2019-10-16 20:53:39 +00:00
|
|
|
package nomad
|
|
|
|
|
|
|
|
import (
|
2020-02-13 15:18:55 +00:00
|
|
|
"fmt"
|
|
|
|
"math/rand"
|
2019-10-16 20:53:39 +00:00
|
|
|
"time"
|
|
|
|
|
|
|
|
metrics "github.com/armon/go-metrics"
|
|
|
|
log "github.com/hashicorp/go-hclog"
|
|
|
|
memdb "github.com/hashicorp/go-memdb"
|
|
|
|
multierror "github.com/hashicorp/go-multierror"
|
|
|
|
"github.com/hashicorp/nomad/acl"
|
2020-02-13 15:18:55 +00:00
|
|
|
cstructs "github.com/hashicorp/nomad/client/structs"
|
2019-10-16 20:53:39 +00:00
|
|
|
"github.com/hashicorp/nomad/nomad/state"
|
|
|
|
"github.com/hashicorp/nomad/nomad/structs"
|
|
|
|
)
|
|
|
|
|
|
|
|
// CSIVolume wraps the structs.CSIVolume with request data and server context
|
|
|
|
type CSIVolume struct {
|
|
|
|
srv *Server
|
|
|
|
logger log.Logger
|
|
|
|
}
|
|
|
|
|
|
|
|
// QueryACLObj looks up the ACL token in the request and returns the acl.ACL object
|
|
|
|
// - fallback to node secret ids
|
2020-02-11 11:41:18 +00:00
|
|
|
func (srv *Server) QueryACLObj(args *structs.QueryOptions, allowNodeAccess bool) (*acl.ACL, error) {
|
2019-10-16 20:53:39 +00:00
|
|
|
// Lookup the token
|
|
|
|
aclObj, err := srv.ResolveToken(args.AuthToken)
|
|
|
|
if err != nil {
|
|
|
|
// If ResolveToken had an unexpected error return that
|
2020-02-11 11:41:18 +00:00
|
|
|
if !structs.IsErrTokenNotFound(err) {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
// If we don't allow access to this endpoint from Nodes, then return token
|
|
|
|
// not found.
|
|
|
|
if !allowNodeAccess {
|
|
|
|
return nil, structs.ErrTokenNotFound
|
|
|
|
}
|
2019-10-16 20:53:39 +00:00
|
|
|
|
|
|
|
ws := memdb.NewWatchSet()
|
2020-02-11 11:41:18 +00:00
|
|
|
// Attempt to lookup AuthToken as a Node.SecretID since nodes may call
|
|
|
|
// call this endpoint and don't have an ACL token.
|
2019-10-16 20:53:39 +00:00
|
|
|
node, stateErr := srv.fsm.State().NodeBySecretID(ws, args.AuthToken)
|
|
|
|
if stateErr != nil {
|
|
|
|
// Return the original ResolveToken error with this err
|
|
|
|
var merr multierror.Error
|
|
|
|
merr.Errors = append(merr.Errors, err, stateErr)
|
|
|
|
return nil, merr.ErrorOrNil()
|
|
|
|
}
|
|
|
|
|
2020-02-11 11:41:18 +00:00
|
|
|
// We did not find a Node for this ID, so return Token Not Found.
|
2019-10-16 20:53:39 +00:00
|
|
|
if node == nil {
|
|
|
|
return nil, structs.ErrTokenNotFound
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-11 11:41:18 +00:00
|
|
|
// Return either the users aclObj, or nil if ACLs are disabled.
|
2019-10-16 20:53:39 +00:00
|
|
|
return aclObj, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// WriteACLObj calls QueryACLObj for a WriteRequest
|
2020-02-11 11:41:18 +00:00
|
|
|
func (srv *Server) WriteACLObj(args *structs.WriteRequest, allowNodeAccess bool) (*acl.ACL, error) {
|
2019-10-16 20:53:39 +00:00
|
|
|
opts := &structs.QueryOptions{
|
|
|
|
Region: args.RequestRegion(),
|
|
|
|
Namespace: args.RequestNamespace(),
|
|
|
|
AuthToken: args.AuthToken,
|
|
|
|
}
|
2020-02-11 11:41:18 +00:00
|
|
|
return srv.QueryACLObj(opts, allowNodeAccess)
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
|
|
|
|
2020-01-28 15:28:34 +00:00
|
|
|
const (
|
|
|
|
csiVolumeTable = "csi_volumes"
|
|
|
|
csiPluginTable = "csi_plugins"
|
|
|
|
)
|
|
|
|
|
|
|
|
// replySetIndex sets the reply with the last index that modified the table
|
|
|
|
func (srv *Server) replySetIndex(table string, reply *structs.QueryMeta) error {
|
|
|
|
s := srv.fsm.State()
|
|
|
|
|
|
|
|
index, err := s.Index(table)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
reply.Index = index
|
|
|
|
|
|
|
|
// Set the query response
|
|
|
|
srv.setQueryMeta(reply)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// List replies with CSIVolumes, filtered by ACL access
|
|
|
|
func (v *CSIVolume) List(args *structs.CSIVolumeListRequest, reply *structs.CSIVolumeListResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIVolume.List", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
allowVolume := acl.NamespaceValidator(acl.NamespaceCapabilityCSIListVolume,
|
|
|
|
acl.NamespaceCapabilityCSIReadVolume,
|
|
|
|
acl.NamespaceCapabilityCSIMountVolume,
|
|
|
|
acl.NamespaceCapabilityListJobs)
|
2020-02-11 11:41:18 +00:00
|
|
|
aclObj, err := v.srv.QueryACLObj(&args.QueryOptions, false)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
if !allowVolume(aclObj, args.RequestNamespace()) {
|
2020-03-17 15:35:34 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
2019-10-16 20:53:39 +00:00
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "volume", "list"}, metricsStart)
|
|
|
|
|
|
|
|
ns := args.RequestNamespace()
|
|
|
|
opts := blockingOptions{
|
|
|
|
queryOpts: &args.QueryOptions,
|
|
|
|
queryMeta: &reply.QueryMeta,
|
|
|
|
run: func(ws memdb.WatchSet, state *state.StateStore) error {
|
|
|
|
// Query all volumes
|
|
|
|
var err error
|
|
|
|
var iter memdb.ResultIterator
|
|
|
|
|
2020-03-11 16:47:14 +00:00
|
|
|
if args.NodeID != "" {
|
2020-03-17 15:35:34 +00:00
|
|
|
iter, err = state.CSIVolumesByNodeID(ws, ns, args.NodeID)
|
2020-03-11 16:47:14 +00:00
|
|
|
} else if args.PluginID != "" {
|
2020-03-17 15:35:34 +00:00
|
|
|
iter, err = state.CSIVolumesByPluginID(ws, ns, args.PluginID)
|
2019-10-16 20:53:39 +00:00
|
|
|
} else {
|
2020-03-17 15:35:34 +00:00
|
|
|
iter, err = state.CSIVolumesByNamespace(ws, ns)
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Collect results, filter by ACL access
|
|
|
|
var vs []*structs.CSIVolListStub
|
|
|
|
|
|
|
|
for {
|
|
|
|
raw := iter.Next()
|
|
|
|
if raw == nil {
|
|
|
|
break
|
|
|
|
}
|
2020-01-28 15:28:34 +00:00
|
|
|
|
2019-10-16 20:53:39 +00:00
|
|
|
vol := raw.(*structs.CSIVolume)
|
2020-03-09 20:58:12 +00:00
|
|
|
vol, err := state.CSIVolumeDenormalizePlugins(ws, vol.Copy())
|
2020-01-28 15:28:34 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2019-10-16 20:53:39 +00:00
|
|
|
|
2020-03-11 16:47:14 +00:00
|
|
|
// Filter (possibly again) on PluginID to handle passing both NodeID and PluginID
|
|
|
|
if args.PluginID != "" && args.PluginID != vol.PluginID {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2020-03-17 15:35:34 +00:00
|
|
|
vs = append(vs, vol.Stub())
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
|
|
|
reply.Volumes = vs
|
2020-01-28 15:28:34 +00:00
|
|
|
return v.srv.replySetIndex(csiVolumeTable, &reply.QueryMeta)
|
2019-10-16 20:53:39 +00:00
|
|
|
}}
|
|
|
|
return v.srv.blockingRPC(&opts)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get fetches detailed information about a specific volume
|
|
|
|
func (v *CSIVolume) Get(args *structs.CSIVolumeGetRequest, reply *structs.CSIVolumeGetResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIVolume.Get", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
allowCSIAccess := acl.NamespaceValidator(acl.NamespaceCapabilityCSIReadVolume,
|
|
|
|
acl.NamespaceCapabilityCSIMountVolume,
|
|
|
|
acl.NamespaceCapabilityReadJob)
|
2020-02-11 11:41:18 +00:00
|
|
|
aclObj, err := v.srv.QueryACLObj(&args.QueryOptions, true)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 15:35:34 +00:00
|
|
|
ns := args.RequestNamespace()
|
|
|
|
if !allowCSIAccess(aclObj, ns) {
|
2019-10-16 20:53:39 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "volume", "get"}, metricsStart)
|
|
|
|
|
|
|
|
opts := blockingOptions{
|
|
|
|
queryOpts: &args.QueryOptions,
|
|
|
|
queryMeta: &reply.QueryMeta,
|
|
|
|
run: func(ws memdb.WatchSet, state *state.StateStore) error {
|
2020-03-17 15:35:34 +00:00
|
|
|
vol, err := state.CSIVolumeByID(ws, ns, args.ID)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2020-01-28 15:28:34 +00:00
|
|
|
if vol != nil {
|
|
|
|
vol, err = state.CSIVolumeDenormalize(ws, vol)
|
|
|
|
}
|
|
|
|
if err != nil {
|
|
|
|
return err
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
reply.Volume = vol
|
2020-01-28 15:28:34 +00:00
|
|
|
return v.srv.replySetIndex(csiVolumeTable, &reply.QueryMeta)
|
2019-10-16 20:53:39 +00:00
|
|
|
}}
|
|
|
|
return v.srv.blockingRPC(&opts)
|
|
|
|
}
|
|
|
|
|
2020-03-09 13:57:59 +00:00
|
|
|
func (srv *Server) pluginValidateVolume(req *structs.CSIVolumeRegisterRequest, vol *structs.CSIVolume) (*structs.CSIPlugin, error) {
|
2020-02-18 16:08:44 +00:00
|
|
|
state := srv.fsm.State()
|
|
|
|
ws := memdb.NewWatchSet()
|
|
|
|
|
|
|
|
plugin, err := state.CSIPluginByID(ws, vol.PluginID)
|
|
|
|
if err != nil {
|
2020-03-09 13:57:59 +00:00
|
|
|
return nil, err
|
2020-02-18 16:08:44 +00:00
|
|
|
}
|
|
|
|
if plugin == nil {
|
2020-03-09 13:57:59 +00:00
|
|
|
return nil, fmt.Errorf("no CSI plugin named: %s could be found", vol.PluginID)
|
2020-02-18 16:08:44 +00:00
|
|
|
}
|
|
|
|
|
2020-03-09 13:57:59 +00:00
|
|
|
vol.Provider = plugin.Provider
|
|
|
|
vol.ProviderVersion = plugin.Version
|
|
|
|
return plugin, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
func (srv *Server) controllerValidateVolume(req *structs.CSIVolumeRegisterRequest, vol *structs.CSIVolume, plugin *structs.CSIPlugin) error {
|
|
|
|
|
2020-02-18 16:08:44 +00:00
|
|
|
if !plugin.ControllerRequired {
|
|
|
|
// The plugin does not require a controller, so for now we won't do any
|
|
|
|
// further validation of the volume.
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// The plugin requires a controller. Now we do some validation of the Volume
|
|
|
|
// to ensure that the registered capabilities are valid and that the volume
|
|
|
|
// exists.
|
2020-02-21 10:32:10 +00:00
|
|
|
|
|
|
|
// plugin IDs are not scoped to region/DC but volumes are.
|
|
|
|
// so any node we get for a controller is already in the same region/DC
|
|
|
|
// for the volume.
|
|
|
|
nodeID, err := srv.nodeForControllerPlugin(plugin)
|
|
|
|
if err != nil || nodeID == "" {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
method := "ClientCSIController.ValidateVolume"
|
2020-02-18 16:08:44 +00:00
|
|
|
cReq := &cstructs.ClientCSIControllerValidateVolumeRequest{
|
2020-03-12 19:08:19 +00:00
|
|
|
VolumeID: vol.RemoteID(),
|
2020-02-18 16:08:44 +00:00
|
|
|
AttachmentMode: vol.AttachmentMode,
|
|
|
|
AccessMode: vol.AccessMode,
|
|
|
|
}
|
2020-02-21 10:32:10 +00:00
|
|
|
cReq.PluginID = plugin.ID
|
|
|
|
cReq.ControllerNodeID = nodeID
|
2020-02-18 16:08:44 +00:00
|
|
|
cResp := &cstructs.ClientCSIControllerValidateVolumeResponse{}
|
|
|
|
|
2020-02-21 10:32:10 +00:00
|
|
|
return srv.RPC(method, cReq, cResp)
|
2020-02-18 16:08:44 +00:00
|
|
|
}
|
|
|
|
|
2019-10-16 20:53:39 +00:00
|
|
|
// Register registers a new volume
|
|
|
|
func (v *CSIVolume) Register(args *structs.CSIVolumeRegisterRequest, reply *structs.CSIVolumeRegisterResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIVolume.Register", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
allowVolume := acl.NamespaceValidator(acl.NamespaceCapabilityCSIWriteVolume)
|
2020-02-11 11:41:18 +00:00
|
|
|
aclObj, err := v.srv.WriteACLObj(&args.WriteRequest, false)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "volume", "register"}, metricsStart)
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
if !allowVolume(aclObj, args.RequestNamespace()) || !aclObj.AllowPluginRead() {
|
2019-10-16 20:53:39 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
2020-02-18 16:08:44 +00:00
|
|
|
// This is the only namespace we ACL checked, force all the volumes to use it.
|
|
|
|
// We also validate that the plugin exists for each plugin, and validate the
|
|
|
|
// capabilities when the plugin has a controller.
|
2020-02-03 20:40:28 +00:00
|
|
|
for _, vol := range args.Volumes {
|
|
|
|
vol.Namespace = args.RequestNamespace()
|
|
|
|
if err = vol.Validate(); err != nil {
|
2019-10-16 20:53:39 +00:00
|
|
|
return err
|
|
|
|
}
|
2020-03-17 21:32:39 +00:00
|
|
|
|
2020-03-09 13:57:59 +00:00
|
|
|
plugin, err := v.srv.pluginValidateVolume(args, vol)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if err := v.srv.controllerValidateVolume(args, vol, plugin); err != nil {
|
2020-02-18 16:08:44 +00:00
|
|
|
return err
|
|
|
|
}
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
|
|
|
|
2020-02-04 13:00:00 +00:00
|
|
|
resp, index, err := v.srv.raftApply(structs.CSIVolumeRegisterRequestType, args)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
2020-02-03 20:40:28 +00:00
|
|
|
v.logger.Error("csi raft apply failed", "error", err, "method", "register")
|
2019-10-16 20:53:39 +00:00
|
|
|
return err
|
|
|
|
}
|
2020-02-04 13:00:00 +00:00
|
|
|
if respErr, ok := resp.(error); ok {
|
|
|
|
return respErr
|
|
|
|
}
|
2019-10-16 20:53:39 +00:00
|
|
|
|
2020-02-03 20:40:28 +00:00
|
|
|
reply.Index = index
|
|
|
|
v.srv.setQueryMeta(&reply.QueryMeta)
|
|
|
|
return nil
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// Deregister removes a set of volumes
|
|
|
|
func (v *CSIVolume) Deregister(args *structs.CSIVolumeDeregisterRequest, reply *structs.CSIVolumeDeregisterResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIVolume.Deregister", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
allowVolume := acl.NamespaceValidator(acl.NamespaceCapabilityCSIWriteVolume)
|
2020-02-11 11:41:18 +00:00
|
|
|
aclObj, err := v.srv.WriteACLObj(&args.WriteRequest, false)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "volume", "deregister"}, metricsStart)
|
|
|
|
|
|
|
|
ns := args.RequestNamespace()
|
2020-03-17 21:32:39 +00:00
|
|
|
if !allowVolume(aclObj, ns) {
|
2019-10-16 20:53:39 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
2020-02-04 13:00:00 +00:00
|
|
|
resp, index, err := v.srv.raftApply(structs.CSIVolumeDeregisterRequestType, args)
|
2019-10-16 20:53:39 +00:00
|
|
|
if err != nil {
|
2020-02-03 20:40:28 +00:00
|
|
|
v.logger.Error("csi raft apply failed", "error", err, "method", "deregister")
|
2019-10-16 20:53:39 +00:00
|
|
|
return err
|
|
|
|
}
|
2020-02-04 13:00:00 +00:00
|
|
|
if respErr, ok := resp.(error); ok {
|
|
|
|
return respErr
|
|
|
|
}
|
|
|
|
|
|
|
|
reply.Index = index
|
|
|
|
v.srv.setQueryMeta(&reply.QueryMeta)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-03-16 19:59:42 +00:00
|
|
|
// Claim submits a change to a volume claim
|
2020-02-04 13:00:00 +00:00
|
|
|
func (v *CSIVolume) Claim(args *structs.CSIVolumeClaimRequest, reply *structs.CSIVolumeClaimResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIVolume.Claim", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
allowVolume := acl.NamespaceValidator(acl.NamespaceCapabilityCSIMountVolume)
|
2020-02-11 11:41:18 +00:00
|
|
|
aclObj, err := v.srv.WriteACLObj(&args.WriteRequest, true)
|
2020-02-04 13:00:00 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "volume", "claim"}, metricsStart)
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
if !allowVolume(aclObj, args.RequestNamespace()) || !aclObj.AllowPluginRead() {
|
2020-02-04 13:00:00 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
2020-03-16 19:59:42 +00:00
|
|
|
// if this is a new claim, add a Volume and PublishContext from the
|
|
|
|
// controller (if any) to the reply
|
|
|
|
if args.Claim != structs.CSIVolumeClaimRelease {
|
|
|
|
err = v.srv.controllerPublishVolume(args, reply)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("controller publish: %v", err)
|
|
|
|
}
|
2020-02-13 15:18:55 +00:00
|
|
|
}
|
|
|
|
|
2020-02-04 13:00:00 +00:00
|
|
|
resp, index, err := v.srv.raftApply(structs.CSIVolumeClaimRequestType, args)
|
|
|
|
if err != nil {
|
|
|
|
v.logger.Error("csi raft apply failed", "error", err, "method", "claim")
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if respErr, ok := resp.(error); ok {
|
|
|
|
return respErr
|
|
|
|
}
|
2019-10-16 20:53:39 +00:00
|
|
|
|
2020-02-03 20:40:28 +00:00
|
|
|
reply.Index = index
|
|
|
|
v.srv.setQueryMeta(&reply.QueryMeta)
|
|
|
|
return nil
|
2020-01-28 15:28:34 +00:00
|
|
|
}
|
|
|
|
|
2020-03-17 21:32:39 +00:00
|
|
|
// allowCSIMount is called on Job register to check mount permission
|
|
|
|
func allowCSIMount(aclObj *acl.ACL, namespace string) bool {
|
|
|
|
return aclObj.AllowPluginRead() &&
|
|
|
|
aclObj.AllowNsOp(namespace, acl.NamespaceCapabilityCSIMountVolume)
|
|
|
|
}
|
|
|
|
|
2020-01-28 15:28:34 +00:00
|
|
|
// CSIPlugin wraps the structs.CSIPlugin with request data and server context
|
|
|
|
type CSIPlugin struct {
|
|
|
|
srv *Server
|
|
|
|
logger log.Logger
|
|
|
|
}
|
|
|
|
|
|
|
|
// List replies with CSIPlugins, filtered by ACL access
|
|
|
|
func (v *CSIPlugin) List(args *structs.CSIPluginListRequest, reply *structs.CSIPluginListResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIPlugin.List", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-02-11 11:41:18 +00:00
|
|
|
allowCSIAccess := acl.NamespaceValidator(acl.NamespaceCapabilityCSIAccess)
|
|
|
|
aclObj, err := v.srv.QueryACLObj(&args.QueryOptions, false)
|
2020-01-28 15:28:34 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-02-11 11:41:18 +00:00
|
|
|
if !allowCSIAccess(aclObj, args.RequestNamespace()) {
|
2020-01-28 15:28:34 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "plugin", "list"}, metricsStart)
|
|
|
|
|
|
|
|
opts := blockingOptions{
|
|
|
|
queryOpts: &args.QueryOptions,
|
|
|
|
queryMeta: &reply.QueryMeta,
|
|
|
|
run: func(ws memdb.WatchSet, state *state.StateStore) error {
|
|
|
|
// Query all plugins
|
|
|
|
iter, err := state.CSIPlugins(ws)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Collect results
|
|
|
|
var ps []*structs.CSIPluginListStub
|
|
|
|
for {
|
|
|
|
raw := iter.Next()
|
|
|
|
if raw == nil {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
|
|
|
|
plug := raw.(*structs.CSIPlugin)
|
|
|
|
|
|
|
|
// FIXME we should filter the ACL access for the plugin's
|
|
|
|
// namespace, but plugins don't currently have namespaces
|
|
|
|
ps = append(ps, plug.Stub())
|
|
|
|
}
|
|
|
|
|
|
|
|
reply.Plugins = ps
|
|
|
|
return v.srv.replySetIndex(csiPluginTable, &reply.QueryMeta)
|
|
|
|
}}
|
|
|
|
return v.srv.blockingRPC(&opts)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get fetches detailed information about a specific plugin
|
|
|
|
func (v *CSIPlugin) Get(args *structs.CSIPluginGetRequest, reply *structs.CSIPluginGetResponse) error {
|
|
|
|
if done, err := v.srv.forward("CSIPlugin.Get", args, args, reply); done {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-02-11 11:41:18 +00:00
|
|
|
allowCSIAccess := acl.NamespaceValidator(acl.NamespaceCapabilityCSIAccess)
|
|
|
|
aclObj, err := v.srv.QueryACLObj(&args.QueryOptions, false)
|
2020-01-28 15:28:34 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2020-02-11 11:41:18 +00:00
|
|
|
if !allowCSIAccess(aclObj, args.RequestNamespace()) {
|
2020-01-28 15:28:34 +00:00
|
|
|
return structs.ErrPermissionDenied
|
|
|
|
}
|
|
|
|
|
|
|
|
metricsStart := time.Now()
|
|
|
|
defer metrics.MeasureSince([]string{"nomad", "plugin", "get"}, metricsStart)
|
|
|
|
|
|
|
|
opts := blockingOptions{
|
|
|
|
queryOpts: &args.QueryOptions,
|
|
|
|
queryMeta: &reply.QueryMeta,
|
|
|
|
run: func(ws memdb.WatchSet, state *state.StateStore) error {
|
|
|
|
plug, err := state.CSIPluginByID(ws, args.ID)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if plug != nil {
|
2020-03-09 15:24:14 +00:00
|
|
|
plug, err = state.CSIPluginDenormalize(ws, plug.Copy())
|
2020-01-28 15:28:34 +00:00
|
|
|
}
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// FIXME we should re-check the ACL access for the plugin's
|
|
|
|
// namespace, but plugins don't currently have namespaces
|
|
|
|
|
|
|
|
reply.Plugin = plug
|
|
|
|
return v.srv.replySetIndex(csiPluginTable, &reply.QueryMeta)
|
|
|
|
}}
|
|
|
|
return v.srv.blockingRPC(&opts)
|
2019-10-16 20:53:39 +00:00
|
|
|
}
|
2020-02-11 15:23:55 +00:00
|
|
|
|
|
|
|
// controllerPublishVolume sends publish request to the CSI controller
|
|
|
|
// plugin associated with a volume, if any.
|
|
|
|
func (srv *Server) controllerPublishVolume(req *structs.CSIVolumeClaimRequest, resp *structs.CSIVolumeClaimResponse) error {
|
2020-03-17 15:35:34 +00:00
|
|
|
plug, vol, err := srv.volAndPluginLookup(req.RequestNamespace(), req.VolumeID)
|
2020-02-17 12:50:37 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Set the Response volume from the lookup
|
|
|
|
resp.Volume = vol
|
|
|
|
|
|
|
|
// Validate the existence of the allocation, regardless of whether we need it
|
|
|
|
// now.
|
|
|
|
state := srv.fsm.State()
|
|
|
|
ws := memdb.NewWatchSet()
|
|
|
|
alloc, err := state.AllocByID(ws, req.AllocationID)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if alloc == nil {
|
|
|
|
return fmt.Errorf("%s: %s", structs.ErrUnknownAllocationPrefix, req.AllocationID)
|
|
|
|
}
|
|
|
|
|
|
|
|
// if no plugin was returned then controller validation is not required.
|
|
|
|
// Here we can return nil.
|
|
|
|
if plug == nil {
|
|
|
|
return nil
|
2020-02-13 15:18:55 +00:00
|
|
|
}
|
|
|
|
|
2020-02-21 10:32:10 +00:00
|
|
|
// plugin IDs are not scoped to region/DC but volumes are.
|
|
|
|
// so any node we get for a controller is already in the same region/DC
|
|
|
|
// for the volume.
|
|
|
|
nodeID, err := srv.nodeForControllerPlugin(plug)
|
|
|
|
if err != nil || nodeID == "" {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
targetNode, err := state.NodeByID(ws, alloc.NodeID)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if targetNode == nil {
|
|
|
|
return fmt.Errorf("%s: %s", structs.ErrUnknownNodePrefix, alloc.NodeID)
|
|
|
|
}
|
|
|
|
targetCSIInfo, ok := targetNode.CSINodePlugins[plug.ID]
|
|
|
|
if !ok {
|
|
|
|
return fmt.Errorf("Failed to find NodeInfo for node: %s", targetNode.ID)
|
|
|
|
}
|
|
|
|
|
|
|
|
method := "ClientCSIController.AttachVolume"
|
2020-02-13 15:18:55 +00:00
|
|
|
cReq := &cstructs.ClientCSIControllerAttachVolumeRequest{
|
2020-03-12 19:08:19 +00:00
|
|
|
VolumeID: vol.RemoteID(),
|
2020-02-21 10:32:10 +00:00
|
|
|
ClientCSINodeID: targetCSIInfo.NodeInfo.ID,
|
|
|
|
AttachmentMode: vol.AttachmentMode,
|
|
|
|
AccessMode: vol.AccessMode,
|
|
|
|
ReadOnly: req.Claim == structs.CSIVolumeClaimRead,
|
2020-02-13 15:18:55 +00:00
|
|
|
// TODO(tgross): we don't have a way of setting these yet.
|
|
|
|
// ref https://github.com/hashicorp/nomad/issues/7007
|
|
|
|
// MountOptions: vol.MountOptions,
|
|
|
|
}
|
2020-02-21 10:32:10 +00:00
|
|
|
cReq.PluginID = plug.ID
|
|
|
|
cReq.ControllerNodeID = nodeID
|
2020-02-13 15:18:55 +00:00
|
|
|
cResp := &cstructs.ClientCSIControllerAttachVolumeResponse{}
|
|
|
|
|
2020-02-21 10:32:10 +00:00
|
|
|
err = srv.RPC(method, cReq, cResp)
|
2020-02-13 15:18:55 +00:00
|
|
|
if err != nil {
|
2020-03-10 14:22:42 +00:00
|
|
|
return fmt.Errorf("attach volume: %v", err)
|
2020-02-13 15:18:55 +00:00
|
|
|
}
|
|
|
|
resp.PublishContext = cResp.PublishContext
|
2020-02-11 15:23:55 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// controllerUnpublishVolume sends an unpublish request to the CSI
|
|
|
|
// controller plugin associated with a volume, if any.
|
2020-02-19 14:05:33 +00:00
|
|
|
// TODO: the only caller of this won't have an alloc pointer handy, should it be its own request arg type?
|
2020-02-21 10:32:10 +00:00
|
|
|
func (srv *Server) controllerUnpublishVolume(req *structs.CSIVolumeClaimRequest, targetNomadNodeID string) error {
|
2020-03-17 15:35:34 +00:00
|
|
|
plug, vol, err := srv.volAndPluginLookup(req.RequestNamespace(), req.VolumeID)
|
2020-02-13 15:18:55 +00:00
|
|
|
if plug == nil || vol == nil || err != nil {
|
|
|
|
return err // possibly nil if no controller required
|
|
|
|
}
|
|
|
|
|
2020-02-21 10:32:10 +00:00
|
|
|
ws := memdb.NewWatchSet()
|
|
|
|
state := srv.State()
|
|
|
|
|
|
|
|
targetNode, err := state.NodeByID(ws, targetNomadNodeID)
|
2020-02-13 15:18:55 +00:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2020-02-21 10:32:10 +00:00
|
|
|
if targetNode == nil {
|
|
|
|
return fmt.Errorf("%s: %s", structs.ErrUnknownNodePrefix, targetNomadNodeID)
|
|
|
|
}
|
|
|
|
targetCSIInfo, ok := targetNode.CSINodePlugins[plug.ID]
|
|
|
|
if !ok {
|
|
|
|
return fmt.Errorf("Failed to find NodeInfo for node: %s", targetNode.ID)
|
|
|
|
}
|
|
|
|
|
|
|
|
// plugin IDs are not scoped to region/DC but volumes are.
|
|
|
|
// so any node we get for a controller is already in the same region/DC
|
|
|
|
// for the volume.
|
|
|
|
nodeID, err := srv.nodeForControllerPlugin(plug)
|
|
|
|
if err != nil || nodeID == "" {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
method := "ClientCSIController.DetachVolume"
|
|
|
|
cReq := &cstructs.ClientCSIControllerDetachVolumeRequest{
|
2020-03-12 19:08:19 +00:00
|
|
|
VolumeID: vol.RemoteID(),
|
2020-02-21 10:32:10 +00:00
|
|
|
ClientCSINodeID: targetCSIInfo.NodeInfo.ID,
|
|
|
|
}
|
|
|
|
cReq.PluginID = plug.ID
|
|
|
|
cReq.ControllerNodeID = nodeID
|
|
|
|
return srv.RPC(method, cReq, &cstructs.ClientCSIControllerDetachVolumeResponse{})
|
2020-02-11 15:23:55 +00:00
|
|
|
}
|
2020-02-13 15:18:55 +00:00
|
|
|
|
2020-03-17 15:35:34 +00:00
|
|
|
func (srv *Server) volAndPluginLookup(namespace, volID string) (*structs.CSIPlugin, *structs.CSIVolume, error) {
|
2020-02-13 15:18:55 +00:00
|
|
|
state := srv.fsm.State()
|
|
|
|
ws := memdb.NewWatchSet()
|
|
|
|
|
2020-03-17 15:35:34 +00:00
|
|
|
vol, err := state.CSIVolumeByID(ws, namespace, volID)
|
2020-02-13 15:18:55 +00:00
|
|
|
if err != nil {
|
|
|
|
return nil, nil, err
|
|
|
|
}
|
|
|
|
if vol == nil {
|
|
|
|
return nil, nil, fmt.Errorf("volume not found: %s", volID)
|
|
|
|
}
|
|
|
|
if !vol.ControllerRequired {
|
2020-02-17 12:50:37 +00:00
|
|
|
return nil, vol, nil
|
2020-02-13 15:18:55 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// note: we do this same lookup in CSIVolumeByID but then throw
|
|
|
|
// away the pointer to the plugin rather than attaching it to
|
|
|
|
// the volume so we have to do it again here.
|
|
|
|
plug, err := state.CSIPluginByID(ws, vol.PluginID)
|
|
|
|
if err != nil {
|
|
|
|
return nil, nil, err
|
|
|
|
}
|
|
|
|
if plug == nil {
|
|
|
|
return nil, nil, fmt.Errorf("plugin not found: %s", vol.PluginID)
|
|
|
|
}
|
|
|
|
return plug, vol, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// nodeForControllerPlugin returns the node ID for a random controller
|
|
|
|
// to load-balance long-blocking RPCs across client nodes.
|
|
|
|
func (srv *Server) nodeForControllerPlugin(plugin *structs.CSIPlugin) (string, error) {
|
|
|
|
count := len(plugin.Controllers)
|
|
|
|
if count == 0 {
|
|
|
|
return "", fmt.Errorf("no controllers available for plugin %q", plugin.ID)
|
|
|
|
}
|
|
|
|
snap, err := srv.fsm.State().Snapshot()
|
|
|
|
if err != nil {
|
|
|
|
return "", err
|
|
|
|
}
|
|
|
|
|
|
|
|
// iterating maps is "random" but unspecified and isn't particularly
|
|
|
|
// random with small maps, so not well-suited for load balancing.
|
|
|
|
// so we shuffle the keys and iterate over them.
|
|
|
|
clientIDs := make([]string, count)
|
|
|
|
for clientID := range plugin.Controllers {
|
|
|
|
clientIDs = append(clientIDs, clientID)
|
|
|
|
}
|
|
|
|
rand.Shuffle(count, func(i, j int) {
|
|
|
|
clientIDs[i], clientIDs[j] = clientIDs[j], clientIDs[i]
|
|
|
|
})
|
|
|
|
|
|
|
|
for _, clientID := range clientIDs {
|
|
|
|
controller := plugin.Controllers[clientID]
|
|
|
|
if !controller.IsController() {
|
|
|
|
// we don't have separate types for CSIInfo depending on
|
|
|
|
// whether it's a controller or node. this error shouldn't
|
|
|
|
// make it to production but is to aid developers during
|
|
|
|
// development
|
|
|
|
err = fmt.Errorf("plugin is not a controller")
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
_, err = getNodeForRpc(snap, clientID)
|
|
|
|
if err != nil {
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
return clientID, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
return "", err
|
|
|
|
}
|