X-Git-Url: https://git.arvados.org/arvados.git/blobdiff_plain/988971784cd3c294245fe65ca9141384e0f673f0..3f4edc70aa8866f735f49b435434828d7b42c2ce:/lib/boot/nginx.go diff --git a/lib/boot/nginx.go b/lib/boot/nginx.go index 1b361dd9c4..0f105d6b6c 100644 --- a/lib/boot/nginx.go +++ b/lib/boot/nginx.go @@ -8,6 +8,7 @@ import ( "context" "fmt" "io/ioutil" + "net" "os" "os/exec" "path/filepath" @@ -16,36 +17,59 @@ import ( "git.arvados.org/arvados.git/sdk/go/arvados" ) -func runNginx(ctx context.Context, boot *Booter) error { +// Run an Nginx process that proxies the supervisor's configured +// ExternalURLs to the appropriate InternalURLs. +type runNginx struct{} + +func (runNginx) String() string { + return "nginx" +} + +func (runNginx) Run(ctx context.Context, fail func(error), super *Supervisor) error { + err := super.wait(ctx, createCertificates{}) + if err != nil { + return err + } vars := map[string]string{ - "SSLCERT": filepath.Join(boot.SourcePath, "services", "api", "tmp", "self-signed.pem"), // TODO: root ca - "SSLKEY": filepath.Join(boot.SourcePath, "services", "api", "tmp", "self-signed.key"), // TODO: root ca - "ACCESSLOG": filepath.Join(boot.tempdir, "nginx_access.log"), - "ERRORLOG": filepath.Join(boot.tempdir, "nginx_error.log"), - "TMPDIR": boot.tempdir, + "LISTENHOST": super.ListenHost, + "SSLCERT": filepath.Join(super.tempdir, "server.crt"), + "SSLKEY": filepath.Join(super.tempdir, "server.key"), + "ACCESSLOG": filepath.Join(super.tempdir, "nginx_access.log"), + "ERRORLOG": filepath.Join(super.tempdir, "nginx_error.log"), + "TMPDIR": super.tempdir, } - var err error for _, cmpt := range []struct { varname string svc arvados.Service }{ - {"CONTROLLER", boot.cluster.Services.Controller}, - {"KEEPWEB", boot.cluster.Services.WebDAV}, - {"KEEPWEBDL", boot.cluster.Services.WebDAVDownload}, - {"KEEPPROXY", boot.cluster.Services.Keepproxy}, - {"GIT", boot.cluster.Services.GitHTTP}, - {"WS", boot.cluster.Services.Websocket}, + {"CONTROLLER", super.cluster.Services.Controller}, + {"KEEPWEB", super.cluster.Services.WebDAV}, + {"KEEPWEBDL", super.cluster.Services.WebDAVDownload}, + {"KEEPPROXY", super.cluster.Services.Keepproxy}, + {"GIT", super.cluster.Services.GitHTTP}, + {"HEALTH", super.cluster.Services.Health}, + {"WORKBENCH1", super.cluster.Services.Workbench1}, + {"WS", super.cluster.Services.Websocket}, } { - vars[cmpt.varname+"PORT"], err = internalPort(cmpt.svc) + port, err := internalPort(cmpt.svc) if err != nil { return fmt.Errorf("%s internal port: %s (%v)", cmpt.varname, err, cmpt.svc) } - vars[cmpt.varname+"SSLPORT"], err = externalPort(cmpt.svc) + if ok, err := addrIsLocal(net.JoinHostPort(super.ListenHost, port)); !ok || err != nil { + return fmt.Errorf("urlIsLocal() failed for host %q port %q: %v", super.ListenHost, port, err) + } + vars[cmpt.varname+"PORT"] = port + + port, err = externalPort(cmpt.svc) if err != nil { return fmt.Errorf("%s external port: %s (%v)", cmpt.varname, err, cmpt.svc) } + if ok, err := addrIsLocal(net.JoinHostPort(super.ListenHost, port)); !ok || err != nil { + return fmt.Errorf("urlIsLocal() failed for host %q port %q: %v", super.ListenHost, port, err) + } + vars[cmpt.varname+"SSLPORT"] = port } - tmpl, err := ioutil.ReadFile(filepath.Join(boot.SourcePath, "sdk", "python", "tests", "nginx.conf")) + tmpl, err := ioutil.ReadFile(filepath.Join(super.SourcePath, "sdk", "python", "tests", "nginx.conf")) if err != nil { return err } @@ -55,7 +79,7 @@ func runNginx(ctx context.Context, boot *Booter) error { } return vars[src[2:len(src)-2]] }) - conffile := filepath.Join(boot.tempdir, "nginx.conf") + conffile := filepath.Join(super.tempdir, "nginx.conf") err = ioutil.WriteFile(conffile, []byte(conf), 0755) if err != nil { return err @@ -69,8 +93,13 @@ func runNginx(ctx context.Context, boot *Booter) error { } } } - return boot.RunProgram(ctx, ".", nil, nil, nginx, - "-g", "error_log stderr info;", - "-g", "pid "+filepath.Join(boot.tempdir, "nginx.pid")+";", - "-c", conffile) + super.waitShutdown.Add(1) + go func() { + defer super.waitShutdown.Done() + fail(super.RunProgram(ctx, ".", nil, nil, nginx, + "-g", "error_log stderr info;", + "-g", "pid "+filepath.Join(super.tempdir, "nginx.pid")+";", + "-c", conffile)) + }() + return waitForConnect(ctx, super.cluster.Services.Controller.ExternalURL.Host) }