Documentation
¶
Index ¶
- Constants
- Variables
- func InitConfigFromFileOrEnv(file string)
- func InitJWT(jwtConfig *Jwt)
- func Print()
- func Validate(file string) (bool, error)
- type Cache
- type Configuration
- type DomainSet
- type Domains
- type HSTS
- type HealthCheck
- type Internals
- type Jwt
- type JwtError
- type Log
- type Port
- type Purge
- type Server
- type TLS
- type Timeout
- type Tracing
- type Upstream
Constants ¶
const DefaultPurgeSecretHeader = "X-Go-Proxy-Cache-Purge-Key"
DefaultPurgeSecretHeader - Default HTTP header carrying the PURGE shared secret.
const PasswordOmittedValue = "*** OMITTED ***"
PasswordOmittedValue - Replacement value when showing passwords in configuration.
const SchemeWildcard = "*"
SchemeWildcard - Label to be shown when no schema (http/https) is selected.
Variables ¶
var DefaultCBFailureRate float64 = 0.5
DefaultCBFailureRate - Default value used for circuitbreaker.CircuitBreaker.FailureRate
var DefaultCBInterval time.Duration = 0 * time.Second
DefaultCBInterval - Default value used for circuitbreaker.CircuitBreaker.Interval
var DefaultCBMaxRequests uint32 = 1
DefaultCBMaxRequests - Default value used for circuitbreaker.CircuitBreaker.MaxRequests
var DefaultCBThreshold uint32 = 2
DefaultCBThreshold - Default value used for circuitbreaker.CircuitBreaker.Threshold
var DefaultCBTimeout time.Duration = 60 * time.Second
DefaultCBTimeout - Default value used for circuitbreaker.CircuitBreaker.Timeout
var DefaultTimeoutHandler time.Duration = 5 * time.Second
DefaultTimeoutHandler - Default value used for http.TimeoutHandler
var DefaultTimeoutIdle time.Duration = 20 * time.Second
DefaultTimeoutIdle - Default value used for http.Server.IdleTimeout
var DefaultTimeoutRead time.Duration = 5 * time.Second
DefaultTimeoutRead - Default value used for http.Server.ReadTimeout
var DefaultTimeoutReadHeader time.Duration = 2 * time.Second
DefaultTimeoutReadHeader - Default value used for http.Server.ReadHeaderTimeout
var DefaultTimeoutWrite time.Duration = 5 * time.Second
DefaultTimeoutWrite - Default value used for http.Server.WriteTimeout
Functions ¶
func InitConfigFromFileOrEnv ¶
func InitConfigFromFileOrEnv(file string)
InitConfigFromFileOrEnv - Init the configuration in sequence: from a YAML file, from environment variables, then defaults.
Types ¶
type Cache ¶
type Cache struct {
Hosts []string `yaml:"hosts" envconfig:"REDIS_HOSTS"`
Password string `yaml:"password" envconfig:"REDIS_PASSWORD"`
DB int `yaml:"db" envconfig:"REDIS_DB"`
TTL int `yaml:"ttl" envconfig:"DEFAULT_TTL"`
AllowedStatuses []int `yaml:"allowed_statuses" envconfig:"CACHE_ALLOWED_STATUSES" split_words:"true"`
AllowedMethods []string `yaml:"allowed_methods" envconfig:"CACHE_ALLOWED_METHODS" split_words:"true"`
// EvictionPolicy - Redis maxmemory-policy applied on connect. One of:
// noeviction, allkeys-lru, allkeys-lfu, volatile-lru, volatile-lfu,
// allkeys-random, volatile-random, volatile-ttl. Empty leaves Redis's own
// default (noeviction) untouched.
EvictionPolicy string `yaml:"eviction_policy" envconfig:"REDIS_EVICTION_POLICY"`
// NegativeTTL - Per-status TTL override (in seconds), e.g. {404: 30, 502: 10},
// to cache error responses briefly and shield the origin without waiting on
// its (often absent/wrong) Cache-Control headers. YAML-only: envconfig has no
// clean map[int]int support, unlike the slice fields above.
NegativeTTL map[int]int `yaml:"negative_ttl"`
// OverrideTTL - Forced TTL (in seconds) for storable responses, replacing
// the origin's Expires / max-age / s-maxage and the default TTL. It never
// makes a response storable, and NegativeTTL wins for its statuses.
// 0 = off (default); negative values are rejected.
OverrideTTL int `yaml:"override_ttl" envconfig:"OVERRIDE_TTL"`
}
Cache - Defines the config for the cache backend.
func (Cache) EffectiveAllowedStatuses ¶ added in v1.3.1
EffectiveAllowedStatuses - AllowedStatuses plus any status codes that have a NegativeTTL override, so operators don't have to list the same status twice.
type Configuration ¶
type Configuration struct {
Server Server `yaml:"server"`
Cache Cache `yaml:"cache"`
CircuitBreaker circuitbreaker.CircuitBreaker `yaml:"circuit_breaker"`
Domains Domains `yaml:"domains"`
Log Log `yaml:"log"`
Tracing Tracing `yaml:"tracing"`
Jwt Jwt `yaml:"jwt"`
// contains filtered or unexported fields
}
Configuration - Defines the server configuration.
var Config Configuration = Configuration{ Server: Server{ Port: Port{ HTTP: "80", HTTPS: "443", }, TLS: TLS{ Auto: false, Email: "", CertFile: "", KeyFile: "", Override: &tls.Config{ CurvePreferences: []tls.CurveID{ tls.CurveP256, }, MinVersion: tls.VersionTLS12, MaxVersion: tls.VersionTLS13, CipherSuites: []uint16{ tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384, tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256, tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256, tls.TLS_AES_128_GCM_SHA256, tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256, }, }, }, Timeout: Timeout{ Read: DefaultTimeoutRead, ReadHeader: DefaultTimeoutReadHeader, Write: DefaultTimeoutWrite, Idle: DefaultTimeoutIdle, Handler: DefaultTimeoutHandler, }, Upstream: Upstream{ HTTP2HTTPS: false, InsecureBridge: false, RedirectStatusCode: http.StatusPermanentRedirect, BalancingAlgorithm: "round-robin", HealthCheck: HealthCheck{ StatusCodes: []string{"200"}, Scheme: "https", }, }, GZip: false, }, Cache: Cache{ DB: 0, TTL: 0, AllowedStatuses: []int{200, 301, 302}, AllowedMethods: []string{"HEAD", "GET"}, }, CircuitBreaker: circuitbreaker.CircuitBreaker{ Threshold: DefaultCBThreshold, FailureRate: DefaultCBFailureRate, Interval: DefaultCBInterval, Timeout: DefaultCBTimeout, MaxRequests: DefaultCBMaxRequests, }, Log: Log{ TimeFormat: "2006/01/02 15:04:05", Format: `$host - $remote_addr - $remote_user $protocol $request_method "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $cached_status_label`, }, }
Config - Holds the server configuration.
func DomainConf ¶
func DomainConf(domain string, scheme string) (Configuration, bool)
DomainConf - Returns the configuration for the requested domain (Global Access).
func (*Configuration) CopyOverWith ¶ added in v1.3.1
func (c *Configuration) CopyOverWith(overrides Configuration, file *string)
CopyOverWith - Copies the Configuration over another (preserving not defined settings).
func (*Configuration) DomainConf ¶ added in v1.3.1
func (c *Configuration) DomainConf(domain string, scheme string) (Configuration, bool)
DomainConf - Returns the configuration for the requested domain.
The result is memoized on the receiver. A pointer receiver is required so the cache persists across calls (a value receiver mutated a throwaway copy, so the memoization never actually took effect and every request re-scanned all domains). Access is guarded by domainsCacheMu since DomainConf runs on the request path and is invoked concurrently.
type HSTS ¶ added in v1.3.1
type HSTS struct {
Enabled bool `yaml:"enabled" envconfig:"TLS_HSTS_ENABLED"`
MaxAge int `yaml:"max_age" envconfig:"TLS_HSTS_MAX_AGE" default:"31536000"`
IncludeSubdomains bool `yaml:"include_subdomains" envconfig:"TLS_HSTS_INCLUDE_SUBDOMAINS"`
Preload bool `yaml:"preload" envconfig:"TLS_HSTS_PRELOAD"`
}
HSTS - Defines the configuration for the Strict-Transport-Security header. Mitigates MITM/SSL-stripping attacks by telling browsers to never downgrade this host to plain HTTP again, once seen over HTTPS.
type HealthCheck ¶ added in v1.3.1
type HealthCheck struct {
StatusCodes []string `yaml:"status_codes" envconfig:"HEALTHCHECK_STATUS_CODES" split_words:"true"`
Timeout time.Duration `yaml:"timeout" envconfig:"HEALTHCHECK_TIMEOUT"`
Interval time.Duration `yaml:"interval" envconfig:"HEALTHCHECK_INTERVAL"`
// No defaults on these two: unset has to stay representable, so the
// balancer can inherit the upstream's scheme and port. Defaulting them to
// https/443 here probed a plain-HTTP upstream over TLS and failed every
// check with "server gave HTTP response to HTTPS client".
Port string `yaml:"port" envconfig:"HEALTHCHECK_PORT"`
Scheme string `yaml:"scheme" envconfig:"HEALTHCHECK_SCHEME"`
AllowInsecure bool `yaml:"allow_insecure" envconfig:"HEALTHCHECK_ALLOW_INSECURE"`
}
HealthCheck - Defines the health check settings.
type Internals ¶ added in v1.3.1
type Internals struct {
ListeningAddress string `yaml:"listening_address" envconfig:"INTERNAL_LISTENING_ADDRESS" default:"127.0.0.1"`
ListeningPort string `yaml:"listening_port" envconfig:"INTERNAL_LISTENING_PORT" default:"52021"`
}
Internals - Defines the config for the internal listening address/port.
type Jwt ¶ added in v1.3.1
type Jwt struct {
ExcludedPaths []string `yaml:"excluded_paths" envconfig:"JWT_EXCLUDED_PATHS" split_words:"true"`
AllowedScopes []string `yaml:"allowed_scopes" envconfig:"JWT_ALLOWED_SCOPES" split_words:"true"`
JwksUrl string `yaml:"jwks_url" envconfig:"JWT_JWKS_URL"`
JwksRefreshInterval int `yaml:"jwks_refresh_interval" envconfig:"JWT_REFRESH_INTERVAL" default:"15"`
JwkCache *jwk.Cache
Context context.Context
Logger *logrus.Logger
}
Jwt - Defines the config for the jwt validation.
type JwtError ¶ added in v1.3.1
type JwtError struct {
ErrorCode string `json:"errorCode"`
ErrorDescription string `json:"errorDescription"`
}
Jwt - Defines the jwt validation error.
type Log ¶
type Log struct {
TimeFormat string `yaml:"time_format"`
Format string `yaml:"format"`
SentryDsn string `yaml:"sentry_dsn" envconfig:"SENTRY_DSN"`
SyslogProtocol string `yaml:"syslog_protocol" envconfig:"SYSLOG_PROTOCOL"`
SyslogEndpoint string `yaml:"syslog_endpoint" envconfig:"SYSLOG_ENDPOINT"`
}
Log - Defines the config for the logs.
type Port ¶
type Port struct {
HTTPS string `yaml:"https" envconfig:"SERVER_HTTPS_PORT"`
HTTP string `yaml:"http" envconfig:"SERVER_HTTP_PORT"`
}
Port - Defines the listening ports per protocol.
type Purge ¶ added in v1.3.1
type Purge struct {
// AllowedIPs - Allowlist of client IPs/CIDRs permitted to issue PURGE. The
// direct connection IP (RemoteAddr) is checked, not the spoofable
// X-Forwarded-For header.
AllowedIPs []string `yaml:"allowed_ips" envconfig:"PURGE_ALLOWED_IPS" split_words:"true"`
// Secret - Shared secret that must be presented in SecretHeader.
Secret string `yaml:"secret" envconfig:"PURGE_SECRET"`
// SecretHeader - HTTP header carrying the shared secret. Defaults to
// DefaultPurgeSecretHeader when Secret is set but no header is specified.
SecretHeader string `yaml:"secret_header" envconfig:"PURGE_SECRET_HEADER"`
}
Purge - Defines access control for PURGE requests. When both AllowedIPs and Secret are empty, PURGE is unrestricted (backward compatible). When either is set, a PURGE request must satisfy every configured check to be authorized.
type Server ¶
type Server struct {
Port Port `yaml:"port"`
TLS TLS `yaml:"tls"`
Timeout Timeout `yaml:"timeout"`
Upstream Upstream `yaml:"upstream"`
GZip bool `yaml:"gzip" envconfig:"GZIP_ENABLED"`
Internals Internals `yaml:"internals"`
Purge Purge `yaml:"purge"`
}
Server - Defines basic info for the server.
type TLS ¶
type TLS struct {
Auto bool `yaml:"auto" envconfig:"TLS_AUTO_CERT"`
Email string `yaml:"email" envconfig:"TLS_EMAIL"`
CertFile string `yaml:"cert_file" envconfig:"TLS_CERT_FILE"`
KeyFile string `yaml:"key_file" envconfig:"TLS_KEY_FILE"`
Override *tls.Config `yaml:"override"`
// CertCacheDir - Directory where ACME (Let's Encrypt) certificates are
// cached. Must be persistent: an ephemeral directory forces re-issuance on
// every restart, burning through the CA's rate limits.
CertCacheDir string `yaml:"cert_cache_dir" envconfig:"TLS_CERT_CACHE_DIR"`
HSTS HSTS `yaml:"hsts"`
}
TLS - Defines the configuration for SSL/TLS.
type Timeout ¶
type Timeout struct {
Read time.Duration `yaml:"read" envconfig:"TIMEOUT_READ"`
ReadHeader time.Duration `yaml:"read_header" envconfig:"TIMEOUT_READ_HEADER"`
Write time.Duration `yaml:"write" envconfig:"TIMEOUT_WRITE"`
Idle time.Duration `yaml:"idle" envconfig:"TIMEOUT_IDLE"`
Handler time.Duration `yaml:"handler" envconfig:"TIMEOUT_HANDLER"`
}
Timeout - Defines the server timeouts.
type Tracing ¶ added in v1.3.1
type Tracing struct {
JaegerEndpoint string `yaml:"jaeger_endpoint" envconfig:"TRACING_JAEGER_ENDPOINT"`
Enabled bool `yaml:"enabled" envconfig:"TRACING_ENABLED"`
SamplingRatio float64 `yaml:"sampling_ratio" envconfig:"TRACING_SAMPLING_RATIO" default:"1.0"`
}
Tracing - Defines the config for the OpenTelemetry tracing.
type Upstream ¶
type Upstream struct {
Host string `yaml:"host" envconfig:"FORWARD_HOST"`
Port string `yaml:"port" envconfig:"FORWARD_PORT"`
Scheme string `yaml:"scheme" envconfig:"FORWARD_SCHEME"`
BalancingAlgorithm string `yaml:"balancing_algorithm" envconfig:"BALANCING_ALGORITHM" default:"round-robin"`
Endpoints []string `yaml:"endpoints" envconfig:"LB_ENDPOINT_LIST" split_words:"true"`
InsecureBridge bool `yaml:"insecure_bridge"`
HTTP2HTTPS bool `yaml:"http_to_https" envconfig:"HTTP2HTTPS"`
RedirectStatusCode int `yaml:"redirect_status_code" envconfig:"REDIRECT_STATUS_CODE" default:"301"`
HealthCheck HealthCheck `yaml:"health_check"`
// CollapsedForwarding - Feature flag for collapsed forwarding, off by
// default. When true, concurrent identical GET/HEAD cache misses are
// coalesced into a single upstream round-trip.
CollapsedForwarding bool `yaml:"collapsed_forwarding" envconfig:"COLLAPSED_FORWARDING"`
}
Upstream - Defines the upstream settings.
func (Upstream) GetDomainID ¶ added in v1.3.1
GetDomainID - Returns the unique ID for the upstream.