-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathdeploy_stack.py
102 lines (86 loc) · 2.94 KB
/
deploy_stack.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
import argparse
import json
import logging
import boto3
from botocore.exceptions import ClientError
logger = logging.getLogger(__name__)
def read_parameters(param_file):
logging.info(f"Reading param_file from {param_file}")
with open(param_file, "r") as f:
params = json.load(f)
parameters = params["Parameters"]
tags = params["Tags"]
paramlist = []
for key in parameters:
p = {
"ParameterKey": key,
"ParameterValue": parameters[key],
"UsePreviousValue": False,
}
paramlist.append(p)
taglist = []
for key in tags.keys():
t = {"Key": key, "Value": tags[key]}
taglist.append(t)
return paramlist, taglist
# assume cross account role
def assume_role(role_arn, session_name):
sts_client = boto3.client("sts")
try:
assumed_role_object = sts_client.assume_role(
RoleArn=role_arn, RoleSessionName=session_name
)
return assumed_role_object["Credentials"]
except ClientError as e:
logger.error(f"Error assuming role: {e}")
return None
if __name__ == "__main__":
parser = argparse.ArgumentParser()
parser.add_argument("--stack-name")
parser.add_argument("--region")
parser.add_argument("--param-file")
parser.add_argument("--project-name")
parser.add_argument("--role-arn")
args, _ = parser.parse_known_args()
# Configure logging to output the line number and message
log_format = "%(levelname)s: [%(filename)s:%(lineno)s] %(message)s"
logging.basicConfig(format=log_format, level=logging.INFO)
credentials = assume_role(args.role_arn, "cfn-deploy")
cfn_client = boto3.client("cloudformation", region_name=args.region,
aws_access_key_id=credentials["AccessKeyId"],
aws_secret_access_key=credentials["SecretAccessKey"],
aws_session_token=credentials["SessionToken"])
stack_name = (
args.project_name
+ "-"
+ args.stack_name
)
# Read parameters and tags
parameters, tags = read_parameters(args.param_file)
# Read Cfn template body
with open("endpoint-config-template.yml", "r") as f:
template_body = f.read()
try:
cfn_client.create_stack(
StackName=stack_name,
TemplateBody=template_body,
Parameters=parameters,
Capabilities=[
'CAPABILITY_IAM',
'CAPABILITY_NAMED_IAM'
],
Tags=tags,
)
logging.info("Creating a new stack...")
except cfn_client.exceptions.AlreadyExistsException:
cfn_client.update_stack(
StackName=stack_name,
TemplateBody=template_body,
Parameters=parameters,
Capabilities=[
'CAPABILITY_IAM',
'CAPABILITY_NAMED_IAM'
],
Tags=tags,
)
logging.info("Updating existing stack...")