o
    .&ßaH%  ã                   @   sr   d dl Z d dlmZmZmZmZmZmZ d dlm	Z	 d dl
mZmZmZ d dlmZ e  e¡ZG dd„ de	ƒZdS )é    N)Ú&DATAPIPELINE_DEFAULT_SERVICE_ROLE_NAMEÚ'DATAPIPELINE_DEFAULT_RESOURCE_ROLE_NAMEÚ%DATAPIPELINE_DEFAULT_SERVICE_ROLE_ARNÚ&DATAPIPELINE_DEFAULT_RESOURCE_ROLE_ARNÚ/DATAPIPELINE_DEFAULT_SERVICE_ROLE_ASSUME_POLICYÚ0DATAPIPELINE_DEFAULT_RESOURCE_ROLE_ASSUME_POLICY)ÚBasicCommand)Údisplay_responseÚdict_to_stringÚ
get_region)ÚClientErrorc                       s†   e Zd ZdZde d e d Zd‡ fdd„	Zdd	„ Zd
d„ Z	dd„ Z
dd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Z‡  ZS )ÚCreateDefaultRoleszcreate-default-roleszCreates the default IAM role z and zî which are used while creating an EMR cluster.
If the roles do not exist, create-default-roles will automatically create them and set their policies. If these roles are already created create-default-roles will not update their policies.
Nc                    s   t t| ƒ |¡ d S ©N)Úsuperr   Ú__init__)ÚselfÚsessionÚ	formatter©Ú	__class__© úW/usr/lib/python3/dist-packages/awscli/customizations/datapipeline/createdefaultroles.pyr   .   s   zCreateDefaultRoles.__init__c                 K   s>   t | j|ƒ| _|j| _| jjd| j| j|jd�| _|  ||¡S )zCall to run the commandsÚiam)Úregion_nameÚendpoint_urlÚverify)	r   Ú_sessionÚ_regionr   Ú_endpoint_urlÚcreate_clientÚ
verify_sslÚ_iam_clientÚ_create_default_roles)r   Úparsed_argsÚparsed_globalsÚkwargsr   r   r   Ú	_run_main1   s   üzCreateDefaultRoles._run_mainc                 C   sb   d}d}|   |¡rt d| d ¡ ||fS t d| d | ¡ |  |||¡}|  |¡}||fS )z[Method to create a role for a given role name and arn
        if it does not exist
        NzRole ú exists.z0 does not exist. Creating default role for EC2: )Ú_check_if_role_existsÚLOGÚdebugÚ_create_role_with_role_policyÚ_get_role_policy)r   Ú	role_nameÚrole_arnÚrole_policyÚrole_resultÚrole_policy_resultr   r   r   Ú_create_role=   s   

øÿþ
zCreateDefaultRoles._create_rolec                 C   s$   g }|   |||¡ |   |||¡ |S )znMethod to create a resultant list of responses for create roles
        for service and resource role
        )Ú)_construct_role_and_role_policy_structure)r   Údpl_default_resultÚdpl_default_policyÚdpl_default_res_resultÚdpl_default_res_policyÚresultr   r   r   Ú_construct_resultR   s   þþz$CreateDefaultRoles._construct_resultc           	      C   sŒ   |   ttt¡\}}|   ttt¡\}}t}|  |¡r#t 	d| d ¡ nt 	d| d | ¡ |  
||¡ |  ||||¡}t| jd||ƒ dS )NzInstance Profile r'   z2does not exist. Creating default Instance Profile Úcreate_roler   )r2   r   r   r   r   r   r   Ú!_check_if_instance_profile_existsr)   r*   Ú"_create_instance_profile_with_roler9   r	   r   )	r   r#   r$   Údatapipline_default_resultÚdatapipline_default_policyÚ#datapipline_default_resource_resultÚ#datapipline_default_resource_policyÚinstance_profile_namer8   r   r   r   r"   c   s@   ýÿýÿ

ÿþÿýz(CreateDefaultRoles._create_default_rolesc                 C   s2   | j j|d�}| j j||d d d�}|d d S )zvMethod to get the Policy for a particular ARN
        This is used to display the policy contents to the user
        )Ú	PolicyArnÚPolicyÚDefaultVersionId)rB   Ú	VersionIdÚPolicyVersionÚDocument)r!   Ú
get_policyÚget_policy_version)r   ÚarnÚpol_detÚpolicy_version_detailsr   r   r   r,   †   s
   ÿz#CreateDefaultRoles._get_role_policyc                 C   s(   | j j|t|ƒd�}| j j||d� |S )z]Method to create role with a given rolename, assume_role_policy
        and role_arn
        )ÚRoleNameÚAssumeRolePolicyDocument)rB   rM   )r!   r:   r
   Úattach_role_policy)r   r-   Úassume_role_policyr.   Úcreate_role_responser   r   r   r+   �   s   ÿÿÿz0CreateDefaultRoles._create_role_with_role_policyc                 C   s4   |dur|d dur|  |d |dœ¡ |S dS dS )z;Method to construct the message to be displayed to the userNÚRole)rR   Ú
RolePolicy)Úappend)r   Úlist_valÚresponseÚpolicyr   r   r   r3   Ÿ   s   þz<CreateDefaultRoles._construct_role_and_role_policy_structurec              
   C   óR   z
| j j|d� W dS  ty( } z|jd d dkr"W Y d}~dS |‚d}~ww )ú,Method to verify if a particular role exists©ÚInstanceProfileNameÚErrorÚCodeÚNoSuchEntityNFT)r!   Úget_instance_profiler   rV   )r   rA   Úer   r   r   r;   ©   s   ÿö€øz4CreateDefaultRoles._check_if_instance_profile_existsc              
   C   rX   )rY   )rM   r\   r]   r^   NFT)r!   Úget_roler   rV   )r   r-   r`   r   r   r   r(   ¼   s   ö€øz(CreateDefaultRoles._check_if_role_existsc                 C   s"   | j j|d� | j j||d� dS )z3Method to create the instance profile with the rolerZ   )r[   rM   N)r!   Úcreate_instance_profileÚadd_role_to_instance_profile)r   rA   r-   r   r   r   r<   Í   s   ÿ
ÿz5CreateDefaultRoles._create_instance_profile_with_roler   )Ú__name__Ú
__module__Ú__qualname__ÚNAMEr   r   ÚDESCRIPTIONr   r&   r2   r9   r"   r,   r+   r3   r;   r(   r<   Ú__classcell__r   r   r   r   r       s,    ÿÿþý#	
r   )ÚloggingÚ,awscli.customizations.datapipeline.constantsr   r   r   r   r   r   Úawscli.customizations.commandsr   Ú-awscli.customizations.datapipeline.translatorr	   r
   r   Úbotocore.exceptionsr   Ú	getLoggerrd   r)   r   r   r   r   r   Ú<module>   s    
