-
Notifications
You must be signed in to change notification settings - Fork 7
/
utils.go
74 lines (64 loc) · 1.73 KB
/
utils.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
package utils
import (
"context"
"crypto/tls"
"crypto/x509"
"fmt"
"net"
"net/http"
"os"
"time"
"go.uber.org/zap"
v1 "k8s.io/api/core/v1"
metav1 "k8s.io/apimachinery/pkg/apis/meta/v1"
"k8s.io/client-go/kubernetes"
"k8s.io/client-go/rest"
)
func ConfigureTLS(logger *zap.Logger, certAuthorityFile string, insecure bool, nodeHost string) error {
// Set the root CA pool
cadata, err := os.ReadFile(certAuthorityFile)
if err != nil {
return err
}
certs := x509.NewCertPool()
if !certs.AppendCertsFromPEM(cadata) {
return fmt.Errorf("failed to append certs from pem")
}
newTlsConfig := &tls.Config{}
newTlsConfig.RootCAs = certs
if insecure {
logger.Warn("using insecure tls")
newTlsConfig.InsecureSkipVerify = insecure
}
defaultTransport := http.DefaultTransport.(*http.Transport)
defaultTransport.TLSClientConfig = newTlsConfig
dialer := &net.Dialer{
Timeout: 2 * time.Second,
KeepAlive: 2 * time.Second,
}
defaultTransport.DialContext = func(ctx context.Context, network, addr string) (net.Conn, error) {
return dialer.DialContext(ctx, network, fmt.Sprintf("%s:10250", nodeHost))
}
return nil
}
// ServerAddrFromCluster uses incluster config to determine a node's Hostname
func ServerAddrFromCluster(nodeHost string) (string, error) {
kubeConfig, err := rest.InClusterConfig()
if err != nil {
return "", err
}
clientset, err := kubernetes.NewForConfig(kubeConfig)
if err != nil {
return "", err
}
node, err := clientset.CoreV1().Nodes().Get(context.TODO(), nodeHost, metav1.GetOptions{})
if err != nil {
return "", err
}
for _, addr := range node.Status.Addresses {
if addr.Type == v1.NodeHostName {
return addr.Address, nil
}
}
return "", fmt.Errorf("no node matching %q found", nodeHost)
}