cluster.go 41 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389139013911392139313941395139613971398139914001401140214031404140514061407140814091410141114121413141414151416141714181419142014211422142314241425142614271428142914301431143214331434143514361437143814391440144114421443144414451446144714481449145014511452145314541455145614571458145914601461146214631464146514661467146814691470147114721473147414751476147714781479148014811482148314841485148614871488148914901491149214931494149514961497149814991500150115021503150415051506150715081509151015111512151315141515151615171518151915201521152215231524152515261527152815291530153115321533153415351536153715381539154015411542154315441545154615471548154915501551155215531554155515561557155815591560156115621563156415651566156715681569157015711572157315741575157615771578157915801581158215831584158515861587158815891590159115921593159415951596159715981599160016011602160316041605160616071608160916101611
  1. package cluster
  2. import (
  3. "encoding/json"
  4. "fmt"
  5. "io/ioutil"
  6. "net"
  7. "os"
  8. "path/filepath"
  9. "strings"
  10. "sync"
  11. "time"
  12. "google.golang.org/grpc"
  13. "github.com/Sirupsen/logrus"
  14. "github.com/docker/docker/api/errors"
  15. apitypes "github.com/docker/docker/api/types"
  16. "github.com/docker/docker/api/types/filters"
  17. "github.com/docker/docker/api/types/network"
  18. types "github.com/docker/docker/api/types/swarm"
  19. "github.com/docker/docker/daemon/cluster/convert"
  20. executorpkg "github.com/docker/docker/daemon/cluster/executor"
  21. "github.com/docker/docker/daemon/cluster/executor/container"
  22. "github.com/docker/docker/opts"
  23. "github.com/docker/docker/pkg/ioutils"
  24. "github.com/docker/docker/pkg/signal"
  25. "github.com/docker/docker/runconfig"
  26. swarmagent "github.com/docker/swarmkit/agent"
  27. swarmapi "github.com/docker/swarmkit/api"
  28. "golang.org/x/net/context"
  29. )
  30. const swarmDirName = "swarm"
  31. const controlSocket = "control.sock"
  32. const swarmConnectTimeout = 20 * time.Second
  33. const swarmRequestTimeout = 20 * time.Second
  34. const stateFile = "docker-state.json"
  35. const defaultAddr = "0.0.0.0:2377"
  36. const (
  37. initialReconnectDelay = 100 * time.Millisecond
  38. maxReconnectDelay = 30 * time.Second
  39. )
  40. // ErrNoSwarm is returned on leaving a cluster that was never initialized
  41. var ErrNoSwarm = fmt.Errorf("This node is not part of a swarm")
  42. // ErrSwarmExists is returned on initialize or join request for a cluster that has already been activated
  43. var ErrSwarmExists = fmt.Errorf("This node is already part of a swarm. Use \"docker swarm leave\" to leave this swarm and join another one.")
  44. // ErrPendingSwarmExists is returned on initialize or join request for a cluster that is already processing a similar request but has not succeeded yet.
  45. var ErrPendingSwarmExists = fmt.Errorf("This node is processing an existing join request that has not succeeded yet. Use \"docker swarm leave\" to cancel the current request.")
  46. // ErrSwarmJoinTimeoutReached is returned when cluster join could not complete before timeout was reached.
  47. var ErrSwarmJoinTimeoutReached = fmt.Errorf("Timeout was reached before node was joined. The attempt to join the swarm will continue in the background. Use the \"docker info\" command to see the current swarm status of your node.")
  48. // defaultSpec contains some sane defaults if cluster options are missing on init
  49. var defaultSpec = types.Spec{
  50. Raft: types.RaftConfig{
  51. SnapshotInterval: 10000,
  52. KeepOldSnapshots: 0,
  53. LogEntriesForSlowFollowers: 500,
  54. HeartbeatTick: 1,
  55. ElectionTick: 3,
  56. },
  57. CAConfig: types.CAConfig{
  58. NodeCertExpiry: 90 * 24 * time.Hour,
  59. },
  60. Dispatcher: types.DispatcherConfig{
  61. HeartbeatPeriod: 5 * time.Second,
  62. },
  63. Orchestration: types.OrchestrationConfig{
  64. TaskHistoryRetentionLimit: 10,
  65. },
  66. }
  67. type state struct {
  68. // LocalAddr is this machine's local IP or hostname, if specified.
  69. LocalAddr string
  70. // RemoteAddr is the address that was given to "swarm join. It is used
  71. // to find LocalAddr if necessary.
  72. RemoteAddr string
  73. // ListenAddr is the address we bind to, including a port.
  74. ListenAddr string
  75. // AdvertiseAddr is the address other nodes should connect to,
  76. // including a port.
  77. AdvertiseAddr string
  78. }
  79. // NetworkSubnetsProvider exposes functions for retrieving the subnets
  80. // of networks managed by Docker, so they can be filtered.
  81. type NetworkSubnetsProvider interface {
  82. V4Subnets() []net.IPNet
  83. V6Subnets() []net.IPNet
  84. }
  85. // Config provides values for Cluster.
  86. type Config struct {
  87. Root string
  88. Name string
  89. Backend executorpkg.Backend
  90. NetworkSubnetsProvider NetworkSubnetsProvider
  91. // DefaultAdvertiseAddr is the default host/IP or network interface to use
  92. // if no AdvertiseAddr value is specified.
  93. DefaultAdvertiseAddr string
  94. // path to store runtime state, such as the swarm control socket
  95. RuntimeRoot string
  96. }
  97. // Cluster provides capabilities to participate in a cluster as a worker or a
  98. // manager.
  99. type Cluster struct {
  100. sync.RWMutex
  101. *node
  102. root string
  103. runtimeRoot string
  104. config Config
  105. configEvent chan struct{} // todo: make this array and goroutine safe
  106. localAddr string
  107. actualLocalAddr string // after resolution, not persisted
  108. remoteAddr string
  109. listenAddr string
  110. advertiseAddr string
  111. stop bool
  112. err error
  113. cancelDelay func()
  114. attachers map[string]*attacher
  115. }
  116. // attacher manages the in-memory attachment state of a container
  117. // attachment to a global scope network managed by swarm manager. It
  118. // helps in identifying the attachment ID via the taskID and the
  119. // corresponding attachment configuration obtained from the manager.
  120. type attacher struct {
  121. taskID string
  122. config *network.NetworkingConfig
  123. attachWaitCh chan *network.NetworkingConfig
  124. attachCompleteCh chan struct{}
  125. detachWaitCh chan struct{}
  126. }
  127. type node struct {
  128. *swarmagent.Node
  129. done chan struct{}
  130. ready bool
  131. conn *grpc.ClientConn
  132. client swarmapi.ControlClient
  133. reconnectDelay time.Duration
  134. }
  135. // New creates a new Cluster instance using provided config.
  136. func New(config Config) (*Cluster, error) {
  137. root := filepath.Join(config.Root, swarmDirName)
  138. if err := os.MkdirAll(root, 0700); err != nil {
  139. return nil, err
  140. }
  141. if config.RuntimeRoot == "" {
  142. config.RuntimeRoot = root
  143. }
  144. if err := os.MkdirAll(config.RuntimeRoot, 0700); err != nil {
  145. return nil, err
  146. }
  147. c := &Cluster{
  148. root: root,
  149. config: config,
  150. configEvent: make(chan struct{}, 10),
  151. runtimeRoot: config.RuntimeRoot,
  152. attachers: make(map[string]*attacher),
  153. }
  154. st, err := c.loadState()
  155. if err != nil {
  156. if os.IsNotExist(err) {
  157. return c, nil
  158. }
  159. return nil, err
  160. }
  161. n, err := c.startNewNode(false, st.LocalAddr, st.RemoteAddr, st.ListenAddr, st.AdvertiseAddr, "", "")
  162. if err != nil {
  163. return nil, err
  164. }
  165. select {
  166. case <-time.After(swarmConnectTimeout):
  167. logrus.Errorf("swarm component could not be started before timeout was reached")
  168. case <-n.Ready():
  169. case <-n.done:
  170. return nil, fmt.Errorf("swarm component could not be started: %v", c.err)
  171. }
  172. go c.reconnectOnFailure(n)
  173. return c, nil
  174. }
  175. func (c *Cluster) loadState() (*state, error) {
  176. dt, err := ioutil.ReadFile(filepath.Join(c.root, stateFile))
  177. if err != nil {
  178. return nil, err
  179. }
  180. // missing certificate means no actual state to restore from
  181. if _, err := os.Stat(filepath.Join(c.root, "certificates/swarm-node.crt")); err != nil {
  182. if os.IsNotExist(err) {
  183. c.clearState()
  184. }
  185. return nil, err
  186. }
  187. var st state
  188. if err := json.Unmarshal(dt, &st); err != nil {
  189. return nil, err
  190. }
  191. return &st, nil
  192. }
  193. func (c *Cluster) saveState() error {
  194. dt, err := json.Marshal(state{
  195. LocalAddr: c.localAddr,
  196. RemoteAddr: c.remoteAddr,
  197. ListenAddr: c.listenAddr,
  198. AdvertiseAddr: c.advertiseAddr,
  199. })
  200. if err != nil {
  201. return err
  202. }
  203. return ioutils.AtomicWriteFile(filepath.Join(c.root, stateFile), dt, 0600)
  204. }
  205. func (c *Cluster) reconnectOnFailure(n *node) {
  206. for {
  207. <-n.done
  208. c.Lock()
  209. if c.stop || c.node != nil {
  210. c.Unlock()
  211. return
  212. }
  213. n.reconnectDelay *= 2
  214. if n.reconnectDelay > maxReconnectDelay {
  215. n.reconnectDelay = maxReconnectDelay
  216. }
  217. logrus.Warnf("Restarting swarm in %.2f seconds", n.reconnectDelay.Seconds())
  218. delayCtx, cancel := context.WithTimeout(context.Background(), n.reconnectDelay)
  219. c.cancelDelay = cancel
  220. c.Unlock()
  221. <-delayCtx.Done()
  222. if delayCtx.Err() != context.DeadlineExceeded {
  223. return
  224. }
  225. c.Lock()
  226. if c.node != nil {
  227. c.Unlock()
  228. return
  229. }
  230. var err error
  231. n, err = c.startNewNode(false, c.localAddr, c.getRemoteAddress(), c.listenAddr, c.advertiseAddr, c.getRemoteAddress(), "")
  232. if err != nil {
  233. c.err = err
  234. close(n.done)
  235. }
  236. c.Unlock()
  237. }
  238. }
  239. func (c *Cluster) startNewNode(forceNewCluster bool, localAddr, remoteAddr, listenAddr, advertiseAddr, joinAddr, joinToken string) (*node, error) {
  240. if err := c.config.Backend.IsSwarmCompatible(); err != nil {
  241. return nil, err
  242. }
  243. actualLocalAddr := localAddr
  244. if actualLocalAddr == "" {
  245. // If localAddr was not specified, resolve it automatically
  246. // based on the route to joinAddr. localAddr can only be left
  247. // empty on "join".
  248. listenHost, _, err := net.SplitHostPort(listenAddr)
  249. if err != nil {
  250. return nil, fmt.Errorf("could not parse listen address: %v", err)
  251. }
  252. listenAddrIP := net.ParseIP(listenHost)
  253. if listenAddrIP == nil || !listenAddrIP.IsUnspecified() {
  254. actualLocalAddr = listenHost
  255. } else {
  256. if remoteAddr == "" {
  257. // Should never happen except using swarms created by
  258. // old versions that didn't save remoteAddr.
  259. remoteAddr = "8.8.8.8:53"
  260. }
  261. conn, err := net.Dial("udp", remoteAddr)
  262. if err != nil {
  263. return nil, fmt.Errorf("could not find local IP address: %v", err)
  264. }
  265. localHostPort := conn.LocalAddr().String()
  266. actualLocalAddr, _, _ = net.SplitHostPort(localHostPort)
  267. conn.Close()
  268. }
  269. }
  270. c.node = nil
  271. c.cancelDelay = nil
  272. c.stop = false
  273. n, err := swarmagent.NewNode(&swarmagent.NodeConfig{
  274. Hostname: c.config.Name,
  275. ForceNewCluster: forceNewCluster,
  276. ListenControlAPI: filepath.Join(c.runtimeRoot, controlSocket),
  277. ListenRemoteAPI: listenAddr,
  278. AdvertiseRemoteAPI: advertiseAddr,
  279. JoinAddr: joinAddr,
  280. StateDir: c.root,
  281. JoinToken: joinToken,
  282. Executor: container.NewExecutor(c.config.Backend),
  283. HeartbeatTick: 1,
  284. ElectionTick: 3,
  285. })
  286. if err != nil {
  287. return nil, err
  288. }
  289. ctx := context.Background()
  290. if err := n.Start(ctx); err != nil {
  291. return nil, err
  292. }
  293. node := &node{
  294. Node: n,
  295. done: make(chan struct{}),
  296. reconnectDelay: initialReconnectDelay,
  297. }
  298. c.node = node
  299. c.localAddr = localAddr
  300. c.actualLocalAddr = actualLocalAddr // not saved
  301. c.remoteAddr = remoteAddr
  302. c.listenAddr = listenAddr
  303. c.advertiseAddr = advertiseAddr
  304. c.saveState()
  305. c.config.Backend.SetClusterProvider(c)
  306. go func() {
  307. err := n.Err(ctx)
  308. if err != nil {
  309. logrus.Errorf("cluster exited with error: %v", err)
  310. }
  311. c.Lock()
  312. c.node = nil
  313. c.err = err
  314. c.Unlock()
  315. close(node.done)
  316. }()
  317. go func() {
  318. select {
  319. case <-n.Ready():
  320. c.Lock()
  321. node.ready = true
  322. c.err = nil
  323. c.Unlock()
  324. case <-ctx.Done():
  325. }
  326. c.configEvent <- struct{}{}
  327. }()
  328. go func() {
  329. for conn := range n.ListenControlSocket(ctx) {
  330. c.Lock()
  331. if node.conn != conn {
  332. if conn == nil {
  333. node.client = nil
  334. } else {
  335. node.client = swarmapi.NewControlClient(conn)
  336. }
  337. }
  338. node.conn = conn
  339. c.Unlock()
  340. c.configEvent <- struct{}{}
  341. }
  342. }()
  343. return node, nil
  344. }
  345. // Init initializes new cluster from user provided request.
  346. func (c *Cluster) Init(req types.InitRequest) (string, error) {
  347. c.Lock()
  348. if node := c.node; node != nil {
  349. if !req.ForceNewCluster {
  350. c.Unlock()
  351. return "", ErrSwarmExists
  352. }
  353. if err := c.stopNode(); err != nil {
  354. c.Unlock()
  355. return "", err
  356. }
  357. }
  358. if err := validateAndSanitizeInitRequest(&req); err != nil {
  359. c.Unlock()
  360. return "", err
  361. }
  362. listenHost, listenPort, err := resolveListenAddr(req.ListenAddr)
  363. if err != nil {
  364. c.Unlock()
  365. return "", err
  366. }
  367. advertiseHost, advertisePort, err := c.resolveAdvertiseAddr(req.AdvertiseAddr, listenPort)
  368. if err != nil {
  369. c.Unlock()
  370. return "", err
  371. }
  372. localAddr := listenHost
  373. // If the advertise address is not one of the system's
  374. // addresses, we also require a listen address.
  375. listenAddrIP := net.ParseIP(listenHost)
  376. if listenAddrIP != nil && listenAddrIP.IsUnspecified() {
  377. advertiseIP := net.ParseIP(advertiseHost)
  378. if advertiseIP == nil {
  379. // not an IP
  380. c.Unlock()
  381. return "", errMustSpecifyListenAddr
  382. }
  383. systemIPs := listSystemIPs()
  384. found := false
  385. for _, systemIP := range systemIPs {
  386. if systemIP.Equal(advertiseIP) {
  387. found = true
  388. break
  389. }
  390. }
  391. if !found {
  392. c.Unlock()
  393. return "", errMustSpecifyListenAddr
  394. }
  395. localAddr = advertiseIP.String()
  396. }
  397. // todo: check current state existing
  398. n, err := c.startNewNode(req.ForceNewCluster, localAddr, "", net.JoinHostPort(listenHost, listenPort), net.JoinHostPort(advertiseHost, advertisePort), "", "")
  399. if err != nil {
  400. c.Unlock()
  401. return "", err
  402. }
  403. c.Unlock()
  404. select {
  405. case <-n.Ready():
  406. if err := initClusterSpec(n, req.Spec); err != nil {
  407. return "", err
  408. }
  409. go c.reconnectOnFailure(n)
  410. return n.NodeID(), nil
  411. case <-n.done:
  412. c.RLock()
  413. defer c.RUnlock()
  414. if !req.ForceNewCluster { // if failure on first attempt don't keep state
  415. if err := c.clearState(); err != nil {
  416. return "", err
  417. }
  418. }
  419. return "", c.err
  420. }
  421. }
  422. // Join makes current Cluster part of an existing swarm cluster.
  423. func (c *Cluster) Join(req types.JoinRequest) error {
  424. c.Lock()
  425. if node := c.node; node != nil {
  426. c.Unlock()
  427. return ErrSwarmExists
  428. }
  429. if err := validateAndSanitizeJoinRequest(&req); err != nil {
  430. c.Unlock()
  431. return err
  432. }
  433. listenHost, listenPort, err := resolveListenAddr(req.ListenAddr)
  434. if err != nil {
  435. c.Unlock()
  436. return err
  437. }
  438. var advertiseAddr string
  439. if req.AdvertiseAddr != "" {
  440. advertiseHost, advertisePort, err := c.resolveAdvertiseAddr(req.AdvertiseAddr, listenPort)
  441. // For joining, we don't need to provide an advertise address,
  442. // since the remote side can detect it.
  443. if err == nil {
  444. advertiseAddr = net.JoinHostPort(advertiseHost, advertisePort)
  445. }
  446. }
  447. // todo: check current state existing
  448. n, err := c.startNewNode(false, "", req.RemoteAddrs[0], net.JoinHostPort(listenHost, listenPort), advertiseAddr, req.RemoteAddrs[0], req.JoinToken)
  449. if err != nil {
  450. c.Unlock()
  451. return err
  452. }
  453. c.Unlock()
  454. select {
  455. case <-time.After(swarmConnectTimeout):
  456. // attempt to connect will continue in background, also reconnecting
  457. go c.reconnectOnFailure(n)
  458. return ErrSwarmJoinTimeoutReached
  459. case <-n.Ready():
  460. go c.reconnectOnFailure(n)
  461. return nil
  462. case <-n.done:
  463. c.RLock()
  464. defer c.RUnlock()
  465. return c.err
  466. }
  467. }
  468. // stopNode is a helper that stops the active c.node and waits until it has
  469. // shut down. Call while keeping the cluster lock.
  470. func (c *Cluster) stopNode() error {
  471. if c.node == nil {
  472. return nil
  473. }
  474. c.stop = true
  475. if c.cancelDelay != nil {
  476. c.cancelDelay()
  477. c.cancelDelay = nil
  478. }
  479. node := c.node
  480. ctx, cancel := context.WithTimeout(context.Background(), 15*time.Second)
  481. defer cancel()
  482. // TODO: can't hold lock on stop because it calls back to network
  483. c.Unlock()
  484. defer c.Lock()
  485. if err := node.Stop(ctx); err != nil && !strings.Contains(err.Error(), "context canceled") {
  486. return err
  487. }
  488. <-node.done
  489. return nil
  490. }
  491. func removingManagerCausesLossOfQuorum(reachable, unreachable int) bool {
  492. return reachable-2 <= unreachable
  493. }
  494. func isLastManager(reachable, unreachable int) bool {
  495. return reachable == 1 && unreachable == 0
  496. }
  497. // Leave shuts down Cluster and removes current state.
  498. func (c *Cluster) Leave(force bool) error {
  499. c.Lock()
  500. node := c.node
  501. if node == nil {
  502. c.Unlock()
  503. return ErrNoSwarm
  504. }
  505. if node.Manager() != nil && !force {
  506. msg := "You are attempting to leave the swarm on a node that is participating as a manager. "
  507. if c.isActiveManager() {
  508. active, reachable, unreachable, err := c.managerStats()
  509. if err == nil {
  510. if active && removingManagerCausesLossOfQuorum(reachable, unreachable) {
  511. if isLastManager(reachable, unreachable) {
  512. msg += "Removing the last manager erases all current state of the swarm. Use `--force` to ignore this message. "
  513. c.Unlock()
  514. return fmt.Errorf(msg)
  515. }
  516. msg += fmt.Sprintf("Removing this node leaves %v managers out of %v. Without a Raft quorum your swarm will be inaccessible. ", reachable-1, reachable+unreachable)
  517. }
  518. }
  519. } else {
  520. msg += "Doing so may lose the consensus of your cluster. "
  521. }
  522. msg += "The only way to restore a swarm that has lost consensus is to reinitialize it with `--force-new-cluster`. Use `--force` to suppress this message."
  523. c.Unlock()
  524. return fmt.Errorf(msg)
  525. }
  526. if err := c.stopNode(); err != nil {
  527. logrus.Errorf("failed to shut down cluster node: %v", err)
  528. signal.DumpStacks("")
  529. c.Unlock()
  530. return err
  531. }
  532. c.Unlock()
  533. if nodeID := node.NodeID(); nodeID != "" {
  534. nodeContainers, err := c.listContainerForNode(nodeID)
  535. if err != nil {
  536. return err
  537. }
  538. for _, id := range nodeContainers {
  539. if err := c.config.Backend.ContainerRm(id, &apitypes.ContainerRmConfig{ForceRemove: true}); err != nil {
  540. logrus.Errorf("error removing %v: %v", id, err)
  541. }
  542. }
  543. }
  544. c.configEvent <- struct{}{}
  545. // todo: cleanup optional?
  546. if err := c.clearState(); err != nil {
  547. return err
  548. }
  549. return nil
  550. }
  551. func (c *Cluster) listContainerForNode(nodeID string) ([]string, error) {
  552. var ids []string
  553. filters := filters.NewArgs()
  554. filters.Add("label", fmt.Sprintf("com.docker.swarm.node.id=%s", nodeID))
  555. containers, err := c.config.Backend.Containers(&apitypes.ContainerListOptions{
  556. Filter: filters,
  557. })
  558. if err != nil {
  559. return []string{}, err
  560. }
  561. for _, c := range containers {
  562. ids = append(ids, c.ID)
  563. }
  564. return ids, nil
  565. }
  566. func (c *Cluster) clearState() error {
  567. // todo: backup this data instead of removing?
  568. if err := os.RemoveAll(c.root); err != nil {
  569. return err
  570. }
  571. if err := os.MkdirAll(c.root, 0700); err != nil {
  572. return err
  573. }
  574. c.config.Backend.SetClusterProvider(nil)
  575. return nil
  576. }
  577. func (c *Cluster) getRequestContext() (context.Context, func()) { // TODO: not needed when requests don't block on qourum lost
  578. return context.WithTimeout(context.Background(), swarmRequestTimeout)
  579. }
  580. // Inspect retrieves the configuration properties of a managed swarm cluster.
  581. func (c *Cluster) Inspect() (types.Swarm, error) {
  582. c.RLock()
  583. defer c.RUnlock()
  584. if !c.isActiveManager() {
  585. return types.Swarm{}, c.errNoManager()
  586. }
  587. ctx, cancel := c.getRequestContext()
  588. defer cancel()
  589. swarm, err := getSwarm(ctx, c.client)
  590. if err != nil {
  591. return types.Swarm{}, err
  592. }
  593. if err != nil {
  594. return types.Swarm{}, err
  595. }
  596. return convert.SwarmFromGRPC(*swarm), nil
  597. }
  598. // Update updates configuration of a managed swarm cluster.
  599. func (c *Cluster) Update(version uint64, spec types.Spec, flags types.UpdateFlags) error {
  600. c.RLock()
  601. defer c.RUnlock()
  602. if !c.isActiveManager() {
  603. return c.errNoManager()
  604. }
  605. ctx, cancel := c.getRequestContext()
  606. defer cancel()
  607. swarm, err := getSwarm(ctx, c.client)
  608. if err != nil {
  609. return err
  610. }
  611. swarmSpec, err := convert.SwarmSpecToGRPC(spec)
  612. if err != nil {
  613. return err
  614. }
  615. _, err = c.client.UpdateCluster(
  616. ctx,
  617. &swarmapi.UpdateClusterRequest{
  618. ClusterID: swarm.ID,
  619. Spec: &swarmSpec,
  620. ClusterVersion: &swarmapi.Version{
  621. Index: version,
  622. },
  623. Rotation: swarmapi.JoinTokenRotation{
  624. RotateWorkerToken: flags.RotateWorkerToken,
  625. RotateManagerToken: flags.RotateManagerToken,
  626. },
  627. },
  628. )
  629. return err
  630. }
  631. // IsManager returns true if Cluster is participating as a manager.
  632. func (c *Cluster) IsManager() bool {
  633. c.RLock()
  634. defer c.RUnlock()
  635. return c.isActiveManager()
  636. }
  637. // IsAgent returns true if Cluster is participating as a worker/agent.
  638. func (c *Cluster) IsAgent() bool {
  639. c.RLock()
  640. defer c.RUnlock()
  641. return c.node != nil && c.ready
  642. }
  643. // GetLocalAddress returns the local address.
  644. func (c *Cluster) GetLocalAddress() string {
  645. c.RLock()
  646. defer c.RUnlock()
  647. return c.actualLocalAddr
  648. }
  649. // GetAdvertiseAddress returns the remotely reachable address of this node.
  650. func (c *Cluster) GetAdvertiseAddress() string {
  651. c.RLock()
  652. defer c.RUnlock()
  653. if c.advertiseAddr != "" {
  654. advertiseHost, _, _ := net.SplitHostPort(c.advertiseAddr)
  655. return advertiseHost
  656. }
  657. return c.actualLocalAddr
  658. }
  659. // GetRemoteAddress returns a known advertise address of a remote manager if
  660. // available.
  661. // todo: change to array/connect with info
  662. func (c *Cluster) GetRemoteAddress() string {
  663. c.RLock()
  664. defer c.RUnlock()
  665. return c.getRemoteAddress()
  666. }
  667. func (c *Cluster) getRemoteAddress() string {
  668. if c.node == nil {
  669. return ""
  670. }
  671. nodeID := c.node.NodeID()
  672. for _, r := range c.node.Remotes() {
  673. if r.NodeID != nodeID {
  674. return r.Addr
  675. }
  676. }
  677. return ""
  678. }
  679. // ListenClusterEvents returns a channel that receives messages on cluster
  680. // participation changes.
  681. // todo: make cancelable and accessible to multiple callers
  682. func (c *Cluster) ListenClusterEvents() <-chan struct{} {
  683. return c.configEvent
  684. }
  685. // Info returns information about the current cluster state.
  686. func (c *Cluster) Info() types.Info {
  687. info := types.Info{
  688. NodeAddr: c.GetAdvertiseAddress(),
  689. }
  690. c.RLock()
  691. defer c.RUnlock()
  692. if c.node == nil {
  693. info.LocalNodeState = types.LocalNodeStateInactive
  694. if c.cancelDelay != nil {
  695. info.LocalNodeState = types.LocalNodeStateError
  696. }
  697. } else {
  698. info.LocalNodeState = types.LocalNodeStatePending
  699. if c.ready == true {
  700. info.LocalNodeState = types.LocalNodeStateActive
  701. }
  702. }
  703. if c.err != nil {
  704. info.Error = c.err.Error()
  705. }
  706. ctx, cancel := c.getRequestContext()
  707. defer cancel()
  708. if c.isActiveManager() {
  709. info.ControlAvailable = true
  710. swarm, err := c.Inspect()
  711. if err != nil {
  712. info.Error = err.Error()
  713. }
  714. // Strip JoinTokens
  715. info.Cluster = swarm.ClusterInfo
  716. if r, err := c.client.ListNodes(ctx, &swarmapi.ListNodesRequest{}); err == nil {
  717. info.Nodes = len(r.Nodes)
  718. for _, n := range r.Nodes {
  719. if n.ManagerStatus != nil {
  720. info.Managers = info.Managers + 1
  721. }
  722. }
  723. }
  724. }
  725. if c.node != nil {
  726. for _, r := range c.node.Remotes() {
  727. info.RemoteManagers = append(info.RemoteManagers, types.Peer{NodeID: r.NodeID, Addr: r.Addr})
  728. }
  729. info.NodeID = c.node.NodeID()
  730. }
  731. return info
  732. }
  733. // isActiveManager should not be called without a read lock
  734. func (c *Cluster) isActiveManager() bool {
  735. return c.node != nil && c.conn != nil
  736. }
  737. // errNoManager returns error describing why manager commands can't be used.
  738. // Call with read lock.
  739. func (c *Cluster) errNoManager() error {
  740. if c.node == nil {
  741. return fmt.Errorf("This node is not a swarm manager. Use \"docker swarm init\" or \"docker swarm join\" to connect this node to swarm and try again.")
  742. }
  743. if c.node.Manager() != nil {
  744. return fmt.Errorf("This node is not a swarm manager. Manager is being prepared or has trouble connecting to the cluster.")
  745. }
  746. return fmt.Errorf("This node is not a swarm manager. Worker nodes can't be used to view or modify cluster state. Please run this command on a manager node or promote the current node to a manager.")
  747. }
  748. // GetServices returns all services of a managed swarm cluster.
  749. func (c *Cluster) GetServices(options apitypes.ServiceListOptions) ([]types.Service, error) {
  750. c.RLock()
  751. defer c.RUnlock()
  752. if !c.isActiveManager() {
  753. return nil, c.errNoManager()
  754. }
  755. filters, err := newListServicesFilters(options.Filter)
  756. if err != nil {
  757. return nil, err
  758. }
  759. ctx, cancel := c.getRequestContext()
  760. defer cancel()
  761. r, err := c.client.ListServices(
  762. ctx,
  763. &swarmapi.ListServicesRequest{Filters: filters})
  764. if err != nil {
  765. return nil, err
  766. }
  767. services := []types.Service{}
  768. for _, service := range r.Services {
  769. services = append(services, convert.ServiceFromGRPC(*service))
  770. }
  771. return services, nil
  772. }
  773. // CreateService creates a new service in a managed swarm cluster.
  774. func (c *Cluster) CreateService(s types.ServiceSpec, encodedAuth string) (string, error) {
  775. c.RLock()
  776. defer c.RUnlock()
  777. if !c.isActiveManager() {
  778. return "", c.errNoManager()
  779. }
  780. ctx, cancel := c.getRequestContext()
  781. defer cancel()
  782. err := c.populateNetworkID(ctx, c.client, &s)
  783. if err != nil {
  784. return "", err
  785. }
  786. serviceSpec, err := convert.ServiceSpecToGRPC(s)
  787. if err != nil {
  788. return "", err
  789. }
  790. if encodedAuth != "" {
  791. ctnr := serviceSpec.Task.GetContainer()
  792. if ctnr == nil {
  793. return "", fmt.Errorf("service does not use container tasks")
  794. }
  795. ctnr.PullOptions = &swarmapi.ContainerSpec_PullOptions{RegistryAuth: encodedAuth}
  796. }
  797. r, err := c.client.CreateService(ctx, &swarmapi.CreateServiceRequest{Spec: &serviceSpec})
  798. if err != nil {
  799. return "", err
  800. }
  801. return r.Service.ID, nil
  802. }
  803. // GetService returns a service based on an ID or name.
  804. func (c *Cluster) GetService(input string) (types.Service, error) {
  805. c.RLock()
  806. defer c.RUnlock()
  807. if !c.isActiveManager() {
  808. return types.Service{}, c.errNoManager()
  809. }
  810. ctx, cancel := c.getRequestContext()
  811. defer cancel()
  812. service, err := getService(ctx, c.client, input)
  813. if err != nil {
  814. return types.Service{}, err
  815. }
  816. return convert.ServiceFromGRPC(*service), nil
  817. }
  818. // UpdateService updates existing service to match new properties.
  819. func (c *Cluster) UpdateService(serviceIDOrName string, version uint64, spec types.ServiceSpec, encodedAuth string) error {
  820. c.RLock()
  821. defer c.RUnlock()
  822. if !c.isActiveManager() {
  823. return c.errNoManager()
  824. }
  825. ctx, cancel := c.getRequestContext()
  826. defer cancel()
  827. err := c.populateNetworkID(ctx, c.client, &spec)
  828. if err != nil {
  829. return err
  830. }
  831. serviceSpec, err := convert.ServiceSpecToGRPC(spec)
  832. if err != nil {
  833. return err
  834. }
  835. currentService, err := getService(ctx, c.client, serviceIDOrName)
  836. if err != nil {
  837. return err
  838. }
  839. if encodedAuth != "" {
  840. ctnr := serviceSpec.Task.GetContainer()
  841. if ctnr == nil {
  842. return fmt.Errorf("service does not use container tasks")
  843. }
  844. ctnr.PullOptions = &swarmapi.ContainerSpec_PullOptions{RegistryAuth: encodedAuth}
  845. } else {
  846. // this is needed because if the encodedAuth isn't being updated then we
  847. // shouldn't lose it, and continue to use the one that was already present
  848. ctnr := currentService.Spec.Task.GetContainer()
  849. if ctnr == nil {
  850. return fmt.Errorf("service does not use container tasks")
  851. }
  852. serviceSpec.Task.GetContainer().PullOptions = ctnr.PullOptions
  853. }
  854. _, err = c.client.UpdateService(
  855. ctx,
  856. &swarmapi.UpdateServiceRequest{
  857. ServiceID: currentService.ID,
  858. Spec: &serviceSpec,
  859. ServiceVersion: &swarmapi.Version{
  860. Index: version,
  861. },
  862. },
  863. )
  864. return err
  865. }
  866. // RemoveService removes a service from a managed swarm cluster.
  867. func (c *Cluster) RemoveService(input string) error {
  868. c.RLock()
  869. defer c.RUnlock()
  870. if !c.isActiveManager() {
  871. return c.errNoManager()
  872. }
  873. ctx, cancel := c.getRequestContext()
  874. defer cancel()
  875. service, err := getService(ctx, c.client, input)
  876. if err != nil {
  877. return err
  878. }
  879. if _, err := c.client.RemoveService(ctx, &swarmapi.RemoveServiceRequest{ServiceID: service.ID}); err != nil {
  880. return err
  881. }
  882. return nil
  883. }
  884. // GetNodes returns a list of all nodes known to a cluster.
  885. func (c *Cluster) GetNodes(options apitypes.NodeListOptions) ([]types.Node, error) {
  886. c.RLock()
  887. defer c.RUnlock()
  888. if !c.isActiveManager() {
  889. return nil, c.errNoManager()
  890. }
  891. filters, err := newListNodesFilters(options.Filter)
  892. if err != nil {
  893. return nil, err
  894. }
  895. ctx, cancel := c.getRequestContext()
  896. defer cancel()
  897. r, err := c.client.ListNodes(
  898. ctx,
  899. &swarmapi.ListNodesRequest{Filters: filters})
  900. if err != nil {
  901. return nil, err
  902. }
  903. nodes := []types.Node{}
  904. for _, node := range r.Nodes {
  905. nodes = append(nodes, convert.NodeFromGRPC(*node))
  906. }
  907. return nodes, nil
  908. }
  909. // GetNode returns a node based on an ID or name.
  910. func (c *Cluster) GetNode(input string) (types.Node, error) {
  911. c.RLock()
  912. defer c.RUnlock()
  913. if !c.isActiveManager() {
  914. return types.Node{}, c.errNoManager()
  915. }
  916. ctx, cancel := c.getRequestContext()
  917. defer cancel()
  918. node, err := getNode(ctx, c.client, input)
  919. if err != nil {
  920. return types.Node{}, err
  921. }
  922. return convert.NodeFromGRPC(*node), nil
  923. }
  924. // UpdateNode updates existing nodes properties.
  925. func (c *Cluster) UpdateNode(nodeID string, version uint64, spec types.NodeSpec) error {
  926. c.RLock()
  927. defer c.RUnlock()
  928. if !c.isActiveManager() {
  929. return c.errNoManager()
  930. }
  931. nodeSpec, err := convert.NodeSpecToGRPC(spec)
  932. if err != nil {
  933. return err
  934. }
  935. ctx, cancel := c.getRequestContext()
  936. defer cancel()
  937. _, err = c.client.UpdateNode(
  938. ctx,
  939. &swarmapi.UpdateNodeRequest{
  940. NodeID: nodeID,
  941. Spec: &nodeSpec,
  942. NodeVersion: &swarmapi.Version{
  943. Index: version,
  944. },
  945. },
  946. )
  947. return err
  948. }
  949. // RemoveNode removes a node from a cluster
  950. func (c *Cluster) RemoveNode(input string, force bool) error {
  951. c.RLock()
  952. defer c.RUnlock()
  953. if !c.isActiveManager() {
  954. return c.errNoManager()
  955. }
  956. ctx, cancel := c.getRequestContext()
  957. defer cancel()
  958. node, err := getNode(ctx, c.client, input)
  959. if err != nil {
  960. return err
  961. }
  962. if _, err := c.client.RemoveNode(ctx, &swarmapi.RemoveNodeRequest{NodeID: node.ID, Force: force}); err != nil {
  963. return err
  964. }
  965. return nil
  966. }
  967. // GetTasks returns a list of tasks matching the filter options.
  968. func (c *Cluster) GetTasks(options apitypes.TaskListOptions) ([]types.Task, error) {
  969. c.RLock()
  970. defer c.RUnlock()
  971. if !c.isActiveManager() {
  972. return nil, c.errNoManager()
  973. }
  974. byName := func(filter filters.Args) error {
  975. if filter.Include("service") {
  976. serviceFilters := filter.Get("service")
  977. for _, serviceFilter := range serviceFilters {
  978. service, err := c.GetService(serviceFilter)
  979. if err != nil {
  980. return err
  981. }
  982. filter.Del("service", serviceFilter)
  983. filter.Add("service", service.ID)
  984. }
  985. }
  986. if filter.Include("node") {
  987. nodeFilters := filter.Get("node")
  988. for _, nodeFilter := range nodeFilters {
  989. node, err := c.GetNode(nodeFilter)
  990. if err != nil {
  991. return err
  992. }
  993. filter.Del("node", nodeFilter)
  994. filter.Add("node", node.ID)
  995. }
  996. }
  997. return nil
  998. }
  999. filters, err := newListTasksFilters(options.Filter, byName)
  1000. if err != nil {
  1001. return nil, err
  1002. }
  1003. ctx, cancel := c.getRequestContext()
  1004. defer cancel()
  1005. r, err := c.client.ListTasks(
  1006. ctx,
  1007. &swarmapi.ListTasksRequest{Filters: filters})
  1008. if err != nil {
  1009. return nil, err
  1010. }
  1011. tasks := []types.Task{}
  1012. for _, task := range r.Tasks {
  1013. if task.Spec.GetContainer() != nil {
  1014. tasks = append(tasks, convert.TaskFromGRPC(*task))
  1015. }
  1016. }
  1017. return tasks, nil
  1018. }
  1019. // GetTask returns a task by an ID.
  1020. func (c *Cluster) GetTask(input string) (types.Task, error) {
  1021. c.RLock()
  1022. defer c.RUnlock()
  1023. if !c.isActiveManager() {
  1024. return types.Task{}, c.errNoManager()
  1025. }
  1026. ctx, cancel := c.getRequestContext()
  1027. defer cancel()
  1028. task, err := getTask(ctx, c.client, input)
  1029. if err != nil {
  1030. return types.Task{}, err
  1031. }
  1032. return convert.TaskFromGRPC(*task), nil
  1033. }
  1034. // GetNetwork returns a cluster network by an ID.
  1035. func (c *Cluster) GetNetwork(input string) (apitypes.NetworkResource, error) {
  1036. c.RLock()
  1037. defer c.RUnlock()
  1038. if !c.isActiveManager() {
  1039. return apitypes.NetworkResource{}, c.errNoManager()
  1040. }
  1041. ctx, cancel := c.getRequestContext()
  1042. defer cancel()
  1043. network, err := getNetwork(ctx, c.client, input)
  1044. if err != nil {
  1045. return apitypes.NetworkResource{}, err
  1046. }
  1047. return convert.BasicNetworkFromGRPC(*network), nil
  1048. }
  1049. // GetNetworks returns all current cluster managed networks.
  1050. func (c *Cluster) GetNetworks() ([]apitypes.NetworkResource, error) {
  1051. c.RLock()
  1052. defer c.RUnlock()
  1053. if !c.isActiveManager() {
  1054. return nil, c.errNoManager()
  1055. }
  1056. ctx, cancel := c.getRequestContext()
  1057. defer cancel()
  1058. r, err := c.client.ListNetworks(ctx, &swarmapi.ListNetworksRequest{})
  1059. if err != nil {
  1060. return nil, err
  1061. }
  1062. var networks []apitypes.NetworkResource
  1063. for _, network := range r.Networks {
  1064. networks = append(networks, convert.BasicNetworkFromGRPC(*network))
  1065. }
  1066. return networks, nil
  1067. }
  1068. func attacherKey(target, containerID string) string {
  1069. return containerID + ":" + target
  1070. }
  1071. // UpdateAttachment signals the attachment config to the attachment
  1072. // waiter who is trying to start or attach the container to the
  1073. // network.
  1074. func (c *Cluster) UpdateAttachment(target, containerID string, config *network.NetworkingConfig) error {
  1075. c.RLock()
  1076. attacher, ok := c.attachers[attacherKey(target, containerID)]
  1077. c.RUnlock()
  1078. if !ok || attacher == nil {
  1079. return fmt.Errorf("could not find attacher for container %s to network %s", containerID, target)
  1080. }
  1081. attacher.attachWaitCh <- config
  1082. close(attacher.attachWaitCh)
  1083. return nil
  1084. }
  1085. // WaitForDetachment waits for the container to stop or detach from
  1086. // the network.
  1087. func (c *Cluster) WaitForDetachment(ctx context.Context, networkName, networkID, taskID, containerID string) error {
  1088. c.RLock()
  1089. attacher, ok := c.attachers[attacherKey(networkName, containerID)]
  1090. if !ok {
  1091. attacher, ok = c.attachers[attacherKey(networkID, containerID)]
  1092. }
  1093. if c.node == nil || c.node.Agent() == nil {
  1094. c.RUnlock()
  1095. return fmt.Errorf("invalid cluster node while waiting for detachment")
  1096. }
  1097. agent := c.node.Agent()
  1098. c.RUnlock()
  1099. if ok && attacher != nil &&
  1100. attacher.detachWaitCh != nil &&
  1101. attacher.attachCompleteCh != nil {
  1102. // Attachment may be in progress still so wait for
  1103. // attachment to complete.
  1104. select {
  1105. case <-attacher.attachCompleteCh:
  1106. case <-ctx.Done():
  1107. return ctx.Err()
  1108. }
  1109. if attacher.taskID == taskID {
  1110. select {
  1111. case <-attacher.detachWaitCh:
  1112. case <-ctx.Done():
  1113. return ctx.Err()
  1114. }
  1115. }
  1116. }
  1117. return agent.ResourceAllocator().DetachNetwork(ctx, taskID)
  1118. }
  1119. // AttachNetwork generates an attachment request towards the manager.
  1120. func (c *Cluster) AttachNetwork(target string, containerID string, addresses []string) (*network.NetworkingConfig, error) {
  1121. aKey := attacherKey(target, containerID)
  1122. c.Lock()
  1123. if c.node == nil || c.node.Agent() == nil {
  1124. c.Unlock()
  1125. return nil, fmt.Errorf("invalid cluster node while attaching to network")
  1126. }
  1127. if attacher, ok := c.attachers[aKey]; ok {
  1128. c.Unlock()
  1129. return attacher.config, nil
  1130. }
  1131. agent := c.node.Agent()
  1132. attachWaitCh := make(chan *network.NetworkingConfig)
  1133. detachWaitCh := make(chan struct{})
  1134. attachCompleteCh := make(chan struct{})
  1135. c.attachers[aKey] = &attacher{
  1136. attachWaitCh: attachWaitCh,
  1137. attachCompleteCh: attachCompleteCh,
  1138. detachWaitCh: detachWaitCh,
  1139. }
  1140. c.Unlock()
  1141. ctx, cancel := c.getRequestContext()
  1142. defer cancel()
  1143. taskID, err := agent.ResourceAllocator().AttachNetwork(ctx, containerID, target, addresses)
  1144. if err != nil {
  1145. c.Lock()
  1146. delete(c.attachers, aKey)
  1147. c.Unlock()
  1148. return nil, fmt.Errorf("Could not attach to network %s: %v", target, err)
  1149. }
  1150. c.Lock()
  1151. c.attachers[aKey].taskID = taskID
  1152. close(attachCompleteCh)
  1153. c.Unlock()
  1154. logrus.Debugf("Successfully attached to network %s with tid %s", target, taskID)
  1155. var config *network.NetworkingConfig
  1156. select {
  1157. case config = <-attachWaitCh:
  1158. case <-ctx.Done():
  1159. return nil, fmt.Errorf("attaching to network failed, make sure your network options are correct and check manager logs: %v", ctx.Err())
  1160. }
  1161. c.Lock()
  1162. c.attachers[aKey].config = config
  1163. c.Unlock()
  1164. return config, nil
  1165. }
  1166. // DetachNetwork unblocks the waiters waiting on WaitForDetachment so
  1167. // that a request to detach can be generated towards the manager.
  1168. func (c *Cluster) DetachNetwork(target string, containerID string) error {
  1169. aKey := attacherKey(target, containerID)
  1170. c.Lock()
  1171. attacher, ok := c.attachers[aKey]
  1172. delete(c.attachers, aKey)
  1173. c.Unlock()
  1174. if !ok {
  1175. return fmt.Errorf("could not find network attachment for container %s to network %s", containerID, target)
  1176. }
  1177. close(attacher.detachWaitCh)
  1178. return nil
  1179. }
  1180. // CreateNetwork creates a new cluster managed network.
  1181. func (c *Cluster) CreateNetwork(s apitypes.NetworkCreateRequest) (string, error) {
  1182. c.RLock()
  1183. defer c.RUnlock()
  1184. if !c.isActiveManager() {
  1185. return "", c.errNoManager()
  1186. }
  1187. if runconfig.IsPreDefinedNetwork(s.Name) {
  1188. err := fmt.Errorf("%s is a pre-defined network and cannot be created", s.Name)
  1189. return "", errors.NewRequestForbiddenError(err)
  1190. }
  1191. ctx, cancel := c.getRequestContext()
  1192. defer cancel()
  1193. networkSpec := convert.BasicNetworkCreateToGRPC(s)
  1194. r, err := c.client.CreateNetwork(ctx, &swarmapi.CreateNetworkRequest{Spec: &networkSpec})
  1195. if err != nil {
  1196. return "", err
  1197. }
  1198. return r.Network.ID, nil
  1199. }
  1200. // RemoveNetwork removes a cluster network.
  1201. func (c *Cluster) RemoveNetwork(input string) error {
  1202. c.RLock()
  1203. defer c.RUnlock()
  1204. if !c.isActiveManager() {
  1205. return c.errNoManager()
  1206. }
  1207. ctx, cancel := c.getRequestContext()
  1208. defer cancel()
  1209. network, err := getNetwork(ctx, c.client, input)
  1210. if err != nil {
  1211. return err
  1212. }
  1213. if _, err := c.client.RemoveNetwork(ctx, &swarmapi.RemoveNetworkRequest{NetworkID: network.ID}); err != nil {
  1214. return err
  1215. }
  1216. return nil
  1217. }
  1218. func (c *Cluster) populateNetworkID(ctx context.Context, client swarmapi.ControlClient, s *types.ServiceSpec) error {
  1219. // Always prefer NetworkAttachmentConfigs from TaskTemplate
  1220. // but fallback to service spec for backward compatibility
  1221. networks := s.TaskTemplate.Networks
  1222. if len(networks) == 0 {
  1223. networks = s.Networks
  1224. }
  1225. for i, n := range networks {
  1226. apiNetwork, err := getNetwork(ctx, client, n.Target)
  1227. if err != nil {
  1228. if ln, _ := c.config.Backend.FindNetwork(n.Target); ln != nil && !ln.Info().Dynamic() {
  1229. err = fmt.Errorf("network %s is not eligible for docker services", ln.Name())
  1230. return errors.NewRequestForbiddenError(err)
  1231. }
  1232. return err
  1233. }
  1234. networks[i].Target = apiNetwork.ID
  1235. }
  1236. return nil
  1237. }
  1238. func getNetwork(ctx context.Context, c swarmapi.ControlClient, input string) (*swarmapi.Network, error) {
  1239. // GetNetwork to match via full ID.
  1240. rg, err := c.GetNetwork(ctx, &swarmapi.GetNetworkRequest{NetworkID: input})
  1241. if err != nil {
  1242. // If any error (including NotFound), ListNetworks to match via ID prefix and full name.
  1243. rl, err := c.ListNetworks(ctx, &swarmapi.ListNetworksRequest{Filters: &swarmapi.ListNetworksRequest_Filters{Names: []string{input}}})
  1244. if err != nil || len(rl.Networks) == 0 {
  1245. rl, err = c.ListNetworks(ctx, &swarmapi.ListNetworksRequest{Filters: &swarmapi.ListNetworksRequest_Filters{IDPrefixes: []string{input}}})
  1246. }
  1247. if err != nil {
  1248. return nil, err
  1249. }
  1250. if len(rl.Networks) == 0 {
  1251. return nil, fmt.Errorf("network %s not found", input)
  1252. }
  1253. if l := len(rl.Networks); l > 1 {
  1254. return nil, fmt.Errorf("network %s is ambiguous (%d matches found)", input, l)
  1255. }
  1256. return rl.Networks[0], nil
  1257. }
  1258. return rg.Network, nil
  1259. }
  1260. // Cleanup stops active swarm node. This is run before daemon shutdown.
  1261. func (c *Cluster) Cleanup() {
  1262. c.Lock()
  1263. node := c.node
  1264. if node == nil {
  1265. c.Unlock()
  1266. return
  1267. }
  1268. defer c.Unlock()
  1269. if c.isActiveManager() {
  1270. active, reachable, unreachable, err := c.managerStats()
  1271. if err == nil {
  1272. singlenode := active && isLastManager(reachable, unreachable)
  1273. if active && !singlenode && removingManagerCausesLossOfQuorum(reachable, unreachable) {
  1274. logrus.Errorf("Leaving cluster with %v managers left out of %v. Raft quorum will be lost.", reachable-1, reachable+unreachable)
  1275. }
  1276. }
  1277. }
  1278. c.stopNode()
  1279. }
  1280. func (c *Cluster) managerStats() (current bool, reachable int, unreachable int, err error) {
  1281. ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
  1282. defer cancel()
  1283. nodes, err := c.client.ListNodes(ctx, &swarmapi.ListNodesRequest{})
  1284. if err != nil {
  1285. return false, 0, 0, err
  1286. }
  1287. for _, n := range nodes.Nodes {
  1288. if n.ManagerStatus != nil {
  1289. if n.ManagerStatus.Reachability == swarmapi.RaftMemberStatus_REACHABLE {
  1290. reachable++
  1291. if n.ID == c.node.NodeID() {
  1292. current = true
  1293. }
  1294. }
  1295. if n.ManagerStatus.Reachability == swarmapi.RaftMemberStatus_UNREACHABLE {
  1296. unreachable++
  1297. }
  1298. }
  1299. }
  1300. return
  1301. }
  1302. func validateAndSanitizeInitRequest(req *types.InitRequest) error {
  1303. var err error
  1304. req.ListenAddr, err = validateAddr(req.ListenAddr)
  1305. if err != nil {
  1306. return fmt.Errorf("invalid ListenAddr %q: %v", req.ListenAddr, err)
  1307. }
  1308. spec := &req.Spec
  1309. // provide sane defaults instead of erroring
  1310. if spec.Name == "" {
  1311. spec.Name = "default"
  1312. }
  1313. if spec.Raft.SnapshotInterval == 0 {
  1314. spec.Raft.SnapshotInterval = defaultSpec.Raft.SnapshotInterval
  1315. }
  1316. if spec.Raft.LogEntriesForSlowFollowers == 0 {
  1317. spec.Raft.LogEntriesForSlowFollowers = defaultSpec.Raft.LogEntriesForSlowFollowers
  1318. }
  1319. if spec.Raft.ElectionTick == 0 {
  1320. spec.Raft.ElectionTick = defaultSpec.Raft.ElectionTick
  1321. }
  1322. if spec.Raft.HeartbeatTick == 0 {
  1323. spec.Raft.HeartbeatTick = defaultSpec.Raft.HeartbeatTick
  1324. }
  1325. if spec.Dispatcher.HeartbeatPeriod == 0 {
  1326. spec.Dispatcher.HeartbeatPeriod = defaultSpec.Dispatcher.HeartbeatPeriod
  1327. }
  1328. if spec.CAConfig.NodeCertExpiry == 0 {
  1329. spec.CAConfig.NodeCertExpiry = defaultSpec.CAConfig.NodeCertExpiry
  1330. }
  1331. if spec.Orchestration.TaskHistoryRetentionLimit == 0 {
  1332. spec.Orchestration.TaskHistoryRetentionLimit = defaultSpec.Orchestration.TaskHistoryRetentionLimit
  1333. }
  1334. return nil
  1335. }
  1336. func validateAndSanitizeJoinRequest(req *types.JoinRequest) error {
  1337. var err error
  1338. req.ListenAddr, err = validateAddr(req.ListenAddr)
  1339. if err != nil {
  1340. return fmt.Errorf("invalid ListenAddr %q: %v", req.ListenAddr, err)
  1341. }
  1342. if len(req.RemoteAddrs) == 0 {
  1343. return fmt.Errorf("at least 1 RemoteAddr is required to join")
  1344. }
  1345. for i := range req.RemoteAddrs {
  1346. req.RemoteAddrs[i], err = validateAddr(req.RemoteAddrs[i])
  1347. if err != nil {
  1348. return fmt.Errorf("invalid remoteAddr %q: %v", req.RemoteAddrs[i], err)
  1349. }
  1350. }
  1351. return nil
  1352. }
  1353. func validateAddr(addr string) (string, error) {
  1354. if addr == "" {
  1355. return addr, fmt.Errorf("invalid empty address")
  1356. }
  1357. newaddr, err := opts.ParseTCPAddr(addr, defaultAddr)
  1358. if err != nil {
  1359. return addr, nil
  1360. }
  1361. return strings.TrimPrefix(newaddr, "tcp://"), nil
  1362. }
  1363. func initClusterSpec(node *node, spec types.Spec) error {
  1364. ctx, _ := context.WithTimeout(context.Background(), 5*time.Second)
  1365. for conn := range node.ListenControlSocket(ctx) {
  1366. if ctx.Err() != nil {
  1367. return ctx.Err()
  1368. }
  1369. if conn != nil {
  1370. client := swarmapi.NewControlClient(conn)
  1371. var cluster *swarmapi.Cluster
  1372. for i := 0; ; i++ {
  1373. lcr, err := client.ListClusters(ctx, &swarmapi.ListClustersRequest{})
  1374. if err != nil {
  1375. return fmt.Errorf("error on listing clusters: %v", err)
  1376. }
  1377. if len(lcr.Clusters) == 0 {
  1378. if i < 10 {
  1379. time.Sleep(200 * time.Millisecond)
  1380. continue
  1381. }
  1382. return fmt.Errorf("empty list of clusters was returned")
  1383. }
  1384. cluster = lcr.Clusters[0]
  1385. break
  1386. }
  1387. newspec, err := convert.SwarmSpecToGRPC(spec)
  1388. if err != nil {
  1389. return fmt.Errorf("error updating cluster settings: %v", err)
  1390. }
  1391. _, err = client.UpdateCluster(ctx, &swarmapi.UpdateClusterRequest{
  1392. ClusterID: cluster.ID,
  1393. ClusterVersion: &cluster.Meta.Version,
  1394. Spec: &newspec,
  1395. })
  1396. if err != nil {
  1397. return fmt.Errorf("error updating cluster settings: %v", err)
  1398. }
  1399. return nil
  1400. }
  1401. }
  1402. return ctx.Err()
  1403. }