| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | /* | 
					
						
							| 
									
										
										
										
											2020-03-18 07:37:28 +08:00
										 |  |  |  * MinIO Cloud Storage, (C) 2017-2020 MinIO, Inc. | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  |  * | 
					
						
							|  |  |  |  * Licensed under the Apache License, Version 2.0 (the "License"); | 
					
						
							|  |  |  |  * you may not use this file except in compliance with the License. | 
					
						
							|  |  |  |  * You may obtain a copy of the License at | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  *     http://www.apache.org/licenses/LICENSE-2.0
 | 
					
						
							|  |  |  |  * | 
					
						
							|  |  |  |  * Unless required by applicable law or agreed to in writing, software | 
					
						
							|  |  |  |  * distributed under the License is distributed on an "AS IS" BASIS, | 
					
						
							|  |  |  |  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | 
					
						
							|  |  |  |  * See the License for the specific language governing permissions and | 
					
						
							|  |  |  |  * limitations under the License. | 
					
						
							|  |  |  |  */ | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | package cmd | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import ( | 
					
						
							| 
									
										
										
										
											2020-04-17 02:54:12 +08:00
										 |  |  | 	"context" | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 	"fmt" | 
					
						
							| 
									
										
										
										
											2020-04-17 02:54:12 +08:00
										 |  |  | 	"net" | 
					
						
							| 
									
										
										
										
											2017-04-12 08:44:26 +08:00
										 |  |  | 	"net/url" | 
					
						
							| 
									
										
										
										
											2017-07-13 07:33:21 +08:00
										 |  |  | 	"os" | 
					
						
							|  |  |  | 	"os/signal" | 
					
						
							| 
									
										
										
										
											2017-04-12 08:44:26 +08:00
										 |  |  | 	"strings" | 
					
						
							| 
									
										
										
										
											2017-07-13 07:33:21 +08:00
										 |  |  | 	"syscall" | 
					
						
							| 
									
										
										
										
											2017-06-06 06:18:03 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	"github.com/gorilla/mux" | 
					
						
							|  |  |  | 	"github.com/minio/cli" | 
					
						
							| 
									
										
										
										
											2019-10-05 01:35:33 +08:00
										 |  |  | 	"github.com/minio/minio/cmd/config" | 
					
						
							| 
									
										
										
										
											2018-04-22 10:23:54 +08:00
										 |  |  | 	xhttp "github.com/minio/minio/cmd/http" | 
					
						
							| 
									
										
										
										
											2018-04-06 06:04:40 +08:00
										 |  |  | 	"github.com/minio/minio/cmd/logger" | 
					
						
							| 
									
										
										
										
											2018-06-01 03:30:15 +08:00
										 |  |  | 	"github.com/minio/minio/pkg/certs" | 
					
						
							| 
									
										
										
										
											2019-10-05 01:35:33 +08:00
										 |  |  | 	"github.com/minio/minio/pkg/color" | 
					
						
							|  |  |  | 	"github.com/minio/minio/pkg/env" | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | ) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | var ( | 
					
						
							|  |  |  | 	gatewayCmd = cli.Command{ | 
					
						
							|  |  |  | 		Name:            "gateway", | 
					
						
							| 
									
										
										
										
											2018-11-21 09:35:33 +08:00
										 |  |  | 		Usage:           "start object storage gateway", | 
					
						
							| 
									
										
										
										
											2019-06-10 22:57:42 +08:00
										 |  |  | 		Flags:           append(ServerFlags, GlobalFlags...), | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | 		HideHelpCommand: true, | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | ) | 
					
						
							| 
									
										
										
										
											2017-06-09 14:28:45 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-10-28 06:07:46 +08:00
										 |  |  | // RegisterGatewayCommand registers a new command for gateway.
 | 
					
						
							|  |  |  | func RegisterGatewayCommand(cmd cli.Command) error { | 
					
						
							| 
									
										
										
										
											2019-07-04 05:31:19 +08:00
										 |  |  | 	cmd.Flags = append(append(cmd.Flags, ServerFlags...), GlobalFlags...) | 
					
						
							| 
									
										
										
										
											2017-10-28 06:07:46 +08:00
										 |  |  | 	gatewayCmd.Subcommands = append(gatewayCmd.Subcommands, cmd) | 
					
						
							|  |  |  | 	return nil | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | // ParseGatewayEndpoint - Return endpoint.
 | 
					
						
							|  |  |  | func ParseGatewayEndpoint(arg string) (endPoint string, secure bool, err error) { | 
					
						
							| 
									
										
										
										
											2017-04-12 08:44:26 +08:00
										 |  |  | 	schemeSpecified := len(strings.Split(arg, "://")) > 1 | 
					
						
							|  |  |  | 	if !schemeSpecified { | 
					
						
							|  |  |  | 		// Default connection will be "secure".
 | 
					
						
							|  |  |  | 		arg = "https://" + arg | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2017-04-28 02:26:00 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-04-12 08:44:26 +08:00
										 |  |  | 	u, err := url.Parse(arg) | 
					
						
							|  |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		return "", false, err | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	switch u.Scheme { | 
					
						
							|  |  |  | 	case "http": | 
					
						
							|  |  |  | 		return u.Host, false, nil | 
					
						
							|  |  |  | 	case "https": | 
					
						
							|  |  |  | 		return u.Host, true, nil | 
					
						
							|  |  |  | 	default: | 
					
						
							|  |  |  | 		return "", false, fmt.Errorf("Unrecognized scheme %s", u.Scheme) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | // ValidateGatewayArguments - Validate gateway arguments.
 | 
					
						
							|  |  |  | func ValidateGatewayArguments(serverAddr, endpointAddr string) error { | 
					
						
							| 
									
										
										
										
											2017-06-09 02:20:56 +08:00
										 |  |  | 	if err := CheckLocalServerAddr(serverAddr); err != nil { | 
					
						
							|  |  |  | 		return err | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	if endpointAddr != "" { | 
					
						
							|  |  |  | 		// Reject the endpoint if it points to the gateway handler itself.
 | 
					
						
							|  |  |  | 		sameTarget, err := sameLocalAddrs(endpointAddr, serverAddr) | 
					
						
							|  |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			return err | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		if sameTarget { | 
					
						
							| 
									
										
										
										
											2017-11-26 03:58:29 +08:00
										 |  |  | 			return fmt.Errorf("endpoint points to the local gateway") | 
					
						
							| 
									
										
										
										
											2017-06-09 02:20:56 +08:00
										 |  |  | 		} | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 	return nil | 
					
						
							|  |  |  | } | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | // StartGateway - handler for 'minio gateway <name>'.
 | 
					
						
							|  |  |  | func StartGateway(ctx *cli.Context, gw Gateway) { | 
					
						
							| 
									
										
										
										
											2020-05-19 02:35:05 +08:00
										 |  |  | 	// This is only to uniquely identify each gateway deployments.
 | 
					
						
							|  |  |  | 	globalDeploymentID = env.Get("MINIO_GATEWAY_DEPLOYMENT_ID", mustGetUUID()) | 
					
						
							|  |  |  | 	logger.SetDeploymentID(globalDeploymentID) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | 	if gw == nil { | 
					
						
							| 
									
										
										
										
											2018-05-10 06:11:24 +08:00
										 |  |  | 		logger.FatalIf(errUnexpected, "Gateway implementation not initialized") | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Validate if we have access, secret set through environment.
 | 
					
						
							| 
									
										
										
										
											2019-08-15 02:43:43 +08:00
										 |  |  | 	globalGatewayName = gw.Name() | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | 	gatewayName := gw.Name() | 
					
						
							|  |  |  | 	if ctx.Args().First() == "help" { | 
					
						
							|  |  |  | 		cli.ShowCommandHelpAndExit(ctx, gatewayName, 1) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | 	// Handle common command args.
 | 
					
						
							|  |  |  | 	handleCommonCmdArgs(ctx) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-12-05 07:32:37 +08:00
										 |  |  | 	// Initialize all help
 | 
					
						
							|  |  |  | 	initHelp() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-09-07 07:42:33 +08:00
										 |  |  | 	// Get port to listen on from gateway address
 | 
					
						
							| 
									
										
										
										
											2018-12-19 08:08:11 +08:00
										 |  |  | 	globalMinioHost, globalMinioPort = mustSplitHostPort(globalCLIContext.Addr) | 
					
						
							| 
									
										
										
										
											2018-09-07 07:42:33 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-08-18 12:06:36 +08:00
										 |  |  | 	// On macOS, if a process already listens on LOCALIPADDR:PORT, net.Listen() falls back
 | 
					
						
							|  |  |  | 	// to IPv6 address ie minio will start listening on IPv6 address whereas another
 | 
					
						
							|  |  |  | 	// (non-)minio process is listening on IPv4 of given port.
 | 
					
						
							|  |  |  | 	// To avoid this error situation we check for port availability.
 | 
					
						
							| 
									
										
										
										
											2019-06-25 06:02:40 +08:00
										 |  |  | 	logger.FatalIf(checkPortAvailability(globalMinioHost, globalMinioPort), "Unable to start the gateway") | 
					
						
							| 
									
										
										
										
											2018-08-18 12:06:36 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-10-28 08:51:00 +08:00
										 |  |  | 	// Check and load TLS certificates.
 | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | 	var err error | 
					
						
							| 
									
										
										
										
											2018-10-28 08:51:00 +08:00
										 |  |  | 	globalPublicCerts, globalTLSCerts, globalIsSSL, err = getTLSConfig() | 
					
						
							|  |  |  | 	logger.FatalIf(err, "Invalid TLS certificate file") | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Check and load Root CAs.
 | 
					
						
							| 
									
										
										
										
											2019-10-08 13:47:56 +08:00
										 |  |  | 	globalRootCAs, err = config.GetRootCAs(globalCertsCADir.Get()) | 
					
						
							| 
									
										
										
										
											2018-10-28 08:51:00 +08:00
										 |  |  | 	logger.FatalIf(err, "Failed to read root CAs (%v)", err) | 
					
						
							| 
									
										
										
										
											2017-03-31 13:26:24 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-04-27 21:25:05 +08:00
										 |  |  | 	globalMinioEndpoint = func() string { | 
					
						
							|  |  |  | 		host := globalMinioHost | 
					
						
							|  |  |  | 		if host == "" { | 
					
						
							|  |  |  | 			host = sortIPs(localIP4.ToSlice())[0] | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		return fmt.Sprintf("%s://%s", getURLScheme(globalIsSSL), net.JoinHostPort(host, globalMinioPort)) | 
					
						
							|  |  |  | 	}() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-01-06 06:16:43 +08:00
										 |  |  | 	// Handle gateway specific env
 | 
					
						
							| 
									
										
										
										
											2019-11-02 06:53:16 +08:00
										 |  |  | 	gatewayHandleEnvVars() | 
					
						
							| 
									
										
										
										
											2019-01-06 06:16:43 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-24 22:39:30 +08:00
										 |  |  | 	// Set system resources to maximum.
 | 
					
						
							| 
									
										
										
										
											2020-04-10 00:30:02 +08:00
										 |  |  | 	logger.LogIf(GlobalContext, setMaxResources()) | 
					
						
							| 
									
										
										
										
											2017-12-24 22:39:30 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-06-08 06:49:13 +08:00
										 |  |  | 	// Set when gateway is enabled
 | 
					
						
							|  |  |  | 	globalIsGateway = true | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-12 19:16:25 +08:00
										 |  |  | 	enableConfigOps := gatewayName == "nas" | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// TODO: We need to move this code with globalConfigSys.Init()
 | 
					
						
							|  |  |  | 	// for now keep it here such that "s3" gateway layer initializes
 | 
					
						
							|  |  |  | 	// itself properly when KMS is set.
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Initialize server config.
 | 
					
						
							|  |  |  | 	srvCfg := newServerConfig() | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 	// Override any values from ENVs.
 | 
					
						
							| 
									
										
										
										
											2019-12-15 09:27:57 +08:00
										 |  |  | 	lookupConfigs(srvCfg) | 
					
						
							| 
									
										
										
										
											2019-11-12 19:16:25 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | 	// hold the mutex lock before a new config is assigned.
 | 
					
						
							|  |  |  | 	globalServerConfigMu.Lock() | 
					
						
							|  |  |  | 	globalServerConfig = srvCfg | 
					
						
							|  |  |  | 	globalServerConfigMu.Unlock() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-02-12 11:38:02 +08:00
										 |  |  | 	// Initialize router. `SkipClean(true)` stops gorilla/mux from
 | 
					
						
							|  |  |  | 	// normalizing URL path minio/minio#3256
 | 
					
						
							|  |  |  | 	// avoid URL path encoding minio/minio#8950
 | 
					
						
							|  |  |  | 	router := mux.NewRouter().SkipClean(true).UseEncodedPath() | 
					
						
							| 
									
										
										
										
											2017-06-02 00:43:20 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-10-18 08:25:16 +08:00
										 |  |  | 	if globalEtcdClient != nil { | 
					
						
							|  |  |  | 		// Enable STS router if etcd is enabled.
 | 
					
						
							|  |  |  | 		registerSTSRouter(router) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-01-24 03:10:59 +08:00
										 |  |  | 	enableIAMOps := globalEtcdClient != nil | 
					
						
							| 
									
										
										
										
											2020-05-01 06:55:54 +08:00
										 |  |  | 	enableBucketQuotaOps := env.Get(envDataUsageCrawlConf, config.EnableOn) == config.EnableOn | 
					
						
							| 
									
										
										
										
											2019-01-24 03:10:59 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-19 05:03:26 +08:00
										 |  |  | 	// Enable IAM admin APIs if etcd is enabled, if not just enable basic
 | 
					
						
							|  |  |  | 	// operations such as profiling, server info etc.
 | 
					
						
							| 
									
										
										
										
											2020-05-01 06:55:54 +08:00
										 |  |  | 	registerAdminRouter(router, enableConfigOps, enableIAMOps, enableBucketQuotaOps) | 
					
						
							| 
									
										
										
										
											2018-12-19 05:03:26 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-04-05 10:07:54 +08:00
										 |  |  | 	// Add healthcheck router
 | 
					
						
							|  |  |  | 	registerHealthCheckRouter(router) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-05-30 12:43:46 +08:00
										 |  |  | 	// Add server metrics router
 | 
					
						
							|  |  |  | 	registerMetricsRouter(router) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-06-02 00:43:20 +08:00
										 |  |  | 	// Register web router when its enabled.
 | 
					
						
							| 
									
										
										
										
											2019-10-23 13:59:13 +08:00
										 |  |  | 	if globalBrowserEnabled { | 
					
						
							| 
									
										
										
										
											2018-04-06 06:04:40 +08:00
										 |  |  | 		logger.FatalIf(registerWebRouter(router), "Unable to configure web browser") | 
					
						
							| 
									
										
										
										
											2017-06-02 00:43:20 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-01-06 06:16:43 +08:00
										 |  |  | 	// Currently only NAS and S3 gateway support encryption headers.
 | 
					
						
							|  |  |  | 	encryptionEnabled := gatewayName == "s3" || gatewayName == "nas" | 
					
						
							| 
									
										
										
										
											2019-06-20 08:37:08 +08:00
										 |  |  | 	allowSSEKMS := gatewayName == "s3" // Only S3 can support SSE-KMS (as pass-through)
 | 
					
						
							| 
									
										
										
										
											2019-01-06 06:16:43 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-04-05 10:07:54 +08:00
										 |  |  | 	// Add API router.
 | 
					
						
							| 
									
										
										
										
											2019-06-20 08:37:08 +08:00
										 |  |  | 	registerAPIRouter(router, encryptionEnabled, allowSSEKMS) | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-06-01 03:30:15 +08:00
										 |  |  | 	var getCert certs.GetCertificateFunc | 
					
						
							|  |  |  | 	if globalTLSCerts != nil { | 
					
						
							|  |  |  | 		getCert = globalTLSCerts.GetCertificate | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-12-03 07:54:26 +08:00
										 |  |  | 	httpServer := xhttp.NewServer([]string{globalCLIContext.Addr}, | 
					
						
							| 
									
										
										
										
											2019-11-12 19:16:25 +08:00
										 |  |  | 		criticalErrorHandler{registerHandlers(router, globalHandlers...)}, getCert) | 
					
						
							| 
									
										
										
										
											2020-04-17 02:54:12 +08:00
										 |  |  | 	httpServer.BaseContext = func(listener net.Listener) context.Context { | 
					
						
							|  |  |  | 		return GlobalContext | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 	go func() { | 
					
						
							| 
									
										
										
										
											2019-12-03 07:54:26 +08:00
										 |  |  | 		globalHTTPServerErrorCh <- httpServer.Start() | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 	}() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-12-03 07:54:26 +08:00
										 |  |  | 	globalObjLayerMutex.Lock() | 
					
						
							|  |  |  | 	globalHTTPServer = httpServer | 
					
						
							|  |  |  | 	globalObjLayerMutex.Unlock() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-07-13 07:33:21 +08:00
										 |  |  | 	signal.Notify(globalOSSignalCh, os.Interrupt, syscall.SIGTERM) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-10-23 13:59:13 +08:00
										 |  |  | 	newObject, err := gw.NewGatewayLayer(globalActiveCred) | 
					
						
							| 
									
										
										
										
											2018-12-19 02:42:09 +08:00
										 |  |  | 	if err != nil { | 
					
						
							|  |  |  | 		// Stop watching for any certificate changes.
 | 
					
						
							|  |  |  | 		globalTLSCerts.Stop() | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 		globalHTTPServer.Shutdown() | 
					
						
							|  |  |  | 		logger.FatalIf(err, "Unable to initialize gateway backend") | 
					
						
							|  |  |  | 	} | 
					
						
							| 
									
										
										
										
											2019-11-20 08:45:35 +08:00
										 |  |  | 	newObject = NewGatewayLayerWithLocker(newObject) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-10 01:27:23 +08:00
										 |  |  | 	// Once endpoints are finalized, initialize the new object api in safe mode.
 | 
					
						
							|  |  |  | 	globalObjLayerMutex.Lock() | 
					
						
							|  |  |  | 	globalSafeMode = true | 
					
						
							|  |  |  | 	globalObjectAPI = newObject | 
					
						
							|  |  |  | 	globalObjLayerMutex.Unlock() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-02 06:53:16 +08:00
										 |  |  | 	// Migrate all backend configs to encrypted backend, also handles rotation as well.
 | 
					
						
							|  |  |  | 	// For "nas" gateway we need to specially handle the backend migration as well.
 | 
					
						
							|  |  |  | 	// Internally code handles migrating etcd if enabled automatically.
 | 
					
						
							|  |  |  | 	logger.FatalIf(handleEncryptedConfigBackend(newObject, enableConfigOps), | 
					
						
							|  |  |  | 		"Unable to handle encrypted backend for config, iam and policies") | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-10 01:27:23 +08:00
										 |  |  | 	// Calls all New() for all sub-systems.
 | 
					
						
							|  |  |  | 	newAllSubsystems() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-02 06:53:16 +08:00
										 |  |  | 	// ****  WARNING ****
 | 
					
						
							|  |  |  | 	// Migrating to encrypted backend should happen before initialization of any
 | 
					
						
							|  |  |  | 	// sub-systems, make sure that we do not move the above codeblock elsewhere.
 | 
					
						
							| 
									
										
										
										
											2019-01-24 03:10:59 +08:00
										 |  |  | 	if enableConfigOps { | 
					
						
							| 
									
										
										
										
											2019-11-10 01:27:23 +08:00
										 |  |  | 		logger.FatalIf(globalConfigSys.Init(newObject), "Unable to initialize config system") | 
					
						
							| 
									
										
										
										
											2020-04-10 00:30:02 +08:00
										 |  |  | 		buckets, err := newObject.ListBuckets(GlobalContext) | 
					
						
							| 
									
										
										
										
											2020-02-02 17:52:07 +08:00
										 |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			logger.Fatal(err, "Unable to list buckets") | 
					
						
							|  |  |  | 		} | 
					
						
							| 
									
										
										
										
											2019-07-26 08:41:25 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2020-02-02 17:52:07 +08:00
										 |  |  | 		logger.FatalIf(globalNotificationSys.Init(buckets, newObject), "Unable to initialize notification system") | 
					
						
							| 
									
										
										
										
											2019-07-26 08:41:25 +08:00
										 |  |  | 		// Start watching disk for reloading config, this
 | 
					
						
							|  |  |  | 		// is only enabled for "NAS" gateway.
 | 
					
						
							| 
									
										
										
										
											2020-04-17 01:56:18 +08:00
										 |  |  | 		globalConfigSys.WatchConfigNASDisk(GlobalContext, newObject) | 
					
						
							| 
									
										
										
										
											2018-12-19 02:42:09 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2018-10-13 03:25:59 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-02 06:53:16 +08:00
										 |  |  | 	if globalEtcdClient != nil { | 
					
						
							|  |  |  | 		// ****  WARNING ****
 | 
					
						
							|  |  |  | 		// Migrating to encrypted backend on etcd should happen before initialization of
 | 
					
						
							|  |  |  | 		// IAM sub-systems, make sure that we do not move the above codeblock elsewhere.
 | 
					
						
							| 
									
										
										
										
											2020-04-08 05:26:39 +08:00
										 |  |  | 		logger.FatalIf(migrateIAMConfigsEtcdToEncrypted(GlobalContext, globalEtcdClient), | 
					
						
							| 
									
										
										
										
											2019-11-02 06:53:16 +08:00
										 |  |  | 			"Unable to handle encrypted backend for iam and policies") | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-01-24 03:10:59 +08:00
										 |  |  | 	if enableIAMOps { | 
					
						
							| 
									
										
										
										
											2018-10-13 02:32:18 +08:00
										 |  |  | 		// Initialize IAM sys.
 | 
					
						
							| 
									
										
										
										
											2020-04-08 05:26:39 +08:00
										 |  |  | 		logger.FatalIf(globalIAMSys.Init(GlobalContext, newObject), "Unable to initialize IAM system") | 
					
						
							| 
									
										
										
										
											2018-10-13 02:32:18 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2018-10-10 05:00:01 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-10 01:27:23 +08:00
										 |  |  | 	if globalCacheConfig.Enabled { | 
					
						
							|  |  |  | 		// initialize the new disk cache objects.
 | 
					
						
							|  |  |  | 		var cacheAPI CacheObjectLayer | 
					
						
							| 
									
										
										
										
											2020-03-23 03:16:36 +08:00
										 |  |  | 		cacheAPI, err = newServerCacheObjects(GlobalContext, globalCacheConfig) | 
					
						
							| 
									
										
										
										
											2019-11-10 01:27:23 +08:00
										 |  |  | 		logger.FatalIf(err, "Unable to initialize disk caching") | 
					
						
							| 
									
										
										
										
											2019-07-20 04:20:33 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-10 01:27:23 +08:00
										 |  |  | 		globalObjLayerMutex.Lock() | 
					
						
							|  |  |  | 		globalCacheObjectAPI = cacheAPI | 
					
						
							|  |  |  | 		globalObjLayerMutex.Unlock() | 
					
						
							| 
									
										
										
										
											2019-10-31 14:39:09 +08:00
										 |  |  | 	} | 
					
						
							| 
									
										
										
										
											2018-12-15 05:35:48 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-12-18 05:50:07 +08:00
										 |  |  | 	// Populate existing buckets to the etcd backend
 | 
					
						
							|  |  |  | 	if globalDNSConfig != nil { | 
					
						
							| 
									
										
										
										
											2020-03-23 03:16:36 +08:00
										 |  |  | 		buckets, err := newObject.ListBuckets(GlobalContext) | 
					
						
							| 
									
										
										
										
											2019-12-18 05:50:07 +08:00
										 |  |  | 		if err != nil { | 
					
						
							|  |  |  | 			logger.Fatal(err, "Unable to list buckets") | 
					
						
							|  |  |  | 		} | 
					
						
							|  |  |  | 		initFederatorBackend(buckets, newObject) | 
					
						
							|  |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-07-26 17:41:16 +08:00
										 |  |  | 	// Verify if object layer supports
 | 
					
						
							|  |  |  | 	// - encryption
 | 
					
						
							|  |  |  | 	// - compression
 | 
					
						
							|  |  |  | 	verifyObjectLayerFeatures("gateway "+gatewayName, newObject) | 
					
						
							| 
									
										
										
										
											2018-12-15 05:35:48 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2019-11-17 05:44:28 +08:00
										 |  |  | 	// Disable safe mode operation, after all initialization is over.
 | 
					
						
							|  |  |  | 	globalObjLayerMutex.Lock() | 
					
						
							|  |  |  | 	globalSafeMode = false | 
					
						
							|  |  |  | 	globalObjLayerMutex.Unlock() | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 	// Prints the formatted startup message once object layer is initialized.
 | 
					
						
							| 
									
										
										
										
											2018-12-19 08:08:11 +08:00
										 |  |  | 	if !globalCLIContext.Quiet { | 
					
						
							| 
									
										
										
										
											2017-10-28 06:07:46 +08:00
										 |  |  | 		mode := globalMinioModeGatewayPrefix + gatewayName | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | 		// Check update mode.
 | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 		checkUpdate(mode) | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | 		// Print a warning message if gateway is not ready for production before the startup banner.
 | 
					
						
							|  |  |  | 		if !gw.Production() { | 
					
						
							| 
									
										
										
										
											2019-10-05 01:35:33 +08:00
										 |  |  | 			logStartupMessage(color.Yellow("               *** Warning: Not Ready for Production ***")) | 
					
						
							| 
									
										
										
										
											2017-12-06 09:58:09 +08:00
										 |  |  | 		} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-06-10 10:50:51 +08:00
										 |  |  | 		// Print gateway startup message.
 | 
					
						
							| 
									
										
										
										
											2018-12-14 15:37:46 +08:00
										 |  |  | 		printGatewayStartupMessage(getAPIEndpoints(), gatewayName) | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | 	} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-07-13 07:33:21 +08:00
										 |  |  | 	handleSignals() | 
					
						
							| 
									
										
										
										
											2017-03-17 03:21:58 +08:00
										 |  |  | } |