serverconf.go 16 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652
  1. package servercfg
  2. import (
  3. "errors"
  4. "io"
  5. "net/http"
  6. "os"
  7. "strconv"
  8. "strings"
  9. "time"
  10. "github.com/gravitl/netmaker/config"
  11. "github.com/gravitl/netmaker/models"
  12. )
  13. var (
  14. Version = "dev"
  15. Is_EE = false
  16. )
  17. // SetHost - sets the host ip
  18. func SetHost() error {
  19. remoteip, err := GetPublicIP()
  20. if err != nil {
  21. return err
  22. }
  23. os.Setenv("SERVER_HOST", remoteip)
  24. return nil
  25. }
  26. // GetServerConfig - gets the server config into memory from file or env
  27. func GetServerConfig() config.ServerConfig {
  28. var cfg config.ServerConfig
  29. cfg.APIConnString = GetAPIConnString()
  30. cfg.CoreDNSAddr = GetCoreDNSAddr()
  31. cfg.APIHost = GetAPIHost()
  32. cfg.APIPort = GetAPIPort()
  33. cfg.MQPort = GetMQPort()
  34. cfg.MasterKey = "(hidden)"
  35. cfg.DNSKey = "(hidden)"
  36. cfg.AllowedOrigin = GetAllowedOrigin()
  37. cfg.RestBackend = "off"
  38. cfg.NodeID = GetNodeID()
  39. if IsRestBackend() {
  40. cfg.RestBackend = "on"
  41. }
  42. cfg.AgentBackend = "off"
  43. if IsAgentBackend() {
  44. cfg.AgentBackend = "on"
  45. }
  46. cfg.ClientMode = "off"
  47. if IsClientMode() != "off" {
  48. cfg.ClientMode = IsClientMode()
  49. }
  50. cfg.DNSMode = "off"
  51. if IsDNSMode() {
  52. cfg.DNSMode = "on"
  53. }
  54. cfg.DisplayKeys = "off"
  55. if IsDisplayKeys() {
  56. cfg.DisplayKeys = "on"
  57. }
  58. cfg.DisableRemoteIPCheck = "off"
  59. if DisableRemoteIPCheck() {
  60. cfg.DisableRemoteIPCheck = "on"
  61. }
  62. cfg.Database = GetDB()
  63. cfg.Platform = GetPlatform()
  64. cfg.Version = GetVersion()
  65. // == auth config ==
  66. var authInfo = GetAuthProviderInfo()
  67. cfg.AuthProvider = authInfo[0]
  68. cfg.ClientID = authInfo[1]
  69. cfg.ClientSecret = authInfo[2]
  70. cfg.FrontendURL = GetFrontendURL()
  71. if GetRce() {
  72. cfg.RCE = "on"
  73. } else {
  74. cfg.RCE = "off"
  75. }
  76. cfg.Telemetry = Telemetry()
  77. cfg.ManageIPTables = ManageIPTables()
  78. services := strings.Join(GetPortForwardServiceList(), ",")
  79. cfg.PortForwardServices = services
  80. cfg.Server = GetServer()
  81. cfg.Verbosity = GetVerbosity()
  82. cfg.IsEE = "no"
  83. if Is_EE {
  84. cfg.IsEE = "yes"
  85. }
  86. return cfg
  87. }
  88. // GetServerConfig - gets the server config into memory from file or env
  89. func GetServerInfo() models.ServerConfig {
  90. var cfg models.ServerConfig
  91. cfg.API = GetAPIConnString()
  92. cfg.CoreDNSAddr = GetCoreDNSAddr()
  93. cfg.APIPort = GetAPIPort()
  94. cfg.MQPort = GetMQPort()
  95. cfg.DNSMode = "off"
  96. if IsDNSMode() {
  97. cfg.DNSMode = "on"
  98. }
  99. cfg.Version = GetVersion()
  100. cfg.Server = GetServer()
  101. cfg.Is_EE = GetServerConfig().IsEE == "yes"
  102. return cfg
  103. }
  104. // GetFrontendURL - gets the frontend url
  105. func GetFrontendURL() string {
  106. var frontend = ""
  107. if os.Getenv("FRONTEND_URL") != "" {
  108. frontend = os.Getenv("FRONTEND_URL")
  109. } else if config.Config.Server.FrontendURL != "" {
  110. frontend = config.Config.Server.FrontendURL
  111. }
  112. return frontend
  113. }
  114. // GetAPIConnString - gets the api connections string
  115. func GetAPIConnString() string {
  116. conn := ""
  117. if os.Getenv("SERVER_API_CONN_STRING") != "" {
  118. conn = os.Getenv("SERVER_API_CONN_STRING")
  119. } else if config.Config.Server.APIConnString != "" {
  120. conn = config.Config.Server.APIConnString
  121. }
  122. return conn
  123. }
  124. // SetVersion - set version of netmaker
  125. func SetVersion(v string) {
  126. Version = v
  127. }
  128. // GetVersion - version of netmaker
  129. func GetVersion() string {
  130. return Version
  131. }
  132. // GetDB - gets the database type
  133. func GetDB() string {
  134. database := "sqlite"
  135. if os.Getenv("DATABASE") != "" {
  136. database = os.Getenv("DATABASE")
  137. } else if config.Config.Server.Database != "" {
  138. database = config.Config.Server.Database
  139. }
  140. return database
  141. }
  142. // GetAPIHost - gets the api host
  143. func GetAPIHost() string {
  144. serverhost := "127.0.0.1"
  145. remoteip, _ := GetPublicIP()
  146. if os.Getenv("SERVER_HTTP_HOST") != "" {
  147. serverhost = os.Getenv("SERVER_HTTP_HOST")
  148. } else if config.Config.Server.APIHost != "" {
  149. serverhost = config.Config.Server.APIHost
  150. } else if os.Getenv("SERVER_HOST") != "" {
  151. serverhost = os.Getenv("SERVER_HOST")
  152. } else {
  153. if remoteip != "" {
  154. serverhost = remoteip
  155. }
  156. }
  157. return serverhost
  158. }
  159. // GetPodIP - get the pod's ip
  160. func GetPodIP() string {
  161. podip := "127.0.0.1"
  162. if os.Getenv("POD_IP") != "" {
  163. podip = os.Getenv("POD_IP")
  164. }
  165. return podip
  166. }
  167. // GetAPIPort - gets the api port
  168. func GetAPIPort() string {
  169. apiport := "8081"
  170. if os.Getenv("API_PORT") != "" {
  171. apiport = os.Getenv("API_PORT")
  172. } else if config.Config.Server.APIPort != "" {
  173. apiport = config.Config.Server.APIPort
  174. }
  175. return apiport
  176. }
  177. // GetDefaultNodeLimit - get node limit if one is set
  178. func GetDefaultNodeLimit() int32 {
  179. var limit int32
  180. limit = 999999999
  181. envlimit, err := strconv.Atoi(os.Getenv("DEFAULT_NODE_LIMIT"))
  182. if err == nil && envlimit != 0 {
  183. limit = int32(envlimit)
  184. } else if config.Config.Server.DefaultNodeLimit != 0 {
  185. limit = config.Config.Server.DefaultNodeLimit
  186. }
  187. return limit
  188. }
  189. // GetCoreDNSAddr - gets the core dns address
  190. func GetCoreDNSAddr() string {
  191. addr, _ := GetPublicIP()
  192. if os.Getenv("COREDNS_ADDR") != "" {
  193. addr = os.Getenv("COREDNS_ADDR")
  194. } else if config.Config.Server.CoreDNSAddr != "" {
  195. addr = config.Config.Server.CoreDNSAddr
  196. }
  197. return addr
  198. }
  199. // GetMQPort - gets the mq port
  200. func GetMQPort() string {
  201. port := "8883" //default
  202. if os.Getenv("MQ_PORT") != "" {
  203. port = os.Getenv("MQ_PORT")
  204. } else if config.Config.Server.MQPort != "" {
  205. port = config.Config.Server.MQPort
  206. }
  207. return port
  208. }
  209. // GetMessageQueueEndpoint - gets the message queue endpoint
  210. func GetMessageQueueEndpoint() (string, bool) {
  211. host, _ := GetPublicIP()
  212. if os.Getenv("MQ_HOST") != "" {
  213. host = os.Getenv("MQ_HOST")
  214. } else if config.Config.Server.MQHOST != "" {
  215. host = config.Config.Server.MQHOST
  216. }
  217. secure := strings.Contains(host, "mqtts") || strings.Contains(host, "ssl")
  218. return host + ":" + GetMQServerPort(), secure
  219. }
  220. // GetMasterKey - gets the configured master key of server
  221. func GetMasterKey() string {
  222. key := ""
  223. if os.Getenv("MASTER_KEY") != "" {
  224. key = os.Getenv("MASTER_KEY")
  225. } else if config.Config.Server.MasterKey != "" {
  226. key = config.Config.Server.MasterKey
  227. }
  228. return key
  229. }
  230. // GetDNSKey - gets the configured dns key of server
  231. func GetDNSKey() string {
  232. key := "secretkey"
  233. if os.Getenv("DNS_KEY") != "" {
  234. key = os.Getenv("DNS_KEY")
  235. } else if config.Config.Server.DNSKey != "" {
  236. key = config.Config.Server.DNSKey
  237. }
  238. return key
  239. }
  240. // GetAllowedOrigin - get the allowed origin
  241. func GetAllowedOrigin() string {
  242. allowedorigin := "*"
  243. if os.Getenv("CORS_ALLOWED_ORIGIN") != "" {
  244. allowedorigin = os.Getenv("CORS_ALLOWED_ORIGIN")
  245. } else if config.Config.Server.AllowedOrigin != "" {
  246. allowedorigin = config.Config.Server.AllowedOrigin
  247. }
  248. return allowedorigin
  249. }
  250. // IsRestBackend - checks if rest is on or off
  251. func IsRestBackend() bool {
  252. isrest := true
  253. if os.Getenv("REST_BACKEND") != "" {
  254. if os.Getenv("REST_BACKEND") == "off" {
  255. isrest = false
  256. }
  257. } else if config.Config.Server.RestBackend != "" {
  258. if config.Config.Server.RestBackend == "off" {
  259. isrest = false
  260. }
  261. }
  262. return isrest
  263. }
  264. // IsMetricsExporter - checks if metrics exporter is on or off
  265. func IsMetricsExporter() bool {
  266. export := false
  267. if os.Getenv("METRICS_EXPORTER") != "" {
  268. if os.Getenv("METRICS_EXPORTER") == "on" {
  269. export = true
  270. }
  271. } else if config.Config.Server.MetricsExporter != "" {
  272. if config.Config.Server.MetricsExporter == "on" {
  273. export = true
  274. }
  275. }
  276. return export
  277. }
  278. // IsAgentBackend - checks if agent backed is on or off
  279. func IsAgentBackend() bool {
  280. isagent := true
  281. if os.Getenv("AGENT_BACKEND") != "" {
  282. if os.Getenv("AGENT_BACKEND") == "off" {
  283. isagent = false
  284. }
  285. } else if config.Config.Server.AgentBackend != "" {
  286. if config.Config.Server.AgentBackend == "off" {
  287. isagent = false
  288. }
  289. }
  290. return isagent
  291. }
  292. // IsMessageQueueBackend - checks if message queue is on or off
  293. func IsMessageQueueBackend() bool {
  294. ismessagequeue := true
  295. if os.Getenv("MESSAGEQUEUE_BACKEND") != "" {
  296. if os.Getenv("MESSAGEQUEUE_BACKEND") == "off" {
  297. ismessagequeue = false
  298. }
  299. } else if config.Config.Server.MessageQueueBackend != "" {
  300. if config.Config.Server.MessageQueueBackend == "off" {
  301. ismessagequeue = false
  302. }
  303. }
  304. return ismessagequeue
  305. }
  306. // IsClientMode - checks if it should run in client mode
  307. func IsClientMode() string {
  308. isclient := "on"
  309. if os.Getenv("CLIENT_MODE") == "off" {
  310. isclient = "off"
  311. }
  312. if config.Config.Server.ClientMode == "off" {
  313. isclient = "off"
  314. }
  315. return isclient
  316. }
  317. // Telemetry - checks if telemetry data should be sent
  318. func Telemetry() string {
  319. telemetry := "on"
  320. if os.Getenv("TELEMETRY") == "off" {
  321. telemetry = "off"
  322. }
  323. if config.Config.Server.Telemetry == "off" {
  324. telemetry = "off"
  325. }
  326. return telemetry
  327. }
  328. // ManageIPTables - checks if iptables should be manipulated on host
  329. func ManageIPTables() string {
  330. manage := "on"
  331. if os.Getenv("MANAGE_IPTABLES") == "off" {
  332. manage = "off"
  333. }
  334. if config.Config.Server.ManageIPTables == "off" {
  335. manage = "off"
  336. }
  337. return manage
  338. }
  339. // GetServer - gets the server name
  340. func GetServer() string {
  341. server := ""
  342. if os.Getenv("SERVER_NAME") != "" {
  343. server = os.Getenv("SERVER_NAME")
  344. } else if config.Config.Server.Server != "" {
  345. server = config.Config.Server.Server
  346. }
  347. return server
  348. }
  349. func GetVerbosity() int32 {
  350. var verbosity = 0
  351. var err error
  352. if os.Getenv("VERBOSITY") != "" {
  353. verbosity, err = strconv.Atoi(os.Getenv("VERBOSITY"))
  354. if err != nil {
  355. verbosity = 0
  356. }
  357. } else if config.Config.Server.Verbosity != 0 {
  358. verbosity = int(config.Config.Server.Verbosity)
  359. }
  360. if verbosity < 0 || verbosity > 4 {
  361. verbosity = 0
  362. }
  363. return int32(verbosity)
  364. }
  365. // IsDNSMode - should it run with DNS
  366. func IsDNSMode() bool {
  367. isdns := true
  368. if os.Getenv("DNS_MODE") != "" {
  369. if os.Getenv("DNS_MODE") == "off" {
  370. isdns = false
  371. }
  372. } else if config.Config.Server.DNSMode != "" {
  373. if config.Config.Server.DNSMode == "off" {
  374. isdns = false
  375. }
  376. }
  377. return isdns
  378. }
  379. // IsDisplayKeys - should server be able to display keys?
  380. func IsDisplayKeys() bool {
  381. isdisplay := true
  382. if os.Getenv("DISPLAY_KEYS") != "" {
  383. if os.Getenv("DISPLAY_KEYS") == "off" {
  384. isdisplay = false
  385. }
  386. } else if config.Config.Server.DisplayKeys != "" {
  387. if config.Config.Server.DisplayKeys == "off" {
  388. isdisplay = false
  389. }
  390. }
  391. return isdisplay
  392. }
  393. // DisableRemoteIPCheck - disable the remote ip check
  394. func DisableRemoteIPCheck() bool {
  395. disabled := false
  396. if os.Getenv("DISABLE_REMOTE_IP_CHECK") != "" {
  397. if os.Getenv("DISABLE_REMOTE_IP_CHECK") == "on" {
  398. disabled = true
  399. }
  400. } else if config.Config.Server.DisableRemoteIPCheck != "" {
  401. if config.Config.Server.DisableRemoteIPCheck == "on" {
  402. disabled = true
  403. }
  404. }
  405. return disabled
  406. }
  407. // GetPublicIP - gets public ip
  408. func GetPublicIP() (string, error) {
  409. endpoint := ""
  410. var err error
  411. iplist := []string{"https://ip.server.gravitl.com", "https://ifconfig.me", "https://api.ipify.org", "https://ipinfo.io/ip"}
  412. publicIpService := os.Getenv("PUBLIC_IP_SERVICE")
  413. if publicIpService != "" {
  414. // prepend the user-specified service so it's checked first
  415. iplist = append([]string{publicIpService}, iplist...)
  416. } else if config.Config.Server.PublicIPService != "" {
  417. publicIpService = config.Config.Server.PublicIPService
  418. // prepend the user-specified service so it's checked first
  419. iplist = append([]string{publicIpService}, iplist...)
  420. }
  421. for _, ipserver := range iplist {
  422. client := &http.Client{
  423. Timeout: time.Second * 10,
  424. }
  425. resp, err := client.Get(ipserver)
  426. if err != nil {
  427. continue
  428. }
  429. defer resp.Body.Close()
  430. if resp.StatusCode == http.StatusOK {
  431. bodyBytes, err := io.ReadAll(resp.Body)
  432. if err != nil {
  433. continue
  434. }
  435. endpoint = string(bodyBytes)
  436. break
  437. }
  438. }
  439. if err == nil && endpoint == "" {
  440. err = errors.New("public address not found")
  441. }
  442. return endpoint, err
  443. }
  444. // GetPlatform - get the system type of server
  445. func GetPlatform() string {
  446. platform := "linux"
  447. if os.Getenv("PLATFORM") != "" {
  448. platform = os.Getenv("PLATFORM")
  449. } else if config.Config.Server.Platform != "" {
  450. platform = config.Config.Server.SQLConn
  451. }
  452. return platform
  453. }
  454. // GetIPForwardServiceList - get the list of services that the server should be forwarding
  455. func GetPortForwardServiceList() []string {
  456. //services := "mq,dns,ssh"
  457. services := ""
  458. if os.Getenv("PORT_FORWARD_SERVICES") != "" {
  459. services = os.Getenv("PORT_FORWARD_SERVICES")
  460. } else if config.Config.Server.PortForwardServices != "" {
  461. services = config.Config.Server.PortForwardServices
  462. }
  463. serviceSlice := strings.Split(services, ",")
  464. return serviceSlice
  465. }
  466. // GetSQLConn - get the sql connection string
  467. func GetSQLConn() string {
  468. sqlconn := "http://"
  469. if os.Getenv("SQL_CONN") != "" {
  470. sqlconn = os.Getenv("SQL_CONN")
  471. } else if config.Config.Server.SQLConn != "" {
  472. sqlconn = config.Config.Server.SQLConn
  473. }
  474. return sqlconn
  475. }
  476. // IsHostNetwork - checks if running on host network
  477. func IsHostNetwork() bool {
  478. ishost := false
  479. if os.Getenv("HOST_NETWORK") == "on" {
  480. ishost = true
  481. } else if config.Config.Server.HostNetwork == "on" {
  482. ishost = true
  483. }
  484. return ishost
  485. }
  486. // GetNodeID - gets the node id
  487. func GetNodeID() string {
  488. var id string
  489. var err error
  490. // id = getMacAddr()
  491. if os.Getenv("NODE_ID") != "" {
  492. id = os.Getenv("NODE_ID")
  493. } else if config.Config.Server.NodeID != "" {
  494. id = config.Config.Server.NodeID
  495. } else {
  496. id, err = os.Hostname()
  497. if err != nil {
  498. return ""
  499. }
  500. }
  501. return id
  502. }
  503. func SetNodeID(id string) {
  504. config.Config.Server.NodeID = id
  505. }
  506. // GetServerCheckinInterval - gets the server check-in time
  507. func GetServerCheckinInterval() int64 {
  508. var t = int64(5)
  509. var envt, _ = strconv.Atoi(os.Getenv("SERVER_CHECKIN_INTERVAL"))
  510. if envt > 0 {
  511. t = int64(envt)
  512. } else if config.Config.Server.ServerCheckinInterval > 0 {
  513. t = config.Config.Server.ServerCheckinInterval
  514. }
  515. return t
  516. }
  517. // GetAuthProviderInfo = gets the oauth provider info
  518. func GetAuthProviderInfo() (pi []string) {
  519. var authProvider = ""
  520. defer func() {
  521. if authProvider == "oidc" {
  522. if os.Getenv("OIDC_ISSUER") != "" {
  523. pi = append(pi, os.Getenv("OIDC_ISSUER"))
  524. } else if config.Config.Server.OIDCIssuer != "" {
  525. pi = append(pi, config.Config.Server.OIDCIssuer)
  526. } else {
  527. pi = []string{"", "", ""}
  528. }
  529. }
  530. }()
  531. if os.Getenv("AUTH_PROVIDER") != "" && os.Getenv("CLIENT_ID") != "" && os.Getenv("CLIENT_SECRET") != "" {
  532. authProvider = strings.ToLower(os.Getenv("AUTH_PROVIDER"))
  533. if authProvider == "google" || authProvider == "azure-ad" || authProvider == "github" || authProvider == "oidc" {
  534. return []string{authProvider, os.Getenv("CLIENT_ID"), os.Getenv("CLIENT_SECRET")}
  535. } else {
  536. authProvider = ""
  537. }
  538. } else if config.Config.Server.AuthProvider != "" && config.Config.Server.ClientID != "" && config.Config.Server.ClientSecret != "" {
  539. authProvider = strings.ToLower(config.Config.Server.AuthProvider)
  540. if authProvider == "google" || authProvider == "azure-ad" || authProvider == "github" || authProvider == "oidc" {
  541. return []string{authProvider, config.Config.Server.ClientID, config.Config.Server.ClientSecret}
  542. }
  543. }
  544. return []string{"", "", ""}
  545. }
  546. // GetAzureTenant - retrieve the azure tenant ID from env variable or config file
  547. func GetAzureTenant() string {
  548. var azureTenant = ""
  549. if os.Getenv("AZURE_TENANT") != "" {
  550. azureTenant = os.Getenv("AZURE_TENANT")
  551. } else if config.Config.Server.AzureTenant != "" {
  552. azureTenant = config.Config.Server.AzureTenant
  553. }
  554. return azureTenant
  555. }
  556. // GetRce - sees if Rce is enabled, off by default
  557. func GetRce() bool {
  558. return os.Getenv("RCE") == "on" || config.Config.Server.RCE == "on"
  559. }
  560. // GetMQServerPort - get mq port for server
  561. func GetMQServerPort() string {
  562. port := "1883" //default
  563. if os.Getenv("MQ_SERVER_PORT") != "" {
  564. port = os.Getenv("MQ_SERVER_PORT")
  565. } else if config.Config.Server.MQServerPort != "" {
  566. port = config.Config.Server.MQServerPort
  567. }
  568. return port
  569. }
  570. // IsBasicAuthEnabled - checks if basic auth has been configured to be turned off
  571. func IsBasicAuthEnabled() bool {
  572. var enabled = true //default
  573. if os.Getenv("BASIC_AUTH") != "" {
  574. enabled = os.Getenv("BASIC_AUTH") == "yes"
  575. } else if config.Config.Server.BasicAuth != "" {
  576. enabled = config.Config.Server.BasicAuth == "yes"
  577. }
  578. return enabled
  579. }
  580. // GetLicenseKey - retrieves pro license value from env or conf files
  581. func GetLicenseKey() string {
  582. licenseKeyValue := os.Getenv("LICENSE_KEY")
  583. if licenseKeyValue == "" {
  584. licenseKeyValue = config.Config.Server.LicenseValue
  585. }
  586. return licenseKeyValue
  587. }
  588. // GetNetmakerAccountID - get's the associated, Netmaker, account ID to verify ownership
  589. func GetNetmakerAccountID() string {
  590. netmakerAccountID := os.Getenv("NETMAKER_ACCOUNT_ID")
  591. if netmakerAccountID == "" {
  592. netmakerAccountID = config.Config.Server.LicenseValue
  593. }
  594. return netmakerAccountID
  595. }