feat(provider): new deployment provider: byteplus clb

This commit is contained in:
Fu Diwei
2026-06-04 01:14:21 +08:00
committed by RHQYZ
parent 155b186978
commit a4a0ed57e4
16 changed files with 707 additions and 13 deletions
@@ -0,0 +1,235 @@
package byteplusclb
import (
"context"
"errors"
"fmt"
"log/slog"
bp "github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus"
bpsession "github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/session"
bpclb "github.com/certimate-go/certimate/pkg/sdk3rd-trimmed/github.com/byteplus-sdk/byteplus-go-sdk-v2/service/clb"
"github.com/certimate-go/certimate/pkg/core"
cmgrimpl "github.com/certimate-go/certimate/pkg/core/certmgr/providers/byteplus-certcenter"
)
type (
Provider = core.Deployer
DeployResult = core.DeployerDeployResult
)
type DeployerConfig struct {
// BytePlus AccessKeyId。
AccessKeyId string `json:"accessKeyId"`
// BytePlus SecretAccessKey。
SecretAccessKey string `json:"secretAccessKey"`
// BytePlus 项目名称。
ProjectName string `json:"projectName,omitempty"`
// BytePlus 地域。
Region string `json:"region"`
// 部署目标。
DeployTarget string `json:"deployTarget"`
// 负载均衡实例 ID。
// 部署目标为 [DEPLOY_TARGET_LOADBALANCER] 时必填。
LoadbalancerId string `json:"loadbalancerId,omitempty"`
// 负载均衡监听器 ID。
// 部署目标为 [DEPLOY_TARGET_LISTENER] 时必填。
ListenerId string `json:"listenerId,omitempty"`
}
type Deployer struct {
config *DeployerConfig
logger *slog.Logger
sdkClient *bpclb.CLB
sdkCertmgr core.Certmgr
}
var _ Provider = (*Deployer)(nil)
func NewDeployer(config *DeployerConfig) (*Deployer, error) {
if config == nil {
return nil, fmt.Errorf("the configuration of the deployer provider is nil")
}
client, err := createSDKClient(config.AccessKeyId, config.SecretAccessKey, config.Region)
if err != nil {
return nil, fmt.Errorf("could not create client: %w", err)
}
pcertmgr, err := cmgrimpl.NewCertmgr(&cmgrimpl.CertmgrConfig{
AccessKeyId: config.AccessKeyId,
SecretAccessKey: config.SecretAccessKey,
ProjectName: config.ProjectName,
Region: "ap-singapore-1",
})
if err != nil {
return nil, fmt.Errorf("could not create certmgr: %w", err)
}
return &Deployer{
config: config,
logger: slog.Default(),
sdkClient: client,
sdkCertmgr: pcertmgr,
}, nil
}
func (d *Deployer) SetLogger(logger *slog.Logger) {
if logger == nil {
d.logger = slog.New(slog.DiscardHandler)
} else {
d.logger = logger
}
d.sdkCertmgr.SetLogger(logger)
}
func (d *Deployer) Deploy(ctx context.Context, certPEM, privkeyPEM string) (*DeployResult, error) {
// 上传证书
upres, err := d.sdkCertmgr.Upload(ctx, certPEM, privkeyPEM)
if err != nil {
return nil, fmt.Errorf("failed to upload certificate file: %w", err)
} else {
d.logger.Info("ssl certificate uploaded", slog.Any("result", upres))
}
// 根据部署目标决定业务流程
switch d.config.DeployTarget {
case DEPLOY_TARGET_LOADBALANCER:
if err := d.deployToLoadbalancer(ctx, upres.CertId); err != nil {
return nil, err
}
case DEPLOY_TARGET_LISTENER:
if err := d.deployToListener(ctx, upres.CertId); err != nil {
return nil, err
}
default:
return nil, fmt.Errorf("unsupported deploy target '%s'", d.config.DeployTarget)
}
return &DeployResult{}, nil
}
func (d *Deployer) deployToLoadbalancer(ctx context.Context, cloudCertId string) error {
if d.config.LoadbalancerId == "" {
return fmt.Errorf("config `loadbalancerId` is required")
}
// 查看指定负载均衡实例的详情
// REF: https://docs.byteplus.com/en/docs/clb/DescribeLoadBalancerAttributes
describeLoadBalancerAttributesReq := &bpclb.DescribeLoadBalancerAttributesInput{
LoadBalancerId: bp.String(d.config.LoadbalancerId),
}
describeLoadBalancerAttributesResp, err := d.sdkClient.DescribeLoadBalancerAttributesWithContext(ctx, describeLoadBalancerAttributesReq)
d.logger.Debug("sdk request 'clb.DescribeLoadBalancerAttributes'", slog.Any("request", describeLoadBalancerAttributesReq), slog.Any("response", describeLoadBalancerAttributesResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'clb.DescribeLoadBalancerAttributes': %w", err)
}
// 查询 HTTPS 监听器列表
// REF: https://docs.byteplus.com/en/docs/clb/DescribeListeners
listenerIds := make([]string, 0)
describeListenersPageSize := 100
describeListenersPageNumber := 1
for {
select {
case <-ctx.Done():
return ctx.Err()
default:
}
describeListenersReq := &bpclb.DescribeListenersInput{
LoadBalancerId: bp.String(d.config.LoadbalancerId),
Protocol: bp.String("HTTPS"),
PageNumber: bp.Int64(int64(describeListenersPageNumber)),
PageSize: bp.Int64(int64(describeListenersPageSize)),
}
describeListenersResp, err := d.sdkClient.DescribeListenersWithContext(ctx, describeListenersReq)
d.logger.Debug("sdk request 'clb.DescribeListeners'", slog.Any("request", describeListenersReq), slog.Any("response", describeListenersResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'clb.DescribeListeners': %w", err)
}
for _, listener := range describeListenersResp.Listeners {
listenerIds = append(listenerIds, *listener.ListenerId)
}
if len(describeListenersResp.Listeners) < describeListenersPageSize {
break
}
describeListenersPageNumber++
}
// 遍历更新监听证书
if len(listenerIds) == 0 {
d.logger.Info("no clb listeners to deploy")
} else {
d.logger.Info("found https listeners to deploy", slog.Any("listenerIds", listenerIds))
var errs []error
for _, listenerId := range listenerIds {
select {
case <-ctx.Done():
return ctx.Err()
default:
if err := d.updateListenerCertificate(ctx, listenerId, cloudCertId); err != nil {
errs = append(errs, err)
}
}
}
if len(errs) > 0 {
return errors.Join(errs...)
}
}
return nil
}
func (d *Deployer) deployToListener(ctx context.Context, cloudCertId string) error {
if d.config.ListenerId == "" {
return fmt.Errorf("config `listenerId` is required")
}
if err := d.updateListenerCertificate(ctx, d.config.ListenerId, cloudCertId); err != nil {
return err
}
return nil
}
func (d *Deployer) updateListenerCertificate(ctx context.Context, cloudListenerId string, cloudCertId string) error {
// 修改指定监听器
// REF: https://docs.byteplus.com/en/docs/clb/ModifyListenerAttributes
modifyListenerAttributesReq := &bpclb.ModifyListenerAttributesInput{
ListenerId: bp.String(cloudListenerId),
CertificateSource: bp.String("cert_center"),
CertCenterCertificateId: bp.String(cloudCertId),
}
modifyListenerAttributesResp, err := d.sdkClient.ModifyListenerAttributesWithContext(ctx, modifyListenerAttributesReq)
d.logger.Debug("sdk request 'clb.ModifyListenerAttributes'", slog.Any("request", modifyListenerAttributesReq), slog.Any("response", modifyListenerAttributesResp))
if err != nil {
return fmt.Errorf("failed to execute sdk request 'clb.ModifyListenerAttributes': %w", err)
}
return nil
}
func createSDKClient(accessKeyId, secretAccessKey, region string) (*bpclb.CLB, error) {
config := bp.NewConfig().
WithAkSk(accessKeyId, secretAccessKey).
WithRegion(region)
session, err := bpsession.NewSession(config)
if err != nil {
return nil, err
}
client := bpclb.New(session)
return client, nil
}
@@ -0,0 +1,58 @@
package byteplusclb_test
import (
"testing"
"github.com/certimate-go/certimate/pkg/core/deployer/internal/tester"
impl "github.com/certimate-go/certimate/pkg/core/deployer/providers/byteplus-clb"
)
var (
fp = tester.Args("BYTEPLUSCLB_")
fTestCertPath string
fTestKeyPath string
fAccessKeyId string
fSecretAccessKey string
fRegion string
fListenerId string
)
func init() {
fp.DefineString(&fTestCertPath, "TESTCERTPATH")
fp.DefineString(&fTestKeyPath, "TESTKEYPATH")
fp.DefineString(&fAccessKeyId, "ACCESSKEYID")
fp.DefineString(&fSecretAccessKey, "SECRETACCESSKEY")
fp.DefineString(&fRegion, "REGION")
fp.DefineString(&fListenerId, "LISTENERID")
}
/*
Shell command to run this test:
go test -v ./byteplus_clb_test.go -args \
--BYTEPLUSCLB_TESTCERTPATH="/path/to/your-test-cert.pem" \
--BYTEPLUSCLB_TESTKEYPATH="/path/to/your-test-key.pem" \
--BYTEPLUSCLB_ACCESSKEYID="your-access-key-id" \
--BYTEPLUSCLB_SECRETACCESSKEY="your-secret-access-key" \
--BYTEPLUSCLB_REGION="ap-southeast-1" \
--BYTEPLUSCLB_LISTENERID="your-listener-id"
*/
func TestProvider(t *testing.T) {
fp.Parse()
t.Run("Deploy_ToListener", func(t *testing.T) {
provider, err := impl.NewDeployer(&impl.DeployerConfig{
AccessKeyId: fAccessKeyId,
SecretAccessKey: fSecretAccessKey,
Region: fRegion,
DeployTarget: impl.DEPLOY_TARGET_LISTENER,
ListenerId: fListenerId,
})
if err != nil {
t.Errorf("err: %+v", err)
return
}
tester.TestDeploy(t, provider, tester.TestDeployArgs{CertPath: fTestCertPath, KeyPath: fTestKeyPath})
})
}
@@ -0,0 +1,8 @@
package byteplusclb
const (
// 部署目标:部署到指定负载均衡器。
DEPLOY_TARGET_LOADBALANCER = "loadbalancer"
// 部署目标:部署到指定监听器。
DEPLOY_TARGET_LISTENER = "listener"
)
@@ -0,0 +1,37 @@
package clb
import (
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/request"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/service/clb"
)
const opDescribeListeners = "DescribeListeners"
func (c *CLB) DescribeListenersRequest(input *DescribeListenersInput) (req *request.Request, output *DescribeListenersOutput) {
op := &request.Operation{
Name: opDescribeListeners,
HTTPMethod: "GET",
HTTPPath: "/",
}
if input == nil {
input = &DescribeListenersInput{}
}
output = &DescribeListenersOutput{}
req = c.newRequest(op, input, output)
return
}
func (c *CLB) DescribeListenersWithContext(ctx byteplus.Context, input *DescribeListenersInput, opts ...request.Option) (*DescribeListenersOutput, error) {
req, out := c.DescribeListenersRequest(input)
req.SetContext(ctx)
req.ApplyOptions(opts...)
return out, req.Send()
}
type DescribeListenersInput = clb.DescribeListenersInput
type DescribeListenersOutput = clb.DescribeListenersOutput
@@ -0,0 +1,37 @@
package clb
import (
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/request"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/service/clb"
)
const opDescribeLoadBalancerAttributes = "DescribeLoadBalancerAttributes"
func (c *CLB) DescribeLoadBalancerAttributesRequest(input *DescribeLoadBalancerAttributesInput) (req *request.Request, output *DescribeLoadBalancerAttributesOutput) {
op := &request.Operation{
Name: opDescribeLoadBalancerAttributes,
HTTPMethod: "GET",
HTTPPath: "/",
}
if input == nil {
input = &DescribeLoadBalancerAttributesInput{}
}
output = &DescribeLoadBalancerAttributesOutput{}
req = c.newRequest(op, input, output)
return
}
func (c *CLB) DescribeLoadBalancerAttributesWithContext(ctx byteplus.Context, input *DescribeLoadBalancerAttributesInput, opts ...request.Option) (*DescribeLoadBalancerAttributesOutput, error) {
req, out := c.DescribeLoadBalancerAttributesRequest(input)
req.SetContext(ctx)
req.ApplyOptions(opts...)
return out, req.Send()
}
type DescribeLoadBalancerAttributesInput = clb.DescribeLoadBalancerAttributesInput
type DescribeLoadBalancerAttributesOutput = clb.DescribeLoadBalancerAttributesOutput
@@ -0,0 +1,37 @@
package clb
import (
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/request"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/service/clb"
)
const opModifyListenerAttributes = "ModifyListenerAttributes"
func (c *CLB) ModifyListenerAttributesRequest(input *ModifyListenerAttributesInput) (req *request.Request, output *ModifyListenerAttributesOutput) {
op := &request.Operation{
Name: opModifyListenerAttributes,
HTTPMethod: "GET",
HTTPPath: "/",
}
if input == nil {
input = &ModifyListenerAttributesInput{}
}
output = &ModifyListenerAttributesOutput{}
req = c.newRequest(op, input, output)
return
}
func (c *CLB) ModifyListenerAttributesWithContext(ctx byteplus.Context, input *ModifyListenerAttributesInput, opts ...request.Option) (*ModifyListenerAttributesOutput, error) {
req, out := c.ModifyListenerAttributesRequest(input)
req.SetContext(ctx)
req.ApplyOptions(opts...)
return out, req.Send()
}
type ModifyListenerAttributesInput = clb.ModifyListenerAttributesInput
type ModifyListenerAttributesOutput = clb.ModifyListenerAttributesOutput
@@ -0,0 +1,60 @@
package clb
import (
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/byteplusquery"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/client"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/client/metadata"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/corehandlers"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/request"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/byteplus/signer/byteplussign"
"github.com/byteplus-sdk/byteplus-go-sdk-v2/service/clb"
)
type CLB struct {
*client.Client
}
const (
ServiceName = clb.ServiceName
EndpointsID = clb.EndpointsID
ServiceID = clb.ServiceID
)
func New(p client.ConfigProvider, cfgs ...*byteplus.Config) *CLB {
c := p.ClientConfig(clb.EndpointsID, cfgs...)
return newClient(*c.Config, c.Handlers, c.Endpoint, c.SigningRegion, c.SigningName)
}
func newClient(cfg byteplus.Config, handlers request.Handlers, endpoint, signingRegion, signingName string) *CLB {
svc := &CLB{
Client: client.New(
cfg,
metadata.ClientInfo{
ServiceName: clb.ServiceName,
ServiceID: clb.ServiceID,
SigningName: signingName,
SigningRegion: signingRegion,
Endpoint: endpoint,
APIVersion: "2020-04-01",
},
handlers,
),
}
svc.Handlers.Build.PushBackNamed(corehandlers.SDKVersionUserAgentHandler)
svc.Handlers.Build.PushBackNamed(corehandlers.AddHostExecEnvUserAgentHandler)
svc.Handlers.Sign.PushBackNamed(byteplussign.SignRequestHandler)
svc.Handlers.Build.PushBackNamed(byteplusquery.BuildHandler)
svc.Handlers.Unmarshal.PushBackNamed(byteplusquery.UnmarshalHandler)
svc.Handlers.UnmarshalMeta.PushBackNamed(byteplusquery.UnmarshalMetaHandler)
svc.Handlers.UnmarshalError.PushBackNamed(byteplusquery.UnmarshalErrorHandler)
return svc
}
func (c *CLB) newRequest(op *request.Operation, params, data interface{}) *request.Request {
req := c.NewRequest(op, params, data)
return req
}