sdk.go 8.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309
  1. package amazon
  2. import (
  3. "context"
  4. "fmt"
  5. "github.com/aws/aws-sdk-go/aws"
  6. "github.com/aws/aws-sdk-go/aws/session"
  7. "github.com/aws/aws-sdk-go/service/cloudformation"
  8. "github.com/aws/aws-sdk-go/service/cloudformation/cloudformationiface"
  9. "github.com/aws/aws-sdk-go/service/cloudwatchlogs"
  10. "github.com/aws/aws-sdk-go/service/cloudwatchlogs/cloudwatchlogsiface"
  11. "github.com/aws/aws-sdk-go/service/ec2"
  12. "github.com/aws/aws-sdk-go/service/ec2/ec2iface"
  13. "github.com/aws/aws-sdk-go/service/ecs"
  14. "github.com/aws/aws-sdk-go/service/ecs/ecsiface"
  15. "github.com/aws/aws-sdk-go/service/elbv2"
  16. "github.com/aws/aws-sdk-go/service/elbv2/elbv2iface"
  17. "github.com/aws/aws-sdk-go/service/iam"
  18. "github.com/aws/aws-sdk-go/service/iam/iamiface"
  19. "github.com/aws/aws-sdk-go/service/secretsmanager"
  20. "github.com/aws/aws-sdk-go/service/secretsmanager/secretsmanageriface"
  21. cf "github.com/awslabs/goformation/v4/cloudformation"
  22. "github.com/sirupsen/logrus"
  23. "github.com/docker/ecs-plugin/pkg/docker"
  24. )
  25. type sdk struct {
  26. sess *session.Session
  27. ECS ecsiface.ECSAPI
  28. EC2 ec2iface.EC2API
  29. ELB elbv2iface.ELBV2API
  30. CW cloudwatchlogsiface.CloudWatchLogsAPI
  31. IAM iamiface.IAMAPI
  32. CF cloudformationiface.CloudFormationAPI
  33. SM secretsmanageriface.SecretsManagerAPI
  34. }
  35. func NewAPI(sess *session.Session) API {
  36. return sdk{
  37. ECS: ecs.New(sess),
  38. EC2: ec2.New(sess),
  39. ELB: elbv2.New(sess),
  40. CW: cloudwatchlogs.New(sess),
  41. IAM: iam.New(sess),
  42. CF: cloudformation.New(sess),
  43. SM: secretsmanager.New(sess),
  44. }
  45. }
  46. func (s sdk) ClusterExists(ctx context.Context, name string) (bool, error) {
  47. logrus.Debug("Check if cluster was already created: ", name)
  48. clusters, err := s.ECS.DescribeClustersWithContext(ctx, &ecs.DescribeClustersInput{
  49. Clusters: []*string{aws.String(name)},
  50. })
  51. if err != nil {
  52. return false, err
  53. }
  54. return len(clusters.Clusters) > 0, nil
  55. }
  56. func (s sdk) CreateCluster(ctx context.Context, name string) (string, error) {
  57. logrus.Debug("Create cluster ", name)
  58. response, err := s.ECS.CreateClusterWithContext(ctx, &ecs.CreateClusterInput{ClusterName: aws.String(name)})
  59. if err != nil {
  60. return "", err
  61. }
  62. return *response.Cluster.Status, nil
  63. }
  64. func (s sdk) DeleteCluster(ctx context.Context, name string) error {
  65. logrus.Debug("Delete cluster ", name)
  66. response, err := s.ECS.DeleteClusterWithContext(ctx, &ecs.DeleteClusterInput{Cluster: aws.String(name)})
  67. if err != nil {
  68. return err
  69. }
  70. if *response.Cluster.Status == "INACTIVE" {
  71. return nil
  72. }
  73. return fmt.Errorf("Failed to delete cluster, status: %s" + *response.Cluster.Status)
  74. }
  75. func (s sdk) VpcExists(ctx context.Context, vpcID string) (bool, error) {
  76. logrus.Debug("Check if VPC exists: ", vpcID)
  77. _, err := s.EC2.DescribeVpcsWithContext(ctx, &ec2.DescribeVpcsInput{VpcIds: []*string{&vpcID}})
  78. return err == nil, err
  79. }
  80. func (s sdk) GetDefaultVPC(ctx context.Context) (string, error) {
  81. logrus.Debug("Retrieve default VPC")
  82. vpcs, err := s.EC2.DescribeVpcsWithContext(ctx, &ec2.DescribeVpcsInput{
  83. Filters: []*ec2.Filter{
  84. {
  85. Name: aws.String("isDefault"),
  86. Values: []*string{aws.String("true")},
  87. },
  88. },
  89. })
  90. if err != nil {
  91. return "", err
  92. }
  93. if len(vpcs.Vpcs) == 0 {
  94. return "", fmt.Errorf("account has not default VPC")
  95. }
  96. return *vpcs.Vpcs[0].VpcId, nil
  97. }
  98. func (s sdk) GetSubNets(ctx context.Context, vpcID string) ([]string, error) {
  99. logrus.Debug("Retrieve SubNets")
  100. subnets, err := s.EC2.DescribeSubnetsWithContext(ctx, &ec2.DescribeSubnetsInput{
  101. DryRun: nil,
  102. Filters: []*ec2.Filter{
  103. {
  104. Name: aws.String("vpc-id"),
  105. Values: []*string{aws.String(vpcID)},
  106. },
  107. {
  108. Name: aws.String("default-for-az"),
  109. Values: []*string{aws.String("true")},
  110. },
  111. },
  112. })
  113. if err != nil {
  114. return nil, err
  115. }
  116. ids := []string{}
  117. for _, subnet := range subnets.Subnets {
  118. ids = append(ids, *subnet.SubnetId)
  119. }
  120. return ids, nil
  121. }
  122. func (s sdk) GetRoleArn(ctx context.Context, name string) (string, error) {
  123. role, err := s.IAM.GetRoleWithContext(ctx, &iam.GetRoleInput{
  124. RoleName: aws.String(name),
  125. })
  126. if err != nil {
  127. return "", err
  128. }
  129. return *role.Role.Arn, nil
  130. }
  131. func (s sdk) StackExists(ctx context.Context, name string) (bool, error) {
  132. stacks, err := s.CF.DescribeStacksWithContext(ctx, &cloudformation.DescribeStacksInput{
  133. StackName: aws.String(name),
  134. })
  135. if err != nil {
  136. // FIXME doesn't work as expected
  137. return false, nil
  138. }
  139. return len(stacks.Stacks) > 0, nil
  140. }
  141. func (s sdk) CreateStack(ctx context.Context, name string, template *cf.Template, parameters map[string]string) error {
  142. logrus.Debug("Create CloudFormation stack")
  143. json, err := template.JSON()
  144. if err != nil {
  145. return err
  146. }
  147. param := []*cloudformation.Parameter{}
  148. for name, value := range parameters {
  149. param = append(param, &cloudformation.Parameter{
  150. ParameterKey: aws.String(name),
  151. ParameterValue: aws.String(value),
  152. UsePreviousValue: aws.Bool(true),
  153. })
  154. }
  155. _, err = s.CF.CreateStackWithContext(ctx, &cloudformation.CreateStackInput{
  156. OnFailure: aws.String("DELETE"),
  157. StackName: aws.String(name),
  158. TemplateBody: aws.String(string(json)),
  159. Parameters: param,
  160. TimeoutInMinutes: aws.Int64(10),
  161. Capabilities: []*string{
  162. aws.String(cloudformation.CapabilityCapabilityIam),
  163. },
  164. })
  165. return err
  166. }
  167. func (s sdk) WaitStackComplete(ctx context.Context, name string, operation int) error {
  168. input := &cloudformation.DescribeStacksInput{
  169. StackName: aws.String(name),
  170. }
  171. switch operation {
  172. case StackCreate:
  173. return s.CF.WaitUntilStackCreateCompleteWithContext(ctx, input)
  174. case StackDelete:
  175. return s.CF.WaitUntilStackDeleteCompleteWithContext(ctx, input)
  176. default:
  177. return fmt.Errorf("internal error: unexpected stack operation %d", operation)
  178. }
  179. }
  180. func (s sdk) GetStackID(ctx context.Context, name string) (string, error) {
  181. stacks, err := s.CF.DescribeStacksWithContext(ctx, &cloudformation.DescribeStacksInput{
  182. StackName: aws.String(name),
  183. })
  184. if err != nil {
  185. return "", err
  186. }
  187. return *stacks.Stacks[0].StackId, nil
  188. }
  189. func (s sdk) DescribeStackEvents(ctx context.Context, stackID string) ([]*cloudformation.StackEvent, error) {
  190. // Fixme implement Paginator on Events and return as a chan(events)
  191. events := []*cloudformation.StackEvent{}
  192. var nextToken *string
  193. for {
  194. resp, err := s.CF.DescribeStackEventsWithContext(ctx, &cloudformation.DescribeStackEventsInput{
  195. StackName: aws.String(stackID),
  196. NextToken: nextToken,
  197. })
  198. if err != nil {
  199. return nil, err
  200. }
  201. events = append(events, resp.StackEvents...)
  202. if resp.NextToken == nil {
  203. return events, nil
  204. }
  205. nextToken = resp.NextToken
  206. }
  207. }
  208. func (s sdk) DeleteStack(ctx context.Context, name string) error {
  209. logrus.Debug("Delete CloudFormation stack")
  210. _, err := s.CF.DeleteStackWithContext(ctx, &cloudformation.DeleteStackInput{
  211. StackName: aws.String(name),
  212. })
  213. return err
  214. }
  215. func (s sdk) CreateSecret(ctx context.Context, secret docker.Secret) (string, error) {
  216. logrus.Debug("Create secret " + secret.Name)
  217. secretStr, err := secret.GetCredString()
  218. if err != nil {
  219. return "", err
  220. }
  221. response, err := s.SM.CreateSecret(&secretsmanager.CreateSecretInput{
  222. Name: &secret.Name,
  223. SecretString: &secretStr,
  224. Description: &secret.Description,
  225. })
  226. if err != nil {
  227. return "", err
  228. }
  229. return *response.ARN, nil
  230. }
  231. func (s sdk) InspectSecret(ctx context.Context, id string) (docker.Secret, error) {
  232. logrus.Debug("Inspect secret " + id)
  233. response, err := s.SM.DescribeSecret(&secretsmanager.DescribeSecretInput{SecretId: &id})
  234. if err != nil {
  235. return docker.Secret{}, err
  236. }
  237. labels := map[string]string{}
  238. for _, tag := range response.Tags {
  239. labels[*tag.Key] = *tag.Value
  240. }
  241. secret := docker.Secret{
  242. ID: *response.ARN,
  243. Name: *response.Name,
  244. Labels: labels,
  245. }
  246. if response.Description != nil {
  247. secret.Description = *response.Description
  248. }
  249. return secret, nil
  250. }
  251. func (s sdk) ListSecrets(ctx context.Context) ([]docker.Secret, error) {
  252. logrus.Debug("List secrets ...")
  253. response, err := s.SM.ListSecrets(&secretsmanager.ListSecretsInput{})
  254. if err != nil {
  255. return []docker.Secret{}, err
  256. }
  257. var secrets []docker.Secret
  258. for _, sec := range response.SecretList {
  259. labels := map[string]string{}
  260. for _, tag := range sec.Tags {
  261. labels[*tag.Key] = *tag.Value
  262. }
  263. description := ""
  264. if sec.Description != nil {
  265. description = *sec.Description
  266. }
  267. secrets = append(secrets, docker.Secret{
  268. ID: *sec.ARN,
  269. Name: *sec.Name,
  270. Labels: labels,
  271. Description: description,
  272. })
  273. }
  274. return secrets, nil
  275. }
  276. func (s sdk) DeleteSecret(ctx context.Context, id string, recover bool) error {
  277. logrus.Debug("List secrets ...")
  278. force := !recover
  279. _, err := s.SM.DeleteSecret(&secretsmanager.DeleteSecretInput{SecretId: &id, ForceDeleteWithoutRecovery: &force})
  280. return err
  281. }