-
Notifications
You must be signed in to change notification settings - Fork 0
/
config.go
108 lines (95 loc) · 2.19 KB
/
config.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
package eks_cert_fingerprint_indexer
import (
"log"
"os"
"regexp"
"strconv"
)
const (
CertificateIndexEnvVar = "CERT_INDEX"
SSMKeyPrefixEnvVar = "SSM_KEY_PFX"
SSMOverwriteEnvVar = "SSM_OVERWRITE"
VerifyCertChainEnvVar = "VERIFY_CERTS"
DefaultCertificateIndex = 0
DefaultSSMKeyPrefix = "/eks_cluster_oidc_fingerprints/"
DefaultSSMOverwrite = false
DefaultVerifyCertChain = true
ssmPathPattern = "^/[0-9A-Za-z_/.-]+/$"
)
var (
ssmRegex = regexp.MustCompile(ssmPathPattern)
)
type Config struct {
CertificateIndex int
SSMKeyPrefix string
SSMOverwrite bool
VerifyCertChain bool
}
func NewConfig() Config {
return Config{
CertificateIndex: DefaultCertificateIndex,
SSMKeyPrefix: DefaultSSMKeyPrefix,
SSMOverwrite: DefaultSSMOverwrite,
VerifyCertChain: DefaultVerifyCertChain,
}
}
func NewConfigFromEnv() Config {
config := NewConfig()
if certIdx := os.Getenv(CertificateIndexEnvVar); certIdx != "" {
if certIdxVal, err := strconv.Atoi(certIdx); err == nil {
config.CertificateIndex = certIdxVal
} else {
log.Println(
"error - unable to parse env var:",
CertificateIndexEnvVar,
"value:",
certIdx,
"err:",
err,
)
}
}
if ssmPfx := os.Getenv(SSMKeyPrefixEnvVar); ssmPfx != "" {
if ssmRegex.MatchString(ssmPfx) {
config.SSMKeyPrefix = ssmPfx
} else {
log.Println(
"error - invalid env var value:",
SSMKeyPrefixEnvVar,
"value:",
ssmPfx,
"validation pattern:",
ssmPathPattern,
)
}
}
if ssmOverwrite := os.Getenv(SSMOverwriteEnvVar); ssmOverwrite != "" {
if ssmOverwriteVal, err := strconv.ParseBool(ssmOverwrite); err == nil {
config.SSMOverwrite = ssmOverwriteVal
} else {
log.Println(
"error - unable to parse env var:",
SSMOverwriteEnvVar,
"value:",
ssmOverwrite,
"err:",
err,
)
}
}
if verifyCerts := os.Getenv(VerifyCertChainEnvVar); verifyCerts != "" {
if verifyCertsVal, err := strconv.ParseBool(verifyCerts); err == nil {
config.VerifyCertChain = verifyCertsVal
} else {
log.Println(
"error - unable to parse env var:",
VerifyCertChainEnvVar,
"value:",
verifyCerts,
"err:",
err,
)
}
}
return config
}