You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

275 lines
8.6 KiB

5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
4 years ago
  1. package command
  2. import (
  3. "context"
  4. "fmt"
  5. "github.com/seaweedfs/seaweedfs/weed/s3api/s3err"
  6. "google.golang.org/grpc/reflection"
  7. "net/http"
  8. "time"
  9. "github.com/seaweedfs/seaweedfs/weed/pb"
  10. "github.com/seaweedfs/seaweedfs/weed/pb/filer_pb"
  11. "github.com/seaweedfs/seaweedfs/weed/pb/s3_pb"
  12. "github.com/seaweedfs/seaweedfs/weed/security"
  13. "github.com/gorilla/mux"
  14. "github.com/seaweedfs/seaweedfs/weed/glog"
  15. "github.com/seaweedfs/seaweedfs/weed/s3api"
  16. stats_collect "github.com/seaweedfs/seaweedfs/weed/stats"
  17. "github.com/seaweedfs/seaweedfs/weed/util"
  18. )
  19. var (
  20. s3StandaloneOptions S3Options
  21. )
  22. type S3Options struct {
  23. filer *string
  24. bindIp *string
  25. port *int
  26. portGrpc *int
  27. config *string
  28. domainName *string
  29. tlsPrivateKey *string
  30. tlsCertificate *string
  31. metricsHttpPort *int
  32. allowEmptyFolder *bool
  33. allowDeleteBucketNotEmpty *bool
  34. auditLogConfig *string
  35. localFilerSocket *string
  36. dataCenter *string
  37. }
  38. func init() {
  39. cmdS3.Run = runS3 // break init cycle
  40. s3StandaloneOptions.filer = cmdS3.Flag.String("filer", "localhost:8888", "filer server address")
  41. s3StandaloneOptions.bindIp = cmdS3.Flag.String("ip.bind", "", "ip address to bind to. Default to localhost.")
  42. s3StandaloneOptions.port = cmdS3.Flag.Int("port", 8333, "s3 server http listen port")
  43. s3StandaloneOptions.portGrpc = cmdS3.Flag.Int("port.grpc", 0, "s3 server grpc listen port")
  44. s3StandaloneOptions.domainName = cmdS3.Flag.String("domainName", "", "suffix of the host name in comma separated list, {bucket}.{domainName}")
  45. s3StandaloneOptions.dataCenter = cmdS3.Flag.String("dataCenter", "", "prefer to read and write to volumes in this data center")
  46. s3StandaloneOptions.config = cmdS3.Flag.String("config", "", "path to the config file")
  47. s3StandaloneOptions.auditLogConfig = cmdS3.Flag.String("auditLogConfig", "", "path to the audit log config file")
  48. s3StandaloneOptions.tlsPrivateKey = cmdS3.Flag.String("key.file", "", "path to the TLS private key file")
  49. s3StandaloneOptions.tlsCertificate = cmdS3.Flag.String("cert.file", "", "path to the TLS certificate file")
  50. s3StandaloneOptions.metricsHttpPort = cmdS3.Flag.Int("metricsPort", 0, "Prometheus metrics listen port")
  51. s3StandaloneOptions.allowEmptyFolder = cmdS3.Flag.Bool("allowEmptyFolder", true, "allow empty folders")
  52. s3StandaloneOptions.allowDeleteBucketNotEmpty = cmdS3.Flag.Bool("allowDeleteBucketNotEmpty", true, "allow recursive deleting all entries along with bucket")
  53. s3StandaloneOptions.localFilerSocket = cmdS3.Flag.String("localFilerSocket", "", "local filer socket path")
  54. }
  55. var cmdS3 = &Command{
  56. UsageLine: "s3 [-port=8333] [-filer=<ip:port>] [-config=</path/to/config.json>]",
  57. Short: "start a s3 API compatible server that is backed by a filer",
  58. Long: `start a s3 API compatible server that is backed by a filer.
  59. By default, you can use any access key and secret key to access the S3 APIs.
  60. To enable credential based access, create a config.json file similar to this:
  61. {
  62. "identities": [
  63. {
  64. "name": "anonymous",
  65. "actions": [
  66. "Read"
  67. ]
  68. },
  69. {
  70. "name": "some_admin_user",
  71. "credentials": [
  72. {
  73. "accessKey": "some_access_key1",
  74. "secretKey": "some_secret_key1"
  75. }
  76. ],
  77. "actions": [
  78. "Admin",
  79. "Read",
  80. "List",
  81. "Tagging",
  82. "Write"
  83. ]
  84. },
  85. {
  86. "name": "some_read_only_user",
  87. "credentials": [
  88. {
  89. "accessKey": "some_access_key2",
  90. "secretKey": "some_secret_key2"
  91. }
  92. ],
  93. "actions": [
  94. "Read"
  95. ]
  96. },
  97. {
  98. "name": "some_normal_user",
  99. "credentials": [
  100. {
  101. "accessKey": "some_access_key3",
  102. "secretKey": "some_secret_key3"
  103. }
  104. ],
  105. "actions": [
  106. "Read",
  107. "List",
  108. "Tagging",
  109. "Write"
  110. ]
  111. },
  112. {
  113. "name": "user_limited_to_bucket1",
  114. "credentials": [
  115. {
  116. "accessKey": "some_access_key4",
  117. "secretKey": "some_secret_key4"
  118. }
  119. ],
  120. "actions": [
  121. "Read:bucket1",
  122. "List:bucket1",
  123. "Tagging:bucket1",
  124. "Write:bucket1"
  125. ]
  126. }
  127. ]
  128. }
  129. `,
  130. }
  131. func runS3(cmd *Command, args []string) bool {
  132. util.LoadConfiguration("security", false)
  133. go stats_collect.StartMetricsServer(*s3StandaloneOptions.bindIp, *s3StandaloneOptions.metricsHttpPort)
  134. return s3StandaloneOptions.startS3Server()
  135. }
  136. func (s3opt *S3Options) startS3Server() bool {
  137. filerAddress := pb.ServerAddress(*s3opt.filer)
  138. filerBucketsPath := "/buckets"
  139. filerGroup := ""
  140. grpcDialOption := security.LoadClientTLS(util.GetViper(), "grpc.client")
  141. // metrics read from the filer
  142. var metricsAddress string
  143. var metricsIntervalSec int
  144. for {
  145. err := pb.WithGrpcFilerClient(false, 0, filerAddress, grpcDialOption, func(client filer_pb.SeaweedFilerClient) error {
  146. resp, err := client.GetFilerConfiguration(context.Background(), &filer_pb.GetFilerConfigurationRequest{})
  147. if err != nil {
  148. return fmt.Errorf("get filer %s configuration: %v", filerAddress, err)
  149. }
  150. filerBucketsPath = resp.DirBuckets
  151. filerGroup = resp.FilerGroup
  152. metricsAddress, metricsIntervalSec = resp.MetricsAddress, int(resp.MetricsIntervalSec)
  153. glog.V(0).Infof("S3 read filer buckets dir: %s", filerBucketsPath)
  154. return nil
  155. })
  156. if err != nil {
  157. glog.V(0).Infof("wait to connect to filer %s grpc address %s", *s3opt.filer, filerAddress.ToGrpcAddress())
  158. time.Sleep(time.Second)
  159. } else {
  160. glog.V(0).Infof("connected to filer %s grpc address %s", *s3opt.filer, filerAddress.ToGrpcAddress())
  161. break
  162. }
  163. }
  164. go stats_collect.LoopPushingMetric("s3", stats_collect.SourceName(uint32(*s3opt.port)), metricsAddress, metricsIntervalSec)
  165. router := mux.NewRouter().SkipClean(true)
  166. var localFilerSocket string
  167. if s3opt.localFilerSocket != nil {
  168. localFilerSocket = *s3opt.localFilerSocket
  169. }
  170. s3ApiServer, s3ApiServer_err := s3api.NewS3ApiServer(router, &s3api.S3ApiServerOption{
  171. Filer: filerAddress,
  172. Port: *s3opt.port,
  173. Config: *s3opt.config,
  174. DomainName: *s3opt.domainName,
  175. BucketsPath: filerBucketsPath,
  176. GrpcDialOption: grpcDialOption,
  177. AllowEmptyFolder: *s3opt.allowEmptyFolder,
  178. AllowDeleteBucketNotEmpty: *s3opt.allowDeleteBucketNotEmpty,
  179. LocalFilerSocket: localFilerSocket,
  180. DataCenter: *s3opt.dataCenter,
  181. FilerGroup: filerGroup,
  182. })
  183. if s3ApiServer_err != nil {
  184. glog.Fatalf("S3 API Server startup error: %v", s3ApiServer_err)
  185. }
  186. httpS := &http.Server{Handler: router}
  187. if *s3opt.portGrpc == 0 {
  188. *s3opt.portGrpc = 10000 + *s3opt.port
  189. }
  190. if *s3opt.bindIp == "" {
  191. *s3opt.bindIp = "localhost"
  192. }
  193. listenAddress := fmt.Sprintf("%s:%d", *s3opt.bindIp, *s3opt.port)
  194. s3ApiListener, s3ApiLocalListener, err := util.NewIpAndLocalListeners(*s3opt.bindIp, *s3opt.port, time.Duration(10)*time.Second)
  195. if err != nil {
  196. glog.Fatalf("S3 API Server listener on %s error: %v", listenAddress, err)
  197. }
  198. if len(*s3opt.auditLogConfig) > 0 {
  199. s3err.InitAuditLog(*s3opt.auditLogConfig)
  200. if s3err.Logger != nil {
  201. defer s3err.Logger.Close()
  202. }
  203. }
  204. // starting grpc server
  205. grpcPort := *s3opt.portGrpc
  206. grpcL, grpcLocalL, err := util.NewIpAndLocalListeners(*s3opt.bindIp, grpcPort, 0)
  207. if err != nil {
  208. glog.Fatalf("s3 failed to listen on grpc port %d: %v", grpcPort, err)
  209. }
  210. grpcS := pb.NewGrpcServer(security.LoadServerTLS(util.GetViper(), "grpc.s3"))
  211. s3_pb.RegisterSeaweedS3Server(grpcS, s3ApiServer)
  212. reflection.Register(grpcS)
  213. if grpcLocalL != nil {
  214. go grpcS.Serve(grpcLocalL)
  215. }
  216. go grpcS.Serve(grpcL)
  217. if *s3opt.tlsPrivateKey != "" {
  218. glog.V(0).Infof("Start Seaweed S3 API Server %s at https port %d", util.Version(), *s3opt.port)
  219. if s3ApiLocalListener != nil {
  220. go func() {
  221. if err = httpS.ServeTLS(s3ApiLocalListener, *s3opt.tlsCertificate, *s3opt.tlsPrivateKey); err != nil {
  222. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  223. }
  224. }()
  225. }
  226. if err = httpS.ServeTLS(s3ApiListener, *s3opt.tlsCertificate, *s3opt.tlsPrivateKey); err != nil {
  227. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  228. }
  229. } else {
  230. glog.V(0).Infof("Start Seaweed S3 API Server %s at http port %d", util.Version(), *s3opt.port)
  231. if s3ApiLocalListener != nil {
  232. go func() {
  233. if err = httpS.Serve(s3ApiLocalListener); err != nil {
  234. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  235. }
  236. }()
  237. }
  238. if err = httpS.Serve(s3ApiListener); err != nil {
  239. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  240. }
  241. }
  242. return true
  243. }