nifi icon indicating copy to clipboard operation
nifi copied to clipboard

NIFI-12061: add SECRET_NAME parameter to avoid listing all secrets

Open grishick opened this issue 1 year ago • 7 comments

Summary

NIFI-12061 Add Secret Name parameter to AwsSecretsManagerParameterProvider to allow the provider to work without ListSecrets permission. Original behavior where the provider lists all secrets and matches them to Secret Name Pattern is preserved by leaving Secret Name parameter undefined. The new behavior will skip listing secrets and ignore Secret Name Pattern only if Secret Name is provided. I made this change in Anetac's Nifi fork months ago and we are using it in production.

Tracking

Please complete the following tracking steps prior to pull request creation.

Issue Tracking

Pull Request Tracking

  • [x] Pull Request title starts with Apache NiFi Jira issue number, such as NIFI-12061
  • [x] Pull Request commit message starts with Apache NiFi Jira issue number, as such NIFI-12061

Pull Request Formatting

  • [x] Pull Request based on current revision of the support/nifi-1.x branch
  • [x] Pull Request refers to a feature branch with one commit containing changes

Verification

Please indicate the verification steps performed prior to pull request creation.

Build

  • [x] Build completed using mvn clean install -P contrib-check
    • [x] JDK 21

Licensing

  • [x] New dependencies are compatible with the Apache License 2.0 according to the License Policy
  • [x] New dependencies are documented in applicable LICENSE and NOTICE files

Documentation

  • [x] Documentation formatting appears as expected in rendered files

grishick avatar Oct 14 '24 00:10 grishick