forked from TykTechnologies/tyk
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathle_helpers.go
106 lines (79 loc) · 2.29 KB
/
le_helpers.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
package gateway
import (
"encoding/json"
"rsc.io/letsencrypt"
"github.com/sirupsen/logrus"
"github.com/TykTechnologies/tyk/storage"
)
const LEKeyPrefix = "le_ssl:"
func (gw *Gateway) StoreLEState(m *letsencrypt.Manager) {
log.Debug("Storing SSL backup")
log.Debug("[SSL] --> Connecting to DB")
store := storage.RedisCluster{KeyPrefix: LEKeyPrefix, RedisController: gw.RedisController}
connected := store.Connect()
log.Debug("--> Connected to DB")
if !connected {
log.Error("[SSL] --> SSL Backup save failed: redis connection failed")
return
}
state := m.Marshal()
secret := rightPad2Len(gw.GetConfig().Secret, "=", 32)
cryptoText := encrypt([]byte(secret), state)
if err := store.SetKey("cache", cryptoText, -1); err != nil {
log.Error("[SSL] --> Failed to store SSL backup: ", err)
return
}
}
func (gw *Gateway) GetLEState(m *letsencrypt.Manager) {
checkKey := "cache"
store := storage.RedisCluster{KeyPrefix: LEKeyPrefix, RedisController: gw.RedisController}
connected := store.Connect()
log.Debug("[SSL] --> Connected to DB")
if !connected {
log.Error("[SSL] --> SSL Backup recovery failed: redis connection failed")
return
}
cryptoText, err := store.GetKey(checkKey)
if err != nil {
log.Warning("[SSL] --> No SSL backup: ", err)
return
}
secret := rightPad2Len(gw.GetConfig().Secret, "=", 32)
sslState := decrypt([]byte(secret), cryptoText)
m.Unmarshal(sslState)
}
type LE_ServerInfo struct {
HostName string
ID string
}
func (gw *Gateway) onLESSLStatusReceivedHandler(payload string) {
serverData := LE_ServerInfo{}
if err := json.Unmarshal([]byte(payload), &serverData); err != nil {
log.WithFields(logrus.Fields{
"prefix": "pub-sub",
}).Error("Failed unmarshal server data: ", err)
return
}
log.Debug("Received LE data: ", serverData)
// not great
if serverData.ID != gw.GetNodeID() {
log.Info("Received Redis LE change notification!")
gw.GetLEState(&gw.LE_MANAGER)
}
log.Info("Received Redis LE change notification from myself, ignoring")
}
func (gw *Gateway) StartPeriodicStateBackup(m *letsencrypt.Manager) {
watch := m.Watch()
for {
select {
case <-gw.ctx.Done():
return
case <-watch:
if gw.LE_FIRSTRUN {
log.Info("[SSL] State change detected, storing")
gw.StoreLEState(m)
}
gw.LE_FIRSTRUN = true
}
}
}