peering: initial sync (#12842)
- Add endpoints related to peering: read, list, generate token, initiate peering
- Update node/service/check table indexing to account for peers
- Foundational changes for pushing service updates to a peer
- Plumb peer name through Health.ServiceNodes path
see: ENT-1765, ENT-1280, ENT-1283, ENT-1283, ENT-1756, ENT-1739, ENT-1750, ENT-1679,
ENT-1709, ENT-1704, ENT-1690, ENT-1689, ENT-1702, ENT-1701, ENT-1683, ENT-1663,
ENT-1650, ENT-1678, ENT-1628, ENT-1658, ENT-1640, ENT-1637, ENT-1597, ENT-1634,
ENT-1613, ENT-1616, ENT-1617, ENT-1591, ENT-1588, ENT-1596, ENT-1572, ENT-1555
Co-authored-by: R.B. Boyer <rb@hashicorp.com>
Co-authored-by: freddygv <freddy@hashicorp.com>
Co-authored-by: Chris S. Kim <ckim@hashicorp.com>
Co-authored-by: Evan Culver <eculver@hashicorp.com>
Co-authored-by: Nitya Dhanushkodi <nitya@hashicorp.com>
2022-04-21 22:34:40 +00:00
|
|
|
package peering
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"net"
|
2022-05-19 21:37:52 +00:00
|
|
|
"net/netip"
|
peering: initial sync (#12842)
- Add endpoints related to peering: read, list, generate token, initiate peering
- Update node/service/check table indexing to account for peers
- Foundational changes for pushing service updates to a peer
- Plumb peer name through Health.ServiceNodes path
see: ENT-1765, ENT-1280, ENT-1283, ENT-1283, ENT-1756, ENT-1739, ENT-1750, ENT-1679,
ENT-1709, ENT-1704, ENT-1690, ENT-1689, ENT-1702, ENT-1701, ENT-1683, ENT-1663,
ENT-1650, ENT-1678, ENT-1628, ENT-1658, ENT-1640, ENT-1637, ENT-1597, ENT-1634,
ENT-1613, ENT-1616, ENT-1617, ENT-1591, ENT-1588, ENT-1596, ENT-1572, ENT-1555
Co-authored-by: R.B. Boyer <rb@hashicorp.com>
Co-authored-by: freddygv <freddy@hashicorp.com>
Co-authored-by: Chris S. Kim <ckim@hashicorp.com>
Co-authored-by: Evan Culver <eculver@hashicorp.com>
Co-authored-by: Nitya Dhanushkodi <nitya@hashicorp.com>
2022-04-21 22:34:40 +00:00
|
|
|
"strconv"
|
|
|
|
|
|
|
|
"github.com/hashicorp/consul/agent/connect"
|
|
|
|
"github.com/hashicorp/consul/agent/structs"
|
|
|
|
)
|
|
|
|
|
|
|
|
// validatePeeringToken ensures that the token has valid values.
|
|
|
|
func validatePeeringToken(tok *structs.PeeringToken) error {
|
|
|
|
// the CA values here should be valid x509 certs
|
|
|
|
for _, certStr := range tok.CA {
|
|
|
|
// TODO(peering): should we put these in a cert pool on the token?
|
|
|
|
// maybe there's a better place to do the parsing?
|
|
|
|
if _, err := connect.ParseCert(certStr); err != nil {
|
|
|
|
return fmt.Errorf("peering token invalid CA: %w", err)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(tok.ServerAddresses) == 0 {
|
|
|
|
return errPeeringTokenEmptyServerAddresses
|
|
|
|
}
|
|
|
|
for _, addr := range tok.ServerAddresses {
|
|
|
|
host, portRaw, err := net.SplitHostPort(addr)
|
|
|
|
if err != nil {
|
|
|
|
return &errPeeringInvalidServerAddress{addr}
|
|
|
|
}
|
|
|
|
|
|
|
|
port, err := strconv.Atoi(portRaw)
|
|
|
|
if err != nil {
|
|
|
|
return &errPeeringInvalidServerAddress{addr}
|
|
|
|
}
|
|
|
|
if port < 1 || port > 65535 {
|
|
|
|
return &errPeeringInvalidServerAddress{addr}
|
|
|
|
}
|
2022-05-19 21:37:52 +00:00
|
|
|
if _, err := netip.ParseAddr(host); err != nil {
|
peering: initial sync (#12842)
- Add endpoints related to peering: read, list, generate token, initiate peering
- Update node/service/check table indexing to account for peers
- Foundational changes for pushing service updates to a peer
- Plumb peer name through Health.ServiceNodes path
see: ENT-1765, ENT-1280, ENT-1283, ENT-1283, ENT-1756, ENT-1739, ENT-1750, ENT-1679,
ENT-1709, ENT-1704, ENT-1690, ENT-1689, ENT-1702, ENT-1701, ENT-1683, ENT-1663,
ENT-1650, ENT-1678, ENT-1628, ENT-1658, ENT-1640, ENT-1637, ENT-1597, ENT-1634,
ENT-1613, ENT-1616, ENT-1617, ENT-1591, ENT-1588, ENT-1596, ENT-1572, ENT-1555
Co-authored-by: R.B. Boyer <rb@hashicorp.com>
Co-authored-by: freddygv <freddy@hashicorp.com>
Co-authored-by: Chris S. Kim <ckim@hashicorp.com>
Co-authored-by: Evan Culver <eculver@hashicorp.com>
Co-authored-by: Nitya Dhanushkodi <nitya@hashicorp.com>
2022-04-21 22:34:40 +00:00
|
|
|
return &errPeeringInvalidServerAddress{addr}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// TODO(peering): validate name matches SNI?
|
|
|
|
// TODO(peering): validate name well formed?
|
|
|
|
if tok.ServerName == "" {
|
|
|
|
return errPeeringTokenEmptyServerName
|
|
|
|
}
|
|
|
|
|
|
|
|
if tok.PeerID == "" {
|
|
|
|
return errPeeringTokenEmptyPeerID
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|