Commit Graph
876 Commits
Author SHA1 Message Date
Wez Furlong 23e1700a13 ready_queue: allow dynamically changing max_ready
This was deliberately adjusted to only change when a queue
was reapead in a prior release, in the interests of raw performance.

While that might work for most domains, it's not ideal for busy
domains that have continual traffic.

This change adopts an ArcSwap to atomically swap out the underlying
ArrayQueue.  This introduces a small amount of overhead in the hot
path to atomically acquire the current version of the queue, but
it shouldn't be enough to be noticeable in practice.
2024-08-08 09:51:13 -07:00
Wez Furlong ab2b5af56f improve shutdown latency
We need to explicitly launch the connection attempt into a separate
task, otherwise the select! macro won't run it in parallel with
awaiting the shutdown notification.
2024-08-08 08:52:57 -07:00
Wez Furlong d0170cdab2 docs: changelog for bounce classifier fix 2024-08-06 21:03:16 -07:00
Wez Furlong 52ca4d8be0 redis: embrace the async interface in updated redis crate
Remove the r2d2 dep (which is synchronous only) and replace with
mobc which is a bit easier to use, async, and seems more developed.

Update the interface to expose more of mobc's connection pool
options.

Add explicit redis cluster integration tests.
2024-08-06 19:41:00 -07:00
Mike Hillyer 3dd8c21dff Add check-liveness endpoint to changelog. 2024-08-01 13:31:38 -04:00
Wez Furlong 179af07289 add /api/check-liveness/v1 endpoint
This is useful for load balancers to determine when service
is available and ready to receive messages
2024-07-31 14:41:46 -07:00
Daniel Schaaff c2675b2bb7 docs: al2023 install incorrectly using yum instead of dnf 2024-07-30 16:54:49 -07:00
Wez Furlong b5596183be proxy-server: simplify passthru implementation
We've been trying to run down an issue where a user has reported that
some sessions that are running via the proxy seem to hang waiting for a
response from the peer.  The common theme is that the size of the
payload is approximately 1MB in size, and that the proxy is in use.

I haven't been able to get it to reproduce at all, but in looking
carefully at the code here, my splice(2) implementation used a pipe
buffer that was 1MB in size, and doing non-blocking IO outside of
tokio's internals is a bit of a black art, so I'd buy the theory
that we might be getting stuck somewhere if we did fill up that
pipe buffer.

Since I couldn't catch it in the act, I've opted to go for the simple
and safer route here, as a speculative remediation:

* Added a `--no-splice` command line parameter to opt out of using
  `splice(2)` completely on Linux so that we can rule out weirdness
  with splice completely. The result will have lower theoretical
  max throughput, but a simpler internal implementation.
* There now exists a `tokio-splice` crate that has the same
  functionality as my own splice_copy code does, but a different
  implementation. Adopt that for the `splice(2)` mode.
* Switch away from splitting the stream into read/write halves: there
  are now utility functions available in tokio and tokio_splice that
  don't require splitting the streams, which further simplifies
  the implementation.
2024-07-30 16:32:39 -07:00
Wez Furlong d014237eb7 docs: more tweaks to sources
try to nudge folks away from adopting copypasta of the advanced
section; we've seen more than few people using this when they
should just use the sources policy helper.

Add the note about the weighted robin implementation to make_egress_pool
as well.
2024-07-27 07:08:31 -07:00
Wez Furlong 70cb58a36f docs: add note on round robin to user guide section on IPs 2024-07-27 06:49:59 -07:00
Wez Furlong 7bd6f3a912 mta-sts: fix an issue where a trailing dot may cause a redirect
Some http servers would canonicalize the trailing dot from the policy
domain by issuing a redirect. Since we don't follow redirects for
MTA-STS policies (per the RFC: redirects MUST NOT be followed), this
would result in no policy being loaded for that domain.

Correct this by stripping off that trailing dot.
2024-07-26 14:26:54 -07:00
Wez Furlong 10193434a8 queue: integration test to validate initial retry interval
To facilitate this, some adjustments needed to be made to the time
calculation in the maintainer because we previously didn't consider it
to be valid to have a retry_interval below 1 minute, but in order for
this integration test to be viable to run as part of the CI it needs to
run in significantly less time than 1 minute.

The approach taken here is to avoid considering 1 minute as the
baseline, but rather take 1/20th of the retry_interval. In the default
configuration, the numbers work out the same as previously, but they
will scale down as the retry_interval is reduced.

Care is taken to avoid a couple of borderline busy wait scenarios where
we might otherwise have woken up at unrealistically small intervals:
timeq can suggest 1ms in a few scenarios, and we just round those up to
the next second to avoid that.

It's worth noting that we do not consider the scheduled queue to be a
realtime, high granularity queue: anything that lands there is
considered to be bulk/batch and will be handled later: it isn't worth
prioritizing with high granularity because messages that land there are
generally not going to be delivered quickly.
2024-07-25 09:21:44 -07:00
Wez Furlong a8318836cf fix overly aggressive delay for the first deferral 2024-07-24 13:00:32 -07:00
Wez Furlong 040d074a0b docs: changelog for unsupported auth mech rejection log fix 2024-07-23 07:48:12 -07:00
Wez Furlong e129ee8149 docs: retire centos 7 from install page
We haven't build binaries for this platform in a long while,
and we don't intend on supporting it any further.
2024-07-21 15:05:48 -07:00
Wez Furlong d62781e7fa rfc5321 client: add openssl and rustls cipher/options 2024-07-20 16:16:47 -07:00
Wez Furlong b13ab592e5 kumoproxy: improve diagnostics around connectivity issues
Previously we were very tight-lipped. We now will log some
context to the journal for the proxy service for issues that
we couldn't propagate back to the client.
2024-07-15 11:55:00 -07:00
Wez Furlong d385a1a684 logs: expand source_address to include proxy information
Change the field from a SocketAddr to a struct with distinct fields:

```json
    // For SMTP delivery, the source address (and port) that was used.
    // (*Since: Dev Builds Only*)
    "source_address": {
        // The source address. The port number may be unknown and reported
        // as zero when using a proxy protocol.
        "address": "10.0.0.1:53210",
        // If a proxy protocol was used, this field will be
        // set to its name. It may be null/not set for no proxy,
        // "haproxy" or "socks5".
        "protocol": "socks5",
        // If a proxy protocol was used, this field will be
        // set to the proxy server address. It will be null/not set
        // when no proxy was used.
        "server": "192.168.1.1:5000"
    },
```

In #154, the request was to log configuration information here, but I
opted against this as there can be a number of different configuration
fields and the combinatorics for future changes make me uncomfortable
from a code maintainance perspective--it will already be heavy to
try to pass thu all of the existing config information, and as we
add more options in the future it will be awful not just to look at,
but also from a memory and storage overhead.

The approach taken here is to make a little struct that is flexible
enough to convey the desired information without it being too much of a
burden.

closes: #40
closes: #154
2024-07-12 09:22:46 -07:00
Wez Furlong 9a9443be71 logs: add source_address field to SMTP client logs
Previously we would log the pool and source name, but it is
desirable to also log the underlying socket address information,
so here we go!

refs: #40
2024-07-12 08:39:15 -07:00
Wez Furlong b003e49c9c rfc5321: split out banner_timeout from connect_timeout
The motivation for this is:

My test environment is not permitted to reach outbound port 25.
If I run an ad-hoc test without setting up an explicit sink,
I end up with messages that try to reach the public internet.
Since they are blocked at a firewall, each of the MX hosts in
the connection plan is subject to a 60s wait before trying the next
thing.

In addition, this can cause the shutdown to take longer while
we wait for the in-flight delivery attempts to complete.

Making a separate configuration option allows the local administrator
to decide how to split the time waiting for a connection from
the time waiting for the banner.

refs: https://github.com/KumoCorp/kumomta/issues/196
2024-07-12 07:54:43 -07:00
Wez Furlong a00e8d0f0a NEW: add tracing to smtp client, kcli trace-smtp-client
It is now possible to trace outbound SMTP sessions, filtering
by a variety of properties.

Details are in `kcli trace-smtp-client --help` and also in
the docs at /reference/kcli/trace-smtp-client.md

refs: #87
2024-07-11 08:56:25 -07:00
Wez Furlong 4369bd8355 docs: document rollup module
closes: https://github.com/KumoCorp/kumomta/issues/213
2024-07-10 10:35:00 -07:00
Wez Furlong c1565d2478 docs: forgot to format 2024-07-10 10:34:21 -07:00
Wez Furlong af103457a7 docs: remove low-level webhook example
There are subtle edge cases that are handled by the helper,
so I want everyone to use the helper in order to reduce potential
headaches for everyone.
2024-07-10 08:27:55 -07:00
Wez Furlong 9ea02c3968 docs: cover --validate mode
closes: #211
2024-07-10 08:16:31 -07:00
Wez Furlong f898e53502 docs: show how to setup up grafana dashboard
closes: https://github.com/KumoCorp/kumomta/issues/215
2024-07-10 07:10:05 -07:00
Wez Furlong fdf7fcf249 docs: show how you can compose kumo.encode with kumo.uuid 2024-07-10 06:29:02 -07:00
Wez Furlong f99f852747 mod-sqlite: add :close method 2024-07-09 16:50:48 -07:00
Wez Furlong cde3ba66cb mod-kafka: add explicit close method 2024-07-09 14:09:23 -07:00
Wez Furlong ec795b71d3 mod-http: add client:close() method
Allows explicit closure of any cached connections in the client
object.

Make use of this in the log_hooks:new_json method.
2024-07-09 13:57:46 -07:00
Wez Furlong 73b8b5b4e0 docs: add missing page for configure_unbound_resolver 2024-07-09 13:42:01 -07:00
Wez Furlong c659fe6d4f new: add kumo.uuid lua module 2024-07-09 13:25:32 -07:00
Wez Furlong bd43edee14 lua_deliver: add close method
This is to facilitate more precise control over the lifetime of
connection objects.

You can now define `function sender:close()` on the connection
object that is returned from your lua protocol constructor.

This method will be called when the underlying
QueueDispatcher::close_connection method is called.

Adjust the logic in ready_queue to explicitly call
QueueDispatcher::close_connection in the cases where we're closing the
connection; previously we'd just leave it to the Drop handler to take
care of this.

Adjust the amqp docs to show how to bubble the close call through
to the associated client.
2024-07-09 09:55:10 -07:00
Wez Furlong 58f53687e6 mod-amqp: add explicit client close method
This allows explicit and clean shutdown of a connection.
2024-07-09 09:55:10 -07:00
Tom Mairs 6d4ef9a303 fix typo 2024-07-09 15:09:09 +00:00
Tom Mairs 53b16cefb4 fix typo 2024-07-08 20:40:32 +00:00
Wez Furlong 722f19a078 docs: fix name of requeue_message event in the example 2024-07-08 09:11:34 -07:00
Mike Hillyer cf7f5843ab Add a stronger warning that the quickstart does not produce production-ready installs. 2024-07-05 10:58:37 -04:00
Mike Hillyer c42536ee77 Updating the quickstart tutorial. 2024-07-05 09:48:20 -04:00
Wez Furlong f7604a3f7f docs: cut over toml examples to toml_data data macro
refs: https://github.com/KumoCorp/kumomta/issues/212
2024-07-03 16:09:52 -07:00
Wez Furlong aa22e788c9 mkdocs: make build the default command, rather than serve
This makes it easier to run in woodpecker
2024-07-03 15:37:27 -07:00
Wez Furlong d416b31af9 docs: add toml_data macro
This macro allows embedding TOML data into the docs,
and showing it in a tab that has both the TOML and JSON
representation of that data.

It works by executing the toml2jsonc helper that was added
in an earlier commit.

There's some machinery here to compile that utility to run
in the context of the mkdocs docker image; that works
locally, let's see how well it works in CI!

Usage is simple; before:

```toml
["something"]
foo = "bar"
```

after:

{% call toml_data() %}
["something"]
foo = "bar"
{% endcall %}

The first page to get switched over to this is https://docs.kumomta.com/tutorial/configuring_kumomta/

refs: https://github.com/KumoCorp/kumomta/issues/212
2024-07-03 14:59:52 -07:00
Wez Furlong e49985ff54 logging: capture incoming SMTP command line for Rejections 2024-07-03 06:46:01 -07:00
Wez Furlong acdb8e36d4 docs: add some diagrams to the deployment architecture page
I noticed that this page was totally blank; let's add some
useful content here!

refs: https://github.com/KumoCorp/kumomta/issues/214
2024-07-01 09:50:24 -07:00
Wez Furlong ca3339cebb docs: remove "building docker image" from "using docker" docs
It doesn't fit there, and the topic is a bit more complex
than that brief summary.
2024-07-01 07:21:08 -07:00
Wez Furlong ef8cbea354 docs: fixup links to the rapidoc http page 2024-06-27 19:56:53 -07:00
Wez Furlong 49facb4d0a docs: fixup amqp docs some more 2024-06-27 19:51:09 -07:00
Wez Furlong 5b0d936ef7 docs: improve markdown output for the kcli help 2024-06-27 15:40:39 -07:00
Wez Furlong fa2c6225e8 docs: add kcli reference docs
These are automatically extracted from `kcli --help`.
2024-06-27 15:18:07 -07:00
Wez Furlong 5d7cf4005f docs: fixup AMQP example 2024-06-27 09:42:36 -07:00