Documentation
¶
Index ¶
Constants ¶
View Source
const ( // FlagAudience represents the name of the flag for setting the OIDC provider audience for the plugin. FlagAudience = "audience" // FlagLogFormat represents the name of the flag for setting the log format for the plugin. FlagLogFormat = "log.format" // FlagLogLevel represents the name of the flag for setting the log level for the plugin. FlagLogLevel = "log.level" // FlagScriptFormat represents the name of the flag for setting the format of the AWS credentials script for the plugin. FlagScriptFormat = "script_format" // FlagScriptPath represents the name of the flag for setting the path to write the AWS credentials script for the plugin. FlagScriptPath = "script_path" // FlagScriptWrite represents the name of the flag for setting whether to write the AWS credentials script for the plugin. FlagScriptWrite = "script_write" // FlagVerify represents the name of the flag for setting whether to validate the AWS credentials for the plugin. FlagVerify = "verify" // FlagAWSInlineSessionPolicy represents the name of the flag for setting the AWS inline session policy for the plugin. FlagAWSInlineSessionPolicy = "aws.inline_session_policy" // FlagAWSManagedSessionPolicies represents the name of the flag for setting the AWS managed session policies for the plugin. FlagAWSManagedSessionPolicies = "aws.managed_session_policies" // FlagAWSRegion represents the name of the flag for setting the AWS region for the plugin. FlagAWSRegion = "aws.region" // FlagAWSRole represents the name of the flag for setting the AWS IAM role to assume for the plugin. FlagAWSRole = "aws.role" // FlagAWSRoleDurationSeconds represents the name of the flag for setting the duration in seconds for assuming the AWS IAM role for the plugin. FlagAWSRoleDurationSeconds = "aws.role_duration_seconds" // FlagAWSRoleSessionName represents the name of the flag for setting the session name when assuming the AWS IAM role for the plugin. FlagAWSRoleSessionName = "aws.role_session_name" // FlagVelaBuildNumber represents the name of the flag for capturing the build number from Vela for the plugin. FlagVelaBuildNumber = "vela.build_number" // FlagVelaIDTokenRequestToken represents the name of the flag for capturing the OIDC request token from Vela for the plugin. // //nolint:gosec // ignore false positive for hardcoded credential FlagVelaIDTokenRequestToken = "vela.id_token_request_token" // FlagVelaIDTokenRequestURL represents the name of the flag for capturing the OIDC request token URL from Vela for the plugin. // //nolint:gosec // ignore false positive for hardcoded credential FlagVelaIDTokenRequestURL = "vela.id_token_request_url" // FlagVelaOrgName represents the name of the flag for capturing the organization name from Vela for the plugin. FlagVelaOrgName = "vela.org_name" // FlagVelaRepoName represents the name of the flag for capturing the repository name from Vela for the plugin. FlagVelaRepoName = "vela.repo_name" // ScriptFormatCredentialFile represents the value for the script format flag to write AWS credentials as a credential file. // //nolint:gosec // ignore false positive for hardcoded credential ScriptFormatCredentialFile = "credential_file" // ScriptFormatShell represents the value for the script format flag to write AWS credentials as a shell script. ScriptFormatShell = "shell" )
Variables ¶
View Source
var ( // Flags represents all supported command line interface (CLI) flags for the plugin. Flags = []cli.Flag{ &cli.StringFlag{ EnvVars: []string{"PARAMETER_AUDIENCE", "AWS_CREDENTIALS_AUDIENCE"}, FilePath: "/vela/parameters/aws-credentials/audience,/vela/secrets/aws-credentials/audience", Name: FlagAudience, Usage: "Audience to use for the OIDC provider", Value: "sts.amazonaws.com", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_LOG_FORMAT", "AWS_CREDENTIALS_LOG_FORMAT"}, FilePath: "/vela/parameters/aws-credentials/log_format,/vela/secrets/aws-credentials/log_format", Name: FlagLogFormat, Usage: "set log format - options: (text|json)", Value: "text", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_LOG_LEVEL", "AWS_CREDENTIALS_LOG_LEVEL"}, FilePath: "/vela/parameters/aws-credentials/log_level,/vela/secrets/aws-credentials/log_level", Name: FlagLogLevel, Usage: "set log level - options: (trace|debug|info|warn|error|fatal|panic)", Value: "info", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_SCRIPT_PATH", "AWS_CREDENTIALS_SCRIPT_PATH"}, FilePath: "/vela/parameters/aws-credentials/script_path,/vela/secrets/aws-credentials/script_path", Name: FlagScriptPath, Usage: "path where to write script that contains AWS credentials", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_SCRIPT_FORMAT", "AWS_CREDENTIALS_SCRIPT_FORMAT"}, FilePath: "/vela/parameters/aws-credentials/script_format,/vela/secrets/aws-credentials/script_format", Name: FlagScriptFormat, Usage: "format of AWS credentials script (shell or credential_file)", Value: ScriptFormatShell, }, &cli.BoolFlag{ EnvVars: []string{"PARAMETER_SCRIPT_WRITE", "AWS_CREDENTIALS_SCRIPT_WRITE"}, Name: FlagScriptWrite, Usage: "if the credentials script should be created", Value: false, }, &cli.BoolFlag{ EnvVars: []string{"PARAMETER_VERIFY", "AWS_CREDENTIALS_VERIFY"}, Name: FlagVerify, Usage: "if the AWS credentials should be validated", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_INLINE_SESSION_POLICY", "AWS_CREDENTIALS_INLINE_SESSION_POLICY"}, FilePath: "/vela/parameters/aws-credentials/inline_session_policy,/vela/secrets/aws-credentials/inline_session_policy", Name: FlagAWSInlineSessionPolicy, Usage: "Inline session policy to use when assuming the role", }, &cli.StringSliceFlag{ EnvVars: []string{"PARAMETER_MANAGED_SESSION_POLICIES", "AWS_CREDENTIALS_MANAGED_SESSION_POLICIES"}, FilePath: "/vela/parameters/aws-credentials/managed_session_policies,/vela/secrets/aws-credentials/managed_session_policies", Name: FlagAWSManagedSessionPolicies, Usage: "list of managed session policies to use when assuming the role", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_REGION", "AWS_CREDENTIALS_REGION"}, FilePath: "/vela/parameters/aws-credentials/region,/vela/secrets/aws-credentials/region", Name: FlagAWSRegion, Usage: "AWS region to use for assume role", Value: "us-east-1", }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_ROLE", "AWS_CREDENTIALS_ROLE"}, FilePath: "/vela/parameters/aws-credentials/role,/vela/secrets/aws-credentials/role", Name: FlagAWSRole, Usage: "AWS IAM role to assume", }, &cli.IntFlag{ EnvVars: []string{"PARAMETER_ROLE_DURATION_SECONDS", "AWS_CREDENTIALS_ROLE_DURATION_SECONDS"}, FilePath: "/vela/parameters/aws-credentials/role_duration_seconds,/vela/secrets/aws-credentials/role_duration_seconds", Name: FlagAWSRoleDurationSeconds, Usage: "Role duration in seconds", Value: 3600, }, &cli.StringFlag{ EnvVars: []string{"PARAMETER_ROLE_SESSION_NAME", "AWS_CREDENTIALS_ROLE_SESSION_NAME"}, FilePath: "/vela/parameters/aws-credentials/role_session_name,/vela/secrets/aws-credentials/role_session_name", Name: FlagAWSRoleSessionName, Usage: "Role session name", Value: "vela", }, &cli.IntFlag{ EnvVars: []string{"VELA_BUILD_NUMBER", "BUILD_NUMBER"}, Name: FlagVelaBuildNumber, Usage: "environment variable reference for reading in build number", }, &cli.StringFlag{ EnvVars: []string{"VELA_ID_TOKEN_REQUEST_TOKEN"}, Name: FlagVelaIDTokenRequestToken, Usage: "environment variable reference for reading in OIDC request token", }, &cli.StringFlag{ EnvVars: []string{"VELA_ID_TOKEN_REQUEST_URL"}, Name: FlagVelaIDTokenRequestURL, Usage: "environment variable reference for reading in OIDC request token URL", }, &cli.StringFlag{ EnvVars: []string{"VELA_REPO_ORG", "REPOSITORY_ORG"}, Name: FlagVelaOrgName, Usage: "environment variable reference for reading in repository org", }, &cli.StringFlag{ EnvVars: []string{"VELA_REPO_NAME", "REPOSITORY_NAME"}, Name: FlagVelaRepoName, Usage: "environment variable reference for reading in repository name", }, } )
Functions ¶
This section is empty.
Types ¶
type AWS ¶
type AWS struct {
Region string
Role string
RoleDurationSeconds int
RoleSessionName string
InlineSessionPolicy string
ManagedSessionPolicies []string
}
AWS struct represents the config for the AWS role assumption.
type Config ¶
type Config struct {
Audience string
Verify bool
ScriptPath string
ScriptFormat string
ScriptWrite bool
AWS *AWS
Vela *Vela
Logger *logrus.Entry
}
Config struct represents fields user can present to plugin.
func FromCLIContext ¶ added in v0.5.0
FromCLIContext creates and returns a plugin from the urfave/cli context.
func (*Config) AssumeRole ¶
func (c *Config) AssumeRole(token string) (*aws.Credentials, error)
func (*Config) GenerateVelaToken ¶
func (*Config) WriteCreds ¶
func (c *Config) WriteCreds(creds *aws.Credentials) error
Click to show internal directories.
Click to hide internal directories.