add sercurity rule methods

This commit is contained in:
TangBin
2018-10-15 20:00:38 +08:00
parent 4c2c8c91c4
commit 8d5fc9ec2c
2 changed files with 163 additions and 2 deletions
+32 -2
View File
@@ -180,8 +180,38 @@ func (self *SHost) _createVM(name, imgId string, sysDiskSize, cpu, memMB int,
networkId, ipAddr, desc, passwd,
storageType string, diskSizes []int, publicKey string, secgroupId string) (string, error) {
// 网络配置及安全组绑定
// todo:// https://www.guru99.com/creating-amazon-ec2-instance.html
self.zone.getNetworkById(networkId)
net := self.zone.getNetworkById(networkId)
if net == nil {
return "", fmt.Errorf("invalid network ID %s", networkId)
}
if net.wire == nil {
log.Errorf("network's wire is empty")
return "", fmt.Errorf("network's wire is empty")
}
if net.wire.vpc == nil {
log.Errorf("wire's vpc is empty")
return "", fmt.Errorf("wire's vpc is empty")
}
if len(secgroupId) == 0 {
secgroups, err := net.wire.vpc.GetISecurityGroups()
if err != nil {
return "", fmt.Errorf("get security group error %s", err)
}
if len(secgroups) == 0 {
secId, err := self.zone.region.createDefaultSecurityGroup(net.wire.vpc.VpcId)
if err != nil {
return "", fmt.Errorf("no secgroup for vpc and failed to create a default One!!")
} else {
secgroupId = secId
}
} else {
secgroupId = secgroups[0].GetId()
}
}
// 同步keypair
// 镜像及硬盘配置
+131
View File
@@ -0,0 +1,131 @@
package aws
import (
"time"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/secrules"
"github.com/aws/aws-sdk-go/service/ec2"
)
type SecurityGroupPermissionNicType string
const (
IntranetNicType SecurityGroupPermissionNicType = "intranet"
InternetNicType SecurityGroupPermissionNicType = "internet"
)
type SPermission struct {
CreateTime time.Time
Description string
DestCidrIp string
DestGroupId string
DestGroupName string
DestGroupOwnerAccount string
Direction string
IpProtocol string
NicType SecurityGroupPermissionNicType
Policy string
PortRange string
Priority int
SourceCidrIp string
SourceGroupId string
SourceGroupName string
SourceGroupOwnerAccount string
}
type SPermissions struct {
Permission []SPermission
}
type Tags struct {
Tag []Tag
}
type Tag struct {
TagKey string
TagValue string
}
type SSecurityGroup struct {
vpc *SVpc
CreationTime time.Time
Description string
SecurityGroupId string
SecurityGroupName string
VpcId string
InnerAccessPolicy string
Permissions SPermissions
RegionId string
Tags Tags
}
func (self *SSecurityGroup) GetId() string {
panic("implement me")
}
func (self *SSecurityGroup) GetName() string {
panic("implement me")
}
func (self *SSecurityGroup) GetGlobalId() string {
panic("implement me")
}
func (self *SSecurityGroup) GetStatus() string {
panic("implement me")
}
func (self *SSecurityGroup) Refresh() error {
panic("implement me")
}
func (self *SSecurityGroup) IsEmulated() bool {
panic("implement me")
}
func (self *SSecurityGroup) GetMetadata() *jsonutils.JSONDict {
panic("implement me")
}
func (self *SSecurityGroup) GetDescription() string {
panic("implement me")
}
func (self *SSecurityGroup) GetRules() ([]secrules.SecurityRule, error) {
panic("implement me")
}
func (self *SRegion) addSecurityGroupRules(secGrpId string, rule *secrules.SecurityRule) error {
// todo: add sercurity rules
return nil
}
func (self *SRegion) addSecurityGroupRule(secGrpId string, rule *secrules.SecurityRule) error {
// todo: add sercurity rules
return nil
}
func (self *SRegion) createSecurityGroup(vpcId string, name string, desc string) (string, error) {
params := &ec2.CreateSecurityGroupInput{}
params.SetVpcId(vpcId)
params.SetDescription(desc)
params.SetGroupName(name)
group, err := self.ec2Client.CreateSecurityGroup(params)
if err != nil {
return "", err
}
return *group.GroupId, nil
}
func (self *SRegion) createDefaultSecurityGroup(vpcId string) (string, error) {
secId, err := self.createSecurityGroup(vpcId, "vpc default", "vpc default group")
if err != nil {
return "", err
}
// todo : add sercurity rules
return secId, nil
}