domain.go 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218
  1. package domain
  2. import (
  3. "context"
  4. "fmt"
  5. "math/rand"
  6. "net"
  7. "strings"
  8. "github.com/porter-dev/porter/internal/models"
  9. v1 "k8s.io/api/core/v1"
  10. "k8s.io/api/extensions/v1beta1"
  11. "k8s.io/client-go/kubernetes"
  12. metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
  13. "k8s.io/apimachinery/pkg/util/intstr"
  14. )
  15. // GetNGINXIngressServiceIP retrieves the external address of the nginx-ingress service
  16. func GetNGINXIngressServiceIP(clientset kubernetes.Interface) (string, bool, error) {
  17. svcList, err := clientset.CoreV1().Services("").List(context.TODO(), metav1.ListOptions{
  18. LabelSelector: "app.kubernetes.io/managed-by=Helm",
  19. })
  20. if err != nil {
  21. return "", false, err
  22. }
  23. var nginxSvc *v1.Service
  24. exists := false
  25. for _, svc := range svcList.Items {
  26. // check that helm chart annotation is correct exists
  27. if chartAnn, found := svc.ObjectMeta.Labels["helm.sh/chart"]; found {
  28. if (strings.Contains(chartAnn, "ingress-nginx") || strings.Contains(chartAnn, "nginx-ingress")) && svc.Spec.Type == v1.ServiceTypeLoadBalancer {
  29. nginxSvc = &svc
  30. exists = true
  31. }
  32. }
  33. }
  34. if !exists {
  35. return "", false, nil
  36. }
  37. if ipArr := nginxSvc.Status.LoadBalancer.Ingress; len(ipArr) > 0 {
  38. return ipArr[0].IP, true, nil
  39. }
  40. return "", false, nil
  41. }
  42. // DNSRecord wraps the gorm DNSRecord model
  43. type DNSRecord models.DNSRecord
  44. type CreateDNSRecordConfig struct {
  45. ReleaseName string
  46. RootDomain string
  47. Endpoint string
  48. }
  49. // NewDNSRecordForEndpoint generates a random subdomain and returns a DNSRecord
  50. // model
  51. func (c *CreateDNSRecordConfig) NewDNSRecordForEndpoint() *models.DNSRecord {
  52. const allowed = "123456789abcdefghijklmnopqrstuvwxyz"
  53. suffix := make([]byte, 8)
  54. for i := range suffix {
  55. suffix[i] = allowed[rand.Intn(len(allowed))]
  56. }
  57. subdomain := fmt.Sprintf("%s-%s", c.ReleaseName, string(suffix))
  58. return &models.DNSRecord{
  59. SubdomainPrefix: subdomain,
  60. RootDomain: c.RootDomain,
  61. Endpoint: c.Endpoint,
  62. Hostname: fmt.Sprintf("%s.%s", subdomain, c.RootDomain),
  63. }
  64. }
  65. func (e *DNSRecord) CreateDomain(clientset kubernetes.Interface) error {
  66. // determine if IP address or domain
  67. err := e.createIngress(clientset)
  68. if err != nil {
  69. return err
  70. }
  71. return e.createServiceWithEndpoint(clientset)
  72. }
  73. func (e *DNSRecord) createIngress(clientset kubernetes.Interface) error {
  74. _, err := clientset.ExtensionsV1beta1().Ingresses("default").Create(
  75. context.TODO(),
  76. &v1beta1.Ingress{
  77. ObjectMeta: metav1.ObjectMeta{
  78. Annotations: map[string]string{
  79. "kubernetes.io/ingress.class": "nginx",
  80. "nginx.ingress.kubernetes.io/ssl-redirect": "true",
  81. "nginx.ingress.kubernetes.io/backend-protocol": "HTTPS",
  82. "nginx.ingress.kubernetes.io/upstream-vhost": e.Hostname,
  83. },
  84. Name: e.SubdomainPrefix,
  85. Namespace: "default",
  86. },
  87. Spec: v1beta1.IngressSpec{
  88. Rules: []v1beta1.IngressRule{
  89. {
  90. Host: fmt.Sprintf("%s.%s", e.SubdomainPrefix, e.RootDomain),
  91. IngressRuleValue: v1beta1.IngressRuleValue{
  92. HTTP: &v1beta1.HTTPIngressRuleValue{
  93. Paths: []v1beta1.HTTPIngressPath{
  94. {
  95. Backend: v1beta1.IngressBackend{
  96. ServiceName: e.SubdomainPrefix,
  97. ServicePort: intstr.IntOrString{
  98. Type: intstr.Int,
  99. IntVal: 443,
  100. },
  101. },
  102. },
  103. },
  104. },
  105. },
  106. },
  107. },
  108. },
  109. },
  110. metav1.CreateOptions{},
  111. )
  112. return err
  113. }
  114. func (e *DNSRecord) createServiceWithEndpoint(clientset kubernetes.Interface) error {
  115. // determine if endpoint needs to be created or external name is ok
  116. isIPv4 := net.ParseIP(e.Endpoint) != nil
  117. svcSpec := v1.ServiceSpec{
  118. Ports: []v1.ServicePort{
  119. {
  120. Port: 80,
  121. TargetPort: intstr.IntOrString{
  122. Type: intstr.Int,
  123. IntVal: 80,
  124. },
  125. Name: "http",
  126. },
  127. {
  128. Port: 443,
  129. TargetPort: intstr.IntOrString{
  130. Type: intstr.Int,
  131. IntVal: 443,
  132. },
  133. Name: "https",
  134. },
  135. },
  136. }
  137. // case service spec on ipv4
  138. if isIPv4 {
  139. svcSpec.ClusterIP = "None"
  140. } else {
  141. svcSpec.Type = "ExternalName"
  142. svcSpec.ExternalName = e.Endpoint
  143. }
  144. // create service
  145. _, err := clientset.CoreV1().Services("default").Create(
  146. context.TODO(),
  147. &v1.Service{
  148. ObjectMeta: metav1.ObjectMeta{
  149. Name: e.SubdomainPrefix,
  150. Namespace: "default",
  151. },
  152. Spec: svcSpec,
  153. },
  154. metav1.CreateOptions{},
  155. )
  156. if err != nil {
  157. return err
  158. }
  159. if isIPv4 {
  160. _, err = clientset.CoreV1().Endpoints("default").Create(
  161. context.TODO(),
  162. &v1.Endpoints{
  163. ObjectMeta: metav1.ObjectMeta{
  164. Name: e.SubdomainPrefix,
  165. Namespace: "default",
  166. },
  167. Subsets: []v1.EndpointSubset{
  168. {
  169. Addresses: []v1.EndpointAddress{
  170. {
  171. IP: e.Endpoint,
  172. },
  173. },
  174. Ports: []v1.EndpointPort{
  175. {
  176. Name: "http",
  177. Port: 80,
  178. },
  179. {
  180. Name: "https",
  181. Port: 443,
  182. },
  183. },
  184. },
  185. },
  186. },
  187. metav1.CreateOptions{},
  188. )
  189. }
  190. return err
  191. }