-
Notifications
You must be signed in to change notification settings - Fork 8
/
resource_grant_database_default_privilege.go
86 lines (66 loc) · 2.39 KB
/
resource_grant_database_default_privilege.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
package resources
import (
"context"
"github.com/MaterializeInc/terraform-provider-materialize/pkg/materialize"
"github.com/MaterializeInc/terraform-provider-materialize/pkg/utils"
"github.com/hashicorp/terraform-plugin-sdk/v2/diag"
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema"
)
var grantDatabaseDefaultPrivilegeSchema = map[string]*schema.Schema{
"grantee_name": GranteeNameSchema(),
"target_role_name": TargetRoleNameSchema(),
"privilege": PrivilegeSchema("DATABASE"),
"region": RegionSchema(),
}
func GrantDatabaseDefaultPrivilege() *schema.Resource {
return &schema.Resource{
Description: DefaultPrivilegeDefinition,
CreateContext: grantDatabaseDefaultPrivilegeCreate,
ReadContext: grantDefaultPrivilegeRead,
DeleteContext: grantDatabaseDefaultPrivilegeDelete,
Importer: &schema.ResourceImporter{
StateContext: schema.ImportStatePassthroughContext,
},
Schema: grantDatabaseDefaultPrivilegeSchema,
}
}
func grantDatabaseDefaultPrivilegeCreate(ctx context.Context, d *schema.ResourceData, meta interface{}) diag.Diagnostics {
granteeName := d.Get("grantee_name").(string)
targetName := d.Get("target_role_name").(string)
privilege := d.Get("privilege").(string)
metaDb, region, err := utils.GetDBClientFromMeta(meta, d)
if err != nil {
return diag.FromErr(err)
}
b := materialize.NewDefaultPrivilegeBuilder(metaDb, "DATABASE", granteeName, targetName, privilege)
// create resource
if err := b.Grant(); err != nil {
return diag.FromErr(err)
}
// Query ids
gId, err := materialize.RoleId(metaDb, granteeName)
if err != nil {
return diag.FromErr(err)
}
tId, err := materialize.RoleId(metaDb, targetName)
if err != nil {
return diag.FromErr(err)
}
key := b.GrantKey(string(region), "DATABASE", gId, tId, "", "", privilege)
d.SetId(key)
return grantDefaultPrivilegeRead(ctx, d, meta)
}
func grantDatabaseDefaultPrivilegeDelete(ctx context.Context, d *schema.ResourceData, meta interface{}) diag.Diagnostics {
granteenName := d.Get("grantee_name").(string)
targetName := d.Get("target_role_name").(string)
privilege := d.Get("privilege").(string)
metaDb, _, err := utils.GetDBClientFromMeta(meta, d)
if err != nil {
return diag.FromErr(err)
}
b := materialize.NewDefaultPrivilegeBuilder(metaDb, "DATABASE", granteenName, targetName, privilege)
if err := b.Revoke(); err != nil {
return diag.FromErr(err)
}
return nil
}