2023-03-28 19:39:22 +01:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
2023-08-11 09:12:13 -04:00
|
|
|
// SPDX-License-Identifier: BUSL-1.1
|
2023-03-28 19:39:22 +01:00
|
|
|
|
2022-07-13 16:33:48 +01:00
|
|
|
package external
|
2022-03-22 12:40:24 +00:00
|
|
|
|
|
|
|
import (
|
2024-01-31 12:05:47 -08:00
|
|
|
"context"
|
|
|
|
"fmt"
|
|
|
|
"strings"
|
2022-08-24 18:31:38 +02:00
|
|
|
"time"
|
|
|
|
|
2022-10-11 17:00:32 -05:00
|
|
|
"github.com/armon/go-metrics"
|
2022-03-22 12:40:24 +00:00
|
|
|
middleware "github.com/grpc-ecosystem/go-grpc-middleware"
|
|
|
|
recovery "github.com/grpc-ecosystem/go-grpc-middleware/recovery"
|
2024-01-31 12:05:47 -08:00
|
|
|
"github.com/hashi-derek/grpc-proxy/proxy"
|
|
|
|
"github.com/hashicorp/go-hclog"
|
2022-03-22 12:40:24 +00:00
|
|
|
"google.golang.org/grpc"
|
2024-01-31 12:05:47 -08:00
|
|
|
"google.golang.org/grpc/codes"
|
2022-10-28 15:34:41 -05:00
|
|
|
"google.golang.org/grpc/credentials"
|
2022-07-18 16:12:03 -07:00
|
|
|
"google.golang.org/grpc/keepalive"
|
2024-01-31 12:05:47 -08:00
|
|
|
"google.golang.org/grpc/metadata"
|
|
|
|
"google.golang.org/grpc/status"
|
2022-03-22 12:40:24 +00:00
|
|
|
|
2022-12-13 13:09:55 -07:00
|
|
|
"github.com/hashicorp/consul/agent/consul/rate"
|
2022-07-13 16:33:48 +01:00
|
|
|
agentmiddleware "github.com/hashicorp/consul/agent/grpc-middleware"
|
2022-10-28 15:34:41 -05:00
|
|
|
"github.com/hashicorp/consul/tlsutil"
|
2022-03-22 12:40:24 +00:00
|
|
|
)
|
|
|
|
|
2024-02-02 12:48:45 -08:00
|
|
|
const FORWARD_SERVICE_NAME_PREFIX = "/hashicorp.consul."
|
2024-01-31 12:05:47 -08:00
|
|
|
|
2022-10-11 17:00:32 -05:00
|
|
|
var (
|
|
|
|
metricsLabels = []metrics.Label{{
|
|
|
|
Name: "server_type",
|
|
|
|
Value: "external",
|
|
|
|
}}
|
|
|
|
)
|
|
|
|
|
2022-07-13 16:33:48 +01:00
|
|
|
// NewServer constructs a gRPC server for the external gRPC port, to which
|
2022-03-22 12:40:24 +00:00
|
|
|
// handlers can be registered.
|
2023-10-24 08:05:31 -05:00
|
|
|
func NewServer(
|
2024-01-31 12:05:47 -08:00
|
|
|
logger hclog.Logger,
|
2023-10-24 08:05:31 -05:00
|
|
|
metricsObj *metrics.Metrics,
|
|
|
|
tls *tlsutil.Configurator,
|
|
|
|
limiter rate.RequestLimitsHandler,
|
|
|
|
keepaliveParams keepalive.ServerParameters,
|
2024-01-31 12:05:47 -08:00
|
|
|
serverConn *grpc.ClientConn,
|
2023-10-24 08:05:31 -05:00
|
|
|
) *grpc.Server {
|
2022-10-11 17:00:32 -05:00
|
|
|
if metricsObj == nil {
|
|
|
|
metricsObj = metrics.Default()
|
|
|
|
}
|
2022-03-22 12:40:24 +00:00
|
|
|
recoveryOpts := agentmiddleware.PanicHandlerMiddlewareOpts(logger)
|
|
|
|
|
2022-10-28 15:34:41 -05:00
|
|
|
unaryInterceptors := []grpc.UnaryServerInterceptor{
|
|
|
|
// Add middlware interceptors to recover in case of panics.
|
|
|
|
recovery.UnaryServerInterceptor(recoveryOpts...),
|
|
|
|
}
|
|
|
|
streamInterceptors := []grpc.StreamServerInterceptor{
|
|
|
|
// Add middlware interceptors to recover in case of panics.
|
|
|
|
recovery.StreamServerInterceptor(recoveryOpts...),
|
|
|
|
agentmiddleware.NewActiveStreamCounter(metricsObj, metricsLabels).Intercept,
|
|
|
|
}
|
|
|
|
|
|
|
|
if tls != nil {
|
|
|
|
// Attach TLS middleware if TLS is provided.
|
|
|
|
authInterceptor := agentmiddleware.AuthInterceptor{TLS: tls, Logger: logger}
|
|
|
|
unaryInterceptors = append(unaryInterceptors, authInterceptor.InterceptUnary)
|
|
|
|
streamInterceptors = append(streamInterceptors, authInterceptor.InterceptStream)
|
|
|
|
}
|
2022-03-22 12:40:24 +00:00
|
|
|
opts := []grpc.ServerOption{
|
|
|
|
grpc.MaxConcurrentStreams(2048),
|
2022-10-13 13:46:51 -07:00
|
|
|
grpc.MaxRecvMsgSize(50 * 1024 * 1024),
|
2023-01-04 16:07:02 +00:00
|
|
|
grpc.InTapHandle(agentmiddleware.ServerRateLimiterMiddleware(limiter, agentmiddleware.NewPanicHandler(logger), logger)),
|
2022-10-11 17:00:32 -05:00
|
|
|
grpc.StatsHandler(agentmiddleware.NewStatsHandler(metricsObj, metricsLabels)),
|
2022-10-28 15:34:41 -05:00
|
|
|
middleware.WithUnaryServerChain(unaryInterceptors...),
|
|
|
|
middleware.WithStreamServerChain(streamInterceptors...),
|
2023-10-24 08:05:31 -05:00
|
|
|
grpc.KeepaliveParams(keepaliveParams),
|
2022-07-18 16:12:03 -07:00
|
|
|
grpc.KeepaliveEnforcementPolicy(keepalive.EnforcementPolicy{
|
|
|
|
// This must be less than the keealive.ClientParameters Time setting, otherwise
|
|
|
|
// the server will disconnect the client for sending too many keepalive pings.
|
|
|
|
// Currently the client param is set to 30s.
|
|
|
|
MinTime: 15 * time.Second,
|
|
|
|
}),
|
2022-03-22 12:40:24 +00:00
|
|
|
}
|
2022-10-28 15:34:41 -05:00
|
|
|
|
2024-01-31 12:05:47 -08:00
|
|
|
// forward FORWARD_SERVICE_NAME_PREFIX services from client agent to server agent
|
|
|
|
if serverConn != nil {
|
|
|
|
opts = append(opts, grpc.UnknownServiceHandler(proxy.TransparentHandler(makeDirector(serverConn, logger))))
|
|
|
|
}
|
|
|
|
|
2022-10-28 15:34:41 -05:00
|
|
|
if tls != nil {
|
|
|
|
// Attach TLS credentials, if provided.
|
|
|
|
tlsCreds := agentmiddleware.NewOptionalTransportCredentials(
|
|
|
|
credentials.NewTLS(tls.IncomingGRPCConfig()),
|
|
|
|
logger)
|
|
|
|
opts = append(opts, grpc.Creds(tlsCreds))
|
|
|
|
}
|
2022-03-22 12:40:24 +00:00
|
|
|
return grpc.NewServer(opts...)
|
|
|
|
}
|
2024-01-31 12:05:47 -08:00
|
|
|
|
|
|
|
func makeDirector(serverConn *grpc.ClientConn, logger hclog.Logger) func(ctx context.Context, fullMethodName string) (context.Context, *grpc.ClientConn, error) {
|
|
|
|
return func(ctx context.Context, fullMethodName string) (context.Context, *grpc.ClientConn, error) {
|
|
|
|
var mdCopy metadata.MD
|
|
|
|
md, ok := metadata.FromIncomingContext(ctx)
|
|
|
|
if !ok {
|
|
|
|
mdCopy = metadata.MD{}
|
|
|
|
} else {
|
|
|
|
mdCopy = md.Copy()
|
|
|
|
}
|
|
|
|
outCtx := metadata.NewOutgoingContext(ctx, mdCopy)
|
|
|
|
|
|
|
|
logger.Debug("forwarding the request to the consul server", "method", fullMethodName)
|
|
|
|
// throw unimplemented error if the method is not meant to be forwarded
|
|
|
|
if !strings.HasPrefix(fullMethodName, FORWARD_SERVICE_NAME_PREFIX) {
|
|
|
|
return outCtx, nil, status.Errorf(codes.Unimplemented, fmt.Sprintf("Unknown method %s", fullMethodName))
|
|
|
|
}
|
|
|
|
|
|
|
|
return outCtx, serverConn, nil
|
|
|
|
}
|
|
|
|
}
|