-
Notifications
You must be signed in to change notification settings - Fork 0
/
backends.py
161 lines (136 loc) · 5.23 KB
/
backends.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
import os
import requests
import logging
import time
from concurrent.futures import ThreadPoolExecutor, as_completed
from dataclasses import InitVar, dataclass, field
import requests
import requests.adapters
from textual import log
logger = logging.getLogger(__name__)
class VaultServerException(BaseException):
pass
class VaultServer:
def __init__(self, api_version: str = "v1"):
self.base_url = os.getenv('VAULT_ADDR')
self.token = os.getenv('VAULT_TOKEN')
self.cacert = os.getenv('VAULT_CACERT', None)
self.api_version = api_version
self.session = requests.session()
self.session.headers.update({"X-Vault-Token": self.token})
if self.cacert is not None:
self.session.verify = self.cacert
def _request(self, url: str, method="GET"):
full_url = f"{self.base_url}/{self.api_version}/{url.lstrip('/')}"
logger.debug("Calling %s on %s", method, full_url)
req = self.session.request(
method=method,
url=full_url
)
if not req.ok:
logger.warning("Following request %s failed with %s %s",
full_url, req.status_code, req.reason)
# TODO: parse errors and warnings
return req.json()['data']
def mounts(self):
# Remove system backends
data = self._request('sys/mounts')
return {x: {"type": v['type']} for x, v in data.items()
if v['type'] not in ['system', 'cubbyhole', 'identity']}
def list_secrets(self, mount, path="/"):
data = self._request(f"{mount}/metadata/{path.lstrip('/')}", method="LIST")
return data['keys']
def get_secret(self, mount, path):
return self._request(f"{mount}/data/{path}")['data']
@dataclass
class NomadTask:
expected: int
running: int
@dataclass
class NomadJob:
name: str
status: str
type: str
tasks: dict[str, NomadTask] = field(default_factory=dict)
deployment: str = "unknown"
@dataclass
class NomadCluster:
url: str
namespace: str | None
client_cert: str | None
client_key: str | None
ca: str | None
token: str | None
jobs: dict[str, NomadJob] = field(default_factory=dict)
session: InitVar[requests.Session | None] = None
poolexecutor: ThreadPoolExecutor | None = None
api_version: int = 1
@classmethod
def from_environ(cls):
return cls(
# Remove final slash if exists
url=os.environ["NOMAD_ADDR"].rstrip("/"),
namespace=os.getenv("NOMAD_NAMESPACE", "default"),
client_cert=os.getenv("NOMAD_CLIENT_CERT", None),
client_key=os.getenv("NOMAD_CLIENT_KEY", None),
ca=os.getenv("NOMAD_CACERT", None),
token=os.getenv("NOMAD_TOKEN", None),
jobs=dict(),
)
def __post_init__(self, attr):
# 10 is the requests.session pool
self.poolexecutor = ThreadPoolExecutor(max_workers=32)
self.session = requests.session()
custom_adapter = requests.adapters.HTTPAdapter(pool_maxsize=32)
self.session.mount('https://', custom_adapter)
# Prepare request defaults
if self.token:
self.session.headers.update(
{
"X-Nomad-Token": self.token,
}
)
if self.ca:
self.session.verify = self.ca
if self.client_cert and self.client_key:
self.session.cert = (self.client_cert, self.client_key)
def _request(self, url: str, method: str = "get") -> requests.Response:
started = time.monotonic()
url = url.lstrip("/")
url = f"{self.url}/v{self.api_version}/{url}?namespace={self.namespace}&stale=true"
r = self.session.request(method, url)
elapsed = time.monotonic() - started
logger.debug("Requested url %s, time: %2.3fs", url, elapsed)
return r
def refresh_jobs(self):
for job in self._request("/jobs").json():
name = job["Name"]
tasks = {}
for task, tasks_details in sorted(job["JobSummary"]["Summary"].items()):
tasks[task] = NomadTask(expected=0, running=tasks_details["Running"])
self.jobs[name] = NomadJob(
name=name,
status=job["Status"],
type=job["Type"],
tasks=tasks,
deployment="unknown",
)
self.refresh_deployments()
self.refresh_scales()
def refresh_scales(self):
futures = {
self.poolexecutor.submit(self._request, f"/job/{name}/scale"): name
for name in self.jobs.keys()
}
for future in as_completed(futures):
name = futures[future]
for task, details in future.result().json()["TaskGroups"].items():
self.jobs[name].tasks[task].expected = details["Desired"]
self.jobs[name].tasks[task].running = details["Running"]
def refresh_deployments(self):
deployments = {k["JobID"]: k for k in self._request("/deployments").json()}
for job in self.jobs.keys():
try:
self.jobs[job].deployment = deployments[job]["Status"]
except KeyError:
self.jobs[job].deployment = "unknown"