Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove storage account network rule #2

Merged
merged 5 commits into from
Mar 31, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 2 additions & 14 deletions src/storage-preview/azext_storage_preview/_params.py
Original file line number Diff line number Diff line change
Expand Up @@ -379,6 +379,8 @@ def load_arguments(self, _): # pylint: disable=too-many-locals, too-many-statem
c.argument('public_network_access', arg_type=get_enum_type(public_network_access_enum), min_api='2021-06-01',
help='Enable or disable public network access to the storage account. '
'Possible values include: `Enabled` or `Disabled`.')
c.argument('account_name', acct_name_type, options_list=['--name', '-n'])
c.argument('resource_group_name', required=False, validator=process_resource_group)

for scope in ['storage account create', 'storage account update']:
with self.argument_context(scope, arg_group='Customer managed key', min_api='2017-06-01',
Expand Down Expand Up @@ -417,20 +419,6 @@ def load_arguments(self, _): # pylint: disable=too-many-locals, too-many-statem
c.argument('vnet_name', help='Name of a virtual network.', validator=validate_subnet)
c.argument('action', action_type)

for item in ['update', 'network-rule']:
with self.argument_context('storage account {}'.format(item)) as c:
c.argument('account_name', acct_name_type, options_list=['--name', '-n'])
c.argument('resource_group_name', required=False, validator=process_resource_group)

with self.argument_context('storage account network-rule') as c:
c.argument('account_name', acct_name_type, id_part=None)
c.argument('ip_address', help='IPv4 address or CIDR range.')
c.argument('subnet', help='Name or ID of subnet. If name is supplied, `--vnet-name` must be supplied.')
c.argument('vnet_name', help='Name of a virtual network.', validator=validate_subnet)
c.argument('action', help='The action of virtual network rule.')
c.argument('resource_id', help='The resource id to add in network rule.')
c.argument('tenant_id', help='The tenant id to add in network rule.')

with self.argument_context('storage account local-user') as c:
c.argument('account_name', acct_name_type, options_list='--account-name', id_part=None)
c.argument('username', options_list=['--username', '--name', '-n'],
Expand Down
7 changes: 0 additions & 7 deletions src/storage-preview/azext_storage_preview/commands.py
Original file line number Diff line number Diff line change
Expand Up @@ -44,13 +44,6 @@ def get_custom_sdk(custom_module, client_factory, resource_type=CUSTOM_DATA_STOR
g.generic_update_command('update', getter_name='get_properties', setter_name='update',
custom_func_name='update_storage_account')

with self.command_group('storage account network-rule', storage_account_sdk,
custom_command_type=storage_account_custom_type,
resource_type=CUSTOM_MGMT_STORAGE, min_api='2017-06-01') as g:
g.custom_command('add', 'add_network_rule')
g.custom_command('list', 'list_network_rules')
g.custom_command('remove', 'remove_network_rule')

local_users_sdk = CliCommandType(
operations_tmpl='azext_storage_preview.vendored_sdks.azure_mgmt_storage.operations#'
'LocalUsersOperations.{}',
Expand Down
60 changes: 0 additions & 60 deletions src/storage-preview/azext_storage_preview/operations/account.py
Original file line number Diff line number Diff line change
Expand Up @@ -621,66 +621,6 @@ def update_blob_inventory_policy(cmd, client, resource_group_name, account_name,
blob_inventory_policy_name=BlobInventoryPolicyName.DEFAULT, properties=parameters)


def list_network_rules(client, resource_group_name, account_name):
sa = client.get_properties(resource_group_name, account_name)
rules = sa.network_rule_set
delattr(rules, 'bypass')
delattr(rules, 'default_action')
return rules


def add_network_rule(cmd, client, resource_group_name, account_name, action='Allow', subnet=None,
vnet_name=None, ip_address=None, tenant_id=None, resource_id=None): # pylint: disable=unused-argument
sa = client.get_properties(resource_group_name, account_name)
rules = sa.network_rule_set
if subnet:
from msrestazure.tools import is_valid_resource_id
if not is_valid_resource_id(subnet):
raise CLIError("Expected fully qualified resource ID: got '{}'".format(subnet))
VirtualNetworkRule = cmd.get_models('VirtualNetworkRule')
if not rules.virtual_network_rules:
rules.virtual_network_rules = []
rules.virtual_network_rules = [r for r in rules.virtual_network_rules
if r.virtual_network_resource_id.lower() != subnet.lower()]
rules.virtual_network_rules.append(VirtualNetworkRule(virtual_network_resource_id=subnet, action=action))
if ip_address:
IpRule = cmd.get_models('IPRule')
if not rules.ip_rules:
rules.ip_rules = []
rules.ip_rules = [r for r in rules.ip_rules if r.ip_address_or_range != ip_address]
rules.ip_rules.append(IpRule(ip_address_or_range=ip_address, action=action))
if resource_id:
ResourceAccessRule = cmd.get_models('ResourceAccessRule')
if not rules.resource_access_rules:
rules.resource_access_rules = []
rules.resource_access_rules = [r for r in rules.resource_access_rules if r.resource_id !=
resource_id or r.tenant_id != tenant_id]
rules.resource_access_rules.append(ResourceAccessRule(tenant_id=tenant_id, resource_id=resource_id))

StorageAccountUpdateParameters = cmd.get_models('StorageAccountUpdateParameters')
params = StorageAccountUpdateParameters(network_rule_set=rules)
return client.update(resource_group_name, account_name, params)


def remove_network_rule(cmd, client, resource_group_name, account_name, ip_address=None, subnet=None,
vnet_name=None, tenant_id=None, resource_id=None): # pylint: disable=unused-argument
sa = client.get_properties(resource_group_name, account_name)
rules = sa.network_rule_set
if subnet:
rules.virtual_network_rules = [x for x in rules.virtual_network_rules
if not x.virtual_network_resource_id.endswith(subnet)]
if ip_address:
rules.ip_rules = [x for x in rules.ip_rules if x.ip_address_or_range != ip_address]

if resource_id:
rules.resource_access_rules = [x for x in rules.resource_access_rules if
not (x.tenant_id == tenant_id and x.resource_id == resource_id)]

StorageAccountUpdateParameters = cmd.get_models('StorageAccountUpdateParameters')
params = StorageAccountUpdateParameters(network_rule_set=rules)
return client.update(resource_group_name, account_name, params)


def create_management_policies(client, resource_group_name, account_name, policy=None):
if policy:
if os.path.exists(policy):
Expand Down
Loading