-
Notifications
You must be signed in to change notification settings - Fork 9
/
computeirsa.go
94 lines (77 loc) · 2.56 KB
/
computeirsa.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
// Copyright 2022 Namespace Labs Inc; All rights reserved.
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
package eks
import (
"context"
"fmt"
"github.com/spf13/cobra"
"google.golang.org/protobuf/encoding/prototext"
"namespacelabs.dev/foundation/internal/cli/fncobra"
"namespacelabs.dev/foundation/internal/console"
"namespacelabs.dev/foundation/internal/fnerrors"
"namespacelabs.dev/foundation/internal/providers/aws/eks"
"namespacelabs.dev/foundation/std/cfg"
"namespacelabs.dev/foundation/std/execution"
fneks "namespacelabs.dev/foundation/universe/aws/eks"
)
func newComputeIrsaCmd() *cobra.Command {
var iamRole, namespace, serviceAccount string
var dryRun bool
cmd := fncobra.CmdWithEnv(&cobra.Command{
Use: "compute-irsa",
Short: "Sets up IRSA for the specified IAM role and Service Account.",
Args: cobra.NoArgs,
}, func(ctx context.Context, env cfg.Context, args []string) error {
s, err := eks.NewSession(ctx, env.Configuration())
if err != nil {
return err
}
eksCluster, err := eks.PrepareClusterInfo(ctx, s)
if err != nil {
return err
}
if eksCluster == nil {
return fnerrors.New("not an eks cluster")
}
result, err := fneks.PrepareIrsa(eksCluster, iamRole, namespace, serviceAccount, nil)
if err != nil {
return err
}
p := execution.NewEmptyPlan()
for _, inv := range result.Invocations {
def, err := inv.ToDefinition()
if err != nil {
return err
}
if dryRun {
fmt.Fprintln(console.Stdout(ctx), prototext.Format(def))
} else {
p.Add(def)
}
}
if dryRun {
fmt.Fprintf(console.Stdout(ctx), "Not making changes to the cluster, as --dry_run=true.\n\n")
} else {
if err := execution.Execute(ctx, "eks.irsa.apply", p, nil, execution.FromContext(env)); err != nil {
return err
}
}
for _, ext := range result.Extensions {
def, err := ext.ToDefinition()
if err != nil {
return err
}
fmt.Fprintln(console.Stdout(ctx), prototext.Format(def))
}
return err
})
cmd.Flags().StringVar(&iamRole, "iam_role", "", "IAM Role to manage.")
cmd.Flags().StringVar(&namespace, "namespace", "", "Namespace where the service account lives.")
cmd.Flags().StringVar(&serviceAccount, "service_account", "", "Which service account to bind to IAM role.")
cmd.Flags().BoolVar(&dryRun, "dry_run", true, "If true, print invocations, rather than executing them.")
_ = cmd.MarkFlagRequired("iam_role")
_ = cmd.MarkFlagRequired("namespace")
_ = cmd.MarkFlagRequired("service_account")
return cmd
}