Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions .github/workflows/prcomment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -163,7 +163,7 @@ jobs:
run: |
grep '\-\-' docs/reference/*.md | sed 's+docs/reference/\(.*\).md+\1+g' | sed 's/,//g' | awk '{
for (i = 2; i <= NF; i++) {
if ($i ~ /^-./) print $1,$i
if (i <= 3 && $i ~ /^-./) print $1,$i
}
}' > flags.before
- name: ⬇️ Checkout repository
Expand All @@ -175,24 +175,24 @@ jobs:
run: |
grep '\-\-' docs/reference/*.md | sed 's+docs/reference/\(.*\).md+\1+g' | sed 's/,//g' | awk '{
for (i = 2; i <= NF; i++) {
if ($i ~ /^-./) print $1,$i
if (i <= 3 && $i ~ /^-./) print $1,$i
}
}' > flags.after
- name: ⚖️ Compute diff
id: diff
run: |
set -x
diff -U 0 flags.before flags.after | tail -n +4 | tee diff
diff -U 0 flags.before flags.after | grep '^-octl' | tee diff
DELETES=`egrep '^-' diff || true`
if [ -n "$DELETES" ]; then
echo "**DANGER : some flags have changed or have been deleted** 😱" > diffmsg.txt
echo "**DANGER : some flags have been deleted** 😱" > diffmsg.txt
echo '```' >> diffmsg.txt
cat diff >> diffmsg.txt
echo '```' >> diffmsg.txt
echo 'Set a "allow-flag-change" label to allow it.' >> diffmsg.txt
echo result=failure >> $GITHUB_OUTPUT
else
echo "**No flags have changed or have been deleted** 😀" > diffmsg.txt
echo "**No flags have been deleted** 😀" > diffmsg.txt
echo result=success >> $GITHUB_OUTPUT
fi
- name: 🔎 Find Comment
Expand All @@ -201,7 +201,7 @@ jobs:
with:
issue-number: ${{ github.event.pull_request.number }}
comment-author: 'github-actions[bot]'
body-includes: flags have changed or have been deleted
body-includes: flags have been deleted
- name: 📝 Create or update comment
uses: peter-evans/create-or-update-comment@e8674b075228eee787fea43ef493e45ece1004c9 # v5.0.0
with:
Expand Down
10 changes: 9 additions & 1 deletion cmd/helpers.go
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
package cmd

import "github.com/spf13/cobra"
import (
"github.com/spf13/cobra"
"github.com/spf13/pflag"
)

func walkCommandTree(root *cobra.Command, fn func(cmd *cobra.Command)) {
fn(root)
Expand All @@ -17,3 +20,8 @@ func walkCommandTreeWithFlag(root *cobra.Command, flag string, fn func(cmd *cobr
fn(cmd)
})
}

func setFlag(f *pflag.Flag, v string) error {
f.Changed = true
return f.Value.Set(v)
}
60 changes: 56 additions & 4 deletions cmd/iaas.go
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,9 @@ SPDX-License-Identifier: BSD-3-Clause
package cmd

import (
"fmt"
"regexp"
"strings"
"time"

commandbuilder "github.com/outscale/octl/pkg/builder/command"
Expand All @@ -19,9 +22,10 @@ import (

// iaasCmd represents the iaascommand
var iaasCmd = &cobra.Command{
GroupID: "services",
Use: "iaas",
Short: "OUTSCALE IaaS management",
GroupID: "services",
Use: "iaas",
Short: "OUTSCALE IaaS management",
PersistentPreRunE: securityGroupRulePorts,
}

func init() {
Expand All @@ -40,7 +44,6 @@ func init() {
}

func oapi(cmd *cobra.Command, args []string) {
debug.Println(cmd.Name() + " called")
p := loadProfile(cmd)
cl, err := osc.NewClient(p, sdkOptions(cmd)...)
if err == nil {
Expand All @@ -53,3 +56,52 @@ func oapi(cmd *cobra.Command, args []string) {
messages.ExitErr(err)
}
}

var rePorts = regexp.MustCompile("([a-z0-9-]+)(/(-?[0-9]+)(-([0-9]+))?)?")

// securityGroupRulePorts parses the --ports flag into --protocol/--from-port/--to-port flags.
func securityGroupRulePorts(cmd *cobra.Command, args []string) error {
flags := cmd.Flags()
ports, err := flags.GetStringSlice("ports")
if err != nil {
return nil //nolint
}
debug.Println("found ports", ports)
var protocols, fromPorts, toPorts []string
for _, port := range ports {
ms := rePorts.FindAllStringSubmatch(port, 1)
if len(ms) == 0 {
return nil
}
protocol, from, to := ms[0][1], ms[0][3], ms[0][5]
fromPort, toPort := "-1", "-1"
if from != "" {
fromPort = from
}
if to != "" {
toPort = to
}
if fromPort != "-1" && toPort == "-1" {
toPort = fromPort
}
if err != nil {
return fmt.Errorf("invalid ports: %w", err)
}
protocols = append(protocols, protocol)
fromPorts = append(fromPorts, fromPort)
toPorts = append(toPorts, toPort)
}
if f := flags.Lookup("protocol"); f != nil {
debug.Println("set protocol", protocols)
_ = setFlag(f, strings.Join(protocols, ","))
}
if f := flags.Lookup("from-port"); f != nil {
debug.Println("set from", fromPorts)
_ = setFlag(f, strings.Join(fromPorts, ","))
}
if f := flags.Lookup("to-port"); f != nil {
debug.Println("set to", toPorts)
_ = setFlag(f, strings.Join(toPorts, ","))
}
return nil
}
19 changes: 19 additions & 0 deletions cmd/iaas_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -435,3 +435,22 @@ func TestVolumeByDeviceName(t *testing.T) {
require.Len(t, resp.LinkedVolumes, 1)
assert.Equal(t, "/dev/sda1", resp.LinkedVolumes[0].DeviceName)
}

func TestSecurityGroupRules(t *testing.T) {
var resp osc.SecurityGroup
runJSON(t, []string{"iaas", "sg", "create", "--name", "test-octl", "--description", "test-octl", "-o", "json"}, nil, &resp)
defer func() {
_ = run(t, []string{"iaas", "sg", "del", resp.SecurityGroupId, "-y"}, nil)
}()
runJSON(t, []string{"iaas", "sgr", "create", "--group-id", resp.SecurityGroupId, "--ports", "icmp,tcp/22,tcp/8080-8081", "--remote-ranges", "0.0.0.0/0", "-o", "json"}, nil, &resp)
assert.Len(t, resp.InboundRules, 3)
// drop rule id for comparison
for i := range resp.InboundRules {
resp.InboundRules[i].SecurityGroupRuleId = ""
}
assert.Contains(t, resp.InboundRules, osc.SecurityGroupRule{IpProtocol: "icmp", FromPortRange: -1, ToPortRange: -1, IpRanges: []string{"0.0.0.0/0"}})
assert.Contains(t, resp.InboundRules, osc.SecurityGroupRule{IpProtocol: "tcp", FromPortRange: 22, ToPortRange: 22, IpRanges: []string{"0.0.0.0/0"}})
assert.Contains(t, resp.InboundRules, osc.SecurityGroupRule{IpProtocol: "tcp", FromPortRange: 8080, ToPortRange: 8081, IpRanges: []string{"0.0.0.0/0"}})
runJSON(t, []string{"iaas", "sgr", "del", "--group-id", resp.SecurityGroupId, "--ports", "icmp,tcp/22,tcp/8080-8081", "--remote-ranges", "0.0.0.0/0", "-o", "json"}, nil, &resp)
assert.Empty(t, resp.InboundRules)
}
1 change: 0 additions & 1 deletion cmd/kube.go
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,6 @@ func init() {
}

func kube(cmd *cobra.Command, args []string) {
debug.Println(cmd.Name() + " called")
p := loadProfile(cmd)
cl, err := oks.NewClient(p, sdkOptions(cmd)...)
if err == nil {
Expand Down
3 changes: 0 additions & 3 deletions cmd/storage.go
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,6 @@ import (
"github.com/gabriel-vasile/mimetype"
commandbuilder "github.com/outscale/octl/pkg/builder/command"
"github.com/outscale/octl/pkg/config"
"github.com/outscale/octl/pkg/debug"
"github.com/outscale/octl/pkg/flags"
"github.com/outscale/octl/pkg/messages"
"github.com/outscale/octl/pkg/runner"
Expand Down Expand Up @@ -62,7 +61,6 @@ func init() {
}

func callOOS(cmd *cobra.Command, args []string) {
debug.Println(cmd.Name() + " called")
p := loadProfile(cmd)
cl, err := oos.NewClient(cmd.Context(), p, awsOptions(cmd)...)
if err == nil {
Expand All @@ -83,7 +81,6 @@ func callOOS(cmd *cobra.Command, args []string) {
}

func presign(cmd *cobra.Command, args []string) {
debug.Println(cmd.Name() + " called")
p := loadProfile(cmd)
s3cl, err := oos.NewClient(cmd.Context(), p, awsOptions(cmd)...)
if err != nil {
Expand Down
1 change: 1 addition & 0 deletions docs/reference/octl_iaas_securitygroup.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,4 +42,5 @@ Manage SecurityGroup resources
* [octl iaas securitygroup delete](octl_iaas_securitygroup_delete.md) - Deletes a specified security group.
* [octl iaas securitygroup describe](octl_iaas_securitygroup_describe.md) - Lists one or more security groups.
* [octl iaas securitygroup list](octl_iaas_securitygroup_list.md) - Lists one or more security groups.
* [octl iaas securitygroup rules](octl_iaas_securitygroup_rules.md) - Lists all rules from a security group.

51 changes: 51 additions & 0 deletions docs/reference/octl_iaas_securitygroup_rules.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,51 @@
## octl iaas securitygroup rules

Lists all rules from a security group.

### Synopsis

Lists all rules from a security group.

> alias for ReadSecurityGroups

```
octl iaas securitygroup rules id [flags]
```

### Options

```
-h, --help help for rules
```

### Options inherited from parent commands

```
-c, --columns string columns to display - [+]<title>:<jq query for content>||<title>:<jq query for content>
--config string Path of profile file (by default, ~/.osc/config.json)
--dry-run Display the request payload that would be sent to the API without sending it
--elapsed add elapsed time column when using --watch (default true)
--filter strings comma separated list of filters for results - name:value,name:value, alias for jq filter 'select(.name | tostring | test("value"))'
--interval duration interval between two watch/waitfor iterations (default 5s)
--jq string jq filter
--max-pages int maximum number of pages a command can fetch (default 20)
--no-upgrade do not check for new versions
-O, --out-file string redirect output to file
-o, --output string output format (json, yaml, raw, rawyaml, table, csv, none, text)
--payload string JSON content for query body
--profile string Profile to use in profile file (by default, "default")
-s, --silent Hides all information messages
--single convert single entry lists to a single object
--style string style to use for syntax-highlighting (doom-one, github, monokai, nord, paraiso, solarized) (default "github")
--template string JSON template file for query body
-v, --verbose Verbose output
--waitfor string repeatedly call the API until the specified jq expression returns 1/true or a non empty result
--waitfor-timeout duration maximum duration of a wait (default 10m0s)
--watch repeatedly call the API and display changes
-y, --yes answer yes to all prompts
```

### SEE ALSO

* [octl iaas securitygroup](octl_iaas_securitygroup.md) - Manage SecurityGroup resources

1 change: 1 addition & 0 deletions docs/reference/octl_iaas_securitygrouprule.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,4 +39,5 @@ Manage SecurityGroupRule resources

* [octl iaas](octl_iaas.md) - OUTSCALE IaaS management
* [octl iaas securitygrouprule create](octl_iaas_securitygrouprule_create.md) - Adds one or more rules to a security group.
* [octl iaas securitygrouprule delete](octl_iaas_securitygrouprule_delete.md) - Deletes one or more inbound or outbound rules from a security group.

27 changes: 9 additions & 18 deletions docs/reference/octl_iaas_securitygrouprule_create.md
Original file line number Diff line number Diff line change
Expand Up @@ -38,24 +38,15 @@ octl iaas securitygrouprule create [flags]
### Options

```
--flow string [REQUIRED] The direction of the flow: Inbound or Outbound.
--from-port-range int The beginning of the port range for the TCP and UDP protocols, or an ICMP type number.
--group-account-id-to-link string The OUTSCALE account ID that owns the source or destination security group specified in the SecurityGroupNameToLink parameter.
--group-id string [REQUIRED] The ID of the security group for which you want to create a rule.
--group-name-to-link string The ID of a source or destination security group that you want to link to the security group of the rule.
-h, --help help for create
--ip-protocol string The IP protocol name (tcp, udp, icmp, or -1 for all protocols).
--ip-range string The IP range for the security group rule, in CIDR notation (for example, 10.0.0.0/16).
--rule-from-port-range int The beginning of the port range for the TCP and UDP protocols, or an ICMP type number.
--rule-ip-protocol string The IP protocol name (tcp, udp, icmp, or -1 for all protocols).
--rule-ip-range strings One or more IP ranges for the security group rules, in CIDR notation (for example, ["10.0.0.0/24" , "10.0.1.0/24"]).
--rule-security-group-member-account-id string The OUTSCALE account ID that owns the source or destination security group.
--rule-security-group-member-security-group-id string The ID of a source or destination security group that you want to link to the security group of the rule.
--rule-security-group-member-security-group-name string The name of a source or destination security group that you want to link to the security group of the rule.
--rule-security-group-rule-id string The ID of the security group rule.
--rule-service-id strings One or more service IDs to allow traffic from a Net to access the corresponding OUTSCALE services.
--rule-to-port-range int The end of the port range for the TCP and UDP protocols, or an ICMP code number.
--to-port-range int The end of the port range for the TCP and UDP protocols, or an ICMP code number.
--flow string [REQUIRED] The direction of the flow: Inbound or Outbound. (default "Inbound")
--group-id string [REQUIRED] The ID of the security group for which you want to create a rule.
-h, --help help for create
--ports strings A list of either protocol (all ports from a protocol, e.g. icmp), protocol/port (a single port/protocol, e.g. tcp/80) or protocol/from-to (a range, e.g. tcp/8080-8082)
--remote-account string The OUTSCALE account ID that owns the source or destination security group.
--remote-ranges strings One or more IP ranges for the security group rules, in CIDR notation (for example, ["10.0.0.0/24" , "10.0.1.0/24"]).
--remote-security-group string The ID of a source or destination security group that you want to link to the security group of the rule.
--remote-security-group-name string The name of a source or destination security group that you want to link to the security group of the rule.
--remote-service strings One or more service IDs to allow traffic from a Net to access the corresponding OUTSCALE services.
```

### Options inherited from parent commands
Expand Down
70 changes: 70 additions & 0 deletions docs/reference/octl_iaas_securitygrouprule_delete.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
## octl iaas securitygrouprule delete

Deletes one or more inbound or outbound rules from a security group.

### Synopsis

Deletes one or more inbound or outbound rules from a security group.

For the rule to be deleted, the values specified in the deletion request must exactly match the value of the existing rule.

In case of TCP and UDP protocols, you have to indicate the destination port or range of ports. In case of ICMP protocol, you have to specify the ICMP type and code numbers.

Rules (IP permissions) consist of the protocol, IP range or source security group.

To remove outbound access to a destination security group, we recommend to use a set of IP permissions. We also recommend to specify the protocol in a set of IP permissions.


Alternatively, you can use the `Rules` parameter to delete several rules at the same time.

> alias for DeleteSecurityGroupRule

```
octl iaas securitygrouprule delete [flags]
```

### Options

```
--flow string [REQUIRED] The direction of the flow: Inbound or Outbound. (default "Inbound")
--group-id string [REQUIRED] The ID of the security group you want to delete a rule from.
-h, --help help for delete
--ports strings A list of either protocol (all ports from a protocol, e.g. icmp), protocol/port (a single port/protocol, e.g. tcp/80) or protocol/from-to (a range, e.g. tcp/8080-8082)
--remote-account string The OUTSCALE account ID that owns the source or destination security group.
--remote-ranges strings One or more IP ranges for the security group rules, in CIDR notation (for example, ["10.0.0.0/24" , "10.0.1.0/24"]).
--remote-security-group string The ID of a source or destination security group that you want to link to the security group of the rule.
--remote-security-group-name string The name of a source or destination security group that you want to link to the security group of the rule.
--remote-service strings One or more service IDs to allow traffic from a Net to access the corresponding OUTSCALE services.
```

### Options inherited from parent commands

```
-c, --columns string columns to display - [+]<title>:<jq query for content>||<title>:<jq query for content>
--config string Path of profile file (by default, ~/.osc/config.json)
--dry-run Display the request payload that would be sent to the API without sending it
--elapsed add elapsed time column when using --watch (default true)
--filter strings comma separated list of filters for results - name:value,name:value, alias for jq filter 'select(.name | tostring | test("value"))'
--interval duration interval between two watch/waitfor iterations (default 5s)
--jq string jq filter
--max-pages int maximum number of pages a command can fetch (default 20)
--no-upgrade do not check for new versions
-O, --out-file string redirect output to file
-o, --output string output format (json, yaml, raw, rawyaml, table, csv, none, text)
--payload string JSON content for query body
--profile string Profile to use in profile file (by default, "default")
-s, --silent Hides all information messages
--single convert single entry lists to a single object
--style string style to use for syntax-highlighting (doom-one, github, monokai, nord, paraiso, solarized) (default "github")
--template string JSON template file for query body
-v, --verbose Verbose output
--waitfor string repeatedly call the API until the specified jq expression returns 1/true or a non empty result
--waitfor-timeout duration maximum duration of a wait (default 10m0s)
--watch repeatedly call the API and display changes
-y, --yes answer yes to all prompts
```

### SEE ALSO

* [octl iaas securitygrouprule](octl_iaas_securitygrouprule.md) - Manage SecurityGroupRule resources

Loading
Loading