alien-core 3.3.18

Deploy software into your customers' cloud accounts and keep it fully managed
Documentation
use crate::{
    error::{ErrorData, Result},
    resource::{ResourceDefinition, ResourceOutputsDefinition, ResourceRef, ResourceType},
};
use alien_error::AlienError;
use bon::Builder;
use serde::{Deserialize, Serialize};
use std::any::Any;

/// A customer-managed encryption key.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize, Builder)]
#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
#[serde(rename_all = "camelCase", deny_unknown_fields)]
#[builder(start_fn = new)]
pub struct Key {
    /// Identifier for the key resource.
    #[builder(start_fn)]
    pub id: String,
}

impl Key {
    pub const RESOURCE_TYPE: ResourceType = ResourceType::from_static("key");

    pub fn id(&self) -> &str {
        &self.id
    }
}

/// Stable identity of a provider key family.
///
/// Provider-native version rotation does not change this value. Replacing the
/// provider key does.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
#[serde(tag = "provider", rename_all = "lowercase", deny_unknown_fields)]
pub enum KeyFingerprint {
    /// An immutable AWS KMS key ARN. Alias ARNs are not accepted.
    Aws { key_arn: String },
    /// A full GCP CryptoKey resource name, without a CryptoKeyVersion.
    Gcp { crypto_key_name: String },
    /// An Azure Key Vault key family pinned to its original lineage.
    Azure {
        vault_resource_id: String,
        key_name: String,
        lineage_version_id: String,
    },
}

/// Outputs generated by a successfully provisioned Key.
#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[cfg_attr(feature = "openapi", derive(utoipa::ToSchema))]
#[serde(rename_all = "camelCase", deny_unknown_fields)]
pub struct KeyOutputs {
    /// Stable provider key-family identity.
    pub fingerprint: KeyFingerprint,
    /// Exact provider key version used for new wrapping operations.
    pub wrapping_key_id: String,
}

impl ResourceDefinition for Key {
    fn get_resource_type(&self) -> ResourceType {
        Self::RESOURCE_TYPE
    }

    fn id(&self) -> &str {
        &self.id
    }

    fn get_dependencies(&self) -> Vec<ResourceRef> {
        Vec::new()
    }

    fn validate_update(&self, new_config: &dyn ResourceDefinition) -> Result<()> {
        let Some(new_key) = new_config.as_any().downcast_ref::<Self>() else {
            return Err(AlienError::new(ErrorData::UnexpectedResourceType {
                resource_id: self.id.clone(),
                expected: Self::RESOURCE_TYPE,
                actual: new_config.get_resource_type(),
            }));
        };

        if self.id != new_key.id {
            return Err(AlienError::new(ErrorData::InvalidResourceUpdate {
                resource_id: self.id.clone(),
                reason: "the 'id' field is immutable".to_string(),
            }));
        }

        Ok(())
    }

    fn as_any(&self) -> &dyn Any {
        self
    }

    fn as_any_mut(&mut self) -> &mut dyn Any {
        self
    }

    fn box_clone(&self) -> Box<dyn ResourceDefinition> {
        Box::new(self.clone())
    }

    fn resource_eq(&self, other: &dyn ResourceDefinition) -> bool {
        other.as_any().downcast_ref::<Self>() == Some(self)
    }

    fn to_json_value(&self) -> serde_json::Result<serde_json::Value> {
        serde_json::to_value(self)
    }
}

impl ResourceOutputsDefinition for KeyOutputs {
    fn get_resource_type(&self) -> ResourceType {
        Key::RESOURCE_TYPE
    }

    fn as_any(&self) -> &dyn Any {
        self
    }

    fn box_clone(&self) -> Box<dyn ResourceOutputsDefinition> {
        Box::new(self.clone())
    }

    fn outputs_eq(&self, other: &dyn ResourceOutputsDefinition) -> bool {
        other.as_any().downcast_ref::<Self>() == Some(self)
    }

    fn to_json_value(&self) -> serde_json::Result<serde_json::Value> {
        serde_json::to_value(self)
    }
}

#[cfg(test)]
mod tests {
    use super::*;

    #[test]
    fn provider_rotation_preserves_the_key_family_fingerprint() {
        let fingerprint = KeyFingerprint::Gcp {
            crypto_key_name: "projects/example/locations/us/keyRings/data/cryptoKeys/customer"
                .to_string(),
        };
        let before = KeyOutputs {
            fingerprint: fingerprint.clone(),
            wrapping_key_id: "projects/example/locations/us/keyRings/data/cryptoKeys/customer/cryptoKeyVersions/1".to_string(),
        };
        let after = KeyOutputs {
            fingerprint,
            wrapping_key_id: "projects/example/locations/us/keyRings/data/cryptoKeys/customer/cryptoKeyVersions/2".to_string(),
        };

        assert_eq!(before.fingerprint, after.fingerprint);
        assert_ne!(before.wrapping_key_id, after.wrapping_key_id);
    }
}