2021-04-18 12:41:13 -07:00
|
|
|
// Copyright (c) 2015-2021 MinIO, Inc.
|
|
|
|
//
|
|
|
|
// This file is part of MinIO Object Storage stack
|
|
|
|
//
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// This program is distributed in the hope that it will be useful
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU Affero General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
2017-03-16 12:21:58 -07:00
|
|
|
|
|
|
|
package cmd
|
|
|
|
|
|
|
|
import (
|
2020-04-16 20:54:12 +02:00
|
|
|
"context"
|
2017-03-16 12:21:58 -07:00
|
|
|
"fmt"
|
2020-04-16 20:54:12 +02:00
|
|
|
"net"
|
2017-04-11 17:44:26 -07:00
|
|
|
"net/url"
|
2017-07-13 05:03:21 +05:30
|
|
|
"os"
|
|
|
|
"os/signal"
|
2017-04-11 17:44:26 -07:00
|
|
|
"strings"
|
2017-07-13 05:03:21 +05:30
|
|
|
"syscall"
|
2017-06-05 15:18:03 -07:00
|
|
|
|
|
|
|
"github.com/gorilla/mux"
|
|
|
|
"github.com/minio/cli"
|
2021-06-14 12:53:49 -07:00
|
|
|
"github.com/minio/madmin-go"
|
2021-06-01 14:59:40 -07:00
|
|
|
xhttp "github.com/minio/minio/internal/http"
|
|
|
|
"github.com/minio/minio/internal/logger"
|
2021-05-28 15:17:01 -07:00
|
|
|
"github.com/minio/pkg/certs"
|
|
|
|
"github.com/minio/pkg/env"
|
2017-03-16 12:21:58 -07:00
|
|
|
)
|
|
|
|
|
2017-06-09 19:50:51 -07:00
|
|
|
var (
|
|
|
|
gatewayCmd = cli.Command{
|
|
|
|
Name: "gateway",
|
2018-11-20 17:35:33 -08:00
|
|
|
Usage: "start object storage gateway",
|
2019-06-10 07:57:42 -07:00
|
|
|
Flags: append(ServerFlags, GlobalFlags...),
|
2017-06-09 19:50:51 -07:00
|
|
|
HideHelpCommand: true,
|
|
|
|
}
|
|
|
|
)
|
2017-06-09 11:58:45 +05:30
|
|
|
|
2020-06-29 17:07:23 -07:00
|
|
|
// GatewayLocker implements custom NewNSLock implementation
|
|
|
|
type GatewayLocker struct {
|
|
|
|
ObjectLayer
|
|
|
|
nsMutex *nsLockMap
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewNSLock - implements gateway level locker
|
2020-11-04 08:25:42 -08:00
|
|
|
func (l *GatewayLocker) NewNSLock(bucket string, objects ...string) RWLocker {
|
|
|
|
return l.nsMutex.NewNSLock(nil, bucket, objects...)
|
2020-06-29 17:07:23 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// Walk - implements common gateway level Walker, to walk on all objects recursively at a prefix
|
2020-07-10 22:21:04 -07:00
|
|
|
func (l *GatewayLocker) Walk(ctx context.Context, bucket, prefix string, results chan<- ObjectInfo, opts ObjectOptions) error {
|
2020-06-29 17:07:23 -07:00
|
|
|
walk := func(ctx context.Context, bucket, prefix string, results chan<- ObjectInfo) error {
|
2020-07-26 22:56:05 -07:00
|
|
|
go func() {
|
|
|
|
// Make sure the results channel is ready to be read when we're done.
|
|
|
|
defer close(results)
|
2020-07-01 14:29:45 -07:00
|
|
|
|
2020-07-26 22:56:05 -07:00
|
|
|
var marker string
|
2020-07-01 14:29:45 -07:00
|
|
|
|
2020-07-26 22:56:05 -07:00
|
|
|
for {
|
|
|
|
// set maxKeys to '0' to list maximum possible objects in single call.
|
|
|
|
loi, err := l.ObjectLayer.ListObjects(ctx, bucket, prefix, marker, "", 0)
|
|
|
|
if err != nil {
|
|
|
|
logger.LogIf(ctx, err)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
marker = loi.NextMarker
|
|
|
|
for _, obj := range loi.Objects {
|
|
|
|
select {
|
|
|
|
case results <- obj:
|
|
|
|
case <-ctx.Done():
|
|
|
|
return
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if !loi.IsTruncated {
|
|
|
|
break
|
2020-06-29 17:07:23 -07:00
|
|
|
}
|
|
|
|
}
|
2020-07-26 22:56:05 -07:00
|
|
|
}()
|
2020-06-29 17:07:23 -07:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2020-07-10 22:21:04 -07:00
|
|
|
if err := l.ObjectLayer.Walk(ctx, bucket, prefix, results, opts); err != nil {
|
2020-06-29 17:07:23 -07:00
|
|
|
if _, ok := err.(NotImplemented); ok {
|
|
|
|
return walk(ctx, bucket, prefix, results)
|
|
|
|
}
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewGatewayLayerWithLocker - initialize gateway with locker.
|
|
|
|
func NewGatewayLayerWithLocker(gwLayer ObjectLayer) ObjectLayer {
|
|
|
|
return &GatewayLocker{ObjectLayer: gwLayer, nsMutex: newNSLock(false)}
|
|
|
|
}
|
|
|
|
|
2017-10-27 17:07:46 -05:00
|
|
|
// RegisterGatewayCommand registers a new command for gateway.
|
|
|
|
func RegisterGatewayCommand(cmd cli.Command) error {
|
2019-07-04 06:31:19 +09:00
|
|
|
cmd.Flags = append(append(cmd.Flags, ServerFlags...), GlobalFlags...)
|
2017-10-27 17:07:46 -05:00
|
|
|
gatewayCmd.Subcommands = append(gatewayCmd.Subcommands, cmd)
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2017-12-05 17:58:09 -08:00
|
|
|
// ParseGatewayEndpoint - Return endpoint.
|
|
|
|
func ParseGatewayEndpoint(arg string) (endPoint string, secure bool, err error) {
|
2017-04-11 17:44:26 -07:00
|
|
|
schemeSpecified := len(strings.Split(arg, "://")) > 1
|
|
|
|
if !schemeSpecified {
|
|
|
|
// Default connection will be "secure".
|
|
|
|
arg = "https://" + arg
|
|
|
|
}
|
2017-04-27 20:26:00 +02:00
|
|
|
|
2017-04-11 17:44:26 -07:00
|
|
|
u, err := url.Parse(arg)
|
|
|
|
if err != nil {
|
|
|
|
return "", false, err
|
|
|
|
}
|
|
|
|
|
|
|
|
switch u.Scheme {
|
|
|
|
case "http":
|
|
|
|
return u.Host, false, nil
|
|
|
|
case "https":
|
|
|
|
return u.Host, true, nil
|
|
|
|
default:
|
|
|
|
return "", false, fmt.Errorf("Unrecognized scheme %s", u.Scheme)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2017-12-05 17:58:09 -08:00
|
|
|
// ValidateGatewayArguments - Validate gateway arguments.
|
|
|
|
func ValidateGatewayArguments(serverAddr, endpointAddr string) error {
|
2017-06-08 11:20:56 -07:00
|
|
|
if err := CheckLocalServerAddr(serverAddr); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if endpointAddr != "" {
|
|
|
|
// Reject the endpoint if it points to the gateway handler itself.
|
|
|
|
sameTarget, err := sameLocalAddrs(endpointAddr, serverAddr)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if sameTarget {
|
2017-11-25 11:58:29 -08:00
|
|
|
return fmt.Errorf("endpoint points to the local gateway")
|
2017-06-08 11:20:56 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2017-12-05 17:58:09 -08:00
|
|
|
// StartGateway - handler for 'minio gateway <name>'.
|
|
|
|
func StartGateway(ctx *cli.Context, gw Gateway) {
|
2020-10-16 14:49:05 -07:00
|
|
|
defer globalDNSCache.Stop()
|
|
|
|
|
2021-06-17 20:27:04 -07:00
|
|
|
signal.Notify(globalOSSignalCh, os.Interrupt, syscall.SIGTERM, syscall.SIGQUIT)
|
|
|
|
|
|
|
|
go handleSignals()
|
|
|
|
|
|
|
|
signal.Notify(globalOSSignalCh, os.Interrupt, syscall.SIGTERM, syscall.SIGQUIT)
|
2020-05-18 20:35:05 +02:00
|
|
|
// This is only to uniquely identify each gateway deployments.
|
|
|
|
globalDeploymentID = env.Get("MINIO_GATEWAY_DEPLOYMENT_ID", mustGetUUID())
|
|
|
|
logger.SetDeploymentID(globalDeploymentID)
|
|
|
|
|
2017-12-05 17:58:09 -08:00
|
|
|
if gw == nil {
|
2018-05-09 15:11:24 -07:00
|
|
|
logger.FatalIf(errUnexpected, "Gateway implementation not initialized")
|
2017-12-05 17:58:09 -08:00
|
|
|
}
|
|
|
|
|
|
|
|
// Validate if we have access, secret set through environment.
|
2019-08-14 11:43:43 -07:00
|
|
|
globalGatewayName = gw.Name()
|
2017-12-05 17:58:09 -08:00
|
|
|
gatewayName := gw.Name()
|
|
|
|
if ctx.Args().First() == "help" {
|
|
|
|
cli.ShowCommandHelpAndExit(ctx, gatewayName, 1)
|
|
|
|
}
|
|
|
|
|
2020-09-16 02:02:54 +01:00
|
|
|
// Initialize globalConsoleSys system
|
|
|
|
globalConsoleSys = NewConsoleLogger(GlobalContext)
|
|
|
|
logger.AddTarget(globalConsoleSys)
|
|
|
|
|
2017-06-09 19:50:51 -07:00
|
|
|
// Handle common command args.
|
|
|
|
handleCommonCmdArgs(ctx)
|
|
|
|
|
2020-08-06 18:03:16 -07:00
|
|
|
// Check and load TLS certificates.
|
|
|
|
var err error
|
2020-12-21 21:42:38 -08:00
|
|
|
globalPublicCerts, globalTLSCerts, globalIsTLS, err = getTLSConfig()
|
2020-08-06 18:03:16 -07:00
|
|
|
logger.FatalIf(err, "Invalid TLS certificate file")
|
|
|
|
|
|
|
|
// Check and load Root CAs.
|
2020-08-11 08:29:50 -07:00
|
|
|
globalRootCAs, err = certs.GetRootCAs(globalCertsCADir.Get())
|
2020-08-06 18:03:16 -07:00
|
|
|
logger.FatalIf(err, "Failed to read root CAs (%v)", err)
|
|
|
|
|
2020-08-13 09:46:50 -07:00
|
|
|
// Add the global public crts as part of global root CAs
|
|
|
|
for _, publicCrt := range globalPublicCerts {
|
|
|
|
globalRootCAs.AddCert(publicCrt)
|
|
|
|
}
|
|
|
|
|
2020-08-06 18:03:16 -07:00
|
|
|
// Register root CAs for remote ENVs
|
|
|
|
env.RegisterGlobalCAs(globalRootCAs)
|
|
|
|
|
2019-12-04 15:32:37 -08:00
|
|
|
// Initialize all help
|
|
|
|
initHelp()
|
|
|
|
|
2018-08-17 21:06:36 -07:00
|
|
|
// On macOS, if a process already listens on LOCALIPADDR:PORT, net.Listen() falls back
|
|
|
|
// to IPv6 address ie minio will start listening on IPv6 address whereas another
|
|
|
|
// (non-)minio process is listening on IPv4 of given port.
|
|
|
|
// To avoid this error situation we check for port availability.
|
2019-06-25 03:32:40 +05:30
|
|
|
logger.FatalIf(checkPortAvailability(globalMinioHost, globalMinioPort), "Unable to start the gateway")
|
2018-08-17 21:06:36 -07:00
|
|
|
|
2020-04-27 06:25:05 -07:00
|
|
|
globalMinioEndpoint = func() string {
|
|
|
|
host := globalMinioHost
|
|
|
|
if host == "" {
|
|
|
|
host = sortIPs(localIP4.ToSlice())[0]
|
|
|
|
}
|
2020-12-21 21:42:38 -08:00
|
|
|
return fmt.Sprintf("%s://%s", getURLScheme(globalIsTLS), net.JoinHostPort(host, globalMinioPort))
|
2020-04-27 06:25:05 -07:00
|
|
|
}()
|
|
|
|
|
2019-01-05 14:16:43 -08:00
|
|
|
// Handle gateway specific env
|
2019-11-01 15:53:16 -07:00
|
|
|
gatewayHandleEnvVars()
|
2019-01-05 14:16:43 -08:00
|
|
|
|
2017-12-24 20:09:30 +05:30
|
|
|
// Set system resources to maximum.
|
2020-06-16 18:57:29 -07:00
|
|
|
setMaxResources()
|
2017-12-24 20:09:30 +05:30
|
|
|
|
2019-06-07 15:49:13 -07:00
|
|
|
// Set when gateway is enabled
|
|
|
|
globalIsGateway = true
|
|
|
|
|
2020-06-25 15:59:28 +05:30
|
|
|
enableConfigOps := false
|
2019-11-12 03:16:25 -08:00
|
|
|
|
|
|
|
// TODO: We need to move this code with globalConfigSys.Init()
|
|
|
|
// for now keep it here such that "s3" gateway layer initializes
|
|
|
|
// itself properly when KMS is set.
|
|
|
|
|
|
|
|
// Initialize server config.
|
|
|
|
srvCfg := newServerConfig()
|
|
|
|
|
|
|
|
// Override any values from ENVs.
|
2021-01-22 12:09:24 -08:00
|
|
|
lookupConfigs(srvCfg, nil)
|
2019-11-12 03:16:25 -08:00
|
|
|
|
|
|
|
// hold the mutex lock before a new config is assigned.
|
|
|
|
globalServerConfigMu.Lock()
|
|
|
|
globalServerConfig = srvCfg
|
|
|
|
globalServerConfigMu.Unlock()
|
|
|
|
|
2020-02-12 09:08:02 +05:30
|
|
|
// Initialize router. `SkipClean(true)` stops gorilla/mux from
|
|
|
|
// normalizing URL path minio/minio#3256
|
|
|
|
// avoid URL path encoding minio/minio#8950
|
|
|
|
router := mux.NewRouter().SkipClean(true).UseEncodedPath()
|
2017-06-01 09:43:20 -07:00
|
|
|
|
2021-07-10 08:32:52 -07:00
|
|
|
// Enable STS router if etcd is enabled.
|
|
|
|
registerSTSRouter(router)
|
2019-01-24 00:40:59 +05:30
|
|
|
|
2018-12-18 13:03:26 -08:00
|
|
|
// Enable IAM admin APIs if etcd is enabled, if not just enable basic
|
|
|
|
// operations such as profiling, server info etc.
|
2021-07-10 08:32:52 -07:00
|
|
|
registerAdminRouter(router, enableConfigOps)
|
2018-12-18 13:03:26 -08:00
|
|
|
|
2018-04-04 21:07:54 -05:00
|
|
|
// Add healthcheck router
|
|
|
|
registerHealthCheckRouter(router)
|
|
|
|
|
2018-05-30 06:43:46 +02:00
|
|
|
// Add server metrics router
|
|
|
|
registerMetricsRouter(router)
|
|
|
|
|
2018-04-04 21:07:54 -05:00
|
|
|
// Add API router.
|
2020-09-15 13:57:15 -07:00
|
|
|
registerAPIRouter(router)
|
2017-03-16 12:21:58 -07:00
|
|
|
|
2020-06-11 08:19:55 -07:00
|
|
|
// Use all the middlewares
|
2021-01-04 18:54:22 +01:00
|
|
|
router.Use(globalHandlers...)
|
2020-06-11 08:19:55 -07:00
|
|
|
|
2018-05-31 12:30:15 -07:00
|
|
|
var getCert certs.GetCertificateFunc
|
|
|
|
if globalTLSCerts != nil {
|
|
|
|
getCert = globalTLSCerts.GetCertificate
|
|
|
|
}
|
|
|
|
|
2021-06-20 23:04:47 -07:00
|
|
|
httpServer := xhttp.NewServer([]string{globalMinioAddr},
|
2020-07-12 10:56:57 -07:00
|
|
|
criticalErrorHandler{corsHandler(router)}, getCert)
|
2020-04-16 20:54:12 +02:00
|
|
|
httpServer.BaseContext = func(listener net.Listener) context.Context {
|
|
|
|
return GlobalContext
|
|
|
|
}
|
2017-03-16 12:21:58 -07:00
|
|
|
go func() {
|
2019-12-02 15:54:26 -08:00
|
|
|
globalHTTPServerErrorCh <- httpServer.Start()
|
2017-03-16 12:21:58 -07:00
|
|
|
}()
|
|
|
|
|
2019-12-02 15:54:26 -08:00
|
|
|
globalObjLayerMutex.Lock()
|
|
|
|
globalHTTPServer = httpServer
|
|
|
|
globalObjLayerMutex.Unlock()
|
|
|
|
|
2021-06-14 12:53:49 -07:00
|
|
|
newObject, err := gw.NewGatewayLayer(madmin.Credentials{
|
|
|
|
AccessKey: globalActiveCred.AccessKey,
|
|
|
|
SecretKey: globalActiveCred.SecretKey,
|
|
|
|
})
|
2018-12-18 10:42:09 -08:00
|
|
|
if err != nil {
|
|
|
|
globalHTTPServer.Shutdown()
|
|
|
|
logger.FatalIf(err, "Unable to initialize gateway backend")
|
|
|
|
}
|
2019-11-19 16:45:35 -08:00
|
|
|
newObject = NewGatewayLayerWithLocker(newObject)
|
|
|
|
|
2020-10-19 09:54:40 -07:00
|
|
|
// Calls all New() for all sub-systems.
|
|
|
|
newAllSubsystems()
|
|
|
|
|
2019-11-09 09:27:23 -08:00
|
|
|
// Once endpoints are finalized, initialize the new object api in safe mode.
|
|
|
|
globalObjLayerMutex.Lock()
|
|
|
|
globalObjectAPI = newObject
|
|
|
|
globalObjLayerMutex.Unlock()
|
|
|
|
|
2020-08-26 23:52:46 +08:00
|
|
|
if gatewayName == NASBackendGateway {
|
2020-04-09 09:30:02 -07:00
|
|
|
buckets, err := newObject.ListBuckets(GlobalContext)
|
2020-02-02 01:52:07 -08:00
|
|
|
if err != nil {
|
|
|
|
logger.Fatal(err, "Unable to list buckets")
|
|
|
|
}
|
2020-08-20 10:38:53 -07:00
|
|
|
logger.FatalIf(globalNotificationSys.Init(GlobalContext, buckets, newObject), "Unable to initialize notification system")
|
2018-12-18 10:42:09 -08:00
|
|
|
}
|
2018-10-12 12:25:59 -07:00
|
|
|
|
2021-07-10 08:32:52 -07:00
|
|
|
// Initialize users credentials and policies in background.
|
|
|
|
globalIAMSys.InitStore(newObject)
|
2020-10-19 09:54:40 -07:00
|
|
|
|
2021-07-10 08:32:52 -07:00
|
|
|
go globalIAMSys.Init(GlobalContext, newObject)
|
2018-10-09 14:00:01 -07:00
|
|
|
|
2019-11-09 09:27:23 -08:00
|
|
|
if globalCacheConfig.Enabled {
|
|
|
|
// initialize the new disk cache objects.
|
|
|
|
var cacheAPI CacheObjectLayer
|
2020-03-22 12:16:36 -07:00
|
|
|
cacheAPI, err = newServerCacheObjects(GlobalContext, globalCacheConfig)
|
2019-11-09 09:27:23 -08:00
|
|
|
logger.FatalIf(err, "Unable to initialize disk caching")
|
2019-07-19 13:20:33 -07:00
|
|
|
|
2019-11-09 09:27:23 -08:00
|
|
|
globalObjLayerMutex.Lock()
|
|
|
|
globalCacheObjectAPI = cacheAPI
|
|
|
|
globalObjLayerMutex.Unlock()
|
2019-10-30 23:39:09 -07:00
|
|
|
}
|
2018-12-14 22:35:48 +01:00
|
|
|
|
2019-12-17 13:50:07 -08:00
|
|
|
// Populate existing buckets to the etcd backend
|
|
|
|
if globalDNSConfig != nil {
|
2020-03-22 12:16:36 -07:00
|
|
|
buckets, err := newObject.ListBuckets(GlobalContext)
|
2019-12-17 13:50:07 -08:00
|
|
|
if err != nil {
|
|
|
|
logger.Fatal(err, "Unable to list buckets")
|
|
|
|
}
|
|
|
|
initFederatorBackend(buckets, newObject)
|
|
|
|
}
|
|
|
|
|
2019-07-26 02:41:16 -07:00
|
|
|
// Verify if object layer supports
|
|
|
|
// - encryption
|
|
|
|
// - compression
|
|
|
|
verifyObjectLayerFeatures("gateway "+gatewayName, newObject)
|
2018-12-14 22:35:48 +01:00
|
|
|
|
2017-03-16 12:21:58 -07:00
|
|
|
// Prints the formatted startup message once object layer is initialized.
|
2021-06-14 12:53:49 -07:00
|
|
|
if !globalCLIContext.Quiet && !globalInplaceUpdateDisabled {
|
2017-06-09 19:50:51 -07:00
|
|
|
// Check update mode.
|
2021-06-14 12:53:49 -07:00
|
|
|
checkUpdate(globalMinioModeGatewayPrefix + gatewayName)
|
|
|
|
}
|
2017-12-05 17:58:09 -08:00
|
|
|
|
2021-06-14 12:53:49 -07:00
|
|
|
if !globalCLIContext.Quiet {
|
2017-06-09 19:50:51 -07:00
|
|
|
// Print gateway startup message.
|
2018-12-13 23:37:46 -08:00
|
|
|
printGatewayStartupMessage(getAPIEndpoints(), gatewayName)
|
2017-03-16 12:21:58 -07:00
|
|
|
}
|
|
|
|
|
2021-06-17 20:27:04 -07:00
|
|
|
if globalBrowserEnabled {
|
|
|
|
consoleSrv, err := initConsoleServer()
|
|
|
|
if err != nil {
|
|
|
|
logger.FatalIf(err, "Unable to initialize console service")
|
|
|
|
}
|
|
|
|
|
|
|
|
go func() {
|
|
|
|
<-globalOSSignalCh
|
|
|
|
consoleSrv.Shutdown()
|
|
|
|
}()
|
|
|
|
|
|
|
|
consoleSrv.Serve()
|
|
|
|
} else {
|
|
|
|
<-globalOSSignalCh
|
|
|
|
}
|
2017-03-16 12:21:58 -07:00
|
|
|
}
|