Merge pull request #419 in YUNIONIO/onecloud from ~QIUJIAN/onecloud:feature/qj-scheduler-add-ssl-support to release/2.3.0

* commit '7e463a4644fc774061305fcacfc82f3722947ce4':
  hack: scheduler ping/version escape auth
  make reverse proxy insecure ssl (for influxdb)
  make webconsole ssl capable
  scheduler add ssl support
This commit is contained in:
邱剑
2018-11-03 13:33:19 +08:00
5 changed files with 39 additions and 5 deletions
+7 -1
View File
@@ -86,7 +86,13 @@ func startHTTP(s *SchedulerServer) error {
}
log.Infof("Start server on: %s:%d", s.Address, s.Port)
return server.ListenAndServe()
if o.GetOptions().EnableSsl {
return server.ListenAndServeTLS(o.GetOptions().SslCertfile,
o.GetOptions().SslKeyfile)
} else {
return server.ListenAndServe()
}
}
func Execute() error {
+4
View File
@@ -104,6 +104,10 @@ type Options struct {
AdminPasswd string `help:"Admin password" default:"eBVVSNaMeyzDnD8F" alias:"admin-password"`
AdminTenant string `help:"Admin tenant" default:"system" alias:"admin-tenant-name"`
EnableSsl bool `help:"Enable https"`
SslCertfile string `help:"ssl certification file"`
SslKeyfile string `help:"ssl certification key file"`
// scheduler options
SchedulerOptions
}
+4
View File
@@ -2,6 +2,7 @@ package proxy
import (
"context"
"crypto/tls"
"fmt"
"net/http"
"net/http/httputil"
@@ -48,6 +49,9 @@ func (p *SReverseProxy) ServeHTTP(ctx context.Context, w http.ResponseWriter, r
}
log.Debugf("Forwarding to servie: %q, url: %q", p.serviceName, remoteUrl.String())
proxy := httputil.NewSingleHostReverseProxy(remoteUrl)
proxy.Transport = &http.Transport{
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
}
r.Header.Del("Cookie")
r.Header.Del("X-Auth-Token")
proxy.ServeHTTP(w, r)
+10
View File
@@ -3,6 +3,7 @@ package middleware
import (
"fmt"
"net/http"
"strings"
"gopkg.in/gin-gonic/gin.v1"
@@ -15,6 +16,15 @@ const (
func KeystoneTokenVerifyMiddleware() gin.HandlerFunc {
return func(c *gin.Context) {
// hack
escapeAuth := []string{"ping", "version", "metrics"}
for _, s := range escapeAuth {
if strings.HasSuffix(c.Request.URL.Path, s) {
c.Next()
return
}
}
token := c.Request.Header.Get(XAuthTokenKey)
if len(token) == 0 {
c.AbortWithError(http.StatusBadRequest, fmt.Errorf("Not found %s in http header.", XAuthTokenKey))
+14 -4
View File
@@ -2,7 +2,6 @@ package service
import (
"net"
"net/http"
"net/url"
"os"
"strconv"
@@ -11,6 +10,7 @@ import (
"yunion.io/x/log"
"net/http"
"yunion.io/x/onecloud/pkg/cloudcommon"
"yunion.io/x/onecloud/pkg/webconsole"
o "yunion.io/x/onecloud/pkg/webconsole/options"
@@ -62,8 +62,18 @@ func start() {
addr := net.JoinHostPort(o.Options.Address, strconv.Itoa(o.Options.Port))
log.Infof("Start listen on %s", addr)
err := http.ListenAndServe(addr, root)
if err != nil {
log.Fatalf("%v", err)
if o.Options.EnableSsl {
err := http.ListenAndServeTLS(addr,
o.Options.SslCertfile,
o.Options.SslKeyfile,
root)
if err != nil && err != http.ErrServerClosed {
log.Fatalf("%v", err)
}
} else {
err := http.ListenAndServe(addr, root)
if err != nil {
log.Fatalf("%v", err)
}
}
}