o
    .&ßaä  ã                   @   sš   d dl Z d dlZd dlmZ d dlmZmZmZ d dlm	Z	 d dl
mZ d dlmZ d dlmZmZ e e¡Zdd	„ Zd
d„ Zdd„ ZG dd„ deƒZdS )é    N)ÚBasicCommand)ÚTRUST_POLICY_STATEMENT_FORMATÚ%TRUST_POLICY_STATEMENT_ALREADY_EXISTSÚTRUST_POLICY_UPDATE_SUCCESSFUL)ÚBase36)ÚEKS)ÚIAM)Ú	uni_printÚget_policy_arn_suffixc                 C   s   |j }|d u r|  d¡}|S )NÚregion)r   Úget_config_variable)ÚsessionÚparsed_globalsr   © r   ú^/usr/lib/python3/dist-packages/awscli/customizations/emrcontainers/update_role_trust_policy.pyÚ
get_region   s   
r   c                 C   s:   |d u rdS |  dg ¡}|D ]}t| |ƒ}|r dS qdS )NFÚ	StatementT)ÚgetÚcheck_if_dict_matches)Úexpected_statementÚactual_assume_role_documentÚexisting_statementsÚexisting_statementÚmatchesr   r   r   Úcheck_if_statement_exists(   s   
ÿr   c                 C   st   t | ƒt |ƒkr
dS | D ]+}t|ƒ}| | }t|tƒr(t|| |i ¡ƒs' dS q||vs4|| t|ƒkr7 dS qdS )NFT)ÚlenÚstrÚ
isinstanceÚdictr   r   )Úexpected_dictÚactual_dictÚkeyÚkey_strÚvalr   r   r   r   5   s   
ÿÿr   c                
   @   sj   e Zd ZdZe ddd¡Zddddœdd	ddœd
dddœdddddœddddddœgZdd„ Zdd„ Z	dS )ÚUpdateRoleTrustPolicyCommandzupdate-role-trust-policyzemr-containersz_description.rstzcluster-namezQSpecify the name of the Amazon EKS cluster with which the IAM Role would be used.T)ÚnameÚ	help_textÚrequiredÚ	namespacezXSpecify the namespace from the Amazon EKS cluster with which the IAM Role would be used.z	role-namezESpecify the IAM Role name that you want to usewith Amazon EMR on EKS.ziam-endpointz§The  IAM  endpoint  to call for updating the role trust policy. This is optional and should only bespecified when a custom endpoint should be calledfor IAM operations.F)r%   Úno_paramfiler&   r'   zdry-runÚ
store_truezbPrint the merged trust policy document tostdout instead of updating the role trustpolicy directly.)r%   ÚactionÚdefaultr&   r'   c                 C   sT   |j | _|j| _|j| _t| j|ƒ| _|j	| _
|j| _|  |¡}t|ƒ tdƒ dS )zCall to run the commandsÚ
r   )Úcluster_nameÚ_cluster_namer(   Ú
_namespaceÚ	role_nameÚ
_role_namer   Ú_sessionÚ_regionÚiam_endpointÚ_endpoint_urlÚdry_runÚ_dry_runÚ_update_role_trust_policyr	   )ÚselfÚparsed_argsr   Úresultr   r   r   Ú	_run_mainv   s   
z&UpdateRoleTrustPolicyCommand._run_mainc              	   C   s:  t ƒ }t| jjd| j|jd�ƒ}| | j¡}| | j¡}| 	| j
¡}t d|¡ t t||| j|t| jƒdœ ¡}t dtj|dd�¡ t| jjd| j| j|jd	�ƒ}| | j
¡}	t||	ƒ}
|
s˜t d
| j
¡ |	 d¡}|du rv|g|	d< n| |¡ | jr…tj|	dd�S t d| j
¡ | | j
|	¡ t| j
 S t| j
 S )z2Method to update  trust policy if not done alreadyÚeks)Úregion_nameÚverifyzBase36 encoded role name: %s)ÚAWS_ACCOUNT_IDÚOIDC_PROVIDERÚ	NAMESPACEÚBASE36_ENCODED_ROLE_NAMEÚAWS_PARTITIONz#Computed Trust Policy Statement:
%sé   )ÚindentÚiam)r?   Úendpoint_urlr@   z0Role %s does not have the required trust policy r   Nz Updating trust policy of role %s)r   r   r3   Úcreate_clientr4   Ú
verify_sslÚget_account_idr/   Úget_oidc_issuer_idÚencoder2   ÚLOGÚdebugÚjsonÚloadsr   r0   r
   Údumpsr   r6   Úget_assume_role_policyr   r   Úappendr8   Úupdate_assume_role_policyr   r   )r:   r   Úbase36Ú
eks_clientÚ
account_idÚoidc_providerÚbase36_encoded_role_nameÚtrust_policy_statementÚ
iam_clientÚassume_role_documentr   r   r   r   r   r9   †   s`   ý
û
ÿüÿÿÿ

ÿ

z6UpdateRoleTrustPolicyCommand._update_role_trust_policyN)
Ú__name__Ú
__module__Ú__qualname__ÚNAMEr   Ú	FROM_FILEÚDESCRIPTIONÚ	ARG_TABLEr=   r9   r   r   r   r   r$   F   sB    ýüüüù
ùä'r$   )rQ   ÚloggingÚawscli.customizations.commandsr   Ú-awscli.customizations.emrcontainers.constantsr   r   r   Ú*awscli.customizations.emrcontainers.base36r   Ú'awscli.customizations.emrcontainers.eksr   Ú'awscli.customizations.emrcontainers.iamr   Úawscli.customizations.utilsr	   r
   Ú	getLoggerr_   rO   r   r   r   r$   r   r   r   r   Ú<module>   s   
	