config

package
v1.5.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: MIT Imports: 18 Imported by: 0

Documentation

Index

Constants

View Source
const DefaultPurgeSecretHeader = "X-Go-Proxy-Cache-Purge-Key"

DefaultPurgeSecretHeader - Default HTTP header carrying the PURGE shared secret.

View Source
const PasswordOmittedValue = "*** OMITTED ***"

PasswordOmittedValue - Replacement value when showing passwords in configuration.

View Source
const SchemeWildcard = "*"

SchemeWildcard - Label to be shown when no schema (http/https) is selected.

Variables

View Source
var DefaultCBFailureRate float64 = 0.5

DefaultCBFailureRate - Default value used for circuitbreaker.CircuitBreaker.FailureRate

View Source
var DefaultCBInterval time.Duration = 0 * time.Second

DefaultCBInterval - Default value used for circuitbreaker.CircuitBreaker.Interval

View Source
var DefaultCBMaxRequests uint32 = 1

DefaultCBMaxRequests - Default value used for circuitbreaker.CircuitBreaker.MaxRequests

View Source
var DefaultCBThreshold uint32 = 2

DefaultCBThreshold - Default value used for circuitbreaker.CircuitBreaker.Threshold

View Source
var DefaultCBTimeout time.Duration = 60 * time.Second

DefaultCBTimeout - Default value used for circuitbreaker.CircuitBreaker.Timeout

View Source
var DefaultTimeoutHandler time.Duration = 5 * time.Second

DefaultTimeoutHandler - Default value used for http.TimeoutHandler

View Source
var DefaultTimeoutIdle time.Duration = 20 * time.Second

DefaultTimeoutIdle - Default value used for http.Server.IdleTimeout

View Source
var DefaultTimeoutRead time.Duration = 5 * time.Second

DefaultTimeoutRead - Default value used for http.Server.ReadTimeout

View Source
var DefaultTimeoutReadHeader time.Duration = 2 * time.Second

DefaultTimeoutReadHeader - Default value used for http.Server.ReadHeaderTimeout

View Source
var DefaultTimeoutWrite time.Duration = 5 * time.Second

DefaultTimeoutWrite - Default value used for http.Server.WriteTimeout

Functions

func InitConfigFromFileOrEnv

func InitConfigFromFileOrEnv(file string)

InitConfigFromFileOrEnv - Init the configuration in sequence: from a YAML file, from environment variables, then defaults.

func InitJWT added in v1.3.1

func InitJWT(jwtConfig *Jwt)

InitJWT - Configure the jwk auto-refresh and save it into the JWT config

func Print

func Print()

Print - Shows the current configuration.

func Validate

func Validate(file string) (bool, error)

Validate - Validate a YAML config file is syntactically valid.

Types

type Cache

type Cache struct {
	Hosts           []string `yaml:"hosts" envconfig:"REDIS_HOSTS"`
	Password        string   `yaml:"password" envconfig:"REDIS_PASSWORD"`
	DB              int      `yaml:"db" envconfig:"REDIS_DB"`
	TTL             int      `yaml:"ttl" envconfig:"DEFAULT_TTL"`
	AllowedStatuses []int    `yaml:"allowed_statuses" envconfig:"CACHE_ALLOWED_STATUSES" split_words:"true"`
	AllowedMethods  []string `yaml:"allowed_methods" envconfig:"CACHE_ALLOWED_METHODS" split_words:"true"`
	// EvictionPolicy - Redis maxmemory-policy applied on connect. One of:
	// noeviction, allkeys-lru, allkeys-lfu, volatile-lru, volatile-lfu,
	// allkeys-random, volatile-random, volatile-ttl. Empty leaves Redis's own
	// default (noeviction) untouched.
	EvictionPolicy string `yaml:"eviction_policy" envconfig:"REDIS_EVICTION_POLICY"`
	// NegativeTTL - Per-status TTL override (in seconds), e.g. {404: 30, 502: 10},
	// to cache error responses briefly and shield the origin without waiting on
	// its (often absent/wrong) Cache-Control headers. YAML-only: envconfig has no
	// clean map[int]int support, unlike the slice fields above.
	NegativeTTL map[int]int `yaml:"negative_ttl"`
	// OverrideTTL - Forced TTL (in seconds) for storable responses, replacing
	// the origin's Expires / max-age / s-maxage and the default TTL. It never
	// makes a response storable, and NegativeTTL wins for its statuses.
	// 0 = off (default); negative values are rejected.
	OverrideTTL int `yaml:"override_ttl" envconfig:"OVERRIDE_TTL"`
}

Cache - Defines the config for the cache backend.

func (Cache) EffectiveAllowedStatuses added in v1.3.1

func (c Cache) EffectiveAllowedStatuses() []int

EffectiveAllowedStatuses - AllowedStatuses plus any status codes that have a NegativeTTL override, so operators don't have to list the same status twice.

type Configuration

type Configuration struct {
	Server         Server                        `yaml:"server"`
	Cache          Cache                         `yaml:"cache"`
	CircuitBreaker circuitbreaker.CircuitBreaker `yaml:"circuit_breaker"`
	Domains        Domains                       `yaml:"domains"`
	Log            Log                           `yaml:"log"`
	Tracing        Tracing                       `yaml:"tracing"`

	Jwt Jwt `yaml:"jwt"`
	// contains filtered or unexported fields
}

Configuration - Defines the server configuration.

var Config Configuration = Configuration{
	Server: Server{
		Port: Port{
			HTTP:  "80",
			HTTPS: "443",
		},
		TLS: TLS{
			Auto:     false,
			Email:    "",
			CertFile: "",
			KeyFile:  "",
			Override: &tls.Config{

				CurvePreferences: []tls.CurveID{
					tls.CurveP256,
				},
				MinVersion: tls.VersionTLS12,
				MaxVersion: tls.VersionTLS13,
				CipherSuites: []uint16{
					tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
					tls.TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
					tls.TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256,
					tls.TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256,

					tls.TLS_AES_128_GCM_SHA256,
					tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
					tls.TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
				},
			},
		},
		Timeout: Timeout{
			Read:       DefaultTimeoutRead,
			ReadHeader: DefaultTimeoutReadHeader,
			Write:      DefaultTimeoutWrite,
			Idle:       DefaultTimeoutIdle,
			Handler:    DefaultTimeoutHandler,
		},
		Upstream: Upstream{
			HTTP2HTTPS:         false,
			InsecureBridge:     false,
			RedirectStatusCode: http.StatusPermanentRedirect,
			BalancingAlgorithm: "round-robin",
			HealthCheck: HealthCheck{
				StatusCodes: []string{"200"},
				Scheme:      "https",
			},
		},
		GZip: false,
	},
	Cache: Cache{
		DB:              0,
		TTL:             0,
		AllowedStatuses: []int{200, 301, 302},
		AllowedMethods:  []string{"HEAD", "GET"},
	},
	CircuitBreaker: circuitbreaker.CircuitBreaker{
		Threshold:   DefaultCBThreshold,
		FailureRate: DefaultCBFailureRate,
		Interval:    DefaultCBInterval,
		Timeout:     DefaultCBTimeout,
		MaxRequests: DefaultCBMaxRequests,
	},
	Log: Log{
		TimeFormat: "2006/01/02 15:04:05",
		Format:     `$host - $remote_addr - $remote_user $protocol $request_method "$request" $status $body_bytes_sent "$http_referer" "$http_user_agent" $cached_status_label`,
	},
}

Config - Holds the server configuration.

func DomainConf

func DomainConf(domain string, scheme string) (Configuration, bool)

DomainConf - Returns the configuration for the requested domain (Global Access).

func (*Configuration) CopyOverWith added in v1.3.1

func (c *Configuration) CopyOverWith(overrides Configuration, file *string)

CopyOverWith - Copies the Configuration over another (preserving not defined settings).

func (*Configuration) DomainConf added in v1.3.1

func (c *Configuration) DomainConf(domain string, scheme string) (Configuration, bool)

DomainConf - Returns the configuration for the requested domain.

The result is memoized on the receiver. A pointer receiver is required so the cache persists across calls (a value receiver mutated a throwaway copy, so the memoization never actually took effect and every request re-scanned all domains). Access is guarded by domainsCacheMu since DomainConf runs on the request path and is invoked concurrently.

type DomainSet added in v0.2.0

type DomainSet struct {
	Host   string
	Scheme string
}

DomainSet - Holds the uniqueness details of the domain.

func GetDomains

func GetDomains() []DomainSet

GetDomains - Returns a list of domains.

type Domains

type Domains map[string]Configuration

Domains - Overrides per domain.

type HSTS added in v1.3.1

type HSTS struct {
	Enabled           bool `yaml:"enabled" envconfig:"TLS_HSTS_ENABLED"`
	MaxAge            int  `yaml:"max_age" envconfig:"TLS_HSTS_MAX_AGE" default:"31536000"`
	IncludeSubdomains bool `yaml:"include_subdomains" envconfig:"TLS_HSTS_INCLUDE_SUBDOMAINS"`
	Preload           bool `yaml:"preload" envconfig:"TLS_HSTS_PRELOAD"`
}

HSTS - Defines the configuration for the Strict-Transport-Security header. Mitigates MITM/SSL-stripping attacks by telling browsers to never downgrade this host to plain HTTP again, once seen over HTTPS.

func (HSTS) Header added in v1.3.1

func (h HSTS) Header() string

Header - Builds the Strict-Transport-Security header value.

type HealthCheck added in v1.3.1

type HealthCheck struct {
	StatusCodes []string      `yaml:"status_codes" envconfig:"HEALTHCHECK_STATUS_CODES" split_words:"true"`
	Timeout     time.Duration `yaml:"timeout" envconfig:"HEALTHCHECK_TIMEOUT"`
	Interval    time.Duration `yaml:"interval" envconfig:"HEALTHCHECK_INTERVAL"`
	// No defaults on these two: unset has to stay representable, so the
	// balancer can inherit the upstream's scheme and port. Defaulting them to
	// https/443 here probed a plain-HTTP upstream over TLS and failed every
	// check with "server gave HTTP response to HTTPS client".
	Port          string `yaml:"port" envconfig:"HEALTHCHECK_PORT"`
	Scheme        string `yaml:"scheme" envconfig:"HEALTHCHECK_SCHEME"`
	AllowInsecure bool   `yaml:"allow_insecure" envconfig:"HEALTHCHECK_ALLOW_INSECURE"`
}

HealthCheck - Defines the health check settings.

type Internals added in v1.3.1

type Internals struct {
	ListeningAddress string `yaml:"listening_address" envconfig:"INTERNAL_LISTENING_ADDRESS" default:"127.0.0.1"`
	ListeningPort    string `yaml:"listening_port" envconfig:"INTERNAL_LISTENING_PORT" default:"52021"`
}

Internals - Defines the config for the internal listening address/port.

type Jwt added in v1.3.1

type Jwt struct {
	ExcludedPaths       []string `yaml:"excluded_paths" envconfig:"JWT_EXCLUDED_PATHS" split_words:"true"`
	AllowedScopes       []string `yaml:"allowed_scopes" envconfig:"JWT_ALLOWED_SCOPES" split_words:"true"`
	JwksUrl             string   `yaml:"jwks_url" envconfig:"JWT_JWKS_URL"`
	JwksRefreshInterval int      `yaml:"jwks_refresh_interval" envconfig:"JWT_REFRESH_INTERVAL" default:"15"`
	JwkCache            *jwk.Cache
	Context             context.Context
	Logger              *logrus.Logger
}

Jwt - Defines the config for the jwt validation.

type JwtError added in v1.3.1

type JwtError struct {
	ErrorCode        string `json:"errorCode"`
	ErrorDescription string `json:"errorDescription"`
}

Jwt - Defines the jwt validation error.

type Log

type Log struct {
	TimeFormat     string `yaml:"time_format"`
	Format         string `yaml:"format"`
	SentryDsn      string `yaml:"sentry_dsn" envconfig:"SENTRY_DSN"`
	SyslogProtocol string `yaml:"syslog_protocol" envconfig:"SYSLOG_PROTOCOL"`
	SyslogEndpoint string `yaml:"syslog_endpoint" envconfig:"SYSLOG_ENDPOINT"`
}

Log - Defines the config for the logs.

type Port

type Port struct {
	HTTPS string `yaml:"https" envconfig:"SERVER_HTTPS_PORT"`
	HTTP  string `yaml:"http" envconfig:"SERVER_HTTP_PORT"`
}

Port - Defines the listening ports per protocol.

type Purge added in v1.3.1

type Purge struct {
	// AllowedIPs - Allowlist of client IPs/CIDRs permitted to issue PURGE. The
	// direct connection IP (RemoteAddr) is checked, not the spoofable
	// X-Forwarded-For header.
	AllowedIPs []string `yaml:"allowed_ips" envconfig:"PURGE_ALLOWED_IPS" split_words:"true"`
	// Secret - Shared secret that must be presented in SecretHeader.
	Secret string `yaml:"secret" envconfig:"PURGE_SECRET"`
	// SecretHeader - HTTP header carrying the shared secret. Defaults to
	// DefaultPurgeSecretHeader when Secret is set but no header is specified.
	SecretHeader string `yaml:"secret_header" envconfig:"PURGE_SECRET_HEADER"`
}

Purge - Defines access control for PURGE requests. When both AllowedIPs and Secret are empty, PURGE is unrestricted (backward compatible). When either is set, a PURGE request must satisfy every configured check to be authorized.

type Server

type Server struct {
	Port      Port      `yaml:"port"`
	TLS       TLS       `yaml:"tls"`
	Timeout   Timeout   `yaml:"timeout"`
	Upstream  Upstream  `yaml:"upstream"`
	GZip      bool      `yaml:"gzip" envconfig:"GZIP_ENABLED"`
	Internals Internals `yaml:"internals"`
	Purge     Purge     `yaml:"purge"`
}

Server - Defines basic info for the server.

type TLS

type TLS struct {
	Auto     bool        `yaml:"auto" envconfig:"TLS_AUTO_CERT"`
	Email    string      `yaml:"email" envconfig:"TLS_EMAIL"`
	CertFile string      `yaml:"cert_file" envconfig:"TLS_CERT_FILE"`
	KeyFile  string      `yaml:"key_file" envconfig:"TLS_KEY_FILE"`
	Override *tls.Config `yaml:"override"`
	// CertCacheDir - Directory where ACME (Let's Encrypt) certificates are
	// cached. Must be persistent: an ephemeral directory forces re-issuance on
	// every restart, burning through the CA's rate limits.
	CertCacheDir string `yaml:"cert_cache_dir" envconfig:"TLS_CERT_CACHE_DIR"`
	HSTS         HSTS   `yaml:"hsts"`
}

TLS - Defines the configuration for SSL/TLS.

type Timeout

type Timeout struct {
	Read       time.Duration `yaml:"read" envconfig:"TIMEOUT_READ"`
	ReadHeader time.Duration `yaml:"read_header" envconfig:"TIMEOUT_READ_HEADER"`
	Write      time.Duration `yaml:"write" envconfig:"TIMEOUT_WRITE"`
	Idle       time.Duration `yaml:"idle" envconfig:"TIMEOUT_IDLE"`
	Handler    time.Duration `yaml:"handler" envconfig:"TIMEOUT_HANDLER"`
}

Timeout - Defines the server timeouts.

type Tracing added in v1.3.1

type Tracing struct {
	JaegerEndpoint string  `yaml:"jaeger_endpoint" envconfig:"TRACING_JAEGER_ENDPOINT"`
	Enabled        bool    `yaml:"enabled" envconfig:"TRACING_ENABLED"`
	SamplingRatio  float64 `yaml:"sampling_ratio" envconfig:"TRACING_SAMPLING_RATIO" default:"1.0"`
}

Tracing - Defines the config for the OpenTelemetry tracing.

type Upstream

type Upstream struct {
	Host               string      `yaml:"host" envconfig:"FORWARD_HOST"`
	Port               string      `yaml:"port" envconfig:"FORWARD_PORT"`
	Scheme             string      `yaml:"scheme" envconfig:"FORWARD_SCHEME"`
	BalancingAlgorithm string      `yaml:"balancing_algorithm" envconfig:"BALANCING_ALGORITHM" default:"round-robin"`
	Endpoints          []string    `yaml:"endpoints" envconfig:"LB_ENDPOINT_LIST" split_words:"true"`
	InsecureBridge     bool        `yaml:"insecure_bridge"`
	HTTP2HTTPS         bool        `yaml:"http_to_https" envconfig:"HTTP2HTTPS"`
	RedirectStatusCode int         `yaml:"redirect_status_code" envconfig:"REDIRECT_STATUS_CODE" default:"301"`
	HealthCheck        HealthCheck `yaml:"health_check"`
	// CollapsedForwarding - Feature flag for collapsed forwarding, off by
	// default. When true, concurrent identical GET/HEAD cache misses are
	// coalesced into a single upstream round-trip.
	CollapsedForwarding bool `yaml:"collapsed_forwarding" envconfig:"COLLAPSED_FORWARDING"`
}

Upstream - Defines the upstream settings.

func (Upstream) GetDomainID added in v1.3.1

func (u Upstream) GetDomainID() string

GetDomainID - Returns the unique ID for the upstream.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL