2
0

main.go 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238
  1. //go:build ee
  2. package main
  3. import (
  4. "context"
  5. "encoding/json"
  6. "fmt"
  7. "log"
  8. "net/http"
  9. "os"
  10. "os/signal"
  11. "syscall"
  12. "time"
  13. "github.com/go-chi/chi"
  14. "github.com/go-chi/chi/middleware"
  15. "github.com/joeshaw/envdecode"
  16. "github.com/porter-dev/porter/api/server/shared/config/env"
  17. "github.com/porter-dev/porter/internal/adapter"
  18. "github.com/porter-dev/porter/internal/opa"
  19. "github.com/porter-dev/porter/internal/repository"
  20. "github.com/porter-dev/porter/internal/worker"
  21. "github.com/porter-dev/porter/workers/jobs"
  22. "gorm.io/gorm"
  23. "github.com/porter-dev/porter/ee/integrations/vault"
  24. rcreds "github.com/porter-dev/porter/internal/repository/credentials"
  25. pgorm "github.com/porter-dev/porter/internal/repository/gorm"
  26. )
  27. var (
  28. jobQueue chan worker.Job
  29. envDecoder = EnvConf{}
  30. dbConn *gorm.DB
  31. repo repository.Repository
  32. opaPolicies *opa.KubernetesPolicies
  33. )
  34. // EnvConf holds the environment variables for this binary
  35. type EnvConf struct {
  36. ServerURL string `env:"SERVER_URL,default=http://localhost:8080"`
  37. DOClientID string `env:"DO_CLIENT_ID"`
  38. DOClientSecret string `env:"DO_CLIENT_SECRET"`
  39. DBConf env.DBConf
  40. MaxWorkers uint `env:"MAX_WORKERS,default=10"`
  41. MaxQueue uint `env:"MAX_QUEUE,default=100"`
  42. AWSAccessKeyID string `env:"AWS_ACCESS_KEY_ID"`
  43. AWSSecretAccessKey string `env:"AWS_SECRET_ACCESS_KEY"`
  44. AWSRegion string `env:"AWS_REGION"`
  45. S3BucketName string `env:"S3_BUCKET_NAME"`
  46. EncryptionKey string `env:"S3_ENCRYPTION_KEY"`
  47. OPAConfigFileDir string `env:"OPA_CONFIG_FILE_DIR,default=./internal/opa"`
  48. LegacyProjectIDs []uint `env:"LEGACY_PROJECT_IDS"`
  49. Port uint `env:"PORT,default=3000"`
  50. RevisionsCount int `env:"REVISIONS_COUNT,default=20"`
  51. }
  52. func main() {
  53. if err := envdecode.StrictDecode(&envDecoder); err != nil {
  54. log.Fatalf("Failed to decode server conf: %v", err)
  55. }
  56. log.Printf("setting max worker count to: %d\n", envDecoder.MaxWorkers)
  57. log.Printf("setting max job queue count to: %d\n", envDecoder.MaxQueue)
  58. log.Printf("legacy project ids are: %v", envDecoder.LegacyProjectIDs)
  59. db, err := adapter.New(&envDecoder.DBConf)
  60. if err != nil {
  61. log.Fatalln(err)
  62. }
  63. dbConn = db
  64. var credBackend rcreds.CredentialStorage
  65. if envDecoder.DBConf.VaultAPIKey != "" && envDecoder.DBConf.VaultServerURL != "" && envDecoder.DBConf.VaultPrefix != "" {
  66. credBackend = vault.NewClient(
  67. envDecoder.DBConf.VaultServerURL,
  68. envDecoder.DBConf.VaultAPIKey,
  69. envDecoder.DBConf.VaultPrefix,
  70. )
  71. }
  72. var key [32]byte
  73. for i, b := range []byte(envDecoder.DBConf.EncryptionKey) {
  74. key[i] = b
  75. }
  76. repo = pgorm.NewRepository(db, &key, credBackend)
  77. opaPolicies, err = opa.LoadPolicies(envDecoder.OPAConfigFileDir)
  78. if err != nil {
  79. log.Fatalln(err)
  80. }
  81. jobQueue = make(chan worker.Job, envDecoder.MaxQueue)
  82. d := worker.NewDispatcher(int(envDecoder.MaxWorkers))
  83. log.Println("starting worker dispatcher")
  84. err = d.Run(jobQueue)
  85. if err != nil {
  86. log.Fatalln(err)
  87. }
  88. server := &http.Server{Addr: fmt.Sprintf(":%d", envDecoder.Port), Handler: httpService()}
  89. serverCtx, serverStopCtx := context.WithCancel(context.Background())
  90. sig := make(chan os.Signal, 1)
  91. signal.Notify(sig, syscall.SIGHUP, syscall.SIGINT, syscall.SIGTERM, syscall.SIGQUIT)
  92. go func() {
  93. <-sig
  94. log.Println("shutting down server")
  95. shutdownCtx, shutdownCtxCancel := context.WithTimeout(serverCtx, 30*time.Second)
  96. defer shutdownCtxCancel()
  97. go func() {
  98. <-shutdownCtx.Done()
  99. if shutdownCtx.Err() == context.DeadlineExceeded {
  100. log.Fatal("graceful shutdown timed out.. forcing exit.")
  101. }
  102. }()
  103. err = server.Shutdown(shutdownCtx)
  104. if err != nil {
  105. log.Fatalln(err)
  106. }
  107. log.Println("server shutdown completed")
  108. serverStopCtx()
  109. }()
  110. log.Println("starting HTTP server at :3000")
  111. err = server.ListenAndServe()
  112. if err != nil && err != http.ErrServerClosed {
  113. log.Fatalf("error starting HTTP server: %v", err)
  114. }
  115. // Wait for server context to be stopped
  116. <-serverCtx.Done()
  117. d.Exit()
  118. }
  119. func httpService() http.Handler {
  120. log.Println("setting up HTTP router and adding middleware")
  121. r := chi.NewRouter()
  122. r.Use(middleware.Logger)
  123. r.Use(middleware.Recoverer)
  124. r.Use(middleware.Heartbeat("/ping"))
  125. // r.Use(middleware.AllowContentType("application/json"))
  126. r.Mount("/debug", middleware.Profiler())
  127. log.Println("setting up HTTP POST endpoint to enqueue jobs")
  128. r.Post("/enqueue/{id}", func(w http.ResponseWriter, r *http.Request) {
  129. req := make(map[string]interface{})
  130. if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
  131. log.Printf("error converting body to json: %v", err)
  132. return
  133. }
  134. job := getJob(chi.URLParam(r, "id"), req)
  135. if job == nil {
  136. w.WriteHeader(http.StatusNotFound)
  137. return
  138. }
  139. jobQueue <- job
  140. w.WriteHeader(http.StatusCreated)
  141. })
  142. return r
  143. }
  144. func getJob(id string, input map[string]interface{}) worker.Job {
  145. if id == "helm-revisions-count-tracker" {
  146. newJob, err := jobs.NewHelmRevisionsCountTracker(dbConn, time.Now().UTC(), &jobs.HelmRevisionsCountTrackerOpts{
  147. DBConf: &envDecoder.DBConf,
  148. DOClientID: envDecoder.DOClientID,
  149. DOClientSecret: envDecoder.DOClientSecret,
  150. DOScopes: []string{"read", "write"},
  151. ServerURL: envDecoder.ServerURL,
  152. AWSAccessKeyID: envDecoder.AWSAccessKeyID,
  153. AWSSecretAccessKey: envDecoder.AWSSecretAccessKey,
  154. AWSRegion: envDecoder.AWSRegion,
  155. S3BucketName: envDecoder.S3BucketName,
  156. EncryptionKey: envDecoder.EncryptionKey,
  157. RevisionsCount: envDecoder.RevisionsCount,
  158. })
  159. if err != nil {
  160. log.Printf("error creating job with ID: helm-revisions-count-tracker. Error: %v", err)
  161. return nil
  162. }
  163. return newJob
  164. } else if id == "recommender" {
  165. newJob, err := jobs.NewRecommender(dbConn, time.Now().UTC(), &jobs.RecommenderOpts{
  166. DBConf: &envDecoder.DBConf,
  167. DOClientID: envDecoder.DOClientID,
  168. DOClientSecret: envDecoder.DOClientSecret,
  169. DOScopes: []string{"read", "write"},
  170. ServerURL: envDecoder.ServerURL,
  171. Input: input,
  172. LegacyProjectIDs: envDecoder.LegacyProjectIDs,
  173. }, opaPolicies)
  174. if err != nil {
  175. log.Printf("error creating job with ID: recommender. Error: %v", err)
  176. return nil
  177. }
  178. return newJob
  179. }
  180. return nil
  181. }