2021-07-01 09:32:19 +00:00
|
|
|
package aws
|
|
|
|
|
|
|
|
import (
|
2021-08-03 10:34:36 +00:00
|
|
|
"github.com/cloudskiff/driftctl/pkg/alerter"
|
|
|
|
"github.com/cloudskiff/driftctl/pkg/remote/alerts"
|
2021-07-01 09:32:19 +00:00
|
|
|
"github.com/cloudskiff/driftctl/pkg/remote/aws/repository"
|
2021-08-03 10:34:36 +00:00
|
|
|
"github.com/cloudskiff/driftctl/pkg/remote/common"
|
2021-07-01 09:32:19 +00:00
|
|
|
remoteerror "github.com/cloudskiff/driftctl/pkg/remote/error"
|
|
|
|
tf "github.com/cloudskiff/driftctl/pkg/remote/terraform"
|
|
|
|
"github.com/cloudskiff/driftctl/pkg/resource"
|
|
|
|
"github.com/cloudskiff/driftctl/pkg/resource/aws"
|
|
|
|
"github.com/sirupsen/logrus"
|
|
|
|
)
|
|
|
|
|
|
|
|
type S3BucketPolicyEnumerator struct {
|
|
|
|
repository repository.S3Repository
|
|
|
|
factory resource.ResourceFactory
|
|
|
|
providerConfig tf.TerraformProviderConfig
|
2021-08-03 10:34:36 +00:00
|
|
|
alerter alerter.AlerterInterface
|
2021-07-01 09:32:19 +00:00
|
|
|
}
|
|
|
|
|
2021-08-03 10:34:36 +00:00
|
|
|
func NewS3BucketPolicyEnumerator(repo repository.S3Repository, factory resource.ResourceFactory, providerConfig tf.TerraformProviderConfig, alerter alerter.AlerterInterface) *S3BucketPolicyEnumerator {
|
2021-07-01 09:32:19 +00:00
|
|
|
return &S3BucketPolicyEnumerator{
|
|
|
|
repository: repo,
|
|
|
|
factory: factory,
|
|
|
|
providerConfig: providerConfig,
|
2021-08-03 10:34:36 +00:00
|
|
|
alerter: alerter,
|
2021-07-01 09:32:19 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (e *S3BucketPolicyEnumerator) SupportedType() resource.ResourceType {
|
|
|
|
return aws.AwsS3BucketPolicyResourceType
|
|
|
|
}
|
|
|
|
|
2021-08-09 14:03:04 +00:00
|
|
|
func (e *S3BucketPolicyEnumerator) Enumerate() ([]*resource.Resource, error) {
|
2021-07-01 09:32:19 +00:00
|
|
|
buckets, err := e.repository.ListAllBuckets()
|
|
|
|
if err != nil {
|
2021-08-03 10:34:36 +00:00
|
|
|
return nil, remoteerror.NewResourceListingErrorWithType(err, string(e.SupportedType()), aws.AwsS3BucketResourceType)
|
2021-07-01 09:32:19 +00:00
|
|
|
}
|
|
|
|
|
2021-10-27 09:30:47 +00:00
|
|
|
results := make([]*resource.Resource, 0, len(buckets))
|
2021-07-01 09:32:19 +00:00
|
|
|
|
|
|
|
for _, bucket := range buckets {
|
|
|
|
region, err := e.repository.GetBucketLocation(*bucket.Name)
|
|
|
|
if err != nil {
|
2021-08-03 10:34:36 +00:00
|
|
|
alerts.SendEnumerationAlert(common.RemoteAWSTerraform, e.alerter, remoteerror.NewResourceScanningError(err, string(e.SupportedType()), *bucket.Name))
|
|
|
|
continue
|
2021-07-01 09:32:19 +00:00
|
|
|
}
|
|
|
|
if region == "" || region != e.providerConfig.DefaultAlias {
|
|
|
|
logrus.WithFields(logrus.Fields{
|
|
|
|
"region": region,
|
|
|
|
"bucket": *bucket.Name,
|
|
|
|
}).Debug("Skipped bucket policy")
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
|
|
|
policy, err := e.repository.GetBucketPolicy(*bucket.Name, region)
|
|
|
|
if err != nil {
|
2021-08-03 10:34:36 +00:00
|
|
|
alerts.SendEnumerationAlert(common.RemoteAWSTerraform, e.alerter, remoteerror.NewResourceScanningError(err, string(e.SupportedType()), *bucket.Name))
|
|
|
|
continue
|
2021-07-01 09:32:19 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if policy != nil {
|
|
|
|
results = append(
|
|
|
|
results,
|
|
|
|
e.factory.CreateAbstractResource(
|
|
|
|
string(e.SupportedType()),
|
|
|
|
*bucket.Name,
|
|
|
|
map[string]interface{}{
|
|
|
|
"region": region,
|
|
|
|
},
|
|
|
|
),
|
|
|
|
)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return results, err
|
|
|
|
}
|