forked from TykTechnologies/tyk
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathle_helpers.go
102 lines (75 loc) · 2.17 KB
/
le_helpers.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
package main
import (
"encoding/json"
"rsc.io/letsencrypt"
"github.com/Sirupsen/logrus"
"github.com/TykTechnologies/tyk/config"
"github.com/TykTechnologies/tyk/storage"
)
const LEKeyPrefix = "le_ssl:"
func StoreLEState(m *letsencrypt.Manager) {
log.Debug("Storing SSL backup")
log.Debug("[SSL] --> Connecting to DB")
store := storage.RedisCluster{KeyPrefix: LEKeyPrefix}
connected := store.Connect()
log.Debug("--> Connected to DB")
if !connected {
log.Error("[SSL] --> SSL Backup save failed: redis connection failed")
return
}
state := m.Marshal()
secret := rightPad2Len(config.Global.Secret, "=", 32)
cryptoText := encrypt([]byte(secret), state)
if err := store.SetKey("cache", cryptoText, -1); err != nil {
log.Error("[SSL] --> Failed to store SSL backup: ", err)
return
}
}
func GetLEState(m *letsencrypt.Manager) {
checkKey := "cache"
store := storage.RedisCluster{KeyPrefix: LEKeyPrefix}
connected := store.Connect()
log.Debug("[SSL] --> Connected to DB")
if !connected {
log.Error("[SSL] --> SSL Backup recovery failed: redis connection failed")
return
}
cryptoText, err := store.GetKey(checkKey)
if err != nil {
log.Warning("[SSL] --> No SSL backup: ", err)
return
}
secret := rightPad2Len(config.Global.Secret, "=", 32)
sslState := decrypt([]byte(secret), cryptoText)
m.Unmarshal(sslState)
}
type LE_ServerInfo struct {
HostName string
ID string
}
func onLESSLStatusReceivedHandler(payload string) {
serverData := LE_ServerInfo{}
if err := json.Unmarshal([]byte(payload), &serverData); err != nil {
log.WithFields(logrus.Fields{
"prefix": "pub-sub",
}).Error("Failed unmarshal server data: ", err)
return
}
log.Debug("Received LE data: ", serverData)
// not great
if serverData.ID != NodeID {
log.Info("Received Redis LE change notification!")
GetLEState(&LE_MANAGER)
}
log.Info("Received Redis LE change notification from myself, ignoring")
}
func StartPeriodicStateBackup(m *letsencrypt.Manager) {
for range m.Watch() {
// First run will call a cache save that overwrites with null data
if LE_FIRSTRUN {
log.Info("[SSL] State change detected, storing")
StoreLEState(m)
}
LE_FIRSTRUN = true
}
}