cloudwatch.go 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416
  1. package cloudwatch
  2. import (
  3. "encoding/json"
  4. "errors"
  5. "io/ioutil"
  6. "strings"
  7. "sync"
  8. "time"
  9. "github.com/aws/aws-sdk-go/aws"
  10. "github.com/aws/aws-sdk-go/aws/awsutil"
  11. "github.com/aws/aws-sdk-go/aws/credentials"
  12. "github.com/aws/aws-sdk-go/aws/credentials/ec2rolecreds"
  13. "github.com/aws/aws-sdk-go/aws/ec2metadata"
  14. "github.com/aws/aws-sdk-go/aws/session"
  15. "github.com/aws/aws-sdk-go/service/cloudwatch"
  16. "github.com/aws/aws-sdk-go/service/ec2"
  17. "github.com/aws/aws-sdk-go/service/sts"
  18. "github.com/grafana/grafana/pkg/log"
  19. "github.com/grafana/grafana/pkg/middleware"
  20. m "github.com/grafana/grafana/pkg/models"
  21. )
  22. type actionHandler func(*cwRequest, *middleware.Context)
  23. var actionHandlers map[string]actionHandler
  24. type cwRequest struct {
  25. Region string `json:"region"`
  26. Action string `json:"action"`
  27. Body []byte `json:"-"`
  28. DataSource *m.DataSource
  29. }
  30. type datasourceInfo struct {
  31. Profile string
  32. Region string
  33. AssumeRoleArn string
  34. Namespace string
  35. AccessKey string
  36. SecretKey string
  37. }
  38. func (req *cwRequest) GetDatasourceInfo() *datasourceInfo {
  39. assumeRoleArn := req.DataSource.JsonData.Get("assumeRoleArn").MustString()
  40. accessKey := ""
  41. secretKey := ""
  42. for key, value := range req.DataSource.SecureJsonData.Decrypt() {
  43. if key == "accessKey" {
  44. accessKey = value
  45. }
  46. if key == "secretKey" {
  47. secretKey = value
  48. }
  49. }
  50. return &datasourceInfo{
  51. AssumeRoleArn: assumeRoleArn,
  52. Region: req.Region,
  53. Profile: req.DataSource.Database,
  54. AccessKey: accessKey,
  55. SecretKey: secretKey,
  56. }
  57. }
  58. func init() {
  59. actionHandlers = map[string]actionHandler{
  60. "GetMetricStatistics": handleGetMetricStatistics,
  61. "ListMetrics": handleListMetrics,
  62. "DescribeAlarms": handleDescribeAlarms,
  63. "DescribeAlarmsForMetric": handleDescribeAlarmsForMetric,
  64. "DescribeAlarmHistory": handleDescribeAlarmHistory,
  65. "DescribeInstances": handleDescribeInstances,
  66. "__GetRegions": handleGetRegions,
  67. "__GetNamespaces": handleGetNamespaces,
  68. "__GetMetrics": handleGetMetrics,
  69. "__GetDimensions": handleGetDimensions,
  70. }
  71. }
  72. type cache struct {
  73. credential *credentials.Credentials
  74. expiration *time.Time
  75. }
  76. var awsCredentialCache map[string]cache = make(map[string]cache)
  77. var credentialCacheLock sync.RWMutex
  78. func getCredentials(dsInfo *datasourceInfo) *credentials.Credentials {
  79. cacheKey := dsInfo.Profile + ":" + dsInfo.AssumeRoleArn
  80. credentialCacheLock.RLock()
  81. if _, ok := awsCredentialCache[cacheKey]; ok {
  82. if awsCredentialCache[cacheKey].expiration != nil &&
  83. (*awsCredentialCache[cacheKey].expiration).After(time.Now().UTC()) {
  84. result := awsCredentialCache[cacheKey].credential
  85. credentialCacheLock.RUnlock()
  86. return result
  87. }
  88. }
  89. credentialCacheLock.RUnlock()
  90. accessKeyId := ""
  91. secretAccessKey := ""
  92. sessionToken := ""
  93. var expiration *time.Time
  94. expiration = nil
  95. if strings.Index(dsInfo.AssumeRoleArn, "arn:aws:iam:") == 0 {
  96. params := &sts.AssumeRoleInput{
  97. RoleArn: aws.String(dsInfo.AssumeRoleArn),
  98. RoleSessionName: aws.String("GrafanaSession"),
  99. DurationSeconds: aws.Int64(900),
  100. }
  101. stsSess := session.New()
  102. stsCreds := credentials.NewChainCredentials(
  103. []credentials.Provider{
  104. &credentials.EnvProvider{},
  105. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  106. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(stsSess), ExpiryWindow: 5 * time.Minute},
  107. })
  108. stsConfig := &aws.Config{
  109. Region: aws.String(dsInfo.Region),
  110. Credentials: stsCreds,
  111. }
  112. svc := sts.New(session.New(stsConfig), stsConfig)
  113. resp, err := svc.AssumeRole(params)
  114. if err != nil {
  115. // ignore
  116. log.Error(3, "CloudWatch: Failed to assume role", err)
  117. }
  118. if resp.Credentials != nil {
  119. accessKeyId = *resp.Credentials.AccessKeyId
  120. secretAccessKey = *resp.Credentials.SecretAccessKey
  121. sessionToken = *resp.Credentials.SessionToken
  122. expiration = resp.Credentials.Expiration
  123. }
  124. }
  125. sess := session.New()
  126. creds := credentials.NewChainCredentials(
  127. []credentials.Provider{
  128. &credentials.StaticProvider{Value: credentials.Value{
  129. AccessKeyID: accessKeyId,
  130. SecretAccessKey: secretAccessKey,
  131. SessionToken: sessionToken,
  132. }},
  133. &credentials.EnvProvider{},
  134. &credentials.StaticProvider{Value: credentials.Value{
  135. AccessKeyID: dsInfo.AccessKey,
  136. SecretAccessKey: dsInfo.SecretKey,
  137. }},
  138. &credentials.SharedCredentialsProvider{Filename: "", Profile: dsInfo.Profile},
  139. &ec2rolecreds.EC2RoleProvider{Client: ec2metadata.New(sess), ExpiryWindow: 5 * time.Minute},
  140. })
  141. credentialCacheLock.Lock()
  142. awsCredentialCache[cacheKey] = cache{
  143. credential: creds,
  144. expiration: expiration,
  145. }
  146. credentialCacheLock.Unlock()
  147. return creds
  148. }
  149. func getAwsConfig(req *cwRequest) *aws.Config {
  150. cfg := &aws.Config{
  151. Region: aws.String(req.Region),
  152. Credentials: getCredentials(req.GetDatasourceInfo()),
  153. }
  154. return cfg
  155. }
  156. func handleGetMetricStatistics(req *cwRequest, c *middleware.Context) {
  157. cfg := getAwsConfig(req)
  158. svc := cloudwatch.New(session.New(cfg), cfg)
  159. reqParam := &struct {
  160. Parameters struct {
  161. Namespace string `json:"namespace"`
  162. MetricName string `json:"metricName"`
  163. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  164. Statistics []*string `json:"statistics"`
  165. ExtendedStatistics []*string `json:"extendedStatistics"`
  166. StartTime int64 `json:"startTime"`
  167. EndTime int64 `json:"endTime"`
  168. Period int64 `json:"period"`
  169. } `json:"parameters"`
  170. }{}
  171. json.Unmarshal(req.Body, reqParam)
  172. params := &cloudwatch.GetMetricStatisticsInput{
  173. Namespace: aws.String(reqParam.Parameters.Namespace),
  174. MetricName: aws.String(reqParam.Parameters.MetricName),
  175. Dimensions: reqParam.Parameters.Dimensions,
  176. StartTime: aws.Time(time.Unix(reqParam.Parameters.StartTime, 0)),
  177. EndTime: aws.Time(time.Unix(reqParam.Parameters.EndTime, 0)),
  178. Period: aws.Int64(reqParam.Parameters.Period),
  179. }
  180. if len(reqParam.Parameters.Statistics) != 0 {
  181. params.Statistics = reqParam.Parameters.Statistics
  182. }
  183. if len(reqParam.Parameters.ExtendedStatistics) != 0 {
  184. params.ExtendedStatistics = reqParam.Parameters.ExtendedStatistics
  185. }
  186. resp, err := svc.GetMetricStatistics(params)
  187. if err != nil {
  188. c.JsonApiErr(500, "Unable to call AWS API", err)
  189. return
  190. }
  191. c.JSON(200, resp)
  192. }
  193. func handleListMetrics(req *cwRequest, c *middleware.Context) {
  194. cfg := getAwsConfig(req)
  195. svc := cloudwatch.New(session.New(cfg), cfg)
  196. reqParam := &struct {
  197. Parameters struct {
  198. Namespace string `json:"namespace"`
  199. MetricName string `json:"metricName"`
  200. Dimensions []*cloudwatch.DimensionFilter `json:"dimensions"`
  201. } `json:"parameters"`
  202. }{}
  203. json.Unmarshal(req.Body, reqParam)
  204. params := &cloudwatch.ListMetricsInput{
  205. Namespace: aws.String(reqParam.Parameters.Namespace),
  206. MetricName: aws.String(reqParam.Parameters.MetricName),
  207. Dimensions: reqParam.Parameters.Dimensions,
  208. }
  209. var resp cloudwatch.ListMetricsOutput
  210. err := svc.ListMetricsPages(params,
  211. func(page *cloudwatch.ListMetricsOutput, lastPage bool) bool {
  212. metrics, _ := awsutil.ValuesAtPath(page, "Metrics")
  213. for _, metric := range metrics {
  214. resp.Metrics = append(resp.Metrics, metric.(*cloudwatch.Metric))
  215. }
  216. return !lastPage
  217. })
  218. if err != nil {
  219. c.JsonApiErr(500, "Unable to call AWS API", err)
  220. return
  221. }
  222. c.JSON(200, resp)
  223. }
  224. func handleDescribeAlarms(req *cwRequest, c *middleware.Context) {
  225. cfg := getAwsConfig(req)
  226. svc := cloudwatch.New(session.New(cfg), cfg)
  227. reqParam := &struct {
  228. Parameters struct {
  229. ActionPrefix string `json:"actionPrefix"`
  230. AlarmNamePrefix string `json:"alarmNamePrefix"`
  231. AlarmNames []*string `json:"alarmNames"`
  232. StateValue string `json:"stateValue"`
  233. } `json:"parameters"`
  234. }{}
  235. json.Unmarshal(req.Body, reqParam)
  236. params := &cloudwatch.DescribeAlarmsInput{
  237. MaxRecords: aws.Int64(100),
  238. }
  239. if reqParam.Parameters.ActionPrefix != "" {
  240. params.ActionPrefix = aws.String(reqParam.Parameters.ActionPrefix)
  241. }
  242. if reqParam.Parameters.AlarmNamePrefix != "" {
  243. params.AlarmNamePrefix = aws.String(reqParam.Parameters.AlarmNamePrefix)
  244. }
  245. if len(reqParam.Parameters.AlarmNames) != 0 {
  246. params.AlarmNames = reqParam.Parameters.AlarmNames
  247. }
  248. if reqParam.Parameters.StateValue != "" {
  249. params.StateValue = aws.String(reqParam.Parameters.StateValue)
  250. }
  251. resp, err := svc.DescribeAlarms(params)
  252. if err != nil {
  253. c.JsonApiErr(500, "Unable to call AWS API", err)
  254. return
  255. }
  256. c.JSON(200, resp)
  257. }
  258. func handleDescribeAlarmsForMetric(req *cwRequest, c *middleware.Context) {
  259. cfg := getAwsConfig(req)
  260. svc := cloudwatch.New(session.New(cfg), cfg)
  261. reqParam := &struct {
  262. Parameters struct {
  263. Namespace string `json:"namespace"`
  264. MetricName string `json:"metricName"`
  265. Dimensions []*cloudwatch.Dimension `json:"dimensions"`
  266. Statistic string `json:"statistic"`
  267. ExtendedStatistic string `json:"extendedStatistic"`
  268. Period int64 `json:"period"`
  269. } `json:"parameters"`
  270. }{}
  271. json.Unmarshal(req.Body, reqParam)
  272. params := &cloudwatch.DescribeAlarmsForMetricInput{
  273. Namespace: aws.String(reqParam.Parameters.Namespace),
  274. MetricName: aws.String(reqParam.Parameters.MetricName),
  275. Period: aws.Int64(reqParam.Parameters.Period),
  276. }
  277. if len(reqParam.Parameters.Dimensions) != 0 {
  278. params.Dimensions = reqParam.Parameters.Dimensions
  279. }
  280. if reqParam.Parameters.Statistic != "" {
  281. params.Statistic = aws.String(reqParam.Parameters.Statistic)
  282. }
  283. if reqParam.Parameters.ExtendedStatistic != "" {
  284. params.ExtendedStatistic = aws.String(reqParam.Parameters.ExtendedStatistic)
  285. }
  286. resp, err := svc.DescribeAlarmsForMetric(params)
  287. if err != nil {
  288. c.JsonApiErr(500, "Unable to call AWS API", err)
  289. return
  290. }
  291. c.JSON(200, resp)
  292. }
  293. func handleDescribeAlarmHistory(req *cwRequest, c *middleware.Context) {
  294. cfg := getAwsConfig(req)
  295. svc := cloudwatch.New(session.New(cfg), cfg)
  296. reqParam := &struct {
  297. Parameters struct {
  298. AlarmName string `json:"alarmName"`
  299. HistoryItemType string `json:"historyItemType"`
  300. StartDate int64 `json:"startDate"`
  301. EndDate int64 `json:"endDate"`
  302. } `json:"parameters"`
  303. }{}
  304. json.Unmarshal(req.Body, reqParam)
  305. params := &cloudwatch.DescribeAlarmHistoryInput{
  306. AlarmName: aws.String(reqParam.Parameters.AlarmName),
  307. StartDate: aws.Time(time.Unix(reqParam.Parameters.StartDate, 0)),
  308. EndDate: aws.Time(time.Unix(reqParam.Parameters.EndDate, 0)),
  309. }
  310. if reqParam.Parameters.HistoryItemType != "" {
  311. params.HistoryItemType = aws.String(reqParam.Parameters.HistoryItemType)
  312. }
  313. resp, err := svc.DescribeAlarmHistory(params)
  314. if err != nil {
  315. c.JsonApiErr(500, "Unable to call AWS API", err)
  316. return
  317. }
  318. c.JSON(200, resp)
  319. }
  320. func handleDescribeInstances(req *cwRequest, c *middleware.Context) {
  321. cfg := getAwsConfig(req)
  322. svc := ec2.New(session.New(cfg), cfg)
  323. reqParam := &struct {
  324. Parameters struct {
  325. Filters []*ec2.Filter `json:"filters"`
  326. InstanceIds []*string `json:"instanceIds"`
  327. } `json:"parameters"`
  328. }{}
  329. json.Unmarshal(req.Body, reqParam)
  330. params := &ec2.DescribeInstancesInput{}
  331. if len(reqParam.Parameters.Filters) > 0 {
  332. params.Filters = reqParam.Parameters.Filters
  333. }
  334. if len(reqParam.Parameters.InstanceIds) > 0 {
  335. params.InstanceIds = reqParam.Parameters.InstanceIds
  336. }
  337. var resp ec2.DescribeInstancesOutput
  338. err := svc.DescribeInstancesPages(params,
  339. func(page *ec2.DescribeInstancesOutput, lastPage bool) bool {
  340. reservations, _ := awsutil.ValuesAtPath(page, "Reservations")
  341. for _, reservation := range reservations {
  342. resp.Reservations = append(resp.Reservations, reservation.(*ec2.Reservation))
  343. }
  344. return !lastPage
  345. })
  346. if err != nil {
  347. c.JsonApiErr(500, "Unable to call AWS API", err)
  348. return
  349. }
  350. c.JSON(200, resp)
  351. }
  352. func HandleRequest(c *middleware.Context, ds *m.DataSource) {
  353. var req cwRequest
  354. req.Body, _ = ioutil.ReadAll(c.Req.Request.Body)
  355. req.DataSource = ds
  356. json.Unmarshal(req.Body, &req)
  357. if handler, found := actionHandlers[req.Action]; !found {
  358. c.JsonApiErr(500, "Unexpected AWS Action", errors.New(req.Action))
  359. return
  360. } else {
  361. handler(&req, c)
  362. }
  363. }