-
Notifications
You must be signed in to change notification settings - Fork 14
/
iam_org_policy.go
73 lines (57 loc) · 1.69 KB
/
iam_org_policy.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
package v2
import (
"context"
apiv2 "github.com/exoscale/egoscale/v2/api"
"github.com/exoscale/egoscale/v2/oapi"
)
// GetIAMOrgPolicy returns the IAM Organization policy.
func (c *Client) GetIAMOrgPolicy(ctx context.Context, zone string) (*IAMPolicy, error) {
resp, err := c.GetIamOrganizationPolicyWithResponse(apiv2.WithZone(ctx, zone))
if err != nil {
return nil, err
}
return iamPolicyFromAPI(resp.JSON200), nil
}
// UpdateIAMOrgPolicy updates existing IAM Organization policy.
func (c *Client) UpdateIAMOrgPolicy(ctx context.Context, zone string, policy *IAMPolicy) error {
req := oapi.UpdateIamOrganizationPolicyJSONRequestBody{
DefaultServiceStrategy: oapi.IamPolicyDefaultServiceStrategy(policy.DefaultServiceStrategy),
Services: oapi.IamPolicy_Services{
AdditionalProperties: map[string]oapi.IamServicePolicy{},
},
}
if len(policy.Services) > 0 {
for name, service := range policy.Services {
t := oapi.IamServicePolicy{
Type: (*oapi.IamServicePolicyType)(service.Type),
}
if service.Rules != nil {
rules := []oapi.IamServicePolicyRule{}
for _, rule := range service.Rules {
r := oapi.IamServicePolicyRule{
Action: (*oapi.IamServicePolicyRuleAction)(rule.Action),
Expression: rule.Expression,
}
rules = append(rules, r)
}
t.Rules = &rules
}
req.Services.AdditionalProperties[name] = t
}
}
resp, err := c.UpdateIamOrganizationPolicyWithResponse(
apiv2.WithZone(ctx, zone),
req,
)
if err != nil {
return err
}
_, err = oapi.NewPoller().
WithTimeout(c.timeout).
WithInterval(c.pollInterval).
Poll(ctx, oapi.OperationPoller(c, zone, *resp.JSON200.Id))
if err != nil {
return err
}
return nil
}