1 // Copyright (C) The Arvados Authors. All rights reserved.
3 // SPDX-License-Identifier: AGPL-3.0
18 "git.arvados.org/arvados.git/sdk/go/arvados"
21 // Run an Nginx process that proxies the supervisor's configured
22 // ExternalURLs to the appropriate InternalURLs.
23 type runNginx struct{}
25 func (runNginx) String() string {
29 func (runNginx) Run(ctx context.Context, fail func(error), super *Supervisor) error {
30 err := super.wait(ctx, createCertificates{})
34 vars := map[string]string{
35 "LISTENHOST": super.ListenHost,
36 "SSLCERT": filepath.Join(super.tempdir, "server.crt"),
37 "SSLKEY": filepath.Join(super.tempdir, "server.key"),
38 "ACCESSLOG": filepath.Join(super.tempdir, "nginx_access.log"),
39 "ERRORLOG": filepath.Join(super.tempdir, "nginx_error.log"),
40 "TMPDIR": super.tempdir,
42 for _, cmpt := range []struct {
46 {"CONTROLLER", super.cluster.Services.Controller},
47 {"KEEPWEB", super.cluster.Services.WebDAV},
48 {"KEEPWEBDL", super.cluster.Services.WebDAVDownload},
49 {"KEEPPROXY", super.cluster.Services.Keepproxy},
50 {"GIT", super.cluster.Services.GitHTTP},
51 {"HEALTH", super.cluster.Services.Health},
52 {"WORKBENCH1", super.cluster.Services.Workbench1},
53 {"WS", super.cluster.Services.Websocket},
55 port, err := internalPort(cmpt.svc)
57 return fmt.Errorf("%s internal port: %w (%v)", cmpt.varname, err, cmpt.svc)
59 if ok, err := addrIsLocal(net.JoinHostPort(super.ListenHost, port)); !ok || err != nil {
60 return fmt.Errorf("urlIsLocal() failed for host %q port %q: %v", super.ListenHost, port, err)
62 vars[cmpt.varname+"PORT"] = port
64 port, err = externalPort(cmpt.svc)
66 return fmt.Errorf("%s external port: %w (%v)", cmpt.varname, err, cmpt.svc)
68 if ok, err := addrIsLocal(net.JoinHostPort(super.ListenHost, port)); !ok || err != nil {
69 return fmt.Errorf("urlIsLocal() failed for host %q port %q: %v", super.ListenHost, port, err)
71 vars[cmpt.varname+"SSLPORT"] = port
73 var conftemplate string
74 if super.ClusterType == "production" {
75 conftemplate = "/var/lib/arvados/share/nginx.conf"
77 conftemplate = filepath.Join(super.SourcePath, "sdk", "python", "tests", "nginx.conf")
79 tmpl, err := ioutil.ReadFile(conftemplate)
83 conf := regexp.MustCompile(`{{.*?}}`).ReplaceAllStringFunc(string(tmpl), func(src string) string {
87 return vars[src[2:len(src)-2]]
89 conffile := filepath.Join(super.tempdir, "nginx.conf")
90 err = ioutil.WriteFile(conffile, []byte(conf), 0755)
95 if _, err := exec.LookPath(nginx); err != nil {
96 for _, dir := range []string{"/sbin", "/usr/sbin", "/usr/local/sbin"} {
97 if _, err = os.Stat(dir + "/nginx"); err == nil {
98 nginx = dir + "/nginx"
103 super.waitShutdown.Add(1)
105 defer super.waitShutdown.Done()
106 fail(super.RunProgram(ctx, ".", nil, nil, nginx,
107 "-g", "error_log stderr info;",
108 "-g", "pid "+filepath.Join(super.tempdir, "nginx.pid")+";",
111 // Choose one of the ports where Nginx should listen, and wait
112 // here until we can connect. If ExternalURL is https://foo (with no port) then we connect to "foo:https"
113 testurl := url.URL(super.cluster.Services.Controller.ExternalURL)
114 if testurl.Port() == "" {
115 testurl.Host = net.JoinHostPort(testurl.Host, testurl.Scheme)
117 return waitForConnect(ctx, testurl.Host)