cloudwatch.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397
  1. package cloudwatch
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "io/ioutil"
  6. "strings"
  7. "sync"
  8. "time"
  9. "github.com/aws/aws-sdk-go/aws"
  10. "github.com/aws/aws-sdk-go/aws/awsutil"
  11. "github.com/aws/aws-sdk-go/aws/credentials"
  12. "github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds"
  13. "github.com/aws/aws-sdk-go/aws/ec2metadata"
  14. "github.com/aws/aws-sdk-go/aws/session"
  15. "github.com/aws/aws-sdk-go/service/cloudwatch"
  16. "github.com/aws/aws-sdk-go/service/ec2"
  17. "github.com/aws/aws-sdk-go/service/sts"
  18. "github.com/grafana/grafana/pkg/log"
  19. "github.com/grafana/grafana/pkg/middleware"
  20. m "github.com/grafana/grafana/pkg/models"
  21. )
  22. type actionHandler func(*cwRequest, *middleware.Context)
  23. var actionHandlers map[string]actionHandler
  24. type cwRequest struct {
  25. Region string `json:"region"`
  26. Action string `json:"action"`
  27. Body []byte `json:"-"`
  28. DataSource *m.DataSource
  29. }
  30. type datasourceInfo struct {
  31. Profile string
  32. Region string
  33. AssumeRoleArn string
  34. Namespace string
  35. AccessKey string
  36. SecretKey string
  37. }
  38. func (req *cwRequest) GetDatasourceInfo() *datasourceInfo {
  39. assumeRoleArn := req.DataSource.JsonData.Get("assumeRoleArn").MustString()
  40. accessKey := req.DataSource.JsonData.Get("accessKey").MustString()
  41. secretKey := req.DataSource.JsonData.Get("secretKey").MustString()
  42. return &datasourceInfo{
  43. AssumeRoleArn: assumeRoleArn,
  44. Region: req.Region,
  45. Profile: req.DataSource.Database,
  46. AccessKey: accessKey,
  47. SecretKey: secretKey,
  48. }
  49. }
  50. func init() {
  51. actionHandlers = map[string]actionHandler{
  52. "GetMetricStatistics": handleGetMetricStatistics,
  53. "ListMetrics": handleListMetrics,
  54. "DescribeAlarms": handleDescribeAlarms,
  55. "DescribeAlarmsForMetric": handleDescribeAlarmsForMetric,
  56. "DescribeAlarmHistory": handleDescribeAlarmHistory,
  57. "DescribeInstances": handleDescribeInstances,
  58. "__GetRegions": handleGetRegions,
  59. "__GetNamespaces": handleGetNamespaces,
  60. "__GetMetrics": handleGetMetrics,
  61. "__GetDimensions": handleGetDimensions,
  62. }
  63. }
  64. type cache struct {
  65. credential *credentials.Credentials
  66. expiration *time.Time
  67. }
  68. var awsCredentialCache map[string]cache = make(map[string]cache)
  69. var credentialCacheLock sync.RWMutex
  70. func getCredentials(dsInfo *datasourceInfo) *credentials.Credentials {
  71. cacheKey := dsInfo.Profile + ":" + dsInfo.AssumeRoleArn
  72. credentialCacheLock.RLock()
  73. if _, ok := awsCredentialCache[cacheKey]; ok {
  74. if awsCredentialCache[cacheKey].expiration != nil &&
  75. (*awsCredentialCache[cacheKey].expiration).After(time.Now().UTC()) {
  76. result := awsCredentialCache[cacheKey].credential
  77. credentialCacheLock.RUnlock()
  78. return result
  79. }
  80. }
  81. credentialCacheLock.RUnlock()
  82. accessKeyId := ""
  83. secretAccessKey := ""
  84. sessionToken := ""
  85. var expiration *time.Time
  86. expiration = nil
  87. if strings.Index(dsInfo.AssumeRoleArn, "arn:aws:iam:") == 0 {
  88. params := &sts.AssumeRoleInput{
  89. RoleArn: aws.String(dsInfo.AssumeRoleArn),
  90. RoleSessionName: aws.String("GrafanaSession"),
  91. DurationSeconds: aws.Int64(900),
  92. }
  93. stsSess := session.New()
  94. stsCreds := credentials.NewChainCredentials(
  95. []credentials.Provider{
  96. &credentials.EnvProvider{},
  97. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  98. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(stsSess), ExpiryWindow: 5 * time.Minute},
  99. })
  100. stsConfig := &aws.Config{
  101. Region: aws.String(dsInfo.Region),
  102. Credentials: stsCreds,
  103. }
  104. svc := sts.New(session.New(stsConfig), stsConfig)
  105. resp, err := svc.AssumeRole(params)
  106. if err != nil {
  107. // ignore
  108. log.Error(3, "CloudWatch: Failed to assume role", err)
  109. }
  110. if resp.Credentials != nil {
  111. accessKeyId = *resp.Credentials.AccessKeyId
  112. secretAccessKey = *resp.Credentials.SecretAccessKey
  113. sessionToken = *resp.Credentials.SessionToken
  114. expiration = resp.Credentials.Expiration
  115. }
  116. }
  117. sess := session.New()
  118. creds := credentials.NewChainCredentials(
  119. []credentials.Provider{
  120. &credentials.StaticProvider{Value: credentials.Value{
  121. AccessKeyID: accessKeyId,
  122. SecretAccessKey: secretAccessKey,
  123. SessionToken: sessionToken,
  124. }},
  125. &credentials.EnvProvider{},
  126. &credentials.StaticProvider{Value: credentials.Value{
  127. AccessKeyID: dsInfo.AccessKey,
  128. SecretAccessKey: dsInfo.SecretKey,
  129. }},
  130. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  131. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(sess), ExpiryWindow: 5 * time.Minute},
  132. })
  133. credentialCacheLock.Lock()
  134. awsCredentialCache[cacheKey] = cache{
  135. credential: creds,
  136. expiration: expiration,
  137. }
  138. credentialCacheLock.Unlock()
  139. return creds
  140. }
  141. func getAwsConfig(req *cwRequest) *aws.Config {
  142. cfg := &aws.Config{
  143. Region: aws.String(req.Region),
  144. Credentials: getCredentials(req.GetDatasourceInfo()),
  145. }
  146. return cfg
  147. }
  148. func handleGetMetricStatistics(req *cwRequest, c *middleware.Context) {
  149. cfg := getAwsConfig(req)
  150. svc := cloudwatch.New(session.New(cfg), cfg)
  151. reqParam := &struct {
  152. Parameters struct {
  153. Namespace string `json:"namespace"`
  154. MetricName string `json:"metricName"`
  155. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  156. Statistics []*string `json:"statistics"`
  157. StartTime int64 `json:"startTime"`
  158. EndTime int64 `json:"endTime"`
  159. Period int64 `json:"period"`
  160. } `json:"parameters"`
  161. }{}
  162. json.Unmarshal(req.Body, reqParam)
  163. params := &cloudwatch.GetMetricStatisticsInput{
  164. Namespace: aws.String(reqParam.Parameters.Namespace),
  165. MetricName: aws.String(reqParam.Parameters.MetricName),
  166. Dimensions: reqParam.Parameters.Dimensions,
  167. Statistics: reqParam.Parameters.Statistics,
  168. StartTime: aws.Time(time.Unix(reqParam.Parameters.StartTime, 0)),
  169. EndTime: aws.Time(time.Unix(reqParam.Parameters.EndTime, 0)),
  170. Period: aws.Int64(reqParam.Parameters.Period),
  171. }
  172. resp, err := svc.GetMetricStatistics(params)
  173. if err != nil {
  174. c.JsonApiErr(500, "Unable to call AWS API", err)
  175. return
  176. }
  177. c.JSON(200, resp)
  178. }
  179. func handleListMetrics(req *cwRequest, c *middleware.Context) {
  180. cfg := getAwsConfig(req)
  181. svc := cloudwatch.New(session.New(cfg), cfg)
  182. reqParam := &struct {
  183. Parameters struct {
  184. Namespace string `json:"namespace"`
  185. MetricName string `json:"metricName"`
  186. Dimensions []*cloudwatch.DimensionFilter `json:"dimensions"`
  187. } `json:"parameters"`
  188. }{}
  189. json.Unmarshal(req.Body, reqParam)
  190. params := &cloudwatch.ListMetricsInput{
  191. Namespace: aws.String(reqParam.Parameters.Namespace),
  192. MetricName: aws.String(reqParam.Parameters.MetricName),
  193. Dimensions: reqParam.Parameters.Dimensions,
  194. }
  195. var resp cloudwatch.ListMetricsOutput
  196. err := svc.ListMetricsPages(params,
  197. func(page *cloudwatch.ListMetricsOutput, lastPage bool) bool {
  198. metrics, _ := awsutil.ValuesAtPath(page, "Metrics")
  199. for _, metric := range metrics {
  200. resp.Metrics = append(resp.Metrics, metric.(*cloudwatch.Metric))
  201. }
  202. return !lastPage
  203. })
  204. if err != nil {
  205. c.JsonApiErr(500, "Unable to call AWS API", err)
  206. return
  207. }
  208. c.JSON(200, resp)
  209. }
  210. func handleDescribeAlarms(req *cwRequest, c *middleware.Context) {
  211. cfg := getAwsConfig(req)
  212. svc := cloudwatch.New(session.New(cfg), cfg)
  213. reqParam := &struct {
  214. Parameters struct {
  215. ActionPrefix string `json:"actionPrefix"`
  216. AlarmNamePrefix string `json:"alarmNamePrefix"`
  217. AlarmNames []*string `json:"alarmNames"`
  218. StateValue string `json:"stateValue"`
  219. } `json:"parameters"`
  220. }{}
  221. json.Unmarshal(req.Body, reqParam)
  222. params := &cloudwatch.DescribeAlarmsInput{
  223. MaxRecords: aws.Int64(100),
  224. }
  225. if reqParam.Parameters.ActionPrefix != "" {
  226. params.ActionPrefix = aws.String(reqParam.Parameters.ActionPrefix)
  227. }
  228. if reqParam.Parameters.AlarmNamePrefix != "" {
  229. params.AlarmNamePrefix = aws.String(reqParam.Parameters.AlarmNamePrefix)
  230. }
  231. if len(reqParam.Parameters.AlarmNames) != 0 {
  232. params.AlarmNames = reqParam.Parameters.AlarmNames
  233. }
  234. if reqParam.Parameters.StateValue != "" {
  235. params.StateValue = aws.String(reqParam.Parameters.StateValue)
  236. }
  237. resp, err := svc.DescribeAlarms(params)
  238. if err != nil {
  239. c.JsonApiErr(500, "Unable to call AWS API", err)
  240. return
  241. }
  242. c.JSON(200, resp)
  243. }
  244. func handleDescribeAlarmsForMetric(req *cwRequest, c *middleware.Context) {
  245. cfg := getAwsConfig(req)
  246. svc := cloudwatch.New(session.New(cfg), cfg)
  247. reqParam := &struct {
  248. Parameters struct {
  249. Namespace string `json:"namespace"`
  250. MetricName string `json:"metricName"`
  251. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  252. Statistic string `json:"statistic"`
  253. Period int64 `json:"period"`
  254. } `json:"parameters"`
  255. }{}
  256. json.Unmarshal(req.Body, reqParam)
  257. params := &cloudwatch.DescribeAlarmsForMetricInput{
  258. Namespace: aws.String(reqParam.Parameters.Namespace),
  259. MetricName: aws.String(reqParam.Parameters.MetricName),
  260. Period: aws.Int64(reqParam.Parameters.Period),
  261. }
  262. if len(reqParam.Parameters.Dimensions) != 0 {
  263. params.Dimensions = reqParam.Parameters.Dimensions
  264. }
  265. if reqParam.Parameters.Statistic != "" {
  266. params.Statistic = aws.String(reqParam.Parameters.Statistic)
  267. }
  268. resp, err := svc.DescribeAlarmsForMetric(params)
  269. if err != nil {
  270. c.JsonApiErr(500, "Unable to call AWS API", err)
  271. return
  272. }
  273. c.JSON(200, resp)
  274. }
  275. func handleDescribeAlarmHistory(req *cwRequest, c *middleware.Context) {
  276. cfg := getAwsConfig(req)
  277. svc := cloudwatch.New(session.New(cfg), cfg)
  278. reqParam := &struct {
  279. Parameters struct {
  280. AlarmName string `json:"alarmName"`
  281. HistoryItemType string `json:"historyItemType"`
  282. StartDate int64 `json:"startDate"`
  283. EndDate int64 `json:"endDate"`
  284. } `json:"parameters"`
  285. }{}
  286. json.Unmarshal(req.Body, reqParam)
  287. params := &cloudwatch.DescribeAlarmHistoryInput{
  288. AlarmName: aws.String(reqParam.Parameters.AlarmName),
  289. StartDate: aws.Time(time.Unix(reqParam.Parameters.StartDate, 0)),
  290. EndDate: aws.Time(time.Unix(reqParam.Parameters.EndDate, 0)),
  291. }
  292. if reqParam.Parameters.HistoryItemType != "" {
  293. params.HistoryItemType = aws.String(reqParam.Parameters.HistoryItemType)
  294. }
  295. resp, err := svc.DescribeAlarmHistory(params)
  296. if err != nil {
  297. c.JsonApiErr(500, "Unable to call AWS API", err)
  298. return
  299. }
  300. c.JSON(200, resp)
  301. }
  302. func handleDescribeInstances(req *cwRequest, c *middleware.Context) {
  303. cfg := getAwsConfig(req)
  304. svc := ec2.New(session.New(cfg), cfg)
  305. reqParam := &struct {
  306. Parameters struct {
  307. Filters []*ec2.Filter `json:"filters"`
  308. InstanceIds []*string `json:"instanceIds"`
  309. } `json:"parameters"`
  310. }{}
  311. json.Unmarshal(req.Body, reqParam)
  312. params := &ec2.DescribeInstancesInput{}
  313. if len(reqParam.Parameters.Filters) > 0 {
  314. params.Filters = reqParam.Parameters.Filters
  315. }
  316. if len(reqParam.Parameters.InstanceIds) > 0 {
  317. params.InstanceIds = reqParam.Parameters.InstanceIds
  318. }
  319. var resp ec2.DescribeInstancesOutput
  320. err := svc.DescribeInstancesPages(params,
  321. func(page *ec2.DescribeInstancesOutput, lastPage bool) bool {
  322. reservations, _ := awsutil.ValuesAtPath(page, "Reservations")
  323. for _, reservation := range reservations {
  324. resp.Reservations = append(resp.Reservations, reservation.(*ec2.Reservation))
  325. }
  326. return !lastPage
  327. })
  328. if err != nil {
  329. c.JsonApiErr(500, "Unable to call AWS API", err)
  330. return
  331. }
  332. c.JSON(200, resp)
  333. }
  334. func HandleRequest(c *middleware.Context, ds *m.DataSource) {
  335. var req cwRequest
  336. req.Body, _ = ioutil.ReadAll(c.Req.Request.Body)
  337. req.DataSource = ds
  338. json.Unmarshal(req.Body, &req)
  339. if handler, found := actionHandlers[req.Action]; !found {
  340. c.JsonApiErr(500, "Unexpected AWS Action", errors.New(req.Action))
  341. return
  342. } else {
  343. handler(&req, c)
  344. }
  345. }