Secure socks proxy: use Grafana Plugin SDK (#71616)

This commit is contained in:
Stephanie Hingtgen
2023-07-18 15:23:02 -06:00
committed by GitHub
parent 600f623610
commit 4ece133fce
18 changed files with 101 additions and 226 deletions
+5 -2
View File
@@ -16,6 +16,7 @@ import (
"github.com/grafana/grafana-plugin-sdk-go/backend"
"github.com/grafana/grafana-plugin-sdk-go/backend/datasource"
"github.com/grafana/grafana-plugin-sdk-go/backend/instancemgmt"
sdkproxy "github.com/grafana/grafana-plugin-sdk-go/backend/proxy"
"github.com/grafana/grafana-plugin-sdk-go/data"
"github.com/grafana/grafana-plugin-sdk-go/data/sqlutil"
@@ -23,6 +24,7 @@ import (
"github.com/grafana/grafana/pkg/infra/log"
"github.com/grafana/grafana/pkg/setting"
"github.com/grafana/grafana/pkg/tsdb/sqleng"
"github.com/grafana/grafana/pkg/tsdb/sqleng/proxyutil"
)
const (
@@ -85,10 +87,11 @@ func newInstanceSettings(cfg *setting.Cfg, httpClientProvider httpclient.Provide
}
// register the secure socks proxy dialer context, if enabled
if cfg.SecureSocksDSProxy.Enabled && jsonData.SecureDSProxy {
proxyOpts := proxyutil.GetSQLProxyOptions(dsInfo)
if sdkproxy.Cli.SecureSocksProxyEnabled(proxyOpts) {
// UID is only unique per org, the only way to ensure uniqueness is to do it by connection information
uniqueIdentifier := dsInfo.User + dsInfo.DecryptedSecureJSONData["password"] + dsInfo.URL + dsInfo.Database
protocol, err = registerProxyDialerContext(&cfg.SecureSocksDSProxy, protocol, uniqueIdentifier)
protocol, err = registerProxyDialerContext(protocol, uniqueIdentifier, proxyOpts)
if err != nil {
return nil, err
}
+5 -6
View File
@@ -5,17 +5,16 @@ import (
"net"
"github.com/go-sql-driver/mysql"
iproxy "github.com/grafana/grafana/pkg/infra/proxy"
"github.com/grafana/grafana/pkg/setting"
sdkproxy "github.com/grafana/grafana-plugin-sdk-go/backend/proxy"
"github.com/grafana/grafana/pkg/util"
"golang.org/x/net/proxy"
)
// registerProxyDialerContext registers a new dialer context to be used by mysql when the proxy network is
// specified in the connection string
func registerProxyDialerContext(settings *setting.SecureSocksDSProxySettings, protocol, cnnstr string) (string, error) {
func registerProxyDialerContext(protocol, cnnstr string, opts *sdkproxy.Options) (string, error) {
// the dialer contains the true network used behind the scenes
dialer, err := getProxyDialerContext(settings, protocol)
dialer, err := getProxyDialerContext(protocol, opts)
if err != nil {
return "", err
}
@@ -39,8 +38,8 @@ type mySQLContextDialer struct {
}
// getProxyDialerContext returns a context dialer that will send the request through to the secure socks proxy
func getProxyDialerContext(cfg *setting.SecureSocksDSProxySettings, actualNetwork string) (*mySQLContextDialer, error) {
dialer, err := iproxy.NewSecureSocksProxyContextDialer(cfg)
func getProxyDialerContext(actualNetwork string, opts *sdkproxy.Options) (*mySQLContextDialer, error) {
dialer, err := sdkproxy.Cli.NewSecureSocksProxyContextDialer(opts)
if err != nil {
return nil, err
}
+6 -4
View File
@@ -6,7 +6,8 @@ import (
"testing"
"github.com/go-sql-driver/mysql"
"github.com/grafana/grafana/pkg/infra/proxy/proxyutil"
"github.com/grafana/grafana/pkg/tsdb/sqleng"
"github.com/grafana/grafana/pkg/tsdb/sqleng/proxyutil"
"github.com/stretchr/testify/require"
)
@@ -14,10 +15,11 @@ func TestMySQLProxyDialer(t *testing.T) {
settings := proxyutil.SetupTestSecureSocksProxySettings(t)
protocol := "tcp"
network, err := registerProxyDialerContext(settings, protocol, "1")
opts := proxyutil.GetSQLProxyOptions(sqleng.DataSourceInfo{UID: "1", JsonData: sqleng.JsonData{SecureDSProxy: true}})
dbURL := "localhost:5432"
network, err := registerProxyDialerContext(protocol, dbURL, opts)
require.NoError(t, err)
driver := mysql.MySQLDriver{}
dbURL := "localhost:5432"
cnnstr := fmt.Sprintf("test:test@%s(%s)/db",
network,
dbURL,
@@ -28,7 +30,7 @@ func TestMySQLProxyDialer(t *testing.T) {
})
t.Run("Multiple networks can be created", func(t *testing.T) {
network, err := registerProxyDialerContext(settings, protocol, "2")
network, err := registerProxyDialerContext(protocol, dbURL, opts)
require.NoError(t, err)
cnnstr2 := fmt.Sprintf("test:test@%s(%s)/db",
network,