From 4ed63edea0ae61ce36406f62ded79e5dbc5d845a Mon Sep 17 00:00:00 2001 From: Steve Kriss Date: Thu, 25 Apr 2019 12:32:43 -0600 Subject: [PATCH 1/2] GCP: add optional 'project' config to volume snapshot location Signed-off-by: Steve Kriss --- changelogs/unreleased/1405-skriss | 1 + docs/api-types/volumesnapshotlocation.md | 1 + pkg/cloudprovider/gcp/volume_snapshotter.go | 18 ++++++++++++------ 3 files changed, 14 insertions(+), 6 deletions(-) create mode 100644 changelogs/unreleased/1405-skriss diff --git a/changelogs/unreleased/1405-skriss b/changelogs/unreleased/1405-skriss new file mode 100644 index 000000000..62f954430 --- /dev/null +++ b/changelogs/unreleased/1405-skriss @@ -0,0 +1 @@ +GCP: add optional 'project' config to volume snapshot location for if snapshots are in a different project than the IAM account diff --git a/docs/api-types/volumesnapshotlocation.md b/docs/api-types/volumesnapshotlocation.md index 7d287dc73..10cc61735 100644 --- a/docs/api-types/volumesnapshotlocation.md +++ b/docs/api-types/volumesnapshotlocation.md @@ -57,6 +57,7 @@ The configurable parameters are as follows: | Key | Type | Default | Meaning | | --- | --- | --- | --- | | `snapshotLocation` | string | Empty | *Example*: "us-central1"

See [GCP documentation][4] for the full list.

If not specified the snapshots are stored in the [default location][5]. | +| `project` | string | Empty | The project ID where snapshots should be stored, if different than the project that your IAM account is in. Optional. | [0]: #aws [1]: #gcp diff --git a/pkg/cloudprovider/gcp/volume_snapshotter.go b/pkg/cloudprovider/gcp/volume_snapshotter.go index 8a1c5dc63..d9fe8dc3c 100644 --- a/pkg/cloudprovider/gcp/volume_snapshotter.go +++ b/pkg/cloudprovider/gcp/volume_snapshotter.go @@ -38,8 +38,8 @@ import ( ) const ( - projectKey = "project" zoneSeparator = "__" + projectKey = "project" snapshotLocationKey = "snapshotLocation" ) @@ -55,15 +55,22 @@ func NewVolumeSnapshotter(logger logrus.FieldLogger) *VolumeSnapshotter { } func (b *VolumeSnapshotter) Init(config map[string]string) error { - if err := cloudprovider.ValidateVolumeSnapshotterConfigKeys(config, snapshotLocationKey); err != nil { + if err := cloudprovider.ValidateVolumeSnapshotterConfigKeys(config, snapshotLocationKey, projectKey); err != nil { return err } b.snapshotLocation = config[snapshotLocationKey] - project, err := extractProjectFromCreds() - if err != nil { - return err + // take 'project' from config if specified, otherwise get it + // from the credentials file + if val := config[projectKey]; val != "" { + b.project = val + } else { + project, err := extractProjectFromCreds() + if err != nil { + return err + } + b.project = project } client, err := google.DefaultClient(oauth2.NoContext, compute.ComputeScope) @@ -77,7 +84,6 @@ func (b *VolumeSnapshotter) Init(config map[string]string) error { } b.gce = gce - b.project = project return nil } From 3b5de11c74d265dc37b0b377cac2d09838a0f549 Mon Sep 17 00:00:00 2001 From: Steve Kriss Date: Mon, 29 Apr 2019 09:47:06 -0600 Subject: [PATCH 2/2] update to optionally use distinct snapshot vs volume project Signed-off-by: Steve Kriss --- pkg/cloudprovider/gcp/volume_snapshotter.go | 48 +++++++++++---------- 1 file changed, 25 insertions(+), 23 deletions(-) diff --git a/pkg/cloudprovider/gcp/volume_snapshotter.go b/pkg/cloudprovider/gcp/volume_snapshotter.go index d9fe8dc3c..0cb9cf5e6 100644 --- a/pkg/cloudprovider/gcp/volume_snapshotter.go +++ b/pkg/cloudprovider/gcp/volume_snapshotter.go @@ -44,10 +44,11 @@ const ( ) type VolumeSnapshotter struct { - gce *compute.Service - project string log logrus.FieldLogger + gce *compute.Service snapshotLocation string + volumeProject string + snapshotProject string } func NewVolumeSnapshotter(logger logrus.FieldLogger) *VolumeSnapshotter { @@ -61,16 +62,17 @@ func (b *VolumeSnapshotter) Init(config map[string]string) error { b.snapshotLocation = config[snapshotLocationKey] - // take 'project' from config if specified, otherwise get it - // from the credentials file - if val := config[projectKey]; val != "" { - b.project = val - } else { - project, err := extractProjectFromCreds() - if err != nil { - return err - } - b.project = project + project, err := extractProjectFromCreds() + if err != nil { + return err + } + b.volumeProject = project + + // get snapshot project from 'project' config key if specified, + // otherwise from the credentials file + b.snapshotProject = config[projectKey] + if b.snapshotProject == "" { + b.snapshotProject = b.volumeProject } client, err := google.DefaultClient(oauth2.NoContext, compute.ComputeScope) @@ -145,7 +147,7 @@ func (b *VolumeSnapshotter) getZoneURLs(volumeAZ string) ([]string, error) { zones := strings.Split(volumeAZ, zoneSeparator) var zoneURLs []string for _, z := range zones { - zone, err := b.gce.Zones.Get(b.project, z).Do() + zone, err := b.gce.Zones.Get(b.volumeProject, z).Do() if err != nil { return nil, errors.WithStack(err) } @@ -158,7 +160,7 @@ func (b *VolumeSnapshotter) getZoneURLs(volumeAZ string) ([]string, error) { func (b *VolumeSnapshotter) CreateVolumeFromSnapshot(snapshotID, volumeType, volumeAZ string, iops *int64) (volumeID string, err error) { // get the snapshot so we can apply its tags to the volume - res, err := b.gce.Snapshots.Get(b.project, snapshotID).Do() + res, err := b.gce.Snapshots.Get(b.snapshotProject, snapshotID).Do() if err != nil { return "", errors.WithStack(err) } @@ -189,11 +191,11 @@ func (b *VolumeSnapshotter) CreateVolumeFromSnapshot(snapshotID, volumeType, vol disk.ReplicaZones = zoneURLs - if _, err = b.gce.RegionDisks.Insert(b.project, volumeRegion, disk).Do(); err != nil { + if _, err = b.gce.RegionDisks.Insert(b.volumeProject, volumeRegion, disk).Do(); err != nil { return "", errors.WithStack(err) } } else { - if _, err = b.gce.Disks.Insert(b.project, volumeAZ, disk).Do(); err != nil { + if _, err = b.gce.Disks.Insert(b.volumeProject, volumeAZ, disk).Do(); err != nil { return "", errors.WithStack(err) } } @@ -212,12 +214,12 @@ func (b *VolumeSnapshotter) GetVolumeInfo(volumeID, volumeAZ string) (string, *i if err != nil { return "", nil, errors.WithStack(err) } - res, err = b.gce.RegionDisks.Get(b.project, volumeRegion, volumeID).Do() + res, err = b.gce.RegionDisks.Get(b.volumeProject, volumeRegion, volumeID).Do() if err != nil { return "", nil, errors.WithStack(err) } } else { - res, err = b.gce.Disks.Get(b.project, volumeAZ, volumeID).Do() + res, err = b.gce.Disks.Get(b.volumeProject, volumeAZ, volumeID).Do() if err != nil { return "", nil, errors.WithStack(err) } @@ -249,7 +251,7 @@ func (b *VolumeSnapshotter) CreateSnapshot(volumeID, volumeAZ string, tags map[s } func (b *VolumeSnapshotter) createSnapshot(snapshotName, volumeID, volumeAZ string, tags map[string]string) (string, error) { - disk, err := b.gce.Disks.Get(b.project, volumeAZ, volumeID).Do() + disk, err := b.gce.Disks.Get(b.volumeProject, volumeAZ, volumeID).Do() if err != nil { return "", errors.WithStack(err) } @@ -263,7 +265,7 @@ func (b *VolumeSnapshotter) createSnapshot(snapshotName, volumeID, volumeAZ stri gceSnap.StorageLocations = []string{b.snapshotLocation} } - _, err = b.gce.Disks.CreateSnapshot(b.project, volumeAZ, volumeID, &gceSnap).Do() + _, err = b.gce.Disks.CreateSnapshot(b.snapshotProject, volumeAZ, volumeID, &gceSnap).Do() if err != nil { return "", errors.WithStack(err) } @@ -272,7 +274,7 @@ func (b *VolumeSnapshotter) createSnapshot(snapshotName, volumeID, volumeAZ stri } func (b *VolumeSnapshotter) createRegionSnapshot(snapshotName, volumeID, volumeRegion string, tags map[string]string) (string, error) { - disk, err := b.gce.RegionDisks.Get(b.project, volumeRegion, volumeID).Do() + disk, err := b.gce.RegionDisks.Get(b.volumeProject, volumeRegion, volumeID).Do() if err != nil { return "", errors.WithStack(err) } @@ -286,7 +288,7 @@ func (b *VolumeSnapshotter) createRegionSnapshot(snapshotName, volumeID, volumeR gceSnap.StorageLocations = []string{b.snapshotLocation} } - _, err = b.gce.RegionDisks.CreateSnapshot(b.project, volumeRegion, volumeID, &gceSnap).Do() + _, err = b.gce.RegionDisks.CreateSnapshot(b.snapshotProject, volumeRegion, volumeID, &gceSnap).Do() if err != nil { return "", errors.WithStack(err) } @@ -329,7 +331,7 @@ func getSnapshotTags(veleroTags map[string]string, diskDescription string, log l } func (b *VolumeSnapshotter) DeleteSnapshot(snapshotID string) error { - _, err := b.gce.Snapshots.Delete(b.project, snapshotID).Do() + _, err := b.gce.Snapshots.Delete(b.snapshotProject, snapshotID).Do() // if it's a 404 (not found) error, we don't need to return an error // since the snapshot is not there.