mqpublish.go 7.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229
  1. package functions
  2. import (
  3. "context"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "net"
  8. "os"
  9. "strconv"
  10. "sync"
  11. "time"
  12. "github.com/cloverstd/tcping/ping"
  13. "github.com/gravitl/netmaker/logger"
  14. "github.com/gravitl/netmaker/models"
  15. "github.com/gravitl/netmaker/netclient/auth"
  16. "github.com/gravitl/netmaker/netclient/config"
  17. "github.com/gravitl/netmaker/netclient/ncutils"
  18. "github.com/gravitl/netmaker/tls"
  19. )
  20. // Checkin -- go routine that checks for public or local ip changes, publishes changes
  21. //
  22. // if there are no updates, simply "pings" the server as a checkin
  23. func Checkin(ctx context.Context, wg *sync.WaitGroup) {
  24. logger.Log(2, "starting checkin goroutine")
  25. defer wg.Done()
  26. checkin()
  27. ticker := time.NewTicker(time.Second * 60)
  28. defer ticker.Stop()
  29. for {
  30. select {
  31. case <-ctx.Done():
  32. logger.Log(0, "checkin routine closed")
  33. return
  34. //delay should be configuraable -> use cfg.Node.NetworkSettings.DefaultCheckInInterval ??
  35. case <-ticker.C:
  36. checkin()
  37. }
  38. }
  39. }
  40. func checkin() {
  41. networks, _ := ncutils.GetSystemNetworks()
  42. logger.Log(3, "checkin with server(s) for all networks")
  43. for _, network := range networks {
  44. var nodeCfg config.ClientConfig
  45. nodeCfg.Network = network
  46. nodeCfg.ReadConfig()
  47. // check for nftables present if on Linux
  48. if ncutils.IsLinux() {
  49. if ncutils.IsNFTablesPresent() {
  50. nodeCfg.Node.FirewallInUse = models.FIREWALL_NFTABLES
  51. } else {
  52. nodeCfg.Node.FirewallInUse = models.FIREWALL_IPTABLES
  53. }
  54. } else {
  55. // defaults to iptables for now, may need another default for non-Linux OSes
  56. nodeCfg.Node.FirewallInUse = models.FIREWALL_IPTABLES
  57. }
  58. if nodeCfg.Node.IsStatic != "yes" {
  59. extIP, err := ncutils.GetPublicIP(nodeCfg.Server.API)
  60. if err != nil {
  61. logger.Log(1, "error encountered checking public ip addresses: ", err.Error())
  62. }
  63. if nodeCfg.Node.Endpoint != extIP && extIP != "" {
  64. logger.Log(1, "network:", nodeCfg.Node.Network, "endpoint has changed from ", nodeCfg.Node.Endpoint, " to ", extIP)
  65. nodeCfg.Node.Endpoint = extIP
  66. if err := PublishNodeUpdate(&nodeCfg); err != nil {
  67. logger.Log(0, "network:", nodeCfg.Node.Network, "could not publish endpoint change")
  68. }
  69. }
  70. intIP, err := getPrivateAddr()
  71. if err != nil {
  72. logger.Log(1, "network:", nodeCfg.Node.Network, "error encountered checking private ip addresses: ", err.Error())
  73. }
  74. if nodeCfg.Node.LocalAddress != intIP && intIP != "" {
  75. logger.Log(1, "network:", nodeCfg.Node.Network, "local Address has changed from ", nodeCfg.Node.LocalAddress, " to ", intIP)
  76. nodeCfg.Node.LocalAddress = intIP
  77. if err := PublishNodeUpdate(&nodeCfg); err != nil {
  78. logger.Log(0, "Network: ", nodeCfg.Node.Network, " could not publish local address change")
  79. }
  80. }
  81. _ = UpdateLocalListenPort(&nodeCfg)
  82. } else if nodeCfg.Node.IsLocal == "yes" && nodeCfg.Node.LocalRange != "" {
  83. localIP, err := ncutils.GetLocalIP(nodeCfg.Node.LocalRange)
  84. if err != nil {
  85. logger.Log(1, "network:", nodeCfg.Node.Network, "error encountered checking local ip addresses: ", err.Error())
  86. }
  87. if nodeCfg.Node.Endpoint != localIP && localIP != "" {
  88. logger.Log(1, "network:", nodeCfg.Node.Network, "endpoint has changed from "+nodeCfg.Node.Endpoint+" to ", localIP)
  89. nodeCfg.Node.Endpoint = localIP
  90. if err := PublishNodeUpdate(&nodeCfg); err != nil {
  91. logger.Log(0, "network:", nodeCfg.Node.Network, "could not publish localip change")
  92. }
  93. }
  94. }
  95. //check version
  96. if nodeCfg.Node.Version != ncutils.Version {
  97. nodeCfg.Node.Version = ncutils.Version
  98. config.Write(&nodeCfg, nodeCfg.Network)
  99. }
  100. Hello(&nodeCfg)
  101. checkCertExpiry(&nodeCfg)
  102. }
  103. }
  104. // PublishNodeUpdates -- saves node and pushes changes to broker
  105. func PublishNodeUpdate(nodeCfg *config.ClientConfig) error {
  106. if err := config.Write(nodeCfg, nodeCfg.Network); err != nil {
  107. return err
  108. }
  109. data, err := json.Marshal(nodeCfg.Node)
  110. if err != nil {
  111. return err
  112. }
  113. if err = publish(nodeCfg, fmt.Sprintf("update/%s", nodeCfg.Node.ID), data, 1); err != nil {
  114. return err
  115. }
  116. logger.Log(0, "network:", nodeCfg.Node.Network, "sent a node update to server for node", nodeCfg.Node.Name, ", ", nodeCfg.Node.ID)
  117. return nil
  118. }
  119. // Hello -- ping the broker to let server know node it's alive and well
  120. func Hello(nodeCfg *config.ClientConfig) {
  121. var checkin models.NodeCheckin
  122. checkin.Version = ncutils.Version
  123. checkin.Connected = nodeCfg.Node.Connected
  124. data, err := json.Marshal(checkin)
  125. if err != nil {
  126. logger.Log(0, "unable to marshal checkin data", err.Error())
  127. return
  128. }
  129. if err := publish(nodeCfg, fmt.Sprintf("ping/%s", nodeCfg.Node.ID), data, 0); err != nil {
  130. logger.Log(0, fmt.Sprintf("Network: %s error publishing ping, %v", nodeCfg.Node.Network, err))
  131. logger.Log(0, "running pull on "+nodeCfg.Node.Network+" to reconnect")
  132. _, err := Pull(nodeCfg.Node.Network, true)
  133. if err != nil {
  134. logger.Log(0, "could not run pull on "+nodeCfg.Node.Network+", error: "+err.Error())
  135. }
  136. } else {
  137. logger.Log(3, "checkin for", nodeCfg.Network, "complete")
  138. }
  139. }
  140. // node cfg is required in order to fetch the traffic keys of that node for encryption
  141. func publish(nodeCfg *config.ClientConfig, dest string, msg []byte, qos byte) error {
  142. // setup the keys
  143. trafficPrivKey, err := auth.RetrieveTrafficKey(nodeCfg.Node.Network)
  144. if err != nil {
  145. return err
  146. }
  147. serverPubKey, err := ncutils.ConvertBytesToKey(nodeCfg.Node.TrafficKeys.Server)
  148. if err != nil {
  149. return err
  150. }
  151. encrypted, err := ncutils.Chunk(msg, serverPubKey, trafficPrivKey)
  152. if err != nil {
  153. return err
  154. }
  155. if mqclient == nil {
  156. return errors.New("unable to publish ... no mqclient")
  157. }
  158. if token := mqclient.Publish(dest, qos, false, encrypted); !token.WaitTimeout(30*time.Second) || token.Error() != nil {
  159. logger.Log(0, "could not connect to broker at "+nodeCfg.Server.Server+":"+nodeCfg.Server.MQPort)
  160. var err error
  161. if token.Error() == nil {
  162. err = errors.New("connection timeout")
  163. } else {
  164. err = token.Error()
  165. }
  166. if err != nil {
  167. return err
  168. }
  169. }
  170. return nil
  171. }
  172. func checkCertExpiry(cfg *config.ClientConfig) error {
  173. cert, err := tls.ReadCertFromFile(ncutils.GetNetclientServerPath(cfg.Server.Server) + ncutils.GetSeparator() + "client.pem")
  174. //if cert doesn't exist or will expire within 10 days
  175. if errors.Is(err, os.ErrNotExist) || cert.NotAfter.Before(time.Now().Add(time.Hour*24*10)) {
  176. key, err := tls.ReadKeyFromFile(ncutils.GetNetclientPath() + ncutils.GetSeparator() + "client.key")
  177. if err != nil {
  178. return err
  179. }
  180. return RegisterWithServer(key, cfg)
  181. }
  182. if err != nil {
  183. return err
  184. }
  185. return nil
  186. }
  187. func checkBroker(broker string, port string) error {
  188. if broker == "" {
  189. return errors.New("error: broker address is blank")
  190. }
  191. if port == "" {
  192. return errors.New("error: broker port is blank")
  193. }
  194. _, err := net.LookupIP(broker)
  195. if err != nil {
  196. return errors.New("nslookup failed for broker ... check dns records")
  197. }
  198. pinger := ping.NewTCPing()
  199. intPort, err := strconv.Atoi(port)
  200. if err != nil {
  201. logger.Log(1, "error converting port to int: "+err.Error())
  202. }
  203. pinger.SetTarget(&ping.Target{
  204. Protocol: ping.TCP,
  205. Host: broker,
  206. Port: intPort,
  207. Counter: 3,
  208. Interval: 1 * time.Second,
  209. Timeout: 2 * time.Second,
  210. })
  211. pingerDone := pinger.Start()
  212. <-pingerDone
  213. if pinger.Result().SuccessCounter == 0 {
  214. return errors.New("unable to connect to broker port ... check netmaker server and firewalls")
  215. }
  216. return nil
  217. }