| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 1 | package main |
| 2 | |
| 3 | import ( |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 4 | "embed" |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 5 | "encoding/base64" |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 6 | "encoding/json" |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 7 | "flag" |
| 8 | "fmt" |
| 9 | "html/template" |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 10 | "io/ioutil" |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 11 | "log" |
| 12 | "net/http" |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 13 | "time" |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 14 | |
| 15 | "github.com/gorilla/mux" |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 16 | "sigs.k8s.io/yaml" |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 17 | |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 18 | "k8s.io/client-go/kubernetes" |
| 19 | "k8s.io/client-go/tools/clientcmd" |
| 20 | |
| giolekva | c6859b0 | 2021-12-09 18:40:51 +0400 | [diff] [blame] | 21 | clientset "github.com/giolekva/pcloud/core/nebula/controller/generated/clientset/versioned" |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 22 | ) |
| 23 | |
| 24 | var port = flag.Int("port", 8080, "Port to listen on.") |
| 25 | var kubeConfig = flag.String("kubeconfig", "", "Path to a kubeconfig. Only required if out-of-cluster.") |
| 26 | var masterURL = flag.String("master", "", "The address of the Kubernetes API server. Overrides any value in kubeconfig. Only required if out-of-cluster.") |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 27 | var namespace = flag.String("namespace", "", "Namespace where Nebula CA and Node secrets are stored.") |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 28 | var caName = flag.String("ca-name", "", "Name of the Nebula CA.") |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 29 | var configTmpl = flag.String("config-tmpl", "", "Path to the lighthouse configuration template file.") |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 30 | |
| 31 | //go:embed templates/* |
| 32 | var tmpls embed.FS |
| 33 | |
| 34 | type Templates struct { |
| 35 | Index *template.Template |
| 36 | } |
| 37 | |
| 38 | func ParseTemplates(fs embed.FS) (*Templates, error) { |
| 39 | index, err := template.ParseFS(fs, "templates/index.html") |
| 40 | if err != nil { |
| 41 | return nil, err |
| 42 | } |
| 43 | return &Templates{index}, nil |
| 44 | } |
| 45 | |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 46 | type Handler struct { |
| 47 | mgr Manager |
| 48 | tmpls *Templates |
| 49 | } |
| 50 | |
| 51 | func (h *Handler) handleIndex(w http.ResponseWriter, r *http.Request) { |
| 52 | cas, err := h.mgr.ListAll() |
| 53 | if err != nil { |
| 54 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 55 | return |
| 56 | } |
| 57 | if err := h.tmpls.Index.Execute(w, cas); err != nil { |
| 58 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 59 | } |
| 60 | } |
| 61 | |
| 62 | func (h *Handler) handleNode(w http.ResponseWriter, r *http.Request) { |
| 63 | vars := mux.Vars(r) |
| 64 | namespace := vars["namespace"] |
| 65 | name := vars["name"] |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 66 | qr, err := h.mgr.GetNodeCertQR(namespace, name) |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 67 | if err != nil { |
| 68 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 69 | } |
| 70 | w.Header().Set("Content-Type", "img/png") |
| 71 | w.Write(qr) |
| 72 | } |
| 73 | |
| 74 | func (h *Handler) handleCA(w http.ResponseWriter, r *http.Request) { |
| 75 | vars := mux.Vars(r) |
| 76 | namespace := vars["namespace"] |
| 77 | name := vars["name"] |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 78 | qr, err := h.mgr.GetCACertQR(namespace, name) |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 79 | if err != nil { |
| 80 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 81 | } |
| 82 | w.Header().Set("Content-Type", "img/png") |
| 83 | w.Write(qr) |
| 84 | } |
| 85 | |
| 86 | func (h *Handler) handleSignNode(w http.ResponseWriter, r *http.Request) { |
| 87 | if err := r.ParseForm(); err != nil { |
| 88 | http.Error(w, err.Error(), http.StatusBadRequest) |
| 89 | return |
| 90 | } |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 91 | _, _, err := h.mgr.CreateNode( |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 92 | r.FormValue("node-namespace"), |
| 93 | r.FormValue("node-name"), |
| 94 | r.FormValue("ca-namespace"), |
| 95 | r.FormValue("ca-name"), |
| 96 | r.FormValue("ip-cidr"), |
| 97 | r.FormValue("pub-key"), |
| 98 | ) |
| 99 | if err != nil { |
| 100 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 101 | return |
| 102 | } |
| 103 | http.Redirect(w, r, "/", http.StatusSeeOther) |
| 104 | } |
| 105 | |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 106 | func (h *Handler) getNextIP(w http.ResponseWriter, r *http.Request) { |
| 107 | ip, err := h.mgr.getNextIP() |
| 108 | if err != nil { |
| 109 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 110 | return |
| 111 | } |
| 112 | fmt.Fprint(w, ip) |
| 113 | } |
| 114 | |
| 115 | type signReq struct { |
| 116 | Message []byte `json:"message"` |
| 117 | } |
| 118 | |
| 119 | type signResp struct { |
| 120 | Signature []byte `json:"signature"` |
| 121 | } |
| 122 | |
| 123 | func (h *Handler) sign(w http.ResponseWriter, r *http.Request) { |
| 124 | var req signReq |
| 125 | if err := json.NewDecoder(r.Body).Decode(&req); err != nil { |
| 126 | http.Error(w, err.Error(), http.StatusBadRequest) |
| 127 | return |
| 128 | } |
| 129 | signature, err := h.mgr.Sign(req.Message) |
| 130 | if err != nil { |
| 131 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 132 | return |
| 133 | } |
| 134 | w.Header().Set("Content-Type", "application/json") |
| 135 | resp := signResp{ |
| 136 | signature, |
| 137 | } |
| 138 | if err := json.NewEncoder(w).Encode(resp); err != nil { |
| 139 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 140 | return |
| 141 | } |
| 142 | } |
| 143 | |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 144 | type joinReq struct { |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 145 | Message []byte `json:"message"` |
| 146 | Signature []byte `json:"signature"` |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 147 | Name string `json:"name"` |
| 148 | PublicKey []byte `json:"public_key"` |
| 149 | IPCidr string `json:"ip_cidr"` |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 150 | } |
| 151 | |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 152 | type joinResp struct { |
| 153 | } |
| 154 | |
| 155 | func (h *Handler) join(w http.ResponseWriter, r *http.Request) { |
| 156 | var req joinReq |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 157 | if err := json.NewDecoder(r.Body).Decode(&req); err != nil { |
| 158 | http.Error(w, err.Error(), http.StatusBadRequest) |
| 159 | return |
| 160 | } |
| 161 | valid, err := h.mgr.VerifySignature(req.Message, req.Signature) |
| 162 | if err != nil { |
| 163 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 164 | return |
| 165 | } |
| 166 | if !valid { |
| 167 | http.Error(w, "Signature could not be verified", http.StatusBadRequest) |
| 168 | return |
| 169 | } |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 170 | _, _, err = h.mgr.CreateNode( |
| 171 | *namespace, |
| 172 | req.Name, |
| 173 | *namespace, |
| 174 | *caName, |
| 175 | req.IPCidr, |
| 176 | string(req.PublicKey), |
| 177 | ) |
| 178 | if err != nil { |
| 179 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 180 | return |
| 181 | } |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 182 | for { |
| 183 | time.Sleep(1 * time.Second) |
| 184 | cfg, err := h.mgr.GetNodeConfig(*namespace, req.Name) |
| 185 | if err != nil { |
| 186 | fmt.Println(err.Error()) |
| 187 | continue |
| 188 | } |
| 189 | cfgBytes, err := yaml.Marshal(cfg) |
| 190 | if err != nil { |
| 191 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 192 | return |
| 193 | } |
| 194 | cfgB64 := base64.StdEncoding.EncodeToString(cfgBytes) |
| 195 | if _, err := fmt.Fprint(w, cfgB64); err != nil { |
| 196 | http.Error(w, err.Error(), http.StatusInternalServerError) |
| 197 | return |
| 198 | } |
| 199 | break |
| 200 | } |
| 201 | } |
| 202 | |
| 203 | func loadConfigTemplate(path string) (map[string]interface{}, error) { |
| 204 | tmpl, err := ioutil.ReadFile(path) |
| 205 | if err != nil { |
| 206 | return nil, err |
| 207 | } |
| 208 | var m map[string]interface{} |
| 209 | if err := yaml.Unmarshal(tmpl, &m); err != nil { |
| 210 | return nil, err |
| 211 | } |
| 212 | return m, nil |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 213 | } |
| 214 | |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 215 | func main() { |
| 216 | flag.Parse() |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 217 | cfgTmpl, err := loadConfigTemplate(*configTmpl) |
| 218 | if err != nil { |
| 219 | panic(err) |
| 220 | } |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 221 | cfg, err := clientcmd.BuildConfigFromFlags(*masterURL, *kubeConfig) |
| 222 | if err != nil { |
| 223 | panic(err) |
| 224 | } |
| 225 | kubeClient, err := kubernetes.NewForConfig(cfg) |
| 226 | if err != nil { |
| 227 | panic(err) |
| 228 | } |
| 229 | nebulaClient := clientset.NewForConfigOrDie(cfg) |
| 230 | t, err := ParseTemplates(tmpls) |
| 231 | if err != nil { |
| 232 | log.Fatal(err) |
| 233 | } |
| 234 | mgr := Manager{ |
| 235 | kubeClient: kubeClient, |
| 236 | nebulaClient: nebulaClient, |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 237 | namespace: *namespace, |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 238 | caName: *caName, |
| giolekva | cc3ebcb | 2021-12-17 10:52:17 +0400 | [diff] [blame] | 239 | cfgTmpl: cfgTmpl, |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 240 | } |
| 241 | handler := Handler{ |
| 242 | mgr: mgr, |
| 243 | tmpls: t, |
| 244 | } |
| 245 | r := mux.NewRouter() |
| giolekva | b64297c | 2021-12-13 14:36:32 +0400 | [diff] [blame] | 246 | r.HandleFunc("/api/ip", handler.getNextIP) |
| 247 | r.HandleFunc("/api/sign", handler.sign) |
| giolekva | f58a769 | 2021-12-15 18:05:39 +0400 | [diff] [blame] | 248 | r.HandleFunc("/api/join", handler.join) |
| giolekva | 4b2934b | 2021-10-08 19:37:12 +0400 | [diff] [blame] | 249 | r.HandleFunc("/node/{namespace:[a-zA-z0-9-]+}/{name:[a-zA-z0-9-]+}", handler.handleNode) |
| 250 | r.HandleFunc("/ca/{namespace:[a-zA-z0-9-]+}/{name:[a-zA-z0-9-]+}", handler.handleCA) |
| 251 | r.HandleFunc("/sign-node", handler.handleSignNode) |
| 252 | r.HandleFunc("/", handler.handleIndex) |
| 253 | http.Handle("/", r) |
| 254 | fmt.Printf("Starting HTTP server on port: %d\n", *port) |
| 255 | log.Fatal(http.ListenAndServe(fmt.Sprintf(":%d", *port), nil)) |
| 256 | } |