This repository was archived by the owner on Jun 27, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathmain.go
More file actions
51 lines (47 loc) · 1.39 KB
/
Copy pathmain.go
File metadata and controls
51 lines (47 loc) · 1.39 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
package main
import (
"fmt"
"log"
"os"
"time"
"github.com/namsral/flag"
"github.com/securityscorecard/vault-vouch/vault"
"github.com/securityscorecard/vault-vouch/vault/aws"
)
var (
fs = flag.NewFlagSetWithEnvPrefix(os.Args[0], "IV", 0)
Role = fs.String("role", "", "Role to request from Vault")
AwsArnRole = fs.String("aws_arn_role", "", "ARN of AWS role to assume before preparing auth payload for Vault")
AwsRole = fs.String("aws_role", "", "Name of AWS role on current account to assume before preparing auth payload for Vault")
VaultAddress = fs.String("vault_addr", "", "Vault address")
WrapTokenTTL = fs.String("wrap_token_ttl", "5m", "TTL for wrapped token")
)
func main() {
err := fs.Parse(os.Args[1:])
if err != nil {
if err == flag.ErrHelp {
os.Exit(0)
}
log.Fatal(err)
}
wrapTokenTTL, err := time.ParseDuration(*WrapTokenTTL)
if err != nil {
log.Fatal(err)
}
if wrapTokenTTL < 0 {
log.Fatal(fmt.Printf("WrapTokenTTL must not be negative, given: %s", wrapTokenTTL.String()))
}
var gen vault.Generator
if *AwsArnRole != "" {
gen = aws.AssumeRoleArnGenerator(*VaultAddress, *AwsArnRole)
} else if *AwsRole != "" {
gen = aws.AssumeRoleGenerator(*VaultAddress, *AwsRole)
} else {
gen = aws.DefaultGenerator(*VaultAddress)
}
token, err := gen.WrappedToken(*Role, wrapTokenTTL)
if err != nil {
log.Fatal(err)
}
fmt.Printf("%s", token)
}