2020-04-01 08:08:00 -04:00
|
|
|
# frozen_string_literal: true
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
require_dependency 'api/validations/validators/limit'
|
|
|
|
|
2020-04-01 08:08:00 -04:00
|
|
|
module API
|
|
|
|
module Terraform
|
2020-10-14 20:08:42 -04:00
|
|
|
class State < ::API::Base
|
2020-04-21 11:21:10 -04:00
|
|
|
include ::Gitlab::Utils::StrongMemoize
|
|
|
|
|
2020-10-30 14:08:56 -04:00
|
|
|
feature_category :infrastructure_as_code
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
default_format :json
|
|
|
|
|
|
|
|
before do
|
|
|
|
authenticate!
|
2020-07-14 02:09:17 -04:00
|
|
|
authorize! :read_terraform_state, user_project
|
2020-12-22 16:10:06 -05:00
|
|
|
|
|
|
|
increment_unique_values('p_terraform_state_api_unique_users', current_user.id)
|
2020-04-21 11:21:10 -04:00
|
|
|
end
|
2020-04-01 08:08:00 -04:00
|
|
|
|
|
|
|
params do
|
|
|
|
requires :id, type: String, desc: 'The ID of a project'
|
|
|
|
end
|
2020-04-21 11:21:10 -04:00
|
|
|
|
2020-04-01 08:08:00 -04:00
|
|
|
resource :projects, requirements: API::NAMESPACE_OR_PROJECT_REQUIREMENTS do
|
|
|
|
namespace ':id/terraform/state/:name' do
|
2020-04-21 11:21:10 -04:00
|
|
|
params do
|
|
|
|
requires :name, type: String, desc: 'The name of a Terraform state'
|
|
|
|
optional :ID, type: String, limit: 255, desc: 'Terraform state lock ID'
|
|
|
|
end
|
|
|
|
|
|
|
|
helpers do
|
|
|
|
def remote_state_handler
|
|
|
|
::Terraform::RemoteStateHandler.new(user_project, current_user, name: params[:name], lock_id: params[:ID])
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2020-04-01 08:08:00 -04:00
|
|
|
desc 'Get a terraform state by its name'
|
2020-06-16 11:08:32 -04:00
|
|
|
route_setting :authentication, basic_auth_personal_access_token: true, job_token_allowed: :basic_auth
|
2020-04-01 08:08:00 -04:00
|
|
|
get do
|
2020-04-21 11:21:10 -04:00
|
|
|
remote_state_handler.find_with_lock do |state|
|
2020-09-16 08:10:15 -04:00
|
|
|
no_content! unless state.latest_file && state.latest_file.exists?
|
2020-04-21 11:21:10 -04:00
|
|
|
|
|
|
|
env['api.format'] = :binary # this bypasses json serialization
|
2020-09-16 08:10:15 -04:00
|
|
|
body state.latest_file.read
|
2020-04-21 11:21:10 -04:00
|
|
|
end
|
2020-04-01 08:08:00 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
desc 'Add a new terraform state or update an existing one'
|
2020-06-16 11:08:32 -04:00
|
|
|
route_setting :authentication, basic_auth_personal_access_token: true, job_token_allowed: :basic_auth
|
2020-04-01 08:08:00 -04:00
|
|
|
post do
|
2020-07-14 02:09:17 -04:00
|
|
|
authorize! :admin_terraform_state, user_project
|
|
|
|
|
2020-04-24 02:10:09 -04:00
|
|
|
data = request.body.read
|
2020-04-21 11:21:10 -04:00
|
|
|
no_content! if data.empty?
|
|
|
|
|
|
|
|
remote_state_handler.handle_with_lock do |state|
|
2020-10-25 20:09:02 -04:00
|
|
|
state.update_file!(CarrierWaveStringFile.new(data), version: params[:serial], build: current_authenticated_job)
|
2020-04-21 11:21:10 -04:00
|
|
|
end
|
2020-11-02 16:09:10 -05:00
|
|
|
|
|
|
|
body false
|
|
|
|
status :ok
|
2020-04-01 08:08:00 -04:00
|
|
|
end
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
desc 'Delete a terraform state of a certain name'
|
2020-06-16 11:08:32 -04:00
|
|
|
route_setting :authentication, basic_auth_personal_access_token: true, job_token_allowed: :basic_auth
|
2020-04-01 08:08:00 -04:00
|
|
|
delete do
|
2020-07-14 02:09:17 -04:00
|
|
|
authorize! :admin_terraform_state, user_project
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
remote_state_handler.handle_with_lock do |state|
|
|
|
|
state.destroy!
|
|
|
|
end
|
2020-11-02 16:09:10 -05:00
|
|
|
|
|
|
|
body false
|
|
|
|
status :ok
|
2020-04-21 11:21:10 -04:00
|
|
|
end
|
|
|
|
|
|
|
|
desc 'Lock a terraform state of a certain name'
|
2020-06-16 11:08:32 -04:00
|
|
|
route_setting :authentication, basic_auth_personal_access_token: true, job_token_allowed: :basic_auth
|
2020-04-21 11:21:10 -04:00
|
|
|
params do
|
|
|
|
requires :ID, type: String, limit: 255, desc: 'Terraform state lock ID'
|
|
|
|
requires :Operation, type: String, desc: 'Terraform operation'
|
|
|
|
requires :Info, type: String, desc: 'Terraform info'
|
|
|
|
requires :Who, type: String, desc: 'Terraform state lock owner'
|
|
|
|
requires :Version, type: String, desc: 'Terraform version'
|
|
|
|
requires :Created, type: String, desc: 'Terraform state lock timestamp'
|
|
|
|
requires :Path, type: String, desc: 'Terraform path'
|
|
|
|
end
|
|
|
|
post '/lock' do
|
2020-07-14 02:09:17 -04:00
|
|
|
authorize! :admin_terraform_state, user_project
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
status_code = :ok
|
|
|
|
lock_info = {
|
|
|
|
'Operation' => params[:Operation],
|
|
|
|
'Info' => params[:Info],
|
|
|
|
'Version' => params[:Version],
|
|
|
|
'Path' => params[:Path]
|
|
|
|
}
|
|
|
|
|
|
|
|
begin
|
|
|
|
remote_state_handler.lock!
|
|
|
|
rescue ::Terraform::RemoteStateHandler::StateLockedError
|
|
|
|
status_code = :conflict
|
|
|
|
end
|
|
|
|
|
|
|
|
remote_state_handler.find_with_lock do |state|
|
|
|
|
lock_info['ID'] = state.lock_xid
|
|
|
|
lock_info['Who'] = state.locked_by_user.username
|
|
|
|
lock_info['Created'] = state.locked_at
|
|
|
|
|
|
|
|
env['api.format'] = :binary # this bypasses json serialization
|
|
|
|
body lock_info.to_json
|
|
|
|
status status_code
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
desc 'Unlock a terraform state of a certain name'
|
2020-06-16 11:08:32 -04:00
|
|
|
route_setting :authentication, basic_auth_personal_access_token: true, job_token_allowed: :basic_auth
|
2020-04-21 11:21:10 -04:00
|
|
|
params do
|
|
|
|
optional :ID, type: String, limit: 255, desc: 'Terraform state lock ID'
|
|
|
|
end
|
|
|
|
delete '/lock' do
|
2020-07-14 02:09:17 -04:00
|
|
|
authorize! :admin_terraform_state, user_project
|
|
|
|
|
2020-04-21 11:21:10 -04:00
|
|
|
remote_state_handler.unlock!
|
|
|
|
status :ok
|
|
|
|
rescue ::Terraform::RemoteStateHandler::StateLockedError
|
|
|
|
status :conflict
|
2020-04-01 08:08:00 -04:00
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|
|
|
|
end
|