-
Notifications
You must be signed in to change notification settings - Fork 6
/
Copy pathgrants.go
102 lines (93 loc) · 2.28 KB
/
grants.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
package main
import (
"github.com/aws/aws-sdk-go/aws"
"github.com/aws/aws-sdk-go/aws/session"
"github.com/aws/aws-sdk-go/service/dynamodb"
"github.com/aws/aws-sdk-go/service/kms"
)
func ComputerGrant() KeyRecord {
record := GetDynamoRecord(GrantDynamoKey())
if record.KeyData == "" {
return CreateComputerGrant()
}
return record
}
func CreateComputerGrant() KeyRecord {
svc := kms.New(session.New())
params := &kms.CreateGrantInput{
Constraints: &kms.GrantConstraints{
EncryptionContextSubset: EncryptionContext(),
},
GranteePrincipal: aws.String(ComputerUser()),
KeyId: aws.String(KeyARN()),
Name: aws.String(ComputerContext()),
Operations: []*string{
aws.String("Encrypt"),
aws.String("Decrypt"),
aws.String("GenerateDataKey"),
aws.String("DescribeKey"),
},
}
result, err := svc.CreateGrant(params)
HandleError(err)
record := KeyRecord{
GrantID: *result.GrantId,
GrantToken: *result.GrantToken,
}
StoreGrant(record)
return record
}
func RevokeGrant() {
record := ComputerGrant()
svc := kms.New(session.New())
params := &kms.RevokeGrantInput{
GrantId: aws.String(record.GrantID),
KeyId: aws.String(KeyARN()),
}
_, err := svc.RevokeGrant(params)
HandleError(err)
DeleteGrant(record)
}
func DeleteGrant(record KeyRecord) {
svc := dynamodb.New(session.New())
input := &dynamodb.DeleteItemInput{
Key: GrantDynamoKey(),
ReturnConsumedCapacity: aws.String("TOTAL"),
TableName: aws.String("kms-cryptsetup"),
}
_, err := svc.DeleteItem(input)
HandleError(err)
}
func StoreGrant(record KeyRecord) {
svc := dynamodb.New(session.New())
input := &dynamodb.PutItemInput{
Item: map[string]*dynamodb.AttributeValue{
"Computer": {
S: aws.String(ComputerContext()),
},
"Disk": {
S: aws.String("KeyGrant"),
},
"GrantID": {
S: aws.String(record.GrantID),
},
"GrantToken": {
S: aws.String(record.GrantToken),
},
},
ReturnConsumedCapacity: aws.String("TOTAL"),
TableName: aws.String("kms-cryptsetup"),
}
_, err := svc.PutItem(input)
HandleError(err)
}
func GrantDynamoKey() map[string]*dynamodb.AttributeValue {
return map[string]*dynamodb.AttributeValue{
"Computer": {
S: aws.String(ComputerContext()),
},
"Disk": {
S: aws.String("KeyGrant"),
},
}
}