plugin

package
v0.5.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: May 8, 2026 License: Apache-2.0 Imports: 14 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// FlagAudience represents the name of the flag for setting the OIDC provider audience for the plugin.
	FlagAudience = "audience"
	// FlagLogFormat represents the name of the flag for setting the log format for the plugin.
	FlagLogFormat = "log.format"
	// FlagLogLevel represents the name of the flag for setting the log level for the plugin.
	FlagLogLevel = "log.level"
	// FlagScriptFormat represents the name of the flag for setting the format of the AWS credentials script for the plugin.
	FlagScriptFormat = "script_format"
	// FlagScriptPath represents the name of the flag for setting the path to write the AWS credentials script for the plugin.
	FlagScriptPath = "script_path"
	// FlagScriptWrite represents the name of the flag for setting whether to write the AWS credentials script for the plugin.
	FlagScriptWrite = "script_write"
	// FlagVerify represents the name of the flag for setting whether to validate the AWS credentials for the plugin.
	FlagVerify = "verify"

	// FlagAWSInlineSessionPolicy represents the name of the flag for setting the AWS inline session policy for the plugin.
	FlagAWSInlineSessionPolicy = "aws.inline_session_policy"
	// FlagAWSManagedSessionPolicies represents the name of the flag for setting the AWS managed session policies for the plugin.
	FlagAWSManagedSessionPolicies = "aws.managed_session_policies"
	// FlagAWSRegion represents the name of the flag for setting the AWS region for the plugin.
	FlagAWSRegion = "aws.region"
	// FlagAWSRole represents the name of the flag for setting the AWS IAM role to assume for the plugin.
	FlagAWSRole = "aws.role"
	// FlagAWSRoleDurationSeconds represents the name of the flag for setting the duration in seconds for assuming the AWS IAM role for the plugin.
	FlagAWSRoleDurationSeconds = "aws.role_duration_seconds"
	// FlagAWSRoleSessionName represents the name of the flag for setting the session name when assuming the AWS IAM role for the plugin.
	FlagAWSRoleSessionName = "aws.role_session_name"

	// FlagVelaBuildNumber represents the name of the flag for capturing the build number from Vela for the plugin.
	FlagVelaBuildNumber = "vela.build_number"
	// FlagVelaIDTokenRequestToken represents the name of the flag for capturing the OIDC request token from Vela for the plugin.
	//
	//nolint:gosec // ignore false positive for hardcoded credential
	FlagVelaIDTokenRequestToken = "vela.id_token_request_token"
	// FlagVelaIDTokenRequestURL represents the name of the flag for capturing the OIDC request token URL from Vela for the plugin.
	//
	//nolint:gosec // ignore false positive for hardcoded credential
	FlagVelaIDTokenRequestURL = "vela.id_token_request_url"
	// FlagVelaOrgName represents the name of the flag for capturing the organization name from Vela for the plugin.
	FlagVelaOrgName = "vela.org_name"
	// FlagVelaRepoName represents the name of the flag for capturing the repository name from Vela for the plugin.
	FlagVelaRepoName = "vela.repo_name"

	// ScriptFormatCredentialFile represents the value for the script format flag to write AWS credentials as a credential file.
	//
	//nolint:gosec // ignore false positive for hardcoded credential
	ScriptFormatCredentialFile = "credential_file"
	// ScriptFormatShell represents the value for the script format flag to write AWS credentials as a shell script.
	ScriptFormatShell = "shell"
)

Variables

View Source
var (
	// Flags represents all supported command line interface (CLI) flags for the plugin.
	Flags = []cli.Flag{

		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_AUDIENCE", "AWS_CREDENTIALS_AUDIENCE"},
			FilePath: "/vela/parameters/aws-credentials/audience,/vela/secrets/aws-credentials/audience",
			Name:     FlagAudience,
			Usage:    "Audience to use for the OIDC provider",
			Value:    "sts.amazonaws.com",
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_LOG_FORMAT", "AWS_CREDENTIALS_LOG_FORMAT"},
			FilePath: "/vela/parameters/aws-credentials/log_format,/vela/secrets/aws-credentials/log_format",
			Name:     FlagLogFormat,
			Usage:    "set log format - options: (text|json)",
			Value:    "text",
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_LOG_LEVEL", "AWS_CREDENTIALS_LOG_LEVEL"},
			FilePath: "/vela/parameters/aws-credentials/log_level,/vela/secrets/aws-credentials/log_level",
			Name:     FlagLogLevel,
			Usage:    "set log level - options: (trace|debug|info|warn|error|fatal|panic)",
			Value:    "info",
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_SCRIPT_PATH", "AWS_CREDENTIALS_SCRIPT_PATH"},
			FilePath: "/vela/parameters/aws-credentials/script_path,/vela/secrets/aws-credentials/script_path",
			Name:     FlagScriptPath,
			Usage:    "path where to write script that contains AWS credentials",
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_SCRIPT_FORMAT", "AWS_CREDENTIALS_SCRIPT_FORMAT"},
			FilePath: "/vela/parameters/aws-credentials/script_format,/vela/secrets/aws-credentials/script_format",
			Name:     FlagScriptFormat,
			Usage:    "format of AWS credentials script (shell or credential_file)",
			Value:    ScriptFormatShell,
		},
		&cli.BoolFlag{
			EnvVars: []string{"PARAMETER_SCRIPT_WRITE", "AWS_CREDENTIALS_SCRIPT_WRITE"},
			Name:    FlagScriptWrite,
			Usage:   "if the credentials script should be created",
			Value:   false,
		},
		&cli.BoolFlag{
			EnvVars: []string{"PARAMETER_VERIFY", "AWS_CREDENTIALS_VERIFY"},
			Name:    FlagVerify,
			Usage:   "if the AWS credentials should be validated",
		},

		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_INLINE_SESSION_POLICY", "AWS_CREDENTIALS_INLINE_SESSION_POLICY"},
			FilePath: "/vela/parameters/aws-credentials/inline_session_policy,/vela/secrets/aws-credentials/inline_session_policy",
			Name:     FlagAWSInlineSessionPolicy,
			Usage:    "Inline session policy to use when assuming the role",
		},
		&cli.StringSliceFlag{
			EnvVars:  []string{"PARAMETER_MANAGED_SESSION_POLICIES", "AWS_CREDENTIALS_MANAGED_SESSION_POLICIES"},
			FilePath: "/vela/parameters/aws-credentials/managed_session_policies,/vela/secrets/aws-credentials/managed_session_policies",
			Name:     FlagAWSManagedSessionPolicies,
			Usage:    "list of managed session policies to use when assuming the role",
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_REGION", "AWS_CREDENTIALS_REGION"},
			FilePath: "/vela/parameters/aws-credentials/region,/vela/secrets/aws-credentials/region",
			Name:     FlagAWSRegion,
			Usage:    "AWS region to use for assume role",
			Value:    "us-east-1",
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_ROLE", "AWS_CREDENTIALS_ROLE"},
			FilePath: "/vela/parameters/aws-credentials/role,/vela/secrets/aws-credentials/role",
			Name:     FlagAWSRole,
			Usage:    "AWS IAM role to assume",
		},
		&cli.IntFlag{
			EnvVars:  []string{"PARAMETER_ROLE_DURATION_SECONDS", "AWS_CREDENTIALS_ROLE_DURATION_SECONDS"},
			FilePath: "/vela/parameters/aws-credentials/role_duration_seconds,/vela/secrets/aws-credentials/role_duration_seconds",
			Name:     FlagAWSRoleDurationSeconds,
			Usage:    "Role duration in seconds",
			Value:    3600,
		},
		&cli.StringFlag{
			EnvVars:  []string{"PARAMETER_ROLE_SESSION_NAME", "AWS_CREDENTIALS_ROLE_SESSION_NAME"},
			FilePath: "/vela/parameters/aws-credentials/role_session_name,/vela/secrets/aws-credentials/role_session_name",
			Name:     FlagAWSRoleSessionName,
			Usage:    "Role session name",
			Value:    "vela",
		},

		&cli.IntFlag{
			EnvVars: []string{"VELA_BUILD_NUMBER", "BUILD_NUMBER"},
			Name:    FlagVelaBuildNumber,
			Usage:   "environment variable reference for reading in build number",
		},
		&cli.StringFlag{
			EnvVars: []string{"VELA_ID_TOKEN_REQUEST_TOKEN"},
			Name:    FlagVelaIDTokenRequestToken,
			Usage:   "environment variable reference for reading in OIDC request token",
		},
		&cli.StringFlag{
			EnvVars: []string{"VELA_ID_TOKEN_REQUEST_URL"},
			Name:    FlagVelaIDTokenRequestURL,
			Usage:   "environment variable reference for reading in OIDC request token URL",
		},
		&cli.StringFlag{
			EnvVars: []string{"VELA_REPO_ORG", "REPOSITORY_ORG"},
			Name:    FlagVelaOrgName,
			Usage:   "environment variable reference for reading in repository org",
		},
		&cli.StringFlag{
			EnvVars: []string{"VELA_REPO_NAME", "REPOSITORY_NAME"},
			Name:    FlagVelaRepoName,
			Usage:   "environment variable reference for reading in repository name",
		},
	}
)

Functions

This section is empty.

Types

type AWS

type AWS struct {
	Region                 string
	Role                   string
	RoleDurationSeconds    int
	RoleSessionName        string
	InlineSessionPolicy    string
	ManagedSessionPolicies []string
}

AWS struct represents the config for the AWS role assumption.

type Config

type Config struct {
	Audience     string
	Verify       bool
	ScriptPath   string
	ScriptFormat string
	ScriptWrite  bool
	AWS          *AWS
	Vela         *Vela
	Logger       *logrus.Entry
}

Config struct represents fields user can present to plugin.

func FromCLIContext added in v0.5.0

func FromCLIContext(ctx *cli.Context, logger *logrus.Entry) *Config

FromCLIContext creates and returns a plugin from the urfave/cli context.

func (*Config) AssumeRole

func (c *Config) AssumeRole(token string) (*aws.Credentials, error)

func (*Config) Exec

func (c *Config) Exec() error

Exec generates a set of temporary AWS credentials for later usage.

func (*Config) GenerateVelaToken

func (c *Config) GenerateVelaToken() (string, error)

func (*Config) Validate

func (c *Config) Validate() error

Validate function to validate plugin configuration.

func (*Config) WriteCreds

func (c *Config) WriteCreds(creds *aws.Credentials) error

type Vela

type Vela struct {
	BuildNumber     int
	RepoName        string
	OrgName         string
	RequestToken    string
	RequestTokenURL string
}

Vela struct represents the config for the Vela API calls.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL