Fixing errors / reformating code
This commit is contained in:
parent
078cb31eb7
commit
3b2e9a43fd
11 changed files with 368 additions and 316 deletions
|
|
@ -1,46 +1,26 @@
|
|||
from easymapping import HaproxyConfigGenerator
|
||||
from functions import Functions, Consts
|
||||
import yaml
|
||||
import sys
|
||||
import os
|
||||
import json
|
||||
import base64
|
||||
import docker
|
||||
import socket
|
||||
|
||||
import docker
|
||||
import yaml
|
||||
from kubernetes import client, config
|
||||
from kubernetes.client.rest import ApiException
|
||||
|
||||
class ContainerEnv:
|
||||
@staticmethod
|
||||
def read():
|
||||
env_vars = {
|
||||
"customerrors": True if os.getenv("HAPROXY_CUSTOMERRORS") == "true" else False,
|
||||
"ssl_mode": os.getenv("EASYHAPROXY_SSL_MODE").lower() if os.getenv("EASYHAPROXY_SSL_MODE") else 'default'
|
||||
}
|
||||
|
||||
if os.getenv("HAPROXY_PASSWORD"):
|
||||
env_vars["stats"] = {
|
||||
"username": os.getenv("HAPROXY_USERNAME") if os.getenv("HAPROXY_USERNAME") else "admin",
|
||||
"password": os.getenv("HAPROXY_PASSWORD"),
|
||||
"port": os.getenv("HAPROXY_STATS_PORT") if os.getenv("HAPROXY_STATS_PORT") else "1936",
|
||||
}
|
||||
|
||||
env_vars["lookup_label"] = os.getenv("EASYHAPROXY_LABEL_PREFIX") if os.getenv("EASYHAPROXY_LABEL_PREFIX") else "easyhaproxy"
|
||||
|
||||
env_vars["certbot"] = {
|
||||
"email": os.getenv("EASYHAPROXY_CERTBOT_EMAIL", ""),
|
||||
"server": os.getenv("EASYHAPROXY_CERTBOT_SERVER", False),
|
||||
"eab_kid": os.getenv("EASYHAPROXY_CERTBOT_EAB_KID", ""),
|
||||
"eab_hmac_key": os.getenv("EASYHAPROXY_CERTBOT_EAB_HMAC_KEY", ""),
|
||||
}
|
||||
|
||||
return env_vars
|
||||
from easymapping import HaproxyConfigGenerator
|
||||
from functions import Functions, Consts, ContainerEnv
|
||||
|
||||
|
||||
class ProcessorInterface:
|
||||
static_file = Consts.easyhaproxy_config
|
||||
|
||||
def __init__(self, filename = None):
|
||||
def __init__(self, filename=None):
|
||||
self.certbot_hosts = None
|
||||
self.parsed_object = None
|
||||
self.cfg = None
|
||||
self.hosts = None
|
||||
self.cfg = None
|
||||
self.certbot_hosts = None
|
||||
self.hosts = None
|
||||
self.filename = filename
|
||||
self.refresh()
|
||||
|
||||
|
|
@ -55,7 +35,8 @@ class ProcessorInterface:
|
|||
elif mode == "kubernetes":
|
||||
return Kubernetes()
|
||||
else:
|
||||
Functions.log("EASYHAPROXY", Functions.FATAL, "Expected mode to be 'static', 'docker', 'swarm' or 'kubernetes'. I got '%s'" % (mode))
|
||||
Functions.log("EASYHAPROXY", Functions.FATAL,
|
||||
"Expected mode to be 'static', 'docker', 'swarm' or 'kubernetes'. I got '%s'" % mode)
|
||||
return None
|
||||
|
||||
def refresh(self):
|
||||
|
|
@ -67,7 +48,7 @@ class ProcessorInterface:
|
|||
self.parse()
|
||||
|
||||
def inspect_network(self):
|
||||
#Abstract
|
||||
# Abstract
|
||||
pass
|
||||
|
||||
def parse(self):
|
||||
|
|
@ -82,7 +63,7 @@ class ProcessorInterface:
|
|||
def get_parsed_object(self):
|
||||
return self.parsed_object
|
||||
|
||||
def get_certs(self, key = None):
|
||||
def get_certs(self, key=None):
|
||||
if key is None:
|
||||
return self.cfg.certs
|
||||
else:
|
||||
|
|
@ -103,20 +84,27 @@ class ProcessorInterface:
|
|||
|
||||
|
||||
class Static(ProcessorInterface):
|
||||
def __init__(self, filename=None):
|
||||
self.parsed_object = None
|
||||
self.static_content = None
|
||||
self.static_content = None
|
||||
self.cfg = None
|
||||
super().__init__(filename)
|
||||
|
||||
def inspect_network(self):
|
||||
self.parsed_object = {}
|
||||
self.static_content = None
|
||||
|
||||
|
||||
def get_parsed_object(self):
|
||||
return self.static_content["easymapping"] if "easymapping" in self.static_content else []
|
||||
|
||||
def get_hosts(self):
|
||||
hosts = []
|
||||
for object in self.get_parsed_object():
|
||||
if "hosts" not in object:
|
||||
for obj in self.get_parsed_object():
|
||||
if "hosts" not in obj:
|
||||
continue
|
||||
for host in object["hosts"].keys():
|
||||
hosts.append("%s:%s" % (host, object["port"]))
|
||||
for host in obj["hosts"].keys():
|
||||
hosts.append("%s:%s" % (host, obj["port"]))
|
||||
return hosts
|
||||
|
||||
def parse(self):
|
||||
|
|
@ -125,18 +113,21 @@ class Static(ProcessorInterface):
|
|||
|
||||
|
||||
class Docker(ProcessorInterface):
|
||||
def __init__(self, filename = None):
|
||||
def __init__(self, filename=None):
|
||||
self.parsed_object = None
|
||||
self.client = docker.from_env()
|
||||
super().__init__()
|
||||
|
||||
|
||||
def inspect_network(self):
|
||||
try:
|
||||
ha_proxy_network_name = next(iter(self.client.containers.get(socket.gethostname()).attrs["NetworkSettings"]["Networks"]))
|
||||
ha_proxy_network_name = next(
|
||||
iter(self.client.containers.get(socket.gethostname()).attrs["NetworkSettings"]["Networks"]))
|
||||
except:
|
||||
# HAProxy is not running in a container, get first container network
|
||||
if len(self.client.containers.list()) == 0:
|
||||
return
|
||||
ha_proxy_network_name = next(iter(self.client.containers.get(self.client.containers.list()[0].name).attrs["NetworkSettings"]["Networks"]))
|
||||
ha_proxy_network_name = next(iter(
|
||||
self.client.containers.get(self.client.containers.list()[0].name).attrs["NetworkSettings"]["Networks"]))
|
||||
|
||||
ha_proxy_network = self.client.networks.get(ha_proxy_network_name)
|
||||
|
||||
|
|
@ -152,17 +143,22 @@ class Docker(ProcessorInterface):
|
|||
|
||||
|
||||
class Swarm(ProcessorInterface):
|
||||
def __init__(self, filename = None):
|
||||
def __init__(self, filename=None):
|
||||
self.parsed_object = None
|
||||
self.client = docker.from_env()
|
||||
super().__init__()
|
||||
|
||||
def inspect_network(self):
|
||||
ha_proxy_service_name = self.client.containers.get(socket.gethostname()).name.split('.')[0]
|
||||
for endpoint in self.client.services.get(ha_proxy_service_name).attrs['Endpoint']["VirtualIPs"]:
|
||||
ha_proxy_network_id = None
|
||||
for endpoint in self.client.services.get(ha_proxy_service_name).attrs['Endpoint']["VirtualIPs"]:
|
||||
ha_proxy_network_id = endpoint["NetworkID"]
|
||||
if self.client.networks.get(ha_proxy_network_id).name != 'ingress':
|
||||
break
|
||||
|
||||
if ha_proxy_network_id is None:
|
||||
raise "Could not find ingress network"
|
||||
|
||||
self.parsed_object = {}
|
||||
for service in self.client.services.list():
|
||||
ip_address = None
|
||||
|
|
@ -172,17 +168,18 @@ class Swarm(ProcessorInterface):
|
|||
ip_address = endpoint["Addr"].split("/")[0]
|
||||
break
|
||||
network_list.append(endpoint["NetworkID"])
|
||||
|
||||
|
||||
if ip_address is None:
|
||||
network_list.append(ha_proxy_network_id)
|
||||
service.update(networks = network_list)
|
||||
continue # skip to the next service to give time to update the network
|
||||
|
||||
service.update(networks=network_list)
|
||||
continue # skip to the next service to give time to update the network
|
||||
|
||||
self.parsed_object[ip_address] = service.attrs["Spec"]["Labels"]
|
||||
|
||||
|
||||
class Kubernetes(ProcessorInterface):
|
||||
def __init__(self, filename = None):
|
||||
def __init__(self, filename=None):
|
||||
self.parsed_object = None
|
||||
config.load_incluster_config()
|
||||
config.verify_ssl = False
|
||||
self.api_instance = client.CoreV1Api()
|
||||
|
|
@ -190,13 +187,14 @@ class Kubernetes(ProcessorInterface):
|
|||
self.cert_cache = {}
|
||||
super().__init__()
|
||||
|
||||
def _check_annotation(self, annotations, key):
|
||||
@staticmethod
|
||||
def _check_annotation(annotations, key):
|
||||
if key not in annotations:
|
||||
return None
|
||||
return annotations[key]
|
||||
|
||||
def inspect_network(self):
|
||||
|
||||
|
||||
ret = self.v1.list_ingress_for_all_namespaces(watch=False)
|
||||
|
||||
self.parsed_object = {}
|
||||
|
|
@ -216,10 +214,8 @@ class Kubernetes(ProcessorInterface):
|
|||
if listen_port is None:
|
||||
listen_port = 80
|
||||
|
||||
data = {}
|
||||
data["creation_timestamp"] = ingress.metadata.creation_timestamp.strftime("%x %X")
|
||||
data["resource_version"] = ingress.metadata.resource_version
|
||||
data["namespace"] = ingress.metadata.namespace
|
||||
data = {"creation_timestamp": ingress.metadata.creation_timestamp.strftime("%x %X"),
|
||||
"resource_version": ingress.metadata.resource_version, "namespace": ingress.metadata.namespace}
|
||||
|
||||
ingress_name = ingress.metadata.namespace
|
||||
|
||||
|
|
@ -233,33 +229,36 @@ class Kubernetes(ProcessorInterface):
|
|||
if tls.secret_name not in self.cert_cache or self.cert_cache[tls.secret_name] != secret.data:
|
||||
self.cert_cache[tls.secret_name] = secret.data
|
||||
Functions.save(
|
||||
"{0}/{1}.pem".format(Consts.certs_haproxy, tls.secret_name),
|
||||
base64.b64decode(secret.data["tls.crt"]).decode('ascii') + "\n" + base64.b64decode(secret.data["tls.key"]).decode('ascii')
|
||||
"{0}/{1}.pem".format(Consts.certs_haproxy, tls.secret_name),
|
||||
base64.b64decode(secret.data["tls.crt"]).decode('ascii') + "\n" + base64.b64decode(
|
||||
secret.data["tls.key"]).decode('ascii')
|
||||
)
|
||||
|
||||
ssl_hosts.extend(tls.hosts)
|
||||
except Exception as e:
|
||||
Functions.log("EASYHAPROXY", Functions.WARN, "Ingress %s - Get secret failed: '%s'" % (ingress_name, e))
|
||||
Functions.log("EASYHAPROXY", Functions.WARN,
|
||||
"Ingress %s - Get secret failed: '%s'" % (ingress_name, e))
|
||||
|
||||
Functions.log("EASYHAPROXY", Functions.TRACE, "Ingress %s - SSL Hosts found '%s'" % (ingress_name, ssl_hosts))
|
||||
Functions.log("EASYHAPROXY", Functions.TRACE,
|
||||
"Ingress %s - SSL Hosts found '%s'" % (ingress_name, ssl_hosts))
|
||||
|
||||
for rule in ingress.spec.rules:
|
||||
rule_data = {}
|
||||
port_number = rule.http.paths[0].backend.service.port.number
|
||||
definition = "easyhaproxy.%s_%s" % (rule.host.replace(".", "-"), port_number)
|
||||
rule_data["%s.host" % (definition)] = rule.host
|
||||
rule_data["%s.port" % (definition)] = listen_port
|
||||
rule_data["%s.localport" % (definition)] = port_number
|
||||
rule_data["%s.host" % definition] = rule.host
|
||||
rule_data["%s.port" % definition] = listen_port
|
||||
rule_data["%s.localport" % definition] = port_number
|
||||
if rule.host in ssl_hosts:
|
||||
rule_data["%s.clone_to_ssl" % (definition)] = 'true'
|
||||
rule_data["%s.clone_to_ssl" % definition] = 'true'
|
||||
if redirect_ssl is not None:
|
||||
rule_data["%s.redirect_ssl" % (definition)] = redirect_ssl
|
||||
rule_data["%s.redirect_ssl" % definition] = redirect_ssl
|
||||
if certbot is not None:
|
||||
rule_data["%s.certbot" % (definition)] = certbot
|
||||
rule_data["%s.certbot" % definition] = certbot
|
||||
if redirect is not None:
|
||||
rule_data["%s.redirect" % (definition)] = redirect
|
||||
rule_data["%s.redirect" % definition] = redirect
|
||||
if mode is not None:
|
||||
rule_data["%s.mode" % (definition)] = mode
|
||||
rule_data["%s.mode" % definition] = mode
|
||||
|
||||
service_name = rule.http.paths[0].backend.service.name
|
||||
try:
|
||||
|
|
@ -267,13 +266,10 @@ class Kubernetes(ProcessorInterface):
|
|||
cluster_ip = api_response.spec.cluster_ip
|
||||
except ApiException as e:
|
||||
cluster_ip = None
|
||||
Functions.log("EASYHAPROXY", Functions.WARN, "Ingress %s - Service %s - Failed: '%s'" % (ingress_name, service_name, e))
|
||||
|
||||
Functions.log("EASYHAPROXY", Functions.WARN,
|
||||
"Ingress %s - Service %s - Failed: '%s'" % (ingress_name, service_name, e))
|
||||
|
||||
if cluster_ip is not None:
|
||||
if cluster_ip not in self.parsed_object.keys():
|
||||
self.parsed_object[cluster_ip] = data
|
||||
self.parsed_object[cluster_ip].update(rule_data)
|
||||
|
||||
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue