You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

315 lines
10 KiB

5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
5 years ago
4 years ago
  1. package command
  2. import (
  3. "context"
  4. "crypto/tls"
  5. "fmt"
  6. "github.com/seaweedfs/seaweedfs/weed/s3api/s3err"
  7. "google.golang.org/grpc/credentials/tls/certprovider"
  8. "google.golang.org/grpc/credentials/tls/certprovider/pemfile"
  9. "google.golang.org/grpc/reflection"
  10. "net/http"
  11. "time"
  12. "github.com/seaweedfs/seaweedfs/weed/pb"
  13. "github.com/seaweedfs/seaweedfs/weed/pb/filer_pb"
  14. "github.com/seaweedfs/seaweedfs/weed/pb/s3_pb"
  15. "github.com/seaweedfs/seaweedfs/weed/security"
  16. "github.com/gorilla/mux"
  17. "github.com/seaweedfs/seaweedfs/weed/glog"
  18. "github.com/seaweedfs/seaweedfs/weed/s3api"
  19. stats_collect "github.com/seaweedfs/seaweedfs/weed/stats"
  20. "github.com/seaweedfs/seaweedfs/weed/util"
  21. )
  22. var (
  23. s3StandaloneOptions S3Options
  24. )
  25. type S3Options struct {
  26. filer *string
  27. bindIp *string
  28. port *int
  29. portHttps *int
  30. portGrpc *int
  31. config *string
  32. domainName *string
  33. tlsPrivateKey *string
  34. tlsCertificate *string
  35. metricsHttpPort *int
  36. allowEmptyFolder *bool
  37. allowDeleteBucketNotEmpty *bool
  38. auditLogConfig *string
  39. localFilerSocket *string
  40. dataCenter *string
  41. certProvider certprovider.Provider
  42. }
  43. func init() {
  44. cmdS3.Run = runS3 // break init cycle
  45. s3StandaloneOptions.filer = cmdS3.Flag.String("filer", "localhost:8888", "filer server address")
  46. s3StandaloneOptions.bindIp = cmdS3.Flag.String("ip.bind", "", "ip address to bind to. Default to localhost.")
  47. s3StandaloneOptions.port = cmdS3.Flag.Int("port", 8333, "s3 server http listen port")
  48. s3StandaloneOptions.portHttps = cmdS3.Flag.Int("port.https", 0, "s3 server https listen port")
  49. s3StandaloneOptions.portGrpc = cmdS3.Flag.Int("port.grpc", 0, "s3 server grpc listen port")
  50. s3StandaloneOptions.domainName = cmdS3.Flag.String("domainName", "", "suffix of the host name in comma separated list, {bucket}.{domainName}")
  51. s3StandaloneOptions.dataCenter = cmdS3.Flag.String("dataCenter", "", "prefer to read and write to volumes in this data center")
  52. s3StandaloneOptions.config = cmdS3.Flag.String("config", "", "path to the config file")
  53. s3StandaloneOptions.auditLogConfig = cmdS3.Flag.String("auditLogConfig", "", "path to the audit log config file")
  54. s3StandaloneOptions.tlsPrivateKey = cmdS3.Flag.String("key.file", "", "path to the TLS private key file")
  55. s3StandaloneOptions.tlsCertificate = cmdS3.Flag.String("cert.file", "", "path to the TLS certificate file")
  56. s3StandaloneOptions.metricsHttpPort = cmdS3.Flag.Int("metricsPort", 0, "Prometheus metrics listen port")
  57. s3StandaloneOptions.allowEmptyFolder = cmdS3.Flag.Bool("allowEmptyFolder", true, "allow empty folders")
  58. s3StandaloneOptions.allowDeleteBucketNotEmpty = cmdS3.Flag.Bool("allowDeleteBucketNotEmpty", true, "allow recursive deleting all entries along with bucket")
  59. s3StandaloneOptions.localFilerSocket = cmdS3.Flag.String("localFilerSocket", "", "local filer socket path")
  60. }
  61. var cmdS3 = &Command{
  62. UsageLine: "s3 [-port=8333] [-filer=<ip:port>] [-config=</path/to/config.json>]",
  63. Short: "start a s3 API compatible server that is backed by a filer",
  64. Long: `start a s3 API compatible server that is backed by a filer.
  65. By default, you can use any access key and secret key to access the S3 APIs.
  66. To enable credential based access, create a config.json file similar to this:
  67. {
  68. "identities": [
  69. {
  70. "name": "anonymous",
  71. "actions": [
  72. "Read"
  73. ]
  74. },
  75. {
  76. "name": "some_admin_user",
  77. "credentials": [
  78. {
  79. "accessKey": "some_access_key1",
  80. "secretKey": "some_secret_key1"
  81. }
  82. ],
  83. "actions": [
  84. "Admin",
  85. "Read",
  86. "List",
  87. "Tagging",
  88. "Write"
  89. ]
  90. },
  91. {
  92. "name": "some_read_only_user",
  93. "credentials": [
  94. {
  95. "accessKey": "some_access_key2",
  96. "secretKey": "some_secret_key2"
  97. }
  98. ],
  99. "actions": [
  100. "Read"
  101. ]
  102. },
  103. {
  104. "name": "some_normal_user",
  105. "credentials": [
  106. {
  107. "accessKey": "some_access_key3",
  108. "secretKey": "some_secret_key3"
  109. }
  110. ],
  111. "actions": [
  112. "Read",
  113. "List",
  114. "Tagging",
  115. "Write"
  116. ]
  117. },
  118. {
  119. "name": "user_limited_to_bucket1",
  120. "credentials": [
  121. {
  122. "accessKey": "some_access_key4",
  123. "secretKey": "some_secret_key4"
  124. }
  125. ],
  126. "actions": [
  127. "Read:bucket1",
  128. "List:bucket1",
  129. "Tagging:bucket1",
  130. "Write:bucket1"
  131. ]
  132. }
  133. ]
  134. }
  135. `,
  136. }
  137. func runS3(cmd *Command, args []string) bool {
  138. util.LoadConfiguration("security", false)
  139. go stats_collect.StartMetricsServer(*s3StandaloneOptions.bindIp, *s3StandaloneOptions.metricsHttpPort)
  140. return s3StandaloneOptions.startS3Server()
  141. }
  142. // GetCertificateWithUpdate Auto refreshing TSL certificate
  143. func (S3opt *S3Options) GetCertificateWithUpdate(*tls.ClientHelloInfo) (*tls.Certificate, error) {
  144. certs, err := S3opt.certProvider.KeyMaterial(context.Background())
  145. return &certs.Certs[0], err
  146. }
  147. func (s3opt *S3Options) startS3Server() bool {
  148. filerAddress := pb.ServerAddress(*s3opt.filer)
  149. filerBucketsPath := "/buckets"
  150. filerGroup := ""
  151. grpcDialOption := security.LoadClientTLS(util.GetViper(), "grpc.client")
  152. // metrics read from the filer
  153. var metricsAddress string
  154. var metricsIntervalSec int
  155. for {
  156. err := pb.WithGrpcFilerClient(false, 0, filerAddress, grpcDialOption, func(client filer_pb.SeaweedFilerClient) error {
  157. resp, err := client.GetFilerConfiguration(context.Background(), &filer_pb.GetFilerConfigurationRequest{})
  158. if err != nil {
  159. return fmt.Errorf("get filer %s configuration: %v", filerAddress, err)
  160. }
  161. filerBucketsPath = resp.DirBuckets
  162. filerGroup = resp.FilerGroup
  163. metricsAddress, metricsIntervalSec = resp.MetricsAddress, int(resp.MetricsIntervalSec)
  164. glog.V(0).Infof("S3 read filer buckets dir: %s", filerBucketsPath)
  165. return nil
  166. })
  167. if err != nil {
  168. glog.V(0).Infof("wait to connect to filer %s grpc address %s", *s3opt.filer, filerAddress.ToGrpcAddress())
  169. time.Sleep(time.Second)
  170. } else {
  171. glog.V(0).Infof("connected to filer %s grpc address %s", *s3opt.filer, filerAddress.ToGrpcAddress())
  172. break
  173. }
  174. }
  175. go stats_collect.LoopPushingMetric("s3", stats_collect.SourceName(uint32(*s3opt.port)), metricsAddress, metricsIntervalSec)
  176. router := mux.NewRouter().SkipClean(true)
  177. var localFilerSocket string
  178. if s3opt.localFilerSocket != nil {
  179. localFilerSocket = *s3opt.localFilerSocket
  180. }
  181. s3ApiServer, s3ApiServer_err := s3api.NewS3ApiServer(router, &s3api.S3ApiServerOption{
  182. Filer: filerAddress,
  183. Port: *s3opt.port,
  184. Config: *s3opt.config,
  185. DomainName: *s3opt.domainName,
  186. BucketsPath: filerBucketsPath,
  187. GrpcDialOption: grpcDialOption,
  188. AllowEmptyFolder: *s3opt.allowEmptyFolder,
  189. AllowDeleteBucketNotEmpty: *s3opt.allowDeleteBucketNotEmpty,
  190. LocalFilerSocket: localFilerSocket,
  191. DataCenter: *s3opt.dataCenter,
  192. FilerGroup: filerGroup,
  193. })
  194. if s3ApiServer_err != nil {
  195. glog.Fatalf("S3 API Server startup error: %v", s3ApiServer_err)
  196. }
  197. httpS := &http.Server{Handler: router}
  198. if *s3opt.portGrpc == 0 {
  199. *s3opt.portGrpc = 10000 + *s3opt.port
  200. }
  201. if *s3opt.bindIp == "" {
  202. *s3opt.bindIp = "localhost"
  203. }
  204. listenAddress := fmt.Sprintf("%s:%d", *s3opt.bindIp, *s3opt.port)
  205. s3ApiListener, s3ApiLocalListener, err := util.NewIpAndLocalListeners(*s3opt.bindIp, *s3opt.port, time.Duration(10)*time.Second)
  206. if err != nil {
  207. glog.Fatalf("S3 API Server listener on %s error: %v", listenAddress, err)
  208. }
  209. if len(*s3opt.auditLogConfig) > 0 {
  210. s3err.InitAuditLog(*s3opt.auditLogConfig)
  211. if s3err.Logger != nil {
  212. defer s3err.Logger.Close()
  213. }
  214. }
  215. // starting grpc server
  216. grpcPort := *s3opt.portGrpc
  217. grpcL, grpcLocalL, err := util.NewIpAndLocalListeners(*s3opt.bindIp, grpcPort, 0)
  218. if err != nil {
  219. glog.Fatalf("s3 failed to listen on grpc port %d: %v", grpcPort, err)
  220. }
  221. grpcS := pb.NewGrpcServer(security.LoadServerTLS(util.GetViper(), "grpc.s3"))
  222. s3_pb.RegisterSeaweedS3Server(grpcS, s3ApiServer)
  223. reflection.Register(grpcS)
  224. if grpcLocalL != nil {
  225. go grpcS.Serve(grpcLocalL)
  226. }
  227. go grpcS.Serve(grpcL)
  228. if *s3opt.tlsPrivateKey != "" {
  229. pemfileOptions := pemfile.Options{
  230. CertFile: *s3opt.tlsCertificate,
  231. KeyFile: *s3opt.tlsPrivateKey,
  232. RefreshDuration: security.CredRefreshingInterval,
  233. }
  234. if s3opt.certProvider, err = pemfile.NewProvider(pemfileOptions); err != nil {
  235. glog.Fatalf("pemfile.NewProvider(%v) failed: %v", pemfileOptions, err)
  236. }
  237. httpS.TLSConfig = &tls.Config{GetCertificate: s3opt.GetCertificateWithUpdate}
  238. if *s3opt.portHttps == 0 {
  239. glog.V(0).Infof("Start Seaweed S3 API Server %s at https port %d", util.Version(), *s3opt.port)
  240. if s3ApiLocalListener != nil {
  241. go func() {
  242. if err = httpS.ServeTLS(s3ApiLocalListener, "", ""); err != nil {
  243. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  244. }
  245. }()
  246. }
  247. if err = httpS.ServeTLS(s3ApiListener, "", ""); err != nil {
  248. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  249. }
  250. } else {
  251. glog.V(0).Infof("Start Seaweed S3 API Server %s at https port %d", util.Version(), *s3opt.portHttps)
  252. s3ApiListenerHttps, s3ApiLocalListenerHttps, _ := util.NewIpAndLocalListeners(
  253. *s3opt.bindIp, *s3opt.portHttps, time.Duration(10)*time.Second)
  254. if s3ApiLocalListenerHttps != nil {
  255. go func() {
  256. if err = httpS.ServeTLS(s3ApiLocalListenerHttps, "", ""); err != nil {
  257. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  258. }
  259. }()
  260. }
  261. go func() {
  262. if err = httpS.ServeTLS(s3ApiListenerHttps, "", ""); err != nil {
  263. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  264. }
  265. }()
  266. }
  267. }
  268. if *s3opt.tlsPrivateKey == "" || *s3opt.portHttps > 0 {
  269. glog.V(0).Infof("Start Seaweed S3 API Server %s at http port %d", util.Version(), *s3opt.port)
  270. if s3ApiLocalListener != nil {
  271. go func() {
  272. if err = httpS.Serve(s3ApiLocalListener); err != nil {
  273. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  274. }
  275. }()
  276. }
  277. if err = httpS.Serve(s3ApiListener); err != nil {
  278. glog.Fatalf("S3 API Server Fail to serve: %v", err)
  279. }
  280. }
  281. return true
  282. }