global.go 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427
  1. // Copyright 2015 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package command
  15. import (
  16. "crypto/tls"
  17. "errors"
  18. "fmt"
  19. "io"
  20. "io/ioutil"
  21. "os"
  22. "strings"
  23. "time"
  24. "github.com/bgentry/speakeasy"
  25. "github.com/coreos/etcd/clientv3"
  26. "github.com/coreos/etcd/pkg/flags"
  27. "github.com/coreos/etcd/pkg/srv"
  28. "github.com/coreos/etcd/pkg/transport"
  29. "github.com/spf13/cobra"
  30. "github.com/spf13/pflag"
  31. "go.uber.org/zap"
  32. "google.golang.org/grpc/grpclog"
  33. )
  34. // GlobalFlags are flags that defined globally
  35. // and are inherited to all sub-commands.
  36. type GlobalFlags struct {
  37. Insecure bool
  38. InsecureSkipVerify bool
  39. InsecureDiscovery bool
  40. Endpoints []string
  41. DialTimeout time.Duration
  42. CommandTimeOut time.Duration
  43. KeepAliveTime time.Duration
  44. KeepAliveTimeout time.Duration
  45. TLS transport.TLSInfo
  46. OutputFormat string
  47. IsHex bool
  48. User string
  49. Debug bool
  50. }
  51. type secureCfg struct {
  52. cert string
  53. key string
  54. cacert string
  55. serverName string
  56. insecureTransport bool
  57. insecureSkipVerify bool
  58. }
  59. type authCfg struct {
  60. username string
  61. password string
  62. }
  63. type discoveryCfg struct {
  64. domain string
  65. insecure bool
  66. }
  67. var display printer = &simplePrinter{}
  68. func initDisplayFromCmd(cmd *cobra.Command) {
  69. isHex, err := cmd.Flags().GetBool("hex")
  70. if err != nil {
  71. ExitWithError(ExitError, err)
  72. }
  73. outputType, err := cmd.Flags().GetString("write-out")
  74. if err != nil {
  75. ExitWithError(ExitError, err)
  76. }
  77. if display = NewPrinter(outputType, isHex); display == nil {
  78. ExitWithError(ExitBadFeature, errors.New("unsupported output format"))
  79. }
  80. }
  81. type clientConfig struct {
  82. endpoints []string
  83. dialTimeout time.Duration
  84. keepAliveTime time.Duration
  85. keepAliveTimeout time.Duration
  86. scfg *secureCfg
  87. acfg *authCfg
  88. }
  89. type discardValue struct{}
  90. func (*discardValue) String() string { return "" }
  91. func (*discardValue) Set(string) error { return nil }
  92. func (*discardValue) Type() string { return "" }
  93. func clientConfigFromCmd(cmd *cobra.Command) *clientConfig {
  94. fs := cmd.InheritedFlags()
  95. // silence "pkg/flags: unrecognized environment variable ETCDCTL_WATCH_KEY=foo" warnings
  96. // silence "pkg/flags: unrecognized environment variable ETCDCTL_WATCH_RANGE_END=bar" warnings
  97. fs.AddFlag(&pflag.Flag{Name: "watch-key", Value: &discardValue{}})
  98. fs.AddFlag(&pflag.Flag{Name: "watch-range-end", Value: &discardValue{}})
  99. flags.SetPflagsFromEnv("ETCDCTL", fs)
  100. debug, err := cmd.Flags().GetBool("debug")
  101. if err != nil {
  102. ExitWithError(ExitError, err)
  103. }
  104. if debug {
  105. clientv3.SetLogger(grpclog.NewLoggerV2WithVerbosity(os.Stderr, os.Stderr, os.Stderr, 4))
  106. fs.VisitAll(func(f *pflag.Flag) {
  107. fmt.Fprintf(os.Stderr, "%s=%v\n", flags.FlagToEnv("ETCDCTL", f.Name), f.Value)
  108. })
  109. } else {
  110. // WARNING logs contain important information like TLS misconfirugation, but spams
  111. // too many routine connection disconnects to turn on by default.
  112. //
  113. // See https://github.com/coreos/etcd/pull/9623 for background
  114. clientv3.SetLogger(grpclog.NewLoggerV2(ioutil.Discard, ioutil.Discard, os.Stderr))
  115. }
  116. cfg := &clientConfig{}
  117. cfg.endpoints, err = endpointsFromCmd(cmd)
  118. if err != nil {
  119. ExitWithError(ExitError, err)
  120. }
  121. cfg.dialTimeout = dialTimeoutFromCmd(cmd)
  122. cfg.keepAliveTime = keepAliveTimeFromCmd(cmd)
  123. cfg.keepAliveTimeout = keepAliveTimeoutFromCmd(cmd)
  124. cfg.scfg = secureCfgFromCmd(cmd)
  125. cfg.acfg = authCfgFromCmd(cmd)
  126. initDisplayFromCmd(cmd)
  127. return cfg
  128. }
  129. func mustClientCfgFromCmd(cmd *cobra.Command) *clientv3.Config {
  130. cc := clientConfigFromCmd(cmd)
  131. cfg, err := newClientCfg(cc.endpoints, cc.dialTimeout, cc.keepAliveTime, cc.keepAliveTimeout, cc.scfg, cc.acfg)
  132. if err != nil {
  133. ExitWithError(ExitBadArgs, err)
  134. }
  135. return cfg
  136. }
  137. func mustClientFromCmd(cmd *cobra.Command) *clientv3.Client {
  138. cfg := clientConfigFromCmd(cmd)
  139. return cfg.mustClient()
  140. }
  141. func (cc *clientConfig) mustClient() *clientv3.Client {
  142. cfg, err := newClientCfg(cc.endpoints, cc.dialTimeout, cc.keepAliveTime, cc.keepAliveTimeout, cc.scfg, cc.acfg)
  143. if err != nil {
  144. ExitWithError(ExitBadArgs, err)
  145. }
  146. client, err := clientv3.New(*cfg)
  147. if err != nil {
  148. ExitWithError(ExitBadConnection, err)
  149. }
  150. return client
  151. }
  152. func newClientCfg(endpoints []string, dialTimeout, keepAliveTime, keepAliveTimeout time.Duration, scfg *secureCfg, acfg *authCfg) (*clientv3.Config, error) {
  153. // set tls if any one tls option set
  154. var cfgtls *transport.TLSInfo
  155. tlsinfo := transport.TLSInfo{}
  156. tlsinfo.Logger, _ = zap.NewProduction()
  157. if scfg.cert != "" {
  158. tlsinfo.CertFile = scfg.cert
  159. cfgtls = &tlsinfo
  160. }
  161. if scfg.key != "" {
  162. tlsinfo.KeyFile = scfg.key
  163. cfgtls = &tlsinfo
  164. }
  165. if scfg.cacert != "" {
  166. tlsinfo.TrustedCAFile = scfg.cacert
  167. cfgtls = &tlsinfo
  168. }
  169. if scfg.serverName != "" {
  170. tlsinfo.ServerName = scfg.serverName
  171. cfgtls = &tlsinfo
  172. }
  173. cfg := &clientv3.Config{
  174. Endpoints: endpoints,
  175. DialTimeout: dialTimeout,
  176. DialKeepAliveTime: keepAliveTime,
  177. DialKeepAliveTimeout: keepAliveTimeout,
  178. }
  179. if cfgtls != nil {
  180. clientTLS, err := cfgtls.ClientConfig()
  181. if err != nil {
  182. return nil, err
  183. }
  184. cfg.TLS = clientTLS
  185. }
  186. // if key/cert is not given but user wants secure connection, we
  187. // should still setup an empty tls configuration for gRPC to setup
  188. // secure connection.
  189. if cfg.TLS == nil && !scfg.insecureTransport {
  190. cfg.TLS = &tls.Config{}
  191. }
  192. // If the user wants to skip TLS verification then we should set
  193. // the InsecureSkipVerify flag in tls configuration.
  194. if scfg.insecureSkipVerify && cfg.TLS != nil {
  195. cfg.TLS.InsecureSkipVerify = true
  196. }
  197. if acfg != nil {
  198. cfg.Username = acfg.username
  199. cfg.Password = acfg.password
  200. }
  201. return cfg, nil
  202. }
  203. func argOrStdin(args []string, stdin io.Reader, i int) (string, error) {
  204. if i < len(args) {
  205. return args[i], nil
  206. }
  207. bytes, err := ioutil.ReadAll(stdin)
  208. if string(bytes) == "" || err != nil {
  209. return "", errors.New("no available argument and stdin")
  210. }
  211. return string(bytes), nil
  212. }
  213. func dialTimeoutFromCmd(cmd *cobra.Command) time.Duration {
  214. dialTimeout, err := cmd.Flags().GetDuration("dial-timeout")
  215. if err != nil {
  216. ExitWithError(ExitError, err)
  217. }
  218. return dialTimeout
  219. }
  220. func keepAliveTimeFromCmd(cmd *cobra.Command) time.Duration {
  221. keepAliveTime, err := cmd.Flags().GetDuration("keepalive-time")
  222. if err != nil {
  223. ExitWithError(ExitError, err)
  224. }
  225. return keepAliveTime
  226. }
  227. func keepAliveTimeoutFromCmd(cmd *cobra.Command) time.Duration {
  228. keepAliveTimeout, err := cmd.Flags().GetDuration("keepalive-timeout")
  229. if err != nil {
  230. ExitWithError(ExitError, err)
  231. }
  232. return keepAliveTimeout
  233. }
  234. func secureCfgFromCmd(cmd *cobra.Command) *secureCfg {
  235. cert, key, cacert := keyAndCertFromCmd(cmd)
  236. insecureTr := insecureTransportFromCmd(cmd)
  237. skipVerify := insecureSkipVerifyFromCmd(cmd)
  238. discoveryCfg := discoveryCfgFromCmd(cmd)
  239. if discoveryCfg.insecure {
  240. discoveryCfg.domain = ""
  241. }
  242. return &secureCfg{
  243. cert: cert,
  244. key: key,
  245. cacert: cacert,
  246. serverName: discoveryCfg.domain,
  247. insecureTransport: insecureTr,
  248. insecureSkipVerify: skipVerify,
  249. }
  250. }
  251. func insecureTransportFromCmd(cmd *cobra.Command) bool {
  252. insecureTr, err := cmd.Flags().GetBool("insecure-transport")
  253. if err != nil {
  254. ExitWithError(ExitError, err)
  255. }
  256. return insecureTr
  257. }
  258. func insecureSkipVerifyFromCmd(cmd *cobra.Command) bool {
  259. skipVerify, err := cmd.Flags().GetBool("insecure-skip-tls-verify")
  260. if err != nil {
  261. ExitWithError(ExitError, err)
  262. }
  263. return skipVerify
  264. }
  265. func keyAndCertFromCmd(cmd *cobra.Command) (cert, key, cacert string) {
  266. var err error
  267. if cert, err = cmd.Flags().GetString("cert"); err != nil {
  268. ExitWithError(ExitBadArgs, err)
  269. } else if cert == "" && cmd.Flags().Changed("cert") {
  270. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --cert option"))
  271. }
  272. if key, err = cmd.Flags().GetString("key"); err != nil {
  273. ExitWithError(ExitBadArgs, err)
  274. } else if key == "" && cmd.Flags().Changed("key") {
  275. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --key option"))
  276. }
  277. if cacert, err = cmd.Flags().GetString("cacert"); err != nil {
  278. ExitWithError(ExitBadArgs, err)
  279. } else if cacert == "" && cmd.Flags().Changed("cacert") {
  280. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --cacert option"))
  281. }
  282. return cert, key, cacert
  283. }
  284. func authCfgFromCmd(cmd *cobra.Command) *authCfg {
  285. userFlag, err := cmd.Flags().GetString("user")
  286. if err != nil {
  287. ExitWithError(ExitBadArgs, err)
  288. }
  289. if userFlag == "" {
  290. return nil
  291. }
  292. var cfg authCfg
  293. splitted := strings.SplitN(userFlag, ":", 2)
  294. if len(splitted) < 2 {
  295. cfg.username = userFlag
  296. cfg.password, err = speakeasy.Ask("Password: ")
  297. if err != nil {
  298. ExitWithError(ExitError, err)
  299. }
  300. } else {
  301. cfg.username = splitted[0]
  302. cfg.password = splitted[1]
  303. }
  304. return &cfg
  305. }
  306. func insecureDiscoveryFromCmd(cmd *cobra.Command) bool {
  307. discovery, err := cmd.Flags().GetBool("insecure-discovery")
  308. if err != nil {
  309. ExitWithError(ExitError, err)
  310. }
  311. return discovery
  312. }
  313. func discoverySrvFromCmd(cmd *cobra.Command) string {
  314. domainStr, err := cmd.Flags().GetString("discovery-srv")
  315. if err != nil {
  316. ExitWithError(ExitBadArgs, err)
  317. }
  318. return domainStr
  319. }
  320. func discoveryCfgFromCmd(cmd *cobra.Command) *discoveryCfg {
  321. return &discoveryCfg{
  322. domain: discoverySrvFromCmd(cmd),
  323. insecure: insecureDiscoveryFromCmd(cmd),
  324. }
  325. }
  326. func endpointsFromCmd(cmd *cobra.Command) ([]string, error) {
  327. eps, err := endpointsFromFlagValue(cmd)
  328. if err != nil {
  329. return nil, err
  330. }
  331. // If domain discovery returns no endpoints, check endpoints flag
  332. if len(eps) == 0 {
  333. eps, err = cmd.Flags().GetStringSlice("endpoints")
  334. }
  335. return eps, err
  336. }
  337. func endpointsFromFlagValue(cmd *cobra.Command) ([]string, error) {
  338. discoveryCfg := discoveryCfgFromCmd(cmd)
  339. // If we still don't have domain discovery, return nothing
  340. if discoveryCfg.domain == "" {
  341. return []string{}, nil
  342. }
  343. srvs, err := srv.GetClient("etcd-client", discoveryCfg.domain)
  344. if err != nil {
  345. return nil, err
  346. }
  347. eps := srvs.Endpoints
  348. if discoveryCfg.insecure {
  349. return eps, err
  350. }
  351. // strip insecure connections
  352. ret := []string{}
  353. for _, ep := range eps {
  354. if strings.HasPrefix("http://", ep) {
  355. fmt.Fprintf(os.Stderr, "ignoring discovered insecure endpoint %q\n", ep)
  356. continue
  357. }
  358. ret = append(ret, ep)
  359. }
  360. return ret, err
  361. }