|
| 1 | +// Copyright (c) Ultraviolet |
| 2 | +// SPDX-License-Identifier: Apache-2.0 |
| 3 | + |
| 4 | +package agent |
| 5 | + |
| 6 | +import ( |
| 7 | + "crypto/tls" |
| 8 | + "fmt" |
| 9 | + "log" |
| 10 | + "net/http" |
| 11 | + "net/http/httputil" |
| 12 | + "net/url" |
| 13 | + "time" |
| 14 | + |
| 15 | + "github.com/absmach/supermq/api/http/util" |
| 16 | + "github.com/absmach/supermq/pkg/authn" |
| 17 | + "github.com/absmach/supermq/pkg/errors" |
| 18 | + "github.com/ultravioletrs/cocos/pkg/attestation" |
| 19 | + "github.com/ultravioletrs/cocos/pkg/attestation/quoteprovider" |
| 20 | + "github.com/ultravioletrs/cocos/pkg/attestation/vtpm" |
| 21 | +) |
| 22 | + |
| 23 | +var ( |
| 24 | + // ErrAttestationFailed indicates that attestation failed. |
| 25 | + ErrAttestationFailed = errors.New("attestation failed") |
| 26 | + // ErrAttestationVTpmFailed indicates that vTPM attestation failed. |
| 27 | + ErrAttestationVTpmFailed = errors.New("vTPM attestation failed") |
| 28 | + // ErrAttestationType indicates that the attestation type is invalid. |
| 29 | + ErrAttestationType = errors.New("invalid attestation type") |
| 30 | + // ErrUnauthorized indicates that authentication failed. |
| 31 | + ErrUnauthorized = errors.New("unauthorized") |
| 32 | +) |
| 33 | + |
| 34 | +type TLSConfig struct { |
| 35 | + Enabled bool |
| 36 | + InsecureSkipVerify bool |
| 37 | + CertFile string |
| 38 | + KeyFile string |
| 39 | + CAFile string |
| 40 | + MinVersion uint16 |
| 41 | + MaxVersion uint16 |
| 42 | +} |
| 43 | + |
| 44 | +type Config struct { |
| 45 | + OllamaURL string |
| 46 | + TLS TLSConfig |
| 47 | +} |
| 48 | + |
| 49 | +type agentService struct { |
| 50 | + config *Config |
| 51 | + provider attestation.Provider |
| 52 | + transport *http.Transport |
| 53 | + auth authn.Authentication |
| 54 | +} |
| 55 | + |
| 56 | +type Service interface { |
| 57 | + Proxy() *httputil.ReverseProxy |
| 58 | + Attestation( |
| 59 | + reportData [quoteprovider.Nonce]byte, nonce [vtpm.Nonce]byte, attType attestation.PlatformType, |
| 60 | + ) ([]byte, error) |
| 61 | + Authenticate(req *http.Request) error |
| 62 | + AuthMiddleware(next http.Handler) http.Handler |
| 63 | +} |
| 64 | + |
| 65 | +func New(config *Config, auth authn.Authentication, provider attestation.Provider) (Service, error) { |
| 66 | + if config.OllamaURL == "" { |
| 67 | + return nil, errors.New("ollama URL is required") |
| 68 | + } |
| 69 | + |
| 70 | + transport := &http.Transport{ |
| 71 | + MaxIdleConns: 100, |
| 72 | + IdleConnTimeout: 90 * time.Second, |
| 73 | + TLSHandshakeTimeout: 10 * time.Second, |
| 74 | + } |
| 75 | + |
| 76 | + if config.TLS.Enabled { |
| 77 | + tlsConfig, err := setTLSConfig(config) |
| 78 | + if err != nil { |
| 79 | + return nil, fmt.Errorf("failed to set TLS config: %w", err) |
| 80 | + } |
| 81 | + |
| 82 | + transport.TLSClientConfig = tlsConfig |
| 83 | + } |
| 84 | + |
| 85 | + return &agentService{ |
| 86 | + config: config, |
| 87 | + transport: transport, |
| 88 | + provider: provider, |
| 89 | + auth: auth, |
| 90 | + }, nil |
| 91 | +} |
| 92 | + |
| 93 | +func (a *agentService) Authenticate(req *http.Request) error { |
| 94 | + token := util.ExtractBearerToken(req) |
| 95 | + |
| 96 | + if token == "" { |
| 97 | + return errors.Wrap(ErrUnauthorized, errors.New("missing or invalid token")) |
| 98 | + } |
| 99 | + |
| 100 | + _, err := a.auth.Authenticate(req.Context(), token) |
| 101 | + if err != nil { |
| 102 | + return errors.Wrap(ErrUnauthorized, err) |
| 103 | + } |
| 104 | + |
| 105 | + return nil |
| 106 | +} |
| 107 | + |
| 108 | +func (a *agentService) Proxy() *httputil.ReverseProxy { |
| 109 | + target, err := url.Parse(a.config.OllamaURL) |
| 110 | + if err != nil { |
| 111 | + log.Printf("Invalid Ollama URL: %v", err) |
| 112 | + |
| 113 | + return nil |
| 114 | + } |
| 115 | + |
| 116 | + proxy := httputil.NewSingleHostReverseProxy(target) |
| 117 | + |
| 118 | + proxy.Transport = a.transport |
| 119 | + |
| 120 | + originalDirector := proxy.Director |
| 121 | + proxy.Director = func(req *http.Request) { |
| 122 | + originalDirector(req) |
| 123 | + a.modifyHeaders(req) |
| 124 | + log.Printf("Agent forwarding to Ollama: %s %s", req.Method, req.URL.Path) |
| 125 | + } |
| 126 | + |
| 127 | + proxy.ErrorHandler = func(w http.ResponseWriter, _ *http.Request, err error) { |
| 128 | + log.Printf("Proxy error: %v", err) |
| 129 | + http.Error(w, "Bad Gateway", http.StatusBadGateway) |
| 130 | + } |
| 131 | + |
| 132 | + return proxy |
| 133 | +} |
| 134 | + |
| 135 | +func (a *agentService) Attestation( |
| 136 | + reportData [quoteprovider.Nonce]byte, nonce [vtpm.Nonce]byte, attType attestation.PlatformType, |
| 137 | +) ([]byte, error) { |
| 138 | + switch attType { |
| 139 | + case attestation.SNP, attestation.TDX: |
| 140 | + rawQuote, err := a.provider.TeeAttestation(reportData[:]) |
| 141 | + if err != nil { |
| 142 | + return []byte{}, errors.Wrap(ErrAttestationFailed, err) |
| 143 | + } |
| 144 | + |
| 145 | + return rawQuote, nil |
| 146 | + case attestation.VTPM: |
| 147 | + vTPMQuote, err := a.provider.VTpmAttestation(nonce[:]) |
| 148 | + if err != nil { |
| 149 | + return []byte{}, errors.Wrap(ErrAttestationVTpmFailed, err) |
| 150 | + } |
| 151 | + |
| 152 | + return vTPMQuote, nil |
| 153 | + case attestation.SNPvTPM: |
| 154 | + vTPMQuote, err := a.provider.Attestation(reportData[:], nonce[:]) |
| 155 | + if err != nil { |
| 156 | + return []byte{}, errors.Wrap(ErrAttestationVTpmFailed, err) |
| 157 | + } |
| 158 | + |
| 159 | + return vTPMQuote, nil |
| 160 | + case attestation.Azure, attestation.NoCC, attestation.AzureToken: |
| 161 | + return []byte{}, ErrAttestationType |
| 162 | + default: |
| 163 | + return []byte{}, ErrAttestationType |
| 164 | + } |
| 165 | +} |
| 166 | + |
| 167 | +func (a *agentService) AuthMiddleware(next http.Handler) http.Handler { |
| 168 | + return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { |
| 169 | + err := a.Authenticate(r) |
| 170 | + if err != nil { |
| 171 | + log.Printf("Authentication failed: %v", err) |
| 172 | + http.Error(w, "Unauthorized", http.StatusUnauthorized) |
| 173 | + |
| 174 | + return |
| 175 | + } |
| 176 | + |
| 177 | + next.ServeHTTP(w, r) |
| 178 | + }) |
| 179 | +} |
| 180 | + |
| 181 | +func DefaultTLSConfig() TLSConfig { |
| 182 | + return TLSConfig{ |
| 183 | + Enabled: true, |
| 184 | + InsecureSkipVerify: false, |
| 185 | + MinVersion: tls.VersionTLS12, |
| 186 | + MaxVersion: tls.VersionTLS13, |
| 187 | + } |
| 188 | +} |
| 189 | + |
| 190 | +func InsecureTLSConfig() TLSConfig { |
| 191 | + return TLSConfig{ |
| 192 | + Enabled: true, |
| 193 | + InsecureSkipVerify: true, |
| 194 | + MinVersion: tls.VersionTLS12, |
| 195 | + MaxVersion: tls.VersionTLS13, |
| 196 | + } |
| 197 | +} |
| 198 | + |
| 199 | +func (a *agentService) modifyHeaders(req *http.Request) { |
| 200 | + req.Header.Set("Content-Type", "application/json") |
| 201 | + |
| 202 | + req.Header.Del("Authorization") |
| 203 | +} |
| 204 | + |
| 205 | +func setTLSConfig(config *Config) (*tls.Config, error) { |
| 206 | + tlsConfig := &tls.Config{ |
| 207 | + InsecureSkipVerify: config.TLS.InsecureSkipVerify, |
| 208 | + } |
| 209 | + |
| 210 | + if config.TLS.MinVersion != 0 { |
| 211 | + tlsConfig.MinVersion = config.TLS.MinVersion |
| 212 | + } |
| 213 | + |
| 214 | + if config.TLS.MaxVersion != 0 { |
| 215 | + tlsConfig.MaxVersion = config.TLS.MaxVersion |
| 216 | + } |
| 217 | + |
| 218 | + if config.TLS.CertFile != "" && config.TLS.KeyFile != "" { |
| 219 | + cert, err := tls.LoadX509KeyPair(config.TLS.CertFile, config.TLS.KeyFile) |
| 220 | + if err != nil { |
| 221 | + return nil, fmt.Errorf("failed to load client certificate: %w", err) |
| 222 | + } |
| 223 | + |
| 224 | + tlsConfig.Certificates = []tls.Certificate{cert} |
| 225 | + } |
| 226 | + |
| 227 | + return tlsConfig, nil |
| 228 | +} |
0 commit comments