Add volume and image encryption feature

Signed-off-by: andy.lee <andy.lee@suse.com>
This commit is contained in:
andy.lee
2024-10-23 17:01:27 +02:00
committed by Francesco Torchia
parent 68b264dca1
commit 7f72fdf2c5
10 changed files with 340 additions and 30 deletions
@@ -37,7 +37,7 @@ export default class HciPv extends HarvesterResource {
return [
{
action: 'exportImage',
enabled: this.hasAction('export'),
enabled: this.hasAction('export') && !this.isEncrypted,
icon: 'icon icon-copy',
label: this.t('harvester.action.exportImage')
},
@@ -213,6 +213,14 @@ export default class HciPv extends HarvesterResource {
return false;
}
get isEncrypted() {
const inStore = this.$rootGetters['currentProduct'].inStore;
const longhornVolume = this.$rootGetters[`${ inStore }/all`](LONGHORN.VOLUMES).find(v => v.metadata?.name === this.spec?.volumeName);
return longhornVolume?.spec.encrypted || false;
}
get longhornVolume() {
const inStore = this.$rootGetters['currentProduct'].inStore;
@@ -11,6 +11,12 @@ import { _CLONE } from '@shell/config/query-params';
import { HCI } from '../types';
import { PRODUCT_NAME as HARVESTER_PRODUCT } from '../config/harvester';
import HarvesterResource from './harvester';
import { CSI_SECRETS } from '@pkg/harvester/config/harvester-map';
const {
CSI_PROVISIONER_SECRET_NAME,
CSI_PROVISIONER_SECRET_NAMESPACE,
} = CSI_SECRETS;
function isReady() {
function getStatusConditionOfType(type, defaultValue = []) {
@@ -127,6 +133,24 @@ export default class HciVmImage extends HarvesterResource {
return stateDisplay(this.metadata.state.name);
}
get encryptionSecret() {
const secretNS = this.spec.storageClassParameters[CSI_PROVISIONER_SECRET_NAMESPACE];
const secretName = this.spec.storageClassParameters[CSI_PROVISIONER_SECRET_NAME];
if (secretNS && secretName) {
return `${ secretNS }/${ secretName }`;
}
return '';
}
get isEncrypted() {
return this.spec.sourceType === 'clone' &&
this.spec.securityParameters?.cryptoOperation === 'encrypt' &&
!!this.spec.securityParameters?.sourceImageName &&
!!this.spec.securityParameters?.sourceImageNamespace;
}
get imageMessage() {
if (this.uploadError) {
return ucFirst(this.uploadError);