mirror of
https://github.com/opentofu/opentofu.git
synced 2025-01-05 21:53:04 -06:00
Merge branch 'paginate_roles' of https://github.com/stripe/terraform into stripe-paginate_roles
This commit is contained in:
commit
2e454181fc
@ -157,12 +157,10 @@ func testAccCheckAWSGroupMembershipAttributes(group *iam.GetGroupOutput, users [
|
||||
const testAccAWSGroupMemberConfig = `
|
||||
resource "aws_iam_group" "group" {
|
||||
name = "test-group-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "user" {
|
||||
name = "test-user-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_group_membership" "team" {
|
||||
@ -175,22 +173,18 @@ resource "aws_iam_group_membership" "team" {
|
||||
const testAccAWSGroupMemberConfigUpdate = `
|
||||
resource "aws_iam_group" "group" {
|
||||
name = "test-group-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "user" {
|
||||
name = "test-user-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "user_two" {
|
||||
name = "test-user-two-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "user_three" {
|
||||
name = "test-user-three-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_group_membership" "team" {
|
||||
@ -206,12 +200,10 @@ resource "aws_iam_group_membership" "team" {
|
||||
const testAccAWSGroupMemberConfigUpdateDown = `
|
||||
resource "aws_iam_group" "group" {
|
||||
name = "test-group-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "user_three" {
|
||||
name = "test-user-three-%s"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_group_membership" "team" {
|
||||
@ -226,7 +218,6 @@ resource "aws_iam_group_membership" "team" {
|
||||
const testAccAWSGroupMemberConfigPaginatedUserList = `
|
||||
resource "aws_iam_group" "group" {
|
||||
name = "test-paginated-group"
|
||||
path = "/"
|
||||
}
|
||||
|
||||
resource "aws_iam_group_membership" "team" {
|
||||
@ -236,8 +227,7 @@ resource "aws_iam_group_membership" "team" {
|
||||
}
|
||||
|
||||
resource "aws_iam_user" "user" {
|
||||
count = 101
|
||||
count = 101
|
||||
name = "${format("paged-test-user-%d", count.index + 1)}"
|
||||
path = "/"
|
||||
}
|
||||
`
|
||||
|
@ -103,30 +103,31 @@ func resourceAwsIamPolicyAttachmentRead(d *schema.ResourceData, meta interface{}
|
||||
return err
|
||||
}
|
||||
|
||||
policyEntities, err := conn.ListEntitiesForPolicy(&iam.ListEntitiesForPolicyInput{
|
||||
PolicyArn: aws.String(arn),
|
||||
})
|
||||
ul := make([]string, 0)
|
||||
rl := make([]string, 0)
|
||||
gl := make([]string, 0)
|
||||
|
||||
args := iam.ListEntitiesForPolicyInput{
|
||||
PolicyArn: aws.String(arn),
|
||||
}
|
||||
err = conn.ListEntitiesForPolicyPages(&args, func(page *iam.ListEntitiesForPolicyOutput, lastPage bool) bool {
|
||||
for _, u := range page.PolicyUsers {
|
||||
ul = append(ul, *u.UserName)
|
||||
}
|
||||
|
||||
for _, r := range page.PolicyRoles {
|
||||
rl = append(rl, *r.RoleName)
|
||||
}
|
||||
|
||||
for _, g := range page.PolicyGroups {
|
||||
gl = append(gl, *g.GroupName)
|
||||
}
|
||||
return true
|
||||
})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
ul := make([]string, 0, len(policyEntities.PolicyUsers))
|
||||
rl := make([]string, 0, len(policyEntities.PolicyRoles))
|
||||
gl := make([]string, 0, len(policyEntities.PolicyGroups))
|
||||
|
||||
for _, u := range policyEntities.PolicyUsers {
|
||||
ul = append(ul, *u.UserName)
|
||||
}
|
||||
|
||||
for _, r := range policyEntities.PolicyRoles {
|
||||
rl = append(rl, *r.RoleName)
|
||||
}
|
||||
|
||||
for _, g := range policyEntities.PolicyGroups {
|
||||
gl = append(gl, *g.GroupName)
|
||||
}
|
||||
|
||||
userErr := d.Set("users", ul)
|
||||
roleErr := d.Set("roles", rl)
|
||||
groupErr := d.Set("groups", gl)
|
||||
|
@ -35,8 +35,26 @@ func TestAccAWSPolicyAttachment_basic(t *testing.T) {
|
||||
},
|
||||
})
|
||||
}
|
||||
func testAccCheckAWSPolicyAttachmentDestroy(s *terraform.State) error {
|
||||
|
||||
func TestAccAWSPolicyAttachment_paginatedEntities(t *testing.T) {
|
||||
var out iam.ListEntitiesForPolicyOutput
|
||||
|
||||
resource.Test(t, resource.TestCase{
|
||||
PreCheck: func() { testAccPreCheck(t) },
|
||||
Providers: testAccProviders,
|
||||
CheckDestroy: testAccCheckAWSPolicyAttachmentDestroy,
|
||||
Steps: []resource.TestStep{
|
||||
resource.TestStep{
|
||||
Config: testAccAWSPolicyAttachConfig,
|
||||
Check: resource.ComposeTestCheckFunc(
|
||||
testAccCheckAWSPolicyAttachmentExists("aws_iam_policy_attachment.test-attach", 101, &out),
|
||||
),
|
||||
},
|
||||
},
|
||||
})
|
||||
}
|
||||
|
||||
func testAccCheckAWSPolicyAttachmentDestroy(s *terraform.State) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
@ -74,6 +92,7 @@ func testAccCheckAWSPolicyAttachmentExists(n string, c int64, out *iam.ListEntit
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
func testAccCheckAWSPolicyAttachmentAttributes(users []string, roles []string, groups []string, out *iam.ListEntitiesForPolicyOutput) resource.TestCheckFunc {
|
||||
return func(s *terraform.State) error {
|
||||
uc := len(users)
|
||||
@ -130,7 +149,6 @@ resource "aws_iam_role" "role" {
|
||||
}
|
||||
EOF
|
||||
}
|
||||
|
||||
resource "aws_iam_group" "group" {
|
||||
name = "test-group"
|
||||
}
|
||||
@ -276,3 +294,35 @@ resource "aws_iam_policy_attachment" "test-attach" {
|
||||
policy_arn = "${aws_iam_policy.policy.arn}"
|
||||
}
|
||||
`
|
||||
|
||||
const testAccAWSPolicyPaginatedAttachConfig = `
|
||||
resource "aws_iam_user" "user" {
|
||||
count = 101
|
||||
name = "${format("paged-test-user-%d", count.index + 1)}"
|
||||
}
|
||||
|
||||
resource "aws_iam_policy" "policy" {
|
||||
name = "test-policy"
|
||||
description = "A test policy"
|
||||
policy = <<EOF
|
||||
{
|
||||
"Version": "2012-10-17",
|
||||
"Statement": [
|
||||
{
|
||||
"Action": [
|
||||
"iam:ChangePassword"
|
||||
],
|
||||
"Resource": "*",
|
||||
"Effect": "Allow"
|
||||
}
|
||||
]
|
||||
}
|
||||
EOF
|
||||
}
|
||||
|
||||
resource "aws_iam_policy_attachment" "test-paginated-attach" {
|
||||
name = "test-attachment"
|
||||
users = ["${aws_iam_user.user.*.name}"]
|
||||
policy_arn = "${aws_iam_policy.policy.arn}"
|
||||
}
|
||||
`
|
||||
|
@ -67,20 +67,22 @@ func resourceAwsIamRolePolicyAttachmentRead(d *schema.ResourceData, meta interfa
|
||||
return err
|
||||
}
|
||||
|
||||
attachedPolicies, err := conn.ListAttachedRolePolicies(&iam.ListAttachedRolePoliciesInput{
|
||||
args := iam.ListAttachedRolePoliciesInput{
|
||||
RoleName: aws.String(role),
|
||||
}
|
||||
var policy string
|
||||
err = conn.ListAttachedRolePoliciesPages(&args, func(page *iam.ListAttachedRolePoliciesOutput, lastPage bool) bool {
|
||||
for _, p := range page.AttachedPolicies {
|
||||
if *p.PolicyArn == arn {
|
||||
policy = *p.PolicyArn
|
||||
}
|
||||
}
|
||||
|
||||
return policy == ""
|
||||
})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
var policy string
|
||||
for _, p := range attachedPolicies.AttachedPolicies {
|
||||
if *p.PolicyArn == arn {
|
||||
policy = *p.PolicyArn
|
||||
}
|
||||
}
|
||||
|
||||
if policy == "" {
|
||||
log.Printf("[WARN] No such policy found for Role Policy Attachment (%s)", role)
|
||||
d.SetId("")
|
||||
|
Loading…
Reference in New Issue
Block a user