2017-05-23 18:56:10 +00:00
|
|
|
package proxy
|
|
|
|
|
|
|
|
import (
|
2017-10-15 17:24:40 +00:00
|
|
|
"net"
|
2017-05-23 18:56:10 +00:00
|
|
|
"net/http"
|
|
|
|
"net/http/httputil"
|
|
|
|
"net/url"
|
|
|
|
|
|
|
|
"github.com/portainer/portainer"
|
|
|
|
"github.com/portainer/portainer/crypto"
|
|
|
|
)
|
|
|
|
|
|
|
|
// proxyFactory is a factory to create reverse proxies to Docker endpoints
|
|
|
|
type proxyFactory struct {
|
|
|
|
ResourceControlService portainer.ResourceControlService
|
|
|
|
TeamMembershipService portainer.TeamMembershipService
|
2017-06-01 08:14:55 +00:00
|
|
|
SettingsService portainer.SettingsService
|
2017-05-23 18:56:10 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (factory *proxyFactory) newHTTPProxy(u *url.URL) http.Handler {
|
|
|
|
u.Scheme = "http"
|
|
|
|
return factory.createReverseProxy(u)
|
|
|
|
}
|
|
|
|
|
|
|
|
func (factory *proxyFactory) newHTTPSProxy(u *url.URL, endpoint *portainer.Endpoint) (http.Handler, error) {
|
|
|
|
u.Scheme = "https"
|
|
|
|
proxy := factory.createReverseProxy(u)
|
2017-09-14 06:08:37 +00:00
|
|
|
config, err := crypto.CreateTLSConfiguration(&endpoint.TLSConfig)
|
2017-05-23 18:56:10 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
proxy.Transport.(*proxyTransport).dockerTransport.TLSClientConfig = config
|
|
|
|
return proxy, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (factory *proxyFactory) newSocketProxy(path string) http.Handler {
|
|
|
|
proxy := &socketProxy{}
|
|
|
|
transport := &proxyTransport{
|
|
|
|
ResourceControlService: factory.ResourceControlService,
|
|
|
|
TeamMembershipService: factory.TeamMembershipService,
|
2017-06-01 08:14:55 +00:00
|
|
|
SettingsService: factory.SettingsService,
|
2017-05-23 18:56:10 +00:00
|
|
|
dockerTransport: newSocketTransport(path),
|
|
|
|
}
|
|
|
|
proxy.Transport = transport
|
|
|
|
return proxy
|
|
|
|
}
|
|
|
|
|
|
|
|
func (factory *proxyFactory) createReverseProxy(u *url.URL) *httputil.ReverseProxy {
|
|
|
|
proxy := newSingleHostReverseProxyWithHostHeader(u)
|
|
|
|
transport := &proxyTransport{
|
|
|
|
ResourceControlService: factory.ResourceControlService,
|
|
|
|
TeamMembershipService: factory.TeamMembershipService,
|
2017-06-01 08:14:55 +00:00
|
|
|
SettingsService: factory.SettingsService,
|
2017-05-23 18:56:10 +00:00
|
|
|
dockerTransport: newHTTPTransport(),
|
|
|
|
}
|
|
|
|
proxy.Transport = transport
|
|
|
|
return proxy
|
|
|
|
}
|
2017-10-15 17:24:40 +00:00
|
|
|
|
|
|
|
func newSocketTransport(socketPath string) *http.Transport {
|
|
|
|
return &http.Transport{
|
|
|
|
Dial: func(proto, addr string) (conn net.Conn, err error) {
|
|
|
|
return net.Dial("unix", socketPath)
|
|
|
|
},
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func newHTTPTransport() *http.Transport {
|
|
|
|
return &http.Transport{}
|
|
|
|
}
|