mirror of
https://github.com/yunionio/cloudpods.git
synced 2026-09-24 16:03:43 +08:00
Merge pull request #419 in YUNIONIO/onecloud from ~QIUJIAN/onecloud:feature/qj-scheduler-add-ssl-support to release/2.3.0
* commit '7e463a4644fc774061305fcacfc82f3722947ce4': hack: scheduler ping/version escape auth make reverse proxy insecure ssl (for influxdb) make webconsole ssl capable scheduler add ssl support
This commit is contained in:
@@ -86,7 +86,13 @@ func startHTTP(s *SchedulerServer) error {
|
||||
}
|
||||
|
||||
log.Infof("Start server on: %s:%d", s.Address, s.Port)
|
||||
return server.ListenAndServe()
|
||||
|
||||
if o.GetOptions().EnableSsl {
|
||||
return server.ListenAndServeTLS(o.GetOptions().SslCertfile,
|
||||
o.GetOptions().SslKeyfile)
|
||||
} else {
|
||||
return server.ListenAndServe()
|
||||
}
|
||||
}
|
||||
|
||||
func Execute() error {
|
||||
|
||||
@@ -104,6 +104,10 @@ type Options struct {
|
||||
AdminPasswd string `help:"Admin password" default:"eBVVSNaMeyzDnD8F" alias:"admin-password"`
|
||||
AdminTenant string `help:"Admin tenant" default:"system" alias:"admin-tenant-name"`
|
||||
|
||||
EnableSsl bool `help:"Enable https"`
|
||||
SslCertfile string `help:"ssl certification file"`
|
||||
SslKeyfile string `help:"ssl certification key file"`
|
||||
|
||||
// scheduler options
|
||||
SchedulerOptions
|
||||
}
|
||||
|
||||
@@ -2,6 +2,7 @@ package proxy
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/tls"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"net/http/httputil"
|
||||
@@ -48,6 +49,9 @@ func (p *SReverseProxy) ServeHTTP(ctx context.Context, w http.ResponseWriter, r
|
||||
}
|
||||
log.Debugf("Forwarding to servie: %q, url: %q", p.serviceName, remoteUrl.String())
|
||||
proxy := httputil.NewSingleHostReverseProxy(remoteUrl)
|
||||
proxy.Transport = &http.Transport{
|
||||
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
|
||||
}
|
||||
r.Header.Del("Cookie")
|
||||
r.Header.Del("X-Auth-Token")
|
||||
proxy.ServeHTTP(w, r)
|
||||
|
||||
@@ -3,6 +3,7 @@ package middleware
|
||||
import (
|
||||
"fmt"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"gopkg.in/gin-gonic/gin.v1"
|
||||
|
||||
@@ -15,6 +16,15 @@ const (
|
||||
|
||||
func KeystoneTokenVerifyMiddleware() gin.HandlerFunc {
|
||||
return func(c *gin.Context) {
|
||||
// hack
|
||||
escapeAuth := []string{"ping", "version", "metrics"}
|
||||
for _, s := range escapeAuth {
|
||||
if strings.HasSuffix(c.Request.URL.Path, s) {
|
||||
c.Next()
|
||||
return
|
||||
}
|
||||
}
|
||||
|
||||
token := c.Request.Header.Get(XAuthTokenKey)
|
||||
if len(token) == 0 {
|
||||
c.AbortWithError(http.StatusBadRequest, fmt.Errorf("Not found %s in http header.", XAuthTokenKey))
|
||||
|
||||
@@ -2,7 +2,6 @@ package service
|
||||
|
||||
import (
|
||||
"net"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"os"
|
||||
"strconv"
|
||||
@@ -11,6 +10,7 @@ import (
|
||||
|
||||
"yunion.io/x/log"
|
||||
|
||||
"net/http"
|
||||
"yunion.io/x/onecloud/pkg/cloudcommon"
|
||||
"yunion.io/x/onecloud/pkg/webconsole"
|
||||
o "yunion.io/x/onecloud/pkg/webconsole/options"
|
||||
@@ -62,8 +62,18 @@ func start() {
|
||||
|
||||
addr := net.JoinHostPort(o.Options.Address, strconv.Itoa(o.Options.Port))
|
||||
log.Infof("Start listen on %s", addr)
|
||||
err := http.ListenAndServe(addr, root)
|
||||
if err != nil {
|
||||
log.Fatalf("%v", err)
|
||||
if o.Options.EnableSsl {
|
||||
err := http.ListenAndServeTLS(addr,
|
||||
o.Options.SslCertfile,
|
||||
o.Options.SslKeyfile,
|
||||
root)
|
||||
if err != nil && err != http.ErrServerClosed {
|
||||
log.Fatalf("%v", err)
|
||||
}
|
||||
} else {
|
||||
err := http.ListenAndServe(addr, root)
|
||||
if err != nil {
|
||||
log.Fatalf("%v", err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user