open-vault/command/server/listener.go

59 lines
1.7 KiB
Go
Raw Normal View History

// Copyright (c) HashiCorp, Inc.
// SPDX-License-Identifier: MPL-2.0
2015-03-13 16:37:32 +00:00
package server
import (
2015-07-23 20:51:45 +00:00
_ "crypto/sha512"
2015-03-13 16:37:32 +00:00
"fmt"
2016-06-02 16:40:25 +00:00
"io"
2015-03-13 16:37:32 +00:00
"net"
2016-07-12 23:32:47 +00:00
// We must import sha512 so that it registers with the runtime so that
// certificates that use it can be parsed.
"github.com/hashicorp/go-secure-stdlib/reloadutil"
"github.com/hashicorp/vault/helper/proxyutil"
"github.com/hashicorp/vault/internalshared/configutil"
"github.com/mitchellh/cli"
2015-03-13 16:37:32 +00:00
)
// ListenerFactory is the factory function to create a listener.
type ListenerFactory func(*configutil.Listener, io.Writer, cli.Ui) (net.Listener, map[string]string, reloadutil.ReloadFunc, error)
2015-03-13 16:37:32 +00:00
// BuiltinListeners is the list of built-in listener types.
var BuiltinListeners = map[string]ListenerFactory{
"tcp": tcpListenerFactory,
"unix": unixListenerFactory,
2015-03-13 16:37:32 +00:00
}
// NewListener creates a new listener of the given type with the given
// configuration. The type is looked up in the BuiltinListeners map.
func NewListener(l *configutil.Listener, logger io.Writer, ui cli.Ui) (net.Listener, map[string]string, reloadutil.ReloadFunc, error) {
f, ok := BuiltinListeners[l.Type]
2015-03-13 16:37:32 +00:00
if !ok {
return nil, nil, nil, fmt.Errorf("unknown listener type: %q", l.Type)
2015-03-13 16:37:32 +00:00
}
return f(l, logger, ui)
2015-03-13 16:37:32 +00:00
}
2015-03-13 16:56:08 +00:00
func listenerWrapProxy(ln net.Listener, l *configutil.Listener) (net.Listener, error) {
behavior := l.ProxyProtocolBehavior
if behavior == "" {
return ln, nil
}
proxyProtoConfig := &proxyutil.ProxyProtoConfig{
Behavior: behavior,
AuthorizedAddrs: l.ProxyProtocolAuthorizedAddrs,
}
newLn, err := proxyutil.WrapInProxyProto(ln, proxyProtoConfig)
if err != nil {
return nil, fmt.Errorf("failed configuring PROXY protocol wrapper: %w", err)
}
return newLn, nil
}