provider.go 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137
  1. /*
  2. Copyright © The ESO Authors
  3. Licensed under the Apache License, Version 2.0 (the "License");
  4. you may not use this file except in compliance with the License.
  5. You may obtain a copy of the License at
  6. https://www.apache.org/licenses/LICENSE-2.0
  7. Unless required by applicable law or agreed to in writing, software
  8. distributed under the License is distributed on an "AS IS" BASIS,
  9. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  10. See the License for the specific language governing permissions and
  11. limitations under the License.
  12. */
  13. package barbican
  14. import (
  15. "context"
  16. "errors"
  17. "fmt"
  18. "github.com/gophercloud/gophercloud/v2"
  19. "github.com/gophercloud/gophercloud/v2/openstack"
  20. "sigs.k8s.io/controller-runtime/pkg/client"
  21. "sigs.k8s.io/controller-runtime/pkg/webhook/admission"
  22. esv1 "github.com/external-secrets/external-secrets/apis/externalsecrets/v1"
  23. "github.com/external-secrets/external-secrets/runtime/esutils/resolvers"
  24. )
  25. const (
  26. errGeneric = "barbican provider error: %w"
  27. errMissingField = "barbican provider missing required field: %w"
  28. errAuthFailed = "barbican provider authentication failed: %w"
  29. errClientInit = "barbican provider client initialization failed: %w"
  30. )
  31. var _ esv1.Provider = &Provider{}
  32. // Provider implements the Barbican provider.
  33. type Provider struct{}
  34. // Capabilities returns the capabilities of the Barbican provider.
  35. func (p *Provider) Capabilities() esv1.SecretStoreCapabilities {
  36. return esv1.SecretStoreReadOnly
  37. }
  38. // ValidateStore validates the Barbican store configuration.
  39. func (p *Provider) ValidateStore(store esv1.GenericStore) (admission.Warnings, error) {
  40. if store == nil {
  41. return nil, fmt.Errorf(errGeneric, errors.New("store is nil"))
  42. }
  43. return nil, nil
  44. }
  45. // NewClient creates a new Barbican client.
  46. func (p *Provider) NewClient(ctx context.Context, store esv1.GenericStore, kube client.Client, namespace string) (esv1.SecretsClient, error) {
  47. return newClient(ctx, store, kube, namespace)
  48. }
  49. // getProvider retrieves the Barbican provider configuration from the store.
  50. func getProvider(store esv1.GenericStore) (*esv1.BarbicanProvider, error) {
  51. spec := store.GetSpec()
  52. if spec.Provider == nil || spec.Provider.Barbican == nil {
  53. return nil, fmt.Errorf(errMissingField, errors.New("provider barbican is nil"))
  54. }
  55. return spec.Provider.Barbican, nil
  56. }
  57. func newClient(ctx context.Context, store esv1.GenericStore, kube client.Client, namespace string) (esv1.SecretsClient, error) {
  58. provider, err := getProvider(store)
  59. if err != nil {
  60. return nil, err
  61. }
  62. if provider.AuthURL == "" {
  63. return nil, fmt.Errorf(errMissingField, errors.New("authURL is required"))
  64. }
  65. username := provider.Auth.Username.Value
  66. if username == "" {
  67. username, err = resolvers.SecretKeyRef(ctx, kube, store.GetKind(), namespace, provider.Auth.Username.SecretRef)
  68. if err != nil {
  69. return nil, fmt.Errorf(errMissingField, err)
  70. }
  71. }
  72. password, err := resolvers.SecretKeyRef(ctx, kube, store.GetKind(), namespace, provider.Auth.Password.SecretRef)
  73. if err != nil {
  74. return nil, fmt.Errorf(errMissingField, err)
  75. }
  76. authopts := gophercloud.AuthOptions{
  77. IdentityEndpoint: provider.AuthURL,
  78. TenantName: provider.TenantName,
  79. DomainName: provider.DomainName,
  80. Username: username,
  81. Password: password,
  82. }
  83. auth, err := openstack.AuthenticatedClient(ctx, authopts)
  84. if err != nil {
  85. return nil, fmt.Errorf(errAuthFailed, err)
  86. }
  87. barbicanClient, err := openstack.NewKeyManagerV1(auth, gophercloud.EndpointOpts{
  88. Region: provider.Region,
  89. })
  90. if err != nil {
  91. return nil, fmt.Errorf(errClientInit, err)
  92. }
  93. c := &Client{
  94. keyManager: barbicanClient,
  95. }
  96. return c, nil
  97. }
  98. // NewProvider constructs a new Barbican provider.
  99. func NewProvider() esv1.Provider {
  100. return &Provider{}
  101. }
  102. // ProviderSpec returns a sample Barbican provider spec.
  103. func ProviderSpec() *esv1.SecretStoreProvider {
  104. return &esv1.SecretStoreProvider{
  105. Barbican: &esv1.BarbicanProvider{},
  106. }
  107. }
  108. // MaintenanceStatus returns the maintenance status of the Barbican provider.
  109. func MaintenanceStatus() esv1.MaintenanceStatus {
  110. return esv1.MaintenanceStatusMaintained
  111. }