-
Notifications
You must be signed in to change notification settings - Fork 48
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feat(ip filter) Add ip filter resource for both monitor and secure (#534
) * feat(allowed ip range) Add allowed ip range resource for both monitor and secure SP-3101 * add build tag to acc test * remove unused `allowedIpRangeWrapper` * rename resource: 'allowed_ip_range' > 'ip_filter' * remove check for status 200 when deleting ip filter * minor refactor - change 'Ip' > 'IP' in method names * add ip_filters_settings resource used for enabling/disabling IP filters * update `sysdig_ip_filters_settings` documentation * rename helper methods in tests * add Attributes Reference to docs * rename `ip_filters_settings` resource to `ip_filtering_settings`
- Loading branch information
Showing
12 changed files
with
637 additions
and
7 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,65 @@ | ||
package v2 | ||
|
||
import ( | ||
"context" | ||
"fmt" | ||
"net/http" | ||
) | ||
|
||
const ( | ||
IPFiltersSettingsPath = "%s/platform/v1/ip-filters-settings" | ||
) | ||
|
||
type IPFilteringSettingsInterface interface { | ||
Base | ||
GetIPFilteringSettings(ctx context.Context) (*IPFiltersSettings, error) | ||
UpdateIPFilteringSettings(ctx context.Context, ipFiltersSettings *IPFiltersSettings) (*IPFiltersSettings, error) | ||
} | ||
|
||
func (client *Client) GetIPFilteringSettings(ctx context.Context) (*IPFiltersSettings, error) { | ||
response, err := client.requester.Request(ctx, http.MethodGet, client.GetIPFiltersSettingsURL(), nil) | ||
if err != nil { | ||
return nil, err | ||
} | ||
defer response.Body.Close() | ||
|
||
if response.StatusCode != http.StatusOK { | ||
err = client.ErrorFromResponse(response) | ||
return nil, err | ||
} | ||
|
||
ipFiltersSettings, err := Unmarshal[IPFiltersSettings](response.Body) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return &ipFiltersSettings, nil | ||
} | ||
|
||
func (client *Client) UpdateIPFilteringSettings(ctx context.Context, ipFiltersSettings *IPFiltersSettings) (*IPFiltersSettings, error) { | ||
payload, err := Marshal(ipFiltersSettings) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
response, err := client.requester.Request(ctx, http.MethodPut, client.GetIPFiltersSettingsURL(), payload) | ||
if err != nil { | ||
return nil, err | ||
} | ||
defer response.Body.Close() | ||
|
||
if response.StatusCode != http.StatusOK { | ||
return nil, client.ErrorFromResponse(response) | ||
} | ||
|
||
updated, err := Unmarshal[IPFiltersSettings](response.Body) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return &updated, nil | ||
} | ||
|
||
func (client *Client) GetIPFiltersSettingsURL() string { | ||
return fmt.Sprintf(IPFiltersSettingsPath, client.config.url) | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,114 @@ | ||
package v2 | ||
|
||
import ( | ||
"context" | ||
"errors" | ||
"fmt" | ||
"net/http" | ||
) | ||
|
||
var IPFilterNotFound = errors.New("IP filter not found") | ||
|
||
const ( | ||
IPFiltersPath = "%s/platform/v1/ip-filters" | ||
IPFilterPath = "%s/platform/v1/ip-filters/%d" | ||
) | ||
|
||
type IPFiltersInterface interface { | ||
Base | ||
GetIPFilterById(ctx context.Context, id int) (*IPFilter, error) | ||
CreateIPFilter(ctx context.Context, ipFilter *IPFilter) (*IPFilter, error) | ||
UpdateIPFilter(ctx context.Context, ipFilter *IPFilter, id int) (*IPFilter, error) | ||
DeleteIPFilter(ctx context.Context, id int) error | ||
} | ||
|
||
func (client *Client) GetIPFilterById(ctx context.Context, id int) (*IPFilter, error) { | ||
response, err := client.requester.Request(ctx, http.MethodGet, client.GetIPFilterURL(id), nil) | ||
if err != nil { | ||
return nil, err | ||
} | ||
defer response.Body.Close() | ||
|
||
if response.StatusCode != http.StatusOK { | ||
err = client.ErrorFromResponse(response) | ||
return nil, err | ||
} | ||
|
||
ipFilter, err := Unmarshal[IPFilter](response.Body) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return &ipFilter, nil | ||
} | ||
|
||
func (client *Client) CreateIPFilter(ctx context.Context, ipFilter *IPFilter) (*IPFilter, error) { | ||
payload, err := Marshal(ipFilter) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
response, err := client.requester.Request(ctx, http.MethodPost, client.GetIPFiltersURL(), payload) | ||
if err != nil { | ||
return nil, err | ||
} | ||
defer response.Body.Close() | ||
|
||
if response.StatusCode != http.StatusCreated { | ||
return nil, client.ErrorFromResponse(response) | ||
} | ||
|
||
created, err := Unmarshal[IPFilter](response.Body) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return &created, nil | ||
|
||
} | ||
|
||
func (client *Client) UpdateIPFilter(ctx context.Context, ipFilter *IPFilter, id int) (*IPFilter, error) { | ||
payload, err := Marshal(ipFilter) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
response, err := client.requester.Request(ctx, http.MethodPut, client.GetIPFilterURL(id), payload) | ||
if err != nil { | ||
return nil, err | ||
} | ||
defer response.Body.Close() | ||
|
||
if response.StatusCode != http.StatusOK { | ||
return nil, client.ErrorFromResponse(response) | ||
} | ||
|
||
updated, err := Unmarshal[IPFilter](response.Body) | ||
if err != nil { | ||
return nil, err | ||
} | ||
|
||
return &updated, nil | ||
} | ||
|
||
func (client *Client) DeleteIPFilter(ctx context.Context, id int) error { | ||
response, err := client.requester.Request(ctx, http.MethodDelete, client.GetIPFilterURL(id), nil) | ||
if err != nil { | ||
return err | ||
} | ||
defer response.Body.Close() | ||
|
||
if response.StatusCode != http.StatusNoContent && response.StatusCode != http.StatusNotFound { | ||
return client.ErrorFromResponse(response) | ||
} | ||
|
||
return nil | ||
} | ||
|
||
func (client *Client) GetIPFilterURL(id int) string { | ||
return fmt.Sprintf(IPFilterPath, client.config.url, id) | ||
} | ||
|
||
func (client *Client) GetIPFiltersURL() string { | ||
return fmt.Sprintf(IPFiltersPath, client.config.url) | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,155 @@ | ||
package sysdig | ||
|
||
import ( | ||
"context" | ||
v2 "github.com/draios/terraform-provider-sysdig/sysdig/internal/client/v2" | ||
"github.com/hashicorp/terraform-plugin-sdk/v2/diag" | ||
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema" | ||
"strconv" | ||
) | ||
|
||
func resourceSysdigIPFilter() *schema.Resource { | ||
return &schema.Resource{ | ||
ReadContext: resourceSysdigIPFilterRead, | ||
CreateContext: resourceSysdigIPFilterCreate, | ||
UpdateContext: resourceSysdigIPFilterUpdate, | ||
DeleteContext: resourceSysdigIPFilterDelete, | ||
Schema: map[string]*schema.Schema{ | ||
"ip_range": { | ||
Type: schema.TypeString, | ||
Required: true, | ||
}, | ||
"note": { | ||
Type: schema.TypeString, | ||
Optional: true, | ||
}, | ||
"enabled": { | ||
Type: schema.TypeBool, | ||
Required: true, | ||
}, | ||
}, | ||
} | ||
} | ||
|
||
func resourceSysdigIPFilterRead(ctx context.Context, d *schema.ResourceData, m interface{}) diag.Diagnostics { | ||
client, err := m.(SysdigClients).sysdigCommonClientV2() | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
id, err := strconv.Atoi(d.Id()) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
ipFilter, err := client.GetIPFilterById(ctx, id) | ||
if err != nil { | ||
if err == v2.IPFilterNotFound { | ||
d.SetId("") | ||
return nil | ||
} | ||
return diag.FromErr(err) | ||
} | ||
|
||
err = ipFilterToResourceData(ipFilter, d) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
return nil | ||
} | ||
|
||
func resourceSysdigIPFilterCreate(ctx context.Context, d *schema.ResourceData, m interface{}) diag.Diagnostics { | ||
client, err := m.(SysdigClients).sysdigCommonClientV2() | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
ipFilter, err := ipFilterFromResourceData(d) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
createdIPFilter, err := client.CreateIPFilter(ctx, ipFilter) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
d.SetId(strconv.Itoa(createdIPFilter.ID)) | ||
|
||
resourceSysdigIPFilterRead(ctx, d, m) | ||
|
||
return nil | ||
} | ||
|
||
func resourceSysdigIPFilterUpdate(ctx context.Context, d *schema.ResourceData, m interface{}) diag.Diagnostics { | ||
client, err := m.(SysdigClients).sysdigCommonClientV2() | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
ipFilter, err := ipFilterFromResourceData(d) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
id, err := strconv.Atoi(d.Id()) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
|
||
} | ||
|
||
ipFilter.ID = id | ||
_, err = client.UpdateIPFilter(ctx, ipFilter, id) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
resourceSysdigIPFilterRead(ctx, d, m) | ||
|
||
return nil | ||
} | ||
|
||
func resourceSysdigIPFilterDelete(ctx context.Context, d *schema.ResourceData, m interface{}) diag.Diagnostics { | ||
client, err := m.(SysdigClients).sysdigCommonClientV2() | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
id, err := strconv.Atoi(d.Id()) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
err = client.DeleteIPFilter(ctx, id) | ||
if err != nil { | ||
return diag.FromErr(err) | ||
} | ||
|
||
return nil | ||
} | ||
|
||
func ipFilterToResourceData(ipFilter *v2.IPFilter, d *schema.ResourceData) error { | ||
err := d.Set("ip_range", ipFilter.IPRange) | ||
if err != nil { | ||
return err | ||
} | ||
err = d.Set("note", ipFilter.Note) | ||
if err != nil { | ||
return err | ||
} | ||
err = d.Set("enabled", ipFilter.Enabled) | ||
if err != nil { | ||
return err | ||
} | ||
|
||
return nil | ||
} | ||
|
||
func ipFilterFromResourceData(d *schema.ResourceData) (*v2.IPFilter, error) { | ||
return &v2.IPFilter{ | ||
IPRange: d.Get("ip_range").(string), | ||
Note: d.Get("note").(string), | ||
Enabled: d.Get("enabled").(bool), | ||
}, nil | ||
} |
Oops, something went wrong.