docker_client.py 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120
  1. from __future__ import absolute_import
  2. from __future__ import unicode_literals
  3. import logging
  4. import os.path
  5. import ssl
  6. from docker import APIClient
  7. from docker.errors import TLSParameterError
  8. from docker.tls import TLSConfig
  9. from docker.utils import kwargs_from_env
  10. from docker.utils.config import home_dir
  11. from ..config.environment import Environment
  12. from ..const import HTTP_TIMEOUT
  13. from .errors import UserError
  14. from .utils import generate_user_agent
  15. from .utils import unquote_path
  16. log = logging.getLogger(__name__)
  17. def default_cert_path():
  18. return os.path.join(home_dir(), '.docker')
  19. def get_tls_version(environment):
  20. compose_tls_version = environment.get('COMPOSE_TLS_VERSION', None)
  21. if not compose_tls_version:
  22. return None
  23. tls_attr_name = "PROTOCOL_{}".format(compose_tls_version)
  24. if not hasattr(ssl, tls_attr_name):
  25. log.warn(
  26. 'The "{}" protocol is unavailable. You may need to update your '
  27. 'version of Python or OpenSSL. Falling back to TLSv1 (default).'
  28. .format(compose_tls_version)
  29. )
  30. return None
  31. return getattr(ssl, tls_attr_name)
  32. def tls_config_from_options(options, environment=None):
  33. environment = environment or Environment()
  34. cert_path = environment.get('DOCKER_CERT_PATH') or None
  35. tls = options.get('--tls', False)
  36. ca_cert = unquote_path(options.get('--tlscacert'))
  37. cert = unquote_path(options.get('--tlscert'))
  38. key = unquote_path(options.get('--tlskey'))
  39. # verify is a special case - with docopt `--tlsverify` = False means it
  40. # wasn't used, so we set it if either the environment or the flag is True
  41. # see https://github.com/docker/compose/issues/5632
  42. verify = options.get('--tlsverify') or environment.get_boolean('DOCKER_TLS_VERIFY')
  43. skip_hostname_check = options.get('--skip-hostname-check', False)
  44. if cert_path is not None and not any((ca_cert, cert, key)):
  45. # FIXME: Modify TLSConfig to take a cert_path argument and do this internally
  46. cert = os.path.join(cert_path, 'cert.pem')
  47. key = os.path.join(cert_path, 'key.pem')
  48. ca_cert = os.path.join(cert_path, 'ca.pem')
  49. if verify and not any((ca_cert, cert, key)):
  50. # Default location for cert files is ~/.docker
  51. ca_cert = os.path.join(default_cert_path(), 'ca.pem')
  52. cert = os.path.join(default_cert_path(), 'cert.pem')
  53. key = os.path.join(default_cert_path(), 'key.pem')
  54. tls_version = get_tls_version(environment)
  55. advanced_opts = any([ca_cert, cert, key, verify, tls_version])
  56. if tls is True and not advanced_opts:
  57. return True
  58. elif advanced_opts: # --tls is a noop
  59. client_cert = None
  60. if cert or key:
  61. client_cert = (cert, key)
  62. return TLSConfig(
  63. client_cert=client_cert, verify=verify, ca_cert=ca_cert,
  64. assert_hostname=False if skip_hostname_check else None,
  65. ssl_version=tls_version
  66. )
  67. return None
  68. def docker_client(environment, version=None, tls_config=None, host=None,
  69. tls_version=None):
  70. """
  71. Returns a docker-py client configured using environment variables
  72. according to the same logic as the official Docker client.
  73. """
  74. try:
  75. kwargs = kwargs_from_env(environment=environment, ssl_version=tls_version)
  76. except TLSParameterError:
  77. raise UserError(
  78. "TLS configuration is invalid - make sure your DOCKER_TLS_VERIFY "
  79. "and DOCKER_CERT_PATH are set correctly.\n"
  80. "You might need to run `eval \"$(docker-machine env default)\"`")
  81. if host:
  82. kwargs['base_url'] = host
  83. if tls_config:
  84. kwargs['tls'] = tls_config
  85. if version:
  86. kwargs['version'] = version
  87. timeout = environment.get('COMPOSE_HTTP_TIMEOUT')
  88. if timeout:
  89. kwargs['timeout'] = int(timeout)
  90. else:
  91. kwargs['timeout'] = HTTP_TIMEOUT
  92. kwargs['user_agent'] = generate_user_agent()
  93. return APIClient(**kwargs)