mirror of
https://github.com/lucky-sideburn/kubeinvaders.git
synced 2026-08-23 21:46:21 +00:00
some fixes...
This commit is contained in:
+81
-23
@@ -22,15 +22,57 @@ local http = require("socket.http")
|
||||
math.randomseed(os.clock()*100000000000)
|
||||
local rand = math.random(999, 9999)
|
||||
local arg = ngx.req.get_uri_args()
|
||||
local req_headers = ngx.req.get_headers()
|
||||
local k8s_url = ""
|
||||
local kube_host = os.getenv("KUBERNETES_SERVICE_HOST")
|
||||
local kube_port = os.getenv("KUBERNETES_SERVICE_PORT_HTTPS")
|
||||
local endpoint = os.getenv("ENDPOINT")
|
||||
|
||||
if os.getenv("KUBERNETES_SERVICE_HOST") then
|
||||
k8s_url = "https://" .. os.getenv("KUBERNETES_SERVICE_HOST") .. ":" .. os.getenv("KUBERNETES_SERVICE_PORT_HTTPS")
|
||||
if kube_host and kube_host ~= "" then
|
||||
local port_suffix = ""
|
||||
if kube_port and kube_port ~= "" then
|
||||
port_suffix = ":" .. kube_port
|
||||
end
|
||||
k8s_url = "https://" .. kube_host .. port_suffix
|
||||
else
|
||||
k8s_url = os.getenv("ENDPOINT")
|
||||
k8s_url = endpoint or ""
|
||||
end
|
||||
|
||||
local token = os.getenv("TOKEN")
|
||||
local target = arg['target'] or req_headers["x-k8s-target"] or req_headers["X-K8S-Target"]
|
||||
if target and target ~= "" then
|
||||
if not string.match(target, "^https?://") then
|
||||
target = "https://" .. target
|
||||
end
|
||||
k8s_url = string.gsub(target, "/+$", "")
|
||||
end
|
||||
|
||||
if k8s_url == "" then
|
||||
ngx.status = 500
|
||||
ngx.say("Missing Kubernetes endpoint configuration. Set KUBERNETES_SERVICE_HOST or ENDPOINT.")
|
||||
ngx.exit(ngx.OK)
|
||||
end
|
||||
|
||||
if not string.match(k8s_url, "^https?://") then
|
||||
k8s_url = "https://" .. k8s_url
|
||||
end
|
||||
|
||||
k8s_url = string.gsub(k8s_url, "/+$", "")
|
||||
|
||||
local token = req_headers["x-k8s-token"] or req_headers["X-K8S-Token"] or tostring(os.getenv("TOKEN") or "")
|
||||
if token == "" then
|
||||
ngx.status = 500
|
||||
ngx.say("Missing Kubernetes API token configuration.")
|
||||
ngx.exit(ngx.OK)
|
||||
end
|
||||
|
||||
local ca_cert_b64 = req_headers["x-k8s-ca-cert-b64"] or req_headers["X-K8S-CA-CERT-B64"]
|
||||
local ca_cert = nil
|
||||
if ca_cert_b64 and ca_cert_b64 ~= "" then
|
||||
ca_cert = ngx.decode_base64(ca_cert_b64)
|
||||
end
|
||||
|
||||
local disable_tls_env = string.lower(tostring(os.getenv("DISABLE_TLS") or "false"))
|
||||
local disable_tls = disable_tls_env == "true" or disable_tls_env == "1" or disable_tls_env == "yes"
|
||||
local namespace = arg['namespace']
|
||||
local node_name = arg['nodename']
|
||||
local url = k8s_url .. "/apis/batch/v1/namespaces/" .. namespace .. "/jobs"
|
||||
@@ -123,16 +165,38 @@ local headers2 = {
|
||||
["Content-Length"] = string.len(body)
|
||||
}
|
||||
|
||||
local function create_request_opts(request_url, request_headers, request_method, request_source)
|
||||
local request_opts = {
|
||||
url = request_url,
|
||||
headers = request_headers,
|
||||
method = request_method,
|
||||
verify = disable_tls and "none" or "peer",
|
||||
sink = ltn12.sink.table(resp)
|
||||
}
|
||||
|
||||
if request_source then
|
||||
request_opts.source = request_source
|
||||
end
|
||||
|
||||
if not disable_tls and ca_cert and ca_cert ~= "" then
|
||||
local ca_file_path = "/tmp/kubeinv-custom-ca.crt"
|
||||
local ca_file = io.open(ca_file_path, "w")
|
||||
if ca_file then
|
||||
ca_file:write(ca_cert)
|
||||
ca_file:close()
|
||||
request_opts.cafile = ca_file_path
|
||||
end
|
||||
end
|
||||
|
||||
return request_opts
|
||||
end
|
||||
|
||||
local url = k8s_url .. "/apis/batch/v1/namespaces/" .. namespace .. "/jobs"
|
||||
ngx.log(ngx.INFO, "Creating chaos_node job kubeinvaders-chaos-" ..rand)
|
||||
|
||||
local ok, statusCode, headers, statusText = https.request{
|
||||
url = url,
|
||||
headers = headers2,
|
||||
method = "POST",
|
||||
sink = ltn12.sink.table(resp),
|
||||
source = ltn12.source.string(body)
|
||||
}
|
||||
local ok, statusCode, headers, statusText = https.request(
|
||||
create_request_opts(url, headers2, "POST", ltn12.source.string(body))
|
||||
)
|
||||
|
||||
ngx.log(ngx.INFO, ok)
|
||||
ngx.log(ngx.INFO, statusCode)
|
||||
@@ -141,12 +205,9 @@ ngx.log(ngx.INFO, statusText)
|
||||
local url = k8s_url.. "/apis/batch/v1/namespaces/" .. namespace .. "/jobs"
|
||||
ngx.log(ngx.INFO, "Getting JobList" .. rand)
|
||||
|
||||
local ok, statusCode, headers, statusText = https.request{
|
||||
url = url,
|
||||
headers = headers,
|
||||
method = "GET",
|
||||
sink = ltn12.sink.table(resp)
|
||||
}
|
||||
local ok, statusCode, headers, statusText = https.request(
|
||||
create_request_opts(url, headers, "GET")
|
||||
)
|
||||
|
||||
ngx.log(ngx.INFO, ok)
|
||||
ngx.log(ngx.INFO, statusCode)
|
||||
@@ -167,12 +228,9 @@ end
|
||||
local url = k8s_url.. "/api/v1/namespaces/" .. namespace .. "/pods"
|
||||
ngx.log(ngx.INFO, "Getting PodList" .. rand)
|
||||
|
||||
local ok, statusCode, headers, statusText = https.request{
|
||||
url = url,
|
||||
headers = headers,
|
||||
method = "GET",
|
||||
sink = ltn12.sink.table(resp)
|
||||
}
|
||||
local ok, statusCode, headers, statusText = https.request(
|
||||
create_request_opts(url, headers, "GET")
|
||||
)
|
||||
|
||||
ngx.log(ngx.INFO, ok)
|
||||
ngx.log(ngx.INFO, statusCode)
|
||||
|
||||
Reference in New Issue
Block a user