Coder Social home page Coder Social logo

smart_proxy_salt's Introduction

Smart Proxy - Salt

This plug-in adds support for Salt to Foreman's Smart Proxy.

smart_proxy_salt's People

Contributors

adamruzicka avatar archanaserver avatar arthurzenika avatar bastian-src avatar bochi avatar do3meli avatar dosas avatar ekohl avatar erkki avatar gvengel avatar lzap avatar mmoll avatar nadjaheitmann avatar philpep avatar q1x avatar sbernhard avatar sherifnagy avatar stbenjam avatar tamcore avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar

smart_proxy_salt's Issues

Suggestions for the salt report upload runner

Hi,
I have some suggestions for packaging the salt report upload runner. When manually copying it to salt://_runners it could be that when there are updates or fixes they are missed because its not included in the package.
So I'd rather have it installed via package to some location and documented that one has to add whatever directory it is installed to to runner_dirs in the salt master config, ie:

runner_dirs:
  - /wherever/the/package/puts/the/runner

This also eliminates the need to sync the runners.

Same goes for the reactor, it should be installed to the same directory and referenced directly (with full path) in the reactor's config. Reactors or runners do not have to reside in file_roots.

Package ruby-smart-proxy-salt requires python 2.7 on ubuntu 20.04

Package ruby-smart-proxy-salt installs python2.7 due to the python dependency:

# apt show ruby-smart-proxy-salt
Package: ruby-smart-proxy-salt
Version: 5.0.0-1
Priority: optional
Section: ruby
Maintainer: Michael Moll <[email protected]>
Installed-Size: 72.7 kB
Depends: ruby | ruby-interpreter, foreman-proxy (>= 2.5), ruby-smart-proxy-dynflow (>= 0.5.0), salt-master, python
Homepage: https://github.com/theforeman/smart_proxy_salt
Ruby-Versions: all
Download-Size: 12.1 kB
APT-Sources: http://deb.theforeman.org plugins/3.4 amd64 Packages
Description: SaltStack Plug-In for Foreman's Smart Proxy
 SaltStack Plug-In for Foreman's Smart Proxy

And the python package has a dependency on python2.7:

# apt show python -a
Package: python
Version: 2.7.15~rc1-1
Status: deinstall ok config-files
Priority: optional
Section: python
Source: python-defaults
Maintainer: Ubuntu Developers <[email protected]>
Original-Maintainer: Matthias Klose <[email protected]>
Config-Version: 2.7.15~rc1-1
Installed-Size: 639 kB
Provides: python-ctypes, python-email, python-importlib, python-profiler, python-wsgiref
Pre-Depends: python-minimal (= 2.7.15~rc1-1)
Depends: python2.7 (>= 2.7.15~rc1-1~), libpython-stdlib (= 2.7.15~rc1-1)
Suggests: python-doc (= 2.7.15~rc1-1), python-tk (>= 2.7.15~rc1-1~)
Conflicts: python-central (<< 0.5.5)
Breaks: update-manager-core (<< 0.200.5-2)
Replaces: python-dev (<< 2.6.5-2)
Homepage: http://www.python.org/
Cnf-Extra-Commands: python
Cnf-Priority-Bonus: 3
Download-Size: unknown
APT-Sources: /var/lib/dpkg/status
Description: interactive high-level object-oriented language (default version)
 Python, the high-level, interactive object oriented language,
 includes an extensive class library with lots of goodies for
 network programming, system administration, sounds and graphics.
 .
 This package is a dependency package, which depends on Debian's default
 Python version (currently v2.7).

As python2.7 is EOL since January 2020 the dependency should be switched to python3?

Suggestion: Use Salt's Reactor to Upload Reports

Currently, reports need to be manually uploaded after a highstate (or via a script). Instead, we can use Salt's event system and reactor to upload reports after every high state. Not only does this make for better usability, but also reduces load on the system as we don't have to run upload-reports in a cron job all the time.

Here's how I've done it on Salt 2016.11.3, although it does need more testing:

In /etc/salt/master.d/reactor.conf:

reactor:
  - 'salt/job/*/ret/*':
    - /srv/reactor/upload-salt-reports.sls

In /srv/reactor/upload-salt-reports.sls:

upload-salt-reports:
  runner.foreman.upload_reports:
    - data: {{ data|yaml_dquote }}

In /var/cache/salt/master/extmods/runners/foreman.py:

#!/usr/bin/env python
import ast
import logging
import httplib
import ssl
import yaml
import base64
import json

LOGGER = logging.getLogger(__name__)

FOREMAN_CONFIG = '/etc/salt/foreman.yaml'

def upload_reports(data):
    '''
    Upload Salt reports to Foreman. Note that only data that
    contains a highstate is uploaded.

    :data: A data object returned by a Salt event.
    '''
    data = ast.literal_eval(data)

    if data['fun'] != 'state.highstate':
        return True

    LOGGER.info("Uploading report for " + data['id'] + "...")

    job = {
        'job': {
            'function': data['fun'],
            'result': {
                data['id']: data['return']
            }
        }
    }

    config = None
    with open(FOREMAN_CONFIG, 'r') as f:
        config = yaml.load(f.read())

    headers = {'Accept': 'application/json',
               'Content-Type': 'application/json'}

    if config[':proto'] == 'https':
        ctx = ssl.create_default_context()
        ctx.load_cert_chain(
            certfile=config[':ssl_cert'], keyfile=config[':ssl_key'])

        if config[':ssl_ca']:
            ctx.load_verify_locations(cafile=config[':ssl_ca'])

        connection = httplib.HTTPSConnection(config[':host'],
                                             port=config[':port'], context=ctx)
    else:
        connection = httplib.HTTPConnection(config[':host'],
                                            port=config[':port'])

        if ':username' in config and ':password' in config:
            token = base64.b64encode('{}:{}'.format(config[':username'],
                                                    config[':password']))
            headers['Authorization'] = 'Basic {}'.format(token)

    connection.request('POST', '/salt/api/v2/jobs/upload',
                       json.dumps(job), headers)
    response = connection.getresponse()

    if response.status == 200:
        return True
    else:
        raise Exception(response.read())

    return True

Note that my runners come from git; I'm not sure of the best way to integrate this with the smart_proxy_salt packaging.

I feel like there are some obvious problems with this so I'd love to start a discussion.

Edit: Updated to not rely on upload-salt-reports at all as that was causing all kinds of weirdness.

Salt report upload broken with PyYaml versions shipped with salt onedir packages

Recent salt versions are available as onedir packages only (see https://docs.saltproject.io/salt/install-guide/en/latest/topics/upgrade-to-onedir.html#upgrade-to-onedir), here by default the current version of PyYAML 6.0.1 is shipped. While PyYaml versions 5.x already deprecated the yaml.load(input) function call (see https://github.com/yaml/pyyaml/wiki/PyYAML-yaml.load(input)-Deprecation), 6.x removed it.

smart_proxy_salt uses the function call in 3 places:

  • /salt/minion_auth/srv/salt/_runners/foreman_https.py
  • /salt/report_upload/srv/salt/_runners/foreman_report_upload.py
  • /sbin/upload-salt-reports

A straightforward fix would be, to replace the yaml.load(f.read()) calls with yaml.load(f.read(), Loader=yaml.FullLoader) ones, this was the default behavior for PyYaml 5.x. For security reasons it might be also desirable to check if a switch to the yaml.SafeLoader is feasable.

upload-salt-reports hanging or killed

We're trying to get salt reports uploaded to foreman and hitting an hang/kill issue in the script. I added some print commands to each of the functions. Looks like it gets to the run block where it appears to want to read /etc/salt/master config:

def run(*args, **kwargs):
    print("run")
    __opts__ = salt.config.master_config(
            os.environ.get('SALT_MASTER_CONFIG', '/etc/salt/master'))
    #print(__opts__)
    runner = salt.runner.Runner(__opts__)
    #print(runner)
    with io.open(os.devnull, 'w') as f:
        print("io open block")
        print(f)
        stdout_bak, sys.stdout = sys.stdout, f
        print("stdout block")
        try:
            ret = runner.cmd(*args, **kwargs)
            #print(ret)
        finally:
            sys.stdout = stdout_bak
    return ret['data'] if 'data' in ret else ret

Here is what that looks like when I run it:

[root@10-222-76-237 salt]# /usr/sbin/upload-salt-reports
get_lock
upload(jobs)
salt_config
jobs_to_upload
run
io open block
f is <_io.TextIOWrapper name='/dev/null' mode='w' encoding='UTF-8'>
Killed

Any idea what is going on here? I know that most of our salt config lives in /etc/salt/master.d/<confs> is this the issue?

Suggestion: Bulk change of Salt-Master

It'd be great to have a bulk change action to change the Salt Master of multiple hosts at once.

The salt-master is not set automatically when salt smart-proxy plugin creates a new host entry or atleast it didn't for me. Therefore you have to manually set the salt-master for each host. With growing host count that is quite a lot of work.

Theres an option to bulk change the monitoring proxy for example. I am not fluent in Ruby but I am familiar with how web applications handle requests and return views. If you guys could point me to the relevant components I need to analyze, I'd try giving it a shot to fork and pull request.

image

Throttle upload-salt-reports

I am using salt in combination with katello 3.2. I am wondering is there a way to throttle upload-salt-reports. I am seeing a problem when I am running this. It is causing my machine to utilize 100% cpu and cause memory to spike from 4gb to 13gb. It appears to be a problem with passenger, but I have done as much as I can to tune passenger. I have the report upload running every 10 minutes, so every 10 minutes it spikes. I need a way to batch the reports if possible, 20 to 30 at a time. Thanks!

Unable to install ruby-smart-proxy-salt on Ubuntu 20.04

Due to wrong package dependencies I'm unable to install the ruby-smart-proxy-salt package:

# apt install ruby-smart-proxy-salt
Reading package lists... Done
Building dependency tree
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:

The following packages have unmet dependencies:
 ruby-smart-proxy-salt : Depends: ruby-smart-proxy-salt-core (>= 0.0.2) but it is not going to be installed
E: Unable to correct problems, you have held broken packages.

Ubuntu Version:

# lsb_release -a
No LSB modules are available.
Distributor ID:	Ubuntu
Description:	Ubuntu 20.04.3 LTS
Release:	20.04
Codename:	focal

Foreman sources:

deb http://deb.theforeman.org focal 3.1
deb http://deb.theforeman.org plugins 3.1

I already reported it here, but there was no response to it: https://projects.theforeman.org/issues/33994

Thank you in advance and let me know if there are more details needed.

salt runner fails to upload - Exception encountered: a bytes-like object is required, not 'str'

Problem:
Using the foreman salt plugins and proxies, reports from the reactor/runners fail to upload.

Expected outcome:
They upload.

Foreman and Proxy versions:
Latest.

Foreman and Proxy plugin versions:
Latest.

Distribution and version:
Linux Alma 8 / Salt 3005.1

Other relevant data:
Added some additional logging to the foreman_reports_upload.py runner:

2024-07-24 19:26:22,703 [salt.loaded.ext.runners.foreman_report_upload:76  ][DEBUG   ][388458] HTTP connection created
2024-07-24 19:26:22,703 [salt.loaded.ext.runners.foreman_report_upload:158 ][ERROR   ][388458] Exception encountered: a bytes-like object is required, not 'str'
2024-07-24 19:26:22,703 [salt.loaded.ext.runners.foreman_report_upload:139 ][DEBUG   ][388458] Releasing lock
2024-07-24 19:26:22,704 [salt.loaded.ext.runners.foreman_report_upload:142 ][DEBUG   ][388458] Lock released

I do see the salt event log showing the reactor is triggering the runner. However, something about it isnt quite right and I cant figure it out. The long string below is a base64 encoded string.

salt/run/20240724192622670225/ret       {
    "_stamp": "2024-07-24T19:26:22.706437",
    "fun": "runner.foreman_report_upload.now",
    "fun_args": [
        {
            "highstate": ""
        }
    ],
    "jid": "20240724192622670225",
    "return": null,
    "success": true,
    "user": "Reactor"
}

Salt Compatibility with Foreman 1.20

Hi guys,

I'm planning to upgrade my Foreman 1.18 instance to 1.20 but i wanted to make sure that Salt is still supported with the current version. As there were no indications in the 1.20 release notes I'd assume it will still work. Nevertheless, I think it'd be great to update the Salt plugin doc as they stop listing support at Foreman 1.13.X with smart proxy 2.X.

Maybe a table like the foreman_salt repo would be a good fit to indicate anything above 1.13 is fine:
image
source https://github.com/theforeman/foreman_salt

salt runner foreman_reports_upload.py script issues with load balancers

As we continue to build out our large foreman/salt infrastructure, we use multiple load balancers for the foremanUI, API, etc. It is common use with load balancers to set them up as ssl managed, where as you forward port 443 from the load balancer, to 443 on the foreman server. But then you modify the apache configuration to be https, without the SSL engine itself. This allows the load balancer to handle http traffic via SSL, then forward it to the Foreman servers, where the SSL ends.

The current script will not work this way, as it does a check for https. If https is enabled in the config file this if will run:

    if config[":proto"] == "https":

Which will look for ssl certs, and fail. The foreman-node script, for example, doesnt care if you set it to https or http. It will only use the ssl certs if they are NOT empty.

This isnt a bug so to say, but it will prevent people from using the script if they are using managed load balancers.

I edited the script to ignore the checking of https, and instead check to see if ssl_cert and ssl_key are empty or not. If they are empty, it assumes ssl is not enable, but still uses https.

New Reactor Upload fails for some host

A Host of mine outputs a lot of data and the reactor uploaded fails on this

2019-10-30 23:34:55,563 [salt.utils.reactor:106 ][ERROR   ][30823] Failed to render "/srv/salt/foreman_report_upload.sls":
Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/salt/renderers/yaml.py", line 65, in render
    data = yamlloader.load(yaml_data, Loader=get_yaml_loader(argline))
  File "/usr/lib/python3/dist-packages/salt/utils/yamlloader.py", line 170, in load
    return yaml.load(stream, Loader=Loader)
  File "/usr/lib/python3/dist-packages/yaml/__init__.py", line 72, in load
    return loader.get_single_data()
  File "/usr/lib/python3/dist-packages/yaml/constructor.py", line 35, in get_single_data
    node = self.get_single_node()
  File "ext/_yaml.pyx", line 707, in _yaml.CParser.get_single_node (ext/_yaml.c:9612)
  File "ext/_yaml.pyx", line 725, in _yaml.CParser._compose_document (ext/_yaml.c:9922)
  File "ext/_yaml.pyx", line 776, in _yaml.CParser._compose_node (ext/_yaml.c:10814)
  File "ext/_yaml.pyx", line 890, in _yaml.CParser._compose_mapping_node (ext/_yaml.c:12609)
  File "ext/_yaml.pyx", line 776, in _yaml.CParser._compose_node (ext/_yaml.c:10814)
  File "ext/_yaml.pyx", line 890, in _yaml.CParser._compose_mapping_node (ext/_yaml.c:12609)
  File "ext/_yaml.pyx", line 774, in _yaml.CParser._compose_node (ext/_yaml.c:10784)
  File "ext/_yaml.pyx", line 851, in _yaml.CParser._compose_sequence_node (ext/_yaml.c:12011)
  File "ext/_yaml.pyx", line 776, in _yaml.CParser._compose_node (ext/_yaml.c:10814)
  File "ext/_yaml.pyx", line 890, in _yaml.CParser._compose_mapping_node (ext/_yaml.c:12609)
  File "ext/_yaml.pyx", line 774, in _yaml.CParser._compose_node (ext/_yaml.c:10784)
  File "ext/_yaml.pyx", line 851, in _yaml.CParser._compose_sequence_node (ext/_yaml.c:12011)
  File "ext/_yaml.pyx", line 776, in _yaml.CParser._compose_node (ext/_yaml.c:10814)
  File "ext/_yaml.pyx", line 892, in _yaml.CParser._compose_mapping_node (ext/_yaml.c:12639)
  File "ext/_yaml.pyx", line 905, in _yaml.CParser._parse_next_event (ext/_yaml.c:12818)
yaml.parser.ParserError: while parsing a block mapping
  in "<unicode string>", line 5, column 10
did not find expected key
  in "<unicode string>", line 5, column 2131

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
  File "/usr/lib/python3/dist-packages/salt/utils/reactor.py", line 97, in render_reaction
    data=data)
  File "/usr/lib/python3/dist-packages/salt/state.py", line 385, in render_template
    **kwargs)
  File "/usr/lib/python3/dist-packages/salt/template.py", line 101, in compile_template
    ret = render(input_data, saltenv, sls, **render_kwargs)
  File "/usr/lib/python3/dist-packages/salt/renderers/yaml.py", line 71, in render
    raise SaltRenderError(exc)
salt.exceptions.SaltRenderError: while parsing a block mapping
  in "<unicode string>", line 5, column 10
did not find expected key
  in "<unicode string>", line 5, column 2131

No reports uploaded to foreman via https

Following Foreman (v. 1.12) & foreman_salt (v. 5.0) integration manual I've set up working evironment that properly runs salt from foreman.
Unfortunately I wasn't able to gather any reports.

After some investigation I found (in /var/log/foreman-proxy/salt-cron.log):

SLError: [SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:590)
Traceback (most recent call last):
File "/usr/sbin/upload-salt-reports", line 137, in
upload(jobs_to_upload())
File "/usr/sbin/upload-salt-reports", line 112, in upload
json.dumps(job), headers)
File "/usr/lib/python2.7/httplib.py", line 1057, in request
self._send_request(method, url, body, headers)
File "/usr/lib/python2.7/httplib.py", line 1097, in _send_request
self.endheaders(body)
File "/usr/lib/python2.7/httplib.py", line 1053, in endheaders
self._send_output(message_body)
File "/usr/lib/python2.7/httplib.py", line 897, in _send_output
self.send(msg)
File "/usr/lib/python2.7/httplib.py", line 859, in send
self.connect()
File "/usr/lib/python2.7/httplib.py", line 1278, in connect
server_hostname=server_hostname)
File "/usr/lib/python2.7/ssl.py", line 353, in wrap_socket
_context=self)
File "/usr/lib/python2.7/ssl.py", line 601, in init
self.do_handshake()
File "/usr/lib/python2.7/ssl.py", line 830, in do_handshake
self._sslobj.do_handshake()

tcpdump showed that the client script (upload-salt-reports) was responding with: alert unknown ca

Changing the following (connection initialization):
context = ssl.SSLContext(ssl.PROTOCOL_TLSv1_2) context.load_cert_chain(certfile=config[':ssl_cert'], keyfile=config[':ssl_key']) connection = httplib.HTTPSConnection(config[':host'], port=config[':port'], context=context)
yields proper report upload.
Please advice if this is some kind of bug or have I misconfigured something ?

My /etc/salt/foreman.yaml


:proto: https
:host: fancy.host
:port: 443
:ssl_ca: "/etc/foreman/ssl/certs/ca.pem"
:ssl_cert: "/etc/foreman/ssl/certs/fancy.host.pem"
:ssl_key: "/etc/foreman/ssl/private/fancy.host.key"
:timeout: 60
๐Ÿง‚ /usr/bin/salt
:upload_grains: true

Support for state.apply command

Hi is it possible for upload-salt-reports to support the state.apply command also instead of only working for only state.highstate?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.