main.go 4.6 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177
  1. package main
  2. import (
  3. "errors"
  4. "log"
  5. "github.com/porter-dev/porter/api/server/shared/config/envloader"
  6. "github.com/porter-dev/porter/cmd/migrate/keyrotate"
  7. "github.com/porter-dev/porter/cmd/migrate/populate_source_config_display_name"
  8. "github.com/porter-dev/porter/cmd/migrate/startup_migrations"
  9. adapter "github.com/porter-dev/porter/internal/adapter"
  10. "github.com/porter-dev/porter/internal/models"
  11. "github.com/porter-dev/porter/internal/repository/gorm"
  12. lr "github.com/porter-dev/porter/pkg/logger"
  13. "github.com/joeshaw/envdecode"
  14. pgorm "gorm.io/gorm"
  15. )
  16. func main() {
  17. logger := lr.NewConsole(true)
  18. logger.Info().Msg("running migrations")
  19. envConf, err := envloader.FromEnv()
  20. if err != nil {
  21. logger.Fatal().Err(err).Msg("could not load env conf")
  22. return
  23. }
  24. db, err := adapter.New(envConf.DBConf)
  25. if err != nil {
  26. logger.Fatal().Err(err).Msg("could not connect to the database")
  27. return
  28. }
  29. err = gorm.AutoMigrate(db, envConf.ServerConf.Debug)
  30. if err != nil {
  31. logger.Fatal().Err(err).Msg("gorm auto-migration failed")
  32. return
  33. }
  34. if err := db.Raw("ALTER TABLE clusters DROP CONSTRAINT IF EXISTS fk_cluster_token_caches").Error; err != nil {
  35. logger.Fatal().Err(err).Msg("failed to drop cluster token cache constraint")
  36. return
  37. }
  38. if err := db.Raw("ALTER TABLE cluster_token_caches DROP CONSTRAINT IF EXISTS fk_clusters_token_cache").Error; err != nil {
  39. logger.Fatal().Err(err).Msg("failed to drop clusters token cache constraint")
  40. return
  41. }
  42. tx := db.Begin()
  43. switch tx.Dialector.Name() {
  44. case "sqlite":
  45. if err := tx.Raw("PRAGMA schema.locking_mode = EXCLUSIVE").Error; err != nil {
  46. tx.Rollback()
  47. logger.Fatal().Err(err).Msg("error acquiring lock on db_migrations")
  48. return
  49. }
  50. case "postgres":
  51. if err := tx.Raw("LOCK TABLE db_migrations IN SHARE ROW EXCLUSIVE MODE").Error; err != nil {
  52. tx.Rollback()
  53. logger.Fatal().Err(err).Msg("error acquiring lock on db_migrations")
  54. return
  55. }
  56. }
  57. dbMigration := &models.DbMigration{}
  58. if err := tx.Model(&models.DbMigration{}).First(dbMigration).Error; err != nil {
  59. if errors.Is(err, pgorm.ErrRecordNotFound) {
  60. dbMigration.Version = 0
  61. } else {
  62. tx.Rollback()
  63. logger.Fatal().Err(err).Msg("failed to check for db migration version")
  64. return
  65. }
  66. }
  67. latestMigrationVersion := startup_migrations.LatestMigrationVersion
  68. if dbMigration.Version < latestMigrationVersion {
  69. for ver, fn := range startup_migrations.StartupMigrations {
  70. if ver > dbMigration.Version {
  71. err := fn(tx, logger)
  72. if err != nil {
  73. tx.Rollback()
  74. logger.Fatal().Err(err).Msg("failed to run startup migration script")
  75. return
  76. }
  77. }
  78. }
  79. dbMigration.Version = latestMigrationVersion
  80. if err := tx.Save(dbMigration).Error; err != nil {
  81. tx.Rollback()
  82. logger.Fatal().Err(err).Msg("failed to update migration version to latest")
  83. return
  84. }
  85. }
  86. tx.Commit()
  87. if shouldRotate, oldKeyStr, newKeyStr := shouldKeyRotate(); shouldRotate {
  88. oldKey := [32]byte{}
  89. newKey := [32]byte{}
  90. copy(oldKey[:], []byte(oldKeyStr))
  91. copy(newKey[:], []byte(newKeyStr))
  92. err := keyrotate.Rotate(db, &oldKey, &newKey)
  93. if err != nil {
  94. logger.Fatal().Err(err).Msg("key rotation failed")
  95. }
  96. }
  97. if shouldPopulateSourceConfigDisplayName() {
  98. err := populate_source_config_display_name.PopulateSourceConfigDisplayName(db, logger)
  99. if err != nil {
  100. logger.Fatal().Err(err).Msg("failed to populate source config display name")
  101. }
  102. }
  103. if err := InstanceMigrate(db, envConf.DBConf); err != nil {
  104. logger.Fatal().Err(err).Msg("vault migration failed")
  105. }
  106. }
  107. type RotateConf struct {
  108. // we add a dummy field to avoid empty struct issue with envdecode
  109. DummyField string `env:"ASDF,default=asdf"`
  110. OldEncryptionKey string `env:"OLD_ENCRYPTION_KEY"`
  111. NewEncryptionKey string `env:"NEW_ENCRYPTION_KEY"`
  112. }
  113. func shouldKeyRotate() (bool, string, string) {
  114. var c RotateConf
  115. if err := envdecode.StrictDecode(&c); err != nil {
  116. log.Fatalf("Failed to decode migration conf: %s", err)
  117. return false, "", ""
  118. }
  119. return c.OldEncryptionKey != "" && c.NewEncryptionKey != "", c.OldEncryptionKey, c.NewEncryptionKey
  120. }
  121. type PopulateSourceConfigDisplayNameConf struct {
  122. // we add a dummy field to avoid empty struct issue with envdecode
  123. DummyField string `env:"ASDF,default=asdf"`
  124. // if true, will populate the display name for all source configs
  125. PopulateSourceConfigDisplayName bool `env:"POPULATE_SOURCE_CONFIG_DISPLAY_NAME"`
  126. }
  127. func shouldPopulateSourceConfigDisplayName() bool {
  128. var c PopulateSourceConfigDisplayNameConf
  129. if err := envdecode.StrictDecode(&c); err != nil {
  130. log.Fatalf("Failed to decode migration conf: %s", err)
  131. return false
  132. }
  133. return c.PopulateSourceConfigDisplayName
  134. }