/
main.go
89 lines (72 loc) · 1.83 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
package main
import (
"crypto/tls"
"crypto/x509"
"errors"
"fmt"
"io"
"net/http"
"net/http/httputil"
"net/url"
"os"
)
func proxy(upstreamURL *url.URL, ca *x509.CertPool) http.Handler {
transport := (http.DefaultTransport.(*http.Transport)).Clone()
transport.TLSClientConfig = &tls.Config{RootCAs: ca}
proxy := httputil.NewSingleHostReverseProxy(upstreamURL)
proxy.Transport = &http.Transport{}
return proxy
}
func loadCA(filePath string) (*x509.CertPool, error) {
caFile, err := os.ReadFile(filePath)
if err != nil {
return nil, err
}
pool := x509.NewCertPool()
if ok := pool.AppendCertsFromPEM([]byte(caFile)); !ok {
return nil, errors.New("parsing upstream CA certificate")
}
return pool, nil
}
func start(address string, handler http.Handler) error {
server := http.Server{
Addr: address, Handler: handler,
}
return server.ListenAndServe()
}
func startTLS(address string, certFilePath, keyFilePath string) error {
mux := http.NewServeMux()
mux.HandleFunc("/", func(w http.ResponseWriter, req *http.Request) {
_, _ = io.WriteString(w, "ok")
})
server := http.Server{
Addr: address,
Handler: mux,
}
return server.ListenAndServeTLS(certFilePath, keyFilePath)
}
func main() {
certFile := "./certs/server.crt"
keyFile := "./certs/server.key"
caFile := "./certs/ca.crt"
listenAddress := ":8443"
proxyAddress := ":4433"
listenURL, err := url.Parse(fmt.Sprintf("https://localhost%s", listenAddress))
if err != nil {
panic(err)
}
ca, err := loadCA(caFile)
if err != nil {
panic(err)
}
go func() {
fmt.Printf("Proxy listens to %s and proxies to %s\n", proxyAddress, listenURL)
if err := start(proxyAddress, proxy(listenURL, ca)); err != nil {
panic(err)
}
}()
fmt.Printf("Server listens to %s\n", listenAddress)
if err := startTLS(listenAddress, certFile, keyFile); err != nil {
panic(err)
}
}