UNPKG

@aws-cdk/aws-eks-v2-alpha

Version:

The CDK Construct Library for AWS::EKS

318 lines 34.3 kB
"use strict"; var __runInitializers = (this && this.__runInitializers) || function (thisArg, initializers, value) { var useValue = arguments.length > 2; for (var i = 0; i < initializers.length; i++) { value = useValue ? initializers[i].call(thisArg, value) : initializers[i].call(thisArg); } return useValue ? value : void 0; }; var __esDecorate = (this && this.__esDecorate) || function (ctor, descriptorIn, decorators, contextIn, initializers, extraInitializers) { function accept(f) { if (f !== void 0 && typeof f !== "function") throw new TypeError("Function expected"); return f; } var kind = contextIn.kind, key = kind === "getter" ? "get" : kind === "setter" ? "set" : "value"; var target = !descriptorIn && ctor ? contextIn["static"] ? ctor : ctor.prototype : null; var descriptor = descriptorIn || (target ? Object.getOwnPropertyDescriptor(target, contextIn.name) : {}); var _, done = false; for (var i = decorators.length - 1; i >= 0; i--) { var context = {}; for (var p in contextIn) context[p] = p === "access" ? {} : contextIn[p]; for (var p in contextIn.access) context.access[p] = contextIn.access[p]; context.addInitializer = function (f) { if (done) throw new TypeError("Cannot add initializers after decoration has completed"); extraInitializers.push(accept(f || null)); }; var result = (0, decorators[i])(kind === "accessor" ? { get: descriptor.get, set: descriptor.set } : descriptor[key], context); if (kind === "accessor") { if (result === void 0) continue; if (result === null || typeof result !== "object") throw new TypeError("Object expected"); if (_ = accept(result.get)) descriptor.get = _; if (_ = accept(result.set)) descriptor.set = _; if (_ = accept(result.init)) initializers.unshift(_); } else if (_ = accept(result)) { if (kind === "field") initializers.unshift(_); else descriptor[key] = _; } } if (target) Object.defineProperty(target, contextIn.name, descriptor); done = true; }; Object.defineProperty(exports, "__esModule", { value: true }); exports.AccessEntry = exports.AccessEntryType = exports.AccessPolicy = exports.AccessPolicyArn = exports.AccessScopeType = void 0; const jsiiDeprecationWarnings = require("../.warnings.jsii.js"); const JSII_RTTI_SYMBOL_1 = Symbol.for("jsii.rtti"); const aws_eks_1 = require("aws-cdk-lib/aws-eks"); const core_1 = require("aws-cdk-lib/core"); const metadata_resource_1 = require("aws-cdk-lib/core/lib/metadata-resource"); const prop_injectable_1 = require("aws-cdk-lib/core/lib/prop-injectable"); /** * Represents the scope type of an access policy. * * The scope type determines the level of access granted by the policy. * * @export * @enum {string} */ var AccessScopeType; (function (AccessScopeType) { /** * The policy applies to a specific namespace within the cluster. */ AccessScopeType["NAMESPACE"] = "namespace"; /** * The policy applies to the entire cluster. */ AccessScopeType["CLUSTER"] = "cluster"; })(AccessScopeType || (exports.AccessScopeType = AccessScopeType = {})); /** * Represents an Amazon EKS Access Policy ARN. * * Amazon EKS Access Policies are used to control access to Amazon EKS clusters. * * @see https://docs.aws.amazon.com/eks/latest/userguide/access-policies.html */ class AccessPolicyArn { policyName; static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-eks-v2-alpha.AccessPolicyArn", version: "2.223.0-alpha.0" }; /** * The Amazon EKS Admin Policy. This access policy includes permissions that grant an IAM principal * most permissions to resources. When associated to an access entry, its access scope is typically * one or more Kubernetes namespaces. */ static AMAZON_EKS_ADMIN_POLICY = AccessPolicyArn.of('AmazonEKSAdminPolicy'); /** * The Amazon EKS Cluster Admin Policy. This access policy includes permissions that grant an IAM * principal administrator access to a cluster. When associated to an access entry, its access scope * is typically the cluster, rather than a Kubernetes namespace. */ static AMAZON_EKS_CLUSTER_ADMIN_POLICY = AccessPolicyArn.of('AmazonEKSClusterAdminPolicy'); /** * The Amazon EKS Admin View Policy. This access policy includes permissions that grant an IAM principal * access to list/view all resources in a cluster. */ static AMAZON_EKS_ADMIN_VIEW_POLICY = AccessPolicyArn.of('AmazonEKSAdminViewPolicy'); /** * The Amazon EKS Edit Policy. This access policy includes permissions that allow an IAM principal * to edit most Kubernetes resources. */ static AMAZON_EKS_EDIT_POLICY = AccessPolicyArn.of('AmazonEKSEditPolicy'); /** * The Amazon EKS View Policy. This access policy includes permissions that grant an IAM principal * access to list/view all resources in a cluster. */ static AMAZON_EKS_VIEW_POLICY = AccessPolicyArn.of('AmazonEKSViewPolicy'); /** * Creates a new instance of the AccessPolicy class with the specified policy name. * @param policyName The name of the access policy. * @returns A new instance of the AccessPolicy class. */ static of(policyName) { return new AccessPolicyArn(policyName); } /** * The Amazon Resource Name (ARN) of the access policy. */ policyArn; /** * Constructs a new instance of the `AccessEntry` class. * * @param policyName - The name of the Amazon EKS access policy. This is used to construct the policy ARN. */ constructor(policyName) { this.policyName = policyName; this.policyArn = `arn:${core_1.Aws.PARTITION}:eks::aws:cluster-access-policy/${policyName}`; } } exports.AccessPolicyArn = AccessPolicyArn; /** * Represents an Amazon EKS Access Policy that implements the IAccessPolicy interface. * * @implements {IAccessPolicy} */ class AccessPolicy { static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-eks-v2-alpha.AccessPolicy", version: "2.223.0-alpha.0" }; /** * Import AccessPolicy by name. */ static fromAccessPolicyName(policyName, options) { try { jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessPolicyNameOptions(options); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.fromAccessPolicyName); } throw error; } class Import { policy = `arn:${core_1.Aws.PARTITION}:eks::aws:cluster-access-policy/${policyName}`; accessScope = { type: options.accessScopeType, namespaces: options.namespaces, }; } return new Import(); } /** * The scope of the access policy, which determines the level of access granted. */ accessScope; /** * The access policy itself, which defines the specific permissions. */ policy; /** * Constructs a new instance of the AccessPolicy class. * * @param {AccessPolicyProps} props - The properties for configuring the access policy. */ constructor(props) { try { jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessPolicyProps(props); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, AccessPolicy); } throw error; } this.accessScope = props.accessScope; this.policy = props.policy.policyArn; } } exports.AccessPolicy = AccessPolicy; /** * Represents the different types of access entries that can be used in an Amazon EKS cluster. * * @enum {string} */ var AccessEntryType; (function (AccessEntryType) { /** * Represents a standard access entry. */ AccessEntryType["STANDARD"] = "STANDARD"; /** * Represents a Fargate Linux access entry. */ AccessEntryType["FARGATE_LINUX"] = "FARGATE_LINUX"; /** * Represents an EC2 Linux access entry. */ AccessEntryType["EC2_LINUX"] = "EC2_LINUX"; /** * Represents an EC2 Windows access entry. */ AccessEntryType["EC2_WINDOWS"] = "EC2_WINDOWS"; })(AccessEntryType || (exports.AccessEntryType = AccessEntryType = {})); /** * Represents an access entry in an Amazon EKS cluster. * * An access entry defines the permissions and scope for a user or role to access an Amazon EKS cluster. * * @implements {IAccessEntry} * @resource AWS::EKS::AccessEntry */ let AccessEntry = (() => { let _classDecorators = [prop_injectable_1.propertyInjectable]; let _classDescriptor; let _classExtraInitializers = []; let _classThis; let _classSuper = core_1.Resource; let _instanceExtraInitializers = []; let _addAccessPolicies_decorators; var AccessEntry = class extends _classSuper { static { _classThis = this; } static { const _metadata = typeof Symbol === "function" && Symbol.metadata ? Object.create(_classSuper[Symbol.metadata] ?? null) : void 0; _addAccessPolicies_decorators = [(0, metadata_resource_1.MethodMetadata)()]; __esDecorate(this, null, _addAccessPolicies_decorators, { kind: "method", name: "addAccessPolicies", static: false, private: false, access: { has: obj => "addAccessPolicies" in obj, get: obj => obj.addAccessPolicies }, metadata: _metadata }, null, _instanceExtraInitializers); __esDecorate(null, _classDescriptor = { value: _classThis }, _classDecorators, { kind: "class", name: _classThis.name, metadata: _metadata }, null, _classExtraInitializers); AccessEntry = _classThis = _classDescriptor.value; if (_metadata) Object.defineProperty(_classThis, Symbol.metadata, { enumerable: true, configurable: true, writable: true, value: _metadata }); } static [JSII_RTTI_SYMBOL_1] = { fqn: "@aws-cdk/aws-eks-v2-alpha.AccessEntry", version: "2.223.0-alpha.0" }; /** Uniquely identifies this class. */ static PROPERTY_INJECTION_ID = '@aws-cdk.aws-eks-v2-alpha.AccessEntry'; /** * Imports an `AccessEntry` from its attributes. * * @param scope - The parent construct. * @param id - The ID of the imported construct. * @param attrs - The attributes of the access entry to import. * @returns The imported access entry. */ static fromAccessEntryAttributes(scope, id, attrs) { try { jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessEntryAttributes(attrs); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, this.fromAccessEntryAttributes); } throw error; } class Import extends core_1.Resource { accessEntryName = attrs.accessEntryName; accessEntryArn = attrs.accessEntryArn; } return new Import(scope, id); } /** * The name of the access entry. */ accessEntryName = __runInitializers(this, _instanceExtraInitializers); /** * The Amazon Resource Name (ARN) of the access entry. */ accessEntryArn; cluster; principal; accessPolicies; constructor(scope, id, props) { super(scope, id); try { jsiiDeprecationWarnings._aws_cdk_aws_eks_v2_alpha_AccessEntryProps(props); } catch (error) { if (process.env.JSII_DEBUG !== "1" && error.name === "DeprecationError") { Error.captureStackTrace(error, AccessEntry); } throw error; } // Enhanced CDK Analytics Telemetry (0, metadata_resource_1.addConstructMetadata)(this, props); this.cluster = props.cluster; this.principal = props.principal; this.accessPolicies = props.accessPolicies; const resource = new aws_eks_1.CfnAccessEntry(this, 'Resource', { clusterName: this.cluster.clusterName, principalArn: this.principal, type: props.accessEntryType, accessPolicies: core_1.Lazy.any({ produce: () => this.accessPolicies.map(p => ({ accessScope: { type: p.accessScope.type, namespaces: p.accessScope.namespaces, }, policyArn: p.policy, })), }), }); this.accessEntryName = this.getResourceNameAttribute(resource.ref); this.accessEntryArn = this.getResourceArnAttribute(resource.attrAccessEntryArn, { service: 'eks', resource: 'accessentry', resourceName: this.physicalName, }); } /** * Add the access policies for this entry. * @param newAccessPolicies - The new access policies to add. */ addAccessPolicies(newAccessPolicies) { // add newAccessPolicies to this.accessPolicies this.accessPolicies.push(...newAccessPolicies); } static { __runInitializers(_classThis, _classExtraInitializers); } }; return AccessEntry = _classThis; })(); exports.AccessEntry = AccessEntry; //# sourceMappingURL=data:application/json;base64,