]> git.proxmox.com Git - proxmox-backup.git/blame - src/bin/proxmox-backup-proxy.rs
src/api2/pull.rs: add access permission
[proxmox-backup.git] / src / bin / proxmox-backup-proxy.rs
CommitLineData
a2479cfa
WB
1use std::sync::Arc;
2
3use failure::*;
4use futures::*;
5use hyper;
6use openssl::ssl::{SslMethod, SslAcceptor, SslFiletype};
7
9ea4bce4 8use proxmox::try_block;
a2479cfa
WB
9use proxmox::api::RpcEnvironmentType;
10
a2ca7137 11use proxmox_backup::configdir;
4a7de56e 12use proxmox_backup::buildcfg;
e3f41f21 13use proxmox_backup::server;
a690ecac 14use proxmox_backup::tools::daemon;
e57e1cd8 15use proxmox_backup::server::{ApiConfig, rest::*};
d01e2420 16use proxmox_backup::auth_helpers::*;
02c7a755 17
d973aa82
WB
18fn main() {
19 if let Err(err) = proxmox_backup::tools::runtime::main(run()) {
4223d9f8
DM
20 eprintln!("Error: {}", err);
21 std::process::exit(-1);
22 }
23}
24
fda5797b 25async fn run() -> Result<(), Error> {
02c7a755
DM
26 if let Err(err) = syslog::init(
27 syslog::Facility::LOG_DAEMON,
28 log::LevelFilter::Info,
29 Some("proxmox-backup-proxy")) {
4223d9f8 30 bail!("unable to inititialize syslog - {}", err);
02c7a755
DM
31 }
32
d01e2420
DM
33 let _ = public_auth_key(); // load with lazy_static
34 let _ = csrf_secret(); // load with lazy_static
35
02c7a755 36 let mut config = ApiConfig::new(
255f378a 37 buildcfg::JS_DIR, &proxmox_backup::api2::ROUTER, RpcEnvironmentType::PUBLIC);
02c7a755
DM
38
39 // add default dirs which includes jquery and bootstrap
40 // my $base = '/usr/share/libpve-http-server-perl';
41 // add_dirs($self->{dirs}, '/css/' => "$base/css/");
42 // add_dirs($self->{dirs}, '/js/' => "$base/js/");
43 // add_dirs($self->{dirs}, '/fonts/' => "$base/fonts/");
44 config.add_alias("novnc", "/usr/share/novnc-pve");
45 config.add_alias("extjs", "/usr/share/javascript/extjs");
46 config.add_alias("fontawesome", "/usr/share/fonts-font-awesome");
47 config.add_alias("xtermjs", "/usr/share/pve-xtermjs");
48 config.add_alias("widgettoolkit", "/usr/share/javascript/proxmox-widget-toolkit");
2d694f8f 49 config.add_alias("css", "/usr/share/javascript/proxmox-backup/css");
9c01e73c 50 config.add_alias("docs", "/usr/share/doc/proxmox-backup/html");
02c7a755
DM
51
52 let rest_server = RestServer::new(config);
53
6d1f61b2
DM
54 //openssl req -x509 -newkey rsa:4096 -keyout /etc/proxmox-backup/proxy.key -out /etc/proxmox-backup/proxy.pem -nodes
55 let key_path = configdir!("/proxy.key");
56 let cert_path = configdir!("/proxy.pem");
57
58 let mut acceptor = SslAcceptor::mozilla_intermediate(SslMethod::tls()).unwrap();
59 acceptor.set_private_key_file(key_path, SslFiletype::PEM)
60 .map_err(|err| format_err!("unable to read proxy key {} - {}", key_path, err))?;
61 acceptor.set_certificate_chain_file(cert_path)
62 .map_err(|err| format_err!("unable to read proxy cert {} - {}", cert_path, err))?;
63 acceptor.check_private_key().unwrap();
64
65 let acceptor = Arc::new(acceptor.build());
0d176f36 66
a690ecac
WB
67 let server = daemon::create_daemon(
68 ([0,0,0,0,0,0,0,0], 8007).into(),
083ff3fd 69 |listener, ready| {
db0cb9ce 70 let connections = proxmox_backup::tools::async_io::StaticIncoming::from(listener)
a690ecac 71 .map_err(Error::from)
db0cb9ce 72 .try_filter_map(move |(sock, _addr)| {
fda5797b
WB
73 let acceptor = Arc::clone(&acceptor);
74 async move {
75 sock.set_nodelay(true).unwrap();
76 sock.set_send_buffer_size(1024*1024).unwrap();
77 sock.set_recv_buffer_size(1024*1024).unwrap();
78 Ok(tokio_openssl::accept(&acceptor, sock)
79 .await
80 .ok() // handshake errors aren't be fatal, so return None to filter
81 )
a690ecac 82 }
a690ecac 83 });
db0cb9ce 84 let connections = proxmox_backup::tools::async_io::HyperAccept(connections);
083ff3fd
WB
85
86 Ok(ready
87 .and_then(|_| hyper::Server::builder(connections)
88 .serve(rest_server)
89 .with_graceful_shutdown(server::shutdown_future())
90 .map_err(Error::from)
91 )
92 .map_err(|err| eprintln!("server error: {}", err))
93 .map(|_| ())
a690ecac 94 )
a2ca7137 95 },
083ff3fd 96 );
a2ca7137 97
d98c9a7a
WB
98 daemon::systemd_notify(daemon::SystemdNotify::Ready)?;
99
fda5797b
WB
100 let init_result: Result<(), Error> = try_block!({
101 server::create_task_control_socket()?;
102 server::server_state_init()?;
103 Ok(())
104 });
d607b886 105
fda5797b
WB
106 if let Err(err) = init_result {
107 bail!("unable to start daemon - {}", err);
108 }
e3f41f21 109
083ff3fd 110 server.await?;
a546a8a0
WB
111 log::info!("server shutting down, waiting for active workers to complete");
112 proxmox_backup::server::last_worker_future().await?;
fda5797b 113 log::info!("done - exit server");
e3f41f21 114
4223d9f8 115 Ok(())
02c7a755 116}