o
    .&ßa:  ã                   @   s’   d dl Z d dlmZ d dlmZ d dlmZ d dlmZ d dl	m
Z
mZmZmZmZ e  e¡Zdd„ Zd	d
„ Zdd„ Zdd„ ZG dd„ deƒZdS )é    N)ÚCLIOperationCaller)Úget_policy_arn_suffix)ÚBasicCommand)ÚIAM)Ú	RESOURCESÚ$LIFECYCLE_DEFAULT_ROLE_ASSUME_POLICYÚPOLICY_ARN_PATTERNÚRESOURCE_TYPE_SNAPSHOTÚRESOURCE_TYPE_IMAGEc                 C   s.   |  dd ¡ |   dd ¡ d|i}| | ¡ |S )NÚResponseMetadataÚ
RolePolicy)ÚpopÚupdate)Úcreate_role_responseÚget_policy_responseÚresult© r   úM/usr/lib/python3/dist-packages/awscli/customizations/dlm/createdefaultrole.pyÚ_construct_result   s
   
r   c                 C   s&   |d urt | ƒ}| |||¡ d S d S ©N)r   Ú_display_response)ÚsessionÚoperation_namer   Úparsed_globalsÚcli_operation_callerr   r   r   Údisplay_response'   s   ÿür   c                 C   s   t | ƒ}t ||¡}|S r   )r   r   Úformat)ÚregionÚpolicy_nameÚregion_suffixÚrole_arnr   r   r   Úget_policy_arn1   s   r!   c                 C   s   |j }|d u r|  d¡}|S )Nr   )r   Úget_config_variable)r   r   r   r   r   r   Ú
get_region8   s   
r#   c                       s\   e Zd ZdZdZddddœdeeegdeeef d	œgZ‡ fd
d„Zdd„ Z	dd„ Z
‡  ZS )ÚCreateDefaultRolezcreate-default-rolezþCreates the default IAM role  which will be used by Lifecycle service.
If the role does not exist, create-default-role will automatically create it and set its policy. If the role has been already created, create-default-role will not update its policy.
ziam-endpointTz¡<p>The IAM endpoint to call for creating the roles. This is optional and should only be specified when a custom endpoint should be called for IAM operations.</p>)ÚnameÚno_paramfileÚ	help_textzresource-typezŠ<p>The resource type for which the role needs to be created. The available options are '%s' and '%s'. This parameter defaults to '%s'.</p>)r%   ÚdefaultÚchoicesr'   c                    s   t t| ƒ |¡ d S r   )Úsuperr$   Ú__init__)Úselfr   ©Ú	__class__r   r   r+   \   s   zCreateDefaultRole.__init__c                 C   s\   t | j|ƒ| _|j| _|j| _t| jjd| j| j|j	d�ƒ| _
|  |¡}t| jd||ƒ dS )zCall to run the commandsÚiam)Úregion_nameÚendpoint_urlÚverifyÚcreate_roler   )r#   Ú_sessionÚ_regionÚiam_endpointÚ_endpoint_urlÚresource_typeÚ_resource_typer   Úcreate_clientÚ
verify_sslÚ_iam_clientÚ"_create_default_role_if_not_existsr   )r,   Úparsed_argsr   r   r   r   r   Ú	_run_main_   s"   
ü
üzCreateDefaultRole._run_mainc                 C   sÄ   t | j d }t}| j |¡rt d|¡ dS t d|¡ t| j|ƒ}|du r+t	dƒ‚t
|t | j d ƒ}| j |¡sCt d|¡ dS t d|¡ | j ||¡}| j ||¡ | j |¡}t||ƒS )	zXMethod to create default lifecycle role
            if it doesn't exist already
        Údefault_role_namezRole %s existsNz;Role %s does not exist. Creating default role for LifecyclezYYou must specify a region. You can also configure your region by running "aws configure".Údefault_policy_namez!Managed Policy %s does not exist.zManaged Policy %s exists.)r   r9   r   r<   Úcheck_if_role_existsÚLOGÚdebugr#   r4   Ú
ValueErrorr!   Úcheck_if_policy_existsÚcreate_role_with_trust_policyÚattach_policy_to_roleÚ
get_policyr   )r,   r   Ú	role_nameÚassume_role_policyr   Úmanaged_policy_arnr   r   r   r   r   r=   w   s<   ÿþþÿþ
z4CreateDefaultRole._create_default_role_if_not_exists)Ú__name__Ú
__module__Ú__qualname__ÚNAMEÚDESCRIPTIONr	   r
   Ú	ARG_TABLEr+   r?   r=   Ú__classcell__r   r   r-   r   r$   ?   s(    	þÿýüùr$   )ÚloggingÚawscli.clidriverr   Úawscli.customizations.utilsr   Úawscli.customizations.commandsr   Úawscli.customizations.dlm.iamr   Ú#awscli.customizations.dlm.constantsr   r   r   r	   r
   Ú	getLoggerrM   rC   r   r   r!   r#   r$   r   r   r   r   Ú<module>   s   
	
