@relaycorp/webcrypto-kms
Version:
WebCrypto-compatible client for Key Management Services like GCP KMS
64 lines • 3.09 kB
JavaScript
;
var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
var desc = Object.getOwnPropertyDescriptor(m, k);
if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {
desc = { enumerable: true, get: function() { return m[k]; } };
}
Object.defineProperty(o, k2, desc);
}) : (function(o, m, k, k2) {
if (k2 === undefined) k2 = k;
o[k2] = m[k];
}));
var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {
Object.defineProperty(o, "default", { enumerable: true, value: v });
}) : function(o, v) {
o["default"] = v;
});
var __importStar = (this && this.__importStar) || function (mod) {
if (mod && mod.__esModule) return mod;
var result = {};
if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);
__setModuleDefault(result, mod);
return result;
};
Object.defineProperty(exports, "__esModule", { value: true });
exports.initGcpProvider = exports.initAwsProvider = exports.initKmsProviderFromEnv = void 0;
const env_var_1 = require("env-var");
const KmsError_1 = require("./KmsError");
const GcpKmsRsaPssProvider_1 = require("./gcp/GcpKmsRsaPssProvider");
const INITIALISERS = {
AWS: initAwsProvider,
GCP: initGcpProvider,
};
async function initKmsProviderFromEnv(adapter) {
const init = INITIALISERS[adapter];
if (!init) {
throw new KmsError_1.KmsError(`Invalid adapter (${adapter})`);
}
return init();
}
exports.initKmsProviderFromEnv = initKmsProviderFromEnv;
async function initAwsProvider() {
// Avoid import-time side effects (e.g., expensive API calls)
const { AwsKmsRsaPssProvider } = await Promise.resolve().then(() => __importStar(require('./aws/AwsKmsRsaPssProvider')));
const { KMSClient } = await Promise.resolve().then(() => __importStar(require('@aws-sdk/client-kms')));
return new AwsKmsRsaPssProvider(new KMSClient({
endpoint: (0, env_var_1.get)('AWS_KMS_ENDPOINT').asString(),
region: (0, env_var_1.get)('AWS_KMS_REGION').asString(),
}));
}
exports.initAwsProvider = initAwsProvider;
async function initGcpProvider() {
const kmsConfig = {
location: (0, env_var_1.get)('GCP_KMS_LOCATION').required().asString(),
keyRing: (0, env_var_1.get)('GCP_KMS_KEYRING').required().asString(),
protectionLevel: (0, env_var_1.get)('GCP_KMS_PROTECTION_LEVEL').required().asEnum(['SOFTWARE', 'HSM']),
destroyScheduledDurationSeconds: (0, env_var_1.get)('GCP_KMS_DESTROY_SCHEDULED_DURATION_SECONDS').asIntPositive(),
};
// Avoid import-time side effects (e.g., expensive API calls)
const { KeyManagementServiceClient } = await Promise.resolve().then(() => __importStar(require('@google-cloud/kms')));
return new GcpKmsRsaPssProvider_1.GcpKmsRsaPssProvider(new KeyManagementServiceClient(), kmsConfig);
}
exports.initGcpProvider = initGcpProvider;
//# sourceMappingURL=init.js.map