egress.go 8.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327
  1. package logic
  2. import (
  3. "context"
  4. "encoding/json"
  5. "errors"
  6. "maps"
  7. "github.com/gravitl/netmaker/db"
  8. "github.com/gravitl/netmaker/models"
  9. "github.com/gravitl/netmaker/schema"
  10. "github.com/gravitl/netmaker/servercfg"
  11. )
  12. func ValidateEgressReq(e *schema.Egress) error {
  13. if e.Network == "" {
  14. return errors.New("network id is empty")
  15. }
  16. _, err := GetNetwork(e.Network)
  17. if err != nil {
  18. return errors.New("failed to get network " + err.Error())
  19. }
  20. if !servercfg.IsPro && len(e.Nodes) > 1 {
  21. return errors.New("can only set one routing node on CE")
  22. }
  23. if len(e.Nodes) > 0 {
  24. for k := range e.Nodes {
  25. _, err := GetNodeByID(k)
  26. if err != nil {
  27. return errors.New("invalid routing node " + err.Error())
  28. }
  29. }
  30. }
  31. return nil
  32. }
  33. func DoesUserHaveAccessToEgress(user *models.User, e *schema.Egress, acls []models.Acl) bool {
  34. if !e.Status {
  35. return false
  36. }
  37. for _, acl := range acls {
  38. if !acl.Enabled {
  39. continue
  40. }
  41. dstTags := ConvAclTagToValueMap(acl.Dst)
  42. _, all := dstTags["*"]
  43. if _, ok := dstTags[e.ID]; ok || all {
  44. // get all src tags
  45. for _, srcAcl := range acl.Src {
  46. if srcAcl.ID == models.UserAclID && srcAcl.Value == user.UserName {
  47. return true
  48. } else if srcAcl.ID == models.UserGroupAclID {
  49. // fetch all users in the group
  50. if _, ok := user.UserGroups[models.UserGroupID(srcAcl.Value)]; ok {
  51. return true
  52. }
  53. }
  54. }
  55. }
  56. }
  57. return false
  58. }
  59. func DoesNodeHaveAccessToEgress(node *models.Node, e *schema.Egress, acls []models.Acl) bool {
  60. nodeTags := maps.Clone(node.Tags)
  61. nodeTags[models.TagID(node.ID.String())] = struct{}{}
  62. nodeTags[models.TagID("*")] = struct{}{}
  63. for _, acl := range acls {
  64. if !acl.Enabled {
  65. continue
  66. }
  67. srcVal := ConvAclTagToValueMap(acl.Src)
  68. for _, dstI := range acl.Dst {
  69. if (dstI.ID == models.EgressID && dstI.Value == e.ID) || (dstI.ID == models.NodeTagID && dstI.Value == "*") {
  70. if dstI.ID == models.EgressID {
  71. e := schema.Egress{ID: dstI.Value}
  72. err := e.Get(db.WithContext(context.TODO()))
  73. if err != nil {
  74. continue
  75. }
  76. }
  77. if node.IsStatic {
  78. if _, ok := srcVal[node.StaticNode.ClientID]; ok {
  79. return true
  80. }
  81. } else {
  82. if _, ok := srcVal[node.ID.String()]; ok {
  83. return true
  84. }
  85. }
  86. for tagID := range nodeTags {
  87. if _, ok := srcVal[tagID.String()]; ok {
  88. return true
  89. }
  90. }
  91. }
  92. }
  93. }
  94. return false
  95. }
  96. func AddEgressInfoToPeerByAccess(node, targetNode *models.Node, eli []schema.Egress, acls []models.Acl, isDefaultPolicyActive bool) {
  97. req := models.EgressGatewayRequest{
  98. NodeID: targetNode.ID.String(),
  99. NetID: targetNode.Network,
  100. NatEnabled: "yes",
  101. }
  102. for _, e := range eli {
  103. if !e.Status || e.Network != targetNode.Network {
  104. continue
  105. }
  106. if !isDefaultPolicyActive {
  107. if !DoesNodeHaveAccessToEgress(node, &e, acls) {
  108. if node.IsRelayed && node.RelayedBy == targetNode.ID.String() {
  109. if !DoesNodeHaveAccessToEgress(targetNode, &e, acls) {
  110. continue
  111. }
  112. } else {
  113. continue
  114. }
  115. }
  116. }
  117. if metric, ok := e.Nodes[targetNode.ID.String()]; ok {
  118. m64, err := metric.(json.Number).Int64()
  119. if err != nil {
  120. m64 = 256
  121. }
  122. m := uint32(m64)
  123. if e.Range != "" {
  124. req.Ranges = append(req.Ranges, e.Range)
  125. } else {
  126. req.Ranges = append(req.Ranges, e.DomainAns...)
  127. }
  128. if e.Range != "" {
  129. req.Ranges = append(req.Ranges, e.Range)
  130. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  131. Network: e.Range,
  132. Nat: e.Nat,
  133. RouteMetric: m,
  134. })
  135. }
  136. if e.Domain != "" && len(e.DomainAns) > 0 {
  137. req.Ranges = append(req.Ranges, e.DomainAns...)
  138. for _, domainAnsI := range e.DomainAns {
  139. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  140. Network: domainAnsI,
  141. Nat: e.Nat,
  142. RouteMetric: m,
  143. })
  144. }
  145. }
  146. }
  147. }
  148. if targetNode.Mutex != nil {
  149. targetNode.Mutex.Lock()
  150. }
  151. if len(req.Ranges) > 0 {
  152. targetNode.EgressDetails.IsEgressGateway = true
  153. targetNode.EgressDetails.EgressGatewayRanges = req.Ranges
  154. targetNode.EgressDetails.EgressGatewayRequest = req
  155. } else {
  156. targetNode.EgressDetails = models.EgressDetails{}
  157. }
  158. if targetNode.Mutex != nil {
  159. targetNode.Mutex.Unlock()
  160. }
  161. }
  162. func GetEgressDomainsByAccess(user *models.User, network models.NetworkID) (domains []string) {
  163. acls := ListUserPolicies(network)
  164. eli, _ := (&schema.Egress{Network: network.String()}).ListByNetwork(db.WithContext(context.TODO()))
  165. defaultDevicePolicy, _ := GetDefaultPolicy(network, models.DevicePolicy)
  166. isDefaultPolicyActive := defaultDevicePolicy.Enabled
  167. for _, e := range eli {
  168. if !e.Status || e.Network != network.String() {
  169. continue
  170. }
  171. if !isDefaultPolicyActive {
  172. if !DoesUserHaveAccessToEgress(user, &e, acls) {
  173. continue
  174. }
  175. }
  176. if e.Domain != "" && len(e.DomainAns) > 0 {
  177. domains = append(domains, e.Domain)
  178. }
  179. }
  180. return
  181. }
  182. func GetNodeEgressInfo(targetNode *models.Node, eli []schema.Egress, acls []models.Acl) {
  183. req := models.EgressGatewayRequest{
  184. NodeID: targetNode.ID.String(),
  185. NetID: targetNode.Network,
  186. NatEnabled: "yes",
  187. }
  188. for _, e := range eli {
  189. if !e.Status || e.Network != targetNode.Network {
  190. continue
  191. }
  192. if metric, ok := e.Nodes[targetNode.ID.String()]; ok {
  193. m64, err := metric.(json.Number).Int64()
  194. if err != nil {
  195. m64 = 256
  196. }
  197. m := uint32(m64)
  198. if e.Range != "" {
  199. req.Ranges = append(req.Ranges, e.Range)
  200. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  201. Network: e.Range,
  202. Nat: e.Nat,
  203. RouteMetric: m,
  204. })
  205. }
  206. if e.Domain != "" && len(e.DomainAns) > 0 {
  207. req.Ranges = append(req.Ranges, e.DomainAns...)
  208. for _, domainAnsI := range e.DomainAns {
  209. req.RangesWithMetric = append(req.RangesWithMetric, models.EgressRangeMetric{
  210. Network: domainAnsI,
  211. Nat: e.Nat,
  212. RouteMetric: m,
  213. })
  214. }
  215. }
  216. }
  217. }
  218. if targetNode.Mutex != nil {
  219. targetNode.Mutex.Lock()
  220. }
  221. if len(req.Ranges) > 0 {
  222. targetNode.EgressDetails.IsEgressGateway = true
  223. targetNode.EgressDetails.EgressGatewayRanges = req.Ranges
  224. targetNode.EgressDetails.EgressGatewayRequest = req
  225. } else {
  226. targetNode.EgressDetails = models.EgressDetails{}
  227. }
  228. if targetNode.Mutex != nil {
  229. targetNode.Mutex.Unlock()
  230. }
  231. }
  232. func RemoveNodeFromEgress(node models.Node) {
  233. egs, _ := (&schema.Egress{
  234. Network: node.Network,
  235. }).ListByNetwork(db.WithContext(context.TODO()))
  236. for _, egI := range egs {
  237. if _, ok := egI.Nodes[node.ID.String()]; ok {
  238. delete(egI.Nodes, node.ID.String())
  239. egI.Update(db.WithContext(context.TODO()))
  240. }
  241. }
  242. }
  243. func GetEgressRanges(netID models.NetworkID) (map[string][]string, map[string]struct{}, error) {
  244. resultMap := make(map[string]struct{})
  245. nodeEgressMap := make(map[string][]string)
  246. networkNodes, err := GetNetworkNodes(netID.String())
  247. if err != nil {
  248. return nil, nil, err
  249. }
  250. for _, currentNode := range networkNodes {
  251. if currentNode.Network != netID.String() {
  252. continue
  253. }
  254. if currentNode.EgressDetails.IsEgressGateway { // add the egress gateway range(s) to the result
  255. if len(currentNode.EgressDetails.EgressGatewayRanges) > 0 {
  256. nodeEgressMap[currentNode.ID.String()] = currentNode.EgressDetails.EgressGatewayRanges
  257. for _, egressRangeI := range currentNode.EgressDetails.EgressGatewayRanges {
  258. resultMap[egressRangeI] = struct{}{}
  259. }
  260. }
  261. }
  262. }
  263. extclients, _ := GetNetworkExtClients(netID.String())
  264. for _, extclient := range extclients {
  265. if len(extclient.ExtraAllowedIPs) > 0 {
  266. nodeEgressMap[extclient.ClientID] = extclient.ExtraAllowedIPs
  267. for _, extraAllowedIP := range extclient.ExtraAllowedIPs {
  268. resultMap[extraAllowedIP] = struct{}{}
  269. }
  270. }
  271. }
  272. return nodeEgressMap, resultMap, nil
  273. }
  274. func ListAllByRoutingNodeWithDomain(egs []schema.Egress, nodeID string) (egWithDomain []models.EgressDomain) {
  275. for _, egI := range egs {
  276. if !egI.Status || egI.Domain == "" {
  277. continue
  278. }
  279. if _, ok := egI.Nodes[nodeID]; ok {
  280. node, err := GetNodeByID(nodeID)
  281. if err != nil {
  282. continue
  283. }
  284. host, err := GetHost(node.HostID.String())
  285. if err != nil {
  286. continue
  287. }
  288. egWithDomain = append(egWithDomain, models.EgressDomain{
  289. ID: egI.ID,
  290. Domain: egI.Domain,
  291. Node: node,
  292. Host: *host,
  293. })
  294. }
  295. }
  296. return
  297. }