-
Notifications
You must be signed in to change notification settings - Fork 1
/
Copy pathapp.js
76 lines (61 loc) · 1.84 KB
/
app.js
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
var ROLEID = process.env.ROLEID;
var WRAP_SECRET_TOKEN = process.env.WST;
var VAULT_URL = 'http://54.224.180.35:8200';
if (!WRAP_SECRET_TOKEN) {
console.error('No wrap token');
process.exit();
}
var options = {
apiVersion: 'v1',
endpoint: VAULT_URL,
token: WRAP_SECRET_TOKEN
};
console.log('Wrapped secret token: ' + WRAP_SECRET_TOKEN);
var vault = require('node-vault')(options);
var secret = '';
vault
.unwrap()
.then(result => {
var secretId = result.data.secret_id;
console.log('Secret id: ' + result.data.secret_id);
vault
.approleLogin({ role_id: ROLEID, secret_id: secretId })
.then(login_result => {
var client_token = login_result.auth.client_token;
console.log('Client token: ' + client_token);
var client_options = {
apiVersion: 'v1',
endpoint: VAULT_URL,
token: client_token
};
var client_vault = require('node-vault')(client_options);
client_vault
.read('secret/secretapp/config')
.then(secretData => {
console.log(secretData);
secret = secretData;
});
});
})
.catch(console.error);
var express = require('express');
var app = express();
app.get('/', function(req, res) {
if (secret === '') {
res.statusMessage = 'It is a secret';
res.status(401).end();
} else {
res.send(secret);
}
});
app.get('/secret', function(req, res) {
res.send(
'Role id: ' +
process.env.ROLEID +
'<br />' +
'Wrapped secret token: ' +
process.env.WST
);
});
app.listen(process.env.PORT || 3000);
module.exports = app;