mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #9217 from ioito/bugfix/qx-qcloud-secgroup-sync
fix(region): optimized qcloud secgroup sync, only redis need secgroup be in same project
This commit is contained in:
@@ -331,7 +331,7 @@ func (self *SManagedVirtualizedGuestDriver) RequestDeployGuestOnHost(ctx context
|
||||
return errors.Wrap(err, "GetSecgroups")
|
||||
}
|
||||
for i, secgroup := range secgroups {
|
||||
externalId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, task.GetUserCred(), vpcId, vpc, &secgroup, desc.ProjectId)
|
||||
externalId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, task.GetUserCred(), vpcId, vpc, &secgroup, desc.ProjectId, "")
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "RequestSyncSecurityGroup")
|
||||
}
|
||||
@@ -1003,7 +1003,7 @@ func (self *SManagedVirtualizedGuestDriver) RequestSyncSecgroupsOnHost(ctx conte
|
||||
}
|
||||
externalIds := []string{}
|
||||
for _, secgroup := range secgroups {
|
||||
externalId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, task.GetUserCred(), vpcId, vpc, &secgroup, remoteProjectId)
|
||||
externalId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, task.GetUserCred(), vpcId, vpc, &secgroup, remoteProjectId, "")
|
||||
if err != nil {
|
||||
return errors.Wrap(err, "RequestSyncSecurityGroup")
|
||||
}
|
||||
|
||||
@@ -126,7 +126,7 @@ type IRegionDriver interface {
|
||||
BindIPToNatgatewayRollback(ctx context.Context, eipId string) error
|
||||
|
||||
RequestCacheSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, region *SCloudregion, vpc *SVpc, secgroup *SSecurityGroup, classic bool, removeProjectId string, task taskman.ITask) error
|
||||
RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *SVpc, secgroup *SSecurityGroup, removeProjectId string) (string, error)
|
||||
RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *SVpc, secgroup *SSecurityGroup, removeProjectId, service string) (string, error)
|
||||
GetSecurityGroupRuleOrder() cloudprovider.TPriorityOrder // Desc(priority值越大,优先级越高) Asc(priority值越小,优先级越高)
|
||||
GetDefaultSecurityGroupInRule() cloudprovider.SecurityRule
|
||||
GetDefaultSecurityGroupOutRule() cloudprovider.SecurityRule
|
||||
@@ -139,7 +139,7 @@ type IRegionDriver interface {
|
||||
IsSecurityGroupBelongGlobalVpc() bool //安全组子账号范围内可用
|
||||
GetDefaultSecurityGroupVpcId() string
|
||||
GetSecurityGroupVpcId(ctx context.Context, userCred mcclient.TokenCredential, region *SCloudregion, host *SHost, vpc *SVpc, classic bool) (string, error)
|
||||
GetSecurityGroupPublicScope() rbacutils.TRbacScope
|
||||
GetSecurityGroupPublicScope(service string) rbacutils.TRbacScope
|
||||
|
||||
IsSupportedBillingCycle(bc billing.SBillingCycle, resource string) bool
|
||||
GetSecgroupVpcid(vpcId string) string
|
||||
|
||||
@@ -251,7 +251,7 @@ func (self *SBaseRegionDriver) GetDefaultSecurityGroupVpcId() string {
|
||||
return api.NORMAL_VPC_ID
|
||||
}
|
||||
|
||||
func (self *SBaseRegionDriver) GetSecurityGroupPublicScope() rbacutils.TRbacScope {
|
||||
func (self *SBaseRegionDriver) GetSecurityGroupPublicScope(service string) rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeSystem
|
||||
}
|
||||
|
||||
@@ -259,7 +259,7 @@ func (self *SBaseRegionDriver) GetSecurityGroupVpcId(ctx context.Context, userCr
|
||||
return "", cloudprovider.ErrNotImplemented
|
||||
}
|
||||
|
||||
func (self *SBaseRegionDriver) RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *models.SVpc, secgroup *models.SSecurityGroup, removeProjectId string) (string, error) {
|
||||
func (self *SBaseRegionDriver) RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *models.SVpc, secgroup *models.SSecurityGroup, removeProjectId, service string) (string, error) {
|
||||
return "", fmt.Errorf("Not Implemented RequestSyncSecurityGroup")
|
||||
}
|
||||
|
||||
|
||||
@@ -1567,7 +1567,7 @@ func (self *SManagedVirtualizationRegionDriver) GetSecurityGroupVpcId(ctx contex
|
||||
return region.GetDriver().GetDefaultSecurityGroupVpcId(), nil
|
||||
}
|
||||
|
||||
func (self *SManagedVirtualizationRegionDriver) RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *models.SVpc, secgroup *models.SSecurityGroup, remoteProjectId string) (string, error) {
|
||||
func (self *SManagedVirtualizationRegionDriver) RequestSyncSecurityGroup(ctx context.Context, userCred mcclient.TokenCredential, vpcId string, vpc *models.SVpc, secgroup *models.SSecurityGroup, remoteProjectId, service string) (string, error) {
|
||||
lockman.LockRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-%s-%s", secgroup.Id, vpcId, vpc.ManagerId))
|
||||
defer lockman.ReleaseRawObject(ctx, "secgroupcache", fmt.Sprintf("%s-%s-%s", secgroup.Id, vpcId, vpc.ManagerId))
|
||||
|
||||
@@ -1576,7 +1576,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestSyncSecurityGroup(ctx con
|
||||
return "", errors.Wrap(err, "vpc.GetRegon")
|
||||
}
|
||||
|
||||
if region.GetDriver().GetSecurityGroupPublicScope() == rbacutils.ScopeSystem {
|
||||
if region.GetDriver().GetSecurityGroupPublicScope(service) == rbacutils.ScopeSystem {
|
||||
remoteProjectId = ""
|
||||
}
|
||||
|
||||
@@ -1699,7 +1699,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestCacheSecurityGroup(ctx co
|
||||
return errors.Wrap(err, "GetSecurityGroupVpcId")
|
||||
}
|
||||
taskman.LocalTaskRun(task, func() (jsonutils.JSONObject, error) {
|
||||
_, err := self.RequestSyncSecurityGroup(ctx, userCred, vpcId, vpc, secgroup, removeProjectId)
|
||||
_, err := self.RequestSyncSecurityGroup(ctx, userCred, vpcId, vpc, secgroup, removeProjectId, "")
|
||||
return nil, err
|
||||
})
|
||||
return nil
|
||||
@@ -1773,7 +1773,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestCreateDBInstance(ctx cont
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "GetSecurityGroupVpcId")
|
||||
}
|
||||
secId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, userCred, vpcId, vpc, &secgroups[i], desc.ProjectId)
|
||||
secId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, userCred, vpcId, vpc, &secgroups[i], desc.ProjectId, "")
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "SyncSecurityGroup")
|
||||
}
|
||||
@@ -1924,7 +1924,7 @@ func (self *SManagedVirtualizationRegionDriver) RequestCreateDBInstanceFromBacku
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "GetSecurityGroupVpcId")
|
||||
}
|
||||
secId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, userCred, vpcId, vpc, &secgroups[i], desc.ProjectId)
|
||||
secId, err := region.GetDriver().RequestSyncSecurityGroup(ctx, userCred, vpcId, vpc, &secgroups[i], desc.ProjectId, "")
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "SyncSecurityGroup")
|
||||
}
|
||||
|
||||
@@ -72,7 +72,7 @@ func (self *SOpenStackRegionDriver) IsOnlySupportAllowRules() bool {
|
||||
return true
|
||||
}
|
||||
|
||||
func (self *SOpenStackRegionDriver) GetSecurityGroupPublicScope() rbacutils.TRbacScope {
|
||||
func (self *SOpenStackRegionDriver) GetSecurityGroupPublicScope(service string) rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeProject
|
||||
}
|
||||
|
||||
|
||||
@@ -1628,8 +1628,11 @@ func (self *SQcloudRegionDriver) RequestCreateElasticcache(ctx context.Context,
|
||||
return nil
|
||||
}
|
||||
|
||||
func (self *SQcloudRegionDriver) GetSecurityGroupPublicScope() rbacutils.TRbacScope {
|
||||
return rbacutils.ScopeProject
|
||||
func (self *SQcloudRegionDriver) GetSecurityGroupPublicScope(service string) rbacutils.TRbacScope {
|
||||
if service == "redis" {
|
||||
return rbacutils.ScopeProject
|
||||
}
|
||||
return rbacutils.ScopeSystem
|
||||
}
|
||||
|
||||
func (self *SQcloudRegionDriver) RequestSyncSecgroupsForElasticcache(ctx context.Context, userCred mcclient.TokenCredential, ec *models.SElasticcache, task taskman.ITask) error {
|
||||
@@ -1659,7 +1662,7 @@ func (self *SQcloudRegionDriver) RequestSyncSecgroupsForElasticcache(ctx context
|
||||
}
|
||||
|
||||
for i := range ess {
|
||||
externalId, err := self.RequestSyncSecurityGroup(ctx, task.GetUserCred(), vpcId, vpc, ess[i].GetSecGroup(), extProjectId)
|
||||
externalId, err := self.RequestSyncSecurityGroup(ctx, task.GetUserCred(), vpcId, vpc, ess[i].GetSecGroup(), extProjectId, "redis")
|
||||
if err != nil {
|
||||
return nil, errors.Wrap(err, "RequestSyncSecurityGroup")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user