mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
aws S3 bucket public
This commit is contained in:
+12
-3
@@ -4,11 +4,13 @@ import (
|
|||||||
"bytes"
|
"bytes"
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"strings"
|
||||||
|
|
||||||
"github.com/aws/aws-sdk-go-v2/aws"
|
"github.com/aws/aws-sdk-go-v2/aws"
|
||||||
"github.com/aws/aws-sdk-go-v2/config"
|
"github.com/aws/aws-sdk-go-v2/config"
|
||||||
"github.com/aws/aws-sdk-go-v2/service/iam"
|
"github.com/aws/aws-sdk-go-v2/service/iam"
|
||||||
"github.com/aws/aws-sdk-go-v2/service/s3"
|
"github.com/aws/aws-sdk-go-v2/service/s3"
|
||||||
|
"github.com/aws/aws-sdk-go-v2/service/s3/types"
|
||||||
)
|
)
|
||||||
|
|
||||||
type AwsConfig struct {
|
type AwsConfig struct {
|
||||||
@@ -54,7 +56,12 @@ func (a *AwsS3Client) PutObject(ctx context.Context, key string, body []byte) er
|
|||||||
|
|
||||||
func (a *AwsS3Client) CreateBucket(ctx context.Context) error {
|
func (a *AwsS3Client) CreateBucket(ctx context.Context) error {
|
||||||
_, err := a.client.CreateBucket(ctx, &s3.CreateBucketInput{
|
_, err := a.client.CreateBucket(ctx, &s3.CreateBucketInput{
|
||||||
|
ACL: types.BucketCannedACLPublicRead,
|
||||||
Bucket: aws.String(a.bucketName),
|
Bucket: aws.String(a.bucketName),
|
||||||
|
CreateBucketConfiguration: &types.CreateBucketConfiguration{
|
||||||
|
LocationConstraint: types.BucketLocationConstraint(a.Region()),
|
||||||
|
},
|
||||||
|
ObjectOwnership: types.ObjectOwnershipBucketOwnerPreferred,
|
||||||
})
|
})
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -73,9 +80,11 @@ type AwsIamClient struct {
|
|||||||
|
|
||||||
func (a *AwsIamClient) CreateOIDCProvider(ctx context.Context, providerUrl string) (string, error) {
|
func (a *AwsIamClient) CreateOIDCProvider(ctx context.Context, providerUrl string) (string, error) {
|
||||||
result, err := a.client.CreateOpenIDConnectProvider(ctx, &iam.CreateOpenIDConnectProviderInput{
|
result, err := a.client.CreateOpenIDConnectProvider(ctx, &iam.CreateOpenIDConnectProviderInput{
|
||||||
Url: &providerUrl,
|
Url: &providerUrl,
|
||||||
ClientIDList: []string{"sts.amazonaws.com"},
|
ClientIDList: []string{"sts.amazonaws.com"},
|
||||||
ThumbprintList: []string{},
|
ThumbprintList: []string{
|
||||||
|
strings.Repeat("x", 40), // Thumbprint is required, but IAM will retrieve and use the top intermediate CA thumbprint of the OpenID Connect identity provider server certificate.
|
||||||
|
},
|
||||||
})
|
})
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return "", err
|
return "", err
|
||||||
|
|||||||
@@ -51,7 +51,15 @@ var _ = Describe("IRSASetup Controller", func() {
|
|||||||
Name: resourceName,
|
Name: resourceName,
|
||||||
Namespace: "default",
|
Namespace: "default",
|
||||||
},
|
},
|
||||||
// TODO(user): Specify other spec details if needed.
|
Spec: irsav1alpha1.IRSASetupSpec{
|
||||||
|
Mode: "selfhoted",
|
||||||
|
Discovery: irsav1alpha1.Discovery{
|
||||||
|
S3: irsav1alpha1.S3Discovery{
|
||||||
|
Region: "ap-northeast-1",
|
||||||
|
BucketName: "irsa-manager-kkb-1",
|
||||||
|
},
|
||||||
|
},
|
||||||
|
},
|
||||||
}
|
}
|
||||||
Expect(k8sClient.Create(ctx, resource)).To(Succeed())
|
Expect(k8sClient.Create(ctx, resource)).To(Succeed())
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user