Core/ServerRake.Core.SessionManagement.ps1
|
############################ ### SESSION MANAGEMENT ### ############################ # SECRET SERVER function Open-SecretSession { [CmdletBinding()] param ( [Parameter()] [String] $Username, [Parameter()] [String] $ApiToken, [Parameter(Mandatory = $true)] [String] $SecretName, [Parameter(Mandatory = $true)] [String] $SecretServerURL ) $baseUrl = "https://$($SecretServerURL)" if (!$secret) { try { Write-Host "`nConnecting to SecretServer..." if ($ApiToken) { $script:secretServerSession = New-TssSession -SecretServer $baseUrl -AccessToken $ApiToken -ErrorAction Stop -WarningAction SilentlyContinue } else { if($Username) { $script:corporateCredentials = Get-Credential -Credential $Username } else { $script:corporateCredentials = Get-Credential -Credential $localuser } $script:secretServerSession = New-TssSession -SecretServer $baseUrl -Credential $corporateCredentials -ErrorAction Stop } Write-Host "`nConnection Successful!" -ForegroundColor Magenta Write-Host "Collecting Secret...`n" $secretId = Find-TssSecret -TssSession $secretServerSession -SecretName $SecretName -ErrorAction Stop $secretObject = Get-TssSecret -TssSession $secretServerSession -Id $secretId.SecretId -ErrorAction Stop $script:secret = $secretObject.GetCredential('domain', 'username', 'password') $script:secretPlain = $secretObject.GetCredential($null, 'username', 'password') Write-Host "`nSecret collected!" -ForegroundColor Green Write-Host "Use 'Close-SecretSession' to exit open Secret Server sessions when finished.`n" -ForegroundColor Yellow } catch { throw $_ } } else { Write-Host "`nThere is already an active SecretServer session." -ForegroundColor Yellow Write-Host "To make a new session, close the current session by running 'Close-SecretSession'.`n" -ForegroundColor Yellow } } function Close-SecretSession { if ($secret) { try { Close-TssSession -TssSession $secretServerSession -ErrorAction Stop | Out-Null $script:secretServerSession = $null $script:corporateCredentials = $null $script:secret = $null $script:secretPlain = $null Write-Host "`nSecretServer Session successfully closed. Cached secrets cleared.`n" -ForegroundColor Blue } catch { Write-Host "`nAn error occured closing the SecretServer session.`n" -ForegroundColor Red throw $_ } } else { Write-Host "`nNo secret session currently exists.`n" -ForegroundColor Red } } # JUMPHOSTS function Open-DoubleHopSession { [CmdletBinding()] param ( [Parameter(Mandatory = $True)] [String] $Jumphost ) if ($secret) { if (!$doublehop) { try { $script:jh = New-PSSession -ComputerName $jumphost -Credential $secret -ErrorAction Stop $script:doublehop = $true Write-Host "`nDouble-hop now active. Cmdlets will now be sent to VMs via [$jumphost]." -ForegroundColor Green Write-Host "Use 'Close-DoubleHopSession' to exit double-hopping when finished.`n" -ForegroundColor Yellow } catch { Write-Host "`nCould not establish double-hop session.`n" -ForegroundColor Red throw $_ } } else { Write-Host "`nThere is already an active Double Hop session." -ForegroundColor Yellow Write-Host "To start a session with a different jumphost, run 'Close-DoubleHopSession', then 'Open-DoubleHopSession'.`n" -ForegroundColor Yellow } } else { Write-Host "`nNo secret sessions are currently opened. Start a session with 'Open-SecretSession' and try again.`n" -ForegroundColor Red } } function Close-DoubleHopSession { if ($DoubleHop) { $script:DoubleHop = $false Remove-PSSession -Name $jh Write-Host "`nSession with jumphost is now closed.`n" -ForegroundColor Blue } else { Write-Host "`nNo double hop session exists.`n" -ForegroundColor Red } } # NUTANIX function Set-NutanixCredentials { [CmdletBinding()] param ( [Parameter(Mandatory = $True)] [String] $Username ) if ($secretPlain -AND $secretPlain.Username -eq $Username) { $script:nxAPICreds = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes("$($secretPlain.Username):$($secretPlain.GetNetworkCredential().Password)")) } else { $credential = Get-Credential -Credential $Username $script:nxAPICreds = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes("$($credential.Username):$($credential.GetNetworkCredential().Password)")) } } |