node.go 9.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322
  1. package controlapi
  2. import (
  3. "crypto/x509"
  4. "encoding/pem"
  5. "github.com/docker/swarmkit/api"
  6. "github.com/docker/swarmkit/manager/state/raft/membership"
  7. "github.com/docker/swarmkit/manager/state/store"
  8. gogotypes "github.com/gogo/protobuf/types"
  9. "golang.org/x/net/context"
  10. "google.golang.org/grpc"
  11. "google.golang.org/grpc/codes"
  12. )
  13. func validateNodeSpec(spec *api.NodeSpec) error {
  14. if spec == nil {
  15. return grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  16. }
  17. return nil
  18. }
  19. // GetNode returns a Node given a NodeID.
  20. // - Returns `InvalidArgument` if NodeID is not provided.
  21. // - Returns `NotFound` if the Node is not found.
  22. func (s *Server) GetNode(ctx context.Context, request *api.GetNodeRequest) (*api.GetNodeResponse, error) {
  23. if request.NodeID == "" {
  24. return nil, grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  25. }
  26. var node *api.Node
  27. s.store.View(func(tx store.ReadTx) {
  28. node = store.GetNode(tx, request.NodeID)
  29. })
  30. if node == nil {
  31. return nil, grpc.Errorf(codes.NotFound, "node %s not found", request.NodeID)
  32. }
  33. if s.raft != nil {
  34. memberlist := s.raft.GetMemberlist()
  35. for _, member := range memberlist {
  36. if member.NodeID == node.ID {
  37. node.ManagerStatus = &api.ManagerStatus{
  38. RaftID: member.RaftID,
  39. Addr: member.Addr,
  40. Leader: member.Status.Leader,
  41. Reachability: member.Status.Reachability,
  42. }
  43. break
  44. }
  45. }
  46. }
  47. return &api.GetNodeResponse{
  48. Node: node,
  49. }, nil
  50. }
  51. func filterNodes(candidates []*api.Node, filters ...func(*api.Node) bool) []*api.Node {
  52. result := []*api.Node{}
  53. for _, c := range candidates {
  54. match := true
  55. for _, f := range filters {
  56. if !f(c) {
  57. match = false
  58. break
  59. }
  60. }
  61. if match {
  62. result = append(result, c)
  63. }
  64. }
  65. return result
  66. }
  67. // ListNodes returns a list of all nodes.
  68. func (s *Server) ListNodes(ctx context.Context, request *api.ListNodesRequest) (*api.ListNodesResponse, error) {
  69. var (
  70. nodes []*api.Node
  71. err error
  72. )
  73. s.store.View(func(tx store.ReadTx) {
  74. switch {
  75. case request.Filters != nil && len(request.Filters.Names) > 0:
  76. nodes, err = store.FindNodes(tx, buildFilters(store.ByName, request.Filters.Names))
  77. case request.Filters != nil && len(request.Filters.NamePrefixes) > 0:
  78. nodes, err = store.FindNodes(tx, buildFilters(store.ByNamePrefix, request.Filters.NamePrefixes))
  79. case request.Filters != nil && len(request.Filters.IDPrefixes) > 0:
  80. nodes, err = store.FindNodes(tx, buildFilters(store.ByIDPrefix, request.Filters.IDPrefixes))
  81. case request.Filters != nil && len(request.Filters.Roles) > 0:
  82. filters := make([]store.By, 0, len(request.Filters.Roles))
  83. for _, v := range request.Filters.Roles {
  84. filters = append(filters, store.ByRole(v))
  85. }
  86. nodes, err = store.FindNodes(tx, store.Or(filters...))
  87. case request.Filters != nil && len(request.Filters.Memberships) > 0:
  88. filters := make([]store.By, 0, len(request.Filters.Memberships))
  89. for _, v := range request.Filters.Memberships {
  90. filters = append(filters, store.ByMembership(v))
  91. }
  92. nodes, err = store.FindNodes(tx, store.Or(filters...))
  93. default:
  94. nodes, err = store.FindNodes(tx, store.All)
  95. }
  96. })
  97. if err != nil {
  98. return nil, err
  99. }
  100. if request.Filters != nil {
  101. nodes = filterNodes(nodes,
  102. func(e *api.Node) bool {
  103. if len(request.Filters.Names) == 0 {
  104. return true
  105. }
  106. if e.Description == nil {
  107. return false
  108. }
  109. return filterContains(e.Description.Hostname, request.Filters.Names)
  110. },
  111. func(e *api.Node) bool {
  112. if len(request.Filters.NamePrefixes) == 0 {
  113. return true
  114. }
  115. if e.Description == nil {
  116. return false
  117. }
  118. return filterContainsPrefix(e.Description.Hostname, request.Filters.NamePrefixes)
  119. },
  120. func(e *api.Node) bool {
  121. return filterContainsPrefix(e.ID, request.Filters.IDPrefixes)
  122. },
  123. func(e *api.Node) bool {
  124. if len(request.Filters.Labels) == 0 {
  125. return true
  126. }
  127. if e.Description == nil {
  128. return false
  129. }
  130. return filterMatchLabels(e.Description.Engine.Labels, request.Filters.Labels)
  131. },
  132. func(e *api.Node) bool {
  133. if len(request.Filters.Roles) == 0 {
  134. return true
  135. }
  136. for _, c := range request.Filters.Roles {
  137. if c == e.Role {
  138. return true
  139. }
  140. }
  141. return false
  142. },
  143. func(e *api.Node) bool {
  144. if len(request.Filters.Memberships) == 0 {
  145. return true
  146. }
  147. for _, c := range request.Filters.Memberships {
  148. if c == e.Spec.Membership {
  149. return true
  150. }
  151. }
  152. return false
  153. },
  154. )
  155. }
  156. // Add in manager information on nodes that are managers
  157. if s.raft != nil {
  158. memberlist := s.raft.GetMemberlist()
  159. for _, node := range nodes {
  160. for _, member := range memberlist {
  161. if member.NodeID == node.ID {
  162. node.ManagerStatus = &api.ManagerStatus{
  163. RaftID: member.RaftID,
  164. Addr: member.Addr,
  165. Leader: member.Status.Leader,
  166. Reachability: member.Status.Reachability,
  167. }
  168. break
  169. }
  170. }
  171. }
  172. }
  173. return &api.ListNodesResponse{
  174. Nodes: nodes,
  175. }, nil
  176. }
  177. // UpdateNode updates a Node referenced by NodeID with the given NodeSpec.
  178. // - Returns `NotFound` if the Node is not found.
  179. // - Returns `InvalidArgument` if the NodeSpec is malformed.
  180. // - Returns an error if the update fails.
  181. func (s *Server) UpdateNode(ctx context.Context, request *api.UpdateNodeRequest) (*api.UpdateNodeResponse, error) {
  182. if request.NodeID == "" || request.NodeVersion == nil {
  183. return nil, grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  184. }
  185. if err := validateNodeSpec(request.Spec); err != nil {
  186. return nil, err
  187. }
  188. var (
  189. node *api.Node
  190. member *membership.Member
  191. )
  192. err := s.store.Update(func(tx store.Tx) error {
  193. node = store.GetNode(tx, request.NodeID)
  194. if node == nil {
  195. return grpc.Errorf(codes.NotFound, "node %s not found", request.NodeID)
  196. }
  197. // Demotion sanity checks.
  198. if node.Spec.DesiredRole == api.NodeRoleManager && request.Spec.DesiredRole == api.NodeRoleWorker {
  199. // Check for manager entries in Store.
  200. managers, err := store.FindNodes(tx, store.ByRole(api.NodeRoleManager))
  201. if err != nil {
  202. return grpc.Errorf(codes.Internal, "internal store error: %v", err)
  203. }
  204. if len(managers) == 1 && managers[0].ID == node.ID {
  205. return grpc.Errorf(codes.FailedPrecondition, "attempting to demote the last manager of the swarm")
  206. }
  207. // Check for node in memberlist
  208. if member = s.raft.GetMemberByNodeID(request.NodeID); member == nil {
  209. return grpc.Errorf(codes.NotFound, "can't find manager in raft memberlist")
  210. }
  211. // Quorum safeguard
  212. if !s.raft.CanRemoveMember(member.RaftID) {
  213. return grpc.Errorf(codes.FailedPrecondition, "can't remove member from the raft: this would result in a loss of quorum")
  214. }
  215. }
  216. node.Meta.Version = *request.NodeVersion
  217. node.Spec = *request.Spec.Copy()
  218. return store.UpdateNode(tx, node)
  219. })
  220. if err != nil {
  221. return nil, err
  222. }
  223. return &api.UpdateNodeResponse{
  224. Node: node,
  225. }, nil
  226. }
  227. // RemoveNode removes a Node referenced by NodeID with the given NodeSpec.
  228. // - Returns NotFound if the Node is not found.
  229. // - Returns FailedPrecondition if the Node has manager role (and is part of the memberlist) or is not shut down.
  230. // - Returns InvalidArgument if NodeID or NodeVersion is not valid.
  231. // - Returns an error if the delete fails.
  232. func (s *Server) RemoveNode(ctx context.Context, request *api.RemoveNodeRequest) (*api.RemoveNodeResponse, error) {
  233. if request.NodeID == "" {
  234. return nil, grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  235. }
  236. err := s.store.Update(func(tx store.Tx) error {
  237. node := store.GetNode(tx, request.NodeID)
  238. if node == nil {
  239. return grpc.Errorf(codes.NotFound, "node %s not found", request.NodeID)
  240. }
  241. if node.Spec.DesiredRole == api.NodeRoleManager {
  242. if s.raft == nil {
  243. return grpc.Errorf(codes.FailedPrecondition, "node %s is a manager but cannot access node information from the raft memberlist", request.NodeID)
  244. }
  245. if member := s.raft.GetMemberByNodeID(request.NodeID); member != nil {
  246. return grpc.Errorf(codes.FailedPrecondition, "node %s is a cluster manager and is a member of the raft cluster. It must be demoted to worker before removal", request.NodeID)
  247. }
  248. }
  249. if !request.Force && node.Status.State == api.NodeStatus_READY {
  250. return grpc.Errorf(codes.FailedPrecondition, "node %s is not down and can't be removed", request.NodeID)
  251. }
  252. // lookup the cluster
  253. clusters, err := store.FindClusters(tx, store.ByName("default"))
  254. if err != nil {
  255. return err
  256. }
  257. if len(clusters) != 1 {
  258. return grpc.Errorf(codes.Internal, "could not fetch cluster object")
  259. }
  260. cluster := clusters[0]
  261. blacklistedCert := &api.BlacklistedCertificate{}
  262. // Set an expiry time for this RemovedNode if a certificate
  263. // exists and can be parsed.
  264. if len(node.Certificate.Certificate) != 0 {
  265. certBlock, _ := pem.Decode(node.Certificate.Certificate)
  266. if certBlock != nil {
  267. X509Cert, err := x509.ParseCertificate(certBlock.Bytes)
  268. if err == nil && !X509Cert.NotAfter.IsZero() {
  269. expiry, err := gogotypes.TimestampProto(X509Cert.NotAfter)
  270. if err == nil {
  271. blacklistedCert.Expiry = expiry
  272. }
  273. }
  274. }
  275. }
  276. if cluster.BlacklistedCertificates == nil {
  277. cluster.BlacklistedCertificates = make(map[string]*api.BlacklistedCertificate)
  278. }
  279. cluster.BlacklistedCertificates[node.ID] = blacklistedCert
  280. expireBlacklistedCerts(cluster)
  281. if err := store.UpdateCluster(tx, cluster); err != nil {
  282. return err
  283. }
  284. return store.DeleteNode(tx, request.NodeID)
  285. })
  286. if err != nil {
  287. return nil, err
  288. }
  289. return &api.RemoveNodeResponse{}, nil
  290. }