node.go 9.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335
  1. package controlapi
  2. import (
  3. "crypto/x509"
  4. "encoding/pem"
  5. "github.com/docker/swarmkit/api"
  6. "github.com/docker/swarmkit/manager/state/raft/membership"
  7. "github.com/docker/swarmkit/manager/state/store"
  8. "github.com/docker/swarmkit/protobuf/ptypes"
  9. "golang.org/x/net/context"
  10. "google.golang.org/grpc"
  11. "google.golang.org/grpc/codes"
  12. )
  13. func validateNodeSpec(spec *api.NodeSpec) error {
  14. if spec == nil {
  15. return grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  16. }
  17. return nil
  18. }
  19. // GetNode returns a Node given a NodeID.
  20. // - Returns `InvalidArgument` if NodeID is not provided.
  21. // - Returns `NotFound` if the Node is not found.
  22. func (s *Server) GetNode(ctx context.Context, request *api.GetNodeRequest) (*api.GetNodeResponse, error) {
  23. if request.NodeID == "" {
  24. return nil, grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  25. }
  26. var node *api.Node
  27. s.store.View(func(tx store.ReadTx) {
  28. node = store.GetNode(tx, request.NodeID)
  29. })
  30. if node == nil {
  31. return nil, grpc.Errorf(codes.NotFound, "node %s not found", request.NodeID)
  32. }
  33. if s.raft != nil {
  34. memberlist := s.raft.GetMemberlist()
  35. for _, member := range memberlist {
  36. if member.NodeID == node.ID {
  37. node.ManagerStatus = &api.ManagerStatus{
  38. RaftID: member.RaftID,
  39. Addr: member.Addr,
  40. Leader: member.Status.Leader,
  41. Reachability: member.Status.Reachability,
  42. }
  43. break
  44. }
  45. }
  46. }
  47. return &api.GetNodeResponse{
  48. Node: node,
  49. }, nil
  50. }
  51. func filterNodes(candidates []*api.Node, filters ...func(*api.Node) bool) []*api.Node {
  52. result := []*api.Node{}
  53. for _, c := range candidates {
  54. match := true
  55. for _, f := range filters {
  56. if !f(c) {
  57. match = false
  58. break
  59. }
  60. }
  61. if match {
  62. result = append(result, c)
  63. }
  64. }
  65. return result
  66. }
  67. // ListNodes returns a list of all nodes.
  68. func (s *Server) ListNodes(ctx context.Context, request *api.ListNodesRequest) (*api.ListNodesResponse, error) {
  69. var (
  70. nodes []*api.Node
  71. err error
  72. )
  73. s.store.View(func(tx store.ReadTx) {
  74. switch {
  75. case request.Filters != nil && len(request.Filters.Names) > 0:
  76. nodes, err = store.FindNodes(tx, buildFilters(store.ByName, request.Filters.Names))
  77. case request.Filters != nil && len(request.Filters.NamePrefixes) > 0:
  78. nodes, err = store.FindNodes(tx, buildFilters(store.ByNamePrefix, request.Filters.NamePrefixes))
  79. case request.Filters != nil && len(request.Filters.IDPrefixes) > 0:
  80. nodes, err = store.FindNodes(tx, buildFilters(store.ByIDPrefix, request.Filters.IDPrefixes))
  81. case request.Filters != nil && len(request.Filters.Roles) > 0:
  82. filters := make([]store.By, 0, len(request.Filters.Roles))
  83. for _, v := range request.Filters.Roles {
  84. filters = append(filters, store.ByRole(v))
  85. }
  86. nodes, err = store.FindNodes(tx, store.Or(filters...))
  87. case request.Filters != nil && len(request.Filters.Memberships) > 0:
  88. filters := make([]store.By, 0, len(request.Filters.Memberships))
  89. for _, v := range request.Filters.Memberships {
  90. filters = append(filters, store.ByMembership(v))
  91. }
  92. nodes, err = store.FindNodes(tx, store.Or(filters...))
  93. default:
  94. nodes, err = store.FindNodes(tx, store.All)
  95. }
  96. })
  97. if err != nil {
  98. return nil, err
  99. }
  100. if request.Filters != nil {
  101. nodes = filterNodes(nodes,
  102. func(e *api.Node) bool {
  103. if len(request.Filters.Names) == 0 {
  104. return true
  105. }
  106. if e.Description == nil {
  107. return false
  108. }
  109. return filterContains(e.Description.Hostname, request.Filters.Names)
  110. },
  111. func(e *api.Node) bool {
  112. if len(request.Filters.NamePrefixes) == 0 {
  113. return true
  114. }
  115. if e.Description == nil {
  116. return false
  117. }
  118. return filterContainsPrefix(e.Description.Hostname, request.Filters.NamePrefixes)
  119. },
  120. func(e *api.Node) bool {
  121. return filterContainsPrefix(e.ID, request.Filters.IDPrefixes)
  122. },
  123. func(e *api.Node) bool {
  124. if len(request.Filters.Labels) == 0 {
  125. return true
  126. }
  127. if e.Description == nil {
  128. return false
  129. }
  130. return filterMatchLabels(e.Description.Engine.Labels, request.Filters.Labels)
  131. },
  132. func(e *api.Node) bool {
  133. if len(request.Filters.Roles) == 0 {
  134. return true
  135. }
  136. for _, c := range request.Filters.Roles {
  137. if c == e.Spec.Role {
  138. return true
  139. }
  140. }
  141. return false
  142. },
  143. func(e *api.Node) bool {
  144. if len(request.Filters.Memberships) == 0 {
  145. return true
  146. }
  147. for _, c := range request.Filters.Memberships {
  148. if c == e.Spec.Membership {
  149. return true
  150. }
  151. }
  152. return false
  153. },
  154. )
  155. }
  156. // Add in manager information on nodes that are managers
  157. if s.raft != nil {
  158. memberlist := s.raft.GetMemberlist()
  159. for _, node := range nodes {
  160. for _, member := range memberlist {
  161. if member.NodeID == node.ID {
  162. node.ManagerStatus = &api.ManagerStatus{
  163. RaftID: member.RaftID,
  164. Addr: member.Addr,
  165. Leader: member.Status.Leader,
  166. Reachability: member.Status.Reachability,
  167. }
  168. break
  169. }
  170. }
  171. }
  172. }
  173. return &api.ListNodesResponse{
  174. Nodes: nodes,
  175. }, nil
  176. }
  177. // UpdateNode updates a Node referenced by NodeID with the given NodeSpec.
  178. // - Returns `NotFound` if the Node is not found.
  179. // - Returns `InvalidArgument` if the NodeSpec is malformed.
  180. // - Returns an error if the update fails.
  181. func (s *Server) UpdateNode(ctx context.Context, request *api.UpdateNodeRequest) (*api.UpdateNodeResponse, error) {
  182. if request.NodeID == "" || request.NodeVersion == nil {
  183. return nil, grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  184. }
  185. if err := validateNodeSpec(request.Spec); err != nil {
  186. return nil, err
  187. }
  188. var (
  189. node *api.Node
  190. member *membership.Member
  191. demote bool
  192. )
  193. err := s.store.Update(func(tx store.Tx) error {
  194. node = store.GetNode(tx, request.NodeID)
  195. if node == nil {
  196. return grpc.Errorf(codes.NotFound, "node %s not found", request.NodeID)
  197. }
  198. // Demotion sanity checks.
  199. if node.Spec.Role == api.NodeRoleManager && request.Spec.Role == api.NodeRoleWorker {
  200. demote = true
  201. // Check for manager entries in Store.
  202. managers, err := store.FindNodes(tx, store.ByRole(api.NodeRoleManager))
  203. if err != nil {
  204. return grpc.Errorf(codes.Internal, "internal store error: %v", err)
  205. }
  206. if len(managers) == 1 && managers[0].ID == node.ID {
  207. return grpc.Errorf(codes.FailedPrecondition, "attempting to demote the last manager of the swarm")
  208. }
  209. // Check for node in memberlist
  210. if member = s.raft.GetMemberByNodeID(request.NodeID); member == nil {
  211. return grpc.Errorf(codes.NotFound, "can't find manager in raft memberlist")
  212. }
  213. // Quorum safeguard
  214. if !s.raft.CanRemoveMember(member.RaftID) {
  215. return grpc.Errorf(codes.FailedPrecondition, "can't remove member from the raft: this would result in a loss of quorum")
  216. }
  217. }
  218. node.Meta.Version = *request.NodeVersion
  219. node.Spec = *request.Spec.Copy()
  220. return store.UpdateNode(tx, node)
  221. })
  222. if err != nil {
  223. return nil, err
  224. }
  225. if demote && s.raft != nil {
  226. // TODO(abronan): the remove can potentially fail and leave the node with
  227. // an incorrect role (worker rather than manager), we need to reconcile the
  228. // memberlist with the desired state rather than attempting to remove the
  229. // member once.
  230. if err := s.raft.RemoveMember(ctx, member.RaftID); err != nil {
  231. return nil, grpc.Errorf(codes.Internal, "cannot demote manager to worker: %v", err)
  232. }
  233. }
  234. return &api.UpdateNodeResponse{
  235. Node: node,
  236. }, nil
  237. }
  238. // RemoveNode removes a Node referenced by NodeID with the given NodeSpec.
  239. // - Returns NotFound if the Node is not found.
  240. // - Returns FailedPrecondition if the Node has manager role (and is part of the memberlist) or is not shut down.
  241. // - Returns InvalidArgument if NodeID or NodeVersion is not valid.
  242. // - Returns an error if the delete fails.
  243. func (s *Server) RemoveNode(ctx context.Context, request *api.RemoveNodeRequest) (*api.RemoveNodeResponse, error) {
  244. if request.NodeID == "" {
  245. return nil, grpc.Errorf(codes.InvalidArgument, errInvalidArgument.Error())
  246. }
  247. err := s.store.Update(func(tx store.Tx) error {
  248. node := store.GetNode(tx, request.NodeID)
  249. if node == nil {
  250. return grpc.Errorf(codes.NotFound, "node %s not found", request.NodeID)
  251. }
  252. if node.Spec.Role == api.NodeRoleManager {
  253. if s.raft == nil {
  254. return grpc.Errorf(codes.FailedPrecondition, "node %s is a manager but cannot access node information from the raft memberlist", request.NodeID)
  255. }
  256. if member := s.raft.GetMemberByNodeID(request.NodeID); member != nil {
  257. return grpc.Errorf(codes.FailedPrecondition, "node %s is a cluster manager and is a member of the raft cluster. It must be demoted to worker before removal", request.NodeID)
  258. }
  259. }
  260. if !request.Force && node.Status.State == api.NodeStatus_READY {
  261. return grpc.Errorf(codes.FailedPrecondition, "node %s is not down and can't be removed", request.NodeID)
  262. }
  263. // lookup the cluster
  264. clusters, err := store.FindClusters(tx, store.ByName("default"))
  265. if err != nil {
  266. return err
  267. }
  268. if len(clusters) != 1 {
  269. return grpc.Errorf(codes.Internal, "could not fetch cluster object")
  270. }
  271. cluster := clusters[0]
  272. blacklistedCert := &api.BlacklistedCertificate{}
  273. // Set an expiry time for this RemovedNode if a certificate
  274. // exists and can be parsed.
  275. if len(node.Certificate.Certificate) != 0 {
  276. certBlock, _ := pem.Decode(node.Certificate.Certificate)
  277. if certBlock != nil {
  278. X509Cert, err := x509.ParseCertificate(certBlock.Bytes)
  279. if err == nil && !X509Cert.NotAfter.IsZero() {
  280. expiry, err := ptypes.TimestampProto(X509Cert.NotAfter)
  281. if err == nil {
  282. blacklistedCert.Expiry = expiry
  283. }
  284. }
  285. }
  286. }
  287. if cluster.BlacklistedCertificates == nil {
  288. cluster.BlacklistedCertificates = make(map[string]*api.BlacklistedCertificate)
  289. }
  290. cluster.BlacklistedCertificates[node.ID] = blacklistedCert
  291. expireBlacklistedCerts(cluster)
  292. if err := store.UpdateCluster(tx, cluster); err != nil {
  293. return err
  294. }
  295. return store.DeleteNode(tx, request.NodeID)
  296. })
  297. if err != nil {
  298. return nil, err
  299. }
  300. return &api.RemoveNodeResponse{}, nil
  301. }