global.go 8.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353
  1. // Copyright 2015 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package command
  15. import (
  16. "crypto/tls"
  17. "errors"
  18. "fmt"
  19. "io"
  20. "io/ioutil"
  21. "os"
  22. "strings"
  23. "time"
  24. "github.com/bgentry/speakeasy"
  25. "github.com/coreos/etcd/clientv3"
  26. "github.com/coreos/etcd/pkg/flags"
  27. "github.com/coreos/etcd/pkg/srv"
  28. "github.com/coreos/etcd/pkg/transport"
  29. "github.com/spf13/cobra"
  30. "google.golang.org/grpc/grpclog"
  31. )
  32. // GlobalFlags are flags that defined globally
  33. // and are inherited to all sub-commands.
  34. type GlobalFlags struct {
  35. Insecure bool
  36. InsecureSkipVerify bool
  37. InsecureDiscovery bool
  38. Endpoints []string
  39. DialTimeout time.Duration
  40. CommandTimeOut time.Duration
  41. TLS transport.TLSInfo
  42. OutputFormat string
  43. IsHex bool
  44. User string
  45. Debug bool
  46. }
  47. type secureCfg struct {
  48. cert string
  49. key string
  50. cacert string
  51. serverName string
  52. insecureTransport bool
  53. insecureSkipVerify bool
  54. }
  55. type authCfg struct {
  56. username string
  57. password string
  58. }
  59. type discoveryCfg struct {
  60. domain string
  61. insecure bool
  62. }
  63. var display printer = &simplePrinter{}
  64. func initDisplayFromCmd(cmd *cobra.Command) {
  65. isHex, err := cmd.Flags().GetBool("hex")
  66. if err != nil {
  67. ExitWithError(ExitError, err)
  68. }
  69. outputType, err := cmd.Flags().GetString("write-out")
  70. if err != nil {
  71. ExitWithError(ExitError, err)
  72. }
  73. if display = NewPrinter(outputType, isHex); display == nil {
  74. ExitWithError(ExitBadFeature, errors.New("unsupported output format"))
  75. }
  76. }
  77. func mustClientFromCmd(cmd *cobra.Command) *clientv3.Client {
  78. flags.SetPflagsFromEnv("ETCDCTL", cmd.InheritedFlags())
  79. debug, derr := cmd.Flags().GetBool("debug")
  80. if derr != nil {
  81. ExitWithError(ExitError, derr)
  82. }
  83. if debug {
  84. clientv3.SetLogger(grpclog.NewLoggerV2(os.Stderr, os.Stderr, os.Stderr))
  85. }
  86. endpoints, err := endpointsFromCmd(cmd)
  87. if err != nil {
  88. ExitWithError(ExitError, err)
  89. }
  90. dialTimeout := dialTimeoutFromCmd(cmd)
  91. sec := secureCfgFromCmd(cmd)
  92. auth := authCfgFromCmd(cmd)
  93. initDisplayFromCmd(cmd)
  94. return mustClient(endpoints, dialTimeout, sec, auth)
  95. }
  96. func mustClient(endpoints []string, dialTimeout time.Duration, scfg *secureCfg, acfg *authCfg) *clientv3.Client {
  97. cfg, err := newClientCfg(endpoints, dialTimeout, scfg, acfg)
  98. if err != nil {
  99. ExitWithError(ExitBadArgs, err)
  100. }
  101. client, err := clientv3.New(*cfg)
  102. if err != nil {
  103. ExitWithError(ExitBadConnection, err)
  104. }
  105. return client
  106. }
  107. func newClientCfg(endpoints []string, dialTimeout time.Duration, scfg *secureCfg, acfg *authCfg) (*clientv3.Config, error) {
  108. // set tls if any one tls option set
  109. var cfgtls *transport.TLSInfo
  110. tlsinfo := transport.TLSInfo{}
  111. if scfg.cert != "" {
  112. tlsinfo.CertFile = scfg.cert
  113. cfgtls = &tlsinfo
  114. }
  115. if scfg.key != "" {
  116. tlsinfo.KeyFile = scfg.key
  117. cfgtls = &tlsinfo
  118. }
  119. if scfg.cacert != "" {
  120. tlsinfo.CAFile = scfg.cacert
  121. cfgtls = &tlsinfo
  122. }
  123. if scfg.serverName != "" {
  124. tlsinfo.ServerName = scfg.serverName
  125. cfgtls = &tlsinfo
  126. }
  127. cfg := &clientv3.Config{
  128. Endpoints: endpoints,
  129. DialTimeout: dialTimeout,
  130. }
  131. if cfgtls != nil {
  132. clientTLS, err := cfgtls.ClientConfig()
  133. if err != nil {
  134. return nil, err
  135. }
  136. cfg.TLS = clientTLS
  137. }
  138. // if key/cert is not given but user wants secure connection, we
  139. // should still setup an empty tls configuration for gRPC to setup
  140. // secure connection.
  141. if cfg.TLS == nil && !scfg.insecureTransport {
  142. cfg.TLS = &tls.Config{}
  143. }
  144. // If the user wants to skip TLS verification then we should set
  145. // the InsecureSkipVerify flag in tls configuration.
  146. if scfg.insecureSkipVerify && cfg.TLS != nil {
  147. cfg.TLS.InsecureSkipVerify = true
  148. }
  149. if acfg != nil {
  150. cfg.Username = acfg.username
  151. cfg.Password = acfg.password
  152. }
  153. return cfg, nil
  154. }
  155. func argOrStdin(args []string, stdin io.Reader, i int) (string, error) {
  156. if i < len(args) {
  157. return args[i], nil
  158. }
  159. bytes, err := ioutil.ReadAll(stdin)
  160. if string(bytes) == "" || err != nil {
  161. return "", errors.New("no available argument and stdin")
  162. }
  163. return string(bytes), nil
  164. }
  165. func dialTimeoutFromCmd(cmd *cobra.Command) time.Duration {
  166. dialTimeout, err := cmd.Flags().GetDuration("dial-timeout")
  167. if err != nil {
  168. ExitWithError(ExitError, err)
  169. }
  170. return dialTimeout
  171. }
  172. func secureCfgFromCmd(cmd *cobra.Command) *secureCfg {
  173. cert, key, cacert := keyAndCertFromCmd(cmd)
  174. insecureTr := insecureTransportFromCmd(cmd)
  175. skipVerify := insecureSkipVerifyFromCmd(cmd)
  176. discoveryCfg := discoveryCfgFromCmd(cmd)
  177. if discoveryCfg.insecure {
  178. discoveryCfg.domain = ""
  179. }
  180. return &secureCfg{
  181. cert: cert,
  182. key: key,
  183. cacert: cacert,
  184. serverName: discoveryCfg.domain,
  185. insecureTransport: insecureTr,
  186. insecureSkipVerify: skipVerify,
  187. }
  188. }
  189. func insecureTransportFromCmd(cmd *cobra.Command) bool {
  190. insecureTr, err := cmd.Flags().GetBool("insecure-transport")
  191. if err != nil {
  192. ExitWithError(ExitError, err)
  193. }
  194. return insecureTr
  195. }
  196. func insecureSkipVerifyFromCmd(cmd *cobra.Command) bool {
  197. skipVerify, err := cmd.Flags().GetBool("insecure-skip-tls-verify")
  198. if err != nil {
  199. ExitWithError(ExitError, err)
  200. }
  201. return skipVerify
  202. }
  203. func keyAndCertFromCmd(cmd *cobra.Command) (cert, key, cacert string) {
  204. var err error
  205. if cert, err = cmd.Flags().GetString("cert"); err != nil {
  206. ExitWithError(ExitBadArgs, err)
  207. } else if cert == "" && cmd.Flags().Changed("cert") {
  208. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --cert option"))
  209. }
  210. if key, err = cmd.Flags().GetString("key"); err != nil {
  211. ExitWithError(ExitBadArgs, err)
  212. } else if key == "" && cmd.Flags().Changed("key") {
  213. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --key option"))
  214. }
  215. if cacert, err = cmd.Flags().GetString("cacert"); err != nil {
  216. ExitWithError(ExitBadArgs, err)
  217. } else if cacert == "" && cmd.Flags().Changed("cacert") {
  218. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --cacert option"))
  219. }
  220. return cert, key, cacert
  221. }
  222. func authCfgFromCmd(cmd *cobra.Command) *authCfg {
  223. userFlag, err := cmd.Flags().GetString("user")
  224. if err != nil {
  225. ExitWithError(ExitBadArgs, err)
  226. }
  227. if userFlag == "" {
  228. return nil
  229. }
  230. var cfg authCfg
  231. splitted := strings.SplitN(userFlag, ":", 2)
  232. if len(splitted) < 2 {
  233. cfg.username = userFlag
  234. cfg.password, err = speakeasy.Ask("Password: ")
  235. if err != nil {
  236. ExitWithError(ExitError, err)
  237. }
  238. } else {
  239. cfg.username = splitted[0]
  240. cfg.password = splitted[1]
  241. }
  242. return &cfg
  243. }
  244. func insecureDiscoveryFromCmd(cmd *cobra.Command) bool {
  245. discovery, err := cmd.Flags().GetBool("insecure-discovery")
  246. if err != nil {
  247. ExitWithError(ExitError, err)
  248. }
  249. return discovery
  250. }
  251. func discoverySrvFromCmd(cmd *cobra.Command) string {
  252. domainStr, err := cmd.Flags().GetString("discovery-srv")
  253. if err != nil {
  254. ExitWithError(ExitBadArgs, err)
  255. }
  256. return domainStr
  257. }
  258. func discoveryCfgFromCmd(cmd *cobra.Command) *discoveryCfg {
  259. return &discoveryCfg{
  260. domain: discoverySrvFromCmd(cmd),
  261. insecure: insecureDiscoveryFromCmd(cmd),
  262. }
  263. }
  264. func endpointsFromCmd(cmd *cobra.Command) ([]string, error) {
  265. eps, err := endpointsFromFlagValue(cmd)
  266. if err != nil {
  267. return nil, err
  268. }
  269. // If domain discovery returns no endpoints, check endpoints flag
  270. if len(eps) == 0 {
  271. eps, err = cmd.Flags().GetStringSlice("endpoints")
  272. }
  273. return eps, err
  274. }
  275. func endpointsFromFlagValue(cmd *cobra.Command) ([]string, error) {
  276. discoveryCfg := discoveryCfgFromCmd(cmd)
  277. // If we still don't have domain discovery, return nothing
  278. if discoveryCfg.domain == "" {
  279. return []string{}, nil
  280. }
  281. srvs, err := srv.GetClient("etcd-client", discoveryCfg.domain)
  282. if err != nil {
  283. return nil, err
  284. }
  285. eps := srvs.Endpoints
  286. if discoveryCfg.insecure {
  287. return eps, err
  288. }
  289. // strip insecure connections
  290. ret := []string{}
  291. for _, ep := range eps {
  292. if strings.HasPrefix("http://", ep) {
  293. fmt.Fprintf(os.Stderr, "ignoring discovered insecure endpoint %q\n", ep)
  294. continue
  295. }
  296. ret = append(ret, ep)
  297. }
  298. return ret, err
  299. }