main.go 6.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233
  1. //go:build ee
  2. package main
  3. import (
  4. "context"
  5. "encoding/json"
  6. "fmt"
  7. "log"
  8. "net/http"
  9. "os"
  10. "os/signal"
  11. "syscall"
  12. "time"
  13. "github.com/go-chi/chi"
  14. "github.com/go-chi/chi/middleware"
  15. "github.com/joeshaw/envdecode"
  16. "github.com/porter-dev/porter/api/server/shared/config/env"
  17. "github.com/porter-dev/porter/internal/adapter"
  18. "github.com/porter-dev/porter/internal/opa"
  19. "github.com/porter-dev/porter/internal/repository"
  20. "github.com/porter-dev/porter/internal/worker"
  21. "github.com/porter-dev/porter/workers/jobs"
  22. "gorm.io/gorm"
  23. "github.com/porter-dev/porter/ee/integrations/vault"
  24. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  25. pgorm "github.com/porter-dev/porter/internal/repository/gorm"
  26. )
  27. var (
  28. jobQueue chan worker.Job
  29. envDecoder = EnvConf{}
  30. dbConn *gorm.DB
  31. repo repository.Repository
  32. opaPolicies *opa.KubernetesPolicies
  33. )
  34. // EnvConf holds the environment variables for this binary
  35. type EnvConf struct {
  36. ServerURL string `env:"SERVER_URL,default=http://localhost:8080"`
  37. DOClientID string `env:"DO_CLIENT_ID"`
  38. DOClientSecret string `env:"DO_CLIENT_SECRET"`
  39. DBConf env.DBConf
  40. MaxWorkers uint `env:"MAX_WORKERS,default=10"`
  41. MaxQueue uint `env:"MAX_QUEUE,default=100"`
  42. AWSAccessKeyID string `env:"AWS_ACCESS_KEY_ID"`
  43. AWSSecretAccessKey string `env:"AWS_SECRET_ACCESS_KEY"`
  44. AWSRegion string `env:"AWS_REGION"`
  45. S3BucketName string `env:"S3_BUCKET_NAME"`
  46. EncryptionKey string `env:"S3_ENCRYPTION_KEY"`
  47. OPAConfigFileDir string `env:"OPA_CONFIG_FILE_DIR,default=./internal/opa"`
  48. LegacyProjectIDs []uint `env:"LEGACY_PROJECT_IDS"`
  49. Port uint `env:"PORT,default=3000"`
  50. }
  51. func main() {
  52. if err := envdecode.StrictDecode(&envDecoder); err != nil {
  53. log.Fatalf("Failed to decode server conf: %v", err)
  54. }
  55. log.Printf("setting max worker count to: %d\n", envDecoder.MaxWorkers)
  56. log.Printf("setting max job queue count to: %d\n", envDecoder.MaxQueue)
  57. db, err := adapter.New(&envDecoder.DBConf)
  58. if err != nil {
  59. log.Fatalln(err)
  60. }
  61. dbConn = db
  62. var credBackend rcreds.CredentialStorage
  63. if envDecoder.DBConf.VaultAPIKey != "" && envDecoder.DBConf.VaultServerURL != "" && envDecoder.DBConf.VaultPrefix != "" {
  64. credBackend = vault.NewClient(
  65. envDecoder.DBConf.VaultServerURL,
  66. envDecoder.DBConf.VaultAPIKey,
  67. envDecoder.DBConf.VaultPrefix,
  68. )
  69. }
  70. var key [32]byte
  71. for i, b := range []byte(envDecoder.DBConf.EncryptionKey) {
  72. key[i] = b
  73. }
  74. repo = pgorm.NewRepository(db, &key, credBackend)
  75. opaPolicies, err = opa.LoadPolicies(envDecoder.OPAConfigFileDir)
  76. if err != nil {
  77. log.Fatalln(err)
  78. }
  79. jobQueue = make(chan worker.Job, envDecoder.MaxQueue)
  80. d := worker.NewDispatcher(int(envDecoder.MaxWorkers))
  81. log.Println("starting worker dispatcher")
  82. err = d.Run(jobQueue)
  83. if err != nil {
  84. log.Fatalln(err)
  85. }
  86. server := &http.Server{Addr: fmt.Sprintf(":%d", envDecoder.Port), Handler: httpService()}
  87. serverCtx, serverStopCtx := context.WithCancel(context.Background())
  88. sig := make(chan os.Signal, 1)
  89. signal.Notify(sig, syscall.SIGHUP, syscall.SIGINT, syscall.SIGTERM, syscall.SIGQUIT)
  90. go func() {
  91. <-sig
  92. log.Println("shutting down server")
  93. shutdownCtx, shutdownCtxCancel := context.WithTimeout(serverCtx, 30*time.Second)
  94. defer shutdownCtxCancel()
  95. go func() {
  96. <-shutdownCtx.Done()
  97. if shutdownCtx.Err() == context.DeadlineExceeded {
  98. log.Fatal("graceful shutdown timed out.. forcing exit.")
  99. }
  100. }()
  101. err = server.Shutdown(shutdownCtx)
  102. if err != nil {
  103. log.Fatalln(err)
  104. }
  105. log.Println("server shutdown completed")
  106. serverStopCtx()
  107. }()
  108. log.Println("starting HTTP server at :3000")
  109. err = server.ListenAndServe()
  110. if err != nil && err != http.ErrServerClosed {
  111. log.Fatalf("error starting HTTP server: %v", err)
  112. }
  113. // Wait for server context to be stopped
  114. <-serverCtx.Done()
  115. d.Exit()
  116. }
  117. func httpService() http.Handler {
  118. log.Println("setting up HTTP router and adding middleware")
  119. r := chi.NewRouter()
  120. r.Use(middleware.Logger)
  121. r.Use(middleware.Recoverer)
  122. r.Use(middleware.Heartbeat("/ping"))
  123. // r.Use(middleware.AllowContentType("application/json"))
  124. r.Mount("/debug", middleware.Profiler())
  125. log.Println("setting up HTTP POST endpoint to enqueue jobs")
  126. r.Post("/enqueue/{id}", func(w http.ResponseWriter, r *http.Request) {
  127. req := make(map[string]interface{})
  128. if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
  129. log.Printf("error converting body to json: %v", err)
  130. return
  131. }
  132. job := getJob(chi.URLParam(r, "id"), req)
  133. if job == nil {
  134. w.WriteHeader(http.StatusNotFound)
  135. return
  136. }
  137. jobQueue <- job
  138. w.WriteHeader(http.StatusCreated)
  139. })
  140. return r
  141. }
  142. func getJob(id string, input map[string]interface{}) worker.Job {
  143. if id == "helm-revisions-count-tracker" {
  144. newJob, err := jobs.NewHelmRevisionsCountTracker(dbConn, time.Now().UTC(), &jobs.HelmRevisionsCountTrackerOpts{
  145. DBConf: &envDecoder.DBConf,
  146. DOClientID: envDecoder.DOClientID,
  147. DOClientSecret: envDecoder.DOClientSecret,
  148. DOScopes: []string{"read", "write"},
  149. ServerURL: envDecoder.ServerURL,
  150. AWSAccessKeyID: envDecoder.AWSAccessKeyID,
  151. AWSSecretAccessKey: envDecoder.AWSSecretAccessKey,
  152. AWSRegion: envDecoder.AWSRegion,
  153. S3BucketName: envDecoder.S3BucketName,
  154. EncryptionKey: envDecoder.EncryptionKey,
  155. })
  156. if err != nil {
  157. log.Printf("error creating job with ID: helm-revisions-count-tracker. Error: %v", err)
  158. return nil
  159. }
  160. return newJob
  161. } else if id == "recommender" {
  162. newJob, err := jobs.NewRecommender(dbConn, time.Now().UTC(), &jobs.RecommenderOpts{
  163. DBConf: &envDecoder.DBConf,
  164. DOClientID: envDecoder.DOClientID,
  165. DOClientSecret: envDecoder.DOClientSecret,
  166. DOScopes: []string{"read", "write"},
  167. ServerURL: envDecoder.ServerURL,
  168. Input: input,
  169. LegacyProjectIDs: envDecoder.LegacyProjectIDs,
  170. }, opaPolicies)
  171. if err != nil {
  172. log.Printf("error creating job with ID: recommender. Error: %v", err)
  173. return nil
  174. }
  175. return newJob
  176. }
  177. return nil
  178. }