cloudwatch.go 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486
  1. package cloudwatch
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "io/ioutil"
  6. "strings"
  7. "sync"
  8. "time"
  9. "github.com/aws/aws-sdk-go/aws"
  10. "github.com/aws/aws-sdk-go/aws/awsutil"
  11. "github.com/aws/aws-sdk-go/aws/credentials"
  12. "github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds"
  13. "github.com/aws/aws-sdk-go/aws/ec2metadata"
  14. "github.com/aws/aws-sdk-go/aws/session"
  15. "github.com/aws/aws-sdk-go/service/cloudwatch"
  16. "github.com/aws/aws-sdk-go/service/ec2"
  17. "github.com/aws/aws-sdk-go/service/sts"
  18. "github.com/grafana/grafana/pkg/metrics"
  19. "github.com/grafana/grafana/pkg/middleware"
  20. m "github.com/grafana/grafana/pkg/models"
  21. )
  22. type actionHandler func(*cwRequest, *middleware.Context)
  23. var actionHandlers map[string]actionHandler
  24. type cwRequest struct {
  25. Region string `json:"region"`
  26. Action string `json:"action"`
  27. Body []byte `json:"-"`
  28. DataSource *m.DataSource
  29. }
  30. type datasourceInfo struct {
  31. Profile string
  32. Region string
  33. AssumeRoleArn string
  34. Namespace string
  35. AccessKey string
  36. SecretKey string
  37. }
  38. func (req *cwRequest) GetDatasourceInfo() *datasourceInfo {
  39. assumeRoleArn := req.DataSource.JsonData.Get("assumeRoleArn").MustString()
  40. accessKey := ""
  41. secretKey := ""
  42. for key, value := range req.DataSource.SecureJsonData.Decrypt() {
  43. if key == "accessKey" {
  44. accessKey = value
  45. }
  46. if key == "secretKey" {
  47. secretKey = value
  48. }
  49. }
  50. return &datasourceInfo{
  51. AssumeRoleArn: assumeRoleArn,
  52. Region: req.Region,
  53. Profile: req.DataSource.Database,
  54. AccessKey: accessKey,
  55. SecretKey: secretKey,
  56. }
  57. }
  58. func init() {
  59. actionHandlers = map[string]actionHandler{
  60. "GetMetricStatistics": handleGetMetricStatistics,
  61. "ListMetrics": handleListMetrics,
  62. "DescribeAlarms": handleDescribeAlarms,
  63. "DescribeAlarmsForMetric": handleDescribeAlarmsForMetric,
  64. "DescribeAlarmHistory": handleDescribeAlarmHistory,
  65. "DescribeInstances": handleDescribeInstances,
  66. "__GetRegions": handleGetRegions,
  67. "__GetNamespaces": handleGetNamespaces,
  68. "__GetMetrics": handleGetMetrics,
  69. "__GetDimensions": handleGetDimensions,
  70. }
  71. }
  72. type cache struct {
  73. credential *credentials.Credentials
  74. expiration *time.Time
  75. }
  76. var awsCredentialCache map[string]cache = make(map[string]cache)
  77. var credentialCacheLock sync.RWMutex
  78. func getCredentials(dsInfo *datasourceInfo) (*credentials.Credentials, error) {
  79. cacheKey := dsInfo.Profile + ":" + dsInfo.AssumeRoleArn
  80. credentialCacheLock.RLock()
  81. if _, ok := awsCredentialCache[cacheKey]; ok {
  82. if awsCredentialCache[cacheKey].expiration != nil &&
  83. (*awsCredentialCache[cacheKey].expiration).After(time.Now().UTC()) {
  84. result := awsCredentialCache[cacheKey].credential
  85. credentialCacheLock.RUnlock()
  86. return result, nil
  87. }
  88. }
  89. credentialCacheLock.RUnlock()
  90. accessKeyId := ""
  91. secretAccessKey := ""
  92. sessionToken := ""
  93. var expiration *time.Time
  94. expiration = nil
  95. if strings.Index(dsInfo.AssumeRoleArn, "arn:aws:iam:") == 0 {
  96. params := &sts.AssumeRoleInput{
  97. RoleArn: aws.String(dsInfo.AssumeRoleArn),
  98. RoleSessionName: aws.String("GrafanaSession"),
  99. DurationSeconds: aws.Int64(900),
  100. }
  101. stsSess, err := session.NewSession()
  102. if err != nil {
  103. return nil, err
  104. }
  105. stsCreds := credentials.NewChainCredentials(
  106. []credentials.Provider{
  107. &credentials.EnvProvider{},
  108. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  109. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(stsSess), ExpiryWindow: 5 * time.Minute},
  110. })
  111. stsConfig := &aws.Config{
  112. Region: aws.String(dsInfo.Region),
  113. Credentials: stsCreds,
  114. }
  115. sess, err := session.NewSession(stsConfig)
  116. if err != nil {
  117. return nil, err
  118. }
  119. svc := sts.New(sess, stsConfig)
  120. resp, err := svc.AssumeRole(params)
  121. if err != nil {
  122. return nil, err
  123. }
  124. if resp.Credentials != nil {
  125. accessKeyId = *resp.Credentials.AccessKeyId
  126. secretAccessKey = *resp.Credentials.SecretAccessKey
  127. sessionToken = *resp.Credentials.SessionToken
  128. expiration = resp.Credentials.Expiration
  129. }
  130. }
  131. sess, err := session.NewSession()
  132. if err != nil {
  133. return nil, err
  134. }
  135. creds := credentials.NewChainCredentials(
  136. []credentials.Provider{
  137. &credentials.StaticProvider{Value: credentials.Value{
  138. AccessKeyID: accessKeyId,
  139. SecretAccessKey: secretAccessKey,
  140. SessionToken: sessionToken,
  141. }},
  142. &credentials.EnvProvider{},
  143. &credentials.StaticProvider{Value: credentials.Value{
  144. AccessKeyID: dsInfo.AccessKey,
  145. SecretAccessKey: dsInfo.SecretKey,
  146. }},
  147. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  148. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(sess), ExpiryWindow: 5 * time.Minute},
  149. })
  150. credentialCacheLock.Lock()
  151. awsCredentialCache[cacheKey] = cache{
  152. credential: creds,
  153. expiration: expiration,
  154. }
  155. credentialCacheLock.Unlock()
  156. return creds, nil
  157. }
  158. func getAwsConfig(req *cwRequest) (*aws.Config, error) {
  159. creds, err := getCredentials(req.GetDatasourceInfo())
  160. if err != nil {
  161. return nil, err
  162. }
  163. cfg := &aws.Config{
  164. Region: aws.String(req.Region),
  165. Credentials: creds,
  166. }
  167. return cfg, nil
  168. }
  169. func handleGetMetricStatistics(req *cwRequest, c *middleware.Context) {
  170. cfg, err := getAwsConfig(req)
  171. if err != nil {
  172. c.JsonApiErr(500, "Unable to call AWS API", err)
  173. return
  174. }
  175. sess, err := session.NewSession(cfg)
  176. if err != nil {
  177. c.JsonApiErr(500, "Unable to call AWS API", err)
  178. return
  179. }
  180. svc := cloudwatch.New(sess, cfg)
  181. reqParam := &struct {
  182. Parameters struct {
  183. Namespace string `json:"namespace"`
  184. MetricName string `json:"metricName"`
  185. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  186. Statistics []*string `json:"statistics"`
  187. ExtendedStatistics []*string `json:"extendedStatistics"`
  188. StartTime int64 `json:"startTime"`
  189. EndTime int64 `json:"endTime"`
  190. Period int64 `json:"period"`
  191. } `json:"parameters"`
  192. }{}
  193. json.Unmarshal(req.Body, reqParam)
  194. params := &cloudwatch.GetMetricStatisticsInput{
  195. Namespace: aws.String(reqParam.Parameters.Namespace),
  196. MetricName: aws.String(reqParam.Parameters.MetricName),
  197. Dimensions: reqParam.Parameters.Dimensions,
  198. StartTime: aws.Time(time.Unix(reqParam.Parameters.StartTime, 0)),
  199. EndTime: aws.Time(time.Unix(reqParam.Parameters.EndTime, 0)),
  200. Period: aws.Int64(reqParam.Parameters.Period),
  201. }
  202. if len(reqParam.Parameters.Statistics) != 0 {
  203. params.Statistics = reqParam.Parameters.Statistics
  204. }
  205. if len(reqParam.Parameters.ExtendedStatistics) != 0 {
  206. params.ExtendedStatistics = reqParam.Parameters.ExtendedStatistics
  207. }
  208. resp, err := svc.GetMetricStatistics(params)
  209. if err != nil {
  210. c.JsonApiErr(500, "Unable to call AWS API", err)
  211. return
  212. }
  213. metrics.M_Aws_CloudWatch_GetMetricStatistics.Inc(1)
  214. c.JSON(200, resp)
  215. }
  216. func handleListMetrics(req *cwRequest, c *middleware.Context) {
  217. cfg, err := getAwsConfig(req)
  218. if err != nil {
  219. c.JsonApiErr(500, "Unable to call AWS API", err)
  220. return
  221. }
  222. sess, err := session.NewSession(cfg)
  223. if err != nil {
  224. c.JsonApiErr(500, "Unable to call AWS API", err)
  225. return
  226. }
  227. svc := cloudwatch.New(sess, cfg)
  228. reqParam := &struct {
  229. Parameters struct {
  230. Namespace string `json:"namespace"`
  231. MetricName string `json:"metricName"`
  232. Dimensions []*cloudwatch.DimensionFilter `json:"dimensions"`
  233. } `json:"parameters"`
  234. }{}
  235. json.Unmarshal(req.Body, reqParam)
  236. params := &cloudwatch.ListMetricsInput{
  237. Namespace: aws.String(reqParam.Parameters.Namespace),
  238. MetricName: aws.String(reqParam.Parameters.MetricName),
  239. Dimensions: reqParam.Parameters.Dimensions,
  240. }
  241. var resp cloudwatch.ListMetricsOutput
  242. err = svc.ListMetricsPages(params,
  243. func(page *cloudwatch.ListMetricsOutput, lastPage bool) bool {
  244. metrics.M_Aws_CloudWatch_ListMetrics.Inc(1)
  245. metrics, _ := awsutil.ValuesAtPath(page, "Metrics")
  246. for _, metric := range metrics {
  247. resp.Metrics = append(resp.Metrics, metric.(*cloudwatch.Metric))
  248. }
  249. return !lastPage
  250. })
  251. if err != nil {
  252. c.JsonApiErr(500, "Unable to call AWS API", err)
  253. return
  254. }
  255. c.JSON(200, resp)
  256. }
  257. func handleDescribeAlarms(req *cwRequest, c *middleware.Context) {
  258. cfg, err := getAwsConfig(req)
  259. if err != nil {
  260. c.JsonApiErr(500, "Unable to call AWS API", err)
  261. return
  262. }
  263. sess, err := session.NewSession(cfg)
  264. if err != nil {
  265. c.JsonApiErr(500, "Unable to call AWS API", err)
  266. return
  267. }
  268. svc := cloudwatch.New(sess, cfg)
  269. reqParam := &struct {
  270. Parameters struct {
  271. ActionPrefix string `json:"actionPrefix"`
  272. AlarmNamePrefix string `json:"alarmNamePrefix"`
  273. AlarmNames []*string `json:"alarmNames"`
  274. StateValue string `json:"stateValue"`
  275. } `json:"parameters"`
  276. }{}
  277. json.Unmarshal(req.Body, reqParam)
  278. params := &cloudwatch.DescribeAlarmsInput{
  279. MaxRecords: aws.Int64(100),
  280. }
  281. if reqParam.Parameters.ActionPrefix != "" {
  282. params.ActionPrefix = aws.String(reqParam.Parameters.ActionPrefix)
  283. }
  284. if reqParam.Parameters.AlarmNamePrefix != "" {
  285. params.AlarmNamePrefix = aws.String(reqParam.Parameters.AlarmNamePrefix)
  286. }
  287. if len(reqParam.Parameters.AlarmNames) != 0 {
  288. params.AlarmNames = reqParam.Parameters.AlarmNames
  289. }
  290. if reqParam.Parameters.StateValue != "" {
  291. params.StateValue = aws.String(reqParam.Parameters.StateValue)
  292. }
  293. resp, err := svc.DescribeAlarms(params)
  294. if err != nil {
  295. c.JsonApiErr(500, "Unable to call AWS API", err)
  296. return
  297. }
  298. c.JSON(200, resp)
  299. }
  300. func handleDescribeAlarmsForMetric(req *cwRequest, c *middleware.Context) {
  301. cfg, err := getAwsConfig(req)
  302. if err != nil {
  303. c.JsonApiErr(500, "Unable to call AWS API", err)
  304. return
  305. }
  306. sess, err := session.NewSession(cfg)
  307. if err != nil {
  308. c.JsonApiErr(500, "Unable to call AWS API", err)
  309. return
  310. }
  311. svc := cloudwatch.New(sess, cfg)
  312. reqParam := &struct {
  313. Parameters struct {
  314. Namespace string `json:"namespace"`
  315. MetricName string `json:"metricName"`
  316. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  317. Statistic string `json:"statistic"`
  318. ExtendedStatistic string `json:"extendedStatistic"`
  319. Period int64 `json:"period"`
  320. } `json:"parameters"`
  321. }{}
  322. json.Unmarshal(req.Body, reqParam)
  323. params := &cloudwatch.DescribeAlarmsForMetricInput{
  324. Namespace: aws.String(reqParam.Parameters.Namespace),
  325. MetricName: aws.String(reqParam.Parameters.MetricName),
  326. Period: aws.Int64(reqParam.Parameters.Period),
  327. }
  328. if len(reqParam.Parameters.Dimensions) != 0 {
  329. params.Dimensions = reqParam.Parameters.Dimensions
  330. }
  331. if reqParam.Parameters.Statistic != "" {
  332. params.Statistic = aws.String(reqParam.Parameters.Statistic)
  333. }
  334. if reqParam.Parameters.ExtendedStatistic != "" {
  335. params.ExtendedStatistic = aws.String(reqParam.Parameters.ExtendedStatistic)
  336. }
  337. resp, err := svc.DescribeAlarmsForMetric(params)
  338. if err != nil {
  339. c.JsonApiErr(500, "Unable to call AWS API", err)
  340. return
  341. }
  342. c.JSON(200, resp)
  343. }
  344. func handleDescribeAlarmHistory(req *cwRequest, c *middleware.Context) {
  345. cfg, err := getAwsConfig(req)
  346. if err != nil {
  347. c.JsonApiErr(500, "Unable to call AWS API", err)
  348. return
  349. }
  350. sess, err := session.NewSession(cfg)
  351. if err != nil {
  352. c.JsonApiErr(500, "Unable to call AWS API", err)
  353. return
  354. }
  355. svc := cloudwatch.New(sess, cfg)
  356. reqParam := &struct {
  357. Parameters struct {
  358. AlarmName string `json:"alarmName"`
  359. HistoryItemType string `json:"historyItemType"`
  360. StartDate int64 `json:"startDate"`
  361. EndDate int64 `json:"endDate"`
  362. } `json:"parameters"`
  363. }{}
  364. json.Unmarshal(req.Body, reqParam)
  365. params := &cloudwatch.DescribeAlarmHistoryInput{
  366. AlarmName: aws.String(reqParam.Parameters.AlarmName),
  367. StartDate: aws.Time(time.Unix(reqParam.Parameters.StartDate, 0)),
  368. EndDate: aws.Time(time.Unix(reqParam.Parameters.EndDate, 0)),
  369. }
  370. if reqParam.Parameters.HistoryItemType != "" {
  371. params.HistoryItemType = aws.String(reqParam.Parameters.HistoryItemType)
  372. }
  373. resp, err := svc.DescribeAlarmHistory(params)
  374. if err != nil {
  375. c.JsonApiErr(500, "Unable to call AWS API", err)
  376. return
  377. }
  378. c.JSON(200, resp)
  379. }
  380. func handleDescribeInstances(req *cwRequest, c *middleware.Context) {
  381. cfg, err := getAwsConfig(req)
  382. if err != nil {
  383. c.JsonApiErr(500, "Unable to call AWS API", err)
  384. return
  385. }
  386. sess, err := session.NewSession(cfg)
  387. if err != nil {
  388. c.JsonApiErr(500, "Unable to call AWS API", err)
  389. return
  390. }
  391. svc := ec2.New(sess, cfg)
  392. reqParam := &struct {
  393. Parameters struct {
  394. Filters []*ec2.Filter `json:"filters"`
  395. InstanceIds []*string `json:"instanceIds"`
  396. } `json:"parameters"`
  397. }{}
  398. json.Unmarshal(req.Body, reqParam)
  399. params := &ec2.DescribeInstancesInput{}
  400. if len(reqParam.Parameters.Filters) > 0 {
  401. params.Filters = reqParam.Parameters.Filters
  402. }
  403. if len(reqParam.Parameters.InstanceIds) > 0 {
  404. params.InstanceIds = reqParam.Parameters.InstanceIds
  405. }
  406. var resp ec2.DescribeInstancesOutput
  407. err = svc.DescribeInstancesPages(params,
  408. func(page *ec2.DescribeInstancesOutput, lastPage bool) bool {
  409. reservations, _ := awsutil.ValuesAtPath(page, "Reservations")
  410. for _, reservation := range reservations {
  411. resp.Reservations = append(resp.Reservations, reservation.(*ec2.Reservation))
  412. }
  413. return !lastPage
  414. })
  415. if err != nil {
  416. c.JsonApiErr(500, "Unable to call AWS API", err)
  417. return
  418. }
  419. c.JSON(200, resp)
  420. }
  421. func HandleRequest(c *middleware.Context, ds *m.DataSource) {
  422. var req cwRequest
  423. req.Body, _ = ioutil.ReadAll(c.Req.Request.Body)
  424. req.DataSource = ds
  425. json.Unmarshal(req.Body, &req)
  426. if handler, found := actionHandlers[req.Action]; !found {
  427. c.JsonApiErr(500, "Unexpected AWS Action", errors.New(req.Action))
  428. return
  429. } else {
  430. handler(&req, c)
  431. }
  432. }