main.go 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195
  1. package main
  2. import (
  3. "errors"
  4. "fmt"
  5. "log"
  6. "github.com/porter-dev/porter/api/server/shared/config/envloader"
  7. "github.com/porter-dev/porter/cmd/migrate/keyrotate"
  8. "github.com/porter-dev/porter/cmd/migrate/populate_source_config_display_name"
  9. "github.com/porter-dev/porter/cmd/migrate/startup_migrations"
  10. adapter "github.com/porter-dev/porter/internal/adapter"
  11. "github.com/porter-dev/porter/internal/features"
  12. "github.com/porter-dev/porter/internal/models"
  13. "github.com/porter-dev/porter/internal/repository/gorm"
  14. lr "github.com/porter-dev/porter/pkg/logger"
  15. "github.com/joeshaw/envdecode"
  16. pgorm "gorm.io/gorm"
  17. )
  18. func main() {
  19. logger := lr.NewConsole(true)
  20. logger.Info().Msg("running migrations")
  21. envConf, err := envloader.FromEnv()
  22. if err != nil {
  23. logger.Fatal().Err(err).Msg("could not load env conf")
  24. return
  25. }
  26. launchDarklyClient, err := features.GetClient(envConf.ServerConf.FeatureFlagClient, envConf.ServerConf.LaunchDarklySDKKey)
  27. if err != nil {
  28. logger.Fatal().Err(err).Msg("could not load launch darkly client")
  29. return
  30. }
  31. db, err := adapter.New(envConf.DBConf)
  32. if err != nil {
  33. logger.Fatal().Err(err).Msg("could not connect to the database")
  34. return
  35. }
  36. err = gorm.AutoMigrate(db, envConf.ServerConf.Debug)
  37. if err != nil {
  38. logger.Fatal().Err(err).Msg("gorm auto-migration failed")
  39. return
  40. }
  41. if err := db.Raw("ALTER TABLE clusters DROP CONSTRAINT IF EXISTS fk_cluster_token_caches").Error; err != nil {
  42. logger.Fatal().Err(err).Msg("failed to drop cluster token cache constraint")
  43. return
  44. }
  45. if err := db.Raw("ALTER TABLE cluster_token_caches DROP CONSTRAINT IF EXISTS fk_clusters_token_cache").Error; err != nil {
  46. logger.Fatal().Err(err).Msg("failed to drop clusters token cache constraint")
  47. return
  48. }
  49. err = db.Transaction(func(tx *pgorm.DB) error {
  50. if err := db.Exec("alter table aws_assume_role_chains DROP CONSTRAINT IF EXISTS fk_projects;").Error; err != nil {
  51. return fmt.Errorf("failed to drop fk constraint for assume role chains: %w", err)
  52. }
  53. if err := db.Exec("alter table aws_assume_role_chains ADD CONSTRAINT fk_projects FOREIGN KEY(project_id) REFERENCES projects(id);").Error; err != nil {
  54. return fmt.Errorf("failed to create fk constraint for assume role chains: %w", err)
  55. }
  56. if err := db.Exec("alter table aws_assume_role_chains ADD unique (project_id, source_arn, target_arn);").Error; err != nil {
  57. return fmt.Errorf("failed to create unique constraint for assume role chains: %w", err)
  58. }
  59. return nil
  60. })
  61. if err != nil {
  62. logger.Fatal().Err(err).Msg("error updating cluster control plane tables")
  63. }
  64. tx := db.Begin()
  65. switch tx.Dialector.Name() {
  66. case "sqlite":
  67. if err := tx.Raw("PRAGMA schema.locking_mode = EXCLUSIVE").Error; err != nil {
  68. tx.Rollback()
  69. logger.Fatal().Err(err).Msg("error acquiring lock on db_migrations")
  70. return
  71. }
  72. case "postgres":
  73. if err := tx.Raw("LOCK TABLE db_migrations IN SHARE ROW EXCLUSIVE MODE").Error; err != nil {
  74. tx.Rollback()
  75. logger.Fatal().Err(err).Msg("error acquiring lock on db_migrations")
  76. return
  77. }
  78. }
  79. dbMigration := &models.DbMigration{}
  80. if err := tx.Model(&models.DbMigration{}).First(dbMigration).Error; err != nil {
  81. if errors.Is(err, pgorm.ErrRecordNotFound) {
  82. dbMigration.Version = 0
  83. } else {
  84. tx.Rollback()
  85. logger.Fatal().Err(err).Msg("failed to check for db migration version")
  86. return
  87. }
  88. }
  89. latestMigrationVersion := startup_migrations.LatestMigrationVersion
  90. if dbMigration.Version < latestMigrationVersion {
  91. for ver, fn := range startup_migrations.StartupMigrations {
  92. if ver > dbMigration.Version {
  93. err := fn(tx, launchDarklyClient, logger)
  94. if err != nil {
  95. tx.Rollback()
  96. logger.Fatal().Err(err).Msg("failed to run startup migration script")
  97. return
  98. }
  99. }
  100. }
  101. dbMigration.Version = latestMigrationVersion
  102. if err := tx.Save(dbMigration).Error; err != nil {
  103. tx.Rollback()
  104. logger.Fatal().Err(err).Msg("failed to update migration version to latest")
  105. return
  106. }
  107. }
  108. tx.Commit()
  109. if shouldRotate, oldKeyStr, newKeyStr := shouldKeyRotate(); shouldRotate {
  110. oldKey := [32]byte{}
  111. newKey := [32]byte{}
  112. copy(oldKey[:], []byte(oldKeyStr))
  113. copy(newKey[:], []byte(newKeyStr))
  114. err := keyrotate.Rotate(db, &oldKey, &newKey)
  115. if err != nil {
  116. logger.Fatal().Err(err).Msg("key rotation failed")
  117. }
  118. }
  119. if shouldPopulateSourceConfigDisplayName() {
  120. err := populate_source_config_display_name.PopulateSourceConfigDisplayName(db, logger)
  121. if err != nil {
  122. logger.Fatal().Err(err).Msg("failed to populate source config display name")
  123. }
  124. }
  125. if err := InstanceMigrate(db, envConf.DBConf); err != nil {
  126. logger.Fatal().Err(err).Msg("vault migration failed")
  127. }
  128. }
  129. type RotateConf struct {
  130. // we add a dummy field to avoid empty struct issue with envdecode
  131. DummyField string `env:"ASDF,default=asdf"`
  132. OldEncryptionKey string `env:"OLD_ENCRYPTION_KEY"`
  133. NewEncryptionKey string `env:"NEW_ENCRYPTION_KEY"`
  134. }
  135. func shouldKeyRotate() (bool, string, string) {
  136. var c RotateConf
  137. if err := envdecode.StrictDecode(&c); err != nil {
  138. log.Fatalf("Failed to decode migration conf: %s", err)
  139. return false, "", ""
  140. }
  141. return c.OldEncryptionKey != "" && c.NewEncryptionKey != "", c.OldEncryptionKey, c.NewEncryptionKey
  142. }
  143. type PopulateSourceConfigDisplayNameConf struct {
  144. // we add a dummy field to avoid empty struct issue with envdecode
  145. DummyField string `env:"ASDF,default=asdf"`
  146. // if true, will populate the display name for all source configs
  147. PopulateSourceConfigDisplayName bool `env:"POPULATE_SOURCE_CONFIG_DISPLAY_NAME"`
  148. }
  149. func shouldPopulateSourceConfigDisplayName() bool {
  150. var c PopulateSourceConfigDisplayNameConf
  151. if err := envdecode.StrictDecode(&c); err != nil {
  152. log.Fatalf("Failed to decode migration conf: %s", err)
  153. return false
  154. }
  155. return c.PopulateSourceConfigDisplayName
  156. }