/
resource_cloud_project_containerregistry_ip_restrictions_registry.go
173 lines (135 loc) · 5.53 KB
/
resource_cloud_project_containerregistry_ip_restrictions_registry.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
package ovh
import (
"errors"
"fmt"
"log"
"net"
"net/url"
"strings"
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema"
"github.com/ovh/terraform-provider-ovh/ovh/helpers"
)
func resourceCloudProjectContainerRegistryIPRestrictionsRegistry() *schema.Resource {
return &schema.Resource{
Create: resourceCloudProjectContainerRegistryIPRestrictionsRegistryPut,
Delete: resourceCloudProjectContainerRegistryIPRestrictionsRegistryDelete,
Update: resourceCloudProjectContainerRegistryIPRestrictionsRegistryPut,
Read: resourceCloudProjectContainerIPRestrictionsRegistryRead,
Importer: &schema.ResourceImporter{
State: resourceCloudProjectContainerRegistryIPRestrictionsRegistryImportState,
},
Schema: map[string]*schema.Schema{
"service_name": {
Type: schema.TypeString,
Description: "Service name",
ForceNew: true,
Required: true,
DefaultFunc: schema.EnvDefaultFunc("OVH_CLOUD_PROJECT_SERVICE", nil),
},
"registry_id": {
Type: schema.TypeString,
ForceNew: true,
Description: "RegistryID",
Required: true,
},
"ip_restrictions": {
Type: schema.TypeList,
Description: "List your IP restrictions applied on artifact manager component",
Required: true,
Elem: &schema.Schema{
Type: schema.TypeMap,
Set: schema.HashString,
ValidateFunc: func(ipRestrictionInterface interface{}, path string) (warning []string, errorList []error) {
ipRestriction := ipRestrictionInterface.(map[string]interface{})
if ipRestriction["ip_block"] == nil {
return nil, []error{errors.New(fmt.Sprintf("ipBlock attribute is mandatory for ip_restrictions: %s", path))}
}
ipBlockString := ipRestriction["ip_block"].(string)
if _, _, err := net.ParseCIDR(ipBlockString); err != nil {
return nil, []error{fmt.Errorf("ip_block: %s is not CIDR format", ipBlockString)}
}
return nil, nil
},
},
},
},
}
}
func resourceCloudProjectContainerRegistryIPRestrictionsRegistryImportState(d *schema.ResourceData, meta interface{}) ([]*schema.ResourceData, error) {
givenId := d.Id()
log.Printf("[DEBUG] Importing cloud project registry IP restrictions of registry type %s", givenId)
splitId := strings.SplitN(givenId, "/", 2)
if len(splitId) != 2 {
return nil, fmt.Errorf("import Id is not service_name/registry_id formatted")
}
serviceName := splitId[0]
registryID := splitId[1]
d.SetId(serviceName + "/" + registryID)
d.Set("registry_id", registryID)
d.Set("service_name", serviceName)
results := make([]*schema.ResourceData, 1)
results[0] = d
return results, nil
}
func resourceCloudProjectContainerRegistryIPRestrictionsRegistryPut(d *schema.ResourceData, meta interface{}) error {
config := meta.(*Config)
serviceName := d.Get("service_name").(string)
registryID := d.Get("registry_id").(string)
endpoint := fmt.Sprintf(
"/cloud/project/%s/containerRegistry/%s/ipRestrictions/registry",
url.PathEscape(serviceName),
url.PathEscape(registryID),
)
params := (&CloudProjectContainerRegistryIPRestrictionCreateOpts{}).FromResource(d)
var res []CloudProjectContainerRegistryIPRestriction
log.Printf("[DEBUG] Will create registry IP restrictions for registry %s in cloud project %s: %+v", registryID, serviceName, params)
err := config.OVHClient.Put(endpoint, params.IPRestrictions, res)
if err != nil {
return fmt.Errorf("Error calling put %s:\n\t %q", endpoint, err)
}
d.SetId(serviceName + "/" + registryID)
log.Printf("[DEBUG] Registry %s IP restrictions of registry type are created", registryID)
return resourceCloudProjectContainerIPRestrictionsRegistryRead(d, meta)
}
func resourceCloudProjectContainerIPRestrictionsRegistryRead(d *schema.ResourceData, meta interface{}) error {
config := meta.(*Config)
serviceName := d.Get("service_name").(string)
registryID := d.Get("registry_id").(string)
log.Printf("[DEBUG] Will read cloud project registry IP restrictions of registry type %s for project: %s", registryID, serviceName)
endpoint := fmt.Sprintf(
"/cloud/project/%s/containerRegistry/%s/ipRestrictions/registry",
url.PathEscape(serviceName),
url.PathEscape(registryID),
)
ipRestrictions := []CloudProjectContainerRegistryIPRestriction{}
if err := config.OVHClient.Get(endpoint, &ipRestrictions); err != nil {
return helpers.CheckDeleted(d, err, endpoint)
}
log.Printf("[DEBUG] Read Registry IP Restrictions before Mapping %+v", ipRestrictions)
mapIPRestrictions := make([]map[string]interface{}, len(ipRestrictions))
for i, ipRestriction := range ipRestrictions {
mapIPRestrictions[i] = ipRestriction.ToMap()
}
d.Set("ip_restrictions", mapIPRestrictions)
d.SetId(serviceName + "/" + registryID)
log.Printf("[DEBUG] Read Registry IP Restrictions %+v", mapIPRestrictions)
return nil
}
func resourceCloudProjectContainerRegistryIPRestrictionsRegistryDelete(d *schema.ResourceData, meta interface{}) error {
config := meta.(*Config)
serviceName := d.Get("service_name").(string)
registryID := d.Get("registry_id").(string)
log.Printf("[DEBUG] Will delete registry IP restrictions for registry %s in cloud project: %s", registryID, serviceName)
params := make([]CloudProjectContainerRegistryIPRestriction, 0)
var res []CloudProjectContainerRegistryIPRestriction
endpoint := fmt.Sprintf(
"/cloud/project/%s/containerRegistry/%s/ipRestrictions/registry",
url.PathEscape(serviceName),
url.PathEscape(registryID),
)
err := config.OVHClient.Put(endpoint, params, res)
if err != nil {
return fmt.Errorf("Error calling put %s:\n\t %q", endpoint, err)
}
return nil
}