109ba2ce27
ci/woodpecker/tag/docker Pipeline was successful
## Why Anonymous GitHub is capped at 60 requests/hour and cannot read private repositories. A machine credential usable by a free (non-enterprise) account is needed to lift the request budget to ~5000/hr and to read private-repo release assets. Builds on the background syncer (#108, now merged to `master`); this diff is the auth changes only. ## How - Add `internal/githubauth`: a process-wide GitHub credential delivered via env/secret, applied by default to every outbound GitHub request (releases scan, ranged asset-header GETs, and the generic-github byte proxy for private assets). - Support two modes: - **PAT** — `GITHUB_TOKEN` sent as `Authorization: Bearer <token>`. - **GitHub App** — `GITHUB_APP_ID` + `GITHUB_APP_INSTALLATION_ID` + private key (`GITHUB_APP_PRIVATE_KEY` inline PEM or `GITHUB_APP_PRIVATE_KEY_PATH`). Mint a short-lived RS256 JWT with stdlib `crypto/rsa` (no new dependency), exchange it at `POST /app/installations/{id}/access_tokens` for a ~1h installation token, cache it, and single-flight a refresh a few minutes before expiry. - Inject at the two GitHub call paths: the rpm github provider header builder (releases + ranged fetches) and the generic provider `AuthHeaders` (byte proxy, github.com hosts only; the pre-signed `objects.githubusercontent.com` redirect deliberately gets no Authorization). - Honor precedence: a remote's own `username`/`password` overrides the server credential; no credential configured stays anonymous (current behavior). - Fail closed at startup on partial App configuration (e.g. App id without a private key); a token-and-App conflict is also rejected. - Never persist the credential to the DB, return it from an API, or log it (token-exchange failures never echo the response body). - Read config via the existing `getenv` convention; document PAT vs App setup, the free-account fine-grained PAT scopes (Contents:read + Metadata:read), precedence, and the rate-limit implication. ## Rate limit Authenticated requests share the syncer's single global limiter — no second limiter is added. A token raises the effective GitHub ceiling (~5000/hr vs ~60/hr), so the limiter defaults stay safe. ## Tests `internal/githubauth` and `internal/provider/{rpm,generic}`: - PAT attaches the correct `Authorization` header to releases + asset-header requests. - App mints a valid RS256 JWT (verified against the app public key), exchanges it at a mocked endpoint, reuses the cached token without re-exchanging, refreshes near expiry, and single-flights concurrent callers. - Per-remote credential overrides the server credential (rpm + generic). - No credential → no `Authorization` header, requests still succeed anonymously. - ETag/304 flow still works with auth attached. - The credential does not appear in a remote's serialized JSON. - Config validation: no-config is anonymous; partial App config and token/App conflict both error. Verified fail-before/pass-after for the injection tests. `gofmt -l`, `go build ./...`, `go vet ./...`, `go test ./...` all clean (26 packages). Reviewed-on: #109 Co-authored-by: Ben Vincent <ben@unkin.net> Co-committed-by: Ben Vincent <ben@unkin.net>
265 lines
8.2 KiB
Go
265 lines
8.2 KiB
Go
package server
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"fmt"
|
|
"log/slog"
|
|
"net"
|
|
"net/http"
|
|
"time"
|
|
|
|
"github.com/go-chi/chi/v5"
|
|
"github.com/go-chi/chi/v5/middleware"
|
|
|
|
tfregistry "git.unkin.net/unkin/artifactapi/internal/api/terraform"
|
|
v1 "git.unkin.net/unkin/artifactapi/internal/api/v1"
|
|
v2 "git.unkin.net/unkin/artifactapi/internal/api/v2"
|
|
"git.unkin.net/unkin/artifactapi/internal/cache"
|
|
"git.unkin.net/unkin/artifactapi/internal/config"
|
|
"git.unkin.net/unkin/artifactapi/internal/database"
|
|
"git.unkin.net/unkin/artifactapi/internal/gc"
|
|
"git.unkin.net/unkin/artifactapi/internal/githubauth"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/alpine"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/docker"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/generic"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/goproxy"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/helm"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/npm"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/puppet"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/pypi"
|
|
"git.unkin.net/unkin/artifactapi/internal/provider/rpm"
|
|
_ "git.unkin.net/unkin/artifactapi/internal/provider/terraform"
|
|
"git.unkin.net/unkin/artifactapi/internal/proxy"
|
|
"git.unkin.net/unkin/artifactapi/internal/storage"
|
|
"git.unkin.net/unkin/artifactapi/internal/tfsign"
|
|
"git.unkin.net/unkin/artifactapi/internal/virtual"
|
|
)
|
|
|
|
type Server struct {
|
|
cfg *config.Config
|
|
version string
|
|
router chi.Router
|
|
db *database.DB
|
|
cache *cache.Redis
|
|
store *storage.S3
|
|
engine *proxy.Engine
|
|
virtEngine *virtual.Engine
|
|
localHandler *v2.LocalHandler
|
|
tfRegistry *tfregistry.Handler
|
|
gc *gc.Collector
|
|
syncer *rpm.Syncer
|
|
}
|
|
|
|
func New(cfg *config.Config, version string) (*Server, error) {
|
|
db, err := database.New(cfg.DatabaseDSN())
|
|
if err != nil {
|
|
return nil, fmt.Errorf("database: %w", err)
|
|
}
|
|
|
|
redis, err := cache.NewRedis(cfg.RedisURL)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("redis: %w", err)
|
|
}
|
|
|
|
s3, err := storage.NewS3(cfg.S3Endpoint, cfg.S3AccessKey, cfg.S3SecretKey, cfg.S3Bucket, cfg.S3Secure, cfg.S3Region)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("s3: %w", err)
|
|
}
|
|
|
|
// Install the process-wide GitHub credential before any provider makes an
|
|
// outbound call. A misconfiguration (e.g. App id without a private key) fails
|
|
// closed here rather than silently falling back to anonymous. No credential
|
|
// configured is fine — requests stay anonymous.
|
|
ghCred, err := githubauth.New(githubauth.Options{
|
|
Token: cfg.GitHubToken,
|
|
AppID: cfg.GitHubAppID,
|
|
InstallationID: cfg.GitHubAppInstallationID,
|
|
PrivateKeyPEM: cfg.GitHubAppPrivateKey,
|
|
PrivateKeyPath: cfg.GitHubAppPrivateKeyPath,
|
|
})
|
|
if err != nil {
|
|
return nil, fmt.Errorf("github auth: %w", err)
|
|
}
|
|
githubauth.SetServer(ghCred)
|
|
if ghCred != nil {
|
|
slog.Info("github machine credential configured")
|
|
}
|
|
|
|
engine := proxy.NewEngine(db, redis, s3)
|
|
localHandler := v2.NewLocalHandler(db, s3)
|
|
virtEngine := virtual.NewEngine(db, engine)
|
|
collector := gc.New(db, s3, 1*time.Hour)
|
|
syncer := rpm.NewSyncer(db, rpm.SyncConfig{
|
|
RatePerSec: cfg.GitHubSyncRatePerSec,
|
|
Burst: cfg.GitHubSyncBurst,
|
|
Workers: cfg.GitHubSyncWorkers,
|
|
PollInterval: time.Duration(cfg.GitHubSyncPollInterval) * time.Second,
|
|
})
|
|
|
|
// The terraform registry signs with a GPG key. A configured file wins (BYO
|
|
// key); otherwise artifactapi generates one on first start and persists it in
|
|
// the database so every replica shares it. A failure here must not take the
|
|
// server down — the registry just stays disabled.
|
|
var signer *tfsign.Signer
|
|
if cfg.TFSigningKeyPath != "" {
|
|
signer, err = tfsign.Load(cfg.TFSigningKeyPath, cfg.TFSigningKeyPassphrase)
|
|
} else {
|
|
signer, err = tfsign.LoadOrCreate(context.Background(), db, "terraform-provider")
|
|
}
|
|
if err != nil {
|
|
slog.Warn("terraform provider registry disabled", "error", err)
|
|
signer = nil
|
|
}
|
|
tfRegistry := tfregistry.NewHandler(db, signer, cfg.TFProviderProtocols)
|
|
if tfRegistry.Enabled() {
|
|
slog.Info("terraform provider registry enabled", "key_id", signer.KeyID())
|
|
}
|
|
|
|
s := &Server{
|
|
cfg: cfg,
|
|
version: version,
|
|
db: db,
|
|
cache: redis,
|
|
store: s3,
|
|
engine: engine,
|
|
virtEngine: virtEngine,
|
|
localHandler: localHandler,
|
|
tfRegistry: tfRegistry,
|
|
gc: collector,
|
|
syncer: syncer,
|
|
}
|
|
|
|
s.router = s.routes()
|
|
return s, nil
|
|
}
|
|
|
|
func (s *Server) routes() chi.Router {
|
|
r := chi.NewRouter()
|
|
|
|
r.Use(middleware.RequestID)
|
|
r.Use(middleware.RealIP)
|
|
r.Use(NewStructuredLogger())
|
|
r.Use(middleware.Recoverer)
|
|
|
|
r.Use(cors)
|
|
|
|
r.Get("/health", s.handleHealth)
|
|
r.Get("/", s.handleRoot)
|
|
r.Get("/version", s.handleVersion)
|
|
|
|
// Terraform provider registry: service discovery at the well-known path,
|
|
// providers.v1 protocol under /terraform/v1/providers.
|
|
r.Get("/.well-known/terraform.json", s.tfRegistry.ServiceDiscovery)
|
|
r.Mount(tfregistry.MountPath, s.tfRegistry.Routes())
|
|
|
|
proxyHandler := v1.NewProxyHandler(s.engine, s.virtEngine, s.db, s.store, s.localHandler)
|
|
r.Mount("/api/v1", proxyHandler.Routes())
|
|
r.Mount("/v2", proxyHandler.DockerV2Routes())
|
|
|
|
remotesHandler := v2.NewRemotesHandler(s.db, s.syncer)
|
|
virtualsHandler := v2.NewVirtualsHandler(s.db)
|
|
healthHandler := v2.NewHealthHandler(s.db, s.cache, s.store)
|
|
statsHandler := v2.NewStatsHandler(s.db)
|
|
eventsHandler := v2.NewEventsHandler()
|
|
probeHandler := v2.NewProbeHandler(s.engine, s.db)
|
|
|
|
r.Route("/api/v2", func(r chi.Router) {
|
|
r.Mount("/remotes", remotesHandler.Routes())
|
|
r.Mount("/virtuals", virtualsHandler.Routes())
|
|
r.Mount("/health", healthHandler.Routes())
|
|
r.Mount("/stats", statsHandler.Routes())
|
|
r.Mount("/events", eventsHandler.Routes())
|
|
r.Mount("/probe", probeHandler.Routes())
|
|
|
|
r.Route("/remotes/{name}/objects", func(r chi.Router) {
|
|
objHandler := v2.NewObjectsHandler(s.db)
|
|
r.Get("/", objHandler.Routes().ServeHTTP)
|
|
r.Delete("/*", objHandler.Routes().ServeHTTP)
|
|
})
|
|
|
|
r.Route("/locals/{name}/objects", func(r chi.Router) {
|
|
objHandler := v2.NewObjectsHandler(s.db)
|
|
r.Get("/", objHandler.LocalRoutes().ServeHTTP)
|
|
r.Delete("/*", objHandler.LocalRoutes().ServeHTTP)
|
|
})
|
|
|
|
r.Route("/remotes/{name}/files", func(r chi.Router) {
|
|
r.Put("/*", s.localHandler.Routes().ServeHTTP)
|
|
r.Get("/*", s.localHandler.Routes().ServeHTTP)
|
|
r.Delete("/*", s.localHandler.Routes().ServeHTTP)
|
|
})
|
|
})
|
|
|
|
return r
|
|
}
|
|
|
|
func (s *Server) handleHealth(w http.ResponseWriter, r *http.Request) {
|
|
w.Header().Set("Content-Type", "application/json")
|
|
w.WriteHeader(http.StatusOK)
|
|
fmt.Fprint(w, `{"status":"ok"}`)
|
|
}
|
|
|
|
// handleRoot sends browsers landing on the bare domain to the web UI, which is
|
|
// served under /ui. The service identity that used to live here is at /version.
|
|
func (s *Server) handleRoot(w http.ResponseWriter, r *http.Request) {
|
|
http.Redirect(w, r, "/ui/", http.StatusFound)
|
|
}
|
|
|
|
func (s *Server) handleVersion(w http.ResponseWriter, r *http.Request) {
|
|
w.Header().Set("Content-Type", "application/json")
|
|
w.WriteHeader(http.StatusOK)
|
|
fmt.Fprintf(w, `{"name":"artifactapi","version":"%s"}`, s.version)
|
|
}
|
|
|
|
func (s *Server) newHTTPServer() *http.Server {
|
|
return &http.Server{
|
|
Addr: s.cfg.ListenAddr,
|
|
Handler: s.router,
|
|
ReadTimeout: 30 * time.Second,
|
|
WriteTimeout: 300 * time.Second,
|
|
IdleTimeout: 120 * time.Second,
|
|
}
|
|
}
|
|
|
|
func (s *Server) Run(ctx context.Context) error {
|
|
go s.gc.Run(ctx)
|
|
go s.syncer.Run(ctx)
|
|
|
|
httpServer := s.newHTTPServer()
|
|
|
|
go func() {
|
|
<-ctx.Done()
|
|
slog.Info("shutting down server")
|
|
shutdownCtx, cancel := context.WithTimeout(context.Background(), 10*time.Second)
|
|
defer cancel()
|
|
_ = httpServer.Shutdown(shutdownCtx)
|
|
}()
|
|
|
|
slog.Info("starting server", "addr", s.cfg.ListenAddr)
|
|
if err := httpServer.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
|
return err
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func (s *Server) RunOnListener(ctx context.Context, ln net.Listener) error {
|
|
go s.gc.Run(ctx)
|
|
go s.syncer.Run(ctx)
|
|
|
|
httpServer := s.newHTTPServer()
|
|
|
|
go func() {
|
|
<-ctx.Done()
|
|
shutdownCtx, cancel := context.WithTimeout(context.Background(), 10*time.Second)
|
|
defer cancel()
|
|
_ = httpServer.Shutdown(shutdownCtx)
|
|
}()
|
|
|
|
slog.Info("starting server", "addr", ln.Addr().String())
|
|
if err := httpServer.Serve(ln); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
|
return err
|
|
}
|
|
return nil
|
|
}
|