ip_ranges.js 3.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147
  1. const https = require('https');
  2. const fs = require('fs');
  3. const logger = require('../logger').ip_ranges;
  4. const error = require('../lib/error');
  5. const internalNginx = require('./nginx');
  6. const { Liquid } = require('liquidjs');
  7. const CLOUDFRONT_URL = 'https://ip-ranges.amazonaws.com/ip-ranges.json';
  8. const CLOUDFARE_V4_URL = 'https://www.cloudflare.com/ips-v4';
  9. const CLOUDFARE_V6_URL = 'https://www.cloudflare.com/ips-v6';
  10. const internalIpRanges = {
  11. interval_timeout: 1000 * 60 * 60 * 6, // 6 hours
  12. interval: null,
  13. interval_processing: false,
  14. iteration_count: 0,
  15. initTimer: () => {
  16. logger.info('IP Ranges Renewal Timer initialized');
  17. internalIpRanges.interval = setInterval(internalIpRanges.fetch, internalIpRanges.interval_timeout);
  18. },
  19. fetchUrl: (url) => {
  20. return new Promise((resolve, reject) => {
  21. logger.info('Fetching ' + url);
  22. return https.get(url, (res) => {
  23. res.setEncoding('utf8');
  24. let raw_data = '';
  25. res.on('data', (chunk) => {
  26. raw_data += chunk;
  27. });
  28. res.on('end', () => {
  29. resolve(raw_data);
  30. });
  31. }).on('error', (err) => {
  32. reject(err);
  33. });
  34. });
  35. },
  36. /**
  37. * Triggered at startup and then later by a timer, this will fetch the ip ranges from services and apply them to nginx.
  38. */
  39. fetch: () => {
  40. if (!internalIpRanges.interval_processing) {
  41. internalIpRanges.interval_processing = true;
  42. logger.info('Fetching IP Ranges from online services...');
  43. let ip_ranges = [];
  44. return internalIpRanges.fetchUrl(CLOUDFRONT_URL)
  45. .then((cloudfront_data) => {
  46. let data = JSON.parse(cloudfront_data);
  47. if (data && typeof data.prefixes !== 'undefined') {
  48. data.prefixes.map((item) => {
  49. if (item.service === 'CLOUDFRONT') {
  50. ip_ranges.push(item.ip_prefix);
  51. }
  52. });
  53. }
  54. if (data && typeof data.ipv6_prefixes !== 'undefined') {
  55. data.ipv6_prefixes.map((item) => {
  56. if (item.service === 'CLOUDFRONT') {
  57. ip_ranges.push(item.ipv6_prefix);
  58. }
  59. });
  60. }
  61. })
  62. .then(() => {
  63. return internalIpRanges.fetchUrl(CLOUDFARE_V4_URL);
  64. })
  65. .then((cloudfare_data) => {
  66. let items = cloudfare_data.split('\n');
  67. ip_ranges = [... ip_ranges, ... items];
  68. })
  69. .then(() => {
  70. return internalIpRanges.fetchUrl(CLOUDFARE_V6_URL);
  71. })
  72. .then((cloudfare_data) => {
  73. let items = cloudfare_data.split('\n');
  74. ip_ranges = [... ip_ranges, ... items];
  75. })
  76. .then(() => {
  77. let clean_ip_ranges = [];
  78. ip_ranges.map((range) => {
  79. if (range) {
  80. clean_ip_ranges.push(range);
  81. }
  82. });
  83. return internalIpRanges.generateConfig(clean_ip_ranges)
  84. .then(() => {
  85. if (internalIpRanges.iteration_count) {
  86. // Reload nginx
  87. return internalNginx.reload();
  88. }
  89. });
  90. })
  91. .then(() => {
  92. internalIpRanges.interval_processing = false;
  93. internalIpRanges.iteration_count++;
  94. })
  95. .catch((err) => {
  96. logger.error(err.message);
  97. internalIpRanges.interval_processing = false;
  98. });
  99. }
  100. },
  101. /**
  102. * @param {Array} ip_ranges
  103. * @returns {Promise}
  104. */
  105. generateConfig: (ip_ranges) => {
  106. let renderEngine = new Liquid({
  107. root: __dirname + '/../templates/'
  108. });
  109. return new Promise((resolve, reject) => {
  110. let template = null;
  111. let filename = '/etc/nginx/conf.d/include/ip_ranges.conf';
  112. try {
  113. template = fs.readFileSync(__dirname + '/../templates/ip_ranges.conf', {encoding: 'utf8'});
  114. } catch (err) {
  115. reject(new error.ConfigurationError(err.message));
  116. return;
  117. }
  118. renderEngine
  119. .parseAndRender(template, {ip_ranges: ip_ranges})
  120. .then((config_text) => {
  121. fs.writeFileSync(filename, config_text, {encoding: 'utf8'});
  122. resolve(true);
  123. })
  124. .catch((err) => {
  125. logger.warn('Could not write ' + filename + ':', err.message);
  126. reject(new error.ConfigurationError(err.message));
  127. });
  128. });
  129. }
  130. };
  131. module.exports = internalIpRanges;