2021-06-08 23:11:18 +03:00
|
|
|
package config
|
2019-06-20 16:36:40 -07:00
|
|
|
|
|
|
|
import (
|
2021-05-13 21:59:12 +03:00
|
|
|
"fmt"
|
2022-08-10 22:28:52 +00:00
|
|
|
"os"
|
2022-02-10 00:51:35 +00:00
|
|
|
"time"
|
2021-05-13 21:59:12 +03:00
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
"github.com/getlantern/deepcopy"
|
2021-05-21 20:47:28 +00:00
|
|
|
distspec "github.com/opencontainers/distribution-spec/specs-go"
|
2021-05-13 21:59:12 +03:00
|
|
|
"github.com/spf13/viper"
|
2022-10-20 19:39:20 +03:00
|
|
|
|
2021-12-04 03:50:58 +00:00
|
|
|
extconf "zotregistry.io/zot/pkg/extensions/config"
|
2022-02-10 00:51:35 +00:00
|
|
|
"zotregistry.io/zot/pkg/storage"
|
2019-06-20 16:36:40 -07:00
|
|
|
)
|
|
|
|
|
2021-02-12 16:52:02 -08:00
|
|
|
var (
|
2022-10-05 13:21:14 +03:00
|
|
|
Commit string //nolint: gochecknoglobals
|
2022-10-11 19:01:59 +03:00
|
|
|
ReleaseTag string //nolint: gochecknoglobals
|
2022-10-05 13:21:14 +03:00
|
|
|
BinaryType string //nolint: gochecknoglobals
|
|
|
|
GoVersion string //nolint: gochecknoglobals
|
2021-02-12 16:52:02 -08:00
|
|
|
)
|
2019-09-16 11:01:59 -07:00
|
|
|
|
2019-06-20 16:36:40 -07:00
|
|
|
type StorageConfig struct {
|
|
|
|
RootDirectory string
|
2020-04-15 16:24:05 -07:00
|
|
|
Dedupe bool
|
2022-11-03 00:53:08 +02:00
|
|
|
RemoteCache bool
|
|
|
|
GC bool
|
2022-01-21 04:11:44 +00:00
|
|
|
Commit bool
|
2022-02-10 00:51:35 +00:00
|
|
|
GCDelay time.Duration
|
2022-03-21 20:40:37 +02:00
|
|
|
GCInterval time.Duration
|
2021-07-17 06:53:05 +03:00
|
|
|
StorageDriver map[string]interface{} `mapstructure:",omitempty"`
|
2019-06-20 16:36:40 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
type TLSConfig struct {
|
|
|
|
Cert string
|
|
|
|
Key string
|
|
|
|
CACert string
|
|
|
|
}
|
|
|
|
|
|
|
|
type AuthHTPasswd struct {
|
|
|
|
Path string
|
|
|
|
}
|
|
|
|
|
|
|
|
type AuthConfig struct {
|
|
|
|
FailDelay int
|
|
|
|
HTPasswd AuthHTPasswd
|
2019-08-15 09:34:54 -07:00
|
|
|
LDAP *LDAPConfig
|
2020-01-24 15:32:38 -06:00
|
|
|
Bearer *BearerConfig
|
|
|
|
}
|
|
|
|
|
|
|
|
type BearerConfig struct {
|
|
|
|
Realm string
|
|
|
|
Service string
|
|
|
|
Cert string
|
2019-06-20 16:36:40 -07:00
|
|
|
}
|
|
|
|
|
2022-01-21 20:30:09 +00:00
|
|
|
type MethodRatelimitConfig struct {
|
|
|
|
Method string
|
|
|
|
Rate int
|
|
|
|
}
|
|
|
|
|
|
|
|
type RatelimitConfig struct {
|
|
|
|
Rate *int // requests per second
|
|
|
|
Methods []MethodRatelimitConfig `mapstructure:",omitempty"`
|
|
|
|
}
|
|
|
|
|
2019-06-20 16:36:40 -07:00
|
|
|
type HTTPConfig struct {
|
2021-05-13 21:59:12 +03:00
|
|
|
Address string
|
|
|
|
Port string
|
2022-02-16 01:15:13 +00:00
|
|
|
AllowOrigin string // comma separated
|
2021-05-13 21:59:12 +03:00
|
|
|
TLS *TLSConfig
|
|
|
|
Auth *AuthConfig
|
|
|
|
RawAccessControl map[string]interface{} `mapstructure:"accessControl,omitempty"`
|
|
|
|
Realm string
|
2022-01-21 20:30:09 +00:00
|
|
|
Ratelimit *RatelimitConfig `mapstructure:",omitempty"`
|
2019-06-20 16:36:40 -07:00
|
|
|
}
|
|
|
|
|
2019-08-15 09:34:54 -07:00
|
|
|
type LDAPConfig struct {
|
|
|
|
Port int
|
|
|
|
Insecure bool
|
|
|
|
StartTLS bool // if !Insecure, then StartTLS or LDAPs
|
|
|
|
SkipVerify bool
|
|
|
|
SubtreeSearch bool
|
|
|
|
Address string
|
|
|
|
BindDN string
|
|
|
|
BindPassword string
|
|
|
|
BaseDN string
|
|
|
|
UserAttribute string
|
|
|
|
CACert string
|
|
|
|
}
|
|
|
|
|
2019-06-20 16:36:40 -07:00
|
|
|
type LogConfig struct {
|
|
|
|
Level string
|
|
|
|
Output string
|
2021-05-25 11:38:21 +03:00
|
|
|
Audit string
|
2019-06-20 16:36:40 -07:00
|
|
|
}
|
|
|
|
|
2021-04-05 17:40:33 -07:00
|
|
|
type GlobalStorageConfig struct {
|
2022-11-03 00:53:08 +02:00
|
|
|
StorageConfig `mapstructure:",squash"`
|
2021-04-05 17:40:33 -07:00
|
|
|
SubPaths map[string]StorageConfig
|
|
|
|
}
|
|
|
|
|
2021-06-08 23:11:18 +03:00
|
|
|
type AccessControlConfig struct {
|
|
|
|
Repositories Repositories
|
|
|
|
AdminPolicy Policy
|
|
|
|
}
|
|
|
|
|
|
|
|
type Repositories map[string]PolicyGroup
|
|
|
|
|
|
|
|
type PolicyGroup struct {
|
2022-07-14 18:13:46 +03:00
|
|
|
Policies []Policy
|
|
|
|
DefaultPolicy []string
|
|
|
|
AnonymousPolicy []string
|
2021-06-08 23:11:18 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
type Policy struct {
|
|
|
|
Users []string
|
|
|
|
Actions []string
|
|
|
|
}
|
|
|
|
|
2019-06-20 16:36:40 -07:00
|
|
|
type Config struct {
|
2022-03-07 14:50:15 +02:00
|
|
|
DistSpecVersion string `json:"distSpecVersion" mapstructure:"distSpecVersion"`
|
|
|
|
GoVersion string
|
|
|
|
Commit string
|
2022-10-11 19:01:59 +03:00
|
|
|
ReleaseTag string
|
2022-03-07 14:50:15 +02:00
|
|
|
BinaryType string
|
|
|
|
AccessControl *AccessControlConfig
|
|
|
|
Storage GlobalStorageConfig
|
|
|
|
HTTP HTTPConfig
|
|
|
|
Log *LogConfig
|
|
|
|
Extensions *extconf.ExtensionConfig
|
2019-06-20 16:36:40 -07:00
|
|
|
}
|
|
|
|
|
2021-06-08 23:11:18 +03:00
|
|
|
func New() *Config {
|
2019-06-20 16:36:40 -07:00
|
|
|
return &Config{
|
2022-03-07 14:50:15 +02:00
|
|
|
DistSpecVersion: distspec.Version,
|
|
|
|
GoVersion: GoVersion,
|
|
|
|
Commit: Commit,
|
2022-10-11 19:01:59 +03:00
|
|
|
ReleaseTag: ReleaseTag,
|
2022-03-07 14:50:15 +02:00
|
|
|
BinaryType: BinaryType,
|
2022-11-03 00:53:08 +02:00
|
|
|
Storage: GlobalStorageConfig{
|
|
|
|
StorageConfig: StorageConfig{GC: true, GCDelay: storage.DefaultGCDelay, Dedupe: true},
|
|
|
|
},
|
|
|
|
HTTP: HTTPConfig{Address: "127.0.0.1", Port: "8080", Auth: &AuthConfig{FailDelay: 0}},
|
|
|
|
Log: &LogConfig{Level: "debug"},
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2022-08-10 22:28:52 +00:00
|
|
|
func (expConfig StorageConfig) ParamsEqual(actConfig StorageConfig) bool {
|
|
|
|
return expConfig.GC == actConfig.GC && expConfig.Dedupe == actConfig.Dedupe &&
|
|
|
|
expConfig.GCDelay == actConfig.GCDelay && expConfig.GCInterval == actConfig.GCInterval
|
|
|
|
}
|
|
|
|
|
|
|
|
// SameFile compare two files.
|
|
|
|
// This method will first do the stat of two file and compare using os.SameFile method.
|
|
|
|
func SameFile(str1, str2 string) (bool, error) {
|
|
|
|
sFile, err := os.Stat(str1)
|
|
|
|
if err != nil {
|
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
|
|
|
|
tFile, err := os.Stat(str2)
|
|
|
|
if err != nil {
|
|
|
|
return false, err
|
|
|
|
}
|
|
|
|
|
|
|
|
return os.SameFile(sFile, tFile), nil
|
|
|
|
}
|
|
|
|
|
2020-05-11 15:13:24 -07:00
|
|
|
// Sanitize makes a sanitized copy of the config removing any secrets.
|
2019-08-15 09:34:54 -07:00
|
|
|
func (c *Config) Sanitize() *Config {
|
2021-12-13 19:23:31 +00:00
|
|
|
sanitizedConfig := &Config{}
|
|
|
|
if err := deepcopy.Copy(sanitizedConfig, c); err != nil {
|
2021-06-08 23:11:18 +03:00
|
|
|
panic(err)
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2021-06-08 23:11:18 +03:00
|
|
|
if c.HTTP.Auth != nil && c.HTTP.Auth.LDAP != nil && c.HTTP.Auth.LDAP.BindPassword != "" {
|
2021-12-13 19:23:31 +00:00
|
|
|
sanitizedConfig.HTTP.Auth.LDAP = &LDAPConfig{}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
if err := deepcopy.Copy(sanitizedConfig.HTTP.Auth.LDAP, c.HTTP.Auth.LDAP); err != nil {
|
2019-08-15 09:34:54 -07:00
|
|
|
panic(err)
|
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
sanitizedConfig.HTTP.Auth.LDAP.BindPassword = "******"
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
2019-12-13 00:53:18 -05:00
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
return sanitizedConfig
|
2019-08-15 09:34:54 -07:00
|
|
|
}
|
|
|
|
|
2021-05-13 21:59:12 +03:00
|
|
|
// LoadAccessControlConfig populates config.AccessControl struct with values from config.
|
2021-09-10 18:23:26 +03:00
|
|
|
func (c *Config) LoadAccessControlConfig(viperInstance *viper.Viper) error {
|
2021-05-13 21:59:12 +03:00
|
|
|
if c.HTTP.RawAccessControl == nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
c.AccessControl = &AccessControlConfig{}
|
|
|
|
c.AccessControl.Repositories = make(map[string]PolicyGroup)
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
for policy := range c.HTTP.RawAccessControl {
|
2021-05-13 21:59:12 +03:00
|
|
|
var policies []Policy
|
|
|
|
|
|
|
|
var policyGroup PolicyGroup
|
|
|
|
|
2021-12-13 19:23:31 +00:00
|
|
|
if policy == "adminpolicy" {
|
2021-09-10 18:23:26 +03:00
|
|
|
adminPolicy := viperInstance.GetStringMapStringSlice("http::accessControl::adminPolicy")
|
2021-05-13 21:59:12 +03:00
|
|
|
c.AccessControl.AdminPolicy.Actions = adminPolicy["actions"]
|
|
|
|
c.AccessControl.AdminPolicy.Users = adminPolicy["users"]
|
|
|
|
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
|
2021-09-10 18:23:26 +03:00
|
|
|
err := viperInstance.UnmarshalKey(fmt.Sprintf("http::accessControl::%s::policies", policy), &policies)
|
2021-05-13 21:59:12 +03:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2021-09-10 18:23:26 +03:00
|
|
|
defaultPolicy := viperInstance.GetStringSlice(fmt.Sprintf("http::accessControl::%s::defaultPolicy", policy))
|
2021-05-13 21:59:12 +03:00
|
|
|
policyGroup.DefaultPolicy = defaultPolicy
|
2022-07-14 18:13:46 +03:00
|
|
|
|
|
|
|
anonymousPolicy := viperInstance.GetStringSlice(fmt.Sprintf("http::accessControl::%s::anonymousPolicy", policy))
|
|
|
|
policyGroup.Policies = policies
|
|
|
|
policyGroup.AnonymousPolicy = anonymousPolicy
|
2021-12-13 19:23:31 +00:00
|
|
|
c.AccessControl.Repositories[policy] = policyGroup
|
2021-05-13 21:59:12 +03:00
|
|
|
}
|
|
|
|
|
|
|
|
return nil
|
|
|
|
}
|