Skip to content

Commit 265aac9

Browse files
committed
AWS-API Throttling feature implemented.
1 parent b875dc8 commit 265aac9

7 files changed

Lines changed: 68 additions & 8 deletions

File tree

deploy/helm/Chart.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ type: application
66
# This is the chart version. This version number should be incremented each time you make changes
77
# to the chart and its templates, including the app version.
88
# Versions are expected to follow Semantic Versioning (https://semver.org/)
9-
version: 0.10.1
9+
version: 0.10.2
1010

1111
# This is the version number of the application being deployed. This version number should be
1212
# incremented each time you make changes to the application. Versions are not expected to

deploy/helm/templates/config.yaml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,9 @@ data:
6666
{{- if .useEcrRoleCreds }}
6767
trivy.useEcrRoleCreds: {{ .useEcrRoleCreds | quote }}
6868
{{- end }}
69+
{{- if .useEcrRoleCreds }}
70+
trivy.ecrTokenRefreshTTL: {{ .ecrTokenRefreshTTL | quote }}
71+
{{- end }}
6972
{{- if .timeout }}
7073
trivy.timeout: {{ .timeout | quote }}
7174
{{- end }}

deploy/helm/values.yaml

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -124,6 +124,12 @@ trivy:
124124
#
125125
# useEcrRoleCreds: false
126126

127+
# Set the TokenExpiry for the next AWS-Tokengeneration
128+
# AWS authorization token is valid for 12 hours by default
129+
# Unit is hours(h)
130+
#
131+
# ecrTokenRefreshTTL = 11h
132+
127133
# Registries without SSL. There can be multiple registries with different keys.
128134
nonSslRegistries: {}
129135
# pocRegistry: poc.myregistry.harbor.com.pl

go.mod

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -90,6 +90,7 @@ require (
9090
github.com/valyala/bytebufferpool v1.0.0 // indirect
9191
github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb // indirect
9292
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 // indirect
93+
github.com/xhit/go-str2duration/v2 v2.0.0 // indirect
9394
github.com/xlab/treeprint v0.0.0-20181112141820-a009c3971eca // indirect
9495
github.com/yashtewari/glob-intersection v0.0.0-20180916065949-5c77d914dd0b // indirect
9596
go.starlark.net v0.0.0-20200306205701-8dd3e2ee1dd5 // indirect

go.sum

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -615,6 +615,7 @@ github.com/jmespath/go-jmespath v0.0.0-20160202185014-0b12d6b521d8/go.mod h1:Nht
615615
github.com/jmespath/go-jmespath v0.0.0-20160803190731-bd40a432e4c7/go.mod h1:Nht3zPeWKUH0NzdCt2Blrr5ys8VGpn0CEB0cQHVjt7k=
616616
github.com/jmespath/go-jmespath v0.4.0 h1:BEgLn5cpjn8UN1mAw4NjwDrS35OdebyEtFe+9YPoQUg=
617617
github.com/jmespath/go-jmespath v0.4.0/go.mod h1:T8mJZnbsbmF+m6zOOFylbeCJqk5+pHWvzYPziyZiYoo=
618+
github.com/jmespath/go-jmespath/internal/testify v1.5.1/go.mod h1:L3OGu8Wl2/fWfCI6z80xFu9LTZmf1ZRjMHUOPmWr69U=
618619
github.com/jonboulle/clockwork v0.1.0/go.mod h1:Ii8DK3G1RaLaWxj9trq07+26W01tbo22gdxWY5EU2bo=
619620
github.com/jonboulle/clockwork v0.2.2/go.mod h1:Pkfl5aHPm1nk2H9h0bjmnJD/BcgbGXUBGnn1kMkgxc8=
620621
github.com/josharian/intern v1.0.0 h1:vlS4z54oSdjm0bgjRigI+G1HpF+tI+9rE5LLzOg8HmY=
@@ -963,6 +964,8 @@ github.com/xeipuuv/gojsonpointer v0.0.0-20190905194746-02993c407bfb/go.mod h1:N2
963964
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 h1:EzJWgHovont7NscjpAxXsDA8S8BMYve8Y5+7cuRE7R0=
964965
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415/go.mod h1:GwrjFmJcFw6At/Gs6z4yjiIwzuJ1/+UwLxMQDVQXShQ=
965966
github.com/xeipuuv/gojsonschema v0.0.0-20180618132009-1d523034197f/go.mod h1:5yf86TLmAcydyeJq5YvxkGPE2fm/u4myDekKRoLuqhs=
967+
github.com/xhit/go-str2duration/v2 v2.0.0 h1:uFtk6FWB375bP7ewQl+/1wBcn840GPhnySOdcz/okPE=
968+
github.com/xhit/go-str2duration/v2 v2.0.0/go.mod h1:ohY8p+0f07DiV6Em5LKB0s2YpLtXVyJfNt1+BlmyAsU=
966969
github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2/go.mod h1:UETIi67q53MR2AWcXfiuqkDkRtnGDLqkBTpCHuJHxtU=
967970
github.com/xlab/treeprint v0.0.0-20181112141820-a009c3971eca h1:1CFlNzQhALwjS9mBAUkycX616GzgsuYUOCHA5+HSlXI=
968971
github.com/xlab/treeprint v0.0.0-20181112141820-a009c3971eca/go.mod h1:ce1O1j6UtZfjr22oyGxGLbauSBp2YVXpARAosm7dHBg=
@@ -1167,6 +1170,7 @@ golang.org/x/net v0.0.0-20211015210444-4f30a5c0130f/go.mod h1:9nx3DQGgdP8bBQD5qx
11671170
golang.org/x/net v0.0.0-20211111083644-e5c967477495/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
11681171
golang.org/x/net v0.0.0-20211209124913-491a49abca63/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
11691172
golang.org/x/net v0.0.0-20211216030914-fe4d6282115f/go.mod h1:9nx3DQGgdP8bBQD5qxJ1jj9UTztislL4KSBs9R2vV5Y=
1173+
golang.org/x/net v0.0.0-20220127200216-cd36cc0744dd/go.mod h1:CfG3xpIq0wQ8r1q4Su4UZFWDARRcnwPjda9FqA0JpMk=
11701174
golang.org/x/net v0.0.0-20220225172249-27dd8689420f h1:oA4XRj0qtSt8Yo1Zms0CUlsT3KG69V2UGQWPBxujDmc=
11711175
golang.org/x/net v0.0.0-20220225172249-27dd8689420f/go.mod h1:CfG3xpIq0wQ8r1q4Su4UZFWDARRcnwPjda9FqA0JpMk=
11721176
golang.org/x/oauth2 v0.0.0-20180821212333-d2e6202438be/go.mod h1:N/0e6XlmueqKjAGxoOufVs8QHGRruUQn6yWY3a++T0U=

pkg/plugin/trivy/plugin.go

Lines changed: 31 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -9,12 +9,14 @@ import (
99
"io"
1010
"regexp"
1111
"strings"
12+
"time"
1213

1314
"github.com/aquasecurity/starboard/pkg/apis/aquasecurity/v1alpha1"
1415
"github.com/aquasecurity/starboard/pkg/docker"
1516
"github.com/aquasecurity/starboard/pkg/ext"
1617
"github.com/aquasecurity/starboard/pkg/kube"
1718
"github.com/aquasecurity/starboard/pkg/starboard"
19+
"github.com/aquasecurity/starboard/pkg/utils"
1820
"github.com/aquasecurity/starboard/pkg/vulnerabilityreport"
1921
"github.com/aws/aws-sdk-go/aws"
2022
"github.com/aws/aws-sdk-go/aws/awserr"
@@ -55,6 +57,7 @@ const (
5557
keyTrivySkipFiles = "trivy.skipFiles"
5658
keyTrivySkipDirs = "trivy.skipDirs"
5759
keyTrivyUseECRRoleCreds = "trivy.useEcrRoleCreds"
60+
keyTrivyECRTokenRefreshTTL = "trivy.ecrTokenRefreshTTL"
5861

5962
keyTrivyServerURL = "trivy.serverURL"
6063
keyTrivyServerTokenHeader = "trivy.serverTokenHeader"
@@ -71,6 +74,10 @@ const (
7174
// Mode in which Trivy client operates.
7275
type Mode string
7376

77+
var aws_creds [][]string
78+
var EcrTokenTTL time.Duration = 0
79+
var EcrTokenGen time.Time
80+
7481
const (
7582
Standalone Mode = "Standalone"
7683
ClientServer Mode = "ClientServer"
@@ -146,6 +153,10 @@ func (c Config) UseECRCredentials() bool {
146153
}
147154
}
148155

156+
func (c Config) GetECRRefreshTTL() (string, error) {
157+
return c.GetRequiredData(keyTrivyECRTokenRefreshTTL)
158+
}
159+
149160
func (c Config) GetServerInsecure() bool {
150161
_, ok := c.Data[keyTrivyServerInsecure]
151162
return ok
@@ -599,10 +610,16 @@ func (p *plugin) getPodSpecForStandaloneMode(ctx starboard.PluginContext, config
599610
})
600611
}
601612

613+
TTLresult, err := config.GetECRRefreshTTL()
614+
602615
if config.UseECRCredentials() && CheckAwsEcrPrivateRegistry(c.Image) != "" {
603-
var aws_creds, err = GetAuthorizationToken(CheckAwsEcrPrivateRegistry(c.Image))
604-
if err != nil {
605-
return corev1.PodSpec{}, nil, err
616+
617+
if utils.TokenTTLValidation(EcrTokenGen, TTLresult) {
618+
EcrTokenGen = time.Now()
619+
aws_creds, err = GetAuthorizationToken(CheckAwsEcrPrivateRegistry(c.Image))
620+
if err != nil {
621+
return corev1.PodSpec{}, nil, err
622+
}
606623
}
607624

608625
var creds (ecr_credentials) = ecr_credentials{aws_creds[0][1], aws_creds[0][2]}
@@ -882,11 +899,18 @@ func (p *plugin) getPodSpecForClientServerMode(ctx starboard.PluginContext, conf
882899
},
883900
}
884901

902+
TTLresult, err := config.GetECRRefreshTTL()
903+
885904
if config.UseECRCredentials() && CheckAwsEcrPrivateRegistry(container.Image) != "" {
886-
var aws_creds, err = GetAuthorizationToken(CheckAwsEcrPrivateRegistry(container.Image))
887-
if err != nil {
888-
return corev1.PodSpec{}, nil, err
905+
906+
if utils.TokenTTLValidation(EcrTokenGen, TTLresult) {
907+
EcrTokenGen = time.Now()
908+
aws_creds, err = GetAuthorizationToken(CheckAwsEcrPrivateRegistry(container.Image))
909+
if err != nil {
910+
return corev1.PodSpec{}, nil, err
911+
}
889912
}
913+
890914
var creds (ecr_credentials) = ecr_credentials{aws_creds[0][1], aws_creds[0][2]}
891915

892916
env = append(env, corev1.EnvVar{
@@ -1450,7 +1474,7 @@ func GetAuthorizationToken(AwsEcrRegion string) ([][]string, error) {
14501474
errormsg = "GetAuthorizationToken (AWS-API): " + aerr.Error()
14511475
}
14521476
} else {
1453-
fmt.Println(err.Error())
1477+
errormsg = err.Error()
14541478
}
14551479
return nil, errors.New((errormsg))
14561480
}

pkg/utils/durationutil.go

Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
package utils
2+
3+
import (
4+
"time"
5+
6+
"github.com/xhit/go-str2duration/v2"
7+
)
8+
9+
func TokenTTLValidation(TokenGen time.Time, TokenTTL string) bool {
10+
duration, err := str2duration.ParseDuration(TokenTTL)
11+
12+
if err == nil {
13+
if time.Now().Sub(TokenGen) >= duration {
14+
return true
15+
} else {
16+
return false
17+
}
18+
} else {
19+
return false
20+
}
21+
22+
}

0 commit comments

Comments
 (0)