-
Notifications
You must be signed in to change notification settings - Fork 3
/
Copy pathmain.go
82 lines (70 loc) · 2.42 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
package main
import (
"context"
"crypto/tls"
"flag"
"fmt"
"github.com/golang/glog"
"github.com/yisaer/sidecar-inject-server/pkg/config"
"github.com/yisaer/sidecar-inject-server/pkg/webhook"
"net/http"
"os"
"os/signal"
"syscall"
)
func main() {
var parameters webhook.WhSvrParameters
// get command line parameters
flag.IntVar(¶meters.Port, "port", 443, "Webhook server port.")
flag.StringVar(¶meters.CertFile, "tlsCertFile", "/etc/webhook/certs/cert.pem", "File containing the x509 Certificate for HTTPS.")
flag.StringVar(¶meters.KeyFile, "tlsKeyFile", "/etc/webhook/certs/key.pem", "File containing the x509 private key to --tlsCertFile.")
flag.StringVar(¶meters.Token, "authToken", "/var/run/secrets/kubernetes.io/serviceaccount/token", "Token to communicate with apiServer")
flag.StringVar(¶meters.Crt, "ca", "/var/run/secrets/kubernetes.io/serviceaccount/ca.crt", "crt to verify api server")
flag.Parse()
url := "https://kubernetes.default.svc.cluster.local/apis/yisaer.github.io/v1alpha1/sidecars"
// load apiServer ca.crt
certPool, err := config.LoadCA(parameters.Crt)
if err != nil {
glog.Errorf("Filed to load crt: %v", err)
}
// load apiServer token
token, err := config.LoadToken(parameters.Token)
if err != nil {
glog.Errorf("failed to load token")
}
// load tls key pair
pair, err := tls.LoadX509KeyPair(parameters.CertFile, parameters.KeyFile)
if err != nil {
glog.Errorf("Filed to load key pair: %v", err)
}
// build server
whsvr := &webhook.WebhookServer{
Client: &config.WebClient{
Url: url,
Token: token,
Client: &http.Client{Transport: &http.Transport{
TLSClientConfig: &tls.Config{RootCAs: certPool},
}},
},
Server: &http.Server{
Addr: fmt.Sprintf(":%v", parameters.Port),
TLSConfig: &tls.Config{Certificates: []tls.Certificate{pair}},
},
}
// define http server and server handler
mux := http.NewServeMux()
mux.HandleFunc("/mutate", whsvr.Serve)
whsvr.Server.Handler = mux
// start webhook server in new rountine
go func() {
if err := whsvr.Server.ListenAndServeTLS("", ""); err != nil {
glog.Errorf("Filed to listen and serve webhook server: %v", err)
}
}()
// listening OS shutdown singal
signalChan := make(chan os.Signal, 1)
signal.Notify(signalChan, syscall.SIGINT, syscall.SIGTERM)
<-signalChan
glog.Infof("Got OS shutdown signal, shutting down wenhook server gracefully...")
whsvr.Server.Shutdown(context.Background())
}