mirror of
https://github.com/portainer/portainer.git
synced 2025-07-22 06:49:40 +02:00
* feat(edge): fix webconsole and agent deployment command * feat(edge): display agent features when connected to IoT endpoint * feat(edge): add -e CAP_HOST_MANAGEMENT=1 to agent command * feat(edge): add -v /:/host and --name portainer_agent_iot to agent command * style(endpoint-creation): refactor IoT agent to Edge agent * refactor(api): rename AgentIoTEnvironment to AgentEdgeEnvironment * refactor(api): rename AgentIoTEnvironment to AgentEdgeEnvironment * feat(endpoint-creation): update Edge agent deployment instructions * feat(edge): wip edge * feat(edge): refactor key creation * feat(edge): update deployment instructions * feat(home): update Edge agent endpoint item * feat(edge): support dynamic ports * feat(edge): support sleep/wake and snapshots * feat(edge): support offline mode * feat(edge): host job support for Edge endpoints * feat(edge): introduce STANDBY state * feat(edge): update Edge agent deployment command * feat(edge): introduce EDGE_ID support * feat(edge): update default inactivity interval to 5min * feat(edge): reload Edge schedules after restart * fix(edge): fix execution of endpoint job against an Edge endpoint * fix(edge): fix minor issues with scheduling UI/UX * feat(edge): introduce EdgeSchedule version management * feat(edge): switch back to REQUIRED state from ACTIVE on error * refactor(edge): remove comment * feat(edge): updated tunnel status management * feat(edge): fix flickering UI when accessing Edge endpoint from home view * feat(edge): remove STANDBY status * fix(edge): fix an issue with console and Swarm endpoint * fix(edge): fix an issue with stack deployment * fix(edge): reset timer when applying active status * feat(edge): add background ping for Edge endpoints * fix(edge): fix infinite loading loop after Edge endpoint connection failure * fix(home): fix an issue with merge * feat(api): remove SnapshotRaw from EndpointList response * feat(api): add pagination for EndpointList operation * feat(api): rename last_id query parameter to start * feat(api): implement filter for EndpointList operation * fix(edge): prevent a pointer issue after removing an active Edge endpoint * feat(home): front - endpoint backend pagination (#2990) * feat(home): endpoint pagination with backend * feat(api): remove default limit value * fix(endpoints): fix a minor issue with column span * fix(endpointgroup-create): fix an issue with endpoint group creation * feat(app): minor loading optimizations * refactor(api): small refactor of EndpointList operation * fix(home): fix minor loading text display issue * refactor(api): document bolt services functions * feat(home): minor optimization * fix(api): replace seek with index scanning for EndpointPaginated * fix(api): fix invalid starting index issue * fix(api): first implementation of working filter * fix(home): endpoints list keeps backend pagination when it needs to * fix(api): endpoint pagination doesn't drop the first item on pages >=2 anymore * fix(home): UI flickering on page/filter load/change * feat(auth): login spinner * feat(api): support searching in associated endpoint group data * refactor(api): remove unused API endpoint * refactor(api): remove comment * refactor(api): refactor proxy manager * feat(api): declare EndpointList params as optional * feat(api): support groupID filter on endpoints route * feat(api): add new API operations endpointGroupAddEndpoint and endpointGroupDeleteEndpoint * feat(edge): new icon for Edge agent endpoint * fix(edge): fix missing exec quick action * fix(edge): add loading indicator when connecting to Edge endpoint * feat(edge): disable service webhooks for Edge endpoints * feat(endpoints): backend pagination for endpoints view (#3004) * feat(edge): dynamic loading for stack migration feature * feat(edge): wordwrap edge key * feat(endpoint-groups): backend pagination support for create and edit * feat(endpoint-groups): debounce on filter for create/edit views * feat(endpoint-groups): filter assigned on create view * (endpoint-groups): unassigned endpoints edit view * refactor(endpoint-groups): code clean * feat(endpoint-groups): remove message for Unassigned group * refactor(websocket): minor refactor associated to Edge agent * feat(endpoint-group): enable backend pagination (#3017) * feat(api): support groupID filter on endpoints route * feat(api): add new API operations endpointGroupAddEndpoint and endpointGroupDeleteEndpoint * feat(endpoint-groups): backend pagination support for create and edit * feat(endpoint-groups): debounce on filter for create/edit views * feat(endpoint-groups): filter assigned on create view * (endpoint-groups): unassigned endpoints edit view * refactor(endpoint-groups): code clean * feat(endpoint-groups): remove message for Unassigned group * refactor(api): endpoint group endpoint association refactor * refactor(api): rename files and remove comments * refactor(api): remove usage of utils * refactor(api): optional parameters * Merge branch 'feat-endpoint-backend-pagination' into edge # Conflicts: # api/bolt/endpoint/endpoint.go # api/http/handler/endpointgroups/endpointgroup_update.go # api/http/handler/endpointgroups/handler.go # api/http/handler/endpoints/endpoint_list.go # app/portainer/services/api/endpointService.js * fix(api): fix default tunnel server credentials * feat(api): update endpointListOperation behavior and parameters * fix(api): fix interface declaration * feat(edge): support configurable Edge agent checkin interval * feat(edge): support dynamic tunnel credentials * feat(edge): update Edge agent deployment commands * style(edge): update Edge agent settings text * refactor(edge): remove unused credentials management methods * feat(edge): associate a remote addr to tunnel credentials * style(edge): update Edge endpoint icon * feat(edge): support encrypted tunnel credentials * fix(edge): fix invalid pointer cast * feat(bolt): decode endpoints with jsoniter * feat(edge): persist reverse tunnel keyseed * refactor(edge): minor refactor * feat(edge): update chisel library usage * refactor(endpoint): use controller function * feat(api): database migration to DBVersion 19 * refactor(api): refactor AddSchedule function * refactor(schedules): remove comment * refactor(api): remove comment * refactor(api): remove comment * feat(api): tunnel manager now only manage Edge endpoints * refactor(api): clean-up and clarification of the Edge service * refactor(api): clean-up and clarification of the Edge service * fix(api): fix an issue with Edge agent snapshots * refactor(api): add missing comments * refactor(api): update constant description * style(home): remove loading text on error * feat(endpoint): remove 15s timeout for ping request * style(home): display information about associated Edge endpoints * feat(home): redirect to endpoint details on click on unassociated Edge endpoint * feat(settings): remove 60s Edge poll frequency option
263 lines
12 KiB
Go
263 lines
12 KiB
Go
package http
|
|
|
|
import (
|
|
"time"
|
|
|
|
"github.com/portainer/portainer/api/http/handler/roles"
|
|
|
|
"github.com/portainer/portainer/api"
|
|
"github.com/portainer/portainer/api/docker"
|
|
"github.com/portainer/portainer/api/http/handler"
|
|
"github.com/portainer/portainer/api/http/handler/auth"
|
|
"github.com/portainer/portainer/api/http/handler/dockerhub"
|
|
"github.com/portainer/portainer/api/http/handler/endpointgroups"
|
|
"github.com/portainer/portainer/api/http/handler/endpointproxy"
|
|
"github.com/portainer/portainer/api/http/handler/endpoints"
|
|
"github.com/portainer/portainer/api/http/handler/extensions"
|
|
"github.com/portainer/portainer/api/http/handler/file"
|
|
"github.com/portainer/portainer/api/http/handler/motd"
|
|
"github.com/portainer/portainer/api/http/handler/registries"
|
|
"github.com/portainer/portainer/api/http/handler/resourcecontrols"
|
|
"github.com/portainer/portainer/api/http/handler/schedules"
|
|
"github.com/portainer/portainer/api/http/handler/settings"
|
|
"github.com/portainer/portainer/api/http/handler/stacks"
|
|
"github.com/portainer/portainer/api/http/handler/status"
|
|
"github.com/portainer/portainer/api/http/handler/tags"
|
|
"github.com/portainer/portainer/api/http/handler/teammemberships"
|
|
"github.com/portainer/portainer/api/http/handler/teams"
|
|
"github.com/portainer/portainer/api/http/handler/templates"
|
|
"github.com/portainer/portainer/api/http/handler/upload"
|
|
"github.com/portainer/portainer/api/http/handler/users"
|
|
"github.com/portainer/portainer/api/http/handler/webhooks"
|
|
"github.com/portainer/portainer/api/http/handler/websocket"
|
|
"github.com/portainer/portainer/api/http/proxy"
|
|
"github.com/portainer/portainer/api/http/security"
|
|
|
|
"net/http"
|
|
"path/filepath"
|
|
)
|
|
|
|
// Server implements the portainer.Server interface
|
|
type Server struct {
|
|
BindAddress string
|
|
AssetsPath string
|
|
AuthDisabled bool
|
|
EndpointManagement bool
|
|
Status *portainer.Status
|
|
ReverseTunnelService portainer.ReverseTunnelService
|
|
ExtensionManager portainer.ExtensionManager
|
|
ComposeStackManager portainer.ComposeStackManager
|
|
CryptoService portainer.CryptoService
|
|
SignatureService portainer.DigitalSignatureService
|
|
JobScheduler portainer.JobScheduler
|
|
Snapshotter portainer.Snapshotter
|
|
RoleService portainer.RoleService
|
|
DockerHubService portainer.DockerHubService
|
|
EndpointService portainer.EndpointService
|
|
EndpointGroupService portainer.EndpointGroupService
|
|
FileService portainer.FileService
|
|
GitService portainer.GitService
|
|
JWTService portainer.JWTService
|
|
LDAPService portainer.LDAPService
|
|
ExtensionService portainer.ExtensionService
|
|
RegistryService portainer.RegistryService
|
|
ResourceControlService portainer.ResourceControlService
|
|
ScheduleService portainer.ScheduleService
|
|
SettingsService portainer.SettingsService
|
|
StackService portainer.StackService
|
|
SwarmStackManager portainer.SwarmStackManager
|
|
TagService portainer.TagService
|
|
TeamService portainer.TeamService
|
|
TeamMembershipService portainer.TeamMembershipService
|
|
TemplateService portainer.TemplateService
|
|
UserService portainer.UserService
|
|
WebhookService portainer.WebhookService
|
|
Handler *handler.Handler
|
|
SSL bool
|
|
SSLCert string
|
|
SSLKey string
|
|
DockerClientFactory *docker.ClientFactory
|
|
JobService portainer.JobService
|
|
}
|
|
|
|
// Start starts the HTTP server
|
|
func (server *Server) Start() error {
|
|
proxyManagerParameters := &proxy.ManagerParams{
|
|
ResourceControlService: server.ResourceControlService,
|
|
TeamMembershipService: server.TeamMembershipService,
|
|
SettingsService: server.SettingsService,
|
|
RegistryService: server.RegistryService,
|
|
DockerHubService: server.DockerHubService,
|
|
SignatureService: server.SignatureService,
|
|
ReverseTunnelService: server.ReverseTunnelService,
|
|
}
|
|
proxyManager := proxy.NewManager(proxyManagerParameters)
|
|
|
|
requestBouncerParameters := &security.RequestBouncerParams{
|
|
JWTService: server.JWTService,
|
|
UserService: server.UserService,
|
|
TeamMembershipService: server.TeamMembershipService,
|
|
EndpointService: server.EndpointService,
|
|
EndpointGroupService: server.EndpointGroupService,
|
|
ExtensionService: server.ExtensionService,
|
|
RBACExtensionURL: proxyManager.GetExtensionURL(portainer.RBACExtension),
|
|
AuthDisabled: server.AuthDisabled,
|
|
}
|
|
requestBouncer := security.NewRequestBouncer(requestBouncerParameters)
|
|
|
|
rateLimiter := security.NewRateLimiter(10, 1*time.Second, 1*time.Hour)
|
|
|
|
var authHandler = auth.NewHandler(requestBouncer, rateLimiter, server.AuthDisabled)
|
|
authHandler.UserService = server.UserService
|
|
authHandler.CryptoService = server.CryptoService
|
|
authHandler.JWTService = server.JWTService
|
|
authHandler.LDAPService = server.LDAPService
|
|
authHandler.SettingsService = server.SettingsService
|
|
authHandler.TeamService = server.TeamService
|
|
authHandler.TeamMembershipService = server.TeamMembershipService
|
|
authHandler.ExtensionService = server.ExtensionService
|
|
authHandler.EndpointService = server.EndpointService
|
|
authHandler.EndpointGroupService = server.EndpointGroupService
|
|
authHandler.RoleService = server.RoleService
|
|
authHandler.ProxyManager = proxyManager
|
|
|
|
var roleHandler = roles.NewHandler(requestBouncer)
|
|
roleHandler.RoleService = server.RoleService
|
|
|
|
var dockerHubHandler = dockerhub.NewHandler(requestBouncer)
|
|
dockerHubHandler.DockerHubService = server.DockerHubService
|
|
|
|
var endpointHandler = endpoints.NewHandler(requestBouncer, server.EndpointManagement)
|
|
endpointHandler.EndpointService = server.EndpointService
|
|
endpointHandler.EndpointGroupService = server.EndpointGroupService
|
|
endpointHandler.FileService = server.FileService
|
|
endpointHandler.ProxyManager = proxyManager
|
|
endpointHandler.Snapshotter = server.Snapshotter
|
|
endpointHandler.JobService = server.JobService
|
|
endpointHandler.ReverseTunnelService = server.ReverseTunnelService
|
|
endpointHandler.SettingsService = server.SettingsService
|
|
|
|
var endpointGroupHandler = endpointgroups.NewHandler(requestBouncer)
|
|
endpointGroupHandler.EndpointGroupService = server.EndpointGroupService
|
|
endpointGroupHandler.EndpointService = server.EndpointService
|
|
|
|
var endpointProxyHandler = endpointproxy.NewHandler(requestBouncer)
|
|
endpointProxyHandler.EndpointService = server.EndpointService
|
|
endpointProxyHandler.ProxyManager = proxyManager
|
|
endpointProxyHandler.SettingsService = server.SettingsService
|
|
endpointProxyHandler.ReverseTunnelService = server.ReverseTunnelService
|
|
|
|
var fileHandler = file.NewHandler(filepath.Join(server.AssetsPath, "public"))
|
|
|
|
var motdHandler = motd.NewHandler(requestBouncer)
|
|
|
|
var extensionHandler = extensions.NewHandler(requestBouncer)
|
|
extensionHandler.ExtensionService = server.ExtensionService
|
|
extensionHandler.ExtensionManager = server.ExtensionManager
|
|
extensionHandler.EndpointGroupService = server.EndpointGroupService
|
|
extensionHandler.EndpointService = server.EndpointService
|
|
extensionHandler.RegistryService = server.RegistryService
|
|
|
|
var registryHandler = registries.NewHandler(requestBouncer)
|
|
registryHandler.RegistryService = server.RegistryService
|
|
registryHandler.ExtensionService = server.ExtensionService
|
|
registryHandler.FileService = server.FileService
|
|
registryHandler.ProxyManager = proxyManager
|
|
|
|
var resourceControlHandler = resourcecontrols.NewHandler(requestBouncer)
|
|
resourceControlHandler.ResourceControlService = server.ResourceControlService
|
|
|
|
var schedulesHandler = schedules.NewHandler(requestBouncer)
|
|
schedulesHandler.ScheduleService = server.ScheduleService
|
|
schedulesHandler.EndpointService = server.EndpointService
|
|
schedulesHandler.FileService = server.FileService
|
|
schedulesHandler.JobService = server.JobService
|
|
schedulesHandler.JobScheduler = server.JobScheduler
|
|
schedulesHandler.SettingsService = server.SettingsService
|
|
schedulesHandler.ReverseTunnelService = server.ReverseTunnelService
|
|
|
|
var settingsHandler = settings.NewHandler(requestBouncer)
|
|
settingsHandler.SettingsService = server.SettingsService
|
|
settingsHandler.LDAPService = server.LDAPService
|
|
settingsHandler.FileService = server.FileService
|
|
settingsHandler.JobScheduler = server.JobScheduler
|
|
settingsHandler.ScheduleService = server.ScheduleService
|
|
|
|
var stackHandler = stacks.NewHandler(requestBouncer)
|
|
stackHandler.FileService = server.FileService
|
|
stackHandler.StackService = server.StackService
|
|
stackHandler.EndpointService = server.EndpointService
|
|
stackHandler.ResourceControlService = server.ResourceControlService
|
|
stackHandler.SwarmStackManager = server.SwarmStackManager
|
|
stackHandler.ComposeStackManager = server.ComposeStackManager
|
|
stackHandler.GitService = server.GitService
|
|
stackHandler.RegistryService = server.RegistryService
|
|
stackHandler.DockerHubService = server.DockerHubService
|
|
|
|
var tagHandler = tags.NewHandler(requestBouncer)
|
|
tagHandler.TagService = server.TagService
|
|
|
|
var teamHandler = teams.NewHandler(requestBouncer)
|
|
teamHandler.TeamService = server.TeamService
|
|
teamHandler.TeamMembershipService = server.TeamMembershipService
|
|
|
|
var teamMembershipHandler = teammemberships.NewHandler(requestBouncer)
|
|
teamMembershipHandler.TeamMembershipService = server.TeamMembershipService
|
|
var statusHandler = status.NewHandler(requestBouncer, server.Status)
|
|
|
|
var templatesHandler = templates.NewHandler(requestBouncer)
|
|
templatesHandler.TemplateService = server.TemplateService
|
|
templatesHandler.SettingsService = server.SettingsService
|
|
|
|
var uploadHandler = upload.NewHandler(requestBouncer)
|
|
uploadHandler.FileService = server.FileService
|
|
|
|
var userHandler = users.NewHandler(requestBouncer, rateLimiter)
|
|
userHandler.UserService = server.UserService
|
|
userHandler.TeamService = server.TeamService
|
|
userHandler.TeamMembershipService = server.TeamMembershipService
|
|
userHandler.CryptoService = server.CryptoService
|
|
userHandler.ResourceControlService = server.ResourceControlService
|
|
userHandler.SettingsService = server.SettingsService
|
|
|
|
var websocketHandler = websocket.NewHandler(requestBouncer)
|
|
websocketHandler.EndpointService = server.EndpointService
|
|
websocketHandler.SignatureService = server.SignatureService
|
|
websocketHandler.ReverseTunnelService = server.ReverseTunnelService
|
|
|
|
var webhookHandler = webhooks.NewHandler(requestBouncer)
|
|
webhookHandler.WebhookService = server.WebhookService
|
|
webhookHandler.EndpointService = server.EndpointService
|
|
webhookHandler.DockerClientFactory = server.DockerClientFactory
|
|
|
|
server.Handler = &handler.Handler{
|
|
RoleHandler: roleHandler,
|
|
AuthHandler: authHandler,
|
|
DockerHubHandler: dockerHubHandler,
|
|
EndpointGroupHandler: endpointGroupHandler,
|
|
EndpointHandler: endpointHandler,
|
|
EndpointProxyHandler: endpointProxyHandler,
|
|
FileHandler: fileHandler,
|
|
MOTDHandler: motdHandler,
|
|
ExtensionHandler: extensionHandler,
|
|
RegistryHandler: registryHandler,
|
|
ResourceControlHandler: resourceControlHandler,
|
|
SettingsHandler: settingsHandler,
|
|
StatusHandler: statusHandler,
|
|
StackHandler: stackHandler,
|
|
TagHandler: tagHandler,
|
|
TeamHandler: teamHandler,
|
|
TeamMembershipHandler: teamMembershipHandler,
|
|
TemplatesHandler: templatesHandler,
|
|
UploadHandler: uploadHandler,
|
|
UserHandler: userHandler,
|
|
WebSocketHandler: websocketHandler,
|
|
WebhookHandler: webhookHandler,
|
|
SchedulesHanlder: schedulesHandler,
|
|
}
|
|
|
|
if server.SSL {
|
|
return http.ListenAndServeTLS(server.BindAddress, server.SSLCert, server.SSLKey, server.Handler)
|
|
}
|
|
return http.ListenAndServe(server.BindAddress, server.Handler)
|
|
}
|