config_logging.go 8.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288
  1. // Copyright 2018 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package embed
  15. import (
  16. "crypto/tls"
  17. "errors"
  18. "fmt"
  19. "io/ioutil"
  20. "os"
  21. "reflect"
  22. "sort"
  23. "sync"
  24. "syscall"
  25. "github.com/coreos/etcd/pkg/logutil"
  26. "github.com/coreos/pkg/capnslog"
  27. "go.uber.org/zap"
  28. "go.uber.org/zap/zapcore"
  29. "google.golang.org/grpc"
  30. "google.golang.org/grpc/grpclog"
  31. )
  32. // GetLogger returns the logger.
  33. func (cfg Config) GetLogger() *zap.Logger {
  34. cfg.loggerMu.RLock()
  35. l := cfg.logger
  36. cfg.loggerMu.RUnlock()
  37. return l
  38. }
  39. // for testing
  40. var grpcLogOnce = new(sync.Once)
  41. // setupLogging initializes etcd logging.
  42. // Must be called after flag parsing or finishing configuring embed.Config.
  43. func (cfg *Config) setupLogging() error {
  44. // handle "DeprecatedLogOutput" in v3.4
  45. // TODO: remove "DeprecatedLogOutput" in v3.5
  46. len1 := len(cfg.DeprecatedLogOutput)
  47. len2 := len(cfg.LogOutputs)
  48. if len1 != len2 {
  49. switch {
  50. case len1 > len2: // deprecate "log-output" flag is used
  51. fmt.Fprintln(os.Stderr, "'--log-output' flag has been deprecated! Please use '--log-outputs'!")
  52. cfg.LogOutputs = cfg.DeprecatedLogOutput
  53. case len1 < len2: // "--log-outputs" flag has been set with multiple writers
  54. cfg.DeprecatedLogOutput = []string{}
  55. }
  56. } else {
  57. if len1 > 1 {
  58. return errors.New("both '--log-output' and '--log-outputs' are set; only set '--log-outputs'")
  59. }
  60. if len1 < 1 {
  61. return errors.New("either '--log-output' or '--log-outputs' flag must be set")
  62. }
  63. if reflect.DeepEqual(cfg.DeprecatedLogOutput, cfg.LogOutputs) && cfg.DeprecatedLogOutput[0] != DefaultLogOutput {
  64. return fmt.Errorf("'--log-output=%q' and '--log-outputs=%q' are incompatible; only set --log-outputs", cfg.DeprecatedLogOutput, cfg.LogOutputs)
  65. }
  66. if !reflect.DeepEqual(cfg.DeprecatedLogOutput, []string{DefaultLogOutput}) {
  67. fmt.Fprintf(os.Stderr, "Deprecated '--log-output' flag is set to %q\n", cfg.DeprecatedLogOutput)
  68. fmt.Fprintln(os.Stderr, "Please use '--log-outputs' flag")
  69. }
  70. }
  71. switch cfg.Logger {
  72. case "capnslog": // TODO: deprecate this in v3.5
  73. cfg.ClientTLSInfo.HandshakeFailure = logTLSHandshakeFailure
  74. cfg.PeerTLSInfo.HandshakeFailure = logTLSHandshakeFailure
  75. if cfg.Debug {
  76. capnslog.SetGlobalLogLevel(capnslog.DEBUG)
  77. grpc.EnableTracing = true
  78. // enable info, warning, error
  79. grpclog.SetLoggerV2(grpclog.NewLoggerV2(os.Stderr, os.Stderr, os.Stderr))
  80. } else {
  81. capnslog.SetGlobalLogLevel(capnslog.INFO)
  82. // only discard info
  83. grpclog.SetLoggerV2(grpclog.NewLoggerV2(ioutil.Discard, os.Stderr, os.Stderr))
  84. }
  85. // TODO: deprecate with "capnslog"
  86. if cfg.LogPkgLevels != "" {
  87. repoLog := capnslog.MustRepoLogger("github.com/coreos/etcd")
  88. settings, err := repoLog.ParseLogLevelConfig(cfg.LogPkgLevels)
  89. if err != nil {
  90. plog.Warningf("couldn't parse log level string: %s, continuing with default levels", err.Error())
  91. return nil
  92. }
  93. repoLog.SetLogLevel(settings)
  94. }
  95. if len(cfg.LogOutputs) != 1 {
  96. fmt.Printf("--logger=capnslog supports only 1 value in '--log-outputs', got %q\n", cfg.LogOutputs)
  97. os.Exit(1)
  98. }
  99. // capnslog initially SetFormatter(NewDefaultFormatter(os.Stderr))
  100. // where NewDefaultFormatter returns NewJournaldFormatter when syscall.Getppid() == 1
  101. // specify 'stdout' or 'stderr' to skip journald logging even when running under systemd
  102. output := cfg.LogOutputs[0]
  103. switch output {
  104. case "stdout":
  105. capnslog.SetFormatter(capnslog.NewPrettyFormatter(os.Stdout, cfg.Debug))
  106. case "stderr":
  107. capnslog.SetFormatter(capnslog.NewPrettyFormatter(os.Stderr, cfg.Debug))
  108. case DefaultLogOutput:
  109. default:
  110. plog.Panicf(`unknown log-output %q (only supports %q, "stdout", "stderr")`, output, DefaultLogOutput)
  111. }
  112. case "zap":
  113. if len(cfg.LogOutputs) == 0 {
  114. cfg.LogOutputs = []string{DefaultLogOutput}
  115. }
  116. if len(cfg.LogOutputs) > 1 {
  117. for _, v := range cfg.LogOutputs {
  118. if v == DefaultLogOutput {
  119. panic(fmt.Errorf("multi logoutput for %q is not supported yet", DefaultLogOutput))
  120. }
  121. }
  122. }
  123. // TODO: use zapcore to support more features?
  124. lcfg := zap.Config{
  125. Level: zap.NewAtomicLevelAt(zap.InfoLevel),
  126. Development: false,
  127. Sampling: &zap.SamplingConfig{
  128. Initial: 100,
  129. Thereafter: 100,
  130. },
  131. Encoding: "json",
  132. EncoderConfig: zap.NewProductionEncoderConfig(),
  133. OutputPaths: make([]string, 0),
  134. ErrorOutputPaths: make([]string, 0),
  135. }
  136. outputPaths, errOutputPaths := make(map[string]struct{}), make(map[string]struct{})
  137. isJournald := false
  138. for _, v := range cfg.LogOutputs {
  139. switch v {
  140. case DefaultLogOutput:
  141. if syscall.Getppid() == 1 {
  142. // capnslog initially SetFormatter(NewDefaultFormatter(os.Stderr))
  143. // where "NewDefaultFormatter" returns "NewJournaldFormatter"
  144. // specify 'stdout' or 'stderr' to override this redirects
  145. // when syscall.Getppid() == 1
  146. isJournald = true
  147. break
  148. }
  149. outputPaths["stderr"] = struct{}{}
  150. errOutputPaths["stderr"] = struct{}{}
  151. case "stderr":
  152. outputPaths["stderr"] = struct{}{}
  153. errOutputPaths["stderr"] = struct{}{}
  154. case "stdout":
  155. outputPaths["stdout"] = struct{}{}
  156. errOutputPaths["stdout"] = struct{}{}
  157. default:
  158. outputPaths[v] = struct{}{}
  159. errOutputPaths[v] = struct{}{}
  160. }
  161. }
  162. if !isJournald {
  163. for v := range outputPaths {
  164. lcfg.OutputPaths = append(lcfg.OutputPaths, v)
  165. }
  166. for v := range errOutputPaths {
  167. lcfg.ErrorOutputPaths = append(lcfg.ErrorOutputPaths, v)
  168. }
  169. sort.Strings(lcfg.OutputPaths)
  170. sort.Strings(lcfg.ErrorOutputPaths)
  171. if cfg.Debug {
  172. lcfg.Level = zap.NewAtomicLevelAt(zap.DebugLevel)
  173. grpc.EnableTracing = true
  174. }
  175. var err error
  176. cfg.logger, err = lcfg.Build()
  177. if err != nil {
  178. return err
  179. }
  180. cfg.loggerConfig = &lcfg
  181. cfg.loggerCore = nil
  182. cfg.loggerWriteSyncer = nil
  183. grpcLogOnce.Do(func() {
  184. // debug true, enable info, warning, error
  185. // debug false, only discard info
  186. var gl grpclog.LoggerV2
  187. gl, err = logutil.NewGRPCLoggerV2(lcfg)
  188. if err == nil {
  189. grpclog.SetLoggerV2(gl)
  190. }
  191. })
  192. if err != nil {
  193. return err
  194. }
  195. } else {
  196. if len(cfg.LogOutputs) > 1 {
  197. for _, v := range cfg.LogOutputs {
  198. if v != DefaultLogOutput {
  199. return fmt.Errorf("running as a systemd unit but other '--log-output' values (%q) are configured with 'default'; override 'default' value with something else", cfg.LogOutputs)
  200. }
  201. }
  202. }
  203. // use stderr as fallback
  204. syncer := getZapWriteSyncer()
  205. lvl := zap.NewAtomicLevelAt(zap.InfoLevel)
  206. if cfg.Debug {
  207. lvl = zap.NewAtomicLevelAt(zap.DebugLevel)
  208. grpc.EnableTracing = true
  209. }
  210. // WARN: do not change field names in encoder config
  211. // journald logging writer assumes field names of "level" and "caller"
  212. cr := zapcore.NewCore(
  213. zapcore.NewJSONEncoder(zap.NewProductionEncoderConfig()),
  214. syncer,
  215. lvl,
  216. )
  217. cfg.logger = zap.New(cr, zap.AddCaller(), zap.ErrorOutput(syncer))
  218. cfg.loggerConfig = nil
  219. cfg.loggerCore = cr
  220. cfg.loggerWriteSyncer = syncer
  221. grpcLogOnce.Do(func() {
  222. grpclog.SetLoggerV2(logutil.NewGRPCLoggerV2FromZapCore(cr, syncer))
  223. })
  224. }
  225. logTLSHandshakeFailure := func(conn *tls.Conn, err error) {
  226. state := conn.ConnectionState()
  227. remoteAddr := conn.RemoteAddr().String()
  228. serverName := state.ServerName
  229. if len(state.PeerCertificates) > 0 {
  230. cert := state.PeerCertificates[0]
  231. ips := make([]string, 0, len(cert.IPAddresses))
  232. for i := range cert.IPAddresses {
  233. ips[i] = cert.IPAddresses[i].String()
  234. }
  235. cfg.logger.Warn(
  236. "rejected connection",
  237. zap.String("remote-addr", remoteAddr),
  238. zap.String("server-name", serverName),
  239. zap.Strings("ip-addresses", ips),
  240. zap.Strings("dns-names", cert.DNSNames),
  241. zap.Error(err),
  242. )
  243. } else {
  244. cfg.logger.Warn(
  245. "rejected connection",
  246. zap.String("remote-addr", remoteAddr),
  247. zap.String("server-name", serverName),
  248. zap.Error(err),
  249. )
  250. }
  251. }
  252. cfg.ClientTLSInfo.HandshakeFailure = logTLSHandshakeFailure
  253. cfg.PeerTLSInfo.HandshakeFailure = logTLSHandshakeFailure
  254. default:
  255. return fmt.Errorf("unknown logger option %q", cfg.Logger)
  256. }
  257. return nil
  258. }