global.go 9.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400
  1. // Copyright 2015 The etcd Authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. package command
  15. import (
  16. "crypto/tls"
  17. "errors"
  18. "fmt"
  19. "io"
  20. "io/ioutil"
  21. "os"
  22. "strings"
  23. "time"
  24. "github.com/bgentry/speakeasy"
  25. "github.com/coreos/etcd/clientv3"
  26. "github.com/coreos/etcd/pkg/flags"
  27. "github.com/coreos/etcd/pkg/srv"
  28. "github.com/coreos/etcd/pkg/transport"
  29. "github.com/spf13/cobra"
  30. "github.com/spf13/pflag"
  31. "google.golang.org/grpc/grpclog"
  32. )
  33. // GlobalFlags are flags that defined globally
  34. // and are inherited to all sub-commands.
  35. type GlobalFlags struct {
  36. Insecure bool
  37. InsecureSkipVerify bool
  38. InsecureDiscovery bool
  39. Endpoints []string
  40. DialTimeout time.Duration
  41. CommandTimeOut time.Duration
  42. KeepAliveTime time.Duration
  43. KeepAliveTimeout time.Duration
  44. TLS transport.TLSInfo
  45. OutputFormat string
  46. IsHex bool
  47. User string
  48. Debug bool
  49. }
  50. type secureCfg struct {
  51. cert string
  52. key string
  53. cacert string
  54. serverName string
  55. insecureTransport bool
  56. insecureSkipVerify bool
  57. }
  58. type authCfg struct {
  59. username string
  60. password string
  61. }
  62. type discoveryCfg struct {
  63. domain string
  64. insecure bool
  65. }
  66. var display printer = &simplePrinter{}
  67. func initDisplayFromCmd(cmd *cobra.Command) {
  68. isHex, err := cmd.Flags().GetBool("hex")
  69. if err != nil {
  70. ExitWithError(ExitError, err)
  71. }
  72. outputType, err := cmd.Flags().GetString("write-out")
  73. if err != nil {
  74. ExitWithError(ExitError, err)
  75. }
  76. if display = NewPrinter(outputType, isHex); display == nil {
  77. ExitWithError(ExitBadFeature, errors.New("unsupported output format"))
  78. }
  79. }
  80. type clientConfig struct {
  81. endpoints []string
  82. dialTimeout time.Duration
  83. keepAliveTime time.Duration
  84. keepAliveTimeout time.Duration
  85. scfg *secureCfg
  86. acfg *authCfg
  87. }
  88. func clientConfigFromCmd(cmd *cobra.Command) *clientConfig {
  89. fs := cmd.InheritedFlags()
  90. flags.SetPflagsFromEnv("ETCDCTL", fs)
  91. debug, err := cmd.Flags().GetBool("debug")
  92. if err != nil {
  93. ExitWithError(ExitError, err)
  94. }
  95. if debug {
  96. clientv3.SetLogger(grpclog.NewLoggerV2WithVerbosity(os.Stderr, os.Stderr, os.Stderr, 4))
  97. fs.VisitAll(func(f *pflag.Flag) {
  98. fmt.Fprintf(os.Stderr, "%s=%v\n", flags.FlagToEnv("ETCDCTL", f.Name), f.Value)
  99. })
  100. } else {
  101. clientv3.SetLogger(grpclog.NewLoggerV2(ioutil.Discard, ioutil.Discard, ioutil.Discard))
  102. }
  103. cfg := &clientConfig{}
  104. cfg.endpoints, err = endpointsFromCmd(cmd)
  105. if err != nil {
  106. ExitWithError(ExitError, err)
  107. }
  108. cfg.dialTimeout = dialTimeoutFromCmd(cmd)
  109. cfg.keepAliveTime = keepAliveTimeFromCmd(cmd)
  110. cfg.keepAliveTimeout = keepAliveTimeoutFromCmd(cmd)
  111. cfg.scfg = secureCfgFromCmd(cmd)
  112. cfg.acfg = authCfgFromCmd(cmd)
  113. initDisplayFromCmd(cmd)
  114. return cfg
  115. }
  116. func mustClientFromCmd(cmd *cobra.Command) *clientv3.Client {
  117. cfg := clientConfigFromCmd(cmd)
  118. return cfg.mustClient()
  119. }
  120. func (cc *clientConfig) mustClient() *clientv3.Client {
  121. cfg, err := newClientCfg(cc.endpoints, cc.dialTimeout, cc.keepAliveTime, cc.keepAliveTimeout, cc.scfg, cc.acfg)
  122. if err != nil {
  123. ExitWithError(ExitBadArgs, err)
  124. }
  125. client, err := clientv3.New(*cfg)
  126. if err != nil {
  127. ExitWithError(ExitBadConnection, err)
  128. }
  129. return client
  130. }
  131. func newClientCfg(endpoints []string, dialTimeout, keepAliveTime, keepAliveTimeout time.Duration, scfg *secureCfg, acfg *authCfg) (*clientv3.Config, error) {
  132. // set tls if any one tls option set
  133. var cfgtls *transport.TLSInfo
  134. tlsinfo := transport.TLSInfo{}
  135. if scfg.cert != "" {
  136. tlsinfo.CertFile = scfg.cert
  137. cfgtls = &tlsinfo
  138. }
  139. if scfg.key != "" {
  140. tlsinfo.KeyFile = scfg.key
  141. cfgtls = &tlsinfo
  142. }
  143. if scfg.cacert != "" {
  144. tlsinfo.CAFile = scfg.cacert
  145. cfgtls = &tlsinfo
  146. }
  147. if scfg.serverName != "" {
  148. tlsinfo.ServerName = scfg.serverName
  149. cfgtls = &tlsinfo
  150. }
  151. cfg := &clientv3.Config{
  152. Endpoints: endpoints,
  153. DialTimeout: dialTimeout,
  154. DialKeepAliveTime: keepAliveTime,
  155. DialKeepAliveTimeout: keepAliveTimeout,
  156. }
  157. if cfgtls != nil {
  158. clientTLS, err := cfgtls.ClientConfig()
  159. if err != nil {
  160. return nil, err
  161. }
  162. cfg.TLS = clientTLS
  163. }
  164. // if key/cert is not given but user wants secure connection, we
  165. // should still setup an empty tls configuration for gRPC to setup
  166. // secure connection.
  167. if cfg.TLS == nil && !scfg.insecureTransport {
  168. cfg.TLS = &tls.Config{}
  169. }
  170. // If the user wants to skip TLS verification then we should set
  171. // the InsecureSkipVerify flag in tls configuration.
  172. if scfg.insecureSkipVerify && cfg.TLS != nil {
  173. cfg.TLS.InsecureSkipVerify = true
  174. }
  175. if acfg != nil {
  176. cfg.Username = acfg.username
  177. cfg.Password = acfg.password
  178. }
  179. return cfg, nil
  180. }
  181. func argOrStdin(args []string, stdin io.Reader, i int) (string, error) {
  182. if i < len(args) {
  183. return args[i], nil
  184. }
  185. bytes, err := ioutil.ReadAll(stdin)
  186. if string(bytes) == "" || err != nil {
  187. return "", errors.New("no available argument and stdin")
  188. }
  189. return string(bytes), nil
  190. }
  191. func dialTimeoutFromCmd(cmd *cobra.Command) time.Duration {
  192. dialTimeout, err := cmd.Flags().GetDuration("dial-timeout")
  193. if err != nil {
  194. ExitWithError(ExitError, err)
  195. }
  196. return dialTimeout
  197. }
  198. func keepAliveTimeFromCmd(cmd *cobra.Command) time.Duration {
  199. keepAliveTime, err := cmd.Flags().GetDuration("keepalive-time")
  200. if err != nil {
  201. ExitWithError(ExitError, err)
  202. }
  203. return keepAliveTime
  204. }
  205. func keepAliveTimeoutFromCmd(cmd *cobra.Command) time.Duration {
  206. keepAliveTimeout, err := cmd.Flags().GetDuration("keepalive-timeout")
  207. if err != nil {
  208. ExitWithError(ExitError, err)
  209. }
  210. return keepAliveTimeout
  211. }
  212. func secureCfgFromCmd(cmd *cobra.Command) *secureCfg {
  213. cert, key, cacert := keyAndCertFromCmd(cmd)
  214. insecureTr := insecureTransportFromCmd(cmd)
  215. skipVerify := insecureSkipVerifyFromCmd(cmd)
  216. discoveryCfg := discoveryCfgFromCmd(cmd)
  217. if discoveryCfg.insecure {
  218. discoveryCfg.domain = ""
  219. }
  220. return &secureCfg{
  221. cert: cert,
  222. key: key,
  223. cacert: cacert,
  224. serverName: discoveryCfg.domain,
  225. insecureTransport: insecureTr,
  226. insecureSkipVerify: skipVerify,
  227. }
  228. }
  229. func insecureTransportFromCmd(cmd *cobra.Command) bool {
  230. insecureTr, err := cmd.Flags().GetBool("insecure-transport")
  231. if err != nil {
  232. ExitWithError(ExitError, err)
  233. }
  234. return insecureTr
  235. }
  236. func insecureSkipVerifyFromCmd(cmd *cobra.Command) bool {
  237. skipVerify, err := cmd.Flags().GetBool("insecure-skip-tls-verify")
  238. if err != nil {
  239. ExitWithError(ExitError, err)
  240. }
  241. return skipVerify
  242. }
  243. func keyAndCertFromCmd(cmd *cobra.Command) (cert, key, cacert string) {
  244. var err error
  245. if cert, err = cmd.Flags().GetString("cert"); err != nil {
  246. ExitWithError(ExitBadArgs, err)
  247. } else if cert == "" && cmd.Flags().Changed("cert") {
  248. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --cert option"))
  249. }
  250. if key, err = cmd.Flags().GetString("key"); err != nil {
  251. ExitWithError(ExitBadArgs, err)
  252. } else if key == "" && cmd.Flags().Changed("key") {
  253. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --key option"))
  254. }
  255. if cacert, err = cmd.Flags().GetString("cacert"); err != nil {
  256. ExitWithError(ExitBadArgs, err)
  257. } else if cacert == "" && cmd.Flags().Changed("cacert") {
  258. ExitWithError(ExitBadArgs, errors.New("empty string is passed to --cacert option"))
  259. }
  260. return cert, key, cacert
  261. }
  262. func authCfgFromCmd(cmd *cobra.Command) *authCfg {
  263. userFlag, err := cmd.Flags().GetString("user")
  264. if err != nil {
  265. ExitWithError(ExitBadArgs, err)
  266. }
  267. if userFlag == "" {
  268. return nil
  269. }
  270. var cfg authCfg
  271. splitted := strings.SplitN(userFlag, ":", 2)
  272. if len(splitted) < 2 {
  273. cfg.username = userFlag
  274. cfg.password, err = speakeasy.Ask("Password: ")
  275. if err != nil {
  276. ExitWithError(ExitError, err)
  277. }
  278. } else {
  279. cfg.username = splitted[0]
  280. cfg.password = splitted[1]
  281. }
  282. return &cfg
  283. }
  284. func insecureDiscoveryFromCmd(cmd *cobra.Command) bool {
  285. discovery, err := cmd.Flags().GetBool("insecure-discovery")
  286. if err != nil {
  287. ExitWithError(ExitError, err)
  288. }
  289. return discovery
  290. }
  291. func discoverySrvFromCmd(cmd *cobra.Command) string {
  292. domainStr, err := cmd.Flags().GetString("discovery-srv")
  293. if err != nil {
  294. ExitWithError(ExitBadArgs, err)
  295. }
  296. return domainStr
  297. }
  298. func discoveryCfgFromCmd(cmd *cobra.Command) *discoveryCfg {
  299. return &discoveryCfg{
  300. domain: discoverySrvFromCmd(cmd),
  301. insecure: insecureDiscoveryFromCmd(cmd),
  302. }
  303. }
  304. func endpointsFromCmd(cmd *cobra.Command) ([]string, error) {
  305. eps, err := endpointsFromFlagValue(cmd)
  306. if err != nil {
  307. return nil, err
  308. }
  309. // If domain discovery returns no endpoints, check endpoints flag
  310. if len(eps) == 0 {
  311. eps, err = cmd.Flags().GetStringSlice("endpoints")
  312. }
  313. return eps, err
  314. }
  315. func endpointsFromFlagValue(cmd *cobra.Command) ([]string, error) {
  316. discoveryCfg := discoveryCfgFromCmd(cmd)
  317. // If we still don't have domain discovery, return nothing
  318. if discoveryCfg.domain == "" {
  319. return []string{}, nil
  320. }
  321. srvs, err := srv.GetClient("etcd-client", discoveryCfg.domain)
  322. if err != nil {
  323. return nil, err
  324. }
  325. eps := srvs.Endpoints
  326. if discoveryCfg.insecure {
  327. return eps, err
  328. }
  329. // strip insecure connections
  330. ret := []string{}
  331. for _, ep := range eps {
  332. if strings.HasPrefix("http://", ep) {
  333. fmt.Fprintf(os.Stderr, "ignoring discovered insecure endpoint %q\n", ep)
  334. continue
  335. }
  336. ret = append(ret, ep)
  337. }
  338. return ret, err
  339. }