base.go 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. package integration
  2. import (
  3. "github.com/aliyun/alibaba-cloud-sdk-go/services/ram"
  4. "github.com/aliyun/alibaba-cloud-sdk-go/services/sts"
  5. "fmt"
  6. "os"
  7. "strings"
  8. )
  9. var role_doc = `{
  10. "Statement": [{
  11. "Action": "sts:AssumeRole",
  12. "Effect": "Allow",
  13. "Principal": {
  14. "RAM": [
  15. "acs:ram::%s:root"
  16. ]
  17. }
  18. }],
  19. "Version": "1"
  20. }`
  21. var (
  22. travisValue = strings.Split(os.Getenv("TRAVIS_JOB_NUMBER"), ".")
  23. username = "testuser" + travisValue[len(travisValue)-1]
  24. rolename = "testrole" + travisValue[len(travisValue)-1]
  25. )
  26. func createRole(userid string) (string, string, error) {
  27. listRequest := ram.CreateListRolesRequest()
  28. listRequest.Scheme = "HTTPS"
  29. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  30. if err != nil {
  31. return "", "", err
  32. }
  33. listResponse, err := client.ListRoles(listRequest)
  34. if err != nil {
  35. return "", "", err
  36. }
  37. for _, role := range listResponse.Roles.Role {
  38. if strings.ToLower(role.RoleName) == rolename {
  39. return role.RoleName, role.Arn, nil
  40. }
  41. }
  42. createRequest := ram.CreateCreateRoleRequest()
  43. createRequest.Scheme = "HTTPS"
  44. createRequest.RoleName = rolename
  45. createRequest.AssumeRolePolicyDocument = fmt.Sprintf(role_doc, userid)
  46. res, err := client.CreateRole(createRequest)
  47. if err != nil {
  48. return "", "", err
  49. }
  50. return res.Role.RoleName, res.Role.Arn, nil
  51. }
  52. func createUser() error {
  53. listRequest := ram.CreateListUsersRequest()
  54. listRequest.Scheme = "HTTPS"
  55. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  56. if err != nil {
  57. return err
  58. }
  59. listResponse, err := client.ListUsers(listRequest)
  60. if err != nil {
  61. return err
  62. }
  63. for _, user := range listResponse.Users.User {
  64. if user.UserName == username {
  65. return nil
  66. }
  67. }
  68. createRequest := ram.CreateCreateUserRequest()
  69. createRequest.Scheme = "HTTPS"
  70. createRequest.UserName = username
  71. _, err = client.CreateUser(createRequest)
  72. if err != nil {
  73. return err
  74. }
  75. return nil
  76. }
  77. func createAttachPolicyToUser() error {
  78. listRequest := ram.CreateListPoliciesForUserRequest()
  79. listRequest.UserName = username
  80. listRequest.Scheme = "HTTPS"
  81. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  82. if err != nil {
  83. return err
  84. }
  85. listResponse, err := client.ListPoliciesForUser(listRequest)
  86. if err != nil {
  87. return err
  88. }
  89. for _, policy := range listResponse.Policies.Policy {
  90. if policy.PolicyName == "AliyunSTSAssumeRoleAccess" {
  91. return nil
  92. }
  93. }
  94. createRequest := ram.CreateAttachPolicyToUserRequest()
  95. createRequest.Scheme = "HTTPS"
  96. createRequest.PolicyName = "AliyunSTSAssumeRoleAccess"
  97. createRequest.UserName = username
  98. createRequest.PolicyType = "System"
  99. _, err = client.AttachPolicyToUser(createRequest)
  100. if err != nil {
  101. return err
  102. }
  103. return nil
  104. }
  105. func createAccessKey() (string, string, error) {
  106. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  107. if err != nil {
  108. return "", "", err
  109. }
  110. listrequest := ram.CreateListAccessKeysRequest()
  111. listrequest.UserName = username
  112. listrequest.Scheme = "HTTPS"
  113. listresponse, err := client.ListAccessKeys(listrequest)
  114. if err != nil {
  115. return "", "", err
  116. }
  117. if listresponse.AccessKeys.AccessKey != nil {
  118. if len(listresponse.AccessKeys.AccessKey) >= 2 {
  119. accesskey := listresponse.AccessKeys.AccessKey[0]
  120. deleterequest := ram.CreateDeleteAccessKeyRequest()
  121. deleterequest.UserAccessKeyId = accesskey.AccessKeyId
  122. deleterequest.UserName = username
  123. deleterequest.Scheme = "HTTPS"
  124. _, err := client.DeleteAccessKey(deleterequest)
  125. if err != nil {
  126. return "", "", err
  127. }
  128. }
  129. }
  130. request := ram.CreateCreateAccessKeyRequest()
  131. request.Scheme = "HTTPS"
  132. request.UserName = username
  133. response, err := client.CreateAccessKey(request)
  134. if err != nil {
  135. return "", "", err
  136. }
  137. return response.AccessKey.AccessKeyId, response.AccessKey.AccessKeySecret, nil
  138. }
  139. func createAssumeRole() (*sts.AssumeRoleResponse, error) {
  140. err := createUser()
  141. if err != nil {
  142. return nil, err
  143. }
  144. _, _, err = createRole(os.Getenv("USER_ID"))
  145. if err != nil {
  146. return nil, err
  147. }
  148. err = createAttachPolicyToUser()
  149. if err != nil {
  150. return nil, err
  151. }
  152. subaccesskeyid, subaccesskeysecret, err := createAccessKey()
  153. if err != nil {
  154. return nil, err
  155. }
  156. request := sts.CreateAssumeRoleRequest()
  157. request.RoleArn = fmt.Sprintf("acs:ram::%s:role/testrole", os.Getenv("USER_ID"))
  158. request.RoleSessionName = "alice_test"
  159. request.Scheme = "HTTPS"
  160. client, err := sts.NewClientWithAccessKey("cn-hangzhou", subaccesskeyid, subaccesskeysecret)
  161. response, err := client.AssumeRole(request)
  162. if err != nil {
  163. return nil, err
  164. }
  165. return response, nil
  166. }