create_aws.go 2.7 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788
  1. package project_integration
  2. import (
  3. "fmt"
  4. "net/http"
  5. "github.com/bufbuild/connect-go"
  6. porterv1 "github.com/porter-dev/api-contracts/generated/go/porter/v1"
  7. "github.com/porter-dev/porter/api/server/handlers"
  8. "github.com/porter-dev/porter/api/server/shared"
  9. "github.com/porter-dev/porter/api/server/shared/apierrors"
  10. "github.com/porter-dev/porter/api/server/shared/config"
  11. "github.com/porter-dev/porter/api/types"
  12. "github.com/porter-dev/porter/internal/models"
  13. ints "github.com/porter-dev/porter/internal/models/integrations"
  14. )
  15. type CreateAWSHandler struct {
  16. handlers.PorterHandlerReadWriter
  17. }
  18. func NewCreateAWSHandler(
  19. config *config.Config,
  20. decoderValidator shared.RequestDecoderValidator,
  21. writer shared.ResultWriter,
  22. ) *CreateAWSHandler {
  23. return &CreateAWSHandler{
  24. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  25. }
  26. }
  27. func (p *CreateAWSHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  28. user, _ := r.Context().Value(types.UserScope).(*models.User)
  29. project, _ := r.Context().Value(types.ProjectScope).(*models.Project)
  30. ctx := r.Context()
  31. request := &types.CreateAWSRequest{}
  32. if ok := p.DecodeAndValidate(w, r, request); !ok {
  33. return
  34. }
  35. aws := CreateAWSIntegration(request, project.ID, user.ID)
  36. aws, err := p.Repo().AWSIntegration().CreateAWSIntegration(aws)
  37. if err != nil {
  38. p.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  39. return
  40. }
  41. res := types.CreateAWSResponse{
  42. AWSIntegration: aws.ToAWSIntegrationType(),
  43. }
  44. if !p.Config().DisableCAPIProvisioner {
  45. credReq := porterv1.CreateAssumeRoleChainRequest{
  46. ProjectId: int64(project.ID),
  47. SourceArn: "arn:aws:iam::108458755588:role/CAPIManagement", // hard coded as this is the final hop for a CAPI cluster
  48. TargetAccessId: request.AWSAccessKeyID,
  49. TargetSecretKey: request.AWSSecretAccessKey,
  50. }
  51. credResp, err := p.Config().ClusterControlPlaneClient.CreateAssumeRoleChain(ctx, connect.NewRequest(&credReq))
  52. if err != nil {
  53. e := fmt.Errorf("unable to create CAPI required credential: %w", err)
  54. p.HandleAPIError(w, r, apierrors.NewErrInternal(e))
  55. return
  56. }
  57. res.CloudProviderCredentialIdentifier = credResp.Msg.TargetArn
  58. }
  59. p.WriteResult(w, r, res)
  60. }
  61. func CreateAWSIntegration(request *types.CreateAWSRequest, projectID, userID uint) *ints.AWSIntegration {
  62. resp := &ints.AWSIntegration{
  63. UserID: userID,
  64. ProjectID: projectID,
  65. AWSRegion: request.AWSRegion,
  66. AWSAssumeRoleArn: request.AWSAssumeRoleArn,
  67. AWSClusterID: []byte(request.AWSClusterID),
  68. AWSAccessKeyID: []byte(request.AWSAccessKeyID),
  69. AWSSecretAccessKey: []byte(request.AWSSecretAccessKey),
  70. }
  71. // attempt to populate the ARN
  72. resp.PopulateAWSArn()
  73. return resp
  74. }