mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
fix(region): support secgroup ipv6 (#19542)
This commit is contained in:
@@ -88,7 +88,7 @@ require (
|
||||
k8s.io/client-go v0.19.3
|
||||
k8s.io/cluster-bootstrap v0.19.3
|
||||
moul.io/http2curl/v2 v2.3.0
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240222090059-3680ddee35d6
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240223082945-bab3d04c48fa
|
||||
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32
|
||||
yunion.io/x/jsonutils v1.0.1-0.20240203102553-4096f103b401
|
||||
yunion.io/x/log v1.0.1-0.20230411060016-feb3f46ab361
|
||||
|
||||
@@ -1201,8 +1201,8 @@ sigs.k8s.io/structured-merge-diff/v4 v4.0.1/go.mod h1:bJZC9H9iH24zzfZ/41RGcq60oK
|
||||
sigs.k8s.io/yaml v1.1.0/go.mod h1:UJmg0vDUVViEyp3mgSv9WPwZCDxu4rQW1olrI1uml+o=
|
||||
sigs.k8s.io/yaml v1.2.0 h1:kr/MCeFWJWTwyaHoR9c8EjH9OumOmoF9YGiZd7lFm/Q=
|
||||
sigs.k8s.io/yaml v1.2.0/go.mod h1:yfXDCHCao9+ENCvLSE62v9VSji2MKu5jeNfTrofGhJc=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240222090059-3680ddee35d6 h1:j0t6qiUkWz7wHgC1mbyJkXLTFTr3cWY/FFP2aZibSpM=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240222090059-3680ddee35d6/go.mod h1:dsUESXIbXJ+/ywbNClhldOrbPOiBi2udrgOnB/ffoWk=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240223082945-bab3d04c48fa h1:rpcxzdhsSbkFK2YzsuMsrSjKzskk1EE8+1AgWffhfsA=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240223082945-bab3d04c48fa/go.mod h1:dsUESXIbXJ+/ywbNClhldOrbPOiBi2udrgOnB/ffoWk=
|
||||
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32 h1:v7POYkQwo1XzOxBoIoRVr/k0V9Y5JyjpshlIFa9raug=
|
||||
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32/go.mod h1:Uxuou9WQIeJXNpy7t2fPLL0BYLvLiMvGQwY7Qc6aSws=
|
||||
yunion.io/x/jsonutils v0.0.0-20190625054549-a964e1e8a051/go.mod h1:4N0/RVzsYL3kH3WE/H1BjUQdFiWu50JGCFQuuy+Z634=
|
||||
|
||||
Vendored
+1
-1
@@ -1465,7 +1465,7 @@ sigs.k8s.io/structured-merge-diff/v4/value
|
||||
# sigs.k8s.io/yaml v1.2.0
|
||||
## explicit; go 1.12
|
||||
sigs.k8s.io/yaml
|
||||
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240222090059-3680ddee35d6
|
||||
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240223082945-bab3d04c48fa
|
||||
## explicit; go 1.18
|
||||
yunion.io/x/cloudmux/pkg/apis
|
||||
yunion.io/x/cloudmux/pkg/apis/billing
|
||||
|
||||
+8
@@ -30,6 +30,7 @@ type SPermission struct {
|
||||
CreateTime time.Time
|
||||
Description string
|
||||
DestCidrIp string
|
||||
Ipv6DestCidrIp string
|
||||
DestGroupId string
|
||||
DestGroupName string
|
||||
DestGroupOwnerAccount string
|
||||
@@ -40,6 +41,7 @@ type SPermission struct {
|
||||
PortRange string
|
||||
Priority int
|
||||
SourceCidrIp string
|
||||
Ipv6SourceCidrIp string
|
||||
SourceGroupId string
|
||||
SourceGroupName string
|
||||
SourceGroupOwnerAccount string
|
||||
@@ -83,6 +85,12 @@ func (self *SPermission) GetCIDRs() []string {
|
||||
if len(self.DestCidrIp) > 0 {
|
||||
ret = append(ret, self.DestCidrIp)
|
||||
}
|
||||
if len(self.Ipv6DestCidrIp) > 0 {
|
||||
ret = append(ret, self.Ipv6DestCidrIp)
|
||||
}
|
||||
if len(self.Ipv6SourceCidrIp) > 0 {
|
||||
ret = append(ret, self.Ipv6SourceCidrIp)
|
||||
}
|
||||
return ret
|
||||
}
|
||||
|
||||
|
||||
+15
-6
@@ -21,6 +21,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/netutils"
|
||||
"yunion.io/x/pkg/util/secrules"
|
||||
"yunion.io/x/pkg/utils"
|
||||
|
||||
@@ -276,14 +277,22 @@ func (self *SRegion) CreateSecurityGroupRule(secGrpId string, opts *cloudprovide
|
||||
action := "AuthorizeSecurityGroup"
|
||||
params["Permissions.1.Priority"] = fmt.Sprintf("%d", opts.Priority)
|
||||
if opts.Direction == secrules.SecurityRuleIngress {
|
||||
params["Permissions.1.SourceCidrIp"] = "0.0.0.0/0"
|
||||
if len(opts.CIDR) > 0 {
|
||||
params["Permissions.1.SourceCidrIp"] = opts.CIDR
|
||||
if _, err := netutils.NewIPV6Prefix(opts.CIDR); err == nil {
|
||||
params["Permissions.1.Ipv6SourceCidrIp"] = opts.CIDR
|
||||
} else {
|
||||
params["Permissions.1.SourceCidrIp"] = "0.0.0.0/0"
|
||||
if len(opts.CIDR) > 0 {
|
||||
params["Permissions.1.SourceCidrIp"] = opts.CIDR
|
||||
}
|
||||
}
|
||||
} else {
|
||||
params["Permissions.1.DestCidrIp"] = "0.0.0.0/0"
|
||||
if len(opts.CIDR) > 0 {
|
||||
params["Permissions.1.DestCidrIp"] = opts.CIDR
|
||||
if _, err := netutils.NewIPV6Prefix(opts.CIDR); err == nil {
|
||||
params["Permissions.1.Ipv6DestCidrIp"] = opts.CIDR
|
||||
} else {
|
||||
params["Permissions.1.DestCidrIp"] = "0.0.0.0/0"
|
||||
if len(opts.CIDR) > 0 {
|
||||
params["Permissions.1.DestCidrIp"] = opts.CIDR
|
||||
}
|
||||
}
|
||||
action = "AuthorizeSecurityGroupEgress"
|
||||
}
|
||||
|
||||
+12
-6
@@ -21,6 +21,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/netutils"
|
||||
"yunion.io/x/pkg/util/secrules"
|
||||
|
||||
api "yunion.io/x/cloudmux/pkg/apis/compute"
|
||||
@@ -93,17 +94,22 @@ func (self *SSecurityGroup) GetRules() ([]cloudprovider.ISecurityGroupRule, erro
|
||||
|
||||
func (self *SRegion) CreateSecurityGroupRule(secGrpId string, opts *cloudprovider.SecurityGroupRuleCreateOptions) (*SSecurityGroupRule, error) {
|
||||
params := map[string]string{
|
||||
"GroupId": secGrpId,
|
||||
"IpPermissions.1.IpProtocol": "-1",
|
||||
"IpPermissions.1.IpRanges.1.Description": opts.Desc,
|
||||
"IpPermissions.1.FromPort": "0",
|
||||
"IpPermissions.1.ToPort": "65535",
|
||||
"GroupId": secGrpId,
|
||||
"IpPermissions.1.IpProtocol": "-1",
|
||||
"IpPermissions.1.FromPort": "0",
|
||||
"IpPermissions.1.ToPort": "65535",
|
||||
}
|
||||
if opts.Protocol != secrules.PROTO_ANY {
|
||||
params["IpPermissions.1.IpProtocol"] = strings.ToLower(opts.Protocol)
|
||||
}
|
||||
if len(opts.CIDR) > 0 {
|
||||
params["IpPermissions.1.IpRanges.1.CidrIp"] = opts.CIDR
|
||||
if _, err := netutils.NewIPV6Prefix(opts.CIDR); err == nil {
|
||||
params["IpPermissions.1.Ipv6Ranges.1.CidrIpv6"] = opts.CIDR
|
||||
params["IpPermissions.1.Ipv6Ranges.1.Description"] = opts.Desc
|
||||
} else {
|
||||
params["IpPermissions.1.IpRanges.1.CidrIp"] = opts.CIDR
|
||||
params["IpPermissions.1.IpRanges.1.Description"] = opts.Desc
|
||||
}
|
||||
}
|
||||
start, end := 0, 0
|
||||
if len(opts.Ports) > 0 {
|
||||
|
||||
+4
@@ -20,6 +20,7 @@ import (
|
||||
|
||||
"yunion.io/x/cloudmux/pkg/cloudprovider"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/netutils"
|
||||
"yunion.io/x/pkg/util/secrules"
|
||||
"yunion.io/x/pkg/utils"
|
||||
)
|
||||
@@ -114,6 +115,9 @@ func (self *SRegion) CreateSecurityGroupRule(groupId string, opts *cloudprovider
|
||||
"description": opts.Desc,
|
||||
"range": "1-65535",
|
||||
}
|
||||
if _, err := netutils.NewIPV6Prefix(opts.CIDR); err == nil {
|
||||
rule["ethertype"] = "IPv6"
|
||||
}
|
||||
api := "/v4/vpc/create-security-group-egress"
|
||||
if opts.Direction == secrules.DIR_IN {
|
||||
rule["direction"] = "ingress"
|
||||
|
||||
+4
@@ -21,6 +21,7 @@ import (
|
||||
|
||||
"yunion.io/x/cloudmux/pkg/cloudprovider"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/netutils"
|
||||
"yunion.io/x/pkg/util/secrules"
|
||||
)
|
||||
|
||||
@@ -148,6 +149,9 @@ func (self *SRegion) CreateSecurityGroupRule(groupId string, opts *cloudprovider
|
||||
}
|
||||
if len(opts.CIDR) > 0 {
|
||||
rule["remote_ip_prefix"] = opts.CIDR
|
||||
if _, err := netutils.NewIPV6Prefix(opts.CIDR); err == nil {
|
||||
rule["ethertype"] = "IPv6"
|
||||
}
|
||||
}
|
||||
if opts.Action == secrules.SecurityRuleDeny {
|
||||
rule["action"] = "deny"
|
||||
|
||||
+5
@@ -21,6 +21,7 @@ import (
|
||||
|
||||
"yunion.io/x/jsonutils"
|
||||
"yunion.io/x/pkg/errors"
|
||||
"yunion.io/x/pkg/util/netutils"
|
||||
"yunion.io/x/pkg/util/secrules"
|
||||
|
||||
api "yunion.io/x/cloudmux/pkg/apis/compute"
|
||||
@@ -346,6 +347,10 @@ func (self *SRegion) CreateSecurityGroupRule(groupId string, opts *cloudprovider
|
||||
prefix + "Port": opts.Ports,
|
||||
prefix + "CidrBlock": opts.CIDR,
|
||||
}
|
||||
if _, err := netutils.NewIPV6Prefix(opts.CIDR); err == nil {
|
||||
params[prefix+"Ipv6CidrBlock"] = opts.CIDR
|
||||
delete(params, prefix+"CidrBlock")
|
||||
}
|
||||
|
||||
_, err := self.vpcRequest("CreateSecurityGroupPolicies", params)
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user