2019-04-24 21:52:08 +00:00
|
|
|
package schema
|
|
|
|
|
2021-01-04 10:55:23 +00:00
|
|
|
// AccessControlConfiguration represents the configuration related to ACLs.
|
|
|
|
type AccessControlConfiguration struct {
|
|
|
|
DefaultPolicy string `mapstructure:"default_policy"`
|
|
|
|
Networks []ACLNetwork `mapstructure:"networks"`
|
|
|
|
Rules []ACLRule `mapstructure:"rules"`
|
|
|
|
}
|
|
|
|
|
|
|
|
// ACLNetwork represents one ACL network group entry; "weak" coerces a single value into slice.
|
|
|
|
type ACLNetwork struct {
|
2021-03-05 04:18:31 +00:00
|
|
|
Name string `mapstructure:"name"`
|
2021-01-04 10:55:23 +00:00
|
|
|
Networks []string `mapstructure:"networks"`
|
|
|
|
}
|
2019-04-24 21:52:08 +00:00
|
|
|
|
2020-06-25 08:22:42 +00:00
|
|
|
// ACLRule represents one ACL rule entry; "weak" coerces a single value into slice.
|
2019-04-24 21:52:08 +00:00
|
|
|
type ACLRule struct {
|
2020-06-25 08:22:42 +00:00
|
|
|
Domains []string `mapstructure:"domain,weak"`
|
|
|
|
Policy string `mapstructure:"policy"`
|
|
|
|
Subjects [][]string `mapstructure:"subject,weak"`
|
|
|
|
Networks []string `mapstructure:"networks"`
|
|
|
|
Resources []string `mapstructure:"resources"`
|
2021-03-05 04:18:31 +00:00
|
|
|
Methods []string `mapstructure:"methods"`
|
2019-04-24 21:52:08 +00:00
|
|
|
}
|
2021-01-16 10:05:41 +00:00
|
|
|
|
|
|
|
// DefaultACLNetwork represents the default configuration related to access control network group configuration.
|
|
|
|
var DefaultACLNetwork = []ACLNetwork{
|
|
|
|
{
|
2021-03-05 04:18:31 +00:00
|
|
|
Name: "localhost",
|
2021-01-16 10:05:41 +00:00
|
|
|
Networks: []string{"127.0.0.1"},
|
|
|
|
},
|
|
|
|
{
|
2021-03-05 04:18:31 +00:00
|
|
|
Name: "internal",
|
2021-01-16 10:05:41 +00:00
|
|
|
Networks: []string{"10.0.0.0/8"},
|
|
|
|
},
|
|
|
|
}
|
|
|
|
|
|
|
|
// DefaultACLRule represents the default configuration related to access control rule configuration.
|
|
|
|
var DefaultACLRule = []ACLRule{
|
|
|
|
{
|
|
|
|
Domains: []string{"public.example.com"},
|
|
|
|
Policy: "bypass",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Domains: []string{"singlefactor.example.com"},
|
|
|
|
Policy: "one_factor",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Domains: []string{"secure.example.com"},
|
|
|
|
Policy: "two_factor",
|
|
|
|
},
|
|
|
|
}
|