mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #10163 from ioito/hotfix/qx-role-sync-policy
fix(cloudid): sync role policy
This commit is contained in:
@@ -206,10 +206,16 @@ func (self *SCloudrole) GetICloudrole() (cloudprovider.ICloudrole, error) {
|
||||
|
||||
func (self *SCloudrole) GetCloudpolicies() ([]SCloudpolicy, error) {
|
||||
q := CloudpolicyManager.Query()
|
||||
samlUsers := SamluserManager.Query("cloudgroup_id").Equals("owner_id", self.OwnerId).Equals("cloudaccount_id", self.CloudaccountId).SubQuery()
|
||||
groups := CloudgroupManager.Query("id").In("id", samlUsers)
|
||||
gp := CloudgroupPolicyManager.Query("cloudpolicy_id").In("cloudgroup_id", groups).SubQuery()
|
||||
q = q.In("id", gp)
|
||||
var sq *sqlchemy.SSubQuery
|
||||
if len(self.OwnerId) > 0 {
|
||||
su := SamluserManager.Query("cloudgroup_id").Equals("owner_id", self.OwnerId).Equals("cloudaccount_id", self.CloudaccountId).SubQuery()
|
||||
sq = CloudgroupPolicyManager.Query("cloudpolicy_id").In("cloudgroup_id", su).SubQuery()
|
||||
} else if len(self.CloudgroupId) > 0 {
|
||||
sq = CloudgroupPolicyManager.Query("cloudpolicy_id").Equals("cloudgroup_id", self.CloudgroupId).SubQuery()
|
||||
} else {
|
||||
return nil, fmt.Errorf("empty owner id or cloudgroup id")
|
||||
}
|
||||
q = q.In("id", sq)
|
||||
policies := []SCloudpolicy{}
|
||||
err := db.FetchModelObjects(CloudpolicyManager, q, &policies)
|
||||
if err != nil {
|
||||
|
||||
@@ -15,6 +15,10 @@
|
||||
package shell
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"yunion.io/x/pkg/errors"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/cloudprovider"
|
||||
"yunion.io/x/onecloud/pkg/multicloud/aws"
|
||||
"yunion.io/x/onecloud/pkg/util/shellutils"
|
||||
@@ -52,6 +56,25 @@ func init() {
|
||||
return nil
|
||||
})
|
||||
|
||||
type RoleAttachPolicyListOptions struct {
|
||||
ROLE string
|
||||
Marker string
|
||||
MaxItems int
|
||||
PathPrefix string
|
||||
}
|
||||
|
||||
shellutils.R(&RoleAttachPolicyListOptions{}, "cloud-role-attach-policy-list", "List Role attach policy", func(cli *aws.SRegion, args *RoleAttachPolicyListOptions) error {
|
||||
policy, err := cli.GetClient().ListAttachedRolePolicies(args.ROLE, args.Marker, args.MaxItems, args.PathPrefix)
|
||||
if err != nil {
|
||||
return errors.Wrapf(err, "ListAttachedRolePolicies")
|
||||
}
|
||||
printList(policy.AttachedPolicies, 0, 0, 0, nil)
|
||||
if len(policy.Marker) > 0 {
|
||||
fmt.Println("marker: ", policy.Marker)
|
||||
}
|
||||
return nil
|
||||
})
|
||||
|
||||
shellutils.R(&RoleNameOptions{}, "cloud-role-delete", "Delete role", func(cli *aws.SRegion, args *RoleNameOptions) error {
|
||||
return cli.GetClient().DeleteRole(args.ROLE)
|
||||
})
|
||||
|
||||
Reference in New Issue
Block a user