mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #11021 from ioito/automated-cherry-pick-of-#11010-upstream-release-3.7
Automated cherry pick of #11010: fix(region): support project mapping
This commit is contained in:
@@ -99,6 +99,7 @@ func init() {
|
||||
cmd.Perform("change-owner", &options.ClouaccountChangeOwnerOptions{})
|
||||
cmd.Perform("change-project", &options.ClouaccountChangeProjectOptions{})
|
||||
cmd.Perform("create-subscription", &options.SubscriptionCreateOptions{})
|
||||
cmd.Perform("project-mapping", &options.ClouaccountProjectMappingOptions{})
|
||||
|
||||
cmd.Get("change-owner-candidate-domains", &options.SCloudAccountIdOptions{})
|
||||
cmd.Get("enrollment-accounts", &options.SCloudAccountIdOptions{})
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package compute
|
||||
|
||||
import (
|
||||
"yunion.io/x/onecloud/cmd/climc/shell"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/modules"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/options"
|
||||
"yunion.io/x/onecloud/pkg/mcclient/options/compute"
|
||||
)
|
||||
|
||||
func init() {
|
||||
cmd := shell.NewResourceCmd(&modules.ProjectMappings)
|
||||
cmd.List(&compute.ProjectMappingListOptions{})
|
||||
cmd.Update(&compute.ProjectMappingUpdateOption{})
|
||||
cmd.Delete(&options.BaseIdOptions{})
|
||||
cmd.Show(&options.BaseIdOptions{})
|
||||
cmd.Create(&compute.ProjectMappingCreateOption{})
|
||||
}
|
||||
@@ -100,7 +100,7 @@ func (cmd ResourceCmd) RunWithDesc(action, desc string, args interface{}, callba
|
||||
if ok {
|
||||
desc = descArgs.Description()
|
||||
}
|
||||
R(args, fmt.Sprintf("%s%s-%s", prefix, cmd.keyword, action), desc, callback)
|
||||
R(args, fmt.Sprintf("%s%s-%s", prefix, strings.ReplaceAll(cmd.keyword, "_", "-"), action), desc, callback)
|
||||
}
|
||||
|
||||
func (cmd ResourceCmd) Run(action string, args interface{}, callback interface{}) {
|
||||
|
||||
@@ -309,6 +309,8 @@ type CloudaccountDetail struct {
|
||||
StoragecacheCount int `json:"storagecache_count,allowempty"`
|
||||
|
||||
ProxySetting proxyapi.SProxySetting `json:"proxy_setting"`
|
||||
|
||||
ProjectMappingResourceInfo
|
||||
}
|
||||
|
||||
type CloudaccountUpdateInput struct {
|
||||
@@ -475,3 +477,7 @@ type CloudaccountEnableAutoSyncInput struct {
|
||||
// 最小值为region服务的minimal_sync_interval_seconds
|
||||
SyncIntervalSeconds int `json:"sync_interval_seconds"`
|
||||
}
|
||||
|
||||
type CloudaccountProjectMappingInput struct {
|
||||
ProjectMappingId string
|
||||
}
|
||||
|
||||
@@ -0,0 +1,184 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package compute
|
||||
|
||||
import (
|
||||
"reflect"
|
||||
"strings"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/gotypes"
|
||||
"yunion.io/x/pkg/utils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
)
|
||||
|
||||
const (
|
||||
PROJECT_MAPPING_STATUS_AVAILABLE = "available"
|
||||
|
||||
MAPPING_CONDITION_AND = "and"
|
||||
MAPPING_CONDITION_OR = "or"
|
||||
)
|
||||
|
||||
type STag struct {
|
||||
Key string
|
||||
Value string
|
||||
}
|
||||
|
||||
type ProjectMappingRuleInfo struct {
|
||||
// 标签列表, 不可为空
|
||||
Tags []STag
|
||||
// 条件表达式
|
||||
// enmu: and, or
|
||||
// default: and
|
||||
Condition string
|
||||
// 是否自动根据标签值创建项目, 仅标签列表中有且仅有一个没有value的key时支持
|
||||
AutoCreateProject bool
|
||||
// 符合条件时,资源放置的项目id, 此参数和auto_create_project互斥
|
||||
ProjectId string
|
||||
// swagger:ignore
|
||||
DomainId string
|
||||
}
|
||||
|
||||
type MappingRules []ProjectMappingRuleInfo
|
||||
|
||||
func (rule *ProjectMappingRuleInfo) Validate() error {
|
||||
if len(rule.Tags) == 0 {
|
||||
return httperrors.NewInputParameterError("missing tags")
|
||||
}
|
||||
if len(rule.Condition) == 0 {
|
||||
rule.Condition = MAPPING_CONDITION_AND
|
||||
}
|
||||
if !utils.IsInStringArray(rule.Condition, []string{MAPPING_CONDITION_AND, MAPPING_CONDITION_OR}) {
|
||||
return httperrors.NewInputParameterError("invalid condition")
|
||||
}
|
||||
emptyValueTags := 0
|
||||
for _, tag := range rule.Tags {
|
||||
if len(tag.Key) == 0 {
|
||||
return httperrors.NewInputParameterError("missing tag key for")
|
||||
}
|
||||
if len(tag.Value) == 0 {
|
||||
emptyValueTags++
|
||||
}
|
||||
}
|
||||
if emptyValueTags != 1 && rule.AutoCreateProject {
|
||||
return httperrors.NewInputParameterError("not support auto_create_project")
|
||||
}
|
||||
if !rule.AutoCreateProject && len(rule.ProjectId) == 0 {
|
||||
return httperrors.NewInputParameterError("missing project_id")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// return domainId, projectId, newProj, isMatch
|
||||
func (self *ProjectMappingRuleInfo) IsMatchTags(_extTags map[string]string) (string, string, string, bool) {
|
||||
newProj := ""
|
||||
extTags := map[string]string{}
|
||||
for k, v := range _extTags {
|
||||
extTags[strings.ToUpper(k)] = v
|
||||
}
|
||||
switch self.Condition {
|
||||
case MAPPING_CONDITION_AND:
|
||||
for _, tag := range self.Tags {
|
||||
extTag, ok := extTags[strings.ToUpper(tag.Key)]
|
||||
if !ok || (len(tag.Value) > 0 && tag.Value != extTag) {
|
||||
return "", "", "", false
|
||||
}
|
||||
if self.AutoCreateProject && len(tag.Value) == 0 && len(extTag) > 0 {
|
||||
newProj = extTag
|
||||
}
|
||||
}
|
||||
return self.DomainId, self.ProjectId, newProj, true
|
||||
case MAPPING_CONDITION_OR:
|
||||
for _, tag := range self.Tags {
|
||||
extTag, ok := extTags[strings.ToUpper(tag.Key)]
|
||||
if ok && len(tag.Value) == 0 || tag.Value == extTag {
|
||||
if self.AutoCreateProject && len(tag.Value) == 0 && len(extTag) > 0 {
|
||||
return "", "", extTag, true
|
||||
} else {
|
||||
return self.DomainId, self.ProjectId, "", true
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return "", "", "", false
|
||||
}
|
||||
|
||||
func (rules MappingRules) Validate() error {
|
||||
for i := range rules {
|
||||
err := rules[i].Validate()
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type ProjectMappingRuleInfoDetails struct {
|
||||
ProjectMappingRuleInfo
|
||||
Project string
|
||||
TenantId string
|
||||
Tenant string
|
||||
Domain string
|
||||
}
|
||||
|
||||
type ProjectMappingDetails struct {
|
||||
apis.EnabledStatusInfrasResourceBaseDetails
|
||||
|
||||
Rules []ProjectMappingRuleInfoDetails
|
||||
}
|
||||
|
||||
type ProjectMappingCreateInput struct {
|
||||
apis.EnabledStatusInfrasResourceBaseCreateInput
|
||||
|
||||
Rules MappingRules
|
||||
}
|
||||
|
||||
type ProjectMappingListInput struct {
|
||||
apis.EnabledStatusInfrasResourceBaseListInput
|
||||
}
|
||||
|
||||
type ProjectMappingResourceInfo struct {
|
||||
ProjectMapping string
|
||||
}
|
||||
|
||||
type ProjectMappingUpdateInput struct {
|
||||
apis.EnabledStatusInfrasResourceBaseUpdateInput
|
||||
|
||||
Rules MappingRules
|
||||
}
|
||||
|
||||
type ProjectMappingFilterListInput struct {
|
||||
ProjectMappingId string `json:"project_mapping_id"`
|
||||
OrderByProjectMapping string
|
||||
}
|
||||
|
||||
func (self MappingRules) String() string {
|
||||
return jsonutils.Marshal(self).String()
|
||||
}
|
||||
|
||||
func (self MappingRules) IsZero() bool {
|
||||
if len(self) == 0 {
|
||||
return true
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func init() {
|
||||
gotypes.RegisterSerializable(reflect.TypeOf(&MappingRules{}), func() gotypes.ISerializable {
|
||||
return &MappingRules{}
|
||||
})
|
||||
}
|
||||
@@ -117,6 +117,18 @@ type EnabledBaseResourceCreateInput struct {
|
||||
Disabled *bool `json:"disabled" help:"turn off enabled flag"`
|
||||
}
|
||||
|
||||
func (self *EnabledBaseResourceCreateInput) SetEnabled() {
|
||||
enabled := true
|
||||
self.Enabled = &enabled
|
||||
self.Disabled = nil
|
||||
}
|
||||
|
||||
func (self *EnabledBaseResourceCreateInput) SetDisabled() {
|
||||
disabled := true
|
||||
self.Disabled = &disabled
|
||||
self.Enabled = nil
|
||||
}
|
||||
|
||||
func (input *EnabledBaseResourceCreateInput) AfterUnmarshal() {
|
||||
if input.Disabled != nil && input.Enabled == nil {
|
||||
enabled := !(*input.Disabled)
|
||||
|
||||
@@ -56,6 +56,7 @@ import (
|
||||
|
||||
type SCloudaccountManager struct {
|
||||
db.SEnabledStatusInfrasResourceBaseManager
|
||||
SProjectMappingResourceBaseManager
|
||||
SSyncableBaseResourceManager
|
||||
}
|
||||
|
||||
@@ -162,6 +163,8 @@ type SCloudaccount struct {
|
||||
|
||||
SAMLAuth tristate.TriState `nullable:"false" get:"user" update:"domain" create:"optional" list:"user" default:"false"`
|
||||
vmwareHostWireCache map[string][]SVs2Wire
|
||||
|
||||
SProjectMappingResourceBase
|
||||
}
|
||||
|
||||
func (self *SCloudaccount) GetCloudproviders() []SCloudprovider {
|
||||
@@ -1202,6 +1205,7 @@ func (manager *SCloudaccountManager) FetchCustomizeColumns(
|
||||
) []api.CloudaccountDetail {
|
||||
rows := make([]api.CloudaccountDetail, len(objs))
|
||||
stdRows := manager.SEnabledStatusInfrasResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
|
||||
pmRows := manager.SProjectMappingResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
|
||||
|
||||
proxySettings := make(map[string]proxy.SProxySetting)
|
||||
{
|
||||
@@ -1226,6 +1230,7 @@ func (manager *SCloudaccountManager) FetchCustomizeColumns(
|
||||
account := objs[i].(*SCloudaccount)
|
||||
detail := api.CloudaccountDetail{
|
||||
EnabledStatusInfrasResourceBaseDetails: stdRows[i],
|
||||
ProjectMappingResourceInfo: pmRows[i],
|
||||
}
|
||||
if proxySetting, ok := proxySettings[account.ProxySettingId]; ok {
|
||||
detail.ProxySetting.Id = proxySetting.Id
|
||||
@@ -2853,3 +2858,28 @@ func (cd *SCloudaccount) GetHost2Wire(ctx context.Context, userCred mcclient.Tok
|
||||
cd.vmwareHostWireCache = ret
|
||||
return cd.vmwareHostWireCache, nil
|
||||
}
|
||||
|
||||
func (self *SCloudaccount) AllowPerformProjectMapping(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject) bool {
|
||||
return self.IsOwner(userCred) || db.IsAdminAllowPerform(userCred, self, "project-mapping")
|
||||
}
|
||||
|
||||
func (self *SCloudaccount) PerformProjectMapping(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, input api.CloudaccountProjectMappingInput) (jsonutils.JSONObject, error) {
|
||||
if len(input.ProjectMappingId) > 0 {
|
||||
_, err := validators.ValidateModel(userCred, ProjectMappingManager, &input.ProjectMappingId)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
// no changes
|
||||
if self.ProjectMappingId == input.ProjectMappingId {
|
||||
return nil, nil
|
||||
}
|
||||
_, err := db.Update(self, func() error {
|
||||
self.ProjectMappingId = input.ProjectMappingId
|
||||
return nil
|
||||
})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return nil, refreshMapping()
|
||||
}
|
||||
|
||||
@@ -110,6 +110,49 @@ type SCloudprovider struct {
|
||||
Provider string `width:"64" charset:"ascii" list:"domain" create:"domain_required"`
|
||||
}
|
||||
|
||||
type providerMapping struct {
|
||||
Id string
|
||||
CloudaccountId string
|
||||
ProjectMappingId string
|
||||
}
|
||||
|
||||
var providerProjectMapping map[string]*providerMapping = map[string]*providerMapping{}
|
||||
|
||||
func refreshMapping() error {
|
||||
q := CloudproviderManager.Query("cloudaccount_id", "id")
|
||||
sq := CloudaccountManager.Query().SubQuery()
|
||||
q = q.LeftJoin(sq, sqlchemy.Equals(q.Field("cloudaccount_id"), sq.Field("id"))).AppendField(sq.Field("project_mapping_id"))
|
||||
pms := []providerMapping{}
|
||||
err := q.All(&pms)
|
||||
if err != nil {
|
||||
return errors.Wrapf(err, "q.All")
|
||||
}
|
||||
for i := range pms {
|
||||
providerProjectMapping[pms[i].Id] = &pms[i]
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (self *providerMapping) GetCloudaccount() (*SCloudaccount, error) {
|
||||
account, err := CloudaccountManager.FetchById(self.CloudaccountId)
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "FetchById(%s)", self.CloudaccountId)
|
||||
}
|
||||
return account.(*SCloudaccount), nil
|
||||
}
|
||||
|
||||
func GetProviderMapping(id string) (*providerMapping, error) {
|
||||
mp, ok := providerProjectMapping[id]
|
||||
if ok {
|
||||
return mp, nil
|
||||
}
|
||||
err := refreshMapping()
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return providerProjectMapping[id], nil
|
||||
}
|
||||
|
||||
func (self *SCloudprovider) ValidateDeleteCondition(ctx context.Context) error {
|
||||
// allow delete cloudprovider if it is disabled
|
||||
// account := self.GetCloudaccount()
|
||||
|
||||
@@ -1405,8 +1405,50 @@ func (manager *SCloudproviderregionManager) initAllRecords() {
|
||||
}
|
||||
|
||||
func SyncCloudProject(userCred mcclient.TokenCredential, model db.IVirtualModel, syncOwnerId mcclient.IIdentityProvider, extModel cloudprovider.IVirtualResource, managerId string) {
|
||||
var newOwnerId mcclient.IIdentityProvider
|
||||
if extProjectId := extModel.GetProjectId(); len(extProjectId) > 0 {
|
||||
newOwnerId, err := func() (mcclient.IIdentityProvider, error) {
|
||||
pm, err := GetProviderMapping(managerId)
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "GetProviderMapping")
|
||||
}
|
||||
if len(pm.ProjectMappingId) == 0 {
|
||||
return nil, nil
|
||||
}
|
||||
account, err := pm.GetCloudaccount()
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "GetCloudaccount")
|
||||
}
|
||||
rm, err := GetRuleMapping(pm.ProjectMappingId)
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "GetRuleMapping")
|
||||
}
|
||||
if rm != nil && rm.Enabled.Bool() {
|
||||
extTags, err := extModel.GetTags()
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "extModel.GetTags")
|
||||
}
|
||||
if rm.Rules != nil {
|
||||
for _, rule := range *rm.Rules {
|
||||
domainId, projectId, newProj, isMatch := rule.IsMatchTags(extTags)
|
||||
if isMatch {
|
||||
if len(newProj) > 0 {
|
||||
domainId, projectId, err = account.getOrCreateTenant(context.TODO(), newProj, "", "auto create from tag")
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "getOrCreateTenant(%s)", newProj)
|
||||
}
|
||||
}
|
||||
if len(domainId) > 0 && len(projectId) > 0 {
|
||||
return &db.SOwnerId{DomainId: domainId, ProjectId: projectId}, nil
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return nil, nil
|
||||
}()
|
||||
if err != nil {
|
||||
log.Errorf("try sync project for %s %s by tags error: %v", model.Keyword(), model.GetName(), err)
|
||||
}
|
||||
if extProjectId := extModel.GetProjectId(); len(extProjectId) > 0 && newOwnerId == nil {
|
||||
extProject, err := ExternalProjectManager.GetProject(extProjectId, managerId)
|
||||
if err != nil {
|
||||
log.Errorf("sync project for %s %s error: %v", model.Keyword(), model.GetName(), err)
|
||||
|
||||
@@ -0,0 +1,163 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package models
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/log"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/reflectutils"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
api "yunion.io/x/onecloud/pkg/apis/compute"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/validators"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
type SProjectMappingResourceBase struct {
|
||||
ProjectMappingId string `width:"36" charset:"ascii" nullable:"false" create:"required" index:"true" list:"user" json:"project_mapping_id"`
|
||||
}
|
||||
|
||||
type SProjectMappingResourceBaseManager struct{}
|
||||
|
||||
func (self *SProjectMappingResourceBase) GetProjectMapping() (*SProjectMapping, error) {
|
||||
pm, err := ProjectMappingManager.FetchById(self.ProjectMappingId)
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "FetchById")
|
||||
}
|
||||
return pm.(*SProjectMapping), nil
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) FetchCustomizeColumns(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
objs []interface{},
|
||||
fields stringutils2.SSortedStrings,
|
||||
isList bool,
|
||||
) []api.ProjectMappingResourceInfo {
|
||||
rows := make([]api.ProjectMappingResourceInfo, len(objs))
|
||||
pmIds := make([]string, len(objs))
|
||||
for i := range objs {
|
||||
var base *SProjectMappingResourceBase
|
||||
err := reflectutils.FindAnonymouStructPointer(objs[i], &base)
|
||||
if err != nil {
|
||||
log.Errorf("Cannot find SProjectMappingResourceBase in object %s", objs[i])
|
||||
continue
|
||||
}
|
||||
pmIds[i] = base.ProjectMappingId
|
||||
}
|
||||
pmNames, err := db.FetchIdNameMap2(ProjectMappingManager, pmIds)
|
||||
if err != nil {
|
||||
log.Errorf("FetchIdNameMap2 fail %s", err)
|
||||
return rows
|
||||
}
|
||||
for i := range rows {
|
||||
if name, ok := pmNames[pmIds[i]]; ok {
|
||||
rows[i].ProjectMapping = name
|
||||
}
|
||||
}
|
||||
return rows
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) ListItemFilter(
|
||||
ctx context.Context,
|
||||
q *sqlchemy.SQuery,
|
||||
userCred mcclient.TokenCredential,
|
||||
query api.ProjectMappingFilterListInput,
|
||||
) (*sqlchemy.SQuery, error) {
|
||||
if len(query.ProjectMappingId) > 0 {
|
||||
_, err := validators.ValidateModel(userCred, ProjectMappingManager, &query.ProjectMappingId)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
q = q.Equals("project_mapping_id", query.ProjectMappingId)
|
||||
}
|
||||
return q, nil
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) OrderByExtraFields(
|
||||
ctx context.Context,
|
||||
q *sqlchemy.SQuery,
|
||||
userCred mcclient.TokenCredential,
|
||||
query api.ProjectMappingFilterListInput,
|
||||
) (*sqlchemy.SQuery, error) {
|
||||
if !db.NeedOrderQuery(manager.GetOrderByFields(query)) {
|
||||
return q, nil
|
||||
}
|
||||
orderQ := ProjectMappingManager.Query("id")
|
||||
orderSubQ := orderQ.SubQuery()
|
||||
orderQ, orders, fields := manager.GetOrderBySubQuery(orderQ, orderSubQ, orderQ.Field("id"), userCred, query, nil, nil)
|
||||
q = q.LeftJoin(orderSubQ, sqlchemy.Equals(q.Field("project_mapping_id"), orderSubQ.Field("id")))
|
||||
q = db.OrderByFields(q, orders, fields)
|
||||
return q, nil
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error) {
|
||||
if field == "project_mapping" {
|
||||
mpQuery := ProjectMappingManager.Query("name", "id").Distinct().SubQuery()
|
||||
q.AppendField(mpQuery.Field("name", field))
|
||||
q = q.Join(mpQuery, sqlchemy.Equals(q.Field("project_mapping_id"), mpQuery.Field("id")))
|
||||
q.GroupBy(mpQuery.Field("name"))
|
||||
return q, nil
|
||||
}
|
||||
return q, httperrors.ErrNotFound
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) GetOrderBySubQuery(
|
||||
q *sqlchemy.SQuery,
|
||||
subq *sqlchemy.SSubQuery,
|
||||
joinField sqlchemy.IQueryField,
|
||||
userCred mcclient.TokenCredential,
|
||||
query api.ProjectMappingFilterListInput,
|
||||
orders []string,
|
||||
fields []sqlchemy.IQueryField,
|
||||
) (*sqlchemy.SQuery, []string, []sqlchemy.IQueryField) {
|
||||
if !db.NeedOrderQuery(manager.GetOrderByFields(query)) {
|
||||
return q, orders, fields
|
||||
}
|
||||
mpQ := ProjectMappingManager.Query().SubQuery()
|
||||
q = q.LeftJoin(mpQ, sqlchemy.Equals(joinField, mpQ.Field("id")))
|
||||
q = q.AppendField(mpQ.Field("name").Label("project_mapping"))
|
||||
orders = append(orders, query.OrderByProjectMapping)
|
||||
fields = append(fields, subq.Field("project_mapping"))
|
||||
return q, orders, fields
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) GetOrderByFields(query api.ProjectMappingFilterListInput) []string {
|
||||
return []string{query.OrderByProjectMapping}
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) ListItemExportKeys(ctx context.Context,
|
||||
q *sqlchemy.SQuery,
|
||||
userCred mcclient.TokenCredential,
|
||||
keys stringutils2.SSortedStrings,
|
||||
) (*sqlchemy.SQuery, error) {
|
||||
if keys.ContainsAny(manager.GetExportKeys()...) {
|
||||
subq := ProjectMappingManager.Query("id", "name").SubQuery()
|
||||
q = q.LeftJoin(subq, sqlchemy.Equals(q.Field("project_mapping_id"), subq.Field("id")))
|
||||
q = q.AppendField(subq.Field("name", "project_mapping"))
|
||||
}
|
||||
return q, nil
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingResourceBaseManager) GetExportKeys() []string {
|
||||
return []string{"project_mapping"}
|
||||
}
|
||||
@@ -0,0 +1,285 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package models
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/sqlchemy"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/apis"
|
||||
api "yunion.io/x/onecloud/pkg/apis/compute"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon/db"
|
||||
"yunion.io/x/onecloud/pkg/httperrors"
|
||||
"yunion.io/x/onecloud/pkg/mcclient"
|
||||
"yunion.io/x/onecloud/pkg/util/stringutils2"
|
||||
)
|
||||
|
||||
type SProjectMappingManager struct {
|
||||
db.SEnabledStatusInfrasResourceBaseManager
|
||||
}
|
||||
|
||||
var ProjectMappingManager *SProjectMappingManager
|
||||
|
||||
var projectRuleMapping map[string]*SProjectMapping = map[string]*SProjectMapping{}
|
||||
|
||||
func init() {
|
||||
ProjectMappingManager = &SProjectMappingManager{
|
||||
SEnabledStatusInfrasResourceBaseManager: db.NewEnabledStatusInfrasResourceBaseManager(
|
||||
SProjectMapping{},
|
||||
"project_mappings_tbl",
|
||||
"project_mapping",
|
||||
"project_mappings",
|
||||
),
|
||||
}
|
||||
ProjectMappingManager.SetVirtualObject(ProjectMappingManager)
|
||||
}
|
||||
|
||||
func GetRuleMapping(id string) (*SProjectMapping, error) {
|
||||
rm, ok := projectRuleMapping[id]
|
||||
if ok {
|
||||
return rm, nil
|
||||
}
|
||||
pm, err := ProjectMappingManager.FetchById(id)
|
||||
if err != nil {
|
||||
return nil, errors.Wrapf(err, "ProjectMappingManager.FetchById(%s)", id)
|
||||
}
|
||||
projectMap := pm.(*SProjectMapping)
|
||||
projectRuleMapping[id] = projectMap
|
||||
return projectMap, nil
|
||||
}
|
||||
|
||||
type SProjectMapping struct {
|
||||
db.SEnabledStatusInfrasResourceBase
|
||||
|
||||
Rules *api.MappingRules `list:"domain" update:"domain" create:"required"`
|
||||
}
|
||||
|
||||
// 列出项目映射表
|
||||
func (manager *SProjectMappingManager) ListItemFilter(
|
||||
ctx context.Context,
|
||||
q *sqlchemy.SQuery,
|
||||
userCred mcclient.TokenCredential,
|
||||
query api.ProjectMappingListInput,
|
||||
) (*sqlchemy.SQuery, error) {
|
||||
var err error
|
||||
|
||||
q, err = manager.SEnabledStatusInfrasResourceBaseManager.ListItemFilter(ctx, q, userCred, query.EnabledStatusInfrasResourceBaseListInput)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "SEnabledStatusInfrasResourceBaseManager.ListItemFilter")
|
||||
}
|
||||
return q, nil
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingManager) ValidateCreateData(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
ownerId mcclient.IIdentityProvider,
|
||||
query jsonutils.JSONObject,
|
||||
input api.ProjectMappingCreateInput,
|
||||
) (api.ProjectMappingCreateInput, error) {
|
||||
err := input.Rules.Validate()
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
var tenant *db.STenant
|
||||
for i := range input.Rules {
|
||||
if len(input.Rules[i].ProjectId) > 0 {
|
||||
projectInput := apis.ProjectizedResourceInput{ProjectId: input.Rules[i].ProjectId}
|
||||
tenant, projectInput, err = db.ValidateProjectizedResourceInput(ctx, projectInput)
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
input.Rules[i].DomainId = tenant.DomainId
|
||||
}
|
||||
}
|
||||
input.SetEnabled()
|
||||
input.Status = api.PROJECT_MAPPING_STATUS_AVAILABLE
|
||||
input.EnabledStatusInfrasResourceBaseCreateInput, err = manager.SEnabledStatusInfrasResourceBaseManager.ValidateCreateData(ctx, userCred, ownerId, query, input.EnabledStatusInfrasResourceBaseCreateInput)
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
return input, nil
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) PostCreate(ctx context.Context, userCred mcclient.TokenCredential, ownerId mcclient.IIdentityProvider, query jsonutils.JSONObject, data jsonutils.JSONObject) {
|
||||
self.SEnabledStatusInfrasResourceBase.PostCreate(ctx, userCred, ownerId, query, data)
|
||||
self.refreshMapping()
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingManager) FetchCustomizeColumns(
|
||||
ctx context.Context,
|
||||
userCred mcclient.TokenCredential,
|
||||
query jsonutils.JSONObject,
|
||||
objs []interface{},
|
||||
fields stringutils2.SSortedStrings,
|
||||
isList bool,
|
||||
) []api.ProjectMappingDetails {
|
||||
rows := make([]api.ProjectMappingDetails, len(objs))
|
||||
stdRows := manager.SEnabledStatusInfrasResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
|
||||
mpIds := make([]string, len(objs))
|
||||
projIds := []string{}
|
||||
domainIds := []string{}
|
||||
for i := range rows {
|
||||
rows[i] = api.ProjectMappingDetails{
|
||||
EnabledStatusInfrasResourceBaseDetails: stdRows[i],
|
||||
}
|
||||
mp := objs[i].(*SProjectMapping)
|
||||
mpIds[i] = mp.Id
|
||||
if mp.Rules != nil {
|
||||
for _, r := range *mp.Rules {
|
||||
if len(r.ProjectId) > 0 {
|
||||
projIds = append(projIds, r.ProjectId)
|
||||
domainIds = append(domainIds, r.DomainId)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
q := db.DefaultDomainQuery("domain", "domain_id").In("domain_id", domainIds)
|
||||
domains := []struct {
|
||||
DomainId string
|
||||
Domain string
|
||||
}{}
|
||||
err := q.All(&domainIds)
|
||||
if err != nil {
|
||||
return rows
|
||||
}
|
||||
domainMaps := map[string]string{}
|
||||
for _, domain := range domains {
|
||||
domainMaps[domain.DomainId] = domain.Domain
|
||||
}
|
||||
q = db.DefaultProjectQuery("id", "name").In("id", projIds)
|
||||
projects := []struct {
|
||||
Id string
|
||||
Name string
|
||||
}{}
|
||||
err = q.All(&projects)
|
||||
if err != nil {
|
||||
return rows
|
||||
}
|
||||
projectMaps := map[string]string{}
|
||||
for _, proj := range projects {
|
||||
projectMaps[proj.Id] = proj.Name
|
||||
}
|
||||
for i := range rows {
|
||||
mp := objs[i].(*SProjectMapping)
|
||||
if mp.Rules != nil {
|
||||
rows[i].Rules = []api.ProjectMappingRuleInfoDetails{}
|
||||
for i := range *mp.Rules {
|
||||
rules := *mp.Rules
|
||||
rule := api.ProjectMappingRuleInfoDetails{
|
||||
ProjectMappingRuleInfo: rules[i],
|
||||
}
|
||||
rule.Tenant, _ = projectMaps[rules[i].ProjectId]
|
||||
rule.Project = rule.Tenant
|
||||
rule.Domain, _ = domainMaps[rules[i].DomainId]
|
||||
rows[i].Rules = append(rows[i].Rules, rule)
|
||||
}
|
||||
}
|
||||
}
|
||||
return rows
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingManager) QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error) {
|
||||
var err error
|
||||
q, err = manager.SEnabledStatusInfrasResourceBaseManager.QueryDistinctExtraField(q, field)
|
||||
if err == nil {
|
||||
return q, nil
|
||||
}
|
||||
return q, httperrors.ErrNotFound
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingManager) OrderByExtraFields(
|
||||
ctx context.Context,
|
||||
q *sqlchemy.SQuery,
|
||||
userCred mcclient.TokenCredential,
|
||||
query api.ProjectMappingListInput,
|
||||
) (*sqlchemy.SQuery, error) {
|
||||
q, err := manager.SEnabledStatusInfrasResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.EnabledStatusInfrasResourceBaseListInput)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "SEnabledStatusInfrasResourceBaseManager.OrderByExtraFields")
|
||||
}
|
||||
return q, nil
|
||||
}
|
||||
|
||||
func (manager *SProjectMappingManager) ListItemExportKeys(ctx context.Context,
|
||||
q *sqlchemy.SQuery,
|
||||
userCred mcclient.TokenCredential,
|
||||
keys stringutils2.SSortedStrings,
|
||||
) (*sqlchemy.SQuery, error) {
|
||||
q, err := manager.SEnabledStatusInfrasResourceBaseManager.ListItemExportKeys(ctx, q, userCred, keys)
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "SEnabledStatusInfrasResourceBaseManager.ListItemExportKeys")
|
||||
}
|
||||
return q, nil
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) ValidateUpdateData(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, input api.ProjectMappingUpdateInput) (api.ProjectMappingUpdateInput, error) {
|
||||
err := input.Rules.Validate()
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
var tenant *db.STenant
|
||||
for i := range input.Rules {
|
||||
if len(input.Rules[i].ProjectId) > 0 {
|
||||
projectInput := apis.ProjectizedResourceInput{ProjectId: input.Rules[i].ProjectId}
|
||||
tenant, projectInput, err = db.ValidateProjectizedResourceInput(ctx, projectInput)
|
||||
if err != nil {
|
||||
return input, err
|
||||
}
|
||||
input.Rules[i].DomainId = tenant.DomainId
|
||||
}
|
||||
}
|
||||
input.EnabledStatusInfrasResourceBaseUpdateInput, err = self.SEnabledStatusInfrasResourceBase.ValidateUpdateData(ctx, userCred, query, input.EnabledStatusInfrasResourceBaseUpdateInput)
|
||||
return input, err
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) GetCloudaccounts() ([]SCloudaccount, error) {
|
||||
q := CloudaccountManager.Query().Equals("project_mapping_id", self.Id)
|
||||
accounts := []SCloudaccount{}
|
||||
err := db.FetchModelObjects(CloudaccountManager, q, &accounts)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return accounts, nil
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) Delete(ctx context.Context, userCred mcclient.TokenCredential) error {
|
||||
delete(projectRuleMapping, self.Id)
|
||||
return self.SEnabledStatusInfrasResourceBase.Delete(ctx, userCred)
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) ValidateDeleteCondition(ctx context.Context) error {
|
||||
accounts, err := self.GetCloudaccounts()
|
||||
if err != nil {
|
||||
return errors.Wrapf(err, "GetCloudaccounts")
|
||||
}
|
||||
if len(accounts) > 0 {
|
||||
return httperrors.NewNotEmptyError("project mapping has associate %d accounts", len(accounts))
|
||||
}
|
||||
return self.SEnabledStatusInfrasResourceBase.ValidateDeleteCondition(ctx)
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) PostUpdate(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, data jsonutils.JSONObject) {
|
||||
self.SEnabledStatusInfrasResourceBase.PostUpdate(ctx, userCred, query, data)
|
||||
self.refreshMapping()
|
||||
}
|
||||
|
||||
func (self *SProjectMapping) refreshMapping() error {
|
||||
projectRuleMapping[self.Id] = self
|
||||
return nil
|
||||
}
|
||||
@@ -212,6 +212,8 @@ func InitHandlers(app *appsrv.Application) {
|
||||
models.AccessGroupRuleManager,
|
||||
models.AccessGroupCacheManager,
|
||||
models.MountTargetManager,
|
||||
|
||||
models.ProjectMappingManager,
|
||||
} {
|
||||
db.RegisterModelManager(manager)
|
||||
handler := db.NewModelHandler(manager)
|
||||
|
||||
@@ -0,0 +1,29 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package modules
|
||||
|
||||
import "yunion.io/x/onecloud/pkg/mcclient/modulebase"
|
||||
|
||||
var (
|
||||
ProjectMappings modulebase.ResourceManager
|
||||
)
|
||||
|
||||
func init() {
|
||||
ProjectMappings = NewComputeManager("project_mapping", "project_mappings",
|
||||
[]string{"ID", "Name", "Enabled", "Status", "Public_Scope", "Domain_Id", "Domain", "Rules", "Metadata"},
|
||||
[]string{})
|
||||
|
||||
registerCompute(&ProjectMappings)
|
||||
}
|
||||
@@ -909,3 +909,12 @@ func (opts *SubscriptionCreateOptions) Params() (jsonutils.JSONObject, error) {
|
||||
"enrollment_account_id": opts.ENROLLMENTACCOUNT,
|
||||
}), nil
|
||||
}
|
||||
|
||||
type ClouaccountProjectMappingOptions struct {
|
||||
SCloudAccountIdOptions
|
||||
ProjectMappingId string `json:"project_mapping_id" help:"project mapping id"`
|
||||
}
|
||||
|
||||
func (opts *ClouaccountProjectMappingOptions) Params() (jsonutils.JSONObject, error) {
|
||||
return jsonutils.Marshal(map[string]string{"project_mapping_id": opts.ProjectMappingId}), nil
|
||||
}
|
||||
|
||||
@@ -0,0 +1,73 @@
|
||||
// Copyright 2019 Yunion
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package compute
|
||||
|
||||
import (
|
||||
"io/ioutil"
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
|
||||
"yunion.io/x/onecloud/pkg/mcclient/options"
|
||||
)
|
||||
|
||||
type ProjectMappingListOptions struct {
|
||||
options.BaseListOptions
|
||||
}
|
||||
|
||||
func (opts *ProjectMappingListOptions) Params() (jsonutils.JSONObject, error) {
|
||||
return options.ListStructToParams(opts)
|
||||
}
|
||||
|
||||
type ProjectMappingCreateOption struct {
|
||||
options.BaseCreateOptions
|
||||
RULES_FILE string
|
||||
}
|
||||
|
||||
func (opts *ProjectMappingCreateOption) Params() (jsonutils.JSONObject, error) {
|
||||
ret := jsonutils.NewDict()
|
||||
ret.Update(jsonutils.Marshal(opts.BaseCreateOptions))
|
||||
data, err := ioutil.ReadFile(opts.RULES_FILE)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
rules, err := jsonutils.Parse(data)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
ret.Add(rules, "rules")
|
||||
return ret, nil
|
||||
}
|
||||
|
||||
type ProjectMappingUpdateOption struct {
|
||||
options.BaseUpdateOptions
|
||||
RulesFile string
|
||||
}
|
||||
|
||||
func (opts *ProjectMappingUpdateOption) Params() (jsonutils.JSONObject, error) {
|
||||
ret := jsonutils.NewDict()
|
||||
ret.Update(jsonutils.Marshal(opts.BaseUpdateOptions))
|
||||
if len(opts.RulesFile) > 0 {
|
||||
data, err := ioutil.ReadFile(opts.RulesFile)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
rules, err := jsonutils.Parse(data)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
ret.Add(rules, "rules")
|
||||
}
|
||||
return ret, nil
|
||||
}
|
||||
Reference in New Issue
Block a user