create_aws.go 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140
  1. package project_integration
  2. import (
  3. "net/http"
  4. "connectrpc.com/connect"
  5. porterv1 "github.com/porter-dev/api-contracts/generated/go/porter/v1"
  6. "github.com/porter-dev/porter/api/server/handlers"
  7. "github.com/porter-dev/porter/api/server/shared"
  8. "github.com/porter-dev/porter/api/server/shared/apierrors"
  9. "github.com/porter-dev/porter/api/server/shared/config"
  10. "github.com/porter-dev/porter/api/types"
  11. "github.com/porter-dev/porter/internal/models"
  12. ints "github.com/porter-dev/porter/internal/models/integrations"
  13. "github.com/porter-dev/porter/internal/telemetry"
  14. )
  15. type CreateAWSHandler struct {
  16. handlers.PorterHandlerReadWriter
  17. }
  18. func NewCreateAWSHandler(
  19. config *config.Config,
  20. decoderValidator shared.RequestDecoderValidator,
  21. writer shared.ResultWriter,
  22. ) *CreateAWSHandler {
  23. return &CreateAWSHandler{
  24. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  25. }
  26. }
  27. func (p *CreateAWSHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  28. ctx, span := telemetry.NewSpan(r.Context(), "serve-create-aws-integration")
  29. defer span.End()
  30. user, _ := ctx.Value(types.UserScope).(*models.User)
  31. project, _ := ctx.Value(types.ProjectScope).(*models.Project)
  32. request := &types.CreateAWSRequest{}
  33. if ok := p.DecodeAndValidate(w, r, request); !ok {
  34. err := telemetry.Error(ctx, span, nil, "error decoding request")
  35. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusBadRequest))
  36. return
  37. }
  38. aws := CreateAWSIntegration(request, project.ID, user.ID)
  39. aws, err := p.Repo().AWSIntegration().CreateAWSIntegration(aws)
  40. if err != nil {
  41. err = telemetry.Error(ctx, span, err, "error creating aws integration")
  42. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusInternalServerError))
  43. return
  44. }
  45. res := types.CreateAWSResponse{
  46. AWSIntegration: aws.ToAWSIntegrationType(),
  47. }
  48. if project.GetFeatureFlag(models.CapiProvisionerEnabled, p.Config().LaunchDarklyClient) {
  49. telemetry.WithAttributes(span,
  50. telemetry.AttributeKV{Key: "target-arn", Value: request.TargetArn},
  51. telemetry.AttributeKV{Key: "external-id", Value: request.ExternalID},
  52. telemetry.AttributeKV{Key: "target-access-id", Value: request.AWSAccessKeyID},
  53. )
  54. if project.GetFeatureFlag(models.AWSACKAuthEnabled, p.Config().LaunchDarklyClient) {
  55. if request.TargetArn == "" {
  56. err = telemetry.Error(ctx, span, err, "target arn is required for AWS ACK auth")
  57. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusBadRequest, "target arn is required for AWS ACK auth"))
  58. return
  59. }
  60. credReq := porterv1.UpdateCloudProviderCredentialsRequest{
  61. ProjectId: int64(project.ID),
  62. CloudProvider: porterv1.EnumCloudProvider_ENUM_CLOUD_PROVIDER_AWS,
  63. CloudProviderCredentials: &porterv1.UpdateCloudProviderCredentialsRequest_AwsCredentials{
  64. AwsCredentials: &porterv1.AWSCredentials{
  65. TargetArn: request.TargetArn,
  66. ExternalId: request.ExternalID,
  67. },
  68. },
  69. }
  70. credResp, err := p.Config().ClusterControlPlaneClient.UpdateCloudProviderCredentials(ctx, connect.NewRequest(&credReq))
  71. if err != nil {
  72. err = telemetry.Error(ctx, span, err, "error updating AWS credential")
  73. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusPreconditionFailed, err.Error()))
  74. return
  75. }
  76. if credResp == nil {
  77. err = telemetry.Error(ctx, span, err, "error reading AWS credential response")
  78. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusPreconditionFailed, "response is nil"))
  79. return
  80. }
  81. if credResp.Msg == nil {
  82. err = telemetry.Error(ctx, span, err, "error reading AWS credential message")
  83. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusPreconditionFailed, "response message is nil"))
  84. return
  85. }
  86. res.CloudProviderCredentialIdentifier = credResp.Msg.CredentialsIdentifier
  87. } else {
  88. credReq := porterv1.CreateAssumeRoleChainRequest{ //nolint:staticcheck // being deprecated by the above UpdateCloudProviderCredentials
  89. ProjectId: int64(project.ID),
  90. SourceArn: "arn:aws:iam::108458755588:role/CAPIManagement", // hard coded as this is the final hop for a CAPI cluster
  91. TargetAccessId: request.AWSAccessKeyID,
  92. TargetSecretKey: request.AWSSecretAccessKey,
  93. TargetArn: request.TargetArn,
  94. ExternalId: request.ExternalID,
  95. }
  96. credResp, err := p.Config().ClusterControlPlaneClient.CreateAssumeRoleChain(ctx, connect.NewRequest(&credReq)) //nolint:staticcheck // being deprecated by the above UpdateCloudProviderCredentials
  97. if err != nil {
  98. err = telemetry.Error(ctx, span, err, "error creating CAPI required credential")
  99. p.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusPreconditionFailed, err.Error()))
  100. return
  101. }
  102. res.CloudProviderCredentialIdentifier = credResp.Msg.TargetArn
  103. }
  104. telemetry.WithAttributes(span, telemetry.AttributeKV{Key: "cloud-provider-credential-identifier", Value: res.CloudProviderCredentialIdentifier})
  105. }
  106. p.WriteResult(w, r, res)
  107. }
  108. func CreateAWSIntegration(request *types.CreateAWSRequest, projectID, userID uint) *ints.AWSIntegration {
  109. resp := &ints.AWSIntegration{
  110. UserID: userID,
  111. ProjectID: projectID,
  112. AWSRegion: request.AWSRegion,
  113. AWSAssumeRoleArn: request.AWSAssumeRoleArn,
  114. AWSClusterID: []byte(request.AWSClusterID),
  115. AWSAccessKeyID: []byte(request.AWSAccessKeyID),
  116. AWSSecretAccessKey: []byte(request.AWSSecretAccessKey),
  117. }
  118. // attempt to populate the ARN
  119. resp.PopulateAWSArn()
  120. return resp
  121. }