2014-06-06 23:40:48 +00:00
|
|
|
/*
|
|
|
|
Copyright 2014 Google Inc. All rights reserved.
|
|
|
|
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
package proxy
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"io"
|
|
|
|
"net"
|
2014-07-30 13:52:03 +00:00
|
|
|
"strconv"
|
2014-09-10 20:44:20 +00:00
|
|
|
"strings"
|
2014-07-30 13:52:03 +00:00
|
|
|
"sync"
|
2014-06-06 23:40:48 +00:00
|
|
|
"time"
|
|
|
|
|
|
|
|
"github.com/GoogleCloudPlatform/kubernetes/pkg/api"
|
2014-07-30 13:52:03 +00:00
|
|
|
"github.com/GoogleCloudPlatform/kubernetes/pkg/util"
|
2014-09-18 23:03:34 +00:00
|
|
|
"github.com/GoogleCloudPlatform/kubernetes/pkg/util/iptables"
|
2014-06-25 03:51:57 +00:00
|
|
|
"github.com/golang/glog"
|
2014-06-06 23:40:48 +00:00
|
|
|
)
|
|
|
|
|
2014-07-30 13:52:03 +00:00
|
|
|
type serviceInfo struct {
|
2014-09-18 23:03:34 +00:00
|
|
|
portalIP net.IP
|
|
|
|
portalPort int
|
|
|
|
protocol api.Protocol
|
|
|
|
proxyPort int
|
|
|
|
socket proxySocket
|
|
|
|
timeout time.Duration
|
|
|
|
mu sync.Mutex // protects active
|
|
|
|
active bool
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
|
|
|
|
2014-09-11 23:08:25 +00:00
|
|
|
func (si *serviceInfo) isActive() bool {
|
|
|
|
si.mu.Lock()
|
|
|
|
defer si.mu.Unlock()
|
|
|
|
return si.active
|
|
|
|
}
|
|
|
|
|
|
|
|
func (si *serviceInfo) setActive(val bool) bool {
|
|
|
|
si.mu.Lock()
|
|
|
|
defer si.mu.Unlock()
|
|
|
|
tmp := si.active
|
|
|
|
si.active = val
|
|
|
|
return tmp
|
|
|
|
}
|
|
|
|
|
2014-09-11 16:00:06 +00:00
|
|
|
// How long we wait for a connection to a backend.
|
|
|
|
const endpointDialTimeout = 5 * time.Second
|
|
|
|
|
2014-09-10 20:44:20 +00:00
|
|
|
// Abstraction over TCP/UDP sockets which are proxied.
|
|
|
|
type proxySocket interface {
|
|
|
|
// Addr gets the net.Addr for a proxySocket.
|
|
|
|
Addr() net.Addr
|
2014-09-11 16:00:06 +00:00
|
|
|
// Close stops the proxySocket from accepting incoming connections. Each implementation should comment
|
|
|
|
// on the impact of calling Close while sessions are active.
|
2014-09-10 20:44:20 +00:00
|
|
|
Close() error
|
|
|
|
// ProxyLoop proxies incoming connections for the specified service to the service endpoints.
|
2014-09-18 23:03:34 +00:00
|
|
|
ProxyLoop(service string, info *serviceInfo, proxier *Proxier)
|
2014-09-10 20:44:20 +00:00
|
|
|
}
|
|
|
|
|
2014-09-11 16:00:06 +00:00
|
|
|
// tcpProxySocket implements proxySocket. Close() is implemented by net.Listener. When Close() is called,
|
|
|
|
// no new connections are allowed but existing connections are left untouched.
|
2014-09-10 20:44:20 +00:00
|
|
|
type tcpProxySocket struct {
|
|
|
|
net.Listener
|
|
|
|
}
|
|
|
|
|
2014-09-18 23:03:34 +00:00
|
|
|
func (tcp *tcpProxySocket) ProxyLoop(service string, info *serviceInfo, proxier *Proxier) {
|
2014-09-10 20:44:20 +00:00
|
|
|
for {
|
2014-09-11 23:08:25 +00:00
|
|
|
if !info.isActive() {
|
2014-09-10 20:44:20 +00:00
|
|
|
break
|
|
|
|
}
|
|
|
|
|
|
|
|
// Block until a connection is made.
|
|
|
|
inConn, err := tcp.Accept()
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Accept failed: %v", err)
|
|
|
|
continue
|
|
|
|
}
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(2).Infof("Accepted TCP connection from %v to %v", inConn.RemoteAddr(), inConn.LocalAddr())
|
2014-09-10 20:44:20 +00:00
|
|
|
endpoint, err := proxier.loadBalancer.NextEndpoint(service, inConn.RemoteAddr())
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Couldn't find an endpoint for %s %v", service, err)
|
|
|
|
inConn.Close()
|
|
|
|
continue
|
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
glog.V(3).Infof("Mapped service %q to endpoint %s", service, endpoint)
|
2014-09-10 20:44:20 +00:00
|
|
|
// TODO: This could spin up a new goroutine to make the outbound connection,
|
|
|
|
// and keep accepting inbound traffic.
|
2014-09-11 16:00:06 +00:00
|
|
|
outConn, err := net.DialTimeout("tcp", endpoint, endpointDialTimeout)
|
2014-09-10 20:44:20 +00:00
|
|
|
if err != nil {
|
|
|
|
// TODO: Try another endpoint?
|
|
|
|
glog.Errorf("Dial failed: %v", err)
|
|
|
|
inConn.Close()
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
// Spin up an async copy loop.
|
2014-09-14 19:14:22 +00:00
|
|
|
go proxyTCP(inConn.(*net.TCPConn), outConn.(*net.TCPConn))
|
2014-09-10 20:44:20 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// proxyTCP proxies data bi-directionally between in and out.
|
|
|
|
func proxyTCP(in, out *net.TCPConn) {
|
2014-09-14 19:14:22 +00:00
|
|
|
var wg sync.WaitGroup
|
|
|
|
wg.Add(2)
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(4).Infof("Creating proxy between %v <-> %v <-> %v <-> %v",
|
2014-09-10 20:44:20 +00:00
|
|
|
in.RemoteAddr(), in.LocalAddr(), out.LocalAddr(), out.RemoteAddr())
|
2014-09-18 23:03:34 +00:00
|
|
|
go copyBytes("from backend", in, out, &wg)
|
|
|
|
go copyBytes("to backend", out, in, &wg)
|
2014-09-14 19:14:22 +00:00
|
|
|
wg.Wait()
|
|
|
|
in.Close()
|
|
|
|
out.Close()
|
2014-09-10 20:44:20 +00:00
|
|
|
}
|
|
|
|
|
2014-09-18 23:03:34 +00:00
|
|
|
func copyBytes(direction string, dest, src *net.TCPConn, wg *sync.WaitGroup) {
|
2014-09-20 18:31:13 +00:00
|
|
|
defer wg.Done()
|
2014-09-18 23:03:34 +00:00
|
|
|
glog.V(4).Infof("Copying %s: %s -> %s", direction, src.RemoteAddr(), dest.RemoteAddr())
|
|
|
|
n, err := io.Copy(dest, src)
|
|
|
|
if err != nil {
|
2014-09-20 18:31:13 +00:00
|
|
|
glog.Errorf("I/O error: %v", err)
|
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
glog.V(4).Infof("Copied %d bytes %s: %s -> %s", n, direction, src.RemoteAddr(), dest.RemoteAddr())
|
|
|
|
dest.CloseWrite()
|
|
|
|
src.CloseRead()
|
2014-09-20 18:31:13 +00:00
|
|
|
}
|
|
|
|
|
2014-09-11 16:00:06 +00:00
|
|
|
// udpProxySocket implements proxySocket. Close() is implemented by net.UDPConn. When Close() is called,
|
|
|
|
// no new connections are allowed and existing connections are broken.
|
|
|
|
// TODO: We could lame-duck this ourselves, if it becomes important.
|
|
|
|
type udpProxySocket struct {
|
|
|
|
*net.UDPConn
|
|
|
|
}
|
|
|
|
|
|
|
|
func (udp *udpProxySocket) Addr() net.Addr {
|
|
|
|
return udp.LocalAddr()
|
|
|
|
}
|
|
|
|
|
|
|
|
// Holds all the known UDP clients that have not timed out.
|
|
|
|
type clientCache struct {
|
|
|
|
mu sync.Mutex
|
|
|
|
clients map[string]net.Conn // addr string -> connection
|
|
|
|
}
|
|
|
|
|
|
|
|
func newClientCache() *clientCache {
|
|
|
|
return &clientCache{clients: map[string]net.Conn{}}
|
|
|
|
}
|
|
|
|
|
2014-09-18 23:03:34 +00:00
|
|
|
func (udp *udpProxySocket) ProxyLoop(service string, info *serviceInfo, proxier *Proxier) {
|
2014-09-11 16:00:06 +00:00
|
|
|
activeClients := newClientCache()
|
|
|
|
var buffer [4096]byte // 4KiB should be enough for most whole-packets
|
|
|
|
for {
|
2014-09-11 23:08:25 +00:00
|
|
|
if !info.isActive() {
|
2014-09-11 16:00:06 +00:00
|
|
|
break
|
|
|
|
}
|
|
|
|
|
|
|
|
// Block until data arrives.
|
|
|
|
// TODO: Accumulate a histogram of n or something, to fine tune the buffer size.
|
|
|
|
n, cliAddr, err := udp.ReadFrom(buffer[0:])
|
|
|
|
if err != nil {
|
|
|
|
if e, ok := err.(net.Error); ok {
|
|
|
|
if e.Temporary() {
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(1).Infof("ReadFrom had a temporary failure: %v", err)
|
2014-09-11 16:00:06 +00:00
|
|
|
continue
|
|
|
|
}
|
|
|
|
}
|
|
|
|
glog.Errorf("ReadFrom failed, exiting ProxyLoop: %v", err)
|
|
|
|
break
|
|
|
|
}
|
|
|
|
// If this is a client we know already, reuse the connection and goroutine.
|
2014-09-11 23:08:25 +00:00
|
|
|
svrConn, err := udp.getBackendConn(activeClients, cliAddr, proxier, service, info.timeout)
|
|
|
|
if err != nil {
|
|
|
|
continue
|
2014-09-11 16:00:06 +00:00
|
|
|
}
|
|
|
|
// TODO: It would be nice to let the goroutine handle this write, but we don't
|
|
|
|
// really want to copy the buffer. We could do a pool of buffers or something.
|
|
|
|
_, err = svrConn.Write(buffer[0:n])
|
|
|
|
if err != nil {
|
|
|
|
if !logTimeout(err) {
|
|
|
|
glog.Errorf("Write failed: %v", err)
|
|
|
|
// TODO: Maybe tear down the goroutine for this client/server pair?
|
|
|
|
}
|
|
|
|
continue
|
|
|
|
}
|
2014-09-11 16:50:20 +00:00
|
|
|
svrConn.SetDeadline(time.Now().Add(info.timeout))
|
2014-09-11 16:00:06 +00:00
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("SetDeadline failed: %v", err)
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-09-11 23:08:25 +00:00
|
|
|
func (udp *udpProxySocket) getBackendConn(activeClients *clientCache, cliAddr net.Addr, proxier *Proxier, service string, timeout time.Duration) (net.Conn, error) {
|
|
|
|
activeClients.mu.Lock()
|
|
|
|
defer activeClients.mu.Unlock()
|
|
|
|
|
|
|
|
svrConn, found := activeClients.clients[cliAddr.String()]
|
|
|
|
if !found {
|
|
|
|
// TODO: This could spin up a new goroutine to make the outbound connection,
|
|
|
|
// and keep accepting inbound traffic.
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(2).Infof("New UDP connection from %s", cliAddr)
|
2014-09-11 23:08:25 +00:00
|
|
|
endpoint, err := proxier.loadBalancer.NextEndpoint(service, cliAddr)
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Couldn't find an endpoint for %s %v", service, err)
|
|
|
|
return nil, err
|
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
glog.V(3).Infof("Mapped service %q to endpoint %s", service, endpoint)
|
2014-09-11 23:08:25 +00:00
|
|
|
svrConn, err = net.DialTimeout("udp", endpoint, endpointDialTimeout)
|
|
|
|
if err != nil {
|
|
|
|
// TODO: Try another endpoint?
|
|
|
|
glog.Errorf("Dial failed: %v", err)
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
activeClients.clients[cliAddr.String()] = svrConn
|
2014-09-11 23:21:00 +00:00
|
|
|
go func(cliAddr net.Addr, svrConn net.Conn, activeClients *clientCache, timeout time.Duration) {
|
|
|
|
defer util.HandleCrash()
|
|
|
|
udp.proxyClient(cliAddr, svrConn, activeClients, timeout)
|
|
|
|
}(cliAddr, svrConn, activeClients, timeout)
|
2014-09-11 23:08:25 +00:00
|
|
|
}
|
|
|
|
return svrConn, nil
|
|
|
|
}
|
|
|
|
|
2014-09-11 16:00:06 +00:00
|
|
|
// This function is expected to be called as a goroutine.
|
2014-09-18 23:03:34 +00:00
|
|
|
// TODO: Track and log bytes copied, like TCP
|
2014-09-11 16:50:20 +00:00
|
|
|
func (udp *udpProxySocket) proxyClient(cliAddr net.Addr, svrConn net.Conn, activeClients *clientCache, timeout time.Duration) {
|
2014-09-11 16:00:06 +00:00
|
|
|
defer svrConn.Close()
|
|
|
|
var buffer [4096]byte
|
|
|
|
for {
|
|
|
|
n, err := svrConn.Read(buffer[0:])
|
|
|
|
if err != nil {
|
|
|
|
if !logTimeout(err) {
|
|
|
|
glog.Errorf("Read failed: %v", err)
|
|
|
|
}
|
|
|
|
break
|
|
|
|
}
|
2014-09-11 16:50:20 +00:00
|
|
|
svrConn.SetDeadline(time.Now().Add(timeout))
|
2014-09-11 16:00:06 +00:00
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("SetDeadline failed: %v", err)
|
|
|
|
break
|
|
|
|
}
|
|
|
|
n, err = udp.WriteTo(buffer[0:n], cliAddr)
|
|
|
|
if err != nil {
|
|
|
|
if !logTimeout(err) {
|
|
|
|
glog.Errorf("WriteTo failed: %v", err)
|
|
|
|
}
|
|
|
|
break
|
|
|
|
}
|
|
|
|
}
|
|
|
|
activeClients.mu.Lock()
|
|
|
|
delete(activeClients.clients, cliAddr.String())
|
|
|
|
activeClients.mu.Unlock()
|
|
|
|
}
|
|
|
|
|
|
|
|
func logTimeout(err error) bool {
|
|
|
|
if e, ok := err.(net.Error); ok {
|
|
|
|
if e.Timeout() {
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(1).Infof("connection to endpoint closed due to inactivity")
|
2014-09-11 16:00:06 +00:00
|
|
|
return true
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return false
|
|
|
|
}
|
|
|
|
|
2014-10-04 04:34:30 +00:00
|
|
|
func newProxySocket(protocol api.Protocol, ip net.IP, port int) (proxySocket, error) {
|
|
|
|
host := ip.String()
|
2014-09-28 03:31:37 +00:00
|
|
|
switch strings.ToUpper(string(protocol)) {
|
2014-09-10 20:44:20 +00:00
|
|
|
case "TCP":
|
2014-09-11 16:00:06 +00:00
|
|
|
listener, err := net.Listen("tcp", net.JoinHostPort(host, strconv.Itoa(port)))
|
2014-09-10 20:44:20 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return &tcpProxySocket{listener}, nil
|
2014-09-11 16:00:06 +00:00
|
|
|
case "UDP":
|
|
|
|
addr, err := net.ResolveUDPAddr("udp", net.JoinHostPort(host, strconv.Itoa(port)))
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
conn, err := net.ListenUDP("udp", addr)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return &udpProxySocket{conn}, nil
|
2014-09-10 20:44:20 +00:00
|
|
|
}
|
|
|
|
return nil, fmt.Errorf("Unknown protocol %q", protocol)
|
|
|
|
}
|
|
|
|
|
2014-08-03 19:23:15 +00:00
|
|
|
// Proxier is a simple proxy for TCP connections between a localhost:lport
|
|
|
|
// and services that provide the actual implementations.
|
2014-06-06 23:40:48 +00:00
|
|
|
type Proxier struct {
|
2014-09-18 23:03:34 +00:00
|
|
|
loadBalancer LoadBalancer
|
|
|
|
mu sync.Mutex // protects serviceMap
|
|
|
|
serviceMap map[string]*serviceInfo
|
|
|
|
listenAddress net.IP
|
|
|
|
iptables iptables.Interface
|
2014-06-06 23:40:48 +00:00
|
|
|
}
|
|
|
|
|
2014-09-18 23:03:34 +00:00
|
|
|
// NewProxier returns a new Proxier given a LoadBalancer and an address on
|
|
|
|
// which to listen. Because of the iptables logic, It is assumed that there
|
|
|
|
// is only a single Proxier active on a machine.
|
|
|
|
func NewProxier(loadBalancer LoadBalancer, listenAddress net.IP, iptables iptables.Interface) *Proxier {
|
|
|
|
glog.Infof("Initializing iptables")
|
|
|
|
// Set up the iptables foundations we need.
|
|
|
|
if err := iptablesInit(iptables); err != nil {
|
|
|
|
glog.Errorf("Failed to initialize iptables: %s", err)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
// Flush old iptables rules (since the bound ports will be invalid after a restart).
|
|
|
|
// When OnUpdate() is first called, the rules will be recreated.
|
|
|
|
if err := iptablesFlush(iptables); err != nil {
|
|
|
|
glog.Errorf("Failed to flush iptables: %s", err)
|
|
|
|
return nil
|
|
|
|
}
|
2014-08-03 19:23:15 +00:00
|
|
|
return &Proxier{
|
2014-09-18 23:03:34 +00:00
|
|
|
loadBalancer: loadBalancer,
|
|
|
|
serviceMap: make(map[string]*serviceInfo),
|
|
|
|
listenAddress: listenAddress,
|
|
|
|
iptables: iptables,
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// The periodic interval for checking the state of things.
|
|
|
|
const syncInterval = 5 * time.Second
|
|
|
|
|
|
|
|
// SyncLoop runs periodic work. This is expected to run as a goroutine or as the main loop of the app. It does not return.
|
|
|
|
func (proxier *Proxier) SyncLoop() {
|
|
|
|
for {
|
|
|
|
select {
|
|
|
|
case <-time.After(syncInterval):
|
|
|
|
glog.V(2).Infof("Periodic sync")
|
|
|
|
if err := iptablesInit(proxier.iptables); err != nil {
|
|
|
|
glog.Errorf("Failed to ensure iptables: %s", err)
|
|
|
|
}
|
|
|
|
proxier.ensurePortals()
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Ensure that portals exist for all services.
|
|
|
|
func (proxier *Proxier) ensurePortals() {
|
|
|
|
proxier.mu.Lock()
|
|
|
|
defer proxier.mu.Unlock()
|
|
|
|
// NB: This does not remove rules that should not be present.
|
|
|
|
for name, info := range proxier.serviceMap {
|
|
|
|
err := proxier.openPortal(name, info)
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Failed to ensure portal for %q: %s", name, err)
|
|
|
|
}
|
2014-08-03 19:23:15 +00:00
|
|
|
}
|
2014-06-06 23:40:48 +00:00
|
|
|
}
|
|
|
|
|
2014-09-20 18:29:04 +00:00
|
|
|
// This assumes proxier.mu is not locked.
|
|
|
|
func (proxier *Proxier) stopProxy(service string, info *serviceInfo) error {
|
|
|
|
proxier.mu.Lock()
|
|
|
|
defer proxier.mu.Unlock()
|
2014-09-17 00:04:23 +00:00
|
|
|
return proxier.stopProxyInternal(service, info)
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
|
|
|
|
2014-09-20 18:29:04 +00:00
|
|
|
// This assumes proxier.mu is locked.
|
2014-09-17 00:04:23 +00:00
|
|
|
func (proxier *Proxier) stopProxyInternal(service string, info *serviceInfo) error {
|
2014-09-11 23:08:25 +00:00
|
|
|
if !info.setActive(false) {
|
2014-08-03 19:23:15 +00:00
|
|
|
return nil
|
|
|
|
}
|
2014-09-20 18:29:04 +00:00
|
|
|
delete(proxier.serviceMap, service)
|
2014-09-10 20:44:20 +00:00
|
|
|
return info.socket.Close()
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (proxier *Proxier) getServiceInfo(service string) (*serviceInfo, bool) {
|
2014-08-03 19:23:15 +00:00
|
|
|
proxier.mu.Lock()
|
|
|
|
defer proxier.mu.Unlock()
|
2014-07-30 13:52:03 +00:00
|
|
|
info, ok := proxier.serviceMap[service]
|
|
|
|
return info, ok
|
|
|
|
}
|
|
|
|
|
|
|
|
func (proxier *Proxier) setServiceInfo(service string, info *serviceInfo) {
|
2014-08-03 19:23:15 +00:00
|
|
|
proxier.mu.Lock()
|
|
|
|
defer proxier.mu.Unlock()
|
2014-07-30 13:52:03 +00:00
|
|
|
proxier.serviceMap[service] = info
|
|
|
|
}
|
|
|
|
|
2014-09-18 23:03:34 +00:00
|
|
|
// addServiceOnPort starts listening for a new service, returning the serviceInfo.
|
|
|
|
// Pass proxyPort=0 to allocate a random port. The timeout only applies to UDP
|
2014-09-11 16:50:20 +00:00
|
|
|
// connections, for now.
|
2014-09-18 23:03:34 +00:00
|
|
|
func (proxier *Proxier) addServiceOnPort(service string, protocol api.Protocol, proxyPort int, timeout time.Duration) (*serviceInfo, error) {
|
|
|
|
sock, err := newProxySocket(protocol, proxier.listenAddress, proxyPort)
|
2014-06-13 00:18:19 +00:00
|
|
|
if err != nil {
|
2014-09-18 23:03:34 +00:00
|
|
|
return nil, err
|
2014-06-13 00:18:19 +00:00
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
_, portStr, err := net.SplitHostPort(sock.Addr().String())
|
2014-07-30 13:52:03 +00:00
|
|
|
if err != nil {
|
2014-09-18 23:03:34 +00:00
|
|
|
sock.Close()
|
|
|
|
return nil, err
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
portNum, err := strconv.Atoi(portStr)
|
2014-07-30 13:52:03 +00:00
|
|
|
if err != nil {
|
2014-09-18 23:03:34 +00:00
|
|
|
sock.Close()
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
si := &serviceInfo{
|
|
|
|
proxyPort: portNum,
|
|
|
|
protocol: protocol,
|
|
|
|
active: true,
|
|
|
|
socket: sock,
|
|
|
|
timeout: timeout,
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
proxier.setServiceInfo(service, si)
|
|
|
|
|
|
|
|
glog.V(1).Infof("Proxying for service %q on %s port %d", service, protocol, portNum)
|
|
|
|
go func(service string, info *serviceInfo, proxier *Proxier) {
|
2014-09-11 23:21:00 +00:00
|
|
|
defer util.HandleCrash()
|
2014-09-18 23:03:34 +00:00
|
|
|
sock.ProxyLoop(service, info, proxier)
|
|
|
|
}(service, si, proxier)
|
|
|
|
|
|
|
|
return si, nil
|
2014-06-13 00:18:19 +00:00
|
|
|
}
|
|
|
|
|
2014-09-11 16:50:20 +00:00
|
|
|
// How long we leave idle UDP connections open.
|
|
|
|
const udpIdleTimeout = 1 * time.Minute
|
|
|
|
|
2014-08-03 19:23:15 +00:00
|
|
|
// OnUpdate manages the active set of service proxies.
|
|
|
|
// Active service proxies are reinitialized if found in the update set or
|
|
|
|
// shutdown if missing from the update set.
|
2014-08-05 19:34:54 +00:00
|
|
|
func (proxier *Proxier) OnUpdate(services []api.Service) {
|
2014-09-18 10:46:14 +00:00
|
|
|
glog.V(4).Infof("Received update notice: %+v", services)
|
2014-08-03 19:23:15 +00:00
|
|
|
activeServices := util.StringSet{}
|
2014-06-06 23:40:48 +00:00
|
|
|
for _, service := range services {
|
2014-10-22 17:02:02 +00:00
|
|
|
activeServices.Insert(service.Name)
|
|
|
|
info, exists := proxier.getServiceInfo(service.Name)
|
2014-09-18 23:03:34 +00:00
|
|
|
serviceIP := net.ParseIP(service.PortalIP)
|
2014-09-11 16:00:06 +00:00
|
|
|
// TODO: check health of the socket? What if ProxyLoop exited?
|
2014-09-18 23:03:34 +00:00
|
|
|
if exists && info.isActive() && info.portalPort == service.Port && info.portalIP.Equal(serviceIP) {
|
2014-07-15 11:55:04 +00:00
|
|
|
continue
|
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
if exists && (info.portalPort != service.Port || !info.portalIP.Equal(serviceIP)) {
|
2014-10-22 17:02:02 +00:00
|
|
|
glog.V(4).Infof("Something changed for service %q: stopping it", service.Name)
|
|
|
|
err := proxier.closePortal(service.Name, info)
|
2014-09-18 23:03:34 +00:00
|
|
|
if err != nil {
|
2014-10-22 17:02:02 +00:00
|
|
|
glog.Errorf("Failed to close portal for %q: %s", service.Name, err)
|
2014-09-18 23:03:34 +00:00
|
|
|
}
|
2014-10-22 17:02:02 +00:00
|
|
|
err = proxier.stopProxy(service.Name, info)
|
2014-09-11 16:00:06 +00:00
|
|
|
if err != nil {
|
2014-10-22 17:02:02 +00:00
|
|
|
glog.Errorf("Failed to stop service %q: %s", service.Name, err)
|
2014-09-11 16:00:06 +00:00
|
|
|
}
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
2014-10-22 17:02:02 +00:00
|
|
|
glog.V(1).Infof("Adding new service %q at %s:%d/%s (local :%d)", service.Name, serviceIP, service.Port, service.Protocol, service.ProxyPort)
|
|
|
|
info, err := proxier.addServiceOnPort(service.Name, service.Protocol, service.ProxyPort, udpIdleTimeout)
|
2014-07-15 11:55:04 +00:00
|
|
|
if err != nil {
|
2014-10-22 17:02:02 +00:00
|
|
|
glog.Errorf("Failed to start proxy for %q: %+v", service.Name, err)
|
2014-07-15 11:55:04 +00:00
|
|
|
continue
|
2014-06-06 23:40:48 +00:00
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
info.portalIP = serviceIP
|
|
|
|
info.portalPort = service.Port
|
2014-10-22 17:02:02 +00:00
|
|
|
err = proxier.openPortal(service.Name, info)
|
2014-09-18 23:03:34 +00:00
|
|
|
if err != nil {
|
2014-10-22 17:02:02 +00:00
|
|
|
glog.Errorf("Failed to open portal for %q: %s", service.Name, err)
|
2014-09-18 23:03:34 +00:00
|
|
|
}
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
2014-08-03 19:23:15 +00:00
|
|
|
proxier.mu.Lock()
|
|
|
|
defer proxier.mu.Unlock()
|
2014-07-30 13:52:03 +00:00
|
|
|
for name, info := range proxier.serviceMap {
|
2014-08-03 19:23:15 +00:00
|
|
|
if !activeServices.Has(name) {
|
2014-09-18 23:03:34 +00:00
|
|
|
glog.V(1).Infof("Stopping service %q", name)
|
|
|
|
err := proxier.closePortal(name, info)
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Failed to close portal for %q: %s", name, err)
|
|
|
|
}
|
|
|
|
err = proxier.stopProxyInternal(name, info)
|
2014-09-11 16:00:06 +00:00
|
|
|
if err != nil {
|
2014-09-18 23:03:34 +00:00
|
|
|
glog.Errorf("Failed to stop service %q: %s", name, err)
|
2014-09-11 16:00:06 +00:00
|
|
|
}
|
2014-07-30 13:52:03 +00:00
|
|
|
}
|
2014-06-06 23:40:48 +00:00
|
|
|
}
|
|
|
|
}
|
2014-09-18 23:03:34 +00:00
|
|
|
|
|
|
|
func (proxier *Proxier) openPortal(service string, info *serviceInfo) error {
|
|
|
|
args := iptablesPortalArgs(info.portalIP, info.portalPort, proxier.listenAddress, info.proxyPort, service)
|
|
|
|
existed, err := proxier.iptables.EnsureRule(iptables.TableNAT, iptablesProxyChain, args...)
|
|
|
|
if err != nil {
|
|
|
|
glog.Errorf("Failed to install iptables %s rule for service %q", iptablesProxyChain, service)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if !existed {
|
|
|
|
glog.Infof("Opened iptables portal for service %q on %s:%d", service, info.portalIP, info.portalPort)
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (proxier *Proxier) closePortal(service string, info *serviceInfo) error {
|
|
|
|
args := iptablesPortalArgs(info.portalIP, info.portalPort, proxier.listenAddress, info.proxyPort, service)
|
|
|
|
if err := proxier.iptables.DeleteRule(iptables.TableNAT, iptablesProxyChain, args...); err != nil {
|
|
|
|
glog.Errorf("Failed to delete iptables %s rule for service %q", iptablesProxyChain, service)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
glog.Infof("Closed iptables portal for service %q", service)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
var iptablesProxyChain iptables.Chain = "KUBE-PROXY"
|
|
|
|
|
|
|
|
// Ensure that the iptables infrastructure we use is set up. This can safely be called periodically.
|
|
|
|
func iptablesInit(ipt iptables.Interface) error {
|
|
|
|
// TODO: There is almost certainly room for optimization here. E.g. If
|
|
|
|
// we knew the portal_net CIDR we could fast-track outbound packets not
|
|
|
|
// destined for a service. There's probably more, help wanted.
|
|
|
|
if _, err := ipt.EnsureChain(iptables.TableNAT, iptablesProxyChain); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if _, err := ipt.EnsureRule(iptables.TableNAT, iptables.ChainPrerouting, "-j", string(iptablesProxyChain)); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if _, err := ipt.EnsureRule(iptables.TableNAT, iptables.ChainOutput, "-j", string(iptablesProxyChain)); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Flush all of our custom iptables rules.
|
|
|
|
func iptablesFlush(ipt iptables.Interface) error {
|
|
|
|
return ipt.FlushChain(iptables.TableNAT, iptablesProxyChain)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Used below.
|
|
|
|
var zeroIP = net.ParseIP("0.0.0.0")
|
|
|
|
var localhostIP = net.ParseIP("127.0.0.1")
|
|
|
|
|
|
|
|
// Build a slice of iptables args for a portal rule.
|
|
|
|
func iptablesPortalArgs(destIP net.IP, destPort int, proxyIP net.IP, proxyPort int, service string) []string {
|
|
|
|
args := []string{
|
|
|
|
"-m", "comment",
|
|
|
|
"--comment", service,
|
|
|
|
"-p", "tcp",
|
|
|
|
"-d", destIP.String(),
|
|
|
|
"--dport", fmt.Sprintf("%d", destPort),
|
|
|
|
}
|
|
|
|
// This is tricky. If the proxy is bound (see Proxier.listenAddress)
|
|
|
|
// to 0.0.0.0 ("any interface") or 127.0.0.1, we can use REDIRECT,
|
|
|
|
// which will bring packets back to the host's loopback interface. If
|
|
|
|
// the proxy is bound to any other interface, then it is not listening
|
|
|
|
// on the hosts's loopback, so we have to use DNAT to that specific
|
|
|
|
// IP. We can not simply use DNAT to 127.0.0.1 in the first case
|
|
|
|
// because from within a container, 127.0.0.1 is the container's
|
|
|
|
// loopback interface, not the host's.
|
|
|
|
//
|
|
|
|
// Why would anyone bind to an address that is not inclusive of
|
|
|
|
// localhost? Apparently some cloud environments have their public IP
|
|
|
|
// exposed as a real network interface AND do not have firewalling. We
|
|
|
|
// don't want to expose everything out to the world.
|
|
|
|
//
|
|
|
|
// Unfortunately, I don't know of any way to listen on some (N > 1)
|
|
|
|
// interfaces but not ALL interfaces, short of doing it manually, and
|
|
|
|
// this is simpler than that.
|
|
|
|
if proxyIP.Equal(zeroIP) || proxyIP.Equal(localhostIP) {
|
|
|
|
args = append(args, "-j", "REDIRECT", "--to-ports", fmt.Sprintf("%d", proxyPort))
|
|
|
|
} else {
|
|
|
|
args = append(args, "-j", "DNAT", "--to-destination", fmt.Sprintf("%s:%d", proxyIP.String(), proxyPort))
|
|
|
|
}
|
|
|
|
return args
|
|
|
|
}
|