main.go 6.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235
  1. //go:build ee
  2. package main
  3. import (
  4. "context"
  5. "encoding/json"
  6. "fmt"
  7. "log"
  8. "net/http"
  9. "os"
  10. "os/signal"
  11. "syscall"
  12. "time"
  13. "github.com/go-chi/chi"
  14. "github.com/go-chi/chi/middleware"
  15. "github.com/joeshaw/envdecode"
  16. "github.com/porter-dev/porter/api/server/shared/config/env"
  17. "github.com/porter-dev/porter/internal/adapter"
  18. "github.com/porter-dev/porter/internal/opa"
  19. "github.com/porter-dev/porter/internal/repository"
  20. "github.com/porter-dev/porter/internal/worker"
  21. "github.com/porter-dev/porter/workers/jobs"
  22. "gorm.io/gorm"
  23. "github.com/porter-dev/porter/ee/integrations/vault"
  24. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  25. pgorm "github.com/porter-dev/porter/internal/repository/gorm"
  26. )
  27. var (
  28. jobQueue chan worker.Job
  29. envDecoder = EnvConf{}
  30. dbConn *gorm.DB
  31. repo repository.Repository
  32. opaPolicies *opa.KubernetesPolicies
  33. )
  34. // EnvConf holds the environment variables for this binary
  35. type EnvConf struct {
  36. ServerURL string `env:"SERVER_URL,default=http://localhost:8080"`
  37. DOClientID string `env:"DO_CLIENT_ID"`
  38. DOClientSecret string `env:"DO_CLIENT_SECRET"`
  39. DBConf env.DBConf
  40. MaxWorkers uint `env:"MAX_WORKERS,default=10"`
  41. MaxQueue uint `env:"MAX_QUEUE,default=100"`
  42. AWSAccessKeyID string `env:"AWS_ACCESS_KEY_ID"`
  43. AWSSecretAccessKey string `env:"AWS_SECRET_ACCESS_KEY"`
  44. AWSRegion string `env:"AWS_REGION"`
  45. S3BucketName string `env:"S3_BUCKET_NAME"`
  46. EncryptionKey string `env:"S3_ENCRYPTION_KEY"`
  47. OPAConfigFileDir string `env:"OPA_CONFIG_FILE_DIR,default=./internal/opa"`
  48. LegacyProjectIDs []uint `env:"LEGACY_PROJECT_IDS"`
  49. Port uint `env:"PORT,default=3000"`
  50. }
  51. func main() {
  52. if err := envdecode.StrictDecode(&envDecoder); err != nil {
  53. log.Fatalf("Failed to decode server conf: %v", err)
  54. }
  55. log.Printf("setting max worker count to: %d\n", envDecoder.MaxWorkers)
  56. log.Printf("setting max job queue count to: %d\n", envDecoder.MaxQueue)
  57. log.Printf("legacy project ids are: %v", envDecoder.LegacyProjectIDs)
  58. db, err := adapter.New(&envDecoder.DBConf)
  59. if err != nil {
  60. log.Fatalln(err)
  61. }
  62. dbConn = db
  63. var credBackend rcreds.CredentialStorage
  64. if envDecoder.DBConf.VaultAPIKey != "" && envDecoder.DBConf.VaultServerURL != "" && envDecoder.DBConf.VaultPrefix != "" {
  65. credBackend = vault.NewClient(
  66. envDecoder.DBConf.VaultServerURL,
  67. envDecoder.DBConf.VaultAPIKey,
  68. envDecoder.DBConf.VaultPrefix,
  69. )
  70. }
  71. var key [32]byte
  72. for i, b := range []byte(envDecoder.DBConf.EncryptionKey) {
  73. key[i] = b
  74. }
  75. repo = pgorm.NewRepository(db, &key, credBackend)
  76. opaPolicies, err = opa.LoadPolicies(envDecoder.OPAConfigFileDir)
  77. if err != nil {
  78. log.Fatalln(err)
  79. }
  80. jobQueue = make(chan worker.Job, envDecoder.MaxQueue)
  81. d := worker.NewDispatcher(int(envDecoder.MaxWorkers))
  82. log.Println("starting worker dispatcher")
  83. err = d.Run(jobQueue)
  84. if err != nil {
  85. log.Fatalln(err)
  86. }
  87. server := &http.Server{Addr: fmt.Sprintf(":%d", envDecoder.Port), Handler: httpService()}
  88. serverCtx, serverStopCtx := context.WithCancel(context.Background())
  89. sig := make(chan os.Signal, 1)
  90. signal.Notify(sig, syscall.SIGHUP, syscall.SIGINT, syscall.SIGTERM, syscall.SIGQUIT)
  91. go func() {
  92. <-sig
  93. log.Println("shutting down server")
  94. shutdownCtx, shutdownCtxCancel := context.WithTimeout(serverCtx, 30*time.Second)
  95. defer shutdownCtxCancel()
  96. go func() {
  97. <-shutdownCtx.Done()
  98. if shutdownCtx.Err() == context.DeadlineExceeded {
  99. log.Fatal("graceful shutdown timed out.. forcing exit.")
  100. }
  101. }()
  102. err = server.Shutdown(shutdownCtx)
  103. if err != nil {
  104. log.Fatalln(err)
  105. }
  106. log.Println("server shutdown completed")
  107. serverStopCtx()
  108. }()
  109. log.Println("starting HTTP server at :3000")
  110. err = server.ListenAndServe()
  111. if err != nil && err != http.ErrServerClosed {
  112. log.Fatalf("error starting HTTP server: %v", err)
  113. }
  114. // Wait for server context to be stopped
  115. <-serverCtx.Done()
  116. d.Exit()
  117. }
  118. func httpService() http.Handler {
  119. log.Println("setting up HTTP router and adding middleware")
  120. r := chi.NewRouter()
  121. r.Use(middleware.Logger)
  122. r.Use(middleware.Recoverer)
  123. r.Use(middleware.Heartbeat("/ping"))
  124. // r.Use(middleware.AllowContentType("application/json"))
  125. r.Mount("/debug", middleware.Profiler())
  126. log.Println("setting up HTTP POST endpoint to enqueue jobs")
  127. r.Post("/enqueue/{id}", func(w http.ResponseWriter, r *http.Request) {
  128. req := make(map[string]interface{})
  129. if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
  130. log.Printf("error converting body to json: %v", err)
  131. return
  132. }
  133. job := getJob(chi.URLParam(r, "id"), req)
  134. if job == nil {
  135. w.WriteHeader(http.StatusNotFound)
  136. return
  137. }
  138. jobQueue <- job
  139. w.WriteHeader(http.StatusCreated)
  140. })
  141. return r
  142. }
  143. func getJob(id string, input map[string]interface{}) worker.Job {
  144. if id == "helm-revisions-count-tracker" {
  145. newJob, err := jobs.NewHelmRevisionsCountTracker(dbConn, time.Now().UTC(), &jobs.HelmRevisionsCountTrackerOpts{
  146. DBConf: &envDecoder.DBConf,
  147. DOClientID: envDecoder.DOClientID,
  148. DOClientSecret: envDecoder.DOClientSecret,
  149. DOScopes: []string{"read", "write"},
  150. ServerURL: envDecoder.ServerURL,
  151. AWSAccessKeyID: envDecoder.AWSAccessKeyID,
  152. AWSSecretAccessKey: envDecoder.AWSSecretAccessKey,
  153. AWSRegion: envDecoder.AWSRegion,
  154. S3BucketName: envDecoder.S3BucketName,
  155. EncryptionKey: envDecoder.EncryptionKey,
  156. })
  157. if err != nil {
  158. log.Printf("error creating job with ID: helm-revisions-count-tracker. Error: %v", err)
  159. return nil
  160. }
  161. return newJob
  162. } else if id == "recommender" {
  163. newJob, err := jobs.NewRecommender(dbConn, time.Now().UTC(), &jobs.RecommenderOpts{
  164. DBConf: &envDecoder.DBConf,
  165. DOClientID: envDecoder.DOClientID,
  166. DOClientSecret: envDecoder.DOClientSecret,
  167. DOScopes: []string{"read", "write"},
  168. ServerURL: envDecoder.ServerURL,
  169. Input: input,
  170. LegacyProjectIDs: envDecoder.LegacyProjectIDs,
  171. }, opaPolicies)
  172. if err != nil {
  173. log.Printf("error creating job with ID: recommender. Error: %v", err)
  174. return nil
  175. }
  176. return newJob
  177. }
  178. return nil
  179. }