filer.go 20 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458
  1. package command
  2. import (
  3. "context"
  4. "crypto/tls"
  5. "crypto/x509"
  6. "fmt"
  7. "net"
  8. "net/http"
  9. "os"
  10. "runtime"
  11. "sort"
  12. "strings"
  13. "time"
  14. "github.com/spf13/viper"
  15. "google.golang.org/grpc/credentials/tls/certprovider"
  16. "google.golang.org/grpc/credentials/tls/certprovider/pemfile"
  17. "google.golang.org/grpc/reflection"
  18. "github.com/seaweedfs/seaweedfs/weed/filer"
  19. "github.com/seaweedfs/seaweedfs/weed/glog"
  20. "github.com/seaweedfs/seaweedfs/weed/pb"
  21. "github.com/seaweedfs/seaweedfs/weed/pb/filer_pb"
  22. "github.com/seaweedfs/seaweedfs/weed/security"
  23. weed_server "github.com/seaweedfs/seaweedfs/weed/server"
  24. stats_collect "github.com/seaweedfs/seaweedfs/weed/stats"
  25. "github.com/seaweedfs/seaweedfs/weed/util"
  26. "github.com/seaweedfs/seaweedfs/weed/util/version"
  27. )
  28. var (
  29. f FilerOptions
  30. filerStartS3 *bool
  31. filerS3Options S3Options
  32. filerStartWebDav *bool
  33. filerWebDavOptions WebDavOption
  34. filerStartIam *bool
  35. filerIamOptions IamOptions
  36. filerStartSftp *bool
  37. filerSftpOptions SftpOptions
  38. )
  39. type FilerOptions struct {
  40. masters *pb.ServerDiscovery
  41. mastersString *string
  42. ip *string
  43. bindIp *string
  44. port *int
  45. portGrpc *int
  46. publicPort *int
  47. filerGroup *string
  48. collection *string
  49. defaultReplicaPlacement *string
  50. disableDirListing *bool
  51. maxMB *int
  52. dirListingLimit *int
  53. dataCenter *string
  54. rack *string
  55. enableNotification *bool
  56. disableHttp *bool
  57. cipher *bool
  58. metricsHttpPort *int
  59. metricsHttpIp *string
  60. saveToFilerLimit *int
  61. defaultLevelDbDirectory *string
  62. concurrentUploadLimitMB *int
  63. debug *bool
  64. debugPort *int
  65. localSocket *string
  66. showUIDirectoryDelete *bool
  67. downloadMaxMBps *int
  68. diskType *string
  69. allowedOrigins *string
  70. exposeDirectoryData *bool
  71. certProvider certprovider.Provider
  72. }
  73. func init() {
  74. cmdFiler.Run = runFiler // break init cycle
  75. f.mastersString = cmdFiler.Flag.String("master", "localhost:9333", "comma-separated master servers or a single DNS SRV record of at least 1 master server, prepended with dnssrv+")
  76. f.filerGroup = cmdFiler.Flag.String("filerGroup", "", "share metadata with other filers in the same filerGroup")
  77. f.collection = cmdFiler.Flag.String("collection", "", "all data will be stored in this default collection")
  78. f.ip = cmdFiler.Flag.String("ip", util.DetectedHostAddress(), "filer server http listen ip address")
  79. f.bindIp = cmdFiler.Flag.String("ip.bind", "", "ip address to bind to. If empty, default to same as -ip option.")
  80. f.port = cmdFiler.Flag.Int("port", 8888, "filer server http listen port")
  81. f.portGrpc = cmdFiler.Flag.Int("port.grpc", 0, "filer server grpc listen port")
  82. f.publicPort = cmdFiler.Flag.Int("port.readonly", 0, "readonly port opened to public")
  83. f.defaultReplicaPlacement = cmdFiler.Flag.String("defaultReplicaPlacement", "", "default replication type. If not specified, use master setting.")
  84. f.disableDirListing = cmdFiler.Flag.Bool("disableDirListing", false, "turn off directory listing")
  85. f.maxMB = cmdFiler.Flag.Int("maxMB", 4, "split files larger than the limit")
  86. f.dirListingLimit = cmdFiler.Flag.Int("dirListLimit", 100000, "limit sub dir listing size")
  87. f.dataCenter = cmdFiler.Flag.String("dataCenter", "", "prefer to read and write to volumes in this data center")
  88. f.rack = cmdFiler.Flag.String("rack", "", "prefer to write to volumes in this rack")
  89. f.disableHttp = cmdFiler.Flag.Bool("disableHttp", false, "disable http request, only gRpc operations are allowed")
  90. f.cipher = cmdFiler.Flag.Bool("encryptVolumeData", false, "encrypt data on volume servers")
  91. f.metricsHttpPort = cmdFiler.Flag.Int("metricsPort", 0, "Prometheus metrics listen port")
  92. f.metricsHttpIp = cmdFiler.Flag.String("metricsIp", "", "metrics listen ip. If empty, default to same as -ip.bind option.")
  93. f.saveToFilerLimit = cmdFiler.Flag.Int("saveToFilerLimit", 0, "files smaller than this limit will be saved in filer store")
  94. f.defaultLevelDbDirectory = cmdFiler.Flag.String("defaultStoreDir", ".", "if filer.toml is empty, use an embedded filer store in the directory")
  95. f.concurrentUploadLimitMB = cmdFiler.Flag.Int("concurrentUploadLimitMB", 128, "limit total concurrent upload size")
  96. f.debug = cmdFiler.Flag.Bool("debug", false, "serves runtime profiling data, e.g., http://localhost:<debug.port>/debug/pprof/goroutine?debug=2")
  97. f.debugPort = cmdFiler.Flag.Int("debug.port", 6060, "http port for debugging")
  98. f.localSocket = cmdFiler.Flag.String("localSocket", "", "default to /tmp/seaweedfs-filer-<port>.sock")
  99. f.showUIDirectoryDelete = cmdFiler.Flag.Bool("ui.deleteDir", true, "enable filer UI show delete directory button")
  100. f.downloadMaxMBps = cmdFiler.Flag.Int("downloadMaxMBps", 0, "download max speed for each download request, in MB per second")
  101. f.diskType = cmdFiler.Flag.String("disk", "", "[hdd|ssd|<tag>] hard drive or solid state drive or any tag")
  102. f.allowedOrigins = cmdFiler.Flag.String("allowedOrigins", "*", "comma separated list of allowed origins")
  103. f.exposeDirectoryData = cmdFiler.Flag.Bool("exposeDirectoryData", true, "whether to return directory metadata and content in Filer UI")
  104. // start s3 on filer
  105. filerStartS3 = cmdFiler.Flag.Bool("s3", false, "whether to start S3 gateway")
  106. filerS3Options.port = cmdFiler.Flag.Int("s3.port", 8333, "s3 server http listen port")
  107. filerS3Options.portHttps = cmdFiler.Flag.Int("s3.port.https", 0, "s3 server https listen port")
  108. filerS3Options.portGrpc = cmdFiler.Flag.Int("s3.port.grpc", 0, "s3 server grpc listen port")
  109. filerS3Options.domainName = cmdFiler.Flag.String("s3.domainName", "", "suffix of the host name in comma separated list, {bucket}.{domainName}")
  110. filerS3Options.allowedOrigins = cmdFiler.Flag.String("s3.allowedOrigins", "*", "comma separated list of allowed origins")
  111. filerS3Options.dataCenter = cmdFiler.Flag.String("s3.dataCenter", "", "prefer to read and write to volumes in this data center")
  112. filerS3Options.tlsPrivateKey = cmdFiler.Flag.String("s3.key.file", "", "path to the TLS private key file")
  113. filerS3Options.tlsCertificate = cmdFiler.Flag.String("s3.cert.file", "", "path to the TLS certificate file")
  114. filerS3Options.config = cmdFiler.Flag.String("s3.config", "", "path to the config file")
  115. filerS3Options.auditLogConfig = cmdFiler.Flag.String("s3.auditLogConfig", "", "path to the audit log config file")
  116. filerS3Options.allowEmptyFolder = cmdFiler.Flag.Bool("s3.allowEmptyFolder", true, "allow empty folders")
  117. filerS3Options.allowDeleteBucketNotEmpty = cmdFiler.Flag.Bool("s3.allowDeleteBucketNotEmpty", true, "allow recursive deleting all entries along with bucket")
  118. filerS3Options.localSocket = cmdFiler.Flag.String("s3.localSocket", "", "default to /tmp/seaweedfs-s3-<port>.sock")
  119. filerS3Options.tlsCACertificate = cmdFiler.Flag.String("s3.cacert.file", "", "path to the TLS CA certificate file")
  120. filerS3Options.tlsVerifyClientCert = cmdFiler.Flag.Bool("s3.tlsVerifyClientCert", false, "whether to verify the client's certificate")
  121. filerS3Options.bindIp = cmdFiler.Flag.String("s3.ip.bind", "", "ip address to bind to. If empty, default to same as -ip.bind option.")
  122. filerS3Options.idleTimeout = cmdFiler.Flag.Int("s3.idleTimeout", 10, "connection idle seconds")
  123. // start webdav on filer
  124. filerStartWebDav = cmdFiler.Flag.Bool("webdav", false, "whether to start webdav gateway")
  125. filerWebDavOptions.port = cmdFiler.Flag.Int("webdav.port", 7333, "webdav server http listen port")
  126. filerWebDavOptions.collection = cmdFiler.Flag.String("webdav.collection", "", "collection to create the files")
  127. filerWebDavOptions.replication = cmdFiler.Flag.String("webdav.replication", "", "replication to create the files")
  128. filerWebDavOptions.disk = cmdFiler.Flag.String("webdav.disk", "", "[hdd|ssd|<tag>] hard drive or solid state drive or any tag")
  129. filerWebDavOptions.tlsPrivateKey = cmdFiler.Flag.String("webdav.key.file", "", "path to the TLS private key file")
  130. filerWebDavOptions.tlsCertificate = cmdFiler.Flag.String("webdav.cert.file", "", "path to the TLS certificate file")
  131. filerWebDavOptions.cacheDir = cmdFiler.Flag.String("webdav.cacheDir", os.TempDir(), "local cache directory for file chunks")
  132. filerWebDavOptions.cacheSizeMB = cmdFiler.Flag.Int64("webdav.cacheCapacityMB", 0, "local cache capacity in MB")
  133. filerWebDavOptions.maxMB = cmdFiler.Flag.Int("webdav.maxMB", 4, "split files larger than the limit")
  134. filerWebDavOptions.filerRootPath = cmdFiler.Flag.String("webdav.filer.path", "/", "use this remote path from filer server")
  135. // start iam on filer
  136. filerStartIam = cmdFiler.Flag.Bool("iam", false, "whether to start IAM service")
  137. filerIamOptions.ip = cmdFiler.Flag.String("iam.ip", *f.ip, "iam server http listen ip address")
  138. filerIamOptions.port = cmdFiler.Flag.Int("iam.port", 8111, "iam server http listen port")
  139. filerStartSftp = cmdFiler.Flag.Bool("sftp", false, "whether to start the SFTP server")
  140. filerSftpOptions.port = cmdFiler.Flag.Int("sftp.port", 2022, "SFTP server listen port")
  141. filerSftpOptions.sshPrivateKey = cmdFiler.Flag.String("sftp.sshPrivateKey", "", "path to the SSH private key file for host authentication")
  142. filerSftpOptions.hostKeysFolder = cmdFiler.Flag.String("sftp.hostKeysFolder", "", "path to folder containing SSH private key files for host authentication")
  143. filerSftpOptions.authMethods = cmdFiler.Flag.String("sftp.authMethods", "password,publickey", "comma-separated list of allowed auth methods: password, publickey, keyboard-interactive")
  144. filerSftpOptions.maxAuthTries = cmdFiler.Flag.Int("sftp.maxAuthTries", 6, "maximum number of authentication attempts per connection")
  145. filerSftpOptions.bannerMessage = cmdFiler.Flag.String("sftp.bannerMessage", "SeaweedFS SFTP Server - Unauthorized access is prohibited", "message displayed before authentication")
  146. filerSftpOptions.loginGraceTime = cmdFiler.Flag.Duration("sftp.loginGraceTime", 2*time.Minute, "timeout for authentication")
  147. filerSftpOptions.clientAliveInterval = cmdFiler.Flag.Duration("sftp.clientAliveInterval", 5*time.Second, "interval for sending keep-alive messages")
  148. filerSftpOptions.clientAliveCountMax = cmdFiler.Flag.Int("sftp.clientAliveCountMax", 3, "maximum number of missed keep-alive messages before disconnecting")
  149. filerSftpOptions.userStoreFile = cmdFiler.Flag.String("sftp.userStoreFile", "", "path to JSON file containing user credentials and permissions")
  150. filerSftpOptions.dataCenter = cmdFiler.Flag.String("sftp.dataCenter", "", "prefer to read and write to volumes in this data center")
  151. filerSftpOptions.bindIp = cmdFiler.Flag.String("sftp.ip.bind", "", "ip address to bind to. If empty, default to same as -ip.bind option.")
  152. filerSftpOptions.localSocket = cmdFiler.Flag.String("sftp.localSocket", "", "default to /tmp/seaweedfs-sftp-<port>.sock")
  153. }
  154. func filerLongDesc() string {
  155. desc := `start a file server which accepts REST operation for any files.
  156. //create or overwrite the file, the directories /path/to will be automatically created
  157. POST /path/to/file
  158. //get the file content
  159. GET /path/to/file
  160. //create or overwrite the file, the filename in the multipart request will be used
  161. POST /path/to/
  162. //return a json format subdirectory and files listing
  163. GET /path/to/
  164. The configuration file "filer.toml" is read from ".", "$HOME/.seaweedfs/", "/usr/local/etc/seaweedfs/", or "/etc/seaweedfs/", in that order.
  165. If the "filer.toml" is not found, an embedded filer store will be created under "-defaultStoreDir".
  166. The example filer.toml configuration file can be generated by "weed scaffold -config=filer"
  167. Supported Filer Stores:
  168. `
  169. storeNames := make([]string, len(filer.Stores))
  170. for i, store := range filer.Stores {
  171. storeNames[i] = "\t" + store.GetName()
  172. }
  173. sort.Strings(storeNames)
  174. storeList := strings.Join(storeNames, "\n")
  175. return desc + storeList
  176. }
  177. var cmdFiler = &Command{
  178. UsageLine: "filer -port=8888 -master=<ip:port>[,<ip:port>]*",
  179. Short: "start a file server that points to a master server, or a list of master servers",
  180. Long: filerLongDesc(),
  181. }
  182. func runFiler(cmd *Command, args []string) bool {
  183. if *f.debug {
  184. go http.ListenAndServe(fmt.Sprintf(":%d", *f.debugPort), nil)
  185. }
  186. util.LoadSecurityConfiguration()
  187. switch {
  188. case *f.metricsHttpIp != "":
  189. // noting to do, use f.metricsHttpIp
  190. case *f.bindIp != "":
  191. *f.metricsHttpIp = *f.bindIp
  192. case *f.ip != "":
  193. *f.metricsHttpIp = *f.ip
  194. }
  195. go stats_collect.StartMetricsServer(*f.metricsHttpIp, *f.metricsHttpPort)
  196. filerAddress := pb.NewServerAddress(*f.ip, *f.port, *f.portGrpc).String()
  197. startDelay := time.Duration(2)
  198. if *filerStartS3 {
  199. filerS3Options.filer = &filerAddress
  200. if *filerS3Options.bindIp == "" {
  201. filerS3Options.bindIp = f.bindIp
  202. }
  203. filerS3Options.localFilerSocket = f.localSocket
  204. if *f.dataCenter != "" && *filerS3Options.dataCenter == "" {
  205. filerS3Options.dataCenter = f.dataCenter
  206. }
  207. go func(delay time.Duration) {
  208. time.Sleep(delay * time.Second)
  209. filerS3Options.startS3Server()
  210. }(startDelay)
  211. startDelay++
  212. }
  213. if *filerStartWebDav {
  214. filerWebDavOptions.filer = &filerAddress
  215. filerWebDavOptions.ipBind = f.bindIp
  216. if *filerWebDavOptions.disk == "" {
  217. filerWebDavOptions.disk = f.diskType
  218. }
  219. go func(delay time.Duration) {
  220. time.Sleep(delay * time.Second)
  221. filerWebDavOptions.startWebDav()
  222. }(startDelay)
  223. startDelay++
  224. }
  225. if *filerStartIam {
  226. filerIamOptions.filer = &filerAddress
  227. filerIamOptions.masters = f.mastersString
  228. go func(delay time.Duration) {
  229. time.Sleep(delay * time.Second)
  230. filerIamOptions.startIamServer()
  231. }(startDelay)
  232. startDelay++
  233. }
  234. if *filerStartSftp {
  235. filerSftpOptions.filer = &filerAddress
  236. if *filerSftpOptions.bindIp == "" {
  237. filerSftpOptions.bindIp = f.bindIp
  238. }
  239. if *f.dataCenter != "" && *filerSftpOptions.dataCenter == "" {
  240. filerSftpOptions.dataCenter = f.dataCenter
  241. }
  242. go func(delay time.Duration) {
  243. time.Sleep(delay * time.Second)
  244. filerSftpOptions.startSftpServer()
  245. }(startDelay)
  246. }
  247. f.masters = pb.ServerAddresses(*f.mastersString).ToServiceDiscovery()
  248. f.startFiler()
  249. return true
  250. }
  251. // GetCertificateWithUpdate Auto refreshing TSL certificate
  252. func (fo *FilerOptions) GetCertificateWithUpdate(*tls.ClientHelloInfo) (*tls.Certificate, error) {
  253. certs, err := fo.certProvider.KeyMaterial(context.Background())
  254. if certs == nil {
  255. return nil, err
  256. }
  257. return &certs.Certs[0], err
  258. }
  259. func (fo *FilerOptions) startFiler() {
  260. defaultMux := http.NewServeMux()
  261. publicVolumeMux := defaultMux
  262. if *fo.publicPort != 0 {
  263. publicVolumeMux = http.NewServeMux()
  264. }
  265. if *fo.portGrpc == 0 {
  266. *fo.portGrpc = 10000 + *fo.port
  267. }
  268. if *fo.bindIp == "" {
  269. *fo.bindIp = *fo.ip
  270. }
  271. if *fo.allowedOrigins == "" {
  272. *fo.allowedOrigins = "*"
  273. }
  274. defaultLevelDbDirectory := util.ResolvePath(*fo.defaultLevelDbDirectory + "/filerldb2")
  275. filerAddress := pb.NewServerAddress(*fo.ip, *fo.port, *fo.portGrpc)
  276. fs, nfs_err := weed_server.NewFilerServer(defaultMux, publicVolumeMux, &weed_server.FilerOption{
  277. Masters: fo.masters,
  278. FilerGroup: *fo.filerGroup,
  279. Collection: *fo.collection,
  280. DefaultReplication: *fo.defaultReplicaPlacement,
  281. DisableDirListing: *fo.disableDirListing,
  282. MaxMB: *fo.maxMB,
  283. DirListingLimit: *fo.dirListingLimit,
  284. DataCenter: *fo.dataCenter,
  285. Rack: *fo.rack,
  286. DefaultLevelDbDir: defaultLevelDbDirectory,
  287. DisableHttp: *fo.disableHttp,
  288. Host: filerAddress,
  289. Cipher: *fo.cipher,
  290. SaveToFilerLimit: int64(*fo.saveToFilerLimit),
  291. ConcurrentUploadLimit: int64(*fo.concurrentUploadLimitMB) * 1024 * 1024,
  292. ShowUIDirectoryDelete: *fo.showUIDirectoryDelete,
  293. DownloadMaxBytesPs: int64(*fo.downloadMaxMBps) * 1024 * 1024,
  294. DiskType: *fo.diskType,
  295. AllowedOrigins: strings.Split(*fo.allowedOrigins, ","),
  296. })
  297. if nfs_err != nil {
  298. glog.Fatalf("Filer startup error: %v", nfs_err)
  299. }
  300. if *fo.publicPort != 0 {
  301. publicListeningAddress := util.JoinHostPort(*fo.bindIp, *fo.publicPort)
  302. glog.V(0).Infoln("Start Seaweed filer server", version.Version(), "public at", publicListeningAddress)
  303. publicListener, localPublicListener, e := util.NewIpAndLocalListeners(*fo.bindIp, *fo.publicPort, 0)
  304. if e != nil {
  305. glog.Fatalf("Filer server public listener error on port %d:%v", *fo.publicPort, e)
  306. }
  307. go func() {
  308. if e := http.Serve(publicListener, publicVolumeMux); e != nil {
  309. glog.Fatalf("Volume server fail to serve public: %v", e)
  310. }
  311. }()
  312. if localPublicListener != nil {
  313. go func() {
  314. if e := http.Serve(localPublicListener, publicVolumeMux); e != nil {
  315. glog.Errorf("Volume server fail to serve public: %v", e)
  316. }
  317. }()
  318. }
  319. }
  320. glog.V(0).Infof("Start Seaweed Filer %s at %s:%d", version.Version(), *fo.ip, *fo.port)
  321. filerListener, filerLocalListener, e := util.NewIpAndLocalListeners(
  322. *fo.bindIp, *fo.port,
  323. time.Duration(10)*time.Second,
  324. )
  325. if e != nil {
  326. glog.Fatalf("Filer listener error: %v", e)
  327. }
  328. // starting grpc server
  329. grpcPort := *fo.portGrpc
  330. grpcL, grpcLocalL, err := util.NewIpAndLocalListeners(*fo.bindIp, grpcPort, 0)
  331. if err != nil {
  332. glog.Fatalf("failed to listen on grpc port %d: %v", grpcPort, err)
  333. }
  334. grpcS := pb.NewGrpcServer(security.LoadServerTLS(util.GetViper(), "grpc.filer"))
  335. filer_pb.RegisterSeaweedFilerServer(grpcS, fs)
  336. reflection.Register(grpcS)
  337. if grpcLocalL != nil {
  338. go grpcS.Serve(grpcLocalL)
  339. }
  340. go grpcS.Serve(grpcL)
  341. if runtime.GOOS != "windows" {
  342. localSocket := *fo.localSocket
  343. if localSocket == "" {
  344. localSocket = fmt.Sprintf("/tmp/seaweedfs-filer-%d.sock", *fo.port)
  345. }
  346. if err := os.Remove(localSocket); err != nil && !os.IsNotExist(err) {
  347. glog.Fatalf("Failed to remove %s, error: %s", localSocket, err.Error())
  348. }
  349. go func() {
  350. // start on local unix socket
  351. filerSocketListener, err := net.Listen("unix", localSocket)
  352. if err != nil {
  353. glog.Fatalf("Failed to listen on %s: %v", localSocket, err)
  354. }
  355. newHttpServer(defaultMux, nil).Serve(filerSocketListener)
  356. }()
  357. }
  358. if viper.GetString("https.filer.key") != "" {
  359. certFile := viper.GetString("https.filer.cert")
  360. keyFile := viper.GetString("https.filer.key")
  361. caCertFile := viper.GetString("https.filer.ca")
  362. disbaleTlsVerifyClientCert := viper.GetBool("https.filer.disable_tls_verify_client_cert")
  363. pemfileOptions := pemfile.Options{
  364. CertFile: certFile,
  365. KeyFile: keyFile,
  366. RefreshDuration: security.CredRefreshingInterval,
  367. }
  368. if fo.certProvider, err = pemfile.NewProvider(pemfileOptions); err != nil {
  369. glog.Fatalf("pemfile.NewProvider(%v) failed: %v", pemfileOptions, err)
  370. }
  371. caCertPool := x509.NewCertPool()
  372. if caCertFile != "" {
  373. caCertFile, err := os.ReadFile(caCertFile)
  374. if err != nil {
  375. glog.Fatalf("error reading CA certificate: %v", err)
  376. }
  377. caCertPool.AppendCertsFromPEM(caCertFile)
  378. }
  379. clientAuth := tls.NoClientCert
  380. if !disbaleTlsVerifyClientCert {
  381. clientAuth = tls.RequireAndVerifyClientCert
  382. }
  383. tlsConfig := &tls.Config{
  384. GetCertificate: fo.GetCertificateWithUpdate,
  385. ClientAuth: clientAuth,
  386. ClientCAs: caCertPool,
  387. }
  388. security.FixTlsConfig(util.GetViper(), tlsConfig)
  389. if filerLocalListener != nil {
  390. go func() {
  391. if err := newHttpServer(defaultMux, tlsConfig).ServeTLS(filerLocalListener, "", ""); err != nil {
  392. glog.Errorf("Filer Fail to serve: %v", e)
  393. }
  394. }()
  395. }
  396. if err := newHttpServer(defaultMux, tlsConfig).ServeTLS(filerListener, "", ""); err != nil {
  397. glog.Fatalf("Filer Fail to serve: %v", e)
  398. }
  399. } else {
  400. if filerLocalListener != nil {
  401. go func() {
  402. if err := newHttpServer(defaultMux, nil).Serve(filerLocalListener); err != nil {
  403. glog.Errorf("Filer Fail to serve: %v", e)
  404. }
  405. }()
  406. }
  407. if err := newHttpServer(defaultMux, nil).Serve(filerListener); err != nil {
  408. glog.Fatalf("Filer Fail to serve: %v", e)
  409. }
  410. }
  411. }