helm_revisions_count_tracker.go 8.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288
  1. //go:build ee
  2. /*
  3. === Helm Release Revisions Tracker Job ===
  4. This job keeps a track of helm releases and their revisions and deletes older revisions once they are
  5. backed up to an S3 bucket.
  6. - The job looks for clusters which have the `monitor_helm_releases` set to true.
  7. - The clusters are then checked for old helm release revisions.
  8. - In a cluster, list of all namespaces is fetched.
  9. - For every namespace, the list of releases is fetched.
  10. - For every release, its revision history is fetched.
  11. - If the number of revisions exceeds 100, then we intend to only keep the most recent 100 revisions.
  12. - For this, the older revisions are first backed up to an S3 bucket and then deleted.
  13. */
  14. package jobs
  15. import (
  16. "encoding/json"
  17. "fmt"
  18. "log"
  19. "os"
  20. "sync"
  21. "time"
  22. "github.com/porter-dev/porter/api/server/shared/config/env"
  23. "github.com/porter-dev/porter/api/types"
  24. "github.com/porter-dev/porter/pkg/logger"
  25. "github.com/porter-dev/porter/provisioner/integrations/storage/s3"
  26. "github.com/porter-dev/porter/workers/utils"
  27. "github.com/porter-dev/porter/ee/integrations/vault"
  28. "github.com/porter-dev/porter/internal/helm"
  29. "github.com/porter-dev/porter/internal/kubernetes"
  30. "github.com/porter-dev/porter/internal/models"
  31. "github.com/porter-dev/porter/internal/oauth"
  32. "github.com/porter-dev/porter/internal/repository"
  33. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  34. rgorm "github.com/porter-dev/porter/internal/repository/gorm"
  35. "github.com/stefanmcshane/helm/pkg/releaseutil"
  36. "golang.org/x/oauth2"
  37. "gorm.io/gorm"
  38. )
  39. type helmRevisionsCountTracker struct {
  40. enqueueTime time.Time
  41. db *gorm.DB
  42. repo repository.Repository
  43. doConf *oauth2.Config
  44. awsAccessKeyID string
  45. awsSecretAccessKey string
  46. awsRegion string
  47. s3BucketName string
  48. encryptionKey *[32]byte
  49. revisionsCount int
  50. }
  51. // HelmRevisionsCountTrackerOpts holds the options required to run this job
  52. type HelmRevisionsCountTrackerOpts struct {
  53. DBConf *env.DBConf
  54. DOClientID string
  55. DOClientSecret string
  56. DOScopes []string
  57. ServerURL string
  58. AWSAccessKeyID string
  59. AWSSecretAccessKey string
  60. AWSRegion string
  61. S3BucketName string
  62. EncryptionKey string
  63. RevisionsCount int
  64. }
  65. func NewHelmRevisionsCountTracker(
  66. db *gorm.DB,
  67. enqueueTime time.Time,
  68. opts *HelmRevisionsCountTrackerOpts,
  69. ) (*helmRevisionsCountTracker, error) {
  70. var credBackend rcreds.CredentialStorage
  71. if opts.DBConf.VaultAPIKey != "" && opts.DBConf.VaultServerURL != "" && opts.DBConf.VaultPrefix != "" {
  72. credBackend = vault.NewClient(
  73. opts.DBConf.VaultServerURL,
  74. opts.DBConf.VaultAPIKey,
  75. opts.DBConf.VaultPrefix,
  76. )
  77. }
  78. var key [32]byte
  79. for i, b := range []byte(opts.DBConf.EncryptionKey) {
  80. key[i] = b
  81. }
  82. repo := rgorm.NewRepository(db, &key, credBackend)
  83. doConf := oauth.NewDigitalOceanClient(&oauth.Config{
  84. ClientID: opts.DOClientID,
  85. ClientSecret: opts.DOClientSecret,
  86. Scopes: opts.DOScopes,
  87. BaseURL: opts.ServerURL,
  88. })
  89. var s3Key [32]byte
  90. for i, b := range []byte(opts.EncryptionKey) {
  91. s3Key[i] = b
  92. }
  93. return &helmRevisionsCountTracker{
  94. enqueueTime, db, repo, doConf, opts.AWSAccessKeyID, opts.AWSSecretAccessKey, opts.AWSRegion,
  95. opts.S3BucketName, &s3Key, opts.RevisionsCount,
  96. }, nil
  97. }
  98. func (t *helmRevisionsCountTracker) ID() string {
  99. return "helm-revisions-count-tracker"
  100. }
  101. func (t *helmRevisionsCountTracker) EnqueueTime() time.Time {
  102. return t.enqueueTime
  103. }
  104. func (t *helmRevisionsCountTracker) Run() error {
  105. var count int64
  106. if err := t.db.Model(&models.Cluster{}).Count(&count).Error; err != nil {
  107. return err
  108. }
  109. var wg sync.WaitGroup
  110. for i := 0; i < (int(count)/stepSize)+1; i++ {
  111. var clusters []*models.Cluster
  112. if err := t.db.Order("id asc").Offset(i*stepSize).Limit(stepSize).Find(&clusters, "monitor_helm_releases = ?", "1").
  113. Error; err != nil {
  114. return err
  115. }
  116. // go through each project
  117. for _, cluster := range clusters {
  118. wg.Add(1)
  119. go func(projID, clusterID uint) {
  120. defer wg.Done()
  121. log.Printf("starting release revision monitoring for cluster with ID %d", cluster.ID)
  122. cluster, err := t.repo.Cluster().ReadCluster(projID, clusterID)
  123. if err != nil {
  124. log.Printf("error reading cluster ID %d: %v. skipping cluster ...", clusterID, err)
  125. return
  126. }
  127. // create s3 client to store revisions that need to be deleted
  128. s3Client, err := s3.NewS3StorageClient(&s3.S3Options{
  129. t.awsRegion, t.awsAccessKeyID, t.awsSecretAccessKey, t.s3BucketName, t.encryptionKey,
  130. })
  131. if err != nil {
  132. log.Printf("error creating S3 client for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  133. return
  134. }
  135. k8sAgent, err := kubernetes.GetAgentOutOfClusterConfig(&kubernetes.OutOfClusterConfig{
  136. Cluster: cluster,
  137. Repo: t.repo,
  138. DigitalOceanOAuth: t.doConf,
  139. AllowInClusterConnections: false,
  140. Timeout: 5 * time.Second,
  141. })
  142. if err != nil {
  143. log.Printf("error getting k8s agent for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  144. return
  145. }
  146. namespaces, err := k8sAgent.ListNamespaces()
  147. if err != nil {
  148. log.Printf("error fetching namespaces for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  149. return
  150. }
  151. log.Printf("fetched %d namespaces for cluster ID %d", len(namespaces.Items), cluster.ID)
  152. for _, ns := range namespaces.Items {
  153. agent, err := utils.NewRetryHelmAgent(&helm.Form{
  154. Cluster: cluster,
  155. Namespace: ns.Name,
  156. Repo: t.repo,
  157. DigitalOceanOAuth: t.doConf,
  158. AllowInClusterConnections: false,
  159. Timeout: 5 * time.Second,
  160. }, logger.New(true, os.Stdout), 3, time.Second)
  161. if err != nil {
  162. log.Printf("error fetching helm client for namespace %s in cluster ID %d: %v. "+
  163. "skipping namespace ...", ns.Name, cluster.ID, err)
  164. continue
  165. }
  166. releases, err := agent.ListReleases(ns.GetName(), &types.ReleaseListFilter{
  167. ByDate: true,
  168. StatusFilter: []string{
  169. "deployed",
  170. "pending",
  171. "pending-install",
  172. "pending-upgrade",
  173. "pending-rollback",
  174. "failed",
  175. },
  176. })
  177. if err != nil {
  178. log.Printf("error fetching releases for namespace %s in cluster ID %d: %v. skipping namespace ...",
  179. ns.Name, cluster.ID, err)
  180. continue
  181. }
  182. log.Printf("fetched %d releases for namespace %s in cluster ID %d", len(releases), ns.Name, cluster.ID)
  183. for _, rel := range releases {
  184. revisions, err := agent.GetReleaseHistory(rel.Name)
  185. if err != nil {
  186. log.Printf("error fetching release history for release %s in namespace %s of cluster ID %d: %v."+
  187. " skipping release ...", rel.Name, ns.Name, cluster.ID, err)
  188. continue
  189. }
  190. if len(revisions) <= t.revisionsCount {
  191. log.Printf("release %s of namespace %s in cluster ID %d has <= %d revisions. "+
  192. "skipping release...", t.revisionsCount, rel.Name, ns.Name, cluster.ID)
  193. continue
  194. }
  195. log.Printf("release %s of namespace %s in cluster ID %d has more than %d revisions. attempting to "+
  196. "delete the older ones.", t.revisionsCount, rel.Name, ns.Name, cluster.ID)
  197. // sort revisions from newest to oldest
  198. releaseutil.Reverse(revisions, releaseutil.SortByRevision)
  199. for i := t.revisionsCount; i < len(revisions); i += 1 {
  200. rev := revisions[i]
  201. // store the revision in the s3 bucket before deleting it
  202. data, err := json.Marshal(rev)
  203. if err != nil {
  204. log.Printf("error marshalling revision for release %s, number %d: %v. skipping revision ...",
  205. rev.Name, rev.Version, err)
  206. continue
  207. }
  208. // write to the bucket with key - <project_id>/<cluster_id>/<namespace>/<release_name>/<revision_number>
  209. err = s3Client.WriteFileWithKey(data, true, fmt.Sprintf("%d/%d/%s/%s/%d", cluster.ProjectID,
  210. cluster.ID, rel.Namespace, rel.Name, rev.Version))
  211. if err != nil {
  212. log.Printf("error backing up revision for release %s, number %d: %v. skipping revision ...",
  213. rev.Name, rev.Version, err)
  214. continue
  215. }
  216. log.Printf("revision %d of release %s in namespace %s of cluster ID %d was successfully backed up.",
  217. rev.Version, rel.Name, ns.Name, cluster.ID)
  218. err = agent.DeleteReleaseRevision(rev.Name, rev.Version)
  219. if err != nil {
  220. log.Printf("error deleting revision %d of release %s in namespace %s of cluster ID %d: %v",
  221. rev.Version, rel.Name, ns.Name, cluster.ID, err)
  222. continue
  223. }
  224. log.Printf("revision %d of release %s in namespace %s of cluster ID %d was successfully deleted.",
  225. rev.Version, rel.Name, ns.Name, cluster.ID)
  226. }
  227. }
  228. }
  229. }(cluster.ProjectID, cluster.ID)
  230. }
  231. wg.Wait()
  232. }
  233. return nil
  234. }
  235. func (t *helmRevisionsCountTracker) SetData([]byte) {}