helm_revisions_count_tracker.go 9.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290
  1. //go:build ee
  2. /*
  3. === Helm Release Revisions Tracker Job ===
  4. This job keeps a track of helm releases and their revisions and deletes older revisions once they are
  5. backed up to an S3 bucket.
  6. - The job looks for clusters which have the `monitor_helm_releases` set to true.
  7. - The clusters are then checked for old helm release revisions.
  8. - In a cluster, list of all namespaces is fetched.
  9. - For every namespace, the list of releases is fetched.
  10. - For every release, its revision history is fetched.
  11. - If the number of revisions exceeds 100, then we intend to only keep the most recent 100 revisions.
  12. - For this, the older revisions are first backed up to an S3 bucket and then deleted.
  13. */
  14. package jobs
  15. import (
  16. "context"
  17. "encoding/json"
  18. "fmt"
  19. "log"
  20. "os"
  21. "sync"
  22. "time"
  23. "github.com/porter-dev/porter/api/server/shared/config/env"
  24. "github.com/porter-dev/porter/api/types"
  25. "github.com/porter-dev/porter/pkg/logger"
  26. "github.com/porter-dev/porter/provisioner/integrations/storage/s3"
  27. "github.com/porter-dev/porter/workers/utils"
  28. "github.com/porter-dev/porter/ee/integrations/vault"
  29. "github.com/porter-dev/porter/internal/helm"
  30. "github.com/porter-dev/porter/internal/kubernetes"
  31. "github.com/porter-dev/porter/internal/models"
  32. "github.com/porter-dev/porter/internal/oauth"
  33. "github.com/porter-dev/porter/internal/repository"
  34. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  35. rgorm "github.com/porter-dev/porter/internal/repository/gorm"
  36. "github.com/stefanmcshane/helm/pkg/releaseutil"
  37. "golang.org/x/oauth2"
  38. "gorm.io/gorm"
  39. )
  40. type helmRevisionsCountTracker struct {
  41. enqueueTime time.Time
  42. db *gorm.DB
  43. repo repository.Repository
  44. doConf *oauth2.Config
  45. awsAccessKeyID string
  46. awsSecretAccessKey string
  47. awsRegion string
  48. s3BucketName string
  49. encryptionKey *[32]byte
  50. revisionsCount int
  51. }
  52. // HelmRevisionsCountTrackerOpts holds the options required to run this job
  53. type HelmRevisionsCountTrackerOpts struct {
  54. DBConf *env.DBConf
  55. DOClientID string
  56. DOClientSecret string
  57. DOScopes []string
  58. ServerURL string
  59. AWSAccessKeyID string
  60. AWSSecretAccessKey string
  61. AWSRegion string
  62. S3BucketName string
  63. EncryptionKey string
  64. RevisionsCount int
  65. }
  66. func NewHelmRevisionsCountTracker(
  67. ctx context.Context,
  68. db *gorm.DB,
  69. enqueueTime time.Time,
  70. opts *HelmRevisionsCountTrackerOpts,
  71. ) (*helmRevisionsCountTracker, error) {
  72. var credBackend rcreds.CredentialStorage
  73. if opts.DBConf.VaultAPIKey != "" && opts.DBConf.VaultServerURL != "" && opts.DBConf.VaultPrefix != "" {
  74. credBackend = vault.NewClient(
  75. opts.DBConf.VaultServerURL,
  76. opts.DBConf.VaultAPIKey,
  77. opts.DBConf.VaultPrefix,
  78. )
  79. }
  80. var key [32]byte
  81. for i, b := range []byte(opts.DBConf.EncryptionKey) {
  82. key[i] = b
  83. }
  84. repo := rgorm.NewRepository(db, &key, credBackend)
  85. doConf := oauth.NewDigitalOceanClient(&oauth.Config{
  86. ClientID: opts.DOClientID,
  87. ClientSecret: opts.DOClientSecret,
  88. Scopes: opts.DOScopes,
  89. BaseURL: opts.ServerURL,
  90. })
  91. var s3Key [32]byte
  92. for i, b := range []byte(opts.EncryptionKey) {
  93. s3Key[i] = b
  94. }
  95. return &helmRevisionsCountTracker{
  96. enqueueTime, db, repo, doConf, opts.AWSAccessKeyID, opts.AWSSecretAccessKey, opts.AWSRegion,
  97. opts.S3BucketName, &s3Key, opts.RevisionsCount,
  98. }, nil
  99. }
  100. func (t *helmRevisionsCountTracker) ID() string {
  101. return "helm-revisions-count-tracker"
  102. }
  103. func (t *helmRevisionsCountTracker) EnqueueTime() time.Time {
  104. return t.enqueueTime
  105. }
  106. func (t *helmRevisionsCountTracker) Run(ctx context.Context) error {
  107. var count int64
  108. if err := t.db.Model(&models.Cluster{}).Count(&count).Error; err != nil {
  109. return err
  110. }
  111. var wg sync.WaitGroup
  112. for i := 0; i < (int(count)/stepSize)+1; i++ {
  113. var clusters []*models.Cluster
  114. if err := t.db.Order("id asc").Offset(i*stepSize).Limit(stepSize).Find(&clusters, "monitor_helm_releases = ?", "1").
  115. Error; err != nil {
  116. return err
  117. }
  118. // go through each project
  119. for _, cluster := range clusters {
  120. wg.Add(1)
  121. go func(projID, clusterID uint) {
  122. defer wg.Done()
  123. log.Printf("starting release revision monitoring for cluster with ID %d", cluster.ID)
  124. cluster, err := t.repo.Cluster().ReadCluster(projID, clusterID)
  125. if err != nil {
  126. log.Printf("error reading cluster ID %d: %v. skipping cluster ...", clusterID, err)
  127. return
  128. }
  129. // create s3 client to store revisions that need to be deleted
  130. s3Client, err := s3.NewS3StorageClient(&s3.S3Options{
  131. t.awsRegion, t.awsAccessKeyID, t.awsSecretAccessKey, t.s3BucketName, t.encryptionKey,
  132. })
  133. if err != nil {
  134. log.Printf("error creating S3 client for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  135. return
  136. }
  137. k8sAgent, err := kubernetes.GetAgentOutOfClusterConfig(ctx, &kubernetes.OutOfClusterConfig{
  138. Cluster: cluster,
  139. Repo: t.repo,
  140. DigitalOceanOAuth: t.doConf,
  141. AllowInClusterConnections: false,
  142. Timeout: 5 * time.Second,
  143. })
  144. if err != nil {
  145. log.Printf("error getting k8s agent for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  146. return
  147. }
  148. namespaces, err := k8sAgent.ListNamespaces()
  149. if err != nil {
  150. log.Printf("error fetching namespaces for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  151. return
  152. }
  153. log.Printf("fetched %d namespaces for cluster ID %d", len(namespaces.Items), cluster.ID)
  154. for _, ns := range namespaces.Items {
  155. agent, err := utils.NewRetryHelmAgent(ctx, &helm.Form{
  156. Cluster: cluster,
  157. Namespace: ns.Name,
  158. Repo: t.repo,
  159. DigitalOceanOAuth: t.doConf,
  160. AllowInClusterConnections: false,
  161. Timeout: 5 * time.Second,
  162. }, logger.New(true, os.Stdout), 3, time.Second)
  163. if err != nil {
  164. log.Printf("error fetching helm client for namespace %s in cluster ID %d: %v. "+
  165. "skipping namespace ...", ns.Name, cluster.ID, err)
  166. continue
  167. }
  168. releases, err := agent.ListReleases(ctx, ns.GetName(), &types.ReleaseListFilter{
  169. ByDate: true,
  170. StatusFilter: []string{
  171. "deployed",
  172. "pending",
  173. "pending-install",
  174. "pending-upgrade",
  175. "pending-rollback",
  176. "failed",
  177. },
  178. })
  179. if err != nil {
  180. log.Printf("error fetching releases for namespace %s in cluster ID %d: %v. skipping namespace ...",
  181. ns.Name, cluster.ID, err)
  182. continue
  183. }
  184. log.Printf("fetched %d releases for namespace %s in cluster ID %d", len(releases), ns.Name, cluster.ID)
  185. for _, rel := range releases {
  186. revisions, err := agent.GetReleaseHistory(ctx, rel.Name)
  187. if err != nil {
  188. log.Printf("error fetching release history for release %s in namespace %s of cluster ID %d: %v."+
  189. " skipping release ...", rel.Name, ns.Name, cluster.ID, err)
  190. continue
  191. }
  192. if len(revisions) <= t.revisionsCount {
  193. log.Printf("release %s of namespace %s in cluster ID %d has <= %d revisions. "+
  194. "skipping release...", t.revisionsCount, rel.Name, ns.Name, cluster.ID)
  195. continue
  196. }
  197. log.Printf("release %s of namespace %s in cluster ID %d has more than %d revisions. attempting to "+
  198. "delete the older ones.", t.revisionsCount, rel.Name, ns.Name, cluster.ID)
  199. // sort revisions from newest to oldest
  200. releaseutil.Reverse(revisions, releaseutil.SortByRevision)
  201. for i := t.revisionsCount; i < len(revisions); i += 1 {
  202. rev := revisions[i]
  203. // store the revision in the s3 bucket before deleting it
  204. data, err := json.Marshal(rev)
  205. if err != nil {
  206. log.Printf("error marshalling revision for release %s, number %d: %v. skipping revision ...",
  207. rev.Name, rev.Version, err)
  208. continue
  209. }
  210. // write to the bucket with key - <project_id>/<cluster_id>/<namespace>/<release_name>/<revision_number>
  211. err = s3Client.WriteFileWithKey(data, true, fmt.Sprintf("%d/%d/%s/%s/%d", cluster.ProjectID,
  212. cluster.ID, rel.Namespace, rel.Name, rev.Version))
  213. if err != nil {
  214. log.Printf("error backing up revision for release %s, number %d: %v. skipping revision ...",
  215. rev.Name, rev.Version, err)
  216. continue
  217. }
  218. log.Printf("revision %d of release %s in namespace %s of cluster ID %d was successfully backed up.",
  219. rev.Version, rel.Name, ns.Name, cluster.ID)
  220. err = agent.DeleteReleaseRevision(ctx, rev.Name, rev.Version)
  221. if err != nil {
  222. log.Printf("error deleting revision %d of release %s in namespace %s of cluster ID %d: %v",
  223. rev.Version, rel.Name, ns.Name, cluster.ID, err)
  224. continue
  225. }
  226. log.Printf("revision %d of release %s in namespace %s of cluster ID %d was successfully deleted.",
  227. rev.Version, rel.Name, ns.Name, cluster.ID)
  228. }
  229. }
  230. }
  231. }(cluster.ProjectID, cluster.ID)
  232. }
  233. wg.Wait()
  234. }
  235. return nil
  236. }
  237. func (t *helmRevisionsCountTracker) SetData([]byte) {}