feat: add support for aws imds credentials

This commit is contained in:
Fu Diwei
2026-07-30 16:37:17 +08:00
committed by RHQYZ
parent bd6d1266b5
commit 4e7b1a0758
44 changed files with 551 additions and 78 deletions
@@ -4,11 +4,16 @@ import (
"fmt"
"time"
"github.com/aws/aws-sdk-go-v2/aws"
"github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/certimate-go/certimate/pkg/core"
"github.com/certimate-go/certimate/pkg/core/certifier/challengers/dns01/aws-lightsail/internal"
)
type ChallengerConfig struct {
AuthMethod string `json:"authMethod"`
AccessKeyId string `json:"accessKeyId"`
SecretAccessKey string `json:"secretAccessKey"`
Region string `json:"region"`
@@ -22,8 +27,18 @@ func NewChallenger(config *ChallengerConfig) (core.ACMEChallenger, error) {
}
providerConfig := internal.NewDefaultConfig()
providerConfig.AccessKeyID = config.AccessKeyId
providerConfig.SecretAccessKey = config.SecretAccessKey
switch config.AuthMethod {
case "":
if config.AccessKeyId != "" && config.SecretAccessKey != "" {
providerConfig.AWSCredentialsProvider = credentials.NewStaticCredentialsProvider(config.AccessKeyId, config.SecretAccessKey, "")
}
case AUTH_METHOD_ACCESSKEY:
providerConfig.AWSCredentialsProvider = credentials.NewStaticCredentialsProvider(config.AccessKeyId, config.SecretAccessKey, "")
case AUTH_METHOD_IMDS:
providerConfig.AWSCredentialsProvider = aws.NewCredentialsCache(ec2rolecreds.New())
default:
return nil, fmt.Errorf("unsupported auth method '%s'", config.AuthMethod)
}
providerConfig.Region = config.Region
if config.DnsPropagationTimeout != 0 {
providerConfig.PropagationTimeout = time.Duration(config.DnsPropagationTimeout) * time.Second
@@ -0,0 +1,10 @@
package awslightsail
import (
route53 "github.com/certimate-go/certimate/pkg/core/certifier/challengers/dns01/aws-route53"
)
const (
AUTH_METHOD_ACCESSKEY = route53.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = route53.AUTH_METHOD_IMDS
)
@@ -8,7 +8,6 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/service/lightsail"
"github.com/aws/aws-sdk-go-v2/service/lightsail/types"
"github.com/go-acme/lego/v5/challenge"
@@ -25,15 +24,11 @@ const (
EnvPollingInterval = envNamespace + "POLLING_INTERVAL"
)
const maxRetries = 5
var _ challenge.ProviderTimeout = (*DNSProvider)(nil)
type Config struct {
AccessKeyID string
SecretAccessKey string
SessionToken string
Region string
AWSCredentialsProvider aws.CredentialsProvider
Region string
PropagationTimeout time.Duration
PollingInterval time.Duration
@@ -65,11 +60,14 @@ func NewDNSProviderConfig(config *Config) (*DNSProvider, error) {
return nil, fmt.Errorf("lightsail: the configuration of the DNS provider is nil")
}
ctx := context.Background()
cfg, err := awscfg.LoadDefaultConfig(ctx,
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(config.AccessKeyID, config.SecretAccessKey, config.SessionToken)),
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(config.Region),
)
}
if config.AWSCredentialsProvider != nil {
opts = append(opts, awscfg.WithCredentialsProvider(config.AWSCredentialsProvider))
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -10,6 +10,7 @@ import (
)
type ChallengerConfig struct {
AuthMethod string `json:"authMethod"` // not used for now
AccessKeyId string `json:"accessKeyId"`
SecretAccessKey string `json:"secretAccessKey"`
Region string `json:"region"`
@@ -0,0 +1,6 @@
package awsroute53
const (
AUTH_METHOD_ACCESSKEY = "accesskey"
AUTH_METHOD_IMDS = "imds"
)
@@ -32,7 +32,7 @@ func NewChallenger(config *ChallengerConfig) (core.ACMEChallenger, error) {
providerConfig := oraclecloud.NewDefaultConfig()
providerConfig.CompartmentID = config.CompartmentOcid
switch config.AuthMethod {
case AUTH_METHOD_APIKEY:
case "", AUTH_METHOD_APIKEY:
pkpwd := (*string)(nil)
if config.PrivateKeyPassphrase != "" {
pkpwd = &config.PrivateKeyPassphrase
+26 -5
View File
@@ -10,6 +10,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/acm"
"github.com/aws/smithy-go"
@@ -24,6 +25,10 @@ type (
)
type CertmgrConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -45,7 +50,7 @@ func NewCertmgr(config *CertmgrConfig) (*Certmgr, error) {
return nil, fmt.Errorf("the configuration of the certmgr provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -194,11 +199,27 @@ func (c *Certmgr) Replace(ctx context.Context, certIdOrName string, certPEM, pri
return &ReplaceResult{}, nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*acm.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*acm.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -0,0 +1,10 @@
package awsacm
import (
iam "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-iam"
)
const (
AUTH_METHOD_ACCESSKEY = iam.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = iam.AUTH_METHOD_IMDS
)
+26 -5
View File
@@ -11,6 +11,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/iam"
"github.com/aws/smithy-go"
"github.com/samber/lo"
@@ -26,6 +27,10 @@ type (
)
type CertmgrConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -50,7 +55,7 @@ func NewCertmgr(config *CertmgrConfig) (*Certmgr, error) {
return nil, fmt.Errorf("the configuration of the certmgr provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -187,11 +192,27 @@ func (c *Certmgr) Replace(ctx context.Context, certIdOrName string, certPEM, pri
return nil, core.ErrUnsupported
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*iam.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*iam.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -0,0 +1,6 @@
package awsiam
const (
AUTH_METHOD_ACCESSKEY = "accesskey"
AUTH_METHOD_IMDS = "imds"
)
@@ -15,6 +15,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -40,6 +44,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
}
pcertmgr, err := cmgrimpl.NewCertmgr(&cmgrimpl.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -0,0 +1,10 @@
package awsacm
import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimpl.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimpl.AUTH_METHOD_IMDS
)
+28 -5
View File
@@ -8,6 +8,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2"
"github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2/types"
@@ -22,6 +23,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -53,7 +58,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -62,6 +67,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
switch config.CertificateSource {
case CERTIFICATE_SOURCE_ACM:
pcertmgr, err = cmgrimplacm.NewCertmgr(&cmgrimplacm.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -72,6 +78,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
case CERTIFICATE_SOURCE_IAM:
pcertmgr, err = cmgrimpliam.NewCertmgr(&cmgrimpliam.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -220,11 +227,27 @@ func (d *Deployer) updateListenerSniCertificate(ctx context.Context, cloudListen
return nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*elasticloadbalancingv2.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*elasticloadbalancingv2.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -1,5 +1,14 @@
package awsalb
import (
cmgrimplacm "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimplacm.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimplacm.AUTH_METHOD_IMDS
)
const (
CERTIFICATE_SOURCE_ACM = "ACM"
CERTIFICATE_SOURCE_IAM = "IAM"
@@ -8,6 +8,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/amplify"
"github.com/aws/aws-sdk-go-v2/service/amplify/types"
@@ -21,6 +22,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -50,7 +55,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -59,6 +64,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
switch config.CertificateSource {
case CERTIFICATE_SOURCE_ACM:
pcertmgr, err = cmgrimplacm.NewCertmgr(&cmgrimplacm.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -124,11 +130,27 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return &DeployResult{}, nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*amplify.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*amplify.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -1,5 +1,14 @@
package awsamplify
import (
cmgrimplacm "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimplacm.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimplacm.AUTH_METHOD_IMDS
)
const (
CERTIFICATE_SOURCE_ACM = "ACM"
)
@@ -8,6 +8,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/apigatewayv2"
"github.com/aws/aws-sdk-go-v2/service/apigatewayv2/types"
@@ -21,6 +22,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -48,7 +53,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -57,6 +62,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
switch config.CertificateSource {
case CERTIFICATE_SOURCE_ACM:
pcertmgr, err = cmgrimplacm.NewCertmgr(&cmgrimplacm.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -119,11 +125,27 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return &DeployResult{}, nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*apigatewayv2.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*apigatewayv2.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -1,5 +1,14 @@
package awsapigateway
import (
cmgrimplacm "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimplacm.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimplacm.AUTH_METHOD_IMDS
)
const (
CERTIFICATE_SOURCE_ACM = "ACM"
)
+28 -5
View File
@@ -8,6 +8,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing"
"github.com/certimate-go/certimate/pkg/core"
@@ -21,6 +22,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -50,7 +55,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -59,6 +64,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
switch config.CertificateSource {
case CERTIFICATE_SOURCE_ACM:
pcertmgr, err = cmgrimplacm.NewCertmgr(&cmgrimplacm.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -69,6 +75,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
case CERTIFICATE_SOURCE_IAM:
pcertmgr, err = cmgrimpliam.NewCertmgr(&cmgrimpliam.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -132,11 +139,27 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return &DeployResult{}, nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*elasticloadbalancing.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*elasticloadbalancing.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -1,5 +1,14 @@
package awsclb
import (
cmgrimplacm "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimplacm.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimplacm.AUTH_METHOD_IMDS
)
const (
CERTIFICATE_SOURCE_ACM = "ACM"
CERTIFICATE_SOURCE_IAM = "IAM"
@@ -8,6 +8,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/cloudfront"
"github.com/aws/aws-sdk-go-v2/service/cloudfront/types"
@@ -22,6 +23,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -49,7 +54,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -58,6 +63,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
switch config.CertificateSource {
case CERTIFICATE_SOURCE_ACM:
pcertmgr, err = cmgrimplacm.NewCertmgr(&cmgrimplacm.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -68,6 +74,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
case CERTIFICATE_SOURCE_IAM:
pcertmgr, err = cmgrimpliam.NewCertmgr(&cmgrimpliam.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -158,11 +165,27 @@ func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*Dep
return &DeployResult{}, nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*cloudfront.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*cloudfront.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -1,5 +1,14 @@
package awscloudfront
import (
cmgrimplacm "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimplacm.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimplacm.AUTH_METHOD_IMDS
)
const (
CERTIFICATE_SOURCE_ACM = "ACM"
CERTIFICATE_SOURCE_IAM = "IAM"
@@ -15,6 +15,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -40,6 +44,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
}
pcertmgr, err := cmgrimpl.NewCertmgr(&cmgrimpl.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -0,0 +1,10 @@
package awsiam
import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-iam"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimpl.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimpl.AUTH_METHOD_IMDS
)
+28 -5
View File
@@ -8,6 +8,7 @@ import (
aws "github.com/aws/aws-sdk-go-v2/aws"
awscfg "github.com/aws/aws-sdk-go-v2/config"
awscred "github.com/aws/aws-sdk-go-v2/credentials"
"github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds"
"github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2"
"github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2/types"
@@ -22,6 +23,10 @@ type (
)
type DeployerConfig struct {
// AWS API 认证方式。
// 可取值 "accesskey"、"imds"。
// 零值时默认值 [AUTH_METHOD_ACCESSKEY]。
AuthMethod string `json:"authMethod,omitempty"`
// AWS AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// AWS SecretAccessKey。
@@ -53,7 +58,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
client, err := createSDKClient(config.AuthMethod, config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
@@ -62,6 +67,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
switch config.CertificateSource {
case CERTIFICATE_SOURCE_ACM:
pcertmgr, err = cmgrimplacm.NewCertmgr(&cmgrimplacm.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -72,6 +78,7 @@ func NewDeployer(config *DeployerConfig) (*Deployer, error) {
case CERTIFICATE_SOURCE_IAM:
pcertmgr, err = cmgrimpliam.NewCertmgr(&cmgrimpliam.CertmgrConfig{
AuthMethod: config.AuthMethod,
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
Region: config.Region,
@@ -220,11 +227,27 @@ func (d *Deployer) updateListenerSniCertificate(ctx context.Context, cloudListen
return nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*elasticloadbalancingv2.Client, error) {
cfg, err := awscfg.LoadDefaultConfig(context.Background(),
awscfg.WithCredentialsProvider(awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")),
func createSDKClient(authMethod, accessKeyId, secretAccessKey, region string) (*elasticloadbalancingv2.Client, error) {
opts := []func(options *awscfg.LoadOptions) error{
awscfg.WithRegion(region),
)
}
staticCredsProvider := awscred.NewStaticCredentialsProvider(accessKeyId, secretAccessKey, "")
imdsCredsProvider := aws.NewCredentialsCache(ec2rolecreds.New())
switch authMethod {
case "":
if accessKeyId != "" && secretAccessKey != "" {
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
}
case AUTH_METHOD_ACCESSKEY:
opts = append(opts, awscfg.WithCredentialsProvider(staticCredsProvider))
case AUTH_METHOD_IMDS:
opts = append(opts, awscfg.WithCredentialsProvider(imdsCredsProvider))
default:
return nil, fmt.Errorf("unsupported auth method '%s'", authMethod)
}
cfg, err := awscfg.LoadDefaultConfig(context.Background(), opts...)
if err != nil {
return nil, err
}
@@ -1,5 +1,14 @@
package awsnlb
import (
cmgrimplacm "github.com/certimate-go/certimate/pkg/core/certmgr/providers/aws-acm"
)
const (
AUTH_METHOD_ACCESSKEY = cmgrimplacm.AUTH_METHOD_ACCESSKEY
AUTH_METHOD_IMDS = cmgrimplacm.AUTH_METHOD_IMDS
)
const (
CERTIFICATE_SOURCE_ACM = "ACM"
CERTIFICATE_SOURCE_IAM = "IAM"
@@ -1,8 +1,12 @@
package nginxproxymanager
import (
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/nginxproxymanager"
)
const (
AUTH_METHOD_PASSWORD = "password"
AUTH_METHOD_TOKEN = "token"
AUTH_METHOD_PASSWORD = cmgrimpl.AUTH_METHOD_PASSWORD
AUTH_METHOD_TOKEN = cmgrimpl.AUTH_METHOD_TOKEN
)
const (
@@ -383,14 +383,16 @@ func createSDKClient(serverUrl, authMethod, username, password, apiToken string,
switch authMethod {
case "", AUTH_METHOD_PASSWORD:
{
client, err = npmsdk.NewClient(serverUrl,
client, err = npmsdk.NewClient(
serverUrl,
npmsdk.WithLogins(username, password),
)
}
case AUTH_METHOD_TOKEN:
{
client, err = npmsdk.NewClient(serverUrl,
client, err = npmsdk.NewClient(
serverUrl,
npmsdk.WithJwtToken(apiToken),
)
}