feat(server): enhance secret management and logging functionality

- Added SCRUNNER_SECRETS_KEY to README as a required variable for production.
- Implemented redaction of sensitive information in logs across various components.
- Enhanced script execution functions to include an owner parameter for better secret management.
- Introduced a secrets API in the script sandbox for retrieving and managing secrets.
- Updated UI components to support owner selection for script execution and secret management.
This commit is contained in:
2026-08-14 22:11:03 +07:00
parent 94aa5b2efa
commit 3e4d5f443d
19 changed files with 886 additions and 39 deletions
+11 -6
View File
@@ -207,12 +207,13 @@ export function createRegistry(server) {
* @param {string} runId
* @param {import("pino").Logger} runLog
* @param {string} key
* @param {string} owner
*/
async function runLinearSteps(compiled, ctx, runId, runLog, key) {
async function runLinearSteps(compiled, ctx, runId, runLog, key, owner) {
let next = ctx;
for (const index of compiled.order) {
const parsed = compiled.steps[index];
next = await runCompiledStep(parsed, next, index, runId, runLog, key);
next = await runCompiledStep(parsed, next, index, runId, runLog, key, owner);
}
return next;
}
@@ -223,8 +224,9 @@ export function createRegistry(server) {
* @param {string} runId
* @param {import("pino").Logger} runLog
* @param {string} key
* @param {string} owner
*/
async function runDagSteps(compiled, ctx, runId, runLog, key) {
async function runDagSteps(compiled, ctx, runId, runLog, key, owner) {
const triggerData = ctx.data;
/** @type {Map<string, unknown>} */
const outputsById = new Map();
@@ -240,6 +242,7 @@ export function createRegistry(server) {
runId,
runLog,
key,
owner,
);
if (parsed.id) {
outputsById.set(parsed.id, last);
@@ -255,8 +258,9 @@ export function createRegistry(server) {
* @param {string} runId
* @param {import("pino").Logger} runLog
* @param {string} key
* @param {string} owner
*/
async function runCompiledStep(parsed, ctx, index, runId, runLog, key) {
async function runCompiledStep(parsed, ctx, index, runId, runLog, key, owner) {
const script = parsed.kind === "set" ? SET_STEP_SCRIPT : parsed.script;
const config = parsed.config;
const step = await store.startStep({
@@ -287,6 +291,7 @@ export function createRegistry(server) {
const result = await runScript(script, { ...ctx, config }, {
log: stepLog,
workflowName: key,
owner,
});
await store.finishStep(step.id, "success", result);
return result;
@@ -327,9 +332,9 @@ export function createRegistry(server) {
try {
const compiled = compileWorkflowScripts(workflow.scripts);
if (compiled.dagMode) {
ctx = await runDagSteps(compiled, ctx, run.id, runLog, key);
ctx = await runDagSteps(compiled, ctx, run.id, runLog, key, owner);
} else {
ctx = await runLinearSteps(compiled, ctx, run.id, runLog, key);
ctx = await runLinearSteps(compiled, ctx, run.id, runLog, key, owner);
}
await store.finishRun(run.id, "success", ctx);
return { runId: run.id, status: "success", result: ctx };