From 04afc689e9621ca5543d69a2b8e39999f46abed9 Mon Sep 17 00:00:00 2001 From: Qu Xuan Date: Fri, 5 Feb 2021 12:18:08 +0800 Subject: [PATCH] fix(cloudid): sync role policy --- pkg/cloudid/models/cloudrole.go | 14 ++++++++++---- pkg/multicloud/aws/shell/iam_role.go | 23 +++++++++++++++++++++++ 2 files changed, 33 insertions(+), 4 deletions(-) diff --git a/pkg/cloudid/models/cloudrole.go b/pkg/cloudid/models/cloudrole.go index 74f717b7a9..fe97090491 100644 --- a/pkg/cloudid/models/cloudrole.go +++ b/pkg/cloudid/models/cloudrole.go @@ -206,10 +206,16 @@ func (self *SCloudrole) GetICloudrole() (cloudprovider.ICloudrole, error) { func (self *SCloudrole) GetCloudpolicies() ([]SCloudpolicy, error) { q := CloudpolicyManager.Query() - samlUsers := SamluserManager.Query("cloudgroup_id").Equals("owner_id", self.OwnerId).Equals("cloudaccount_id", self.CloudaccountId).SubQuery() - groups := CloudgroupManager.Query("id").In("id", samlUsers) - gp := CloudgroupPolicyManager.Query("cloudpolicy_id").In("cloudgroup_id", groups).SubQuery() - q = q.In("id", gp) + var sq *sqlchemy.SSubQuery + if len(self.OwnerId) > 0 { + su := SamluserManager.Query("cloudgroup_id").Equals("owner_id", self.OwnerId).Equals("cloudaccount_id", self.CloudaccountId).SubQuery() + sq = CloudgroupPolicyManager.Query("cloudpolicy_id").In("cloudgroup_id", su).SubQuery() + } else if len(self.CloudgroupId) > 0 { + sq = CloudgroupPolicyManager.Query("cloudpolicy_id").Equals("cloudgroup_id", self.CloudgroupId).SubQuery() + } else { + return nil, fmt.Errorf("empty owner id or cloudgroup id") + } + q = q.In("id", sq) policies := []SCloudpolicy{} err := db.FetchModelObjects(CloudpolicyManager, q, &policies) if err != nil { diff --git a/pkg/multicloud/aws/shell/iam_role.go b/pkg/multicloud/aws/shell/iam_role.go index a61d82f6b3..12e5455857 100644 --- a/pkg/multicloud/aws/shell/iam_role.go +++ b/pkg/multicloud/aws/shell/iam_role.go @@ -15,6 +15,10 @@ package shell import ( + "fmt" + + "yunion.io/x/pkg/errors" + "yunion.io/x/onecloud/pkg/cloudprovider" "yunion.io/x/onecloud/pkg/multicloud/aws" "yunion.io/x/onecloud/pkg/util/shellutils" @@ -52,6 +56,25 @@ func init() { return nil }) + type RoleAttachPolicyListOptions struct { + ROLE string + Marker string + MaxItems int + PathPrefix string + } + + shellutils.R(&RoleAttachPolicyListOptions{}, "cloud-role-attach-policy-list", "List Role attach policy", func(cli *aws.SRegion, args *RoleAttachPolicyListOptions) error { + policy, err := cli.GetClient().ListAttachedRolePolicies(args.ROLE, args.Marker, args.MaxItems, args.PathPrefix) + if err != nil { + return errors.Wrapf(err, "ListAttachedRolePolicies") + } + printList(policy.AttachedPolicies, 0, 0, 0, nil) + if len(policy.Marker) > 0 { + fmt.Println("marker: ", policy.Marker) + } + return nil + }) + shellutils.R(&RoleNameOptions{}, "cloud-role-delete", "Delete role", func(cli *aws.SRegion, args *RoleNameOptions) error { return cli.GetClient().DeleteRole(args.ROLE) })