Commit 61983981 authored by Jorge Moratinos's avatar Jorge Moratinos
Browse files

First step implementing security context creation for API from other CCF

parent aba73c90
Loading
Loading
Loading
Loading
Loading
+28 −21
Changes for helm/04_capif_services/charts/ocf-security/templates/configmap.yaml: 28 added lines, 21 removed lines.
Original line number Diff line number Diff line
@@ -4,25 +4,32 @@ metadata:
  name: capif-security-configmap
data:
  config.yaml: |
    mongo: {
      'user': '{{ .Values.env.mongoInitdbRootUsername }}',
      'password': '{{ .Values.env.mongoInitdbRootPassword }}',
      'db': 'capif',
      'col': 'security',
      'capif_service_col': 'serviceapidescriptions',
      'certs_col': 'certs',
      'capif_invokers' : 'invokerdetails',
      'host': 'mongo',
      'port': "27017"
    }
    mongo:
      user: '{{ .Values.env.mongoInitdbRootUsername }}'
      password: '{{ .Values.env.mongoInitdbRootPassword }}'
      db: capif
      col: security
      capif_service_col: serviceapidescriptions
      certs_col: certs
      capif_invokers: invokerdetails
      col_interconnected: interconnected
      col_capif_configuration: capif_configuration
      col_capif_configuration: 'capif_configuration'
      host: '{{ .Values.env.mongoHost }}'
      port: '{{ .Values.env.mongoPort }}'

    monitoring: {
      "fluent_bit_host": fluent-bit,
      "fluent_bit_port": 24224,
      "opentelemetry_url": "otel-collector",
      "opentelemetry_port": "55680",
      "opentelemetry_max_queue_size": 8192,
      "opentelemetry_schedule_delay_millis": 20000,
      "opentelemetry_max_export_batch_size": 2048,
      "opentelemetry_export_timeout_millis": 60000
    }
 No newline at end of file
    monitoring:
      fluent_bit_host: fluent-bit
      fluent_bit_port: 24224
      opentelemetry_url: otel-collector
      opentelemetry_port: 55680
      opentelemetry_max_queue_size: 8192
      opentelemetry_schedule_delay_millis: 20000
      opentelemetry_max_export_batch_size: 2048
      opentelemetry_export_timeout_millis: 60000

    ca_factory:
      url: !ENV ${VAULT_HOSTNAME}
      port: !ENV ${VAULT_PORT}
      token: !ENV ${VAULT_ACCESS_TOKEN}
      verify: False
+2 −0
Changes for helm/04_capif_services/charts/ocf-security/values.yaml: 2 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -24,6 +24,8 @@ env:
  mongoInitdbRootPassword: example
  logLevel: "INFO"
  timeout: "30"
  mongoHost: mongo
  mongoPort: 27017

serviceAccount:
  # Specifies whether a service account should be created
+3 −1
Changes for services/TS29222_CAPIF_Security_API/Dockerfile: 3 added lines, 1 removed line.
Original line number Diff line number Diff line
FROM labs.etsi.org:5050/ocf/capif/python:3-slim-bullseye
FROM python:3.13-slim

#FROM labs.etsi.org:5050/ocf/capif/python:3-slim-bullseye

RUN mkdir -p /usr/src/app
WORKDIR /usr/src/app
+1 −1
Changes for services/TS29222_CAPIF_Security_API/capif_security/app.py: 1 added line, 1 removed line.
Original line number Diff line number Diff line
@@ -115,7 +115,7 @@ def verbose_formatter():
    )


with open("/usr/src/app/capif_security/server.key", "rb") as key_file:
with open("/usr/src/app/capif_security/certs/server.key", "rb") as key_file:
        key_data = key_file.read()

app = connexion.App(__name__, specification_dir='openapi/')
+60 −6
Changes for services/TS29222_CAPIF_Security_API/capif_security/config.py: 60 added lines, 6 removed lines.
Original line number Diff line number Diff line
import os

import yaml
import re


# pattern for global vars: look for ${word}
pattern = re.compile(r'.*?\${(\w+)}.*?')
loader = yaml.SafeLoader


def constructor_env_variables(loader, node):
    """
    Extracts the environment variable from the node's value
    :param yaml.Loader loader: the yaml loader
    :param node: the current node in the yaml
    :return: the parsed string that contains the value of the environment
    variable
    """
    value = loader.construct_scalar(node)
    match = pattern.findall(value)  # to find all env variables in line
    if match:
        full_value = value
        for g in match:
            full_value = full_value.replace(
                f'${{{g}}}', os.environ.get(g, g)
            )
        return full_value
    return value


def parse_config(path=None, data=None, tag='!ENV'):
    """
    Load a yaml configuration file and resolve any environment variables
    The environment variables must have !ENV before them and be in this format
    to be parsed: ${VAR_NAME}.
    E.g.:
    database:
        host: !ENV ${HOST}
        port: !ENV ${PORT}
    app:
        log_path: !ENV '/var/${LOG_PATH}'
        something_else: !ENV '${AWESOME_ENV_VAR}/var/${A_SECOND_AWESOME_VAR}'
    :param str path: the path to the yaml file
    :param str data: the yaml data itself as a stream
    :param str tag: the tag to look for
    :return: the dict configuration
    :rtype: dict[str, T]
    """

    # the tag will be used to mark where to start searching for the pattern
    # e.g. somekey: !ENV somestring${MYENVVAR}blah blah blah
    loader.add_implicit_resolver(tag, pattern, None)
    loader.add_constructor(tag, constructor_env_variables)

    if path:
        with open(path) as conf_data:
            return yaml.load(conf_data, Loader=loader)
    elif data:
        return yaml.load(data, Loader=loader)
    else:
        raise ValueError('Either a path or data should be defined as input')


#Config class to get config
@@ -13,11 +71,7 @@ class Config:
        stamp = os.stat(self.file).st_mtime
        if stamp != self.cached:
            self.cached = stamp
			f = open(self.file)
			self.my_config = yaml.safe_load(f)
			f.close()
            self.my_config = parse_config(path=self.file)

    def get_config(self):
        return self.my_config

Loading