/
put_vaultrole.go
139 lines (117 loc) · 3.77 KB
/
put_vaultrole.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
package command
import (
"encoding/json"
"fmt"
"os"
"strings"
"github.com/ibm/vault-cli/pkg/inventory"
vaultapi "github.com/ibm/vault-go/api/v1"
jsoniter "github.com/json-iterator/go"
"github.com/posener/complete"
"gopkg.in/yaml.v2"
)
type PutVaultRoleCommand struct {
Meta Meta
FlagPolicies string
FlagBoundNamespaces string
FlagBoundServiceAccountNames string
}
func (c *PutVaultRoleCommand) Help() string {
helpText := `
Usage: vault-cli put vaultrole [options]
General Options:
` + generalOptionsUsage() + `
`
return strings.TrimSpace(helpText)
}
func (c *PutVaultRoleCommand) AutocompleteFlags() complete.Flags {
return mergeAutocompleteFlags(c.Meta.AutocompleteFlags(),
complete.Flags{})
}
func (c *PutVaultRoleCommand) AutocompleteArgs() complete.Predictor {
return complete.PredictNothing
}
func (c *PutVaultRoleCommand) Synopsis() string {
return "Bootstrap the ACL system for initial token"
}
func (c *PutVaultRoleCommand) Name() string { return "acl bootstrap" }
func (c *PutVaultRoleCommand) Run(args []string) int {
// get the flags specific to this command
flagSet := c.Meta.FlagSet(c.Name())
flagSet.StringVar(&c.FlagPolicies, "policies", "", "")
flagSet.Usage = func() { c.Meta.Ui.Output(c.Help()) }
if err := flagSet.Parse(args); err != nil {
return 1
}
// process args
args = flagSet.Args()
filespec := args[0]
// load config
err := c.Meta.Load()
if err != nil {
fmt.Fprintf(os.Stderr, "Meta Load error: %s\n", err.Error())
return 1
}
files, err := inventory.GetFiles(c.Meta.CurrentContext.InventoryPath+"/vaultrole/", filespec)
if err != nil {
fmt.Printf("get files error: %s\n", err.Error())
return 1
}
if len(files) == 0 {
fmt.Printf("Vault Role (%s) not found in inventory", filespec)
return 1
}
for _, f := range files {
filename := c.Meta.CurrentContext.InventoryPath + "/vaultrole/" + f
data, err := inventory.ReadFile(filename + ".yaml")
if err != nil {
fmt.Println("error reading file: ", err.Error())
return 1
}
yamlbytes, err := c.Meta.TemplateService.Exec("VaultRole", data, c.Meta.flagData)
if err != nil {
fmt.Printf("unable to apply template to vaultrole: %s\n", err.Error())
return 1
}
vaultRole := vaultapi.VaultRole{}
err = yaml.Unmarshal(yamlbytes, &vaultRole)
if err != nil {
fmt.Printf("unable to marshal vaultrole: %s\n", err.Error())
return 1
}
authMethod := vaultRole.Spec.AuthMethod
roleName := vaultRole.Spec.RoleName
c.Meta.SecretService.GetClient().SetNamespace(vaultRole.Spec.VaultNamespace)
if c.FlagPolicies != "" {
pols := strings.Split(c.FlagPolicies, ",")
for _, v := range pols {
vaultRole.Spec.Data.Policies = append(vaultRole.Spec.Data.Policies, v)
vaultRole.Spec.Data.TokenPolicies = append(vaultRole.Spec.Data.TokenPolicies, v)
}
}
if c.FlagBoundNamespaces != "" {
pols := strings.Split(c.FlagBoundNamespaces, ",")
for _, v := range pols {
vaultRole.Spec.Data.BoundServiceAccountNamespaces = append(vaultRole.Spec.Data.BoundServiceAccountNamespaces, v)
}
}
if c.FlagBoundServiceAccountNames != "" {
bsans := strings.Split(c.FlagBoundServiceAccountNames, ",")
for _, v := range bsans {
vaultRole.Spec.Data.BoundServiceAccountNames = append(vaultRole.Spec.Data.BoundServiceAccountNames, v)
}
}
// unmarshal the data
pkiiter := jsoniter.Config{TagKey: "vault"}.Froze()
data, err = pkiiter.Marshal(vaultRole.Spec.Data)
m := make(map[string]interface{})
json.Unmarshal(data, &m)
_, err = c.Meta.SecretService.Write(fmt.Sprintf("auth/%s/role/%s", authMethod, roleName), m)
if err != nil {
fmt.Printf("Role (%s) %s", filename, err)
return 1
}
fmt.Printf(string("Role: %s.yaml, Method: %s, Name: %s write OK\n"), filename, authMethod, roleName)
}
return 0
}