File manager - Edit - /opt/saltstack/salt/lib/python3.10/site-packages/salt/pillar/__pycache__/ec2_pillar.cpython-310.pyc
Back
o ;jE( � @ s� d Z ddlZddlZddlmZ zddlZddlZddlZdZ W n e y+ dZ Y nw e�e�Z e�d��ej� dd� Zd d � Z dd d�ZdS )ao Retrieve EC2 instance data for minions for ec2_tags and ec2_tags_list The minion id must be the AWS instance-id or value in ``tag_match_key``. For example set ``tag_match_key`` to ``Name`` to have the minion-id matched against the tag 'Name'. The tag contents must be unique. The value of ``tag_match_value`` can be 'uqdn' or 'asis'. if 'uqdn', then the domain will be stripped before comparison. Additionally, the ``use_grain`` option can be set to ``True``. This allows the use of an instance-id grain instead of the minion-id. Since this is a potential security risk, the configuration can be further expanded to include a list of minions that are trusted to only allow the alternate id of the instances to specific hosts. There is no glob matching at this time. .. note:: If you are using ``use_grain: True`` in the configuration for this external pillar module, the minion must have :conf_minion:`metadata_server_grains` enabled in the minion config file (see also :py:mod:`here <salt.grains.metadata>`). It is important to also note that enabling the ``use_grain`` option allows the minion to manipulate the pillar data returned, as described above. The optional ``tag_list_key`` indicates which keys should be added to ``ec2_tags_list`` and be split by ``tag_list_sep`` (by default ``;``). If a tag key is included in ``tag_list_key`` it is removed from ec2_tags. If a tag does not exist it is still included as an empty list. .. note:: As with any master configuration change, restart the salt-master daemon for changes to take effect. .. code-block:: yaml ext_pillar: - ec2_pillar: tag_match_key: 'Name' tag_match_value: 'asis' tag_list_key: - Role tag_list_sep: ';' use_grain: True minion_ids: - trusted-minion-1 - trusted-minion-2 - trusted-minion-3 This is a very simple pillar configuration that simply retrieves the instance data from AWS. Currently the only portion implemented are EC2 tags, which returns a list of key/value pairs for all of the EC2 tags assigned to the instance. � N)�VersionTF�botoc C s: t sdS ttj�} td�}| |k rt�dt| |� dS dS )ze Check for required version of boto and make this pillar available depending on outcome. Fz2.8.0z@%s: installed boto version %s < %s, can't retrieve instance dataT)�HAS_BOTOr r �__version__�log�error�__name__)Zboto_versionZrequired_boto_version� r �J/opt/saltstack/salt/lib/python3.10/site-packages/salt/pillar/ec2_pillar.py�__virtual__M s �r c C s t j�� d } | d | d fS )zj Helper function to return the instance ID and region of the master where this pillar is run. �documentZ instanceId�region)r �utilsZget_instance_identity)�identityr r r �_get_instance_infoa s r �asis�;c C s$ ddg}t �di ��dd�} | s"t �di ��di ��di ��dd�} | r6t�d | �du r6t�d t| | � d} |rSt�d|�du rSt�dtt|t �rN|� i S d � i S |rf||vrft�dt|d� |�� i S |sndt| f} ndt| ||f} t�| � d}d}t�d | �dur�d}| }n$|r�|dkr�d|� �| �dd�d i}nd|� �| i}| r�|� d| i� |s�|s�|r�| s�t�d| � i S |dur�| |vr�t�d| |� i S | }|s�|s�t�dt| ||� i S tjjddd�} t| �� �dk r�t�dt� i S t� \}}|�rt �di ��d|�}ztj�|�}W n tjj�y1 } zt�dt|� i W Y d}~S d}~ww |du �r@t�dt|� i S z|�rM|j|gd d!�}n|j|d d"�}W n tjj�ys } zt�d#| |� i W Y d}~S d}~ww |�s�t�d$| |�r�|� i S |� i S g }t|�D ]\}}|jd%v�r�|�|� �q�t|�}|�s�t�d&| |�r�|� i S |� i S |dk�r�t�d'| |�r�|� i S |� i S ||d }|j�r|j}i }t�d(t| |j� |�rt|t��r|D ]}||v �r|| �|�||<