helm_revisions_count_tracker.go 8.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297
  1. //go:build ee
  2. /*
  3. === Helm Release Revisions Tracker Job ===
  4. This job keeps a track of helm releases and their revisions and deletes older revisions once they are
  5. backed up to an S3 bucket.
  6. - The job looks for clusters which have the `monitor_helm_releases` set to true.
  7. - The clusters are then checked for old helm release revisions.
  8. - In a cluster, list of all namespaces is fetched.
  9. - For every namespace, the list of releases is fetched.
  10. - For every release, its revision history is fetched.
  11. - If the number of revisions exceeds 100, then we intend to only keep the most recent 100 revisions.
  12. - For this, the older revisions are first backed up to an S3 bucket and then deleted.
  13. */
  14. package jobs
  15. import (
  16. "encoding/json"
  17. "fmt"
  18. "log"
  19. "os"
  20. "sync"
  21. "time"
  22. "github.com/porter-dev/porter/api/server/shared/config/env"
  23. "github.com/porter-dev/porter/api/types"
  24. "github.com/porter-dev/porter/pkg/logger"
  25. "github.com/porter-dev/porter/provisioner/integrations/storage/s3"
  26. "github.com/porter-dev/porter/workers/utils"
  27. "github.com/porter-dev/porter/ee/integrations/vault"
  28. "github.com/porter-dev/porter/internal/helm"
  29. "github.com/porter-dev/porter/internal/kubernetes"
  30. "github.com/porter-dev/porter/internal/models"
  31. "github.com/porter-dev/porter/internal/oauth"
  32. "github.com/porter-dev/porter/internal/repository"
  33. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  34. rgorm "github.com/porter-dev/porter/internal/repository/gorm"
  35. "golang.org/x/oauth2"
  36. "gorm.io/gorm"
  37. "helm.sh/helm/v3/pkg/releaseutil"
  38. )
  39. var stepSize int = 100
  40. type helmRevisionsCountTracker struct {
  41. enqueueTime time.Time
  42. db *gorm.DB
  43. repo repository.Repository
  44. doConf *oauth2.Config
  45. dbConf *env.DBConf
  46. credBackend rcreds.CredentialStorage
  47. awsAccessKeyID string
  48. awsSecretAccessKey string
  49. awsRegion string
  50. s3BucketName string
  51. encryptionKey *[32]byte
  52. }
  53. // HelmRevisionsCountTrackerOpts holds the options required to run this job
  54. type HelmRevisionsCountTrackerOpts struct {
  55. DBConf *env.DBConf
  56. DOClientID string
  57. DOClientSecret string
  58. DOScopes []string
  59. ServerURL string
  60. AWSAccessKeyID string
  61. AWSSecretAccessKey string
  62. AWSRegion string
  63. S3BucketName string
  64. EncryptionKey string
  65. }
  66. func NewHelmRevisionsCountTracker(
  67. db *gorm.DB,
  68. enqueueTime time.Time,
  69. opts *HelmRevisionsCountTrackerOpts,
  70. ) (*helmRevisionsCountTracker, error) {
  71. var credBackend rcreds.CredentialStorage
  72. if opts.DBConf.VaultAPIKey != "" && opts.DBConf.VaultServerURL != "" && opts.DBConf.VaultPrefix != "" {
  73. credBackend = vault.NewClient(
  74. opts.DBConf.VaultServerURL,
  75. opts.DBConf.VaultAPIKey,
  76. opts.DBConf.VaultPrefix,
  77. )
  78. }
  79. var key [32]byte
  80. for i, b := range []byte(opts.DBConf.EncryptionKey) {
  81. key[i] = b
  82. }
  83. repo := rgorm.NewRepository(db, &key, credBackend)
  84. doConf := oauth.NewDigitalOceanClient(&oauth.Config{
  85. ClientID: opts.DOClientID,
  86. ClientSecret: opts.DOClientSecret,
  87. Scopes: opts.DOScopes,
  88. BaseURL: opts.ServerURL,
  89. })
  90. var s3Key [32]byte
  91. for i, b := range []byte(opts.EncryptionKey) {
  92. s3Key[i] = b
  93. }
  94. return &helmRevisionsCountTracker{
  95. enqueueTime, db, repo, doConf, opts.DBConf, credBackend,
  96. opts.AWSAccessKeyID, opts.AWSSecretAccessKey, opts.AWSRegion,
  97. opts.S3BucketName, &s3Key,
  98. }, nil
  99. }
  100. func (t *helmRevisionsCountTracker) ID() string {
  101. return "helm-revisions-count-tracker"
  102. }
  103. func (t *helmRevisionsCountTracker) EnqueueTime() time.Time {
  104. return t.enqueueTime
  105. }
  106. func (t *helmRevisionsCountTracker) Run() error {
  107. var count int64
  108. if err := t.db.Model(&models.Cluster{}).Count(&count).Error; err != nil {
  109. return err
  110. }
  111. var wg sync.WaitGroup
  112. for i := 0; i < (int(count)/stepSize)+1; i++ {
  113. var clusters []*models.Cluster
  114. if err := t.db.Order("id asc").Offset(i*stepSize).Limit(stepSize).Find(&clusters, "monitor_helm_releases = ?", "1").
  115. Error; err != nil {
  116. return err
  117. }
  118. // go through each project
  119. for _, cluster := range clusters {
  120. wg.Add(1)
  121. go func(projID, clusterID uint) {
  122. defer wg.Done()
  123. log.Printf("starting release revision monitoring for cluster with ID %d", cluster.ID)
  124. cluster, err := t.repo.Cluster().ReadCluster(projID, clusterID)
  125. if err != nil {
  126. log.Printf("error reading cluster ID %d: %v. skipping cluster ...", clusterID, err)
  127. return
  128. }
  129. // create s3 client to store revisions that need to be deleted
  130. s3Client, err := s3.NewS3StorageClient(&s3.S3Options{
  131. t.awsRegion, t.awsAccessKeyID, t.awsSecretAccessKey, t.s3BucketName, t.encryptionKey,
  132. })
  133. if err != nil {
  134. log.Printf("error creating S3 client for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  135. return
  136. }
  137. k8sAgent, err := kubernetes.GetAgentOutOfClusterConfig(&kubernetes.OutOfClusterConfig{
  138. Cluster: cluster,
  139. Repo: t.repo,
  140. DigitalOceanOAuth: t.doConf,
  141. AllowInClusterConnections: false,
  142. })
  143. if err != nil {
  144. log.Printf("error getting k8s agent for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  145. return
  146. }
  147. namespaces, err := k8sAgent.ListNamespaces()
  148. if err != nil {
  149. log.Printf("error fetching namespaces for cluster ID %d: %v. skipping cluster ...", cluster.ID, err)
  150. return
  151. }
  152. log.Printf("fetched %d namespaces for cluster ID %d", len(namespaces.Items), cluster.ID)
  153. for _, ns := range namespaces.Items {
  154. agent, err := utils.NewRetryHelmAgent(&helm.Form{
  155. Cluster: cluster,
  156. Namespace: ns.Name,
  157. Repo: t.repo,
  158. DigitalOceanOAuth: t.doConf,
  159. AllowInClusterConnections: false,
  160. }, logger.New(true, os.Stdout), 3, time.Second)
  161. if err != nil {
  162. log.Printf("error fetching helm client for namespace %s in cluster ID %d: %v. "+
  163. "skipping namespace ...", ns.Name, cluster.ID, err)
  164. continue
  165. }
  166. releases, err := agent.ListReleases(ns.GetName(), &types.ReleaseListFilter{
  167. ByDate: true,
  168. StatusFilter: []string{
  169. "deployed",
  170. "pending",
  171. "pending-install",
  172. "pending-upgrade",
  173. "pending-rollback",
  174. "failed",
  175. },
  176. })
  177. if err != nil {
  178. log.Printf("error fetching releases for namespace %s in cluster ID %d: %v. skipping namespace ...",
  179. ns.Name, cluster.ID, err)
  180. continue
  181. }
  182. log.Printf("fetched %d releases for namespace %s in cluster ID %d", len(releases), ns.Name, cluster.ID)
  183. for _, rel := range releases {
  184. revisions, err := agent.GetReleaseHistory(rel.Name)
  185. if err != nil {
  186. log.Printf("error fetching release history for release %s in namespace %s of cluster ID %d: %v."+
  187. " skipping release ...", rel.Name, ns.Name, cluster.ID, err)
  188. continue
  189. }
  190. if len(revisions) <= 100 {
  191. log.Printf("release %s of namespace %s in cluster ID %d has <= 100 revisions. "+
  192. "skipping release...", rel.Name, ns.Name, cluster.ID)
  193. continue
  194. }
  195. log.Printf("release %s of namespace %s in cluster ID %d has more than 100 revisions. attempting to "+
  196. "delete the older ones.", rel.Name, ns.Name, cluster.ID)
  197. // sort revisions from newest to oldest
  198. releaseutil.Reverse(revisions, releaseutil.SortByRevision)
  199. for i := 100; i < len(revisions); i += 1 {
  200. rev := revisions[i]
  201. // store the revision in the s3 bucket before deleting it
  202. data, err := json.Marshal(rev)
  203. if err != nil {
  204. log.Printf("error marshalling revision for release %s, number %d: %v. skipping revision ...",
  205. rev.Name, rev.Version, err)
  206. continue
  207. }
  208. // write to the bucket with key - <project_id>/<cluster_id>/<namespace>/<release_name>/<revision_number>
  209. err = s3Client.WriteFileWithKey(data, true, fmt.Sprintf("%d/%d/%s/%s/%d", cluster.ProjectID,
  210. cluster.ID, rel.Namespace, rel.Name, rev.Version))
  211. if err != nil {
  212. log.Printf("error backing up revision for release %s, number %d: %v. skipping revision ...",
  213. rev.Name, rev.Version, err)
  214. continue
  215. }
  216. log.Printf("revision %d of release %s in namespace %s of cluster ID %d was successfully backed up.",
  217. rev.Version, rel.Name, ns.Name, cluster.ID)
  218. err = agent.DeleteReleaseRevision(rev.Name, rev.Version)
  219. if err != nil {
  220. log.Printf("error deleting revision %d of release %s in namespace %s of cluster ID %d: %v",
  221. rev.Version, rel.Name, ns.Name, cluster.ID, err)
  222. continue
  223. }
  224. log.Printf("revision %d of release %s in namespace %s of cluster ID %d was successfully deleted.",
  225. rev.Version, rel.Name, ns.Name, cluster.ID)
  226. }
  227. }
  228. }
  229. }(cluster.ProjectID, cluster.ID)
  230. }
  231. wg.Wait()
  232. }
  233. return nil
  234. }
  235. func (t *helmRevisionsCountTracker) SetData([]byte) {}