-
Notifications
You must be signed in to change notification settings - Fork 63
/
Copy pathservice_account_getter.go
129 lines (110 loc) · 3.62 KB
/
service_account_getter.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
// Copyright (c) HashiCorp, Inc.
// SPDX-License-Identifier: MPL-2.0
package kubeauth
import (
"context"
"encoding/json"
"errors"
"fmt"
"io"
"net/http"
"strings"
v1 "k8s.io/api/core/v1"
kubeerrors "k8s.io/apimachinery/pkg/api/errors"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/apimachinery/pkg/runtime"
)
const annotationKeyPrefix = "vault.hashicorp.com/alias-metadata-"
var errAliasMetadataReservedKeysFound = errors.New("entity alias metadata keys for only internal use found" +
" from the client token's associated service account annotations")
// serviceAccountGetter defines a namespace validator interface
type serviceAccountGetter interface {
annotations(context.Context, *http.Client, string, string, string) (map[string]string, error)
}
type serviceAccountGetterFactory func(*kubeConfig) serviceAccountGetter
// serviceAccountGetterWrapper implements the serviceAccountGetter interface
type serviceAccountGetterWrapper struct {
config *kubeConfig
}
func newServiceAccountGetterWrapper(config *kubeConfig) serviceAccountGetter {
return &serviceAccountGetterWrapper{
config: config,
}
}
func (w *serviceAccountGetterWrapper) annotations(ctx context.Context, client *http.Client, jwtStr, namespace, serviceAccount string) (map[string]string, error) {
url := fmt.Sprintf("%s/api/v1/namespaces/%s/serviceaccounts/%s",
strings.TrimSuffix(w.config.Host, "/"), namespace, serviceAccount)
req, err := http.NewRequestWithContext(ctx, "GET", url, nil)
if err != nil {
return nil, err
}
// If we have a configured TokenReviewer JWT use it as the bearer, otherwise
// try to use the passed in JWT.
bearer := fmt.Sprintf("Bearer %s", jwtStr)
if len(w.config.TokenReviewerJWT) > 0 {
bearer = fmt.Sprintf("Bearer %s", w.config.TokenReviewerJWT)
}
setRequestHeader(req, bearer)
resp, err := client.Do(req)
if err != nil {
return nil, err
}
body, err := io.ReadAll(resp.Body)
if err != nil {
return nil, err
}
if resp.StatusCode != http.StatusOK {
var errStatus metav1.Status
if err = json.Unmarshal(body, &errStatus); err != nil {
return nil, fmt.Errorf("failed to parse error status on service account retrieval failure err=%s", err)
}
if errStatus.Status != metav1.StatusSuccess {
return nil, fmt.Errorf("failed to get service account (code %d status %s)",
resp.StatusCode, kubeerrors.FromObject(runtime.Object(&errStatus)))
}
}
var sa v1.ServiceAccount
err = json.Unmarshal(body, &sa)
if err != nil {
return nil, err
}
var found bool
var foundKeys []string
annotations := map[string]string{}
for k, v := range sa.Annotations {
if strings.HasPrefix(k, annotationKeyPrefix) {
newK := strings.TrimPrefix(k, annotationKeyPrefix)
if _, ok := reservedAliasMetadataKeys[newK]; ok {
foundKeys = append(foundKeys, newK)
found = true
} else {
annotations[newK] = v
}
}
}
if found {
errContext := fmt.Sprintf("keys=%+q", foundKeys)
return nil, fmt.Errorf("%w: %s", errAliasMetadataReservedKeysFound, errContext)
}
return annotations, nil
}
type mockServiceAccountGetter struct {
meta metav1.ObjectMeta
}
func mockServiceAccountGetterFactory(meta metav1.ObjectMeta) serviceAccountGetterFactory {
return func(config *kubeConfig) serviceAccountGetter {
return &mockServiceAccountGetter{
meta: meta,
}
}
}
func (v *mockServiceAccountGetter) annotations(context.Context, *http.Client, string, string, string) (map[string]string, error) {
annotations := map[string]string{}
for k, v := range v.meta.Annotations {
if strings.HasPrefix(k, annotationKeyPrefix) {
newK := strings.TrimPrefix(k, annotationKeyPrefix)
annotations[newK] = v
}
}
return annotations, nil
}