Merge pull request #1066 from cloudskiff/fea/google_storage_bucket_iam_binding
add support for google_storage_bucket_iam_bindingmain
commit
52e2aff560
1
go.mod
1
go.mod
|
@ -4,6 +4,7 @@ go 1.16
|
|||
|
||||
require (
|
||||
cloud.google.com/go/asset v0.1.0
|
||||
cloud.google.com/go/storage v1.10.0
|
||||
github.com/Azure/azure-sdk-for-go/sdk/azcore v0.19.0
|
||||
github.com/Azure/azure-sdk-for-go/sdk/azidentity v0.11.0
|
||||
github.com/Azure/azure-sdk-for-go/sdk/network/armnetwork v0.3.0
|
||||
|
|
|
@ -110,6 +110,7 @@ func (d DriftCTL) Run() (*analyser.Analysis, error) {
|
|||
middlewares.NewTagsAllManager(),
|
||||
middlewares.NewEipAssociationExpander(d.resourceFactory),
|
||||
middlewares.NewRDSClusterInstanceExpander(d.resourceFactory),
|
||||
middlewares.NewGoogleLegacyBucketIAMBindings(),
|
||||
)
|
||||
|
||||
if !d.opts.StrictMode {
|
||||
|
|
|
@ -323,6 +323,7 @@ func TestTerraformStateReader_Google_Resources(t *testing.T) {
|
|||
{name: "compute firewall", dirName: "google_compute_firewall", wantErr: false},
|
||||
{name: "compute router", dirName: "google_compute_router", wantErr: false},
|
||||
{name: "compute instance", dirName: "google_compute_instance", wantErr: false},
|
||||
{name: "Bucket IAM Bindings", dirName: "google_bucket_iam_binding", wantErr: false},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
|
|
|
@ -0,0 +1,50 @@
|
|||
[
|
||||
{
|
||||
"Id": "b/dctlgstoragebucketiambinding-2/roles/storage.admin",
|
||||
"Type": "google_storage_bucket_iam_binding",
|
||||
"Attrs": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-2",
|
||||
"id": "b/dctlgstoragebucketiambinding-2/roles/storage.admin",
|
||||
"members": [
|
||||
"user:william.beuil@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.admin"
|
||||
}
|
||||
},
|
||||
{
|
||||
"Id": "b/dctlgstoragebucketiambinding-1/roles/storage.objectViewer",
|
||||
"Type": "google_storage_bucket_iam_binding",
|
||||
"Attrs": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-1",
|
||||
"id": "b/dctlgstoragebucketiambinding-1/roles/storage.objectViewer",
|
||||
"members": [
|
||||
"user:william.beuil@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.objectViewer"
|
||||
}
|
||||
},
|
||||
{
|
||||
"Id": "b/dctlgstoragebucketiambinding-2/roles/storage.objectViewer",
|
||||
"Type": "google_storage_bucket_iam_binding",
|
||||
"Attrs": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-2",
|
||||
"id": "b/dctlgstoragebucketiambinding-2/roles/storage.objectViewer",
|
||||
"members": [
|
||||
"user:elie.charra@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.objectViewer"
|
||||
}
|
||||
},
|
||||
{
|
||||
"Id": "b/dctlgstoragebucketiambinding-1/roles/storage.admin",
|
||||
"Type": "google_storage_bucket_iam_binding",
|
||||
"Attrs": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-1",
|
||||
"id": "b/dctlgstoragebucketiambinding-1/roles/storage.admin",
|
||||
"members": [
|
||||
"user:elie.charra@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.admin"
|
||||
}
|
||||
}
|
||||
]
|
|
@ -0,0 +1,113 @@
|
|||
{
|
||||
"version": 4,
|
||||
"terraform_version": "0.14.5",
|
||||
"serial": 53,
|
||||
"lineage": "c2cd867e-c930-5de3-8592-8eb915e60cb8",
|
||||
"outputs": {},
|
||||
"resources": [
|
||||
{
|
||||
"mode": "managed",
|
||||
"type": "google_storage_bucket_iam_binding",
|
||||
"name": "binding_admin_1",
|
||||
"provider": "provider[\"registry.terraform.io/hashicorp/google\"]",
|
||||
"instances": [
|
||||
{
|
||||
"schema_version": 0,
|
||||
"attributes": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-1",
|
||||
"condition": [],
|
||||
"etag": "CAM=",
|
||||
"id": "b/dctlgstoragebucketiambinding-1/roles/storage.admin",
|
||||
"members": [
|
||||
"user:elie.charra@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.admin"
|
||||
},
|
||||
"sensitive_attributes": [],
|
||||
"private": "bnVsbA==",
|
||||
"dependencies": [
|
||||
"google_storage_bucket.dctlgstoragebucketiambinding-1"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"mode": "managed",
|
||||
"type": "google_storage_bucket_iam_binding",
|
||||
"name": "binding_admin_2",
|
||||
"provider": "provider[\"registry.terraform.io/hashicorp/google\"]",
|
||||
"instances": [
|
||||
{
|
||||
"schema_version": 0,
|
||||
"attributes": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-2",
|
||||
"condition": [],
|
||||
"etag": "CAM=",
|
||||
"id": "b/dctlgstoragebucketiambinding-2/roles/storage.admin",
|
||||
"members": [
|
||||
"user:william.beuil@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.admin"
|
||||
},
|
||||
"sensitive_attributes": [],
|
||||
"private": "bnVsbA==",
|
||||
"dependencies": [
|
||||
"google_storage_bucket.dctlgstoragebucketiambinding-2"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"mode": "managed",
|
||||
"type": "google_storage_bucket_iam_binding",
|
||||
"name": "binding_viewer_1",
|
||||
"provider": "provider[\"registry.terraform.io/hashicorp/google\"]",
|
||||
"instances": [
|
||||
{
|
||||
"schema_version": 0,
|
||||
"attributes": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-1",
|
||||
"condition": [],
|
||||
"etag": "CAM=",
|
||||
"id": "b/dctlgstoragebucketiambinding-1/roles/storage.objectViewer",
|
||||
"members": [
|
||||
"user:william.beuil@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.objectViewer"
|
||||
},
|
||||
"sensitive_attributes": [],
|
||||
"private": "bnVsbA==",
|
||||
"dependencies": [
|
||||
"google_storage_bucket.dctlgstoragebucketiambinding-1"
|
||||
]
|
||||
}
|
||||
]
|
||||
},
|
||||
{
|
||||
"mode": "managed",
|
||||
"type": "google_storage_bucket_iam_binding",
|
||||
"name": "binding_viewer_2",
|
||||
"provider": "provider[\"registry.terraform.io/hashicorp/google\"]",
|
||||
"instances": [
|
||||
{
|
||||
"schema_version": 0,
|
||||
"attributes": {
|
||||
"bucket": "b/dctlgstoragebucketiambinding-2",
|
||||
"condition": [],
|
||||
"etag": "CAM=",
|
||||
"id": "b/dctlgstoragebucketiambinding-2/roles/storage.objectViewer",
|
||||
"members": [
|
||||
"user:elie.charra@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.objectViewer"
|
||||
},
|
||||
"sensitive_attributes": [],
|
||||
"private": "bnVsbA==",
|
||||
"dependencies": [
|
||||
"google_storage_bucket.dctlgstoragebucketiambinding-2"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
|
@ -0,0 +1,60 @@
|
|||
package middlewares
|
||||
|
||||
import (
|
||||
"strings"
|
||||
|
||||
"github.com/cloudskiff/driftctl/pkg/resource"
|
||||
"github.com/cloudskiff/driftctl/pkg/resource/google"
|
||||
"github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
// Creating buckets add legacy role bindings, this middleware will filter them unless they are managed.
|
||||
type GoogleLegacyBucketIAMBindings struct{}
|
||||
|
||||
func NewGoogleLegacyBucketIAMBindings() GoogleLegacyBucketIAMBindings {
|
||||
return GoogleLegacyBucketIAMBindings{}
|
||||
}
|
||||
|
||||
func (m GoogleLegacyBucketIAMBindings) Execute(remoteResources, resourcesFromState *[]*resource.Resource) error {
|
||||
|
||||
newRemoteResources := make([]*resource.Resource, 0)
|
||||
|
||||
for _, remoteResource := range *remoteResources {
|
||||
// Ignore all resources other than BucketIamBinding
|
||||
if remoteResource.ResourceType() != google.GoogleStorageBucketIamBindingResourceType {
|
||||
newRemoteResources = append(newRemoteResources, remoteResource)
|
||||
continue
|
||||
}
|
||||
|
||||
// Ignore all non-legacy bindings
|
||||
if roleName := remoteResource.Attrs.GetString("role"); roleName != nil && !strings.Contains(*roleName, "legacy") {
|
||||
newRemoteResources = append(newRemoteResources, remoteResource)
|
||||
continue
|
||||
}
|
||||
|
||||
// Check if bindings is managed by IaC
|
||||
existInState := false
|
||||
for _, stateResource := range *resourcesFromState {
|
||||
if remoteResource.Equal(stateResource) {
|
||||
existInState = true
|
||||
break
|
||||
}
|
||||
}
|
||||
|
||||
// Include resource if it's managed in IaC
|
||||
if existInState {
|
||||
newRemoteResources = append(newRemoteResources, remoteResource)
|
||||
continue
|
||||
}
|
||||
|
||||
// Else, resource is not added to newRemoteResources slice, so it will be ignored
|
||||
logrus.WithFields(logrus.Fields{
|
||||
"id": remoteResource.ResourceId(),
|
||||
"type": remoteResource.ResourceType(),
|
||||
}).Debug("Ignoring legacy bucket bindings as it is not managed by IaC")
|
||||
}
|
||||
|
||||
*remoteResources = newRemoteResources
|
||||
|
||||
return nil
|
||||
}
|
|
@ -0,0 +1,139 @@
|
|||
package middlewares
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/aws/aws-sdk-go/aws/awsutil"
|
||||
"github.com/cloudskiff/driftctl/pkg/resource"
|
||||
"github.com/cloudskiff/driftctl/pkg/resource/google"
|
||||
"github.com/r3labs/diff/v2"
|
||||
)
|
||||
|
||||
func TestGoogleLegacyBucketIAMBindings_Execute(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
remoteResources []*resource.Resource
|
||||
resourcesFromState []*resource.Resource
|
||||
expected []*resource.Resource
|
||||
}{
|
||||
{
|
||||
"test that non legacy bindings are not ignored when managed by IaC",
|
||||
[]*resource.Resource{
|
||||
{
|
||||
Id: "fake",
|
||||
Type: google.GoogleStorageBucketResourceType,
|
||||
Attrs: &resource.Attributes{},
|
||||
},
|
||||
{
|
||||
Id: "admin bucket",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.admin",
|
||||
},
|
||||
},
|
||||
{
|
||||
Id: "legacy",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.legacyBucketOwner",
|
||||
},
|
||||
},
|
||||
},
|
||||
[]*resource.Resource{},
|
||||
[]*resource.Resource{
|
||||
{
|
||||
Id: "fake",
|
||||
Type: google.GoogleStorageBucketResourceType,
|
||||
Attrs: &resource.Attributes{},
|
||||
},
|
||||
{
|
||||
Id: "admin bucket",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.admin",
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
"test that legacy are not ignored when managed",
|
||||
[]*resource.Resource{
|
||||
{
|
||||
Id: "fake",
|
||||
Type: google.GoogleStorageBucketResourceType,
|
||||
Attrs: &resource.Attributes{},
|
||||
},
|
||||
{
|
||||
Id: "admin bucket",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.admin",
|
||||
},
|
||||
},
|
||||
{
|
||||
Id: "legacy",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.legacyBucketOwner",
|
||||
},
|
||||
},
|
||||
{
|
||||
Id: "legacy-managed",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.legacyBucketOwner",
|
||||
},
|
||||
},
|
||||
},
|
||||
[]*resource.Resource{
|
||||
{
|
||||
Id: "legacy-managed",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.legacyBucketOwner",
|
||||
},
|
||||
},
|
||||
},
|
||||
[]*resource.Resource{
|
||||
{
|
||||
Id: "fake",
|
||||
Type: google.GoogleStorageBucketResourceType,
|
||||
Attrs: &resource.Attributes{},
|
||||
},
|
||||
{
|
||||
Id: "admin bucket",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.admin",
|
||||
},
|
||||
},
|
||||
{
|
||||
Id: "legacy-managed",
|
||||
Type: google.GoogleStorageBucketIamBindingResourceType,
|
||||
Attrs: &resource.Attributes{
|
||||
"role": "storage.legacyBucketOwner",
|
||||
},
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
m := NewGoogleLegacyBucketIAMBindings()
|
||||
err := m.Execute(&tt.remoteResources, &tt.resourcesFromState)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
changelog, err := diff.Diff(tt.expected, tt.remoteResources)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(changelog) > 0 {
|
||||
for _, change := range changelog {
|
||||
t.Errorf("%s got = %v, want %v", strings.Join(change.Path, "."), awsutil.Prettify(change.From), awsutil.Prettify(change.To))
|
||||
}
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
|
@ -0,0 +1,62 @@
|
|||
package google
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
remoteerror "github.com/cloudskiff/driftctl/pkg/remote/error"
|
||||
"github.com/cloudskiff/driftctl/pkg/remote/google/repository"
|
||||
"github.com/cloudskiff/driftctl/pkg/resource"
|
||||
"github.com/cloudskiff/driftctl/pkg/resource/google"
|
||||
)
|
||||
|
||||
type GoogleStorageBucketIamBindingEnumerator struct {
|
||||
repository repository.AssetRepository
|
||||
storageRepository repository.StorageRepository
|
||||
factory resource.ResourceFactory
|
||||
}
|
||||
|
||||
func NewGoogleStorageBucketIamBindingEnumerator(repo repository.AssetRepository, storageRepo repository.StorageRepository, factory resource.ResourceFactory) *GoogleStorageBucketIamBindingEnumerator {
|
||||
return &GoogleStorageBucketIamBindingEnumerator{
|
||||
repository: repo,
|
||||
storageRepository: storageRepo,
|
||||
factory: factory,
|
||||
}
|
||||
}
|
||||
|
||||
func (e *GoogleStorageBucketIamBindingEnumerator) SupportedType() resource.ResourceType {
|
||||
return google.GoogleStorageBucketIamBindingResourceType
|
||||
}
|
||||
|
||||
func (e *GoogleStorageBucketIamBindingEnumerator) Enumerate() ([]*resource.Resource, error) {
|
||||
resources, err := e.repository.SearchAllBuckets()
|
||||
if err != nil {
|
||||
return nil, remoteerror.NewResourceListingErrorWithType(err, string(e.SupportedType()), google.GoogleStorageBucketResourceType)
|
||||
}
|
||||
|
||||
results := make([]*resource.Resource, len(resources))
|
||||
|
||||
for _, bucket := range resources {
|
||||
bindings, err := e.storageRepository.ListAllBindings(bucket.DisplayName)
|
||||
if err != nil {
|
||||
return nil, remoteerror.NewResourceListingError(err, string(e.SupportedType()))
|
||||
}
|
||||
for roleName, members := range bindings {
|
||||
id := fmt.Sprintf("b/%s/%s", bucket.DisplayName, roleName)
|
||||
results = append(
|
||||
results,
|
||||
e.factory.CreateAbstractResource(
|
||||
string(e.SupportedType()),
|
||||
id,
|
||||
map[string]interface{}{
|
||||
"id": id,
|
||||
"bucket": fmt.Sprintf("b/%s", bucket.DisplayName),
|
||||
"role": roleName,
|
||||
"members": members,
|
||||
},
|
||||
),
|
||||
)
|
||||
}
|
||||
}
|
||||
|
||||
return results, err
|
||||
}
|
|
@ -4,6 +4,7 @@ import (
|
|||
"context"
|
||||
|
||||
asset "cloud.google.com/go/asset/apiv1"
|
||||
"cloud.google.com/go/storage"
|
||||
"github.com/cloudskiff/driftctl/pkg/alerter"
|
||||
"github.com/cloudskiff/driftctl/pkg/output"
|
||||
"github.com/cloudskiff/driftctl/pkg/remote/cache"
|
||||
|
@ -38,7 +39,14 @@ func Init(version string, alerter *alerter.Alerter,
|
|||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
storageClient, err := storage.NewClient(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
assetRepository := repository.NewAssetRepository(assetClient, provider.GetConfig(), repositoryCache)
|
||||
storageRepository := repository.NewStorageRepository(storageClient, repositoryCache)
|
||||
|
||||
providerLibrary.AddProvider(terraform.GOOGLE, provider)
|
||||
deserializer := resource.NewDeserializer(factory)
|
||||
|
@ -53,6 +61,9 @@ func Init(version string, alerter *alerter.Alerter,
|
|||
|
||||
remoteLibrary.AddEnumerator(NewGoogleComputeInstanceEnumerator(assetRepository, factory))
|
||||
|
||||
remoteLibrary.AddEnumerator(NewGoogleStorageBucketIamBindingEnumerator(assetRepository, storageRepository, factory))
|
||||
remoteLibrary.AddDetailsFetcher(google.GoogleStorageBucketIamBindingResourceType, common.NewGenericDetailsFetcher(google.GoogleStorageBucketIamBindingResourceType, provider, deserializer))
|
||||
|
||||
remoteLibrary.AddEnumerator(NewGoogleComputeNetworkEnumerator(assetRepository, factory))
|
||||
remoteLibrary.AddDetailsFetcher(google.GoogleComputeNetworkResourceType, common.NewGenericDetailsFetcher(google.GoogleComputeNetworkResourceType, provider, deserializer))
|
||||
|
||||
|
|
|
@ -0,0 +1,128 @@
|
|||
// Code generated by mockery v0.0.0-dev. DO NOT EDIT.
|
||||
|
||||
package repository
|
||||
|
||||
import (
|
||||
mock "github.com/stretchr/testify/mock"
|
||||
asset "google.golang.org/genproto/googleapis/cloud/asset/v1"
|
||||
)
|
||||
|
||||
// MockAssetRepository is an autogenerated mock type for the AssetRepository type
|
||||
type MockAssetRepository struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
// SearchAllBuckets provides a mock function with given fields:
|
||||
func (_m *MockAssetRepository) SearchAllBuckets() ([]*asset.ResourceSearchResult, error) {
|
||||
ret := _m.Called()
|
||||
|
||||
var r0 []*asset.ResourceSearchResult
|
||||
if rf, ok := ret.Get(0).(func() []*asset.ResourceSearchResult); ok {
|
||||
r0 = rf()
|
||||
} else {
|
||||
if ret.Get(0) != nil {
|
||||
r0 = ret.Get(0).([]*asset.ResourceSearchResult)
|
||||
}
|
||||
}
|
||||
|
||||
var r1 error
|
||||
if rf, ok := ret.Get(1).(func() error); ok {
|
||||
r1 = rf()
|
||||
} else {
|
||||
r1 = ret.Error(1)
|
||||
}
|
||||
|
||||
return r0, r1
|
||||
}
|
||||
|
||||
// SearchAllFirewalls provides a mock function with given fields:
|
||||
func (_m *MockAssetRepository) SearchAllFirewalls() ([]*asset.ResourceSearchResult, error) {
|
||||
ret := _m.Called()
|
||||
|
||||
var r0 []*asset.ResourceSearchResult
|
||||
if rf, ok := ret.Get(0).(func() []*asset.ResourceSearchResult); ok {
|
||||
r0 = rf()
|
||||
} else {
|
||||
if ret.Get(0) != nil {
|
||||
r0 = ret.Get(0).([]*asset.ResourceSearchResult)
|
||||
}
|
||||
}
|
||||
|
||||
var r1 error
|
||||
if rf, ok := ret.Get(1).(func() error); ok {
|
||||
r1 = rf()
|
||||
} else {
|
||||
r1 = ret.Error(1)
|
||||
}
|
||||
|
||||
return r0, r1
|
||||
}
|
||||
|
||||
// SearchAllInstances provides a mock function with given fields:
|
||||
func (_m *MockAssetRepository) SearchAllInstances() ([]*asset.ResourceSearchResult, error) {
|
||||
ret := _m.Called()
|
||||
|
||||
var r0 []*asset.ResourceSearchResult
|
||||
if rf, ok := ret.Get(0).(func() []*asset.ResourceSearchResult); ok {
|
||||
r0 = rf()
|
||||
} else {
|
||||
if ret.Get(0) != nil {
|
||||
r0 = ret.Get(0).([]*asset.ResourceSearchResult)
|
||||
}
|
||||
}
|
||||
|
||||
var r1 error
|
||||
if rf, ok := ret.Get(1).(func() error); ok {
|
||||
r1 = rf()
|
||||
} else {
|
||||
r1 = ret.Error(1)
|
||||
}
|
||||
|
||||
return r0, r1
|
||||
}
|
||||
|
||||
// SearchAllNetworks provides a mock function with given fields:
|
||||
func (_m *MockAssetRepository) SearchAllNetworks() ([]*asset.ResourceSearchResult, error) {
|
||||
ret := _m.Called()
|
||||
|
||||
var r0 []*asset.ResourceSearchResult
|
||||
if rf, ok := ret.Get(0).(func() []*asset.ResourceSearchResult); ok {
|
||||
r0 = rf()
|
||||
} else {
|
||||
if ret.Get(0) != nil {
|
||||
r0 = ret.Get(0).([]*asset.ResourceSearchResult)
|
||||
}
|
||||
}
|
||||
|
||||
var r1 error
|
||||
if rf, ok := ret.Get(1).(func() error); ok {
|
||||
r1 = rf()
|
||||
} else {
|
||||
r1 = ret.Error(1)
|
||||
}
|
||||
|
||||
return r0, r1
|
||||
}
|
||||
|
||||
// SearchAllRouters provides a mock function with given fields:
|
||||
func (_m *MockAssetRepository) SearchAllRouters() ([]*asset.ResourceSearchResult, error) {
|
||||
ret := _m.Called()
|
||||
|
||||
var r0 []*asset.ResourceSearchResult
|
||||
if rf, ok := ret.Get(0).(func() []*asset.ResourceSearchResult); ok {
|
||||
r0 = rf()
|
||||
} else {
|
||||
if ret.Get(0) != nil {
|
||||
r0 = ret.Get(0).([]*asset.ResourceSearchResult)
|
||||
}
|
||||
}
|
||||
|
||||
var r1 error
|
||||
if rf, ok := ret.Get(1).(func() error); ok {
|
||||
r1 = rf()
|
||||
} else {
|
||||
r1 = ret.Error(1)
|
||||
}
|
||||
|
||||
return r0, r1
|
||||
}
|
|
@ -0,0 +1,33 @@
|
|||
// Code generated by mockery v0.0.0-dev. DO NOT EDIT.
|
||||
|
||||
package repository
|
||||
|
||||
import mock "github.com/stretchr/testify/mock"
|
||||
|
||||
// MockStorageRepository is an autogenerated mock type for the StorageRepository type
|
||||
type MockStorageRepository struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
// ListAllBindings provides a mock function with given fields: bucketName
|
||||
func (_m *MockStorageRepository) ListAllBindings(bucketName string) (map[string][]string, error) {
|
||||
ret := _m.Called(bucketName)
|
||||
|
||||
var r0 map[string][]string
|
||||
if rf, ok := ret.Get(0).(func(string) map[string][]string); ok {
|
||||
r0 = rf(bucketName)
|
||||
} else {
|
||||
if ret.Get(0) != nil {
|
||||
r0 = ret.Get(0).(map[string][]string)
|
||||
}
|
||||
}
|
||||
|
||||
var r1 error
|
||||
if rf, ok := ret.Get(1).(func(string) error); ok {
|
||||
r1 = rf(bucketName)
|
||||
} else {
|
||||
r1 = ret.Error(1)
|
||||
}
|
||||
|
||||
return r0, r1
|
||||
}
|
|
@ -0,0 +1,52 @@
|
|||
package repository
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"sync"
|
||||
|
||||
"cloud.google.com/go/storage"
|
||||
"github.com/cloudskiff/driftctl/pkg/remote/cache"
|
||||
)
|
||||
|
||||
type StorageRepository interface {
|
||||
ListAllBindings(bucketName string) (map[string][]string, error)
|
||||
}
|
||||
|
||||
type storageRepository struct {
|
||||
client *storage.Client
|
||||
cache cache.Cache
|
||||
lock sync.Locker
|
||||
}
|
||||
|
||||
func NewStorageRepository(client *storage.Client, cache cache.Cache) *storageRepository {
|
||||
return &storageRepository{
|
||||
client: client,
|
||||
cache: cache,
|
||||
lock: &sync.Mutex{},
|
||||
}
|
||||
}
|
||||
|
||||
func (s storageRepository) ListAllBindings(bucketName string) (map[string][]string, error) {
|
||||
|
||||
s.lock.Lock()
|
||||
defer s.lock.Unlock()
|
||||
if cachedResults := s.cache.Get(fmt.Sprintf("%s-%s", "ListAllBindings", bucketName)); cachedResults != nil {
|
||||
return cachedResults.(map[string][]string), nil
|
||||
}
|
||||
|
||||
bucket := s.client.Bucket(bucketName)
|
||||
policy, err := bucket.IAM().Policy(context.Background())
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
bindings := make(map[string][]string)
|
||||
for _, name := range policy.Roles() {
|
||||
members := policy.Members(name)
|
||||
bindings[string(name)] = members
|
||||
}
|
||||
|
||||
s.cache.Put("ListAllBindings", bindings)
|
||||
|
||||
return bindings, nil
|
||||
}
|
|
@ -5,6 +5,7 @@ import (
|
|||
"testing"
|
||||
|
||||
asset "cloud.google.com/go/asset/apiv1"
|
||||
"cloud.google.com/go/storage"
|
||||
"github.com/cloudskiff/driftctl/mocks"
|
||||
"github.com/cloudskiff/driftctl/pkg/filter"
|
||||
"github.com/cloudskiff/driftctl/pkg/remote/alerts"
|
||||
|
@ -21,6 +22,7 @@ import (
|
|||
testgoogle "github.com/cloudskiff/driftctl/test/google"
|
||||
testresource "github.com/cloudskiff/driftctl/test/resource"
|
||||
terraform2 "github.com/cloudskiff/driftctl/test/terraform"
|
||||
"github.com/pkg/errors"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/mock"
|
||||
assetpb "google.golang.org/genproto/googleapis/cloud/asset/v1"
|
||||
|
@ -156,3 +158,172 @@ func TestGoogleStorageBucket(t *testing.T) {
|
|||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestGoogleStorageBucketIAMBinding(t *testing.T) {
|
||||
|
||||
cases := []struct {
|
||||
test string
|
||||
dirName string
|
||||
assetRepositoryMock func(assetRepository *repository.MockAssetRepository)
|
||||
storageRepositoryMock func(storageRepository *repository.MockStorageRepository)
|
||||
responseErr error
|
||||
setupAlerterMock func(alerter *mocks.AlerterInterface)
|
||||
wantErr error
|
||||
}{
|
||||
{
|
||||
test: "no storage buckets",
|
||||
dirName: "google_storage_bucket_empty",
|
||||
assetRepositoryMock: func(assetRepository *repository.MockAssetRepository) {
|
||||
assetRepository.On("SearchAllBuckets").Return([]*assetpb.ResourceSearchResult{}, nil)
|
||||
},
|
||||
wantErr: nil,
|
||||
},
|
||||
{
|
||||
test: "multiples storage buckets, no bindings",
|
||||
dirName: "google_storage_bucket_binding_empty",
|
||||
assetRepositoryMock: func(assetRepository *repository.MockAssetRepository) {
|
||||
assetRepository.On("SearchAllBuckets").Return([]*assetpb.ResourceSearchResult{
|
||||
{
|
||||
AssetType: "storage.googleapis.com/Bucket",
|
||||
DisplayName: "dctlgstoragebucketiambinding-1",
|
||||
},
|
||||
{
|
||||
AssetType: "storage.googleapis.com/Bucket",
|
||||
DisplayName: "dctlgstoragebucketiambinding-2",
|
||||
},
|
||||
}, nil)
|
||||
},
|
||||
storageRepositoryMock: func(storageRepository *repository.MockStorageRepository) {
|
||||
storageRepository.On("ListAllBindings", "dctlgstoragebucketiambinding-1").Return(map[string][]string{}, nil)
|
||||
storageRepository.On("ListAllBindings", "dctlgstoragebucketiambinding-2").Return(map[string][]string{}, nil)
|
||||
},
|
||||
wantErr: nil,
|
||||
},
|
||||
{
|
||||
test: "Cannot list bindings",
|
||||
dirName: "google_storage_bucket_binding_listing_error",
|
||||
assetRepositoryMock: func(assetRepository *repository.MockAssetRepository) {
|
||||
assetRepository.On("SearchAllBuckets").Return([]*assetpb.ResourceSearchResult{
|
||||
{
|
||||
AssetType: "storage.googleapis.com/Bucket",
|
||||
DisplayName: "dctlgstoragebucketiambinding-1",
|
||||
},
|
||||
}, nil)
|
||||
},
|
||||
storageRepositoryMock: func(storageRepository *repository.MockStorageRepository) {
|
||||
storageRepository.On("ListAllBindings", "dctlgstoragebucketiambinding-1").Return(
|
||||
map[string][]string{},
|
||||
errors.New("googleapi: Error 403: driftctl-acc-circle@driftctl-qa-1.iam.gserviceaccount.com does not have storage.buckets.getIamPolicy access to the Google Cloud Storage bucket., forbidden"))
|
||||
},
|
||||
setupAlerterMock: func(alerter *mocks.AlerterInterface) {
|
||||
alerter.On(
|
||||
"SendAlert",
|
||||
"google_storage_bucket_iam_binding",
|
||||
alerts.NewRemoteAccessDeniedAlert(
|
||||
common.RemoteGoogleTerraform,
|
||||
remoteerr.NewResourceListingError(
|
||||
errors.New("googleapi: Error 403: driftctl-acc-circle@driftctl-qa-1.iam.gserviceaccount.com does not have storage.buckets.getIamPolicy access to the Google Cloud Storage bucket., forbidden"),
|
||||
"google_storage_bucket_iam_binding",
|
||||
),
|
||||
alerts.EnumerationPhase,
|
||||
),
|
||||
).Once()
|
||||
},
|
||||
wantErr: nil,
|
||||
},
|
||||
{
|
||||
test: "multiples storage buckets, multiple bindings",
|
||||
dirName: "google_storage_bucket_binding_multiple",
|
||||
assetRepositoryMock: func(assetRepository *repository.MockAssetRepository) {
|
||||
assetRepository.On("SearchAllBuckets").Return([]*assetpb.ResourceSearchResult{
|
||||
{
|
||||
AssetType: "storage.googleapis.com/Bucket",
|
||||
DisplayName: "dctlgstoragebucketiambinding-1",
|
||||
},
|
||||
{
|
||||
AssetType: "storage.googleapis.com/Bucket",
|
||||
DisplayName: "dctlgstoragebucketiambinding-2",
|
||||
},
|
||||
}, nil)
|
||||
},
|
||||
storageRepositoryMock: func(storageRepository *repository.MockStorageRepository) {
|
||||
storageRepository.On("ListAllBindings", "dctlgstoragebucketiambinding-1").Return(map[string][]string{
|
||||
"roles/storage.admin": {"user:elie.charra@cloudskiff.com"},
|
||||
"roles/storage.objectViewer": {"user:william.beuil@cloudskiff.com"},
|
||||
}, nil)
|
||||
|
||||
storageRepository.On("ListAllBindings", "dctlgstoragebucketiambinding-2").Return(map[string][]string{
|
||||
"roles/storage.admin": {"user:william.beuil@cloudskiff.com"},
|
||||
"roles/storage.objectViewer": {"user:elie.charra@cloudskiff.com"},
|
||||
}, nil)
|
||||
},
|
||||
wantErr: nil,
|
||||
},
|
||||
}
|
||||
|
||||
providerVersion := "3.78.0"
|
||||
resType := resource.ResourceType(googleresource.GoogleStorageBucketIamBindingResourceType)
|
||||
schemaRepository := testresource.InitFakeSchemaRepository("google", providerVersion)
|
||||
googleresource.InitResourcesMetadata(schemaRepository)
|
||||
factory := terraform.NewTerraformResourceFactory(schemaRepository)
|
||||
deserializer := resource.NewDeserializer(factory)
|
||||
|
||||
for _, c := range cases {
|
||||
t.Run(c.test, func(tt *testing.T) {
|
||||
repositoryCache := cache.New(100)
|
||||
|
||||
shouldUpdate := c.dirName == *goldenfile.Update
|
||||
|
||||
scanOptions := ScannerOptions{Deep: true}
|
||||
providerLibrary := terraform.NewProviderLibrary()
|
||||
remoteLibrary := common.NewRemoteLibrary()
|
||||
|
||||
// Initialize mocks
|
||||
alerter := &mocks.AlerterInterface{}
|
||||
if c.setupAlerterMock != nil {
|
||||
c.setupAlerterMock(alerter)
|
||||
}
|
||||
|
||||
storageRepo := &repository.MockStorageRepository{}
|
||||
if c.storageRepositoryMock != nil {
|
||||
c.storageRepositoryMock(storageRepo)
|
||||
}
|
||||
var storageRepository repository.StorageRepository = storageRepo
|
||||
if shouldUpdate {
|
||||
storageClient, err := storage.NewClient(context.Background())
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
storageRepository = repository.NewStorageRepository(storageClient, repositoryCache)
|
||||
}
|
||||
|
||||
assetRepo := &repository.MockAssetRepository{}
|
||||
if c.assetRepositoryMock != nil {
|
||||
c.assetRepositoryMock(assetRepo)
|
||||
}
|
||||
var assetRepository repository.AssetRepository = assetRepo
|
||||
|
||||
realProvider, err := terraform2.InitTestGoogleProvider(providerLibrary, providerVersion)
|
||||
if err != nil {
|
||||
tt.Fatal(err)
|
||||
}
|
||||
provider := terraform2.NewFakeTerraformProvider(realProvider)
|
||||
provider.WithResponse(c.dirName)
|
||||
|
||||
remoteLibrary.AddEnumerator(google.NewGoogleStorageBucketIamBindingEnumerator(assetRepository, storageRepository, factory))
|
||||
|
||||
testFilter := &filter.MockFilter{}
|
||||
testFilter.On("IsTypeIgnored", mock.Anything).Return(false)
|
||||
|
||||
s := NewScanner(remoteLibrary, alerter, scanOptions, testFilter)
|
||||
got, err := s.Resources()
|
||||
assert.Equal(tt, c.wantErr, err)
|
||||
if err != nil {
|
||||
return
|
||||
}
|
||||
alerter.AssertExpectations(tt)
|
||||
testFilter.AssertExpectations(tt)
|
||||
test.TestAgainstGoldenFile(got, resType.String(), c.dirName, provider, deserializer, shouldUpdate, tt)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
|
|
@ -28,6 +28,12 @@ func HandleResourceEnumerationError(err error, alerter alerter.AlerterInterface)
|
|||
return handleGoogleEnumerationError(alerter, listError, status.Convert(rootCause))
|
||||
}
|
||||
|
||||
// at least for storage api google sdk does not return grpc error so we parse the error message.
|
||||
if shouldHandleGoogleForbiddenError(listError) {
|
||||
alerts.SendEnumerationAlert(common.RemoteGoogleTerraform, alerter, listError)
|
||||
return nil
|
||||
}
|
||||
|
||||
reqerr, ok := rootCause.(awserr.RequestFailure)
|
||||
if ok {
|
||||
return handleAWSError(alerter, listError, reqerr)
|
||||
|
@ -59,7 +65,7 @@ func HandleResourceDetailsFetchingError(err error, alerter alerter.AlerterInterf
|
|||
|
||||
rootCause := listError.RootCause()
|
||||
|
||||
if shouldHandleGoogleDetailsFetchingError(listError) {
|
||||
if shouldHandleGoogleForbiddenError(listError) {
|
||||
alerts.SendDetailsFetchingAlert(common.RemoteGoogleTerraform, alerter, listError)
|
||||
return nil
|
||||
}
|
||||
|
@ -93,7 +99,7 @@ func handleGoogleEnumerationError(alerter alerter.AlerterInterface, err *remotee
|
|||
return err
|
||||
}
|
||||
|
||||
func shouldHandleGoogleDetailsFetchingError(err *remoteerror.ResourceScanningError) bool {
|
||||
func shouldHandleGoogleForbiddenError(err *remoteerror.ResourceScanningError) bool {
|
||||
errMsg := err.RootCause().Error()
|
||||
|
||||
// Check if this is a Google related error
|
||||
|
|
|
@ -0,0 +1,42 @@
|
|||
[
|
||||
{
|
||||
"bucket": "b/dctlgstoragebucketiambinding-1",
|
||||
"condition": null,
|
||||
"etag": null,
|
||||
"id": "b/dctlgstoragebucketiambinding-1/roles/storage.admin",
|
||||
"members": [
|
||||
"user:elie.charra@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.admin"
|
||||
},
|
||||
{
|
||||
"bucket": "b/dctlgstoragebucketiambinding-1",
|
||||
"condition": null,
|
||||
"etag": null,
|
||||
"id": "b/dctlgstoragebucketiambinding-1/roles/storage.objectViewer",
|
||||
"members": [
|
||||
"user:william.beuil@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.objectViewer"
|
||||
},
|
||||
{
|
||||
"bucket": "b/dctlgstoragebucketiambinding-2",
|
||||
"condition": null,
|
||||
"etag": null,
|
||||
"id": "b/dctlgstoragebucketiambinding-2/roles/storage.objectViewer",
|
||||
"members": [
|
||||
"user:elie.charra@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.objectViewer"
|
||||
},
|
||||
{
|
||||
"bucket": "b/dctlgstoragebucketiambinding-2",
|
||||
"condition": null,
|
||||
"etag": null,
|
||||
"id": "b/dctlgstoragebucketiambinding-2/roles/storage.admin",
|
||||
"members": [
|
||||
"user:william.beuil@cloudskiff.com"
|
||||
],
|
||||
"role": "roles/storage.admin"
|
||||
}
|
||||
]
|
|
@ -0,0 +1,20 @@
|
|||
package google
|
||||
|
||||
import "github.com/cloudskiff/driftctl/pkg/resource"
|
||||
|
||||
const GoogleStorageBucketIamBindingResourceType = "google_storage_bucket_iam_binding"
|
||||
|
||||
func initGoogleStorageBucketIamBindingMetadata(resourceSchemaRepository resource.SchemaRepositoryInterface) {
|
||||
resourceSchemaRepository.SetNormalizeFunc(GoogleStorageBucketIamBindingResourceType, func(res *resource.Resource) {
|
||||
res.Attributes().SafeDelete([]string{"force_destroy"})
|
||||
res.Attributes().SafeDelete([]string{"etag"})
|
||||
})
|
||||
resourceSchemaRepository.SetResolveReadAttributesFunc(GoogleStorageBucketIamBindingResourceType, func(res *resource.Resource) map[string]string {
|
||||
return map[string]string{
|
||||
"bucket": *res.Attrs.GetString("bucket"),
|
||||
"role": *res.Attrs.GetString("role"),
|
||||
}
|
||||
})
|
||||
resourceSchemaRepository.SetFlags(GoogleStorageBucketIamBindingResourceType, resource.FlagDeepMode)
|
||||
|
||||
}
|
|
@ -0,0 +1,31 @@
|
|||
package google_test
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"github.com/cloudskiff/driftctl/test"
|
||||
"github.com/cloudskiff/driftctl/test/acceptance"
|
||||
)
|
||||
|
||||
func TestAcc_Google_StorageBucketIAMBinding(t *testing.T) {
|
||||
acceptance.Run(t, acceptance.AccTestCase{
|
||||
TerraformVersion: "0.15.5",
|
||||
Paths: []string{"./testdata/acc/google_storage_bucket_iam_binding"},
|
||||
Args: []string{
|
||||
"scan",
|
||||
"--to", "gcp+tf",
|
||||
"--filter", "Type=='google_storage_bucket_iam_binding'",
|
||||
},
|
||||
Checks: []acceptance.AccCheck{
|
||||
{
|
||||
Check: func(result *test.ScanResult, stdout string, err error) {
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
result.AssertInfrastructureIsInSync()
|
||||
result.AssertManagedCount(3)
|
||||
},
|
||||
},
|
||||
},
|
||||
})
|
||||
}
|
|
@ -7,4 +7,5 @@ func InitResourcesMetadata(resourceSchemaRepository resource.SchemaRepositoryInt
|
|||
initGoogleComputeFirewallMetadata(resourceSchemaRepository)
|
||||
initGoogleComputeRouterMetadata(resourceSchemaRepository)
|
||||
initGoogleComputeNetworkMetadata(resourceSchemaRepository)
|
||||
initGoogleStorageBucketIamBindingMetadata(resourceSchemaRepository)
|
||||
}
|
||||
|
|
50
pkg/resource/google/testdata/acc/google_storage_bucket_iam_binding/terraform.tf
vendored
Normal file
50
pkg/resource/google/testdata/acc/google_storage_bucket_iam_binding/terraform.tf
vendored
Normal file
|
@ -0,0 +1,50 @@
|
|||
provider "google" {}
|
||||
|
||||
terraform {
|
||||
required_version = "~> 0.15.0"
|
||||
required_providers {
|
||||
google = {
|
||||
version = "3.78.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
resource "random_string" "postfix" {
|
||||
length = 6
|
||||
upper = false
|
||||
special = false
|
||||
}
|
||||
|
||||
resource "google_storage_bucket" "driftctl-unittest" {
|
||||
name = "driftctl-unittest-1-${random_string.postfix.result}"
|
||||
location = "EU"
|
||||
}
|
||||
|
||||
resource "google_storage_bucket_iam_binding" "binding_admin_1" {
|
||||
bucket = google_storage_bucket.driftctl-unittest.name
|
||||
role = "roles/storage.admin"
|
||||
members = [
|
||||
"user:elie.charra@cloudskiff.com",
|
||||
]
|
||||
}
|
||||
|
||||
resource "google_storage_bucket_iam_binding" "binding_viewer_1" {
|
||||
bucket = google_storage_bucket.driftctl-unittest.name
|
||||
role = "roles/storage.objectViewer"
|
||||
members = [
|
||||
"user:william.beuil@cloudskiff.com",
|
||||
]
|
||||
}
|
||||
|
||||
resource "google_storage_bucket" "driftctl-unittest2" {
|
||||
name = "driftctl-unittest-2-${random_string.postfix.result}"
|
||||
location = "EU"
|
||||
}
|
||||
|
||||
resource "google_storage_bucket_iam_binding" "binding_admin_2" {
|
||||
bucket = google_storage_bucket.driftctl-unittest2.name
|
||||
role = "roles/storage.admin"
|
||||
members = [
|
||||
"user:elie.charra@cloudskiff.com",
|
||||
]
|
||||
}
|
|
@ -72,11 +72,12 @@ var supportedTypes = map[string]struct{}{
|
|||
"github_team": {},
|
||||
"github_team_membership": {},
|
||||
|
||||
"google_storage_bucket": {},
|
||||
"google_compute_firewall": {},
|
||||
"google_compute_router": {},
|
||||
"google_compute_instance": {},
|
||||
"google_compute_network": {},
|
||||
"google_storage_bucket": {},
|
||||
"google_compute_firewall": {},
|
||||
"google_compute_router": {},
|
||||
"google_compute_instance": {},
|
||||
"google_compute_network": {},
|
||||
"google_storage_bucket_iam_binding": {},
|
||||
|
||||
"azurerm_storage_account": {},
|
||||
"azurerm_storage_container": {},
|
||||
|
|
Loading…
Reference in New Issue