gateway.go 6.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221
  1. package logic
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "strings"
  6. "time"
  7. "github.com/gravitl/netmaker/database"
  8. "github.com/gravitl/netmaker/logger"
  9. "github.com/gravitl/netmaker/models"
  10. )
  11. // CreateEgressGateway - creates an egress gateway
  12. func CreateEgressGateway(gateway models.EgressGatewayRequest) (models.Node, error) {
  13. node, err := GetNodeByMacAddress(gateway.NetID, gateway.NodeID)
  14. if node.OS == "windows" || node.OS == "macos" { // add in darwin later
  15. return models.Node{}, errors.New(node.OS + " is unsupported for egress gateways")
  16. }
  17. if err != nil {
  18. return models.Node{}, err
  19. }
  20. err = ValidateEgressGateway(gateway)
  21. if err != nil {
  22. return models.Node{}, err
  23. }
  24. node.IsEgressGateway = "yes"
  25. node.EgressGatewayRanges = gateway.Ranges
  26. postUpCmd := "iptables -A FORWARD -i " + node.Interface + " -j ACCEPT; iptables -t nat -A POSTROUTING -o " + gateway.Interface + " -j MASQUERADE"
  27. postDownCmd := "iptables -D FORWARD -i " + node.Interface + " -j ACCEPT; iptables -t nat -D POSTROUTING -o " + gateway.Interface + " -j MASQUERADE"
  28. if gateway.PostUp != "" {
  29. postUpCmd = gateway.PostUp
  30. }
  31. if gateway.PostDown != "" {
  32. postDownCmd = gateway.PostDown
  33. }
  34. if node.PostUp != "" {
  35. if !strings.Contains(node.PostUp, postUpCmd) {
  36. postUpCmd = node.PostUp + "; " + postUpCmd
  37. }
  38. }
  39. if node.PostDown != "" {
  40. if !strings.Contains(node.PostDown, postDownCmd) {
  41. postDownCmd = node.PostDown + "; " + postDownCmd
  42. }
  43. }
  44. key, err := GetRecordKey(gateway.NodeID, gateway.NetID)
  45. if err != nil {
  46. return node, err
  47. }
  48. node.PostUp = postUpCmd
  49. node.PostDown = postDownCmd
  50. node.SetLastModified()
  51. node.PullChanges = "yes"
  52. nodeData, err := json.Marshal(&node)
  53. if err != nil {
  54. return node, err
  55. }
  56. if err = database.Insert(key, string(nodeData), database.NODES_TABLE_NAME); err != nil {
  57. return models.Node{}, err
  58. }
  59. if err = NetworkNodesUpdatePullChanges(node.Network); err != nil {
  60. return models.Node{}, err
  61. }
  62. return node, nil
  63. }
  64. func ValidateEgressGateway(gateway models.EgressGatewayRequest) error {
  65. var err error
  66. empty := len(gateway.Ranges) == 0
  67. if empty {
  68. err = errors.New("IP Ranges Cannot Be Empty")
  69. }
  70. empty = gateway.Interface == ""
  71. if empty {
  72. err = errors.New("Interface cannot be empty")
  73. }
  74. return err
  75. }
  76. // DeleteEgressGateway - deletes egress from node
  77. func DeleteEgressGateway(network, macaddress string) (models.Node, error) {
  78. node, err := GetNodeByMacAddress(network, macaddress)
  79. if err != nil {
  80. return models.Node{}, err
  81. }
  82. node.IsEgressGateway = "no"
  83. node.EgressGatewayRanges = []string{}
  84. node.PostUp = ""
  85. node.PostDown = ""
  86. if node.IsIngressGateway == "yes" { // check if node is still an ingress gateway before completely deleting postdown/up rules
  87. node.PostUp = "iptables -A FORWARD -i " + node.Interface + " -j ACCEPT; iptables -t nat -A POSTROUTING -o " + node.Interface + " -j MASQUERADE"
  88. node.PostDown = "iptables -D FORWARD -i " + node.Interface + " -j ACCEPT; iptables -t nat -D POSTROUTING -o " + node.Interface + " -j MASQUERADE"
  89. }
  90. node.SetLastModified()
  91. node.PullChanges = "yes"
  92. key, err := GetRecordKey(node.MacAddress, node.Network)
  93. if err != nil {
  94. return models.Node{}, err
  95. }
  96. data, err := json.Marshal(&node)
  97. if err != nil {
  98. return models.Node{}, err
  99. }
  100. if err = database.Insert(key, string(data), database.NODES_TABLE_NAME); err != nil {
  101. return models.Node{}, err
  102. }
  103. if err = NetworkNodesUpdatePullChanges(network); err != nil {
  104. return models.Node{}, err
  105. }
  106. return node, nil
  107. }
  108. // CreateIngressGateway - creates an ingress gateway
  109. func CreateIngressGateway(netid string, macaddress string) (models.Node, error) {
  110. node, err := GetNodeByMacAddress(netid, macaddress)
  111. if node.OS == "windows" || node.OS == "macos" { // add in darwin later
  112. return models.Node{}, errors.New(node.OS + " is unsupported for ingress gateways")
  113. }
  114. if err != nil {
  115. return models.Node{}, err
  116. }
  117. network, err := GetParentNetwork(netid)
  118. if err != nil {
  119. return models.Node{}, err
  120. }
  121. node.IsIngressGateway = "yes"
  122. node.IngressGatewayRange = network.AddressRange
  123. postUpCmd := "iptables -A FORWARD -i " + node.Interface + " -j ACCEPT; iptables -t nat -A POSTROUTING -o " + node.Interface + " -j MASQUERADE"
  124. postDownCmd := "iptables -D FORWARD -i " + node.Interface + " -j ACCEPT; iptables -t nat -D POSTROUTING -o " + node.Interface + " -j MASQUERADE"
  125. if node.PostUp != "" {
  126. if !strings.Contains(node.PostUp, postUpCmd) {
  127. postUpCmd = node.PostUp + "; " + postUpCmd
  128. }
  129. }
  130. if node.PostDown != "" {
  131. if !strings.Contains(node.PostDown, postDownCmd) {
  132. postDownCmd = node.PostDown + "; " + postDownCmd
  133. }
  134. }
  135. node.SetLastModified()
  136. node.PostUp = postUpCmd
  137. node.PostDown = postDownCmd
  138. node.PullChanges = "yes"
  139. node.UDPHolePunch = "no"
  140. key, err := GetRecordKey(node.MacAddress, node.Network)
  141. if err != nil {
  142. return models.Node{}, err
  143. }
  144. data, err := json.Marshal(&node)
  145. if err != nil {
  146. return models.Node{}, err
  147. }
  148. err = database.Insert(key, string(data), database.NODES_TABLE_NAME)
  149. if err != nil {
  150. return models.Node{}, err
  151. }
  152. err = SetNetworkNodesLastModified(netid)
  153. return node, err
  154. }
  155. // DeleteIngressGateway - deletes an ingress gateway
  156. func DeleteIngressGateway(networkName string, macaddress string) (models.Node, error) {
  157. node, err := GetNodeByMacAddress(networkName, macaddress)
  158. if err != nil {
  159. return models.Node{}, err
  160. }
  161. network, err := GetParentNetwork(networkName)
  162. if err != nil {
  163. return models.Node{}, err
  164. }
  165. // delete ext clients belonging to ingress gateway
  166. if err = DeleteGatewayExtClients(macaddress, networkName); err != nil {
  167. return models.Node{}, err
  168. }
  169. node.UDPHolePunch = network.DefaultUDPHolePunch
  170. node.LastModified = time.Now().Unix()
  171. node.IsIngressGateway = "no"
  172. node.IngressGatewayRange = ""
  173. node.PullChanges = "yes"
  174. key, err := GetRecordKey(node.MacAddress, node.Network)
  175. if err != nil {
  176. return models.Node{}, err
  177. }
  178. data, err := json.Marshal(&node)
  179. if err != nil {
  180. return models.Node{}, err
  181. }
  182. err = database.Insert(key, string(data), database.NODES_TABLE_NAME)
  183. if err != nil {
  184. return models.Node{}, err
  185. }
  186. err = SetNetworkNodesLastModified(networkName)
  187. return node, err
  188. }
  189. // DeleteGatewayExtClients - deletes ext clients based on gateway (mac) of ingress node and network
  190. func DeleteGatewayExtClients(gatewayID string, networkName string) error {
  191. currentExtClients, err := GetNetworkExtClients(networkName)
  192. if err != nil && !database.IsEmptyRecord(err) {
  193. return err
  194. }
  195. for _, extClient := range currentExtClients {
  196. if extClient.IngressGatewayID == gatewayID {
  197. if err = DeleteExtClient(networkName, extClient.ClientID); err != nil {
  198. logger.Log(1, "failed to remove ext client", extClient.ClientID)
  199. continue
  200. }
  201. }
  202. }
  203. return nil
  204. }