cloudwatch.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446
  1. package cloudwatch
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "io/ioutil"
  6. "strings"
  7. "sync"
  8. "time"
  9. "github.com/aws/aws-sdk-go/aws"
  10. "github.com/aws/aws-sdk-go/aws/awsutil"
  11. "github.com/aws/aws-sdk-go/aws/credentials"
  12. "github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds"
  13. "github.com/aws/aws-sdk-go/aws/ec2metadata"
  14. "github.com/aws/aws-sdk-go/aws/session"
  15. "github.com/aws/aws-sdk-go/service/cloudwatch"
  16. "github.com/aws/aws-sdk-go/service/ec2"
  17. "github.com/aws/aws-sdk-go/service/sts"
  18. "github.com/grafana/grafana/pkg/metrics"
  19. "github.com/grafana/grafana/pkg/middleware"
  20. m "github.com/grafana/grafana/pkg/models"
  21. )
  22. type actionHandler func(*cwRequest, *middleware.Context)
  23. var actionHandlers map[string]actionHandler
  24. type cwRequest struct {
  25. Region string `json:"region"`
  26. Action string `json:"action"`
  27. Body []byte `json:"-"`
  28. DataSource *m.DataSource
  29. }
  30. type datasourceInfo struct {
  31. Profile string
  32. Region string
  33. AssumeRoleArn string
  34. Namespace string
  35. AccessKey string
  36. SecretKey string
  37. }
  38. func (req *cwRequest) GetDatasourceInfo() *datasourceInfo {
  39. assumeRoleArn := req.DataSource.JsonData.Get("assumeRoleArn").MustString()
  40. accessKey := ""
  41. secretKey := ""
  42. for key, value := range req.DataSource.SecureJsonData.Decrypt() {
  43. if key == "accessKey" {
  44. accessKey = value
  45. }
  46. if key == "secretKey" {
  47. secretKey = value
  48. }
  49. }
  50. return &datasourceInfo{
  51. AssumeRoleArn: assumeRoleArn,
  52. Region: req.Region,
  53. Profile: req.DataSource.Database,
  54. AccessKey: accessKey,
  55. SecretKey: secretKey,
  56. }
  57. }
  58. func init() {
  59. actionHandlers = map[string]actionHandler{
  60. "GetMetricStatistics": handleGetMetricStatistics,
  61. "ListMetrics": handleListMetrics,
  62. "DescribeAlarms": handleDescribeAlarms,
  63. "DescribeAlarmsForMetric": handleDescribeAlarmsForMetric,
  64. "DescribeAlarmHistory": handleDescribeAlarmHistory,
  65. "DescribeInstances": handleDescribeInstances,
  66. "__GetRegions": handleGetRegions,
  67. "__GetNamespaces": handleGetNamespaces,
  68. "__GetMetrics": handleGetMetrics,
  69. "__GetDimensions": handleGetDimensions,
  70. }
  71. }
  72. type cache struct {
  73. credential *credentials.Credentials
  74. expiration *time.Time
  75. }
  76. var awsCredentialCache map[string]cache = make(map[string]cache)
  77. var credentialCacheLock sync.RWMutex
  78. func getCredentials(dsInfo *datasourceInfo) (*credentials.Credentials, error) {
  79. cacheKey := dsInfo.Profile + ":" + dsInfo.AssumeRoleArn
  80. credentialCacheLock.RLock()
  81. if _, ok := awsCredentialCache[cacheKey]; ok {
  82. if awsCredentialCache[cacheKey].expiration != nil &&
  83. (*awsCredentialCache[cacheKey].expiration).After(time.Now().UTC()) {
  84. result := awsCredentialCache[cacheKey].credential
  85. credentialCacheLock.RUnlock()
  86. return result, nil
  87. }
  88. }
  89. credentialCacheLock.RUnlock()
  90. accessKeyId := ""
  91. secretAccessKey := ""
  92. sessionToken := ""
  93. var expiration *time.Time
  94. expiration = nil
  95. if strings.Index(dsInfo.AssumeRoleArn, "arn:aws:iam:") == 0 {
  96. params := &sts.AssumeRoleInput{
  97. RoleArn: aws.String(dsInfo.AssumeRoleArn),
  98. RoleSessionName: aws.String("GrafanaSession"),
  99. DurationSeconds: aws.Int64(900),
  100. }
  101. stsSess := session.New()
  102. stsCreds := credentials.NewChainCredentials(
  103. []credentials.Provider{
  104. &credentials.EnvProvider{},
  105. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  106. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(stsSess), ExpiryWindow: 5 * time.Minute},
  107. })
  108. stsConfig := &aws.Config{
  109. Region: aws.String(dsInfo.Region),
  110. Credentials: stsCreds,
  111. }
  112. svc := sts.New(session.New(stsConfig), stsConfig)
  113. resp, err := svc.AssumeRole(params)
  114. if err != nil {
  115. return nil, err
  116. }
  117. if resp.Credentials != nil {
  118. accessKeyId = *resp.Credentials.AccessKeyId
  119. secretAccessKey = *resp.Credentials.SecretAccessKey
  120. sessionToken = *resp.Credentials.SessionToken
  121. expiration = resp.Credentials.Expiration
  122. }
  123. }
  124. sess := session.New()
  125. creds := credentials.NewChainCredentials(
  126. []credentials.Provider{
  127. &credentials.StaticProvider{Value: credentials.Value{
  128. AccessKeyID: accessKeyId,
  129. SecretAccessKey: secretAccessKey,
  130. SessionToken: sessionToken,
  131. }},
  132. &credentials.EnvProvider{},
  133. &credentials.StaticProvider{Value: credentials.Value{
  134. AccessKeyID: dsInfo.AccessKey,
  135. SecretAccessKey: dsInfo.SecretKey,
  136. }},
  137. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  138. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(sess), ExpiryWindow: 5 * time.Minute},
  139. })
  140. credentialCacheLock.Lock()
  141. awsCredentialCache[cacheKey] = cache{
  142. credential: creds,
  143. expiration: expiration,
  144. }
  145. credentialCacheLock.Unlock()
  146. return creds, nil
  147. }
  148. func getAwsConfig(req *cwRequest) (*aws.Config, error) {
  149. creds, err := getCredentials(req.GetDatasourceInfo())
  150. if err != nil {
  151. return nil, err
  152. }
  153. cfg := &aws.Config{
  154. Region: aws.String(req.Region),
  155. Credentials: creds,
  156. }
  157. return cfg, nil
  158. }
  159. func handleGetMetricStatistics(req *cwRequest, c *middleware.Context) {
  160. cfg, err := getAwsConfig(req)
  161. if err != nil {
  162. c.JsonApiErr(500, "Unable to call AWS API", err)
  163. return
  164. }
  165. svc := cloudwatch.New(session.New(cfg), cfg)
  166. reqParam := &struct {
  167. Parameters struct {
  168. Namespace string `json:"namespace"`
  169. MetricName string `json:"metricName"`
  170. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  171. Statistics []*string `json:"statistics"`
  172. ExtendedStatistics []*string `json:"extendedStatistics"`
  173. StartTime int64 `json:"startTime"`
  174. EndTime int64 `json:"endTime"`
  175. Period int64 `json:"period"`
  176. } `json:"parameters"`
  177. }{}
  178. json.Unmarshal(req.Body, reqParam)
  179. params := &cloudwatch.GetMetricStatisticsInput{
  180. Namespace: aws.String(reqParam.Parameters.Namespace),
  181. MetricName: aws.String(reqParam.Parameters.MetricName),
  182. Dimensions: reqParam.Parameters.Dimensions,
  183. StartTime: aws.Time(time.Unix(reqParam.Parameters.StartTime, 0)),
  184. EndTime: aws.Time(time.Unix(reqParam.Parameters.EndTime, 0)),
  185. Period: aws.Int64(reqParam.Parameters.Period),
  186. }
  187. if len(reqParam.Parameters.Statistics) != 0 {
  188. params.Statistics = reqParam.Parameters.Statistics
  189. }
  190. if len(reqParam.Parameters.ExtendedStatistics) != 0 {
  191. params.ExtendedStatistics = reqParam.Parameters.ExtendedStatistics
  192. }
  193. resp, err := svc.GetMetricStatistics(params)
  194. if err != nil {
  195. c.JsonApiErr(500, "Unable to call AWS API", err)
  196. return
  197. }
  198. metrics.M_Aws_CloudWatch_GetMetricStatistics.Inc(1)
  199. c.JSON(200, resp)
  200. }
  201. func handleListMetrics(req *cwRequest, c *middleware.Context) {
  202. cfg, err := getAwsConfig(req)
  203. if err != nil {
  204. c.JsonApiErr(500, "Unable to call AWS API", err)
  205. return
  206. }
  207. svc := cloudwatch.New(session.New(cfg), cfg)
  208. reqParam := &struct {
  209. Parameters struct {
  210. Namespace string `json:"namespace"`
  211. MetricName string `json:"metricName"`
  212. Dimensions []*cloudwatch.DimensionFilter `json:"dimensions"`
  213. } `json:"parameters"`
  214. }{}
  215. json.Unmarshal(req.Body, reqParam)
  216. params := &cloudwatch.ListMetricsInput{
  217. Namespace: aws.String(reqParam.Parameters.Namespace),
  218. MetricName: aws.String(reqParam.Parameters.MetricName),
  219. Dimensions: reqParam.Parameters.Dimensions,
  220. }
  221. var resp cloudwatch.ListMetricsOutput
  222. err = svc.ListMetricsPages(params,
  223. func(page *cloudwatch.ListMetricsOutput, lastPage bool) bool {
  224. metrics.M_Aws_CloudWatch_ListMetrics.Inc(1)
  225. metrics, _ := awsutil.ValuesAtPath(page, "Metrics")
  226. for _, metric := range metrics {
  227. resp.Metrics = append(resp.Metrics, metric.(*cloudwatch.Metric))
  228. }
  229. return !lastPage
  230. })
  231. if err != nil {
  232. c.JsonApiErr(500, "Unable to call AWS API", err)
  233. return
  234. }
  235. c.JSON(200, resp)
  236. }
  237. func handleDescribeAlarms(req *cwRequest, c *middleware.Context) {
  238. cfg, err := getAwsConfig(req)
  239. if err != nil {
  240. c.JsonApiErr(500, "Unable to call AWS API", err)
  241. return
  242. }
  243. svc := cloudwatch.New(session.New(cfg), cfg)
  244. reqParam := &struct {
  245. Parameters struct {
  246. ActionPrefix string `json:"actionPrefix"`
  247. AlarmNamePrefix string `json:"alarmNamePrefix"`
  248. AlarmNames []*string `json:"alarmNames"`
  249. StateValue string `json:"stateValue"`
  250. } `json:"parameters"`
  251. }{}
  252. json.Unmarshal(req.Body, reqParam)
  253. params := &cloudwatch.DescribeAlarmsInput{
  254. MaxRecords: aws.Int64(100),
  255. }
  256. if reqParam.Parameters.ActionPrefix != "" {
  257. params.ActionPrefix = aws.String(reqParam.Parameters.ActionPrefix)
  258. }
  259. if reqParam.Parameters.AlarmNamePrefix != "" {
  260. params.AlarmNamePrefix = aws.String(reqParam.Parameters.AlarmNamePrefix)
  261. }
  262. if len(reqParam.Parameters.AlarmNames) != 0 {
  263. params.AlarmNames = reqParam.Parameters.AlarmNames
  264. }
  265. if reqParam.Parameters.StateValue != "" {
  266. params.StateValue = aws.String(reqParam.Parameters.StateValue)
  267. }
  268. resp, err := svc.DescribeAlarms(params)
  269. if err != nil {
  270. c.JsonApiErr(500, "Unable to call AWS API", err)
  271. return
  272. }
  273. c.JSON(200, resp)
  274. }
  275. func handleDescribeAlarmsForMetric(req *cwRequest, c *middleware.Context) {
  276. cfg, err := getAwsConfig(req)
  277. if err != nil {
  278. c.JsonApiErr(500, "Unable to call AWS API", err)
  279. return
  280. }
  281. svc := cloudwatch.New(session.New(cfg), cfg)
  282. reqParam := &struct {
  283. Parameters struct {
  284. Namespace string `json:"namespace"`
  285. MetricName string `json:"metricName"`
  286. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  287. Statistic string `json:"statistic"`
  288. ExtendedStatistic string `json:"extendedStatistic"`
  289. Period int64 `json:"period"`
  290. } `json:"parameters"`
  291. }{}
  292. json.Unmarshal(req.Body, reqParam)
  293. params := &cloudwatch.DescribeAlarmsForMetricInput{
  294. Namespace: aws.String(reqParam.Parameters.Namespace),
  295. MetricName: aws.String(reqParam.Parameters.MetricName),
  296. Period: aws.Int64(reqParam.Parameters.Period),
  297. }
  298. if len(reqParam.Parameters.Dimensions) != 0 {
  299. params.Dimensions = reqParam.Parameters.Dimensions
  300. }
  301. if reqParam.Parameters.Statistic != "" {
  302. params.Statistic = aws.String(reqParam.Parameters.Statistic)
  303. }
  304. if reqParam.Parameters.ExtendedStatistic != "" {
  305. params.ExtendedStatistic = aws.String(reqParam.Parameters.ExtendedStatistic)
  306. }
  307. resp, err := svc.DescribeAlarmsForMetric(params)
  308. if err != nil {
  309. c.JsonApiErr(500, "Unable to call AWS API", err)
  310. return
  311. }
  312. c.JSON(200, resp)
  313. }
  314. func handleDescribeAlarmHistory(req *cwRequest, c *middleware.Context) {
  315. cfg, err := getAwsConfig(req)
  316. if err != nil {
  317. c.JsonApiErr(500, "Unable to call AWS API", err)
  318. return
  319. }
  320. svc := cloudwatch.New(session.New(cfg), cfg)
  321. reqParam := &struct {
  322. Parameters struct {
  323. AlarmName string `json:"alarmName"`
  324. HistoryItemType string `json:"historyItemType"`
  325. StartDate int64 `json:"startDate"`
  326. EndDate int64 `json:"endDate"`
  327. } `json:"parameters"`
  328. }{}
  329. json.Unmarshal(req.Body, reqParam)
  330. params := &cloudwatch.DescribeAlarmHistoryInput{
  331. AlarmName: aws.String(reqParam.Parameters.AlarmName),
  332. StartDate: aws.Time(time.Unix(reqParam.Parameters.StartDate, 0)),
  333. EndDate: aws.Time(time.Unix(reqParam.Parameters.EndDate, 0)),
  334. }
  335. if reqParam.Parameters.HistoryItemType != "" {
  336. params.HistoryItemType = aws.String(reqParam.Parameters.HistoryItemType)
  337. }
  338. resp, err := svc.DescribeAlarmHistory(params)
  339. if err != nil {
  340. c.JsonApiErr(500, "Unable to call AWS API", err)
  341. return
  342. }
  343. c.JSON(200, resp)
  344. }
  345. func handleDescribeInstances(req *cwRequest, c *middleware.Context) {
  346. cfg, err := getAwsConfig(req)
  347. if err != nil {
  348. c.JsonApiErr(500, "Unable to call AWS API", err)
  349. return
  350. }
  351. svc := ec2.New(session.New(cfg), cfg)
  352. reqParam := &struct {
  353. Parameters struct {
  354. Filters []*ec2.Filter `json:"filters"`
  355. InstanceIds []*string `json:"instanceIds"`
  356. } `json:"parameters"`
  357. }{}
  358. json.Unmarshal(req.Body, reqParam)
  359. params := &ec2.DescribeInstancesInput{}
  360. if len(reqParam.Parameters.Filters) > 0 {
  361. params.Filters = reqParam.Parameters.Filters
  362. }
  363. if len(reqParam.Parameters.InstanceIds) > 0 {
  364. params.InstanceIds = reqParam.Parameters.InstanceIds
  365. }
  366. var resp ec2.DescribeInstancesOutput
  367. err = svc.DescribeInstancesPages(params,
  368. func(page *ec2.DescribeInstancesOutput, lastPage bool) bool {
  369. reservations, _ := awsutil.ValuesAtPath(page, "Reservations")
  370. for _, reservation := range reservations {
  371. resp.Reservations = append(resp.Reservations, reservation.(*ec2.Reservation))
  372. }
  373. return !lastPage
  374. })
  375. if err != nil {
  376. c.JsonApiErr(500, "Unable to call AWS API", err)
  377. return
  378. }
  379. c.JSON(200, resp)
  380. }
  381. func HandleRequest(c *middleware.Context, ds *m.DataSource) {
  382. var req cwRequest
  383. req.Body, _ = ioutil.ReadAll(c.Req.Request.Body)
  384. req.DataSource = ds
  385. json.Unmarshal(req.Body, &req)
  386. if handler, found := actionHandlers[req.Action]; !found {
  387. c.JsonApiErr(500, "Unexpected AWS Action", errors.New(req.Action))
  388. return
  389. } else {
  390. handler(&req, c)
  391. }
  392. }