mqpublish.go 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202
  1. package functions
  2. import (
  3. "context"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "net"
  8. "os"
  9. "strconv"
  10. "sync"
  11. "time"
  12. "github.com/cloverstd/tcping/ping"
  13. "github.com/gravitl/netmaker/logger"
  14. "github.com/gravitl/netmaker/netclient/auth"
  15. "github.com/gravitl/netmaker/netclient/config"
  16. "github.com/gravitl/netmaker/netclient/ncutils"
  17. "github.com/gravitl/netmaker/tls"
  18. )
  19. // pubNetworks hold the currently publishable networks
  20. var pubNetworks []string
  21. // EMPTY_BROKER_ERR is the error to return if no broker address is provided
  22. var EMPTY_BROKER_ERR = "error: broker address is blank"
  23. // Checkin -- go routine that checks for public or local ip changes, publishes changes
  24. // if there are no updates, simply "pings" the server as a checkin
  25. func Checkin(ctx context.Context, wg *sync.WaitGroup) {
  26. defer wg.Done()
  27. for {
  28. select {
  29. case <-ctx.Done():
  30. logger.Log(0, "checkin routine closed")
  31. return
  32. //delay should be configuraable -> use cfg.Node.NetworkSettings.DefaultCheckInInterval ??
  33. case <-time.After(time.Second * 60):
  34. for _, network := range pubNetworks {
  35. var nodeCfg config.ClientConfig
  36. nodeCfg.Network = network
  37. nodeCfg.ReadConfig()
  38. if nodeCfg.Node.IsStatic != "yes" {
  39. extIP, err := ncutils.GetPublicIP()
  40. if err != nil {
  41. logger.Log(1, "error encountered checking public ip addresses: ", err.Error())
  42. }
  43. if nodeCfg.Node.Endpoint != extIP && extIP != "" {
  44. logger.Log(1, "endpoint has changed from ", nodeCfg.Node.Endpoint, " to ", extIP)
  45. nodeCfg.Node.Endpoint = extIP
  46. if err := PublishNodeUpdate(&nodeCfg); err != nil {
  47. logger.Log(0, "could not publish endpoint change")
  48. }
  49. }
  50. intIP, err := getPrivateAddr()
  51. if err != nil {
  52. logger.Log(1, "error encountered checking private ip addresses: ", err.Error())
  53. }
  54. if nodeCfg.Node.LocalAddress != intIP && intIP != "" {
  55. logger.Log(1, "local Address has changed from ", nodeCfg.Node.LocalAddress, " to ", intIP)
  56. nodeCfg.Node.LocalAddress = intIP
  57. if err := PublishNodeUpdate(&nodeCfg); err != nil {
  58. logger.Log(0, "could not publish local address change")
  59. }
  60. }
  61. _ = UpdateLocalListenPort(&nodeCfg)
  62. } else if nodeCfg.Node.IsLocal == "yes" && nodeCfg.Node.LocalRange != "" {
  63. localIP, err := ncutils.GetLocalIP(nodeCfg.Node.LocalRange)
  64. if err != nil {
  65. logger.Log(1, "error encountered checking local ip addresses: ", err.Error())
  66. }
  67. if nodeCfg.Node.Endpoint != localIP && localIP != "" {
  68. logger.Log(1, "endpoint has changed from "+nodeCfg.Node.Endpoint+" to ", localIP)
  69. nodeCfg.Node.Endpoint = localIP
  70. if err := PublishNodeUpdate(&nodeCfg); err != nil {
  71. logger.Log(0, "could not publish localip change")
  72. }
  73. }
  74. }
  75. Hello(&nodeCfg)
  76. checkCertExpiry(&nodeCfg)
  77. }
  78. }
  79. }
  80. }
  81. // PublishNodeUpdates -- saves node and pushes changes to broker
  82. func PublishNodeUpdate(nodeCfg *config.ClientConfig) error {
  83. if err := config.Write(nodeCfg, nodeCfg.Network); err != nil {
  84. return err
  85. }
  86. data, err := json.Marshal(nodeCfg.Node)
  87. if err != nil {
  88. return err
  89. }
  90. if err = publish(nodeCfg, fmt.Sprintf("update/%s", nodeCfg.Node.ID), data, 1); err != nil {
  91. return err
  92. }
  93. logger.Log(0, "sent a node update to server for node", nodeCfg.Node.Name, ", ", nodeCfg.Node.ID)
  94. return nil
  95. }
  96. // Hello -- ping the broker to let server know node it's alive and well
  97. func Hello(nodeCfg *config.ClientConfig) {
  98. if err := publish(nodeCfg, fmt.Sprintf("ping/%s", nodeCfg.Node.ID), []byte(ncutils.Version), 0); err != nil {
  99. logger.Log(0, fmt.Sprintf("error publishing ping, %v", err))
  100. logger.Log(0, "running pull on "+nodeCfg.Node.Network+" to reconnect")
  101. _, err := Pull(nodeCfg.Node.Network, true)
  102. if err != nil {
  103. logger.Log(0, "could not run pull on "+nodeCfg.Node.Network+", error: "+err.Error())
  104. }
  105. }
  106. logger.Log(3, "checkin for", nodeCfg.Network, "complete")
  107. }
  108. // node cfg is required in order to fetch the traffic keys of that node for encryption
  109. func publish(nodeCfg *config.ClientConfig, dest string, msg []byte, qos byte) error {
  110. // setup the keys
  111. trafficPrivKey, err := auth.RetrieveTrafficKey(nodeCfg.Node.Network)
  112. if err != nil {
  113. return err
  114. }
  115. serverPubKey, err := ncutils.ConvertBytesToKey(nodeCfg.Node.TrafficKeys.Server)
  116. if err != nil {
  117. return err
  118. }
  119. client, err := setupMQTT(nodeCfg, true)
  120. if err != nil {
  121. return fmt.Errorf("mq setup error %w", err)
  122. }
  123. defer client.Disconnect(250)
  124. encrypted, err := ncutils.Chunk(msg, serverPubKey, trafficPrivKey)
  125. if err != nil {
  126. return err
  127. }
  128. if token := client.Publish(dest, qos, false, encrypted); !token.WaitTimeout(30*time.Second) || token.Error() != nil {
  129. logger.Log(0, "could not connect to broker at "+nodeCfg.Server.Server+":8883")
  130. var err error
  131. if token.Error() == nil {
  132. err = errors.New("connection timeout")
  133. } else {
  134. err = token.Error()
  135. }
  136. if err != nil {
  137. return err
  138. }
  139. }
  140. return nil
  141. }
  142. func checkCertExpiry(cfg *config.ClientConfig) error {
  143. cert, err := tls.ReadCert(ncutils.GetNetclientServerPath(cfg.Server.Server) + ncutils.GetSeparator() + "client.pem")
  144. //if cert doesn't exist or will expire within 10 days
  145. if errors.Is(err, os.ErrNotExist) || cert.NotAfter.Before(time.Now().Add(time.Hour*24*10)) {
  146. key, err := tls.ReadKey(ncutils.GetNetclientPath() + ncutils.GetSeparator() + "client.key")
  147. if err != nil {
  148. return err
  149. }
  150. return RegisterWithServer(key, cfg)
  151. }
  152. if err != nil {
  153. return err
  154. }
  155. return nil
  156. }
  157. func checkBroker(broker string, port string) error {
  158. if broker == "" {
  159. return errors.New(EMPTY_BROKER_ERR)
  160. }
  161. _, err := net.LookupIP(broker)
  162. if err != nil {
  163. return errors.New("nslookup failed for broker ... check dns records")
  164. }
  165. pinger := ping.NewTCPing()
  166. intPort, err := strconv.Atoi(port)
  167. if err != nil {
  168. logger.Log(1, "error converting port to int: "+err.Error())
  169. }
  170. if intPort == 0 {
  171. logger.Log(1, "port unset in config. Using default of 8883, which may be incorrect.")
  172. intPort = 8883
  173. }
  174. pinger.SetTarget(&ping.Target{
  175. Protocol: ping.TCP,
  176. Host: broker,
  177. Port: intPort,
  178. Counter: 3,
  179. Interval: 1 * time.Second,
  180. Timeout: 2 * time.Second,
  181. })
  182. pingerDone := pinger.Start()
  183. <-pingerDone
  184. if pinger.Result().SuccessCounter == 0 {
  185. return errors.New("unable to connect to broker port ... check netmaker server and firewalls")
  186. }
  187. return nil
  188. }