mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
add more log & fix YunionSecRuleToAws\
This commit is contained in:
@@ -324,7 +324,7 @@ func (self *SRegion) syncSecgroupRules(secgroupId string, rules []secrules.Secur
|
||||
if cmp == 0 {
|
||||
if secgroup.Permissions[j].Description != rules[i].Description {
|
||||
if err := self.updateSecurityGroupRuleDescription(secgroupId, &rules[i]); err != nil {
|
||||
log.Errorf("updateSecurityGroupRuleDescription error %v", rules[i])
|
||||
log.Errorf("updateSecurityGroupRuleDescription %v error: %s", rules[i], err.Error())
|
||||
return err
|
||||
}
|
||||
}
|
||||
@@ -332,26 +332,26 @@ func (self *SRegion) syncSecgroupRules(secgroupId string, rules []secrules.Secur
|
||||
j += 1
|
||||
} else if cmp > 0 {
|
||||
if err := self.delSecurityGroupRule(secgroupId, &secgroup.Permissions[j]); err != nil {
|
||||
log.Errorf("delSecurityGroupRule error %v", secgroup.Permissions[j])
|
||||
log.Errorf("delSecurityGroupRule %v error: %s", secgroup.Permissions[j], err.Error())
|
||||
return err
|
||||
}
|
||||
j += 1
|
||||
} else {
|
||||
if err := self.addSecurityGroupRules(secgroupId, &rules[i]); err != nil {
|
||||
log.Errorf("addSecurityGroupRule error %v", rules[i])
|
||||
log.Errorf("addSecurityGroupRule %v error: %s", rules[i], err.Error())
|
||||
return err
|
||||
}
|
||||
i += 1
|
||||
}
|
||||
} else if i >= len(rules) {
|
||||
if err := self.delSecurityGroupRule(secgroupId, &secgroup.Permissions[j]); err != nil {
|
||||
log.Errorf("delSecurityGroupRule error %v", secgroup.Permissions[j])
|
||||
log.Errorf("delSecurityGroupRule %v error: %s", secgroup.Permissions[j], err.Error())
|
||||
return err
|
||||
}
|
||||
j += 1
|
||||
} else if j >= len(secgroup.Permissions) {
|
||||
if err := self.addSecurityGroupRules(secgroupId, &rules[i]); err != nil {
|
||||
log.Errorf("addSecurityGroupRule error %v", rules[i])
|
||||
log.Errorf("addSecurityGroupRule %v error: %s", rules[i], err.Error())
|
||||
return err
|
||||
}
|
||||
i += 1
|
||||
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"fmt"
|
||||
"net"
|
||||
"reflect"
|
||||
"regexp"
|
||||
"strings"
|
||||
"yunion.io/x/jsonutils"
|
||||
|
||||
@@ -295,6 +296,8 @@ func AwsIpPermissionToYunion(direction secrules.TSecurityRuleDirection, p ec2.Ip
|
||||
return rules, nil
|
||||
}
|
||||
|
||||
// YunionSecRuleToAws 不能保证无损转换
|
||||
// 规则描述如果包含中文等字符,将被丢弃掉
|
||||
func YunionSecRuleToAws(rule secrules.SecurityRule) ([]*ec2.IpPermission, error) {
|
||||
if rule.Action == secrules.SecurityRuleDeny {
|
||||
return nil, fmt.Errorf("YunionSecRuleToAws ignored aws not supported deny rule")
|
||||
@@ -304,8 +307,13 @@ func YunionSecRuleToAws(rule secrules.SecurityRule) ([]*ec2.IpPermission, error)
|
||||
if iprange == "<nil>" {
|
||||
return nil, fmt.Errorf("YunionSecRuleToAws ignored ipnet should not be empty")
|
||||
}
|
||||
|
||||
description := ""
|
||||
if match, err := regexp.MatchString("^[\\sa-zA-Z0-9. _:/()#,@\\]\\[+=&;{}!$*-]+$", rule.Description);err == nil && match {
|
||||
description = rule.Description
|
||||
}
|
||||
ipranges := []*ec2.IpRange{}
|
||||
ipranges = append(ipranges, &ec2.IpRange{CidrIp: &iprange, Description: &rule.Description})
|
||||
ipranges = append(ipranges, &ec2.IpRange{CidrIp: &iprange, Description: &description})
|
||||
|
||||
portranges := yunionPortRangeToAws(rule)
|
||||
protocol := yunionProtocolToAws(rule)
|
||||
|
||||
Reference in New Issue
Block a user