2017-09-19 21:01:08 +00:00
|
|
|
#!/usr/bin/env python
|
|
|
|
# This updates our local copies of AWS' managed policies
|
|
|
|
# Invoked via `make update_managed_policies`
|
|
|
|
#
|
|
|
|
# Credit goes to
|
|
|
|
# https://gist.github.com/gene1wood/55b358748be3c314f956
|
|
|
|
|
|
|
|
from botocore.exceptions import NoCredentialsError
|
|
|
|
from datetime import datetime
|
|
|
|
import boto3
|
|
|
|
import json
|
|
|
|
import sys
|
|
|
|
|
|
|
|
output_file = "./moto/iam/aws_managed_policies.py"
|
|
|
|
|
|
|
|
|
|
|
|
def json_serial(obj):
|
|
|
|
"""JSON serializer for objects not serializable by default json code"""
|
|
|
|
|
|
|
|
if isinstance(obj, datetime):
|
|
|
|
serial = obj.isoformat()
|
|
|
|
return serial
|
|
|
|
raise TypeError("Type not serializable")
|
|
|
|
|
|
|
|
|
2020-10-06 06:46:05 +00:00
|
|
|
client = boto3.client("iam")
|
2017-09-19 21:01:08 +00:00
|
|
|
|
|
|
|
policies = {}
|
|
|
|
|
2020-10-06 06:46:05 +00:00
|
|
|
paginator = client.get_paginator("list_policies")
|
2017-09-19 21:01:08 +00:00
|
|
|
try:
|
2020-10-06 06:46:05 +00:00
|
|
|
response_iterator = paginator.paginate(Scope="AWS")
|
2017-09-19 21:01:08 +00:00
|
|
|
for response in response_iterator:
|
2020-10-06 06:46:05 +00:00
|
|
|
for policy in response["Policies"]:
|
|
|
|
policies[policy["PolicyName"]] = policy
|
2017-09-19 21:01:08 +00:00
|
|
|
except NoCredentialsError:
|
|
|
|
print("USAGE:")
|
|
|
|
print("Put your AWS credentials into ~/.aws/credentials and run:")
|
|
|
|
print(__file__)
|
|
|
|
print("")
|
|
|
|
print("Or specify them on the command line:")
|
2020-10-06 06:46:05 +00:00
|
|
|
print(
|
|
|
|
"AWS_ACCESS_KEY_ID=your_personal_access_key AWS_SECRET_ACCESS_KEY=your_personal_secret {}".format(
|
|
|
|
__file__
|
|
|
|
)
|
|
|
|
)
|
2017-09-19 21:01:08 +00:00
|
|
|
print("")
|
|
|
|
sys.exit(1)
|
|
|
|
|
|
|
|
for policy_name in policies:
|
|
|
|
response = client.get_policy_version(
|
2020-10-06 06:46:05 +00:00
|
|
|
PolicyArn=policies[policy_name]["Arn"],
|
|
|
|
VersionId=policies[policy_name]["DefaultVersionId"],
|
|
|
|
)
|
|
|
|
for key in response["PolicyVersion"]:
|
|
|
|
if (
|
|
|
|
key != "CreateDate"
|
|
|
|
): # the policy's CreateDate should not be overwritten by its version's CreateDate
|
|
|
|
policies[policy_name][key] = response["PolicyVersion"][key]
|
2017-09-19 21:01:08 +00:00
|
|
|
|
2020-10-06 06:46:05 +00:00
|
|
|
with open(output_file, "w") as f:
|
|
|
|
triple_quote = '"""'
|
2017-09-19 21:01:08 +00:00
|
|
|
|
|
|
|
f.write("# Imported via `make aws_managed_policies`\n")
|
2020-10-06 06:46:05 +00:00
|
|
|
f.write("aws_managed_policies_data = {}\n".format(triple_quote))
|
|
|
|
f.write(
|
|
|
|
json.dumps(
|
|
|
|
policies,
|
|
|
|
sort_keys=True,
|
|
|
|
indent=4,
|
|
|
|
separators=(",", ": "),
|
|
|
|
default=json_serial,
|
|
|
|
)
|
|
|
|
)
|
|
|
|
f.write("{}\n".format(triple_quote))
|