2023-03-28 18:39:22 +00:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
2023-08-11 13:12:13 +00:00
|
|
|
// SPDX-License-Identifier: BUSL-1.1
|
2023-03-28 18:39:22 +00:00
|
|
|
|
2022-05-27 11:38:52 +00:00
|
|
|
package local
|
|
|
|
|
|
|
|
import (
|
2023-01-18 18:33:21 +00:00
|
|
|
"github.com/hashicorp/consul/agent/grpc-external/limiter"
|
2022-05-27 11:38:52 +00:00
|
|
|
"github.com/hashicorp/consul/agent/proxycfg"
|
2023-08-24 22:44:14 +00:00
|
|
|
"github.com/hashicorp/consul/agent/proxycfg-sources/catalog"
|
2022-05-27 11:38:52 +00:00
|
|
|
structs "github.com/hashicorp/consul/agent/structs"
|
2023-08-29 15:15:34 +00:00
|
|
|
proxysnapshot "github.com/hashicorp/consul/internal/mesh/proxy-snapshot"
|
2023-08-24 22:44:14 +00:00
|
|
|
"github.com/hashicorp/consul/proto-public/pbresource"
|
2022-05-27 11:38:52 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
// ConfigSource wraps a proxycfg.Manager to create watches on services
|
|
|
|
// local to the agent (pre-registered by Sync).
|
|
|
|
type ConfigSource struct {
|
|
|
|
manager ConfigManager
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewConfigSource builds a ConfigSource with the given proxycfg.Manager.
|
|
|
|
func NewConfigSource(cfgMgr ConfigManager) *ConfigSource {
|
|
|
|
return &ConfigSource{cfgMgr}
|
|
|
|
}
|
|
|
|
|
2024-03-15 18:57:11 +00:00
|
|
|
func (m *ConfigSource) Watch(proxyID *pbresource.ID, nodeName string, _ string) (
|
|
|
|
<-chan proxysnapshot.ProxySnapshot,
|
|
|
|
limiter.SessionTerminatedChan,
|
|
|
|
proxycfg.SrcTerminatedChan,
|
|
|
|
proxysnapshot.CancelFunc,
|
|
|
|
error,
|
|
|
|
) {
|
2023-08-24 22:44:14 +00:00
|
|
|
serviceID := structs.NewServiceID(proxyID.Name, catalog.GetEnterpriseMetaFromResourceID(proxyID))
|
2022-05-27 11:38:52 +00:00
|
|
|
watchCh, cancelWatch := m.manager.Watch(proxycfg.ProxyID{
|
|
|
|
ServiceID: serviceID,
|
|
|
|
NodeName: nodeName,
|
|
|
|
|
|
|
|
// Note: we *intentionally* don't set Token here. All watches on local
|
|
|
|
// services use the same ACL token, regardless of whatever token is
|
|
|
|
// presented in the xDS stream (the token presented to the xDS server
|
|
|
|
// is checked before the watch is created).
|
|
|
|
Token: "",
|
|
|
|
})
|
2024-03-15 18:57:11 +00:00
|
|
|
return watchCh, nil, nil, cancelWatch, nil
|
2022-05-27 11:38:52 +00:00
|
|
|
}
|