cloudwatch.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406
  1. package cloudwatch
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "io/ioutil"
  6. "strings"
  7. "sync"
  8. "time"
  9. "github.com/aws/aws-sdk-go/aws"
  10. "github.com/aws/aws-sdk-go/aws/awsutil"
  11. "github.com/aws/aws-sdk-go/aws/credentials"
  12. "github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds"
  13. "github.com/aws/aws-sdk-go/aws/ec2metadata"
  14. "github.com/aws/aws-sdk-go/aws/session"
  15. "github.com/aws/aws-sdk-go/service/cloudwatch"
  16. "github.com/aws/aws-sdk-go/service/ec2"
  17. "github.com/aws/aws-sdk-go/service/sts"
  18. "github.com/grafana/grafana/pkg/log"
  19. "github.com/grafana/grafana/pkg/middleware"
  20. m "github.com/grafana/grafana/pkg/models"
  21. )
  22. type actionHandler func(*cwRequest, *middleware.Context)
  23. var actionHandlers map[string]actionHandler
  24. type cwRequest struct {
  25. Region string `json:"region"`
  26. Action string `json:"action"`
  27. Body []byte `json:"-"`
  28. DataSource *m.DataSource
  29. }
  30. type datasourceInfo struct {
  31. Profile string
  32. Region string
  33. AssumeRoleArn string
  34. Namespace string
  35. AccessKey string
  36. SecretKey string
  37. }
  38. func (req *cwRequest) GetDatasourceInfo() *datasourceInfo {
  39. assumeRoleArn := req.DataSource.JsonData.Get("assumeRoleArn").MustString()
  40. accessKey := ""
  41. secretKey := ""
  42. for key, value := range req.DataSource.SecureJsonData.Decrypt() {
  43. if key == "accessKey" {
  44. accessKey = value
  45. }
  46. if key == "secretKey" {
  47. secretKey = value
  48. }
  49. }
  50. return &datasourceInfo{
  51. AssumeRoleArn: assumeRoleArn,
  52. Region: req.Region,
  53. Profile: req.DataSource.Database,
  54. AccessKey: accessKey,
  55. SecretKey: secretKey,
  56. }
  57. }
  58. func init() {
  59. actionHandlers = map[string]actionHandler{
  60. "GetMetricStatistics": handleGetMetricStatistics,
  61. "ListMetrics": handleListMetrics,
  62. "DescribeAlarms": handleDescribeAlarms,
  63. "DescribeAlarmsForMetric": handleDescribeAlarmsForMetric,
  64. "DescribeAlarmHistory": handleDescribeAlarmHistory,
  65. "DescribeInstances": handleDescribeInstances,
  66. "__GetRegions": handleGetRegions,
  67. "__GetNamespaces": handleGetNamespaces,
  68. "__GetMetrics": handleGetMetrics,
  69. "__GetDimensions": handleGetDimensions,
  70. }
  71. }
  72. type cache struct {
  73. credential *credentials.Credentials
  74. expiration *time.Time
  75. }
  76. var awsCredentialCache map[string]cache = make(map[string]cache)
  77. var credentialCacheLock sync.RWMutex
  78. func getCredentials(dsInfo *datasourceInfo) *credentials.Credentials {
  79. cacheKey := dsInfo.Profile + ":" + dsInfo.AssumeRoleArn
  80. credentialCacheLock.RLock()
  81. if _, ok := awsCredentialCache[cacheKey]; ok {
  82. if awsCredentialCache[cacheKey].expiration != nil &&
  83. (*awsCredentialCache[cacheKey].expiration).After(time.Now().UTC()) {
  84. result := awsCredentialCache[cacheKey].credential
  85. credentialCacheLock.RUnlock()
  86. return result
  87. }
  88. }
  89. credentialCacheLock.RUnlock()
  90. accessKeyId := ""
  91. secretAccessKey := ""
  92. sessionToken := ""
  93. var expiration *time.Time
  94. expiration = nil
  95. if strings.Index(dsInfo.AssumeRoleArn, "arn:aws:iam:") == 0 {
  96. params := &sts.AssumeRoleInput{
  97. RoleArn: aws.String(dsInfo.AssumeRoleArn),
  98. RoleSessionName: aws.String("GrafanaSession"),
  99. DurationSeconds: aws.Int64(900),
  100. }
  101. stsSess := session.New()
  102. stsCreds := credentials.NewChainCredentials(
  103. []credentials.Provider{
  104. &credentials.EnvProvider{},
  105. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  106. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(stsSess), ExpiryWindow: 5 * time.Minute},
  107. })
  108. stsConfig := &aws.Config{
  109. Region: aws.String(dsInfo.Region),
  110. Credentials: stsCreds,
  111. }
  112. svc := sts.New(session.New(stsConfig), stsConfig)
  113. resp, err := svc.AssumeRole(params)
  114. if err != nil {
  115. // ignore
  116. log.Error(3, "CloudWatch: Failed to assume role", err)
  117. }
  118. if resp.Credentials != nil {
  119. accessKeyId = *resp.Credentials.AccessKeyId
  120. secretAccessKey = *resp.Credentials.SecretAccessKey
  121. sessionToken = *resp.Credentials.SessionToken
  122. expiration = resp.Credentials.Expiration
  123. }
  124. }
  125. sess := session.New()
  126. creds := credentials.NewChainCredentials(
  127. []credentials.Provider{
  128. &credentials.StaticProvider{Value: credentials.Value{
  129. AccessKeyID: accessKeyId,
  130. SecretAccessKey: secretAccessKey,
  131. SessionToken: sessionToken,
  132. }},
  133. &credentials.EnvProvider{},
  134. &credentials.StaticProvider{Value: credentials.Value{
  135. AccessKeyID: dsInfo.AccessKey,
  136. SecretAccessKey: dsInfo.SecretKey,
  137. }},
  138. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  139. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(sess), ExpiryWindow: 5 * time.Minute},
  140. })
  141. credentialCacheLock.Lock()
  142. awsCredentialCache[cacheKey] = cache{
  143. credential: creds,
  144. expiration: expiration,
  145. }
  146. credentialCacheLock.Unlock()
  147. return creds
  148. }
  149. func getAwsConfig(req *cwRequest) *aws.Config {
  150. cfg := &aws.Config{
  151. Region: aws.String(req.Region),
  152. Credentials: getCredentials(req.GetDatasourceInfo()),
  153. }
  154. return cfg
  155. }
  156. func handleGetMetricStatistics(req *cwRequest, c *middleware.Context) {
  157. cfg := getAwsConfig(req)
  158. svc := cloudwatch.New(session.New(cfg), cfg)
  159. reqParam := &struct {
  160. Parameters struct {
  161. Namespace string `json:"namespace"`
  162. MetricName string `json:"metricName"`
  163. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  164. Statistics []*string `json:"statistics"`
  165. StartTime int64 `json:"startTime"`
  166. EndTime int64 `json:"endTime"`
  167. Period int64 `json:"period"`
  168. } `json:"parameters"`
  169. }{}
  170. json.Unmarshal(req.Body, reqParam)
  171. params := &cloudwatch.GetMetricStatisticsInput{
  172. Namespace: aws.String(reqParam.Parameters.Namespace),
  173. MetricName: aws.String(reqParam.Parameters.MetricName),
  174. Dimensions: reqParam.Parameters.Dimensions,
  175. Statistics: reqParam.Parameters.Statistics,
  176. StartTime: aws.Time(time.Unix(reqParam.Parameters.StartTime, 0)),
  177. EndTime: aws.Time(time.Unix(reqParam.Parameters.EndTime, 0)),
  178. Period: aws.Int64(reqParam.Parameters.Period),
  179. }
  180. resp, err := svc.GetMetricStatistics(params)
  181. if err != nil {
  182. c.JsonApiErr(500, "Unable to call AWS API", err)
  183. return
  184. }
  185. c.JSON(200, resp)
  186. }
  187. func handleListMetrics(req *cwRequest, c *middleware.Context) {
  188. cfg := getAwsConfig(req)
  189. svc := cloudwatch.New(session.New(cfg), cfg)
  190. reqParam := &struct {
  191. Parameters struct {
  192. Namespace string `json:"namespace"`
  193. MetricName string `json:"metricName"`
  194. Dimensions []*cloudwatch.DimensionFilter `json:"dimensions"`
  195. } `json:"parameters"`
  196. }{}
  197. json.Unmarshal(req.Body, reqParam)
  198. params := &cloudwatch.ListMetricsInput{
  199. Namespace: aws.String(reqParam.Parameters.Namespace),
  200. MetricName: aws.String(reqParam.Parameters.MetricName),
  201. Dimensions: reqParam.Parameters.Dimensions,
  202. }
  203. var resp cloudwatch.ListMetricsOutput
  204. err := svc.ListMetricsPages(params,
  205. func(page *cloudwatch.ListMetricsOutput, lastPage bool) bool {
  206. metrics, _ := awsutil.ValuesAtPath(page, "Metrics")
  207. for _, metric := range metrics {
  208. resp.Metrics = append(resp.Metrics, metric.(*cloudwatch.Metric))
  209. }
  210. return !lastPage
  211. })
  212. if err != nil {
  213. c.JsonApiErr(500, "Unable to call AWS API", err)
  214. return
  215. }
  216. c.JSON(200, resp)
  217. }
  218. func handleDescribeAlarms(req *cwRequest, c *middleware.Context) {
  219. cfg := getAwsConfig(req)
  220. svc := cloudwatch.New(session.New(cfg), cfg)
  221. reqParam := &struct {
  222. Parameters struct {
  223. ActionPrefix string `json:"actionPrefix"`
  224. AlarmNamePrefix string `json:"alarmNamePrefix"`
  225. AlarmNames []*string `json:"alarmNames"`
  226. StateValue string `json:"stateValue"`
  227. } `json:"parameters"`
  228. }{}
  229. json.Unmarshal(req.Body, reqParam)
  230. params := &cloudwatch.DescribeAlarmsInput{
  231. MaxRecords: aws.Int64(100),
  232. }
  233. if reqParam.Parameters.ActionPrefix != "" {
  234. params.ActionPrefix = aws.String(reqParam.Parameters.ActionPrefix)
  235. }
  236. if reqParam.Parameters.AlarmNamePrefix != "" {
  237. params.AlarmNamePrefix = aws.String(reqParam.Parameters.AlarmNamePrefix)
  238. }
  239. if len(reqParam.Parameters.AlarmNames) != 0 {
  240. params.AlarmNames = reqParam.Parameters.AlarmNames
  241. }
  242. if reqParam.Parameters.StateValue != "" {
  243. params.StateValue = aws.String(reqParam.Parameters.StateValue)
  244. }
  245. resp, err := svc.DescribeAlarms(params)
  246. if err != nil {
  247. c.JsonApiErr(500, "Unable to call AWS API", err)
  248. return
  249. }
  250. c.JSON(200, resp)
  251. }
  252. func handleDescribeAlarmsForMetric(req *cwRequest, c *middleware.Context) {
  253. cfg := getAwsConfig(req)
  254. svc := cloudwatch.New(session.New(cfg), cfg)
  255. reqParam := &struct {
  256. Parameters struct {
  257. Namespace string `json:"namespace"`
  258. MetricName string `json:"metricName"`
  259. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  260. Statistic string `json:"statistic"`
  261. Period int64 `json:"period"`
  262. } `json:"parameters"`
  263. }{}
  264. json.Unmarshal(req.Body, reqParam)
  265. params := &cloudwatch.DescribeAlarmsForMetricInput{
  266. Namespace: aws.String(reqParam.Parameters.Namespace),
  267. MetricName: aws.String(reqParam.Parameters.MetricName),
  268. Period: aws.Int64(reqParam.Parameters.Period),
  269. }
  270. if len(reqParam.Parameters.Dimensions) != 0 {
  271. params.Dimensions = reqParam.Parameters.Dimensions
  272. }
  273. if reqParam.Parameters.Statistic != "" {
  274. params.Statistic = aws.String(reqParam.Parameters.Statistic)
  275. }
  276. resp, err := svc.DescribeAlarmsForMetric(params)
  277. if err != nil {
  278. c.JsonApiErr(500, "Unable to call AWS API", err)
  279. return
  280. }
  281. c.JSON(200, resp)
  282. }
  283. func handleDescribeAlarmHistory(req *cwRequest, c *middleware.Context) {
  284. cfg := getAwsConfig(req)
  285. svc := cloudwatch.New(session.New(cfg), cfg)
  286. reqParam := &struct {
  287. Parameters struct {
  288. AlarmName string `json:"alarmName"`
  289. HistoryItemType string `json:"historyItemType"`
  290. StartDate int64 `json:"startDate"`
  291. EndDate int64 `json:"endDate"`
  292. } `json:"parameters"`
  293. }{}
  294. json.Unmarshal(req.Body, reqParam)
  295. params := &cloudwatch.DescribeAlarmHistoryInput{
  296. AlarmName: aws.String(reqParam.Parameters.AlarmName),
  297. StartDate: aws.Time(time.Unix(reqParam.Parameters.StartDate, 0)),
  298. EndDate: aws.Time(time.Unix(reqParam.Parameters.EndDate, 0)),
  299. }
  300. if reqParam.Parameters.HistoryItemType != "" {
  301. params.HistoryItemType = aws.String(reqParam.Parameters.HistoryItemType)
  302. }
  303. resp, err := svc.DescribeAlarmHistory(params)
  304. if err != nil {
  305. c.JsonApiErr(500, "Unable to call AWS API", err)
  306. return
  307. }
  308. c.JSON(200, resp)
  309. }
  310. func handleDescribeInstances(req *cwRequest, c *middleware.Context) {
  311. cfg := getAwsConfig(req)
  312. svc := ec2.New(session.New(cfg), cfg)
  313. reqParam := &struct {
  314. Parameters struct {
  315. Filters []*ec2.Filter `json:"filters"`
  316. InstanceIds []*string `json:"instanceIds"`
  317. } `json:"parameters"`
  318. }{}
  319. json.Unmarshal(req.Body, reqParam)
  320. params := &ec2.DescribeInstancesInput{}
  321. if len(reqParam.Parameters.Filters) > 0 {
  322. params.Filters = reqParam.Parameters.Filters
  323. }
  324. if len(reqParam.Parameters.InstanceIds) > 0 {
  325. params.InstanceIds = reqParam.Parameters.InstanceIds
  326. }
  327. var resp ec2.DescribeInstancesOutput
  328. err := svc.DescribeInstancesPages(params,
  329. func(page *ec2.DescribeInstancesOutput, lastPage bool) bool {
  330. reservations, _ := awsutil.ValuesAtPath(page, "Reservations")
  331. for _, reservation := range reservations {
  332. resp.Reservations = append(resp.Reservations, reservation.(*ec2.Reservation))
  333. }
  334. return !lastPage
  335. })
  336. if err != nil {
  337. c.JsonApiErr(500, "Unable to call AWS API", err)
  338. return
  339. }
  340. c.JSON(200, resp)
  341. }
  342. func HandleRequest(c *middleware.Context, ds *m.DataSource) {
  343. var req cwRequest
  344. req.Body, _ = ioutil.ReadAll(c.Req.Request.Body)
  345. req.DataSource = ds
  346. json.Unmarshal(req.Body, &req)
  347. if handler, found := actionHandlers[req.Action]; !found {
  348. c.JsonApiErr(500, "Unexpected AWS Action", errors.New(req.Action))
  349. return
  350. } else {
  351. handler(&req, c)
  352. }
  353. }