create Idp

This commit is contained in:
kkb0318
2024-03-31 20:30:15 +09:00
parent ac571e3a97
commit d40d78ca98
8 changed files with 159 additions and 72 deletions
+11 -4
View File
@@ -2,13 +2,20 @@ package selfhosted
import "context"
type OIDCIdProvider interface {
type OIDCIdPDiscoveryContents interface {
Discovery() ([]byte, error)
JWK() ([]byte, error)
JWKsFileName() string
}
type OIDCIdPDiscovery interface {
CreateStorage() error
Upload(ctx context.Context, o OIDCIdPDiscoveryContents) error
Endpoint() string
}
type OIDCIdPCreator interface {
CreateStorage() error
Upload(ctx context.Context, o OIDCIdProvider) error
type OIDCIdP interface {
Create(ctx context.Context) (string, error)
IsUpdate() (bool, error)
Update(ctx context.Context) error
}
+16 -39
View File
@@ -1,57 +1,34 @@
package oidc
import (
"encoding/json"
"fmt"
"context"
"github.com/kkb0318/irsa-manager/internal/client"
"github.com/kkb0318/irsa-manager/internal/selfhosted"
)
type IdProvider struct {
jwk *selfhosted.JWK
issuerHostPath string
jwksFileName string
type AwsIdP struct {
iamClient *client.AwsIamClient
discovery selfhosted.OIDCIdPDiscovery
}
type OIDCDiscoveryConfiguration struct {
Issuer string `json:"issuer"`
JWKSURI string `json:"jwks_uri"`
AuthorizationEndpoint string `json:"authorization_endpoint"`
ResponseTypesSupported []string `json:"response_types_supported"`
SubjectTypesSupported []string `json:"subject_types_supported"`
IDTokenSigningAlgValuesSupported []string `json:"id_token_signing_alg_values_supported"`
ClaimsSupported []string `json:"claims_supported"`
func NewAwsIdP(awsConfig *client.AwsConfig, discovery selfhosted.OIDCIdPDiscovery) (*AwsIdP, error) {
iamClient := awsConfig.IamCient()
return &AwsIdP{iamClient, discovery}, nil
}
func (p *IdProvider) Discovery() ([]byte, error) {
oidcConfig := OIDCDiscoveryConfiguration{
Issuer: fmt.Sprintf("https://%s/", p.issuerHostPath),
JWKSURI: fmt.Sprintf("https://%s/%s", p.issuerHostPath, p.jwksFileName),
AuthorizationEndpoint: "urn:kubernetes:programmatic_authorization",
ResponseTypesSupported: []string{"id_token"},
SubjectTypesSupported: []string{"public"},
IDTokenSigningAlgValuesSupported: []string{"RS256"},
ClaimsSupported: []string{"sub", "iss"},
}
jsonData, err := json.MarshalIndent(oidcConfig, "", " ")
func (a *AwsIdP) Create(ctx context.Context) (string, error) {
arn, err := a.iamClient.CreateOIDCProvider(ctx, a.discovery.Endpoint())
if err != nil {
return nil, err
return "", err
}
return jsonData, nil
return arn, nil
}
func (p *IdProvider) JWK() ([]byte, error) {
jsonData, err := json.MarshalIndent(p.jwk.GetKeys(), "", " ")
if err != nil {
return nil, err
}
return jsonData, nil
func (a *AwsIdP) Update(ctx context.Context) error {
return nil
}
func (p *IdProvider) Endpoint() string {
return ""
}
func NewIdProvider(jwk *selfhosted.JWK, issuerHostPath, jwksFileName string) *IdProvider {
return &IdProvider{jwk, issuerHostPath, jwksFileName}
func (a *AwsIdP) IsUpdate() (bool, error) {
return false, nil
}
@@ -10,19 +10,19 @@ import (
const CONFIGURATION_PATH = ".well-known/openid-configuration"
type S3IdPCreator struct {
type S3IdPDiscovery struct {
s3Client *client.AwsS3Client
}
// NewS3IdPCreator initializes a new instance of S3IdPCreator with the specified AWS region and bucket name.
// NewS3IdPDiscovery initializes a new instance of S3IdPCreator with the specified AWS region and bucket name.
// This function attempts to create an AWS client configured for the specified region.
func NewS3IdPCreator(awsConfig *client.AwsConfig, bucketName string) (*S3IdPCreator, error) {
func NewS3IdPDiscovery(awsConfig *client.AwsConfig, bucketName string) (*S3IdPDiscovery, error) {
s3Client := awsConfig.S3Cient(bucketName)
return &S3IdPCreator{s3Client}, nil
return &S3IdPDiscovery{s3Client}, nil
}
// CreateStorage creates an S3 bucket
func (s *S3IdPCreator) CreateStorage() error {
func (s *S3IdPDiscovery) CreateStorage() error {
err := s.s3Client.CreateBucket(context.TODO())
if err != nil {
return fmt.Errorf("unable to create bucket, %w", err)
@@ -32,7 +32,7 @@ func (s *S3IdPCreator) CreateStorage() error {
// Upload uploads the OIDC provider's discovery configuration and JSON Web Key Set (JWKS) to the specified AWS S3 bucket.
// This method is responsible for uploading the necessary OIDC configuration files to S3, making them accessible for OIDC clients.
func (s *S3IdPCreator) Upload(ctx context.Context, o selfhosted.OIDCIdProvider) error {
func (s *S3IdPDiscovery) Upload(ctx context.Context, o selfhosted.OIDCIdPDiscoveryContents) error {
discovery, err := o.Discovery()
if err != nil {
return nil
@@ -51,7 +51,7 @@ func (s *S3IdPCreator) Upload(ctx context.Context, o selfhosted.OIDCIdProvider)
return nil
}
err = s.s3Client.PutObject(ctx,
"keys.json",
o.JWKsFileName(),
jwk,
)
if err != nil {
@@ -60,9 +60,8 @@ func (s *S3IdPCreator) Upload(ctx context.Context, o selfhosted.OIDCIdProvider)
return nil
}
// issuerHostPath constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name.
// Endpoint constructs the URL path for the OIDC issuer based on the provided AWS region and bucket name.
// This utility function generates the expected host path for accessing the OIDC configuration stored in an S3 bucket.
func issuerHostPath(region, bucketName string) string {
hostName := fmt.Sprintf("s3-%s.amazonaws.com", region)
return fmt.Sprintf("%s/%s", hostName, bucketName)
func (p *S3IdPDiscovery) Endpoint() string {
return fmt.Sprintf("s3-%s.amazonaws.com/%s", p.s3Client.Region(), p.s3Client.BucketName())
}
@@ -0,0 +1,57 @@
package oidc
import (
"encoding/json"
"fmt"
"github.com/kkb0318/irsa-manager/internal/selfhosted"
)
type IdPDiscoveryContents struct {
jwk *selfhosted.JWK
issuerHostPath string
jwksFileName string
}
type oidcDiscoveryConfiguration struct {
Issuer string `json:"issuer"`
JWKSURI string `json:"jwks_uri"`
AuthorizationEndpoint string `json:"authorization_endpoint"`
ResponseTypesSupported []string `json:"response_types_supported"`
SubjectTypesSupported []string `json:"subject_types_supported"`
IDTokenSigningAlgValuesSupported []string `json:"id_token_signing_alg_values_supported"`
ClaimsSupported []string `json:"claims_supported"`
}
func (p *IdPDiscoveryContents) Discovery() ([]byte, error) {
oidcConfig := oidcDiscoveryConfiguration{
Issuer: fmt.Sprintf("https://%s/", p.issuerHostPath),
JWKSURI: fmt.Sprintf("https://%s/%s", p.issuerHostPath, p.jwksFileName),
AuthorizationEndpoint: "urn:kubernetes:programmatic_authorization",
ResponseTypesSupported: []string{"id_token"},
SubjectTypesSupported: []string{"public"},
IDTokenSigningAlgValuesSupported: []string{"RS256"},
ClaimsSupported: []string{"sub", "iss"},
}
jsonData, err := json.MarshalIndent(oidcConfig, "", " ")
if err != nil {
return nil, err
}
return jsonData, nil
}
func (p *IdPDiscoveryContents) JWK() ([]byte, error) {
jsonData, err := json.MarshalIndent(p.jwk.GetKeys(), "", " ")
if err != nil {
return nil, err
}
return jsonData, nil
}
func (p *IdPDiscoveryContents) JWKsFileName() string {
return p.jwksFileName
}
func NewIdPDiscoveryContents(jwk *selfhosted.JWK, issuerHostPath, jwksFileName string) *IdPDiscoveryContents {
return &IdPDiscoveryContents{jwk, issuerHostPath, jwksFileName}
}