base.go 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171
  1. package integration
  2. import (
  3. "github.com/aliyun/alibaba-cloud-sdk-go/services/ram"
  4. "github.com/aliyun/alibaba-cloud-sdk-go/services/sts"
  5. "fmt"
  6. "os"
  7. "strings"
  8. )
  9. var role_doc = `{
  10. "Statement": [{
  11. "Action": "sts:AssumeRole",
  12. "Effect": "Allow",
  13. "Principal": {
  14. "RAM": [
  15. "acs:ram::%s:root"
  16. ]
  17. }
  18. }],
  19. "Version": "1"
  20. }`
  21. func createRole(userid string) (string, string, error) {
  22. ram.CreateGetRoleRequest()
  23. listRequest := ram.CreateListRolesRequest()
  24. listRequest.Scheme = "HTTPS"
  25. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  26. if err != nil {
  27. return "", "", err
  28. }
  29. listResponse, err := client.ListRoles(listRequest)
  30. if err != nil {
  31. return "", "", err
  32. }
  33. for _, role := range listResponse.Roles.Role {
  34. if strings.ToLower(role.RoleName) == "testrole" {
  35. return role.RoleName, role.Arn, nil
  36. }
  37. }
  38. createRequest := ram.CreateCreateRoleRequest()
  39. createRequest.Scheme = "HTTPS"
  40. createRequest.RoleName = "testrole"
  41. createRequest.AssumeRolePolicyDocument = fmt.Sprintf(role_doc, userid)
  42. res, err := client.CreateRole(createRequest)
  43. if err != nil {
  44. return "", "", err
  45. }
  46. return res.Role.RoleName, res.Role.Arn, nil
  47. }
  48. func createUser() error {
  49. listRequest := ram.CreateListUsersRequest()
  50. listRequest.Scheme = "HTTPS"
  51. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  52. if err != nil {
  53. return err
  54. }
  55. listResponse, err := client.ListUsers(listRequest)
  56. if err != nil {
  57. return err
  58. }
  59. for _, user := range listResponse.Users.User {
  60. if user.UserName == "alice" {
  61. return nil
  62. }
  63. }
  64. createRequest := ram.CreateCreateUserRequest()
  65. createRequest.Scheme = "HTTPS"
  66. createRequest.UserName = "alice"
  67. _, err = client.CreateUser(createRequest)
  68. if err != nil {
  69. return err
  70. }
  71. return nil
  72. }
  73. func createAttachPolicyToUser() error {
  74. listRequest := ram.CreateListPoliciesForUserRequest()
  75. listRequest.UserName = "alice"
  76. listRequest.Scheme = "HTTPS"
  77. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  78. if err != nil {
  79. return err
  80. }
  81. listResponse, err := client.ListPoliciesForUser(listRequest)
  82. if err != nil {
  83. return err
  84. }
  85. for _, policy := range listResponse.Policies.Policy {
  86. if policy.PolicyName == "AliyunSTSAssumeRoleAccess" {
  87. return nil
  88. }
  89. }
  90. createRequest := ram.CreateAttachPolicyToUserRequest()
  91. createRequest.Scheme = "HTTPS"
  92. createRequest.PolicyName = "AliyunSTSAssumeRoleAccess"
  93. createRequest.UserName = "alice"
  94. createRequest.PolicyType = "System"
  95. _, err = client.AttachPolicyToUser(createRequest)
  96. if err != nil {
  97. return err
  98. }
  99. return nil
  100. }
  101. func createAccessKey() (string, string, error) {
  102. client, err := ram.NewClientWithAccessKey("cn-hangzhou", os.Getenv("ACCESS_KEY_ID"), os.Getenv("ACCESS_KEY_SECRET"))
  103. if err != nil {
  104. return "", "", err
  105. }
  106. listrequest := ram.CreateListAccessKeysRequest()
  107. listrequest.UserName = "alice"
  108. listrequest.Scheme = "HTTPS"
  109. listresponse, err := client.ListAccessKeys(listrequest)
  110. if err != nil {
  111. return "", "", err
  112. }
  113. if listresponse.AccessKeys.AccessKey != nil {
  114. if len(listresponse.AccessKeys.AccessKey) >= 2 {
  115. accesskey := listresponse.AccessKeys.AccessKey[0]
  116. deleterequest := ram.CreateDeleteAccessKeyRequest()
  117. deleterequest.UserAccessKeyId = accesskey.AccessKeyId
  118. deleterequest.UserName = "alice"
  119. deleterequest.Scheme = "HTTPS"
  120. _, err := client.DeleteAccessKey(deleterequest)
  121. if err != nil {
  122. return "", "", err
  123. }
  124. }
  125. }
  126. request := ram.CreateCreateAccessKeyRequest()
  127. request.Scheme = "HTTPS"
  128. request.UserName = "alice"
  129. response, err := client.CreateAccessKey(request)
  130. if err != nil {
  131. return "", "", err
  132. }
  133. return response.AccessKey.AccessKeyId, response.AccessKey.AccessKeySecret, nil
  134. }
  135. func createAssumeRole() (*sts.AssumeRoleResponse, error) {
  136. err := createUser()
  137. if err != nil {
  138. return nil, err
  139. }
  140. _, _, err = createRole(os.Getenv("USER_ID"))
  141. if err != nil {
  142. return nil, err
  143. }
  144. err = createAttachPolicyToUser()
  145. if err != nil {
  146. return nil, err
  147. }
  148. subaccesskeyid, subaccesskeysecret, err := createAccessKey()
  149. if err != nil {
  150. return nil, err
  151. }
  152. request := sts.CreateAssumeRoleRequest()
  153. request.RoleArn = fmt.Sprintf("acs:ram::%s:role/testrole", os.Getenv("USER_ID"))
  154. request.RoleSessionName = "alice_test"
  155. request.Scheme = "HTTPS"
  156. client, err := sts.NewClientWithAccessKey("cn-hangzhou", subaccesskeyid, subaccesskeysecret)
  157. response, err := client.AssumeRole(request)
  158. if err != nil {
  159. return nil, err
  160. }
  161. return response, nil
  162. }