github.com/zntrio/harp/v2@v2.0.9/pkg/vault/kv/secret_reader.go (about)

     1  // Licensed to Elasticsearch B.V. under one or more contributor
     2  // license agreements. See the NOTICE file distributed with
     3  // this work for additional information regarding copyright
     4  // ownership. Elasticsearch B.V. licenses this file to you under
     5  // the Apache License, Version 2.0 (the "License"); you may
     6  // not use this file except in compliance with the License.
     7  // You may obtain a copy of the License at
     8  //
     9  //     http://www.apache.org/licenses/LICENSE-2.0
    10  //
    11  // Unless required by applicable law or agreed to in writing,
    12  // software distributed under the License is distributed on an
    13  // "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
    14  // KIND, either express or implied.  See the License for the
    15  // specific language governing permissions and limitations
    16  // under the License.
    17  
    18  package kv
    19  
    20  import (
    21  	"context"
    22  	"fmt"
    23  
    24  	"github.com/hashicorp/vault/api"
    25  )
    26  
    27  // SecretGetter pull a secret from Vault using given path.
    28  //
    29  // To be used of template function.
    30  func SecretGetter(ctx context.Context, client *api.Client) func(string) (map[string]interface{}, error) {
    31  	return func(path string) (map[string]interface{}, error) {
    32  		// Create dedicated service reader
    33  		service, err := New(client, path, WithContext(ctx))
    34  		if err != nil {
    35  			return nil, fmt.Errorf("unable to prepare vault reader for path %q: %w", path, err)
    36  		}
    37  
    38  		// Delegate to reader
    39  		data, _, err := service.Read(ctx, path)
    40  		return data, err
    41  	}
    42  }