1 | ;
|
2 | Object.defineProperty(exports, "__esModule", { value: true });
|
3 | exports.stackTemplateFileAsset = exports.resolvedOr = exports.StringSpecializer = exports.assertBound = exports.contentHash = exports.addStackArtifactToAssembly = void 0;
|
4 | const crypto = require("crypto");
|
5 | const fs = require("fs");
|
6 | const path = require("path");
|
7 | const cxschema = require("@aws-cdk/cloud-assembly-schema");
|
8 | const cxapi = require("@aws-cdk/cx-api");
|
9 | const assets_1 = require("../assets");
|
10 | const construct_compat_1 = require("../construct-compat");
|
11 | const stack_1 = require("../stack");
|
12 | const token_1 = require("../token");
|
13 | /**
|
14 | * Shared logic of writing stack artifact to the Cloud Assembly
|
15 | *
|
16 | * This logic is shared between StackSyntheses.
|
17 | *
|
18 | * It could have been a protected method on a base class, but it
|
19 | * uses `Partial<cxapi.AwsCloudFormationStackProperties>` in the
|
20 | * parameters (which is convenient so I can remain typesafe without
|
21 | * copy/pasting), and jsii will choke on this type.
|
22 | */
|
23 | function addStackArtifactToAssembly(session, stack, stackProps, additionalStackDependencies) {
|
24 | // nested stack tags are applied at the AWS::CloudFormation::Stack resource
|
25 | // level and are not needed in the cloud assembly.
|
26 | if (stack.tags.hasTags()) {
|
27 | stack.node.addMetadata(cxschema.ArtifactMetadataEntryType.STACK_TAGS, stack.tags.renderTags());
|
28 | }
|
29 | const deps = [
|
30 | ...stack.dependencies.map(s => s.artifactId),
|
31 | ...additionalStackDependencies,
|
32 | ];
|
33 | const meta = collectStackMetadata(stack);
|
34 | // backwards compatibility since originally artifact ID was always equal to
|
35 | // stack name the stackName attribute is optional and if it is not specified
|
36 | // the CLI will use the artifact ID as the stack name. we *could have*
|
37 | // always put the stack name here but wanted to minimize the risk around
|
38 | // changes to the assembly manifest. so this means that as long as stack
|
39 | // name and artifact ID are the same, the cloud assembly manifest will not
|
40 | // change.
|
41 | const stackNameProperty = stack.stackName === stack.artifactId
|
42 | ? {}
|
43 | : { stackName: stack.stackName };
|
44 | const properties = {
|
45 | templateFile: stack.templateFile,
|
46 | terminationProtection: stack.terminationProtection,
|
47 | tags: nonEmptyDict(stack.tags.tagValues()),
|
48 | validateOnSynth: session.validateOnSynth,
|
49 | ...stackProps,
|
50 | ...stackNameProperty,
|
51 | };
|
52 | // add an artifact that represents this stack
|
53 | session.assembly.addArtifact(stack.artifactId, {
|
54 | type: cxschema.ArtifactType.AWS_CLOUDFORMATION_STACK,
|
55 | environment: stack.environment,
|
56 | properties,
|
57 | dependencies: deps.length > 0 ? deps : undefined,
|
58 | metadata: Object.keys(meta).length > 0 ? meta : undefined,
|
59 | displayName: stack.node.path,
|
60 | });
|
61 | }
|
62 | exports.addStackArtifactToAssembly = addStackArtifactToAssembly;
|
63 | /**
|
64 | * Collect the metadata from a stack
|
65 | */
|
66 | function collectStackMetadata(stack) {
|
67 | const output = {};
|
68 | visit(stack);
|
69 | return output;
|
70 | function visit(node) {
|
71 | // break off if we reached a node that is not a child of this stack
|
72 | const parent = findParentStack(node);
|
73 | if (parent !== stack) {
|
74 | return;
|
75 | }
|
76 | if (node.node.metadataEntry.length > 0) {
|
77 | // Make the path absolute
|
78 | output[construct_compat_1.ConstructNode.PATH_SEP + node.node.path] = node.node.metadataEntry.map(md => stack.resolve(md));
|
79 | }
|
80 | for (const child of node.node.children) {
|
81 | visit(child);
|
82 | }
|
83 | }
|
84 | function findParentStack(node) {
|
85 | if (stack_1.Stack.isStack(node) && node.nestedStackParent === undefined) {
|
86 | return node;
|
87 | }
|
88 | if (!node.node.scope) {
|
89 | return undefined;
|
90 | }
|
91 | return findParentStack(node.node.scope);
|
92 | }
|
93 | }
|
94 | /**
|
95 | * Hash a string
|
96 | */
|
97 | function contentHash(content) {
|
98 | return crypto.createHash('sha256').update(content).digest('hex');
|
99 | }
|
100 | exports.contentHash = contentHash;
|
101 | /**
|
102 | * Throw an error message about binding() if we don't have a value for x.
|
103 | *
|
104 | * This replaces the ! assertions we would need everywhere otherwise.
|
105 | */
|
106 | function assertBound(x) {
|
107 | if (x === null && x === undefined) {
|
108 | throw new Error('You must call bindStack() first');
|
109 | }
|
110 | }
|
111 | exports.assertBound = assertBound;
|
112 | function nonEmptyDict(xs) {
|
113 | return Object.keys(xs).length > 0 ? xs : undefined;
|
114 | }
|
115 | /**
|
116 | * A "replace-all" function that doesn't require us escaping a literal string to a regex
|
117 | */
|
118 | function replaceAll(s, search, replace) {
|
119 | return s.split(search).join(replace);
|
120 | }
|
121 | class StringSpecializer {
|
122 | constructor(stack, qualifier) {
|
123 | this.stack = stack;
|
124 | this.qualifier = qualifier;
|
125 | }
|
126 | /**
|
127 | * Function to replace placeholders in the input string as much as possible
|
128 | *
|
129 | * We replace:
|
130 | * - ${Qualifier}: always
|
131 | * - ${AWS::AccountId}, ${AWS::Region}: only if we have the actual values available
|
132 | * - ${AWS::Partition}: never, since we never have the actual partition value.
|
133 | */
|
134 | specialize(s) {
|
135 | s = replaceAll(s, '${Qualifier}', this.qualifier);
|
136 | return cxapi.EnvironmentPlaceholders.replace(s, {
|
137 | region: resolvedOr(this.stack.region, cxapi.EnvironmentPlaceholders.CURRENT_REGION),
|
138 | accountId: resolvedOr(this.stack.account, cxapi.EnvironmentPlaceholders.CURRENT_ACCOUNT),
|
139 | partition: cxapi.EnvironmentPlaceholders.CURRENT_PARTITION,
|
140 | });
|
141 | }
|
142 | /**
|
143 | * Specialize only the qualifier
|
144 | */
|
145 | qualifierOnly(s) {
|
146 | return replaceAll(s, '${Qualifier}', this.qualifier);
|
147 | }
|
148 | }
|
149 | exports.StringSpecializer = StringSpecializer;
|
150 | /**
|
151 | * Return the given value if resolved or fall back to a default
|
152 | */
|
153 | function resolvedOr(x, def) {
|
154 | return token_1.Token.isUnresolved(x) ? def : x;
|
155 | }
|
156 | exports.resolvedOr = resolvedOr;
|
157 | function stackTemplateFileAsset(stack, session) {
|
158 | const templatePath = path.join(session.assembly.outdir, stack.templateFile);
|
159 | const template = fs.readFileSync(templatePath, { encoding: 'utf-8' });
|
160 | const sourceHash = contentHash(template);
|
161 | return {
|
162 | fileName: stack.templateFile,
|
163 | packaging: assets_1.FileAssetPackaging.FILE,
|
164 | sourceHash,
|
165 | };
|
166 | }
|
167 | exports.stackTemplateFileAsset = stackTemplateFileAsset;
|
168 | //# sourceMappingURL=data:application/json;base64,{"version":3,"file":"_shared.js","sourceRoot":"","sources":["_shared.ts"],"names":[],"mappings":";;;AAAA,iCAAiC;AACjC,yBAAyB;AACzB,6BAA6B;AAC7B,2DAA2D;AAC3D,yCAAyC;AACzC,sCAAgE;AAChE,0DAAmF;AACnF,oCAAiC;AACjC,oCAAiC;AAEjC;;;;;;;;;GASG;AACH,SAAgB,0BAA0B,CACxC,OAA0B,EAC1B,KAAY,EACZ,UAA8D,EAC9D,2BAAqC;IAErC,2EAA2E;IAC3E,kDAAkD;IAClD,IAAI,KAAK,CAAC,IAAI,CAAC,OAAO,EAAE,EAAE;QACxB,KAAK,CAAC,IAAI,CAAC,WAAW,CAAC,QAAQ,CAAC,yBAAyB,CAAC,UAAU,EAAE,KAAK,CAAC,IAAI,CAAC,UAAU,EAAE,CAAC,CAAC;KAChG;IAED,MAAM,IAAI,GAAG;QACX,GAAG,KAAK,CAAC,YAAY,CAAC,GAAG,CAAC,CAAC,CAAC,EAAE,CAAC,CAAC,CAAC,UAAU,CAAC;QAC5C,GAAG,2BAA2B;KAC/B,CAAC;IACF,MAAM,IAAI,GAAG,oBAAoB,CAAC,KAAK,CAAC,CAAC;IAEzC,2EAA2E;IAC3E,4EAA4E;IAC5E,sEAAsE;IACtE,wEAAwE;IACxE,wEAAwE;IACxE,0EAA0E;IAC1E,UAAU;IACV,MAAM,iBAAiB,GAAG,KAAK,CAAC,SAAS,KAAK,KAAK,CAAC,UAAU;QAC5D,CAAC,CAAC,EAAG;QACL,CAAC,CAAC,EAAE,SAAS,EAAE,KAAK,CAAC,SAAS,EAAE,CAAC;IAEnC,MAAM,UAAU,GAA8C;QAC5D,YAAY,EAAE,KAAK,CAAC,YAAY;QAChC,qBAAqB,EAAE,KAAK,CAAC,qBAAqB;QAClD,IAAI,EAAE,YAAY,CAAC,KAAK,CAAC,IAAI,CAAC,SAAS,EAAE,CAAC;QAC1C,eAAe,EAAE,OAAO,CAAC,eAAe;QACxC,GAAG,UAAU;QACb,GAAG,iBAAiB;KACrB,CAAC;IAEF,6CAA6C;IAC7C,OAAO,CAAC,QAAQ,CAAC,WAAW,CAAC,KAAK,CAAC,UAAU,EAAE;QAC7C,IAAI,EAAE,QAAQ,CAAC,YAAY,CAAC,wBAAwB;QACpD,WAAW,EAAE,KAAK,CAAC,WAAW;QAC9B,UAAU;QACV,YAAY,EAAE,IAAI,CAAC,MAAM,GAAG,CAAC,CAAC,CAAC,CAAC,IAAI,CAAC,CAAC,CAAC,SAAS;QAChD,QAAQ,EAAE,MAAM,CAAC,IAAI,CAAC,IAAI,CAAC,CAAC,MAAM,GAAG,CAAC,CAAC,CAAC,CAAC,IAAI,CAAC,CAAC,CAAC,SAAS;QACzD,WAAW,EAAE,KAAK,CAAC,IAAI,CAAC,IAAI;KAC7B,CAAC,CAAC;AACL,CAAC;AA/CD,gEA+CC;AAED;;GAEG;AACH,SAAS,oBAAoB,CAAC,KAAY;IACxC,MAAM,MAAM,GAA+C,EAAG,CAAC;IAE/D,KAAK,CAAC,KAAK,CAAC,CAAC;IAEb,OAAO,MAAM,CAAC;IAEd,SAAS,KAAK,CAAC,IAAgB;QAC7B,mEAAmE;QACnE,MAAM,MAAM,GAAG,eAAe,CAAC,IAAI,CAAC,CAAC;QACrC,IAAI,MAAM,KAAK,KAAK,EAAE;YACpB,OAAO;SACR;QAED,IAAI,IAAI,CAAC,IAAI,CAAC,aAAa,CAAC,MAAM,GAAG,CAAC,EAAE;YACtC,yBAAyB;YACzB,MAAM,CAAC,gCAAa,CAAC,QAAQ,GAAG,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,GAAG,IAAI,CAAC,IAAI,CAAC,aAAa,CAAC,GAAG,CAAC,EAAE,CAAC,EAAE,CAAC,KAAK,CAAC,OAAO,CAAC,EAAE,CAA2B,CAAC,CAAC;SAClI;QAED,KAAK,MAAM,KAAK,IAAI,IAAI,CAAC,IAAI,CAAC,QAAQ,EAAE;YACtC,KAAK,CAAC,KAAK,CAAC,CAAC;SACd;IACH,CAAC;IAED,SAAS,eAAe,CAAC,IAAgB;QACvC,IAAI,aAAK,CAAC,OAAO,CAAC,IAAI,CAAC,IAAI,IAAI,CAAC,iBAAiB,KAAK,SAAS,EAAE;YAC/D,OAAO,IAAI,CAAC;SACb;QAED,IAAI,CAAC,IAAI,CAAC,IAAI,CAAC,KAAK,EAAE;YACpB,OAAO,SAAS,CAAC;SAClB;QAED,OAAO,eAAe,CAAC,IAAI,CAAC,IAAI,CAAC,KAAK,CAAC,CAAC;IAC1C,CAAC;AACH,CAAC;AAED;;GAEG;AACH,SAAgB,WAAW,CAAC,OAAe;IACzC,OAAO,MAAM,CAAC,UAAU,CAAC,QAAQ,CAAC,CAAC,MAAM,CAAC,OAAO,CAAC,CAAC,MAAM,CAAC,KAAK,CAAC,CAAC;AACnE,CAAC;AAFD,kCAEC;AAED;;;;GAIG;AACH,SAAgB,WAAW,CAAI,CAAgB;IAC7C,IAAI,CAAC,KAAK,IAAI,IAAI,CAAC,KAAK,SAAS,EAAE;QACjC,MAAM,IAAI,KAAK,CAAC,iCAAiC,CAAC,CAAC;KACpD;AACH,CAAC;AAJD,kCAIC;AAED,SAAS,YAAY,CAAI,EAAqB;IAC5C,OAAO,MAAM,CAAC,IAAI,CAAC,EAAE,CAAC,CAAC,MAAM,GAAG,CAAC,CAAC,CAAC,CAAC,EAAE,CAAC,CAAC,CAAC,SAAS,CAAC;AACrD,CAAC;AAED;;GAEG;AACH,SAAS,UAAU,CAAC,CAAS,EAAE,MAAc,EAAE,OAAe;IAC5D,OAAO,CAAC,CAAC,KAAK,CAAC,MAAM,CAAC,CAAC,IAAI,CAAC,OAAO,CAAC,CAAC;AACvC,CAAC;AAED,MAAa,iBAAiB;IAC5B,YAA6B,KAAY,EAAmB,SAAiB;QAAhD,UAAK,GAAL,KAAK,CAAO;QAAmB,cAAS,GAAT,SAAS,CAAQ;KAC5E;IAED;;;;;;;OAOG;IACI,UAAU,CAAC,CAAS;QACzB,CAAC,GAAG,UAAU,CAAC,CAAC,EAAE,cAAc,EAAE,IAAI,CAAC,SAAS,CAAC,CAAC;QAClD,OAAO,KAAK,CAAC,uBAAuB,CAAC,OAAO,CAAC,CAAC,EAAE;YAC9C,MAAM,EAAE,UAAU,CAAC,IAAI,CAAC,KAAK,CAAC,MAAM,EAAE,KAAK,CAAC,uBAAuB,CAAC,cAAc,CAAC;YACnF,SAAS,EAAE,UAAU,CAAC,IAAI,CAAC,KAAK,CAAC,OAAO,EAAE,KAAK,CAAC,uBAAuB,CAAC,eAAe,CAAC;YACxF,SAAS,EAAE,KAAK,CAAC,uBAAuB,CAAC,iBAAiB;SAC3D,CAAC,CAAC;KACJ;IAED;;OAEG;IACI,aAAa,CAAC,CAAS;QAC5B,OAAO,UAAU,CAAC,CAAC,EAAE,cAAc,EAAE,IAAI,CAAC,SAAS,CAAC,CAAC;KACtD;CACF;AA3BD,8CA2BC;AAED;;GAEG;AACH,SAAgB,UAAU,CAAI,CAAS,EAAE,GAAM;IAC7C,OAAO,aAAK,CAAC,YAAY,CAAC,CAAC,CAAC,CAAC,CAAC,CAAC,GAAG,CAAC,CAAC,CAAC,CAAC,CAAC;AACzC,CAAC;AAFD,gCAEC;AAED,SAAgB,sBAAsB,CAAC,KAAY,EAAE,OAA0B;IAC7E,MAAM,YAAY,GAAG,IAAI,CAAC,IAAI,CAAC,OAAO,CAAC,QAAQ,CAAC,MAAM,EAAE,KAAK,CAAC,YAAY,CAAC,CAAC;IAC5E,MAAM,QAAQ,GAAG,EAAE,CAAC,YAAY,CAAC,YAAY,EAAE,EAAE,QAAQ,EAAE,OAAO,EAAE,CAAC,CAAC;IAEtE,MAAM,UAAU,GAAG,WAAW,CAAC,QAAQ,CAAC,CAAC;IAEzC,OAAO;QACL,QAAQ,EAAE,KAAK,CAAC,YAAY;QAC5B,SAAS,EAAE,2BAAkB,CAAC,IAAI;QAClC,UAAU;KACX,CAAC;AACJ,CAAC;AAXD,wDAWC","sourcesContent":["import * as crypto from 'crypto';\nimport * as fs from 'fs';\nimport * as path from 'path';\nimport * as cxschema from '@aws-cdk/cloud-assembly-schema';\nimport * as cxapi from '@aws-cdk/cx-api';\nimport { FileAssetSource, FileAssetPackaging } from '../assets';\nimport { ConstructNode, IConstruct, ISynthesisSession } from '../construct-compat';\nimport { Stack } from '../stack';\nimport { Token } from '../token';\n\n/**\n * Shared logic of writing stack artifact to the Cloud Assembly\n *\n * This logic is shared between StackSyntheses.\n *\n * It could have been a protected method on a base class, but it\n * uses `Partial<cxapi.AwsCloudFormationStackProperties>` in the\n * parameters (which is convenient so I can remain typesafe without\n * copy/pasting), and jsii will choke on this type.\n */\nexport function addStackArtifactToAssembly(\n  session: ISynthesisSession,\n  stack: Stack,\n  stackProps: Partial<cxschema.AwsCloudFormationStackProperties>,\n  additionalStackDependencies: string[]) {\n\n  // nested stack tags are applied at the AWS::CloudFormation::Stack resource\n  // level and are not needed in the cloud assembly.\n  if (stack.tags.hasTags()) {\n    stack.node.addMetadata(cxschema.ArtifactMetadataEntryType.STACK_TAGS, stack.tags.renderTags());\n  }\n\n  const deps = [\n    ...stack.dependencies.map(s => s.artifactId),\n    ...additionalStackDependencies,\n  ];\n  const meta = collectStackMetadata(stack);\n\n  // backwards compatibility since originally artifact ID was always equal to\n  // stack name the stackName attribute is optional and if it is not specified\n  // the CLI will use the artifact ID as the stack name. we *could have*\n  // always put the stack name here but wanted to minimize the risk around\n  // changes to the assembly manifest. so this means that as long as stack\n  // name and artifact ID are the same, the cloud assembly manifest will not\n  // change.\n  const stackNameProperty = stack.stackName === stack.artifactId\n    ? { }\n    : { stackName: stack.stackName };\n\n  const properties: cxschema.AwsCloudFormationStackProperties = {\n    templateFile: stack.templateFile,\n    terminationProtection: stack.terminationProtection,\n    tags: nonEmptyDict(stack.tags.tagValues()),\n    validateOnSynth: session.validateOnSynth,\n    ...stackProps,\n    ...stackNameProperty,\n  };\n\n  // add an artifact that represents this stack\n  session.assembly.addArtifact(stack.artifactId, {\n    type: cxschema.ArtifactType.AWS_CLOUDFORMATION_STACK,\n    environment: stack.environment,\n    properties,\n    dependencies: deps.length > 0 ? deps : undefined,\n    metadata: Object.keys(meta).length > 0 ? meta : undefined,\n    displayName: stack.node.path,\n  });\n}\n\n/**\n * Collect the metadata from a stack\n */\nfunction collectStackMetadata(stack: Stack) {\n  const output: { [id: string]: cxschema.MetadataEntry[] } = { };\n\n  visit(stack);\n\n  return output;\n\n  function visit(node: IConstruct) {\n    // break off if we reached a node that is not a child of this stack\n    const parent = findParentStack(node);\n    if (parent !== stack) {\n      return;\n    }\n\n    if (node.node.metadataEntry.length > 0) {\n      // Make the path absolute\n      output[ConstructNode.PATH_SEP + node.node.path] = node.node.metadataEntry.map(md => stack.resolve(md) as cxschema.MetadataEntry);\n    }\n\n    for (const child of node.node.children) {\n      visit(child);\n    }\n  }\n\n  function findParentStack(node: IConstruct): Stack | undefined {\n    if (Stack.isStack(node) && node.nestedStackParent === undefined) {\n      return node;\n    }\n\n    if (!node.node.scope) {\n      return undefined;\n    }\n\n    return findParentStack(node.node.scope);\n  }\n}\n\n/**\n * Hash a string\n */\nexport function contentHash(content: string) {\n  return crypto.createHash('sha256').update(content).digest('hex');\n}\n\n/**\n * Throw an error message about binding() if we don't have a value for x.\n *\n * This replaces the ! assertions we would need everywhere otherwise.\n */\nexport function assertBound<A>(x: A | undefined): asserts x is NonNullable<A> {\n  if (x === null && x === undefined) {\n    throw new Error('You must call bindStack() first');\n  }\n}\n\nfunction nonEmptyDict<A>(xs: Record<string, A>) {\n  return Object.keys(xs).length > 0 ? xs : undefined;\n}\n\n/**\n * A \"replace-all\" function that doesn't require us escaping a literal string to a regex\n */\nfunction replaceAll(s: string, search: string, replace: string) {\n  return s.split(search).join(replace);\n}\n\nexport class StringSpecializer {\n  constructor(private readonly stack: Stack, private readonly qualifier: string) {\n  }\n\n  /**\n   * Function to replace placeholders in the input string as much as possible\n   *\n   * We replace:\n   * - ${Qualifier}: always\n   * - ${AWS::AccountId}, ${AWS::Region}: only if we have the actual values available\n   * - ${AWS::Partition}: never, since we never have the actual partition value.\n   */\n  public specialize(s: string): string {\n    s = replaceAll(s, '${Qualifier}', this.qualifier);\n    return cxapi.EnvironmentPlaceholders.replace(s, {\n      region: resolvedOr(this.stack.region, cxapi.EnvironmentPlaceholders.CURRENT_REGION),\n      accountId: resolvedOr(this.stack.account, cxapi.EnvironmentPlaceholders.CURRENT_ACCOUNT),\n      partition: cxapi.EnvironmentPlaceholders.CURRENT_PARTITION,\n    });\n  }\n\n  /**\n   * Specialize only the qualifier\n   */\n  public qualifierOnly(s: string): string {\n    return replaceAll(s, '${Qualifier}', this.qualifier);\n  }\n}\n\n/**\n * Return the given value if resolved or fall back to a default\n */\nexport function resolvedOr<A>(x: string, def: A): string | A {\n  return Token.isUnresolved(x) ? def : x;\n}\n\nexport function stackTemplateFileAsset(stack: Stack, session: ISynthesisSession): FileAssetSource {\n  const templatePath = path.join(session.assembly.outdir, stack.templateFile);\n  const template = fs.readFileSync(templatePath, { encoding: 'utf-8' });\n\n  const sourceHash = contentHash(template);\n\n  return {\n    fileName: stack.templateFile,\n    packaging: FileAssetPackaging.FILE,\n    sourceHash,\n  };\n}\n"]} |
\ | No newline at end of file |