Merge pull request #3179 from akhilmhdh/feat/connector

feat: quick fix for quic
This commit is contained in:
Maidul Islam
2025-03-04 15:52:48 -05:00
committed by GitHub
6 changed files with 79 additions and 46 deletions
@@ -32,10 +32,10 @@ jobs:
run: touch .env && docker compose -f docker-compose.dev.yml up -d db redis run: touch .env && docker compose -f docker-compose.dev.yml up -d db redis
- name: Start the server - name: Start the server
run: | run: |
echo "SECRET_SCANNING_GIT_APP_ID=793712" >> .env echo "SECRET_SCANNING_GIT_APP_ID=793712" >> .env
echo "SECRET_SCANNING_PRIVATE_KEY=some-random" >> .env echo "SECRET_SCANNING_PRIVATE_KEY=some-random" >> .env
echo "SECRET_SCANNING_WEBHOOK_SECRET=some-random" >> .env echo "SECRET_SCANNING_WEBHOOK_SECRET=some-random" >> .env
docker run --name infisical-api -d -p 4000:4000 -e DB_CONNECTION_URI=$DB_CONNECTION_URI -e REDIS_URL=$REDIS_URL -e JWT_AUTH_SECRET=$JWT_AUTH_SECRET -e ENCRYPTION_KEY=$ENCRYPTION_KEY --env-file .env --entrypoint '/bin/sh' infisical-api -c "npm run migration:latest && ls && node dist/main.mjs" docker run --name infisical-api -d -p 4000:4000 -e DB_CONNECTION_URI=$DB_CONNECTION_URI -e REDIS_URL=$REDIS_URL -e JWT_AUTH_SECRET=$JWT_AUTH_SECRET -e ENCRYPTION_KEY=$ENCRYPTION_KEY --env-file .env --entrypoint '/bin/sh' infisical-api
env: env:
REDIS_URL: redis://172.17.0.1:6379 REDIS_URL: redis://172.17.0.1:6379
DB_CONNECTION_URI: postgres://infisical:[email protected]:5432/infisical?sslmode=disable DB_CONNECTION_URI: postgres://infisical:[email protected]:5432/infisical?sslmode=disable
@@ -43,7 +43,7 @@ jobs:
ENCRYPTION_KEY: 4bnfe4e407b8921c104518903515b218 ENCRYPTION_KEY: 4bnfe4e407b8921c104518903515b218
- uses: actions/setup-go@v5 - uses: actions/setup-go@v5
with: with:
go-version: '1.21.5' go-version: "1.21.5"
- name: Wait for container to be stable and check logs - name: Wait for container to be stable and check logs
run: | run: |
SECONDS=0 SECONDS=0
@@ -61,7 +61,7 @@ jobs:
sleep 2 sleep 2
SECONDS=$((SECONDS+2)) SECONDS=$((SECONDS+2))
done done
if [ $HEALTHY -ne 1 ]; then if [ $HEALTHY -ne 1 ]; then
echo "Container did not become healthy in time" echo "Container did not become healthy in time"
exit 1 exit 1
+1
View File
@@ -122,6 +122,7 @@ RUN apt-get update && apt-get install -y \
unixodbc-dev \ unixodbc-dev \
libc-dev \ libc-dev \
freetds-dev \ freetds-dev \
wget \
openssh-client \ openssh-client \
&& rm -rf /var/lib/apt/lists/* && rm -rf /var/lib/apt/lists/*
+26 -27
View File
@@ -1,23 +1,22 @@
# Build stage # Build stage
FROM node:20-alpine AS build FROM node:20-slim AS build
WORKDIR /app WORKDIR /app
# Required for pkcs11js # Required for pkcs11js
RUN apk --update add \ RUN apt-get update && apt-get install -y \
python3 \ python3 \
make \ make \
g++ \ g++ \
openssh openssh-client
# install dependencies for TDS driver (required for SAP ASE dynamic secrets) # Install dependencies for TDS driver (required for SAP ASE dynamic secrets)
RUN apk add --no-cache \ RUN apt-get install -y \
unixodbc \ unixodbc \
freetds \ freetds-bin \
freetds-dev \
unixodbc-dev \ unixodbc-dev \
libc-dev \ libc-dev
freetds-dev
COPY package*.json ./ COPY package*.json ./
RUN npm ci --only-production RUN npm ci --only-production
@@ -26,36 +25,36 @@ COPY . .
RUN npm run build RUN npm run build
# Production stage # Production stage
FROM node:20-alpine FROM node:20-slim
WORKDIR /app WORKDIR /app
ENV npm_config_cache /home/node/.npm ENV npm_config_cache /home/node/.npm
COPY package*.json ./ COPY package*.json ./
RUN apk --update add \ RUN apt-get update && apt-get install -y \
python3 \ python3 \
make \ make \
g++ g++
# install dependencies for TDS driver (required for SAP ASE dynamic secrets) # Install dependencies for TDS driver (required for SAP ASE dynamic secrets)
RUN apk add --no-cache \ RUN apt-get install -y \
unixodbc \ unixodbc \
freetds \ freetds-bin \
freetds-dev \
unixodbc-dev \ unixodbc-dev \
libc-dev \ libc-dev
freetds-dev
RUN printf "[FreeTDS]\nDescription = FreeTDS Driver\nDriver = /usr/lib/x86_64-linux-gnu/odbc/libtdsodbc.so\nSetup = /usr/lib/x86_64-linux-gnu/odbc/libtdsodbc.so\nFileUsage = 1\n" > /etc/odbcinst.ini
RUN printf "[FreeTDS]\nDescription = FreeTDS Driver\nDriver = /usr/lib/libtdsodbc.so\nSetup = /usr/lib/libtdsodbc.so\nFileUsage = 1\n" > /etc/odbcinst.ini
RUN npm ci --only-production && npm cache clean --force RUN npm ci --only-production && npm cache clean --force
COPY --from=build /app . COPY --from=build /app .
RUN apk add --no-cache bash curl && curl -1sLf \ # Install Infisical CLI
'https://dl.cloudsmith.io/public/infisical/infisical-cli/setup.alpine.sh' | bash \ RUN apt-get install -y curl bash && \
&& apk add infisical=0.8.1 && apk add --no-cache git curl -1sLf 'https://dl.cloudsmith.io/public/infisical/infisical-cli/setup.deb.sh' | bash && \
apt-get update && apt-get install -y infisical=0.8.1 git
HEALTHCHECK --interval=10s --timeout=3s --start-period=10s \ HEALTHCHECK --interval=10s --timeout=3s --start-period=10s \
CMD node healthcheck.js CMD node healthcheck.js
+2 -13
View File
@@ -12,10 +12,10 @@ import (
"strconv" "strconv"
"syscall" "syscall"
udplistener "github.com/Infisical/infisical-merge/packages/gateway/udp_listener"
"github.com/pion/logging" "github.com/pion/logging"
"github.com/pion/turn/v4" "github.com/pion/turn/v4"
"github.com/rs/zerolog/log" "github.com/rs/zerolog/log"
"golang.org/x/sys/unix"
"gopkg.in/yaml.v2" "gopkg.in/yaml.v2"
) )
@@ -115,18 +115,7 @@ func (g *GatewayRelay) Run() error {
// this allows us to add logging, storage or modify inbound/outbound traffic // this allows us to add logging, storage or modify inbound/outbound traffic
// UDP listeners share the same local address:port with setting SO_REUSEPORT and the kernel // UDP listeners share the same local address:port with setting SO_REUSEPORT and the kernel
// will load-balance received packets per the IP 5-tuple // will load-balance received packets per the IP 5-tuple
listenerConfig := &net.ListenConfig{ listenerConfig := udplistener.SetupListenerConfig()
Control: func(network, address string, conn syscall.RawConn) error { // nolint: revive
var operr error
if err = conn.Control(func(fd uintptr) {
operr = syscall.SetsockoptInt(int(fd), syscall.SOL_SOCKET, unix.SO_REUSEPORT, 1)
}); err != nil {
return err
}
return operr
},
}
publicIP := g.Config.PublicIP publicIP := g.Config.PublicIP
relayAddressGenerator := &turn.RelayAddressGeneratorPortRange{ relayAddressGenerator := &turn.RelayAddressGeneratorPortRange{
@@ -0,0 +1,26 @@
//go:build !windows
// +build !windows
package udplistener
import (
"net"
"syscall"
"golang.org/x/sys/unix"
// other imports
)
func SetupListenerConfig() *net.ListenConfig {
return &net.ListenConfig{
Control: func(network, address string, conn syscall.RawConn) error {
var operr error
if err := conn.Control(func(fd uintptr) {
operr = syscall.SetsockoptInt(int(fd), syscall.SOL_SOCKET, unix.SO_REUSEPORT, 1)
}); err != nil {
return err
}
return operr
},
}
}
@@ -0,0 +1,18 @@
//go:build windows
// +build windows
package udplistener
import (
"fmt"
"net"
"syscall"
)
func SetupListenerConfig() *net.ListenConfig {
return &net.ListenConfig{
Control: func(network, address string, conn syscall.RawConn) error {
return fmt.Errorf("Infisical relay not supported for windows.")
},
}
}