mirror of
https://github.com/storytold/irsa-manager.git
synced 2026-10-09 00:09:43 +00:00
aws S3Client
This commit is contained in:
@@ -0,0 +1,53 @@
|
||||
package client
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"fmt"
|
||||
|
||||
"github.com/aws/aws-sdk-go-v2/aws"
|
||||
"github.com/aws/aws-sdk-go-v2/config"
|
||||
"github.com/aws/aws-sdk-go-v2/service/s3"
|
||||
)
|
||||
|
||||
type AwsConfig struct {
|
||||
config aws.Config
|
||||
}
|
||||
|
||||
func NewAwsClient(ctx context.Context, region string) (*AwsConfig, error) {
|
||||
cfg, err := config.LoadDefaultConfig(ctx,
|
||||
config.WithRegion(region),
|
||||
)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("unable to load SDK config, %w", err)
|
||||
}
|
||||
return &AwsConfig{config: cfg}, nil
|
||||
}
|
||||
|
||||
func (a *AwsConfig) S3Cient(bucketName string) *AwsS3Client {
|
||||
return &AwsS3Client{
|
||||
bucketName,
|
||||
s3.NewFromConfig(a.config),
|
||||
}
|
||||
}
|
||||
|
||||
type AwsS3Client struct {
|
||||
bucketName string
|
||||
client *s3.Client
|
||||
}
|
||||
|
||||
func (a *AwsS3Client) PutObject(ctx context.Context, key string, body []byte) error {
|
||||
_, err := a.client.PutObject(ctx, &s3.PutObjectInput{
|
||||
Bucket: aws.String(a.bucketName),
|
||||
Key: aws.String(key),
|
||||
Body: bytes.NewReader(body),
|
||||
})
|
||||
return err
|
||||
}
|
||||
|
||||
func (a *AwsS3Client) CreateBucket(ctx context.Context) error {
|
||||
_, err := a.client.CreateBucket(ctx, &s3.CreateBucketInput{
|
||||
Bucket: aws.String(a.bucketName),
|
||||
})
|
||||
return err
|
||||
}
|
||||
@@ -1,35 +1,12 @@
|
||||
package selfhosted
|
||||
|
||||
import "fmt"
|
||||
|
||||
type OIDCIdProvider interface {
|
||||
Discovery() string
|
||||
JWK() string
|
||||
Discovery() []byte
|
||||
JWK() []byte
|
||||
Endpoint() string
|
||||
}
|
||||
|
||||
type OIDCIdPCreator interface {
|
||||
CreateStorage() error
|
||||
Upload(o OIDCIdProvider) error
|
||||
CreateProvider() error
|
||||
}
|
||||
|
||||
type S3IdPCreator struct {
|
||||
region string
|
||||
bucketName string
|
||||
}
|
||||
|
||||
func (s *S3IdPCreator) CreateProvider() error {
|
||||
// create S3 Bucket // bucketName, Region
|
||||
// create OIDCProvider //
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s *S3IdPCreator) Upload(o OIDCIdProvider) error {
|
||||
o.Discovery() // Upload to Endpoint()/.well-known/openid-configuration
|
||||
o.JWK() // Upload to Endpoint()/keys.json
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s *S3IdPCreator) issuerHostPath() string {
|
||||
hostName := fmt.Sprintf("s3-%s.amazonaws.com", s.region)
|
||||
return fmt.Sprintf("%s/%s", hostName, s.bucketName)
|
||||
}
|
||||
|
||||
@@ -0,0 +1,17 @@
|
||||
package oidc
|
||||
|
||||
type MyIdProvider struct {
|
||||
}
|
||||
|
||||
func (p *MyIdProvider) Discovery() []byte {
|
||||
return []byte{}
|
||||
|
||||
}
|
||||
func (p *MyIdProvider) JWK() []byte {
|
||||
return []byte{}
|
||||
|
||||
}
|
||||
func (p *MyIdProvider) Endpoint() []byte {
|
||||
return []byte{}
|
||||
|
||||
}
|
||||
@@ -0,0 +1,66 @@
|
||||
package oidc
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
|
||||
"github.com/kkb0318/irsa-manager/internal/client"
|
||||
"github.com/kkb0318/irsa-manager/internal/selfhosted"
|
||||
)
|
||||
|
||||
const CONFIGURATION_PATH = ".well-known/openid-configuration"
|
||||
|
||||
type S3IdPCreator struct {
|
||||
s3Client *client.AwsS3Client
|
||||
}
|
||||
|
||||
// NewS3IdPCreator initializes a new instance of S3IdPCreator with the specified AWS region and bucket name.
|
||||
// This function attempts to create an AWS client configured for the specified region.
|
||||
func NewS3IdPCreator(region, bucketName string) (*S3IdPCreator, error) {
|
||||
ctx := context.Background()
|
||||
awsConfig, err := client.NewAwsClient(ctx, region)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("unable to load SDK config, %w", err)
|
||||
}
|
||||
s3Client := awsConfig.S3Cient(bucketName)
|
||||
return &S3IdPCreator{s3Client}, nil
|
||||
}
|
||||
|
||||
|
||||
// CreateStorage creates an S3 bucket
|
||||
func (s *S3IdPCreator) CreateStorage() error {
|
||||
err := s.s3Client.CreateBucket(context.TODO())
|
||||
if err != nil {
|
||||
return fmt.Errorf("unable to create bucket, %w", err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// Upload uploads the OIDC provider's discovery configuration and JSON Web Key Set (JWKS) to the specified AWS S3 bucket.
|
||||
// This method is responsible for uploading the necessary OIDC configuration files to S3, making them accessible for OIDC clients.
|
||||
func (s *S3IdPCreator) Upload(ctx context.Context, o selfhosted.OIDCIdProvider) error {
|
||||
err := s.s3Client.PutObject(ctx,
|
||||
CONFIGURATION_PATH,
|
||||
o.Discovery(),
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("unable to upload discovery document, %w", err)
|
||||
}
|
||||
|
||||
// Uplaod JWK
|
||||
err = s.s3Client.PutObject(ctx,
|
||||
"keys.json",
|
||||
o.JWK(),
|
||||
)
|
||||
if err != nil {
|
||||
return fmt.Errorf("unable to upload JWK, %w", err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
// issuerHostPath constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name.
|
||||
// This utility function generates the expected host path for accessing the OIDC configuration stored in an S3 bucket.
|
||||
func issuerHostPath(region, bucketName string) string {
|
||||
hostName := fmt.Sprintf("s3-%s.amazonaws.com", region)
|
||||
return fmt.Sprintf("%s/%s", hostName, bucketName)
|
||||
}
|
||||
Reference in New Issue
Block a user