o
    .&ßa6  ã                   @   sL  d dl Z d dlZd dlZd dlZd dlmZ d dlmZ d dlm	Z	 d dlm
Z
 d dlmZ d dlmZ d dlmZ d d	lmZ d d
lmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ d dlmZ e  e¡Zdd„ Z dd„ Z!d!dd„Z"dd„ Z#dd„ Z$G dd „ d eƒZ%dS )"é    N)Ú
xform_name)Úget_policy_arn_suffix)Úconfigutils)Úemrutils)Ú
exceptions)ÚCommand)ÚEC2)ÚEC2_ROLE_NAME)ÚROLE_ARN_PATTERN)ÚEMR)ÚEMR_ROLE_NAME)ÚEMR_AUTOSCALING_ROLE_NAME)ÚAPPLICATION_AUTOSCALING)ÚEC2_ROLE_POLICY_NAME)ÚEMR_ROLE_POLICY_NAME)Ú EMR_AUTOSCALING_ROLE_POLICY_NAME)ÚEMR_AUTOSCALING_SERVICE_NAME)Ú!EMR_AUTOSCALING_SERVICE_PRINCIPAL)ÚResolveServicePrincipalErrorc                 C   s   dddd| iddœgdœS )Nz
2008-10-17Ú ÚAllowÚServicezsts:AssumeRole)ÚSidÚEffectÚ	PrincipalÚAction)ÚVersionÚ	Statement© )Úserviceprincipalr   r   úN/usr/lib/python3/dist-packages/awscli/customizations/emr/createdefaultroles.pyÚassume_role_policy-   s   üÿþr!   c                 C   s$   t | ƒ}t d|¡}| d|¡}|S )Nz{{region_suffix}}z{{policy_name}})r   r
   Úreplace)ÚregionÚpolicy_nameÚregion_suffixÚrole_arnr   r   r    Úget_role_policy_arn;   s   r'   c                 C   sF   t |ƒ\}}|d u rtj ¡ }| tkr|| dd¡vrtS | d | S )NÚemrzaws-cnÚ.)Ú)_get_suffix_and_region_from_endpoint_hostÚbotocoreÚsessionÚSessionr   Úget_available_regionsr   )ÚserviceÚendpoint_hostr,   Úsuffixr#   r   r   r    Úget_service_principalB   s   
r2   c                 C   s:   t | ƒ}|d ur|jdkr| d¡}| d¡}||fS t‚)Né   é   )Ú#_get_regex_match_from_endpoint_hostÚ	lastindexÚgroupr   )r0   Úsuffix_matchr1   r#   r   r   r    r*   N   s   

þr*   c                 C   s0   | d u rd S t  d| ¡}|d u rt  d| ¡}|S )Nz+(https?://)([^.]+).elasticmapreduce.([^/]*)z+(https?://elasticmapreduce).([^.]+).([^/]*))ÚreÚmatch)r0   Úregex_matchr   r   r    r5   Z   s   ÿÿr5   c                   @   sŠ   e Zd ZdZde d e d ZddddœgZd	d
„ Zdd„ Z	dd„ Z
dd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ Zdd„ ZdS ) ÚCreateDefaultRoleszcreate-default-roleszCreates the default IAM role z and a»   which can be used when creating the cluster using the create-cluster command. The default roles for EMR use managed policies, which are updated automatically to support future EMR functionality.

If you do not have a Service Role and Instance Profile variable set for your create-cluster command in the AWS CLI config file, create-default-roles will automatically set the values for these variables with these default roles. If you have already set a value for Service Role or Instance Profile, create-default-roles will not automatically set the defaults for these variables in the AWS CLI config file. You can view settings for variables in the config file using the "aws configure get" command.
ziam-endpointTz¡<p>The IAM endpoint to call for creating the roles. This is optional and should only be specified when a custom endpoint should be called for IAM operations.</p>)ÚnameÚno_paramfileÚ	help_textc           
      C   s  |j | _|  | j| j¡ | jjd| j|j|jd�jj| _	t
 d| j	 ¡ |  |tttg¡\}}t}|  ||¡rAt
 d| d ¡ nt
 d| d | ¡ |  |||¡ |  |tttg¡\}}|  |ttttg¡\}}	t | j¡ t | jd|  ||||||	¡|¡ dS )	Nr(   ©Úregion_nameÚendpoint_urlÚverifyz@elasticmapreduce endpoint used for resolving service principal: zInstance Profile ú exists.z2does not exist. Creating default Instance Profile Úcreate_roler   )Úiam_endpointÚiam_endpoint_urlÚ_check_for_iam_endpointr#   Ú_sessionÚcreate_clientrB   Ú
verify_sslÚmetaÚemr_endpoint_urlÚLOGÚdebugÚ_create_role_if_not_existsr	   r   r   Ú check_if_instance_profile_existsÚ"_create_instance_profile_with_roler   r   r   r   r   r   r   Úupdate_rolesr   Údisplay_responseÚ_construct_result)
ÚselfÚparsed_argsÚparsed_globalsÚ
ec2_resultÚ
ec2_policyÚinstance_profile_nameÚ
emr_resultÚ
emr_policyÚemr_autoscaling_resultÚemr_autoscaling_policyr   r   r    Ú_run_main_command‚   s`   üûÿÿÿ
ÿþþÿÿÿþúz$CreateDefaultRoles._run_main_commandc                 C   st   d }d }|   ||¡rt d| d ¡ ||fS t d| d | ¡ t| j|ƒ}|  ||||¡}|  ||¡}||fS )NzRole rD   z( does not exist. Creating default role: )Úcheck_if_role_existsrN   rO   r'   r#   Ú_create_role_with_role_policyÚ_get_role_policy)rV   rX   Ú	role_namer$   Úservice_namesÚresultÚpolicyr&   r   r   r    rP   ¶   s   úÿÿz-CreateDefaultRoles._create_role_if_not_existsc                 C   sB   z
| j  d|¡ W d S  tjjy    |d u rtj|d�‚Y d S w )Nr(   )r#   )rI   rJ   r+   r   ÚUnknownEndpointErrorÚUnknownIamEndpointError)rV   r#   rF   r   r   r    rH   Å   s   ÿÿz*CreateDefaultRoles._check_for_iam_endpointc                 C   s2   g }|   |||¡ |   |||¡ |   |||¡ |S ©N)Ú)_construct_role_and_role_policy_structure)rV   Úec2_responserZ   Úemr_responser]   Úemr_autoscaling_responser_   rf   r   r   r    rU   Ì   s   ÿÿÿz$CreateDefaultRoles._construct_resultc                 C   s4   |d ur|d d ur|  |d |dœ¡ |S d S d S )NÚRole)ro   Ú
RolePolicy)Úappend)rV   ÚlistÚresponserg   r   r   r    rk   Ø   s   þz<CreateDefaultRoles._construct_role_and_role_policy_structurec              
   C   sn   d|i}z
|   d||¡ W dS  tjjy6 } zd}|j di ¡ dd¡}||kr0W Y d }~dS |‚d }~ww )	NÚRoleNameÚGetRoleÚNoSuchEntityÚErrorÚCoder   FT©Ú_call_iam_operationr+   r   ÚClientErrorrs   Úget)rV   rd   rX   Ú
parametersÚeÚrole_not_found_codeÚ
error_coder   r   r    ra   Þ   s   ö€øz'CreateDefaultRoles.check_if_role_existsc              
   C   sl   d|i}z
|   d||¡ W dS  tjjy5 } zd}|j di ¡ d¡}||kr/W Y d }~dS |‚d }~ww )NÚInstanceProfileNameÚGetInstanceProfilerv   rw   rx   FTry   )rV   r[   rX   r}   r~   Úprofile_not_found_coder€   r   r   r    rQ   ï   s   ÿö€øz3CreateDefaultRoles.check_if_instance_profile_existsc                 C   sD   i }||d< |   d||¡}|d d |d< |   d||¡}|d d S )	NÚ	PolicyArnÚ	GetPolicyÚPolicyÚDefaultVersionIdÚ	VersionIdÚGetPolicyVersionÚPolicyVersionÚDocument©rz   )rV   ÚarnrX   r}   Úpolicy_detailsÚpolicy_version_detailsr   r   r    rc     s   ÿþz#CreateDefaultRoles._get_role_policyc           
      C   s¢   t |ƒdkrt|d | j| jƒ}ng }|D ]}| t|| j| jƒ¡ qt |¡ d|i}t t	|ƒ¡}||d< |  
d||¡}	i }||d< ||d< |  
d||¡ |	S )Né   r   rt   ÚAssumeRolePolicyDocumentÚ
CreateRoler„   ÚAttachRolePolicy)Úlenr2   rM   rI   rq   rN   rO   r   Údict_to_stringr!   rz   )
rV   rd   re   r&   rX   Úservice_principalr/   r}   Ú_assume_role_policyÚcreate_role_responser   r   r    rb     s2   ÿ
ÿ
ÿþÿz0CreateDefaultRoles._create_role_with_role_policyc                 C   s<   d|i}|   d||¡ i }||d< ||d< |   d||¡ d S )Nr�   ÚCreateInstanceProfilert   ÚAddRoleToInstanceProfilerŒ   )rV   r[   rd   rX   r}   r   r   r    rR   *  s   ÿÿz5CreateDefaultRoles._create_instance_profile_with_rolec                 C   s2   | j jd| j| j|jd�}t|t|ƒƒdi |¤ŽS )NÚiamr@   r   )rI   rJ   r#   rG   rK   Úgetattrr   )rV   Úoperation_namer}   rX   Úclientr   r   r    rz   7  s
   
þz&CreateDefaultRoles._call_iam_operationN)Ú__name__Ú
__module__Ú__qualname__ÚNAMEr	   r   ÚDESCRIPTIONÚ	ARG_TABLEr`   rP   rH   rU   rk   ra   rQ   rc   rb   rR   rz   r   r   r   r    r<   g   s6    ÿÿþþþÿ	4r<   rj   )&Úloggingr9   Úbotocore.exceptionsr+   Úbotocore.sessionr   Úawscli.customizations.utilsr   Úawscli.customizations.emrr   r   r   Ú!awscli.customizations.emr.commandr   Ú#awscli.customizations.emr.constantsr   r	   r
   r   r   r   r   r   r   r   r   r   Ú$awscli.customizations.emr.exceptionsr   Ú	getLoggerrŸ   rN   r!   r'   r2   r*   r5   r<   r   r   r   r    Ú<module>   s<   

