serverconf.go 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602
  1. package servercfg
  2. import (
  3. "errors"
  4. "io"
  5. "net/http"
  6. "os"
  7. "strconv"
  8. "strings"
  9. "time"
  10. "github.com/gravitl/netmaker/config"
  11. "github.com/gravitl/netmaker/logger"
  12. "github.com/gravitl/netmaker/models"
  13. )
  14. var (
  15. Version = "dev"
  16. )
  17. // SetHost - sets the host ip
  18. func SetHost() error {
  19. remoteip, err := GetPublicIP()
  20. if err != nil {
  21. return err
  22. }
  23. os.Setenv("SERVER_HOST", remoteip)
  24. return nil
  25. }
  26. // GetServerConfig - gets the server config into memory from file or env
  27. func GetServerConfig() config.ServerConfig {
  28. var cfg config.ServerConfig
  29. cfg.APIConnString = GetAPIConnString()
  30. cfg.CoreDNSAddr = GetCoreDNSAddr()
  31. cfg.APIHost = GetAPIHost()
  32. cfg.APIPort = GetAPIPort()
  33. cfg.MQPort = GetMQPort()
  34. cfg.MasterKey = "(hidden)"
  35. cfg.DNSKey = "(hidden)"
  36. cfg.AllowedOrigin = GetAllowedOrigin()
  37. cfg.RestBackend = "off"
  38. cfg.NodeID = GetNodeID()
  39. if IsRestBackend() {
  40. cfg.RestBackend = "on"
  41. }
  42. cfg.AgentBackend = "off"
  43. if IsAgentBackend() {
  44. cfg.AgentBackend = "on"
  45. }
  46. cfg.ClientMode = "off"
  47. if IsClientMode() != "off" {
  48. cfg.ClientMode = IsClientMode()
  49. }
  50. cfg.DNSMode = "off"
  51. if IsDNSMode() {
  52. cfg.DNSMode = "on"
  53. }
  54. cfg.DisplayKeys = "off"
  55. if IsDisplayKeys() {
  56. cfg.DisplayKeys = "on"
  57. }
  58. cfg.DisableRemoteIPCheck = "off"
  59. if DisableRemoteIPCheck() {
  60. cfg.DisableRemoteIPCheck = "on"
  61. }
  62. cfg.Database = GetDB()
  63. cfg.Platform = GetPlatform()
  64. cfg.Version = GetVersion()
  65. // == auth config ==
  66. var authInfo = GetAuthProviderInfo()
  67. cfg.AuthProvider = authInfo[0]
  68. cfg.ClientID = authInfo[1]
  69. cfg.ClientSecret = authInfo[2]
  70. cfg.FrontendURL = GetFrontendURL()
  71. if GetRce() {
  72. cfg.RCE = "on"
  73. } else {
  74. cfg.RCE = "off"
  75. }
  76. cfg.Telemetry = Telemetry()
  77. cfg.ManageIPTables = ManageIPTables()
  78. services := strings.Join(GetPortForwardServiceList(), ",")
  79. cfg.PortForwardServices = services
  80. cfg.Server = GetServer()
  81. cfg.Verbosity = GetVerbosity()
  82. return cfg
  83. }
  84. // GetServerConfig - gets the server config into memory from file or env
  85. func GetServerInfo() models.ServerConfig {
  86. var cfg models.ServerConfig
  87. cfg.API = GetAPIConnString()
  88. cfg.CoreDNSAddr = GetCoreDNSAddr()
  89. cfg.APIPort = GetAPIPort()
  90. cfg.MQPort = GetMQPort()
  91. cfg.DNSMode = "off"
  92. if IsDNSMode() {
  93. cfg.DNSMode = "on"
  94. }
  95. cfg.Version = GetVersion()
  96. cfg.Server = GetServer()
  97. return cfg
  98. }
  99. // GetFrontendURL - gets the frontend url
  100. func GetFrontendURL() string {
  101. var frontend = ""
  102. if os.Getenv("FRONTEND_URL") != "" {
  103. frontend = os.Getenv("FRONTEND_URL")
  104. } else if config.Config.Server.FrontendURL != "" {
  105. frontend = config.Config.Server.FrontendURL
  106. }
  107. return frontend
  108. }
  109. // GetAPIConnString - gets the api connections string
  110. func GetAPIConnString() string {
  111. conn := ""
  112. if os.Getenv("SERVER_API_CONN_STRING") != "" {
  113. conn = os.Getenv("SERVER_API_CONN_STRING")
  114. } else if config.Config.Server.APIConnString != "" {
  115. conn = config.Config.Server.APIConnString
  116. }
  117. return conn
  118. }
  119. // SetVersion - set version of netmaker
  120. func SetVersion(v string) {
  121. Version = v
  122. }
  123. // GetVersion - version of netmaker
  124. func GetVersion() string {
  125. return Version
  126. }
  127. // GetDB - gets the database type
  128. func GetDB() string {
  129. database := "sqlite"
  130. if os.Getenv("DATABASE") != "" {
  131. database = os.Getenv("DATABASE")
  132. } else if config.Config.Server.Database != "" {
  133. database = config.Config.Server.Database
  134. }
  135. return database
  136. }
  137. // GetAPIHost - gets the api host
  138. func GetAPIHost() string {
  139. serverhost := "127.0.0.1"
  140. remoteip, _ := GetPublicIP()
  141. if os.Getenv("SERVER_HTTP_HOST") != "" {
  142. serverhost = os.Getenv("SERVER_HTTP_HOST")
  143. } else if config.Config.Server.APIHost != "" {
  144. serverhost = config.Config.Server.APIHost
  145. } else if os.Getenv("SERVER_HOST") != "" {
  146. serverhost = os.Getenv("SERVER_HOST")
  147. } else {
  148. if remoteip != "" {
  149. serverhost = remoteip
  150. }
  151. }
  152. return serverhost
  153. }
  154. // GetPodIP - get the pod's ip
  155. func GetPodIP() string {
  156. podip := "127.0.0.1"
  157. if os.Getenv("POD_IP") != "" {
  158. podip = os.Getenv("POD_IP")
  159. }
  160. return podip
  161. }
  162. // GetAPIPort - gets the api port
  163. func GetAPIPort() string {
  164. apiport := "8081"
  165. if os.Getenv("API_PORT") != "" {
  166. apiport = os.Getenv("API_PORT")
  167. } else if config.Config.Server.APIPort != "" {
  168. apiport = config.Config.Server.APIPort
  169. }
  170. return apiport
  171. }
  172. // GetDefaultNodeLimit - get node limit if one is set
  173. func GetDefaultNodeLimit() int32 {
  174. var limit int32
  175. limit = 999999999
  176. envlimit, err := strconv.Atoi(os.Getenv("DEFAULT_NODE_LIMIT"))
  177. if err == nil && envlimit != 0 {
  178. limit = int32(envlimit)
  179. } else if config.Config.Server.DefaultNodeLimit != 0 {
  180. limit = config.Config.Server.DefaultNodeLimit
  181. }
  182. return limit
  183. }
  184. // GetCoreDNSAddr - gets the core dns address
  185. func GetCoreDNSAddr() string {
  186. addr, _ := GetPublicIP()
  187. if os.Getenv("COREDNS_ADDR") != "" {
  188. addr = os.Getenv("COREDNS_ADDR")
  189. } else if config.Config.Server.CoreDNSAddr != "" {
  190. addr = config.Config.Server.CoreDNSAddr
  191. }
  192. return addr
  193. }
  194. // GetMQPort - gets the mq port
  195. func GetMQPort() string {
  196. port := "8883" //default
  197. if os.Getenv("MQ_PORT") != "" {
  198. port = os.Getenv("MQ_PORT")
  199. } else if config.Config.Server.MQPort != "" {
  200. port = config.Config.Server.MQPort
  201. }
  202. return port
  203. }
  204. // GetMessageQueueEndpoint - gets the message queue endpoint
  205. func GetMessageQueueEndpoint() (string, bool) {
  206. host, _ := GetPublicIP()
  207. if os.Getenv("MQ_HOST") != "" {
  208. host = os.Getenv("MQ_HOST")
  209. } else if config.Config.Server.MQHOST != "" {
  210. host = config.Config.Server.MQHOST
  211. }
  212. secure := strings.Contains(host, "mqtts") || strings.Contains(host, "ssl")
  213. return host + ":" + GetMQServerPort(), secure
  214. }
  215. // GetMasterKey - gets the configured master key of server
  216. func GetMasterKey() string {
  217. key := ""
  218. if os.Getenv("MASTER_KEY") != "" {
  219. key = os.Getenv("MASTER_KEY")
  220. } else if config.Config.Server.MasterKey != "" {
  221. key = config.Config.Server.MasterKey
  222. }
  223. return key
  224. }
  225. // GetDNSKey - gets the configured dns key of server
  226. func GetDNSKey() string {
  227. key := "secretkey"
  228. if os.Getenv("DNS_KEY") != "" {
  229. key = os.Getenv("DNS_KEY")
  230. } else if config.Config.Server.DNSKey != "" {
  231. key = config.Config.Server.DNSKey
  232. }
  233. return key
  234. }
  235. // GetAllowedOrigin - get the allowed origin
  236. func GetAllowedOrigin() string {
  237. allowedorigin := "*"
  238. if os.Getenv("CORS_ALLOWED_ORIGIN") != "" {
  239. allowedorigin = os.Getenv("CORS_ALLOWED_ORIGIN")
  240. } else if config.Config.Server.AllowedOrigin != "" {
  241. allowedorigin = config.Config.Server.AllowedOrigin
  242. }
  243. return allowedorigin
  244. }
  245. // IsRestBackend - checks if rest is on or off
  246. func IsRestBackend() bool {
  247. isrest := true
  248. if os.Getenv("REST_BACKEND") != "" {
  249. if os.Getenv("REST_BACKEND") == "off" {
  250. isrest = false
  251. }
  252. } else if config.Config.Server.RestBackend != "" {
  253. if config.Config.Server.RestBackend == "off" {
  254. isrest = false
  255. }
  256. }
  257. return isrest
  258. }
  259. // IsAgentBackend - checks if agent backed is on or off
  260. func IsAgentBackend() bool {
  261. isagent := true
  262. if os.Getenv("AGENT_BACKEND") != "" {
  263. if os.Getenv("AGENT_BACKEND") == "off" {
  264. isagent = false
  265. }
  266. } else if config.Config.Server.AgentBackend != "" {
  267. if config.Config.Server.AgentBackend == "off" {
  268. isagent = false
  269. }
  270. }
  271. return isagent
  272. }
  273. // IsMessageQueueBackend - checks if message queue is on or off
  274. func IsMessageQueueBackend() bool {
  275. ismessagequeue := true
  276. if os.Getenv("MESSAGEQUEUE_BACKEND") != "" {
  277. if os.Getenv("MESSAGEQUEUE_BACKEND") == "off" {
  278. ismessagequeue = false
  279. }
  280. } else if config.Config.Server.MessageQueueBackend != "" {
  281. if config.Config.Server.MessageQueueBackend == "off" {
  282. ismessagequeue = false
  283. }
  284. }
  285. return ismessagequeue
  286. }
  287. // IsClientMode - checks if it should run in client mode
  288. func IsClientMode() string {
  289. isclient := "on"
  290. if os.Getenv("CLIENT_MODE") == "off" {
  291. isclient = "off"
  292. }
  293. if config.Config.Server.ClientMode == "off" {
  294. isclient = "off"
  295. }
  296. return isclient
  297. }
  298. // Telemetry - checks if telemetry data should be sent
  299. func Telemetry() string {
  300. telemetry := "on"
  301. if os.Getenv("TELEMETRY") == "off" {
  302. telemetry = "off"
  303. }
  304. if config.Config.Server.Telemetry == "off" {
  305. telemetry = "off"
  306. }
  307. return telemetry
  308. }
  309. // ManageIPTables - checks if iptables should be manipulated on host
  310. func ManageIPTables() string {
  311. manage := "on"
  312. if os.Getenv("MANAGE_IPTABLES") == "off" {
  313. manage = "off"
  314. }
  315. if config.Config.Server.ManageIPTables == "off" {
  316. manage = "off"
  317. }
  318. return manage
  319. }
  320. // GetServer - gets the server name
  321. func GetServer() string {
  322. server := ""
  323. if os.Getenv("SERVER_NAME") != "" {
  324. server = os.Getenv("SERVER_NAME")
  325. } else if config.Config.Server.Server != "" {
  326. server = config.Config.Server.Server
  327. }
  328. return server
  329. }
  330. func GetVerbosity() int32 {
  331. var verbosity = 0
  332. var err error
  333. if os.Getenv("VERBOSITY") != "" {
  334. verbosity, err = strconv.Atoi(os.Getenv("VERBOSITY"))
  335. if err != nil {
  336. verbosity = 0
  337. }
  338. } else if config.Config.Server.Verbosity != 0 {
  339. verbosity = int(config.Config.Server.Verbosity)
  340. }
  341. if verbosity < 0 || verbosity > 4 {
  342. verbosity = 0
  343. }
  344. return int32(verbosity)
  345. }
  346. // IsDNSMode - should it run with DNS
  347. func IsDNSMode() bool {
  348. isdns := true
  349. if os.Getenv("DNS_MODE") != "" {
  350. if os.Getenv("DNS_MODE") == "off" {
  351. isdns = false
  352. }
  353. } else if config.Config.Server.DNSMode != "" {
  354. if config.Config.Server.DNSMode == "off" {
  355. isdns = false
  356. }
  357. }
  358. return isdns
  359. }
  360. // IsDisplayKeys - should server be able to display keys?
  361. func IsDisplayKeys() bool {
  362. isdisplay := true
  363. if os.Getenv("DISPLAY_KEYS") != "" {
  364. if os.Getenv("DISPLAY_KEYS") == "off" {
  365. isdisplay = false
  366. }
  367. } else if config.Config.Server.DisplayKeys != "" {
  368. if config.Config.Server.DisplayKeys == "off" {
  369. isdisplay = false
  370. }
  371. }
  372. return isdisplay
  373. }
  374. // DisableRemoteIPCheck - disable the remote ip check
  375. func DisableRemoteIPCheck() bool {
  376. disabled := false
  377. if os.Getenv("DISABLE_REMOTE_IP_CHECK") != "" {
  378. if os.Getenv("DISABLE_REMOTE_IP_CHECK") == "on" {
  379. disabled = true
  380. }
  381. } else if config.Config.Server.DisableRemoteIPCheck != "" {
  382. if config.Config.Server.DisableRemoteIPCheck == "on" {
  383. disabled = true
  384. }
  385. }
  386. return disabled
  387. }
  388. // GetPublicIP - gets public ip
  389. func GetPublicIP() (string, error) {
  390. endpoint := ""
  391. var err error
  392. iplist := []string{"https://ip.server.gravitl.com", "https://ifconfig.me", "https://api.ipify.org", "https://ipinfo.io/ip"}
  393. publicIpService := os.Getenv("PUBLIC_IP_SERVICE")
  394. if publicIpService != "" {
  395. logger.Log(3, "User provided public IP service is", publicIpService)
  396. // prepend the user-specified service so it's checked first
  397. iplist = append([]string{publicIpService}, iplist...)
  398. }
  399. for _, ipserver := range iplist {
  400. logger.Log(3, "Running public IP check with service", ipserver)
  401. client := &http.Client{
  402. Timeout: time.Second * 10,
  403. }
  404. resp, err := client.Get(ipserver)
  405. if err != nil {
  406. continue
  407. }
  408. defer resp.Body.Close()
  409. if resp.StatusCode == http.StatusOK {
  410. bodyBytes, err := io.ReadAll(resp.Body)
  411. if err != nil {
  412. continue
  413. }
  414. endpoint = string(bodyBytes)
  415. logger.Log(3, "Public IP address is", endpoint)
  416. break
  417. }
  418. }
  419. if err == nil && endpoint == "" {
  420. err = errors.New("public address not found")
  421. }
  422. return endpoint, err
  423. }
  424. // GetPlatform - get the system type of server
  425. func GetPlatform() string {
  426. platform := "linux"
  427. if os.Getenv("PLATFORM") != "" {
  428. platform = os.Getenv("PLATFORM")
  429. } else if config.Config.Server.Platform != "" {
  430. platform = config.Config.Server.SQLConn
  431. }
  432. return platform
  433. }
  434. // GetIPForwardServiceList - get the list of services that the server should be forwarding
  435. func GetPortForwardServiceList() []string {
  436. //services := "mq,dns,ssh"
  437. services := ""
  438. if os.Getenv("PORT_FORWARD_SERVICES") != "" {
  439. services = os.Getenv("PORT_FORWARD_SERVICES")
  440. } else if config.Config.Server.PortForwardServices != "" {
  441. services = config.Config.Server.PortForwardServices
  442. }
  443. serviceSlice := strings.Split(services, ",")
  444. return serviceSlice
  445. }
  446. // GetSQLConn - get the sql connection string
  447. func GetSQLConn() string {
  448. sqlconn := "http://"
  449. if os.Getenv("SQL_CONN") != "" {
  450. sqlconn = os.Getenv("SQL_CONN")
  451. } else if config.Config.Server.SQLConn != "" {
  452. sqlconn = config.Config.Server.SQLConn
  453. }
  454. return sqlconn
  455. }
  456. // IsHostNetwork - checks if running on host network
  457. func IsHostNetwork() bool {
  458. ishost := false
  459. if os.Getenv("HOST_NETWORK") == "on" {
  460. ishost = true
  461. } else if config.Config.Server.HostNetwork == "on" {
  462. ishost = true
  463. }
  464. return ishost
  465. }
  466. // GetNodeID - gets the node id
  467. func GetNodeID() string {
  468. var id string
  469. var err error
  470. // id = getMacAddr()
  471. if os.Getenv("NODE_ID") != "" {
  472. id = os.Getenv("NODE_ID")
  473. } else if config.Config.Server.NodeID != "" {
  474. id = config.Config.Server.NodeID
  475. } else {
  476. id, err = os.Hostname()
  477. if err != nil {
  478. return ""
  479. }
  480. }
  481. return id
  482. }
  483. func SetNodeID(id string) {
  484. config.Config.Server.NodeID = id
  485. }
  486. // GetServerCheckinInterval - gets the server check-in time
  487. func GetServerCheckinInterval() int64 {
  488. var t = int64(5)
  489. var envt, _ = strconv.Atoi(os.Getenv("SERVER_CHECKIN_INTERVAL"))
  490. if envt > 0 {
  491. t = int64(envt)
  492. } else if config.Config.Server.ServerCheckinInterval > 0 {
  493. t = config.Config.Server.ServerCheckinInterval
  494. }
  495. return t
  496. }
  497. // GetAuthProviderInfo = gets the oauth provider info
  498. func GetAuthProviderInfo() (pi []string) {
  499. var authProvider = ""
  500. defer func() {
  501. if authProvider == "oidc" {
  502. if os.Getenv("OIDC_ISSUER") != "" {
  503. pi = append(pi, os.Getenv("OIDC_ISSUER"))
  504. } else if config.Config.Server.OIDCIssuer != "" {
  505. pi = append(pi, config.Config.Server.OIDCIssuer)
  506. } else {
  507. pi = []string{"", "", ""}
  508. }
  509. }
  510. }()
  511. if os.Getenv("AUTH_PROVIDER") != "" && os.Getenv("CLIENT_ID") != "" && os.Getenv("CLIENT_SECRET") != "" {
  512. authProvider = strings.ToLower(os.Getenv("AUTH_PROVIDER"))
  513. if authProvider == "google" || authProvider == "azure-ad" || authProvider == "github" || authProvider == "oidc" {
  514. return []string{authProvider, os.Getenv("CLIENT_ID"), os.Getenv("CLIENT_SECRET")}
  515. } else {
  516. authProvider = ""
  517. }
  518. } else if config.Config.Server.AuthProvider != "" && config.Config.Server.ClientID != "" && config.Config.Server.ClientSecret != "" {
  519. authProvider = strings.ToLower(config.Config.Server.AuthProvider)
  520. if authProvider == "google" || authProvider == "azure-ad" || authProvider == "github" || authProvider == "oidc" {
  521. return []string{authProvider, config.Config.Server.ClientID, config.Config.Server.ClientSecret}
  522. }
  523. }
  524. return []string{"", "", ""}
  525. }
  526. // GetAzureTenant - retrieve the azure tenant ID from env variable or config file
  527. func GetAzureTenant() string {
  528. var azureTenant = ""
  529. if os.Getenv("AZURE_TENANT") != "" {
  530. azureTenant = os.Getenv("AZURE_TENANT")
  531. } else if config.Config.Server.AzureTenant != "" {
  532. azureTenant = config.Config.Server.AzureTenant
  533. }
  534. return azureTenant
  535. }
  536. // GetRce - sees if Rce is enabled, off by default
  537. func GetRce() bool {
  538. return os.Getenv("RCE") == "on" || config.Config.Server.RCE == "on"
  539. }
  540. // GetMQServerPort - get mq port for server
  541. func GetMQServerPort() string {
  542. port := "1883" //default
  543. if os.Getenv("MQ_SERVER_PORT") != "" {
  544. port = os.Getenv("MQ_SERVER_PORT")
  545. } else if config.Config.Server.MQServerPort != "" {
  546. port = config.Config.Server.MQServerPort
  547. }
  548. return port
  549. }