base.go 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175
  1. package integration
  2. import (
  3. "github.com/aliyun/alibaba-cloud-sdk-go/services/ram"
  4. "github.com/aliyun/alibaba-cloud-sdk-go/services/sts"
  5. "fmt"
  6. "os"
  7. "strings"
  8. )
  9. var role_doc = `{
  10. "Statement": [{
  11. "Action": "sts:AssumeRole",
  12. "Effect": "Allow",
  13. "Principal": {
  14. "RAM": [
  15. "acs:ram::%s:root"
  16. ]
  17. }
  18. }],
  19. "Version": "1"
  20. }`
  21. var (
  22. username = "testuser" + strings.Split(os.Getenv("TRAVIS_JOB_NUMBER"), ".")[0]
  23. rolename = "testrole" + strings.Split(os.Getenv("TRAVIS_JOB_NUMBER"), ".")[0]
  24. )
  25. func createRole(userid string) (string, string, error) {
  26. listRequest := ram.CreateListRolesRequest()
  27. listRequest.Scheme = "HTTPS"
  28. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  29. if err != nil {
  30. return "", "", err
  31. }
  32. listResponse, err := client.ListRoles(listRequest)
  33. if err != nil {
  34. return "", "", err
  35. }
  36. for _, role := range listResponse.Roles.Role {
  37. if strings.ToLower(role.RoleName) == rolename {
  38. return role.RoleName, role.Arn, nil
  39. }
  40. }
  41. createRequest := ram.CreateCreateRoleRequest()
  42. createRequest.Scheme = "HTTPS"
  43. createRequest.RoleName = rolename
  44. createRequest.AssumeRolePolicyDocument = fmt.Sprintf(role_doc, userid)
  45. res, err := client.CreateRole(createRequest)
  46. if err != nil {
  47. return "", "", err
  48. }
  49. return res.Role.RoleName, res.Role.Arn, nil
  50. }
  51. func createUser() error {
  52. listRequest := ram.CreateListUsersRequest()
  53. listRequest.Scheme = "HTTPS"
  54. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  55. if err != nil {
  56. return err
  57. }
  58. listResponse, err := client.ListUsers(listRequest)
  59. if err != nil {
  60. return err
  61. }
  62. for _, user := range listResponse.Users.User {
  63. if user.UserName == username {
  64. return nil
  65. }
  66. }
  67. createRequest := ram.CreateCreateUserRequest()
  68. createRequest.Scheme = "HTTPS"
  69. createRequest.UserName = username
  70. _, err = client.CreateUser(createRequest)
  71. if err != nil {
  72. return err
  73. }
  74. return nil
  75. }
  76. func createAttachPolicyToUser() error {
  77. listRequest := ram.CreateListPoliciesForUserRequest()
  78. listRequest.UserName = username
  79. listRequest.Scheme = "HTTPS"
  80. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  81. if err != nil {
  82. return err
  83. }
  84. listResponse, err := client.ListPoliciesForUser(listRequest)
  85. if err != nil {
  86. return err
  87. }
  88. for _, policy := range listResponse.Policies.Policy {
  89. if policy.PolicyName == "AliyunSTSAssumeRoleAccess" {
  90. return nil
  91. }
  92. }
  93. createRequest := ram.CreateAttachPolicyToUserRequest()
  94. createRequest.Scheme = "HTTPS"
  95. createRequest.PolicyName = "AliyunSTSAssumeRoleAccess"
  96. createRequest.UserName = username
  97. createRequest.PolicyType = "System"
  98. _, err = client.AttachPolicyToUser(createRequest)
  99. if err != nil {
  100. return err
  101. }
  102. return nil
  103. }
  104. func createAccessKey() (string, string, error) {
  105. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  106. if err != nil {
  107. return "", "", err
  108. }
  109. listrequest := ram.CreateListAccessKeysRequest()
  110. listrequest.UserName = username
  111. listrequest.Scheme = "HTTPS"
  112. listresponse, err := client.ListAccessKeys(listrequest)
  113. if err != nil {
  114. return "", "", err
  115. }
  116. if listresponse.AccessKeys.AccessKey != nil {
  117. if len(listresponse.AccessKeys.AccessKey) >= 2 {
  118. accesskey := listresponse.AccessKeys.AccessKey[0]
  119. deleterequest := ram.CreateDeleteAccessKeyRequest()
  120. deleterequest.UserAccessKeyId = accesskey.AccessKeyId
  121. deleterequest.UserName = username
  122. deleterequest.Scheme = "HTTPS"
  123. _, err := client.DeleteAccessKey(deleterequest)
  124. if err != nil {
  125. return "", "", err
  126. }
  127. }
  128. }
  129. request := ram.CreateCreateAccessKeyRequest()
  130. request.Scheme = "HTTPS"
  131. request.UserName = username
  132. response, err := client.CreateAccessKey(request)
  133. if err != nil {
  134. return "", "", err
  135. }
  136. return response.AccessKey.AccessKeyId, response.AccessKey.AccessKeySecret, nil
  137. }
  138. func createAssumeRole() (*sts.AssumeRoleResponse, error) {
  139. err := createUser()
  140. if err != nil {
  141. return nil, err
  142. }
  143. _, _, err = createRole(os.Getenv("USER_ID"))
  144. if err != nil {
  145. return nil, err
  146. }
  147. err = createAttachPolicyToUser()
  148. if err != nil {
  149. return nil, err
  150. }
  151. subaccesskeyid, subaccesskeysecret, err := createAccessKey()
  152. if err != nil {
  153. return nil, err
  154. }
  155. request := sts.CreateAssumeRoleRequest()
  156. request.RoleArn = fmt.Sprintf("acs:ram::%s:role/testrole", os.Getenv("USER_ID"))
  157. request.RoleSessionName = "alice_test"
  158. request.Scheme = "HTTPS"
  159. client, err := sts.NewClientWithAccessKey("cn-hangzhou", subaccesskeyid, subaccesskeysecret)
  160. response, err := client.AssumeRole(request)
  161. if err != nil {
  162. return nil, err
  163. }
  164. return response, nil
  165. }