|
7 | 7 |
|
8 | 8 | os.environ["LD_LIBRARY_PATH"] = str(Path(os.environ["CRYPT_SHARED_LIB_PATH"]).parent) |
9 | 9 |
|
| 10 | +AWS_CREDS = { |
| 11 | + "accessKeyId": os.environ.get("FLE_AWS_KEY", ""), |
| 12 | + "secretAccessKey": os.environ.get("FLE_AWS_SECRET", ""), |
| 13 | +} |
| 14 | + |
| 15 | +_USE_AWS_KMS = any(AWS_CREDS.values()) |
| 16 | + |
| 17 | +if _USE_AWS_KMS: |
| 18 | + _AWS_REGION = os.environ.get("FLE_AWS_KMS_REGION", "us-east-1") |
| 19 | + _AWS_KEY_ARN = os.environ.get( |
| 20 | + "FLE_AWS_KMS_KEY_ARN", |
| 21 | + "arn:aws:kms:us-east-1:579766882180:key/89fcc2c4-08b0-4bd9-9f25-e30687b580d0", |
| 22 | + ) |
| 23 | + KMS_PROVIDERS = {"aws": AWS_CREDS} |
| 24 | + KMS_CREDENTIALS = {"aws": {"key": _AWS_KEY_ARN, "region": _AWS_REGION}} |
| 25 | +else: |
| 26 | + KMS_PROVIDERS = {"local": {"key": os.urandom(96)}} |
| 27 | + KMS_CREDENTIALS = {"local": {}} |
| 28 | + |
10 | 29 | DATABASES["encrypted"] = { # noqa: F405 |
11 | 30 | "ENGINE": "django_mongodb_backend", |
12 | 31 | "NAME": "djangotests_encrypted", |
13 | 32 | "OPTIONS": { |
14 | 33 | "auto_encryption_opts": AutoEncryptionOpts( |
15 | 34 | key_vault_namespace="djangotests_encrypted.__keyVault", |
16 | | - kms_providers={"local": {"key": os.urandom(96)}}, |
| 35 | + kms_providers=KMS_PROVIDERS, |
17 | 36 | crypt_shared_lib_path=os.environ["CRYPT_SHARED_LIB_PATH"], |
| 37 | + crypt_shared_lib_required=True, |
18 | 38 | ), |
19 | 39 | "directConnection": True, |
20 | 40 | }, |
21 | | - "KMS_CREDENTIALS": {}, |
| 41 | + "KMS_CREDENTIALS": KMS_CREDENTIALS, |
22 | 42 | } |
23 | 43 |
|
24 | 44 |
|
|
0 commit comments