-
Notifications
You must be signed in to change notification settings - Fork 458
/
ban.go
73 lines (60 loc) · 1.9 KB
/
ban.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
package agent
import (
"context"
"errors"
"flag"
"github.com/mitchellh/cli"
"github.com/spiffe/go-spiffe/v2/spiffeid"
agentv1 "github.com/spiffe/spire-api-sdk/proto/spire/api/server/agent/v1"
"github.com/spiffe/spire/cmd/spire-server/util"
commoncli "github.com/spiffe/spire/pkg/common/cli"
"github.com/spiffe/spire/pkg/common/cliprinter"
"github.com/spiffe/spire/pkg/server/api"
)
type banCommand struct {
env *commoncli.Env
// SPIFFE ID of agent being banned
spiffeID string
printer cliprinter.Printer
}
// NewBanCommand creates a new "ban" subcommand for "agent" command.
func NewBanCommand() cli.Command {
return NewBanCommandWithEnv(commoncli.DefaultEnv)
}
// NewBanCommandWithEnv creates a new "ban" subcommand for "agent" command
// using the environment specified
func NewBanCommandWithEnv(env *commoncli.Env) cli.Command {
return util.AdaptCommand(env, &banCommand{env: env})
}
func (*banCommand) Name() string {
return "agent ban"
}
func (*banCommand) Synopsis() string {
return "Ban an attested agent given its SPIFFE ID"
}
// Run ban an agent given its SPIFFE ID
func (c *banCommand) Run(ctx context.Context, _ *commoncli.Env, serverClient util.ServerClient) error {
if c.spiffeID == "" {
return errors.New("a SPIFFE ID is required")
}
id, err := spiffeid.FromString(c.spiffeID)
if err != nil {
return err
}
agentClient := serverClient.NewAgentClient()
banResponse, err := agentClient.BanAgent(ctx, &agentv1.BanAgentRequest{
Id: api.ProtoFromID(id),
})
if err != nil {
return err
}
return c.printer.PrintProto(banResponse)
}
func (c *banCommand) AppendFlags(fs *flag.FlagSet) {
fs.StringVar(&c.spiffeID, "spiffeID", "", "The SPIFFE ID of the agent to ban (agent identity)")
cliprinter.AppendFlagWithCustomPretty(&c.printer, fs, c.env, prettyPrintBanResult)
}
func prettyPrintBanResult(env *commoncli.Env, _ ...any) error {
env.Println("Agent banned successfully")
return nil
}