Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Changes script to use Java for IAM. #677

Merged
merged 4 commits into from
May 24, 2017
Merged
Show file tree
Hide file tree
Changes from 2 commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion iot/api-client/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,7 @@ Google Cloud IoT Core platform.

## Quickstart

1. Install the gCloud CLI as described in [the device manager guide](https://cloud-dot-devsite.googleplex.com/iot/docs/device_manager_guide).
1. Install the gCloud CLI as described in [the device manager guide](https://cloud.google.com/iot/docs/device_manager_guide).
2. Create a PubSub topic:

gcloud beta pubsub topics create projects/my-iot-project/topics/device-events
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -39,17 +39,26 @@
* </pre>
*/
public class MqttExample {
/** Load a PKCS8 encoded keyfile from the given path. */
private static PrivateKey loadKeyFile(String filename, String algorithm) throws Exception {
byte[] keyBytes = Files.readAllBytes(Paths.get(filename));
/** Create a Cloud IoT Core JWT for the given project id, signed with the given private key. */
private static String createJwtRsa(String projectId, String privateKeyFile) throws Exception {
DateTime now = new DateTime();
// Create a JWT to authenticate this device. The device will be disconnected after the token
// expires, and will have to reconnect with a new token. The audience field should always be set
// to the GCP project id.
JwtBuilder jwtBuilder =
Jwts.builder()
.setIssuedAt(now.toDate())
.setExpiration(now.plusMinutes(20).toDate())
.setAudience(projectId);

byte[] keyBytes = Files.readAllBytes(Paths.get(privateKeyFile));
PKCS8EncodedKeySpec spec = new PKCS8EncodedKeySpec(keyBytes);
KeyFactory kf = KeyFactory.getInstance(algorithm);
return kf.generatePrivate(spec);
KeyFactory kf = KeyFactory.getInstance("RSA256");

return jwtBuilder.signWith(SignatureAlgorithm.RS256, kf.generatePrivate(spec)).compact();
}

/** Create a Cloud IoT Core JWT for the given project id, signed with the given private key. */
private static String createJwt(String projectId, String privateKeyFile, String algorithm)
throws Exception {
private static String createJwtEs(String projectId, String privateKeyFile) throws Exception {
DateTime now = new DateTime();
// Create a JWT to authenticate this device. The device will be disconnected after the token
// expires, and will have to reconnect with a new token. The audience field should always be set
Expand All @@ -60,16 +69,11 @@ private static String createJwt(String projectId, String privateKeyFile, String
.setExpiration(now.plusMinutes(20).toDate())
.setAudience(projectId);

if (algorithm.equals("RS256")) {
PrivateKey privateKey = loadKeyFile(privateKeyFile, "RSA");
return jwtBuilder.signWith(SignatureAlgorithm.RS256, privateKey).compact();
} else if (algorithm.equals("ES256")) {
PrivateKey privateKey = loadKeyFile(privateKeyFile, "EC");
return jwtBuilder.signWith(SignatureAlgorithm.ES256, privateKey).compact();
} else {
throw new IllegalArgumentException(
"Invalid algorithm " + algorithm + ". Should be one of 'RS256' or 'ES256'.");
}
byte[] keyBytes = Files.readAllBytes(Paths.get(privateKeyFile));
PKCS8EncodedKeySpec spec = new PKCS8EncodedKeySpec(keyBytes);
KeyFactory kf = KeyFactory.getInstance("ES256");

return jwtBuilder.signWith(SignatureAlgorithm.ES256, kf.generatePrivate(spec)).compact();
}

public static void main(String[] args) throws Exception {
Expand Down Expand Up @@ -102,8 +106,17 @@ public static void main(String[] args) throws Exception {
// Paho client library to send the password field. The password field is used to transmit a JWT
// to authorize the device.
connectOptions.setUserName("unused");
connectOptions.setPassword(
createJwt(options.projectId, options.privateKeyFile, options.algorithm).toCharArray());

if (options.algorithm == "RSA256") {
connectOptions.setPassword(
createJwtRsa(options.projectId, options.privateKeyFile).toCharArray());
} else if (options.algorithm == "ES256") {
connectOptions.setPassword(
createJwtEs(options.projectId, options.privateKeyFile).toCharArray());
} else {
throw new IllegalArgumentException(
"Invalid algorithm " + options.algorithm + ". Should be one of 'RS256' or 'ES256'.");
}

// Create a client, and connect to the Google MQTT bridge.
MqttClient client = new MqttClient(mqttServerAddress, mqttClientId, new MemoryPersistence());
Expand Down
33 changes: 33 additions & 0 deletions iot/api-client/scripts/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
# Getting Started with Cloud Pub/Sub and the Google Cloud Client libraries

[Google Cloud IoT Core](https://cloud.google.com/iot-core/)
is a fully-managed, globally distributed solution for managing devices and
sending / receiving messages from devices.

This script manages the [Google Cloud Pub/Sub][pubsub] project associated with
your Google Cloud IoT Core project to grant permissions to the protocol bridge.

Create your PubSub topic noting the project ID and topic ID, then build and run
the sample to configure your topic.

[pubsub]: https://cloud.google.com/pubsub/

#### Setup

* Install [Maven](http://maven.apache.org/)
* Build your project with:

mvn clean compile assembly:single

#### Running the script

The following code will run the helper script:

java -cp target/pubsub-google-cloud-samples-1.0.0-jar-with-dependencies.jar \
com.example.pubsub.AddCloudIotService <topicName> <projectId>

For example, the following example will configure the `device-events` topic
for the `my-iot-project` project.

java -cp target/pubsub-google-cloud-samples-1.0.0-jar-with-dependencies.jar \
com.example.pubsub.AddCloudIotService device-events my-iot-project
115 changes: 0 additions & 115 deletions iot/api-client/scripts/README.rst

This file was deleted.

22 changes: 0 additions & 22 deletions iot/api-client/scripts/README.rst.in

This file was deleted.

57 changes: 0 additions & 57 deletions iot/api-client/scripts/iam.py

This file was deleted.

76 changes: 76 additions & 0 deletions iot/api-client/scripts/pom.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,76 @@
<!--
Copyright 2017 Google Inc.

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
-->
<project>
<modelVersion>4.0.0</modelVersion>
<groupId>com.example.pubsub</groupId>
<artifactId>pubsub-google-cloud-samples</artifactId>
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this artifactId probably does n't make sense, maybe pubsub-policy-helper ?

<packaging>jar</packaging>

<!-- Parent defines config for testing & linting. -->
<parent>
<artifactId>doc-samples</artifactId>
<groupId>com.google.cloud</groupId>
<version>1.0.0</version>
<relativePath>../../..</relativePath>
</parent>

<properties>
<maven.compiler.target>1.8</maven.compiler.target>
<maven.compiler.source>1.8</maven.compiler.source>
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<pubsub.version>0.17.2-alpha</pubsub.version>
</properties>

<build>
<plugins>
<plugin>
<artifactId>maven-assembly-plugin</artifactId>
<configuration>
<archive>
<manifest>
<mainClass>com.example.pubsub.AddCloudIotService</mainClass>
</manifest>
</archive>
<descriptorRefs>
<descriptorRef>jar-with-dependencies</descriptorRef>
</descriptorRefs>
</configuration>
</plugin>
</plugins>
</build>

<dependencies>
<dependency>
<groupId>com.google.cloud</groupId>
<artifactId>google-cloud-pubsub</artifactId>
<version>${pubsub.version}</version>
</dependency>

<!-- Test dependencies -->
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>4.12</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>com.google.truth</groupId>
<artifactId>truth</artifactId>
<version>0.32</version>
<scope>test</scope>
</dependency>
</dependencies>
</project>
1 change: 0 additions & 1 deletion iot/api-client/scripts/requirements.txt

This file was deleted.

Loading