bouncers.go 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292
  1. package main
  2. import (
  3. "encoding/csv"
  4. "encoding/json"
  5. "fmt"
  6. "io"
  7. "slices"
  8. "strings"
  9. "time"
  10. "github.com/AlecAivazis/survey/v2"
  11. "github.com/fatih/color"
  12. log "github.com/sirupsen/logrus"
  13. "github.com/spf13/cobra"
  14. middlewares "github.com/crowdsecurity/crowdsec/pkg/apiserver/middlewares/v1"
  15. "github.com/crowdsecurity/crowdsec/pkg/database"
  16. "github.com/crowdsecurity/crowdsec/pkg/types"
  17. "github.com/crowdsecurity/crowdsec/cmd/crowdsec-cli/require"
  18. )
  19. func getBouncers(out io.Writer, dbClient *database.Client) error {
  20. bouncers, err := dbClient.ListBouncers()
  21. if err != nil {
  22. return fmt.Errorf("unable to list bouncers: %s", err)
  23. }
  24. if csConfig.Cscli.Output == "human" {
  25. getBouncersTable(out, bouncers)
  26. } else if csConfig.Cscli.Output == "json" {
  27. enc := json.NewEncoder(out)
  28. enc.SetIndent("", " ")
  29. if err := enc.Encode(bouncers); err != nil {
  30. return fmt.Errorf("failed to unmarshal: %w", err)
  31. }
  32. return nil
  33. } else if csConfig.Cscli.Output == "raw" {
  34. csvwriter := csv.NewWriter(out)
  35. err := csvwriter.Write([]string{"name", "ip", "revoked", "last_pull", "type", "version", "auth_type"})
  36. if err != nil {
  37. return fmt.Errorf("failed to write raw header: %w", err)
  38. }
  39. for _, b := range bouncers {
  40. var revoked string
  41. if !b.Revoked {
  42. revoked = "validated"
  43. } else {
  44. revoked = "pending"
  45. }
  46. err := csvwriter.Write([]string{b.Name, b.IPAddress, revoked, b.LastPull.Format(time.RFC3339), b.Type, b.Version, b.AuthType})
  47. if err != nil {
  48. return fmt.Errorf("failed to write raw: %w", err)
  49. }
  50. }
  51. csvwriter.Flush()
  52. }
  53. return nil
  54. }
  55. func NewBouncersListCmd() *cobra.Command {
  56. cmdBouncersList := &cobra.Command{
  57. Use: "list",
  58. Short: "list all bouncers within the database",
  59. Example: `cscli bouncers list`,
  60. Args: cobra.ExactArgs(0),
  61. DisableAutoGenTag: true,
  62. RunE: func(cmd *cobra.Command, arg []string) error {
  63. err := getBouncers(color.Output, dbClient)
  64. if err != nil {
  65. return fmt.Errorf("unable to list bouncers: %s", err)
  66. }
  67. return nil
  68. },
  69. }
  70. return cmdBouncersList
  71. }
  72. func runBouncersAdd(cmd *cobra.Command, args []string) error {
  73. flags := cmd.Flags()
  74. keyLength, err := flags.GetInt("length")
  75. if err != nil {
  76. return err
  77. }
  78. key, err := flags.GetString("key")
  79. if err != nil {
  80. return err
  81. }
  82. keyName := args[0]
  83. var apiKey string
  84. if keyName == "" {
  85. return fmt.Errorf("please provide a name for the api key")
  86. }
  87. apiKey = key
  88. if key == "" {
  89. apiKey, err = middlewares.GenerateAPIKey(keyLength)
  90. }
  91. if err != nil {
  92. return fmt.Errorf("unable to generate api key: %s", err)
  93. }
  94. _, err = dbClient.CreateBouncer(keyName, "", middlewares.HashSHA512(apiKey), types.ApiKeyAuthType)
  95. if err != nil {
  96. return fmt.Errorf("unable to create bouncer: %s", err)
  97. }
  98. if csConfig.Cscli.Output == "human" {
  99. fmt.Printf("API key for '%s':\n\n", keyName)
  100. fmt.Printf(" %s\n\n", apiKey)
  101. fmt.Print("Please keep this key since you will not be able to retrieve it!\n")
  102. } else if csConfig.Cscli.Output == "raw" {
  103. fmt.Printf("%s", apiKey)
  104. } else if csConfig.Cscli.Output == "json" {
  105. j, err := json.Marshal(apiKey)
  106. if err != nil {
  107. return fmt.Errorf("unable to marshal api key")
  108. }
  109. fmt.Printf("%s", string(j))
  110. }
  111. return nil
  112. }
  113. func NewBouncersAddCmd() *cobra.Command {
  114. cmdBouncersAdd := &cobra.Command{
  115. Use: "add MyBouncerName [--length 16]",
  116. Short: "add a single bouncer to the database",
  117. Example: `cscli bouncers add MyBouncerName
  118. cscli bouncers add MyBouncerName -l 24
  119. cscli bouncers add MyBouncerName -k <random-key>`,
  120. Args: cobra.ExactArgs(1),
  121. DisableAutoGenTag: true,
  122. RunE: runBouncersAdd,
  123. }
  124. flags := cmdBouncersAdd.Flags()
  125. flags.IntP("length", "l", 16, "length of the api key")
  126. flags.StringP("key", "k", "", "api key for the bouncer")
  127. return cmdBouncersAdd
  128. }
  129. func runBouncersDelete(cmd *cobra.Command, args []string) error {
  130. for _, bouncerID := range args {
  131. err := dbClient.DeleteBouncer(bouncerID)
  132. if err != nil {
  133. return fmt.Errorf("unable to delete bouncer '%s': %s", bouncerID, err)
  134. }
  135. log.Infof("bouncer '%s' deleted successfully", bouncerID)
  136. }
  137. return nil
  138. }
  139. func NewBouncersDeleteCmd() *cobra.Command {
  140. cmdBouncersDelete := &cobra.Command{
  141. Use: "delete MyBouncerName",
  142. Short: "delete bouncer(s) from the database",
  143. Args: cobra.MinimumNArgs(1),
  144. Aliases: []string{"remove"},
  145. DisableAutoGenTag: true,
  146. ValidArgsFunction: func(cmd *cobra.Command, args []string, toComplete string) ([]string, cobra.ShellCompDirective) {
  147. var err error
  148. dbClient, err = getDBClient()
  149. if err != nil {
  150. cobra.CompError("unable to create new database client: " + err.Error())
  151. return nil, cobra.ShellCompDirectiveNoFileComp
  152. }
  153. bouncers, err := dbClient.ListBouncers()
  154. if err != nil {
  155. cobra.CompError("unable to list bouncers " + err.Error())
  156. }
  157. ret := make([]string, 0)
  158. for _, bouncer := range bouncers {
  159. if strings.Contains(bouncer.Name, toComplete) && !slices.Contains(args, bouncer.Name) {
  160. ret = append(ret, bouncer.Name)
  161. }
  162. }
  163. return ret, cobra.ShellCompDirectiveNoFileComp
  164. },
  165. RunE: runBouncersDelete,
  166. }
  167. return cmdBouncersDelete
  168. }
  169. func NewBouncersPruneCmd() *cobra.Command {
  170. var parsedDuration time.Duration
  171. cmdBouncersPrune := &cobra.Command{
  172. Use: "prune",
  173. Short: "prune multiple bouncers from the database",
  174. Args: cobra.NoArgs,
  175. DisableAutoGenTag: true,
  176. Example: `cscli bouncers prune -d 60m
  177. cscli bouncers prune -d 60m --force`,
  178. PreRunE: func(cmd *cobra.Command, args []string) error {
  179. dur, _ := cmd.Flags().GetString("duration")
  180. var err error
  181. parsedDuration, err = time.ParseDuration(fmt.Sprintf("-%s", dur))
  182. if err != nil {
  183. return fmt.Errorf("unable to parse duration '%s': %s", dur, err)
  184. }
  185. return nil
  186. },
  187. RunE: func(cmd *cobra.Command, args []string) error {
  188. force, _ := cmd.Flags().GetBool("force")
  189. if parsedDuration >= 0-2*time.Minute {
  190. var answer bool
  191. prompt := &survey.Confirm{
  192. Message: "The duration you provided is less than or equal 2 minutes this may remove active bouncers continue ?",
  193. Default: false,
  194. }
  195. if err := survey.AskOne(prompt, &answer); err != nil {
  196. return fmt.Errorf("unable to ask about prune check: %s", err)
  197. }
  198. if !answer {
  199. fmt.Println("user aborted prune no changes were made")
  200. return nil
  201. }
  202. }
  203. bouncers, err := dbClient.QueryBouncersLastPulltimeLT(time.Now().UTC().Add(parsedDuration))
  204. if err != nil {
  205. return fmt.Errorf("unable to query bouncers: %s", err)
  206. }
  207. if len(bouncers) == 0 {
  208. fmt.Println("no bouncers to prune")
  209. return nil
  210. }
  211. getBouncersTable(color.Output, bouncers)
  212. if !force {
  213. var answer bool
  214. prompt := &survey.Confirm{
  215. Message: "You are about to PERMANENTLY remove the above bouncers from the database these will NOT be recoverable, continue ?",
  216. Default: false,
  217. }
  218. if err := survey.AskOne(prompt, &answer); err != nil {
  219. return fmt.Errorf("unable to ask about prune check: %s", err)
  220. }
  221. if !answer {
  222. fmt.Println("user aborted prune no changes were made")
  223. return nil
  224. }
  225. }
  226. nbDeleted, err := dbClient.BulkDeleteBouncers(bouncers)
  227. if err != nil {
  228. return fmt.Errorf("unable to prune bouncers: %s", err)
  229. }
  230. fmt.Printf("successfully delete %d bouncers\n", nbDeleted)
  231. return nil
  232. },
  233. }
  234. cmdBouncersPrune.Flags().StringP("duration", "d", "60m", "duration of time since last pull")
  235. cmdBouncersPrune.Flags().Bool("force", false, "force prune without asking for confirmation")
  236. return cmdBouncersPrune
  237. }
  238. func NewBouncersCmd() *cobra.Command {
  239. var cmdBouncers = &cobra.Command{
  240. Use: "bouncers [action]",
  241. Short: "Manage bouncers [requires local API]",
  242. Long: `To list/add/delete/prune bouncers.
  243. Note: This command requires database direct access, so is intended to be run on Local API/master.
  244. `,
  245. Args: cobra.MinimumNArgs(1),
  246. Aliases: []string{"bouncer"},
  247. DisableAutoGenTag: true,
  248. PersistentPreRunE: func(cmd *cobra.Command, args []string) error {
  249. var err error
  250. if err = require.LAPI(csConfig); err != nil {
  251. return err
  252. }
  253. dbClient, err = database.NewClient(csConfig.DbConfig)
  254. if err != nil {
  255. return fmt.Errorf("unable to create new database client: %s", err)
  256. }
  257. return nil
  258. },
  259. }
  260. cmdBouncers.AddCommand(NewBouncersListCmd())
  261. cmdBouncers.AddCommand(NewBouncersAddCmd())
  262. cmdBouncers.AddCommand(NewBouncersDeleteCmd())
  263. cmdBouncers.AddCommand(NewBouncersPruneCmd())
  264. return cmdBouncers
  265. }