open-vault/builtin/logical/transit/path_cache_config.go
divyapola5 30563097ea
Enforce minimum cache size for transit backend (#12418)
* Enforce Minimum cache size for transit backend

* enfore minimum cache size and log a warning during backend construction

* Update documentation for transit backend cache configuration

* Added changelog

* Addressed review feedback and added unit test

* Modify code in pathCacheConfigWrite to make use of the updated cache size

* Updated code to refresh cache size on transit backend without restart

* Update code to acquire read and write locks appropriately
2021-09-13 16:44:56 -05:00

107 lines
2.8 KiB
Go

package transit
import (
"context"
"errors"
"github.com/hashicorp/vault/sdk/framework"
"github.com/hashicorp/vault/sdk/logical"
)
func (b *backend) pathCacheConfig() *framework.Path {
return &framework.Path{
Pattern: "cache-config",
Fields: map[string]*framework.FieldSchema{
"size": {
Type: framework.TypeInt,
Required: false,
Default: 0,
Description: `Size of cache, use 0 for an unlimited cache size, defaults to 0`,
},
},
Operations: map[logical.Operation]framework.OperationHandler{
logical.ReadOperation: &framework.PathOperation{
Callback: b.pathCacheConfigRead,
Summary: "Returns the size of the active cache",
},
logical.UpdateOperation: &framework.PathOperation{
Callback: b.pathCacheConfigWrite,
Summary: "Configures a new cache of the specified size",
},
logical.CreateOperation: &framework.PathOperation{
Callback: b.pathCacheConfigWrite,
Summary: "Configures a new cache of the specified size",
},
},
HelpSynopsis: pathCacheConfigHelpSyn,
HelpDescription: pathCacheConfigHelpDesc,
}
}
func (b *backend) pathCacheConfigWrite(ctx context.Context, req *logical.Request, d *framework.FieldData) (*logical.Response, error) {
// get target size
cacheSize := d.Get("size").(int)
if cacheSize != 0 && cacheSize < minCacheSize {
return logical.ErrorResponse("size must be 0 or a value greater or equal to %d", minCacheSize), logical.ErrInvalidRequest
}
// store cache size
entry, err := logical.StorageEntryJSON("config/cache", &configCache{
Size: cacheSize,
})
if err != nil {
return nil, err
}
if err := req.Storage.Put(ctx, entry); err != nil {
return nil, err
}
err = b.lm.InitCache(cacheSize)
if err != nil {
return nil, err
}
return nil, nil
}
type configCache struct {
Size int `json:"size"`
}
func (b *backend) pathCacheConfigRead(ctx context.Context, req *logical.Request, d *framework.FieldData) (*logical.Response, error) {
// error if no cache is configured
if !b.lm.GetUseCache() {
return nil, errors.New(
"caching is disabled for this transit mount",
)
}
// Compare current and stored cache sizes. If they are different warn the user.
currentCacheSize := b.lm.GetCacheSize()
storedCacheSize, err := GetCacheSizeFromStorage(ctx, req.Storage)
if err != nil {
return nil, err
}
resp := &logical.Response{
Data: map[string]interface{}{
"size": storedCacheSize,
},
}
if currentCacheSize != storedCacheSize {
resp.Warnings = []string{"This cache size will not be applied until the transit mount is reloaded"}
}
return resp, nil
}
const pathCacheConfigHelpSyn = `Configure caching strategy`
const pathCacheConfigHelpDesc = `
This path is used to configure and query the cache size of the active cache, a size of 0 means unlimited.
`