Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,143 @@
#
# Module manifest for module 'CloudflareITGlue'
#
# Generated by: Jeremy Colby
#
# Generated on: 06/27/2019
#

@{

# Script module or binary module file associated with this manifest.
RootModule = 'CloudflareITGlue.psm1'

# Version number of this module.
ModuleVersion = '1.2.0'
# 1.0: Matching zones to ITGlue orgs via txt record mechanism
# 1.1: Matching zones to ITGlue orgs via Domain tracker + minor improvements
# 1.2: Full logging functionality
# Cloudflare's zone file export format changed, modified to account for this
# - Also, re Cloudflare zone file import/upload - it is normal for Cloudflare to show error when reading the SOA record from the zone file
# - All other records are still imported normally, This happens with an unmodified exported zone files as well - SOA is a backend setting in Cloudflare
# Files with the same name in ITGlue on a flex asset are not unique, revision history would only show the newest file,
# - Zone files now have unique filename via utc timestamp, revision history keeps copies of each file
# Running the sync command automatically creates the flex asset type if it does not exist
# Related items tagging
# Lowered Cloudflare request buffer
# Formatting + minor improvements

# Supported PSEditions
# CompatiblePSEditions = @()

# ID used to uniquely identify this module
GUID = '55a62423-f6e4-4548-ba2a-7387a32ff6d3'

# Author of this module
Author = 'Jeremy Colby'

# Company or vendor of this module
# CompanyName = ''

# Copyright statement for this module
Copyright = '(c) 2019 Jeremy Colby. All rights reserved.'

# Description of the functionality provided by this module
Description = 'Sync Cloudflare DNS Zones to ITGlue Client Organizations as Flex Assets'

# Minimum version of the Windows PowerShell engine required by this module
PowerShellVersion = '5.0' # New-TemporaryFile seems like only incompatiblity with 4.0

# Name of the Windows PowerShell host required by this module
# PowerShellHostName = ''

# Minimum version of the Windows PowerShell host required by this module
# PowerShellHostVersion = ''

# Minimum version of Microsoft .NET Framework required by this module. This prerequisite is valid for the PowerShell Desktop edition only.
# DotNetFrameworkVersion = ''

# Minimum version of the common language runtime (CLR) required by this module. This prerequisite is valid for the PowerShell Desktop edition only.
# CLRVersion = ''

# Processor architecture (None, X86, Amd64) required by this module
# ProcessorArchitecture = ''

# Modules that must be imported into the global environment prior to importing this module
# RequiredModules = @()

# Assemblies that must be loaded prior to importing this module
# RequiredAssemblies = @()

# Script files (.ps1) that are run in the caller's environment prior to importing this module.
# ScriptsToProcess = @()

# Type files (.ps1xml) to be loaded when importing this module
# TypesToProcess = @()

# Format files (.ps1xml) to be loaded when importing this module
# FormatsToProcess = @()

# Modules to import as nested modules of the module specified in RootModule/ModuleToProcess
NestedModules = 'Private\CloudflareWebRequest.ps1',
'Private\CloudflareZoneData.ps1',
'Private\ITGlueWebRequest.ps1',
'Private\New-CloudflareITGlueFlexAssetType.ps1',
'Public\CloudflareITGlueAPIAuth.ps1',
'Public\Sync-CloudflareITGlueFlexibleAssets.ps1'

# Functions to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no functions to export.
FunctionsToExport = 'Add-CloudflareITGlueAPIAuth',
'Get-CloudflareITGlueAPIAuth',
'Remove-CloudflareITGlueAPIAuth',
'Sync-CloudflareITGlueFlexibleAssets'

# Cmdlets to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no cmdlets to export.
CmdletsToExport = @()

# Variables to export from this module
VariablesToExport = @()

# Aliases to export from this module, for best performance, do not use wildcards and do not delete the entry, use an empty array if there are no aliases to export.
AliasesToExport = @()

# DSC resources to export from this module
# DscResourcesToExport = @()

# List of all modules packaged with this module
# ModuleList = @()

# List of all files packaged with this module
# FileList = @()

# Private data to pass to the module specified in RootModule/ModuleToProcess. This may also contain a PSData hashtable with additional module metadata used by PowerShell.
PrivateData = @{

PSData = @{

# Tags applied to this module. These help with module discovery in online galleries.
# Tags = @()

# A URL to the license for this module.
# LicenseUri = ''

# A URL to the main website for this project.
# ProjectUri = ''

# A URL to an icon representing this module.
# IconUri = ''

# ReleaseNotes of this module
# ReleaseNotes = ''

} # End of PSData hashtable

} # End of PrivateData hashtable

# HelpInfo URI of this module
# HelpInfoURI = ''

# Default prefix for commands exported from this module. Override the default prefix using Import-Module -Prefix.
# DefaultCommandPrefix = ''

}

Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
$ModuleBase = Get-Module CloudflareITGlue -ListAvailable | ForEach-Object ModuleBase

if (Test-Path "$ModuleBase\$env:username.auth") {
Write-Host "CloudflareITGlue: Auth detected for $env:username" -ForegroundColor Green
$Auth = Import-Csv "$ModuleBase\$env:username.auth"
$Global:CloudflareAPIEmail = $Auth.CloudflareEmail
$Global:CloudflareAPIKey = ($Auth.CloudflareAPIKey | ConvertTo-SecureString)
$Global:ITGlueAPIKey = ($Auth.ITGlueAPIKey | ConvertTo-SecureString)
}

$Global:CFITGLog = $null

[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
function New-CloudflareWebRequest {
param(
[Parameter(Mandatory = $true)][string]$Endpoint,
[ValidateSet('GET', 'POST', 'PUT', 'PATCH', 'DELETE')][string]$Method = 'GET',
[string]$Body = $null,
[int]$ResultsPerPage = 50,
[int]$PageNumber = 1
)

if ($CloudflareAPIKey) {
try {
$APIKey = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto([System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($CloudflareAPIKey))
}
catch {
Write-Warning 'Unable to decrypt auth info, run Add-CloudflareITGlueAPIAuth to re-add'
if ($CFITGLog) {
"[CF Request]$(Get-Date -Format G): Unable to decrypt auth info, run Add-CloudflareITGlueAPIAuth to re-add" | Out-File $CFITGLog -Append
}
break
}
}
else {
Write-Warning 'Run Add-CloudflareITGlueAPIAuth to add authorization info'
if ($CFITGLog) {
"[CF Request]$(Get-Date -Format G): Run Add-CloudflareITGlueAPIAuth to add authorization info" | Out-File $CFITGLog -Append
}
break
}

$RequestParams = @{
Uri = 'https://api.cloudflare.com/client/v4/' + $Endpoint + "?per_page=$ResultsPerPage&page=$PageNumber"
Method = $Method
Headers = @{
'X-Auth-Key' = $APIKey
'X-Auth-Email' = $CloudflareAPIEmail
'Content-Type' = 'application/json'
}
}
if ($Body) { $RequestParams.Body = $Body }

try {
$Request = Invoke-RestMethod @RequestParams
Start-Sleep -Milliseconds 325
# RateLimit: 1200/5 min

if ($PageNumber -lt $Request.result_info.total_pages) {
$PageNumber++
New-CloudflareWebRequest -Endpoint $Endpoint -ResultsPerPage $ResultsPerPage -PageNumber $PageNumber
}
$APIKey = $null
$RequestParams = $null
return $Request
}
catch {
Write-Warning "Something went wrong with Cloudflare request:`n$_"
if ($CFITGLog) {
"[CF Request: $Endpoint]$(Get-Date -Format G): $_" | Out-File $CFITGLog -Append
}

$APIKey = $null
$RequestParams = $null
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,125 @@
function Get-CloudflareZoneData {
param(
[Parameter(Mandatory = $true)][string]$ZoneId,
[Parameter(Mandatory = $true)][pscustomobject]$ITGMatch
)

$DateUTC = (Get-Date).ToUniversalTime().ToString('yyyy-M-d')
$AccountId = New-CloudflareWebRequest -Endpoint 'accounts' | ForEach-Object result | ForEach-Object id
$ZoneInfo = New-CloudflareWebRequest -Endpoint "zones/$ZoneId"
$ZoneRecords = New-CloudflareWebRequest -Endpoint "zones/$ZoneId/dns_records"
if ($ZoneRecords.result_info.count -eq 0) {
Write-Host "$($ZoneInfo.result.name): Empty Zone Detected" -ForegroundColor Yellow
if ($CFITGLog) {
"[CF]$(Get-Date -Format G): Empty Zone Detected - $($ZoneInfo.result.name)" | Out-File $CFITGLog -Append
}
break
}
$ZoneFileData = New-CloudflareWebRequest -Endpoint "zones/$ZoneId/dns_records/export"
$ZoneFileData = $ZoneFileData.Replace(
';; SOA Record',
"`$ORIGIN $($ZoneInfo.result.name).`n`n;; SOA Record"
)
$ZoneFileData = $ZoneFileData.Replace(
"SOA`t$($ZoneInfo.result.name). root.$($ZoneInfo.result.name).",
"SOA`t$($ZoneInfo.result.name_servers[0]). $((($CloudflareAPIEmail -split '@')[0]).Replace('.','\.') + '.'+ ($CloudflareAPIEmail -split '@')[1])."
)
$ZoneFileData = $ZoneFileData.Replace(
';; A Records',
";; NS Records`n$($ZoneInfo.result.name). 1 IN NS $($ZoneInfo.result.name_servers[0]).`n$($ZoneInfo.result.name). 1 IN NS $($ZoneInfo.result.name_servers[1]).`n`n;; A Records"
)
$ZoneFileData = $ZoneFileData.Replace(
';; -- update the SOA record with the correct authoritative name server',
";; -- update the SOA record with the correct authoritative name server`n;; ** CloudflareITGlue Module: Updated $($DateUTC)"
)
$ZoneFileData = $ZoneFileData.Replace(
';; -- update the SOA record with the contact e-mail address information',
";; -- update the SOA record with the contact e-mail address information`n;; ** CloudflareITGlue Module: Updated $($DateUTC)"
)
$ZoneFileData = $ZoneFileData.Replace(
';; -- update the NS record(s) with the authoritative name servers for this domain.',
";; -- update the NS record(s) with the authoritative name servers for this domain.`n;; ** CloudflareITGlue Module: Updated $($DateUTC)`n;; ** CloudflareITGlue Module: Added `$ORIGIN directive"
)
$RecordsHtml =
'<div>
<p><a class="btn btn-sm btn-default" href="https://dash.cloudflare.com/' + $AccountId + "/$($ZoneInfo.result.name)" + '/dns" rel="nofollow" style="display: inline" title="Cloudflare">
<i class="fa fa-fw fa-external-link"></i><span>Open in Cloudflare</span></a></p>

<table id="RecordTable" style="width:100%">
<thead>
<th>Type</th>
<th>Name</th>
<th>Value</th>
<th>Priority</th>
<th>TTL</th>
<th>Proxied</th>
<th>Modified</th>
</thead>
<tbody>' +
$(foreach ($Record in $ZoneRecords.result) {
"<tr>
<td>$($Record.type)</td>
<td>$($Record.name)</td>
<td>$($Record.content)</td>
<td>$($Record.priority)</td>
<td>$(if ($Record.ttl -eq 1){'Auto'}else{$Record.ttl})</td>
<td>$($Record.proxied)</td>
<td>$(($Record.modified_on.Replace('T', ' ') -split '\.')[0])</td>
</tr>"
}) +
'</tbody>
</table>
</div>'

$ZoneData = [ordered]@{
Name = $ZoneInfo.result.name
SyncDate = $DateUTC
CfNameServers = $ZoneInfo.result.name_servers
Status = $ZoneInfo.result.status
ZoneFileData = $ZoneFileData
RecordsHtml = $RecordsHtml
ITGOrg = $Match.OrgMatchId
DomainTracker = $Match.DomainTrackerId
}
$ZoneData
}

function Get-CloudflareZoneDataArray {
$Progress = 0
Write-Progress -Activity 'CloudflareAPI' -Status 'Getting Zone Data' -PercentComplete 0 -Id 1
$ZoneDataArray = @()
$AllZones = New-CloudflareWebRequest -Endpoint 'zones'
[pscustomobject]$ITGDomains = New-ITGlueWebRequest -Endpoint 'domains' | ForEach-Object data

foreach ($Zone in $AllZones.result) {
Write-Progress -Activity 'CloudflareAPI' -Status 'Getting Zone Data' -CurrentOperation $Zone.name -PercentComplete ($Progress / ($AllZones.result | Measure-Object | ForEach-Object count) * 100) -Id 1

$ITGMatches = @()
foreach ($ITGDomain in $ITGDomains) {
if ($Zone.name.ToLower() -eq $ITGDomain.attributes.name.ToLower()) {
$Match = @{
OrgMatchId = $ITGDomain.attributes.'organization-id'
DomainTrackerId = $ITGDomain.id
}
$ITGMatches += [pscustomobject]$Match
}
}
if ($ITGMatches) {
foreach ($Match in $ITGMatches) {
$ZoneData = Get-CloudflareZoneData -ZoneId $Zone.id -ITGMatch $Match
if ($ZoneData) {
$ZoneDataArray += [pscustomobject]$ZoneData
}
}
}
else {
Write-Host "$($Zone.name): Add to domain tracker" -ForegroundColor Yellow
if ($CFITGLog) {
"[CFITG]$(Get-Date -Format G): $($Zone.name) - Add to ITG domain tracker" | Out-File $CFITGLog -Append
}
}
$Progress++
}
Write-Progress -Activity 'CloudflareAPI' -Status 'Complete' -PercentComplete 100 -Id 1
$ZoneDataArray
}
Loading