Skip to content

Commit 80bc871

Browse files
authored
refactor: rework acl fetching for kubernetes and docker (#1028)
1 parent 0e7bdf6 commit 80bc871

5 files changed

Lines changed: 769 additions & 388 deletions

File tree

‎internal/service/access_controls_service.go‎

Lines changed: 59 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ import (
1111
)
1212

1313
type LabelProvider interface {
14-
GetLabels(appDomain string) (*model.App, error)
14+
Lookup(locator func(name string, app *model.App) bool) error
1515
}
1616

1717
type AccessControlsService struct {
@@ -37,35 +37,74 @@ func NewAccessControlsService(i AccessControlServiceInput) *AccessControlsServic
3737
}
3838
}
3939

40-
func (service *AccessControlsService) lookupStaticACLs(domain string) *model.App {
41-
var nameMatch *model.App
42-
40+
func (service *AccessControlsService) getACLs(domain string, lookup func(locator func(name string, app *model.App) bool) error) (*model.App, error) {
4341
v := validators.NewDomainValidator(validators.DomainValidatorOptions{})
4442

45-
// First try to find a matching app by domain, then fallback to matching by app name (subdomain)
46-
for app, config := range service.config.Apps {
47-
if config.Config.Domain != "" {
48-
err := v.Validate(config.Config.Domain, domain)
43+
var domainMatch *model.App
44+
var nameMatch *model.App
45+
var nameMatchedApps []string
46+
47+
locatorFunc := func(name string, app *model.App) bool {
48+
if app.Config.Domain != "" {
49+
err := v.Validate(app.Config.Domain, domain)
4950
if err == nil {
50-
service.log.App.Debug().Str("name", app).Msg("Found matching container by domain")
51-
return &config
52-
}
53-
if !errors.Is(err, validators.ErrHostnameMismatch) {
54-
service.log.App.Debug().Str("name", app).Err(err).Msg("Domain validation failed")
51+
service.log.App.Debug().Str("name", name).Msg("Found matching container by domain")
52+
domainMatch = app
53+
return true
54+
} else if !errors.Is(err, validators.ErrHostnameMismatch) {
55+
service.log.App.Debug().Str("name", name).Err(err).Msg("Domain validation failed")
5556
}
5657
}
57-
if strings.HasPrefix(strings.ToLower(domain), strings.ToLower(app+".")) {
58-
service.log.App.Debug().Str("name", app).Msg("Found matching container by app name")
59-
nameMatch = &config
58+
if strings.HasPrefix(strings.ToLower(domain), strings.ToLower(name+".")) {
59+
service.log.App.Debug().Str("name", name).Msg("Found matching container by app name")
60+
nameMatch = app
61+
nameMatchedApps = append(nameMatchedApps, name)
6062
}
63+
return false
6164
}
6265

63-
return nameMatch
66+
err := lookup(locatorFunc)
67+
if err != nil {
68+
return nil, err
69+
}
70+
71+
if domainMatch != nil {
72+
service.log.App.Debug().Str("domain", domain).Msg("Found matching app by domain")
73+
return domainMatch, nil
74+
}
75+
76+
if nameMatch == nil {
77+
service.log.App.Debug().Str("domain", domain).Msg("No match found for domain, skipping")
78+
return nil, nil
79+
}
80+
81+
if len(nameMatchedApps) > 1 {
82+
service.log.App.Warn().Str("domain", domain).Strs("apps", nameMatchedApps).Msg("Multiple apps matched domain by name, app names must be unique, using last match")
83+
}
84+
85+
service.log.App.Debug().Str("domain", domain).Msg("Found matching app by app name")
86+
return nameMatch, nil
87+
}
88+
89+
func (service *AccessControlsService) lookupStaticACLs(domain string) (*model.App, error) {
90+
return service.getACLs(domain, func(locator func(name string, app *model.App) bool) error {
91+
for app, config := range service.config.Apps {
92+
if ok := locator(app, &config); ok {
93+
return nil
94+
}
95+
}
96+
return nil
97+
})
6498
}
6599

66100
func (service *AccessControlsService) GetAccessControls(domain string) (*model.App, error) {
67101
// First check in the static config
68-
app := service.lookupStaticACLs(domain)
102+
app, err := service.lookupStaticACLs(domain)
103+
104+
// Will never return an error here, but we need to check it
105+
if err != nil {
106+
return nil, err
107+
}
69108

70109
if app != nil {
71110
service.log.App.Debug().Msg("Using static ACLs for app")
@@ -74,9 +113,9 @@ func (service *AccessControlsService) GetAccessControls(domain string) (*model.A
74113

75114
// If we have a label provider configured, try to get ACLs from it
76115
if service.labelProvider != nil {
77-
return service.labelProvider.GetLabels(domain)
116+
return service.getACLs(domain, service.labelProvider.Lookup)
78117
}
79118

80-
// no labels
119+
// No labels
81120
return nil, nil
82121
}

0 commit comments

Comments
 (0)