Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Aws organizations organizationalunit idempotency #92

Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,13 +1,11 @@
package software.amazon.organizations.account;

import org.apache.commons.collections4.CollectionUtils;
import software.amazon.awssdk.services.organizations.model.Account;
import software.amazon.awssdk.services.organizations.OrganizationsClient;
import software.amazon.awssdk.services.organizations.model.CreateAccountRequest;
import software.amazon.awssdk.services.organizations.model.CreateAccountResponse;
import software.amazon.awssdk.services.organizations.model.DescribeCreateAccountStatusResponse;
import software.amazon.awssdk.services.organizations.model.DuplicateAccountException;
import software.amazon.awssdk.services.organizations.model.ListAccountsRequest;
import software.amazon.awssdk.services.organizations.model.ListParentsRequest;
import software.amazon.awssdk.services.organizations.model.ListParentsResponse;
import software.amazon.awssdk.services.organizations.model.MoveAccountRequest;
Expand All @@ -19,7 +17,6 @@
import software.amazon.cloudformation.proxy.ResourceHandlerRequest;
import software.amazon.organizations.utils.OrgsLoggerWrapper;

import java.util.Optional;
import java.util.Set;

public class CreateHandler extends BaseHandlerStd {
Expand Down Expand Up @@ -50,57 +47,28 @@ protected ProgressEvent<ResourceModel, CallbackContext> handleRequest(
}

return ProgressEvent.progress(request.getDesiredResourceState(), callbackContext)
.then(progress -> checkIfAccountExists(awsClientProxy, progress, orgsClient))
.then(progress -> {
if (progress.getCallbackContext().isPreExistenceCheckComplete() && progress.getCallbackContext().isDidResourceAlreadyExist()) {
return ProgressEvent.failed(model, callbackContext, HandlerErrorCode.AlreadyExists,
String.format("Account with email [%s] already exists.", model.getEmail()));
}
if (progress.getCallbackContext().isAccountCreated()) {
log.log(String.format("Account has already been created in previous handler invoke with account Id: [%s]. Skip create account.", model.getAccountId()));
return ProgressEvent.progress(model, callbackContext);
}
return awsClientProxy.initiate("AWS-Organizations-Account::CreateAccount", orgsClient, progress.getResourceModel(), progress.getCallbackContext())
.translateToServiceRequest(Translator::translateToCreateAccountRequest)
.makeServiceCall(this::createAccount)
.handleError((organizationsRequest, e, proxyClient1, model1, context) -> handleError(organizationsRequest, request, e, proxyClient1, model1, context, logger))
.done(CreateAccountResponse -> {
callbackContext.setCreateAccountRequestId(CreateAccountResponse.createAccountStatus().id());
logger.log(String.format("Successfully initiated new account creation request with CreateAccountRequestId [%s]", callbackContext.getCreateAccountRequestId()));
return ProgressEvent.progress(model, callbackContext);
});
})
.then(progress -> {
if (progress.getCallbackContext().isAccountCreated()) {
log.log(String.format("Account has already been created in previous handler invoke with account Id: [%s]. Skip create account.", model.getAccountId()));
return ProgressEvent.progress(model, callbackContext);
}
return awsClientProxy.initiate("AWS-Organizations-Account::CreateAccount", orgsClient, progress.getResourceModel(), progress.getCallbackContext())
.translateToServiceRequest(Translator::translateToCreateAccountRequest)
.makeServiceCall(this::createAccount)
.handleError((organizationsRequest, e, proxyClient1, model1, context) -> handleError(organizationsRequest, request, e, proxyClient1, model1, context, logger))
.done(CreateAccountResponse -> {
callbackContext.setCreateAccountRequestId(CreateAccountResponse.createAccountStatus().id());
logger.log(String.format("Successfully initiated new account creation request with CreateAccountRequestId [%s]", callbackContext.getCreateAccountRequestId()));
return ProgressEvent.progress(model, callbackContext);
});
}

)
.then(progress -> describeCreateAccountStatus(awsClientProxy, request, model, callbackContext, orgsClient, logger))
.then(progress -> moveAccount(awsClientProxy, request, model, callbackContext, orgsClient, logger))
.then(progress -> ProgressEvent.success(progress.getResourceModel(), progress.getCallbackContext()));
}

private ProgressEvent<ResourceModel, CallbackContext> checkIfAccountExists(
final AmazonWebServicesClientProxy awsClientProxy,
ProgressEvent<ResourceModel, CallbackContext> progress,
final ProxyClient<OrganizationsClient> orgsClient) {

ResourceModel model = progress.getResourceModel();

return awsClientProxy.initiate("AWS-Organizations-Account::ListAccounts", orgsClient, model, progress.getCallbackContext())
.translateToServiceRequest(resourceModel -> ListAccountsRequest.builder().build())
.makeServiceCall((listAccountsRequest, proxyClient) -> proxyClient.injectCredentialsAndInvokeV2(listAccountsRequest, proxyClient.client()::listAccounts))
.done((listAccountsRequest, listAccountsResponse, proxyClient, resourceModel, context) -> {
Optional<Account> existingAccount = listAccountsResponse.accounts().stream()
.filter(account -> account.email().equals(model.getEmail()))
.findFirst();

if (existingAccount.isPresent()) {
model.setAccountId(existingAccount.get().id());
context.setDidResourceAlreadyExist(true);
log.log(String.format("Failing PreExistenceCheck: Account with email [%s] already exists with Id: [%s]", model.getEmail(), model.getAccountId()));
}

context.setPreExistenceCheckComplete(true);
return ProgressEvent.progress(model, context);
});
}

protected ProgressEvent<ResourceModel, CallbackContext> describeCreateAccountStatus(
final AmazonWebServicesClientProxy awsClientProxy,
final ResourceHandlerRequest<ResourceModel> request,
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,4 +19,6 @@ public void setCurrentRetryAttempt(final Constants.Action actionName, final Cons
String key = actionName.toString() + handlerName.toString();
this.actionToRetryAttemptMap.put(key, getCurrentRetryAttempt(actionName, handlerName)+1);
}
private boolean isPreExistenceCheckComplete = false;
private boolean didResourceAlreadyExist = false;
}
Original file line number Diff line number Diff line change
Expand Up @@ -4,12 +4,17 @@
import software.amazon.awssdk.services.organizations.OrganizationsClient;
import software.amazon.awssdk.services.organizations.model.CreateOrganizationalUnitRequest;
import software.amazon.awssdk.services.organizations.model.CreateOrganizationalUnitResponse;
import software.amazon.awssdk.services.organizations.model.OrganizationalUnit;
import software.amazon.awssdk.services.organizations.model.ListOrganizationalUnitsForParentRequest;
import software.amazon.cloudformation.proxy.AmazonWebServicesClientProxy;
import software.amazon.cloudformation.proxy.HandlerErrorCode;
import software.amazon.cloudformation.proxy.ProgressEvent;
import software.amazon.cloudformation.proxy.ProxyClient;
import software.amazon.cloudformation.proxy.ResourceHandlerRequest;
import software.amazon.organizations.utils.OrgsLoggerWrapper;

import java.util.Optional;

public class CreateHandler extends BaseHandlerStd {
private OrgsLoggerWrapper log;

Expand All @@ -29,16 +34,49 @@ public ProgressEvent<ResourceModel, CallbackContext> handleRequest(

logger.log(String.format("Requesting CreateOrganizationalUnit w/ name: %s and parentId: %s.", name, parentId));
return ProgressEvent.progress(model, callbackContext)
.then(progress ->
awsClientProxy.initiate("AWS-Organizations-OrganizationalUnit::CreateOrganizationalUnit", orgsClient, progress.getResourceModel(), progress.getCallbackContext())
.translateToServiceRequest(x -> Translator.translateToCreateOrganizationalUnitRequest(x, request))
.makeServiceCall(this::createOrganizationalUnit)
.stabilize(this::stabilized)
.handleError((organizationsRequest, e, proxyClient1, model1, context) ->
handleErrorInGeneral(organizationsRequest, e, proxyClient1, model1, context, logger, Constants.Action.CREATE_OU, Constants.Handler.CREATE))
.progress()
)
.then(progress -> new ReadHandler().handleRequest(awsClientProxy, request, callbackContext, orgsClient, logger));
.then(progress -> checkIfOrganizationalUnitExists(awsClientProxy, progress, orgsClient))
.then(progress -> {
if (progress.getCallbackContext().isPreExistenceCheckComplete() && progress.getCallbackContext().isDidResourceAlreadyExist()) {
return ProgressEvent.failed(model, callbackContext, HandlerErrorCode.AlreadyExists,
String.format("Failing PreExistenceCheck: OrganizationalUnit with name [%s] already exists in parent [%s].", name, parentId));
}
return awsClientProxy.initiate("AWS-Organizations-OrganizationalUnit::CreateOrganizationalUnit", orgsClient, progress.getResourceModel(), progress.getCallbackContext())
.translateToServiceRequest(x -> Translator.translateToCreateOrganizationalUnitRequest(x, request))
.makeServiceCall(this::createOrganizationalUnit)
.stabilize(this::stabilized)
.handleError((organizationsRequest, e, proxyClient1, model1, context) ->
handleErrorInGeneral(organizationsRequest, e, proxyClient1, model1, context, logger, Constants.Action.CREATE_OU, Constants.Handler.CREATE))
.progress();
})
.then(progress -> new ReadHandler().handleRequest(awsClientProxy, request, callbackContext, orgsClient, logger));
}

private ProgressEvent<ResourceModel, CallbackContext> checkIfOrganizationalUnitExists(
final AmazonWebServicesClientProxy awsClientProxy,
ProgressEvent<ResourceModel, CallbackContext> progress,
final ProxyClient<OrganizationsClient> orgsClient) {

ResourceModel model = progress.getResourceModel();

return awsClientProxy.initiate("AWS-Organizations-OrganizationalUnit::ListOrganizationalUnitsForParent", orgsClient, model, progress.getCallbackContext())
.translateToServiceRequest(resourceModel -> ListOrganizationalUnitsForParentRequest.builder()
.parentId(resourceModel.getParentId())
.build())
.makeServiceCall((listOURequest, proxyClient) -> proxyClient.injectCredentialsAndInvokeV2(listOURequest, proxyClient.client()::listOrganizationalUnitsForParent))
.done((listOURequest, listOUResponse, proxyClient, resourceModel, context) -> {
Optional<OrganizationalUnit> existingOU = listOUResponse.organizationalUnits().stream()
.filter(ou -> ou.name().equals(model.getName()))
.findFirst();

if (existingOU.isPresent()) {
model.setId(existingOU.get().id());
context.setDidResourceAlreadyExist(true);
log.log(String.format("OrganizationalUnit [%s] already exists with Id: [%s]", model.getName(), model.getId()));
}

context.setPreExistenceCheckComplete(true);
return ProgressEvent.progress(model, context);
});
}

protected CreateOrganizationalUnitResponse createOrganizationalUnit(final CreateOrganizationalUnitRequest createOrganizationalUnitRequest, final ProxyClient<OrganizationsClient> orgsClient) {
Expand Down
Loading
Loading