mirror of
https://github.com/outbackdingo/patroni.git
synced 2026-08-25 14:53:37 +00:00
Merge pull request #35 from zalando/feature/basic-auth
Basic-auth and SSL support
This commit is contained in:
+46
-78
@@ -52,94 +52,62 @@ YAML Configuration
|
||||
For an example file, see ``postgres0.yml``. Below is an explanation of
|
||||
settings:
|
||||
|
||||
- *ttl*: the TTL to acquire the leader lock. Think of it as the length
|
||||
of time before automatic failover process is initiated.
|
||||
- *ttl*: the TTL to acquire the leader lock. Think of it as the length of time before automatic failover process is initiated.
|
||||
- *loop\_wait*: the number of seconds the loop will sleep
|
||||
|
||||
- *restapi*
|
||||
- *listen*: ip address + port that Patroni will listen to provide
|
||||
health-check information for haproxy.
|
||||
- *connect\_address*: ip address + port through which restapi is
|
||||
accessible.
|
||||
- *restapi*:
|
||||
- *listen*: ip address + port that Patroni will listen to provide health-check information for haproxy.
|
||||
- *connect\_address*: ip address + port through which restapi is accessible.
|
||||
- *auth*: (optional) 'username:password' to protect some dangerous REST API endpoints.
|
||||
- *certfile*: (optional) Specifies a file with the certificate in the PEM format. If certfile is not specified or empty API server will work without SSL.
|
||||
- *keyfile*: (optional) Specifies a file with the secret key in the PEM format.
|
||||
|
||||
- *etcd*
|
||||
- *scope*: the relative path used on etcd's http api for this
|
||||
deployment, thus you can run multiple HA deployments from a single
|
||||
etcd
|
||||
- *ttl*: the TTL to acquire the leader lock. Think of it as the length
|
||||
of time before automatic failover process is initiated.
|
||||
- *host*: the host:port for the etcd endpoint
|
||||
- *etcd*:
|
||||
- *scope*: the relative path used on etcd's http api for this deployment, thus you can run multiple HA deployments from a single etcd
|
||||
- *ttl*: the TTL to acquire the leader lock. Think of it as the length of time before automatic failover process is initiated.
|
||||
- *host*: the host:port for the etcd endpoint
|
||||
|
||||
- *zookeeper*
|
||||
- *scope*: the relative path used on etcd's http api for this
|
||||
deployment, thus you can run multiple HA deployments from a single
|
||||
etcd
|
||||
- *session\_timeout*: the TTL to acquire the leader lock. Think of it
|
||||
as the length of time before automatic failover process is initiated.
|
||||
- *reconnect\_timeout*: how long we should try to reconnect to
|
||||
ZooKeeper after connection loss. After this timeout we assume that we
|
||||
don't have lock anymore and will restart in read-only mode.
|
||||
- *hosts*: list of ZooKeeper cluster members in format: [
|
||||
'host1:port1', 'host2:port2', 'etc...']
|
||||
- *exhibitor*: if you are running ZooKeeper cluster under Exhibitor
|
||||
supervisory the following section could be interesting for you
|
||||
- *zookeeper*:
|
||||
- *scope*: the relative path used on etcd's http api for this deployment, thus you can run multiple HA deployments from a single etcd
|
||||
- *session\_timeout*: the TTL to acquire the leader lock. Think of it as the length of time before automatic failover process is initiated.
|
||||
- *reconnect\_timeout*: how long we should try to reconnect to ZooKeeper after connection loss. After this timeout we assume that we don't have lock anymore and will restart in read-only mode.
|
||||
- *hosts*: list of ZooKeeper cluster members in format: ['host1:port1', 'host2:port2', 'etc...']
|
||||
- *exhibitor*: if you are running ZooKeeper cluster under Exhibitor supervisory the following section could be interesting for you
|
||||
- *poll\_interval*: how often list of ZooKeeper and Exhibitor nodes should be updated from Exhibitor
|
||||
- *port*: Exhibitor port
|
||||
- *hosts*: initial list of Exhibitor (ZooKeeper) nodes in format: ['host1', 'host2', 'etc...' ]. This list would be updated automatically when Exhibitor (ZooKeeper) cluster topology changes.
|
||||
|
||||
- *poll\_interval*: how often list of ZooKeeper and Exhibitor nodes
|
||||
should be updated from Exhibitor
|
||||
- *port*: Exhibitor port
|
||||
- *hosts*: initial list of Exhibitor (ZooKeeper) nodes in format: [
|
||||
'host1', 'host2', 'etc...' ]. This list would be updated
|
||||
automatically when Exhibitor (ZooKeeper) cluster topology changes.
|
||||
- *postgresql*:
|
||||
- *name*: the name of the Postgres host, must be unique for the cluster
|
||||
- *listen*: ip address + port that Postgres listening. Must be accessible from other nodes in the cluster if using streaming replication.
|
||||
- *connect\_address*: ip address + port through which Postgres is accessible from other nodes and applications.
|
||||
- *data\_dir*: file path to initialize and store Postgres data files
|
||||
- *maximum\_lag\_on\_failover*: the maximum bytes a follower may lag
|
||||
- *use\_slots*: whether or not to use replication_slots. Must be False for PostgreSQL 9.3, and you should comment out max_replication_slots. before it is not eligible become leader
|
||||
- *pg\_hba*: list of lines which should be added to pg\_hba.conf
|
||||
- *- host all all 0.0.0.0/0 md5*
|
||||
|
||||
- *postgresql*
|
||||
- *name*: the name of the Postgres host, must be unique for the cluster
|
||||
- *listen*: ip address + port that Postgres listening. Must be
|
||||
accessible from other nodes in the cluster if using streaming
|
||||
replication.
|
||||
- *connect\_address*: ip address + port through which Postgres is
|
||||
accessible from other nodes and applications.
|
||||
- *data\_dir*: file path to initialize and store Postgres data files
|
||||
- *maximum\_lag\_on\_failover*: the maximum bytes a follower may lag
|
||||
- *use\_slots*: whether or not to use replication_slots. Must be False for PostgreSQL 9.3, and you should comment out max_replication_slots.
|
||||
before it is not eligible become leader
|
||||
- *pg\_hba*: list of lines which should be added to pg\_hba.conf
|
||||
- *replication*:
|
||||
- *username*: replication username, user will be created during initialization
|
||||
- *password*: replication password, user will be created during initialization
|
||||
- *network*: network setting for replication in pg\_hba.conf
|
||||
|
||||
- *- host all all 0.0.0.0/0 md5*
|
||||
- *callbacks* callback scripts to run on certain actions. Patroni will pass current action, role and cluster name. See scripts/aws.py as an example on how to write them.
|
||||
- *on\_start*: a script to run when the cluster starts
|
||||
- *on\_stop*: a script to run when the cluster stops
|
||||
- *on\_restart*: a script to run when the cluster restarts
|
||||
- *on\_reload*: a script to run when configuration reload is triggered
|
||||
- *on\_role\_change*: a script to run when the cluster is being promoted or demoted
|
||||
|
||||
- *replication*
|
||||
- *superuser*:
|
||||
- *password*: password for postgres user. It would be set during initialization
|
||||
|
||||
- *username*: replication username, user will be created during
|
||||
initialization
|
||||
- *password*: replication password, user will be created during
|
||||
initialization
|
||||
- *network*: network setting for replication in pg\_hba.conf
|
||||
- *admin*:
|
||||
- *username*: admin username, user will be created during initialization. It would have CREATEDB and CREATEROLE privileges
|
||||
- *password*: admin password, user will be created during initialization.
|
||||
|
||||
- *callbacks* callback scripts to run on certain actions. Patroni will
|
||||
pass current action, role and cluster name. See scripts/aws.py as an
|
||||
example on how to write them.
|
||||
|
||||
- *on\_start*: a script to run when the cluster starts
|
||||
- *on\_stop*: a script to run when the cluster stops
|
||||
- *on\_restart*: a script to run when the cluster restarts
|
||||
- *on\_reload*: a script to run when configuration reload is
|
||||
triggered
|
||||
- *on\_role\_change*: a script to run when the cluster is being
|
||||
promoted or demoted
|
||||
|
||||
- *superuser*
|
||||
|
||||
- *password*: password for postgres user. It would be set during
|
||||
initialization
|
||||
|
||||
- *admin*:
|
||||
|
||||
- *username*: admin username, user will be created during
|
||||
initialization. It would have CREATEDB and CREATEROLE privileges
|
||||
- *password*: admin password, user will be created during
|
||||
initialization.
|
||||
|
||||
- *recovery\_conf*: additional configuration settings written to recovery.conf when configuring follower
|
||||
- *parameters*: list of configuration settings for Postgres. Many of these are required for replication to work.
|
||||
- *recovery\_conf*: additional configuration settings written to recovery.conf when configuring follower
|
||||
- *parameters*: list of configuration settings for Postgres. Many of these are required for replication to work.
|
||||
|
||||
Replication choices
|
||||
-------------------
|
||||
|
||||
+78
-1
@@ -1,3 +1,4 @@
|
||||
import base64
|
||||
import fcntl
|
||||
import json
|
||||
import logging
|
||||
@@ -10,9 +11,37 @@ from threading import Thread
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def check_auth(func):
|
||||
"""Decorator function to check authorization header.
|
||||
|
||||
Usage example:
|
||||
@check_auth
|
||||
def do_PUT_foo():
|
||||
pass
|
||||
"""
|
||||
def wrapper(handler):
|
||||
if handler.check_auth_header():
|
||||
return func(handler)
|
||||
return wrapper
|
||||
|
||||
|
||||
class RestApiHandler(BaseHTTPRequestHandler):
|
||||
|
||||
def send_auth_request(self, body):
|
||||
self.send_response(401)
|
||||
self.send_header('WWW-Authenticate', 'Basic realm=\"Patroni\"')
|
||||
self.send_header('Content-type', 'text/html')
|
||||
self.end_headers()
|
||||
self.wfile.write(body.encode('utf-8'))
|
||||
|
||||
def check_auth_header(self):
|
||||
auth_header = self.headers.get('Authorization')
|
||||
status = self.server.check_auth_header(auth_header)
|
||||
return not status or self.send_auth_request(status)
|
||||
|
||||
def do_GET(self):
|
||||
"""Default method for processing all GET requests which can not be routed to other methods"""
|
||||
|
||||
response = self.get_postgresql_status()
|
||||
|
||||
path = '/master' if self.path == '/' else self.path
|
||||
@@ -23,6 +52,31 @@ class RestApiHandler(BaseHTTPRequestHandler):
|
||||
self.end_headers()
|
||||
self.wfile.write(json.dumps(response).encode('utf-8'))
|
||||
|
||||
@check_auth
|
||||
def do_GET_sampleauth(self):
|
||||
self.send_response(200)
|
||||
self.send_header('Content-Type', 'text/html')
|
||||
self.end_headers()
|
||||
self.wfile.write(b'Hello!')
|
||||
|
||||
def parse_request(self):
|
||||
"""Override parse_request method to enrich basic functionality of `BaseHTTPRequestHandler` class
|
||||
|
||||
Original class can only invoke do_GET, do_POST, do_PUT, etc method implementations if they are defined.
|
||||
But we would like to have at least some simple routing mechanism, i.e.:
|
||||
GET /uri1/part2 request should invoke `do_GET_uri1()`
|
||||
POST /other should invoke `do_POST_other()`
|
||||
|
||||
If the `do_<REQUEST_METHOD>_<first_part_url>` method does not exists we'll fallback to original behavior."""
|
||||
|
||||
ret = BaseHTTPRequestHandler.parse_request(self)
|
||||
if ret:
|
||||
mname = self.path.lstrip('/').split('/')[0]
|
||||
mname = self.command + ('_' + mname if mname else '')
|
||||
if hasattr(self, 'do_' + mname):
|
||||
self.command = mname
|
||||
return ret
|
||||
|
||||
def get_postgresql_status(self):
|
||||
try:
|
||||
row = self.server.query("""SELECT to_char(pg_postmaster_start_time(), 'YYYY-MM-DD HH24:MI:SS.MS TZ'),
|
||||
@@ -52,11 +106,24 @@ class RestApiHandler(BaseHTTPRequestHandler):
|
||||
class RestApiServer(ThreadingMixIn, HTTPServer, Thread):
|
||||
|
||||
def __init__(self, patroni, config):
|
||||
self.connection_string = 'http://{}/patroni'.format(config.get('connect_address', None) or config['listen'])
|
||||
self._auth_key = base64.b64encode(config['auth'].encode('utf-8')).decode('utf-8') if 'auth' in config else None
|
||||
host, port = config['listen'].split(':')
|
||||
HTTPServer.__init__(self, (host, int(port)), RestApiHandler)
|
||||
Thread.__init__(self, target=self.serve_forever)
|
||||
self._set_fd_cloexec(self.socket)
|
||||
|
||||
protocol = 'http'
|
||||
|
||||
# wrap socket with ssl if 'certfile' is defined in a config.yaml
|
||||
# Sometime it's also needed to pass reference to a 'keyfile'.
|
||||
options = {option: config[option] for option in ['certfile', 'keyfile'] if option in config}
|
||||
if options.get('certfile', None):
|
||||
import ssl
|
||||
self.socket = ssl.wrap_socket(self.socket, server_side=True, **options)
|
||||
protocol = 'https'
|
||||
|
||||
self.connection_string = '{}://{}/patroni'.format(protocol, config.get('connect_address', config['listen']))
|
||||
|
||||
self.patroni = patroni
|
||||
self.daemon = True
|
||||
|
||||
@@ -71,3 +138,13 @@ class RestApiServer(ThreadingMixIn, HTTPServer, Thread):
|
||||
def _set_fd_cloexec(fd):
|
||||
flags = fcntl.fcntl(fd, fcntl.F_GETFD)
|
||||
fcntl.fcntl(fd, fcntl.F_SETFD, flags | fcntl.FD_CLOEXEC)
|
||||
|
||||
def check_basic_auth_key(self, key):
|
||||
return self._auth_key == key
|
||||
|
||||
def check_auth_header(self, auth_header):
|
||||
if self._auth_key:
|
||||
if auth_header is None:
|
||||
return 'no auth header received'
|
||||
if not auth_header.startswith('Basic ') or not self.check_basic_auth_key(auth_header[6:]):
|
||||
return 'not authenticated'
|
||||
|
||||
@@ -4,6 +4,9 @@ scope: &scope batman
|
||||
restapi:
|
||||
listen: 127.0.0.1:8008
|
||||
connect_address: 127.0.0.1:8008
|
||||
auth: 'username:password'
|
||||
# certfile: /etc/ssl/certs/ssl-cert-snakeoil.pem
|
||||
# keyfile: /etc/ssl/private/ssl-cert-snakeoil.key
|
||||
etcd:
|
||||
scope: *scope
|
||||
ttl: *ttl
|
||||
|
||||
@@ -4,6 +4,9 @@ scope: &scope batman
|
||||
restapi:
|
||||
listen: 127.0.0.1:8009
|
||||
connect_address: 127.0.0.1:8009
|
||||
auth: 'username:password'
|
||||
# certfile: /etc/ssl/certs/ssl-cert-snakeoil.pem
|
||||
# keyfile: /etc/ssl/private/ssl-cert-snakeoil.key
|
||||
etcd:
|
||||
scope: *scope
|
||||
ttl: *ttl
|
||||
|
||||
+34
-1
@@ -1,15 +1,34 @@
|
||||
import psycopg2
|
||||
import unittest
|
||||
import ssl
|
||||
|
||||
from patroni.api import RestApiHandler, RestApiServer
|
||||
from six import BytesIO as IO
|
||||
from six.moves import BaseHTTPServer
|
||||
from test_postgresql import psycopg2_connect
|
||||
|
||||
|
||||
def nop(*args, **kwargs):
|
||||
pass
|
||||
|
||||
|
||||
def throws(*args, **kwargs):
|
||||
raise psycopg2.OperationalError()
|
||||
|
||||
|
||||
def ssl_wrap_socket(socket, *args, **kwargs):
|
||||
return socket
|
||||
|
||||
|
||||
class Mock_BaseServer__is_shut_down:
|
||||
|
||||
def set(self):
|
||||
pass
|
||||
|
||||
def clear(self):
|
||||
pass
|
||||
|
||||
|
||||
class MockPostgresql:
|
||||
|
||||
def connection(self):
|
||||
@@ -37,7 +56,8 @@ class MockRequest:
|
||||
class MockRestApiServer(RestApiServer):
|
||||
|
||||
def __init__(self, Handler, path, *args):
|
||||
self.patroni = MockPatroni()
|
||||
config = {'listen': '127.0.0.1:8008', 'auth': 'test:test', 'certfile': 'dumb'}
|
||||
super(MockRestApiServer, self).__init__(MockPatroni(), config)
|
||||
if len(args) > 0:
|
||||
self.query = args[0]
|
||||
Handler(MockRequest(path), ('0.0.0.0', 8080), self)
|
||||
@@ -46,8 +66,21 @@ class MockRestApiServer(RestApiServer):
|
||||
class TestRestApiHandler(unittest.TestCase):
|
||||
|
||||
def __init__(self, method_name='runTest'):
|
||||
self.setUp = self.set_up
|
||||
super(TestRestApiHandler, self).__init__(method_name)
|
||||
|
||||
def set_up(self):
|
||||
BaseHTTPServer.HTTPServer.__init__ = nop
|
||||
RestApiServer._BaseServer__is_shut_down = Mock_BaseServer__is_shut_down()
|
||||
RestApiServer._BaseServer__shutdown_request = True
|
||||
RestApiServer.socket = 0
|
||||
ssl.wrap_socket = ssl_wrap_socket
|
||||
|
||||
def test_do_GET(self):
|
||||
MockRestApiServer(RestApiHandler, b'GET /')
|
||||
MockRestApiServer(RestApiHandler, b'GET /', throws)
|
||||
|
||||
def test_do_GET_sampleauth(self):
|
||||
MockRestApiServer(RestApiHandler, b'GET /sampleauth')
|
||||
MockRestApiServer(RestApiHandler, b'GET /sampleauth\nAuthorization:')
|
||||
MockRestApiServer(RestApiHandler, b'GET /sampleauth\nAuthorization: Basic dGVzdDp0ZXN0')
|
||||
|
||||
@@ -15,6 +15,7 @@ from patroni.exceptions import DCSError, PostgresException
|
||||
from patroni import Patroni, main
|
||||
from patroni.zookeeper import ZooKeeper
|
||||
from six.moves import BaseHTTPServer
|
||||
from test_api import Mock_BaseServer__is_shut_down
|
||||
from test_etcd import Client, etcd_read, etcd_write
|
||||
from test_ha import true, false
|
||||
from test_postgresql import Postgresql, subprocess_call, psycopg2_connect
|
||||
|
||||
Reference in New Issue
Block a user