ip_ranges.js 4.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147
  1. const https = require('https');
  2. const fs = require('fs');
  3. const logger = require('../logger').ip_ranges;
  4. const error = require('../lib/error');
  5. const utils = require('../lib/utils');
  6. const internalNginx = require('./nginx');
  7. const CLOUDFRONT_URL = 'https://ip-ranges.amazonaws.com/ip-ranges.json';
  8. const CLOUDFARE_V4_URL = 'https://www.cloudflare.com/ips-v4';
  9. const CLOUDFARE_V6_URL = 'https://www.cloudflare.com/ips-v6';
  10. const regIpV4 = /^(\d+\.?){4}\/\d+/;
  11. const regIpV6 = /^(([\da-fA-F]+)?:)+\/\d+/;
  12. const internalIpRanges = {
  13. interval_timeout: 1000 * 60 * 60 * 6, // 6 hours
  14. interval: null,
  15. interval_processing: false,
  16. iteration_count: 0,
  17. initTimer: () => {
  18. logger.info('IP Ranges Renewal Timer initialized');
  19. internalIpRanges.interval = setInterval(internalIpRanges.fetch, internalIpRanges.interval_timeout);
  20. },
  21. fetchUrl: (url) => {
  22. return new Promise((resolve, reject) => {
  23. logger.info('Fetching ' + url);
  24. return https.get(url, (res) => {
  25. res.setEncoding('utf8');
  26. let raw_data = '';
  27. res.on('data', (chunk) => {
  28. raw_data += chunk;
  29. });
  30. res.on('end', () => {
  31. resolve(raw_data);
  32. });
  33. }).on('error', (err) => {
  34. reject(err);
  35. });
  36. });
  37. },
  38. /**
  39. * Triggered at startup and then later by a timer, this will fetch the ip ranges from services and apply them to nginx.
  40. */
  41. fetch: () => {
  42. if (!internalIpRanges.interval_processing) {
  43. internalIpRanges.interval_processing = true;
  44. logger.info('Fetching IP Ranges from online services...');
  45. let ip_ranges = [];
  46. return internalIpRanges.fetchUrl(CLOUDFRONT_URL)
  47. .then((cloudfront_data) => {
  48. let data = JSON.parse(cloudfront_data);
  49. if (data && typeof data.prefixes !== 'undefined') {
  50. data.prefixes.map((item) => {
  51. if (item.service === 'CLOUDFRONT') {
  52. ip_ranges.push(item.ip_prefix);
  53. }
  54. });
  55. }
  56. if (data && typeof data.ipv6_prefixes !== 'undefined') {
  57. data.ipv6_prefixes.map((item) => {
  58. if (item.service === 'CLOUDFRONT') {
  59. ip_ranges.push(item.ipv6_prefix);
  60. }
  61. });
  62. }
  63. })
  64. .then(() => {
  65. return internalIpRanges.fetchUrl(CLOUDFARE_V4_URL);
  66. })
  67. .then((cloudfare_data) => {
  68. let items = cloudfare_data.split('\n').filter((line) => regIpV4.test(line));
  69. ip_ranges = [... ip_ranges, ... items];
  70. })
  71. .then(() => {
  72. return internalIpRanges.fetchUrl(CLOUDFARE_V6_URL);
  73. })
  74. .then((cloudfare_data) => {
  75. let items = cloudfare_data.split('\n').filter((line) => regIpV6.test(line));
  76. ip_ranges = [... ip_ranges, ... items];
  77. })
  78. .then(() => {
  79. let clean_ip_ranges = [];
  80. ip_ranges.map((range) => {
  81. if (range) {
  82. clean_ip_ranges.push(range);
  83. }
  84. });
  85. return internalIpRanges.generateConfig(clean_ip_ranges)
  86. .then(() => {
  87. if (internalIpRanges.iteration_count) {
  88. // Reload nginx
  89. return internalNginx.reload();
  90. }
  91. });
  92. })
  93. .then(() => {
  94. internalIpRanges.interval_processing = false;
  95. internalIpRanges.iteration_count++;
  96. })
  97. .catch((err) => {
  98. logger.error(err.message);
  99. internalIpRanges.interval_processing = false;
  100. });
  101. }
  102. },
  103. /**
  104. * @param {Array} ip_ranges
  105. * @returns {Promise}
  106. */
  107. generateConfig: (ip_ranges) => {
  108. const renderEngine = utils.getRenderEngine();
  109. return new Promise((resolve, reject) => {
  110. let template = null;
  111. let filename = '/etc/nginx/conf.d/include/ip_ranges.conf';
  112. try {
  113. template = fs.readFileSync(__dirname + '/../templates/ip_ranges.conf', {encoding: 'utf8'});
  114. } catch (err) {
  115. reject(new error.ConfigurationError(err.message));
  116. return;
  117. }
  118. renderEngine
  119. .parseAndRender(template, {ip_ranges: ip_ranges})
  120. .then((config_text) => {
  121. fs.writeFileSync(filename, config_text, {encoding: 'utf8'});
  122. resolve(true);
  123. })
  124. .catch((err) => {
  125. logger.warn('Could not write ' + filename + ':', err.message);
  126. reject(new error.ConfigurationError(err.message));
  127. });
  128. });
  129. }
  130. };
  131. module.exports = internalIpRanges;