setconfig.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303
  1. package cmd
  2. import (
  3. "context"
  4. "encoding/base64"
  5. "fmt"
  6. "io/ioutil"
  7. "os"
  8. "github.com/porter-dev/porter/internal/kubernetes/local"
  9. gcpLocal "github.com/porter-dev/porter/internal/providers/gcp/local"
  10. "github.com/porter-dev/porter/internal/utils"
  11. "github.com/spf13/viper"
  12. "github.com/porter-dev/porter/cli/cmd/api"
  13. "github.com/porter-dev/porter/internal/models"
  14. "github.com/spf13/cobra"
  15. )
  16. var setConfigCmd = &cobra.Command{
  17. Use: "set-config",
  18. Short: "Uses the local kubeconfig to set the configuration for a cluster",
  19. Run: func(cmd *cobra.Command, args []string) {
  20. err := setConfig()
  21. if err != nil {
  22. fmt.Printf("Error occurred: %v\n", err)
  23. os.Exit(1)
  24. }
  25. },
  26. }
  27. func init() {
  28. rootCmd.AddCommand(setConfigCmd)
  29. setConfigCmd.PersistentFlags().StringVarP(
  30. &kubeconfigPath,
  31. "kubeconfig",
  32. "k",
  33. "",
  34. "path to kubeconfig",
  35. )
  36. setConfigCmd.PersistentFlags().StringVar(
  37. &host,
  38. "host",
  39. "http://localhost:10000",
  40. "host url of Porter instance",
  41. )
  42. contexts = setConfigCmd.PersistentFlags().StringArray(
  43. "contexts",
  44. nil,
  45. "the list of contexts to use (defaults to the current context)",
  46. )
  47. }
  48. func setConfig() error {
  49. // TODO: construct the kubeconfig based on the passed contexts
  50. // get the current project ID
  51. projectID := viper.GetUint("project")
  52. // if project ID is 0, ask the user to set the project ID or create a project
  53. if projectID == 0 {
  54. return fmt.Errorf("no project set, please run porter project set [id]")
  55. }
  56. // get the kubeconfig
  57. rawBytes, err := local.GetKubeconfigFromHost(kubeconfigPath, *contexts)
  58. if err != nil {
  59. return err
  60. }
  61. // send kubeconfig to client
  62. client := api.NewClient(host+"/api", "cookie.json")
  63. saCandidates, err := client.CreateProjectCandidates(
  64. context.Background(),
  65. projectID,
  66. &api.CreateProjectCandidatesRequest{
  67. Kubeconfig: string(rawBytes),
  68. },
  69. )
  70. if err != nil {
  71. return err
  72. }
  73. for _, saCandidate := range saCandidates {
  74. resolvers := make(api.CreateProjectServiceAccountRequest, 0)
  75. for _, action := range saCandidate.Actions {
  76. switch action.Name {
  77. case models.ClusterCADataAction:
  78. resolveAction, err := resolveClusterCAAction(action.Filename)
  79. if err != nil {
  80. return err
  81. }
  82. resolvers = append(resolvers, resolveAction)
  83. case models.ClientCertDataAction:
  84. resolveAction, err := resolveClientCertAction(action.Filename)
  85. if err != nil {
  86. return err
  87. }
  88. resolvers = append(resolvers, resolveAction)
  89. case models.ClientKeyDataAction:
  90. resolveAction, err := resolveClientKeyAction(action.Filename)
  91. if err != nil {
  92. return err
  93. }
  94. resolvers = append(resolvers, resolveAction)
  95. case models.OIDCIssuerDataAction:
  96. resolveAction, err := resolveOIDCIssuerAction(action.Filename)
  97. if err != nil {
  98. return err
  99. }
  100. resolvers = append(resolvers, resolveAction)
  101. case models.TokenDataAction:
  102. resolveAction, err := resolveTokenDataAction(action.Filename)
  103. if err != nil {
  104. return err
  105. }
  106. resolvers = append(resolvers, resolveAction)
  107. case models.GCPKeyDataAction:
  108. resolveAction, err := resolveGCPKeyAction(saCandidate.ClusterEndpoint)
  109. if err != nil {
  110. return err
  111. }
  112. resolvers = append(resolvers, resolveAction)
  113. case models.AWSKeyDataAction:
  114. }
  115. }
  116. sa, err := client.CreateProjectServiceAccount(
  117. context.Background(),
  118. projectID,
  119. saCandidate.ID,
  120. resolvers,
  121. )
  122. if err != nil {
  123. return err
  124. }
  125. for _, cluster := range sa.Clusters {
  126. fmt.Printf("created service account for cluster %s with id %d\n", cluster.Name, sa.ID)
  127. // sanity check to ensure it's working
  128. // namespaces, err := client.GetK8sNamespaces(
  129. // context.Background(),
  130. // projectID,
  131. // saCandidate.ID,
  132. // cluster.ID,
  133. // )
  134. // if err != nil {
  135. // return err
  136. // }
  137. // for _, ns := range namespaces.Items {
  138. // fmt.Println(ns.ObjectMeta.GetName())
  139. // }
  140. }
  141. }
  142. return nil
  143. }
  144. // resolves a cluster ca data action
  145. func resolveClusterCAAction(
  146. filename string,
  147. ) (*models.ServiceAccountAllActions, error) {
  148. fileBytes, err := ioutil.ReadFile(filename)
  149. if err != nil {
  150. return nil, err
  151. }
  152. return &models.ServiceAccountAllActions{
  153. Name: models.ClusterCADataAction,
  154. ClusterCAData: base64.StdEncoding.EncodeToString(fileBytes),
  155. }, nil
  156. }
  157. // resolves a client cert data action
  158. func resolveClientCertAction(
  159. filename string,
  160. ) (*models.ServiceAccountAllActions, error) {
  161. fileBytes, err := ioutil.ReadFile(filename)
  162. if err != nil {
  163. return nil, err
  164. }
  165. return &models.ServiceAccountAllActions{
  166. Name: models.ClientCertDataAction,
  167. ClientCertData: base64.StdEncoding.EncodeToString(fileBytes),
  168. }, nil
  169. }
  170. // resolves a client key data action
  171. func resolveClientKeyAction(
  172. filename string,
  173. ) (*models.ServiceAccountAllActions, error) {
  174. fileBytes, err := ioutil.ReadFile(filename)
  175. if err != nil {
  176. return nil, err
  177. }
  178. return &models.ServiceAccountAllActions{
  179. Name: models.ClientKeyDataAction,
  180. ClientKeyData: base64.StdEncoding.EncodeToString(fileBytes),
  181. }, nil
  182. }
  183. // resolves an oidc issuer data action
  184. func resolveOIDCIssuerAction(
  185. filename string,
  186. ) (*models.ServiceAccountAllActions, error) {
  187. fileBytes, err := ioutil.ReadFile(filename)
  188. if err != nil {
  189. return nil, err
  190. }
  191. return &models.ServiceAccountAllActions{
  192. Name: models.OIDCIssuerDataAction,
  193. OIDCIssuerCAData: base64.StdEncoding.EncodeToString(fileBytes),
  194. }, nil
  195. }
  196. // resolves a token data action
  197. func resolveTokenDataAction(
  198. filename string,
  199. ) (*models.ServiceAccountAllActions, error) {
  200. fileBytes, err := ioutil.ReadFile(filename)
  201. if err != nil {
  202. return nil, err
  203. }
  204. return &models.ServiceAccountAllActions{
  205. Name: models.TokenDataAction,
  206. TokenData: string(fileBytes),
  207. }, nil
  208. }
  209. // resolves a gcp key data action
  210. func resolveGCPKeyAction(endpoint string) (*models.ServiceAccountAllActions, error) {
  211. agent, _ := gcpLocal.NewDefaultAgent()
  212. projID, err := agent.GetProjectIDForGKECluster(endpoint)
  213. if err != nil {
  214. return nil, err
  215. }
  216. agent.ProjectID = projID
  217. name := "porter-dashboard-" + utils.StringWithCharset(6, "abcdefghijklmnopqrstuvwxyz1234567890")
  218. // create the service account and give it the correct iam permissions
  219. resp, err := agent.CreateServiceAccount(name)
  220. if err != nil {
  221. return nil, err
  222. }
  223. err = agent.SetServiceAccountIAMPolicy(resp)
  224. if err != nil {
  225. return nil, err
  226. }
  227. // get the service account key data to send to the server
  228. bytes, err := agent.CreateServiceAccountKey(resp)
  229. if err != nil {
  230. return nil, err
  231. }
  232. return &models.ServiceAccountAllActions{
  233. Name: models.GCPKeyDataAction,
  234. GCPKeyData: string(bytes),
  235. }, nil
  236. }
  237. // resolves an aws key data action