inet_gws.go 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171
  1. package logic
  2. import (
  3. "errors"
  4. "fmt"
  5. "net"
  6. "github.com/google/uuid"
  7. "golang.org/x/exp/slog"
  8. "github.com/gravitl/netmaker/models"
  9. )
  10. const (
  11. IPv4Network = "0.0.0.0/0"
  12. IPv6Network = "::/0"
  13. )
  14. func ValidateInetGwReq(inetNode models.Node, req models.InetNodeReq, update bool) error {
  15. inetHost, err := GetHost(inetNode.HostID.String())
  16. if err != nil {
  17. return err
  18. }
  19. if inetHost.FirewallInUse == models.FIREWALL_NONE {
  20. return errors.New("iptables or nftables needs to be installed")
  21. }
  22. if inetNode.EgressDetails.InternetGwID != "" {
  23. return fmt.Errorf("node %s is using a internet gateway already", inetHost.Name)
  24. }
  25. if inetNode.IsRelayed {
  26. return fmt.Errorf("node %s is being relayed", inetHost.Name)
  27. }
  28. for _, clientNodeID := range req.InetNodeClientIDs {
  29. clientNode, err := GetNodeByID(clientNodeID)
  30. if err != nil {
  31. return err
  32. }
  33. if clientNode.IsFailOver {
  34. return errors.New("failover node cannot be set to use internet gateway")
  35. }
  36. clientHost, err := GetHost(clientNode.HostID.String())
  37. if err != nil {
  38. return err
  39. }
  40. if clientHost.IsDefault {
  41. return errors.New("default host cannot be set to use internet gateway")
  42. }
  43. if clientHost.OS != models.OS_Types.Linux && clientHost.OS != models.OS_Types.Windows {
  44. return errors.New("can only attach linux or windows machine to a internet gateway")
  45. }
  46. if clientNode.EgressDetails.IsInternetGateway {
  47. return fmt.Errorf("node %s acting as internet gateway cannot use another internet gateway", clientHost.Name)
  48. }
  49. if update {
  50. if clientNode.EgressDetails.InternetGwID != "" && clientNode.EgressDetails.InternetGwID != inetNode.ID.String() {
  51. return fmt.Errorf("node %s is already using a internet gateway", clientHost.Name)
  52. }
  53. } else {
  54. if clientNode.EgressDetails.InternetGwID != "" {
  55. return fmt.Errorf("node %s is already using a internet gateway", clientHost.Name)
  56. }
  57. }
  58. if clientNode.FailedOverBy != uuid.Nil {
  59. ResetFailedOverPeer(&clientNode)
  60. }
  61. if clientNode.IsRelayed && clientNode.RelayedBy != inetNode.ID.String() {
  62. return fmt.Errorf("node %s is being relayed", clientHost.Name)
  63. }
  64. for _, nodeID := range clientHost.Nodes {
  65. node, err := GetNodeByID(nodeID)
  66. if err != nil {
  67. continue
  68. }
  69. if node.EgressDetails.InternetGwID != "" && node.EgressDetails.InternetGwID != inetNode.ID.String() {
  70. return errors.New("nodes on same host cannot use different internet gateway")
  71. }
  72. }
  73. }
  74. return nil
  75. }
  76. // SetInternetGw - sets the node as internet gw based on flag bool
  77. func SetInternetGw(node *models.Node, req models.InetNodeReq) {
  78. node.EgressDetails.IsInternetGateway = true
  79. node.EgressDetails.InetNodeReq = req
  80. for _, clientNodeID := range req.InetNodeClientIDs {
  81. clientNode, err := GetNodeByID(clientNodeID)
  82. if err != nil {
  83. continue
  84. }
  85. clientNode.EgressDetails.InternetGwID = node.ID.String()
  86. UpsertNode(&clientNode)
  87. }
  88. }
  89. func UnsetInternetGw(node *models.Node) {
  90. nodes, err := GetNetworkNodes(node.Network)
  91. if err != nil {
  92. slog.Error("failed to get network nodes", "network", node.Network, "error", err)
  93. return
  94. }
  95. for _, clientNode := range nodes {
  96. if node.ID.String() == clientNode.EgressDetails.InternetGwID {
  97. clientNode.EgressDetails.InternetGwID = ""
  98. UpsertNode(&clientNode)
  99. }
  100. }
  101. node.EgressDetails.IsInternetGateway = false
  102. node.EgressDetails.InetNodeReq = models.InetNodeReq{}
  103. }
  104. func SetDefaultGwForRelayedUpdate(relayed, relay models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate {
  105. if relay.EgressDetails.InternetGwID != "" {
  106. relayedHost, err := GetHost(relayed.HostID.String())
  107. if err != nil {
  108. return peerUpdate
  109. }
  110. peerUpdate.ChangeDefaultGw = true
  111. peerUpdate.DefaultGwIp = relay.Address.IP
  112. if peerUpdate.DefaultGwIp == nil || relayedHost.EndpointIP == nil {
  113. peerUpdate.DefaultGwIp = relay.Address6.IP
  114. }
  115. }
  116. return peerUpdate
  117. }
  118. func SetDefaultGw(node models.Node, peerUpdate models.HostPeerUpdate) models.HostPeerUpdate {
  119. if node.EgressDetails.InternetGwID != "" {
  120. inetNode, err := GetNodeByID(node.EgressDetails.InternetGwID)
  121. if err != nil {
  122. return peerUpdate
  123. }
  124. host, err := GetHost(node.HostID.String())
  125. if err != nil {
  126. return peerUpdate
  127. }
  128. peerUpdate.ChangeDefaultGw = true
  129. peerUpdate.DefaultGwIp = inetNode.Address.IP
  130. if peerUpdate.DefaultGwIp == nil || host.EndpointIP == nil {
  131. peerUpdate.DefaultGwIp = inetNode.Address6.IP
  132. }
  133. }
  134. return peerUpdate
  135. }
  136. // GetAllowedIpForInetNodeClient - get inet cidr for node using a inet gw
  137. func GetAllowedIpForInetNodeClient(node, peer *models.Node) []net.IPNet {
  138. var allowedips = []net.IPNet{}
  139. if peer.Address.IP != nil {
  140. _, ipnet, _ := net.ParseCIDR(IPv4Network)
  141. allowedips = append(allowedips, *ipnet)
  142. }
  143. if peer.Address6.IP != nil {
  144. _, ipnet, _ := net.ParseCIDR(IPv6Network)
  145. allowedips = append(allowedips, *ipnet)
  146. }
  147. return allowedips
  148. }