abc", Some("us-east-1")),
75            KeyBinding::gcp_cloud_kms(
76                "projects/example/locations/us/keyRings/data/cryptoKeys/customer",
77            ),
78            KeyBinding::azure_key_vault("https://example.vault.azure.net/keys/customer/version"),
79        ];
80
81        for binding in bindings {
82            let json = serde_json::to_value(&binding).unwrap();
83            assert_eq!(serde_json::from_value::<KeyBinding>(json).unwrap(), binding);
84        }
85    }
86}