create.go 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226
  1. package environment
  2. import (
  3. "context"
  4. "errors"
  5. "fmt"
  6. "net/http"
  7. "strconv"
  8. "strings"
  9. ghinstallation "github.com/bradleyfalzon/ghinstallation/v2"
  10. "github.com/google/go-github/v41/github"
  11. "github.com/porter-dev/porter/api/server/handlers"
  12. "github.com/porter-dev/porter/api/server/shared"
  13. "github.com/porter-dev/porter/api/server/shared/apierrors"
  14. "github.com/porter-dev/porter/api/server/shared/commonutils"
  15. "github.com/porter-dev/porter/api/server/shared/config"
  16. "github.com/porter-dev/porter/api/types"
  17. "github.com/porter-dev/porter/internal/auth/token"
  18. "github.com/porter-dev/porter/internal/encryption"
  19. "github.com/porter-dev/porter/internal/integrations/ci/actions"
  20. "github.com/porter-dev/porter/internal/models"
  21. "github.com/porter-dev/porter/internal/models/integrations"
  22. )
  23. type CreateEnvironmentHandler struct {
  24. handlers.PorterHandlerReadWriter
  25. }
  26. func NewCreateEnvironmentHandler(
  27. config *config.Config,
  28. decoderValidator shared.RequestDecoderValidator,
  29. writer shared.ResultWriter,
  30. ) *CreateEnvironmentHandler {
  31. return &CreateEnvironmentHandler{
  32. PorterHandlerReadWriter: handlers.NewDefaultPorterHandler(config, decoderValidator, writer),
  33. }
  34. }
  35. func (c *CreateEnvironmentHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
  36. ga, _ := r.Context().Value(types.GitInstallationScope).(*integrations.GithubAppInstallation)
  37. user, _ := r.Context().Value(types.UserScope).(*models.User)
  38. project, _ := r.Context().Value(types.ProjectScope).(*models.Project)
  39. cluster, _ := r.Context().Value(types.ClusterScope).(*models.Cluster)
  40. owner, name, ok := commonutils.GetOwnerAndNameParams(c, w, r)
  41. if !ok {
  42. return
  43. }
  44. // create the environment
  45. request := &types.CreateEnvironmentRequest{}
  46. if ok := c.DecodeAndValidate(w, r, request); !ok {
  47. return
  48. }
  49. // create a random webhook id
  50. webhookUID, err := encryption.GenerateRandomBytes(32)
  51. if err != nil {
  52. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  53. return
  54. }
  55. env := &models.Environment{
  56. ProjectID: project.ID,
  57. ClusterID: cluster.ID,
  58. GitInstallationID: uint(ga.InstallationID),
  59. Name: request.Name,
  60. GitRepoOwner: owner,
  61. GitRepoName: name,
  62. GitRepoBranches: strings.Join(request.GitRepoBranches, ","),
  63. Mode: request.Mode,
  64. WebhookID: string(webhookUID),
  65. NewCommentsDisabled: request.DisableNewComments,
  66. }
  67. // write Github actions files to the repo
  68. client, err := getGithubClientFromEnvironment(c.Config(), env)
  69. if err != nil {
  70. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  71. return
  72. }
  73. webhookURL := getGithubWebhookURLFromUID(c.Config().ServerConf.ServerURL, string(webhookUID))
  74. // create incoming webhook
  75. hook, _, err := client.Repositories.CreateHook(
  76. context.Background(), owner, name, &github.Hook{
  77. Config: map[string]interface{}{
  78. "url": webhookURL,
  79. "content_type": "json",
  80. "secret": c.Config().ServerConf.GithubIncomingWebhookSecret,
  81. },
  82. Events: []string{"pull_request"},
  83. Active: github.Bool(true),
  84. },
  85. )
  86. if err != nil && !strings.Contains(err.Error(), "already exists") {
  87. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(fmt.Errorf("%v: %w", errGithubAPI, err),
  88. http.StatusConflict))
  89. return
  90. }
  91. env.GithubWebhookID = hook.GetID()
  92. env, err = c.Repo().Environment().CreateEnvironment(env)
  93. if err != nil {
  94. _, deleteErr := client.Repositories.DeleteHook(context.Background(), owner, name, hook.GetID())
  95. if deleteErr != nil {
  96. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(fmt.Errorf("%v: %w", errGithubAPI, deleteErr),
  97. http.StatusConflict, "error creating environment"))
  98. return
  99. }
  100. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  101. return
  102. }
  103. // generate porter jwt token
  104. jwt, err := token.GetTokenForAPI(user.ID, project.ID)
  105. if err != nil {
  106. _, deleteErr := client.Repositories.DeleteHook(context.Background(), owner, name, hook.GetID())
  107. if deleteErr != nil {
  108. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(fmt.Errorf("%v: %w", errGithubAPI, deleteErr),
  109. http.StatusConflict, "error getting token for API while creating environment"))
  110. return
  111. }
  112. _, deleteErr = c.Repo().Environment().DeleteEnvironment(env)
  113. if deleteErr != nil {
  114. c.HandleAPIError(w, r, apierrors.NewErrInternal(deleteErr))
  115. return
  116. }
  117. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  118. return
  119. }
  120. encoded, err := jwt.EncodeToken(c.Config().TokenConf)
  121. if err != nil {
  122. _, deleteErr := client.Repositories.DeleteHook(context.Background(), owner, name, hook.GetID())
  123. if deleteErr != nil {
  124. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(fmt.Errorf("%v: %w", errGithubAPI, deleteErr),
  125. http.StatusConflict, "error encoding token while creating environment"))
  126. return
  127. }
  128. _, deleteErr = c.Repo().Environment().DeleteEnvironment(env)
  129. if deleteErr != nil {
  130. c.HandleAPIError(w, r, apierrors.NewErrInternal(deleteErr))
  131. return
  132. }
  133. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  134. return
  135. }
  136. err = actions.SetupEnv(&actions.EnvOpts{
  137. Client: client,
  138. ServerURL: c.Config().ServerConf.ServerURL,
  139. PorterToken: encoded,
  140. GitRepoOwner: owner,
  141. GitRepoName: name,
  142. ProjectID: project.ID,
  143. ClusterID: cluster.ID,
  144. GitInstallationID: uint(ga.InstallationID),
  145. EnvironmentName: request.Name,
  146. })
  147. if err != nil {
  148. unwrappedErr := errors.Unwrap(err)
  149. if unwrappedErr != nil {
  150. if errors.Is(unwrappedErr, actions.ErrProtectedBranch) {
  151. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusConflict))
  152. } else if errors.Is(unwrappedErr, actions.ErrCreatePRForProtectedBranch) {
  153. c.HandleAPIError(w, r, apierrors.NewErrPassThroughToClient(err, http.StatusPreconditionFailed))
  154. }
  155. } else {
  156. c.HandleAPIError(w, r, apierrors.NewErrInternal(err))
  157. return
  158. }
  159. }
  160. c.WriteResult(w, r, env.ToEnvironmentType())
  161. }
  162. func getGithubClientFromEnvironment(config *config.Config, env *models.Environment) (*github.Client, error) {
  163. // get the github app client
  164. ghAppId, err := strconv.Atoi(config.ServerConf.GithubAppID)
  165. if err != nil {
  166. return nil, err
  167. }
  168. // authenticate as github app installation
  169. itr, err := ghinstallation.New(
  170. http.DefaultTransport,
  171. int64(ghAppId),
  172. int64(env.GitInstallationID),
  173. config.ServerConf.GithubAppSecret,
  174. )
  175. if err != nil {
  176. return nil, err
  177. }
  178. return github.NewClient(&http.Client{Transport: itr}), nil
  179. }
  180. func getGithubWebhookURLFromUID(serverURL, webhookUID string) string {
  181. return fmt.Sprintf("%s/api/github/incoming_webhook/%s", serverURL, string(webhookUID))
  182. }