Skip to content

feat: extract activity audit logs to salt #46

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 6 additions & 5 deletions cmd/serve.go
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,7 @@ import (
"time"

_ "github.com/authzed/authzed-go/proto/authzed/api/v0"
auditrepository "github.com/goto/salt/audit/repositories"
_ "github.com/jackc/pgx/v4/stdlib"
newrelic "github.com/newrelic/go-agent"
"go.uber.org/zap"
Expand Down Expand Up @@ -55,7 +56,7 @@ func StartServer(logger *log.Zap, cfg *config.Shield) error {
ctx, cancelFunc := signal.NotifyContext(context.Background(), syscall.SIGTERM, syscall.SIGINT)
defer cancelFunc()

dbClient, err := setupDB(cfg.DB, logger)
dbClient, err := setupDB(cfg.DB)
if err != nil {
return err
}
Expand Down Expand Up @@ -98,15 +99,15 @@ func StartServer(logger *log.Zap, cfg *config.Shield) error {
var activityRepository activity.Repository
switch cfg.Log.Activity.Sink {
case activity.SinkTypeDB:
activityRepository = postgres.NewActivityRepository(dbClient)
activityRepository = postgres.NewAuditActivityRepository(dbClient)
case activity.SinkTypeStdout:
stdoutLogger, err := zap.NewStdLogAt(logger.GetInternalZapLogger().Desugar(), logger.GetInternalZapLogger().Level())
if err != nil {
return err
}
activityRepository = activity.NewStdoutRepository(stdoutLogger.Writer())
activityRepository = auditrepository.NewStdoutRepository(stdoutLogger.Writer())
default:
activityRepository = activity.NewStdoutRepository(io.Discard)
activityRepository = auditrepository.NewStdoutRepository(io.Discard)
}
activityService := activity.NewService(appConfig, activityRepository)

Expand Down Expand Up @@ -261,7 +262,7 @@ func setupNewRelic(cfg config.NewRelic, logger log.Logger) (newrelic.Application
return nil, nil
}

func setupDB(cfg db.Config, logger log.Logger) (dbc *db.Client, err error) {
func setupDB(cfg db.Config) (dbc *db.Client, err error) {
// prefer use pgx instead of lib/pq for postgres to catch pg error
if cfg.Driver == "postgres" {
cfg.Driver = "pgx"
Expand Down
3 changes: 2 additions & 1 deletion core/activity/activity.go
Original file line number Diff line number Diff line change
Expand Up @@ -14,8 +14,9 @@ const (
)

type Repository interface {
Init(context.Context) error
Insert(ctx context.Context, log *audit.Log) error
List(ctx context.Context, filter Filter) ([]audit.Log, error)
List(ctx context.Context, filter audit.Filter) ([]audit.Log, error)
}

type AppConfig struct {
Expand Down
48 changes: 26 additions & 22 deletions core/activity/service.go
Original file line number Diff line number Diff line change
Expand Up @@ -2,21 +2,22 @@ package activity

import (
"context"
"time"

"github.com/goto/salt/audit"
"github.com/mitchellh/mapstructure"
)

type Service struct {
appConfig AppConfig
repository Repository
appConfig AppConfig
auditService *audit.Service
repository Repository
}

func NewService(appConfig AppConfig, repository Repository) *Service {
return &Service{
appConfig: appConfig,
repository: repository,
appConfig: appConfig,
repository: repository,
auditService: audit.New(audit.WithRepository(repository)),
}
}

Expand All @@ -30,34 +31,37 @@ func (s Service) Log(ctx context.Context, action string, actor string, data any)
return err
}

metadata := map[string]string{
metadata := map[string]any{
"app_name": "shield",
"app_version": s.appConfig.Version,
}

log := &audit.Log{
Timestamp: time.Now(),
Action: action,
Data: logDataMap,
Actor: actor,
Metadata: metadata,
ctx = audit.WithActor(ctx, actor)
ctx, err := audit.WithMetadata(ctx, metadata)
if err != nil {
return err
}

return s.repository.Insert(ctx, log)
return s.auditService.Log(ctx, action, logDataMap)
}

func (s Service) List(ctx context.Context, filter Filter) (PagedActivity, error) {
if !filter.EndTime.IsZero() && !filter.StartTime.IsZero() && filter.EndTime.Before(filter.StartTime) {
return PagedActivity{}, ErrInvalidFilter
}

activities, err := s.repository.List(ctx, filter)
func (s Service) List(ctx context.Context, flt Filter) (PagedActivity, error) {
pagedLogs, err := s.auditService.List(ctx, audit.Filter{
Actor: flt.Actor,
Action: flt.Action,
Data: flt.Data,
Metadata: flt.Metadata,
StartTime: flt.StartTime,
EndTime: flt.EndTime,
Limit: flt.Limit,
Page: flt.Page,
})
if err != nil {
return PagedActivity{}, err
return PagedActivity{}, nil
}

return PagedActivity{
Count: int32(len(activities)),
Activities: activities,
Count: pagedLogs.Count,
Activities: pagedLogs.Logs,
}, nil
}
27 changes: 0 additions & 27 deletions core/activity/stdout_repository.go

This file was deleted.

86 changes: 46 additions & 40 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -7,22 +7,22 @@ require (
github.com/MakeNowJust/heredoc v1.0.0
github.com/abbot/go-http-auth v0.4.0
github.com/authzed/authzed-go v0.7.1-0.20221109204547-1aa903788b3b
github.com/authzed/grpcutil v0.0.0-20230109193425-40ce0530e048
github.com/authzed/grpcutil v0.0.0-20230908193239-4286bb1d6403
github.com/authzed/spicedb v1.15.0
github.com/doug-martin/goqu/v9 v9.18.0
github.com/envoyproxy/protoc-gen-validate v0.9.1
github.com/envoyproxy/protoc-gen-validate v1.0.2
github.com/ghodss/yaml v1.0.0
github.com/golang-migrate/migrate/v4 v4.15.2
github.com/golang/protobuf v1.5.2
github.com/google/go-cmp v0.5.9
github.com/google/uuid v1.3.0
github.com/golang-migrate/migrate/v4 v4.16.0
github.com/golang/protobuf v1.5.3
github.com/google/go-cmp v0.6.0
github.com/google/uuid v1.3.1
github.com/gorilla/mux v1.8.0
github.com/goto/salt v0.3.0
github.com/grpc-ecosystem/go-grpc-middleware v1.3.0
github.com/grpc-ecosystem/grpc-gateway/v2 v2.15.0
github.com/jackc/pgconn v1.13.0
github.com/goto/salt v0.3.6-0.20240424230902-5eb203bb515d
github.com/grpc-ecosystem/go-grpc-middleware v1.4.0
github.com/grpc-ecosystem/grpc-gateway/v2 v2.16.0
github.com/jackc/pgconn v1.14.0
github.com/jackc/pgerrcode v0.0.0-20220416144525-469b46aa5efa
github.com/jackc/pgx/v4 v4.17.2
github.com/jackc/pgx/v4 v4.18.1
github.com/jhump/protoreflect v1.14.0
github.com/jmoiron/sqlx v1.3.5
github.com/julienschmidt/httprouter v1.3.0
Expand All @@ -42,26 +42,26 @@ require (
go.opencensus.io v0.24.0
go.uber.org/zap v1.24.0
gocloud.dev v0.28.0
golang.org/x/exp v0.0.0-20230108222341-4b8118a2686a
golang.org/x/net v0.8.0
golang.org/x/oauth2 v0.4.0
google.golang.org/genproto v0.0.0-20230109162033-3c3c17ce83e6
google.golang.org/grpc v1.52.0
google.golang.org/protobuf v1.28.1
golang.org/x/exp v0.0.0-20230315142452-642cacee5cc0
golang.org/x/net v0.17.0
golang.org/x/oauth2 v0.13.0
google.golang.org/genproto/googleapis/api v0.0.0-20231002182017-d307bd883b97
google.golang.org/grpc v1.60.1
google.golang.org/protobuf v1.32.0
gopkg.in/yaml.v2 v2.4.0
gopkg.in/yaml.v3 v3.0.1
)

require github.com/oklog/run v1.1.0 // indirect

require (
cloud.google.com/go v0.108.0 // indirect
cloud.google.com/go/compute v1.15.0 // indirect
cloud.google.com/go v0.110.8 // indirect
cloud.google.com/go/compute v1.23.0 // indirect
cloud.google.com/go/compute/metadata v0.2.3 // indirect
cloud.google.com/go/iam v0.10.0 // indirect
cloud.google.com/go/storage v1.28.1 // indirect
github.com/Azure/go-ansiterm v0.0.0-20210617225240-d185dfc1b5a1 // indirect
github.com/Microsoft/go-winio v0.5.2 // indirect
cloud.google.com/go/iam v1.1.2 // indirect
cloud.google.com/go/storage v1.30.1 // indirect
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
github.com/Microsoft/go-winio v0.6.1 // indirect
github.com/Nvveen/Gotty v0.0.0-20120604004816-cd527374f1e5 // indirect
github.com/alecthomas/chroma v0.10.0 // indirect
github.com/antlr/antlr4/runtime/Go/antlr v1.4.10 // indirect
Expand All @@ -71,7 +71,7 @@ require (
github.com/briandowns/spinner v1.20.0 // indirect
github.com/cenkalti/backoff v2.2.1+incompatible // indirect
github.com/certifi/gocertifi v0.0.0-20210507211836-431795d63e8d // indirect
github.com/cespare/xxhash/v2 v2.1.2 // indirect
github.com/cespare/xxhash/v2 v2.2.0 // indirect
github.com/charmbracelet/glamour v0.6.0 // indirect
github.com/cli/safeexec v1.0.1 // indirect
github.com/containerd/continuity v0.3.0 // indirect
Expand All @@ -91,10 +91,11 @@ require (
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect
github.com/google/cel-go v0.13.0 // indirect
github.com/google/pprof v0.0.0-20221219190121-3cb0bae90811 // indirect
github.com/google/s2a-go v0.1.4 // indirect
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
github.com/google/wire v0.5.0 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.2.1 // indirect
github.com/googleapis/gax-go/v2 v2.7.0 // indirect
github.com/googleapis/enterprise-certificate-proxy v0.2.4 // indirect
github.com/googleapis/gax-go/v2 v2.12.0 // indirect
github.com/gorilla/css v1.0.0 // indirect
github.com/gotestyourself/gotestyourself v2.2.0+incompatible // indirect
github.com/hashicorp/errwrap v1.1.0 // indirect
Expand All @@ -104,17 +105,17 @@ require (
github.com/jackc/chunkreader/v2 v2.0.1 // indirect
github.com/jackc/pgio v1.0.0 // indirect
github.com/jackc/pgpassfile v1.0.0 // indirect
github.com/jackc/pgproto3/v2 v2.3.1 // indirect
github.com/jackc/pgproto3/v2 v2.3.2 // indirect
github.com/jackc/pgservicefile v0.0.0-20221227161230-091c0ba34f0a // indirect
github.com/jackc/pgtype v1.13.0 // indirect
github.com/jackc/pgtype v1.14.0 // indirect
github.com/jeremywohl/flatten v1.0.1 // indirect
github.com/jzelinskie/stringz v0.0.1 // indirect
github.com/lucasb-eyer/go-colorful v1.2.0 // indirect
github.com/magiconair/properties v1.8.7 // indirect
github.com/mattn/go-colorable v0.1.13 // indirect
github.com/mattn/go-isatty v0.0.18 // indirect
github.com/mattn/go-runewidth v0.0.14 // indirect
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 // indirect
github.com/matttproud/golang_protobuf_extensions v1.0.4 // indirect
github.com/microcosm-cc/bluemonday v1.0.21 // indirect
github.com/mitchellh/colorstring v0.0.0-20190213212951-d06e56a500db // indirect
github.com/muesli/reflow v0.3.0 // indirect
Expand All @@ -125,16 +126,16 @@ require (
github.com/opencontainers/runc v1.1.2 // indirect
github.com/pelletier/go-toml/v2 v2.0.6 // indirect
github.com/pmezard/go-difflib v1.0.0 // indirect
github.com/prometheus/client_golang v1.13.1 // indirect
github.com/prometheus/client_model v0.3.0 // indirect
github.com/prometheus/common v0.37.0 // indirect
github.com/prometheus/procfs v0.8.0 // indirect
github.com/prometheus/client_golang v1.17.0 // indirect
github.com/prometheus/client_model v0.4.1-0.20230718164431-9a2bf3000d16 // indirect
github.com/prometheus/common v0.44.0 // indirect
github.com/prometheus/procfs v0.11.1 // indirect
github.com/prometheus/statsd_exporter v0.22.7 // indirect
github.com/rivo/uniseg v0.4.4 // indirect
github.com/rs/zerolog v1.29.0 // indirect
github.com/russross/blackfriday/v2 v2.1.0 // indirect
github.com/schollz/progressbar/v3 v3.13.0 // indirect
github.com/sirupsen/logrus v1.9.0 // indirect
github.com/sirupsen/logrus v1.9.2 // indirect
github.com/spf13/cast v1.5.0 // indirect
github.com/spf13/jwalterweatherman v1.1.0 // indirect
github.com/spf13/pflag v1.0.5 // indirect
Expand All @@ -148,12 +149,17 @@ require (
github.com/yuin/goldmark-emoji v1.0.1 // indirect
go.uber.org/atomic v1.10.0 // indirect
go.uber.org/multierr v1.9.0 // indirect
golang.org/x/crypto v0.5.0 // indirect
golang.org/x/sys v0.7.0 // indirect
golang.org/x/term v0.6.0 // indirect
golang.org/x/text v0.8.0 // indirect
golang.org/x/crypto v0.14.0 // indirect
golang.org/x/mod v0.11.0 // indirect
golang.org/x/sync v0.4.0 // indirect
golang.org/x/sys v0.16.0 // indirect
golang.org/x/term v0.13.0 // indirect
golang.org/x/text v0.13.0 // indirect
golang.org/x/tools v0.10.0 // indirect
golang.org/x/xerrors v0.0.0-20220907171357-04be3eba64a2 // indirect
google.golang.org/api v0.107.0 // indirect
google.golang.org/appengine v1.6.7 // indirect
google.golang.org/api v0.128.0 // indirect
google.golang.org/appengine v1.6.8 // indirect
google.golang.org/genproto v0.0.0-20231002182017-d307bd883b97 // indirect
google.golang.org/genproto/googleapis/rpc v0.0.0-20231002182017-d307bd883b97 // indirect
gopkg.in/ini.v1 v1.67.0 // indirect
)
Loading
Loading