2017-05-23 18:56:10 +00:00
|
|
|
package proxy
|
|
|
|
|
|
|
|
import (
|
2017-10-15 17:24:40 +00:00
|
|
|
"net"
|
2017-05-23 18:56:10 +00:00
|
|
|
"net/http"
|
|
|
|
"net/http/httputil"
|
|
|
|
"net/url"
|
|
|
|
|
2019-03-21 01:20:14 +00:00
|
|
|
"github.com/portainer/portainer/api"
|
|
|
|
"github.com/portainer/portainer/api/crypto"
|
2017-05-23 18:56:10 +00:00
|
|
|
)
|
|
|
|
|
2018-06-01 14:13:24 +00:00
|
|
|
// AzureAPIBaseURL is the URL where Azure API requests will be proxied.
|
|
|
|
const AzureAPIBaseURL = "https://management.azure.com"
|
2018-05-28 14:40:33 +00:00
|
|
|
|
2017-05-23 18:56:10 +00:00
|
|
|
// proxyFactory is a factory to create reverse proxies to Docker endpoints
|
|
|
|
type proxyFactory struct {
|
|
|
|
ResourceControlService portainer.ResourceControlService
|
2019-09-09 22:58:26 +00:00
|
|
|
UserService portainer.UserService
|
2017-05-23 18:56:10 +00:00
|
|
|
TeamMembershipService portainer.TeamMembershipService
|
2017-06-01 08:14:55 +00:00
|
|
|
SettingsService portainer.SettingsService
|
2018-03-22 22:44:43 +00:00
|
|
|
RegistryService portainer.RegistryService
|
|
|
|
DockerHubService portainer.DockerHubService
|
2018-05-06 07:15:57 +00:00
|
|
|
SignatureService portainer.DigitalSignatureService
|
2019-07-25 22:38:07 +00:00
|
|
|
ReverseTunnelService portainer.ReverseTunnelService
|
2017-05-23 18:56:10 +00:00
|
|
|
}
|
|
|
|
|
2018-05-28 14:40:33 +00:00
|
|
|
func (factory *proxyFactory) newHTTPProxy(u *url.URL) http.Handler {
|
2017-05-23 18:56:10 +00:00
|
|
|
u.Scheme = "http"
|
2018-12-09 03:49:27 +00:00
|
|
|
return httputil.NewSingleHostReverseProxy(u)
|
2017-05-23 18:56:10 +00:00
|
|
|
}
|
|
|
|
|
2018-05-28 14:40:33 +00:00
|
|
|
func newAzureProxy(credentials *portainer.AzureCredentials) (http.Handler, error) {
|
2019-07-25 22:38:07 +00:00
|
|
|
remoteURL, err := url.Parse(AzureAPIBaseURL)
|
2018-05-28 14:40:33 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2019-07-25 22:38:07 +00:00
|
|
|
proxy := newSingleHostReverseProxyWithHostHeader(remoteURL)
|
2018-05-28 14:40:33 +00:00
|
|
|
proxy.Transport = NewAzureTransport(credentials)
|
|
|
|
|
|
|
|
return proxy, nil
|
|
|
|
}
|
|
|
|
|
2019-07-25 22:38:07 +00:00
|
|
|
func (factory *proxyFactory) newDockerHTTPSProxy(u *url.URL, tlsConfig *portainer.TLSConfiguration, endpoint *portainer.Endpoint) (http.Handler, error) {
|
2017-05-23 18:56:10 +00:00
|
|
|
u.Scheme = "https"
|
2018-05-06 07:15:57 +00:00
|
|
|
|
2019-07-25 22:38:07 +00:00
|
|
|
proxy := factory.createDockerReverseProxy(u, endpoint)
|
2018-05-19 14:25:11 +00:00
|
|
|
config, err := crypto.CreateTLSConfigurationFromDisk(tlsConfig.TLSCACertPath, tlsConfig.TLSCertPath, tlsConfig.TLSKeyPath, tlsConfig.TLSSkipVerify)
|
2017-05-23 18:56:10 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
proxy.Transport.(*proxyTransport).dockerTransport.TLSClientConfig = config
|
|
|
|
return proxy, nil
|
|
|
|
}
|
|
|
|
|
2019-07-25 22:38:07 +00:00
|
|
|
func (factory *proxyFactory) newDockerHTTPProxy(u *url.URL, endpoint *portainer.Endpoint) http.Handler {
|
2018-02-23 02:10:26 +00:00
|
|
|
u.Scheme = "http"
|
2019-07-25 22:38:07 +00:00
|
|
|
return factory.createDockerReverseProxy(u, endpoint)
|
2018-02-23 02:10:26 +00:00
|
|
|
}
|
|
|
|
|
2019-07-25 22:38:07 +00:00
|
|
|
func (factory *proxyFactory) createDockerReverseProxy(u *url.URL, endpoint *portainer.Endpoint) *httputil.ReverseProxy {
|
2017-05-23 18:56:10 +00:00
|
|
|
proxy := newSingleHostReverseProxyWithHostHeader(u)
|
2019-07-25 22:38:07 +00:00
|
|
|
|
|
|
|
enableSignature := false
|
|
|
|
if endpoint.Type == portainer.AgentOnDockerEnvironment {
|
|
|
|
enableSignature = true
|
|
|
|
}
|
|
|
|
|
2017-05-23 18:56:10 +00:00
|
|
|
transport := &proxyTransport{
|
2018-05-06 07:15:57 +00:00
|
|
|
enableSignature: enableSignature,
|
2017-05-23 18:56:10 +00:00
|
|
|
ResourceControlService: factory.ResourceControlService,
|
2019-09-09 22:58:26 +00:00
|
|
|
UserService: factory.UserService,
|
2017-05-23 18:56:10 +00:00
|
|
|
TeamMembershipService: factory.TeamMembershipService,
|
2017-06-01 08:14:55 +00:00
|
|
|
SettingsService: factory.SettingsService,
|
2018-03-22 22:44:43 +00:00
|
|
|
RegistryService: factory.RegistryService,
|
|
|
|
DockerHubService: factory.DockerHubService,
|
2019-07-25 22:38:07 +00:00
|
|
|
ReverseTunnelService: factory.ReverseTunnelService,
|
2018-02-23 02:10:26 +00:00
|
|
|
dockerTransport: &http.Transport{},
|
2019-07-25 22:38:07 +00:00
|
|
|
endpointIdentifier: endpoint.ID,
|
|
|
|
endpointType: endpoint.Type,
|
2017-05-23 18:56:10 +00:00
|
|
|
}
|
2018-05-06 07:15:57 +00:00
|
|
|
|
|
|
|
if enableSignature {
|
|
|
|
transport.SignatureService = factory.SignatureService
|
|
|
|
}
|
|
|
|
|
2017-05-23 18:56:10 +00:00
|
|
|
proxy.Transport = transport
|
|
|
|
return proxy
|
|
|
|
}
|
2017-10-15 17:24:40 +00:00
|
|
|
|
|
|
|
func newSocketTransport(socketPath string) *http.Transport {
|
|
|
|
return &http.Transport{
|
|
|
|
Dial: func(proto, addr string) (conn net.Conn, err error) {
|
|
|
|
return net.Dial("unix", socketPath)
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|