2020-12-09 15:31:34 +00:00
|
|
|
package aws
|
|
|
|
|
|
|
|
import (
|
2021-05-21 14:09:45 +00:00
|
|
|
"fmt"
|
|
|
|
|
2020-12-09 15:31:34 +00:00
|
|
|
"github.com/aws/aws-sdk-go/service/iam"
|
|
|
|
"github.com/aws/aws-sdk-go/service/iam/iamiface"
|
2021-01-20 13:01:57 +00:00
|
|
|
remoteerror "github.com/cloudskiff/driftctl/pkg/remote/error"
|
|
|
|
|
2020-12-09 15:31:34 +00:00
|
|
|
"github.com/cloudskiff/driftctl/pkg/resource"
|
|
|
|
resourceaws "github.com/cloudskiff/driftctl/pkg/resource/aws"
|
2021-05-21 14:09:45 +00:00
|
|
|
|
2020-12-09 15:31:34 +00:00
|
|
|
"github.com/cloudskiff/driftctl/pkg/terraform"
|
|
|
|
|
|
|
|
"github.com/sirupsen/logrus"
|
|
|
|
"github.com/zclconf/go-cty/cty"
|
|
|
|
)
|
|
|
|
|
|
|
|
type IamRolePolicyAttachmentSupplier struct {
|
|
|
|
reader terraform.ResourceReader
|
2021-05-21 14:09:45 +00:00
|
|
|
deserializer *resource.Deserializer
|
2020-12-09 15:31:34 +00:00
|
|
|
client iamiface.IAMAPI
|
|
|
|
runner *terraform.ParallelResourceReader
|
|
|
|
}
|
|
|
|
|
2021-05-21 14:09:45 +00:00
|
|
|
func NewIamRolePolicyAttachmentSupplier(provider *AWSTerraformProvider, deserializer *resource.Deserializer) *IamRolePolicyAttachmentSupplier {
|
2021-01-20 13:01:57 +00:00
|
|
|
return &IamRolePolicyAttachmentSupplier{
|
2021-01-22 17:06:17 +00:00
|
|
|
provider,
|
2021-05-21 14:09:45 +00:00
|
|
|
deserializer,
|
2021-01-22 17:06:17 +00:00
|
|
|
iam.New(provider.session),
|
|
|
|
terraform.NewParallelResourceReader(provider.Runner().SubRunner()),
|
2021-01-20 13:01:57 +00:00
|
|
|
}
|
2020-12-09 15:31:34 +00:00
|
|
|
}
|
|
|
|
|
2021-03-17 15:54:53 +00:00
|
|
|
func (s *IamRolePolicyAttachmentSupplier) Resources() ([]resource.Resource, error) {
|
2021-01-20 13:01:57 +00:00
|
|
|
roles, err := listIamRoles(s.client, resourceaws.AwsIamRolePolicyAttachmentResourceType)
|
2020-12-09 15:31:34 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
results := make([]cty.Value, 0)
|
|
|
|
if len(roles) > 0 {
|
|
|
|
attachedPolicies := make([]*attachedRolePolicy, 0)
|
|
|
|
for _, role := range roles {
|
|
|
|
roleName := *role.RoleName
|
|
|
|
if awsIamRoleShouldBeIgnored(roleName) {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
roleAttachmentList, err := listIamRolePoliciesAttachment(roleName, s.client)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
attachedPolicies = append(attachedPolicies, roleAttachmentList...)
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, attachedPolicy := range attachedPolicies {
|
|
|
|
attached := *attachedPolicy
|
|
|
|
s.runner.Run(func() (cty.Value, error) {
|
|
|
|
return s.readRes(attached)
|
|
|
|
})
|
|
|
|
}
|
|
|
|
results, err = s.runner.Wait()
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-05-21 14:09:45 +00:00
|
|
|
return s.deserializer.Deserialize(resourceaws.AwsIamRolePolicyAttachmentResourceType, results)
|
2020-12-09 15:31:34 +00:00
|
|
|
}
|
|
|
|
|
2021-03-17 15:54:53 +00:00
|
|
|
func (s *IamRolePolicyAttachmentSupplier) readRes(attachedPol attachedRolePolicy) (cty.Value, error) {
|
2020-12-09 15:31:34 +00:00
|
|
|
res, err := s.reader.ReadResource(
|
|
|
|
terraform.ReadResourceArgs{
|
|
|
|
Ty: resourceaws.AwsIamRolePolicyAttachmentResourceType,
|
2021-05-21 14:09:45 +00:00
|
|
|
ID: fmt.Sprintf("%s-%s", *attachedPol.PolicyName, attachedPol.RoleName),
|
2020-12-09 15:31:34 +00:00
|
|
|
Attributes: map[string]string{
|
|
|
|
"role": attachedPol.RoleName,
|
|
|
|
"policy_arn": *attachedPol.PolicyArn,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
)
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
logrus.Warnf("Error reading iam role policy attachment %s[%s]: %+v", attachedPol, resourceaws.AwsIamRolePolicyAttachmentResourceType, err)
|
|
|
|
return cty.NilVal, err
|
|
|
|
}
|
|
|
|
return *res, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func listIamRolePoliciesAttachment(roleName string, client iamiface.IAMAPI) ([]*attachedRolePolicy, error) {
|
|
|
|
var attachedRolePolicies []*attachedRolePolicy
|
|
|
|
input := &iam.ListAttachedRolePoliciesInput{
|
|
|
|
RoleName: &roleName,
|
|
|
|
}
|
|
|
|
err := client.ListAttachedRolePoliciesPages(input, func(res *iam.ListAttachedRolePoliciesOutput, lastPage bool) bool {
|
|
|
|
for _, policy := range res.AttachedPolicies {
|
|
|
|
attachedRolePolicies = append(attachedRolePolicies, &attachedRolePolicy{
|
|
|
|
AttachedPolicy: *policy,
|
|
|
|
RoleName: roleName,
|
|
|
|
})
|
|
|
|
}
|
|
|
|
return !lastPage
|
|
|
|
})
|
|
|
|
if err != nil {
|
2021-01-20 13:01:57 +00:00
|
|
|
return nil, remoteerror.NewResourceEnumerationErrorWithType(err, resourceaws.AwsIamRolePolicyAttachmentResourceType, resourceaws.AwsIamRolePolicyResourceType)
|
2020-12-09 15:31:34 +00:00
|
|
|
}
|
|
|
|
return attachedRolePolicies, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
type attachedRolePolicy struct {
|
|
|
|
iam.AttachedPolicy
|
|
|
|
RoleName string
|
|
|
|
}
|