main.go 5.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230
  1. //go:build ee
  2. package main
  3. import (
  4. "context"
  5. "encoding/json"
  6. "fmt"
  7. "log"
  8. "net/http"
  9. "os"
  10. "os/signal"
  11. "syscall"
  12. "time"
  13. "github.com/go-chi/chi"
  14. "github.com/go-chi/chi/middleware"
  15. "github.com/joeshaw/envdecode"
  16. "github.com/porter-dev/porter/api/server/shared/config/env"
  17. "github.com/porter-dev/porter/internal/adapter"
  18. "github.com/porter-dev/porter/internal/opa"
  19. "github.com/porter-dev/porter/internal/repository"
  20. "github.com/porter-dev/porter/internal/worker"
  21. "github.com/porter-dev/porter/workers/jobs"
  22. "gorm.io/gorm"
  23. "github.com/porter-dev/porter/ee/integrations/vault"
  24. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  25. pgorm "github.com/porter-dev/porter/internal/repository/gorm"
  26. )
  27. var (
  28. jobQueue chan worker.Job
  29. envDecoder = EnvConf{}
  30. dbConn *gorm.DB
  31. repo repository.Repository
  32. opaPolicies *opa.KubernetesPolicies
  33. )
  34. // EnvConf holds the environment variables for this binary
  35. type EnvConf struct {
  36. ServerURL string `env:"SERVER_URL,default=http://localhost:8080"`
  37. DOClientID string `env:"DO_CLIENT_ID"`
  38. DOClientSecret string `env:"DO_CLIENT_SECRET"`
  39. DBConf env.DBConf
  40. MaxWorkers uint `env:"MAX_WORKERS,default=10"`
  41. MaxQueue uint `env:"MAX_QUEUE,default=100"`
  42. AWSAccessKeyID string `env:"AWS_ACCESS_KEY_ID"`
  43. AWSSecretAccessKey string `env:"AWS_SECRET_ACCESS_KEY"`
  44. AWSRegion string `env:"AWS_REGION"`
  45. S3BucketName string `env:"S3_BUCKET_NAME"`
  46. EncryptionKey string `env:"S3_ENCRYPTION_KEY"`
  47. OPAConfigFileDir string `env:"OPA_CONFIG_FILE_DIR,default=./internal/opa"`
  48. Port uint `env:"PORT,default=3000"`
  49. }
  50. func main() {
  51. if err := envdecode.StrictDecode(&envDecoder); err != nil {
  52. log.Fatalf("Failed to decode server conf: %v", err)
  53. }
  54. log.Printf("setting max worker count to: %d\n", envDecoder.MaxWorkers)
  55. log.Printf("setting max job queue count to: %d\n", envDecoder.MaxQueue)
  56. db, err := adapter.New(&envDecoder.DBConf)
  57. if err != nil {
  58. log.Fatalln(err)
  59. }
  60. dbConn = db
  61. var credBackend rcreds.CredentialStorage
  62. if envDecoder.DBConf.VaultAPIKey != "" && envDecoder.DBConf.VaultServerURL != "" && envDecoder.DBConf.VaultPrefix != "" {
  63. credBackend = vault.NewClient(
  64. envDecoder.DBConf.VaultServerURL,
  65. envDecoder.DBConf.VaultAPIKey,
  66. envDecoder.DBConf.VaultPrefix,
  67. )
  68. }
  69. var key [32]byte
  70. for i, b := range []byte(envDecoder.DBConf.EncryptionKey) {
  71. key[i] = b
  72. }
  73. repo = pgorm.NewRepository(db, &key, credBackend)
  74. opaPolicies, err = opa.LoadPolicies(envDecoder.OPAConfigFileDir)
  75. if err != nil {
  76. log.Fatalln(err)
  77. }
  78. jobQueue = make(chan worker.Job, envDecoder.MaxQueue)
  79. d := worker.NewDispatcher(int(envDecoder.MaxWorkers))
  80. log.Println("starting worker dispatcher")
  81. err = d.Run(jobQueue)
  82. if err != nil {
  83. log.Fatalln(err)
  84. }
  85. server := &http.Server{Addr: fmt.Sprintf(":%d", envDecoder.Port), Handler: httpService()}
  86. serverCtx, serverStopCtx := context.WithCancel(context.Background())
  87. sig := make(chan os.Signal, 1)
  88. signal.Notify(sig, syscall.SIGHUP, syscall.SIGINT, syscall.SIGTERM, syscall.SIGQUIT)
  89. go func() {
  90. <-sig
  91. log.Println("shutting down server")
  92. shutdownCtx, shutdownCtxCancel := context.WithTimeout(serverCtx, 30*time.Second)
  93. defer shutdownCtxCancel()
  94. go func() {
  95. <-shutdownCtx.Done()
  96. if shutdownCtx.Err() == context.DeadlineExceeded {
  97. log.Fatal("graceful shutdown timed out.. forcing exit.")
  98. }
  99. }()
  100. err = server.Shutdown(shutdownCtx)
  101. if err != nil {
  102. log.Fatalln(err)
  103. }
  104. log.Println("server shutdown completed")
  105. serverStopCtx()
  106. }()
  107. log.Println("starting HTTP server at :3000")
  108. err = server.ListenAndServe()
  109. if err != nil && err != http.ErrServerClosed {
  110. log.Fatalf("error starting HTTP server: %v", err)
  111. }
  112. // Wait for server context to be stopped
  113. <-serverCtx.Done()
  114. d.Exit()
  115. }
  116. func httpService() http.Handler {
  117. log.Println("setting up HTTP router and adding middleware")
  118. r := chi.NewRouter()
  119. r.Use(middleware.Logger)
  120. r.Use(middleware.Recoverer)
  121. r.Use(middleware.Heartbeat("/ping"))
  122. // r.Use(middleware.AllowContentType("application/json"))
  123. r.Mount("/debug", middleware.Profiler())
  124. log.Println("setting up HTTP POST endpoint to enqueue jobs")
  125. r.Post("/enqueue/{id}", func(w http.ResponseWriter, r *http.Request) {
  126. req := make(map[string]interface{})
  127. if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
  128. log.Printf("error converting body to json: %v", err)
  129. return
  130. }
  131. job := getJob(chi.URLParam(r, "id"), req)
  132. if job == nil {
  133. w.WriteHeader(http.StatusNotFound)
  134. return
  135. }
  136. jobQueue <- job
  137. w.WriteHeader(http.StatusCreated)
  138. })
  139. return r
  140. }
  141. func getJob(id string, input map[string]interface{}) worker.Job {
  142. if id == "helm-revisions-count-tracker" {
  143. newJob, err := jobs.NewHelmRevisionsCountTracker(dbConn, time.Now().UTC(), &jobs.HelmRevisionsCountTrackerOpts{
  144. DBConf: &envDecoder.DBConf,
  145. DOClientID: envDecoder.DOClientID,
  146. DOClientSecret: envDecoder.DOClientSecret,
  147. DOScopes: []string{"read", "write"},
  148. ServerURL: envDecoder.ServerURL,
  149. AWSAccessKeyID: envDecoder.AWSAccessKeyID,
  150. AWSSecretAccessKey: envDecoder.AWSSecretAccessKey,
  151. AWSRegion: envDecoder.AWSRegion,
  152. S3BucketName: envDecoder.S3BucketName,
  153. EncryptionKey: envDecoder.EncryptionKey,
  154. })
  155. if err != nil {
  156. log.Printf("error creating job with ID: helm-revisions-count-tracker. Error: %v", err)
  157. return nil
  158. }
  159. return newJob
  160. } else if id == "recommender" {
  161. newJob, err := jobs.NewRecommender(dbConn, time.Now().UTC(), &jobs.RecommenderOpts{
  162. DBConf: &envDecoder.DBConf,
  163. DOClientID: envDecoder.DOClientID,
  164. DOClientSecret: envDecoder.DOClientSecret,
  165. DOScopes: []string{"read", "write"},
  166. ServerURL: envDecoder.ServerURL,
  167. Input: input,
  168. }, opaPolicies)
  169. if err != nil {
  170. log.Printf("error creating job with ID: recommender. Error: %v", err)
  171. return nil
  172. }
  173. return newJob
  174. }
  175. return nil
  176. }