1
0
mirror of https://github.com/juanfont/headscale.git synced 2025-01-08 00:11:42 +01:00
juanfont.headscale/namespaces.go

293 lines
7.0 KiB
Go
Raw Normal View History

package headscale
import (
2021-06-24 15:44:19 +02:00
"errors"
"fmt"
"regexp"
"strconv"
"strings"
"time"
v1 "github.com/juanfont/headscale/gen/go/headscale/v1"
2021-08-05 19:23:02 +02:00
"github.com/rs/zerolog/log"
"google.golang.org/protobuf/types/known/timestamppb"
2021-06-24 15:44:19 +02:00
"gorm.io/gorm"
"tailscale.com/tailcfg"
)
const (
2022-07-29 17:35:21 +02:00
ErrNamespaceExists = Error("Namespace already exists")
ErrNamespaceNotFound = Error("Namespace not found")
ErrNamespaceNotEmptyOfNodes = Error("Namespace not empty: node(s) found")
ErrInvalidNamespaceName = Error("Invalid namespace name")
)
2022-02-22 21:05:39 +01:00
const (
// value related to RFC 1123 and 952.
labelHostnameLength = 63
)
var invalidCharsInNamespaceRegex = regexp.MustCompile("[^a-z0-9-.]+")
// Namespace is the way Headscale implements the concept of users in Tailscale
//
// At the end of the day, users in Tailscale are some kind of 'bubbles' or namespaces
// that contain our machines.
type Namespace struct {
gorm.Model
Name string `gorm:"unique"`
}
// CreateNamespace creates a new Namespace. Returns error if could not be created
2021-11-13 09:39:04 +01:00
// or another namespace already exists.
func (h *Headscale) CreateNamespace(name string) (*Namespace, error) {
err := CheckForFQDNRules(name)
if err != nil {
return nil, err
}
namespace := Namespace{}
if err := h.db.Where("name = ?", name).First(&namespace).Error; err == nil {
2022-07-29 17:35:21 +02:00
return nil, ErrNamespaceExists
}
namespace.Name = name
if err := h.db.Create(&namespace).Error; err != nil {
2021-08-05 19:23:02 +02:00
log.Error().
2021-08-05 21:57:47 +02:00
Str("func", "CreateNamespace").
2021-08-05 19:23:02 +02:00
Err(err).
Msg("Could not create row")
2021-11-14 16:46:09 +01:00
return nil, err
}
2021-11-14 16:46:09 +01:00
return &namespace, nil
}
// DestroyNamespace destroys a Namespace. Returns error if the Namespace does
// not exist or if there are machines associated with it.
func (h *Headscale) DestroyNamespace(name string) error {
namespace, err := h.GetNamespace(name)
if err != nil {
2022-07-29 17:35:21 +02:00
return ErrNamespaceNotFound
}
machines, err := h.ListMachinesInNamespace(name)
if err != nil {
return err
}
if len(machines) > 0 {
2022-07-29 17:35:21 +02:00
return ErrNamespaceNotEmptyOfNodes
}
keys, err := h.ListPreAuthKeys(name)
if err != nil {
return err
}
for _, key := range keys {
2021-11-15 19:31:52 +01:00
err = h.DestroyPreAuthKey(key)
2021-11-13 21:24:32 +01:00
if err != nil {
return err
}
}
if result := h.db.Unscoped().Delete(&namespace); result.Error != nil {
return result.Error
}
return nil
}
2021-10-16 17:20:06 +02:00
// RenameNamespace renames a Namespace. Returns error if the Namespace does
// not exist or if another Namespace exists with the new name.
func (h *Headscale) RenameNamespace(oldName, newName string) error {
var err error
oldNamespace, err := h.GetNamespace(oldName)
2021-10-16 17:20:06 +02:00
if err != nil {
return err
}
err = CheckForFQDNRules(newName)
if err != nil {
return err
}
2021-10-16 17:20:06 +02:00
_, err = h.GetNamespace(newName)
if err == nil {
2022-07-29 17:35:21 +02:00
return ErrNamespaceExists
2021-10-16 17:20:06 +02:00
}
2022-07-29 17:35:21 +02:00
if !errors.Is(err, ErrNamespaceNotFound) {
2021-10-16 17:20:06 +02:00
return err
}
oldNamespace.Name = newName
2021-10-16 17:20:06 +02:00
if result := h.db.Save(&oldNamespace); result.Error != nil {
2021-10-16 17:20:06 +02:00
return result.Error
}
return nil
}
2021-11-13 09:39:04 +01:00
// GetNamespace fetches a namespace by name.
func (h *Headscale) GetNamespace(name string) (*Namespace, error) {
namespace := Namespace{}
if result := h.db.First(&namespace, "name = ?", name); errors.Is(
2021-11-13 09:36:45 +01:00
result.Error,
gorm.ErrRecordNotFound,
) {
2022-07-29 17:35:21 +02:00
return nil, ErrNamespaceNotFound
}
2021-11-14 16:46:09 +01:00
return &namespace, nil
}
2021-11-13 09:39:04 +01:00
// ListNamespaces gets all the existing namespaces.
func (h *Headscale) ListNamespaces() ([]Namespace, error) {
namespaces := []Namespace{}
2021-07-04 21:40:46 +02:00
if err := h.db.Find(&namespaces).Error; err != nil {
return nil, err
}
2021-11-14 16:46:09 +01:00
return namespaces, nil
}
2021-11-13 09:39:04 +01:00
// ListMachinesInNamespace gets all the nodes in a given namespace.
func (h *Headscale) ListMachinesInNamespace(name string) ([]Machine, error) {
err := CheckForFQDNRules(name)
if err != nil {
return nil, err
}
namespace, err := h.GetNamespace(name)
if err != nil {
return nil, err
}
machines := []Machine{}
if err := h.db.Preload("AuthKey").Preload("AuthKey.Namespace").Preload("Namespace").Where(&Machine{NamespaceID: namespace.ID}).Find(&machines).Error; err != nil {
return nil, err
}
2021-11-14 16:46:09 +01:00
return machines, nil
}
2021-11-13 09:39:04 +01:00
// SetMachineNamespace assigns a Machine to a namespace.
func (h *Headscale) SetMachineNamespace(machine *Machine, namespaceName string) error {
err := CheckForFQDNRules(namespaceName)
if err != nil {
return err
}
namespace, err := h.GetNamespace(namespaceName)
if err != nil {
return err
}
2022-05-02 11:47:21 +02:00
machine.Namespace = *namespace
if result := h.db.Save(&machine); result.Error != nil {
return result.Error
}
2021-11-14 16:46:09 +01:00
return nil
}
func (n *Namespace) toUser() *tailcfg.User {
user := tailcfg.User{
ID: tailcfg.UserID(n.ID),
LoginName: n.Name,
DisplayName: n.Name,
ProfilePicURL: "",
Domain: "headscale.net",
Logins: []tailcfg.LoginID{},
Created: time.Time{},
}
2021-11-14 16:46:09 +01:00
return &user
}
func (n *Namespace) toLogin() *tailcfg.Login {
login := tailcfg.Login{
ID: tailcfg.LoginID(n.ID),
LoginName: n.Name,
DisplayName: n.Name,
ProfilePicURL: "",
Domain: "headscale.net",
}
2021-11-14 16:46:09 +01:00
return &login
}
2021-10-19 16:26:18 +02:00
func getMapResponseUserProfiles(machine Machine, peers Machines) []tailcfg.UserProfile {
namespaceMap := make(map[string]Namespace)
namespaceMap[machine.Namespace.Name] = machine.Namespace
for _, peer := range peers {
namespaceMap[peer.Namespace.Name] = peer.Namespace // not worth checking if already is there
}
profiles := []tailcfg.UserProfile{}
for _, namespace := range namespaceMap {
profiles = append(profiles,
tailcfg.UserProfile{
ID: tailcfg.UserID(namespace.ID),
LoginName: namespace.Name,
DisplayName: namespace.Name,
})
}
2021-11-14 16:46:09 +01:00
return profiles
}
func (n *Namespace) toProto() *v1.Namespace {
return &v1.Namespace{
Id: strconv.FormatUint(uint64(n.ID), Base10),
Name: n.Name,
CreatedAt: timestamppb.New(n.CreatedAt),
}
}
// NormalizeToFQDNRules will replace forbidden chars in namespace
2022-02-22 21:05:39 +01:00
// it can also return an error if the namespace doesn't respect RFC 952 and 1123.
func NormalizeToFQDNRules(name string, stripEmailDomain bool) (string, error) {
name = strings.ToLower(name)
name = strings.ReplaceAll(name, "'", "")
atIdx := strings.Index(name, "@")
if stripEmailDomain && atIdx > 0 {
name = name[:atIdx]
} else {
name = strings.ReplaceAll(name, "@", ".")
}
name = invalidCharsInNamespaceRegex.ReplaceAllString(name, "-")
for _, elt := range strings.Split(name, ".") {
2022-02-22 21:05:39 +01:00
if len(elt) > labelHostnameLength {
return "", fmt.Errorf(
"label %v is more than 63 chars: %w",
elt,
2022-07-29 17:35:21 +02:00
ErrInvalidNamespaceName,
)
}
}
return name, nil
}
func CheckForFQDNRules(name string) error {
if len(name) > labelHostnameLength {
return fmt.Errorf(
"DNS segment must not be over 63 chars. %v doesn't comply with this rule: %w",
name,
2022-07-29 17:35:21 +02:00
ErrInvalidNamespaceName,
)
}
if strings.ToLower(name) != name {
return fmt.Errorf(
"DNS segment should be lowercase. %v doesn't comply with this rule: %w",
name,
2022-07-29 17:35:21 +02:00
ErrInvalidNamespaceName,
)
}
if invalidCharsInNamespaceRegex.MatchString(name) {
return fmt.Errorf(
"DNS segment should only be composed of lowercase ASCII letters numbers, hyphen and dots. %v doesn't comply with theses rules: %w",
name,
2022-07-29 17:35:21 +02:00
ErrInvalidNamespaceName,
)
}
return nil
}