Migrate from OpenSSL to Rustls (#1865)

* Migrate from OpenSSL to Rustls

* Add TTL based certificate rotation for Rustls in actix

See: <https://github.com/qdrant/qdrant/pull/1865#issuecomment-1539752859>

* Update last update time when certificate is replaced

* Update error message

* Add option to disable certificate TTL, add TTL validation

* Cleanup

* Update comment for service.enable_tls, also enables TLS for gRPC

* Apply suggestions from code review

Co-authored-by: Roman Titov <ffuugoo@users.noreply.github.com>

* Move with_buf_read into certificate_helpers, it is used there

Co-authored-by: Roman Titov <ffuugoo@users.noreply.github.com>

* Remove level of scoping

* Add TLS enabled/disabled log messages

---------

Co-authored-by: timvisee <tim@visee.me>
Co-authored-by: Tim Visée <tim+github@visee.me>
Co-authored-by: Roman Titov <ffuugoo@users.noreply.github.com>
This commit is contained in:
llogiq
2023-06-19 14:45:30 +02:00
committed by Andrey Vasnetsov
co-authored by Roman Titov timvisee Tim Visée
parent 99c3592f9b
commit 403162125a
8 changed files with 191 additions and 332 deletions
Generated
+7 -218
View File
@@ -209,10 +209,10 @@ dependencies = [
"actix-utils",
"futures-core",
"log",
"openssl",
"pin-project-lite",
"tokio-openssl",
"tokio-rustls 0.23.4",
"tokio-util",
"webpki-roots",
]
[[package]]
@@ -1111,16 +1111,6 @@ dependencies = [
"version_check",
]
[[package]]
name = "core-foundation"
version = "0.9.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "194a7a9e6de53fa55116934067c844d9d749312f75c6f6d0980e8c252f8c2146"
dependencies = [
"core-foundation-sys",
"libc",
]
[[package]]
name = "core-foundation-sys"
version = "0.8.3"
@@ -1536,21 +1526,6 @@ version = "1.0.7"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3f9eec918d3f24069decb9af1554cad7c880e2da24a9afd88aca000531ab82c1"
[[package]]
name = "foreign-types"
version = "0.3.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f6f339eb8adc052cd2ca78910fda869aefa38d22d5cb648e6485e4d3fc06f3b1"
dependencies = [
"foreign-types-shared",
]
[[package]]
name = "foreign-types-shared"
version = "0.1.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "00b0228411908ca8685dba7fc2cdd70ec9990a6e753e89b6ac91a84c40fbaf4b"
[[package]]
name = "form_urlencoded"
version = "1.1.0"
@@ -2020,19 +1995,6 @@ dependencies = [
"tokio-io-timeout",
]
[[package]]
name = "hyper-tls"
version = "0.5.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "d6183ddfa99b85da61a140bea0efc93fdf56ceaa041b37d553518030827f9905"
dependencies = [
"bytes",
"hyper",
"native-tls",
"tokio",
"tokio-native-tls",
]
[[package]]
name = "iana-time-zone"
version = "0.1.53"
@@ -2490,24 +2452,6 @@ version = "0.8.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e5ce46fe64a9d73be07dcbe690a38ce1b293be448fd8ce1e6c1b8062c9f72c6a"
[[package]]
name = "native-tls"
version = "0.2.11"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "07226173c32f2926027b63cce4bcd8076c3552846cbe7925f3aaffeac0a3b92e"
dependencies = [
"lazy_static",
"libc",
"log",
"openssl",
"openssl-probe",
"openssl-sys",
"schannel",
"security-framework",
"security-framework-sys",
"tempfile",
]
[[package]]
name = "nias"
version = "0.5.0"
@@ -2641,60 +2585,6 @@ version = "11.1.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0ab1bc2a289d34bd04a330323ac98a1b4bc82c9d9fcb1e66b63caa84da26b575"
[[package]]
name = "openssl"
version = "0.10.52"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "01b8574602df80f7b85fdfc5392fa884a4e3b3f4f35402c070ab34c3d3f78d56"
dependencies = [
"bitflags",
"cfg-if",
"foreign-types",
"libc",
"once_cell",
"openssl-macros",
"openssl-sys",
]
[[package]]
name = "openssl-macros"
version = "0.1.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b501e44f11665960c7e7fcf062c7d96a14ade4aa98116c004b2e37b5be7d736c"
dependencies = [
"proc-macro2",
"quote",
"syn 1.0.107",
]
[[package]]
name = "openssl-probe"
version = "0.1.5"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ff011a302c396a5197692431fc1948019154afc178baf7d8e37367442a4601cf"
[[package]]
name = "openssl-src"
version = "111.25.0+1.1.1t"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "3173cd3626c43e3854b1b727422a276e568d9ec5fe8cec197822cf52cfb743d6"
dependencies = [
"cc",
]
[[package]]
name = "openssl-sys"
version = "0.9.87"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "8e17f59264b2809d77ae94f0e1ebabc434773f370d6ca667bd223ea10e06cc7e"
dependencies = [
"cc",
"libc",
"openssl-src",
"pkg-config",
"vcpkg",
]
[[package]]
name = "ordered-float"
version = "2.10.0"
@@ -3151,13 +3041,14 @@ dependencies = [
"log",
"num-traits",
"num_cpus",
"openssl",
"parking_lot",
"prometheus",
"prost",
"raft",
"raft-proto",
"reqwest",
"rustls 0.20.7",
"rustls-pemfile",
"rusty-hook",
"schemars",
"sealed_test",
@@ -3428,12 +3319,10 @@ dependencies = [
"http-body",
"hyper",
"hyper-rustls",
"hyper-tls",
"ipnet",
"js-sys",
"log",
"mime",
"native-tls",
"once_cell",
"percent-encoding",
"pin-project-lite",
@@ -3443,7 +3332,6 @@ dependencies = [
"serde_json",
"serde_urlencoded",
"tokio",
"tokio-native-tls",
"tokio-rustls 0.23.4",
"tokio-util",
"tower-service",
@@ -3639,11 +3527,11 @@ dependencies = [
[[package]]
name = "rustls-pemfile"
version = "1.0.1"
version = "1.0.2"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0864aeff53f8c05aa08d86e5ef839d3dfcf07aeba2db32f12db0ef716e87bd55"
checksum = "d194b56d58803a43635bdc398cd17e383d6f71f9182b9a192c127ca42494a59b"
dependencies = [
"base64 0.13.1",
"base64 0.21.0",
]
[[package]]
@@ -3713,16 +3601,6 @@ dependencies = [
"winapi-util",
]
[[package]]
name = "schannel"
version = "0.1.20"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "88d6731146462ea25d9244b2ed5fd1d716d25c52e4d54aa4fb0f3c4e9854dbe2"
dependencies = [
"lazy_static",
"windows-sys 0.36.1",
]
[[package]]
name = "schemars"
version = "0.8.12"
@@ -3807,29 +3685,6 @@ dependencies = [
"syn 1.0.107",
]
[[package]]
name = "security-framework"
version = "2.7.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "2bc1bb97804af6631813c55739f771071e0f2ed33ee20b68c86ec505d906356c"
dependencies = [
"bitflags",
"core-foundation",
"core-foundation-sys",
"libc",
"security-framework-sys",
]
[[package]]
name = "security-framework-sys"
version = "2.6.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "0160a13a177a45bfb43ce71c01580998474f556ad854dcbca936dd2841a5c556"
dependencies = [
"core-foundation-sys",
"libc",
]
[[package]]
name = "segment"
version = "0.6.0"
@@ -4127,7 +3982,6 @@ dependencies = [
"itertools",
"log",
"num_cpus",
"openssl",
"parking_lot",
"proptest",
"prost",
@@ -4453,28 +4307,6 @@ dependencies = [
"syn 2.0.11",
]
[[package]]
name = "tokio-native-tls"
version = "0.3.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "f7d995660bd2b7f8c1568414c1126076c13fbb725c40112dc0120b78eb9b717b"
dependencies = [
"native-tls",
"tokio",
]
[[package]]
name = "tokio-openssl"
version = "0.6.3"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c08f9ffb7809f1b20c1b398d92acf4cc719874b3b2b2d9ea2f09b4a80350878a"
dependencies = [
"futures-util",
"openssl",
"openssl-sys",
"tokio",
]
[[package]]
name = "tokio-rustls"
version = "0.23.4"
@@ -5081,19 +4913,6 @@ dependencies = [
"windows-targets 0.48.0",
]
[[package]]
name = "windows-sys"
version = "0.36.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "ea04155a16a59f9eab786fe12a4a450e75cdb175f9e0d80da1e17db09f55b8d2"
dependencies = [
"windows_aarch64_msvc 0.36.1",
"windows_i686_gnu 0.36.1",
"windows_i686_msvc 0.36.1",
"windows_x86_64_gnu 0.36.1",
"windows_x86_64_msvc 0.36.1",
]
[[package]]
name = "windows-sys"
version = "0.42.0"
@@ -5169,12 +4988,6 @@ version = "0.48.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "91ae572e1b79dba883e0d315474df7305d12f569b400fcf90581b06062f7e1bc"
[[package]]
name = "windows_aarch64_msvc"
version = "0.36.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "9bb8c3fd39ade2d67e9874ac4f3db21f0d710bee00fe7cab16949ec184eeaa47"
[[package]]
name = "windows_aarch64_msvc"
version = "0.42.2"
@@ -5187,12 +5000,6 @@ version = "0.48.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "b2ef27e0d7bdfcfc7b868b317c1d32c641a6fe4629c171b8928c7b08d98d7cf3"
[[package]]
name = "windows_i686_gnu"
version = "0.36.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "180e6ccf01daf4c426b846dfc66db1fc518f074baa793aa7d9b9aaeffad6a3b6"
[[package]]
name = "windows_i686_gnu"
version = "0.42.2"
@@ -5205,12 +5012,6 @@ version = "0.48.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "622a1962a7db830d6fd0a69683c80a18fda201879f0f447f065a3b7467daa241"
[[package]]
name = "windows_i686_msvc"
version = "0.36.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "e2e7917148b2812d1eeafaeb22a97e4813dfa60a3f8f78ebe204bcc88f12f024"
[[package]]
name = "windows_i686_msvc"
version = "0.42.2"
@@ -5223,12 +5024,6 @@ version = "0.48.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "4542c6e364ce21bf45d69fdd2a8e455fa38d316158cfd43b3ac1c5b1b19f8e00"
[[package]]
name = "windows_x86_64_gnu"
version = "0.36.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "4dcd171b8776c41b97521e5da127a2d86ad280114807d0b2ab1e462bc764d9e1"
[[package]]
name = "windows_x86_64_gnu"
version = "0.42.2"
@@ -5253,12 +5048,6 @@ version = "0.48.0"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "7896dbc1f41e08872e9d5e8f8baa8fdd2677f29468c4e156210174edc7f7b953"
[[package]]
name = "windows_x86_64_msvc"
version = "0.36.1"
source = "registry+https://github.com/rust-lang/crates.io-index"
checksum = "c811ca4a8c853ef420abd8592ba53ddbbac90410fab6903b3e79972a631f7680"
[[package]]
name = "windows_x86_64_msvc"
version = "0.42.2"
+4 -3
View File
@@ -54,7 +54,7 @@ config = "~0.13.3"
tokio = { version = "~1.28", features = ["full"] }
actix-web = { version = "4.3.1", optional = true, features = ["openssl"] }
actix-web = { version = "4.3.1", optional = true, features = ["rustls", "actix-tls"] }
actix-cors = "0.6.4"
actix-files = "0.6.2"
tonic = { version = "0.9.2", features = ["gzip", "tls"] }
@@ -62,8 +62,9 @@ tower = "0.4.13"
tower-layer = "0.3.2"
num-traits = "0.2.15"
tar = "0.4.38"
reqwest = { version = "0.11", features = ["stream", "rustls-tls", "blocking"] }
openssl = { version = "0.10", features = ["vendored"] }
reqwest = { version = "0.11", default-features = false, features = ["stream", "rustls-tls", "blocking"] }
rustls = "0.20.7"
rustls-pemfile = "1.0.2"
prometheus = { version = "0.13.3", default-features = false }
validator = { version = "0.16", features = ["derive"] }
actix-web-validator = "5.0.1"
+4 -4
View File
@@ -133,7 +133,7 @@ service:
# Default: true
enable_cors: true
# Use HTTPS for the REST API
# Enable HTTPS for the REST and gRPC API
enable_tls: false
# Check user HTTPS client certificate against CA file specified in tls config
@@ -196,8 +196,8 @@ tls:
# Required if cluster.p2p.enable_tls is true.
ca_cert: ./tls/cacert.pem
# TTL, in seconds, to re-load certificate from disk. Useful for certificate rotations,
# Only works for HTTPS endpoints, gRPC endpoints (including intra-cluster communication)
# doesn't support certificate re-load
# TTL in seconds to reload certificate from disk, useful for certificate rotations.
# Only works for HTTPS endpoints. Does not support gRPC (and intra-cluster communication).
# If `null` - TTL is disabled.
cert_ttl: 3600
+1 -2
View File
@@ -42,6 +42,5 @@ futures = "0.3.28"
anyhow = "1.0.71"
uuid = "1.3.3"
url = "2.3.1"
reqwest = { version = "0.11", features = ["stream", "rustls-tls"] }
openssl = { version = "0.10", features = ["vendored"] }
reqwest = { version = "0.11", default-features = false, features = ["stream", "rustls-tls"] }
tempfile = "3.5.0"
+143 -97
View File
@@ -1,126 +1,172 @@
use std::fs;
use std::fs::File;
use std::io::{self, BufRead, BufReader};
use std::sync::Arc;
use std::time::{Duration, Instant};
use openssl::error::ErrorStack;
use openssl::ssl::{
SniError, SslAcceptor, SslAcceptorBuilder, SslContext, SslContextBuilder, SslFiletype,
SslMethod, SslVerifyMode,
};
use openssl::x509::store::X509StoreBuilder;
use openssl::x509::X509;
use parking_lot::RwLock;
use rustls::server::{AllowAnyAuthenticatedClient, ClientHello, ResolvesServerCert};
use rustls::sign::CertifiedKey;
use rustls::{Certificate, RootCertStore, ServerConfig};
use rustls_pemfile::Item;
use crate::settings::{Settings, TlsConfig};
struct SslContextHolder {
ssl_context: SslContext,
/// A TTL based rotating server certificate resolver
struct RotatingCertificateResolver {
/// TLS configuration used for loading/refreshing certified key
tls_config: TlsConfig,
verify_client_cert: bool,
refresh_interval: Duration,
last_updated: Instant,
/// TTL for each rotation
ttl: Option<Duration>,
/// Current certified key
key: RwLock<CertifiedKeyWithAge>,
}
impl SslContextHolder {
fn new(
tls_config: &TlsConfig,
verify_client_cert: bool,
refresh_interval: Duration,
) -> Result<SslContextHolder, ErrorStack> {
let ssl_context = build_ssl_context(tls_config, verify_client_cert)?;
Ok(SslContextHolder {
ssl_context,
tls_config: tls_config.clone(),
verify_client_cert,
refresh_interval,
last_updated: Instant::now(),
impl RotatingCertificateResolver {
pub fn new(tls_config: TlsConfig, ttl: Option<Duration>) -> io::Result<Self> {
let certified_key = load_certified_key(&tls_config)?;
Ok(Self {
tls_config,
ttl,
key: RwLock::new(CertifiedKeyWithAge::from(certified_key)),
})
}
fn try_get_ssl_context(&self) -> Option<&SslContext> {
(self.last_updated.elapsed() < self.refresh_interval).then_some(&self.ssl_context)
}
/// Get certificate key or refresh
///
/// The key is automatically refreshed when the TTL is reached.
/// If refreshing fails, an error is logged and the old key is persisted.
fn get_key_or_refresh(&self) -> Arc<CertifiedKey> {
// Get read-only lock to the key. If TTL is not configured or is not expired, return key.
let key = self.key.read();
let ttl = match self.ttl {
Some(ttl) if key.is_expired(ttl) => ttl,
_ => return key.key.clone(),
};
drop(key);
fn get_ssl_context_or_refresh(&mut self) -> Result<&SslContext, ()> {
if self.last_updated.elapsed() >= self.refresh_interval {
self.refresh()?;
// If TTL is expired:
// - get read-write lock to the key
// - *re-check that TTL is expired* (to avoid refreshing the key multiple times from concurrent threads)
// - refresh and return the key
let mut key = self.key.write();
if key.is_expired(ttl) {
if let Err(err) = key.refresh(&self.tls_config) {
log::error!("Failed to refresh TLS certificate, keeping current: {err}");
}
}
Ok(&self.ssl_context)
}
fn refresh(&mut self) -> Result<(), ()> {
log::info!("Refreshing TLS certificates for actix!");
self.ssl_context =
build_ssl_context(&self.tls_config, self.verify_client_cert).map_err(|_| ())?;
Ok(())
key.key.clone()
}
}
pub fn build_ssl_acceptor(settings: &Settings) -> std::io::Result<SslAcceptorBuilder> {
let mut acceptor = SslAcceptor::mozilla_modern_v5(SslMethod::tls())?;
impl ResolvesServerCert for RotatingCertificateResolver {
fn resolve(&self, _client_hello: ClientHello<'_>) -> Option<Arc<CertifiedKey>> {
Some(self.get_key_or_refresh())
}
}
struct CertifiedKeyWithAge {
/// Last time the certificate was updated/replaced
last_update: Instant,
/// Current certified key
key: Arc<CertifiedKey>,
}
impl CertifiedKeyWithAge {
pub fn from(key: Arc<CertifiedKey>) -> Self {
Self {
last_update: Instant::now(),
key,
}
}
pub fn refresh(&mut self, tls_config: &TlsConfig) -> io::Result<()> {
*self = Self::from(load_certified_key(tls_config)?);
Ok(())
}
pub fn age(&self) -> Duration {
self.last_update.elapsed()
}
pub fn is_expired(&self, ttl: Duration) -> bool {
self.age() >= ttl
}
}
/// Load TLS configuration and construct certified key.
fn load_certified_key(tls_config: &TlsConfig) -> io::Result<Arc<CertifiedKey>> {
// Load certificates
let certs: Vec<Certificate> = with_buf_read(&tls_config.cert, rustls_pemfile::read_all)?
.into_iter()
.filter_map(|item| match item {
Item::X509Certificate(data) => Some(Certificate(data)),
_ => None,
})
.collect();
if certs.is_empty() {
return Err(io::Error::new(
io::ErrorKind::Other,
"No server certificate found",
));
}
// Load private key
let private_key_item = with_buf_read(&tls_config.key, rustls_pemfile::read_one)?
.ok_or_else(|| io::Error::new(io::ErrorKind::Other, "No private key found"))?;
let (Item::RSAKey(pkey) | Item::PKCS8Key(pkey) | Item::ECKey(pkey)) = private_key_item else {
return Err(io::Error::new(io::ErrorKind::Other, "No private key found"))
};
let private_key = rustls::PrivateKey(pkey);
let signing_key = rustls::sign::any_supported_type(&private_key)
.map_err(|err| io::Error::new(io::ErrorKind::Other, err))?;
// Construct certified key
let certified_key = CertifiedKey::new(certs, signing_key);
Ok(Arc::new(certified_key))
}
/// Generate an actix server configuration with TLS
///
/// Uses TLS settings as configured in configuration by user.
pub fn actix_tls_server_config(settings: &Settings) -> io::Result<ServerConfig> {
let config = ServerConfig::builder().with_safe_defaults();
let tls_config = settings
.tls
.clone()
.ok_or_else(Settings::tls_config_is_undefined_error)?;
let verify_client_cert = settings.service.verify_https_client_certificate;
let ssl_context_holder = RwLock::new(SslContextHolder::new(
&tls_config,
verify_client_cert,
Duration::from_secs(tls_config.cert_ttl),
)?);
// Verify client CA or not
let config = if settings.service.verify_https_client_certificate {
let mut root_cert_store = RootCertStore::empty();
let ca_certs: Vec<Vec<u8>> = with_buf_read(&tls_config.ca_cert, rustls_pemfile::certs)?;
root_cert_store.add_parsable_certificates(&ca_certs[..]);
config.with_client_cert_verifier(AllowAnyAuthenticatedClient::new(root_cert_store))
} else {
config.with_no_client_auth()
};
// Use set_servername_callback to implement dynamic certificate loading and refresh
acceptor.set_servername_callback(move |ssl, _alert| -> Result<(), SniError> {
{
let reader = ssl_context_holder.read();
if let Some(ssl_context) = reader.try_get_ssl_context() {
ssl.set_ssl_context(ssl_context).map_err(|error_stack| {
log::error!("Failed to set SSL context: {}", error_stack);
SniError::ALERT_FATAL
})?;
return Ok(());
}
}
// Configure rotating certificate resolver
let ttl = match tls_config.cert_ttl {
None | Some(0) => None,
Some(seconds) => Some(Duration::from_secs(seconds)),
};
let cert_resolver = RotatingCertificateResolver::new(tls_config, ttl)?;
let config = config.with_cert_resolver(Arc::new(cert_resolver));
// If getting the SSL context failed, try to get it again with refreshing
let mut writer = ssl_context_holder.write();
let ssl_context = writer
.get_ssl_context_or_refresh()
.map_err(|_refresh_error| {
log::error!("Failed to refresh certificates!");
SniError::ALERT_FATAL
})?;
ssl.set_ssl_context(ssl_context).map_err(|error_stack| {
log::error!("Failed to set SSL context: {}", error_stack);
SniError::ALERT_FATAL
})?;
Ok(())
});
Ok(acceptor)
Ok(config)
}
fn build_ssl_context(
tls_config: &TlsConfig,
verify_client_cert: bool,
) -> Result<SslContext, ErrorStack> {
let mut ssl_context_builder = SslContextBuilder::new(SslMethod::tls_server())?;
// Server TLS config
ssl_context_builder.set_private_key_file(&tls_config.key, SslFiletype::PEM)?;
ssl_context_builder.set_certificate_chain_file(&tls_config.cert)?;
ssl_context_builder.check_private_key()?;
// Verify client TLS certification
if verify_client_cert {
let client_ca =
fs::read_to_string(&tls_config.ca_cert).expect("Failed to load CA certificate");
let client_ca = X509::from_pem(client_ca.as_bytes())?;
let mut x509_client_store_builder = X509StoreBuilder::new()?;
x509_client_store_builder.add_cert(client_ca)?;
let client_cert_store = x509_client_store_builder.build();
ssl_context_builder.set_verify_cert_store(client_cert_store)?;
ssl_context_builder.set_verify(SslVerifyMode::PEER | SslVerifyMode::FAIL_IF_NO_PEER_CERT);
}
Ok(ssl_context_builder.build())
fn with_buf_read<T>(
path: &str,
f: impl FnOnce(&mut dyn BufRead) -> io::Result<T>,
) -> io::Result<T> {
let file = File::open(path)?;
let mut reader = BufReader::new(file);
let dyn_reader: &mut dyn BufRead = &mut reader;
f(dyn_reader)
}
+17 -3
View File
@@ -6,6 +6,7 @@ mod certificate_helpers;
#[allow(dead_code)] // May contain functions used in different binaries. Not actually dead
pub mod helpers;
use std::io;
use std::sync::Arc;
use ::api::grpc::models::{ApiResponse, ApiStatus, VersionInfo};
@@ -17,7 +18,6 @@ use actix_web::{error, get, web, App, HttpRequest, HttpResponse, HttpServer, Res
use collection::operations::validation;
use storage::dispatcher::Dispatcher;
use self::certificate_helpers::build_ssl_acceptor;
use crate::actix::api::cluster_api::config_cluster_api;
use crate::actix::api::collections_api::config_collections_api;
use crate::actix::api::count_api::count_points;
@@ -41,7 +41,7 @@ pub fn init(
dispatcher: Arc<Dispatcher>,
telemetry_collector: Arc<tokio::sync::Mutex<TelemetryCollector>>,
settings: Settings,
) -> std::io::Result<()> {
) -> io::Result<()> {
actix_web::rt::System::new().block_on(async {
let toc_data = web::Data::from(dispatcher.toc().clone());
let dispatcher_data = web::Data::from(dispatcher);
@@ -103,9 +103,23 @@ pub fn init(
let bind_addr = format!("{}:{}", settings.service.host, settings.service.http_port);
// With TLS enabled, bind with certificate helper and Rustls, or bind regularly
server = if settings.service.enable_tls {
server.bind_openssl(bind_addr, build_ssl_acceptor(&settings)?)?
log::info!(
"TLS enabled for REST API (TTL: {})",
settings
.tls
.as_ref()
.and_then(|tls| tls.cert_ttl)
.map(|ttl| ttl.to_string())
.unwrap_or_else(|| "none".into()),
);
let config = certificate_helpers::actix_tls_server_config(&settings)?;
server.bind_rustls(bind_addr, config)?
} else {
log::info!("TLS disabled for REST API");
server.bind(bind_addr)?
};
+6 -4
View File
@@ -93,13 +93,14 @@ impl Default for ConsensusConfig {
}
}
#[derive(Debug, Deserialize, Clone)]
#[derive(Debug, Deserialize, Clone, Validate)]
pub struct TlsConfig {
pub cert: String,
pub key: String,
pub ca_cert: String,
#[serde(default = "default_tls_cert_ttl")]
pub cert_ttl: u64,
#[validate(range(min = 1))]
pub cert_ttl: Option<u64>,
}
#[derive(Debug, Deserialize, Clone, Validate)]
@@ -117,6 +118,7 @@ pub struct Settings {
pub cluster: ClusterConfig,
#[serde(default = "default_telemetry_disabled")]
pub telemetry_disabled: bool,
#[validate]
pub tls: Option<TlsConfig>,
/// A list of messages for errors that happened during loading the configuration. We collect
/// them and store them here while loading because then our logger is not configured yet.
@@ -210,9 +212,9 @@ const fn default_message_timeout_tics() -> u64 {
10
}
const fn default_tls_cert_ttl() -> u64 {
const fn default_tls_cert_ttl() -> Option<u64> {
// Default one hour
3600
Some(3600)
}
impl Settings {
+9 -1
View File
@@ -67,12 +67,16 @@ pub fn init(
let mut server = Server::builder();
if settings.service.enable_tls {
log::info!("TLS enabled for gRPC API (TTL not supported)");
let tls_server_config = helpers::load_tls_external_server_config(settings.tls()?)?;
server = server
.tls_config(tls_server_config)
.map_err(helpers::tonic_error_to_io_error)?;
};
} else {
log::info!("TLS disabled for gRPC API");
}
// The stack of middleware that our service will be wrapped in
let middleware_layer = tower::ServiceBuilder::new()
@@ -154,7 +158,11 @@ pub fn init_internal(
let mut server = Server::builder();
if let Some(config) = tls_config {
log::info!("TLS enabled for internal gRPC API (TTL not supported)");
server = server.tls_config(config)?;
} else {
log::info!("TLS disabled for internal gRPC API");
};
// The stack of middleware that our service will be wrapped in