mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-19 10:46:58 +08:00
fix(region): sync waf ssl and cc list (#20445)
This commit is contained in:
@@ -94,12 +94,12 @@ require (
|
||||
k8s.io/cri-api v0.22.17
|
||||
k8s.io/klog/v2 v2.2.0
|
||||
moul.io/http2curl/v2 v2.3.0
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240530121614-6903cf4ebad0
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240603072803-dd17647bb71c
|
||||
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32
|
||||
yunion.io/x/jsonutils v1.0.1-0.20240203102553-4096f103b401
|
||||
yunion.io/x/log v1.0.1-0.20240305175729-7cf2d6cd5a91
|
||||
yunion.io/x/ovsdb v0.0.0-20230306173834-f164f413a900
|
||||
yunion.io/x/pkg v1.10.1-0.20240530085551-cc859990d9be
|
||||
yunion.io/x/pkg v1.10.1-0.20240601050854-9e3452bf4d47
|
||||
yunion.io/x/s3cli v0.0.0-20190917004522-13ac36d8687e
|
||||
yunion.io/x/sqlchemy v1.1.3-0.20240530085133-5058648977dd
|
||||
yunion.io/x/structarg v0.0.0-20231017124457-df4d5009457c
|
||||
|
||||
@@ -1309,8 +1309,8 @@ sigs.k8s.io/structured-merge-diff/v4 v4.0.1/go.mod h1:bJZC9H9iH24zzfZ/41RGcq60oK
|
||||
sigs.k8s.io/yaml v1.1.0/go.mod h1:UJmg0vDUVViEyp3mgSv9WPwZCDxu4rQW1olrI1uml+o=
|
||||
sigs.k8s.io/yaml v1.2.0 h1:kr/MCeFWJWTwyaHoR9c8EjH9OumOmoF9YGiZd7lFm/Q=
|
||||
sigs.k8s.io/yaml v1.2.0/go.mod h1:yfXDCHCao9+ENCvLSE62v9VSji2MKu5jeNfTrofGhJc=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240530121614-6903cf4ebad0 h1:u50Gqto+N6cS0O18DTSHaqnz0xtOMHz9OcmwSMRUTHA=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240530121614-6903cf4ebad0/go.mod h1:quoJjGTJ2PjAY0+3YeN5JuN136whECKmfkJQwIsXKjM=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240603072803-dd17647bb71c h1:GRMRxsn9qZVHiqI/+bBnDUT9gGCtoO2RYdoIK96fUco=
|
||||
yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240603072803-dd17647bb71c/go.mod h1:quoJjGTJ2PjAY0+3YeN5JuN136whECKmfkJQwIsXKjM=
|
||||
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32 h1:v7POYkQwo1XzOxBoIoRVr/k0V9Y5JyjpshlIFa9raug=
|
||||
yunion.io/x/executor v0.0.0-20230705125604-c5ac3141db32/go.mod h1:Uxuou9WQIeJXNpy7t2fPLL0BYLvLiMvGQwY7Qc6aSws=
|
||||
yunion.io/x/jsonutils v0.0.0-20190625054549-a964e1e8a051/go.mod h1:4N0/RVzsYL3kH3WE/H1BjUQdFiWu50JGCFQuuy+Z634=
|
||||
@@ -1324,8 +1324,8 @@ yunion.io/x/ovsdb v0.0.0-20230306173834-f164f413a900 h1:Hu/4ERvoWaN6aiFs4h4/yvVB
|
||||
yunion.io/x/ovsdb v0.0.0-20230306173834-f164f413a900/go.mod h1:0vLkNEhlmA64HViPBAnSTUMrx5QP1CLsxXmxDKQ80tc=
|
||||
yunion.io/x/pkg v0.0.0-20190620104149-945c25821dbf/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
|
||||
yunion.io/x/pkg v0.0.0-20190628082551-f4033ba2ea30/go.mod h1:t6rEGG2sQ4J7DhFxSZVOTjNd0YO/KlfWQyK1W4tog+E=
|
||||
yunion.io/x/pkg v1.10.1-0.20240530085551-cc859990d9be h1:HwmFCdWJaGMXD/BjNvkZGcHoQbXeaMtYGF7XVAudGps=
|
||||
yunion.io/x/pkg v1.10.1-0.20240530085551-cc859990d9be/go.mod h1:+3nFKJt+O4xWboiDAv2EqvMM0rmm3tPJaOuQSHFkcY8=
|
||||
yunion.io/x/pkg v1.10.1-0.20240601050854-9e3452bf4d47 h1:uh8OUgdycVKVORSoWNj2w9gMBEaOPgRePSlGqyKYa9s=
|
||||
yunion.io/x/pkg v1.10.1-0.20240601050854-9e3452bf4d47/go.mod h1:+3nFKJt+O4xWboiDAv2EqvMM0rmm3tPJaOuQSHFkcY8=
|
||||
yunion.io/x/s3cli v0.0.0-20190917004522-13ac36d8687e h1:v+EzIadodSwkdZ/7bremd7J8J50Cise/HCylsOJngmo=
|
||||
yunion.io/x/s3cli v0.0.0-20190917004522-13ac36d8687e/go.mod h1:0iFKpOs1y4lbCxeOmq3Xx/0AcQoewVPwj62eRluioEo=
|
||||
yunion.io/x/sqlchemy v1.1.3-0.20240530085133-5058648977dd h1:5y2pHZ4+cDIuh5MTI853yulkgdADRLWKeyYaaFGArcQ=
|
||||
|
||||
@@ -73,12 +73,17 @@ type SWafInstance struct {
|
||||
// 前面是否有代理服务
|
||||
IsAccessProduct bool `nullable:"false" default:"false" list:"user" update:"user" create:"optional"`
|
||||
AccessHeaders []string `width:"512" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
SourceIps []string `width:"512" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
HttpPorts []int `width:"64" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
HttpsPorts []int `width:"64" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
// 源站地址
|
||||
SourceIps []string `width:"512" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
// 回源地址
|
||||
CcList []string `width:"512" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
HttpPorts []int `width:"64" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
HttpsPorts []int `width:"64" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
|
||||
UpstreamScheme string `width:"32" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
UpstreamPort int `nullable:"true" list:"user" update:"admin"`
|
||||
CertId string `width:"36" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
CertName string `width:"128" charset:"utf8" nullable:"true" list:"user" update:"admin"`
|
||||
}
|
||||
|
||||
func (manager *SWafInstanceManager) GetContextManagers() [][]db.IModelManager {
|
||||
@@ -449,6 +454,15 @@ func (self *SWafInstance) SyncWithCloudWafInstance(ctx context.Context, userCred
|
||||
self.HttpPorts = ext.GetHttpPorts()
|
||||
self.Cname = ext.GetCname()
|
||||
self.SourceIps = ext.GetSourceIps()
|
||||
if ccList := ext.GetCcList(); len(ccList) > 0 {
|
||||
self.CcList = ccList
|
||||
}
|
||||
if certId := ext.GetCertId(); len(certId) > 0 {
|
||||
self.CertId = certId
|
||||
}
|
||||
if certName := ext.GetCertName(); len(certName) > 0 {
|
||||
self.CertName = certName
|
||||
}
|
||||
self.UpstreamScheme = ext.GetUpstreamScheme()
|
||||
self.UpstreamPort = ext.GetUpstreamPort()
|
||||
self.AccessHeaders = ext.GetAccessHeaders()
|
||||
@@ -483,6 +497,9 @@ func (self *SCloudregion) newFromCloudWafInstance(ctx context.Context, userCred
|
||||
waf.UpstreamScheme = ext.GetUpstreamScheme()
|
||||
waf.UpstreamPort = ext.GetUpstreamPort()
|
||||
waf.SourceIps = ext.GetSourceIps()
|
||||
waf.CcList = ext.GetCcList()
|
||||
waf.CertId = ext.GetCertId()
|
||||
waf.CertName = ext.GetCertName()
|
||||
waf.AccessHeaders = ext.GetAccessHeaders()
|
||||
var err = func() error {
|
||||
lockman.LockRawObject(ctx, WafInstanceManager.Keyword(), "name")
|
||||
|
||||
Vendored
+2
-2
@@ -1690,7 +1690,7 @@ sigs.k8s.io/structured-merge-diff/v4/value
|
||||
# sigs.k8s.io/yaml v1.2.0
|
||||
## explicit; go 1.12
|
||||
sigs.k8s.io/yaml
|
||||
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240530121614-6903cf4ebad0
|
||||
# yunion.io/x/cloudmux v0.3.10-0-alpha.1.0.20240603072803-dd17647bb71c
|
||||
## explicit; go 1.18
|
||||
yunion.io/x/cloudmux/pkg/apis
|
||||
yunion.io/x/cloudmux/pkg/apis/billing
|
||||
@@ -1787,7 +1787,7 @@ yunion.io/x/log/hooks
|
||||
yunion.io/x/ovsdb/cli_util
|
||||
yunion.io/x/ovsdb/schema/ovn_nb
|
||||
yunion.io/x/ovsdb/types
|
||||
# yunion.io/x/pkg v1.10.1-0.20240530085551-cc859990d9be
|
||||
# yunion.io/x/pkg v1.10.1-0.20240601050854-9e3452bf4d47
|
||||
## explicit; go 1.18
|
||||
yunion.io/x/pkg/appctx
|
||||
yunion.io/x/pkg/errors
|
||||
|
||||
+5
@@ -1478,7 +1478,12 @@ type ICloudWafInstance interface {
|
||||
GetHttpPorts() []int
|
||||
GetHttpsPorts() []int
|
||||
GetCname() string
|
||||
// 源站地址
|
||||
GetSourceIps() []string
|
||||
// 回源地址
|
||||
GetCcList() []string
|
||||
GetCertId() string
|
||||
GetCertName() string
|
||||
GetUpstreamScheme() string
|
||||
GetUpstreamPort() int
|
||||
|
||||
|
||||
+12
@@ -194,10 +194,22 @@ func (self *SWafDomain) GetCname() string {
|
||||
return self.Cname
|
||||
}
|
||||
|
||||
func (self *SWafDomain) GetCertId() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWafDomain) GetCertName() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWafDomain) GetSourceIps() []string {
|
||||
return self.SourceIps
|
||||
}
|
||||
|
||||
func (self *SWafDomain) GetCcList() []string {
|
||||
return []string{}
|
||||
}
|
||||
|
||||
func (self *SWafDomain) Delete() error {
|
||||
return self.region.DeleteDomain(self.insId, self.name)
|
||||
}
|
||||
|
||||
+28
@@ -58,6 +58,10 @@ type SWafDomainV2 struct {
|
||||
Backend string
|
||||
}
|
||||
}
|
||||
CertDetail *struct {
|
||||
Id string
|
||||
Name string
|
||||
}
|
||||
ResourceManagerResourceGroupId string
|
||||
}
|
||||
|
||||
@@ -105,6 +109,26 @@ func (self *SWafDomainV2) GetCname() string {
|
||||
return self.Cname
|
||||
}
|
||||
|
||||
func (self *SWafDomainV2) GetCertId() string {
|
||||
if self.CertDetail == nil {
|
||||
self.Refresh()
|
||||
}
|
||||
if self.CertDetail != nil {
|
||||
return self.CertDetail.Id
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWafDomainV2) GetCertName() string {
|
||||
if self.CertDetail == nil {
|
||||
self.Refresh()
|
||||
}
|
||||
if self.CertDetail != nil {
|
||||
return self.CertDetail.Name
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWafDomainV2) GetUpstreamPort() int {
|
||||
return 0
|
||||
}
|
||||
@@ -121,6 +145,10 @@ func (self *SWafDomainV2) GetSourceIps() []string {
|
||||
return ret
|
||||
}
|
||||
|
||||
func (self *SWafDomainV2) GetCcList() []string {
|
||||
return []string{}
|
||||
}
|
||||
|
||||
func (self *SWafDomainV2) Delete() error {
|
||||
return cloudprovider.ErrNotImplemented
|
||||
}
|
||||
|
||||
+12
@@ -84,6 +84,14 @@ func (self *SWebAcl) GetCname() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWebAcl) GetCertId() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWebAcl) GetCertName() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWebAcl) GetUpstreamScheme() string {
|
||||
return ""
|
||||
}
|
||||
@@ -96,6 +104,10 @@ func (self *SWebAcl) GetSourceIps() []string {
|
||||
return []string{}
|
||||
}
|
||||
|
||||
func (self *SWebAcl) GetCcList() []string {
|
||||
return []string{}
|
||||
}
|
||||
|
||||
func (self *SRegion) ListWebACLs(scope string) ([]SWebAcl, error) {
|
||||
if scope == SCOPE_CLOUDFRONT && self.RegionId != "us-east-1" {
|
||||
return []SWebAcl{}, nil
|
||||
|
||||
+12
@@ -466,6 +466,14 @@ func (self *SAppGatewayWaf) GetUpstreamScheme() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SAppGatewayWaf) GetCertId() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SAppGatewayWaf) GetCertName() string {
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SAppGatewayWaf) GetUpstreamPort() int {
|
||||
return 0
|
||||
}
|
||||
@@ -474,6 +482,10 @@ func (self *SAppGatewayWaf) GetSourceIps() []string {
|
||||
return []string{}
|
||||
}
|
||||
|
||||
func (self *SAppGatewayWaf) GetCcList() []string {
|
||||
return []string{}
|
||||
}
|
||||
|
||||
func (self *SAppGatewayWaf) AddRule(opts *cloudprovider.SWafRule) (cloudprovider.ICloudWafRule, error) {
|
||||
rule, err := wafRuleLocal2Cloud(opts)
|
||||
if err != nil {
|
||||
|
||||
+27
@@ -71,6 +71,7 @@ type SWafInstance struct {
|
||||
SrcList []string
|
||||
Status int
|
||||
UpstreamDomainList []string
|
||||
SSLId *string
|
||||
}
|
||||
|
||||
func (self *SWafInstance) GetName() string {
|
||||
@@ -184,10 +185,36 @@ func (self *SWafInstance) GetHttpsPorts() []int {
|
||||
return ret
|
||||
}
|
||||
|
||||
func (self *SWafInstance) GetCertId() string {
|
||||
if self.SSLId == nil {
|
||||
self.Refresh()
|
||||
}
|
||||
if self.SSLId != nil {
|
||||
return *self.SSLId
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWafInstance) GetCertName() string {
|
||||
sslId := self.GetCertId()
|
||||
if len(sslId) > 0 {
|
||||
cert, err := self.region.client.GetCertificate(sslId)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return cert.GetName()
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (self *SWafInstance) GetSourceIps() []string {
|
||||
return append(self.SrcList, self.UpstreamDomainList...)
|
||||
}
|
||||
|
||||
func (self *SWafInstance) GetCcList() []string {
|
||||
return self.CCList
|
||||
}
|
||||
|
||||
func (self *SWafInstance) Delete() error {
|
||||
return cloudprovider.ErrNotImplemented
|
||||
}
|
||||
|
||||
+1
-1
@@ -147,7 +147,7 @@ var imageVersions = map[string][]string{
|
||||
|
||||
"Alibaba Cloud Linux": {"2.1903", "3.2104"},
|
||||
"Anolis OS": {"7.9", "8.2", "8.4"},
|
||||
"Rocky Linux": {"8.5", "8.6", "8.7", "8.8", "8.9", "9.0", "9.1", "9.2"},
|
||||
"Rocky Linux": {"8.5", "8.6", "8.7", "8.8", "8.9", "8.10", "9.0", "9.1", "9.2", "9.3", "9.4"},
|
||||
"Fedora": {"33", "34", "35"},
|
||||
"AlmaLinux": {"8.5"},
|
||||
"Amazon Linux": {"2023", "2"},
|
||||
|
||||
Reference in New Issue
Block a user