docker_client.py 2.8 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495
  1. from __future__ import absolute_import
  2. from __future__ import unicode_literals
  3. import logging
  4. import ssl
  5. from docker import APIClient
  6. from docker.errors import TLSParameterError
  7. from docker.tls import TLSConfig
  8. from docker.utils import kwargs_from_env
  9. from ..const import HTTP_TIMEOUT
  10. from .errors import UserError
  11. from .utils import generate_user_agent
  12. from .utils import unquote_path
  13. log = logging.getLogger(__name__)
  14. def get_tls_version(environment):
  15. compose_tls_version = environment.get('COMPOSE_TLS_VERSION', None)
  16. if not compose_tls_version:
  17. return None
  18. tls_attr_name = "PROTOCOL_{}".format(compose_tls_version)
  19. if not hasattr(ssl, tls_attr_name):
  20. log.warn(
  21. 'The "{}" protocol is unavailable. You may need to update your '
  22. 'version of Python or OpenSSL. Falling back to TLSv1 (default).'
  23. .format(compose_tls_version)
  24. )
  25. return None
  26. return getattr(ssl, tls_attr_name)
  27. def tls_config_from_options(options, environment=None):
  28. tls = options.get('--tls', False)
  29. ca_cert = unquote_path(options.get('--tlscacert'))
  30. cert = unquote_path(options.get('--tlscert'))
  31. key = unquote_path(options.get('--tlskey'))
  32. verify = options.get('--tlsverify')
  33. skip_hostname_check = options.get('--skip-hostname-check', False)
  34. tls_version = get_tls_version(environment or {})
  35. advanced_opts = any([ca_cert, cert, key, verify, tls_version])
  36. if tls is True and not advanced_opts:
  37. return True
  38. elif advanced_opts: # --tls is a noop
  39. client_cert = None
  40. if cert or key:
  41. client_cert = (cert, key)
  42. return TLSConfig(
  43. client_cert=client_cert, verify=verify, ca_cert=ca_cert,
  44. assert_hostname=False if skip_hostname_check else None,
  45. ssl_version=tls_version
  46. )
  47. return None
  48. def docker_client(environment, version=None, tls_config=None, host=None,
  49. tls_version=None):
  50. """
  51. Returns a docker-py client configured using environment variables
  52. according to the same logic as the official Docker client.
  53. """
  54. try:
  55. kwargs = kwargs_from_env(environment=environment, ssl_version=tls_version)
  56. except TLSParameterError:
  57. raise UserError(
  58. "TLS configuration is invalid - make sure your DOCKER_TLS_VERIFY "
  59. "and DOCKER_CERT_PATH are set correctly.\n"
  60. "You might need to run `eval \"$(docker-machine env default)\"`")
  61. if host:
  62. kwargs['base_url'] = host
  63. if tls_config:
  64. kwargs['tls'] = tls_config
  65. if version:
  66. kwargs['version'] = version
  67. timeout = environment.get('COMPOSE_HTTP_TIMEOUT')
  68. if timeout:
  69. kwargs['timeout'] = int(timeout)
  70. else:
  71. kwargs['timeout'] = HTTP_TIMEOUT
  72. kwargs['user_agent'] = generate_user_agent()
  73. return APIClient(**kwargs)