Skip to content

Commit 98119df

Browse files
authored
Merge pull request #247 from sujithvm/opendistro-0.10
Merge security-parent, security-ssl, security-advanced-modules
2 parents 42b9f86 + 64cd07d commit 98119df

File tree

417 files changed

+53878
-498
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

417 files changed

+53878
-498
lines changed

.github/workflows/cd.yml

Lines changed: 75 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
name: CD
2+
3+
on:
4+
push:
5+
tags:
6+
- 'v*'
7+
8+
jobs:
9+
build:
10+
runs-on: ubuntu-latest
11+
12+
steps:
13+
14+
- name: Set up JDK 11
15+
uses: actions/setup-java@v1
16+
with:
17+
java-version: 11.0.x
18+
19+
- name: Checkout security
20+
uses: actions/checkout@v1
21+
22+
- name: Build
23+
run: |
24+
mvn clean package -Padvanced -DskipTests
25+
artifact_zip=`ls $(pwd)/target/releases/opendistro_security-*.zip | grep -v admin-standalone`
26+
./gradlew build buildDeb buildRpm --no-daemon -ParchivePath=$artifact_zip -Dbuild.snapshot=false
27+
mkdir artifacts
28+
cp $artifact_zip artifacts/
29+
cp gradle-build/distributions/*.deb artifacts/
30+
cp gradle-build/distributions/*.rpm artifacts/
31+
zip -r artifacts.zip artifacts
32+
echo ::set-env name=TAG_VERSION::${GITHUB_REF/refs\/tags\//}
33+
34+
- name: Configure AWS Credentials
35+
uses: aws-actions/configure-aws-credentials@v1
36+
with:
37+
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
38+
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
39+
aws-region: us-west-2
40+
41+
- name: Upload Artifacts to S3
42+
run: |
43+
s3_path=s3://artifacts.opendistroforelasticsearch.amazon.com/downloads
44+
aws s3 cp artifacts/*.zip $s3_path/elasticsearch-plugins/opendistro-security/
45+
aws s3 cp artifacts/*.deb $s3_path/debs/opendistro-security/
46+
aws s3 cp artifacts/*.rpm $s3_path/rpms/opendistro-security/
47+
aws cloudfront create-invalidation --distribution-id ${{ secrets.DISTRIBUTION_ID }} --paths '/downloads/*'
48+
49+
- name: Create Github Draft Release
50+
id: create_release
51+
uses: actions/[email protected]
52+
env:
53+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
54+
with:
55+
tag_name: ${{ github.ref }}
56+
release_name: Release ${{ env.TAG_VERSION }}
57+
draft: true
58+
prerelease: false
59+
60+
- name: Upload Release Asset
61+
id: upload-release-asset
62+
uses: actions/[email protected]
63+
env:
64+
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
65+
with:
66+
upload_url: ${{ steps.create_release.outputs.upload_url }}
67+
asset_name: artifacts.zip
68+
asset_path: artifacts.zip
69+
asset_content_type: application/zip
70+
71+
- name: Upload Workflow Artifacts
72+
uses: actions/upload-artifact@v1
73+
with:
74+
name: artifacts
75+
path: artifacts/

.github/workflows/ci.yml

Lines changed: 18 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,7 @@ on:
77
push:
88
branches:
99
- master
10+
- opendistro-*
1011

1112
jobs:
1213
build:
@@ -15,26 +16,25 @@ jobs:
1516

1617
steps:
1718

18-
- name: Checkout security-parent
19-
uses: actions/checkout@v1
20-
with:
21-
repository: opendistro-for-elasticsearch/security-parent
22-
ref: opendistro-0.10
23-
- name: Install security-parent
24-
run: mvn clean install -DskipTests --file ../security-parent/pom.xml
25-
26-
- name: Checkout security-ssl
27-
uses: actions/checkout@v1
28-
with:
29-
repository: opendistro-for-elasticsearch/security-ssl
30-
ref: opendistro-0.10
31-
- name: Install security-ssl
32-
run: mvn clean install -DskipTests --file ../security-ssl/pom.xml
33-
3419
- name: Checkout security
3520
uses: actions/checkout@v1
36-
- name: Install security
37-
run: mvn clean install -DskipTests
21+
22+
- name: Checkstyle
23+
run: mvn checkstyle:checkstyle
3824

3925
- name: Test
4026
run: mvn test
27+
28+
- name: Coverage
29+
uses: codecov/codecov-action@v1
30+
with:
31+
token: ${{ secrets.CODECOV_TOKEN }}
32+
33+
- name: Package
34+
run: mvn clean package -Padvanced -DskipTests
35+
36+
- name: Upload Artifacts
37+
uses: actions/upload-artifact@v1
38+
with:
39+
name: artifacts
40+
path: target/releases/

.gitignore

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,9 @@
1-
netty*/
21
smoketests/
32
target/
43
test-output/
54
kibana*/
65
logstash*/
76
deploy_all.sh
8-
/build.gradle
97
*.log
108
.externalToolBuilders
119
maven-eclipse.xml
@@ -37,3 +35,8 @@ test.sh
3735
.idea/
3836
*.iml
3937
*.rej
38+
39+
# gradle
40+
build/
41+
gradle-build/
42+
.gradle/

build.gradle

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
// Uses Gradle to build RPMs since that's what we use for the other plugins. When all you have is a hammer...
2+
plugins {
3+
id "nebula.ospackage" version "5.3.0"
4+
}
5+
6+
// To prevent conflicts with maven build under build/
7+
buildDir = 'gradle-build'
8+
9+
ext {
10+
opendistroVersion = '0.10.1'
11+
isSnapshot = "true" == System.getProperty("build.snapshot", "true")
12+
}
13+
14+
group = "com.amazon.opendistroforelasticsearch"
15+
// Increment the final digit when there's a new plugin versions for the same opendistro version
16+
// Reset the final digit to 0 when upgrading to a new opendistro version
17+
version = "${opendistroVersion}.0" + (isSnapshot ? "-SNAPSHOT" : "")
18+
19+
20+
if (!project.hasProperty("archivePath")) {
21+
throw new GradleException("Missing -ParchivePath command line switch pointing to built plugin ZIP")
22+
}
23+
if (!project.file(archivePath).exists()) {
24+
throw new GradleException("Missing plugin zip file: $archivePath")
25+
}
26+
27+
ospackage {
28+
packageName = "opendistro-security"
29+
release = isSnapshot ? "0.0" : '0'
30+
version = "${project.version}" - "-SNAPSHOT"
31+
32+
into '/usr/share/elasticsearch/plugins'
33+
from(zipTree(project.file(archivePath).absolutePath)) {
34+
into "opendistro_security"
35+
}
36+
37+
user 'root'
38+
permissionGroup 'root'
39+
fileMode 0644
40+
dirMode 0755
41+
42+
requires('elasticsearch-oss', "6.8.6", EQUAL)
43+
packager = 'Amazon'
44+
vendor = 'Amazon'
45+
os = 'LINUX'
46+
prefix '/usr'
47+
48+
license 'ASL-2.0'
49+
maintainer 'OpenDistro for Elasticsearch Team <[email protected]>'
50+
url 'https://opendistro.github.io/elasticsearch/downloads'
51+
summary '''
52+
Security plugin for OpenDistro for Elasticsearch.
53+
Reference documentation can be found at https://opendistro.github.io/elasticsearch/docs.
54+
'''.stripIndent().replace('\n', ' ').trim()
55+
56+
//TODO: Would be better if the install_demo_configuration.sh script is marked executable in the upstream plugin instead of running bash manually here
57+
postInstall "exec /bin/bash /usr/share/elasticsearch/plugins/opendistro_security/tools/install_demo_configuration.sh -y -i -s"
58+
}
59+
60+
buildRpm {
61+
arch = 'NOARCH'
62+
archiveName "${packageName}-${version}.rpm"
63+
}
64+
65+
buildDeb {
66+
arch = 'amd64'
67+
archiveName "${packageName}-${version}.deb"
68+
}

gradle/wrapper/gradle-wrapper.jar

54.9 KB
Binary file not shown.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
distributionBase=GRADLE_USER_HOME
2+
distributionPath=wrapper/dists
3+
distributionUrl=https\://services.gradle.org/distributions/gradle-4.10.2-bin.zip
4+
zipStoreBase=GRADLE_USER_HOME
5+
zipStorePath=wrapper/dists

gradlew

Lines changed: 172 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,172 @@
1+
#!/usr/bin/env sh
2+
3+
##############################################################################
4+
##
5+
## Gradle start up script for UN*X
6+
##
7+
##############################################################################
8+
9+
# Attempt to set APP_HOME
10+
# Resolve links: $0 may be a link
11+
PRG="$0"
12+
# Need this for relative symlinks.
13+
while [ -h "$PRG" ] ; do
14+
ls=`ls -ld "$PRG"`
15+
link=`expr "$ls" : '.*-> \(.*\)$'`
16+
if expr "$link" : '/.*' > /dev/null; then
17+
PRG="$link"
18+
else
19+
PRG=`dirname "$PRG"`"/$link"
20+
fi
21+
done
22+
SAVED="`pwd`"
23+
cd "`dirname \"$PRG\"`/" >/dev/null
24+
APP_HOME="`pwd -P`"
25+
cd "$SAVED" >/dev/null
26+
27+
APP_NAME="Gradle"
28+
APP_BASE_NAME=`basename "$0"`
29+
30+
# Add default JVM options here. You can also use JAVA_OPTS and GRADLE_OPTS to pass JVM options to this script.
31+
DEFAULT_JVM_OPTS=""
32+
33+
# Use the maximum available, or set MAX_FD != -1 to use that value.
34+
MAX_FD="maximum"
35+
36+
warn () {
37+
echo "$*"
38+
}
39+
40+
die () {
41+
echo
42+
echo "$*"
43+
echo
44+
exit 1
45+
}
46+
47+
# OS specific support (must be 'true' or 'false').
48+
cygwin=false
49+
msys=false
50+
darwin=false
51+
nonstop=false
52+
case "`uname`" in
53+
CYGWIN* )
54+
cygwin=true
55+
;;
56+
Darwin* )
57+
darwin=true
58+
;;
59+
MINGW* )
60+
msys=true
61+
;;
62+
NONSTOP* )
63+
nonstop=true
64+
;;
65+
esac
66+
67+
CLASSPATH=$APP_HOME/gradle/wrapper/gradle-wrapper.jar
68+
69+
# Determine the Java command to use to start the JVM.
70+
if [ -n "$JAVA_HOME" ] ; then
71+
if [ -x "$JAVA_HOME/jre/sh/java" ] ; then
72+
# IBM's JDK on AIX uses strange locations for the executables
73+
JAVACMD="$JAVA_HOME/jre/sh/java"
74+
else
75+
JAVACMD="$JAVA_HOME/bin/java"
76+
fi
77+
if [ ! -x "$JAVACMD" ] ; then
78+
die "ERROR: JAVA_HOME is set to an invalid directory: $JAVA_HOME
79+
80+
Please set the JAVA_HOME variable in your environment to match the
81+
location of your Java installation."
82+
fi
83+
else
84+
JAVACMD="java"
85+
which java >/dev/null 2>&1 || die "ERROR: JAVA_HOME is not set and no 'java' command could be found in your PATH.
86+
87+
Please set the JAVA_HOME variable in your environment to match the
88+
location of your Java installation."
89+
fi
90+
91+
# Increase the maximum file descriptors if we can.
92+
if [ "$cygwin" = "false" -a "$darwin" = "false" -a "$nonstop" = "false" ] ; then
93+
MAX_FD_LIMIT=`ulimit -H -n`
94+
if [ $? -eq 0 ] ; then
95+
if [ "$MAX_FD" = "maximum" -o "$MAX_FD" = "max" ] ; then
96+
MAX_FD="$MAX_FD_LIMIT"
97+
fi
98+
ulimit -n $MAX_FD
99+
if [ $? -ne 0 ] ; then
100+
warn "Could not set maximum file descriptor limit: $MAX_FD"
101+
fi
102+
else
103+
warn "Could not query maximum file descriptor limit: $MAX_FD_LIMIT"
104+
fi
105+
fi
106+
107+
# For Darwin, add options to specify how the application appears in the dock
108+
if $darwin; then
109+
GRADLE_OPTS="$GRADLE_OPTS \"-Xdock:name=$APP_NAME\" \"-Xdock:icon=$APP_HOME/media/gradle.icns\""
110+
fi
111+
112+
# For Cygwin, switch paths to Windows format before running java
113+
if $cygwin ; then
114+
APP_HOME=`cygpath --path --mixed "$APP_HOME"`
115+
CLASSPATH=`cygpath --path --mixed "$CLASSPATH"`
116+
JAVACMD=`cygpath --unix "$JAVACMD"`
117+
118+
# We build the pattern for arguments to be converted via cygpath
119+
ROOTDIRSRAW=`find -L / -maxdepth 1 -mindepth 1 -type d 2>/dev/null`
120+
SEP=""
121+
for dir in $ROOTDIRSRAW ; do
122+
ROOTDIRS="$ROOTDIRS$SEP$dir"
123+
SEP="|"
124+
done
125+
OURCYGPATTERN="(^($ROOTDIRS))"
126+
# Add a user-defined pattern to the cygpath arguments
127+
if [ "$GRADLE_CYGPATTERN" != "" ] ; then
128+
OURCYGPATTERN="$OURCYGPATTERN|($GRADLE_CYGPATTERN)"
129+
fi
130+
# Now convert the arguments - kludge to limit ourselves to /bin/sh
131+
i=0
132+
for arg in "$@" ; do
133+
CHECK=`echo "$arg"|egrep -c "$OURCYGPATTERN" -`
134+
CHECK2=`echo "$arg"|egrep -c "^-"` ### Determine if an option
135+
136+
if [ $CHECK -ne 0 ] && [ $CHECK2 -eq 0 ] ; then ### Added a condition
137+
eval `echo args$i`=`cygpath --path --ignore --mixed "$arg"`
138+
else
139+
eval `echo args$i`="\"$arg\""
140+
fi
141+
i=$((i+1))
142+
done
143+
case $i in
144+
(0) set -- ;;
145+
(1) set -- "$args0" ;;
146+
(2) set -- "$args0" "$args1" ;;
147+
(3) set -- "$args0" "$args1" "$args2" ;;
148+
(4) set -- "$args0" "$args1" "$args2" "$args3" ;;
149+
(5) set -- "$args0" "$args1" "$args2" "$args3" "$args4" ;;
150+
(6) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" ;;
151+
(7) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" ;;
152+
(8) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" ;;
153+
(9) set -- "$args0" "$args1" "$args2" "$args3" "$args4" "$args5" "$args6" "$args7" "$args8" ;;
154+
esac
155+
fi
156+
157+
# Escape application args
158+
save () {
159+
for i do printf %s\\n "$i" | sed "s/'/'\\\\''/g;1s/^/'/;\$s/\$/' \\\\/" ; done
160+
echo " "
161+
}
162+
APP_ARGS=$(save "$@")
163+
164+
# Collect all arguments for the java command, following the shell quoting and substitution rules
165+
eval set -- $DEFAULT_JVM_OPTS $JAVA_OPTS $GRADLE_OPTS "\"-Dorg.gradle.appname=$APP_BASE_NAME\"" -classpath "\"$CLASSPATH\"" org.gradle.wrapper.GradleWrapperMain "$APP_ARGS"
166+
167+
# by default we should be in the correct project dir, but when run from Finder on Mac, the cwd is wrong
168+
if [ "$(uname)" = "Darwin" ] && [ "$HOME" = "$PWD" ]; then
169+
cd "$(dirname "$0")"
170+
fi
171+
172+
exec "$JAVACMD" "$@"

0 commit comments

Comments
 (0)