2022-03-28 13:07:02 +00:00
|
|
|
package middlewares
|
|
|
|
|
|
|
|
import (
|
|
|
|
"strings"
|
|
|
|
"testing"
|
|
|
|
|
|
|
|
"github.com/aws/aws-sdk-go/aws/awsutil"
|
|
|
|
"github.com/r3labs/diff/v2"
|
2022-06-28 07:23:29 +00:00
|
|
|
"github.com/snyk/driftctl/enumeration/resource"
|
2022-07-21 08:37:03 +00:00
|
|
|
dctlresource "github.com/snyk/driftctl/pkg/resource"
|
|
|
|
"github.com/snyk/driftctl/pkg/resource/aws"
|
2022-03-28 13:07:02 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestAwsEbsEncryptionByDefaultReconciler_Execute(t *testing.T) {
|
|
|
|
tests := []struct {
|
2022-04-04 13:28:59 +00:00
|
|
|
name string
|
2022-07-21 08:37:03 +00:00
|
|
|
mocks func(*dctlresource.MockResourceFactory)
|
2022-04-04 13:28:59 +00:00
|
|
|
remoteResources []*resource.Resource
|
|
|
|
resourcesFromState []*resource.Resource
|
|
|
|
expectedRemoteResources []*resource.Resource
|
|
|
|
expectedStateResources []*resource.Resource
|
2022-03-28 13:07:02 +00:00
|
|
|
}{
|
|
|
|
{
|
2022-03-31 11:59:20 +00:00
|
|
|
name: "test encryption by default is managed",
|
2022-07-21 08:37:03 +00:00
|
|
|
mocks: func(factory *dctlresource.MockResourceFactory) {
|
2022-03-28 13:07:02 +00:00
|
|
|
factory.On("CreateAbstractResource",
|
|
|
|
aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
"terraform-20220328091515068500000001",
|
|
|
|
map[string]interface{}{
|
|
|
|
"id": "terraform-20220328091515068500000001",
|
|
|
|
"enabled": true,
|
|
|
|
}).Return(&resource.Resource{
|
|
|
|
Id: "terraform-20220328091515068500000001",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"id": "terraform-20220328091515068500000001",
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
}).Once()
|
|
|
|
},
|
2022-03-31 11:59:20 +00:00
|
|
|
remoteResources: []*resource.Resource{
|
2022-03-28 13:07:02 +00:00
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "test-encryption",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2022-03-31 11:59:20 +00:00
|
|
|
resourcesFromState: []*resource.Resource{
|
2022-03-28 13:07:02 +00:00
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "terraform-20220328091515068500000001",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"id": "terraform-20220328091515068500000001",
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2022-04-04 13:28:59 +00:00
|
|
|
expectedRemoteResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "terraform-20220328091515068500000001",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"id": "terraform-20220328091515068500000001",
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
expectedStateResources: []*resource.Resource{
|
2022-03-28 13:07:02 +00:00
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "terraform-20220328091515068500000001",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"id": "terraform-20220328091515068500000001",
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2022-03-31 12:34:31 +00:00
|
|
|
{
|
|
|
|
name: "test encryption by default is enabled and unmanaged",
|
2022-07-21 08:37:03 +00:00
|
|
|
mocks: func(factory *dctlresource.MockResourceFactory) {},
|
2022-03-31 12:34:31 +00:00
|
|
|
remoteResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "test-encryption",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
resourcesFromState: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
2022-04-04 13:28:59 +00:00
|
|
|
expectedRemoteResources: []*resource.Resource{
|
2022-03-31 12:34:31 +00:00
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "test-encryption",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2022-04-04 13:28:59 +00:00
|
|
|
expectedStateResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
2022-03-31 12:34:31 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
name: "test encryption by default is disabled and unmanaged",
|
2022-07-21 08:37:03 +00:00
|
|
|
mocks: func(factory *dctlresource.MockResourceFactory) {},
|
2022-03-31 12:34:31 +00:00
|
|
|
remoteResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "test-encryption",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"enabled": false,
|
|
|
|
},
|
|
|
|
},
|
2022-04-05 13:38:55 +00:00
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
2022-03-31 12:34:31 +00:00
|
|
|
},
|
|
|
|
resourcesFromState: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
2022-04-04 13:28:59 +00:00
|
|
|
expectedRemoteResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
expectedStateResources: []*resource.Resource{
|
2022-03-31 12:34:31 +00:00
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2022-04-04 13:28:59 +00:00
|
|
|
{
|
|
|
|
name: "test encryption by default doesn't exist",
|
2022-07-21 08:37:03 +00:00
|
|
|
mocks: func(factory *dctlresource.MockResourceFactory) {},
|
2022-04-04 13:28:59 +00:00
|
|
|
remoteResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
resourcesFromState: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "bucket-2",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "test-encryption",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
expectedRemoteResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
expectedStateResources: []*resource.Resource{
|
|
|
|
{
|
|
|
|
Id: "bucket-1",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "bucket-2",
|
|
|
|
Type: aws.AwsS3BucketResourceType,
|
|
|
|
Attrs: &resource.Attributes{},
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Id: "test-encryption",
|
|
|
|
Type: aws.AwsEbsEncryptionByDefaultResourceType,
|
|
|
|
Attrs: &resource.Attributes{
|
|
|
|
"enabled": true,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
|
|
|
},
|
2022-03-28 13:07:02 +00:00
|
|
|
}
|
|
|
|
for _, tt := range tests {
|
|
|
|
t.Run(tt.name, func(t *testing.T) {
|
2022-07-21 08:37:03 +00:00
|
|
|
factory := &dctlresource.MockResourceFactory{}
|
2022-03-28 13:07:02 +00:00
|
|
|
if tt.mocks != nil {
|
|
|
|
tt.mocks(factory)
|
|
|
|
}
|
|
|
|
|
|
|
|
m := NewAwsEbsEncryptionByDefaultReconciler(factory)
|
|
|
|
err := m.Execute(&tt.remoteResources, &tt.resourcesFromState)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
|
2022-04-04 13:28:59 +00:00
|
|
|
changelog, err := diff.Diff(tt.remoteResources, tt.expectedRemoteResources)
|
2022-03-28 13:07:02 +00:00
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if len(changelog) > 0 {
|
|
|
|
for _, change := range changelog {
|
|
|
|
t.Errorf("%s got = %v, want %v", strings.Join(change.Path, "."), awsutil.Prettify(change.From), awsutil.Prettify(change.To))
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-04-04 13:28:59 +00:00
|
|
|
changelog, err = diff.Diff(tt.resourcesFromState, tt.expectedStateResources)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatal(err)
|
|
|
|
}
|
|
|
|
if len(changelog) > 0 {
|
|
|
|
for _, change := range changelog {
|
|
|
|
t.Errorf("%s got = %v, want %v", strings.Join(change.Path, "."), awsutil.Prettify(change.From), awsutil.Prettify(change.To))
|
|
|
|
}
|
|
|
|
}
|
2022-03-28 13:07:02 +00:00
|
|
|
})
|
|
|
|
}
|
|
|
|
}
|