diff --git a/docs/data-sources/kms_key.md b/docs/data-sources/kms_key.md index 0c56a4c17..1f80073b6 100644 --- a/docs/data-sources/kms_key.md +++ b/docs/data-sources/kms_key.md @@ -41,5 +41,5 @@ data "stackit_kms_key" "key" { - `display_name` (String) The display name to distinguish multiple keys - `id` (String) Terraform's internal resource ID. It is structured as "`project_id`,`region`,`keyring_id`,`key_id`". - `import_only` (Boolean) States whether versions can be created or only imported. -- `protection` (String) The underlying system that is responsible for protecting the key material. Possible values are: `software`, `hsm`. +- `protection` (String) The underlying system that is responsible for protecting the key material. - `purpose` (String) The purpose for which the key will be used. Possible values are: `symmetric_encrypt_decrypt`, `asymmetric_encrypt_decrypt`, `message_authentication_code`, `asymmetric_sign_verify`. diff --git a/docs/data-sources/kms_wrapping_key.md b/docs/data-sources/kms_wrapping_key.md index c792666d1..f5076b62e 100644 --- a/docs/data-sources/kms_wrapping_key.md +++ b/docs/data-sources/kms_wrapping_key.md @@ -42,6 +42,6 @@ data "stackit_kms_wrapping_key" "example" { - `display_name` (String) The display name to distinguish multiple wrapping keys. - `expires_at` (String) The date and time the wrapping key will expire. - `id` (String) Terraform's internal resource ID. It is structured as "`project_id`,`region`,`keyring_id`,`wrapping_key_id`". -- `protection` (String) The underlying system that is responsible for protecting the key material. Possible values are: `software`, `hsm`. +- `protection` (String) The underlying system that is responsible for protecting the key material. - `public_key` (String) The public key of the wrapping key. - `purpose` (String) The purpose for which the key will be used. Possible values are: `wrap_symmetric_key`, `wrap_asymmetric_key`. diff --git a/docs/resources/kms_key.md b/docs/resources/kms_key.md index 49460a215..ea3a9308d 100644 --- a/docs/resources/kms_key.md +++ b/docs/resources/kms_key.md @@ -35,7 +35,7 @@ resource "stackit_kms_key" "key" { - `display_name` (String) The display name to distinguish multiple keys - `keyring_id` (String) The ID of the associated keyring - `project_id` (String) STACKIT project ID to which the key is associated. -- `protection` (String) The underlying system that is responsible for protecting the key material. Possible values are: `software`, `hsm`. +- `protection` (String) The underlying system that is responsible for protecting the key material. - `purpose` (String) The purpose for which the key will be used. Possible values are: `symmetric_encrypt_decrypt`, `asymmetric_encrypt_decrypt`, `message_authentication_code`, `asymmetric_sign_verify`. ### Optional diff --git a/docs/resources/kms_wrapping_key.md b/docs/resources/kms_wrapping_key.md index edd0ca57f..34552e20c 100644 --- a/docs/resources/kms_wrapping_key.md +++ b/docs/resources/kms_wrapping_key.md @@ -32,7 +32,7 @@ resource "stackit_kms_wrapping_key" "example" { - `display_name` (String) The display name to distinguish multiple wrapping keys. - `keyring_id` (String) The ID of the associated keyring - `project_id` (String) STACKIT project ID to which the keyring is associated. -- `protection` (String) The underlying system that is responsible for protecting the key material. Possible values are: `software`, `hsm`. +- `protection` (String) The underlying system that is responsible for protecting the key material. - `purpose` (String) The purpose for which the key will be used. Possible values are: `wrap_symmetric_key`, `wrap_asymmetric_key`. ### Optional diff --git a/go.mod b/go.mod index b3e27f065..5ca60f99a 100644 --- a/go.mod +++ b/go.mod @@ -23,7 +23,7 @@ require ( github.com/stackitcloud/stackit-sdk-go/services/git v0.14.0 github.com/stackitcloud/stackit-sdk-go/services/iaas v1.13.0 github.com/stackitcloud/stackit-sdk-go/services/intake v0.11.0 - github.com/stackitcloud/stackit-sdk-go/services/kms v1.12.0 + github.com/stackitcloud/stackit-sdk-go/services/kms v1.13.0 github.com/stackitcloud/stackit-sdk-go/services/loadbalancer v1.15.0 github.com/stackitcloud/stackit-sdk-go/services/logme v1.1.0 github.com/stackitcloud/stackit-sdk-go/services/logs v0.10.0 diff --git a/go.sum b/go.sum index 14ba1b024..e76c84efc 100644 --- a/go.sum +++ b/go.sum @@ -177,8 +177,8 @@ github.com/stackitcloud/stackit-sdk-go/services/iaas v1.13.0 h1:PQZ6n71CMadLU3Dj github.com/stackitcloud/stackit-sdk-go/services/iaas v1.13.0/go.mod h1:AbPN9BGkdjc+tVsXEX9Vr8BPDjdlDmG26K1FwCKZQVU= github.com/stackitcloud/stackit-sdk-go/services/intake v0.11.0 h1:zuZIWgm8ak6aOyvgHouIBSoAnUkNBy4HMSba5AHYI7U= github.com/stackitcloud/stackit-sdk-go/services/intake v0.11.0/go.mod h1:UXhPs7JXjQvTp14d4ZffSLnFMQyB7y1cj100XWwQudI= -github.com/stackitcloud/stackit-sdk-go/services/kms v1.12.0 h1:rydjdSL+j6Yd+3T7ks+JFkjKMh3a1RfBzTFZBTcdgds= -github.com/stackitcloud/stackit-sdk-go/services/kms v1.12.0/go.mod h1:pVaCmb1ZHAPGVRlSlBlVOjThp9Tb2sX9+nRX0M+d1KU= +github.com/stackitcloud/stackit-sdk-go/services/kms v1.13.0 h1:4S9gcTlijtvlF8wYZR5anbQ98oIP2+fIaEsvBXluux4= +github.com/stackitcloud/stackit-sdk-go/services/kms v1.13.0/go.mod h1:pVaCmb1ZHAPGVRlSlBlVOjThp9Tb2sX9+nRX0M+d1KU= github.com/stackitcloud/stackit-sdk-go/services/loadbalancer v1.15.0 h1:YWpy3VDKrTKVgvnHgbLFYRZ4qUKiNxzCejUNdWIYZ6Q= github.com/stackitcloud/stackit-sdk-go/services/loadbalancer v1.15.0/go.mod h1:+Ld3dn648I+YKcBV3fEkYpDSr3fel421+LurJGywSBs= github.com/stackitcloud/stackit-sdk-go/services/logme v1.1.0 h1:r+MzTC/qI8t4zTB029bp75iLzsx1/F4LzTiZeIwM5Vg= diff --git a/stackit/internal/services/kms/key/datasource.go b/stackit/internal/services/kms/key/datasource.go index dd5f431a2..802bd0a3d 100644 --- a/stackit/internal/services/kms/key/datasource.go +++ b/stackit/internal/services/kms/key/datasource.go @@ -109,7 +109,7 @@ func (k *keyDataSource) Schema(_ context.Context, _ datasource.SchemaRequest, re }, }, "protection": schema.StringAttribute{ - Description: fmt.Sprintf("The underlying system that is responsible for protecting the key material. %s", utils.FormatPossibleValues(sdkUtils.EnumSliceToStringSlice(kms.AllowedProtectionEnumValues)...)), + Description: "The underlying system that is responsible for protecting the key material.", Computed: true, Validators: []validator.String{ stringvalidator.LengthAtLeast(1), diff --git a/stackit/internal/services/kms/key/resource.go b/stackit/internal/services/kms/key/resource.go index f089e465d..52d9da100 100644 --- a/stackit/internal/services/kms/key/resource.go +++ b/stackit/internal/services/kms/key/resource.go @@ -193,7 +193,7 @@ func (r *keyResource) Schema(_ context.Context, _ resource.SchemaRequest, resp * }, }, "protection": schema.StringAttribute{ - Description: fmt.Sprintf("The underlying system that is responsible for protecting the key material. %s", utils.FormatPossibleValues(sdkUtils.EnumSliceToStringSlice(kms.AllowedProtectionEnumValues)...)), + Description: "The underlying system that is responsible for protecting the key material.", Required: true, PlanModifiers: []planmodifier.String{ stringplanmodifier.RequiresReplace(), @@ -453,7 +453,7 @@ func toCreatePayload(model *Model) (*kms.CreateKeyPayload, error) { return &kms.CreateKeyPayload{ AccessScope: accessScope, Algorithm: kms.Algorithm(model.Algorithm.ValueString()), - Protection: kms.Protection(model.Protection.ValueString()), + Protection: model.Protection.ValueString(), Description: conversion.StringValueToPointer(model.Description), DisplayName: model.DisplayName.ValueString(), ImportOnly: conversion.BoolValueToPointer(model.ImportOnly), diff --git a/stackit/internal/services/kms/key/resource_test.go b/stackit/internal/services/kms/key/resource_test.go index a875e19c5..ad79fb29a 100644 --- a/stackit/internal/services/kms/key/resource_test.go +++ b/stackit/internal/services/kms/key/resource_test.go @@ -40,7 +40,7 @@ func TestMapFields(t *testing.T) { input: &kms.Key{ Id: keyId, DisplayName: "display-name", - Protection: kms.PROTECTION_SOFTWARE, + Protection: "software", Algorithm: kms.ALGORITHM_ECDSA_P256_SHA256, Purpose: kms.PURPOSE_ASYMMETRIC_SIGN_VERIFY, AccessScope: kms.ACCESSSCOPE_PUBLIC, @@ -56,7 +56,7 @@ func TestMapFields(t *testing.T) { Id: types.StringValue(fmt.Sprintf("%s,eu01,%s,%s", projectId, keyRingId, keyId)), ProjectId: types.StringValue(projectId), Region: types.StringValue("eu01"), - Protection: types.StringValue(string(kms.PROTECTION_SOFTWARE)), + Protection: types.StringValue("software"), Algorithm: types.StringValue(string(kms.ALGORITHM_ECDSA_P256_SHA256)), Purpose: types.StringValue(string(kms.PURPOSE_ASYMMETRIC_SIGN_VERIFY)), AccessScope: types.StringValue(string(kms.ACCESSSCOPE_PUBLIC)), @@ -77,7 +77,7 @@ func TestMapFields(t *testing.T) { Description: new("descr"), DisplayName: "name", ImportOnly: true, - Protection: kms.PROTECTION_SOFTWARE, + Protection: "software", Algorithm: kms.ALGORITHM_AES_256_GCM, Purpose: kms.PURPOSE_MESSAGE_AUTHENTICATION_CODE, AccessScope: kms.ACCESSSCOPE_SNA, @@ -93,7 +93,7 @@ func TestMapFields(t *testing.T) { ProjectId: types.StringValue(projectId), Region: types.StringValue("eu01"), ImportOnly: types.BoolValue(true), - Protection: types.StringValue(string(kms.PROTECTION_SOFTWARE)), + Protection: types.StringValue("software"), Algorithm: types.StringValue(string(kms.ALGORITHM_AES_256_GCM)), Purpose: types.StringValue(string(kms.PURPOSE_MESSAGE_AUTHENTICATION_CODE)), AccessScope: types.StringValue(string(kms.ACCESSSCOPE_SNA)), diff --git a/stackit/internal/services/kms/kms_acc_test.go b/stackit/internal/services/kms/kms_acc_test.go index 75cf9aacf..ec8d90993 100644 --- a/stackit/internal/services/kms/kms_acc_test.go +++ b/stackit/internal/services/kms/kms_acc_test.go @@ -127,7 +127,7 @@ var testConfigWrappingKeyVarsMin = config.Variables{ "keyring_display_name": config.StringVariable("tf-acc-" + acctest.RandStringFromCharSet(8, acctest.CharSetAlpha)), "display_name": config.StringVariable("tf-acc-" + acctest.RandStringFromCharSet(8, acctest.CharSetAlpha)), "algorithm": config.StringVariable(string(kms.WRAPPINGALGORITHM_RSA_2048_OAEP_SHA256)), - "protection": config.StringVariable(string(kms.PROTECTION_SOFTWARE)), + "protection": config.StringVariable("software"), "purpose": config.StringVariable(string(kms.WRAPPINGPURPOSE_WRAP_SYMMETRIC_KEY)), } @@ -147,7 +147,7 @@ var testConfigWrappingKeyVarsMax = config.Variables{ "keyring_display_name": config.StringVariable("tf-acc-" + acctest.RandStringFromCharSet(8, acctest.CharSetAlpha)), "display_name": config.StringVariable("tf-acc-" + acctest.RandStringFromCharSet(8, acctest.CharSetAlpha)), "algorithm": config.StringVariable(string(kms.WRAPPINGALGORITHM_RSA_2048_OAEP_SHA256)), - "protection": config.StringVariable(string(kms.PROTECTION_SOFTWARE)), + "protection": config.StringVariable("software"), "purpose": config.StringVariable(string(kms.WRAPPINGPURPOSE_WRAP_SYMMETRIC_KEY)), "description": config.StringVariable("kms-wrapping-key-description"), "access_scope": config.StringVariable(string(kms.ACCESSSCOPE_PUBLIC)), diff --git a/stackit/internal/services/kms/wrapping-key/datasource.go b/stackit/internal/services/kms/wrapping-key/datasource.go index 977398d28..937c71224 100644 --- a/stackit/internal/services/kms/wrapping-key/datasource.go +++ b/stackit/internal/services/kms/wrapping-key/datasource.go @@ -84,7 +84,7 @@ func (w *wrappingKeyDataSource) Schema(_ context.Context, _ datasource.SchemaReq }, }, "protection": schema.StringAttribute{ - Description: fmt.Sprintf("The underlying system that is responsible for protecting the key material. %s", utils.FormatPossibleValues(sdkUtils.EnumSliceToStringSlice(kms.AllowedProtectionEnumValues)...)), + Description: "The underlying system that is responsible for protecting the key material.", Computed: true, }, "purpose": schema.StringAttribute{ diff --git a/stackit/internal/services/kms/wrapping-key/resource.go b/stackit/internal/services/kms/wrapping-key/resource.go index f2d5bb301..767be11d8 100644 --- a/stackit/internal/services/kms/wrapping-key/resource.go +++ b/stackit/internal/services/kms/wrapping-key/resource.go @@ -175,7 +175,7 @@ func (r *wrappingKeyResource) Schema(_ context.Context, _ resource.SchemaRequest }, }, "protection": schema.StringAttribute{ - Description: fmt.Sprintf("The underlying system that is responsible for protecting the key material. %s", utils.FormatPossibleValues(sdkUtils.EnumSliceToStringSlice(kms.AllowedProtectionEnumValues)...)), + Description: "The underlying system that is responsible for protecting the key material.", Required: true, PlanModifiers: []planmodifier.String{ stringplanmodifier.RequiresReplace(), @@ -461,7 +461,7 @@ func toCreatePayload(model *Model) (*kms.CreateWrappingKeyPayload, error) { Algorithm: kms.WrappingAlgorithm(model.Algorithm.ValueString()), Description: conversion.StringValueToPointer(model.Description), DisplayName: model.DisplayName.ValueString(), - Protection: kms.Protection(model.Protection.ValueString()), + Protection: model.Protection.ValueString(), Purpose: kms.WrappingPurpose(model.Purpose.ValueString()), }, nil } diff --git a/stackit/internal/services/kms/wrapping-key/resource_test.go b/stackit/internal/services/kms/wrapping-key/resource_test.go index 31762c42a..8647f4d8c 100644 --- a/stackit/internal/services/kms/wrapping-key/resource_test.go +++ b/stackit/internal/services/kms/wrapping-key/resource_test.go @@ -47,7 +47,7 @@ func TestMapFields(t *testing.T) { AccessScope: kms.ACCESSSCOPE_PUBLIC, Algorithm: kms.WRAPPINGALGORITHM_RSA_2048_OAEP_SHA256, Purpose: kms.WRAPPINGPURPOSE_WRAP_ASYMMETRIC_KEY, - Protection: kms.PROTECTION_SOFTWARE, + Protection: "software", PublicKey: new("public-key"), ExpiresAt: expiresAt, CreatedAt: createdAt, @@ -65,7 +65,7 @@ func TestMapFields(t *testing.T) { AccessScope: types.StringValue(string(kms.ACCESSSCOPE_PUBLIC)), Algorithm: types.StringValue(string(kms.WRAPPINGALGORITHM_RSA_2048_OAEP_SHA256)), Purpose: types.StringValue(string(kms.WRAPPINGPURPOSE_WRAP_ASYMMETRIC_KEY)), - Protection: types.StringValue(string(kms.PROTECTION_SOFTWARE)), + Protection: types.StringValue("software"), PublicKey: types.StringValue("public-key"), ExpiresAt: types.StringValue(expiresAt.Format(time.RFC3339)), CreatedAt: types.StringValue(createdAt.Format(time.RFC3339)), @@ -87,7 +87,7 @@ func TestMapFields(t *testing.T) { AccessScope: kms.ACCESSSCOPE_PUBLIC, Algorithm: kms.WRAPPINGALGORITHM_RSA_2048_OAEP_SHA256, Purpose: kms.WRAPPINGPURPOSE_WRAP_ASYMMETRIC_KEY, - Protection: kms.PROTECTION_SOFTWARE, + Protection: "software", PublicKey: new("public-key"), ExpiresAt: expiresAt, CreatedAt: createdAt, @@ -105,7 +105,7 @@ func TestMapFields(t *testing.T) { AccessScope: types.StringValue(string(kms.ACCESSSCOPE_PUBLIC)), Algorithm: types.StringValue(string(kms.WRAPPINGALGORITHM_RSA_2048_OAEP_SHA256)), Purpose: types.StringValue(string(kms.WRAPPINGPURPOSE_WRAP_ASYMMETRIC_KEY)), - Protection: types.StringValue(string(kms.PROTECTION_SOFTWARE)), + Protection: types.StringValue("software"), PublicKey: types.StringValue("public-key"), ExpiresAt: types.StringValue(expiresAt.Format(time.RFC3339)), CreatedAt: types.StringValue(createdAt.Format(time.RFC3339)),