fix(region): gcp secrule update (#19324)

This commit is contained in:
屈轩
2024-01-24 17:17:01 +08:00
committed by GitHub
parent af4c02c0f1
commit fdf0c40119
4 changed files with 42 additions and 7 deletions
+1 -1
View File
@@ -88,7 +88,7 @@ require (
k8s.io/client-go v0.19.3
k8s.io/cluster-bootstrap v0.19.3
moul.io/http2curl/v2 v2.3.0
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240119080537-6f4dd88d8964
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240124090018-b46efa81820a
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32
yunion.io/x/jsonutils v1.0.1-0.20230613121553-0f3b41e2ef19
yunion.io/x/log v1.0.1-0.20230411060016-feb3f46ab361
+2 -2
View File
@@ -1201,8 +1201,8 @@ sigs.k8s.io/structured-merge-diff/v4 v4.0.1/go.mod h1:bJZC9H9iH24zzfZ/41RGcq60oK
sigs.k8s.io/yaml v1.1.0/go.mod h1:UJmg0vDUVViEyp3mgSv9WPwZCDxu4rQW1olrI1uml+o=
sigs.k8s.io/yaml v1.2.0 h1:kr/MCeFWJWTwyaHoR9c8EjH9OumOmoF9YGiZd7lFm/Q=
sigs.k8s.io/yaml v1.2.0/go.mod h1:yfXDCHCao9+ENCvLSE62v9VSji2MKu5jeNfTrofGhJc=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240119080537-6f4dd88d8964 h1:YWJ7DFIQFRRBTn0snFNIcxPS/Adi/Z/9w8rucGxCFA8=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240119080537-6f4dd88d8964/go.mod h1:aj1gR9PPb6eqqKOwvANe26CoZFY8ydmXy0fuvgKYXH0=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240124090018-b46efa81820a h1:iyCDderC0qGhjNx8bT7xxLr9+/uoddKvqCuJAONzYw0=
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240124090018-b46efa81820a/go.mod h1:aj1gR9PPb6eqqKOwvANe26CoZFY8ydmXy0fuvgKYXH0=
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32 h1:v7POYkQwo1XzOxBoIoRVr/k0V9Y5JyjpshlIFa9raug=
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32/go.mod h1:Uxuou9WQIeJXNpy7t2fPLL0BYLvLiMvGQwY7Qc6aSws=
yunion.io/x/jsonutils v0.0.0-20190625054549-a964e1e8a051/go.mod h1:4N0/RVzsYL3kH3WE/H1BjUQdFiWu50JGCFQuuy+Z634=
+1 -1
View File
@@ -1465,7 +1465,7 @@ sigs.k8s.io/structured-merge-diff/v4/value
# sigs.k8s.io/yaml v1.2.0
## explicit; go 1.12
sigs.k8s.io/yaml
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240119080537-6f4dd88d8964
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240124090018-b46efa81820a
## explicit; go 1.18
yunion.io/x/cloudmux/pkg/apis
yunion.io/x/cloudmux/pkg/apis/billing
+38 -3
View File
@@ -20,7 +20,9 @@ import (
"time"
"yunion.io/x/cloudmux/pkg/cloudprovider"
"yunion.io/x/jsonutils"
"yunion.io/x/pkg/util/secrules"
"yunion.io/x/pkg/util/stringutils"
)
type SFirewallAction struct {
@@ -41,8 +43,8 @@ type SFirewall struct {
DestinationRanges []string
TargetServiceAccounts []string
TargetTags []string
Allowed []SFirewallAction
Denied []SFirewallAction
Allowed []SFirewallAction `json:",allowempty"`
Denied []SFirewallAction `json:",allowempty"`
Direction string
Disabled bool
SelfLink string
@@ -116,5 +118,38 @@ func (self *SFirewall) Delete() error {
}
func (self *SFirewall) Update(opts *cloudprovider.SecurityGroupRuleUpdateOptions) error {
return cloudprovider.ErrNotImplemented
params := map[string]string{
"requestId": stringutils.UUID4(),
}
if len(self.SourceRanges) > 0 {
self.SourceRanges = []string{opts.CIDR}
}
if len(self.DestinationRanges) > 0 {
self.DestinationRanges = []string{opts.CIDR}
}
self.Priority = opts.Priority
if len(opts.Desc) > 0 {
self.Description = opts.Desc
}
action := SFirewallAction{}
action.IPProtocol = opts.Protocol
switch opts.Protocol {
case secrules.PROTO_TCP, secrules.PROTO_UDP:
if len(opts.Ports) > 0 {
action.Ports = []string{opts.Ports}
}
case secrules.PROTO_ANY:
action.IPProtocol = "all"
}
switch opts.Action {
case secrules.SecurityRuleAllow:
self.Denied = []SFirewallAction{}
self.Allowed = []SFirewallAction{action}
case secrules.SecurityRuleDeny:
self.Allowed = []SFirewallAction{}
self.Denied = []SFirewallAction{action}
}
resource := fmt.Sprintf("projects/%s/global/firewalls/%s", self.secgroup.gvpc.client.projectId, self.Name)
_, err := self.secgroup.gvpc.client.ecsPatch(resource, "", params, jsonutils.Marshal(self))
return err
}