o
    .&ßa˜  ã                   @   s¬   d dl Z d dlZd dlZd dlmZmZ d dlmZ d dlmZ d dl	m
Z
 d dlmZ dZdZd	Zd
ZdZdZdZdZG dd„ de
ƒZG dd„ deƒZG dd„ deƒZdS )é    N)ÚdatetimeÚ	timedelta)ÚRequestSigner)Ú	ServiceId)ÚBasicCommand)Ú	uni_printÚstsÚGetCallerIdentityz
2011-06-15Úv4é<   é   zk8s-aws-v1.zx-k8s-aws-idc                   @   s<   e Zd ZdZdZddddœddd	dœgZd
d„ Zdd„ ZdS )ÚGetTokenCommandz	get-tokenz{Get a token for authentication with an Amazon EKS cluster. This can be used as an alternative to the aws-iam-authenticator.zcluster-namezASpecify the name of the Amazon EKS cluster to create a token for.T)ÚnameÚ	help_textÚrequiredzrole-arnz8Assume this role for credentials when signing the token.Fc                 C   s   t  ¡ ttd� }| d¡S )N)Úminutesz%Y-%m-%dT%H:%M:%SZ)r   Úutcnowr   ÚTOKEN_EXPIRATION_MINSÚstrftime)ÚselfÚtoken_expiration© r   úE/usr/lib/python3/dist-packages/awscli/customizations/eks/get_token.pyÚget_expiration_time;   s   
z#GetTokenCommand.get_expiration_timec                 C   sb   t | jƒ}|j|j|jd�}t|ƒ |j¡}|  ¡ }ddi ||dœdœ}t	t
 |¡ƒ t	dƒ dS )N)Úregion_nameÚrole_arnÚExecCredentialz%client.authentication.k8s.io/v1alpha1)ÚexpirationTimestampÚtoken)ÚkindÚ
apiVersionÚspecÚstatusÚ
r   )ÚSTSClientFactoryÚ_sessionÚget_sts_clientÚregionr   ÚTokenGeneratorÚ	get_tokenÚcluster_namer   r   ÚjsonÚdumps)r   Úparsed_argsÚparsed_globalsÚclient_factoryÚ
sts_clientr   r   Úfull_objectr   r   r   Ú	_run_main?   s"   
þþü
zGetTokenCommand._run_mainN)Ú__name__Ú
__module__Ú__qualname__ÚNAMEÚDESCRIPTIONÚ	ARG_TABLEr   r2   r   r   r   r   r   '   s    ýýúr   c                   @   s$   e Zd Zdd„ Zdd„ Zdd„ ZdS )r(   c                 C   ó
   || _ d S ©N)Ú_sts_client©r   r0   r   r   r   Ú__init__[   ó   
zTokenGenerator.__init__c                 C   s.   |   |¡}tt | d¡¡ d¡ d¡ }|S )z4 Generate a presigned url token to pass to kubectl. zutf-8ú=)Ú_get_presigned_urlÚTOKEN_PREFIXÚbase64Úurlsafe_b64encodeÚencodeÚdecodeÚrstrip)r   r*   Úurlr   r   r   r   r)   ^   s   
ÿÿzTokenGenerator.get_tokenc                 C   s   | j jdd|itdd�S )NÚget_caller_identityÚClusterNameÚGET)ÚParamsÚ	ExpiresInÚ
HttpMethod)r;   Úgenerate_presigned_urlÚURL_TIMEOUT)r   r*   r   r   r   r@   e   s   üz!TokenGenerator._get_presigned_urlN)r3   r4   r5   r=   r)   r@   r   r   r   r   r(   Z   s    r(   c                   @   s>   e Zd Zdd„ Zddd„Zdd„ Zdd	„ Zd
d„ Zdd„ ZdS )r$   c                 C   r9   r:   )r%   )r   Úsessionr   r   r   r=   o   r>   zSTSClientFactory.__init__Nc                 C   s`   d|i}|d ur |   ||¡}|d |d< |d |d< |d |d< | jjd	i |¤Ž}|  |¡ |S )
Nr   ÚAccessKeyIdÚaws_access_key_idÚSecretAccessKeyÚaws_secret_access_keyÚSessionTokenÚaws_session_tokenr   )r   )Ú_get_role_credentialsr%   Úcreate_clientÚ_register_cluster_name_handlers)r   r   r   Úclient_kwargsÚcredsr   r   r   r   r&   r   s   ÿ
zSTSClientFactory.get_sts_clientc                 C   s    | j  d|¡}|j|dd�d S )Nr   ÚEKSGetTokenAuth)ÚRoleArnÚRoleSessionNameÚCredentials)r%   rX   Úassume_role)r   r   r   r   r   r   r   rW      s   þýz&STSClientFactory._get_role_credentialsc                 C   s(   |j j d| j¡ |j j d| j¡ d S )Nz+provide-client-params.sts.GetCallerIdentityz!before-sign.sts.GetCallerIdentity)ÚmetaÚeventsÚregisterÚ_retrieve_cluster_nameÚ_inject_cluster_name_headerr<   r   r   r   rY   †   s   þþz0STSClientFactory._register_cluster_name_handlersc                 K   s   d|v r|  d¡|d< d S d S )NrI   Úeks_cluster)Úpop)r   ÚparamsÚcontextÚkwargsr   r   r   rd   �   s   ÿz'STSClientFactory._retrieve_cluster_namec                 K   s"   d|j v r|j d |jt< d S d S )Nrf   )ri   ÚheadersÚCLUSTER_NAME_HEADER)r   Úrequestrj   r   r   r   re   ”   s   
ÿÿÿz,STSClientFactory._inject_cluster_name_header)NN)	r3   r4   r5   r=   r&   rW   rY   rd   re   r   r   r   r   r$   n   s    

r$   )rB   Úbotocorer+   r   r   Úbotocore.signersr   Úbotocore.modelr   Úawscli.customizations.commandsr   Úawscli.customizations.utilsr   ÚAUTH_SERVICEÚAUTH_COMMANDÚAUTH_API_VERSIONÚAUTH_SIGNING_VERSIONrO   r   rA   rl   r   Úobjectr(   r$   r   r   r   r   Ú<module>   s&   3