-
Notifications
You must be signed in to change notification settings - Fork 1.8k
ci(NODE-6685): use secrets manager for FLE tests and consolidate FLE setup in CI tooling #4386
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
test/integration/client-side-operations-timeout/client_side_operations_timeout.unit.test.ts
Show resolved
Hide resolved
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
d6a7c8a
to
75f17ee
Compare
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
baileympearson
commented
Jan 30, 2025
durran
requested changes
Jan 31, 2025
durran
approved these changes
Jan 31, 2025
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
What is changing?
Okay, this might look like a huge PR but I promise the changes are pretty manageable, just bear with me as I explain the changes overall. There's a lot of deleted code here too 🙂
I started out making this a preliminary refactor before migrating to secrets manager. However, once I finished the refactor, I realized I was basically already there so I just made the last change and voila.
a. This script fetches all credentials from secrets-manager (replacing some coming from our evergreen project and then loading them with prepare_client_encryption.sh).
b. Secrets manager automatically loads environment variables containing paths to the necessary certificate files, so this is handled automatically. But the names are different (see bullet 2).
c. Downloads crypt_shared and adds it to the path (or not, when we don't want it).
Notably, I haven't made changes to how we launch kms/kmip servers. drivers-evergreen-tools has tooling to start and stop these servers for us, but the ports it launches on are different from our ports, so for the sake of PR size I left that alone. I am happy to reconsider and instead use the shared kms server tooling.
1 except launching KMS servers
Is there new documentation needed for these changes?
no.
What is the motivation for this change?
Release Highlight
Fill in title or leave empty for no highlight
Double check the following
npm run check:lint
scripttype(NODE-xxxx)[!]: description
feat(NODE-1234)!: rewriting everything in coffeescript