95 lines
3.2 KiB
Go
95 lines
3.2 KiB
Go
package main
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/audit"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/auth"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/buildinfo"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/config"
|
|
database "git.send.nrw/sendnrw/dockwatch/internal/db"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/gitops"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/hostsecurity"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/httpapi"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/monitor"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/nodes"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/notify"
|
|
"git.send.nrw/sendnrw/dockwatch/internal/stacks"
|
|
"log/slog"
|
|
"net/http"
|
|
"os"
|
|
"os/signal"
|
|
"syscall"
|
|
"time"
|
|
)
|
|
|
|
func main() {
|
|
cfg, e := config.Load()
|
|
if e != nil {
|
|
slog.Error("config", "error", e)
|
|
os.Exit(1)
|
|
}
|
|
ctx, c := signal.NotifyContext(context.Background(), syscall.SIGINT, syscall.SIGTERM)
|
|
defer c()
|
|
db, e := database.Open(cfg.DBPath())
|
|
if e != nil {
|
|
slog.Error("database", "error", e)
|
|
os.Exit(1)
|
|
}
|
|
defer db.Close()
|
|
ss, e := stacks.New(cfg.StacksDir)
|
|
if e != nil {
|
|
slog.Error("stacks", "error", e)
|
|
os.Exit(1)
|
|
}
|
|
ss.ConfigureHostAccess(cfg.HostRoot, cfg.AllowHostUserManagement)
|
|
ss.ConfigureHostPermissionManagement(cfg.AllowHostPermissionManagement)
|
|
nm := nodes.New(db, cfg.EncryptionKey())
|
|
ms := monitor.New(db, nm, cfg.CheckConcurrency, cfg.RetentionDays)
|
|
au := audit.New(db)
|
|
nt := notify.New(db, cfg.EncryptionKey())
|
|
gs := gitops.New(db, cfg.EncryptionKey(), ss, nm)
|
|
hs := hostsecurity.New(hostsecurity.Config{
|
|
Enabled: cfg.HostSecurityEnabled,
|
|
AllowChanges: cfg.AllowHostSecurityChanges,
|
|
AllowPackageManagement: cfg.AllowHostPackageManagement,
|
|
HostRoot: cfg.HostRoot,
|
|
DataDir: cfg.DataDir,
|
|
HostPID: cfg.HostSecurityPID,
|
|
AURUser: cfg.HostAURUser,
|
|
})
|
|
ms.SetEventSink(func(ctx context.Context, ev monitor.Event) {
|
|
nt.Broadcast(ctx, notify.Message{Title: "Monitor " + ev.To + ": " + ev.Name, Body: ev.Target + " changed from " + ev.From + " to " + ev.To + ". " + ev.Check.Message, Status: ev.To, MonitorID: ev.MonitorID})
|
|
_ = au.Log(ctx, audit.Entry{Actor: "monitor", Action: "monitor.transition", Resource: ev.Name, Detail: map[string]any{"monitor_id": ev.MonitorID, "from": ev.From, "to": ev.To, "latency_ms": ev.Check.LatencyMS}, Status: 200})
|
|
})
|
|
as, e := auth.New(ctx, cfg, db)
|
|
if e != nil {
|
|
slog.Error("auth", "error", e)
|
|
os.Exit(1)
|
|
}
|
|
if cfg.Mode != config.ModeAgent {
|
|
go ms.Run(ctx)
|
|
go au.Run(ctx, cfg.AuditRetentionDays)
|
|
}
|
|
srv := &http.Server{
|
|
Addr: cfg.ListenAddr,
|
|
Handler: httpapi.New(cfg, as, ss, nm, ms, au, nt, gs, hs),
|
|
ReadHeaderTimeout: 10 * time.Second,
|
|
ReadTimeout: 30 * time.Second,
|
|
IdleTimeout: 2 * time.Minute,
|
|
MaxHeaderBytes: 1 << 20,
|
|
}
|
|
go func() {
|
|
<-ctx.Done()
|
|
x, k := context.WithTimeout(context.Background(), 10*time.Second)
|
|
defer k()
|
|
_ = srv.Shutdown(x)
|
|
}()
|
|
bi := buildinfo.Current()
|
|
slog.Info("started", "mode", cfg.Mode, "listen", cfg.ListenAddr, "version", bi.Version, "commit", bi.Commit)
|
|
if e = srv.ListenAndServe(); e != nil && !errors.Is(e, http.ErrServerClosed) {
|
|
slog.Error("http server", "error", e)
|
|
os.Exit(1)
|
|
}
|
|
}
|