egress.go 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338
  1. package logic
  2. import (
  3. "context"
  4. "encoding/json"
  5. "errors"
  6. "maps"
  7. "strings"
  8. "github.com/gravitl/netmaker/db"
  9. "github.com/gravitl/netmaker/models"
  10. "github.com/gravitl/netmaker/schema"
  11. "github.com/gravitl/netmaker/servercfg"
  12. )
  13. func ValidateEgressReq(e *schema.Egress) error {
  14. if e.Network == "" {
  15. return errors.New("network id is empty")
  16. }
  17. _, err := GetNetwork(e.Network)
  18. if err != nil {
  19. return errors.New("failed to get network " + err.Error())
  20. }
  21. if !servercfg.IsPro && len(e.Nodes) > 1 {
  22. return errors.New("can only set one routing node on CE")
  23. }
  24. if len(e.Nodes) > 0 {
  25. for k := range e.Nodes {
  26. _, err := GetNodeByID(k)
  27. if err != nil {
  28. return errors.New("invalid routing node " + err.Error())
  29. }
  30. }
  31. }
  32. return nil
  33. }
  34. func DoesUserHaveAccessToEgress(user *models.User, e *schema.Egress, acls []models.Acl) bool {
  35. if !e.Status {
  36. return false
  37. }
  38. for _, acl := range acls {
  39. if !acl.Enabled {
  40. continue
  41. }
  42. dstTags := ConvAclTagToValueMap(acl.Dst)
  43. _, all := dstTags["*"]
  44. if _, ok := dstTags[e.ID]; ok || all {
  45. // get all src tags
  46. for _, srcAcl := range acl.Src {
  47. if srcAcl.ID == models.UserAclID && srcAcl.Value == user.UserName {
  48. return true
  49. } else if srcAcl.ID == models.UserGroupAclID {
  50. // fetch all users in the group
  51. if _, ok := user.UserGroups[models.UserGroupID(srcAcl.Value)]; ok {
  52. return true
  53. }
  54. }
  55. }
  56. }
  57. }
  58. return false
  59. }
  60. func DoesNodeHaveAccessToEgress(node *models.Node, e *schema.Egress, acls []models.Acl) bool {
  61. nodeTags := maps.Clone(node.Tags)
  62. nodeTags[models.TagID(node.ID.String())] = struct{}{}
  63. nodeTags[models.TagID("*")] = struct{}{}
  64. for _, acl := range acls {
  65. if !acl.Enabled {
  66. continue
  67. }
  68. srcVal := ConvAclTagToValueMap(acl.Src)
  69. for _, dstI := range acl.Dst {
  70. if (dstI.ID == models.EgressID && dstI.Value == e.ID) || (dstI.ID == models.NodeTagID && dstI.Value == "*") {
  71. if dstI.ID == models.EgressID {
  72. e := schema.Egress{ID: dstI.Value}
  73. err := e.Get(db.WithContext(context.TODO()))
  74. if err != nil {
  75. continue
  76. }
  77. }
  78. if node.IsStatic {
  79. if _, ok := srcVal[node.StaticNode.ClientID]; ok {
  80. return true
  81. }
  82. } else {
  83. if _, ok := srcVal[node.ID.String()]; ok {
  84. return true
  85. }
  86. }
  87. for tagID := range nodeTags {
  88. if _, ok := srcVal[tagID.String()]; ok {
  89. return true
  90. }
  91. }
  92. }
  93. }
  94. }
  95. return false
  96. }
  97. func AddEgressInfoToPeerByAccess(node, targetNode *models.Node, eli []schema.Egress, acls []models.Acl, isDefaultPolicyActive bool) {
  98. req := models.EgressGatewayRequest{
  99. NodeID: targetNode.ID.String(),
  100. NetID: targetNode.Network,
  101. NatEnabled: "yes",
  102. }
  103. for _, e := range eli {
  104. if !e.Status || e.Network != targetNode.Network {
  105. continue
  106. }
  107. if !isDefaultPolicyActive {
  108. if !DoesNodeHaveAccessToEgress(node, &e, acls) {
  109. if node.IsRelayed && node.RelayedBy == targetNode.ID.String() {
  110. if !DoesNodeHaveAccessToEgress(targetNode, &e, acls) {
  111. continue
  112. }
  113. } else {
  114. continue
  115. }
  116. }
  117. }
  118. if metric, ok := e.Nodes[targetNode.ID.String()]; ok {
  119. m64, err := metric.(json.Number).Int64()
  120. if err != nil {
  121. m64 = 256
  122. }
  123. m := uint32(m64)
  124. if e.Range != "" {
  125. req.Ranges = append(req.Ranges, e.Range)
  126. } else {
  127. req.Ranges = append(req.Ranges, e.DomainAns...)
  128. }
  129. if e.Range != "" {
  130. req.Ranges = append(req.Ranges, e.Range)
  131. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  132. Network: e.Range,
  133. Nat: e.Nat,
  134. RouteMetric: m,
  135. })
  136. }
  137. if e.Domain != "" && len(e.DomainAns) > 0 {
  138. req.Ranges = append(req.Ranges, e.DomainAns...)
  139. for _, domainAnsI := range e.DomainAns {
  140. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  141. Network: domainAnsI,
  142. Nat: e.Nat,
  143. RouteMetric: m,
  144. })
  145. }
  146. }
  147. }
  148. }
  149. if targetNode.Mutex != nil {
  150. targetNode.Mutex.Lock()
  151. }
  152. if len(req.Ranges) > 0 {
  153. targetNode.EgressDetails.IsEgressGateway = true
  154. targetNode.EgressDetails.EgressGatewayRanges = req.Ranges
  155. targetNode.EgressDetails.EgressGatewayRequest = req
  156. } else {
  157. targetNode.EgressDetails = models.EgressDetails{}
  158. }
  159. if targetNode.Mutex != nil {
  160. targetNode.Mutex.Unlock()
  161. }
  162. }
  163. func GetEgressDomainsByAccess(user *models.User, network models.NetworkID) (domains []string) {
  164. acls, _ := ListAclsByNetwork(network)
  165. eli, _ := (&schema.Egress{Network: network.String()}).ListByNetwork(db.WithContext(context.TODO()))
  166. defaultDevicePolicy, _ := GetDefaultPolicy(network, models.UserPolicy)
  167. isDefaultPolicyActive := defaultDevicePolicy.Enabled
  168. for _, e := range eli {
  169. if !e.Status || e.Network != network.String() {
  170. continue
  171. }
  172. if !isDefaultPolicyActive {
  173. if !DoesUserHaveAccessToEgress(user, &e, acls) {
  174. continue
  175. }
  176. }
  177. if e.Domain != "" && len(e.DomainAns) > 0 {
  178. domains = append(domains, BaseDomain(e.Domain))
  179. }
  180. }
  181. return
  182. }
  183. func GetNodeEgressInfo(targetNode *models.Node, eli []schema.Egress, acls []models.Acl) {
  184. req := models.EgressGatewayRequest{
  185. NodeID: targetNode.ID.String(),
  186. NetID: targetNode.Network,
  187. NatEnabled: "yes",
  188. }
  189. for _, e := range eli {
  190. if !e.Status || e.Network != targetNode.Network {
  191. continue
  192. }
  193. if metric, ok := e.Nodes[targetNode.ID.String()]; ok {
  194. m64, err := metric.(json.Number).Int64()
  195. if err != nil {
  196. m64 = 256
  197. }
  198. m := uint32(m64)
  199. if e.Range != "" {
  200. req.Ranges = append(req.Ranges, e.Range)
  201. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  202. Network: e.Range,
  203. Nat: e.Nat,
  204. RouteMetric: m,
  205. })
  206. }
  207. if e.Domain != "" && len(e.DomainAns) > 0 {
  208. req.Ranges = append(req.Ranges, e.DomainAns...)
  209. for _, domainAnsI := range e.DomainAns {
  210. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  211. Network: domainAnsI,
  212. Nat: e.Nat,
  213. RouteMetric: m,
  214. })
  215. }
  216. }
  217. }
  218. }
  219. if targetNode.Mutex != nil {
  220. targetNode.Mutex.Lock()
  221. }
  222. if len(req.Ranges) > 0 {
  223. targetNode.EgressDetails.IsEgressGateway = true
  224. targetNode.EgressDetails.EgressGatewayRanges = req.Ranges
  225. targetNode.EgressDetails.EgressGatewayRequest = req
  226. } else {
  227. targetNode.EgressDetails = models.EgressDetails{}
  228. }
  229. if targetNode.Mutex != nil {
  230. targetNode.Mutex.Unlock()
  231. }
  232. }
  233. func RemoveNodeFromEgress(node models.Node) {
  234. egs, _ := (&schema.Egress{
  235. Network: node.Network,
  236. }).ListByNetwork(db.WithContext(context.TODO()))
  237. for _, egI := range egs {
  238. if _, ok := egI.Nodes[node.ID.String()]; ok {
  239. delete(egI.Nodes, node.ID.String())
  240. egI.Update(db.WithContext(context.TODO()))
  241. }
  242. }
  243. }
  244. func GetEgressRanges(netID models.NetworkID) (map[string][]string, map[string]struct{}, error) {
  245. resultMap := make(map[string]struct{})
  246. nodeEgressMap := make(map[string][]string)
  247. networkNodes, err := GetNetworkNodes(netID.String())
  248. if err != nil {
  249. return nil, nil, err
  250. }
  251. for _, currentNode := range networkNodes {
  252. if currentNode.Network != netID.String() {
  253. continue
  254. }
  255. if currentNode.EgressDetails.IsEgressGateway { // add the egress gateway range(s) to the result
  256. if len(currentNode.EgressDetails.EgressGatewayRanges) > 0 {
  257. nodeEgressMap[currentNode.ID.String()] = currentNode.EgressDetails.EgressGatewayRanges
  258. for _, egressRangeI := range currentNode.EgressDetails.EgressGatewayRanges {
  259. resultMap[egressRangeI] = struct{}{}
  260. }
  261. }
  262. }
  263. }
  264. extclients, _ := GetNetworkExtClients(netID.String())
  265. for _, extclient := range extclients {
  266. if len(extclient.ExtraAllowedIPs) > 0 {
  267. nodeEgressMap[extclient.ClientID] = extclient.ExtraAllowedIPs
  268. for _, extraAllowedIP := range extclient.ExtraAllowedIPs {
  269. resultMap[extraAllowedIP] = struct{}{}
  270. }
  271. }
  272. }
  273. return nodeEgressMap, resultMap, nil
  274. }
  275. func ListAllByRoutingNodeWithDomain(egs []schema.Egress, nodeID string) (egWithDomain []models.EgressDomain) {
  276. node, err := GetNodeByID(nodeID)
  277. if err != nil {
  278. return
  279. }
  280. host, err := GetHost(node.HostID.String())
  281. if err != nil {
  282. return
  283. }
  284. for _, egI := range egs {
  285. if !egI.Status || egI.Domain == "" {
  286. continue
  287. }
  288. if _, ok := egI.Nodes[nodeID]; ok {
  289. egWithDomain = append(egWithDomain, models.EgressDomain{
  290. ID: egI.ID,
  291. Domain: egI.Domain,
  292. Node: node,
  293. Host: *host,
  294. })
  295. }
  296. }
  297. return
  298. }
  299. func BaseDomain(host string) string {
  300. parts := strings.Split(host, ".")
  301. if len(parts) < 2 {
  302. return host // not a FQDN
  303. }
  304. return strings.Join(parts[len(parts)-2:], ".")
  305. }