mirror of
https://github.com/telemt/telemt.git
synced 2026-10-11 11:55:59 +03:00
Proxy Shared User Drafts
This commit is contained in:
@@ -108,7 +108,7 @@ pub(super) async fn run_telemt_core(
|
||||
);
|
||||
let shared_state =
|
||||
ProxySharedState::new_with_direct_buffer_budget(direct_buffer_budget.clone());
|
||||
shared_state.apply_user_enabled_config(&config.access.user_enabled);
|
||||
shared_state.apply_user_config(&config.access.users, &config.access.user_enabled);
|
||||
shared_state.traffic_limiter.apply_policy(
|
||||
config.access.user_rate_limits.clone(),
|
||||
config.access.cidr_rate_limits.clone(),
|
||||
|
||||
@@ -177,6 +177,7 @@ impl ReloadSupervisor {
|
||||
self.quota_store.clone(),
|
||||
self.runtime_log_filter.clone(),
|
||||
self.tls_full_cert_budget.clone(),
|
||||
old_runtime.proxy_shared.user_admission(),
|
||||
)
|
||||
.await
|
||||
{
|
||||
@@ -277,6 +278,7 @@ impl ReloadSupervisor {
|
||||
generation: new_runtime,
|
||||
detected_ips,
|
||||
config_watcher_activation,
|
||||
user_admission_epoch,
|
||||
} = prepared;
|
||||
let pending_listener_transition = if let Some(listener_transition) = listener_transition {
|
||||
match self
|
||||
@@ -300,6 +302,12 @@ impl ReloadSupervisor {
|
||||
};
|
||||
let replaced = {
|
||||
let listener_manager = self.listener_manager.lock().await;
|
||||
let config = new_runtime.config();
|
||||
let _ = new_runtime.proxy_shared.apply_user_config_if_epoch(
|
||||
user_admission_epoch,
|
||||
&config.access.users,
|
||||
&config.access.user_enabled,
|
||||
);
|
||||
old_runtime.stop_accepting_sessions();
|
||||
listener_manager.activate_runtime_generation(new_runtime.clone())
|
||||
};
|
||||
|
||||
@@ -23,10 +23,12 @@ fn runtime_log_filter() -> RuntimeLogFilter {
|
||||
|
||||
fn prepared_runtime(generation: Arc<RuntimeGeneration>) -> PreparedRuntime {
|
||||
let (config_watcher_activation, _activation_rx) = watch::channel(false);
|
||||
let user_admission_epoch = generation.proxy_shared.user_admission().epoch();
|
||||
PreparedRuntime {
|
||||
generation,
|
||||
detected_ips: (None, None),
|
||||
config_watcher_activation,
|
||||
user_admission_epoch,
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -16,6 +16,7 @@ use crate::proxy::direct_buffer_budget::{
|
||||
};
|
||||
use crate::proxy::route_mode::{RelayRouteMode, RouteRuntimeController};
|
||||
use crate::proxy::shared_state::ProxySharedState;
|
||||
use crate::proxy::user_admission::UserAdmissionAuthority;
|
||||
use crate::startup::StartupTracker;
|
||||
use crate::stats::beobachten::BeobachtenStore;
|
||||
use crate::stats::telemetry::TelemetryPolicy;
|
||||
@@ -39,6 +40,8 @@ pub(crate) struct PreparedRuntime {
|
||||
pub(crate) detected_ips: (Option<IpAddr>, Option<IpAddr>),
|
||||
/// Gate opened only after the candidate becomes the active generation.
|
||||
pub(crate) config_watcher_activation: watch::Sender<bool>,
|
||||
/// User-authority epoch captured before candidate construction.
|
||||
pub(crate) user_admission_epoch: u64,
|
||||
}
|
||||
|
||||
pub(crate) async fn prepare_runtime(
|
||||
@@ -48,7 +51,9 @@ pub(crate) async fn prepare_runtime(
|
||||
quota_store: Arc<QuotaStore>,
|
||||
runtime_log_filter: RuntimeLogFilter,
|
||||
tls_full_cert_budget: Arc<TlsFullCertBudget>,
|
||||
user_admission: Arc<UserAdmissionAuthority>,
|
||||
) -> Result<PreparedRuntime, String> {
|
||||
let user_admission_epoch = user_admission.epoch();
|
||||
config
|
||||
.validate_web_decoy_listener_separation()
|
||||
.map_err(|error| error.to_string())?;
|
||||
@@ -92,9 +97,10 @@ pub(crate) async fn prepare_runtime(
|
||||
let hard_limit =
|
||||
resolve_direct_buffer_hard_limit(config.general.direct_relay_buffer_budget_max_bytes).await;
|
||||
let direct_buffer_budget = DirectBufferBudget::new(hard_limit);
|
||||
let proxy_shared =
|
||||
ProxySharedState::new_with_direct_buffer_budget(direct_buffer_budget.clone());
|
||||
proxy_shared.apply_user_enabled_config(&config.access.user_enabled);
|
||||
let proxy_shared = ProxySharedState::new_with_direct_buffer_budget_and_user_admission(
|
||||
direct_buffer_budget.clone(),
|
||||
user_admission,
|
||||
);
|
||||
proxy_shared.traffic_limiter.apply_policy(
|
||||
config.access.user_rate_limits.clone(),
|
||||
config.access.cidr_rate_limits.clone(),
|
||||
@@ -311,6 +317,7 @@ pub(crate) async fn prepare_runtime(
|
||||
Ok(PreparedRuntime {
|
||||
generation,
|
||||
config_watcher_activation,
|
||||
user_admission_epoch,
|
||||
detected_ips: (
|
||||
probe.detected_ipv4.map(IpAddr::V4),
|
||||
probe.detected_ipv6.map(IpAddr::V6),
|
||||
|
||||
@@ -288,8 +288,8 @@ pub(crate) async fn spawn_runtime_tasks(
|
||||
break;
|
||||
}
|
||||
let cfg = config_rx_user_enabled.borrow_and_update().clone();
|
||||
for (user, cancelled) in
|
||||
shared_user_enabled.apply_user_enabled_config(&cfg.access.user_enabled)
|
||||
for (user, cancelled) in shared_user_enabled
|
||||
.apply_user_config(&cfg.access.users, &cfg.access.user_enabled)
|
||||
{
|
||||
if cancelled > 0 {
|
||||
info!(
|
||||
|
||||
Reference in New Issue
Block a user