145 lines
		
	
	
		
			4.5 KiB
		
	
	
	
		
			Go
		
	
	
	
			
		
		
	
	
			145 lines
		
	
	
		
			4.5 KiB
		
	
	
	
		
			Go
		
	
	
	
/*
 | 
						|
Copyright © 2019 Vineeth Pothulapati <vineethpothulapati@outlook.com>
 | 
						|
 | 
						|
Permission is hereby granted, free of charge, to any person obtaining a copy
 | 
						|
of this software and associated documentation files (the "Software"), to deal
 | 
						|
in the Software without restriction, including without limitation the rights
 | 
						|
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
 | 
						|
copies of the Software, and to permit persons to whom the Software is
 | 
						|
furnished to do so, subject to the following conditions:
 | 
						|
 | 
						|
The above copyright notice and this permission notice shall be included in
 | 
						|
all copies or substantial portions of the Software.
 | 
						|
 | 
						|
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 | 
						|
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 | 
						|
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
 | 
						|
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
 | 
						|
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
 | 
						|
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
 | 
						|
THE SOFTWARE.
 | 
						|
*/
 | 
						|
 | 
						|
package cmd
 | 
						|
 | 
						|
import (
 | 
						|
	"context"
 | 
						|
	"encoding/json"
 | 
						|
	"fmt"
 | 
						|
	"log"
 | 
						|
	"strings"
 | 
						|
 | 
						|
	"github.com/spf13/cobra"
 | 
						|
	PostgresqlLister "github.com/zalando/postgres-operator/pkg/generated/clientset/versioned/typed/acid.zalan.do/v1"
 | 
						|
	metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
 | 
						|
	"k8s.io/apimachinery/pkg/types"
 | 
						|
)
 | 
						|
 | 
						|
var allowedPrivileges = []string{"SUPERUSER", "REPLICATION", "INHERIT", "LOGIN", "NOLOGIN", "CREATEROLE", "CREATEDB", "BYPASSRLS"}
 | 
						|
 | 
						|
// addUserCmd represents the addUser command
 | 
						|
var addUserCmd = &cobra.Command{
 | 
						|
	Use:   "add-user",
 | 
						|
	Short: "Adds a user to the postgres cluster with given privileges",
 | 
						|
	Long:  `Adds a user to the postgres cluster. You can add privileges as well with -p flag.`,
 | 
						|
	Run: func(cmd *cobra.Command, args []string) {
 | 
						|
		clusterName, _ := cmd.Flags().GetString("cluster")
 | 
						|
		privileges, _ := cmd.Flags().GetString("privileges")
 | 
						|
 | 
						|
		if len(args) > 0 {
 | 
						|
			user := args[0]
 | 
						|
			var permissions []string
 | 
						|
			var perms []string
 | 
						|
 | 
						|
			if privileges != "" {
 | 
						|
				parsedRoles := strings.Replace(privileges, ",", " ", -1)
 | 
						|
				parsedRoles = strings.ToUpper(parsedRoles)
 | 
						|
				permissions = strings.Fields(parsedRoles)
 | 
						|
				var invalidPerms []string
 | 
						|
 | 
						|
				for _, userPrivilege := range permissions {
 | 
						|
					validPerm := false
 | 
						|
					for _, privilege := range allowedPrivileges {
 | 
						|
						if privilege == userPrivilege {
 | 
						|
							perms = append(perms, userPrivilege)
 | 
						|
							validPerm = true
 | 
						|
						}
 | 
						|
					}
 | 
						|
					if !validPerm {
 | 
						|
						invalidPerms = append(invalidPerms, userPrivilege)
 | 
						|
					}
 | 
						|
				}
 | 
						|
 | 
						|
				if len(invalidPerms) > 0 {
 | 
						|
					fmt.Printf("Invalid privileges %s\n", invalidPerms)
 | 
						|
					return
 | 
						|
				}
 | 
						|
			}
 | 
						|
			addUser(user, clusterName, perms)
 | 
						|
		}
 | 
						|
	},
 | 
						|
	Example: `
 | 
						|
kubectl pg add-user user01 -p login,createdb -c cluster01
 | 
						|
`,
 | 
						|
}
 | 
						|
 | 
						|
// add user to the cluster with provided permissions
 | 
						|
func addUser(user string, clusterName string, permissions []string) {
 | 
						|
	config := getConfig()
 | 
						|
	postgresConfig, err := PostgresqlLister.NewForConfig(config)
 | 
						|
	if err != nil {
 | 
						|
		log.Fatal(err)
 | 
						|
	}
 | 
						|
 | 
						|
	namespace := getCurrentNamespace()
 | 
						|
	postgresql, err := postgresConfig.Postgresqls(namespace).Get(context.TODO(), clusterName, metav1.GetOptions{})
 | 
						|
	if err != nil {
 | 
						|
		log.Fatal(err)
 | 
						|
	}
 | 
						|
 | 
						|
	setUsers := make(map[string]bool)
 | 
						|
	for _, k := range permissions {
 | 
						|
		setUsers[k] = true
 | 
						|
	}
 | 
						|
 | 
						|
	if existingRoles, key := postgresql.Spec.Users[user]; key {
 | 
						|
		for _, k := range existingRoles {
 | 
						|
			setUsers[k] = true
 | 
						|
		}
 | 
						|
	}
 | 
						|
 | 
						|
	Privileges := []string{}
 | 
						|
	for keys, values := range setUsers {
 | 
						|
		if values {
 | 
						|
			Privileges = append(Privileges, keys)
 | 
						|
		}
 | 
						|
	}
 | 
						|
 | 
						|
	patch := applyUserPatch(user, Privileges)
 | 
						|
	updatedPostgresql, err := postgresConfig.Postgresqls(namespace).Patch(context.TODO(), postgresql.Name, types.MergePatchType, patch, metav1.PatchOptions{})
 | 
						|
	if err != nil {
 | 
						|
		log.Fatal(err)
 | 
						|
	}
 | 
						|
 | 
						|
	if updatedPostgresql.ResourceVersion != postgresql.ResourceVersion {
 | 
						|
		fmt.Printf("postgresql %s is updated with new user %s and with privileges %s.\n", updatedPostgresql.Name, user, permissions)
 | 
						|
	} else {
 | 
						|
		fmt.Printf("postgresql %s is unchanged.\n", updatedPostgresql.Name)
 | 
						|
	}
 | 
						|
}
 | 
						|
 | 
						|
func applyUserPatch(user string, value []string) []byte {
 | 
						|
	ins := map[string]map[string]map[string][]string{"spec": {"users": {user: value}}}
 | 
						|
	patchInstances, err := json.Marshal(ins)
 | 
						|
	if err != nil {
 | 
						|
		log.Fatal(err, "unable to parse number of instances json")
 | 
						|
	}
 | 
						|
	return patchInstances
 | 
						|
}
 | 
						|
 | 
						|
func init() {
 | 
						|
	addUserCmd.Flags().StringP("cluster", "c", "", "add user to the provided cluster.")
 | 
						|
	addUserCmd.Flags().StringP("privileges", "p", "", "add privileges separated by commas without spaces")
 | 
						|
	rootCmd.AddCommand(addUserCmd)
 | 
						|
}
 |