2023-03-28 22:48:58 +00:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
2023-08-11 13:12:13 +00:00
|
|
|
// SPDX-License-Identifier: BUSL-1.1
|
2023-03-28 22:48:58 +00:00
|
|
|
|
2018-04-03 18:10:59 +00:00
|
|
|
package proxy
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
2018-09-12 16:07:47 +00:00
|
|
|
"time"
|
2018-04-03 18:10:59 +00:00
|
|
|
|
2018-04-25 13:53:30 +00:00
|
|
|
"github.com/mitchellh/mapstructure"
|
|
|
|
|
2018-04-03 18:10:59 +00:00
|
|
|
"github.com/hashicorp/consul/api"
|
2019-04-26 16:33:01 +00:00
|
|
|
"github.com/hashicorp/consul/api/watch"
|
2018-04-03 18:10:59 +00:00
|
|
|
"github.com/hashicorp/consul/connect"
|
2019-06-04 14:02:38 +00:00
|
|
|
"github.com/hashicorp/consul/ipaddr"
|
2018-06-14 12:52:48 +00:00
|
|
|
"github.com/hashicorp/consul/lib"
|
2020-01-28 23:50:41 +00:00
|
|
|
"github.com/hashicorp/go-hclog"
|
2018-04-03 18:10:59 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// Config is the publicly configurable state for an entire proxy instance. It's
|
|
|
|
// mostly used as the format for the local-file config mode which is mostly for
|
|
|
|
// dev/testing. In normal use, different parts of this config are pulled from
|
|
|
|
// different locations (e.g. command line, agent config endpoint, agent
|
|
|
|
// certificate endpoints).
|
|
|
|
type Config struct {
|
|
|
|
// Token is the authentication token provided for queries to the local agent.
|
|
|
|
Token string `json:"token" hcl:"token"`
|
|
|
|
|
2018-05-19 07:11:51 +00:00
|
|
|
// ProxiedServiceName is the name of the service this proxy is representing.
|
|
|
|
// This is the service _name_ and not the service _id_. This allows the
|
|
|
|
// proxy to represent services not present in the local catalog.
|
|
|
|
//
|
2018-04-03 18:10:59 +00:00
|
|
|
// ProxiedServiceNamespace is the namespace of the service this proxy is
|
|
|
|
// representing.
|
2018-05-19 07:11:51 +00:00
|
|
|
ProxiedServiceName string `json:"proxied_service_name" hcl:"proxied_service_name"`
|
2018-04-03 18:10:59 +00:00
|
|
|
ProxiedServiceNamespace string `json:"proxied_service_namespace" hcl:"proxied_service_namespace"`
|
|
|
|
|
|
|
|
// PublicListener configures the mTLS listener.
|
|
|
|
PublicListener PublicListenerConfig `json:"public_listener" hcl:"public_listener"`
|
|
|
|
|
|
|
|
// Upstreams configures outgoing proxies for remote connect services.
|
|
|
|
Upstreams []UpstreamConfig `json:"upstreams" hcl:"upstreams"`
|
2018-06-07 13:11:06 +00:00
|
|
|
|
2018-06-11 20:25:13 +00:00
|
|
|
// Telemetry stores configuration for go-metrics. It is typically populated
|
|
|
|
// from the agent's runtime config via the proxy config endpoint so that the
|
2018-06-07 13:11:06 +00:00
|
|
|
// proxy will log metrics to the same location(s) as the agent.
|
2018-06-14 12:52:48 +00:00
|
|
|
Telemetry lib.TelemetryConfig
|
2018-05-19 07:11:51 +00:00
|
|
|
}
|
2018-04-03 18:10:59 +00:00
|
|
|
|
2018-05-19 07:11:51 +00:00
|
|
|
// Service returns the *connect.Service structure represented by this config.
|
2020-01-28 23:50:41 +00:00
|
|
|
func (c *Config) Service(client *api.Client, logger hclog.Logger) (*connect.Service, error) {
|
2021-03-26 11:34:47 +00:00
|
|
|
return connect.NewServiceWithConfig(c.ProxiedServiceName, connect.Config{Client: client, Logger: logger, ServerNextProtos: []string{}})
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// PublicListenerConfig contains the parameters needed for the incoming mTLS
|
|
|
|
// listener.
|
|
|
|
type PublicListenerConfig struct {
|
2018-04-25 13:53:30 +00:00
|
|
|
// BindAddress is the host/IP the public mTLS listener will bind to.
|
2018-05-19 07:11:51 +00:00
|
|
|
//
|
|
|
|
// BindPort is the port the public listener will bind to.
|
2018-04-25 13:53:30 +00:00
|
|
|
BindAddress string `json:"bind_address" hcl:"bind_address" mapstructure:"bind_address"`
|
2018-05-19 07:11:51 +00:00
|
|
|
BindPort int `json:"bind_port" hcl:"bind_port" mapstructure:"bind_port"`
|
2018-04-03 18:10:59 +00:00
|
|
|
|
|
|
|
// LocalServiceAddress is the host:port for the proxied application. This
|
|
|
|
// should be on loopback or otherwise protected as it's plain TCP.
|
2018-04-25 13:53:30 +00:00
|
|
|
LocalServiceAddress string `json:"local_service_address" hcl:"local_service_address" mapstructure:"local_service_address"`
|
2018-04-03 18:10:59 +00:00
|
|
|
|
|
|
|
// LocalConnectTimeout is the timeout for establishing connections with the
|
|
|
|
// local backend. Defaults to 1000 (1s).
|
2018-04-25 13:53:30 +00:00
|
|
|
LocalConnectTimeoutMs int `json:"local_connect_timeout_ms" hcl:"local_connect_timeout_ms" mapstructure:"local_connect_timeout_ms"`
|
2018-04-03 18:10:59 +00:00
|
|
|
|
|
|
|
// HandshakeTimeout is the timeout for incoming mTLS clients to complete a
|
|
|
|
// handshake. Setting this low avoids DOS by malicious clients holding
|
|
|
|
// resources open. Defaults to 10000 (10s).
|
2018-04-25 13:53:30 +00:00
|
|
|
HandshakeTimeoutMs int `json:"handshake_timeout_ms" hcl:"handshake_timeout_ms" mapstructure:"handshake_timeout_ms"`
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
2021-07-02 16:18:46 +00:00
|
|
|
// applyDefaults sets zero-valued params to a reasonable default.
|
2018-04-03 18:10:59 +00:00
|
|
|
func (plc *PublicListenerConfig) applyDefaults() {
|
|
|
|
if plc.LocalConnectTimeoutMs == 0 {
|
|
|
|
plc.LocalConnectTimeoutMs = 1000
|
|
|
|
}
|
|
|
|
if plc.HandshakeTimeoutMs == 0 {
|
|
|
|
plc.HandshakeTimeoutMs = 10000
|
|
|
|
}
|
2018-04-26 13:01:20 +00:00
|
|
|
if plc.BindAddress == "" {
|
|
|
|
plc.BindAddress = "0.0.0.0"
|
|
|
|
}
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
2018-09-12 16:07:47 +00:00
|
|
|
// UpstreamConfig is an alias for api.Upstream so we can parse in a compatible
|
|
|
|
// way but define custom methods for accessing the opaque config metadata.
|
|
|
|
type UpstreamConfig api.Upstream
|
2018-04-25 13:53:30 +00:00
|
|
|
|
2018-09-12 16:07:47 +00:00
|
|
|
// ConnectTimeout returns the connect timeout field of the nested config struct
|
|
|
|
// or the default value.
|
|
|
|
func (uc *UpstreamConfig) ConnectTimeout() time.Duration {
|
|
|
|
if ms, ok := uc.Config["connect_timeout_ms"].(int); ok {
|
|
|
|
return time.Duration(ms) * time.Millisecond
|
|
|
|
}
|
|
|
|
return 10000 * time.Millisecond
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
2021-07-02 16:18:46 +00:00
|
|
|
// applyDefaults sets zero-valued params to a reasonable default.
|
2018-04-03 18:10:59 +00:00
|
|
|
func (uc *UpstreamConfig) applyDefaults() {
|
2018-04-25 13:53:30 +00:00
|
|
|
if uc.DestinationType == "" {
|
|
|
|
uc.DestinationType = "service"
|
|
|
|
}
|
|
|
|
if uc.DestinationNamespace == "" {
|
|
|
|
uc.DestinationNamespace = "default"
|
|
|
|
}
|
2021-08-20 16:57:45 +00:00
|
|
|
if uc.DestinationPartition == "" {
|
|
|
|
uc.DestinationPartition = "default"
|
|
|
|
}
|
2021-03-26 20:00:44 +00:00
|
|
|
if uc.LocalBindAddress == "" && uc.LocalBindSocketPath == "" {
|
2018-04-25 13:53:30 +00:00
|
|
|
uc.LocalBindAddress = "127.0.0.1"
|
|
|
|
}
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// String returns a string that uniquely identifies the Upstream. Used for
|
|
|
|
// identifying the upstream in log output and map keys.
|
|
|
|
func (uc *UpstreamConfig) String() string {
|
2021-03-26 20:00:44 +00:00
|
|
|
addr := uc.LocalBindSocketPath
|
|
|
|
if addr == "" {
|
|
|
|
addr = fmt.Sprintf(
|
|
|
|
"%s:%d",
|
|
|
|
uc.LocalBindAddress, uc.LocalBindPort)
|
|
|
|
}
|
2021-08-20 16:57:45 +00:00
|
|
|
return fmt.Sprintf("%s->%s:%s/%s/%s", addr,
|
|
|
|
uc.DestinationType, uc.DestinationPartition, uc.DestinationNamespace, uc.DestinationName)
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
2018-09-12 16:07:47 +00:00
|
|
|
// UpstreamResolverFuncFromClient returns a closure that captures a consul
|
2018-10-09 16:57:26 +00:00
|
|
|
// client and when called provides a ConsulResolver that can resolve the given
|
2018-09-12 16:07:47 +00:00
|
|
|
// UpstreamConfig using the provided api.Client dependency.
|
|
|
|
func UpstreamResolverFuncFromClient(client *api.Client) func(cfg UpstreamConfig) (connect.Resolver, error) {
|
|
|
|
return func(cfg UpstreamConfig) (connect.Resolver, error) {
|
|
|
|
// For now default to service as it has the most natural meaning and the error
|
|
|
|
// that the service doesn't exist is probably reasonable if misconfigured. We
|
|
|
|
// should probably handle actual configs that have invalid types at a higher
|
|
|
|
// level anyway (like when parsing).
|
|
|
|
typ := connect.ConsulResolverTypeService
|
|
|
|
if cfg.DestinationType == "prepared_query" {
|
|
|
|
typ = connect.ConsulResolverTypePreparedQuery
|
|
|
|
}
|
|
|
|
return &connect.ConsulResolver{
|
|
|
|
Client: client,
|
|
|
|
Namespace: cfg.DestinationNamespace,
|
2021-08-20 16:57:45 +00:00
|
|
|
Partition: cfg.DestinationPartition,
|
2018-09-12 16:07:47 +00:00
|
|
|
Name: cfg.DestinationName,
|
|
|
|
Type: typ,
|
|
|
|
Datacenter: cfg.Datacenter,
|
|
|
|
}, nil
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// ConfigWatcher is a simple interface to allow dynamic configurations from
|
2018-10-09 16:57:26 +00:00
|
|
|
// pluggable sources.
|
2018-04-03 18:10:59 +00:00
|
|
|
type ConfigWatcher interface {
|
|
|
|
// Watch returns a channel that will deliver new Configs if something external
|
|
|
|
// provokes it.
|
|
|
|
Watch() <-chan *Config
|
|
|
|
}
|
|
|
|
|
|
|
|
// StaticConfigWatcher is a simple ConfigWatcher that delivers a static Config
|
|
|
|
// once and then never changes it.
|
|
|
|
type StaticConfigWatcher struct {
|
|
|
|
ch chan *Config
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewStaticConfigWatcher returns a ConfigWatcher for a config that never
|
|
|
|
// changes. It assumes only one "watcher" will ever call Watch. The config is
|
|
|
|
// delivered on the first call but will never be delivered again to allow
|
|
|
|
// callers to call repeatedly (e.g. select in a loop).
|
|
|
|
func NewStaticConfigWatcher(cfg *Config) *StaticConfigWatcher {
|
|
|
|
sc := &StaticConfigWatcher{
|
|
|
|
// Buffer it so we can queue up the config for first delivery.
|
|
|
|
ch: make(chan *Config, 1),
|
|
|
|
}
|
|
|
|
sc.ch <- cfg
|
|
|
|
return sc
|
|
|
|
}
|
|
|
|
|
|
|
|
// Watch implements ConfigWatcher on a static configuration for compatibility.
|
|
|
|
// It returns itself on the channel once and then leaves it open.
|
|
|
|
func (sc *StaticConfigWatcher) Watch() <-chan *Config {
|
|
|
|
return sc.ch
|
|
|
|
}
|
|
|
|
|
|
|
|
// AgentConfigWatcher watches the local Consul agent for proxy config changes.
|
|
|
|
type AgentConfigWatcher struct {
|
|
|
|
client *api.Client
|
|
|
|
proxyID string
|
2020-01-28 23:50:41 +00:00
|
|
|
logger hclog.Logger
|
2018-04-25 13:53:30 +00:00
|
|
|
ch chan *Config
|
|
|
|
plan *watch.Plan
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewAgentConfigWatcher creates an AgentConfigWatcher.
|
|
|
|
func NewAgentConfigWatcher(client *api.Client, proxyID string,
|
2020-01-28 23:50:41 +00:00
|
|
|
logger hclog.Logger) (*AgentConfigWatcher, error) {
|
2018-04-25 13:53:30 +00:00
|
|
|
w := &AgentConfigWatcher{
|
|
|
|
client: client,
|
|
|
|
proxyID: proxyID,
|
2020-01-28 23:50:41 +00:00
|
|
|
logger: logger.With("service_id", proxyID),
|
2018-04-25 13:53:30 +00:00
|
|
|
ch: make(chan *Config),
|
|
|
|
}
|
|
|
|
|
|
|
|
// Setup watch plan for config
|
|
|
|
plan, err := watch.Parse(map[string]interface{}{
|
2018-09-27 14:00:51 +00:00
|
|
|
"type": "agent_service",
|
|
|
|
"service_id": w.proxyID,
|
2018-04-25 13:53:30 +00:00
|
|
|
})
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
w.plan = plan
|
2018-04-25 20:22:31 +00:00
|
|
|
w.plan.HybridHandler = w.handler
|
2020-01-28 23:50:41 +00:00
|
|
|
go w.plan.RunWithClientAndHclog(w.client, w.logger)
|
2018-04-25 13:53:30 +00:00
|
|
|
return w, nil
|
|
|
|
}
|
|
|
|
|
2018-04-25 19:41:26 +00:00
|
|
|
func (w *AgentConfigWatcher) handler(blockVal watch.BlockingParamVal,
|
2018-04-25 13:53:30 +00:00
|
|
|
val interface{}) {
|
|
|
|
|
2018-09-27 14:00:51 +00:00
|
|
|
resp, ok := val.(*api.AgentService)
|
2018-04-25 13:53:30 +00:00
|
|
|
if !ok {
|
2020-01-28 23:50:41 +00:00
|
|
|
w.logger.Warn("proxy config watch returned bad response", "response", val)
|
2018-04-25 13:53:30 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2018-09-27 14:00:51 +00:00
|
|
|
if resp.Kind != api.ServiceKindConnectProxy {
|
2020-01-28 23:50:41 +00:00
|
|
|
w.logger.Error("service is not a valid connect proxy")
|
2018-09-27 14:00:51 +00:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
2018-04-25 13:53:30 +00:00
|
|
|
// Create proxy config from the response
|
|
|
|
cfg := &Config{
|
|
|
|
// Token should be already setup in the client
|
2018-09-27 14:00:51 +00:00
|
|
|
ProxiedServiceName: resp.Proxy.DestinationServiceName,
|
2018-04-25 13:53:30 +00:00
|
|
|
ProxiedServiceNamespace: "default",
|
|
|
|
}
|
|
|
|
|
2018-09-27 14:00:51 +00:00
|
|
|
if tRaw, ok := resp.Proxy.Config["telemetry"]; ok {
|
2018-06-14 12:52:48 +00:00
|
|
|
err := mapstructure.Decode(tRaw, &cfg.Telemetry)
|
|
|
|
if err != nil {
|
2020-01-28 23:50:41 +00:00
|
|
|
w.logger.Warn("proxy telemetry config failed to parse", "error", err)
|
2018-06-14 12:52:48 +00:00
|
|
|
}
|
2018-06-08 15:18:58 +00:00
|
|
|
}
|
|
|
|
|
2018-04-25 13:53:30 +00:00
|
|
|
// Unmarshal configs
|
2018-09-27 14:00:51 +00:00
|
|
|
err := mapstructure.Decode(resp.Proxy.Config, &cfg.PublicListener)
|
2018-04-25 13:53:30 +00:00
|
|
|
if err != nil {
|
2020-01-28 23:50:41 +00:00
|
|
|
w.logger.Error("failed to parse public listener config", "error", err)
|
2018-04-25 13:53:30 +00:00
|
|
|
}
|
2018-09-27 14:00:51 +00:00
|
|
|
cfg.PublicListener.BindAddress = resp.Address
|
|
|
|
cfg.PublicListener.BindPort = resp.Port
|
2021-05-04 04:43:55 +00:00
|
|
|
if resp.Proxy.LocalServiceSocketPath != "" {
|
|
|
|
w.logger.Error("Unhandled unix domain socket config %+v %+v", resp.Proxy, cfg.PublicListener)
|
|
|
|
}
|
2019-06-04 14:02:38 +00:00
|
|
|
cfg.PublicListener.LocalServiceAddress = ipaddr.FormatAddressPort(
|
2018-09-27 14:00:51 +00:00
|
|
|
resp.Proxy.LocalServiceAddress, resp.Proxy.LocalServicePort)
|
|
|
|
|
2018-04-25 13:53:30 +00:00
|
|
|
cfg.PublicListener.applyDefaults()
|
|
|
|
|
2018-09-27 14:00:51 +00:00
|
|
|
for _, u := range resp.Proxy.Upstreams {
|
2018-09-12 16:07:47 +00:00
|
|
|
uc := UpstreamConfig(u)
|
|
|
|
uc.applyDefaults()
|
|
|
|
cfg.Upstreams = append(cfg.Upstreams, uc)
|
2018-04-25 13:53:30 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Parsed config OK, deliver it!
|
|
|
|
w.ch <- cfg
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Watch implements ConfigWatcher.
|
|
|
|
func (w *AgentConfigWatcher) Watch() <-chan *Config {
|
2018-04-25 13:53:30 +00:00
|
|
|
return w.ch
|
|
|
|
}
|
|
|
|
|
|
|
|
// Close frees watcher resources and implements io.Closer
|
|
|
|
func (w *AgentConfigWatcher) Close() error {
|
|
|
|
if w.plan != nil {
|
|
|
|
w.plan.Stop()
|
|
|
|
}
|
|
|
|
return nil
|
2018-04-03 18:10:59 +00:00
|
|
|
}
|