diff --git a/.github/ISSUE_TEMPLATE/bug-report.yml b/.github/ISSUE_TEMPLATE/bug-report.yml index b57a4b134..107322995 100644 --- a/.github/ISSUE_TEMPLATE/bug-report.yml +++ b/.github/ISSUE_TEMPLATE/bug-report.yml @@ -31,6 +31,7 @@ body: label: Version description: What version are you running? options: + - v0.21.1 - v0.21.0 - v0.20.6 - v0.20.5 diff --git a/.github/workflows/branchtest.yml b/.github/workflows/branchtest.yml index ed545dee2..d2b22a051 100644 --- a/.github/workflows/branchtest.yml +++ b/.github/workflows/branchtest.yml @@ -25,7 +25,7 @@ jobs: netclientbranch: ${{ steps.getbranch.outputs.netclientbranch }} steps: - name: checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 with: repository: gravitl/netclient ref: develop diff --git a/.github/workflows/docker-builder.yml b/.github/workflows/docker-builder.yml index d68143371..69373f882 100644 --- a/.github/workflows/docker-builder.yml +++ b/.github/workflows/docker-builder.yml @@ -11,16 +11,16 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: SetUp Buildx - uses: docker/setup-buildx-action@v2 + uses: docker/setup-buildx-action@v3 - name: Login to Dockerhub - uses: docker/login-action@v2 + uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Build and push to docker hub - uses: docker/build-push-action@v3 + uses: docker/build-push-action@v5 with: context: . push: true diff --git a/.github/workflows/publish-docker.yml b/.github/workflows/publish-docker.yml index fcf709ffd..889bcd8a3 100644 --- a/.github/workflows/publish-docker.yml +++ b/.github/workflows/publish-docker.yml @@ -29,22 +29,22 @@ jobs: echo "TAG=${TAG}" >> $GITHUB_ENV - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Set up QEMU - uses: docker/setup-qemu-action@v2 + uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v2 + uses: docker/setup-buildx-action@v3 - name: Login to DockerHub - uses: docker/login-action@v2 + uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Build and push - uses: docker/build-push-action@v3 + uses: docker/build-push-action@v5 with: context: . platforms: linux/amd64, linux/arm64, linux/arm/v7 @@ -69,22 +69,22 @@ jobs: echo "TAG=${TAG}" >> $GITHUB_ENV - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Set up QEMU - uses: docker/setup-qemu-action@v2 + uses: docker/setup-qemu-action@v3 - name: Set up Docker Buildx - uses: docker/setup-buildx-action@v2 + uses: docker/setup-buildx-action@v3 - name: Login to DockerHub - uses: docker/login-action@v2 + uses: docker/login-action@v3 with: username: ${{ secrets.DOCKERHUB_USERNAME }} password: ${{ secrets.DOCKERHUB_TOKEN }} - name: Build and push - uses: docker/build-push-action@v3 + uses: docker/build-push-action@v5 with: context: . platforms: linux/amd64, linux/arm64 diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 072f07b24..3536088de 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -11,7 +11,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Setup Go uses: actions/setup-go@v4 with: @@ -25,7 +25,7 @@ jobs: runs-on: ubuntu-latest steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Setup go uses: actions/setup-go@v4 with: @@ -42,7 +42,7 @@ jobs: runs-on: ubuntu-22.04 steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Setup Go uses: actions/setup-go@v4 with: @@ -62,7 +62,7 @@ jobs: runs-on: ubuntu-22.04 steps: - name: Checkout - uses: actions/checkout@v3 + uses: actions/checkout@v4 - name: Setup Go uses: actions/setup-go@v4 with: diff --git a/Dockerfile b/Dockerfile index 1c5cefaad..f6df8e6f5 100644 --- a/Dockerfile +++ b/Dockerfile @@ -6,7 +6,7 @@ COPY . . RUN GOOS=linux CGO_ENABLED=1 go build -ldflags="-s -w " -tags ${tags} . # RUN go build -tags=ee . -o netmaker main.go -FROM alpine:3.18.3 +FROM alpine:3.18.4 # add a c lib # set the working directory diff --git a/Dockerfile-quick b/Dockerfile-quick index 9502f335c..cf53bdba5 100644 --- a/Dockerfile-quick +++ b/Dockerfile-quick @@ -1,5 +1,5 @@ #first stage - builder -FROM alpine:3.18.3 +FROM alpine:3.18.4 ARG version WORKDIR /app COPY ./netmaker /root/netmaker diff --git a/LICENSE.md b/LICENSE.md new file mode 100644 index 000000000..1aeafe3f4 --- /dev/null +++ b/LICENSE.md @@ -0,0 +1,203 @@ +Copyright (c) 2023 Netmaker,Inc. + +Portions of this software are licensed as follows: + +* All content that resides under the "pro/" directory of this repository, if that directory exists, is licensed under the license defined in "pro/LICENSE". +* All third party components incorporated into the Netmaker Software are licensed under the original license provided by the owner of the applicable component. +* Content outside of the above mentioned directories or restrictions above is available under the "Apache Version 2.0" license as defined below. + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [2023] Netmaker,Inc. + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/LICENSE.txt b/LICENSE.txt deleted file mode 100644 index 4e1383df1..000000000 --- a/LICENSE.txt +++ /dev/null @@ -1,557 +0,0 @@ - Server Side Public License - VERSION 1, OCTOBER 16, 2018 - - Copyright © 2018 MongoDB, Inc. - - Everyone is permitted to copy and distribute verbatim copies of this - license document, but changing it is not allowed. - - TERMS AND CONDITIONS - - 0. Definitions. - - “This License” refers to Server Side Public License. - - “Copyright” also means copyright-like laws that apply to other kinds of - works, such as semiconductor masks. - - “The Program” refers to any copyrightable work licensed under this - License. Each licensee is addressed as “you”. “Licensees” and - “recipients” may be individuals or organizations. - - To “modify” a work means to copy from or adapt all or part of the work in - a fashion requiring copyright permission, other than the making of an - exact copy. The resulting work is called a “modified version” of the - earlier work or a work “based on” the earlier work. - - A “covered work” means either the unmodified Program or a work based on - the Program. - - To “propagate” a work means to do anything with it that, without - permission, would make you directly or secondarily liable for - infringement under applicable copyright law, except executing it on a - computer or modifying a private copy. Propagation includes copying, - distribution (with or without modification), making available to the - public, and in some countries other activities as well. - - To “convey” a work means any kind of propagation that enables other - parties to make or receive copies. Mere interaction with a user through a - computer network, with no transfer of a copy, is not conveying. - - An interactive user interface displays “Appropriate Legal Notices” to the - extent that it includes a convenient and prominently visible feature that - (1) displays an appropriate copyright notice, and (2) tells the user that - there is no warranty for the work (except to the extent that warranties - are provided), that licensees may convey the work under this License, and - how to view a copy of this License. If the interface presents a list of - user commands or options, such as a menu, a prominent item in the list - meets this criterion. - - 1. Source Code. - - The “source code” for a work means the preferred form of the work for - making modifications to it. “Object code” means any non-source form of a - work. - - A “Standard Interface” means an interface that either is an official - standard defined by a recognized standards body, or, in the case of - interfaces specified for a particular programming language, one that is - widely used among developers working in that language. The “System - Libraries” of an executable work include anything, other than the work as - a whole, that (a) is included in the normal form of packaging a Major - Component, but which is not part of that Major Component, and (b) serves - only to enable use of the work with that Major Component, or to implement - a Standard Interface for which an implementation is available to the - public in source code form. A “Major Component”, in this context, means a - major essential component (kernel, window system, and so on) of the - specific operating system (if any) on which the executable work runs, or - a compiler used to produce the work, or an object code interpreter used - to run it. - - The “Corresponding Source” for a work in object code form means all the - source code needed to generate, install, and (for an executable work) run - the object code and to modify the work, including scripts to control - those activities. However, it does not include the work's System - Libraries, or general-purpose tools or generally available free programs - which are used unmodified in performing those activities but which are - not part of the work. For example, Corresponding Source includes - interface definition files associated with source files for the work, and - the source code for shared libraries and dynamically linked subprograms - that the work is specifically designed to require, such as by intimate - data communication or control flow between those subprograms and other - parts of the work. - - The Corresponding Source need not include anything that users can - regenerate automatically from other parts of the Corresponding Source. - - The Corresponding Source for a work in source code form is that same work. - - 2. Basic Permissions. - - All rights granted under this License are granted for the term of - copyright on the Program, and are irrevocable provided the stated - conditions are met. This License explicitly affirms your unlimited - permission to run the unmodified Program, subject to section 13. The - output from running a covered work is covered by this License only if the - output, given its content, constitutes a covered work. This License - acknowledges your rights of fair use or other equivalent, as provided by - copyright law. Subject to section 13, you may make, run and propagate - covered works that you do not convey, without conditions so long as your - license otherwise remains in force. You may convey covered works to - others for the sole purpose of having them make modifications exclusively - for you, or provide you with facilities for running those works, provided - that you comply with the terms of this License in conveying all - material for which you do not control copyright. Those thus making or - running the covered works for you must do so exclusively on your - behalf, under your direction and control, on terms that prohibit them - from making any copies of your copyrighted material outside their - relationship with you. - - Conveying under any other circumstances is permitted solely under the - conditions stated below. Sublicensing is not allowed; section 10 makes it - unnecessary. - - 3. Protecting Users' Legal Rights From Anti-Circumvention Law. - - No covered work shall be deemed part of an effective technological - measure under any applicable law fulfilling obligations under article 11 - of the WIPO copyright treaty adopted on 20 December 1996, or similar laws - prohibiting or restricting circumvention of such measures. - - When you convey a covered work, you waive any legal power to forbid - circumvention of technological measures to the extent such circumvention is - effected by exercising rights under this License with respect to the - covered work, and you disclaim any intention to limit operation or - modification of the work as a means of enforcing, against the work's users, - your or third parties' legal rights to forbid circumvention of - technological measures. - - 4. Conveying Verbatim Copies. - - You may convey verbatim copies of the Program's source code as you - receive it, in any medium, provided that you conspicuously and - appropriately publish on each copy an appropriate copyright notice; keep - intact all notices stating that this License and any non-permissive terms - added in accord with section 7 apply to the code; keep intact all notices - of the absence of any warranty; and give all recipients a copy of this - License along with the Program. You may charge any price or no price for - each copy that you convey, and you may offer support or warranty - protection for a fee. - - 5. Conveying Modified Source Versions. - - You may convey a work based on the Program, or the modifications to - produce it from the Program, in the form of source code under the terms - of section 4, provided that you also meet all of these conditions: - - a) The work must carry prominent notices stating that you modified it, - and giving a relevant date. - - b) The work must carry prominent notices stating that it is released - under this License and any conditions added under section 7. This - requirement modifies the requirement in section 4 to “keep intact all - notices”. - - c) You must license the entire work, as a whole, under this License to - anyone who comes into possession of a copy. This License will therefore - apply, along with any applicable section 7 additional terms, to the - whole of the work, and all its parts, regardless of how they are - packaged. This License gives no permission to license the work in any - other way, but it does not invalidate such permission if you have - separately received it. - - d) If the work has interactive user interfaces, each must display - Appropriate Legal Notices; however, if the Program has interactive - interfaces that do not display Appropriate Legal Notices, your work - need not make them do so. - - A compilation of a covered work with other separate and independent - works, which are not by their nature extensions of the covered work, and - which are not combined with it such as to form a larger program, in or on - a volume of a storage or distribution medium, is called an “aggregate” if - the compilation and its resulting copyright are not used to limit the - access or legal rights of the compilation's users beyond what the - individual works permit. Inclusion of a covered work in an aggregate does - not cause this License to apply to the other parts of the aggregate. - - 6. Conveying Non-Source Forms. - - You may convey a covered work in object code form under the terms of - sections 4 and 5, provided that you also convey the machine-readable - Corresponding Source under the terms of this License, in one of these - ways: - - a) Convey the object code in, or embodied in, a physical product - (including a physical distribution medium), accompanied by the - Corresponding Source fixed on a durable physical medium customarily - used for software interchange. - - b) Convey the object code in, or embodied in, a physical product - (including a physical distribution medium), accompanied by a written - offer, valid for at least three years and valid for as long as you - offer spare parts or customer support for that product model, to give - anyone who possesses the object code either (1) a copy of the - Corresponding Source for all the software in the product that is - covered by this License, on a durable physical medium customarily used - for software interchange, for a price no more than your reasonable cost - of physically performing this conveying of source, or (2) access to - copy the Corresponding Source from a network server at no charge. - - c) Convey individual copies of the object code with a copy of the - written offer to provide the Corresponding Source. This alternative is - allowed only occasionally and noncommercially, and only if you received - the object code with such an offer, in accord with subsection 6b. - - d) Convey the object code by offering access from a designated place - (gratis or for a charge), and offer equivalent access to the - Corresponding Source in the same way through the same place at no - further charge. You need not require recipients to copy the - Corresponding Source along with the object code. If the place to copy - the object code is a network server, the Corresponding Source may be on - a different server (operated by you or a third party) that supports - equivalent copying facilities, provided you maintain clear directions - next to the object code saying where to find the Corresponding Source. - Regardless of what server hosts the Corresponding Source, you remain - obligated to ensure that it is available for as long as needed to - satisfy these requirements. - - e) Convey the object code using peer-to-peer transmission, provided you - inform other peers where the object code and Corresponding Source of - the work are being offered to the general public at no charge under - subsection 6d. - - A separable portion of the object code, whose source code is excluded - from the Corresponding Source as a System Library, need not be included - in conveying the object code work. - - A “User Product” is either (1) a “consumer product”, which means any - tangible personal property which is normally used for personal, family, - or household purposes, or (2) anything designed or sold for incorporation - into a dwelling. In determining whether a product is a consumer product, - doubtful cases shall be resolved in favor of coverage. For a particular - product received by a particular user, “normally used” refers to a - typical or common use of that class of product, regardless of the status - of the particular user or of the way in which the particular user - actually uses, or expects or is expected to use, the product. A product - is a consumer product regardless of whether the product has substantial - commercial, industrial or non-consumer uses, unless such uses represent - the only significant mode of use of the product. - - “Installation Information” for a User Product means any methods, - procedures, authorization keys, or other information required to install - and execute modified versions of a covered work in that User Product from - a modified version of its Corresponding Source. The information must - suffice to ensure that the continued functioning of the modified object - code is in no case prevented or interfered with solely because - modification has been made. - - If you convey an object code work under this section in, or with, or - specifically for use in, a User Product, and the conveying occurs as part - of a transaction in which the right of possession and use of the User - Product is transferred to the recipient in perpetuity or for a fixed term - (regardless of how the transaction is characterized), the Corresponding - Source conveyed under this section must be accompanied by the - Installation Information. But this requirement does not apply if neither - you nor any third party retains the ability to install modified object - code on the User Product (for example, the work has been installed in - ROM). - - The requirement to provide Installation Information does not include a - requirement to continue to provide support service, warranty, or updates - for a work that has been modified or installed by the recipient, or for - the User Product in which it has been modified or installed. Access - to a network may be denied when the modification itself materially - and adversely affects the operation of the network or violates the - rules and protocols for communication across the network. - - Corresponding Source conveyed, and Installation Information provided, in - accord with this section must be in a format that is publicly documented - (and with an implementation available to the public in source code form), - and must require no special password or key for unpacking, reading or - copying. - - 7. Additional Terms. - - “Additional permissions” are terms that supplement the terms of this - License by making exceptions from one or more of its conditions. - Additional permissions that are applicable to the entire Program shall be - treated as though they were included in this License, to the extent that - they are valid under applicable law. If additional permissions apply only - to part of the Program, that part may be used separately under those - permissions, but the entire Program remains governed by this License - without regard to the additional permissions. When you convey a copy of - a covered work, you may at your option remove any additional permissions - from that copy, or from any part of it. (Additional permissions may be - written to require their own removal in certain cases when you modify the - work.) You may place additional permissions on material, added by you to - a covered work, for which you have or can give appropriate copyright - permission. - - Notwithstanding any other provision of this License, for material you add - to a covered work, you may (if authorized by the copyright holders of - that material) supplement the terms of this License with terms: - - a) Disclaiming warranty or limiting liability differently from the - terms of sections 15 and 16 of this License; or - - b) Requiring preservation of specified reasonable legal notices or - author attributions in that material or in the Appropriate Legal - Notices displayed by works containing it; or - - c) Prohibiting misrepresentation of the origin of that material, or - requiring that modified versions of such material be marked in - reasonable ways as different from the original version; or - - d) Limiting the use for publicity purposes of names of licensors or - authors of the material; or - - e) Declining to grant rights under trademark law for use of some trade - names, trademarks, or service marks; or - - f) Requiring indemnification of licensors and authors of that material - by anyone who conveys the material (or modified versions of it) with - contractual assumptions of liability to the recipient, for any - liability that these contractual assumptions directly impose on those - licensors and authors. - - All other non-permissive additional terms are considered “further - restrictions” within the meaning of section 10. If the Program as you - received it, or any part of it, contains a notice stating that it is - governed by this License along with a term that is a further restriction, - you may remove that term. If a license document contains a further - restriction but permits relicensing or conveying under this License, you - may add to a covered work material governed by the terms of that license - document, provided that the further restriction does not survive such - relicensing or conveying. - - If you add terms to a covered work in accord with this section, you must - place, in the relevant source files, a statement of the additional terms - that apply to those files, or a notice indicating where to find the - applicable terms. Additional terms, permissive or non-permissive, may be - stated in the form of a separately written license, or stated as - exceptions; the above requirements apply either way. - - 8. Termination. - - You may not propagate or modify a covered work except as expressly - provided under this License. Any attempt otherwise to propagate or modify - it is void, and will automatically terminate your rights under this - License (including any patent licenses granted under the third paragraph - of section 11). - - However, if you cease all violation of this License, then your license - from a particular copyright holder is reinstated (a) provisionally, - unless and until the copyright holder explicitly and finally terminates - your license, and (b) permanently, if the copyright holder fails to - notify you of the violation by some reasonable means prior to 60 days - after the cessation. - - Moreover, your license from a particular copyright holder is reinstated - permanently if the copyright holder notifies you of the violation by some - reasonable means, this is the first time you have received notice of - violation of this License (for any work) from that copyright holder, and - you cure the violation prior to 30 days after your receipt of the notice. - - Termination of your rights under this section does not terminate the - licenses of parties who have received copies or rights from you under - this License. If your rights have been terminated and not permanently - reinstated, you do not qualify to receive new licenses for the same - material under section 10. - - 9. Acceptance Not Required for Having Copies. - - You are not required to accept this License in order to receive or run a - copy of the Program. Ancillary propagation of a covered work occurring - solely as a consequence of using peer-to-peer transmission to receive a - copy likewise does not require acceptance. However, nothing other than - this License grants you permission to propagate or modify any covered - work. These actions infringe copyright if you do not accept this License. - Therefore, by modifying or propagating a covered work, you indicate your - acceptance of this License to do so. - - 10. Automatic Licensing of Downstream Recipients. - - Each time you convey a covered work, the recipient automatically receives - a license from the original licensors, to run, modify and propagate that - work, subject to this License. You are not responsible for enforcing - compliance by third parties with this License. - - An “entity transaction” is a transaction transferring control of an - organization, or substantially all assets of one, or subdividing an - organization, or merging organizations. If propagation of a covered work - results from an entity transaction, each party to that transaction who - receives a copy of the work also receives whatever licenses to the work - the party's predecessor in interest had or could give under the previous - paragraph, plus a right to possession of the Corresponding Source of the - work from the predecessor in interest, if the predecessor has it or can - get it with reasonable efforts. - - You may not impose any further restrictions on the exercise of the rights - granted or affirmed under this License. For example, you may not impose a - license fee, royalty, or other charge for exercise of rights granted - under this License, and you may not initiate litigation (including a - cross-claim or counterclaim in a lawsuit) alleging that any patent claim - is infringed by making, using, selling, offering for sale, or importing - the Program or any portion of it. - - 11. Patents. - - A “contributor” is a copyright holder who authorizes use under this - License of the Program or a work on which the Program is based. The work - thus licensed is called the contributor's “contributor version”. - - A contributor's “essential patent claims” are all patent claims owned or - controlled by the contributor, whether already acquired or hereafter - acquired, that would be infringed by some manner, permitted by this - License, of making, using, or selling its contributor version, but do not - include claims that would be infringed only as a consequence of further - modification of the contributor version. For purposes of this definition, - “control” includes the right to grant patent sublicenses in a manner - consistent with the requirements of this License. - - Each contributor grants you a non-exclusive, worldwide, royalty-free - patent license under the contributor's essential patent claims, to make, - use, sell, offer for sale, import and otherwise run, modify and propagate - the contents of its contributor version. - - In the following three paragraphs, a “patent license” is any express - agreement or commitment, however denominated, not to enforce a patent - (such as an express permission to practice a patent or covenant not to - sue for patent infringement). To “grant” such a patent license to a party - means to make such an agreement or commitment not to enforce a patent - against the party. - - If you convey a covered work, knowingly relying on a patent license, and - the Corresponding Source of the work is not available for anyone to copy, - free of charge and under the terms of this License, through a publicly - available network server or other readily accessible means, then you must - either (1) cause the Corresponding Source to be so available, or (2) - arrange to deprive yourself of the benefit of the patent license for this - particular work, or (3) arrange, in a manner consistent with the - requirements of this License, to extend the patent license to downstream - recipients. “Knowingly relying” means you have actual knowledge that, but - for the patent license, your conveying the covered work in a country, or - your recipient's use of the covered work in a country, would infringe - one or more identifiable patents in that country that you have reason - to believe are valid. - - If, pursuant to or in connection with a single transaction or - arrangement, you convey, or propagate by procuring conveyance of, a - covered work, and grant a patent license to some of the parties receiving - the covered work authorizing them to use, propagate, modify or convey a - specific copy of the covered work, then the patent license you grant is - automatically extended to all recipients of the covered work and works - based on it. - - A patent license is “discriminatory” if it does not include within the - scope of its coverage, prohibits the exercise of, or is conditioned on - the non-exercise of one or more of the rights that are specifically - granted under this License. You may not convey a covered work if you are - a party to an arrangement with a third party that is in the business of - distributing software, under which you make payment to the third party - based on the extent of your activity of conveying the work, and under - which the third party grants, to any of the parties who would receive the - covered work from you, a discriminatory patent license (a) in connection - with copies of the covered work conveyed by you (or copies made from - those copies), or (b) primarily for and in connection with specific - products or compilations that contain the covered work, unless you - entered into that arrangement, or that patent license was granted, prior - to 28 March 2007. - - Nothing in this License shall be construed as excluding or limiting any - implied license or other defenses to infringement that may otherwise be - available to you under applicable patent law. - - 12. No Surrender of Others' Freedom. - - If conditions are imposed on you (whether by court order, agreement or - otherwise) that contradict the conditions of this License, they do not - excuse you from the conditions of this License. If you cannot use, - propagate or convey a covered work so as to satisfy simultaneously your - obligations under this License and any other pertinent obligations, then - as a consequence you may not use, propagate or convey it at all. For - example, if you agree to terms that obligate you to collect a royalty for - further conveying from those to whom you convey the Program, the only way - you could satisfy both those terms and this License would be to refrain - entirely from conveying the Program. - - 13. Offering the Program as a Service. - - If you make the functionality of the Program or a modified version - available to third parties as a service, you must make the Service Source - Code available via network download to everyone at no charge, under the - terms of this License. Making the functionality of the Program or - modified version available to third parties as a service includes, - without limitation, enabling third parties to interact with the - functionality of the Program or modified version remotely through a - computer network, offering a service the value of which entirely or - primarily derives from the value of the Program or modified version, or - offering a service that accomplishes for users the primary purpose of the - Program or modified version. - - “Service Source Code” means the Corresponding Source for the Program or - the modified version, and the Corresponding Source for all programs that - you use to make the Program or modified version available as a service, - including, without limitation, management software, user interfaces, - application program interfaces, automation software, monitoring software, - backup software, storage software and hosting software, all such that a - user could run an instance of the service using the Service Source Code - you make available. - - 14. Revised Versions of this License. - - MongoDB, Inc. may publish revised and/or new versions of the Server Side - Public License from time to time. Such new versions will be similar in - spirit to the present version, but may differ in detail to address new - problems or concerns. - - Each version is given a distinguishing version number. If the Program - specifies that a certain numbered version of the Server Side Public - License “or any later version” applies to it, you have the option of - following the terms and conditions either of that numbered version or of - any later version published by MongoDB, Inc. If the Program does not - specify a version number of the Server Side Public License, you may - choose any version ever published by MongoDB, Inc. - - If the Program specifies that a proxy can decide which future versions of - the Server Side Public License can be used, that proxy's public statement - of acceptance of a version permanently authorizes you to choose that - version for the Program. - - Later license versions may give you additional or different permissions. - However, no additional obligations are imposed on any author or copyright - holder as a result of your choosing to follow a later version. - - 15. Disclaimer of Warranty. - - THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY - APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT - HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY - OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, - THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR - PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM - IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF - ALL NECESSARY SERVICING, REPAIR OR CORRECTION. - - 16. Limitation of Liability. - - IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING - WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS - THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING - ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF - THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO - LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU - OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER - PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE - POSSIBILITY OF SUCH DAMAGES. - - 17. Interpretation of Sections 15 and 16. - - If the disclaimer of warranty and limitation of liability provided above - cannot be given local legal effect according to their terms, reviewing - courts shall apply local law that most closely approximates an absolute - waiver of all civil liability in connection with the Program, unless a - warranty or assumption of liability accompanies a copy of the Program in - return for a fee. - - END OF TERMS AND CONDITIONS diff --git a/README.md b/README.md index 6ddb8b670..7976720b4 100644 --- a/README.md +++ b/README.md @@ -16,7 +16,7 @@
-
+
@@ -113,4 +113,11 @@ After installing Netmaker, check out the [Walkthrough](https://itnext.io/getting
## License
-Netmaker's source code and all artifacts in this repository are freely available. All versions are published under the Server Side Public License (SSPL), version 1, which can be found here: [LICENSE.txt](./LICENSE.txt).
+Netmaker's source code and all artifacts in this repository are freely available.
+All content that resides under the "pro/" directory of this repository, if that
+directory exists, is licensed under the license defined in "pro/LICENSE".
+All third party components incorporated into the Netmaker Software are licensed
+under the original license provided by the owner of the applicable component.
+Content outside of the above mentioned directories or restrictions above is
+available under the "Apache Version 2.0" license as defined below.
+All details for the licenses used can be found here: [LICENSE.md](./LICENSE.md).
diff --git a/auth/auth.go b/auth/auth.go
index 7be57345a..61bbdda10 100644
--- a/auth/auth.go
+++ b/auth/auth.go
@@ -136,6 +136,8 @@ func HandleAuthCallback(w http.ResponseWriter, r *http.Request) {
//
// Security:
// oauth
+// Responses:
+// 200: okResponse
func HandleAuthLogin(w http.ResponseWriter, r *http.Request) {
if auth_provider == nil {
handleOauthNotConfigured(w)
diff --git a/cli/cmd/host/delete.go b/cli/cmd/host/delete.go
index 4da8acb0c..b4639de3a 100644
--- a/cli/cmd/host/delete.go
+++ b/cli/cmd/host/delete.go
@@ -5,16 +5,19 @@ import (
"github.com/spf13/cobra"
)
+var force bool
+
var hostDeleteCmd = &cobra.Command{
Use: "delete HostID",
Args: cobra.ExactArgs(1),
Short: "Delete a host",
Long: `Delete a host`,
Run: func(cmd *cobra.Command, args []string) {
- functions.PrettyPrint(functions.DeleteHost(args[0]))
+ functions.PrettyPrint(functions.DeleteHost(args[0], force))
},
}
func init() {
rootCmd.AddCommand(hostDeleteCmd)
+ hostDeleteCmd.PersistentFlags().BoolVarP(&force, "force", "f", false, "delete even if part of network(s)")
}
diff --git a/cli/cmd/host/update.go b/cli/cmd/host/update.go
index 87fdb9fe4..0809f2d45 100644
--- a/cli/cmd/host/update.go
+++ b/cli/cmd/host/update.go
@@ -5,9 +5,10 @@ import (
"log"
"os"
+ "github.com/spf13/cobra"
+
"github.com/gravitl/netmaker/cli/functions"
"github.com/gravitl/netmaker/models"
- "github.com/spf13/cobra"
)
var (
@@ -18,6 +19,7 @@ var (
mtu int
isStatic bool
isDefault bool
+ keepAlive int
)
var hostUpdateCmd = &cobra.Command{
@@ -43,6 +45,7 @@ var hostUpdateCmd = &cobra.Command{
apiHost.MTU = mtu
apiHost.IsStatic = isStatic
apiHost.IsDefault = isDefault
+ apiHost.PersistentKeepalive = keepAlive
}
functions.PrettyPrint(functions.UpdateHost(args[0], apiHost))
},
@@ -54,6 +57,7 @@ func init() {
hostUpdateCmd.Flags().StringVar(&name, "name", "", "Host name")
hostUpdateCmd.Flags().IntVar(&listenPort, "listen_port", 0, "Listen port of the host")
hostUpdateCmd.Flags().IntVar(&mtu, "mtu", 0, "Host MTU size")
+ hostUpdateCmd.Flags().IntVar(&keepAlive, "keep_alive", 0, "Interval (seconds) in which packets are sent to keep connections open with peers")
hostUpdateCmd.Flags().BoolVar(&isStatic, "static", false, "Make Host Static ?")
hostUpdateCmd.Flags().BoolVar(&isDefault, "default", false, "Make Host Default ?")
rootCmd.AddCommand(hostUpdateCmd)
diff --git a/cli/cmd/node/delete.go b/cli/cmd/node/delete.go
index 501dd7028..4d05a67d1 100644
--- a/cli/cmd/node/delete.go
+++ b/cli/cmd/node/delete.go
@@ -5,16 +5,19 @@ import (
"github.com/spf13/cobra"
)
+var force bool
+
var nodeDeleteCmd = &cobra.Command{
Use: "delete [NETWORK NAME] [NODE ID]",
Args: cobra.ExactArgs(2),
Short: "Delete a Node",
Long: `Delete a Node`,
Run: func(cmd *cobra.Command, args []string) {
- functions.PrettyPrint(functions.DeleteNode(args[0], args[1]))
+ functions.PrettyPrint(functions.DeleteNode(args[0], args[1], force))
},
}
func init() {
rootCmd.AddCommand(nodeDeleteCmd)
+ nodeDeleteCmd.PersistentFlags().BoolVarP(&force, "force", "f", false, "force delete a node")
}
diff --git a/cli/cmd/node/flags.go b/cli/cmd/node/flags.go
index 48f2f7495..2ed805d75 100644
--- a/cli/cmd/node/flags.go
+++ b/cli/cmd/node/flags.go
@@ -11,7 +11,6 @@ var (
name string
postUp string
postDown string
- keepAlive int
relayedNodes string
egressGatewayRanges string
expirationDateTime int
diff --git a/cli/cmd/node/uncordon.go b/cli/cmd/node/uncordon.go
deleted file mode 100644
index b9b094c2d..000000000
--- a/cli/cmd/node/uncordon.go
+++ /dev/null
@@ -1,22 +0,0 @@
-package node
-
-import (
- "fmt"
-
- "github.com/gravitl/netmaker/cli/functions"
- "github.com/spf13/cobra"
-)
-
-var nodeUncordonCmd = &cobra.Command{
- Use: "uncordon [NETWORK NAME] [NODE ID]",
- Args: cobra.ExactArgs(2),
- Short: "Get a node by ID",
- Long: `Get a node by ID`,
- Run: func(cmd *cobra.Command, args []string) {
- fmt.Println(*functions.UncordonNode(args[0], args[1]))
- },
-}
-
-func init() {
- rootCmd.AddCommand(nodeUncordonCmd)
-}
diff --git a/cli/cmd/node/update.go b/cli/cmd/node/update.go
index e2d2d3836..b8ff74d07 100644
--- a/cli/cmd/node/update.go
+++ b/cli/cmd/node/update.go
@@ -34,7 +34,6 @@ var nodeUpdateCmd = &cobra.Command{
node.Address = address
node.Address6 = address6
node.LocalAddress = localAddress
- node.PersistentKeepalive = int32(keepAlive)
if relayedNodes != "" {
node.RelayedNodes = strings.Split(relayedNodes, ",")
}
@@ -61,7 +60,6 @@ func init() {
nodeUpdateCmd.Flags().StringVar(&name, "name", "", "Node name")
nodeUpdateCmd.Flags().StringVar(&postUp, "post_up", "", "Commands to run after node is up `;` separated")
nodeUpdateCmd.Flags().StringVar(&postDown, "post_down", "", "Commands to run after node is down `;` separated")
- nodeUpdateCmd.Flags().IntVar(&keepAlive, "keep_alive", 0, "Interval in which packets are sent to keep connections open with peers")
nodeUpdateCmd.Flags().StringVar(&relayedNodes, "relayed_nodes", "", "relayed nodes if node acts as a relay")
nodeUpdateCmd.Flags().StringVar(&egressGatewayRanges, "egress_addrs", "", "Addresses for egressing traffic if node acts as an egress")
nodeUpdateCmd.Flags().IntVar(&expirationDateTime, "expiry", 0, "UNIX timestamp after which node will lose access to the network")
diff --git a/cli/functions/host.go b/cli/functions/host.go
index bfcf0f03b..04346829f 100644
--- a/cli/functions/host.go
+++ b/cli/functions/host.go
@@ -17,8 +17,8 @@ func GetHosts() *[]models.ApiHost {
}
// DeleteHost - delete a host
-func DeleteHost(hostID string) *models.ApiHost {
- return request[models.ApiHost](http.MethodDelete, "/api/hosts/"+hostID, nil)
+func DeleteHost(hostID string, force bool) *models.ApiHost {
+ return request[models.ApiHost](http.MethodDelete, fmt.Sprintf("/api/hosts/%s?force=%t", hostID, force), nil)
}
// UpdateHost - update a host
diff --git a/cli/functions/node.go b/cli/functions/node.go
index ef75ce395..50eed3572 100644
--- a/cli/functions/node.go
+++ b/cli/functions/node.go
@@ -27,8 +27,8 @@ func UpdateNode(networkName, nodeID string, node *models.ApiNode) *models.ApiNod
}
// DeleteNode - delete a node
-func DeleteNode(networkName, nodeID string) *models.SuccessResponse {
- return request[models.SuccessResponse](http.MethodDelete, fmt.Sprintf("/api/nodes/%s/%s", networkName, nodeID), nil)
+func DeleteNode(networkName, nodeID string, force bool) *models.SuccessResponse {
+ return request[models.SuccessResponse](http.MethodDelete, fmt.Sprintf("/api/nodes/%s/%s?force=%t", networkName, nodeID, force), nil)
}
// CreateEgress - turn a node into an egress
@@ -52,8 +52,3 @@ func CreateIngress(networkName, nodeID string, failover bool) *models.ApiNode {
func DeleteIngress(networkName, nodeID string) *models.ApiNode {
return request[models.ApiNode](http.MethodDelete, fmt.Sprintf("/api/nodes/%s/%s/deleteingress", networkName, nodeID), nil)
}
-
-// UncordonNode - uncordon a node
-func UncordonNode(networkName, nodeID string) *string {
- return request[string](http.MethodPost, fmt.Sprintf("/api/nodes/%s/%s/approve", networkName, nodeID), nil)
-}
diff --git a/compose/docker-compose.netclient.yml b/compose/docker-compose.netclient.yml
index 8c184fffb..e0901f84b 100644
--- a/compose/docker-compose.netclient.yml
+++ b/compose/docker-compose.netclient.yml
@@ -3,7 +3,7 @@ version: "3.4"
services:
netclient:
container_name: netclient
- image: 'gravitl/netclient:v0.21.0'
+ image: 'gravitl/netclient:v0.21.1'
hostname: netmaker-1
network_mode: host
restart: on-failure
diff --git a/compose/docker-compose.yml b/compose/docker-compose.yml
index 7fbf71136..33d9b090c 100644
--- a/compose/docker-compose.yml
+++ b/compose/docker-compose.yml
@@ -53,7 +53,6 @@ services:
- "host.docker.internal:host-gateway"
volumes:
- ./Caddyfile:/etc/caddy/Caddyfile
- - ./certs:/root/certs
- caddy_data:/data
- caddy_conf:/config
ports:
diff --git a/config/config.go b/config/config.go
index 20a55b253..bf22666c3 100644
--- a/config/config.go
+++ b/config/config.go
@@ -7,6 +7,7 @@ package config
import (
"fmt"
"os"
+ "time"
"gopkg.in/yaml.v3"
)
@@ -32,62 +33,64 @@ type EnvironmentConfig struct {
// ServerConfig - server conf struct
type ServerConfig struct {
- CoreDNSAddr string `yaml:"corednsaddr"`
- APIConnString string `yaml:"apiconn"`
- APIHost string `yaml:"apihost"`
- APIPort string `yaml:"apiport"`
- Broker string `yam:"broker"`
- ServerBrokerEndpoint string `yaml:"serverbrokerendpoint"`
- BrokerType string `yaml:"brokertype"`
- EmqxRestEndpoint string `yaml:"emqxrestendpoint"`
- NetclientAutoUpdate string `yaml:"netclientautoupdate"`
- NetclientEndpointDetection string `yaml:"netclientendpointdetection"`
- MasterKey string `yaml:"masterkey"`
- DNSKey string `yaml:"dnskey"`
- AllowedOrigin string `yaml:"allowedorigin"`
- NodeID string `yaml:"nodeid"`
- RestBackend string `yaml:"restbackend"`
- MessageQueueBackend string `yaml:"messagequeuebackend"`
- DNSMode string `yaml:"dnsmode"`
- DisableRemoteIPCheck string `yaml:"disableremoteipcheck"`
- Version string `yaml:"version"`
- SQLConn string `yaml:"sqlconn"`
- Platform string `yaml:"platform"`
- Database string `yaml:"database"`
- Verbosity int32 `yaml:"verbosity"`
- AuthProvider string `yaml:"authprovider"`
- OIDCIssuer string `yaml:"oidcissuer"`
- ClientID string `yaml:"clientid"`
- ClientSecret string `yaml:"clientsecret"`
- FrontendURL string `yaml:"frontendurl"`
- DisplayKeys string `yaml:"displaykeys"`
- AzureTenant string `yaml:"azuretenant"`
- Telemetry string `yaml:"telemetry"`
- HostNetwork string `yaml:"hostnetwork"`
- Server string `yaml:"server"`
- PublicIPService string `yaml:"publicipservice"`
- MQPassword string `yaml:"mqpassword"`
- MQUserName string `yaml:"mqusername"`
- MetricsExporter string `yaml:"metrics_exporter"`
- BasicAuth string `yaml:"basic_auth"`
- LicenseValue string `yaml:"license_value"`
- NetmakerTenantID string `yaml:"netmaker_tenant_id"`
- IsPro string `yaml:"is_ee" json:"IsEE"`
- StunPort int `yaml:"stun_port"`
- StunList string `yaml:"stun_list"`
- TurnServer string `yaml:"turn_server"`
- TurnApiServer string `yaml:"turn_api_server"`
- TurnPort int `yaml:"turn_port"`
- TurnUserName string `yaml:"turn_username"`
- TurnPassword string `yaml:"turn_password"`
- UseTurn bool `yaml:"use_turn"`
- UsersLimit int `yaml:"user_limit"`
- NetworksLimit int `yaml:"network_limit"`
- MachinesLimit int `yaml:"machines_limit"`
- IngressesLimit int `yaml:"ingresses_limit"`
- EgressesLimit int `yaml:"egresses_limit"`
- DeployedByOperator bool `yaml:"deployed_by_operator"`
- Environment string `yaml:"environment"`
+ CoreDNSAddr string `yaml:"corednsaddr"`
+ APIConnString string `yaml:"apiconn"`
+ APIHost string `yaml:"apihost"`
+ APIPort string `yaml:"apiport"`
+ Broker string `yam:"broker"`
+ ServerBrokerEndpoint string `yaml:"serverbrokerendpoint"`
+ BrokerType string `yaml:"brokertype"`
+ EmqxRestEndpoint string `yaml:"emqxrestendpoint"`
+ NetclientAutoUpdate string `yaml:"netclientautoupdate"`
+ NetclientEndpointDetection string `yaml:"netclientendpointdetection"`
+ MasterKey string `yaml:"masterkey"`
+ DNSKey string `yaml:"dnskey"`
+ AllowedOrigin string `yaml:"allowedorigin"`
+ NodeID string `yaml:"nodeid"`
+ RestBackend string `yaml:"restbackend"`
+ MessageQueueBackend string `yaml:"messagequeuebackend"`
+ DNSMode string `yaml:"dnsmode"`
+ DisableRemoteIPCheck string `yaml:"disableremoteipcheck"`
+ Version string `yaml:"version"`
+ SQLConn string `yaml:"sqlconn"`
+ Platform string `yaml:"platform"`
+ Database string `yaml:"database"`
+ Verbosity int32 `yaml:"verbosity"`
+ AuthProvider string `yaml:"authprovider"`
+ OIDCIssuer string `yaml:"oidcissuer"`
+ ClientID string `yaml:"clientid"`
+ ClientSecret string `yaml:"clientsecret"`
+ FrontendURL string `yaml:"frontendurl"`
+ DisplayKeys string `yaml:"displaykeys"`
+ AzureTenant string `yaml:"azuretenant"`
+ Telemetry string `yaml:"telemetry"`
+ HostNetwork string `yaml:"hostnetwork"`
+ Server string `yaml:"server"`
+ PublicIPService string `yaml:"publicipservice"`
+ MQPassword string `yaml:"mqpassword"`
+ MQUserName string `yaml:"mqusername"`
+ MetricsExporter string `yaml:"metrics_exporter"`
+ BasicAuth string `yaml:"basic_auth"`
+ LicenseValue string `yaml:"license_value"`
+ NetmakerTenantID string `yaml:"netmaker_tenant_id"`
+ IsPro string `yaml:"is_ee" json:"IsEE"`
+ StunPort int `yaml:"stun_port"`
+ StunList string `yaml:"stun_list"`
+ TurnServer string `yaml:"turn_server"`
+ TurnApiServer string `yaml:"turn_api_server"`
+ TurnPort int `yaml:"turn_port"`
+ TurnUserName string `yaml:"turn_username"`
+ TurnPassword string `yaml:"turn_password"`
+ UseTurn bool `yaml:"use_turn"`
+ UsersLimit int `yaml:"user_limit"`
+ NetworksLimit int `yaml:"network_limit"`
+ MachinesLimit int `yaml:"machines_limit"`
+ IngressesLimit int `yaml:"ingresses_limit"`
+ EgressesLimit int `yaml:"egresses_limit"`
+ DeployedByOperator bool `yaml:"deployed_by_operator"`
+ Environment string `yaml:"environment"`
+ JwtValidityDuration time.Duration `yaml:"jwt_validity_duration"`
+ RacAutoDisable bool `yaml:"rac_auto_disable"`
}
// SQLConfig - Generic SQL Config
diff --git a/controllers/dns.go b/controllers/dns.go
index 8d7be2918..8a987a4e8 100644
--- a/controllers/dns.go
+++ b/controllers/dns.go
@@ -33,6 +33,8 @@ func dnsHandlers(r *mux.Router) {
//
// Security:
// oauth
+// Responses:
+// 200: dnsResponse
func getNodeDNS(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
@@ -264,8 +266,8 @@ func GetDNSEntry(domain string, network string) (models.DNSEntry, error) {
// oauth
//
// Responses:
-// 200: dnsStringJSONResponse
-// *: dnsStringJSONResponse
+// 200: dnsResponse
+// *: dnsResponse
func pushDNS(w http.ResponseWriter, r *http.Request) {
// Set header
w.Header().Set("Content-Type", "application/json")
diff --git a/controllers/dns_test.go b/controllers/dns_test.go
index 1e415cc9d..4682f5258 100644
--- a/controllers/dns_test.go
+++ b/controllers/dns_test.go
@@ -238,7 +238,7 @@ func TestSetDNS(t *testing.T) {
assert.False(t, info.IsDir())
content, err := os.ReadFile("./config/dnsconfig/netmaker.hosts")
assert.Nil(t, err)
- assert.Contains(t, string(content), "linuxhost.skynet")
+ assert.Contains(t, string(content), "linuxhost")
})
t.Run("EntryExists", func(t *testing.T) {
entry := models.DNSEntry{Address: "10.0.0.3", Name: "newhost", Network: "skynet"}
@@ -251,7 +251,7 @@ func TestSetDNS(t *testing.T) {
assert.False(t, info.IsDir())
content, err := os.ReadFile("./config/dnsconfig/netmaker.hosts")
assert.Nil(t, err)
- assert.Contains(t, string(content), "newhost.skynet")
+ assert.Contains(t, string(content), "newhost")
})
}
diff --git a/controllers/docs.go b/controllers/docs.go
index 2cbe329ea..491e09039 100644
--- a/controllers/docs.go
+++ b/controllers/docs.go
@@ -10,8 +10,8 @@
//
// Schemes: https
// BasePath: /
-// Version: 0.21.0
-// Host: netmaker.io
+// Version: 0.21.1
+// Host: api.demo.netmaker.io
//
// Consumes:
// - application/json
@@ -26,15 +26,37 @@
package controller
import (
- serverconfigpkg "github.com/gravitl/netmaker/config"
+ "os"
+
+ "github.com/gravitl/netmaker/config"
"github.com/gravitl/netmaker/logic/acls"
"github.com/gravitl/netmaker/models"
)
var _ = useUnused() // "use" the function to prevent "unused function" errors
+// swagger:parameters getFile
+type filenameToGet struct {
+ // Filename
+ // in: path
+ // required: true
+ Filename string `json:"filename"`
+}
+
+// swagger:response hasAdmin
+type hasAdmin struct {
+ // in: body
+ Admin bool
+}
+
+// swagger:response apiHostResponse
+type apiHostResponse struct {
+ // in: body
+ Host models.ApiHost
+}
+
// swagger:parameters getNodeDNS getCustomDNS getDNS
-type dnsPathParams struct {
+type dnsNetworkPathParam struct {
// Network
// in: path
Network string `json:"network"`
@@ -45,7 +67,6 @@ type dnsParams struct {
// Network
// in: path
Network string `json:"network"`
-
// DNS Entry
// in: body
Body []models.DNSEntry `json:"body"`
@@ -76,6 +97,18 @@ type stringJSONResponse struct {
Response string `json:"response"`
}
+//swagger:response EnrollmentKey
+type EnrollmentKey struct {
+ // in: body
+ EnrollmentKey models.EnrollmentKey
+}
+
+//swagger:response EnrollmentKeys
+type EnrollmentKeys struct {
+ // in: body
+ EnrollmentKeys []models.EnrollmentKey
+}
+
// swagger:parameters getAllExtClients
type getAllClientsRequest struct {
// Networks
@@ -97,6 +130,12 @@ type extClientResponse struct {
ExtClient models.ExtClient `json:"ext_client"`
}
+// swagger:response fileResponse
+type fileResponse struct {
+ // in: body
+ File os.File
+}
+
// swagger:response successResponse
type successResponse struct {
// Success Response
@@ -104,12 +143,24 @@ type successResponse struct {
SuccessResponse models.SuccessResponse `json:"success_response"`
}
+// swagger:parameters getExtClientConf
+type extClientConfParams struct {
+ // Client ID
+ // in: path
+ ClientID string `json:"clientid"`
+ // Network
+ // in: path
+ Network string `json:"network"`
+ // Type
+ // in: path
+ Type string `json:"type"`
+}
+
// swagger:parameters getExtClient getExtClientConf updateExtClient deleteExtClient
type extClientPathParams struct {
// Client ID
// in: path
ClientID string `json:"clientid"`
-
// Network
// in: path
Network string `json:"network"`
@@ -137,20 +188,17 @@ type createExtClientPathParams struct {
// Node ID
// in: path
- NodeID string `json:"node"`
+ NodeID string `json:"nodeid"`
// Custom ExtClient
// in: body
CustomExtClient models.CustomExtClient `json:"custom_ext_client"`
}
-// swagger:parameters getNode updateNode deleteNode createRelay deleteRelay createEgressGateway deleteEgressGateway createIngressGateway deleteIngressGateway uncordonNode
+// swagger:parameters getNode updateNode deleteNode createRelay deleteRelay createEgressGateway deleteEgressGateway createIngressGateway deleteIngressGateway ingressGatewayUsers
type networkNodePathParams struct {
- // Network
// in: path
Network string `json:"network"`
-
- // Node ID
// in: path
NodeID string `json:"nodeid"`
}
@@ -161,11 +209,11 @@ type byteArrayResponse struct {
ByteArray []byte `json:"byte_array"`
}
-// swagger:parameters getNetworks
-type headerNetworks struct {
- // name: networks
- // in: header
- Networks []string `json:"networks"`
+// swagger:parameters getNetwork deleteNetwork updateNetwork getNetworkACL updateNetworkACL
+type NetworkParam struct {
+ // name: network name
+ // in: path
+ Networkname string `json:"networkname"`
}
// swagger:response getNetworksSliceResponse
@@ -175,6 +223,13 @@ type getNetworksSliceResponse struct {
Networks []models.Network `json:"networks"`
}
+// swagger:response hostPull
+type hostPull struct {
+ // hostPull
+ // in: body
+ HostPull models.HostPull
+}
+
// swagger:parameters createNetwork updateNetwork
type networkBodyParam struct {
// Network
@@ -182,18 +237,11 @@ type networkBodyParam struct {
Network models.Network `json:"network"`
}
-// swagger:parameters updateNetwork getNetwork updateNetwork updateNetworkNodeLimit deleteNetwork keyUpdate createAccessKey getAccessKeys deleteAccessKey updateNetworkACL getNetworkACL
+// swagger:parameters updateNetworkNodeLimit keyUpdate createAccessKey getAccessKeys getNetworkNodes
type networkPathParam struct {
- // Network Name
- // in: path
- NetworkName string `json:"networkname"`
-}
-
-// swagger:parameters deleteAccessKey
-type networkAccessKeyNamePathParam struct {
- // Access Key Name
+ // Network
// in: path
- AccessKeyName string `json:"access_key_name"`
+ Network string `json:"network"`
}
// swagger:response networkBodyResponse
@@ -238,6 +286,15 @@ type nodeBodyParam struct {
Node models.LegacyNode `json:"node"`
}
+//swagger:response okResponse
+type okRespone struct{}
+
+// swagger:response RegisterResponse
+type RegisterResponse struct {
+ // in: body
+ RegisterResponse models.RegisterResponse
+}
+
// swagger:parameters createRelay
type relayRequestBodyParam struct {
// Relay Request
@@ -252,53 +309,68 @@ type egressGatewayBodyParam struct {
EgressGatewayRequest models.EgressGatewayRequest `json:"egress_gateway_request"`
}
+// swagger:parameters attachUserToRemoteAccessGateway removeUserFromRemoteAccessGW getUserRemoteAccessGws
+type RemoteAccessGatewayUser struct {
+ // in: path
+ Username string `json:"username"`
+}
+
// swagger:parameters authenticate
type authParamBodyParam struct {
+ // network
+ // in: path
+ Network string `json:"network"`
// AuthParams
// in: body
AuthParams models.AuthParams `json:"auth_params"`
}
-// swagger:response serverConfigResponse
-type serverConfigResponse struct {
- // Server Config
+// swagger:response signal
+type signal struct {
// in: body
- ServerConfig serverconfigpkg.ServerConfig `json:"server_config"`
+ Signal models.Signal
}
-// swagger:response nodeGetResponse
-type nodeGetResponse struct {
- // Node Get
- // in: body
- NodeGet models.NodeGet `json:"node_get"`
+// swagger:parameters synchost deleteHost updateHost signalPeer updateKeys
+type HostID struct {
+ // HostID
+ // in: path
+ HostID string `json:"hostid"`
}
-// swagger:response nodeLastModifiedResponse
-type nodeLastModifiedResponse struct {
- // Node Last Modified
- // in: body
- NodesLastModified int64 `json:"nodes_last_modified"`
+// swagger:parameters addHostToNetwork deleteHostFromNetwork
+type HostFromNetworkParams struct {
+ // hostid to add or delete from network
+ // in: path
+ HostID string `json:"hostid"`
+ // network
+ // in: path
+ Network string `json:"network"`
}
-// swagger:parameters register
-//type registerRequestBodyParam struct {
-// // Register Request
-// // in: body
-// RegisterRequest config.RegisterRequest `json:"register_request"`
-//}
-//
-//// swagger:response registerResponse
-//type registerResponse struct {
-// // Register Response
-// // in: body
-// RegisterResponse config.RegisterResponse `json:"register_response"`
-//}
+// swagger:parameters deleteEnrollmentKey
+type DeleteEnrollmentKeyParam struct {
+ // in: path
+ KeyID string `json:"keyid"`
+}
-// swagger:response boolResponse
-type boolResponse struct {
- // Boolean Response
+// swagger:parameters handleHostRegister
+type RegisterParams struct {
+ // in: path
+ Token string `json:"token"`
+ // in: body
+ Host models.Host `json:"host"`
+}
+
+// swagger:response serverConfigResponse
+type serverConfigResponse struct {
+ // Server Config
// in: body
- BoolResponse bool `json:"bool_response"`
+ // example
+ //{
+ //"mqusername": "xxxxxxx"
+ //}
+ ServerConfig config.ServerConfig `json:"server_config"`
}
// swagger:parameters createAdmin updateUser updateUserNetworks createUser
@@ -331,7 +403,6 @@ type usernamePathParam struct {
// prevent issues with integration tests for types just used by Swagger docs.
func useUnused() bool {
- _ = dnsPathParams{}
_ = dnsParams{}
_ = dnsResponse{}
_ = dnsDeletePathParams{}
@@ -346,11 +417,9 @@ func useUnused() bool {
_ = createExtClientPathParams{}
_ = networkNodePathParams{}
_ = byteArrayResponse{}
- _ = headerNetworks{}
_ = getNetworksSliceResponse{}
_ = networkBodyParam{}
_ = networkPathParam{}
- _ = networkAccessKeyNamePathParam{}
_ = networkBodyResponse{}
_ = aclContainerBodyParam{}
_ = aclContainerResponse{}
@@ -361,14 +430,18 @@ func useUnused() bool {
_ = egressGatewayBodyParam{}
_ = authParamBodyParam{}
_ = serverConfigResponse{}
- _ = nodeGetResponse{}
- _ = nodeLastModifiedResponse{}
- // _ = registerRequestBodyParam{}
- // _ = registerResponse{}
- _ = boolResponse{}
_ = userBodyParam{}
_ = userBodyResponse{}
_ = userAuthBodyParam{}
_ = usernamePathParam{}
+ _ = hasAdmin{}
+ _ = apiHostResponse{}
+ _ = fileResponse{}
+ _ = extClientConfParams{}
+ _ = hostPull{}
+ _ = okRespone{}
+ _ = signal{}
+ _ = filenameToGet{}
+ _ = dnsNetworkPathParam{}
return false
}
diff --git a/controllers/enrollmentkeys.go b/controllers/enrollmentkeys.go
index 63aca97d4..33b2c7209 100644
--- a/controllers/enrollmentkeys.go
+++ b/controllers/enrollmentkeys.go
@@ -7,6 +7,7 @@ import (
"time"
"github.com/gorilla/mux"
+
"github.com/gravitl/netmaker/auth"
"github.com/gravitl/netmaker/logger"
"github.com/gravitl/netmaker/logic"
@@ -17,10 +18,14 @@ import (
)
func enrollmentKeyHandlers(r *mux.Router) {
- r.HandleFunc("/api/v1/enrollment-keys", logic.SecurityCheck(true, http.HandlerFunc(createEnrollmentKey))).Methods(http.MethodPost)
- r.HandleFunc("/api/v1/enrollment-keys", logic.SecurityCheck(true, http.HandlerFunc(getEnrollmentKeys))).Methods(http.MethodGet)
- r.HandleFunc("/api/v1/enrollment-keys/{keyID}", logic.SecurityCheck(true, http.HandlerFunc(deleteEnrollmentKey))).Methods(http.MethodDelete)
- r.HandleFunc("/api/v1/host/register/{token}", http.HandlerFunc(handleHostRegister)).Methods(http.MethodPost)
+ r.HandleFunc("/api/v1/enrollment-keys", logic.SecurityCheck(true, http.HandlerFunc(createEnrollmentKey))).
+ Methods(http.MethodPost)
+ r.HandleFunc("/api/v1/enrollment-keys", logic.SecurityCheck(true, http.HandlerFunc(getEnrollmentKeys))).
+ Methods(http.MethodGet)
+ r.HandleFunc("/api/v1/enrollment-keys/{keyID}", logic.SecurityCheck(true, http.HandlerFunc(deleteEnrollmentKey))).
+ Methods(http.MethodDelete)
+ r.HandleFunc("/api/v1/host/register/{token}", http.HandlerFunc(handleHostRegister)).
+ Methods(http.MethodPost)
}
// swagger:route GET /api/v1/enrollment-keys enrollmentKeys getEnrollmentKeys
@@ -33,7 +38,7 @@ func enrollmentKeyHandlers(r *mux.Router) {
// oauth
//
// Responses:
-// 200: getEnrollmentKeysSlice
+// 200: EnrollmentKeys
func getEnrollmentKeys(w http.ResponseWriter, r *http.Request) {
keys, err := logic.GetAllEnrollmentKeys()
if err != nil {
@@ -58,7 +63,7 @@ func getEnrollmentKeys(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(ret)
}
-// swagger:route DELETE /api/v1/enrollment-keys/{keyID} enrollmentKeys deleteEnrollmentKey
+// swagger:route DELETE /api/v1/enrollment-keys/{keyid} enrollmentKeys deleteEnrollmentKey
//
// Deletes an EnrollmentKey from Netmaker server.
//
@@ -68,9 +73,9 @@ func getEnrollmentKeys(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: deleteEnrollmentKeyResponse
+// 200: okResponse
func deleteEnrollmentKey(w http.ResponseWriter, r *http.Request) {
- var params = mux.Vars(r)
+ params := mux.Vars(r)
keyID := params["keyID"]
err := logic.DeleteEnrollmentKey(keyID)
if err != nil {
@@ -92,9 +97,8 @@ func deleteEnrollmentKey(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: createEnrollmentKeyResponse
+// 200: EnrollmentKey
func createEnrollmentKey(w http.ResponseWriter, r *http.Request) {
-
var enrollmentKeyBody models.APIEnrollmentKey
err := json.NewDecoder(r.Body).Decode(&enrollmentKeyBody)
@@ -109,7 +113,13 @@ func createEnrollmentKey(w http.ResponseWriter, r *http.Request) {
newTime = time.Unix(enrollmentKeyBody.Expiration, 0)
}
- newEnrollmentKey, err := logic.CreateEnrollmentKey(enrollmentKeyBody.UsesRemaining, newTime, enrollmentKeyBody.Networks, enrollmentKeyBody.Tags, enrollmentKeyBody.Unlimited)
+ newEnrollmentKey, err := logic.CreateEnrollmentKey(
+ enrollmentKeyBody.UsesRemaining,
+ newTime,
+ enrollmentKeyBody.Networks,
+ enrollmentKeyBody.Tags,
+ enrollmentKeyBody.Unlimited,
+ )
if err != nil {
logger.Log(0, r.Header.Get("user"), "failed to create enrollment key:", err.Error())
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
@@ -136,9 +146,9 @@ func createEnrollmentKey(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: handleHostRegisterResponse
+// 200: RegisterResponse
func handleHostRegister(w http.ResponseWriter, r *http.Request) {
- var params = mux.Vars(r)
+ params := mux.Vars(r)
token := params["token"]
logger.Log(0, "received registration attempt with token", token)
// check if token exists
@@ -156,7 +166,6 @@ func handleHostRegister(w http.ResponseWriter, r *http.Request) {
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
return
}
- hostExists := false
// re-register host with turn just in case.
if servercfg.IsUsingTurn() {
err = logic.RegisterHostWithTurn(newHost.ID.String(), newHost.HostPass)
@@ -165,9 +174,20 @@ func handleHostRegister(w http.ResponseWriter, r *http.Request) {
}
}
// check if host already exists
+ hostExists := false
if hostExists = logic.HostExists(&newHost); hostExists && len(enrollmentKey.Networks) == 0 {
- logger.Log(0, "host", newHost.ID.String(), newHost.Name, "attempted to re-register with no networks")
- logic.ReturnErrorResponse(w, r, logic.FormatError(fmt.Errorf("host already exists"), "badrequest"))
+ logger.Log(
+ 0,
+ "host",
+ newHost.ID.String(),
+ newHost.Name,
+ "attempted to re-register with no networks",
+ )
+ logic.ReturnErrorResponse(
+ w,
+ r,
+ logic.FormatError(fmt.Errorf("host already exists"), "badrequest"),
+ )
return
}
// version check
@@ -190,11 +210,16 @@ func handleHostRegister(w http.ResponseWriter, r *http.Request) {
// use the token
if ok := logic.TryToUseEnrollmentKey(enrollmentKey); !ok {
logger.Log(0, "host", newHost.ID.String(), newHost.Name, "failed registration")
- logic.ReturnErrorResponse(w, r, logic.FormatError(fmt.Errorf("invalid enrollment key"), "badrequest"))
+ logic.ReturnErrorResponse(
+ w,
+ r,
+ logic.FormatError(fmt.Errorf("invalid enrollment key"), "badrequest"),
+ )
return
}
hostPass := newHost.HostPass
if !hostExists {
+ newHost.PersistentKeepalive = models.DefaultPersistentKeepAlive
// register host
logic.CheckHostPorts(&newHost)
// create EMQX credentials and ACLs for host
@@ -209,14 +234,21 @@ func handleHostRegister(w http.ResponseWriter, r *http.Request) {
}
}
if err = logic.CreateHost(&newHost); err != nil {
- logger.Log(0, "host", newHost.ID.String(), newHost.Name, "failed registration -", err.Error())
+ logger.Log(
+ 0,
+ "host",
+ newHost.ID.String(),
+ newHost.Name,
+ "failed registration -",
+ err.Error(),
+ )
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
return
}
} else {
// need to revise the list of networks from key
// based on the ones host currently has
- var networksToAdd = []string{}
+ networksToAdd := []string{}
currentNets := logic.GetHostNetworks(newHost.ID.String())
for _, newNet := range enrollmentKey.Networks {
if !logic.StringSliceContains(currentNets, newNet) {
diff --git a/controllers/ext_client.go b/controllers/ext_client.go
index 898f5098e..e47c6c9b5 100644
--- a/controllers/ext_client.go
+++ b/controllers/ext_client.go
@@ -90,16 +90,6 @@ func getAllExtClients(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
- headerNetworks := r.Header.Get("networks")
- networksSlice := []string{}
- marshalErr := json.Unmarshal([]byte(headerNetworks), &networksSlice)
- if marshalErr != nil {
- slog.Error("error unmarshalling networks", "error", marshalErr.Error())
- logic.ReturnErrorResponse(w, r, logic.FormatError(marshalErr, "internal"))
- return
- }
-
- var err error
clients, err := logic.GetAllExtClients()
if err != nil && !database.IsEmptyRecord(err) {
logger.Log(0, "failed to get all extclients: ", err.Error())
@@ -313,6 +303,8 @@ Endpoint = %s
//
// Security:
// oauth
+// Responses:
+// 200: okResponse
func createExtClient(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
@@ -385,6 +377,11 @@ func createExtClient(w http.ResponseWriter, r *http.Request) {
extclient.RemoteAccessClientID = customExtClient.RemoteAccessClientID
extclient.IngressGatewayID = nodeid
+ // set extclient dns to ingressdns if extclient dns is not explicitly set
+ if (extclient.DNS == "") && (node.IngressDNS != "") {
+ extclient.DNS = node.IngressDNS
+ }
+
extclient.Network = node.Network
host, err := logic.GetHost(node.HostID.String())
if err != nil {
diff --git a/controllers/files.go b/controllers/files.go
index dfe7a3377..e4e6bf0f3 100644
--- a/controllers/files.go
+++ b/controllers/files.go
@@ -7,7 +7,7 @@ import (
)
func fileHandlers(r *mux.Router) {
- // swagger:route GET /meshclient/files/{filename} meshclient fileServer
+ // swagger:route GET /meshclient/files/{filename} meshclient getFile
//
// Retrieve a file from the file server.
//
@@ -15,5 +15,7 @@ func fileHandlers(r *mux.Router) {
//
// Security:
// oauth
+ // Responses:
+ // 200: fileResponse
r.PathPrefix("/meshclient/files").Handler(http.StripPrefix("/meshclient/files", http.FileServer(http.Dir("./meshclient/files"))))
}
diff --git a/controllers/hosts.go b/controllers/hosts.go
index 0c6e9fd65..a587db4a0 100644
--- a/controllers/hosts.go
+++ b/controllers/hosts.go
@@ -23,6 +23,7 @@ func hostHandlers(r *mux.Router) {
r.HandleFunc("/api/hosts/{hostid}/sync", logic.SecurityCheck(true, http.HandlerFunc(syncHost))).Methods(http.MethodPost)
r.HandleFunc("/api/hosts/{hostid}", logic.SecurityCheck(true, http.HandlerFunc(updateHost))).Methods(http.MethodPut)
r.HandleFunc("/api/hosts/{hostid}", Authorize(true, false, "all", http.HandlerFunc(deleteHost))).Methods(http.MethodDelete)
+ r.HandleFunc("/api/hosts/{hostid}/upgrade", logic.SecurityCheck(true, http.HandlerFunc(upgradeHost))).Methods(http.MethodPut)
r.HandleFunc("/api/hosts/{hostid}/networks/{network}", logic.SecurityCheck(true, http.HandlerFunc(addHostToNetwork))).Methods(http.MethodPost)
r.HandleFunc("/api/hosts/{hostid}/networks/{network}", logic.SecurityCheck(true, http.HandlerFunc(deleteHostFromNetwork))).Methods(http.MethodDelete)
r.HandleFunc("/api/hosts/adm/authenticate", authenticateHost).Methods(http.MethodPost)
@@ -31,6 +32,22 @@ func hostHandlers(r *mux.Router) {
r.HandleFunc("/api/v1/auth-register/host", socketHandler)
}
+// upgrade host is a handler to send upgrade message to a host
+func upgradeHost(w http.ResponseWriter, r *http.Request) {
+ host, err := logic.GetHost(mux.Vars(r)["hostid"])
+ if err != nil {
+ slog.Error("failed to find host", "error", err)
+ logic.ReturnErrorResponse(w, r, logic.FormatError(err, "notfound"))
+ return
+ }
+ if err := mq.HostUpdate(&models.HostUpdate{Action: models.Upgrade, Host: *host}); err != nil {
+ slog.Error("failed to upgrade host", "error", err)
+ logic.ReturnErrorResponse(w, r, logic.FormatError(err, "internal"))
+ return
+ }
+ logic.ReturnSuccessResponse(w, r, "passed message to upgrade host")
+}
+
// swagger:route GET /api/hosts hosts getHosts
//
// Lists all hosts.
@@ -41,7 +58,7 @@ func hostHandlers(r *mux.Router) {
// oauth
//
// Responses:
-// 200: getHostsSliceResponse
+// 200: apiHostResponse
func getHosts(w http.ResponseWriter, r *http.Request) {
currentHosts, err := logic.GetAllHosts()
if err != nil {
@@ -56,7 +73,7 @@ func getHosts(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(apiHosts)
}
-// swagger:route GET /api/v1/host pull pullHost
+// swagger:route GET /api/v1/host hosts pullHost
//
// Used by clients for "pull" command
//
@@ -66,7 +83,7 @@ func getHosts(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: pull
+// 200: hostPull
func pull(w http.ResponseWriter, r *http.Request) {
hostID := r.Header.Get(hostIDHeader) // return JSON/API formatted keys
@@ -128,7 +145,7 @@ func pull(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: updateHostResponse
+// 200: apiHostResponse
func updateHost(w http.ResponseWriter, r *http.Request) {
var newHostData models.ApiHost
err := json.NewDecoder(r.Body).Decode(&newHostData)
@@ -196,7 +213,7 @@ func updateHost(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: deleteHostResponse
+// 200: apiHostResponse
func deleteHost(w http.ResponseWriter, r *http.Request) {
var params = mux.Vars(r)
hostid := params["hostid"]
@@ -235,9 +252,8 @@ func deleteHost(w http.ResponseWriter, r *http.Request) {
//
// Security:
// oauth
-//
// Responses:
-// 200: addHostToNetworkResponse
+// 200: okResponse
func addHostToNetwork(w http.ResponseWriter, r *http.Request) {
var params = mux.Vars(r)
@@ -284,7 +300,7 @@ func addHostToNetwork(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: deleteHostFromNetworkResponse
+// 200: okResponse
func deleteHostFromNetwork(w http.ResponseWriter, r *http.Request) {
var params = mux.Vars(r)
@@ -343,9 +359,12 @@ func deleteHostFromNetwork(w http.ResponseWriter, r *http.Request) {
}
node.Action = models.NODE_DELETE
node.PendingDelete = true
- // notify node change
- mq.RunUpdates(node, false)
- go func() { // notify of peer change
+ go func() {
+ // notify node change
+ if err := mq.NodeUpdate(node); err != nil {
+ slog.Error("error publishing node update to node", "node", node.ID, "error", err)
+ }
+ // notify of peer change
err = mq.PublishDeletedNodePeerUpdate(node)
if err != nil {
logger.Log(1, "error publishing peer update ", err.Error())
@@ -358,7 +377,7 @@ func deleteHostFromNetwork(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusOK)
}
-// swagger:route POST /api/hosts/adm/authenticate hosts authenticateHost
+// swagger:route POST /api/hosts/adm/authenticate authenticate authenticateHost
//
// Host based authentication for making further API calls.
//
@@ -451,7 +470,7 @@ func authenticateHost(response http.ResponseWriter, request *http.Request) {
response.Write(successJSONResponse)
}
-// swagger:route POST /api/hosts/{hostid}/signalpeer signalPeer
+// swagger:route POST /api/hosts/{hostid}/signalpeer hosts signalPeer
//
// send signal to peer.
//
@@ -517,7 +536,7 @@ func signalPeer(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(signal)
}
-// swagger:route POST /api/hosts/keys host updateAllKeys
+// swagger:route POST /api/hosts/keys hosts updateAllKeys
//
// Update keys for a network.
//
@@ -555,7 +574,7 @@ func updateAllKeys(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusOK)
}
-// swagger:route POST /api/hosts/{hostid}keys host updateKeys
+// swagger:route POST /api/hosts/{hostid}keys hosts updateKeys
//
// Update keys for a network.
//
@@ -594,7 +613,7 @@ func updateKeys(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusOK)
}
-// swagger:route POST /api/hosts/{hostId}/sync host syncHost
+// swagger:route POST /api/hosts/{hostid}/sync hosts synchost
//
// Requests a host to pull.
//
diff --git a/controllers/legacy.go b/controllers/legacy.go
index d47db645e..a6115be9e 100644
--- a/controllers/legacy.go
+++ b/controllers/legacy.go
@@ -22,7 +22,7 @@ func legacyHandlers(r *mux.Router) {
// oauth
//
// Responses:
-// 200: wipeLegacyNodesResponse
+// 200: successResponse
func wipeLegacyNodes(w http.ResponseWriter, r *http.Request) {
// Set header
w.Header().Set("Content-Type", "application/json")
diff --git a/controllers/migrate.go b/controllers/migrate.go
index cf8089069..148295951 100644
--- a/controllers/migrate.go
+++ b/controllers/migrate.go
@@ -19,7 +19,7 @@ import (
"golang.zx2c4.com/wireguard/wgctrl/wgtypes"
)
-// swagger:route PUT /api/v1/nodes/migrate nodes migrateNode
+// swagger:route PUT /api/v1/nodes/migrate nodes migrateData
//
// Used to migrate a legacy node.
//
@@ -29,7 +29,7 @@ import (
// oauth
//
// Responses:
-// 200: nodeJoinResponse
+// 200: hostPull
func migrate(w http.ResponseWriter, r *http.Request) {
data := models.MigrationData{}
host := models.Host{}
@@ -65,6 +65,7 @@ func migrate(w http.ResponseWriter, r *http.Request) {
host.Name = data.HostName
host.HostPass = data.Password
host.OS = data.OS
+ host.PersistentKeepalive = time.Duration(legacy.PersistentKeepalive)
if err := logic.CreateHost(&host); err != nil {
slog.Error("create host", "error", err)
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "badrequest"))
@@ -123,7 +124,11 @@ func migrate(w http.ResponseWriter, r *http.Request) {
if err != nil {
logger.Log(0, "error creating ingress gateway for node", node.ID, err.Error())
}
- mq.RunUpdates(&ingressNode, true)
+ go func() {
+ if err := mq.NodeUpdate(&ingressNode); err != nil {
+ slog.Error("error publishing node update to node", "node", ingressNode.ID, "error", err)
+ }
+ }()
}
}
}
@@ -198,7 +203,6 @@ func convertLegacyNode(legacy models.LegacyNode, hostID uuid.UUID) models.Node {
node.IsRelay = false
node.RelayedNodes = []string{}
node.DNSOn = models.ParseBool(legacy.DNSOn)
- node.PersistentKeepalive = time.Duration(int64(time.Second) * int64(legacy.PersistentKeepalive))
node.LastModified = time.Now()
node.ExpirationDateTime = time.Unix(legacy.ExpirationDateTime, 0)
node.EgressGatewayNatEnabled = models.ParseBool(legacy.EgressGatewayNatEnabled)
diff --git a/controllers/network.go b/controllers/network.go
index 3e30d07c6..3c8cbf7a3 100644
--- a/controllers/network.go
+++ b/controllers/network.go
@@ -180,7 +180,7 @@ func getNetworkACL(w http.ResponseWriter, r *http.Request) {
// oauth
//
// Responses:
-// 200: stringJSONResponse
+// 200: successResponse
func deleteNetwork(w http.ResponseWriter, r *http.Request) {
// Set header
w.Header().Set("Content-Type", "application/json")
@@ -278,7 +278,7 @@ func createNetwork(w http.ResponseWriter, r *http.Request) {
json.NewEncoder(w).Encode(network)
}
-// swagger:route PUT /api/networks networks updateNetwork
+// swagger:route PUT /api/networks/{networkname} networks updateNetwork
//
// Update pro settings for a network.
//
diff --git a/controllers/node.go b/controllers/node.go
index 81693a03b..2051304dd 100644
--- a/controllers/node.go
+++ b/controllers/node.go
@@ -34,7 +34,7 @@ func nodeHandlers(r *mux.Router) {
r.HandleFunc("/api/v1/nodes/migrate", migrate).Methods(http.MethodPost)
}
-// swagger:route POST /api/nodes/adm/{network}/authenticate nodes authenticate
+// swagger:route POST /api/nodes/adm/{network}/authenticate authenticate authenticate
//
// Authenticate to make further API calls related to a network.
//
@@ -440,9 +440,11 @@ func createEgressGateway(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(apiNode)
go func() {
+ if err := mq.NodeUpdate(&node); err != nil {
+ slog.Error("error publishing node update to node", "node", node.ID, "error", err)
+ }
mq.PublishPeerUpdate()
}()
- mq.RunUpdates(&node, true)
}
// swagger:route DELETE /api/nodes/{network}/{nodeid}/deletegateway nodes deleteEgressGateway
@@ -481,9 +483,11 @@ func deleteEgressGateway(w http.ResponseWriter, r *http.Request) {
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(apiNode)
go func() {
+ if err := mq.NodeUpdate(&node); err != nil {
+ slog.Error("error publishing node update to node", "node", node.ID, "error", err)
+ }
mq.PublishPeerUpdate()
}()
- mq.RunUpdates(&node, true)
}
// == INGRESS ==
@@ -530,8 +534,11 @@ func createIngressGateway(w http.ResponseWriter, r *http.Request) {
logger.Log(1, r.Header.Get("user"), "created ingress gateway on node", nodeid, "on network", netid)
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(apiNode)
-
- mq.RunUpdates(&node, true)
+ go func() {
+ if err := mq.NodeUpdate(&node); err != nil {
+ slog.Error("error publishing node update to node", "node", node.ID, "error", err)
+ }
+ }()
}
// swagger:route DELETE /api/nodes/{network}/{nodeid}/deleteingress nodes deleteIngressGateway
@@ -582,16 +589,16 @@ func deleteIngressGateway(w http.ResponseWriter, r *http.Request) {
if err != nil {
return
}
- go mq.PublishSingleHostPeerUpdate(
- host,
- allNodes,
- nil,
- removedClients[:],
- )
+ go func() {
+ if err := mq.PublishSingleHostPeerUpdate(host, allNodes, nil, removedClients[:]); err != nil {
+ slog.Error("publishSingleHostUpdate", "host", host.Name, "error", err)
+ }
+ if err := mq.NodeUpdate(&node); err != nil {
+ slog.Error("error publishing node update to node", "node", node.ID, "error", err)
+ }
+ }()
}
}
-
- mq.RunUpdates(&node, true)
}
// swagger:route PUT /api/nodes/{network}/{nodeid} nodes updateNode
@@ -660,9 +667,11 @@ func updateNode(w http.ResponseWriter, r *http.Request) {
logger.Log(1, r.Header.Get("user"), "updated node", currentNode.ID.String(), "on network", currentNode.Network)
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(apiNode)
- mq.RunUpdates(newNode, ifaceDelta)
go func(aclUpdate, relayupdate bool, newNode *models.Node) {
- if aclUpdate || relayupdate {
+ if err := mq.NodeUpdate(newNode); err != nil {
+ slog.Error("error publishing node update to node", "node", newNode.ID, "error", err)
+ }
+ if aclUpdate || relayupdate || ifaceDelta {
if err := mq.PublishPeerUpdate(); err != nil {
logger.Log(0, "error during node ACL update for node", newNode.ID.String())
}
@@ -735,13 +744,13 @@ func deleteNode(w http.ResponseWriter, r *http.Request) {
logic.ReturnSuccessResponse(w, r, nodeid+" deleted.")
logger.Log(1, r.Header.Get("user"), "Deleted node", nodeid, "from network", params["network"])
- if !fromNode { // notify node change
- mq.RunUpdates(&node, false)
- }
go func() { // notify of peer change
- var err error
- err = mq.PublishDeletedNodePeerUpdate(&node)
- if err != nil {
+ if !fromNode {
+ if err := mq.NodeUpdate(&node); err != nil {
+ slog.Error("error publishing node update to node", "node", node.ID, "error", err)
+ }
+ }
+ if err := mq.PublishDeletedNodePeerUpdate(&node); err != nil {
logger.Log(1, "error publishing peer update ", err.Error())
}
host, err := logic.GetHost(node.HostID.String())
diff --git a/controllers/server.go b/controllers/server.go
index b4d4f6964..d6a10f547 100644
--- a/controllers/server.go
+++ b/controllers/server.go
@@ -6,6 +6,7 @@ import (
"strings"
"github.com/gorilla/mux"
+
"github.com/gravitl/netmaker/database"
"github.com/gravitl/netmaker/logic"
"github.com/gravitl/netmaker/models"
@@ -15,24 +16,32 @@ import (
func serverHandlers(r *mux.Router) {
// r.HandleFunc("/api/server/addnetwork/{network}", securityCheckServer(true, http.HandlerFunc(addNetwork))).Methods(http.MethodPost)
- r.HandleFunc("/api/server/health", http.HandlerFunc(func(resp http.ResponseWriter, req *http.Request) {
- resp.WriteHeader(http.StatusOK)
- resp.Write([]byte("Server is up and running!!"))
- }))
- r.HandleFunc("/api/server/getconfig", allowUsers(http.HandlerFunc(getConfig))).Methods(http.MethodGet)
- r.HandleFunc("/api/server/getserverinfo", Authorize(true, false, "node", http.HandlerFunc(getServerInfo))).Methods(http.MethodGet)
+ r.HandleFunc(
+ "/api/server/health",
+ http.HandlerFunc(func(resp http.ResponseWriter, req *http.Request) {
+ resp.WriteHeader(http.StatusOK)
+ resp.Write([]byte("Server is up and running!!"))
+ }),
+ )
+ r.HandleFunc("/api/server/getconfig", allowUsers(http.HandlerFunc(getConfig))).
+ Methods(http.MethodGet)
+ r.HandleFunc("/api/server/getserverinfo", Authorize(true, false, "node", http.HandlerFunc(getServerInfo))).
+ Methods(http.MethodGet)
r.HandleFunc("/api/server/status", http.HandlerFunc(getStatus)).Methods(http.MethodGet)
- r.HandleFunc("/api/server/usage", Authorize(true, false, "user", http.HandlerFunc(getUsage))).Methods(http.MethodGet)
+ r.HandleFunc("/api/server/usage", Authorize(true, false, "user", http.HandlerFunc(getUsage))).
+ Methods(http.MethodGet)
}
-func getUsage(w http.ResponseWriter, r *http.Request) {
+func getUsage(w http.ResponseWriter, _ *http.Request) {
type usage struct {
- Hosts int `json:"hosts"`
- Clients int `json:"clients"`
- Networks int `json:"networks"`
- Users int `json:"users"`
- Ingresses int `json:"ingresses"`
- Egresses int `json:"egresses"`
+ Hosts int `json:"hosts"`
+ Clients int `json:"clients"`
+ Networks int `json:"networks"`
+ Users int `json:"users"`
+ Ingresses int `json:"ingresses"`
+ Egresses int `json:"egresses"`
+ Relays int `json:"relays"`
+ InternetGateways int `json:"internet_gateways"`
}
var serverUsage usage
hosts, err := logic.GetAllHosts()
@@ -51,6 +60,7 @@ func getUsage(w http.ResponseWriter, r *http.Request) {
if err == nil {
serverUsage.Networks = len(networks)
}
+ // TODO this part bellow can be optimized to get nodes just once
ingresses, err := logic.GetAllIngresses()
if err == nil {
serverUsage.Ingresses = len(ingresses)
@@ -59,12 +69,19 @@ func getUsage(w http.ResponseWriter, r *http.Request) {
if err == nil {
serverUsage.Egresses = len(egresses)
}
+ relays, err := logic.GetRelays()
+ if err == nil {
+ serverUsage.Relays = len(relays)
+ }
+ gateways, err := logic.GetInternetGateways()
+ if err == nil {
+ serverUsage.InternetGateways = len(gateways)
+ }
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(models.SuccessResponse{
Code: http.StatusOK,
Response: serverUsage,
})
-
}
// swagger:route GET /api/server/status server getStatus
@@ -83,6 +100,7 @@ func getStatus(w http.ResponseWriter, r *http.Request) {
DB bool `json:"db_connected"`
Broker bool `json:"broker_connected"`
LicenseError string `json:"license_error"`
+ IsPro bool `json:"is_pro"`
}
licenseErr := ""
@@ -94,6 +112,7 @@ func getStatus(w http.ResponseWriter, r *http.Request) {
DB: database.IsConnected(),
Broker: mq.IsConnected(),
LicenseError: licenseErr,
+ IsPro: servercfg.IsPro,
}
w.Header().Set("Content-Type", "application/json")
@@ -103,12 +122,12 @@ func getStatus(w http.ResponseWriter, r *http.Request) {
// allowUsers - allow all authenticated (valid) users - only used by getConfig, may be able to remove during refactor
func allowUsers(next http.Handler) http.HandlerFunc {
return func(w http.ResponseWriter, r *http.Request) {
- var errorResponse = models.ErrorResponse{
+ errorResponse := models.ErrorResponse{
Code: http.StatusUnauthorized, Message: logic.Unauthorized_Msg,
}
bearerToken := r.Header.Get("Authorization")
- var tokenSplit = strings.Split(bearerToken, " ")
- var authToken = ""
+ tokenSplit := strings.Split(bearerToken, " ")
+ authToken := ""
if len(tokenSplit) < 2 {
logic.ReturnErrorResponse(w, r, errorResponse)
return
@@ -142,7 +161,7 @@ func getServerInfo(w http.ResponseWriter, r *http.Request) {
// get params
json.NewEncoder(w).Encode(servercfg.GetServerInfo())
- //w.WriteHeader(http.StatusOK)
+ // w.WriteHeader(http.StatusOK)
}
// swagger:route GET /api/server/getconfig server getConfig
@@ -168,5 +187,5 @@ func getConfig(w http.ResponseWriter, r *http.Request) {
scfg.IsPro = "yes"
}
json.NewEncoder(w).Encode(scfg)
- //w.WriteHeader(http.StatusOK)
+ // w.WriteHeader(http.StatusOK)
}
diff --git a/controllers/user.go b/controllers/user.go
index 69f05d677..ff06a67e7 100644
--- a/controllers/user.go
+++ b/controllers/user.go
@@ -12,6 +12,7 @@ import (
"github.com/gravitl/netmaker/logger"
"github.com/gravitl/netmaker/logic"
"github.com/gravitl/netmaker/models"
+ "github.com/gravitl/netmaker/mq"
"github.com/gravitl/netmaker/servercfg"
"golang.org/x/exp/slog"
)
@@ -36,9 +37,9 @@ func userHandlers(r *mux.Router) {
r.HandleFunc("/api/oauth/register/{regKey}", auth.RegisterHostSSO).Methods(http.MethodGet)
}
-// swagger:route POST /api/users/adm/authenticate user authenticateUser
+// swagger:route POST /api/users/adm/authenticate authenticate authenticateUser
//
-// Node authenticates using its password and retrieves a JWT for authorization.
+// User authenticates using its password and retrieves a JWT for authorization.
//
// Schemes: https
//
@@ -96,7 +97,6 @@ func authenticateUser(response http.ResponseWriter, request *http.Request) {
}
// Send back the JWT
successJSONResponse, jsonError := json.Marshal(successResponse)
-
if jsonError != nil {
logger.Log(0, username,
"error marshalling resp: ", err.Error())
@@ -106,6 +106,33 @@ func authenticateUser(response http.ResponseWriter, request *http.Request) {
logger.Log(2, username, "was authenticated")
response.Header().Set("Content-Type", "application/json")
response.Write(successJSONResponse)
+
+ go func() {
+ if servercfg.IsPro && servercfg.GetRacAutoDisable() {
+ // enable all associeated clients for the user
+ clients, err := logic.GetAllExtClients()
+ if err != nil {
+ slog.Error("error getting clients: ", "error", err)
+ return
+ }
+ for _, client := range clients {
+ if client.OwnerID == username && !client.Enabled {
+ slog.Info(fmt.Sprintf("enabling ext client %s for user %s due to RAC autodisabling feature", client.ClientID, client.OwnerID))
+ if newClient, err := logic.ToggleExtClientConnectivity(&client, true); err != nil {
+ slog.Error("error disabling ext client in RAC autodisable hook", "error", err)
+ continue // dont return but try for other clients
+ } else {
+ // publish peer update to ingress gateway
+ if ingressNode, err := logic.GetNodeByID(newClient.IngressGatewayID); err == nil {
+ if err = mq.PublishPeerUpdate(); err != nil {
+ slog.Error("error updating ext clients on", "ingress", ingressNode.ID.String(), "err", err.Error())
+ }
+ }
+ }
+ }
+ }
+ }
+ }()
}
// swagger:route GET /api/users/adm/hassuperadmin user hasSuperAdmin
@@ -118,7 +145,7 @@ func authenticateUser(response http.ResponseWriter, request *http.Request) {
// oauth
//
// Responses:
-// 200: successResponse
+// 200: hasAdmin
func hasSuperAdmin(w http.ResponseWriter, r *http.Request) {
w.Header().Set("Content-Type", "application/json")
@@ -426,9 +453,8 @@ func updateUser(w http.ResponseWriter, r *http.Request) {
}
}
- if auth.IsOauthUser(user) == nil {
- err := fmt.Errorf("cannot update user info for oauth user %s", username)
- logger.Log(0, err.Error())
+ if auth.IsOauthUser(user) == nil && userchange.Password != "" {
+ err := fmt.Errorf("cannot update user's password for an oauth user %s", username)
logic.ReturnErrorResponse(w, r, logic.FormatError(err, "forbidden"))
return
}
diff --git a/docker/Caddyfile b/docker/Caddyfile
index 8fb74138a..4f893bb47 100644
--- a/docker/Caddyfile
+++ b/docker/Caddyfile
@@ -1,6 +1,5 @@
# Dashboard
https://dashboard.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
# Apply basic security headers
header {
# Enable cross origin access to *.{$NM_DOMAIN}
@@ -22,24 +21,20 @@ https://dashboard.{$NM_DOMAIN} {
# API
https://api.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://netmaker:8081
}
# TURN
https://turn.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy host.docker.internal:3479
}
# TURN API
https://turnapi.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://host.docker.internal:8089
}
# MQ
wss://broker.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy ws://mq:8883 # For EMQX websockets use `reverse_proxy ws://mq:8083`
}
diff --git a/docker/Caddyfile-pro b/docker/Caddyfile-pro
index 2b874debc..a0edf2206 100644
--- a/docker/Caddyfile-pro
+++ b/docker/Caddyfile-pro
@@ -1,6 +1,5 @@
# Dashboard
https://dashboard.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
# Apply basic security headers
header {
# Enable cross origin access to *.{$NM_DOMAIN}
@@ -22,42 +21,35 @@ https://dashboard.{$NM_DOMAIN} {
# Netmaker Exporter
https://netmaker-exporter.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://netmaker-exporter:8085
}
# Prometheus
https://prometheus.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://prometheus:9090
}
# Grafana
https://grafana.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://grafana:3000
}
# API
https://api.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://netmaker:8081
}
# TURN
https://turn.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy host.docker.internal:3479
}
# TURN API
https://turnapi.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy http://host.docker.internal:8089
}
# MQ
wss://broker.{$NM_DOMAIN} {
- tls /root/certs/fullchain.pem /root/certs/privkey.pem
reverse_proxy ws://mq:8883
}
diff --git a/go.mod b/go.mod
index 951c4b1ae..46423f016 100644
--- a/go.mod
+++ b/go.mod
@@ -4,7 +4,7 @@ go 1.19
require (
github.com/eclipse/paho.mqtt.golang v1.4.3
- github.com/go-playground/validator/v10 v10.15.1
+ github.com/go-playground/validator/v10 v10.15.5
github.com/golang-jwt/jwt/v4 v4.5.0
github.com/google/uuid v1.3.1
github.com/gorilla/handlers v1.5.1
@@ -14,12 +14,12 @@ require (
github.com/rqlite/gorqlite v0.0.0-20210514125552-08ff1e76b22f
github.com/skip2/go-qrcode v0.0.0-20200617195104-da1b6568686e
github.com/stretchr/testify v1.8.4
- github.com/txn2/txeh v1.5.3
- golang.org/x/crypto v0.12.0
- golang.org/x/net v0.14.0 // indirect
- golang.org/x/oauth2 v0.11.0
- golang.org/x/sys v0.11.0 // indirect
- golang.org/x/text v0.12.0 // indirect
+ github.com/txn2/txeh v1.5.5
+ golang.org/x/crypto v0.13.0
+ golang.org/x/net v0.15.0 // indirect
+ golang.org/x/oauth2 v0.12.0
+ golang.org/x/sys v0.12.0 // indirect
+ golang.org/x/text v0.13.0 // indirect
golang.zx2c4.com/wireguard/wgctrl v0.0.0-20221104135756-97bc4ad4a1cb
google.golang.org/protobuf v1.31.0 // indirect
gopkg.in/yaml.v3 v3.0.1
diff --git a/go.sum b/go.sum
index f8fed2438..8addbbd63 100644
--- a/go.sum
+++ b/go.sum
@@ -30,8 +30,8 @@ github.com/go-playground/locales v0.14.1 h1:EWaQ/wswjilfKLTECiXz7Rh+3BjFhfDFKv/o
github.com/go-playground/locales v0.14.1/go.mod h1:hxrqLVvrK65+Rwrd5Fc6F2O76J/NuW9t0sjnWqG1slY=
github.com/go-playground/universal-translator v0.18.1 h1:Bcnm0ZwsGyWbCzImXv+pAJnYK9S473LQFuzCbDbfSFY=
github.com/go-playground/universal-translator v0.18.1/go.mod h1:xekY+UJKNuX9WP91TpwSH2VMlDf28Uj24BCp08ZFTUY=
-github.com/go-playground/validator/v10 v10.15.1 h1:BSe8uhN+xQ4r5guV/ywQI4gO59C2raYcGffYWZEjZzM=
-github.com/go-playground/validator/v10 v10.15.1/go.mod h1:9iXMNT7sEkjXb0I+enO7QXmzG6QCsPWY4zveKFVRSyU=
+github.com/go-playground/validator/v10 v10.15.5 h1:LEBecTWb/1j5TNY1YYG2RcOUN3R7NLylN+x8TTueE24=
+github.com/go-playground/validator/v10 v10.15.5/go.mod h1:9iXMNT7sEkjXb0I+enO7QXmzG6QCsPWY4zveKFVRSyU=
github.com/golang-jwt/jwt/v4 v4.5.0 h1:7cYmW1XlMY7h7ii7UhUyChSgS5wUJEnm9uZVTGqOWzg=
github.com/golang-jwt/jwt/v4 v4.5.0/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
github.com/golang/protobuf v1.3.1/go.mod h1:6lQm79b+lXiMfvg/cZm0SGofjICqVBUtrP5yJMmIC1U=
@@ -96,33 +96,33 @@ github.com/stretchr/testify v1.8.0/go.mod h1:yNjHg4UonilssWZ8iaSj1OCr/vHnekPRkoO
github.com/stretchr/testify v1.8.2/go.mod h1:w2LPCIKwWwSfY2zedu0+kehJoqGctiVI29o6fzry7u4=
github.com/stretchr/testify v1.8.4 h1:CcVxjf3Q8PM0mHUKJCdn+eZZtm5yQwehR5yeSVQQcUk=
github.com/stretchr/testify v1.8.4/go.mod h1:sz/lmYIOXD/1dqDmKjjqLyZ2RngseejIcXlSw2iwfAo=
-github.com/txn2/txeh v1.5.3 h1:ZMgc3r+5/AFtE/ayCoICpvxj7xl/CYsZjnIGhozV/Kc=
-github.com/txn2/txeh v1.5.3/go.mod h1:qYzGG9kCzeVEI12geK4IlanHWY8X4uy/I3NcW7mk8g4=
+github.com/txn2/txeh v1.5.5 h1:UN4e/lCK5HGw/gGAi2GCVrNKg0GTCUWs7gs5riaZlz4=
+github.com/txn2/txeh v1.5.5/go.mod h1:qYzGG9kCzeVEI12geK4IlanHWY8X4uy/I3NcW7mk8g4=
github.com/urfave/cli v1.22.5/go.mod h1:Gos4lmkARVdJ6EkW0WaNv/tZAAMe9V7XWyB60NtXRu0=
github.com/xtgo/uuid v0.0.0-20140804021211-a0b114877d4c h1:3lbZUMbMiGUW/LMkfsEABsc5zNT9+b1CvsJx47JzJ8g=
github.com/xtgo/uuid v0.0.0-20140804021211-a0b114877d4c/go.mod h1:UrdRz5enIKZ63MEE3IF9l2/ebyx59GyGgPi+tICQdmM=
golang.org/x/crypto v0.0.0-20190308221718-c2843e01d9a2/go.mod h1:djNgcEr1/C05ACkg1iLfiJU5Ep61QUkGW8qpdssI0+w=
golang.org/x/crypto v0.0.0-20190911031432-227b76d455e7/go.mod h1:yigFU9vqHzYiE8UmvKecakEJjdnWj3jj499lnFckfCI=
-golang.org/x/crypto v0.12.0 h1:tFM/ta59kqch6LlvYnPa0yx5a83cL2nHflFhYKvv9Yk=
-golang.org/x/crypto v0.12.0/go.mod h1:NF0Gs7EO5K4qLn+Ylc+fih8BSTeIjAP05siRnAh98yw=
+golang.org/x/crypto v0.13.0 h1:mvySKfSWJ+UKUii46M40LOvyWfN0s2U+46/jDd0e6Ck=
+golang.org/x/crypto v0.13.0/go.mod h1:y6Z2r+Rw4iayiXXAIxJIDAJ1zMW4yaTpebo8fPOliYc=
golang.org/x/exp v0.0.0-20230522175609-2e198f4a06a1 h1:k/i9J1pBpvlfR+9QsetwPyERsqu1GIbi967PQMq3Ivc=
golang.org/x/exp v0.0.0-20230522175609-2e198f4a06a1/go.mod h1:V1LtkGg67GoY2N1AnLN78QLrzxkLyJw7RJb1gzOOz9w=
golang.org/x/net v0.0.0-20190404232315-eb5bcb51f2a3/go.mod h1:t9HGtf8HONx5eT2rtn7q6eTqICYqUVnKs3thJo3Qplg=
golang.org/x/net v0.0.0-20190603091049-60506f45cf65/go.mod h1:HSz+uSET+XFnRR8LxR5pz3Of3rY3CfYBVs4xY44aLks=
-golang.org/x/net v0.14.0 h1:BONx9s002vGdD9umnlX1Po8vOZmrgH34qlHcD1MfK14=
-golang.org/x/net v0.14.0/go.mod h1:PpSgVXXLK0OxS0F31C1/tv6XNguvCrnXIDrFMspZIUI=
-golang.org/x/oauth2 v0.11.0 h1:vPL4xzxBM4niKCW6g9whtaWVXTJf1U5e4aZxxFx/gbU=
-golang.org/x/oauth2 v0.11.0/go.mod h1:LdF7O/8bLR/qWK9DrpXmbHLTouvRHK0SgJl0GmDBchk=
+golang.org/x/net v0.15.0 h1:ugBLEUaxABaB5AJqW9enI0ACdci2RUd4eP51NTBvuJ8=
+golang.org/x/net v0.15.0/go.mod h1:idbUs1IY1+zTqbi8yxTbhexhEEk5ur9LInksu6HrEpk=
+golang.org/x/oauth2 v0.12.0 h1:smVPGxink+n1ZI5pkQa8y6fZT0RW0MgCO5bFpepy4B4=
+golang.org/x/oauth2 v0.12.0/go.mod h1:A74bZ3aGXgCY0qaIC9Ahg6Lglin4AMAco8cIv9baba4=
golang.org/x/sync v0.1.0 h1:wsuoTGHzEhffawBOhz5CYhcrV4IdKZbEyZjBMuTp12o=
golang.org/x/sync v0.1.0/go.mod h1:RxMgew5VJxzue5/jJTE5uejpjVlOe/izrB70Jof72aM=
golang.org/x/sys v0.0.0-20190215142949-d0b11bdaac8a/go.mod h1:STP8DvDyc/dI5b8T5hshtkjS+E42TnysNCUPdjciGhY=
golang.org/x/sys v0.0.0-20190412213103-97732733099d/go.mod h1:h1NjWce9XRLGQEsW7wpKNCjG9DtNlClVuFLEZdDNbEs=
-golang.org/x/sys v0.11.0 h1:eG7RXZHdqOJ1i+0lgLgCpSXAp6M3LYlAo6osgSi0xOM=
-golang.org/x/sys v0.11.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
+golang.org/x/sys v0.12.0 h1:CM0HF96J0hcLAwsHPJZjfdNzs0gftsLfgKt57wWHJ0o=
+golang.org/x/sys v0.12.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
golang.org/x/text v0.3.0/go.mod h1:NqM8EUOU14njkJ3fqMW+pc6Ldnwhi/IjpwHt7yyuwOQ=
golang.org/x/text v0.3.2/go.mod h1:bEr9sfX3Q8Zfm5fL9x+3itogRgK3+ptLWKqgva+5dAk=
-golang.org/x/text v0.12.0 h1:k+n5B8goJNdU7hSvEtMUz3d1Q6D/XW4COJSJR6fN0mc=
-golang.org/x/text v0.12.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
+golang.org/x/text v0.13.0 h1:ablQoSUd0tRdKxZewP80B+BaqeKJuVhuRxj/dkrun3k=
+golang.org/x/text v0.13.0/go.mod h1:TvPlkZtksWOMsz7fbANvkp4WM8x/WCo/om8BMLbz+aE=
golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0=
golang.zx2c4.com/wireguard/wgctrl v0.0.0-20221104135756-97bc4ad4a1cb h1:9aqVcYEDHmSNb0uOWukxV5lHV09WqiSiCuhEgWNETLY=
diff --git a/k8s/client/netclient-daemonset.yaml b/k8s/client/netclient-daemonset.yaml
index 12c897564..d01612917 100644
--- a/k8s/client/netclient-daemonset.yaml
+++ b/k8s/client/netclient-daemonset.yaml
@@ -16,7 +16,7 @@ spec:
hostNetwork: true
containers:
- name: netclient
- image: gravitl/netclient:v0.21.0
+ image: gravitl/netclient:v0.21.1
env:
- name: TOKEN
value: "TOKEN_VALUE"
diff --git a/k8s/client/netclient.yaml b/k8s/client/netclient.yaml
index f329be78a..0152ff960 100644
--- a/k8s/client/netclient.yaml
+++ b/k8s/client/netclient.yaml
@@ -28,7 +28,7 @@ spec:
# - "