serverconf.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646
  1. package servercfg
  2. import (
  3. "errors"
  4. "io"
  5. "net/http"
  6. "os"
  7. "strconv"
  8. "strings"
  9. "time"
  10. "github.com/gravitl/netmaker/config"
  11. "github.com/gravitl/netmaker/models"
  12. )
  13. var (
  14. Version = "dev"
  15. )
  16. // SetHost - sets the host ip
  17. func SetHost() error {
  18. remoteip, err := GetPublicIP()
  19. if err != nil {
  20. return err
  21. }
  22. os.Setenv("SERVER_HOST", remoteip)
  23. return nil
  24. }
  25. // GetServerConfig - gets the server config into memory from file or env
  26. func GetServerConfig() config.ServerConfig {
  27. var cfg config.ServerConfig
  28. cfg.APIConnString = GetAPIConnString()
  29. cfg.CoreDNSAddr = GetCoreDNSAddr()
  30. cfg.APIHost = GetAPIHost()
  31. cfg.APIPort = GetAPIPort()
  32. cfg.MQPort = GetMQPort()
  33. cfg.MasterKey = "(hidden)"
  34. cfg.DNSKey = "(hidden)"
  35. cfg.AllowedOrigin = GetAllowedOrigin()
  36. cfg.RestBackend = "off"
  37. cfg.NodeID = GetNodeID()
  38. if IsRestBackend() {
  39. cfg.RestBackend = "on"
  40. }
  41. cfg.AgentBackend = "off"
  42. if IsAgentBackend() {
  43. cfg.AgentBackend = "on"
  44. }
  45. cfg.ClientMode = "off"
  46. if IsClientMode() != "off" {
  47. cfg.ClientMode = IsClientMode()
  48. }
  49. cfg.DNSMode = "off"
  50. if IsDNSMode() {
  51. cfg.DNSMode = "on"
  52. }
  53. cfg.DisplayKeys = "off"
  54. if IsDisplayKeys() {
  55. cfg.DisplayKeys = "on"
  56. }
  57. cfg.DisableRemoteIPCheck = "off"
  58. if DisableRemoteIPCheck() {
  59. cfg.DisableRemoteIPCheck = "on"
  60. }
  61. cfg.Database = GetDB()
  62. cfg.Platform = GetPlatform()
  63. cfg.Version = GetVersion()
  64. // == auth config ==
  65. var authInfo = GetAuthProviderInfo()
  66. cfg.AuthProvider = authInfo[0]
  67. cfg.ClientID = authInfo[1]
  68. cfg.ClientSecret = authInfo[2]
  69. cfg.FrontendURL = GetFrontendURL()
  70. if GetRce() {
  71. cfg.RCE = "on"
  72. } else {
  73. cfg.RCE = "off"
  74. }
  75. cfg.Telemetry = Telemetry()
  76. cfg.ManageIPTables = ManageIPTables()
  77. services := strings.Join(GetPortForwardServiceList(), ",")
  78. cfg.PortForwardServices = services
  79. cfg.Server = GetServer()
  80. cfg.Verbosity = GetVerbosity()
  81. return cfg
  82. }
  83. // GetServerConfig - gets the server config into memory from file or env
  84. func GetServerInfo() models.ServerConfig {
  85. var cfg models.ServerConfig
  86. cfg.API = GetAPIConnString()
  87. cfg.CoreDNSAddr = GetCoreDNSAddr()
  88. cfg.APIPort = GetAPIPort()
  89. cfg.MQPort = GetMQPort()
  90. cfg.DNSMode = "off"
  91. if IsDNSMode() {
  92. cfg.DNSMode = "on"
  93. }
  94. cfg.Version = GetVersion()
  95. cfg.Server = GetServer()
  96. return cfg
  97. }
  98. // GetFrontendURL - gets the frontend url
  99. func GetFrontendURL() string {
  100. var frontend = ""
  101. if os.Getenv("FRONTEND_URL") != "" {
  102. frontend = os.Getenv("FRONTEND_URL")
  103. } else if config.Config.Server.FrontendURL != "" {
  104. frontend = config.Config.Server.FrontendURL
  105. }
  106. return frontend
  107. }
  108. // GetAPIConnString - gets the api connections string
  109. func GetAPIConnString() string {
  110. conn := ""
  111. if os.Getenv("SERVER_API_CONN_STRING") != "" {
  112. conn = os.Getenv("SERVER_API_CONN_STRING")
  113. } else if config.Config.Server.APIConnString != "" {
  114. conn = config.Config.Server.APIConnString
  115. }
  116. return conn
  117. }
  118. // SetVersion - set version of netmaker
  119. func SetVersion(v string) {
  120. Version = v
  121. }
  122. // GetVersion - version of netmaker
  123. func GetVersion() string {
  124. return Version
  125. }
  126. // GetDB - gets the database type
  127. func GetDB() string {
  128. database := "sqlite"
  129. if os.Getenv("DATABASE") != "" {
  130. database = os.Getenv("DATABASE")
  131. } else if config.Config.Server.Database != "" {
  132. database = config.Config.Server.Database
  133. }
  134. return database
  135. }
  136. // GetAPIHost - gets the api host
  137. func GetAPIHost() string {
  138. serverhost := "127.0.0.1"
  139. remoteip, _ := GetPublicIP()
  140. if os.Getenv("SERVER_HTTP_HOST") != "" {
  141. serverhost = os.Getenv("SERVER_HTTP_HOST")
  142. } else if config.Config.Server.APIHost != "" {
  143. serverhost = config.Config.Server.APIHost
  144. } else if os.Getenv("SERVER_HOST") != "" {
  145. serverhost = os.Getenv("SERVER_HOST")
  146. } else {
  147. if remoteip != "" {
  148. serverhost = remoteip
  149. }
  150. }
  151. return serverhost
  152. }
  153. // GetPodIP - get the pod's ip
  154. func GetPodIP() string {
  155. podip := "127.0.0.1"
  156. if os.Getenv("POD_IP") != "" {
  157. podip = os.Getenv("POD_IP")
  158. }
  159. return podip
  160. }
  161. // GetAPIPort - gets the api port
  162. func GetAPIPort() string {
  163. apiport := "8081"
  164. if os.Getenv("API_PORT") != "" {
  165. apiport = os.Getenv("API_PORT")
  166. } else if config.Config.Server.APIPort != "" {
  167. apiport = config.Config.Server.APIPort
  168. }
  169. return apiport
  170. }
  171. // GetDefaultNodeLimit - get node limit if one is set
  172. func GetDefaultNodeLimit() int32 {
  173. var limit int32
  174. limit = 999999999
  175. envlimit, err := strconv.Atoi(os.Getenv("DEFAULT_NODE_LIMIT"))
  176. if err == nil && envlimit != 0 {
  177. limit = int32(envlimit)
  178. } else if config.Config.Server.DefaultNodeLimit != 0 {
  179. limit = config.Config.Server.DefaultNodeLimit
  180. }
  181. return limit
  182. }
  183. // GetCoreDNSAddr - gets the core dns address
  184. func GetCoreDNSAddr() string {
  185. addr, _ := GetPublicIP()
  186. if os.Getenv("COREDNS_ADDR") != "" {
  187. addr = os.Getenv("COREDNS_ADDR")
  188. } else if config.Config.Server.CoreDNSAddr != "" {
  189. addr = config.Config.Server.CoreDNSAddr
  190. }
  191. return addr
  192. }
  193. // GetMQPort - gets the mq port
  194. func GetMQPort() string {
  195. port := "8883" //default
  196. if os.Getenv("MQ_PORT") != "" {
  197. port = os.Getenv("MQ_PORT")
  198. } else if config.Config.Server.MQPort != "" {
  199. port = config.Config.Server.MQPort
  200. }
  201. return port
  202. }
  203. // GetMessageQueueEndpoint - gets the message queue endpoint
  204. func GetMessageQueueEndpoint() (string, bool) {
  205. host, _ := GetPublicIP()
  206. if os.Getenv("MQ_HOST") != "" {
  207. host = os.Getenv("MQ_HOST")
  208. } else if config.Config.Server.MQHOST != "" {
  209. host = config.Config.Server.MQHOST
  210. }
  211. secure := strings.Contains(host, "mqtts") || strings.Contains(host, "ssl")
  212. return host + ":" + GetMQServerPort(), secure
  213. }
  214. // GetMasterKey - gets the configured master key of server
  215. func GetMasterKey() string {
  216. key := ""
  217. if os.Getenv("MASTER_KEY") != "" {
  218. key = os.Getenv("MASTER_KEY")
  219. } else if config.Config.Server.MasterKey != "" {
  220. key = config.Config.Server.MasterKey
  221. }
  222. return key
  223. }
  224. // GetDNSKey - gets the configured dns key of server
  225. func GetDNSKey() string {
  226. key := "secretkey"
  227. if os.Getenv("DNS_KEY") != "" {
  228. key = os.Getenv("DNS_KEY")
  229. } else if config.Config.Server.DNSKey != "" {
  230. key = config.Config.Server.DNSKey
  231. }
  232. return key
  233. }
  234. // GetAllowedOrigin - get the allowed origin
  235. func GetAllowedOrigin() string {
  236. allowedorigin := "*"
  237. if os.Getenv("CORS_ALLOWED_ORIGIN") != "" {
  238. allowedorigin = os.Getenv("CORS_ALLOWED_ORIGIN")
  239. } else if config.Config.Server.AllowedOrigin != "" {
  240. allowedorigin = config.Config.Server.AllowedOrigin
  241. }
  242. return allowedorigin
  243. }
  244. // IsRestBackend - checks if rest is on or off
  245. func IsRestBackend() bool {
  246. isrest := true
  247. if os.Getenv("REST_BACKEND") != "" {
  248. if os.Getenv("REST_BACKEND") == "off" {
  249. isrest = false
  250. }
  251. } else if config.Config.Server.RestBackend != "" {
  252. if config.Config.Server.RestBackend == "off" {
  253. isrest = false
  254. }
  255. }
  256. return isrest
  257. }
  258. // IsMetricsExporter - checks if metrics exporter is on or off
  259. func IsMetricsExporter() bool {
  260. export := false
  261. if os.Getenv("METRICS_EXPORTER") != "" {
  262. if os.Getenv("METRICS_EXPORTER") == "on" {
  263. export = true
  264. }
  265. } else if config.Config.Server.MetricsExporter != "" {
  266. if config.Config.Server.MetricsExporter == "on" {
  267. export = true
  268. }
  269. }
  270. return export
  271. }
  272. // IsAgentBackend - checks if agent backed is on or off
  273. func IsAgentBackend() bool {
  274. isagent := true
  275. if os.Getenv("AGENT_BACKEND") != "" {
  276. if os.Getenv("AGENT_BACKEND") == "off" {
  277. isagent = false
  278. }
  279. } else if config.Config.Server.AgentBackend != "" {
  280. if config.Config.Server.AgentBackend == "off" {
  281. isagent = false
  282. }
  283. }
  284. return isagent
  285. }
  286. // IsMessageQueueBackend - checks if message queue is on or off
  287. func IsMessageQueueBackend() bool {
  288. ismessagequeue := true
  289. if os.Getenv("MESSAGEQUEUE_BACKEND") != "" {
  290. if os.Getenv("MESSAGEQUEUE_BACKEND") == "off" {
  291. ismessagequeue = false
  292. }
  293. } else if config.Config.Server.MessageQueueBackend != "" {
  294. if config.Config.Server.MessageQueueBackend == "off" {
  295. ismessagequeue = false
  296. }
  297. }
  298. return ismessagequeue
  299. }
  300. // IsClientMode - checks if it should run in client mode
  301. func IsClientMode() string {
  302. isclient := "on"
  303. if os.Getenv("CLIENT_MODE") == "off" {
  304. isclient = "off"
  305. }
  306. if config.Config.Server.ClientMode == "off" {
  307. isclient = "off"
  308. }
  309. return isclient
  310. }
  311. // Telemetry - checks if telemetry data should be sent
  312. func Telemetry() string {
  313. telemetry := "on"
  314. if os.Getenv("TELEMETRY") == "off" {
  315. telemetry = "off"
  316. }
  317. if config.Config.Server.Telemetry == "off" {
  318. telemetry = "off"
  319. }
  320. return telemetry
  321. }
  322. // ManageIPTables - checks if iptables should be manipulated on host
  323. func ManageIPTables() string {
  324. manage := "on"
  325. if os.Getenv("MANAGE_IPTABLES") == "off" {
  326. manage = "off"
  327. }
  328. if config.Config.Server.ManageIPTables == "off" {
  329. manage = "off"
  330. }
  331. return manage
  332. }
  333. // GetServer - gets the server name
  334. func GetServer() string {
  335. server := ""
  336. if os.Getenv("SERVER_NAME") != "" {
  337. server = os.Getenv("SERVER_NAME")
  338. } else if config.Config.Server.Server != "" {
  339. server = config.Config.Server.Server
  340. }
  341. return server
  342. }
  343. func GetVerbosity() int32 {
  344. var verbosity = 0
  345. var err error
  346. if os.Getenv("VERBOSITY") != "" {
  347. verbosity, err = strconv.Atoi(os.Getenv("VERBOSITY"))
  348. if err != nil {
  349. verbosity = 0
  350. }
  351. } else if config.Config.Server.Verbosity != 0 {
  352. verbosity = int(config.Config.Server.Verbosity)
  353. }
  354. if verbosity < 0 || verbosity > 4 {
  355. verbosity = 0
  356. }
  357. return int32(verbosity)
  358. }
  359. // IsDNSMode - should it run with DNS
  360. func IsDNSMode() bool {
  361. isdns := true
  362. if os.Getenv("DNS_MODE") != "" {
  363. if os.Getenv("DNS_MODE") == "off" {
  364. isdns = false
  365. }
  366. } else if config.Config.Server.DNSMode != "" {
  367. if config.Config.Server.DNSMode == "off" {
  368. isdns = false
  369. }
  370. }
  371. return isdns
  372. }
  373. // IsDisplayKeys - should server be able to display keys?
  374. func IsDisplayKeys() bool {
  375. isdisplay := true
  376. if os.Getenv("DISPLAY_KEYS") != "" {
  377. if os.Getenv("DISPLAY_KEYS") == "off" {
  378. isdisplay = false
  379. }
  380. } else if config.Config.Server.DisplayKeys != "" {
  381. if config.Config.Server.DisplayKeys == "off" {
  382. isdisplay = false
  383. }
  384. }
  385. return isdisplay
  386. }
  387. // DisableRemoteIPCheck - disable the remote ip check
  388. func DisableRemoteIPCheck() bool {
  389. disabled := false
  390. if os.Getenv("DISABLE_REMOTE_IP_CHECK") != "" {
  391. if os.Getenv("DISABLE_REMOTE_IP_CHECK") == "on" {
  392. disabled = true
  393. }
  394. } else if config.Config.Server.DisableRemoteIPCheck != "" {
  395. if config.Config.Server.DisableRemoteIPCheck == "on" {
  396. disabled = true
  397. }
  398. }
  399. return disabled
  400. }
  401. // GetPublicIP - gets public ip
  402. func GetPublicIP() (string, error) {
  403. endpoint := ""
  404. var err error
  405. iplist := []string{"https://ip.server.gravitl.com", "https://ifconfig.me", "https://api.ipify.org", "https://ipinfo.io/ip"}
  406. publicIpService := os.Getenv("PUBLIC_IP_SERVICE")
  407. if publicIpService != "" {
  408. // prepend the user-specified service so it's checked first
  409. iplist = append([]string{publicIpService}, iplist...)
  410. } else if config.Config.Server.PublicIPService != "" {
  411. publicIpService = config.Config.Server.PublicIPService
  412. // prepend the user-specified service so it's checked first
  413. iplist = append([]string{publicIpService}, iplist...)
  414. }
  415. for _, ipserver := range iplist {
  416. client := &http.Client{
  417. Timeout: time.Second * 10,
  418. }
  419. resp, err := client.Get(ipserver)
  420. if err != nil {
  421. continue
  422. }
  423. defer resp.Body.Close()
  424. if resp.StatusCode == http.StatusOK {
  425. bodyBytes, err := io.ReadAll(resp.Body)
  426. if err != nil {
  427. continue
  428. }
  429. endpoint = string(bodyBytes)
  430. break
  431. }
  432. }
  433. if err == nil && endpoint == "" {
  434. err = errors.New("public address not found")
  435. }
  436. return endpoint, err
  437. }
  438. // GetPlatform - get the system type of server
  439. func GetPlatform() string {
  440. platform := "linux"
  441. if os.Getenv("PLATFORM") != "" {
  442. platform = os.Getenv("PLATFORM")
  443. } else if config.Config.Server.Platform != "" {
  444. platform = config.Config.Server.SQLConn
  445. }
  446. return platform
  447. }
  448. // GetIPForwardServiceList - get the list of services that the server should be forwarding
  449. func GetPortForwardServiceList() []string {
  450. //services := "mq,dns,ssh"
  451. services := ""
  452. if os.Getenv("PORT_FORWARD_SERVICES") != "" {
  453. services = os.Getenv("PORT_FORWARD_SERVICES")
  454. } else if config.Config.Server.PortForwardServices != "" {
  455. services = config.Config.Server.PortForwardServices
  456. }
  457. serviceSlice := strings.Split(services, ",")
  458. return serviceSlice
  459. }
  460. // GetSQLConn - get the sql connection string
  461. func GetSQLConn() string {
  462. sqlconn := "http://"
  463. if os.Getenv("SQL_CONN") != "" {
  464. sqlconn = os.Getenv("SQL_CONN")
  465. } else if config.Config.Server.SQLConn != "" {
  466. sqlconn = config.Config.Server.SQLConn
  467. }
  468. return sqlconn
  469. }
  470. // IsHostNetwork - checks if running on host network
  471. func IsHostNetwork() bool {
  472. ishost := false
  473. if os.Getenv("HOST_NETWORK") == "on" {
  474. ishost = true
  475. } else if config.Config.Server.HostNetwork == "on" {
  476. ishost = true
  477. }
  478. return ishost
  479. }
  480. // GetNodeID - gets the node id
  481. func GetNodeID() string {
  482. var id string
  483. var err error
  484. // id = getMacAddr()
  485. if os.Getenv("NODE_ID") != "" {
  486. id = os.Getenv("NODE_ID")
  487. } else if config.Config.Server.NodeID != "" {
  488. id = config.Config.Server.NodeID
  489. } else {
  490. id, err = os.Hostname()
  491. if err != nil {
  492. return ""
  493. }
  494. }
  495. return id
  496. }
  497. func SetNodeID(id string) {
  498. config.Config.Server.NodeID = id
  499. }
  500. // GetServerCheckinInterval - gets the server check-in time
  501. func GetServerCheckinInterval() int64 {
  502. var t = int64(5)
  503. var envt, _ = strconv.Atoi(os.Getenv("SERVER_CHECKIN_INTERVAL"))
  504. if envt > 0 {
  505. t = int64(envt)
  506. } else if config.Config.Server.ServerCheckinInterval > 0 {
  507. t = config.Config.Server.ServerCheckinInterval
  508. }
  509. return t
  510. }
  511. // GetAuthProviderInfo = gets the oauth provider info
  512. func GetAuthProviderInfo() (pi []string) {
  513. var authProvider = ""
  514. defer func() {
  515. if authProvider == "oidc" {
  516. if os.Getenv("OIDC_ISSUER") != "" {
  517. pi = append(pi, os.Getenv("OIDC_ISSUER"))
  518. } else if config.Config.Server.OIDCIssuer != "" {
  519. pi = append(pi, config.Config.Server.OIDCIssuer)
  520. } else {
  521. pi = []string{"", "", ""}
  522. }
  523. }
  524. }()
  525. if os.Getenv("AUTH_PROVIDER") != "" && os.Getenv("CLIENT_ID") != "" && os.Getenv("CLIENT_SECRET") != "" {
  526. authProvider = strings.ToLower(os.Getenv("AUTH_PROVIDER"))
  527. if authProvider == "google" || authProvider == "azure-ad" || authProvider == "github" || authProvider == "oidc" {
  528. return []string{authProvider, os.Getenv("CLIENT_ID"), os.Getenv("CLIENT_SECRET")}
  529. } else {
  530. authProvider = ""
  531. }
  532. } else if config.Config.Server.AuthProvider != "" && config.Config.Server.ClientID != "" && config.Config.Server.ClientSecret != "" {
  533. authProvider = strings.ToLower(config.Config.Server.AuthProvider)
  534. if authProvider == "google" || authProvider == "azure-ad" || authProvider == "github" || authProvider == "oidc" {
  535. return []string{authProvider, config.Config.Server.ClientID, config.Config.Server.ClientSecret}
  536. }
  537. }
  538. return []string{"", "", ""}
  539. }
  540. // GetAzureTenant - retrieve the azure tenant ID from env variable or config file
  541. func GetAzureTenant() string {
  542. var azureTenant = ""
  543. if os.Getenv("AZURE_TENANT") != "" {
  544. azureTenant = os.Getenv("AZURE_TENANT")
  545. } else if config.Config.Server.AzureTenant != "" {
  546. azureTenant = config.Config.Server.AzureTenant
  547. }
  548. return azureTenant
  549. }
  550. // GetRce - sees if Rce is enabled, off by default
  551. func GetRce() bool {
  552. return os.Getenv("RCE") == "on" || config.Config.Server.RCE == "on"
  553. }
  554. // GetMQServerPort - get mq port for server
  555. func GetMQServerPort() string {
  556. port := "1883" //default
  557. if os.Getenv("MQ_SERVER_PORT") != "" {
  558. port = os.Getenv("MQ_SERVER_PORT")
  559. } else if config.Config.Server.MQServerPort != "" {
  560. port = config.Config.Server.MQServerPort
  561. }
  562. return port
  563. }
  564. // IsBasicAuthEnabled - checks if basic auth has been configured to be turned off
  565. func IsBasicAuthEnabled() bool {
  566. var enabled = true //default
  567. if os.Getenv("BASIC_AUTH") != "" {
  568. enabled = os.Getenv("BASIC_AUTH") == "yes"
  569. } else if config.Config.Server.BasicAuth != "" {
  570. enabled = config.Config.Server.BasicAuth == "yes"
  571. }
  572. return enabled
  573. }
  574. // GetLicenseKey - retrieves pro license value from env or conf files
  575. func GetLicenseKey() string {
  576. licenseKeyValue := os.Getenv("LICENSE_KEY")
  577. if licenseKeyValue == "" {
  578. licenseKeyValue = config.Config.Server.LicenseValue
  579. }
  580. return licenseKeyValue
  581. }
  582. // GetNetmakerAccountID - get's the associated, Netmaker, account ID to verify ownership
  583. func GetNetmakerAccountID() string {
  584. netmakerAccountID := os.Getenv("NETMAKER_ACCOUNT_ID")
  585. if netmakerAccountID == "" {
  586. netmakerAccountID = config.Config.Server.LicenseValue
  587. }
  588. return netmakerAccountID
  589. }