services
This commit is contained in:
+10
-1
@@ -14,5 +14,14 @@ module.exports = {
|
|||||||
socketFile: '/var/run/proxy_lookup.socket',
|
socketFile: '/var/run/proxy_lookup.socket',
|
||||||
redis: {
|
redis: {
|
||||||
prefix: 'proxy_'
|
prefix: 'proxy_'
|
||||||
}
|
},
|
||||||
|
|
||||||
|
|
||||||
|
service:{
|
||||||
|
hostScheduler:{
|
||||||
|
enabled: true,
|
||||||
|
initial: 30000,
|
||||||
|
interval: 86400000,
|
||||||
|
}
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
'use strict';
|
||||||
|
// Using https://github.com/simpleworkjs/conf to handle configuration
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
userModel: 'redis', // pam, redis, ldap
|
||||||
|
ldap: {
|
||||||
|
url: 'ldap://192.168.1.55:389',
|
||||||
|
bindDN: 'cn=ldapclient service,ou=people,dc=theta42,dc=com',
|
||||||
|
bindPassword: '__IN SRECREST FILE__',
|
||||||
|
searchBase: 'ou=people,dc=theta42,dc=com',
|
||||||
|
userFilter: '(objectClass=inetOrgPerson)',
|
||||||
|
userNameAttribute: 'uid'
|
||||||
|
},
|
||||||
|
socketFile: '/var/run/proxy_lookup.socket',
|
||||||
|
redis: {
|
||||||
|
prefix: 'proxy_'
|
||||||
|
},
|
||||||
|
service:{
|
||||||
|
hostScheduler:{
|
||||||
|
enabled: false,
|
||||||
|
}
|
||||||
|
},
|
||||||
|
};
|
||||||
+18
-2
@@ -82,8 +82,15 @@ class Host extends Table{
|
|||||||
|
|
||||||
static async create(data, ...args){
|
static async create(data, ...args){
|
||||||
try{
|
try{
|
||||||
|
|
||||||
|
console.log('host create data', data.challengeType, data.challengeType === 'DNS-01-wildcard')
|
||||||
|
|
||||||
// Validate requested host is valid host and domain
|
// Validate requested host is valid host and domain
|
||||||
if(data.challengeType === 'DNS-01-wildcard') await this.validateWildcardCreate(data, args);
|
if(data.challengeType === 'DNS-01-wildcard'){
|
||||||
|
data.is_wildcard = true;
|
||||||
|
data.wildcard_status = "Starting"
|
||||||
|
await this.validateWildcardCreate(data, args);
|
||||||
|
}
|
||||||
|
|
||||||
// Validate requested host has a valid wildcard parent
|
// Validate requested host has a valid wildcard parent
|
||||||
if(data.challengeType === 'wildcardChild'){
|
if(data.challengeType === 'wildcardChild'){
|
||||||
@@ -96,24 +103,31 @@ class Host extends Table{
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
console.log('Host create here 102')
|
||||||
|
|
||||||
// Create the new host entry
|
// Create the new host entry
|
||||||
let out = await super.create(data, ...args);
|
let out = await super.create(data, ...args);
|
||||||
|
console.log('Host create here 106')
|
||||||
|
|
||||||
// Update the lookup table to reflect new host
|
// Update the lookup table to reflect new host
|
||||||
await this.buildLookUpObj();
|
await this.buildLookUpObj();
|
||||||
|
|
||||||
|
console.log('Host create here 111')
|
||||||
// Fire the request for the wild card cert
|
// Fire the request for the wild card cert
|
||||||
// This is "back ground" job, await is intentionally missing
|
// This is "back ground" job, await is intentionally missing
|
||||||
if(out.challengeType === 'DNS-01-wildcard') out.createWildcardCert();
|
if(data.challengeType === 'DNS-01-wildcard') out.createWildcardCert();
|
||||||
|
|
||||||
|
console.log('Host create here 111')
|
||||||
return out;
|
return out;
|
||||||
|
|
||||||
} catch(error){
|
} catch(error){
|
||||||
|
console.log(error)
|
||||||
throw error;
|
throw error;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
static async validateWildcardCreate(data, ...args){
|
static async validateWildcardCreate(data, ...args){
|
||||||
|
console.log('validateWildcardCreate here')
|
||||||
try{
|
try{
|
||||||
if(!data.host.startsWith('*.')) throw new Error('not wild card');
|
if(!data.host.startsWith('*.')) throw new Error('not wild card');
|
||||||
await Domain.get(data.host);
|
await Domain.get(data.host);
|
||||||
@@ -125,9 +139,11 @@ class Host extends Table{
|
|||||||
}
|
}
|
||||||
|
|
||||||
async createWildcardCert(){
|
async createWildcardCert(){
|
||||||
|
console.log('createWildcardCert here')
|
||||||
if(!this.host.startsWith('*.')) throw new Error('not wild card');
|
if(!this.host.startsWith('*.')) throw new Error('not wild card');
|
||||||
|
|
||||||
try{
|
try{
|
||||||
|
console.log('createWildcardCert here in try')
|
||||||
let host = this;
|
let host = this;
|
||||||
|
|
||||||
await host.update({
|
await host.update({
|
||||||
|
|||||||
@@ -1,32 +1,39 @@
|
|||||||
'use strict';
|
'use strict';
|
||||||
|
|
||||||
|
const conf = require('@simpleworkjs/conf');
|
||||||
const {Host} = require('../models/host');
|
const {Host} = require('../models/host');
|
||||||
|
|
||||||
/**
|
|
||||||
* Host Scheduler Service
|
|
||||||
*
|
|
||||||
* Manages scheduled tasks for host-related operations:
|
|
||||||
* - Wildcard SSL certificate renewal checks
|
|
||||||
*
|
|
||||||
* Schedule:
|
|
||||||
* - Initial check: 30 seconds after application starts
|
|
||||||
* - Recurring checks: Every 24 hours (86400000ms)
|
|
||||||
*
|
|
||||||
* The checkWildcardForRenew method:
|
|
||||||
* - Iterates through all hosts in the system
|
|
||||||
* - Checks if wildcard certificates are expiring within 30 days
|
|
||||||
* - Automatically renews certificates that are approaching expiration
|
|
||||||
*/
|
|
||||||
|
|
||||||
// Initial wildcard cert check 30 seconds after app starts
|
function hostSchedulerService(){
|
||||||
// Delay allows the system to fully initialize before checking certs
|
/**
|
||||||
// setTimeout(Host.checkWildcardForRenew.bind(Host), 30000);
|
* Host Scheduler Service
|
||||||
|
*
|
||||||
|
* Manages scheduled tasks for host-related operations:
|
||||||
|
* - Wildcard SSL certificate renewal checks
|
||||||
|
*
|
||||||
|
* Schedule:
|
||||||
|
* - Initial check: 30 seconds after application starts
|
||||||
|
* - Recurring checks: Every 24 hours (86400000ms)
|
||||||
|
*
|
||||||
|
* The checkWildcardForRenew method:
|
||||||
|
* - Iterates through all hosts in the system
|
||||||
|
* - Checks if wildcard certificates are expiring within 30 days
|
||||||
|
* - Automatically renews certificates that are approaching expiration
|
||||||
|
*/
|
||||||
|
|
||||||
// Check wildcard certs once every 24 hours
|
// Initial wildcard cert check 30 seconds after app starts
|
||||||
// Ensures certificates are renewed well before expiration
|
// Delay allows the system to fully initialize before checking certs
|
||||||
setInterval(Host.checkWildcardForRenew.bind(Host), 86400000);
|
setTimeout(Host.checkWildcardForRenew.bind(Host), conf.service.hostScheduler.initial);
|
||||||
|
|
||||||
|
// Check wildcard certs once every 24 hours
|
||||||
|
// Ensures certificates are renewed well before expiration
|
||||||
|
setInterval(Host.checkWildcardForRenew.bind(Host), conf.service.hostScheduler.interval);
|
||||||
|
|
||||||
|
console.log('Host scheduler service initialized');
|
||||||
|
console.log('- Wildcard cert check: 30s after start, then every 24h');
|
||||||
|
}
|
||||||
|
|
||||||
|
if(conf.service.hostScheduler.enabled !== false) hostSchedulerService();
|
||||||
|
|
||||||
console.log('Host scheduler service initialized');
|
|
||||||
console.log('- Wildcard cert check: 30s after start, then every 24h');
|
|
||||||
|
|
||||||
module.exports = {};
|
module.exports = {};
|
||||||
|
|||||||
@@ -38,16 +38,16 @@ function ModelPs(model){
|
|||||||
publish(propKey, res, ...args);
|
publish(propKey, res, ...args);
|
||||||
}).catch(function(error){
|
}).catch(function(error){
|
||||||
|
|
||||||
// console.error("Error PS", model.name, propKey, error)
|
console.error("Error async PS", model.name, propKey, error)
|
||||||
console.log('toDo, publish errors...');
|
// console.log('toDo, publish errors...');
|
||||||
});
|
});
|
||||||
}else{
|
}else{
|
||||||
publish(propKey, res, ...args);
|
publish(propKey, res, ...args);
|
||||||
}
|
}
|
||||||
return res;
|
return res;
|
||||||
}catch(error){
|
}catch(error){
|
||||||
// console.error("Error PS", model.name, propKey, error)
|
console.error("Error PS", model.name, propKey, error)
|
||||||
console.log("toDo, publish errors...");
|
// console.log("toDo, publish errors...");
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
|
|||||||
Reference in New Issue
Block a user