ipsec_network.go 5.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207
  1. // Copyright 2017 flannel authors
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // http://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. // +build !windows
  15. package ipsec
  16. import (
  17. "fmt"
  18. "net"
  19. "strconv"
  20. "sync"
  21. "github.com/flannel-io/flannel/backend"
  22. "github.com/flannel-io/flannel/subnet"
  23. "github.com/vishvananda/netlink"
  24. "golang.org/x/net/context"
  25. log "k8s.io/klog"
  26. )
  27. const (
  28. /*
  29. New IP header (Tunnel Mode) : 20
  30. SPI (ESP Header) : 4
  31. Sequence (ESP Header) : 4
  32. ESP-AES IV : 16
  33. ESP-AES Pad : 0-15
  34. Pad length (ESP Trailer) : 1
  35. Next Header (ESP Trailer) : 1
  36. ESP-SHA-256 ICV : 16
  37. */
  38. ipsecOverhead = 77
  39. udpEncapOverhead = 8
  40. defaultReqID = 11
  41. )
  42. type network struct {
  43. backend.SimpleNetwork
  44. password string
  45. UDPEncap bool
  46. sm subnet.Manager
  47. iked *CharonIKEDaemon
  48. }
  49. func newNetwork(sm subnet.Manager, extIface *backend.ExternalInterface,
  50. UDPEncap bool, password string, ikeDaemon *CharonIKEDaemon,
  51. l *subnet.Lease) (*network, error) {
  52. n := &network{
  53. SimpleNetwork: backend.SimpleNetwork{
  54. SubnetLease: l,
  55. ExtIface: extIface,
  56. },
  57. sm: sm,
  58. iked: ikeDaemon,
  59. password: password,
  60. UDPEncap: UDPEncap,
  61. }
  62. return n, nil
  63. }
  64. func (n *network) Run(ctx context.Context) {
  65. err := n.iked.LoadSharedKey(n.SimpleNetwork.SubnetLease.Attrs.PublicIP.ToIP().String(), n.password)
  66. if err != nil {
  67. log.Errorf("Failed to load PSK: %v", err)
  68. return
  69. }
  70. wg := sync.WaitGroup{}
  71. defer wg.Wait()
  72. log.Info("Watching for new subnet leases")
  73. evts := make(chan []subnet.Event)
  74. wg.Add(1)
  75. go func() {
  76. subnet.WatchLeases(ctx, n.sm, n.SubnetLease, evts)
  77. log.Info("WatchLeases exited")
  78. wg.Done()
  79. }()
  80. for {
  81. select {
  82. case evtsBatch, ok := <-evts:
  83. if !ok {
  84. log.Infof("evts chan closed")
  85. return
  86. }
  87. log.Info("Handling event")
  88. n.handleSubnetEvents(evtsBatch)
  89. }
  90. }
  91. }
  92. func (n *network) handleSubnetEvents(batch []subnet.Event) {
  93. for _, evt := range batch {
  94. switch evt.Type {
  95. case subnet.EventAdded:
  96. log.Info("Subnet added: ", evt.Lease.Subnet)
  97. if evt.Lease.Attrs.BackendType != "ipsec" {
  98. log.Warningf("Ignoring non-ipsec event: type: %v", evt.Lease.Attrs.BackendType)
  99. continue
  100. }
  101. if evt.Lease.Subnet.Equal(n.SubnetLease.Subnet) {
  102. log.Warningf("Ignoring own lease add event: %+v", evt.Lease)
  103. continue
  104. }
  105. if err := n.AddIPSECPolicies(&evt.Lease, defaultReqID); err != nil {
  106. log.Errorf("error adding ipsec policy: %v", err)
  107. }
  108. if err := n.iked.LoadSharedKey(evt.Lease.Attrs.PublicIP.String(), n.password); err != nil {
  109. log.Errorf("error loading shared key into IKE daemon: %v", err)
  110. }
  111. if err := n.iked.LoadConnection(n.SubnetLease, &evt.Lease, strconv.Itoa(defaultReqID),
  112. strconv.FormatBool(n.UDPEncap)); err != nil {
  113. log.Errorf("error loading connection into IKE daemon: %v", err)
  114. }
  115. case subnet.EventRemoved:
  116. log.Info("Subnet removed: ", evt.Lease.Subnet)
  117. if evt.Lease.Attrs.BackendType != "ipsec" {
  118. log.Warningf("Ignoring non-ipsec event: type: %v", evt.Lease.Attrs.BackendType)
  119. continue
  120. }
  121. if evt.Lease.Subnet.Equal(n.SubnetLease.Subnet) {
  122. log.Warningf("Ignoring own lease remove event: %+v", evt.Lease)
  123. continue
  124. }
  125. if err := n.iked.UnloadCharonConnection(n.SubnetLease, &evt.Lease); err != nil {
  126. log.Errorf("error unloading charon connections: %v", err)
  127. }
  128. if err := n.DeleteIPSECPolicies(n.SubnetLease.Subnet.ToIPNet(), evt.Lease.Subnet.ToIPNet(),
  129. n.SubnetLease.Attrs.PublicIP.ToIP(), evt.Lease.Attrs.PublicIP.ToIP(), defaultReqID); err != nil {
  130. log.Errorf("error deleting ipsec policies: %v", err)
  131. }
  132. }
  133. }
  134. }
  135. func (n *network) MTU() int {
  136. mtu := n.ExtIface.Iface.MTU - ipsecOverhead
  137. if n.UDPEncap {
  138. mtu -= udpEncapOverhead
  139. }
  140. return mtu
  141. }
  142. func (n *network) AddIPSECPolicies(remoteLease *subnet.Lease, reqID int) error {
  143. err := AddXFRMPolicy(n.SubnetLease, remoteLease, netlink.XFRM_DIR_OUT, reqID)
  144. if err != nil {
  145. return fmt.Errorf("error adding ipsec out policy: %v", err)
  146. }
  147. err = AddXFRMPolicy(remoteLease, n.SubnetLease, netlink.XFRM_DIR_IN, reqID)
  148. if err != nil {
  149. return fmt.Errorf("error adding ipsec in policy: %v", err)
  150. }
  151. err = AddXFRMPolicy(remoteLease, n.SubnetLease, netlink.XFRM_DIR_FWD, reqID)
  152. if err != nil {
  153. return fmt.Errorf("error adding ipsec fwd policy: %v", err)
  154. }
  155. return nil
  156. }
  157. func (n *network) DeleteIPSECPolicies(localSubnet, remoteSubnet *net.IPNet, localPublicIP, remotePublicIP net.IP, reqID int) error {
  158. err := DeleteXFRMPolicy(localSubnet, remoteSubnet, localPublicIP, remotePublicIP, netlink.XFRM_DIR_OUT, reqID)
  159. if err != nil {
  160. return fmt.Errorf("error deleting ipsec out policy: %v", err)
  161. }
  162. err = DeleteXFRMPolicy(remoteSubnet, localSubnet, remotePublicIP, localPublicIP, netlink.XFRM_DIR_IN, reqID)
  163. if err != nil {
  164. return fmt.Errorf("error deleting ipsec in policy: %v", err)
  165. }
  166. err = DeleteXFRMPolicy(remoteSubnet, localSubnet, remotePublicIP, localPublicIP, netlink.XFRM_DIR_FWD, reqID)
  167. if err != nil {
  168. return fmt.Errorf("error deleting ipsec fwd policy: %v", err)
  169. }
  170. return nil
  171. }