mirror of
https://github.com/gravitational/teleport.git
synced 2026-08-30 17:45:43 +08:00
bbe259d31f
* New teleport configure command: AWS Roles Anywhere set up This PR adds a new teleport configuration command which performs the AWS IAM Roles Anywhere Integration set up. It does the following: - creates a new Roles Anywhere Trust Anchor using the certificate received - creates a new IAM Role which allows the required APIs for sync, and is usable by the Roles Anywhere service, filtered by the created Trust Anchor - creates a new Roles Anywhere Profile which can use the IAM Role above This is part of the new AWS IAM Roles Anywhere integration required set up. * clarify placeholder usage + tests * fix godoc
100 lines
2.9 KiB
Go
100 lines
2.9 KiB
Go
/*
|
|
* Teleport
|
|
* Copyright (C) 2023 Gravitational, Inc.
|
|
*
|
|
* This program is free software: you can redistribute it and/or modify
|
|
* it under the terms of the GNU Affero General Public License as published by
|
|
* the Free Software Foundation, either version 3 of the License, or
|
|
* (at your option) any later version.
|
|
*
|
|
* This program is distributed in the hope that it will be useful,
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
* GNU Affero General Public License for more details.
|
|
*
|
|
* You should have received a copy of the GNU Affero General Public License
|
|
* along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
*/
|
|
|
|
package aws
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
|
|
"github.com/aws/aws-sdk-go-v2/aws"
|
|
"github.com/aws/aws-sdk-go-v2/service/sts"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
// TestGetIdentity verifies parsing of AWS identity received from STS API.
|
|
func TestGetIdentity(t *testing.T) {
|
|
tests := []struct {
|
|
description string
|
|
inARN string
|
|
outIdentity Identity
|
|
outName string
|
|
outAccountID string
|
|
outPartition string
|
|
outType string
|
|
}{
|
|
{
|
|
description: "role identity",
|
|
inARN: "arn:aws:iam::123456789012:role/custom/path/EC2ReadOnly",
|
|
outIdentity: Role{},
|
|
outName: "EC2ReadOnly",
|
|
outAccountID: "123456789012",
|
|
outPartition: "aws",
|
|
outType: "role",
|
|
},
|
|
{
|
|
description: "assumed role identity",
|
|
inARN: "arn:aws:sts::123456789012:assumed-role/DatabaseAccess/i-1234567890",
|
|
outIdentity: Role{},
|
|
outName: "DatabaseAccess",
|
|
outAccountID: "123456789012",
|
|
outPartition: "aws",
|
|
outType: "assumed-role",
|
|
},
|
|
{
|
|
description: "user identity",
|
|
inARN: "arn:aws-us-gov:iam::123456789012:user/custom/path/alice",
|
|
outIdentity: User{},
|
|
outName: "alice",
|
|
outAccountID: "123456789012",
|
|
outPartition: "aws-us-gov",
|
|
outType: "user",
|
|
},
|
|
{
|
|
description: "unsupported identity",
|
|
inARN: "arn:aws:iam::123456789012:group/readers",
|
|
outIdentity: Unknown{},
|
|
outName: "readers",
|
|
outAccountID: "123456789012",
|
|
outPartition: "aws",
|
|
outType: "group",
|
|
},
|
|
}
|
|
for _, test := range tests {
|
|
t.Run(test.description, func(t *testing.T) {
|
|
identity, err := GetIdentityWithClient(context.Background(), &STSClient{ARN: test.inARN})
|
|
require.NoError(t, err)
|
|
require.IsType(t, test.outIdentity, identity)
|
|
require.Equal(t, test.outName, identity.GetName())
|
|
require.Equal(t, test.outAccountID, identity.GetAccountID())
|
|
require.Equal(t, test.outPartition, identity.GetPartition())
|
|
require.Equal(t, test.outType, identity.GetType())
|
|
})
|
|
}
|
|
}
|
|
|
|
type STSClient struct {
|
|
ARN string
|
|
}
|
|
|
|
func (m *STSClient) GetCallerIdentity(ctx context.Context, params *sts.GetCallerIdentityInput, optFns ...func(*sts.Options)) (*sts.GetCallerIdentityOutput, error) {
|
|
return &sts.GetCallerIdentityOutput{
|
|
Arn: aws.String(m.ARN),
|
|
}, nil
|
|
}
|