-
Notifications
You must be signed in to change notification settings - Fork 1.4k
/
identity_provider.go
97 lines (85 loc) · 2.76 KB
/
identity_provider.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
package v1alpha5
import (
"encoding/json"
"github.com/pkg/errors"
)
type IdentityProviderType string
const (
OIDCIdentityProviderType IdentityProviderType = "oidc"
)
// IdentityProviderInterface is a dummy interface
// to give some extra type safety
type IdentityProviderInterface interface {
DeepCopyIdentityProviderInterface() IdentityProviderInterface
Type() IdentityProviderType
}
// The idea of the `IdentityProvider` struct is to hold an identity provider
// that can be parsed from the following JSON:
// {
// "name": "user-pool-1",
// "type": "oidc"
// }
// i.e. the type is found adjacent to the other fields of the object
//
// An `IdentityProvider` contains exactly one such identity provider
// which can be accessed with `Inner` and then cast and switched on
// with `.(type)` to get access to the specific type
// IdentityProvider holds an identity provider configuration.
// See [the example eksctl config](https://github.com/weaveworks/eksctl/blob/main/examples/27-oidc-provider.yaml).
// Schema type is one of `OIDCIdentityProvider`
type IdentityProvider struct {
// Valid variants are:
// `"oidc"`: OIDC identity provider
// +required
type_ string `json:"type"` //nolint
Inner IdentityProviderInterface
}
func FromIdentityProvider(idp IdentityProviderInterface) IdentityProvider {
return IdentityProvider{
type_: string(idp.Type()),
Inner: idp,
}
}
func (ip *IdentityProvider) UnmarshalJSON(data []byte) error {
var typ struct {
Type string `json:"type"`
}
if err := json.Unmarshal(data, &typ); err != nil {
return err
}
var inner IdentityProviderInterface
switch typ.Type {
case string(OIDCIdentityProviderType):
oidc := new(OIDCIdentityProvider)
if err := json.Unmarshal(data, oidc); err != nil {
return err
}
inner = oidc
default:
return errors.New("couldn't unmarshal to IdentityProvider, invalid type")
}
ip.Inner = inner
return nil
}
// OIDCIdentityProvider holds the spec of an OIDC provider
// to use for EKS authzn
type OIDCIdentityProvider struct {
// +required
Name string `json:"name,omitempty"`
// +required
IssuerURL string `json:"issuerURL,omitempty"`
// +required
ClientID string `json:"clientID,omitempty"`
UsernameClaim string `json:"usernameClaim,omitempty"`
UsernamePrefix string `json:"usernamePrefix,omitempty"`
GroupsClaim string `json:"groupsClaim,omitempty"`
GroupsPrefix string `json:"groupsPrefix,omitempty"`
RequiredClaims map[string]string `json:"requiredClaims,omitempty"`
Tags map[string]string `json:"tags,omitempty"`
}
func (p *OIDCIdentityProvider) DeepCopyIdentityProviderInterface() IdentityProviderInterface {
return p.DeepCopy()
}
func (p *OIDCIdentityProvider) Type() IdentityProviderType {
return OIDCIdentityProviderType
}