-
Notifications
You must be signed in to change notification settings - Fork 0
/
enabled_apis.go
53 lines (46 loc) · 1.61 KB
/
enabled_apis.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
// Copyright 2019 Google LLC
//
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package rulegen
import (
"fmt"
"github.com/GoogleCloudPlatform/healthcare/deploy/config"
)
// EnabledAPIsRule represents a forseti enabled APIs rule.
type EnabledAPIsRule struct {
Name string `yaml:"name"`
Mode string `yaml:"mode"`
Resources []resource `yaml:"resource"`
Services []string `yaml:"services"`
}
// EnabledAPIsRules builds enabled APIs scanner rules for the given config.
func EnabledAPIsRules(conf *config.Config) ([]EnabledAPIsRule, error) {
rules := []EnabledAPIsRule{{
Name: "Global API whitelist.",
Mode: "whitelist",
Resources: []resource{{Type: "project", IDs: []string{"*"}}},
Services: conf.Overall.AllowedAPIs,
}}
for _, project := range conf.AllProjects() {
if len(project.EnabledAPIs) == 0 {
continue
}
rules = append(rules, EnabledAPIsRule{
Name: fmt.Sprintf("API whitelist for %s.", project.ID),
Mode: "whitelist",
Resources: []resource{{Type: "project", IDs: []string{project.ID}}},
Services: project.EnabledAPIs,
})
}
return rules, nil
}