2016-02-22 00:13:08 +00:00
|
|
|
/*
|
|
|
|
Copyright 2015 The Kubernetes Authors All rights reserved.
|
|
|
|
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
|
|
|
|
package nginx
|
|
|
|
|
|
|
|
import (
|
2016-03-15 15:31:39 +00:00
|
|
|
"bytes"
|
2016-02-22 00:13:08 +00:00
|
|
|
"encoding/json"
|
|
|
|
"fmt"
|
2016-03-22 18:01:04 +00:00
|
|
|
"regexp"
|
2016-05-25 21:04:34 +00:00
|
|
|
"strings"
|
2016-02-22 00:13:08 +00:00
|
|
|
"text/template"
|
|
|
|
|
|
|
|
"github.com/fatih/structs"
|
|
|
|
"github.com/golang/glog"
|
2016-06-05 13:36:00 +00:00
|
|
|
|
|
|
|
"k8s.io/contrib/ingress/controllers/nginx/nginx/config"
|
2016-02-22 00:13:08 +00:00
|
|
|
)
|
|
|
|
|
2016-05-25 21:04:34 +00:00
|
|
|
const (
|
|
|
|
slash = "/"
|
|
|
|
)
|
|
|
|
|
2016-03-22 18:01:04 +00:00
|
|
|
var (
|
|
|
|
camelRegexp = regexp.MustCompile("[0-9A-Za-z]+")
|
2016-04-30 15:34:33 +00:00
|
|
|
tmplPath = "/etc/nginx/template/nginx.tmpl"
|
2016-02-22 00:13:08 +00:00
|
|
|
|
2016-03-22 18:01:04 +00:00
|
|
|
funcMap = template.FuncMap{
|
|
|
|
"empty": func(input interface{}) bool {
|
|
|
|
check, ok := input.(string)
|
|
|
|
if ok {
|
|
|
|
return len(check) == 0
|
|
|
|
}
|
|
|
|
|
|
|
|
return true
|
|
|
|
},
|
2016-05-30 17:39:10 +00:00
|
|
|
"buildLocation": buildLocation,
|
|
|
|
"buildProxyPass": buildProxyPass,
|
|
|
|
"buildRateLimitZones": buildRateLimitZones,
|
|
|
|
"buildRateLimit": buildRateLimit,
|
2016-03-22 18:01:04 +00:00
|
|
|
}
|
|
|
|
)
|
2016-02-22 00:13:08 +00:00
|
|
|
|
2016-07-28 21:35:36 +00:00
|
|
|
func (ngx *Manager) loadTemplate() error {
|
|
|
|
tmpl, err := template.New("nginx.tmpl").Funcs(funcMap).ParseFiles(tmplPath)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2016-02-22 00:13:08 +00:00
|
|
|
ngx.template = tmpl
|
2016-07-28 21:35:36 +00:00
|
|
|
return nil
|
2016-02-22 00:13:08 +00:00
|
|
|
}
|
|
|
|
|
2016-06-05 13:36:00 +00:00
|
|
|
func (ngx *Manager) writeCfg(cfg config.Configuration, ingressCfg IngressConfig) (bool, error) {
|
2016-02-22 00:13:08 +00:00
|
|
|
conf := make(map[string]interface{})
|
2016-07-12 03:04:21 +00:00
|
|
|
conf["backlogSize"] = sysctlSomaxconn()
|
2016-03-19 23:29:29 +00:00
|
|
|
conf["upstreams"] = ingressCfg.Upstreams
|
|
|
|
conf["servers"] = ingressCfg.Servers
|
|
|
|
conf["tcpUpstreams"] = ingressCfg.TCPUpstreams
|
2016-03-29 23:30:44 +00:00
|
|
|
conf["udpUpstreams"] = ingressCfg.UDPUpstreams
|
2016-02-22 00:13:08 +00:00
|
|
|
conf["defResolver"] = ngx.defResolver
|
|
|
|
conf["sslDHParam"] = ngx.sslDHParam
|
2016-05-23 23:15:13 +00:00
|
|
|
conf["customErrors"] = len(cfg.CustomHTTPErrors) > 0
|
2016-04-26 10:27:23 +00:00
|
|
|
conf["cfg"] = fixKeyNames(structs.Map(cfg))
|
2016-02-22 00:13:08 +00:00
|
|
|
|
2016-03-15 15:31:39 +00:00
|
|
|
if glog.V(3) {
|
2016-02-22 00:13:08 +00:00
|
|
|
b, err := json.Marshal(conf)
|
|
|
|
if err != nil {
|
2016-07-28 21:35:36 +00:00
|
|
|
glog.Errorf("unexpected error:", err)
|
2016-02-22 00:13:08 +00:00
|
|
|
}
|
2016-03-19 20:17:58 +00:00
|
|
|
glog.Infof("NGINX configuration: %v", string(b))
|
2016-02-22 00:13:08 +00:00
|
|
|
}
|
|
|
|
|
2016-05-23 23:15:13 +00:00
|
|
|
buffer := new(bytes.Buffer)
|
|
|
|
err := ngx.template.Execute(buffer, conf)
|
|
|
|
if err != nil {
|
2016-07-28 21:35:36 +00:00
|
|
|
glog.V(3).Infof("%v", string(buffer.Bytes()))
|
2016-05-23 23:15:13 +00:00
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
|
2016-03-19 23:29:29 +00:00
|
|
|
changed, err := ngx.needsReload(buffer)
|
|
|
|
if err != nil {
|
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
|
2016-03-15 15:31:39 +00:00
|
|
|
return changed, nil
|
2016-02-22 00:13:08 +00:00
|
|
|
}
|
2016-03-22 18:01:04 +00:00
|
|
|
|
|
|
|
func fixKeyNames(data map[string]interface{}) map[string]interface{} {
|
|
|
|
fixed := make(map[string]interface{})
|
|
|
|
for k, v := range data {
|
|
|
|
fixed[toCamelCase(k)] = v
|
|
|
|
}
|
|
|
|
|
|
|
|
return fixed
|
|
|
|
}
|
|
|
|
|
|
|
|
func toCamelCase(src string) string {
|
|
|
|
byteSrc := []byte(src)
|
|
|
|
chunks := camelRegexp.FindAll(byteSrc, -1)
|
|
|
|
for idx, val := range chunks {
|
|
|
|
if idx > 0 {
|
|
|
|
chunks[idx] = bytes.Title(val)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return string(bytes.Join(chunks, nil))
|
|
|
|
}
|
2016-05-25 21:04:34 +00:00
|
|
|
|
2016-05-27 14:58:13 +00:00
|
|
|
// buildLocation produces the location string, if the ingress has redirects
|
|
|
|
// (specified through the ingress.kubernetes.io/rewrite-to annotation)
|
2016-05-25 21:04:34 +00:00
|
|
|
func buildLocation(input interface{}) string {
|
|
|
|
location, ok := input.(*Location)
|
|
|
|
if !ok {
|
|
|
|
return slash
|
|
|
|
}
|
|
|
|
|
|
|
|
path := location.Path
|
2016-05-27 14:58:13 +00:00
|
|
|
if len(location.Redirect.Target) > 0 && location.Redirect.Target != path {
|
2016-05-25 21:04:34 +00:00
|
|
|
return fmt.Sprintf("~* %s", path)
|
|
|
|
}
|
|
|
|
|
|
|
|
return path
|
|
|
|
}
|
|
|
|
|
2016-05-27 14:58:13 +00:00
|
|
|
// buildProxyPass produces the proxy pass string, if the ingress has redirects
|
|
|
|
// (specified through the ingress.kubernetes.io/rewrite-to annotation)
|
|
|
|
// If the annotation ingress.kubernetes.io/add-base-url:"true" is specified it will
|
|
|
|
// add a base tag in the head of the response from the service
|
2016-05-25 21:04:34 +00:00
|
|
|
func buildProxyPass(input interface{}) string {
|
|
|
|
location, ok := input.(*Location)
|
|
|
|
if !ok {
|
|
|
|
return ""
|
|
|
|
}
|
|
|
|
|
|
|
|
path := location.Path
|
|
|
|
|
2016-06-01 18:47:37 +00:00
|
|
|
proto := "http"
|
|
|
|
if location.SecureUpstream {
|
|
|
|
proto = "https"
|
|
|
|
}
|
2016-05-27 14:58:13 +00:00
|
|
|
// defProxyPass returns the default proxy_pass, just the name of the upstream
|
2016-06-01 18:47:37 +00:00
|
|
|
defProxyPass := fmt.Sprintf("proxy_pass %s://%s;", proto, location.Upstream.Name)
|
2016-05-27 14:58:13 +00:00
|
|
|
// if the path in the ingress rule is equals to the target: no special rewrite
|
|
|
|
if path == location.Redirect.Target {
|
|
|
|
return defProxyPass
|
2016-05-25 21:04:34 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if path != slash && !strings.HasSuffix(path, slash) {
|
|
|
|
path = fmt.Sprintf("%s/", path)
|
|
|
|
}
|
|
|
|
|
2016-05-27 14:58:13 +00:00
|
|
|
if len(location.Redirect.Target) > 0 {
|
|
|
|
abu := ""
|
|
|
|
if location.Redirect.AddBaseURL {
|
|
|
|
bPath := location.Redirect.Target
|
|
|
|
if !strings.HasSuffix(bPath, slash) {
|
|
|
|
bPath = fmt.Sprintf("%s/", bPath)
|
|
|
|
}
|
|
|
|
|
|
|
|
abu = fmt.Sprintf(`subs_filter '<head(.*)>' '<head$1><base href="$scheme://$server_name%v">' r;
|
|
|
|
subs_filter '<HEAD(.*)>' '<HEAD$1><base href="$scheme://$server_name%v">' r;
|
|
|
|
`, bPath, bPath)
|
2016-05-25 21:04:34 +00:00
|
|
|
}
|
|
|
|
|
2016-05-27 14:58:13 +00:00
|
|
|
if location.Redirect.Target == slash {
|
2016-05-25 21:04:34 +00:00
|
|
|
// special case redirect to /
|
|
|
|
// ie /something to /
|
2016-05-27 14:58:13 +00:00
|
|
|
return fmt.Sprintf(`
|
|
|
|
rewrite %s(.*) /$1 break;
|
2016-06-04 18:06:18 +00:00
|
|
|
rewrite %s / break;
|
2016-06-01 18:47:37 +00:00
|
|
|
proxy_pass %s://%s;
|
2016-06-04 18:06:18 +00:00
|
|
|
%v`, path, location.Path, proto, location.Upstream.Name, abu)
|
2016-05-25 21:04:34 +00:00
|
|
|
}
|
|
|
|
|
2016-05-27 14:58:13 +00:00
|
|
|
return fmt.Sprintf(`
|
|
|
|
rewrite %s(.*) %s/$1 break;
|
2016-06-01 18:47:37 +00:00
|
|
|
proxy_pass %s://%s;
|
|
|
|
%v`, path, location.Redirect.Target, proto, location.Upstream.Name, abu)
|
2016-05-25 21:04:34 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// default proxy_pass
|
2016-05-27 14:58:13 +00:00
|
|
|
return defProxyPass
|
2016-05-25 21:04:34 +00:00
|
|
|
}
|
2016-05-30 17:39:10 +00:00
|
|
|
|
|
|
|
// buildRateLimitZones produces an array of limit_conn_zone in order to allow
|
|
|
|
// rate limiting of request. Each Ingress rule could have up to two zones, one
|
|
|
|
// for connection limit by IP address and other for limiting request per second
|
|
|
|
func buildRateLimitZones(input interface{}) []string {
|
|
|
|
zones := []string{}
|
|
|
|
|
|
|
|
servers, ok := input.([]*Server)
|
|
|
|
if !ok {
|
|
|
|
return zones
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, server := range servers {
|
|
|
|
for _, loc := range server.Locations {
|
|
|
|
|
2016-06-01 14:39:12 +00:00
|
|
|
if loc.RateLimit.Connections.Limit > 0 {
|
|
|
|
zone := fmt.Sprintf("limit_conn_zone $binary_remote_addr zone=%v:%vm;",
|
2016-05-30 17:39:10 +00:00
|
|
|
loc.RateLimit.Connections.Name, loc.RateLimit.Connections.SharedSize)
|
|
|
|
zones = append(zones, zone)
|
|
|
|
}
|
|
|
|
|
2016-06-01 14:39:12 +00:00
|
|
|
if loc.RateLimit.RPS.Limit > 0 {
|
|
|
|
zone := fmt.Sprintf("limit_conn_zone $binary_remote_addr zone=%v:%vm rate=%vr/s;",
|
2016-05-30 17:39:10 +00:00
|
|
|
loc.RateLimit.Connections.Name, loc.RateLimit.Connections.SharedSize, loc.RateLimit.Connections.Limit)
|
|
|
|
zones = append(zones, zone)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
return zones
|
|
|
|
}
|
|
|
|
|
|
|
|
// buildRateLimit produces an array of limit_req to be used inside the Path of
|
|
|
|
// Ingress rules. The order: connections by IP first and RPS next.
|
|
|
|
func buildRateLimit(input interface{}) []string {
|
|
|
|
limits := []string{}
|
|
|
|
|
|
|
|
loc, ok := input.(*Location)
|
|
|
|
if !ok {
|
|
|
|
return limits
|
|
|
|
}
|
|
|
|
|
2016-06-01 14:39:12 +00:00
|
|
|
if loc.RateLimit.Connections.Limit > 0 {
|
2016-05-30 17:39:10 +00:00
|
|
|
limit := fmt.Sprintf("limit_conn %v %v;",
|
|
|
|
loc.RateLimit.Connections.Name, loc.RateLimit.Connections.Limit)
|
|
|
|
limits = append(limits, limit)
|
|
|
|
}
|
|
|
|
|
2016-06-01 14:39:12 +00:00
|
|
|
if loc.RateLimit.RPS.Limit > 0 {
|
2016-05-30 17:39:10 +00:00
|
|
|
limit := fmt.Sprintf("limit_req zone=%v burst=%v nodelay;",
|
|
|
|
loc.RateLimit.Connections.Name, loc.RateLimit.Connections.Burst)
|
|
|
|
limits = append(limits, limit)
|
|
|
|
}
|
|
|
|
|
|
|
|
return limits
|
|
|
|
}
|