external_projects.go 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773
  1. // Copyright 2019 Yunion
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package models
  15. import (
  16. "context"
  17. "database/sql"
  18. "fmt"
  19. "strings"
  20. "time"
  21. "yunion.io/x/cloudmux/pkg/cloudprovider"
  22. "yunion.io/x/jsonutils"
  23. "yunion.io/x/log"
  24. "yunion.io/x/pkg/errors"
  25. "yunion.io/x/pkg/util/compare"
  26. "yunion.io/x/pkg/util/rbacscope"
  27. "yunion.io/x/pkg/utils"
  28. "yunion.io/x/sqlchemy"
  29. "yunion.io/x/onecloud/pkg/apis"
  30. api "yunion.io/x/onecloud/pkg/apis/compute"
  31. "yunion.io/x/onecloud/pkg/cloudcommon/consts"
  32. "yunion.io/x/onecloud/pkg/cloudcommon/db"
  33. "yunion.io/x/onecloud/pkg/cloudcommon/db/lockman"
  34. "yunion.io/x/onecloud/pkg/cloudcommon/db/taskman"
  35. "yunion.io/x/onecloud/pkg/cloudcommon/validators"
  36. "yunion.io/x/onecloud/pkg/compute/options"
  37. "yunion.io/x/onecloud/pkg/httperrors"
  38. "yunion.io/x/onecloud/pkg/mcclient"
  39. "yunion.io/x/onecloud/pkg/mcclient/auth"
  40. "yunion.io/x/onecloud/pkg/mcclient/modules/identity"
  41. "yunion.io/x/onecloud/pkg/util/logclient"
  42. "yunion.io/x/onecloud/pkg/util/stringutils2"
  43. )
  44. // +onecloud:swagger-gen-model-singular=externalproject
  45. // +onecloud:swagger-gen-model-plural=externalprojects
  46. type SExternalProjectManager struct {
  47. db.SVirtualResourceBaseManager
  48. db.SExternalizedResourceBaseManager
  49. SManagedResourceBaseManager
  50. }
  51. var ExternalProjectManager *SExternalProjectManager
  52. func init() {
  53. ExternalProjectManager = &SExternalProjectManager{
  54. SVirtualResourceBaseManager: db.NewVirtualResourceBaseManager(
  55. SExternalProject{},
  56. "externalprojects_tbl",
  57. "externalproject",
  58. "externalprojects",
  59. ),
  60. }
  61. ExternalProjectManager.SetVirtualObject(ExternalProjectManager)
  62. }
  63. type SExternalProject struct {
  64. db.SVirtualResourceBase
  65. db.SExternalizedResourceBase
  66. SManagedResourceBase
  67. // 优先级,同一个本地项目映射多个云上项目,优先级高的优先选择
  68. // 数值越高,优先级越大
  69. Priority int `default:"0" list:"user" update:"user" list:"user"`
  70. // swagger: ignore
  71. // 将在3.12之后版本移除
  72. CloudaccountId string `width:"36" charset:"ascii" nullable:"true"`
  73. }
  74. func (manager *SExternalProjectManager) ValidateCreateData(
  75. ctx context.Context,
  76. userCred mcclient.TokenCredential,
  77. ownerId mcclient.IIdentityProvider,
  78. query jsonutils.JSONObject,
  79. input api.ExternalProjectCreateInput,
  80. ) (api.ExternalProjectCreateInput, error) {
  81. _, err := validators.ValidateModel(ctx, userCred, CloudproviderManager, &input.ManagerId)
  82. if err != nil {
  83. return input, err
  84. }
  85. input.VirtualResourceCreateInput, err = manager.SVirtualResourceBaseManager.ValidateCreateData(ctx, userCred, ownerId, query, input.VirtualResourceCreateInput)
  86. if err != nil {
  87. return input, errors.Wrap(err, "SVirtualResourceBaseManager.ValidateCreateData")
  88. }
  89. // check duplicity
  90. exist, err := manager.recordExists(input.ManagerId, input.Name, ownerId.GetProjectId())
  91. if err != nil {
  92. return input, errors.Wrap(err, "recordExits")
  93. } else if exist {
  94. return input, errors.Wrapf(httperrors.ErrDuplicateResource, "manager_id: %s name: %s project: %s", input.ManagerId, input.Name, ownerId.GetProjectId())
  95. }
  96. return input, nil
  97. }
  98. func (manager *SExternalProjectManager) recordExists(managerId, name, projectId string) (bool, error) {
  99. q := manager.Query()
  100. q = q.Equals("name", name)
  101. q = q.Equals("tenant_id", projectId)
  102. if len(managerId) > 0 {
  103. q = q.Equals("manager_id", managerId)
  104. }
  105. cnt, err := q.CountWithError()
  106. if err != nil {
  107. return false, errors.Wrap(err, "CountWithError")
  108. }
  109. return cnt > 0, nil
  110. }
  111. func (extProj *SExternalProject) RemoteCreateProject(ctx context.Context, userCred mcclient.TokenCredential) error {
  112. err := extProj.remoteCreateProjectInternal(ctx, userCred)
  113. if err == nil {
  114. return nil
  115. }
  116. extProj.SetStatus(ctx, userCred, api.EXTERNAL_PROJECT_STATUS_UNAVAILABLE, err.Error())
  117. return errors.Wrap(err, "remoteCreateProjectInternal")
  118. }
  119. func (extProj *SExternalProject) remoteCreateProjectInternal(ctx context.Context, userCred mcclient.TokenCredential) error {
  120. provider, err := extProj.GetCloudprovider()
  121. if err != nil {
  122. return errors.Wrap(err, "GetCloudaccount")
  123. }
  124. driver, err := provider.GetProvider(ctx)
  125. if err != nil {
  126. return errors.Wrap(err, "account.GetProvider")
  127. }
  128. iProj, err := driver.CreateIProject(extProj.Name)
  129. if err != nil {
  130. return errors.Wrapf(err, "driver.CreateIProject")
  131. }
  132. _, err = db.Update(extProj, func() error {
  133. extProj.ExternalId = iProj.GetGlobalId()
  134. extProj.Status = api.EXTERNAL_PROJECT_STATUS_AVAILABLE
  135. return nil
  136. })
  137. if err != nil {
  138. return errors.Wrap(err, "Update Status")
  139. }
  140. db.OpsLog.LogEvent(extProj, db.ACT_UPDATE, extProj.GetShortDesc(ctx), userCred)
  141. logclient.AddActionLogWithContext(ctx, extProj, logclient.ACT_UPDATE, extProj.GetShortDesc(ctx), userCred, true)
  142. return nil
  143. }
  144. func (extProj *SExternalProject) CustomizeCreate(
  145. ctx context.Context,
  146. userCred mcclient.TokenCredential,
  147. ownerId mcclient.IIdentityProvider,
  148. query jsonutils.JSONObject,
  149. data jsonutils.JSONObject,
  150. ) error {
  151. return extProj.SVirtualResourceBase.CustomizeCreate(ctx, userCred, ownerId, query, data)
  152. }
  153. func (extProj *SExternalProject) PostCreate(
  154. ctx context.Context,
  155. userCred mcclient.TokenCredential,
  156. ownerId mcclient.IIdentityProvider,
  157. query jsonutils.JSONObject,
  158. data jsonutils.JSONObject,
  159. ) {
  160. extProj.SVirtualResourceBase.PostCreate(ctx, userCred, ownerId, query, data)
  161. extProj.startExternalProjectCreateTask(ctx, userCred)
  162. }
  163. func (extProj *SExternalProject) startExternalProjectCreateTask(ctx context.Context, userCred mcclient.TokenCredential) error {
  164. extProj.SetStatus(ctx, userCred, api.EXTERNAL_PROJECT_STATUS_CREATING, "")
  165. params := jsonutils.NewDict()
  166. task, err := taskman.TaskManager.NewTask(ctx, "ExternalProjectCreateTask", extProj, userCred, params, "", "", nil)
  167. if err != nil {
  168. return err
  169. }
  170. task.ScheduleRun(nil)
  171. return nil
  172. }
  173. func (manager *SExternalProjectManager) FetchCustomizeColumns(
  174. ctx context.Context,
  175. userCred mcclient.TokenCredential,
  176. query jsonutils.JSONObject,
  177. objs []interface{},
  178. fields stringutils2.SSortedStrings,
  179. isList bool,
  180. ) []api.ExternalProjectDetails {
  181. rows := make([]api.ExternalProjectDetails, len(objs))
  182. virRows := manager.SVirtualResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
  183. managerRows := manager.SManagedResourceBaseManager.FetchCustomizeColumns(ctx, userCred, query, objs, fields, isList)
  184. for i := range rows {
  185. rows[i] = api.ExternalProjectDetails{
  186. VirtualResourceDetails: virRows[i],
  187. ManagedResourceInfo: managerRows[i],
  188. }
  189. }
  190. return rows
  191. }
  192. func (manager *SExternalProjectManager) GetProject(externalId string, providerId string) (*SExternalProject, error) {
  193. project := &SExternalProject{}
  194. project.SetModelManager(manager, project)
  195. q := manager.Query().Equals("external_id", externalId).Equals("manager_id", providerId)
  196. count, err := q.CountWithError()
  197. if err != nil {
  198. return nil, err
  199. }
  200. if count == 0 {
  201. return nil, fmt.Errorf("no external project record %s for provider %s", externalId, providerId)
  202. }
  203. if count > 1 {
  204. return nil, fmt.Errorf("duplicate external project record %s for provider %s", externalId, providerId)
  205. }
  206. return project, q.First(project)
  207. }
  208. func (cp *SCloudprovider) GetExternalProjects() ([]SExternalProject, error) {
  209. projects := []SExternalProject{}
  210. q := ExternalProjectManager.Query().Equals("manager_id", cp.Id)
  211. err := db.FetchModelObjects(ExternalProjectManager, q, &projects)
  212. if err != nil {
  213. return nil, errors.Wrap(err, "db.FetchModelObjects")
  214. }
  215. return projects, nil
  216. }
  217. func (cp *SCloudprovider) SyncProjects(ctx context.Context, userCred mcclient.TokenCredential, projects []cloudprovider.ICloudProject, xor bool) compare.SyncResult {
  218. lockman.LockRawObject(ctx, ExternalProjectManager.Keyword(), cp.Id)
  219. defer lockman.ReleaseRawObject(ctx, ExternalProjectManager.Keyword(), cp.Id)
  220. syncResult := compare.SyncResult{}
  221. dbProjects, err := cp.GetExternalProjects()
  222. if err != nil {
  223. syncResult.Error(err)
  224. return syncResult
  225. }
  226. removed := make([]SExternalProject, 0)
  227. commondb := make([]SExternalProject, 0)
  228. commonext := make([]cloudprovider.ICloudProject, 0)
  229. added := make([]cloudprovider.ICloudProject, 0)
  230. err = compare.CompareSets(dbProjects, projects, &removed, &commondb, &commonext, &added)
  231. if err != nil {
  232. syncResult.Error(err)
  233. return syncResult
  234. }
  235. for i := 0; i < len(removed); i++ {
  236. if removed[i].Source == apis.EXTERNAL_RESOURCE_SOURCE_LOCAL {
  237. removed[i].SetStatus(ctx, userCred, api.EXTERNAL_PROJECT_STATUS_UNKNOWN, "sync delete")
  238. } else {
  239. err = removed[i].syncRemoveCloudProject(ctx, userCred)
  240. if err != nil {
  241. syncResult.DeleteError(err)
  242. } else {
  243. syncResult.Delete()
  244. }
  245. }
  246. }
  247. if !xor {
  248. for i := 0; i < len(commondb); i++ {
  249. err = commondb[i].SyncWithCloudProject(ctx, userCred, cp, commonext[i])
  250. if err != nil {
  251. syncResult.UpdateError(err)
  252. } else {
  253. syncResult.Update()
  254. }
  255. }
  256. }
  257. for i := 0; i < len(added); i++ {
  258. _, err := cp.newFromCloudProject(ctx, userCred, nil, added[i])
  259. if err != nil {
  260. syncResult.AddError(err)
  261. } else {
  262. syncResult.Add()
  263. }
  264. }
  265. return syncResult
  266. }
  267. func (self *SExternalProject) syncRemoveCloudProject(ctx context.Context, userCred mcclient.TokenCredential) error {
  268. lockman.LockObject(ctx, self)
  269. defer lockman.ReleaseObject(ctx, self)
  270. err := func() error {
  271. account, err := self.GetCloudaccount()
  272. if err != nil {
  273. return errors.Wrapf(err, "GetCloudaccount")
  274. }
  275. if !account.AutoCreateProject || !options.Options.EnableAutoRenameProject {
  276. return nil
  277. }
  278. pm, _ := account.GetProjectMapping()
  279. if pm != nil {
  280. return nil
  281. }
  282. count, _ := self.GetProjectCount()
  283. if count != 1 {
  284. return nil
  285. }
  286. s := auth.GetAdminSession(ctx, consts.GetRegion())
  287. _, err = identity.Projects.Delete(s, self.ProjectId, nil)
  288. if err != nil {
  289. return errors.Wrapf(err, "try auto delete project %s error: %v", self.Name, err)
  290. }
  291. return nil
  292. }()
  293. if err != nil {
  294. log.Errorf("syncRemoveCloudProject %s(%s) error: %v", self.Name, self.Id, err)
  295. }
  296. return self.Delete(ctx, userCred)
  297. }
  298. func (self *SExternalProject) GetProjectCount() (int, error) {
  299. return ExternalProjectManager.Query().Equals("tenant_id", self.ProjectId).CountWithError()
  300. }
  301. func (self *SExternalProject) IsMaxPriority() bool {
  302. project := &SExternalProject{}
  303. err := ExternalProjectManager.Query().Equals("tenant_id", self.ProjectId).Desc("priority").First(project)
  304. if err != nil {
  305. return false
  306. }
  307. return project.Priority == self.Priority
  308. }
  309. func (self *SExternalProject) SyncWithCloudProject(ctx context.Context, userCred mcclient.TokenCredential, cp *SCloudprovider, ext cloudprovider.ICloudProject) error {
  310. s := auth.GetAdminSession(ctx, consts.GetRegion())
  311. account, err := cp.GetCloudaccount()
  312. if err != nil {
  313. return errors.Wrapf(err, "GetCloudaccount")
  314. }
  315. domainId := ""
  316. projectId := ""
  317. share := account.GetSharedInfo()
  318. if self.DomainId != account.DomainId && !(share.PublicScope == rbacscope.ScopeSystem ||
  319. (share.PublicScope == rbacscope.ScopeDomain && utils.IsInStringArray(self.DomainId, share.SharedDomains))) {
  320. projectId = account.ProjectId
  321. domainId = account.DomainId
  322. if account.AutoCreateProject {
  323. desc := fmt.Sprintf("auto create from cloud project %s (%s)", self.Name, self.ExternalId)
  324. var err error
  325. domainId, projectId, err = account.getOrCreateTenant(ctx, self.Name, "", "", desc, nil)
  326. if err != nil {
  327. return errors.Wrapf(err, "getOrCreateTenant")
  328. }
  329. }
  330. return nil
  331. }
  332. pm, _ := account.GetProjectMapping()
  333. if self.ProjectSrc != string(apis.OWNER_SOURCE_LOCAL) {
  334. find := false
  335. if pm != nil && pm.Enabled.IsTrue() && pm.IsNeedProjectSync() {
  336. extTags, err := ext.GetTags()
  337. if err != nil {
  338. return errors.Wrapf(err, "extModel.GetTags")
  339. }
  340. if pm.Rules != nil {
  341. for _, rule := range *pm.Rules {
  342. var newProj string
  343. var isMatch bool
  344. domainId, projectId, newProj, isMatch = rule.IsMatchTags(extTags)
  345. if isMatch && len(newProj) > 0 {
  346. domainId, projectId, err = account.getOrCreateTenant(ctx, newProj, "", "", "auto create from tag", nil)
  347. if err != nil {
  348. log.Errorf("getOrCreateTenant(%s) error: %v", newProj, err)
  349. continue
  350. }
  351. find = true
  352. break
  353. }
  354. }
  355. }
  356. }
  357. if !find && account.AutoCreateProject {
  358. domainId, projectId = account.DomainId, account.ProjectId
  359. desc := fmt.Sprintf("auto create from cloud project %s (%s)", self.Name, self.ExternalId)
  360. var err error
  361. domainId, projectId, err = account.getOrCreateTenant(ctx, self.Name, self.DomainId, "", desc, nil)
  362. if err != nil {
  363. return errors.Wrapf(err, "getOrCreateTenant")
  364. }
  365. }
  366. }
  367. oldName := self.Name
  368. diff, err := db.UpdateWithLock(ctx, self, func() error {
  369. self.Name = ext.GetName()
  370. self.IsEmulated = ext.IsEmulated()
  371. self.Status = ext.GetStatus()
  372. if len(domainId) > 0 && len(projectId) > 0 {
  373. self.DomainId = domainId
  374. self.ProjectId = projectId
  375. }
  376. cache, err := db.TenantCacheManager.FetchTenantByIdOrNameInDomain(ctx, self.ProjectId, self.DomainId)
  377. if err != nil {
  378. return errors.Wrapf(err, "FetchProject %s", self.ProjectId)
  379. }
  380. if cache.PendingDeleted {
  381. desc := fmt.Sprintf("auto create from cloud project %s (%s)", self.Name, self.ExternalId)
  382. _, self.ProjectId, err = account.getOrCreateTenant(ctx, self.Name, self.DomainId, "", desc, nil)
  383. if err != nil {
  384. return errors.Wrapf(err, "getOrCreateTenant")
  385. }
  386. return nil
  387. }
  388. if pm == nil && account.AutoCreateProject && options.Options.EnableAutoRenameProject && oldName != self.Name {
  389. count, _ := self.GetProjectCount()
  390. if count == 1 {
  391. params := map[string]string{"name": self.Name}
  392. _, err = identity.Projects.Update(s, self.ProjectId, jsonutils.Marshal(params))
  393. if err != nil {
  394. return errors.Wrapf(err, "update project name from %s -> %s", oldName, self.Name)
  395. }
  396. _, err = db.Update(cache, func() error {
  397. cache.Name = self.Name
  398. return nil
  399. })
  400. return err
  401. }
  402. }
  403. return nil
  404. })
  405. if err != nil {
  406. return errors.Wrapf(err, "db.UpdateWithLock")
  407. }
  408. if self.IsMaxPriority() {
  409. tags, _ := ext.GetTags()
  410. if len(tags) > 0 {
  411. identity.Projects.PerformAction(s, self.ProjectId, "user-metadata", jsonutils.Marshal(tags))
  412. }
  413. }
  414. syncMetadata(ctx, userCred, self, ext, account.ReadOnly)
  415. db.OpsLog.LogSyncUpdate(self, diff, userCred)
  416. return nil
  417. }
  418. func (account *SCloudaccount) getOrCreateTenant(ctx context.Context, name, domainId, projectId, desc string, tags map[string]string) (string, string, error) {
  419. if len(domainId) == 0 {
  420. domainId = account.DomainId
  421. }
  422. ctx = context.WithValue(ctx, time.Now().String(), utils.GenRequestId(20))
  423. lockman.LockRawObject(ctx, domainId, name)
  424. defer lockman.ReleaseRawObject(ctx, domainId, name)
  425. tenant, err := getTenant(ctx, projectId, name, domainId)
  426. if err != nil {
  427. if errors.Cause(err) != sql.ErrNoRows {
  428. return "", "", errors.Wrapf(err, "getTenan")
  429. }
  430. return createTenant(ctx, name, domainId, desc, tags)
  431. }
  432. if tenant.PendingDeleted {
  433. return createTenant(ctx, name, domainId, desc, tags)
  434. }
  435. share := account.GetSharedInfo()
  436. if tenant.DomainId == account.DomainId || (share.PublicScope == rbacscope.ScopeSystem ||
  437. (share.PublicScope == rbacscope.ScopeDomain && utils.IsInStringArray(tenant.DomainId, share.SharedDomains))) {
  438. if len(tags) > 0 {
  439. meta := map[string]string{}
  440. for k, v := range tags {
  441. k = strings.TrimPrefix(k, db.USER_TAG_PREFIX)
  442. meta[k] = v
  443. }
  444. s := auth.GetAdminSession(ctx, consts.GetRegion())
  445. identity.Projects.PerformAction(s, tenant.Id, "user-metadata", jsonutils.Marshal(meta))
  446. }
  447. return tenant.DomainId, tenant.Id, nil
  448. }
  449. return createTenant(ctx, name, domainId, desc, tags)
  450. }
  451. func (cp *SCloudprovider) newFromCloudProject(ctx context.Context, userCred mcclient.TokenCredential, localProject *db.STenant, extProject cloudprovider.ICloudProject) (*SExternalProject, error) {
  452. project := SExternalProject{}
  453. project.SetModelManager(ExternalProjectManager, &project)
  454. project.Name = extProject.GetName()
  455. project.Status = extProject.GetStatus()
  456. project.ExternalId = extProject.GetGlobalId()
  457. project.IsEmulated = extProject.IsEmulated()
  458. project.ManagerId = cp.Id
  459. project.DomainId = cp.DomainId
  460. project.ProjectId = cp.ProjectId
  461. project.ProjectSrc = string(apis.OWNER_SOURCE_CLOUD)
  462. account, err := cp.GetCloudaccount()
  463. if err != nil {
  464. return nil, errors.Wrapf(err, "GetCloudaccount")
  465. }
  466. pm, _ := account.GetProjectMapping()
  467. if localProject != nil {
  468. project.DomainId = localProject.DomainId
  469. project.ProjectId = localProject.Id
  470. } else if pm != nil && pm.Enabled.IsTrue() && pm.IsNeedProjectSync() {
  471. extTags, err := extProject.GetTags()
  472. if err != nil {
  473. return nil, errors.Wrapf(err, "extModel.GetTags")
  474. }
  475. find := false
  476. if pm.Rules != nil {
  477. for _, rule := range *pm.Rules {
  478. domainId, projectId, newProj, isMatch := rule.IsMatchTags(extTags)
  479. if isMatch && len(newProj) > 0 {
  480. domainId, projectId, err = account.getOrCreateTenant(context.TODO(), newProj, "", "", "auto create from tag", nil)
  481. if err != nil {
  482. log.Errorf("getOrCreateTenant(%s) error: %v", newProj, err)
  483. continue
  484. }
  485. if len(domainId) > 0 && len(projectId) > 0 {
  486. project.DomainId = domainId
  487. project.ProjectId = projectId
  488. find = true
  489. break
  490. }
  491. }
  492. }
  493. }
  494. if !find && account.AutoCreateProject {
  495. desc := fmt.Sprintf("auto create from cloud project %s (%s)", project.Name, project.ExternalId)
  496. domainId, projectId, err := account.getOrCreateTenant(ctx, project.Name, project.DomainId, "", desc, nil)
  497. if err != nil {
  498. log.Errorf("failed to get or create tenant %s(%s) %v", project.Name, project.ExternalId, err)
  499. } else {
  500. project.DomainId = domainId
  501. project.ProjectId = projectId
  502. }
  503. }
  504. } else if account.AutoCreateProject {
  505. desc := fmt.Sprintf("auto create from cloud project %s (%s)", project.Name, project.ExternalId)
  506. domainId, projectId, err := account.getOrCreateTenant(ctx, project.Name, project.DomainId, "", desc, nil)
  507. if err != nil {
  508. log.Errorf("failed to get or create tenant %s(%s) %v", project.Name, project.ExternalId, err)
  509. } else {
  510. project.DomainId = domainId
  511. project.ProjectId = projectId
  512. }
  513. }
  514. err = ExternalProjectManager.TableSpec().Insert(ctx, &project)
  515. if err != nil {
  516. return nil, errors.Wrapf(err, "Insert")
  517. }
  518. if account.AutoCreateProject && project.IsMaxPriority() {
  519. tags, _ := extProject.GetTags()
  520. if len(tags) > 0 {
  521. s := auth.GetAdminSession(ctx, consts.GetRegion())
  522. identity.Projects.PerformAction(s, project.ProjectId, "user-metadata", jsonutils.Marshal(tags))
  523. }
  524. }
  525. syncMetadata(ctx, userCred, &project, extProject, account.ReadOnly)
  526. db.OpsLog.LogEvent(&project, db.ACT_CREATE, project.GetShortDesc(ctx), userCred)
  527. return &project, nil
  528. }
  529. func (self *SExternalProject) GetCloudprovider() (*SCloudprovider, error) {
  530. if len(self.ManagerId) == 0 {
  531. return nil, errors.Wrapf(cloudprovider.ErrNotFound, "empty manager_id")
  532. }
  533. provider, err := CloudproviderManager.FetchById(self.ManagerId)
  534. if err != nil {
  535. return nil, err
  536. }
  537. return provider.(*SCloudprovider), nil
  538. }
  539. func (self *SExternalProject) GetCloudaccount() (*SCloudaccount, error) {
  540. provider, err := self.GetCloudprovider()
  541. if err != nil {
  542. return nil, err
  543. }
  544. return provider.GetCloudaccount()
  545. }
  546. // 切换本地项目
  547. func (self *SExternalProject) PerformChangeProject(ctx context.Context, userCred mcclient.TokenCredential, query jsonutils.JSONObject, input api.ExternalProjectChangeProjectInput) (jsonutils.JSONObject, error) {
  548. if len(input.ProjectId) == 0 {
  549. return nil, httperrors.NewMissingParameterError("project_id")
  550. }
  551. tenant, err := db.TenantCacheManager.FetchTenantByIdOrNameInDomain(ctx, input.ProjectId, input.ProjectDomainId)
  552. if err != nil {
  553. return nil, httperrors.NewNotFoundError("project %s not found", input.ProjectId)
  554. }
  555. if self.ProjectId == tenant.Id {
  556. return nil, nil
  557. }
  558. account, err := self.GetCloudaccount()
  559. if err != nil {
  560. return nil, httperrors.NewGeneralError(errors.Wrapf(err, "GetCloudaccount"))
  561. }
  562. share := account.GetSharedInfo()
  563. if self.DomainId != tenant.DomainId && !(tenant.DomainId == account.DomainId || share.PublicScope == rbacscope.ScopeSystem ||
  564. (share.PublicScope == rbacscope.ScopeDomain && utils.IsInStringArray(tenant.DomainId, share.SharedDomains))) {
  565. return nil, httperrors.NewForbiddenError("account %s not share for domain %s", account.Name, tenant.DomainId)
  566. }
  567. oldTenant, _ := db.TenantCacheManager.FetchTenantByIdOrNameInDomain(ctx, self.ProjectId, self.DomainId)
  568. oldDomain, oldProject := "", ""
  569. if oldTenant != nil {
  570. oldDomain, oldProject = oldTenant.Domain, oldTenant.Name
  571. }
  572. notes := struct {
  573. OldProjectId string
  574. OldProject string
  575. OldDomainId string
  576. OldDomain string
  577. NewProjectId string
  578. NewProject string
  579. NewDomainId string
  580. NewDomain string
  581. }{
  582. OldProjectId: self.ProjectId,
  583. OldProject: oldProject,
  584. OldDomainId: self.DomainId,
  585. OldDomain: oldDomain,
  586. NewProjectId: tenant.Id,
  587. NewProject: tenant.Name,
  588. NewDomainId: tenant.DomainId,
  589. NewDomain: tenant.Domain,
  590. }
  591. _, err = db.Update(self, func() error {
  592. self.ProjectId = tenant.Id
  593. self.DomainId = tenant.DomainId
  594. self.ProjectSrc = string(apis.OWNER_SOURCE_LOCAL)
  595. return nil
  596. })
  597. if err != nil {
  598. return nil, httperrors.NewGeneralError(errors.Wrapf(err, "db.Update"))
  599. }
  600. logclient.AddSimpleActionLog(self, logclient.ACT_CHANGE_OWNER, notes, userCred, true)
  601. return nil, nil
  602. }
  603. // 云平台导入项目列表
  604. func (manager *SExternalProjectManager) ListItemFilter(
  605. ctx context.Context,
  606. q *sqlchemy.SQuery,
  607. userCred mcclient.TokenCredential,
  608. query api.ExternalProjectListInput,
  609. ) (*sqlchemy.SQuery, error) {
  610. var err error
  611. q, err = manager.SVirtualResourceBaseManager.ListItemFilter(ctx, q, userCred, query.VirtualResourceListInput)
  612. if err != nil {
  613. return nil, errors.Wrap(err, "SVirtualResourceBaseManager.ListItemFilter")
  614. }
  615. q, err = manager.SExternalizedResourceBaseManager.ListItemFilter(ctx, q, userCred, query.ExternalizedResourceBaseListInput)
  616. if err != nil {
  617. return nil, errors.Wrap(err, "SExternalizedResourceBaseManager.ListItemFilter")
  618. }
  619. q, err = manager.SManagedResourceBaseManager.ListItemFilter(ctx, q, userCred, query.ManagedResourceListInput)
  620. if err != nil {
  621. return nil, err
  622. }
  623. return q, nil
  624. }
  625. func (manager *SExternalProjectManager) OrderByExtraFields(
  626. ctx context.Context,
  627. q *sqlchemy.SQuery,
  628. userCred mcclient.TokenCredential,
  629. query api.ExternalProjectListInput,
  630. ) (*sqlchemy.SQuery, error) {
  631. var err error
  632. q, err = manager.SVirtualResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.VirtualResourceListInput)
  633. if err != nil {
  634. return nil, errors.Wrap(err, "SVirtualResourceBaseManager.OrderByExtraFields")
  635. }
  636. q, err = manager.SManagedResourceBaseManager.OrderByExtraFields(ctx, q, userCred, query.ManagedResourceListInput)
  637. if err != nil {
  638. return nil, errors.Wrap(err, "SManagedResourceBaseManager.OrderByExtraFields")
  639. }
  640. return q, nil
  641. }
  642. func (manager *SExternalProjectManager) QueryDistinctExtraField(q *sqlchemy.SQuery, field string) (*sqlchemy.SQuery, error) {
  643. var err error
  644. q, err = manager.SVirtualResourceBaseManager.QueryDistinctExtraField(q, field)
  645. if err == nil {
  646. return q, nil
  647. }
  648. q, err = manager.SManagedResourceBaseManager.QueryDistinctExtraField(q, field)
  649. if err == nil {
  650. return q, nil
  651. }
  652. return q, httperrors.ErrNotFound
  653. }
  654. func (manager *SExternalProjectManager) QueryDistinctExtraFields(q *sqlchemy.SQuery, resource string, fields []string) (*sqlchemy.SQuery, error) {
  655. var err error
  656. q, err = manager.SManagedResourceBaseManager.QueryDistinctExtraFields(q, resource, fields)
  657. if err == nil {
  658. return q, nil
  659. }
  660. return q, httperrors.ErrNotFound
  661. }
  662. func (manager *SExternalProjectManager) ListItemExportKeys(ctx context.Context, q *sqlchemy.SQuery, userCred mcclient.TokenCredential,
  663. keys stringutils2.SSortedStrings) (*sqlchemy.SQuery, error) {
  664. q, err := manager.SVirtualResourceBaseManager.ListItemExportKeys(ctx, q, userCred, keys)
  665. if err != nil {
  666. return nil, errors.Wrap(err, "SVirtualResourceBaseManager.ListItemExportKeys")
  667. }
  668. return q, nil
  669. }
  670. func (manager *SExternalProjectManager) InitializeData() error {
  671. q := manager.Query().IsNullOrEmpty("manager_id")
  672. projects := []SExternalProject{}
  673. err := db.FetchModelObjects(manager, q, &projects)
  674. if err != nil {
  675. return err
  676. }
  677. for i := range projects {
  678. if len(projects[i].CloudaccountId) > 0 {
  679. accountObj, err := CloudaccountManager.FetchById(projects[i].CloudaccountId)
  680. if err != nil {
  681. continue
  682. }
  683. account := accountObj.(*SCloudaccount)
  684. providers := account.GetCloudproviders()
  685. if len(providers) == 1 {
  686. _, err = db.Update(&projects[i], func() error {
  687. projects[i].ManagerId = providers[0].Id
  688. return nil
  689. })
  690. if err != nil {
  691. return err
  692. }
  693. }
  694. }
  695. }
  696. return nil
  697. }