168 lines
5.2 KiB
Go
168 lines
5.2 KiB
Go
package main
|
|
|
|
import (
|
|
"bytes"
|
|
"crypto/tls"
|
|
"encoding/json"
|
|
"errors"
|
|
"fmt"
|
|
"io"
|
|
"net"
|
|
"os"
|
|
"strings"
|
|
|
|
agentpb "git.ipao.vip/rogee/go-sip/gen/agent"
|
|
"git.ipao.vip/rogee/go-sip/internal/config"
|
|
"git.ipao.vip/rogee/go-sip/internal/rpc"
|
|
"github.com/spf13/cobra"
|
|
"google.golang.org/grpc"
|
|
"google.golang.org/grpc/credentials"
|
|
)
|
|
|
|
func newAgentCommand() *cobra.Command {
|
|
var mode string
|
|
command := &cobra.Command{
|
|
Use: "agent", Short: "Run the bound Agent", Args: cobra.NoArgs,
|
|
SilenceUsage: true,
|
|
RunE: func(cmd *cobra.Command, _ []string) error {
|
|
settings, err := config.LoadAgentEnvironment(mode)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
ca, err := readAgentPEM("MTLS_CA_FILE", settings.CAFile)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
cert, err := readAgentPEM("MTLS_CERT_FILE", settings.CertFile)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
key, err := readAgentPEM("MTLS_KEY_FILE", settings.KeyFile)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
serverTLS, err := rpc.NewServerTLSConfig(ca, cert, key)
|
|
if err != nil {
|
|
return errors.New("Agent mTLS listener certificate is invalid")
|
|
}
|
|
var handler *rpc.Server
|
|
var recoveryClient agentpb.AgentControlServiceClient
|
|
if mode == "sip-only" {
|
|
handler, err = newSIPOnlyAgentServer(settings)
|
|
} else {
|
|
var scenario approvedMockScenario
|
|
var applied map[string]int64
|
|
if mode == "mock" {
|
|
scenario, err = loadApprovedMockScenario(settings.MockScenarioFile)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
applied, err = loadMockAppliedSIP(settings.MockAppliedSIPFile)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
}
|
|
var clientTLS *tls.Config
|
|
clientTLS, err = rpc.NewClientTLSConfig(ca, cert, key, settings.DispatcherServerName)
|
|
if err != nil {
|
|
return errors.New("Agent mTLS Dispatcher certificate configuration is invalid")
|
|
}
|
|
connection, connectErr := grpc.NewClient(settings.DispatcherEndpoint, grpc.WithTransportCredentials(credentials.NewTLS(clientTLS)))
|
|
if connectErr != nil {
|
|
return errors.New("Agent cannot create pinned Dispatcher connection")
|
|
}
|
|
defer connection.Close()
|
|
client := agentpb.NewAgentControlServiceClient(connection)
|
|
if mode == "mock" {
|
|
handler, err = newAgentServer(cmd.Context(), settings, scenario, applied, client)
|
|
} else {
|
|
handler, err = newRealAgentServer(cmd.Context(), settings, client)
|
|
recoveryClient = client
|
|
}
|
|
}
|
|
if err != nil {
|
|
return err
|
|
}
|
|
listener, err := net.Listen("tcp", settings.Listen)
|
|
if err != nil {
|
|
return fmt.Errorf("Agent cannot listen on configured local address: %w", err)
|
|
}
|
|
defer listener.Close()
|
|
server := grpc.NewServer(grpc.Creds(credentials.NewTLS(serverTLS)))
|
|
agentpb.RegisterAgentControlServiceServer(server, handler)
|
|
if mode == "nonprod-real" {
|
|
startRealAgentRecovery(cmd.Context(), settings, recoveryClient, handler)
|
|
}
|
|
stopped := make(chan struct{})
|
|
go func() {
|
|
select {
|
|
case <-cmd.Context().Done():
|
|
server.GracefulStop()
|
|
case <-stopped:
|
|
}
|
|
}()
|
|
err = server.Serve(listener)
|
|
close(stopped)
|
|
if err != nil && !errors.Is(err, grpc.ErrServerStopped) {
|
|
return fmt.Errorf("Agent gRPC listener stopped: %w", err)
|
|
}
|
|
if cmd.Context().Err() == nil {
|
|
return errors.New("Agent gRPC listener stopped without shutdown")
|
|
}
|
|
return nil
|
|
},
|
|
}
|
|
command.Flags().StringVar(&mode, "mode", "mock", "isolated Mock, SIP-only or explicit nonprod-real mode")
|
|
return command
|
|
}
|
|
|
|
// This is an isolated deployment fixture, not SaaS SIP configuration or proof
|
|
// that Asterisk actually loaded the revisions. Nonprod-real cannot load it.
|
|
func loadMockAppliedSIP(path string) (map[string]int64, error) {
|
|
if strings.TrimSpace(path) == "" {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE is required")
|
|
}
|
|
file, err := os.Open(path)
|
|
if err != nil {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE cannot be opened")
|
|
}
|
|
defer file.Close()
|
|
data, err := io.ReadAll(io.LimitReader(file, 64<<10+1))
|
|
if err != nil || len(data) > 64<<10 {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE exceeds its size limit or cannot be read")
|
|
}
|
|
var fixture struct {
|
|
Trunks map[string]int64 `json:"trunks"`
|
|
}
|
|
decoder := json.NewDecoder(bytes.NewReader(data))
|
|
decoder.DisallowUnknownFields()
|
|
if err := decoder.Decode(&fixture); err != nil {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE has invalid fields")
|
|
}
|
|
if err := decoder.Decode(new(any)); err != io.EOF {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE contains extra data")
|
|
}
|
|
if len(fixture.Trunks) == 0 {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE requires explicit trunks")
|
|
}
|
|
for trunk, revision := range fixture.Trunks {
|
|
if strings.TrimSpace(trunk) == "" || revision <= 0 {
|
|
return nil, errors.New("AGENT_MOCK_APPLIED_SIP_FILE has invalid trunk revision")
|
|
}
|
|
}
|
|
return fixture.Trunks, nil
|
|
}
|
|
|
|
func readAgentPEM(name, path string) ([]byte, error) {
|
|
file, err := os.Open(path)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("%s cannot be opened", name)
|
|
}
|
|
defer file.Close()
|
|
data, err := io.ReadAll(io.LimitReader(file, 1<<20+1))
|
|
if err != nil || len(data) == 0 || len(data) > 1<<20 {
|
|
return nil, fmt.Errorf("%s is unreadable or too large", name)
|
|
}
|
|
return data, nil
|
|
}
|