Compare commits

...
Author SHA1 Message Date
wanghe-fit2cloud 3a888d289f fix app image pull check 2026-06-12 14:10:20 +08:00
王贺 dbff9c02e9 fix: improve login page compatibility (#13029) 2026-06-12 11:45:14 +08:00
ssongliu 45c5c5b40f fix: resolve SSH key generation issue (#13027) 2026-06-12 11:17:08 +08:00
CityFun aea71664ee feat: add some translate (#13019) 2026-06-12 11:13:49 +08:00
ssongliu fc65fb9323 fix: fix monitoring tooltip styles (#13017) 2026-06-11 17:26:00 +08:00
ssongliu f476823531 fix: correct node administrator permissions (#13016) 2026-06-11 17:25:47 +08:00
CityFun 8222579d99 feat: update website ssl apply logic (#13015) 2026-06-11 17:25:34 +08:00
蘭 209c126445 ref: update visibility logic alert configuration (#13007) 2026-06-11 14:12:53 +08:00
蘭 c846ca3e71 feat: add methodInvalid translation for alert configuration (#13005) 2026-06-11 12:24:29 +08:00
ssongliu e777fa143e fix: add middleware whitelist (#13004) 2026-06-11 12:24:17 +08:00
蘭 e66000ffd2 feat: improve alert config handling (#13001) 2026-06-10 21:48:54 +08:00
蘭 cfdf448765 feat: add displayName to alert configuration and update related logging (#13000) 2026-06-10 19:08:37 +08:00
CityFun c61139c5cc fix: optimize sync apps button display logic (#12999) 2026-06-10 18:45:32 +08:00
ssongliu 571a4068c4 feat: add missing operation logs (#12998) 2026-06-10 18:30:23 +08:00
CityFun 9ce63adb4f feat: add some translate (#12996)
* feat: add some translate

* feat: add some translate
2026-06-10 18:30:07 +08:00
蘭 ef51a2f9b2 style: adjust width of input help text for better alignment (#12995) 2026-06-10 18:29:54 +08:00
蘭 fa3e137db8 fix: prevent reading of binary preview files and improve file type handling (#12984) 2026-06-10 16:28:16 +08:00
蘭 af6a708049 fix: simplify error messages for unsupported alert methods (#12983) 2026-06-10 16:28:03 +08:00
ssongliu 5d6ccf5717 chore: refine multi-node upgrade text (#12982) 2026-06-10 14:29:37 +08:00
蘭 59c870aca4 fix: refine alert methods (#12980) 2026-06-09 18:53:51 +08:00
CityFun 94cb014598 chore: update dependencies (#12979) 2026-06-09 18:53:37 +08:00
ssongliu ed30567a22 fix: resolve custom login background image issue (#12977) 2026-06-09 17:28:36 +08:00
ssongliu 791350c299 chore: improve API documentation and logs (#12962) 2026-06-09 14:30:43 +08:00
ssongliu 6547de1758 fix: improve firewall port occupancy display (#12961)
* c

* fix: improve firewall port occupancy display
2026-06-09 14:18:54 +08:00
蘭 2151daab1f fix: Fix duplicate alert issues (#12960) 2026-06-09 11:29:28 +08:00
CityFun b791def0df chore: update dependencies (#12959) 2026-06-09 11:29:15 +08:00
ssongliu c036d5859f style: adjust overview memo style (#12958) 2026-06-09 11:28:55 +08:00
ssongliu 6495869664 fix: fix firewall whitelist rules not applied after restart (#12957) 2026-06-09 11:27:38 +08:00
蘭 a2e6e7e879 ref: update alert logging methods and improve alert configuration handling (#12955) 2026-06-08 21:47:47 +08:00
CityFun 338301907a feat: add some translate (#12954) 2026-06-08 19:01:19 +08:00
ssongliu 681141f971 feat: add license import warning message (#12952) 2026-06-08 19:01:04 +08:00
bin64 506ff1d46e fix: preserve custom rewrite template name case (#12714)
* refactor: enhance rewrite configuration handling by introducing safe name validation and custom rewrite existence checks

* test: cover custom rewrite name handling
2026-06-08 17:33:45 +08:00
bin64 c3b7deedb4 fix: parse supervisor uptime with optional days segment (#12713) 2026-06-08 17:33:26 +08:00
ssongliu 51252a15db feat: support port usage check for firewall port range rules (#12950) 2026-06-08 14:57:50 +08:00
ssongliu 375824f77a fix: relocate firewall port whitelist settings (#12949) 2026-06-08 14:24:24 +08:00
Rowan Chen 8918d10253 chore(deps): bump go-acme/lego to v5.2.2 (#12947)
lego v5.2.2 (released 2026-06-02) is a single-fix patch on top of v5.2.1: the Namecheap DNS provider now derives the record key sub-domain correctly. 1Panel exposes the Namecheap provider through agent/utils/ssl/dns_provider.go, so this patch is meaningful for users issuing certificates against Namecheap-hosted zones.

Changes are confined to agent/go.mod and agent/go.sum; the source files under agent/utils/ssl/ already use the import path github.com/go-acme/lego/v5/... and require no code changes. Diff is a 6-line dependency bump (1 line in go.mod plus 4 lines of refreshed go.sum hashes); lego itself did not move any of its own dependency pins between v5.2.1 and v5.2.2.

Built and verified on linux/amd64:

  GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' ./...

agent and core binaries link cleanly against the upgraded lego release; no source-level adaptations needed.
2026-06-08 14:20:21 +08:00
ssongliu fe343a64ed feat: adjust captcha verification method (#12946) 2026-06-05 18:50:11 +08:00
蘭 205f12e14a feat: add display name support for SMS alerts and enhance validation (#12945) 2026-06-05 18:49:58 +08:00
ssongliu aca94e470a style: optimize dark theme styles (#12944) 2026-06-05 18:49:48 +08:00
蘭 a69f7b1144 feat: add proxy support for file wget downloads (#12942) 2026-06-05 18:49:34 +08:00
蘭 e55abfb174 feat: implement range selection for table rows with shift key support (#12941) 2026-06-05 14:49:16 +08:00
CityFun 4a734b5bb6 feat: add some translate (#12940) 2026-06-05 14:48:53 +08:00
ssongliu 758eb9dfda style: optimize container log display (#12939) 2026-06-05 14:48:38 +08:00
ssongliu 04e2770763 style: optimize disabled button styles in tables (#12937) 2026-06-05 14:48:20 +08:00
ssongliu 7391b4bcd0 fix: resolve issues with abnormal operation logs (#12936) 2026-06-05 14:48:07 +08:00
蘭 d9d4d55eca fix: Fix some issues with alarms and reports (#12934) 2026-06-04 19:48:14 +08:00
ssongliu 9a64f8de98 feat: show agents and certificates in node overview (#12933) 2026-06-04 17:32:22 +08:00
ssongliu 9f9c9a2688 chore: adjust partial i18n content (#12931) 2026-06-03 18:18:43 +08:00
CityFun f80f4d1c19 feat: add some translate (#12930) 2026-06-03 18:11:55 +08:00
蘭 145b39c4c0 ref: Remove unnecessary references and improve international content (#12927)
* ref: Remove unnecessary references and improve international content

* ref: Code formatting

* ref: Code formatting
2026-06-03 16:41:26 +08:00
ssongliu 44e264fe65 feat: optimize node switch logic for large node sets (#12928) 2026-06-03 16:36:42 +08:00
蘭 15fef4d84e feat: add alert database initialization and migration steps (#12925) 2026-06-03 10:49:04 +08:00
ssongliu b8bd1490ec fix: remove offline settings from panel settings (#12924) 2026-06-03 10:47:24 +08:00
ssongliu ccd8923fdd feat: support multi-node batch installation in Skills Hub (#12923) 2026-06-03 09:37:50 +08:00
蘭 e49fa620c8 feat: Support adding multiple alert methods (#12922)
* feat: Support adding multiple alert methods

* feat: Support adding multiple alert methods
2026-06-02 22:35:21 +08:00
ssongliu 654691543c feat: support multi-node batch installation in Skills Hub (#12921) 2026-06-02 22:25:05 +08:00
ssongliu 929cd38184 docs: adjust API documentation content (#12920) 2026-06-02 16:31:06 +08:00
ssongliu 9748a0794b refactor: adjust login settings logic (#12916) 2026-06-02 15:13:59 +08:00
王贺 a3f8c30508 fix api annotations (#12915)
* fix api annotations

* complete 1panel api docs

* add operation logs for api docs
2026-06-02 15:11:43 +08:00
CityFun 602c0e8a3b feat: add some translate (#12913) 2026-06-01 18:28:03 +08:00
ssongliu 7b7f840c2e feat: support firewall port whitelist management (#12912) 2026-06-01 18:26:54 +08:00
Rowan Chen ba9a8592ee chore(deps): bump go-acme/lego to v5.2.1 (#12909)
lego v5.2.1 (released 2026-06-01) is a small follow-up patch on top of v5.2.0; the only fixed item is a CLI/migration ergonomics tweak (printing the suggested configuration when the file cannot be created) that does not affect 1Panel, but moving to the latest tag keeps us on a published release rather than the previous one.

Changes are confined to agent/go.mod and agent/go.sum; the source files under agent/utils/ssl/ already use the import path github.com/go-acme/lego/v5/... and require no code changes. Compared with the previous v5.2.0 step, this revision is a 6-line dependency bump (1 line in go.mod plus 4 lines of refreshed go.sum hashes), since lego itself did not move any of its own dependency pins between v5.2.0 and v5.2.1.

Indirect dependency bumps (carried over from the v5.2.0 -> v5.2.1 rebase, produced by 'go mod tidy' on a fresh checkout):

- alibabacloud-go/darabonba-openapi v2.1.16 -> v2.2.1, alibabacloud-go/tea v1.4.0 -> v1.5.0 (alidns provider chain)

- aws-sdk-go-v2 family v1.41.7 -> v1.41.8 plus matching service modules (route53 provider chain)

- baidubce/bce-sdk-go v0.9.266 -> v0.9.267, huaweicloud/huaweicloud-sdk-go-v3 v0.1.197 -> v0.1.198, tencentcloud-sdk-go v1.3.102 -> v1.3.106, volcengine/volc-sdk-golang v1.0.248 -> v1.0.249

- go-acme/alidns-20150109 major bump v4 -> v5, go-acme/esa-20240910 major bump v2 -> v3 (required by lego v5.2.x directly)

- fsnotify/fsnotify v1.9.0 -> v1.10.1 (also targeted by dependabot PRs #12864 / #12865)

Built and verified on linux/amd64:

  GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' ./...

agent and core binaries link cleanly against the upgraded lego and indirect dependencies; no source-level adaptations needed.
2026-06-01 17:42:24 +08:00
ssongliu 389fcbf10c fix: resolve delayed theme update after license import (#12911) 2026-06-01 13:52:54 +08:00
CityFun 9cca14c382 feat: add some translate (#12904) 2026-05-29 22:06:26 +08:00
ssongliu 243a2fe6f3 fix: fix SSH service auto-enable issue (#12898) 2026-05-29 22:06:09 +08:00
ssongliu 3d5069fd40 fix: preserve container IP after upgrade (#12902) 2026-05-29 18:25:02 +08:00
ssongliu 2b78bae451 fix: fix terminal connection failure for overview nodes (#12901) 2026-05-29 16:38:56 +08:00
ssongliu 8693cc17df fix: fix backup retention count not taking effect during script updates (#12896) 2026-05-29 11:41:57 +08:00
蘭 9a2b7a7775 ref: Code formatting (#12894) 2026-05-28 18:19:40 +08:00
蘭 024a4a9ef3 feat: alert better visibility control (#12893)
* feat: alert better visibility control

* feat: alert better visibility control
2026-05-28 18:04:41 +08:00
ssongliu f5b47cf74d fix: fix ClamAV scan failure issue (#12892) 2026-05-28 18:04:29 +08:00
蘭 4956b96193 ref: add some translate (#12891) 2026-05-28 18:04:16 +08:00
CityFun a332dfd3b3 fix: Fix the issue where runtime environments cannot be created when using a custom app repository. (#12887) 2026-05-28 11:54:02 +08:00
蘭 68f8d8d221 feat: add auto export feature for Ops Report (#12885) 2026-05-28 11:26:00 +08:00
王贺 4f78060d35 fix: tighten rbac and release resources (#12886) 2026-05-28 11:09:00 +08:00
ssongliu adb97730c1 fix: fix wildcard file copy issue. (#12883) 2026-05-28 10:30:38 +08:00
蘭 f1a0453615 fix: Fix some bugs in the operation and maintenance report (#12881) 2026-05-28 10:30:26 +08:00
CityFun e64cc875fe feat: add some translate (#12880) 2026-05-27 18:24:21 +08:00
ssongliu b1c028b786 fix: resolve node auto-upgrade failure (#12875) 2026-05-27 16:49:24 +08:00
ssongliu d0e3914a29 fix: resolve ssh service startup failure after enable (#12874) 2026-05-27 16:42:30 +08:00
蘭 fe7d1108cd ref: update dependencies for gopdf and gofpdi (#12873) 2026-05-27 15:07:42 +08:00
蘭andcopilot-swe-agent[bot] 462a3bbc83 feat: add node selection reports (#12871)
* feat: add node selection reports

* Merge dev-v2 and resolve PR conflicts

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
2026-05-27 14:09:50 +08:00
ssongliu b9dff99d63 feat: add login user display to login records (#12870) 2026-05-27 13:44:14 +08:00
崔健壮 612e67e4cc fix(ssl): keep panel certificate in sync after auto-renew (#12858)
The auto-renew flow in obtainSSL returned early when OpenResty was not
installed or `nginx -s reload` failed, skipping reloadSystemSSL. The new
certificate was persisted to the DB and written into website Nginx
configs, but the panel's own server.crt / server.key on disk and the
in-memory constant.CertStore were left pointing at the old material.
Because the cert was now fresh, subsequent cron ticks did not retry the
renewal, so the panel kept serving the stale cert until a user manually
re-applied it from 面板设置 → SSL.

Two changes:

1. agent/app/service/website_ssl.go
   reloadSystemSSL is now called unconditionally after a successful
   renewal, regardless of whether OpenResty is present or nginx reload
   succeeded. The function already short-circuits for non-panel SSLs,
   so this is safe.

2. agent/app/service/website_ssl.go + agent/cron/job/ssl.go
   Add SyncSystemSSL, invoked at the start of every renew cron tick.
   It compares the panel's on-disk cert/key with the WebsiteSSL row
   referenced by the SSLID setting and rewrites the files + notifies
   core when they diverge. This recovers existing installs that are
   already in the "DB ahead of disk" state and self-heals any future
   drift introduced by transient failures.
   https://github.com/1Panel-dev/1Panel/issues/12472
2026-05-27 11:58:40 +08:00
ssongliu 4f0838c98c fix: fix script library execution issue on child nodes (#12869) 2026-05-27 11:25:24 +08:00
ssongliu fe70a77264 feat: support auto popup task log after image deletion (#12868) 2026-05-27 11:25:02 +08:00
glmgbj233andssongliu 8ed33fd06a feat: validate generated terminal commands (#12826)
* Fix taint path 1 detected by Codex

Repository: 1Panel-dev_1Panel
Result: /home/hejunjie/llm_web_serve/find_github_project/codex_find_taint/batch_results_go_llm_full_mini/1Panel-dev_1Panel.json
Sink kind: command_exec

* Fix taint path 0 detected by Codex

Repository: 1Panel-dev_1Panel
Result: /home/hejunjie/llm_web_serve/find_github_project/codex_find_taint/batch_results_go_llm_full_mini/1Panel-dev_1Panel.json
Sink kind: command_exec

* Validate generated terminal commands

Keep generated output behind the intended trust boundary while preserving the normal safe workflow.

Add regression coverage for the unsafe flow and the expected safe behavior.

* Narrow terminal AI input validation

* refine terminal ai command validation

---------

Co-authored-by: ssongliu <sloooop1x@gmail.com>
2026-05-27 11:08:52 +08:00
ssongliu f5662769b3 fix: update node limit handling (#12867) 2026-05-27 09:46:00 +08:00
ssongliu 61a2e20798 fix: handle node admin action permissions (#12857) 2026-05-26 18:34:09 +08:00
ssongliu 7d20118f38 feat: add router expires alert (#12855) 2026-05-26 17:28:26 +08:00
CityFun 7307b9d6fb feat: Upgrade some dependencies. (#12854) 2026-05-26 15:25:08 +08:00
ssongliu c2971812a5 fix: align user list model and local dev config (#12853) 2026-05-26 14:31:24 +08:00
Rowan Chen 176a4bd34c Merge pull request #12829 from rowanchen-com/feat/lego-v5-and-dynadot
feat: upgrade lego to v5.1.0 and add Dynadot DNS provider
2026-05-26 14:18:17 +08:00
ssongliu 4a01726058 feat: guard file editor save and refresh ops report docs (#12852) 2026-05-26 13:48:19 +08:00
王贺 18a372e027 Update OWNERS (#12851) 2026-05-26 10:28:49 +08:00
蘭 483a2a867b feat: Optimize the export page of the operation and maintenance report (#12850) 2026-05-26 10:26:34 +08:00
ssongliu 1a0de94489 feat: update task list and sidebar behavior (#12839) 2026-05-26 09:33:52 +08:00
ssongliu 979c1588e1 fix: improve command output handling (#12837) 2026-05-26 09:33:41 +08:00
ssongliu e39f6b1003 feat: add setting permission controls (#12838) 2026-05-25 17:13:02 +08:00
mei2jun1 4443ed1b7f fix: nil pointer dereference when os.OpenFile fails (#12808) 2026-05-25 14:11:10 +08:00
ssongliu 81f11f13fe chore: remove unused docker compose dependency (#12835) 2026-05-25 11:38:42 +08:00
王贺 4fa14f055d fix: harden command execution helpers (#12834) 2026-05-25 11:38:31 +08:00
王贺 0fe9033d23 fix: update community edition auth defaults (#12828) 2026-05-23 21:17:28 +08:00
ssongliu e5ff53b1af fix: embed all web assets (#12827) 2026-05-23 12:46:20 +08:00
ssongliu d005e61c72 fix: update go sum (#12825) 2026-05-23 10:45:45 +08:00
王贺 9328a79b37 fix: update agent go sum (#12824) 2026-05-23 10:15:51 +08:00
ssongliu 56c7d5e3bd fix: refine rbac permission controls (#12821) 2026-05-23 09:44:11 +08:00
CityFun 0cefe8f6ad feat: Update some dependencies (#12820) 2026-05-22 22:37:08 +08:00
蘭 3759fd2dad feat: enhance ops report functionality and improve export options (#12819) 2026-05-22 18:17:01 +08:00
王贺 b35c771d16 fix: update mcp nav title (#12818) 2026-05-22 18:16:37 +08:00
王贺 3ce70cee4d chore: update skills hub locale (#12812) 2026-05-22 15:18:14 +08:00
CityFun 8dd27a3e7b feat: Update some dependencies (#12811) 2026-05-22 15:17:59 +08:00
CityFun c91769e364 feat: add some translate (#12806) 2026-05-21 18:20:06 +08:00
ssongliu ea7856d591 fix: update commercial edition i18n (#12804) 2026-05-21 18:19:52 +08:00
ssongliu 023040a814 fix: improve ssh log parsing (#12803) 2026-05-21 15:26:41 +08:00
王贺 13fdb6caa9 chore: update (#12802) 2026-05-21 14:52:39 +08:00
CityFun 81e1a41130 fix: Fixed issue with start frontend failed (#12800) 2026-05-21 14:42:45 +08:00
CityFun f3933155d6 Merge pull request #12799 from 1Panel-dev/dev-duo
merge to dev-v2
2026-05-21 12:41:48 +08:00
ssongliu 4e692b8667 fix: adjust file search layout (#12797) 2026-05-21 12:39:50 +08:00
蘭 cf5f1cdb4e feat: Operation and maintenance reports support alarm reports (#12794) 2026-05-21 12:39:50 +08:00
CityFun 46986fba24 fix: Resolve the agent upgrade issue (#12780) 2026-05-21 12:39:50 +08:00
ssongliu 4627e7c0af chore: add permission controls (#12775) 2026-05-21 12:39:50 +08:00
ssongliu 38174a0b9f fix: adjust permission dropdown behavior (#12774) 2026-05-21 12:39:50 +08:00
蘭 c0489245d9 feat: Optimize the UI and style of operation and maintenance reports (#12772) 2026-05-21 12:39:50 +08:00
王贺 bec23f793a fix: harden agent socket and permission checks (#12771)
* fix: harden agent socket and permission checks

* chore: remove agent socket test

* chore: remove redundant comments
2026-05-21 12:39:49 +08:00
ssongliu e7578a9fc5 fix: improve security entrance and user commands (#12770) 2026-05-21 12:39:49 +08:00
王贺 9d3313fe11 fix: allow refreshing skills hub routes (#12767) 2026-05-21 12:39:49 +08:00
ssongliu f41e5e3da5 chore: update website log docs (#12763) 2026-05-21 12:39:49 +08:00
ssongliu 540be68adf chore: update website log docs (#12762) 2026-05-21 12:39:49 +08:00
ssongliu 956bf0992a feat: split website log APIs (#12761) 2026-05-21 12:39:49 +08:00
ssongliuandCityFun d0faee4eeb feat: improve frontend permission handling (#12760)
* feat: change isProductPro logic (#12712)

* fix: tighten frontend RBAC permission guards (#12717)

* fix: tighten frontend RBAC permission guards

* feat: add permission directive coverage

* refactor frontend global store usage

* fix: harden file access and fallback handling

* feat: improve frontend permission handling

---------

Co-authored-by: CityFun <31820853+zhengkunwang223@users.noreply.github.com>
2026-05-21 12:39:49 +08:00
王贺 4517ae2f81 feat: support enterprise local skills hub (#12758) 2026-05-21 12:39:49 +08:00
CityFun c77260193f feat: Modify the model provider loading logic when creating an agent (#12757) 2026-05-21 12:39:49 +08:00
ssongliuandCityFun d57c998047 fix: serve frontend routes with fallback (#12752)
* feat: change isProductPro logic (#12712)

* fix: tighten frontend RBAC permission guards (#12717)

* fix: tighten frontend RBAC permission guards

* feat: add permission directive coverage

* refactor frontend global store usage

* serve frontend routes with fallback

---------

Co-authored-by: CityFun <31820853+zhengkunwang223@users.noreply.github.com>
2026-05-21 12:39:49 +08:00
CityFun 3a5d5bc6d7 feat: add some translate (#12746) 2026-05-21 12:39:49 +08:00
王贺 00afa748e0 feat: add ops report foundation (#12745)
* feat: add ops report foundation

* chore: restore local vite proxy

* chore: restore package lock

* chore: move ops report i18n scope

* chore: remove dashboard permission label

* chore: nest ops report i18n

* chore: update ops report menu i18n key

* chore: sync permission locale cleanup
2026-05-21 12:39:49 +08:00
ssongliu 8c9c7b9b1f chore: add license product i18n (#12739) 2026-05-21 12:39:49 +08:00
ssongliu 1e2dc42554 chore: update enterprise resource URL (#12735) 2026-05-21 12:39:49 +08:00
ssongliu cd621b9dba chore: add permission linkage i18n (#12732) 2026-05-21 12:39:49 +08:00
ssongliu d10afe7a5a chore: update node upgrade translations (#12730) 2026-05-21 12:39:49 +08:00
ssongliu 03fc9302d6 fix: align frontend permission checks with access mode (#12723) 2026-05-21 12:39:49 +08:00
CityFun d522d837ff feat: add icon for ai provider (#12722) 2026-05-21 12:39:49 +08:00
ssongliu aa10760658 feat: sync panel updates (#12721) 2026-05-21 12:39:49 +08:00
ssongliu db6e8841ec fix: adjust container action permission checks (#12718) 2026-05-21 12:39:49 +08:00
ssongliu 75258bb465 fix: tighten frontend RBAC permission guards (#12717)
* fix: tighten frontend RBAC permission guards

* feat: add permission directive coverage

* refactor frontend global store usage
2026-05-21 12:39:47 +08:00
CityFun 7c7a59cf21 feat: add some translate (#12716) 2026-05-21 12:37:33 +08:00
CityFun 6f38c4eb71 feat: change isProductPro logic (#12712) 2026-05-21 12:37:33 +08:00
CityFun 7abedeae22 feat: update some plugin (#12709) 2026-05-21 12:37:33 +08:00
CityFun afacefaccb feat: Add AI agent and benchmarking page URLs (#12696) 2026-05-21 12:37:33 +08:00
ssongliu e5b2b5d5dc fix: pass context to rar extraction and simplify sidebar message entry (#12697) 2026-05-21 12:37:33 +08:00
ssongliu 9508238805 feat: 修改 AI 代理的菜单位置 (#12695) 2026-05-21 12:37:33 +08:00
ssongliu 2c21bd7286 fix: handle stream auth responses (#12693) 2026-05-21 12:37:33 +08:00
CityFun 811ddcc26c fix: Fixed issue with install openclaw plugin failed (#12690) 2026-05-21 12:37:33 +08:00
ssongliu 6cd0373678 fix enterprise user cli updates (#12689) 2026-05-21 12:37:33 +08:00
ssongliu 11771b2b53 fix: improve ai benchmark i18n (#12686) 2026-05-21 12:37:33 +08:00
CityFun ff5c6e878e feat: add some translate (#12678) 2026-05-21 12:37:33 +08:00
ssongliu 1896aed973 feat: update host tools and settings APIs (#12674) 2026-05-21 12:37:32 +08:00
ssongliu 6dc5deb6d3 feat: support enterprise resource urls (#12669) 2026-05-21 12:37:32 +08:00
ssongliu d7242d526c feat: update mfa permissions and panel settings (#12665) 2026-05-21 12:37:32 +08:00
zhengkunwang223 22c3fc8c40 feat: add ai benchmark 2026-05-21 12:37:32 +08:00
ssongliu 8d44105f88 feat: normalize mfa and api config fields (#12642) 2026-05-21 12:37:32 +08:00
ssongliu 8fb8d97dcf feat: add offline environment setting (#12637) 2026-05-21 12:37:31 +08:00
ssongliu 6941014153 fix: refine enterprise license required flow (#12634)
* fix: adjust access control menu (#12633)

* fix: refine enterprise license required flow
2026-05-21 12:35:11 +08:00
ssongliuandCopilot bfd610d255 fix: adjust access control menu (#12633)
Co-authored-by: Copilot <copilot@github.com>
2026-05-21 12:35:11 +08:00
ssongliu 5c61217c78 chore: update xpack integration references (#12628) 2026-05-21 12:35:10 +08:00
ssongliu eb527857f3 fix: avoid license required before login (#12626) 2026-05-21 12:35:10 +08:00
ssongliu d55982bde0 refactor: update agent and core utilities (#12621) 2026-05-21 12:35:09 +08:00
zhengkunwang223 84a27de792 feat: add ai-proxy 2026-05-21 12:32:54 +08:00
ssongliu 111bec547c fix: avoid directives on non-element roots (#12597) 2026-05-21 12:32:54 +08:00
ssongliu db4f699b85 feat: record user in operation logs (#12596) 2026-05-21 12:32:54 +08:00
ssongliu 12f2d95265 chore: update license required handling (#12594) 2026-05-21 12:32:54 +08:00
ssongliu a917ca00a1 feat: refactor auth and xpack integration 2026-05-21 12:32:52 +08:00
ssongliu 69906046e8 feat: add xpackee permission-aware settings flow 2026-05-21 11:34:08 +08:00
ssongliu d9cedeca09 feat: update xpack integration behavior 2026-05-21 11:34:08 +08:00
ssongliu 0e28f27819 feat: Support multi-user login and node management 2026-05-21 11:34:06 +08:00
ssongliu 33fc7f14df fix: update license pro translations (#12781) 2026-05-20 18:38:21 +08:00
CityFun 7159aca226 fix: Fix the issue where deleting the host mapping in the runtime environment causes an error." (#12779) 2026-05-20 14:58:35 +08:00
ssongliu 2c5728e27e fix: add license free node count message (#12778) 2026-05-20 14:30:17 +08:00
ssongliu defb40702c fix snapshot recover tar extraction (#12777) 2026-05-20 14:12:54 +08:00
ssongliu b476df3b61 chore: update pro edition copy (#12776) 2026-05-20 13:55:04 +08:00
蘭 4bbd9b6f06 fix: Fix the issue of deleting project directories caused by failed creation of the running environment (#12756) 2026-05-18 18:08:13 +08:00
蘭 325b9c4d88 fix: Fix directory issue where file management loading does not exist (#12744) 2026-05-15 17:57:47 +08:00
蘭 76d965b3b7 feat: enhance file management UI and improve selection handling (#12740) 2026-05-15 11:35:15 +08:00
KOMATA 4b1b27abd8 feat: enhance upgrade process with space check and file handling (#12708)
* feat: enhance upgrade process with space check and file handling improvements

* fix: update minimum upgrade free space requirement to 500MB and simplify space check logic
2026-05-15 11:29:35 +08:00
CityFun f26b4f290d feat: add some translate (#12738) 2026-05-15 11:25:50 +08:00
蘭 5d2221203a fix: optimize directory size calculation with concurrency control (#12737) 2026-05-15 11:25:35 +08:00
蘭 0aff0d529e fix: improve error handling and refactor file history content retrieval (#12736) 2026-05-15 11:25:16 +08:00
CityFun 20f09b3a0c feat: add model downloader (#12694) 2026-05-09 17:17:34 +08:00
蘭 c392b72470 fix: Fix file decompression issue (#12684)
Refs #12675
2026-05-08 06:42:21 +00:00
王贺 50a70ef1e5 fix: skip large binary file history snapshots (#12683)
#### What this PR does / why we need it?

Refs https://github.com/1Panel-dev/1Panel/issues/12681

#### Summary of your change

#### Please indicate you've done the following:

- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
2026-05-08 06:40:22 +00:00
ssongliu 75266ef659 fix: pause home carousel while editing memo (#12680)
Refs #12679
2026-05-08 02:18:20 +00:00
王贺 b3c593b852 fix openwrt procd init script selection (#12670) 2026-05-07 18:28:30 +08:00
ssongliu 73530bb8b9 fix: route terminal websocket by operate node (#12676) 2026-05-07 18:28:17 +08:00
王贺 1b6e70964b fix: preserve upload file permissions (#12672) 2026-05-07 18:26:39 +08:00
王贺 61d42b05e9 fix: optimize dashboard monitor chart (#12673) 2026-05-07 18:25:27 +08:00
787 changed files with 55094 additions and 16934 deletions
-69
View File
@@ -1,69 +0,0 @@
name: Build And Publish (OSS + R2)
on:
push:
tags:
- 'v*'
jobs:
create-release:
runs-on: ubuntu-latest
steps:
- name: Checkout Code
uses: actions/checkout@v4
- name: Setup Node
uses: actions/setup-node@v4
with:
node-version: '24.11.1'
- name: Build Web
run: |
cd frontend && npm install && npm run build:pro
env:
NODE_OPTIONS: --max-old-space-size=8192
- name: Setup Go
uses: actions/setup-go@v5
with:
go-version: '1.25'
cache-dependency-path: |
core/go.sum
agent/go.sum
- name: Build Release
uses: goreleaser/goreleaser-action@v6
with:
distribution: goreleaser
version: '~> v2'
args: release --skip=publish --clean
- name: Upload Assets
uses: softprops/action-gh-release@v1
if: startsWith(github.ref, 'refs/tags/')
with:
draft: true
files: |
dist/*.tar.gz
dist/checksums.txt
- name: Setup OSSUTIL
uses: yizhoumo/setup-ossutil@v2
with:
endpoint: ${{ secrets.OSS_ENDPOINT }}
access-key-id: ${{ secrets.OSS_ACCESS_KEY_ID }}
access-key-secret: ${{ secrets.OSS_ACCESS_KEY_SECRET }}
ossutil-version: '1.7.18'
- name: Upload Assets to OSS
run: |
ossutil cp -r dist/ oss://resource-fit2cloud-com/1panel/package/v2/stable/${{ github.ref_name }}/release/ --include "*.tar.gz" --include "checksums.txt" --only-current-dir --force
- name: Setup Rclone
uses: AnimMouse/setup-rclone@v1
with:
rclone_config: ${{ secrets.RCLONE_CONFIG }}
- name: Upload to Cloudflare R2
run: |
rclone copy dist/ cloudflare_r2:package/v2/stable/${{ github.ref_name }}/release/ --include "*.tar.gz" --include "checksums.txt" --progress
+16 -3
View File
@@ -40,11 +40,23 @@ core/cmd/server/web/index.html
frontend/auto-imports.d.ts
frontend/components.d.ts
frontend/src/xpack
frontend/src/xpack-ee
frontend/src/enterprise
agent/xpack
agent/xpack-ee
agent/enterprise
agent/router/entry_xpack.go
agent/router/entry_enterprise.go
agent/server/init_xpack.go
agent/server/init_enterprise.go
agent/utils/xpack/xpack.go
agent/utils/xpack/enterprise.go
core/xpack
core/xpack-ee
core/enterprise
core/router/entry_xpack.go
core/router/entry_enterprise.go
core/server/init_xpack.go
core/server/init_enterprise.go
core/utils/xpack/xpack.go
core/utils/xpack/enterprise.go
.history/
dist/
@@ -66,3 +78,4 @@ AGENTS.md
opencode.json
superpowers
.worktrees/
.codex/
-82
View File
@@ -1,82 +0,0 @@
# yaml-language-server: $schema=https://goreleaser.com/static/schema.json
# vim: set ts=2 sw=2 tw=0 fo=jcroql
version: 2
before:
hooks:
# - export NODE_OPTIONS="--max-old-space-size=8192"
# - make build_web
- chmod +x ./ci/script.sh
- ./ci/script.sh
- sed -i 's@ORIGINAL_VERSION=.*@ORIGINAL_VERSION=v{{ .Version }}@g' 1pctl
builds:
- id: agent
dir: agent
main: cmd/server/main.go
binary: 1panel-agent
flags:
- -tags=xpack
- -trimpath
ldflags:
- -w -s
env:
- CGO_ENABLED=0
goos:
- linux
goarm:
- 7
goarch:
- amd64
- arm64
- arm
- ppc64le
- s390x
- riscv64
- id: core
dir: core
main: cmd/server/main.go
binary: 1panel-core
flags:
- -tags=xpack
- -trimpath
ldflags:
- -w -s
env:
- CGO_ENABLED=0
goos:
- linux
goarm:
- 7
goarch:
- amd64
- arm64
- arm
- ppc64le
- s390x
- riscv64
archives:
- formats: [ 'tar.gz' ]
ids: [core, agent]
name_template: "1panel-v{{ .Version }}-{{ .Os }}-{{ .Arch }}{{- if .Arm }}v{{ .Arm }}{{ end }}"
wrap_in_directory: true
files:
- 1pctl
- install.sh
- 1panel-core.service
- 1panel-agent.service
- initscript/*
- lang/*
- GeoIP.mmdb
checksum:
name_template: 'checksums.txt'
changelog:
sort: asc
filters:
exclude:
- "^docs:"
- "^test:"
+2
View File
@@ -2,8 +2,10 @@ reviewers:
- wanghe-fit2cloud
- zhengkunwang223
- ssongliu
- lan-yonghui
approvers:
- wanghe-fit2cloud
- zhengkunwang223
- ssongliu
- lan-yonghui
+125 -20
View File
@@ -27,6 +27,90 @@ func (b *BaseApi) CreateAgent(c *gin.Context) {
helper.SuccessWithData(c, res)
}
// @Tags AI
// @Summary Batch install Agent
// @Accept json
// @Param request body dto.AgentBatchInstallReq true "request"
// @Success 200 {object} dto.AgentItem
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/batch/install [post]
func (b *BaseApi) BatchInstallAgent(c *gin.Context) {
var req dto.AgentBatchInstallReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
res, err := agentService.BatchInstall(req)
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, res)
}
// @Tags AI
// @Summary Batch upgrade Agent
// @Accept json
// @Param request body dto.AgentBatchUpgradeReq true "request"
// @Success 200 {array} dto.AgentBatchUpgradeResult
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/batch/upgrade [post]
func (b *BaseApi) BatchUpgradeAgent(c *gin.Context) {
var req dto.AgentBatchUpgradeReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
res, err := agentService.BatchUpgrade(req)
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, res)
}
// @Tags AI
// @Summary Batch install Agent Skill
// @Accept json
// @Param request body dto.AgentBatchSkillInstallReq true "request"
// @Success 200 {array} dto.AgentBatchSkillInstallResult
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/batch/skill/install [post]
func (b *BaseApi) BatchInstallAgentSkill(c *gin.Context) {
var req dto.AgentBatchSkillInstallReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
res, err := agentService.BatchInstallSkill(req)
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, res)
}
// @Tags AI
// @Summary Batch operate Agent
// @Accept json
// @Param request body dto.AgentBatchOperateReq true "request"
// @Success 200 {array} dto.AgentBatchOperateResult
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/batch/operate [post]
func (b *BaseApi) BatchOperateAgent(c *gin.Context) {
var req dto.AgentBatchOperateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
res, err := agentService.BatchOperate(req)
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, res)
}
// @Tags AI
// @Summary Page Agents
// @Accept json
@@ -296,11 +380,11 @@ func (b *BaseApi) DeleteHermesChatSession(c *gin.Context) {
}
// @Tags AI
// @Summary Get Providers
// @Summary Get model account providers
// @Success 200 {array} dto.ProviderInfo
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/providers [get]
// @Router /ai/accounts/providers [get]
func (b *BaseApi) GetAgentProviders(c *gin.Context) {
list, err := agentService.GetProviders()
if err != nil {
@@ -311,13 +395,13 @@ func (b *BaseApi) GetAgentProviders(c *gin.Context) {
}
// @Tags AI
// @Summary Create Agent account
// @Summary Create model account
// @Accept json
// @Param request body dto.AgentAccountCreateReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts [post]
// @Router /ai/accounts [post]
func (b *BaseApi) CreateAgentAccount(c *gin.Context) {
var req dto.AgentAccountCreateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -331,13 +415,13 @@ func (b *BaseApi) CreateAgentAccount(c *gin.Context) {
}
// @Tags AI
// @Summary Update Agent account
// @Summary Update model account
// @Accept json
// @Param request body dto.AgentAccountUpdateReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/update [post]
// @Router /ai/accounts/update [post]
func (b *BaseApi) UpdateAgentAccount(c *gin.Context) {
var req dto.AgentAccountUpdateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -351,13 +435,13 @@ func (b *BaseApi) UpdateAgentAccount(c *gin.Context) {
}
// @Tags AI
// @Summary Page Agent accounts
// @Summary Page model accounts
// @Accept json
// @Param request body dto.AgentAccountSearch true "request"
// @Success 200 {object} dto.PageResult
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/search [post]
// @Router /ai/accounts/search [post]
func (b *BaseApi) PageAgentAccounts(c *gin.Context) {
var req dto.AgentAccountSearch
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -375,13 +459,34 @@ func (b *BaseApi) PageAgentAccounts(c *gin.Context) {
}
// @Tags AI
// @Summary List Agent account models
// @Summary Count model accounts by provider
// @Accept json
// @Param request body dto.AgentAccountProviderCountReq true "request"
// @Success 200 {object} map[string]int64
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/accounts/counts [post]
func (b *BaseApi) CountAgentAccountsByProviders(c *gin.Context) {
var req dto.AgentAccountProviderCountReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
counts, err := agentService.CountAccountsByProviders(req)
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, counts)
}
// @Tags AI
// @Summary List model account models
// @Accept json
// @Param request body dto.AgentAccountModelReq true "request"
// @Success 200 {array} dto.AgentAccountModel
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/models [post]
// @Router /ai/accounts/models [post]
func (b *BaseApi) GetAgentAccountModels(c *gin.Context) {
var req dto.AgentAccountModelReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -396,13 +501,13 @@ func (b *BaseApi) GetAgentAccountModels(c *gin.Context) {
}
// @Tags AI
// @Summary Create Agent account model
// @Summary Create model account model
// @Accept json
// @Param request body dto.AgentAccountModelCreateReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/models/create [post]
// @Router /ai/accounts/models/create [post]
func (b *BaseApi) CreateAgentAccountModel(c *gin.Context) {
var req dto.AgentAccountModelCreateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -416,13 +521,13 @@ func (b *BaseApi) CreateAgentAccountModel(c *gin.Context) {
}
// @Tags AI
// @Summary Update Agent account model
// @Summary Update model account model
// @Accept json
// @Param request body dto.AgentAccountModelUpdateReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/models/update [post]
// @Router /ai/accounts/models/update [post]
func (b *BaseApi) UpdateAgentAccountModel(c *gin.Context) {
var req dto.AgentAccountModelUpdateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -436,13 +541,13 @@ func (b *BaseApi) UpdateAgentAccountModel(c *gin.Context) {
}
// @Tags AI
// @Summary Delete Agent account model
// @Summary Delete model account model
// @Accept json
// @Param request body dto.AgentAccountModelDeleteReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/models/delete [post]
// @Router /ai/accounts/models/delete [post]
func (b *BaseApi) DeleteAgentAccountModel(c *gin.Context) {
var req dto.AgentAccountModelDeleteReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -456,13 +561,13 @@ func (b *BaseApi) DeleteAgentAccountModel(c *gin.Context) {
}
// @Tags AI
// @Summary Verify Agent account
// @Summary Verify model account
// @Accept json
// @Param request body dto.AgentAccountVerifyReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/verify [post]
// @Router /ai/accounts/verify [post]
func (b *BaseApi) VerifyAgentAccount(c *gin.Context) {
var req dto.AgentAccountVerifyReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -476,13 +581,13 @@ func (b *BaseApi) VerifyAgentAccount(c *gin.Context) {
}
// @Tags AI
// @Summary Delete Agent account
// @Summary Delete model account
// @Accept json
// @Param request body dto.AgentAccountDeleteReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/agents/accounts/delete [post]
// @Router /ai/accounts/delete [post]
func (b *BaseApi) DeleteAgentAccount(c *gin.Context) {
var req dto.AgentAccountDeleteReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+9 -42
View File
@@ -3,9 +3,6 @@ package v2
import (
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/utils/ai_tools/gpu"
"github.com/1Panel-dev/1Panel/agent/utils/ai_tools/gpu/common"
"github.com/1Panel-dev/1Panel/agent/utils/ai_tools/xpu"
"github.com/gin-gonic/gin"
)
@@ -163,37 +160,6 @@ func (b *BaseApi) DeleteOllamaModel(c *gin.Context) {
helper.Success(c)
}
// @Tags AI
// @Summary Load gpu / xpu info
// @Accept json
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/gpu/load [get]
func (b *BaseApi) LoadGpuInfo(c *gin.Context) {
ok, client := gpu.New()
if ok {
info, err := client.LoadGpuInfo()
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, info)
return
}
xpuOK, xpuClient := xpu.New()
if xpuOK {
info, err := xpuClient.LoadGpuInfo()
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, info)
return
}
helper.SuccessWithData(c, &common.GpuInfo{})
}
// @Tags AI
// @Summary Bind domain
// @Accept json
@@ -235,14 +201,15 @@ func (b *BaseApi) GetBindDomain(c *gin.Context) {
helper.SuccessWithData(c, res)
}
// Tags AI
// Summary Update bind domain
// Accept json
// Param request body dto.OllamaBindDomain true "request"
// Success 200
// Security ApiKeyAuth
// Security Timestamp
// Router /ai/domain/update [post]
// @Tags AI
// @Summary Update bind domain
// @Accept json
// @Param request body dto.OllamaBindDomain true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/domain/update [post]
// @x-panel-log {"bodyKeys":["domain"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新 Ollama 绑定域名 [domain]","formatEN":"update Ollama bind domain [domain]"}
func (b *BaseApi) UpdateBindDomain(c *gin.Context) {
var req dto.OllamaBindDomain
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+159 -4
View File
@@ -2,11 +2,24 @@ package v2
import (
"errors"
"net/url"
"strings"
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/gin-gonic/gin"
)
const defaultAuditUser = "system"
// @Tags Alert
// @Summary Page alert
// @Accept json
// @Param request body dto.AlertSearch true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/search [post]
func (b *BaseApi) PageAlert(c *gin.Context) {
var req dto.AlertSearch
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -32,12 +45,21 @@ func (b *BaseApi) GetAlerts(c *gin.Context) {
helper.SuccessWithData(c, alerts)
}
// @Tags Alert
// @Summary Create alert
// @Accept json
// @Param request body dto.AlertCreate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert [post]
// @x-panel-log {"bodyKeys":["title"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"创建告警任务 [title]","formatEN":"create alert [title]"}
func (b *BaseApi) CreateAlert(c *gin.Context) {
var req dto.AlertCreate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
err := alertService.CreateAlert(req)
err := alertService.CreateAlert(req, loadAuditUser(c))
if err != nil {
helper.InternalServer(c, err)
return
@@ -45,6 +67,15 @@ func (b *BaseApi) CreateAlert(c *gin.Context) {
helper.Success(c)
}
// @Tags Alert
// @Summary Delete alert
// @Accept json
// @Param request body dto.DeleteRequest true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/del [post]
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"删除告警任务 [id]","formatEN":"delete alert [id]"}
func (b *BaseApi) DeleteAlert(c *gin.Context) {
var req dto.DeleteRequest
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -58,12 +89,21 @@ func (b *BaseApi) DeleteAlert(c *gin.Context) {
helper.Success(c)
}
// @Tags Alert
// @Summary Update alert
// @Accept json
// @Param request body dto.AlertUpdate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/update [post]
// @x-panel-log {"bodyKeys":["title"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新告警任务 [title]","formatEN":"update alert [title]"}
func (b *BaseApi) UpdateAlert(c *gin.Context) {
var req dto.AlertUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
if err := alertService.UpdateAlert(req); err != nil {
if err := alertService.UpdateAlert(req, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
@@ -84,6 +124,15 @@ func (b *BaseApi) GetAlert(c *gin.Context) {
helper.SuccessWithData(c, alert)
}
// @Tags Alert
// @Summary Update alert status
// @Accept json
// @Param request body dto.AlertUpdateStatus true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/status [post]
// @x-panel-log {"bodyKeys":["id","status"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新告警任务 [id] 状态 [status]","formatEN":"update alert [id] status [status]"}
func (b *BaseApi) UpdateAlertStatus(c *gin.Context) {
var req dto.AlertUpdateStatus
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -97,6 +146,12 @@ func (b *BaseApi) UpdateAlertStatus(c *gin.Context) {
helper.Success(c)
}
// @Tags Alert
// @Summary Get disks
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/disks/list [get]
func (b *BaseApi) GetDisks(c *gin.Context) {
alerts, err := alertService.GetDisks()
if err != nil {
@@ -106,6 +161,14 @@ func (b *BaseApi) GetDisks(c *gin.Context) {
helper.SuccessWithData(c, alerts)
}
// @Tags Alert
// @Summary Page alert logs
// @Accept json
// @Param request body dto.AlertLogSearch true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/logs/search [post]
func (b *BaseApi) PageAlertLogs(c *gin.Context) {
var req dto.AlertLogSearch
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -122,6 +185,13 @@ func (b *BaseApi) PageAlertLogs(c *gin.Context) {
})
}
// @Tags Alert
// @Summary Clean alert logs
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/logs/clean [post]
// @x-panel-log {"bodyKeys":[],"paramKeys":[],"BeforeFunctions":[],"formatZH":"清空告警日志","formatEN":"clean alert logs"}
func (b *BaseApi) CleanAlertLogs(c *gin.Context) {
if err := alertService.CleanAlertLogs(); err != nil {
helper.InternalServer(c, err)
@@ -130,6 +200,12 @@ func (b *BaseApi) CleanAlertLogs(c *gin.Context) {
helper.Success(c)
}
// @Tags Alert
// @Summary Get clams
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/clams/list [get]
func (b *BaseApi) GetClams(c *gin.Context) {
clams, err := alertService.GetClams()
if err != nil {
@@ -139,6 +215,14 @@ func (b *BaseApi) GetClams(c *gin.Context) {
helper.SuccessWithData(c, clams)
}
// @Tags Alert
// @Summary Get cron jobs
// @Accept json
// @Param request body dto.CronJobReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/cronjob/list [post]
func (b *BaseApi) GetCronJobs(c *gin.Context) {
var req dto.CronJobReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -152,8 +236,18 @@ func (b *BaseApi) GetCronJobs(c *gin.Context) {
helper.SuccessWithData(c, cronJobs)
}
// @Tags Alert
// @Summary Get alert config
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/config/info [post]
func (b *BaseApi) GetAlertConfig(c *gin.Context) {
config, err := alertService.GetAlertConfig()
var req dto.AlertConfigQuery
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
config, err := alertService.GetAlertConfig(req)
if err != nil {
helper.InternalServer(c, err)
return
@@ -161,18 +255,71 @@ func (b *BaseApi) GetAlertConfig(c *gin.Context) {
helper.SuccessWithData(c, config)
}
// @Tags Alert
// @Summary Page alert config
// @Accept json
// @Param request body dto.AlertConfigPageReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/config/search [post]
func (b *BaseApi) PageAlertConfig(c *gin.Context) {
var req dto.AlertConfigPageReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
total, configs, err := alertService.PageAlertConfig(req)
if err != nil {
helper.InternalServer(c, err)
return
}
helper.SuccessWithData(c, dto.PageResult{
Total: total,
Items: configs,
})
}
// @Tags Alert
// @Summary Update alert config
// @Accept json
// @Param request body dto.AlertConfigUpdate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/config/update [post]
// @x-panel-log {"bodyKeys":["id","displayName"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新告警配置 [id][displayName]","formatEN":"update alert config [id][displayName]"}
func (b *BaseApi) UpdateAlertConfig(c *gin.Context) {
var req dto.AlertConfigUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
if err := alertService.UpdateAlertConfig(req); err != nil {
if err := alertService.UpdateAlertConfig(req, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
helper.Success(c)
}
func loadAuditUser(c *gin.Context) string {
userName := strings.TrimSpace(c.GetHeader("X-Panel-User"))
if userName == "" {
return defaultAuditUser
}
if decoded, err := url.QueryUnescape(userName); err == nil {
return decoded
}
return userName
}
// @Tags Alert
// @Summary Delete alert config
// @Accept json
// @Param request body dto.DeleteRequest true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/config/del [post]
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"删除告警配置 [id]","formatEN":"delete alert config [id]"}
func (b *BaseApi) DeleteAlertConfig(c *gin.Context) {
var req dto.DeleteRequest
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -186,6 +333,14 @@ func (b *BaseApi) DeleteAlertConfig(c *gin.Context) {
helper.Success(c)
}
// @Tags Alert
// @Summary Test alert config
// @Accept json
// @Param request body dto.AlertConfigTest true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /alert/config/test [post]
func (b *BaseApi) TestAlertConfig(c *gin.Context) {
var req dto.AlertConfigTest
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+10 -4
View File
@@ -107,7 +107,7 @@ func (b *BaseApi) GetApp(c *gin.Context) {
// @Accept json
// @Param appId path integer true "app id"
// @Param version path string true "app 版本"
// @Param version path string true "app 类型"
// @Param type path string true "app 类型"
// @Success 200 {object} response.AppDetailDTO
// @Security ApiKeyAuth
// @Security Timestamp
@@ -131,7 +131,7 @@ func (b *BaseApi) GetAppDetail(c *gin.Context) {
// @Tags App
// @Summary Get app detail by id
// @Accept json
// @Param appId path integer true "id"
// @Param id path integer true "id"
// @Success 200 {object} response.AppDetailDTO
// @Security ApiKeyAuth
// @Security Timestamp
@@ -172,6 +172,12 @@ func (b *BaseApi) InstallApp(c *gin.Context) {
helper.SuccessWithData(c, install)
}
// @Tags App
// @Summary Get app tags
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /apps/tags [get]
func (b *BaseApi) GetAppTags(c *gin.Context) {
tags, err := appService.GetAppTags(c)
if err != nil {
@@ -199,7 +205,7 @@ func (b *BaseApi) GetAppListUpdate(c *gin.Context) {
// @Tags App
// @Summary Get app icon by app_id
// @Accept json
// @Param appId path integer true "app id"
// @Param key path string true "app key"
// @Success 200 {file} file "app icon"
// @Security ApiKeyAuth
// @Security Timestamp
@@ -237,7 +243,7 @@ func (b *BaseApi) GetAppIcon(c *gin.Context) {
// @Tags App
// @Summary Search app detail by appkey and version
// @Accept json
// @Param appId path integer true "app key"
// @Param appKey path string true "app key"
// @Param version path string true "app version"
// @Success 200 {object} response.AppDetailSimpleDTO
// @Security ApiKeyAuth
+10 -2
View File
@@ -203,7 +203,6 @@ func (b *BaseApi) GetServices(c *gin.Context) {
// @Tags App
// @Summary Search app update version by install id
// @Accept json
// @Param appInstallId path integer true "request"
// @Success 200 {array} dto.AppVersion
// @Security ApiKeyAuth
// @Security Timestamp
@@ -267,7 +266,7 @@ func (b *BaseApi) GetDefaultConfig(c *gin.Context) {
// @Tags App
// @Summary Search params by appInstallId
// @Accept json
// @Param appInstallId path string true "request"
// @Param appInstallId path integer true "request"
// @Success 200 {object} response.AppConfig
// @Security ApiKeyAuth
// @Security Timestamp
@@ -350,6 +349,15 @@ func (b *BaseApi) GetAppInstallInfo(c *gin.Context) {
helper.SuccessWithData(c, info)
}
// @Tags App
// @Summary Update app install sort
// @Accept json
// @Param request body request.AppInstallSort true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /apps/installed/sort/update [post]
// @x-panel-log {"bodyKeys":[],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新已安装应用排序","formatEN":"update installed app sort"}
func (b *BaseApi) UpdateAppInstallSort(c *gin.Context) {
var req request.AppInstallSort
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+9 -2
View File
@@ -10,6 +10,13 @@ import (
"github.com/gin-gonic/gin"
)
// @Tags Backup Account
// @Summary Check backup used
// @Param name path string true "name"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /backups/check/{name} [get]
func (b *BaseApi) CheckBackupUsed(c *gin.Context) {
name, err := helper.GetStrParamByKey(c, "name")
if err != nil {
@@ -32,7 +39,7 @@ func (b *BaseApi) CheckBackupUsed(c *gin.Context) {
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /backups/check [post]
// @Router /backups/conn/check [post]
func (b *BaseApi) CheckBackup(c *gin.Context) {
var req dto.BackupOperate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -136,7 +143,7 @@ func (b *BaseApi) DeleteBackup(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /backups/update [post]
// @x-panel-log {"bodyKeys":["type"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新备份账号 [types]","formatEN":"update backup account [types]"}
// @x-panel-log {"bodyKeys":["type"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新备份账号 [type]","formatEN":"update backup account [type]"}
func (b *BaseApi) UpdateBackup(c *gin.Context) {
var req dto.BackupOperate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+3 -3
View File
@@ -21,7 +21,7 @@ func (b *BaseApi) CreateClam(c *gin.Context) {
return
}
if err := clamService.Create(req); err != nil {
if err := clamService.Create(req, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
@@ -43,7 +43,7 @@ func (b *BaseApi) UpdateClam(c *gin.Context) {
return
}
if err := clamService.Update(req); err != nil {
if err := clamService.Update(req, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
@@ -123,7 +123,7 @@ func (b *BaseApi) LoadClamBaseInfo(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /toolbox/clam/operate [post]
// @x-panel-log {"bodyKeys":["operation"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"[operation] Clam","formatEN":"[operation] FTP"}
// @x-panel-log {"bodyKeys":["operation"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"[operation] Clam","formatEN":"[operation] Clam"}
func (b *BaseApi) OperateClam(c *gin.Context) {
var req dto.Operate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+16
View File
@@ -5,6 +5,7 @@ import (
"net/url"
"path"
"strconv"
"strings"
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
@@ -394,6 +395,7 @@ func (b *BaseApi) ContainerInfo(c *gin.Context) {
helper.SuccessWithData(c, data)
}
// @Tags Container
// @Summary Load container limits
// @Success 200 {object} dto.ResourceLimit
// @Security ApiKeyAuth
@@ -408,6 +410,7 @@ func (b *BaseApi) LoadResourceLimit(c *gin.Context) {
helper.SuccessWithData(c, data)
}
// @Tags Container
// @Summary Load container stats
// @Success 200 {array} dto.ContainerListStats
// @Security ApiKeyAuth
@@ -422,6 +425,7 @@ func (b *BaseApi) ContainerListStats(c *gin.Context) {
helper.SuccessWithData(c, data)
}
// @Tags Container
// @Summary Load container stats size
// @Accept json
// @Param request body dto.OperationWithName true "request"
@@ -662,6 +666,14 @@ func (b *BaseApi) Inspect(c *gin.Context) {
helper.SuccessWithData(c, result)
}
// @Tags Container
// @Summary Download container logs
// @Accept json
// @Param request body dto.ContainerLog true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /containers/download/log [post]
func (b *BaseApi) DownloadContainerLogs(c *gin.Context) {
var req dto.ContainerLog
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -901,6 +913,10 @@ func (b *BaseApi) LoadComposeEnv(c *gin.Context) {
// @Security Timestamp
// @Router /containers/search/log [get]
func (b *BaseApi) ContainerStreamLogs(c *gin.Context) {
if !strings.Contains(strings.ToLower(c.GetHeader("Accept")), "text/event-stream") {
helper.Success(c)
return
}
c.Header("Content-Type", "text/event-stream")
c.Header("Cache-Control", "no-cache")
c.Header("Connection", "keep-alive")
+3 -3
View File
@@ -26,7 +26,7 @@ func (b *BaseApi) CreateCronjob(c *gin.Context) {
return
}
if err := cronjobService.Create(req); err != nil {
if err := cronjobService.Create(req, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
@@ -91,7 +91,7 @@ func (b *BaseApi) ImportCronjob(c *gin.Context) {
return
}
if err := cronjobService.Import(req.Cronjobs); err != nil {
if err := cronjobService.Import(req.Cronjobs, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
@@ -285,7 +285,7 @@ func (b *BaseApi) UpdateCronjob(c *gin.Context) {
return
}
if err := cronjobService.Update(req.ID, req); err != nil {
if err := cronjobService.Update(req.ID, req, loadAuditUser(c)); err != nil {
helper.InternalServer(c, err)
return
}
+3
View File
@@ -95,6 +95,7 @@ func (b *BaseApi) SearchDatabase(c *gin.Context) {
// @Success 200 {array} dto.DatabaseOption
// @Security ApiKeyAuth
// @Security Timestamp
// @Param type path string true "type"
// @Router /databases/db/list/:type [get]
func (b *BaseApi) ListDatabase(c *gin.Context) {
dbType, err := helper.GetStrParamByKey(c, "type")
@@ -116,6 +117,7 @@ func (b *BaseApi) ListDatabase(c *gin.Context) {
// @Success 200 {array} dto.DatabaseItem
// @Security ApiKeyAuth
// @Security Timestamp
// @Param type path string true "type"
// @Router /databases/db/item/:type [get]
func (b *BaseApi) LoadDatabaseItems(c *gin.Context) {
dbType, err := helper.GetStrParamByKey(c, "type")
@@ -137,6 +139,7 @@ func (b *BaseApi) LoadDatabaseItems(c *gin.Context) {
// @Success 200 {object} dto.DatabaseInfo
// @Security ApiKeyAuth
// @Security Timestamp
// @Param name path string true "name"
// @Router /databases/db/:name [get]
func (b *BaseApi) GetDatabase(c *gin.Context) {
name, err := helper.GetStrParamByKey(c, "name")
+2 -1
View File
@@ -92,7 +92,7 @@ func (b *BaseApi) UpdatePostgresqlDescription(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/pg/privileges [post]
// @x-panel-log {"bodyKeys":["database", "username"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新数据库 [database] 用户 [username] 权限","formatEN":"Update [user] privileges of database [database]"}
// @x-panel-log {"bodyKeys":["database", "username"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新数据库 [database] 用户 [username] 权限","formatEN":"Update [username] privileges of database [database]"}
func (b *BaseApi) ChangePostgresqlPrivileges(c *gin.Context) {
var req dto.PostgresqlPrivileges
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -170,6 +170,7 @@ func (b *BaseApi) SearchPostgresql(c *gin.Context) {
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Param database path string true "database"
// @Router /databases/pg/:database/load [post]
func (b *BaseApi) LoadPostgresqlDBFromRemote(c *gin.Context) {
database, err := helper.GetStrParamByKey(c, "database")
+6
View File
@@ -74,6 +74,12 @@ func (b *BaseApi) LoadPersistenceConf(c *gin.Context) {
helper.SuccessWithData(c, data)
}
// @Tags Database Redis
// @Summary Check has cli
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/redis/check [get]
func (b *BaseApi) CheckHasCli(c *gin.Context) {
helper.SuccessWithData(c, redisService.CheckHasCli())
}
+48 -18
View File
@@ -193,7 +193,7 @@ func (b *BaseApi) BatchDeleteFile(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /files/mode [post]
// @x-panel-log {"bodyKeys":["path","mode"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改权限 [paths] => [mode]","formatEN":"Change mode [paths] => [mode]"}
// @x-panel-log {"bodyKeys":["path","mode"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改权限 [path] => [mode]","formatEN":"Change mode [path] => [mode]"}
func (b *BaseApi) ChangeFileMode(c *gin.Context) {
var req request.FileCreate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -215,7 +215,7 @@ func (b *BaseApi) ChangeFileMode(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /files/owner [post]
// @x-panel-log {"bodyKeys":["path","user","group"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改用户/组 [paths] => [user]/[group]","formatEN":"Change owner [paths] => [user]/[group]"}
// @x-panel-log {"bodyKeys":["path","user","group"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改用户/组 [path] => [user]/[group]","formatEN":"Change owner [path] => [user]/[group]"}
func (b *BaseApi) ChangeFileOwner(c *gin.Context) {
var req request.FileRoleUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -411,7 +411,7 @@ func (b *BaseApi) UploadFiles(c *gin.Context) {
helper.BadRequest(c, errors.New("error paths in request"))
return
}
dir := path.Dir(paths[0])
dir := path.Clean(paths[0])
_, err = os.Stat(dir)
if err != nil && os.IsNotExist(err) {
@@ -452,8 +452,14 @@ func (b *BaseApi) UploadFiles(c *gin.Context) {
}
_ = os.Chown(dstDir, uid, gid)
}
dstDirMode := mode
dstFileMode := mode.Perm()
if dstDirInfo, err := os.Stat(dstDir); err == nil {
dstDirMode = dstDirInfo.Mode()
dstFileMode = dstDirInfo.Mode().Perm()
}
tmpFilename := dstFilename + ".tmp"
if err := c.SaveUploadedFile(file, tmpFilename); err != nil {
if err := c.SaveUploadedFile(file, tmpFilename, dstDirMode); err != nil {
_ = os.Remove(tmpFilename)
e := fmt.Errorf("upload [%s] file failed, err: %v", file.Filename, err)
failures[file.Filename] = e
@@ -476,7 +482,7 @@ func (b *BaseApi) UploadFiles(c *gin.Context) {
if statErr == nil {
_ = os.Chmod(dstFilename, dstInfo.Mode())
} else {
_ = os.Chmod(dstFilename, mode)
_ = os.Chmod(dstFilename, dstFileMode)
}
if uid != -1 && gid != -1 {
_ = os.Chown(dstFilename, uid, gid)
@@ -634,6 +640,10 @@ func (b *BaseApi) MoveFile(c *gin.Context) {
// @Router /files/download [get]
func (b *BaseApi) Download(c *gin.Context) {
filePath := c.Query("path")
if files.ShouldDenySensitiveFileRead(filePath) {
helper.InternalServer(c, buserr.New("ErrSensitiveFileRead"))
return
}
file, err := os.Open(filePath)
if err != nil {
helper.InternalServer(c, err)
@@ -669,6 +679,10 @@ func (b *BaseApi) DownloadChunkFiles(c *gin.Context) {
helper.ErrorWithDetail(c, http.StatusInternalServerError, "ErrPathNotFound", nil)
return
}
if files.ShouldDenySensitiveFileRead(req.Path) {
helper.InternalServer(c, buserr.New("ErrSensitiveFileRead"))
return
}
filePath := req.Path
fstFile, err := fileOp.OpenFile(filePath)
if err != nil {
@@ -787,12 +801,13 @@ func mergeChunks(fileName string, fileDir string, dstDir string, chunkCount int,
return err
}
}
if dstDirInfo, err := os.Stat(dstDir); err == nil {
mode = dstDirInfo.Mode().Perm()
}
dstFileName := filepath.Join(dstDir, fileName)
dstInfo, statErr := os.Stat(dstFileName)
if statErr == nil {
mode = dstInfo.Mode()
} else {
mode = 0644
}
if overwrite {
_ = os.Remove(dstFileName)
@@ -814,6 +829,7 @@ func mergeChunks(fileName string, fileDir string, dstDir string, chunkCount int,
}
_ = os.Remove(chunkPath)
}
_ = os.Chmod(dstFileName, mode)
return nil
}
@@ -918,7 +934,17 @@ var wsUpgrade = websocket.Upgrader{
},
}
// @Tags File
// @Summary Wget process
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /files/wget/process [get]
func (b *BaseApi) WgetProcess(c *gin.Context) {
if !websocket.IsWebSocketUpgrade(c.Request) {
helper.Success(c)
return
}
ws, err := wsUpgrade.Upgrade(c.Writer, c.Request, nil)
if err != nil {
return
@@ -928,6 +954,12 @@ func (b *BaseApi) WgetProcess(c *gin.Context) {
go wsClient.Write()
}
// @Tags File
// @Summary Process keys
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /files/wget/process/keys [get]
func (b *BaseApi) ProcessKeys(c *gin.Context) {
res := &response.FileProcessKeys{}
keys := global.CACHE.PrefixScanKey("file-wget-")
@@ -947,16 +979,20 @@ func (b *BaseApi) ProcessKeys(c *gin.Context) {
// @Tags File
// @Summary Read file by Line
// @Param type path string true "type"
// @Param request body request.FileReadByLineReq true "request"
// @Success 200 {object} response.FileLineContent
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /files/read [post]
// @Router /files/read/{type} [post]
func (b *BaseApi) ReadFileByLine(c *gin.Context) {
var req request.FileReadByLineReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
if readType := strings.TrimSpace(c.Param("type")); readType != "" {
req.Type = readType
}
res, err := fileService.ReadLogByLine(req)
if err != nil {
helper.InternalServer(c, err)
@@ -989,16 +1025,6 @@ func (b *BaseApi) BatchChangeModeAndOwner(c *gin.Context) {
helper.Success(c)
}
func (b *BaseApi) GetPathByType(c *gin.Context) {
pathType, ok := c.Params.Get("type")
if !ok {
helper.BadRequest(c, errors.New("error pathType id in path"))
return
}
resPath := fileService.GetPathByType(pathType)
helper.SuccessWithData(c, resPath)
}
// @Tags File
// @Summary system mount
// @Accept json
@@ -1330,6 +1356,10 @@ func (b *BaseApi) DownloadFileShare(c *gin.Context) {
helper.InternalServer(c, err)
return
}
if files.ShouldDenySensitiveFileRead(filePath) {
helper.InternalServer(c, buserr.New("ErrSensitiveFileRead"))
return
}
file, err := os.Open(filePath)
if err != nil {
helper.InternalServer(c, err)
+1 -1
View File
@@ -11,7 +11,7 @@ import (
// @Summary Load file history list
// @Accept json
// @Param request body request.FileHistorySearchReq true "request"
// @Success 200 {object} response.PageResult
// @Success 200 {object} dto.PageResult
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /files/history/search [post]
+1 -1
View File
@@ -236,7 +236,7 @@ func (b *BaseApi) UpdateAddrRule(c *gin.Context) {
// @Success 200 {object} dto.PageResult
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/firewall/filter/search [post]
// @Router /hosts/firewall/filter/rule/search [post]
func (b *BaseApi) SearchFilterRules(c *gin.Context) {
var req dto.SearchPageWithType
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+72
View File
@@ -0,0 +1,72 @@
package v2
import (
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/utils/ai_tools/gpu"
"github.com/1Panel-dev/1Panel/agent/utils/ai_tools/gpu/common"
"github.com/1Panel-dev/1Panel/agent/utils/ai_tools/xpu"
"github.com/gin-gonic/gin"
)
// @Tags AI
// @Summary Load gpu / xpu info
// @Accept json
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/gpu/load [get]
func (b *BaseApi) LoadGpuInfo(c *gin.Context) {
ok, client := gpu.New()
if ok {
info, err := client.LoadGpuInfo()
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, info)
return
}
xpuOK, xpuClient := xpu.New()
if xpuOK {
info, err := xpuClient.LoadGpuInfo()
if err != nil {
helper.BadRequest(c, err)
return
}
helper.SuccessWithData(c, info)
return
}
helper.SuccessWithData(c, &common.GpuInfo{})
}
// @Tags AI
// @Summary Get CPU options
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/gpu/options [get]
func (b *BaseApi) GetCPUOptions(c *gin.Context) {
helper.SuccessWithData(c, monitorService.LoadGPUOptions())
}
// @Tags Monitor
// @Summary Load monitor data
// @Param request body dto.MonitorGPUSearch true "request"
// @Success 200 {object} dto.MonitorGPUData
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/gpu/search [post]
func (b *BaseApi) LoadGPUMonitor(c *gin.Context) {
var req dto.MonitorGPUSearch
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
data, err := monitorService.LoadGPUMonitorData(req)
if err != nil {
helper.InternalServer(c, err)
return
}
helper.SuccessWithData(c, data)
}
+6
View File
@@ -5,6 +5,12 @@ import (
"github.com/gin-gonic/gin"
)
// @Tags Health
// @Summary Check health
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /health/check [get]
func (b *BaseApi) CheckHealth(c *gin.Context) {
helper.Success(c)
}
+76
View File
@@ -7,6 +7,15 @@ import (
"github.com/gin-gonic/gin"
)
// @Tags Host
// @Summary Create host
// @Accept json
// @Param request body dto.HostOperate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts [post]
// @x-panel-log {"bodyKeys":["name","addr"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"创建主机 [name][addr]","formatEN":"create host [name][addr]"}
func (b *BaseApi) CreateHost(c *gin.Context) {
var req dto.HostOperate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -21,6 +30,14 @@ func (b *BaseApi) CreateHost(c *gin.Context) {
helper.SuccessWithData(c, host)
}
// @Tags Host
// @Summary Test by info
// @Accept json
// @Param request body dto.HostConnTest true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/test/byinfo [post]
func (b *BaseApi) TestByInfo(c *gin.Context) {
var req dto.HostConnTest
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -30,6 +47,14 @@ func (b *BaseApi) TestByInfo(c *gin.Context) {
helper.SuccessWithData(c, hostService.TestByInfo(req))
}
// @Tags Host
// @Summary Test by ID
// @Accept json
// @Param request body dto.OperateByID true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/test/byid [post]
func (b *BaseApi) TestByID(c *gin.Context) {
var req dto.OperateByID
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -39,6 +64,14 @@ func (b *BaseApi) TestByID(c *gin.Context) {
helper.SuccessWithData(c, hostService.TestLocalConn(req.ID))
}
// @Tags Host
// @Summary Host tree
// @Accept json
// @Param request body dto.SearchForTree true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tree [post]
func (b *BaseApi) HostTree(c *gin.Context) {
var req dto.SearchForTree
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -53,6 +86,14 @@ func (b *BaseApi) HostTree(c *gin.Context) {
helper.SuccessWithData(c, data)
}
// @Tags Host
// @Summary Search host
// @Accept json
// @Param request body dto.SearchPageWithGroup true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/search [post]
func (b *BaseApi) SearchHost(c *gin.Context) {
var req dto.SearchPageWithGroup
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -68,6 +109,15 @@ func (b *BaseApi) SearchHost(c *gin.Context) {
helper.SuccessWithData(c, dto.PageResult{Items: list, Total: total})
}
// @Tags Host
// @Summary Delete host
// @Accept json
// @Param request body dto.OperateByIDs true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/del [post]
// @x-panel-log {"bodyKeys":["ids"],"paramKeys":[],"BeforeFunctions":[{"input_column":"id","input_value":"ids","isList":true,"db":"hosts","output_column":"name","output_value":"names"}],"formatZH":"删除主机 [names]","formatEN":"delete host [names]"}
func (b *BaseApi) DeleteHost(c *gin.Context) {
var req dto.OperateByIDs
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -81,6 +131,15 @@ func (b *BaseApi) DeleteHost(c *gin.Context) {
helper.Success(c)
}
// @Tags Host
// @Summary Update host
// @Accept json
// @Param request body dto.HostOperate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/update [post]
// @x-panel-log {"bodyKeys":["name","addr"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新主机 [name][addr]","formatEN":"update host [name][addr]"}
func (b *BaseApi) UpdateHost(c *gin.Context) {
var req dto.HostOperate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -140,6 +199,15 @@ func (b *BaseApi) UpdateHost(c *gin.Context) {
helper.SuccessWithData(c, hostItem)
}
// @Tags Host
// @Summary Update host group
// @Accept json
// @Param request body dto.ChangeGroup true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/update/group [post]
// @x-panel-log {"bodyKeys":["id","groupID"],"paramKeys":[],"BeforeFunctions":[{"input_column":"id","input_value":"id","isList":false,"db":"hosts","output_column":"name","output_value":"name"}],"formatZH":"更新主机 [name] 分组","formatEN":"update host [name] group"}
func (b *BaseApi) UpdateHostGroup(c *gin.Context) {
var req dto.ChangeGroup
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -153,6 +221,14 @@ func (b *BaseApi) UpdateHostGroup(c *gin.Context) {
helper.Success(c)
}
// @Tags Host
// @Summary Get host by ID
// @Accept json
// @Param request body dto.OperateByID true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/info [post]
func (b *BaseApi) GetHostByID(c *gin.Context) {
var req dto.OperateByID
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+63 -16
View File
@@ -9,13 +9,13 @@ import (
// @Tags Host tool
// @Summary Get tool status
// @Accept json
// @Param request body request.HostToolReq true "request"
// @Param request body request.HostToolTypeReq true "request"
// @Success 200 {object} response.HostToolRes
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tool [post]
// @Router /hosts/tool/status [post]
func (b *BaseApi) GetToolStatus(c *gin.Context) {
var req request.HostToolReq
var req request.HostToolTypeReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
@@ -53,14 +53,14 @@ func (b *BaseApi) InitToolConfig(c *gin.Context) {
// @Tags Host tool
// @Summary Operate tool
// @Accept json
// @Param request body request.HostToolReq true "request"
// @Param request body request.HostToolOperateReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tool/operate [post]
// @x-panel-log {"bodyKeys":["operate","type"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"[operate] [type] ","formatEN":"[operate] [type]"}
func (b *BaseApi) OperateTool(c *gin.Context) {
var req request.HostToolReq
var req request.HostToolOperateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
@@ -75,19 +75,18 @@ func (b *BaseApi) OperateTool(c *gin.Context) {
// @Tags Host tool
// @Summary Get tool config
// @Accept json
// @Param request body request.HostToolConfig true "request"
// @Param request body request.HostToolTypeReq true "request"
// @Success 200 {object} response.HostToolConfig
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tool/config [post]
// @x-panel-log {"bodyKeys":["operate"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"[operate] 主机工具配置文件 ","formatEN":"[operate] tool config"}
func (b *BaseApi) OperateToolConfig(c *gin.Context) {
var req request.HostToolConfig
// @Router /hosts/tool/config/get [post]
func (b *BaseApi) GetToolConfig(c *gin.Context) {
var req request.HostToolTypeReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
config, err := hostToolService.OperateToolConfig(req)
config, err := hostToolService.GetToolConfig(req)
if err != nil {
helper.InternalServer(c, err)
return
@@ -95,6 +94,28 @@ func (b *BaseApi) OperateToolConfig(c *gin.Context) {
helper.SuccessWithData(c, config)
}
// @Tags Host tool
// @Summary Update tool config
// @Accept json
// @Param request body request.HostToolConfigUpdate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tool/config/set [post]
// @x-panel-log {"bodyKeys":["type"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新 [type] 主机工具配置文件 ","formatEN":"update [type] tool config"}
func (b *BaseApi) UpdateToolConfig(c *gin.Context) {
var req request.HostToolConfigUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
if err := hostToolService.UpdateToolConfig(req); err != nil {
helper.InternalServer(c, err)
return
}
helper.Success(c)
}
// @Tags Host tool
// @Summary Create Supervisor process
// @Accept json
@@ -137,18 +158,44 @@ func (b *BaseApi) GetProcess(c *gin.Context) {
// @Tags Host tool
// @Summary Get Supervisor process config file
// @Accept json
// @Param request body request.SupervisorProcessFileReq true "request"
// @Param request body request.HostSupervisorProcessFileGetReq true "request"
// @Success 200 {string} content
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tool/supervisor/process/file [post]
// @x-panel-log {"bodyKeys":["operate"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"[operate] Supervisor 进程文件 ","formatEN":"[operate] Supervisor Process Config file"}
// @Router /hosts/tool/supervisor/process/file/get [post]
func (b *BaseApi) GetProcessFile(c *gin.Context) {
var req request.SupervisorProcessFileReq
var req request.HostSupervisorProcessFileGetReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
content, err := hostToolService.OperateSupervisorProcessFile(req)
content, err := hostToolService.GetSupervisorProcessFile(req)
if err != nil {
helper.InternalServer(c, err)
return
}
helper.SuccessWithData(c, content)
}
// @Tags Host tool
// @Summary Operate Supervisor process config file
// @Accept json
// @Param request body request.HostSupervisorProcessFileOperateReq true "request"
// @Success 200 {string} content
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/tool/supervisor/process/file [post]
// @x-panel-log {"bodyKeys":["operate"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"[operate] Supervisor 进程文件 ","formatEN":"[operate] Supervisor Process Config file"}
func (b *BaseApi) OperateProcessFile(c *gin.Context) {
var req request.HostSupervisorProcessFileOperateReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
content, err := hostToolService.OperateSupervisorProcessFile(request.SupervisorProcessFileReq{
Name: req.Name,
Operate: req.Operate,
Content: req.Content,
File: req.File,
})
if err != nil {
helper.InternalServer(c, err)
return
+13 -26
View File
@@ -31,27 +31,6 @@ func (b *BaseApi) LoadMonitor(c *gin.Context) {
helper.SuccessWithDataGzipped(c, data)
}
// @Tags Monitor
// @Summary Load monitor data
// @Param request body dto.MonitorGPUSearch true "request"
// @Success 200 {object} dto.MonitorGPUData
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/monitor/gpu/search [post]
func (b *BaseApi) LoadGPUMonitor(c *gin.Context) {
var req dto.MonitorGPUSearch
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
data, err := monitorService.LoadGPUMonitorData(req)
if err != nil {
helper.InternalServer(c, err)
return
}
helper.SuccessWithData(c, data)
}
// @Tags Monitor
// @Summary Clean monitor data
// @Success 200
@@ -91,7 +70,7 @@ func (b *BaseApi) LoadMonitorSetting(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/monitor/setting/update [post]
// @x-panel-log {"bodyKeys":["key", "value"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改默认监控网卡 [name]-[value]","formatEN":"update default monitor [name]-[value]"}
// @x-panel-log {"bodyKeys":["key", "value"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改默认监控网卡 [key]-[value]","formatEN":"update default monitor [key]-[value]"}
func (b *BaseApi) UpdateMonitorSetting(c *gin.Context) {
var req dto.MonitorSettingUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -105,6 +84,12 @@ func (b *BaseApi) UpdateMonitorSetting(c *gin.Context) {
helper.Success(c)
}
// @Tags Monitor
// @Summary Get network options
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/monitor/netoptions [get]
func (b *BaseApi) GetNetworkOptions(c *gin.Context) {
netStat, _ := net.IOCounters(true)
var options []string
@@ -116,6 +101,12 @@ func (b *BaseApi) GetNetworkOptions(c *gin.Context) {
helper.SuccessWithData(c, options)
}
// @Tags Monitor
// @Summary Get IO options
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/monitor/iooptions [get]
func (b *BaseApi) GetIOOptions(c *gin.Context) {
diskStat, _ := disk.IOCounters()
var options []string
@@ -126,7 +117,3 @@ func (b *BaseApi) GetIOOptions(c *gin.Context) {
sort.Strings(options)
helper.SuccessWithData(c, options)
}
func (b *BaseApi) GetCPUOptions(c *gin.Context) {
helper.SuccessWithData(c, monitorService.LoadGPUOptions())
}
+11
View File
@@ -5,9 +5,20 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/dto/request"
websocket2 "github.com/1Panel-dev/1Panel/agent/utils/websocket"
"github.com/gin-gonic/gin"
"github.com/gorilla/websocket"
)
// @Tags Process
// @Summary Process ws
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /process/ws [get]
func (b *BaseApi) ProcessWs(c *gin.Context) {
if !websocket.IsWebSocketUpgrade(c.Request) {
helper.Success(c)
return
}
ws, err := wsUpgrade.Upgrade(c.Writer, c.Request, nil)
if err != nil {
return
+5 -4
View File
@@ -61,7 +61,7 @@ func (b *BaseApi) CreateRuntime(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /runtimes/del [post]
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"删除运行环境 [name]","formatEN":"Delete runtime [name]"}
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"删除运行环境 [id]","formatEN":"Delete runtime [id]"}
func (b *BaseApi) DeleteRuntime(c *gin.Context) {
var req request.RuntimeDelete
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -81,6 +81,7 @@ func (b *BaseApi) DeleteRuntime(c *gin.Context) {
// @Success 200 {array} dto.AppResource
// @Security ApiKeyAuth
// @Security Timestamp
// @Param id path integer true "id"
// @Router /runtimes/installed/delete/check/:id [get]
func (b *BaseApi) DeleteRuntimeCheck(c *gin.Context) {
runTimeId, err := helper.GetIntParamByKey(c, "id")
@@ -120,7 +121,7 @@ func (b *BaseApi) UpdateRuntime(c *gin.Context) {
// @Tags Runtime
// @Summary Get runtime
// @Accept json
// @Param id path string true "request"
// @Param id path integer true "request"
// @Success 200 {object} response.RuntimeDTO
// @Security ApiKeyAuth
// @Security Timestamp
@@ -168,7 +169,7 @@ func (b *BaseApi) GetNodePackageRunScript(c *gin.Context) {
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /runtimes/operate [post]
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"操作运行环境 [name]","formatEN":"Operate runtime [name]"}
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"操作运行环境 [id]","formatEN":"Operate runtime [id]"}
func (b *BaseApi) OperateRuntime(c *gin.Context) {
var req request.RuntimeOperate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -242,7 +243,7 @@ func (b *BaseApi) SyncStatus(c *gin.Context) {
// @Tags Runtime
// @Summary Get php runtime extension
// @Accept json
// @Param id path string true "request"
// @Param id path integer true "request"
// @Success 200 {object} response.PHPExtensionRes
// @Security ApiKeyAuth
// @Security Timestamp
+51 -30
View File
@@ -1,16 +1,12 @@
package v2
import (
"encoding/json"
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/dto/request"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/ssh"
"github.com/gin-gonic/gin"
"github.com/pkg/errors"
)
// @Tags System Setting
@@ -28,6 +24,12 @@ func (b *BaseApi) GetSettingInfo(c *gin.Context) {
helper.SuccessWithData(c, setting)
}
// @Tags System Setting
// @Summary Get terminal AI setting info
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/terminal/ai/search [post]
func (b *BaseApi) GetTerminalAISettingInfo(c *gin.Context) {
setting, err := settingService.GetTerminalAIInfo()
if err != nil {
@@ -50,14 +52,14 @@ func (b *BaseApi) GetSystemAvailable(c *gin.Context) {
// @Tags System Setting
// @Summary Update system setting
// @Accept json
// @Param request body dto.SettingUpdate true "request"
// @Param request body dto.AgentSettingUpdate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/update [post]
// @x-panel-log {"bodyKeys":["key","value"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"修改系统配置 [key] => [value]","formatEN":"update system setting [key] => [value]"}
func (b *BaseApi) UpdateSetting(c *gin.Context) {
var req dto.SettingUpdate
var req dto.AgentSettingUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
@@ -69,6 +71,15 @@ func (b *BaseApi) UpdateSetting(c *gin.Context) {
helper.Success(c)
}
// @Tags System Setting
// @Summary Update terminal AI setting
// @Accept json
// @Param request body dto.TerminalAIInfo true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/terminal/ai/update [post]
// @x-panel-log {"bodyKeys":["aiStatus","aiAccountId"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新终端 AI 设置 [aiStatus][aiAccountId]","formatEN":"update terminal AI setting [aiStatus][aiAccountId]"}
func (b *BaseApi) UpdateTerminalAISetting(c *gin.Context) {
var req dto.TerminalAIInfo
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -82,6 +93,12 @@ func (b *BaseApi) UpdateTerminalAISetting(c *gin.Context) {
helper.Success(c)
}
// @Tags System Setting
// @Summary Get file manage AI setting info
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/files/ai/search [post]
func (b *BaseApi) GetFileManageAISettingInfo(c *gin.Context) {
setting, err := settingService.GetFileManageAIInfo()
if err != nil {
@@ -91,6 +108,15 @@ func (b *BaseApi) GetFileManageAISettingInfo(c *gin.Context) {
helper.SuccessWithData(c, setting)
}
// @Tags System Setting
// @Summary Update file manage AI setting
// @Accept json
// @Param request body dto.FileManageAIInfo true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/files/ai/update [post]
// @x-panel-log {"bodyKeys":["aiStatus","aiAccountId"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新文件管理 AI 设置 [aiStatus][aiAccountId]","formatEN":"update file manage AI setting [aiStatus][aiAccountId]"}
func (b *BaseApi) UpdateFileManageAISetting(c *gin.Context) {
var req dto.FileManageAIInfo
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -138,6 +164,16 @@ func (b *BaseApi) UpdateFileHistorySetting(c *gin.Context) {
helper.Success(c)
}
// @Tags System Setting
// @Summary Load website dir
// @Success 200 {string} path
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/website/dir [get]
func (b *BaseApi) LoadWebsiteDir(c *gin.Context) {
helper.SuccessWithData(c, settingService.GetWebsiteDir())
}
// @Tags System Setting
// @Summary Load local backup dir
// @Success 200 {string} path
@@ -158,6 +194,12 @@ func (b *BaseApi) LoadLocalConn(c *gin.Context) {
helper.SuccessWithData(c, settingService.GetLocalConn())
}
// @Tags System Setting
// @Summary Check local conn
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/ssh/check [post]
func (b *BaseApi) CheckLocalConn(c *gin.Context) {
client, err := loadLocalConn()
if err == nil && client != nil {
@@ -173,7 +215,7 @@ func (b *BaseApi) CheckLocalConn(c *gin.Context) {
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/ssh/conn/default [post]
// @Router /settings/ssh/default [post]
// @x-panel-log {"bodyKeys":["defaultConn"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"本地终端默认连接 [defaultConn]","formatEN":"update system default conn [defaultConn]"}
func (b *BaseApi) SetDefaultIsConn(c *gin.Context) {
var req dto.SSHDefaultConn
@@ -223,12 +265,8 @@ func (b *BaseApi) SaveLocalConn(c *gin.Context) {
}
func loadLocalConn() (*ssh.SSHClient, error) {
connInfoInDB := settingService.GetSettingByKey("LocalSSHConn")
if len(connInfoInDB) == 0 {
return nil, errors.New("no such ssh conn info in db!")
}
var connInDB model.LocalConnInfo
if err := json.Unmarshal([]byte(connInfoInDB), &connInDB); err != nil {
connInDB, err := settingService.GetLocalConnForSSH()
if err != nil {
return nil, err
}
sshInfo := ssh.ConnInfo{
@@ -243,23 +281,6 @@ func loadLocalConn() (*ssh.SSHClient, error) {
return ssh.NewClient(sshInfo)
}
// @Tags System Setting
// @Summary Load system setting by key
// @Param key path string true "key"
// @Success 200 {object} dto.SettingInfo
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/get/{key} [get]
func (b *BaseApi) GetSettingByKey(c *gin.Context) {
key := c.Param("key")
if len(key) == 0 {
helper.BadRequest(c, errors.New("key is empty"))
return
}
value := settingService.GetSettingByKey(key)
helper.SuccessWithData(c, value)
}
// @Tags System Setting
// @Summary Save common description
// @Accept json
+27
View File
@@ -3,6 +3,8 @@ package v2
import (
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/dto/request"
"github.com/1Panel-dev/1Panel/agent/app/dto/response"
"github.com/gin-gonic/gin"
)
@@ -30,6 +32,31 @@ func (b *BaseApi) PageTasks(c *gin.Context) {
})
}
// @Tags TaskLog
// @Summary Read task log by Line
// @Param request body request.TaskLogReadReq true "request"
// @Success 200 {object} response.FileLineContent
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /logs/tasks/read [post]
func (b *BaseApi) ReadTaskLogByLine(c *gin.Context) {
var req request.TaskLogReadReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
var res *response.FileLineContent
res, err := taskService.ReadByLine(req)
if err != nil {
helper.InternalServer(c, err)
return
}
if res.TotalLines > 100 {
helper.SuccessWithDataGzipped(c, res)
} else {
helper.SuccessWithData(c, res)
}
}
// @Tags TaskLog
// @Summary Get the number of executing tasks
// @Success 200 {integer} int64
+44
View File
@@ -6,6 +6,14 @@ import (
"github.com/gin-gonic/gin"
)
// @Tags TensorRT LLM
// @Summary Page TensorRT LLMs
// @Accept json
// @Param request body request.TensorRTLLMSearch true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/tensorrt/search [post]
func (b *BaseApi) PageTensorRTLLMs(c *gin.Context) {
var req request.TensorRTLLMSearch
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -15,6 +23,15 @@ func (b *BaseApi) PageTensorRTLLMs(c *gin.Context) {
helper.SuccessWithData(c, list)
}
// @Tags TensorRT LLM
// @Summary Create TensorRT LLM
// @Accept json
// @Param request body request.TensorRTLLMCreate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/tensorrt/create [post]
// @x-panel-log {"bodyKeys":["name"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"创建 TensorRT LLM [name]","formatEN":"create TensorRT LLM [name]"}
func (b *BaseApi) CreateTensorRTLLM(c *gin.Context) {
var req request.TensorRTLLMCreate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -28,6 +45,15 @@ func (b *BaseApi) CreateTensorRTLLM(c *gin.Context) {
helper.Success(c)
}
// @Tags TensorRT LLM
// @Summary Update TensorRT LLM
// @Accept json
// @Param request body request.TensorRTLLMUpdate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/tensorrt/update [post]
// @x-panel-log {"bodyKeys":["id","name"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新 TensorRT LLM [id][name]","formatEN":"update TensorRT LLM [id][name]"}
func (b *BaseApi) UpdateTensorRTLLM(c *gin.Context) {
var req request.TensorRTLLMUpdate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -41,6 +67,15 @@ func (b *BaseApi) UpdateTensorRTLLM(c *gin.Context) {
helper.Success(c)
}
// @Tags TensorRT LLM
// @Summary Delete TensorRT LLM
// @Accept json
// @Param request body request.TensorRTLLMDelete true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/tensorrt/delete [post]
// @x-panel-log {"bodyKeys":["id"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"删除 TensorRT LLM [id]","formatEN":"delete TensorRT LLM [id]"}
func (b *BaseApi) DeleteTensorRTLLM(c *gin.Context) {
var req request.TensorRTLLMDelete
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -54,6 +89,15 @@ func (b *BaseApi) DeleteTensorRTLLM(c *gin.Context) {
helper.Success(c)
}
// @Tags TensorRT LLM
// @Summary Operate TensorRT LLM
// @Accept json
// @Param request body request.TensorRTLLMOperate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /ai/tensorrt/operate [post]
// @x-panel-log {"bodyKeys":["id","operate"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"操作 TensorRT LLM [id][operate]","formatEN":"operate TensorRT LLM [id][operate]"}
func (b *BaseApi) OperateTensorRTLLM(c *gin.Context) {
var req request.TensorRTLLMOperate
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+144 -105
View File
@@ -8,7 +8,9 @@ import (
"strconv"
"time"
"github.com/1Panel-dev/1Panel/agent/app/api/v2/helper"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/app/service"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
@@ -19,117 +21,52 @@ import (
"github.com/pkg/errors"
)
func (b *BaseApi) WsSSH(c *gin.Context) {
wsConn, err := upGrader.Upgrade(c.Writer, c.Request, nil)
if err != nil {
global.LOG.Errorf("gin context http handler failed, err: %v", err)
return
}
defer wsConn.Close()
if global.CONF.Base.IsDemo {
if wshandleError(wsConn, errors.New(" demo server, prohibit this operation!")) {
return
}
}
cols, err := strconv.Atoi(c.DefaultQuery("cols", "80"))
if wshandleError(wsConn, errors.WithMessage(err, "invalid param cols in request")) {
return
}
rows, err := strconv.Atoi(c.DefaultQuery("rows", "40"))
if wshandleError(wsConn, errors.WithMessage(err, "invalid param rows in request")) {
return
}
hostID, _ := strconv.Atoi(c.DefaultQuery("id", "0"))
var client *ssh.SSHClient
if hostID > 0 {
host, err := service.GetHostInfo(uint(hostID))
if wshandleError(wsConn, errors.WithMessage(err, "load host info by id failed")) {
return
}
connInfo := ssh.ConnInfo{
Addr: host.Addr,
Port: int(host.Port),
User: host.User,
AuthMode: host.AuthMode,
Password: host.Password,
PrivateKey: []byte(host.PrivateKey),
}
if len(host.PassPhrase) != 0 {
connInfo.PassPhrase = []byte(host.PassPhrase)
}
client, err = ssh.NewClient(connInfo)
if wshandleError(wsConn, errors.WithMessage(err, "failed to set up the connection. Please check the host information")) {
return
}
} else {
client, err = loadLocalConn()
if wshandleError(wsConn, errors.WithMessage(err, "failed to set up the connection. Please check the host information")) {
return
}
}
defer client.Close()
command := c.DefaultQuery("command", "")
sws, err := terminal.NewLogicSshWsSession(cols, rows, client.Client, wsConn, command)
if wshandleError(wsConn, err) {
return
}
defer sws.Close()
quitChan := make(chan bool, 3)
sws.Start(quitChan)
go sws.Wait(quitChan)
<-quitChan
dt := time.Now().Add(time.Second)
_ = wsConn.WriteControl(websocket.CloseMessage, nil, dt)
// @Tags Terminal
// @Summary Ws local terminal
// @Param command query string false "command"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/terminal/local [get]
func (b *BaseApi) WsLocalTerminal(c *gin.Context) {
b.runSSHSession(c, loadLocalConn, c.DefaultQuery("command", ""))
}
func (b *BaseApi) ContainerWsSSH(c *gin.Context) {
wsConn, err := upGrader.Upgrade(c.Writer, c.Request, nil)
if err != nil {
global.LOG.Errorf("gin context http handler failed, err: %v", err)
// @Tags Terminal
// @Summary Ws host SSH
// @Param id query integer false "id"
// @Param command query string false "command"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/terminal/ssh [get]
func (b *BaseApi) WsHostSSH(c *gin.Context) {
b.runSSHSession(c, func() (*ssh.SSHClient, error) {
hostID, _ := strconv.Atoi(c.DefaultQuery("id", "0"))
if hostID <= 0 {
return nil, errors.New("missing host id")
}
host, err := service.GetHostInfo(uint(hostID))
return newHostSSHClient(host, err)
}, c.DefaultQuery("command", ""))
}
// @Tags Terminal
// @Summary Ws container terminal
// @Param cols query integer false "cols"
// @Param rows query integer false "rows"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/terminal/container [get]
func (b *BaseApi) WsContainerTerminal(c *gin.Context) {
wsConn, cols, rows, ok := prepareTerminalSession(c)
if !ok {
return
}
defer wsConn.Close()
if global.CONF.Base.IsDemo {
if wshandleError(wsConn, errors.New(" demo server, prohibit this operation!")) {
return
}
}
cols, err := strconv.Atoi(c.DefaultQuery("cols", "80"))
if wshandleError(wsConn, errors.WithMessage(err, "invalid param cols in request")) {
return
}
rows, err := strconv.Atoi(c.DefaultQuery("rows", "40"))
if wshandleError(wsConn, errors.WithMessage(err, "invalid param rows in request")) {
return
}
source := c.Query("source")
var initCmd []string
switch source {
case "redis", "redis-cluster":
initCmd, err = loadRedisInitCmd(c, source)
case "ollama":
initCmd, err = loadOllamaInitCmd(c)
case "container":
initCmd, err = loadContainerInitCmd(c)
case "database":
initCmd, err = loadDatabaseInitCmd(c)
default:
if wshandleError(wsConn, fmt.Errorf("not support such source %s", source)) {
return
}
}
if wshandleError(wsConn, err) {
return
}
slave, err := terminal.NewCommand("docker", initCmd...)
slave, err := loadContainerTerminalCommand(c)
if wshandleError(wsConn, err) {
return
}
@@ -147,10 +84,112 @@ func (b *BaseApi) ContainerWsSSH(c *gin.Context) {
<-quitChan
global.LOG.Info("websocket finished")
closeTerminalConn(wsConn)
}
func prepareTerminalSession(c *gin.Context) (*websocket.Conn, int, int, bool) {
if !websocket.IsWebSocketUpgrade(c.Request) {
helper.Success(c)
return nil, 0, 0, false
}
wsConn, err := upGrader.Upgrade(c.Writer, c.Request, nil)
if err != nil {
global.LOG.Errorf("gin context http handler failed, err: %v", err)
return nil, 0, 0, false
}
if global.CONF.Base.IsDemo {
if wshandleError(wsConn, errors.New(" demo server, prohibit this operation!")) {
return nil, 0, 0, false
}
}
cols, err := strconv.Atoi(c.DefaultQuery("cols", "80"))
if wshandleError(wsConn, errors.WithMessage(err, "invalid param cols in request")) {
return nil, 0, 0, false
}
rows, err := strconv.Atoi(c.DefaultQuery("rows", "40"))
if wshandleError(wsConn, errors.WithMessage(err, "invalid param rows in request")) {
return nil, 0, 0, false
}
return wsConn, cols, rows, true
}
func (b *BaseApi) runSSHSession(c *gin.Context, connect func() (*ssh.SSHClient, error), command string) {
wsConn, cols, rows, ok := prepareTerminalSession(c)
if !ok {
return
}
defer wsConn.Close()
client, clientErr := connect()
if wshandleError(wsConn, errors.WithMessage(clientErr, "failed to set up the connection. Please check the host information")) {
return
}
defer client.Close()
sws, err := terminal.NewLogicSshWsSession(cols, rows, client.Client, wsConn, command)
if wshandleError(wsConn, err) {
return
}
defer sws.Close()
quitChan := make(chan bool, 3)
sws.Start(quitChan)
go sws.Wait(quitChan)
<-quitChan
closeTerminalConn(wsConn)
}
func closeTerminalConn(wsConn *websocket.Conn) {
dt := time.Now().Add(time.Second)
_ = wsConn.WriteControl(websocket.CloseMessage, nil, dt)
}
func newHostSSHClient(host *model.Host, err error) (*ssh.SSHClient, error) {
if err != nil {
return nil, errors.WithMessage(err, "load host info by id failed")
}
connInfo := ssh.ConnInfo{
Addr: host.Addr,
Port: int(host.Port),
User: host.User,
AuthMode: host.AuthMode,
Password: host.Password,
PrivateKey: []byte(host.PrivateKey),
}
if len(host.PassPhrase) != 0 {
connInfo.PassPhrase = []byte(host.PassPhrase)
}
return ssh.NewClient(connInfo)
}
func loadContainerTerminalCommand(c *gin.Context) (*terminal.LocalCommand, error) {
source := c.Query("source")
var (
initCmd []string
err error
)
switch source {
case "redis", "redis-cluster":
initCmd, err = loadRedisInitCmd(c, source)
case "ollama":
initCmd, err = loadOllamaInitCmd(c)
case "container":
initCmd, err = loadContainerInitCmd(c)
case "database":
initCmd, err = loadDatabaseInitCmd(c)
default:
return nil, fmt.Errorf("not support such source %s", source)
}
if err != nil {
return nil, err
}
return terminal.NewCommand("docker", initCmd...)
}
func loadRedisInitCmd(c *gin.Context, redisType string) ([]string, error) {
name := c.Query("name")
from := c.Query("from")
+42 -9
View File
@@ -181,6 +181,7 @@ func (b *BaseApi) GetWebsite(c *gin.Context) {
// @Success 200 {object} response.FileInfo
// @Security ApiKeyAuth
// @Security Timestamp
// @Param type path string true "type"
// @Router /websites/:id/config/:type [get]
func (b *BaseApi) GetWebsiteNginx(c *gin.Context) {
id, err := helper.GetParamID(c)
@@ -269,6 +270,7 @@ func (b *BaseApi) GetHTTPSConfig(c *gin.Context) {
// @Success 200 {object} response.WebsiteHTTPS
// @Security ApiKeyAuth
// @Security Timestamp
// @Param id path string true "id"
// @Router /websites/:id/https [post]
// @x-panel-log {"bodyKeys":["websiteId"],"paramKeys":[],"BeforeFunctions":[{"input_column":"id","input_value":"websiteId","isList":false,"db":"websites","output_column":"primary_domain","output_value":"domain"}],"formatZH":"更新网站 [domain] https 配置","formatEN":"Update website https [domain] conf"}
func (b *BaseApi) UpdateHTTPSConfig(c *gin.Context) {
@@ -330,25 +332,45 @@ func (b *BaseApi) UpdateWebsiteNginxConfig(c *gin.Context) {
}
// @Tags Website
// @Summary Operate website log
// @Summary Get website log
// @Accept json
// @Param request body request.WebsiteLogReq true "request"
// @Param request body request.WebsiteLogSearchReq true "request"
// @Success 200 {object} response.WebsiteLog
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /websites/log [post]
// @Router /websites/log/search [post]
func (b *BaseApi) GetWebsiteLog(c *gin.Context) {
var req request.WebsiteLogSearchReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
res, err := websiteService.GetWebsiteLog(req)
if err != nil {
helper.InternalServer(c, err)
return
}
helper.SuccessWithData(c, res)
}
// @Tags Website
// @Summary Operate website log
// @Accept json
// @Param request body request.WebsiteLogReq true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /websites/log/operate [post]
// @x-panel-log {"bodyKeys":["id", "operate"],"paramKeys":[],"BeforeFunctions":[{"input_column":"id","input_value":"id","isList":false,"db":"websites","output_column":"primary_domain","output_value":"domain"}],"formatZH":"[domain][operate] 日志","formatEN":"[domain][operate] logs"}
func (b *BaseApi) OpWebsiteLog(c *gin.Context) {
var req request.WebsiteLogReq
if err := helper.CheckBindAndValidate(&req, c); err != nil {
return
}
res, err := websiteService.OpWebsiteLog(req)
if err != nil {
if err := websiteService.OpWebsiteLog(req); err != nil {
helper.InternalServer(c, err)
return
}
helper.SuccessWithData(c, res)
helper.Success(c)
}
// @Tags Website
@@ -799,6 +821,7 @@ func (b *BaseApi) GetDirConfig(c *gin.Context) {
// @Success 200 {object} response.WebsiteHtmlRes
// @Security ApiKeyAuth
// @Security Timestamp
// @Param type path string true "type"
// @Router /websites/default/html/:type [get]
func (b *BaseApi) GetDefaultHtml(c *gin.Context) {
resourceType, err := helper.GetStrParamByKey(c, "type")
@@ -838,11 +861,11 @@ func (b *BaseApi) UpdateDefaultHtml(c *gin.Context) {
// @Tags Website
// @Summary Get website upstreams
// @Accept json
// @Param request body request.WebsiteCommonReq true "request"
// @Param id path integer true "id"
// @Success 200 {array} dto.NginxUpstream
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /websites/lbs [get]
// @Router /websites/{id}/lbs [get]
func (b *BaseApi) GetLoadBalances(c *gin.Context) {
id, err := helper.GetParamID(c)
if err != nil {
@@ -937,6 +960,15 @@ func (b *BaseApi) UpdateLoadBalanceFile(c *gin.Context) {
helper.Success(c)
}
// @Tags Website
// @Summary Change website group
// @Accept json
// @Param request body dto.UpdateGroup true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /websites/group/change [post]
// @x-panel-log {"bodyKeys":["group","newGroup"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"网站分组 [group] 迁移到 [newGroup]","formatEN":"change website group [group] to [newGroup]"}
func (b *BaseApi) ChangeWebsiteGroup(c *gin.Context) {
var req dto.UpdateGroup
if err := helper.CheckBindAndValidate(&req, c); err != nil {
@@ -969,6 +1001,7 @@ func (b *BaseApi) UpdateProxyCache(c *gin.Context) {
helper.Success(c)
}
// @Tags Website
// @Summary Get website proxy cache config
// @Accept json
// @Param id path int true "id"
@@ -1295,7 +1328,7 @@ func (b *BaseApi) UpdateStreamConfig(c *gin.Context) {
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /websites/batch/https [post]
// @Router /websites/batch/ssl [post]
func (b *BaseApi) BatchSetHttps(c *gin.Context) {
var req request.BatchWebsiteHttps
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+9
View File
@@ -333,6 +333,15 @@ func (b *BaseApi) DownloadWebsiteSSL(c *gin.Context) {
http.ServeContent(c.Writer, c.Request, info.Name(), info.ModTime(), file)
}
// @Tags Website SSL
// @Summary Import master SSL
// @Accept json
// @Param request body model.WebsiteSSL true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /websites/ssl/import [post]
// @x-panel-log {"bodyKeys":["primaryDomain"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"导入主节点证书 [primaryDomain]","formatEN":"import master SSL [primaryDomain]"}
func (b *BaseApi) ImportMasterSSL(c *gin.Context) {
var req model.WebsiteSSL
if err := helper.CheckBindAndValidate(&req, c); err != nil {
+97 -14
View File
@@ -27,6 +27,84 @@ type AgentCreateReq struct {
DockerCompose string `json:"dockerCompose"`
}
type AgentBatchInstallReq struct {
Name string `json:"name"`
Remark string `json:"remark"`
AppVersion string `json:"appVersion" validate:"required"`
WebUIPort int `json:"webUIPort" validate:"required,min=1,max=65535"`
BridgePort int `json:"bridgePort"`
AllowedOrigins []string `json:"allowedOrigins"`
AgentType string `json:"agentType" validate:"required,oneof=openclaw copaw hermes-agent"`
Model string `json:"model"`
AccountID uint `json:"accountId"`
Token string `json:"token"`
TaskID string `json:"taskID"`
Advanced bool `json:"advanced"`
ContainerName string `json:"containerName"`
AllowPort bool `json:"allowPort"`
SpecifyIP string `json:"specifyIP"`
RestartPolicy string `json:"restartPolicy"`
CpuQuota float64 `json:"cpuQuota"`
MemoryLimit float64 `json:"memoryLimit"`
MemoryUnit string `json:"memoryUnit"`
PullImage bool `json:"pullImage"`
EditCompose bool `json:"editCompose"`
DockerCompose string `json:"dockerCompose"`
MasterAccountID uint `json:"masterAccountId"`
FallbackAccessHost string `json:"fallbackAccessHost"`
AccountSnapshot AgentAccountInfo `json:"accountSnapshot"`
AccountModels []AgentAccountModel `json:"accountModels"`
}
type AgentBatchUpgradeReq struct {
AgentType string `json:"agentType" validate:"required,oneof=openclaw copaw hermes-agent"`
TargetVersion string `json:"targetVersion" validate:"required"`
Backup bool `json:"backup"`
PullImage bool `json:"pullImage"`
TaskID string `json:"taskID"`
}
type AgentBatchUpgradeResult struct {
AgentID uint `json:"agentID"`
AgentName string `json:"agentName"`
AppInstallID uint `json:"appInstallID"`
Success bool `json:"success"`
Skipped bool `json:"skipped"`
Message string `json:"message"`
}
type AgentBatchSkillInstallReq struct {
AgentType string `json:"agentType" validate:"required,oneof=openclaw hermes-agent"`
SkillName string `json:"skillName" validate:"required"`
PackagePath string `json:"packagePath" validate:"required"`
TaskID string `json:"taskID"`
}
type AgentBatchSkillInstallResult struct {
AgentID uint `json:"agentID"`
AgentName string `json:"agentName"`
AppInstallID uint `json:"appInstallID"`
Success bool `json:"success"`
Skipped bool `json:"skipped"`
Message string `json:"message"`
}
type AgentBatchOperateReq struct {
AgentType string `json:"agentType" validate:"required,oneof=openclaw copaw hermes-agent"`
Operate string `json:"operate" validate:"required,oneof=start stop restart delete"`
ForceDelete bool `json:"forceDelete"`
TaskID string `json:"taskID"`
}
type AgentBatchOperateResult struct {
AgentID uint `json:"agentID"`
AgentName string `json:"agentName"`
AppInstallID uint `json:"appInstallID"`
Success bool `json:"success"`
Skipped bool `json:"skipped"`
Message string `json:"message"`
}
type AgentItem struct {
ID uint `json:"id"`
Name string `json:"name"`
@@ -274,19 +352,24 @@ type AgentAccountSearch struct {
Name string `json:"name"`
}
type AgentAccountProviderCountReq struct {
Providers []string `json:"providers"`
}
type AgentAccountInfo struct {
ID uint `json:"id"`
Provider string `json:"provider"`
ProviderName string `json:"providerName"`
Name string `json:"name"`
APIKey string `json:"apiKey"`
RememberAPIKey bool `json:"rememberApiKey"`
BaseURL string `json:"baseUrl"`
Models []AgentAccountModel `json:"models"`
APIType string `json:"apiType"`
Verified bool `json:"verified"`
Remark string `json:"remark"`
CreatedAt time.Time `json:"createdAt"`
ID uint `json:"id"`
MasterAccountID uint `json:"masterAccountId"`
Provider string `json:"provider"`
ProviderName string `json:"providerName"`
Name string `json:"name"`
APIKey string `json:"apiKey"`
RememberAPIKey bool `json:"rememberApiKey"`
BaseURL string `json:"baseUrl"`
Models []AgentAccountModel `json:"models"`
APIType string `json:"apiType"`
Verified bool `json:"verified"`
Remark string `json:"remark"`
CreatedAt time.Time `json:"createdAt"`
}
type ProviderModelInfo struct {
@@ -604,7 +687,7 @@ type AgentConfigFile struct {
type AgentSkillSearchReq struct {
AgentID uint `json:"agentId" validate:"required"`
Source string `json:"source" validate:"required,oneof=clawhub-global clawhub-cn skillhub official skills-sh"`
Source string `json:"source" validate:"required,oneof=clawhub-global clawhub-cn skillhub official skills-sh local-hub"`
Keyword string `json:"keyword" validate:"required"`
}
@@ -641,7 +724,7 @@ type AgentSkillUpdateReq struct {
type AgentSkillInstallReq struct {
AgentID uint `json:"agentId" validate:"required"`
Source string `json:"source" validate:"required,oneof=clawhub-global clawhub-cn skillhub official skills-sh"`
Source string `json:"source" validate:"required,oneof=clawhub-global clawhub-cn skillhub official skills-sh local-hub"`
Slug string `json:"slug" validate:"required"`
TaskID string `json:"taskID" validate:"required"`
}
+19 -6
View File
@@ -2,8 +2,9 @@ package dto
import (
"encoding/json"
"github.com/1Panel-dev/1Panel/agent/app/model"
"time"
"github.com/1Panel-dev/1Panel/agent/app/model"
)
type CreateOrUpdateAlert struct {
@@ -35,6 +36,15 @@ type AlertSearch struct {
Method string `json:"method"`
}
type AlertConfigQuery struct {
ExcludeTypes []string `json:"excludeTypes"`
}
type AlertConfigPageReq struct {
PageInfo
ExcludeTypes []string `json:"excludeTypes"`
}
type AlertDTO struct {
ID uint `json:"id"`
Type string `json:"type"`
@@ -46,6 +56,8 @@ type AlertDTO struct {
Status string `json:"status"`
SendCount uint `json:"sendCount"`
AdvancedParams string `json:"advancedParams"`
CreateUser string `json:"createUser"`
UpdateUser string `json:"updateUser"`
CreatedAt time.Time `json:"createdAt"`
UpdatedAt time.Time `json:"updatedAt"`
}
@@ -281,11 +293,12 @@ type OfflineQueryRequest struct {
}
type AlertConfigUpdate struct {
ID uint `json:"id"`
Type string `json:"type"`
Title string `json:"title"`
Status string `json:"status"`
Config string `json:"config"`
ID uint `json:"id"`
Type string `json:"type"`
Title string `json:"title"`
Status string `json:"status"`
Config string `json:"config"`
DisplayName string `json:"displayName"`
}
type AlertConfigTest struct {
+9 -1
View File
@@ -121,6 +121,7 @@ type FileWget struct {
Path string `json:"path" validate:"required"`
Name string `json:"name" validate:"required"`
IgnoreCertificate bool `json:"ignoreCertificate"`
UseProxy bool `json:"useProxy"`
}
type FileMove struct {
@@ -162,13 +163,20 @@ type FileRoleUpdate struct {
type FileReadByLineReq struct {
Page int `json:"page" validate:"required"`
PageSize int `json:"pageSize" validate:"required"`
Type string `json:"type" validate:"required"`
Type string `json:"type"`
ID uint `json:"ID"`
Name string `json:"name"`
Latest bool `json:"latest"`
TaskReq
}
type TaskLogReadReq struct {
Page int `json:"page" validate:"required,min=1"`
PageSize int `json:"pageSize" validate:"required,min=1"`
Latest bool `json:"latest"`
TaskReq
}
type TaskReq struct {
TaskID string `json:"taskID"`
TaskType string `json:"taskType"`
+19 -8
View File
@@ -1,8 +1,12 @@
package request
type HostToolReq struct {
type HostToolTypeReq struct {
Type string `json:"type" validate:"required,oneof=supervisord"`
}
type HostToolOperateReq struct {
Type string `json:"type" validate:"required,oneof=supervisord"`
Operate string `json:"operate" validate:"oneof=status restart start stop"`
Operate string `json:"operate" validate:"required,oneof=restart start stop"`
}
type HostToolCreate struct {
@@ -15,13 +19,8 @@ type SupervisorConfig struct {
ServiceName string `json:"serviceName"`
}
type HostToolLogReq struct {
Type string `json:"type" validate:"required,oneof=supervisord"`
}
type HostToolConfig struct {
type HostToolConfigUpdate struct {
Type string `json:"type" validate:"required,oneof=supervisord"`
Operate string `json:"operate" validate:"oneof=get set"`
Content string `json:"content"`
}
@@ -43,3 +42,15 @@ type SupervisorProcessFileReq struct {
Content string `json:"content"`
File string `json:"file" validate:"required,oneof=out.log err.log config"`
}
type HostSupervisorProcessFileGetReq struct {
Name string `json:"name" validate:"required"`
File string `json:"file" validate:"required,oneof=out.log err.log config"`
}
type HostSupervisorProcessFileOperateReq struct {
Name string `json:"name" validate:"required"`
Operate string `json:"operate" validate:"required,oneof=clear update"`
Content string `json:"content"`
File string `json:"file" validate:"required,oneof=out.log err.log config"`
}
+7 -2
View File
@@ -223,9 +223,14 @@ type WebsiteNginxUpdate struct {
}
type WebsiteLogReq struct {
ID uint `json:"id" validate:"required"`
Operate string `json:"operate" validate:"required,oneof=enable disable delete"`
LogType string `json:"logType" validate:"required,oneof=access.log error.log"`
}
type WebsiteLogSearchReq struct {
ID uint `json:"id" validate:"required"`
Operate string `json:"operate" validate:"required"`
LogType string `json:"logType" validate:"required"`
LogType string `json:"logType" validate:"required,oneof=access.log error.log"`
Page int `json:"page"`
PageSize int `json:"pageSize"`
}
+4 -4
View File
@@ -6,7 +6,7 @@ type WebsiteSSLSearch struct {
dto.PageInfo
AcmeAccountID string `json:"acmeAccountID"`
Domain string `json:"domain"`
OrderBy string `json:"orderBy" validate:"omitempty,oneof=created_at expire_date"`
OrderBy string `json:"orderBy" validate:"omitempty,oneof=created_at updated_at expire_date"`
Order string `json:"order" validate:"omitempty,oneof=null ascending descending"`
}
@@ -61,7 +61,7 @@ type WebsiteSSLObtain struct {
type WebsiteAcmeAccountCreate struct {
Email string `json:"email" validate:"required"`
Type string `json:"type" validate:"required,oneof=letsencrypt zerossl buypass google custom"`
KeyType string `json:"keyType" validate:"required,oneof=P256 P384 2048 3072 4096 8192"`
KeyType string `json:"keyType" validate:"required,oneof=EC256 EC384 RSA2048 RSA3072 RSA4096 RSA8192"`
EabKid string `json:"eabKid"`
EabHmacKey string `json:"eabHmacKey"`
UseProxy bool `json:"useProxy"`
@@ -138,7 +138,7 @@ type WebsiteCACreate struct {
Organization string `json:"organization" validate:"required"`
OrganizationUint string `json:"organizationUint"`
Name string `json:"name" validate:"required"`
KeyType string `json:"keyType" validate:"required,oneof=P256 P384 2048 3072 4096 8192"`
KeyType string `json:"keyType" validate:"required,oneof=EC256 EC384 RSA2048 RSA3072 RSA4096 RSA8192"`
Province string `json:"province" `
City string `json:"city"`
}
@@ -146,7 +146,7 @@ type WebsiteCACreate struct {
type WebsiteCAObtain struct {
ID uint `json:"id" validate:"required"`
Domains string `json:"domains" validate:"required"`
KeyType string `json:"keyType" validate:"required,oneof=P256 P384 2048 3072 4096 8192"`
KeyType string `json:"keyType" validate:"required,oneof=EC256 EC384 RSA2048 RSA3072 RSA4096 RSA8192"`
Time int `json:"time" validate:"required"`
Unit string `json:"unit" validate:"required"`
PushDir bool `json:"pushDir"`
+9 -1
View File
@@ -23,7 +23,10 @@ type SettingInfo struct {
AppStoreLastModified string `json:"appStoreLastModified"`
AppStoreSyncStatus string `json:"appStoreSyncStatus"`
FileRecycleBin string `json:"fileRecycleBin"`
FileRecycleBin string `json:"fileRecycleBin"`
LocalSSHConnShow string `json:"localSSHConnShow"`
FirewallPortWhiteList string `json:"firewallPortWhiteList"`
}
type SettingUpdate struct {
@@ -31,6 +34,11 @@ type SettingUpdate struct {
Value string `json:"value"`
}
type AgentSettingUpdate struct {
Key string `json:"key" validate:"required,oneof=SystemIP DockerSockPath FileRecycleBin FirewallPortWhiteList"`
Value string `json:"value"`
}
type SyncTime struct {
NtpSite string `json:"ntpSite" validate:"required"`
}
+4 -2
View File
@@ -57,8 +57,10 @@ type SSHConfUpdate struct {
}
type SearchSSHLog struct {
PageInfo
Info string `json:"info"`
Status string `json:"Status" validate:"required,oneof=Success Failed All"`
Info string `json:"info"`
Status string `json:"Status" validate:"required,oneof=Success Failed All"`
StartTime time.Time `json:"startTime"`
EndTime time.Time `json:"endTime"`
}
type SSHHistory struct {
+9 -8
View File
@@ -2,14 +2,15 @@ package model
type AgentAccount struct {
BaseModel
Provider string `json:"provider"`
Name string `json:"name"`
APIKey string `json:"apiKey"`
BaseURL string `json:"baseUrl"`
APIType string `json:"apiType"`
RememberAPIKey bool `json:"rememberApiKey"`
Verified bool `json:"verified"`
Remark string `json:"remark"`
Provider string `json:"provider"`
Name string `json:"name"`
APIKey string `json:"apiKey"`
BaseURL string `json:"baseUrl"`
APIType string `json:"apiType"`
RememberAPIKey bool `json:"rememberApiKey"`
Verified bool `json:"verified"`
Remark string `json:"remark"`
MasterAccountID uint `json:"masterAccountId" gorm:"index"`
}
func (AgentAccount) TableName() string {
+11 -7
View File
@@ -9,9 +9,11 @@ type Alert struct {
Count uint `gorm:"type:integer;not null" json:"count"`
Project string `gorm:"type:varchar(64)" json:"project"`
Status string `gorm:"type:varchar(64);not null" json:"status"`
Method string `gorm:"type:varchar(64);not null" json:"method"`
Method string `gorm:"type:text;not null" json:"method"`
SendCount uint `gorm:"type:integer" json:"sendCount"`
AdvancedParams string `gorm:"type:longText" json:"advancedParams"`
CreateUser string `gorm:"type:varchar(256)" json:"createUser"`
UpdateUser string `gorm:"type:varchar(256)" json:"updateUser"`
}
type AlertTask struct {
@@ -19,7 +21,7 @@ type AlertTask struct {
Type string `gorm:"type:varchar(64);not null" json:"type"`
Quota string `gorm:"type:varchar(64)" json:"quota"`
QuotaType string `gorm:"type:varchar(64)" json:"quotaType"`
Method string `gorm:"type:varchar(64);not null;default:'sms'" json:"method"`
Method string `gorm:"type:varchar(128);not null;default:'sms'" json:"method"`
}
type AlertLog struct {
@@ -34,15 +36,17 @@ type AlertLog struct {
Message string `gorm:"type:varchar(256);" json:"message"`
RecordId uint `gorm:"type:integer;" json:"recordId"`
LicenseId string `gorm:"type:varchar(256);not null;" json:"licenseId" `
Method string `gorm:"type:varchar(64);not null;default:'sms'" json:"method"`
Method string `gorm:"type:varchar(128);not null;default:'sms'" json:"method"`
}
type AlertConfig struct {
BaseModel
Type string `gorm:"type:varchar(64);not null" json:"type"`
Title string `gorm:"type:varchar(64);not null" json:"title"`
Status string `gorm:"type:varchar(64);not null" json:"status"`
Config string `gorm:"type:varchar(256);not null" json:"config"`
Type string `gorm:"type:varchar(64);not null" json:"type"`
Title string `gorm:"type:varchar(64);not null" json:"title"`
Status string `gorm:"type:varchar(64);not null" json:"status"`
Config string `gorm:"type:varchar(256);not null" json:"config"`
CreateUser string `gorm:"type:varchar(256)" json:"createUser"`
UpdateUser string `gorm:"type:varchar(256)" json:"updateUser"`
}
type LoginLog struct {
+1 -1
View File
@@ -8,7 +8,7 @@ type WebsiteAcmeAccount struct {
Type string `gorm:"not null;default:letsencrypt" json:"type"`
EabKid string `json:"eabKid"`
EabHmacKey string `json:"eabHmacKey"`
KeyType string `gorm:"not null;default:2048" json:"keyType"`
KeyType string `gorm:"not null;default:RSA2048" json:"keyType"`
UseProxy bool `gorm:"default:false" json:"useProxy"`
CaDirURL string `json:"caDirURL"`
UseEAB bool `json:"useEAB"`
+1 -1
View File
@@ -5,5 +5,5 @@ type WebsiteCA struct {
CSR string `gorm:"not null;" json:"csr"`
Name string `gorm:"not null;" json:"name"`
PrivateKey string `gorm:"not null" json:"privateKey"`
KeyType string `gorm:"not null;default:2048" json:"keyType"`
KeyType string `gorm:"not null;default:RSA2048" json:"keyType"`
}
+60 -1
View File
@@ -1,16 +1,23 @@
package repo
import "github.com/1Panel-dev/1Panel/agent/app/model"
import (
"strings"
"github.com/1Panel-dev/1Panel/agent/app/model"
"gorm.io/gorm"
)
type AgentAccountRepo struct{}
type IAgentAccountRepo interface {
Page(page, size int, opts ...DBOption) (int64, []model.AgentAccount, error)
GetFirst(opts ...DBOption) (*model.AgentAccount, error)
WithByMasterAccountID(masterID uint) DBOption
Create(account *model.AgentAccount) error
Save(account *model.AgentAccount) error
DeleteByID(id uint) error
List(opts ...DBOption) ([]model.AgentAccount, error)
CountByProviders(providers []string) (map[string]int64, error)
}
func NewIAgentAccountRepo() IAgentAccountRepo {
@@ -34,6 +41,12 @@ func (a AgentAccountRepo) GetFirst(opts ...DBOption) (*model.AgentAccount, error
return &account, nil
}
func (a AgentAccountRepo) WithByMasterAccountID(masterID uint) DBOption {
return func(g *gorm.DB) *gorm.DB {
return g.Where("master_account_id = ?", masterID)
}
}
func (a AgentAccountRepo) Create(account *model.AgentAccount) error {
return getDb().Create(account).Error
}
@@ -53,3 +66,49 @@ func (a AgentAccountRepo) List(opts ...DBOption) ([]model.AgentAccount, error) {
}
return accounts, nil
}
func (a AgentAccountRepo) CountByProviders(providers []string) (map[string]int64, error) {
normalizedProviders := normalizeProviders(providers)
counts := make(map[string]int64, len(normalizedProviders))
for _, provider := range normalizedProviders {
counts[provider] = 0
}
if len(normalizedProviders) == 0 {
return counts, nil
}
type providerCount struct {
Provider string
Count int64
}
var rows []providerCount
if err := getDb().
Model(&model.AgentAccount{}).
Select("provider, COUNT(*) as count").
Where("provider IN ?", normalizedProviders).
Group("provider").
Scan(&rows).Error; err != nil {
return nil, err
}
for _, row := range rows {
counts[row.Provider] = row.Count
}
return counts, nil
}
func normalizeProviders(providers []string) []string {
seen := make(map[string]struct{}, len(providers))
result := make([]string, 0, len(providers))
for _, provider := range providers {
provider = strings.TrimSpace(provider)
if provider == "" {
continue
}
if _, ok := seen[provider]; ok {
continue
}
seen[provider] = struct{}{}
result = append(result, provider)
}
return result
}
+235 -14
View File
@@ -1,11 +1,15 @@
package repo
import (
"encoding/json"
"strings"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
"google.golang.org/genproto/googleapis/type/date"
"gorm.io/gorm"
"strconv"
"time"
)
@@ -20,7 +24,8 @@ type IAlertRepo interface {
WithByCreateAt(date *date.Date) DBOption
WithByLicenseId(licenseId string) DBOption
WithByRecordId(recordId uint) DBOption
WithByMethod(method string) DBOption
WithByAlertMethodContainsConfigID(id uint) DBOption
WithByMethodConfigIDs(ids []uint) DBOption
Create(alert *model.Alert) error
Get(opts ...DBOption) (model.Alert, error)
@@ -47,11 +52,15 @@ type IAlertRepo interface {
GetLicensePushCount(method string) (uint, error)
GetConfig(opts ...DBOption) (model.AlertConfig, error)
GetConfigById(id uint) (model.AlertConfig, error)
AlertConfigList(opts ...DBOption) ([]model.AlertConfig, error)
UpdateAlertConfig(maps map[string]interface{}, opts ...DBOption) error
CreateAlertConfig(config *model.AlertConfig) error
DeleteAlertConfig(opts ...DBOption) error
WithByTypeNotIn(types []string) DBOption
PageAlertConfig(page, size int, opts ...DBOption) (int64, []model.AlertConfig, error)
SyncAll(data []model.AlertConfig) error
}
@@ -101,9 +110,20 @@ func (a *AlertRepo) WithByRecordId(recordId uint) DBOption {
}
}
func (a *AlertRepo) WithByMethod(method string) DBOption {
func (a *AlertRepo) WithByAlertMethodContainsConfigID(id uint) DBOption {
method := strconv.Itoa(int(id))
return func(g *gorm.DB) *gorm.DB {
return g.Where("method = ?", method)
return g.Where("(method = ? OR method LIKE ? OR method LIKE ? OR method LIKE ?)", method, method+",%", "%,"+method, "%,"+method+",%")
}
}
func (a *AlertRepo) WithByMethodConfigIDs(ids []uint) DBOption {
return func(g *gorm.DB) *gorm.DB {
methods := make([]string, 0, len(ids))
for _, id := range ids {
methods = append(methods, strconv.Itoa(int(id)))
}
return g.Where("method IN ?", methods)
}
}
@@ -306,32 +326,233 @@ func (a *AlertRepo) GetConfig(opts ...DBOption) (model.AlertConfig, error) {
return alertConfig, err
}
func (a *AlertRepo) GetConfigById(id uint) (model.AlertConfig, error) {
var config model.AlertConfig
err := global.AlertDB.First(&config, id).Error
return config, err
}
func (a *AlertRepo) WithByTypeNotIn(types []string) DBOption {
return func(g *gorm.DB) *gorm.DB {
return g.Where("`type` NOT IN (?)", types)
}
}
func (a *AlertRepo) PageAlertConfig(page, size int, opts ...DBOption) (int64, []model.AlertConfig, error) {
var configs []model.AlertConfig
db := global.AlertDB.Model(&model.AlertConfig{})
for _, opt := range opts {
db = opt(db)
}
count := int64(0)
db = db.Count(&count)
err := db.Limit(size).Offset(size * (page - 1)).Find(&configs).Error
return count, configs, err
}
var singletonTypes = map[string]bool{
constant.CommonConfig: true,
}
func (a *AlertRepo) SyncAll(data []model.AlertConfig) error {
tx := global.AlertDB.Begin()
if tx.Error != nil {
return tx.Error
}
defer func() {
if r := recover(); r != nil {
tx.Rollback()
panic(r)
}
}()
var oldConfigs []model.AlertConfig
_ = tx.Find(&oldConfigs).Error
if err := tx.Find(&oldConfigs).Error; err != nil {
tx.Rollback()
return err
}
usedConfigIDs, err := loadUsedAlertConfigIDs(tx)
if err != nil {
tx.Rollback()
return err
}
oldConfigMap := make(map[string]uint)
oldConfigByType := make(map[string][]model.AlertConfig)
oldConfigByKey := make(map[string][]model.AlertConfig)
consumedConfigIDs := make(map[uint]struct{})
for _, item := range oldConfigs {
oldConfigMap[item.Type] = item.ID
if singletonTypes[item.Type] {
oldConfigMap[item.Type] = item.ID
continue
}
oldConfigByType[item.Type] = append(oldConfigByType[item.Type], item)
oldConfigByKey[alertConfigSyncKey(item)] = append(oldConfigByKey[alertConfigSyncKey(item)], item)
}
for _, item := range data {
if val, ok := oldConfigMap[item.Type]; ok {
item.ID = val
delete(oldConfigMap, item.Type)
} else {
item.ID = 0
if singletonTypes[item.Type] {
if val, ok := oldConfigMap[item.Type]; ok {
item.ID = val
delete(oldConfigMap, item.Type)
consumedConfigIDs[item.ID] = struct{}{}
} else {
item.ID = 0
}
if item.ID == 0 {
if err := tx.Create(&item).Error; err != nil {
tx.Rollback()
return err
}
} else if err := tx.Save(&item).Error; err != nil {
tx.Rollback()
return err
}
continue
}
if err := tx.Model(model.AlertConfig{}).Where("id = ?", item.ID).Save(&item).Error; err != nil {
key := alertConfigSyncKey(item)
if matched, ok := popAlertConfigByKey(oldConfigByKey, key); ok {
item.ID = matched.ID
consumedConfigIDs[item.ID] = struct{}{}
if err := tx.Save(&item).Error; err != nil {
tx.Rollback()
return err
}
deleteAlertConfigByID(oldConfigByType, matched.ID)
continue
}
if matched, ok := popUnusedAlertConfigByType(oldConfigByType, usedConfigIDs, item.Type); ok {
item.ID = matched.ID
consumedConfigIDs[item.ID] = struct{}{}
if err := tx.Save(&item).Error; err != nil {
tx.Rollback()
return err
}
continue
}
item.ID = 0
if err := tx.Create(&item).Error; err != nil {
tx.Rollback()
return err
}
}
for _, val := range oldConfigMap {
if err := tx.Where("id = ?", val).Delete(&model.AlertConfig{}).Error; err != nil {
for _, item := range oldConfigs {
if _, used := usedConfigIDs[item.ID]; used {
continue
}
if _, kept := consumedConfigIDs[item.ID]; kept {
continue
}
if err := tx.Where("id = ?", item.ID).Delete(&model.AlertConfig{}).Error; err != nil {
tx.Rollback()
return err
}
}
tx.Commit()
if err := tx.Commit().Error; err != nil {
tx.Rollback()
return err
}
return nil
}
func loadUsedAlertConfigIDs(tx *gorm.DB) (map[uint]struct{}, error) {
var alerts []model.Alert
if err := tx.Select("method").Find(&alerts).Error; err != nil {
return nil, err
}
usedIDs := make(map[uint]struct{})
for _, alert := range alerts {
for _, item := range strings.Split(alert.Method, ",") {
item = strings.TrimSpace(item)
if item == "" {
continue
}
id, err := strconv.ParseUint(item, 10, 64)
if err != nil {
continue
}
usedIDs[uint(id)] = struct{}{}
}
}
return usedIDs, nil
}
func alertConfigSyncKey(item model.AlertConfig) string {
return item.Type + "::" + normalizeAlertConfigJSON(item.Config)
}
func normalizeAlertConfigJSON(config string) string {
trimmed := strings.TrimSpace(config)
if trimmed == "" {
return ""
}
var data any
if err := json.Unmarshal([]byte(trimmed), &data); err != nil {
return trimmed
}
buf, err := json.Marshal(data)
if err != nil {
return trimmed
}
return string(buf)
}
func popAlertConfigByKey(configMap map[string][]model.AlertConfig, key string) (model.AlertConfig, bool) {
items := configMap[key]
if len(items) == 0 {
return model.AlertConfig{}, false
}
item := items[0]
if len(items) == 1 {
delete(configMap, key)
} else {
configMap[key] = items[1:]
}
return item, true
}
func popUnusedAlertConfigByType(configMap map[string][]model.AlertConfig, usedConfigIDs map[uint]struct{}, configType string) (model.AlertConfig, bool) {
items := configMap[configType]
if len(items) == 0 {
return model.AlertConfig{}, false
}
for idx, item := range items {
if _, used := usedConfigIDs[item.ID]; used {
continue
}
if idx == 0 {
if len(items) == 1 {
delete(configMap, configType)
} else {
configMap[configType] = items[1:]
}
} else {
configMap[configType] = append(items[:idx], items[idx+1:]...)
}
return item, true
}
return model.AlertConfig{}, false
}
func deleteAlertConfigByID(configMap map[string][]model.AlertConfig, id uint) {
for key, items := range configMap {
for idx, item := range items {
if item.ID != id {
continue
}
if len(items) == 1 {
delete(configMap, key)
} else {
configMap[key] = append(items[:idx], items[idx+1:]...)
}
return
}
}
}
+20 -6
View File
@@ -2,8 +2,10 @@ package repo
import (
"context"
"time"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/constant"
"gorm.io/gorm"
)
@@ -21,6 +23,7 @@ type ISSLRepo interface {
Page(page, size int, opts ...DBOption) (int64, []model.WebsiteSSL, error)
GetFirst(opts ...DBOption) (*model.WebsiteSSL, error)
List(opts ...DBOption) ([]model.WebsiteSSL, error)
TryMarkApplying(id uint) (bool, error)
Create(ctx context.Context, ssl *model.WebsiteSSL) error
Save(ssl *model.WebsiteSSL) error
DeleteBy(opts ...DBOption) error
@@ -76,12 +79,12 @@ func (w WebsiteSSLRepo) Page(page, size int, opts ...DBOption) (int64, []model.W
}
func (w WebsiteSSLRepo) GetFirst(opts ...DBOption) (*model.WebsiteSSL, error) {
var website *model.WebsiteSSL
var website model.WebsiteSSL
db := getDb(opts...).Model(&model.WebsiteSSL{})
if err := db.Preload("AcmeAccount").Preload("DnsAccount").First(&website).Error; err != nil {
return website, err
return nil, err
}
return website, nil
return &website, nil
}
func (w WebsiteSSLRepo) List(opts ...DBOption) ([]model.WebsiteSSL, error) {
@@ -93,14 +96,25 @@ func (w WebsiteSSLRepo) List(opts ...DBOption) ([]model.WebsiteSSL, error) {
return websites, nil
}
func (w WebsiteSSLRepo) TryMarkApplying(id uint) (bool, error) {
db := getDb().Model(&model.WebsiteSSL{}).
Where("id = ? AND status <> ?", id, constant.SSLApply).
Updates(map[string]interface{}{
"status": constant.SSLApply,
"updated_at": time.Now(),
})
if db.Error != nil {
return false, db.Error
}
return db.RowsAffected > 0, nil
}
func (w WebsiteSSLRepo) Create(ctx context.Context, ssl *model.WebsiteSSL) error {
return getTx(ctx).Create(ssl).Error
}
func (w WebsiteSSLRepo) Save(ssl *model.WebsiteSSL) error {
return getDb().Model(&model.WebsiteSSL{BaseModel: model.BaseModel{
ID: ssl.ID,
}}).Save(&ssl).Error
return getDb().Save(ssl).Error
}
func (w WebsiteSSLRepo) SaveByMap(ssl *model.WebsiteSSL, params map[string]interface{}) error {
+462 -15
View File
@@ -3,6 +3,7 @@ package service
import (
"context"
"encoding/json"
"errors"
"fmt"
"os"
"path"
@@ -16,6 +17,7 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/model"
providercatalog "github.com/1Panel-dev/1Panel/agent/app/provider"
"github.com/1Panel-dev/1Panel/agent/app/repo"
"github.com/1Panel-dev/1Panel/agent/app/task"
"github.com/1Panel-dev/1Panel/agent/buserr"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
@@ -30,6 +32,10 @@ import (
type IAgentService interface {
Create(req dto.AgentCreateReq) (*dto.AgentItem, error)
BatchInstall(req dto.AgentBatchInstallReq) (*dto.AgentItem, error)
BatchUpgrade(req dto.AgentBatchUpgradeReq) ([]dto.AgentBatchUpgradeResult, error)
BatchInstallSkill(req dto.AgentBatchSkillInstallReq) ([]dto.AgentBatchSkillInstallResult, error)
BatchOperate(req dto.AgentBatchOperateReq) ([]dto.AgentBatchOperateResult, error)
Page(req dto.SearchWithPage) (int64, []dto.AgentItem, error)
DeleteCheck(req dto.AgentIDReq) ([]dto.AppResource, error)
Delete(req dto.AgentDeleteReq) error
@@ -69,6 +75,7 @@ type IAgentService interface {
UpdateAccount(req dto.AgentAccountUpdateReq) error
SyncAgentsByAccount(account *model.AgentAccount) error
PageAccounts(req dto.AgentAccountSearch) (int64, []dto.AgentAccountInfo, error)
CountAccountsByProviders(req dto.AgentAccountProviderCountReq) (map[string]int64, error)
GetAccountModels(req dto.AgentAccountModelReq) ([]dto.AgentAccountModel, error)
CreateAccountModel(req dto.AgentAccountModelCreateReq) error
UpdateAccountModel(req dto.AgentAccountModelUpdateReq) error
@@ -98,6 +105,16 @@ type IAgentService interface {
ApproveChannelPairing(req dto.AgentChannelPairingApproveReq) error
}
type batchUpgradePlan struct {
ctx batchAgentInstallContext
req request.AppInstallUpgrade
}
type batchAgentInstallContext struct {
agent model.Agent
install model.AppInstall
}
const (
defaultBrowserExecutablePath = "/home/node/.cache/ms-playwright/openclaw-browser"
defaultBrowserProfile = "openclaw"
@@ -127,7 +144,7 @@ func (a AgentService) Create(req dto.AgentCreateReq) (*dto.AgentItem, error) {
if installs, _ := appInstallRepo.ListBy(context.Background(), repo.WithByLowerName(req.Name)); len(installs) > 0 {
return nil, buserr.New("ErrNameIsExist")
}
if !xpack.IsXpack() {
if !xpack.MultiNodeProvider.IsXpack() {
count, _, err := agentRepo.Page(1, 1)
if err != nil {
return nil, err
@@ -290,6 +307,431 @@ func (a AgentService) Create(req dto.AgentCreateReq) (*dto.AgentItem, error) {
return &item, nil
}
func (a AgentService) BatchInstall(req dto.AgentBatchInstallReq) (*dto.AgentItem, error) {
accountID, err := a.ensureBatchInstallAccount(req)
if err != nil {
return nil, err
}
createReq := buildCreateReqFromBatchInstallReq(req)
createReq.AccountID = accountID
if strings.TrimSpace(createReq.Name) == "" {
name, err := buildBatchInstallAgentName(createReq.AgentType)
if err != nil {
return nil, err
}
createReq.Name = name
}
if createReq.AgentType == constant.AppOpenclaw && len(createReq.AllowedOrigins) == 0 {
allowedOrigin, err := buildBatchInstallOpenclawAllowedOrigin(req)
if err != nil {
return nil, err
}
createReq.AllowedOrigins = []string{allowedOrigin}
}
return a.Create(createReq)
}
func (a AgentService) BatchUpgrade(req dto.AgentBatchUpgradeReq) ([]dto.AgentBatchUpgradeResult, error) {
plans, results, err := buildBatchUpgradePlans(req)
if err != nil {
return nil, err
}
for _, plan := range plans {
result := dto.AgentBatchUpgradeResult{
AgentID: plan.ctx.agent.ID,
AgentName: plan.ctx.agent.Name,
AppInstallID: plan.ctx.agent.AppInstallID,
}
if err := upgradeInstall(plan.req); err != nil {
result.Message = err.Error()
} else {
result.Success = true
}
results = append(results, result)
}
return results, nil
}
func (a AgentService) BatchInstallSkill(req dto.AgentBatchSkillInstallReq) ([]dto.AgentBatchSkillInstallResult, error) {
if req.AgentType != constant.AppOpenclaw && req.AgentType != constant.AppHermesAgent {
return nil, fmt.Errorf("%s does not support skill batch install", req.AgentType)
}
packagePath, err := validateLocalSkillPackagePath(req.PackagePath)
if err != nil {
return nil, err
}
if format, err := localSkillPackageFormat(packagePath); err != nil {
return nil, err
} else if format != "zip" {
return nil, fmt.Errorf("only .zip skill packages can be installed")
}
skillName := sanitizeLocalSkillDirName(req.SkillName, packagePath, req.SkillName)
agents, err := listBatchAgents(req.AgentType)
if err != nil {
return nil, err
}
results := make([]dto.AgentBatchSkillInstallResult, 0, len(agents))
for _, agent := range agents {
result := dto.AgentBatchSkillInstallResult{
AgentID: agent.ID,
AgentName: agent.Name,
AppInstallID: agent.AppInstallID,
}
ctx, message := loadBatchAgentInstall(agent, req.AgentType)
if message != "" {
result.Message = message
results = append(results, result)
continue
}
install := ctx.install
result.AppInstallID = install.ID
if install.Status == constant.StatusInstalling || install.Status == constant.StatusUpgrading {
result.Message = fmt.Sprintf("agent status is %s", install.Status)
results = append(results, result)
continue
}
if err := ensureContainerRunning(install.ContainerName); err != nil {
result.Message = err.Error()
results = append(results, result)
continue
}
installTask, err := task.NewTaskWithOps(skillName, task.TaskInstall, task.TaskScopeAI, buildBatchSkillInstallTaskID(req.TaskID, agent.ID), agent.ID)
if err != nil {
result.Message = err.Error()
results = append(results, result)
continue
}
currentAgent := ctx.agent
currentInstall := ctx.install
installTask.AddSubTask("Install local skill", func(t *task.Task) error {
mgr := cmd.NewCommandMgr(cmd.WithTask(*t), cmd.WithContext(t.TaskCtx), cmd.WithTimeout(20*time.Minute))
return installLocalSkillPackage(mgr, currentInstall.ContainerName, currentAgent.AgentType, currentAgent.ConfigPath, packagePath, skillName)
}, nil)
go func() {
if err := installTask.Execute(); err != nil {
global.LOG.Errorf("batch install local skill failed: %v", err)
}
}()
result.Success = true
results = append(results, result)
}
return results, nil
}
func (a AgentService) BatchOperate(req dto.AgentBatchOperateReq) ([]dto.AgentBatchOperateResult, error) {
operate := constant.AppOperate(strings.TrimSpace(req.Operate))
if operate != constant.Start && operate != constant.Stop && operate != constant.Restart && operate != constant.Delete {
return nil, fmt.Errorf("operate %s is not supported", req.Operate)
}
agents, err := listBatchAgents(req.AgentType)
if err != nil {
return nil, err
}
results := make([]dto.AgentBatchOperateResult, 0, len(agents))
for _, agent := range agents {
result := dto.AgentBatchOperateResult{
AgentID: agent.ID,
AgentName: agent.Name,
AppInstallID: agent.AppInstallID,
}
if operate == constant.Delete {
if err := a.Delete(dto.AgentDeleteReq{
ID: agent.ID,
TaskID: buildBatchOperateTaskID(req.TaskID, agent.ID),
ForceDelete: req.ForceDelete,
}); err != nil {
result.Message = err.Error()
} else {
result.Success = true
}
results = append(results, result)
continue
}
ctx, message := loadBatchAgentInstall(agent, req.AgentType)
if message != "" {
result.Message = message
results = append(results, result)
continue
}
install := ctx.install
result.AppInstallID = install.ID
if message := batchOperateSkipMessage(operate, install.Status); message != "" {
result.Success = true
result.Skipped = true
result.Message = message
results = append(results, result)
continue
}
if err := NewIAppInstalledService().Operate(request.AppInstalledOperate{
InstallId: install.ID,
Operate: operate,
TaskID: buildBatchOperateTaskID(req.TaskID, agent.ID),
}); err != nil {
result.Message = err.Error()
} else {
result.Success = true
}
results = append(results, result)
}
return results, nil
}
func listBatchAgents(agentType string) ([]model.Agent, error) {
return agentRepo.List(func(db *gorm.DB) *gorm.DB {
return db.Where("agent_type = ?", agentType).Order("id ASC")
})
}
func loadBatchAgentInstall(agent model.Agent, agentType string) (batchAgentInstallContext, string) {
ctx := batchAgentInstallContext{agent: agent}
if agent.AppInstallID == 0 {
return ctx, "agent app install id is empty"
}
install, err := appInstallRepo.GetFirst(repo.WithByID(agent.AppInstallID))
if err != nil {
return ctx, err.Error()
}
ctx.install = install
if install.App.Key != agentType {
return ctx, fmt.Sprintf("app key %s does not match agent type %s", install.App.Key, agentType)
}
return ctx, ""
}
func buildBatchUpgradePlans(req dto.AgentBatchUpgradeReq) ([]batchUpgradePlan, []dto.AgentBatchUpgradeResult, error) {
agents, err := listBatchAgents(req.AgentType)
if err != nil {
return nil, nil, err
}
plans := make([]batchUpgradePlan, 0, len(agents))
results := make([]dto.AgentBatchUpgradeResult, 0)
for _, agent := range agents {
result := dto.AgentBatchUpgradeResult{
AgentID: agent.ID,
AgentName: agent.Name,
AppInstallID: agent.AppInstallID,
}
ctx, message := loadBatchAgentInstall(agent, req.AgentType)
if message != "" {
result.Message = message
results = append(results, result)
continue
}
install := ctx.install
result.AppInstallID = install.ID
if install.Status == constant.StatusInstalling || install.Status == constant.StatusUpgrading {
result.Message = fmt.Sprintf("agent status is %s", install.Status)
results = append(results, result)
continue
}
if install.Version == req.TargetVersion {
result.Success = true
result.Skipped = true
result.Message = "already target version"
results = append(results, result)
continue
}
detail, err := appDetailRepo.GetFirst(appDetailRepo.WithAppId(install.AppId), appDetailRepo.WithVersion(req.TargetVersion))
if err != nil {
result.Message = err.Error()
results = append(results, result)
continue
}
if detail.ID == 0 {
result.Message = fmt.Sprintf("target version %s not found", req.TargetVersion)
results = append(results, result)
continue
}
plans = append(plans, batchUpgradePlan{
ctx: ctx,
req: request.AppInstallUpgrade{
InstallID: install.ID,
DetailID: detail.ID,
Backup: req.Backup,
PullImage: req.PullImage,
TaskID: buildBatchUpgradeTaskID(req.TaskID, install.ID),
},
})
}
return plans, results, nil
}
func buildBatchUpgradeTaskID(taskID string, appInstallID uint) string {
taskID = strings.TrimSpace(taskID)
if taskID == "" {
taskID = fmt.Sprintf("batch-upgrade-%d-%d", appInstallID, time.Now().UnixNano())
}
return fmt.Sprintf("%s-%d", taskID, appInstallID)
}
func buildBatchSkillInstallTaskID(taskID string, agentID uint) string {
taskID = strings.TrimSpace(taskID)
if taskID == "" {
taskID = fmt.Sprintf("batch-skill-install-%d-%d", agentID, time.Now().UnixNano())
}
return fmt.Sprintf("%s-%d", taskID, agentID)
}
func buildBatchOperateTaskID(taskID string, agentID uint) string {
taskID = strings.TrimSpace(taskID)
if taskID == "" {
taskID = fmt.Sprintf("batch-operate-%d-%d", agentID, time.Now().UnixNano())
}
return fmt.Sprintf("%s-%d", taskID, agentID)
}
func batchOperateSkipMessage(operate constant.AppOperate, status string) string {
switch status {
case constant.StatusInstalling, constant.StatusUpgrading, constant.StatusUninstalling, constant.StatusRebuilding:
return fmt.Sprintf("agent status is %s", status)
}
switch operate {
case constant.Start:
if status == constant.StatusRunning || status == constant.StatusStarting || status == constant.StatusRestarting {
return fmt.Sprintf("agent status is %s", status)
}
case constant.Stop:
if status != constant.StatusRunning {
return fmt.Sprintf("agent status is %s", status)
}
case constant.Restart:
if status == constant.StatusStarting {
return fmt.Sprintf("agent status is %s", status)
}
}
return ""
}
func buildCreateReqFromBatchInstallReq(req dto.AgentBatchInstallReq) dto.AgentCreateReq {
return dto.AgentCreateReq{
Name: req.Name,
Remark: req.Remark,
AppVersion: req.AppVersion,
WebUIPort: req.WebUIPort,
BridgePort: req.BridgePort,
AllowedOrigins: req.AllowedOrigins,
AgentType: req.AgentType,
Model: req.Model,
AccountID: req.AccountID,
Token: req.Token,
TaskID: req.TaskID,
Advanced: req.Advanced,
ContainerName: req.ContainerName,
AllowPort: req.AllowPort,
SpecifyIP: req.SpecifyIP,
RestartPolicy: req.RestartPolicy,
CpuQuota: req.CpuQuota,
MemoryLimit: req.MemoryLimit,
MemoryUnit: req.MemoryUnit,
PullImage: req.PullImage,
EditCompose: req.EditCompose,
DockerCompose: req.DockerCompose,
}
}
func buildBatchInstallAgentName(agentType string) (string, error) {
prefix := strings.ToLower(strings.TrimSpace(agentType))
if prefix == "" {
prefix = "agent"
}
for i := 1; i <= 10000; i++ {
name := fmt.Sprintf("%s-%d", prefix, i)
exists, err := agentNameExists(name)
if err != nil {
return "", err
}
if !exists {
return name, nil
}
}
return "", fmt.Errorf("no available agent name")
}
func agentNameExists(name string) (bool, error) {
if exist, err := agentRepo.GetFirst(repo.WithByLowerName(name)); err == nil && exist != nil && exist.ID > 0 {
return true, nil
} else if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
return false, err
}
installs, err := appInstallRepo.ListBy(context.Background(), repo.WithByLowerName(name))
if err != nil {
return false, err
}
return len(installs) > 0, nil
}
func buildBatchInstallOpenclawAllowedOrigin(req dto.AgentBatchInstallReq) (string, error) {
host := ""
if value, err := settingRepo.GetValueByKey("SystemIP"); err == nil {
host = strings.TrimSpace(value)
}
if host == "" {
host = strings.TrimSpace(req.FallbackAccessHost)
}
if host == "" {
host = "127.0.0.1"
}
return buildOpenclawAllowedOrigin(openclawAllowedOriginScheme(req.AppVersion), host, req.WebUIPort)
}
func (a AgentService) ensureBatchInstallAccount(req dto.AgentBatchInstallReq) (uint, error) {
if !requiresAgentAccount(req.AgentType) {
return 0, nil
}
if req.MasterAccountID == 0 {
return 0, buserr.New("ErrInvalidParams")
}
snapshot := req.AccountSnapshot
account, err := agentAccountRepo.GetFirst(agentAccountRepo.WithByMasterAccountID(req.MasterAccountID))
if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
return 0, err
}
if account == nil && global.IsMaster {
account, err = agentAccountRepo.GetFirst(repo.WithByID(req.MasterAccountID))
if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
return 0, err
}
}
if account == nil {
account = &model.AgentAccount{
MasterAccountID: req.MasterAccountID,
}
}
account.MasterAccountID = req.MasterAccountID
account.Provider = snapshot.Provider
account.Name = snapshot.Name
account.APIKey = snapshot.APIKey
account.RememberAPIKey = snapshot.RememberAPIKey
account.BaseURL = snapshot.BaseURL
account.APIType = snapshot.APIType
account.Remark = snapshot.Remark
account.Verified = true
initialModels, err := buildInitialAgentAccountModels(account, req.AccountModels)
if err != nil {
return 0, err
}
if err := global.DB.Transaction(func(tx *gorm.DB) error {
if account.ID == 0 {
if err := tx.Create(account).Error; err != nil {
return err
}
} else {
if err := tx.Save(account).Error; err != nil {
return err
}
}
return replacePersistedAgentAccountModelsWithTx(tx, account.ID, initialModels)
}); err != nil {
return 0, err
}
return account.ID, nil
}
func requiresAgentAccount(agentType string) bool {
return agentType != constant.AppCopaw
}
func setAgentWebUIParams(params map[string]interface{}, agentType, appVersion string, webUIPort int) {
if agentType == constant.AppOpenclaw && isOpenclawHTTPSWindowVersion(appVersion) {
params["PANEL_APP_PORT_HTTPS"] = webUIPort
@@ -652,18 +1094,19 @@ func (a AgentService) PageAccounts(req dto.AgentAccountSearch) (int64, []dto.Age
apiKey = item.APIKey
}
items = append(items, dto.AgentAccountInfo{
ID: item.ID,
Provider: item.Provider,
ProviderName: providercatalog.DisplayName(item.Provider),
Name: item.Name,
APIKey: apiKey,
RememberAPIKey: item.RememberAPIKey,
BaseURL: item.BaseURL,
Models: nil,
APIType: item.APIType,
Verified: item.Verified,
Remark: item.Remark,
CreatedAt: item.CreatedAt,
ID: item.ID,
MasterAccountID: item.MasterAccountID,
Provider: item.Provider,
ProviderName: providercatalog.DisplayName(item.Provider),
Name: item.Name,
APIKey: apiKey,
RememberAPIKey: item.RememberAPIKey,
BaseURL: item.BaseURL,
Models: nil,
APIType: item.APIType,
Verified: item.Verified,
Remark: item.Remark,
CreatedAt: item.CreatedAt,
})
}
for i := range items {
@@ -676,6 +1119,10 @@ func (a AgentService) PageAccounts(req dto.AgentAccountSearch) (int64, []dto.Age
return count, items, nil
}
func (a AgentService) CountAccountsByProviders(req dto.AgentAccountProviderCountReq) (map[string]int64, error) {
return agentAccountRepo.CountByProviders(req.Providers)
}
func (a AgentService) GetAccountModels(req dto.AgentAccountModelReq) ([]dto.AgentAccountModel, error) {
account, err := agentAccountRepo.GetFirst(repo.WithByID(req.AccountID))
if err != nil {
@@ -990,7 +1437,7 @@ func validateAgentConfigFileContent(agentType, content string) error {
}
func getOpenclawNPMRegistry(containerName string) (string, error) {
registry, err := runDockerExecWithStdout(20*time.Second, containerName, "npm", "get", "registry")
registry, err := cmd.RunDockerExecWithStdout(20*time.Second, containerName, "npm", "get", "registry")
if err != nil {
return "", err
}
@@ -1002,7 +1449,7 @@ func getOpenclawNPMRegistry(containerName string) (string, error) {
}
func setOpenclawNPMRegistry(containerName, registry string) error {
return cmd.RunDefaultBashCf("docker exec %s npm set registry %q", containerName, registry)
return cmd.NewCommandMgr().Run("docker", "exec", containerName, "npm", "set", "registry", registry)
}
func (a AgentService) loadAgentAndInstall(agentID uint) (*model.Agent, *model.AppInstall, error) {
+5 -11
View File
@@ -23,7 +23,7 @@ func (a AgentService) CreateRole(req dto.AgentRoleCreateReq) (*dto.AgentRoleCrea
return nil, err
}
args := []string{"exec", install.ContainerName, "openclaw", "agents", "add", req.Name}
args := []string{"openclaw", "agents", "add", req.Name}
workspace := "/home/node/.openclaw/workspace-agent_" + req.Name
agentDir := "/home/node/.openclaw/agents/" + req.Name
args = append(args, "--workspace", workspace)
@@ -43,8 +43,7 @@ func (a AgentService) CreateRole(req dto.AgentRoleCreateReq) (*dto.AgentRoleCrea
args = append(args, "--agent-dir", agentDir)
args = append(args, "--non-interactive", "--json")
mgr := cmd.NewCommandMgr(cmd.WithTimeout(5 * time.Minute))
output, err := mgr.RunWithStdout("docker", args...)
output, err := cmd.RunDockerExecWithStdout(5*time.Minute, install.ContainerName, args...)
if err != nil {
return nil, err
}
@@ -125,10 +124,8 @@ func (a AgentService) DeleteRole(req dto.AgentRoleDeleteReq) error {
return buserr.New("ErrRecordNotFound")
}
args := []string{"exec", install.ContainerName, "openclaw", "agents", "delete", req.ID, "--force"}
mgr := cmd.NewCommandMgr(cmd.WithTimeout(5 * time.Minute))
if _, err = mgr.RunWithStdout("docker", args...); err != nil {
args := []string{"openclaw", "agents", "delete", req.ID, "--force"}
if _, err = cmd.RunDockerExecWithStdout(5*time.Minute, install.ContainerName, args...); err != nil {
return err
}
if target.Workspace != "" {
@@ -171,8 +168,6 @@ func (a AgentService) operateRoleBinding(req dto.AgentRoleBindReq, action string
return buserr.New("ErrInvalidParams")
}
args := []string{
"exec",
install.ContainerName,
"openclaw",
"agents",
action,
@@ -182,8 +177,7 @@ func (a AgentService) operateRoleBinding(req dto.AgentRoleBindReq, action string
binding,
}
args = append(args, "--json")
mgr := cmd.NewCommandMgr(cmd.WithTimeout(5 * time.Minute))
_, err = mgr.RunWithStdout("docker", args...)
_, err = cmd.RunDockerExecWithStdout(5*time.Minute, install.ContainerName, args...)
return err
}
+52 -23
View File
@@ -372,14 +372,14 @@ func (a AgentService) InstallPlugin(req dto.AgentPluginInstallReq) error {
mgr := cmd.NewCommandMgr(cmd.WithTask(*t), cmd.WithContext(t.TaskCtx), cmd.WithTimeout(10*time.Minute))
if req.Type == "qqbot" {
legacyPluginPath := path.Join(openclawPluginBaseDir, "qqbot")
if err := mgr.RunBashCf("docker exec %s test -d %s", install.ContainerName, legacyPluginPath); err == nil {
if _, err := mgr.RunWithStdout("docker", "exec", "-i", install.ContainerName, "sh", "-c", buildOpenclawPluginUninstallScript("qqbot")); err != nil {
if err := mgr.Run("docker", "exec", install.ContainerName, "test", "-d", legacyPluginPath); err == nil {
if err := uninstallOpenclawPlugin(mgr, install.ContainerName, "qqbot"); err != nil {
return err
}
time.Sleep(2 * time.Second)
}
}
if _, err := mgr.RunWithStdout("docker", "exec", install.ContainerName, "sh", "-c", buildOpenclawPluginInstallScript(spec, pluginID)); err != nil {
if err := installOpenclawPlugin(mgr, install.ContainerName, spec, pluginID); err != nil {
return err
}
conf, err := readOpenclawConfig(agent.ConfigPath)
@@ -415,11 +415,11 @@ func (a AgentService) UpgradePlugin(req dto.AgentPluginUpgradeReq) error {
}
upgradeTask.AddSubTask("Upgrade OpenClaw plugin", func(t *task.Task) error {
mgr := cmd.NewCommandMgr(cmd.WithTask(*t), cmd.WithContext(t.TaskCtx), cmd.WithTimeout(10*time.Minute))
if _, err := mgr.RunWithStdout("docker", "exec", "-i", install.ContainerName, "sh", "-c", buildOpenclawPluginUninstallScript(pluginID)); err != nil {
if err := uninstallOpenclawPlugin(mgr, install.ContainerName, pluginID); err != nil {
return err
}
time.Sleep(2 * time.Second)
if _, err := mgr.RunWithStdout("docker", "exec", install.ContainerName, "sh", "-c", buildOpenclawPluginInstallScript(spec, pluginID)); err != nil {
if err := installOpenclawPlugin(mgr, install.ContainerName, spec, pluginID); err != nil {
return err
}
conf, err := readOpenclawConfig(agent.ConfigPath)
@@ -455,7 +455,7 @@ func (a AgentService) UninstallPlugin(req dto.AgentPluginUninstallReq) error {
}
uninstallTask.AddSubTask("Uninstall OpenClaw plugin", func(t *task.Task) error {
mgr := cmd.NewCommandMgr(cmd.WithTask(*t), cmd.WithContext(t.TaskCtx), cmd.WithTimeout(10*time.Minute))
if _, err := mgr.RunWithStdout("docker", "exec", "-i", install.ContainerName, "sh", "-c", buildOpenclawPluginUninstallScript(pluginID)); err != nil {
if err := uninstallOpenclawPlugin(mgr, install.ContainerName, pluginID); err != nil {
return err
}
conf, err := readOpenclawConfig(agent.ConfigPath)
@@ -487,7 +487,7 @@ func (a AgentService) LoginWeixinChannel(req dto.AgentWeixinLoginReq) error {
if agent.AgentType == constant.AppHermesAgent {
return mgr.Run("docker", buildHermesWeixinLoginArgs(install.ContainerName)...)
}
return mgr.RunBashCf("docker exec %s openclaw channels login --channel openclaw-weixin", install.ContainerName)
return mgr.Run("docker", "exec", install.ContainerName, "openclaw", "channels", "login", "--channel", "openclaw-weixin")
}, nil)
if agent.AgentType == constant.AppHermesAgent {
loginTask.AddSubTask("Restart Hermes-Agent container", func(t *task.Task) error {
@@ -584,17 +584,26 @@ func (a AgentService) ApproveChannelPairing(req dto.AgentChannelPairingApproveRe
return validateHermesPairingApproveResult(output, err)
}
if req.AccountID != "" {
return cmd.RunDefaultBashCf(
"docker exec %s openclaw pairing approve %s %q --account %q",
return cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).Run(
"docker",
"exec",
install.ContainerName,
"openclaw",
"pairing",
"approve",
req.Type,
req.PairingCode,
"--account",
req.AccountID,
)
}
return cmd.RunDefaultBashCf(
"docker exec %s openclaw pairing approve %s %q",
return cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).Run(
"docker",
"exec",
install.ContainerName,
"openclaw",
"pairing",
"approve",
req.Type,
req.PairingCode,
)
@@ -1289,20 +1298,40 @@ func appendPluginAllow(conf map[string]interface{}, pluginID string) {
plugins["allow"] = append(allow, pluginID)
}
func buildOpenclawPluginInstallScript(spec, pluginID string) string {
return fmt.Sprintf(
"set -e; workdir=%s/%s; rm -rf \"$workdir\"; mkdir -p \"$workdir\"; cd \"$workdir\"; npm pack --silent %q >/dev/null 2>&1; pkg=$(find \"$workdir\" -maxdepth 1 -type f -name '*.tgz' | head -n 1); printf '%%s\\n' \"$pkg\"; openclaw plugins install \"$pkg\" --dangerously-force-unsafe-install; rm -rf \"$workdir\"",
openclawPluginPackageTmpDir,
pluginID,
spec,
)
func installOpenclawPlugin(mgr *cmd.CommandHelper, containerName, spec, pluginID string) error {
workdir := path.Join(openclawPluginPackageTmpDir, pluginID)
defer func() {
_ = mgr.Run("docker", "exec", containerName, "rm", "-rf", workdir)
}()
if err := mgr.Run("docker", "exec", containerName, "rm", "-rf", workdir); err != nil {
return err
}
if err := mgr.Run("docker", "exec", containerName, "mkdir", "-p", workdir); err != nil {
return err
}
if err := mgr.Run("docker", "exec", "-w", workdir, containerName, "npm", "pack", "--silent", spec); err != nil {
return err
}
pkgPath, err := cmd.RunDockerExecWithStdout(10*time.Minute, containerName, "find", workdir, "-maxdepth", "1", "-type", "f", "-name", "*.tgz", "-print", "-quit")
if err != nil {
return err
}
pkgPath = strings.TrimSpace(pkgPath)
if pkgPath == "" {
return fmt.Errorf("openclaw plugin package not found")
}
return mgr.Run("docker", "exec", containerName, "openclaw", "plugins", "install", pkgPath, "--dangerously-force-unsafe-install")
}
func buildOpenclawPluginUninstallScript(pluginID string) string {
return fmt.Sprintf(
"set +e; printf 'yes\\n' | openclaw plugins uninstall %s; code=$?; if [ \"$code\" -eq 137 ]; then exit 0; fi; exit \"$code\"",
pluginID,
func uninstallOpenclawPlugin(mgr *cmd.CommandHelper, containerName, pluginID string) error {
_, err := mgr.RunPipe(
cmd.PipeCommand{Name: "printf", Args: []string{"yes\n"}},
cmd.PipeCommand{Name: "docker", Args: []string{"exec", "-i", containerName, "openclaw", "plugins", "uninstall", pluginID}},
)
if err != nil && strings.Contains(err.Error(), "exit status 137") {
return nil
}
return err
}
func resolvePluginMeta(pluginType string) (string, string, error) {
@@ -1357,7 +1386,7 @@ func loadOpenclawPluginLatestVersion(containerName, pluginType string) (string,
if err != nil {
return "", err
}
output, err := runDockerExecWithStdout(20*time.Second, containerName, "npm", "view", spec, "version", "--json")
output, err := cmd.RunDockerExecWithStdout(20*time.Second, containerName, "npm", "view", spec, "version", "--json")
if err != nil {
return "", err
}
+2 -1
View File
@@ -10,6 +10,7 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
)
const (
@@ -101,7 +102,7 @@ func countOpenclawConfiguredChannels(conf map[string]interface{}) int {
}
func loadOpenclawOverviewSkillStats(containerName string) (int, error) {
output, err := runDockerExecWithStdout(5*time.Minute, containerName, "sh", "-c", "openclaw skills list --json 2>&1")
output, err := cmd.RunDockerExecWithStdout(5*time.Minute, containerName, "openclaw", "skills", "list", "--json")
if err != nil {
return 0, err
}
+595 -23
View File
@@ -1,9 +1,18 @@
package service
import (
"archive/tar"
"archive/zip"
"compress/gzip"
"encoding/json"
"fmt"
"io"
"os"
"os/exec"
"path"
"path/filepath"
"regexp"
"strconv"
"strings"
"time"
@@ -12,10 +21,15 @@ import (
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/common"
)
const clawhubGlobalRegistry = "https://clawhub.com"
const clawhubChinaRegistry = "https://mirror-cn.clawhub.com"
const localSkillHubSource = "local-hub"
const localSkillHubPublishedStatus = "published"
const clawHubSkillTmpSubDir = "1panel/tmp/clawhub-skills"
const hermesManagedSkillsDir = "/opt/data/skills"
type openclawSkillsList struct {
Skills []openclawSkillListItem `json:"skills"`
@@ -38,8 +52,17 @@ type skillhubSearchPayload struct {
Results []dto.AgentSkillSearchItem `json:"results"`
}
type localSkillHubItem struct {
ID uint
Name string
Status string
ApplicableAgent string
PackagePath string
}
var clawhubSearchLinePattern = regexp.MustCompile(`^(\S+)\s+(.+?)\s+\(([\d.]+)\)$`)
var ansiEscapePattern = regexp.MustCompile(`\x1b\[[0-9;?]*[ -/]*[@-~]`)
var safeLocalSkillDirNamePattern = regexp.MustCompile(`[^a-zA-Z0-9._-]+`)
func (a AgentService) ListSkills(req dto.AgentIDReq) ([]dto.AgentSkillItem, error) {
agent, install, err := a.loadAgentAndInstall(req.AgentID)
@@ -55,7 +78,7 @@ func (a AgentService) ListSkills(req dto.AgentIDReq) ([]dto.AgentSkillItem, erro
if agent.AgentType != constant.AppOpenclaw {
return nil, fmt.Errorf("%s does not support", agent.AgentType)
}
output, err := runDockerExecWithStdout(5*time.Minute, install.ContainerName, "sh", "-c", "openclaw skills list --json 2>&1")
output, err := cmd.RunDockerExecWithStdout(5*time.Minute, install.ContainerName, "openclaw", "skills", "list", "--json")
if err != nil {
return nil, err
}
@@ -66,6 +89,12 @@ func (a AgentService) ListSkills(req dto.AgentIDReq) ([]dto.AgentSkillItem, erro
}
func (a AgentService) SearchSkills(req dto.AgentSkillSearchReq) ([]dto.AgentSkillSearchItem, error) {
if req.Source == localSkillHubSource {
return nil, fmt.Errorf("local skills hub is provided by enterprise edition")
}
if global.CONF.Base.IsOffline {
return nil, fmt.Errorf("offline environment cannot access remote Skills Hub")
}
agent, install, err := a.loadAgentAndInstall(req.AgentID)
if err != nil {
return nil, err
@@ -115,6 +144,9 @@ func (a AgentService) UpdateSkill(req dto.AgentSkillUpdateReq) error {
}
func (a AgentService) InstallSkill(req dto.AgentSkillInstallReq) error {
if global.CONF.Base.IsOffline && req.Source != localSkillHubSource {
return fmt.Errorf("offline environment cannot access remote Skills Hub")
}
agent, install, err := a.loadAgentAndInstall(req.AgentID)
if err != nil {
return err
@@ -122,6 +154,29 @@ func (a AgentService) InstallSkill(req dto.AgentSkillInstallReq) error {
if err := ensureContainerRunning(install.ContainerName); err != nil {
return err
}
if req.Source == localSkillHubSource {
if !global.IsMaster {
return fmt.Errorf("local skills hub is only available on the master node")
}
hostPath, skillName, err := resolveLocalSkillPackage(agent.AgentType, req.Slug)
if err != nil {
return err
}
installTask, err := task.NewTaskWithOps(skillName, task.TaskInstall, task.TaskScopeAI, req.TaskID, req.AgentID)
if err != nil {
return err
}
installTask.AddSubTask("Install local skill", func(t *task.Task) error {
mgr := cmd.NewCommandMgr(cmd.WithTask(*t), cmd.WithContext(t.TaskCtx), cmd.WithTimeout(20*time.Minute))
return installLocalSkillPackage(mgr, install.ContainerName, agent.AgentType, agent.ConfigPath, hostPath, skillName)
}, nil)
go func() {
if err := installTask.Execute(); err != nil {
global.LOG.Errorf("install local skill failed: %v", err)
}
}()
return nil
}
installTask, err := task.NewTaskWithOps(req.Slug, task.TaskInstall, task.TaskScopeAI, req.TaskID, req.AgentID)
if err != nil {
return err
@@ -143,7 +198,7 @@ func (a AgentService) InstallSkill(req dto.AgentSkillInstallReq) error {
}
installTask.AddSubTask("Install OpenClaw skill", func(t *task.Task) error {
mgr := cmd.NewCommandMgr(cmd.WithTask(*t), cmd.WithContext(t.TaskCtx), cmd.WithTimeout(20*time.Minute))
return mgr.Run("docker", "exec", install.ContainerName, "sh", "-c", buildOpenclawSkillInstallCommand(req.Source, req.Slug))
return installOpenclawSkill(mgr, install.ContainerName, req.Source, req.Slug)
}, nil)
go func() {
if err := installTask.Execute(); err != nil {
@@ -153,6 +208,513 @@ func (a AgentService) InstallSkill(req dto.AgentSkillInstallReq) error {
return nil
}
func installLocalSkillPackage(mgr *cmd.CommandHelper, containerName, agentType, configPath, hostPath, skillName string) error {
targetDir, err := resolveAgentLocalSkillDir(agentType)
if err != nil {
return err
}
tempDir, err := os.MkdirTemp("", "1panel-agent-skill-*")
if err != nil {
return err
}
defer os.RemoveAll(tempDir)
extractRoot := filepath.Join(tempDir, "extract")
if err := os.MkdirAll(extractRoot, 0755); err != nil {
return err
}
if err := extractLocalSkillPackage(hostPath, extractRoot); err != nil {
return err
}
copyRoot, installedSkillName, err := normalizeLocalSkillInstallRoot(extractRoot, filepath.Join(tempDir, "install"), skillName)
if err != nil {
return err
}
if err := mgr.Run("docker", "exec", containerName, "mkdir", "-p", targetDir); err != nil {
return err
}
if err := mgr.Run("docker", "cp", copyRoot+"/.", containerName+":"+targetDir); err != nil {
return err
}
if agentType == constant.AppOpenclaw {
return registerOpenclawLocalSkill(containerName, configPath, installedSkillName)
}
return nil
}
func resolveAgentLocalSkillDir(agentType string) (string, error) {
switch agentType {
case constant.AppOpenclaw:
return openclawManagedSkillsDir, nil
case constant.AppHermesAgent:
return hermesManagedSkillsDir, nil
default:
return "", fmt.Errorf("%s does not support", agentType)
}
}
func resolveLocalSkillPackage(agentType, skillID string) (string, string, error) {
skillID = strings.TrimSpace(skillID)
id, err := strconv.ParseUint(skillID, 10, 64)
if err != nil || id == 0 {
return "", "", fmt.Errorf("invalid local skill id")
}
dbPath := filepath.Join(global.CONF.Base.InstallDir, "1panel", "db", "enterprise.db")
if _, err := os.Stat(dbPath); err != nil {
return "", "", fmt.Errorf("local skills hub is unavailable")
}
db, err := common.GetDBWithPath(dbPath)
if err != nil {
return "", "", err
}
defer common.CloseDB(db)
var item localSkillHubItem
if err := db.Table("skill_hub_items").
Select("id,name,status,applicable_agent,package_path").
Where("id = ? AND status = ?", uint(id), localSkillHubPublishedStatus).
First(&item).Error; err != nil {
return "", "", fmt.Errorf("local skill is not published or does not exist")
}
if !matchLocalSkillAgent(item.ApplicableAgent, agentType) {
return "", "", fmt.Errorf("local skill does not support %s", agentType)
}
packagePath, err := validateLocalSkillPackagePath(item.PackagePath)
if err != nil {
return "", "", err
}
return packagePath, sanitizeLocalSkillDirName(item.Name, packagePath, skillID), nil
}
func matchLocalSkillAgent(applicableAgent, agentType string) bool {
applicableAgent = strings.TrimSpace(applicableAgent)
if applicableAgent == "" {
return true
}
for _, item := range strings.Split(applicableAgent, ",") {
normalized := normalizeLocalSkillAgent(strings.TrimSpace(item))
if normalized == "common" || normalized == normalizeLocalSkillAgent(agentType) {
return true
}
}
return false
}
func normalizeLocalSkillAgent(agentType string) string {
switch strings.ToLower(strings.TrimSpace(agentType)) {
case constant.AppHermesAgent:
return "hermes"
default:
return strings.ToLower(strings.TrimSpace(agentType))
}
}
func sanitizeLocalSkillDirName(name, packagePath, fallback string) string {
name = strings.TrimSpace(name)
if name == "" {
name = strings.TrimSuffix(filepath.Base(packagePath), localSkillPackageExtension(packagePath))
}
name = strings.Trim(safeLocalSkillDirNamePattern.ReplaceAllString(name, "-"), "-")
if name == "" || name == "." || name == ".." {
name = "skill-" + strings.TrimSpace(fallback)
}
if name == "skill-" {
return "skill"
}
return name
}
func validateLocalSkillPackagePath(packagePath string) (string, error) {
packagePath = strings.TrimSpace(packagePath)
if packagePath == "" {
return "", fmt.Errorf("skill package path is required")
}
if _, err := localSkillPackageFormat(packagePath); err != nil {
return "", err
}
absPath, err := filepath.Abs(packagePath)
if err != nil {
return "", err
}
resolvedPath, err := filepath.EvalSymlinks(absPath)
if err != nil {
return "", err
}
if !isLocalSkillPackageAllowedPath(resolvedPath) {
return "", fmt.Errorf("invalid local skill package path")
}
info, err := os.Stat(resolvedPath)
if err != nil {
return "", err
}
if info.IsDir() {
return "", fmt.Errorf("skill package must be a file")
}
return resolvedPath, nil
}
func isLocalSkillPackageAllowedPath(resolvedPath string) bool {
roots := []string{
filepath.Join(global.CONF.Base.InstallDir, "1panel", "uploads", "skills-hub"),
filepath.Join(global.CONF.Base.InstallDir, filepath.FromSlash(clawHubSkillTmpSubDir)),
}
for _, root := range roots {
if isPathInsideResolvedRoot(resolvedPath, root) {
return true
}
}
return false
}
func isPathInsideResolvedRoot(resolvedPath, root string) bool {
absRoot, err := filepath.Abs(root)
if err != nil {
return false
}
resolvedRoot, err := filepath.EvalSymlinks(absRoot)
if err != nil {
return false
}
rel, err := filepath.Rel(resolvedRoot, resolvedPath)
return err == nil && rel != "." && rel != ".." && !strings.HasPrefix(rel, ".."+string(os.PathSeparator))
}
func normalizeLocalSkillInstallRoot(extractRoot, installRoot, skillName string) (string, string, error) {
entries, err := os.ReadDir(extractRoot)
if err != nil {
return "", "", err
}
if len(entries) == 0 {
return "", "", fmt.Errorf("skill package is empty")
}
if len(entries) == 1 && entries[0].IsDir() {
return extractRoot, entries[0].Name(), nil
}
skillRoot := filepath.Join(installRoot, skillName)
if err := os.MkdirAll(skillRoot, 0755); err != nil {
return "", "", err
}
if err := copyLocalDirContents(extractRoot, skillRoot); err != nil {
return "", "", err
}
return installRoot, skillName, nil
}
func registerOpenclawLocalSkill(containerName, configPath, skillName string) error {
conf, err := readOpenclawConfig(configPath)
if err != nil {
return err
}
skillKey, err := getOpenclawSkillKey(containerName, skillName)
if err != nil {
return err
}
setOpenclawSkillEnabled(conf, skillKey, true)
return writeOpenclawConfigRaw(configPath, conf)
}
func extractLocalSkillPackage(packagePath, targetDir string) error {
format, err := localSkillPackageFormat(packagePath)
if err != nil {
return err
}
switch format {
case "zip":
return unzipLocalSkillPackage(packagePath, targetDir)
case "tar", "targz":
return untarLocalSkillPackage(packagePath, targetDir, format == "targz")
case "7z":
return un7zLocalSkillPackage(packagePath, targetDir)
default:
return fmt.Errorf("unsupported skill package format")
}
}
func unzipLocalSkillPackage(packagePath, targetDir string) error {
reader, err := zip.OpenReader(packagePath)
if err != nil {
return err
}
defer reader.Close()
root, err := filepath.Abs(targetDir)
if err != nil {
return err
}
for _, file := range reader.File {
name, err := safeLocalSkillZipEntryName(file.Name)
if err != nil {
return err
}
targetPath := filepath.Join(root, name)
rel, err := filepath.Rel(root, targetPath)
if err != nil || rel == ".." || strings.HasPrefix(rel, ".."+string(os.PathSeparator)) {
return fmt.Errorf("invalid zip entry: %s", file.Name)
}
if file.FileInfo().IsDir() {
if err := os.MkdirAll(targetPath, file.Mode()); err != nil {
return err
}
continue
}
if file.Mode()&os.ModeSymlink != 0 {
return fmt.Errorf("unsupported zip entry: %s", file.Name)
}
if err := os.MkdirAll(filepath.Dir(targetPath), 0755); err != nil {
return err
}
rc, err := file.Open()
if err != nil {
return err
}
dst, err := os.OpenFile(targetPath, os.O_CREATE|os.O_WRONLY|os.O_TRUNC, file.Mode())
if err != nil {
_ = rc.Close()
return err
}
_, copyErr := io.Copy(dst, rc)
closeErr := dst.Close()
_ = rc.Close()
if copyErr != nil {
return copyErr
}
if closeErr != nil {
return closeErr
}
}
return nil
}
func untarLocalSkillPackage(packagePath, targetDir string, gzipped bool) error {
src, err := os.Open(packagePath)
if err != nil {
return err
}
defer src.Close()
var reader io.Reader = src
var gzipReader *gzip.Reader
if gzipped {
gzipReader, err = gzip.NewReader(src)
if err != nil {
return err
}
defer gzipReader.Close()
reader = gzipReader
}
root, err := filepath.Abs(targetDir)
if err != nil {
return err
}
tarReader := tar.NewReader(reader)
for {
header, err := tarReader.Next()
if err == io.EOF {
break
}
if err != nil {
return err
}
name, err := safeLocalSkillZipEntryName(header.Name)
if err != nil {
return err
}
targetPath := filepath.Join(root, name)
rel, err := filepath.Rel(root, targetPath)
if err != nil || rel == ".." || strings.HasPrefix(rel, ".."+string(os.PathSeparator)) {
return fmt.Errorf("invalid tar entry: %s", header.Name)
}
info := header.FileInfo()
if info.IsDir() {
if err := os.MkdirAll(targetPath, info.Mode()); err != nil {
return err
}
continue
}
if header.Typeflag != tar.TypeReg && header.Typeflag != tar.TypeRegA {
continue
}
if err := os.MkdirAll(filepath.Dir(targetPath), 0755); err != nil {
return err
}
dst, err := os.OpenFile(targetPath, os.O_CREATE|os.O_WRONLY|os.O_TRUNC, info.Mode())
if err != nil {
return err
}
_, copyErr := io.Copy(dst, tarReader)
closeErr := dst.Close()
if copyErr != nil {
return copyErr
}
if closeErr != nil {
return closeErr
}
}
return nil
}
func un7zLocalSkillPackage(packagePath, targetDir string) error {
if _, err := listLocal7zEntries(packagePath); err != nil {
return err
}
root, err := filepath.Abs(targetDir)
if err != nil {
return err
}
bin, err := findLocal7zBinary()
if err != nil {
return err
}
tempDir, err := os.MkdirTemp("", "1panel-agent-skill-7z-*")
if err != nil {
return err
}
defer os.RemoveAll(tempDir)
if err := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Minute)).Run(bin, "x", "-y", "-o"+tempDir, packagePath); err != nil {
return err
}
if err := validateExtractedLocalSkillPackage(tempDir); err != nil {
return err
}
return copyLocalDirContents(tempDir, root)
}
func safeLocalSkillZipEntryName(name string) (string, error) {
clean := path.Clean(strings.ReplaceAll(name, "\\", "/"))
clean = strings.TrimLeft(clean, "/")
if clean == "." || clean == "" || clean == ".." || strings.HasPrefix(clean, "../") {
return "", fmt.Errorf("invalid zip entry: %s", name)
}
return clean, nil
}
func copyLocalDirContents(sourceRoot, targetRoot string) error {
return filepath.Walk(sourceRoot, func(sourcePath string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if sourcePath == sourceRoot {
return nil
}
if info.Mode()&os.ModeSymlink != 0 || (!info.IsDir() && !info.Mode().IsRegular()) {
return fmt.Errorf("unsupported skill package entry: %s", sourcePath)
}
rel, err := filepath.Rel(sourceRoot, sourcePath)
if err != nil {
return err
}
name, err := safeLocalSkillZipEntryName(rel)
if err != nil {
return err
}
targetPath := filepath.Join(targetRoot, name)
if info.IsDir() {
return os.MkdirAll(targetPath, info.Mode())
}
return copyLocalSkillFile(sourcePath, targetPath)
})
}
func copyLocalSkillFile(source, target string) error {
src, err := os.Open(source)
if err != nil {
return err
}
defer src.Close()
if err := os.MkdirAll(filepath.Dir(target), 0755); err != nil {
return err
}
dst, err := os.OpenFile(target, os.O_CREATE|os.O_WRONLY|os.O_TRUNC, 0644)
if err != nil {
return err
}
if _, err := io.Copy(dst, src); err != nil {
_ = dst.Close()
return err
}
return dst.Close()
}
func validateExtractedLocalSkillPackage(root string) error {
return filepath.Walk(root, func(currentPath string, info os.FileInfo, err error) error {
if err != nil {
return err
}
if currentPath == root {
return nil
}
if info.Mode()&os.ModeSymlink != 0 || (!info.IsDir() && !info.Mode().IsRegular()) {
return fmt.Errorf("unsupported skill package entry: %s", currentPath)
}
return nil
})
}
func localSkillPackageExtension(name string) string {
lower := strings.ToLower(filepath.Base(strings.TrimSpace(name)))
if lower == "" || lower == "." {
return ""
}
if strings.HasSuffix(lower, ".tar.gz") {
return ".tar.gz"
}
return strings.ToLower(filepath.Ext(lower))
}
func localSkillPackageFormat(name string) (string, error) {
switch localSkillPackageExtension(name) {
case ".zip":
return "zip", nil
case ".7z":
return "7z", nil
case ".tar":
return "tar", nil
case ".tar.gz":
return "targz", nil
default:
return "", fmt.Errorf("only .zip, .7z, .tar, and .tar.gz skill packages are supported")
}
}
func findLocal7zBinary() (string, error) {
for _, name := range []string{"7z", "7za", "7zr"} {
if path, err := exec.LookPath(name); err == nil {
return path, nil
}
}
return "", fmt.Errorf("7z command is required to process .7z skill packages")
}
func listLocal7zEntries(packagePath string) ([]string, error) {
bin, err := findLocal7zBinary()
if err != nil {
return nil, err
}
output, err := exec.Command(bin, "l", "-slt", packagePath).CombinedOutput()
if err != nil {
if message := strings.TrimSpace(string(output)); message != "" {
return nil, fmt.Errorf("7z failed: %w: %s", err, message)
}
return nil, fmt.Errorf("7z failed: %w", err)
}
entries := make([]string, 0)
for _, line := range strings.Split(string(output), "\n") {
line = strings.TrimSpace(line)
if !strings.HasPrefix(line, "Path = ") {
continue
}
entry := strings.TrimSpace(strings.TrimPrefix(line, "Path = "))
if entry == "" || entry == packagePath || entry == filepath.Base(packagePath) {
continue
}
name, err := safeLocalSkillZipEntryName(entry)
if err != nil {
return nil, err
}
entries = append(entries, name)
}
if len(entries) == 0 {
return nil, fmt.Errorf("skill package is empty")
}
return entries, nil
}
func (a AgentService) UninstallSkill(req dto.AgentSkillUninstallReq) error {
agent, install, err := a.loadAgentAndInstall(req.AgentID)
if err != nil {
@@ -205,15 +767,19 @@ func parseOpenclawSkillsList(output string) ([]dto.AgentSkillItem, error) {
func loadOpenclawSkillSearchOutput(containerName, source, keyword string) (string, error) {
switch source {
case "skillhub":
return runDockerExecWithStdout(2*time.Minute, containerName, "skillhub", "search", keyword, "--json")
return cmd.RunDockerExecWithStdout(2*time.Minute, containerName, "skillhub", "search", keyword, "--json")
default:
return runDockerExecWithStdout(
2*time.Minute,
containerName,
"sh",
"-c",
fmt.Sprintf("CLAWHUB_REGISTRY=%q clawhub search %q", resolveClawhubRegistry(source), keyword),
)
return cmd.NewCommandMgr(cmd.WithTimeout(2*time.Minute)).
RunWithStdout(
"docker",
"exec",
"-e",
"CLAWHUB_REGISTRY="+resolveClawhubRegistry(source),
containerName,
"clawhub",
"search",
keyword,
)
}
}
@@ -261,22 +827,28 @@ func parseClawhubSearchResult(output, source string) []dto.AgentSkillSearchItem
return items
}
func buildOpenclawSkillInstallCommand(source, slug string) string {
func installOpenclawSkill(mgr *cmd.CommandHelper, containerName, source, slug string) error {
if err := mgr.Run("docker", "exec", containerName, "mkdir", "-p", openclawManagedSkillsDir); err != nil {
return err
}
switch source {
case "clawhub-global", "clawhub-cn":
return fmt.Sprintf(
"mkdir -p %s && CLAWHUB_REGISTRY=%q clawhub --workdir /home/node/.openclaw --dir skills install %q",
openclawManagedSkillsDir,
resolveClawhubRegistry(source),
return mgr.Run(
"docker",
"exec",
"-e",
"CLAWHUB_REGISTRY="+resolveClawhubRegistry(source),
containerName,
"clawhub",
"--workdir",
"/home/node/.openclaw",
"--dir",
"skills",
"install",
slug,
)
default:
return fmt.Sprintf(
"mkdir -p %s && skillhub --dir %s install %q",
openclawManagedSkillsDir,
openclawManagedSkillsDir,
slug,
)
return mgr.Run("docker", "exec", containerName, "skillhub", "--dir", openclawManagedSkillsDir, "install", slug)
}
}
@@ -290,7 +862,7 @@ func resolveClawhubRegistry(source string) string {
}
func getOpenclawSkillKey(containerName, name string) (string, error) {
output, err := runDockerExecWithStdout(2*time.Minute, containerName, "sh", "-c", fmt.Sprintf("openclaw skills info %q --json 2>&1", name))
output, err := cmd.RunDockerExecWithStdout(2*time.Minute, containerName, "openclaw", "skills", "info", name, "--json")
if err != nil {
return "", err
}
@@ -307,7 +879,7 @@ func parseOpenclawSkillKey(name, output string) (string, error) {
return "", err
}
if payload.SkillKey == "" {
return "", fmt.Errorf("skill %s does not have a skillKey", name)
return name, nil
}
return payload.SkillKey, nil
}
+3 -6
View File
@@ -19,7 +19,6 @@ import (
"github.com/1Panel-dev/1Panel/agent/buserr"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/common"
"github.com/1Panel-dev/1Panel/agent/utils/files"
"github.com/1Panel-dev/1Panel/agent/utils/req_helper"
@@ -60,11 +59,6 @@ func ensureContainerRunning(containerName string) error {
return nil
}
func runDockerExecWithStdout(timeout time.Duration, containerName string, args ...string) (string, error) {
commandArgs := append([]string{"exec", containerName}, args...)
return cmd.NewCommandMgr(cmd.WithTimeout(timeout)).RunWithStdout("docker", commandArgs...)
}
func resolveAgentAccountInput(provider, apiKey, baseURL string) (resolvedAgentAccountInput, error) {
resolvedAPIKey := strings.TrimSpace(apiKey)
resolvedBaseURL := strings.TrimSpace(baseURL)
@@ -584,6 +578,9 @@ func checkAgentUpgradable(install model.AppInstall) bool {
if install.App.ID == 0 {
return false
}
if ignoreUpdate(install) {
return false
}
details, err := appDetailRepo.GetBy(appDetailRepo.WithAppId(install.App.ID))
if err != nil || len(details) == 0 {
return false
+8 -5
View File
@@ -77,7 +77,7 @@ func (u *AIToolService) LoadDetail(name string) (string, error) {
if err != nil {
return "", err
}
stdout, err := cmd.RunDefaultWithStdoutBashCf("docker exec %s ollama show %s", containerName, name)
stdout, err := cmd.RunDockerExecWithStdout(20*time.Second, containerName, "ollama", "show", name)
if err != nil {
return "", err
}
@@ -137,7 +137,7 @@ func (u *AIToolService) Close(name string) error {
if err != nil {
return err
}
if err := cmd.RunDefaultBashCf("docker exec %s ollama stop %s", containerName, name); err != nil {
if err := cmd.NewCommandMgr().Run("docker", "exec", containerName, "ollama", "stop", name); err != nil {
return fmt.Errorf("handle ollama stop %s failed, %v", name, err)
}
return nil
@@ -194,7 +194,7 @@ func (u *AIToolService) Delete(req dto.ForceDelete) error {
}
for _, item := range ollamaList {
if item.Status != constant.StatusDeleted {
if err := cmd.RunDefaultBashCf("docker exec %s ollama rm %s", containerName, item.Name); err != nil && !req.ForceDelete {
if err := cmd.NewCommandMgr().Run("docker", "exec", containerName, "ollama", "rm", item.Name); err != nil && !req.ForceDelete {
return fmt.Errorf("handle ollama rm %s failed, %v", item.Name, err)
}
}
@@ -210,7 +210,7 @@ func (u *AIToolService) Sync() ([]dto.OllamaModelDropList, error) {
if err != nil {
return nil, err
}
stdout, err := cmd.RunDefaultWithStdoutBashCf("docker exec %s ollama list", containerName)
stdout, err := cmd.RunDockerExecWithStdout(20*time.Second, containerName, "ollama", "list")
if err != nil {
return nil, err
}
@@ -382,12 +382,15 @@ func LoadContainerName() (string, error) {
}
func loadModelSize(name string, containerName string) (string, error) {
stdout, err := cmd.RunDefaultWithStdoutBashCf("docker exec %s ollama list | grep %s", containerName, name)
stdout, err := cmd.RunDockerExecWithStdout(20*time.Second, containerName, "ollama", "list")
if err != nil {
return "", err
}
lines := strings.Split(stdout, "\n")
for _, line := range lines {
if !strings.Contains(line, name) {
continue
}
parts := strings.Fields(line)
if len(parts) < 5 {
continue
+213 -21
View File
@@ -3,6 +3,13 @@ package service
import (
"encoding/json"
"fmt"
"mime"
"sort"
"strconv"
"strings"
"sync"
"time"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/app/repo"
@@ -15,24 +22,27 @@ import (
"github.com/1Panel-dev/1Panel/agent/utils/email"
"github.com/1Panel-dev/1Panel/agent/utils/xpack"
"github.com/shirou/gopsutil/v4/disk"
"mime"
"sort"
"strings"
"sync"
"time"
)
type AlertService struct{}
var eeHiddenAlertTypes = []string{"licenseException", "panelUpdate", "panelPwdEndTime"}
var communityAlertMethodTypeNames = map[string]string{
constant.WeCom: "WeCom",
constant.DingTalk: "DingTalk",
constant.FeiShu: "FeiShu",
constant.SMS: "SMS",
}
type IAlertService interface {
PageAlert(req dto.AlertSearch) (int64, []dto.AlertDTO, error)
GetAlerts() ([]dto.AlertDTO, error)
CreateAlert(create dto.AlertCreate) error
UpdateAlert(req dto.AlertUpdate) error
CreateAlert(create dto.AlertCreate, operator string) error
UpdateAlert(req dto.AlertUpdate, operator string) error
DeleteAlert(id uint) error
GetAlert(id uint) (dto.AlertDTO, error)
UpdateStatus(id uint, status string) error
ExternalUpdateAlert(req dto.AlertCreate) error
ExternalUpdateAlert(req dto.AlertCreate, operator string) error
GetDisks() ([]dto.DiskDTO, error)
PageAlertLogs(req dto.AlertLogSearch) (int64, []dto.AlertLogDTO, error)
@@ -40,8 +50,9 @@ type IAlertService interface {
GetClams() ([]dto.ClamDTO, error)
GetCronJobs(req dto.CronJobReq) ([]dto.CronJobDTO, error)
GetAlertConfig() ([]model.AlertConfig, error)
UpdateAlertConfig(req dto.AlertConfigUpdate) error
GetAlertConfig(req dto.AlertConfigQuery) ([]model.AlertConfig, error)
PageAlertConfig(req dto.AlertConfigPageReq) (int64, []model.AlertConfig, error)
UpdateAlertConfig(req dto.AlertConfigUpdate, operator string) error
DeleteAlertConfig(id uint) error
TestAlertConfig(req dto.AlertConfigTest) (bool, error)
}
@@ -55,6 +66,9 @@ func (a AlertService) PageAlert(search dto.AlertSearch) (int64, []dto.AlertDTO,
opts []repo.DBOption
result []dto.AlertDTO
)
if global.CONF.Base.IsEnterprise {
opts = append(opts, alertRepo.WithByTypeNotIn(eeHiddenAlertTypes))
}
if search.Status != "" {
opts = append(opts, repo.WithByStatus(search.Status))
}
@@ -81,6 +95,8 @@ func (a AlertService) PageAlert(search dto.AlertSearch) (int64, []dto.AlertDTO,
Status: item.Status,
SendCount: item.SendCount,
AdvancedParams: item.AdvancedParams,
CreateUser: item.CreateUser,
UpdateUser: item.UpdateUser,
CreatedAt: item.CreatedAt,
UpdatedAt: item.UpdatedAt,
})
@@ -112,6 +128,8 @@ func (a AlertService) GetAlerts() ([]dto.AlertDTO, error) {
Status: item.Status,
SendCount: item.SendCount,
AdvancedParams: item.AdvancedParams,
CreateUser: item.CreateUser,
UpdateUser: item.UpdateUser,
CreatedAt: item.CreatedAt,
UpdatedAt: item.UpdatedAt,
})
@@ -120,7 +138,10 @@ func (a AlertService) GetAlerts() ([]dto.AlertDTO, error) {
return result, err
}
func (a AlertService) CreateAlert(create dto.AlertCreate) error {
func (a AlertService) CreateAlert(create dto.AlertCreate, operator string) error {
if err := a.validateCommunityAlertMethod(create.Method); err != nil {
return err
}
var alertID uint
var alertInfo model.Alert
if create.Project != "" {
@@ -137,7 +158,7 @@ func (a AlertService) CreateAlert(create dto.AlertCreate) error {
return buserr.WithErr("ErrStructTransform", err)
}
upAlert.ID = alertID
err := a.UpdateAlert(upAlert)
err := a.UpdateAlert(upAlert, operator)
if err != nil {
return err
}
@@ -146,6 +167,8 @@ func (a AlertService) CreateAlert(create dto.AlertCreate) error {
if err := copier.Copy(&alertInfo, &create); err != nil {
return buserr.WithErr("ErrStructTransform", err)
}
alertInfo.CreateUser = operator
alertInfo.UpdateUser = operator
if err := alertRepo.Create(&alertInfo); err != nil {
return err
@@ -156,7 +179,10 @@ func (a AlertService) CreateAlert(create dto.AlertCreate) error {
return nil
}
func (a AlertService) UpdateAlert(req dto.AlertUpdate) error {
func (a AlertService) UpdateAlert(req dto.AlertUpdate, operator string) error {
if err := a.validateCommunityAlertMethod(req.Method); err != nil {
return err
}
upMap := make(map[string]interface{})
upMap["id"] = req.ID
@@ -169,6 +195,7 @@ func (a AlertService) UpdateAlert(req dto.AlertUpdate) error {
upMap["status"] = req.Status
upMap["send_count"] = req.SendCount
upMap["advanced_params"] = req.AdvancedParams
upMap["update_user"] = operator
if err := alertRepo.Update(upMap, repo.WithByID(req.ID)); err != nil {
return err
@@ -308,12 +335,25 @@ func (a AlertService) GetDisks() ([]dto.DiskDTO, error) {
func executeDiskCommand() (string, error) {
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(2 * time.Second))
stdout, err := cmdMgr.RunWithStdoutBashC("df -hT -P | grep '/' | grep -v tmpfs | grep -v 'snap/core' | grep -v udev")
stdout, err := cmdMgr.RunWithStdout("df", "-hT", "-P")
if err != nil {
cmdMgr2 := cmd.NewCommandMgr(cmd.WithTimeout(1 * time.Second))
stdout, err = cmdMgr2.RunWithStdoutBashC("df -lhT -P | grep '/' | grep -v tmpfs | grep -v 'snap/core' | grep -v udev")
stdout, err = cmdMgr2.RunWithStdout("df", "-lhT", "-P")
}
return stdout, err
if err != nil {
return stdout, err
}
var lines []string
for _, line := range strings.Split(stdout, "\n") {
if !strings.Contains(line, "/") || strings.Contains(line, "tmpfs") || strings.Contains(line, "snap/core") || strings.Contains(line, "udev") {
continue
}
lines = append(lines, line)
}
if len(lines) == 0 {
return "", nil
}
return strings.Join(lines, "\n"), nil
}
func shouldExclude(fields []string, mountPoint string, excludes map[string]struct{}) bool {
@@ -441,17 +481,40 @@ func (a AlertService) GetCronJobs(req dto.CronJobReq) ([]dto.CronJobDTO, error)
return cronJobs, err
}
func (a AlertService) GetAlertConfig() ([]model.AlertConfig, error) {
func (a AlertService) GetAlertConfig(req dto.AlertConfigQuery) ([]model.AlertConfig, error) {
var (
opts []repo.DBOption
configs []model.AlertConfig
)
if len(req.ExcludeTypes) > 0 {
opts = append(opts, alertRepo.WithByTypeNotIn(req.ExcludeTypes))
}
opts = append(opts, repo.WithByStatus(constant.AlertEnable))
configs, err := alertRepo.AlertConfigList(opts...)
return configs, err
}
func (a AlertService) UpdateAlertConfig(req dto.AlertConfigUpdate) error {
func (a AlertService) PageAlertConfig(req dto.AlertConfigPageReq) (int64, []model.AlertConfig, error) {
opts := []repo.DBOption{
alertRepo.WithByTypeNotIn([]string{"common"}),
repo.WithOrderDesc("created_at"),
}
if len(req.ExcludeTypes) > 0 {
opts = append(opts, alertRepo.WithByTypeNotIn(req.ExcludeTypes))
}
return alertRepo.PageAlertConfig(req.Page, req.PageSize, opts...)
}
func (a AlertService) UpdateAlertConfig(req dto.AlertConfigUpdate, operator string) error {
if err := a.validateCommunityAlertConfigType(req.Type); err != nil {
return err
}
if err := a.checkAlertConfigDisplayNameUnique(req); err != nil {
return err
}
if err := a.checkAlertConfigSMSPhoneUnique(req); err != nil {
return err
}
if req.ID != 0 {
upMap := make(map[string]interface{})
upMap["id"] = req.ID
@@ -459,6 +522,7 @@ func (a AlertService) UpdateAlertConfig(req dto.AlertConfigUpdate) error {
upMap["title"] = req.Title
upMap["status"] = req.Status
upMap["config"] = req.Config
upMap["update_user"] = operator
if err := alertRepo.UpdateAlertConfig(upMap, repo.WithByID(req.ID)); err != nil {
return err
}
@@ -467,6 +531,8 @@ func (a AlertService) UpdateAlertConfig(req dto.AlertConfigUpdate) error {
if err := copier.Copy(&alertConfig, &req); err != nil {
return buserr.WithErr("ErrStructTransform", err)
}
alertConfig.CreateUser = operator
alertConfig.UpdateUser = operator
if err := alertRepo.CreateAlertConfig(&alertConfig); err != nil {
return err
}
@@ -475,7 +541,130 @@ func (a AlertService) UpdateAlertConfig(req dto.AlertConfigUpdate) error {
return nil
}
func (a AlertService) checkAlertConfigSMSPhoneUnique(req dto.AlertConfigUpdate) error {
if req.Type != constant.SMSConfig {
return nil
}
phone := alertConfigSMSPhone(req.Config)
configs, err := alertRepo.AlertConfigList(alertRepo.WithByType(req.Type))
if err != nil {
return err
}
for _, config := range configs {
if req.ID != 0 && config.ID == req.ID {
continue
}
if alertConfigSMSPhone(config.Config) == phone {
return buserr.New("ErrAlertConfigPhoneExist")
}
}
return nil
}
func (a AlertService) checkAlertConfigDisplayNameUnique(req dto.AlertConfigUpdate) error {
displayName := alertConfigDisplayName(req.Type, req.Config)
if displayName == "" {
return nil
}
configs, err := alertRepo.AlertConfigList(alertRepo.WithByType(req.Type))
if err != nil {
return err
}
for _, config := range configs {
if req.ID != 0 && config.ID == req.ID {
continue
}
if alertConfigDisplayName(config.Type, config.Config) == displayName {
return buserr.New("ErrNameIsExist")
}
}
return nil
}
func (a AlertService) validateCommunityAlertMethod(method string) error {
if global.CONF.Base.IsEnterprise || global.CONF.Base.Edition == "cn" {
return nil
}
if strings.TrimSpace(method) == "" {
return nil
}
for _, item := range strings.Split(method, ",") {
item = strings.TrimSpace(item)
if item == "" {
continue
}
if configID, err := strconv.ParseUint(item, 10, 64); err == nil {
config, err := alertRepo.GetConfigById(uint(configID))
if err != nil {
return err
}
if _, ok := communityAlertMethodTypeNames[config.Type]; ok {
return buserr.WithErr("ErrAlertMethodNotSupported", nil)
}
continue
}
if _, ok := communityAlertMethodTypeNames[item]; ok {
return buserr.WithErr("ErrAlertMethodNotSupported", nil)
}
}
return nil
}
func (a AlertService) validateCommunityAlertConfigType(configType string) error {
if global.CONF.Base.IsEnterprise || global.CONF.Base.Edition == "cn" {
return nil
}
if _, ok := communityAlertMethodTypeNames[configType]; ok {
return buserr.WithErr("ErrAlertMethodNotSupported", nil)
}
return nil
}
func alertConfigDisplayName(configType, configData string) string {
switch configType {
case constant.Email, constant.WeCom, constant.DingTalk, constant.FeiShu, constant.Bark, constant.SMS:
var cfg struct {
DisplayName string `json:"displayName"`
}
if err := json.Unmarshal([]byte(configData), &cfg); err != nil {
return ""
}
return strings.TrimSpace(cfg.DisplayName)
default:
return ""
}
}
func alertConfigSMSPhone(configData string) string {
var cfg struct {
Phone string `json:"phone"`
}
if err := json.Unmarshal([]byte(configData), &cfg); err != nil {
return ""
}
return strings.TrimSpace(cfg.Phone)
}
func (a AlertService) DeleteAlertConfig(id uint) error {
_, err := alertRepo.GetConfigById(id)
if err != nil {
return err
}
usedAlerts, err := alertRepo.List(alertRepo.WithByAlertMethodContainsConfigID(id))
if err != nil {
return err
}
if len(usedAlerts) > 0 {
return buserr.New("ErrAlertConfigInUse")
}
return alertRepo.DeleteAlertConfig(repo.WithByID(id))
}
@@ -501,14 +690,17 @@ func (a AlertService) TestAlertConfig(req dto.AlertConfigTest) (bool, error) {
Body: i18n.GetMsgByKey("TestAlert"),
IsHTML: false,
}
transport := xpack.LoadRequestTransport()
transport := xpack.MultiNodeProvider.LoadRequestTransport()
if err := email.SendMail(cfg, msg, transport); err != nil {
return false, err
}
return true, nil
}
func (a AlertService) ExternalUpdateAlert(updateAlert dto.AlertCreate) error {
func (a AlertService) ExternalUpdateAlert(updateAlert dto.AlertCreate, operator string) error {
if err := a.validateCommunityAlertMethod(updateAlert.Method); err != nil {
return err
}
upMap := make(map[string]interface{})
var newStatus string
if updateAlert.SendCount == 0 {
@@ -552,7 +744,7 @@ func (a AlertService) ExternalUpdateAlert(updateAlert dto.AlertCreate) error {
} else {
if updateAlert.Method != "" && updateAlert.Title != "" {
updateAlert.Status = newStatus
if err := a.CreateAlert(updateAlert); err != nil {
if err := a.CreateAlert(updateAlert, operator); err != nil {
return err
}
}
+234 -104
View File
@@ -4,9 +4,11 @@ import (
"encoding/json"
"fmt"
"math"
"net"
"sort"
"strconv"
"strings"
"sync"
"time"
"github.com/1Panel-dev/1Panel/agent/app/dto"
@@ -23,7 +25,7 @@ import (
"github.com/shirou/gopsutil/v4/disk"
"github.com/shirou/gopsutil/v4/load"
"github.com/shirou/gopsutil/v4/mem"
"github.com/shirou/gopsutil/v4/net"
gnet "github.com/shirou/gopsutil/v4/net"
)
const (
@@ -34,7 +36,7 @@ const (
type AlertTaskHelper struct {
DiskIO chan []disk.IOCountersStat
NetIO chan []net.IOCountersStat
NetIO chan []gnet.IOCountersStat
}
type IAlertTaskHelper interface {
@@ -46,6 +48,7 @@ type IAlertTaskHelper interface {
var cpuLoad1, cpuLoad5, cpuLoad15 []float64
var memoryLoad1, memoryLoad5, memoryLoad15 []float64
var alertTaskMu sync.Mutex
var baseTypes = map[string]bool{"ssl": true, "siteEndTime": true, "panelPwdEndTime": true, "panelUpdate": true}
var resourceTypes = map[string]bool{"cpu": true, "memory": true, "disk": true, "load": true, "panelLogin": true, "sshLogin": true, "nodeException": true, "licenseException": true}
@@ -53,36 +56,53 @@ var resourceTypes = map[string]bool{"cpu": true, "memory": true, "disk": true, "
func NewIAlertTaskHelper() IAlertTaskHelper {
return &AlertTaskHelper{
DiskIO: make(chan []disk.IOCountersStat, 1),
NetIO: make(chan []net.IOCountersStat, 1),
NetIO: make(chan []gnet.IOCountersStat, 1),
}
}
func (m *AlertTaskHelper) StartTask() {
alertTaskMu.Lock()
defer alertTaskMu.Unlock()
m.startTaskLocked()
}
func (m *AlertTaskHelper) startTaskLocked() {
baseAlert, resourceAlert := m.getClassifiedAlerts()
if len(baseAlert) == 0 && len(resourceAlert) == 0 {
return
}
handleBaseAlerts(baseAlert)
handleResourceAlerts(resourceAlert)
handleBaseAlertsLocked(baseAlert)
handleResourceAlertsLocked(resourceAlert)
}
func (m *AlertTaskHelper) StopTask() {
stopBaseJob()
stopResourceJob()
alertTaskMu.Lock()
defer alertTaskMu.Unlock()
stopBaseJobLocked()
stopResourceJobLocked()
}
func (m *AlertTaskHelper) ResetTask() {
m.StopTask()
m.StartTask()
alertTaskMu.Lock()
defer alertTaskMu.Unlock()
stopBaseJobLocked()
stopResourceJobLocked()
m.startTaskLocked()
}
func (m *AlertTaskHelper) InitTask(alertType string) {
alertTaskMu.Lock()
defer alertTaskMu.Unlock()
m.initTaskLocked(alertType)
}
func (m *AlertTaskHelper) initTaskLocked(alertType string) {
resetAlertState(alertType)
if baseTypes[alertType] {
stopBaseJob()
stopBaseJobLocked()
} else if resourceTypes[alertType] {
stopResourceJob()
stopResourceJobLocked()
}
m.StartTask()
m.startTaskLocked()
}
func resetAlertState(alertType string) {
@@ -110,14 +130,14 @@ func (m *AlertTaskHelper) getClassifiedAlerts() (baseAlerts, resourceAlerts []dt
return
}
func handleBaseAlerts(baseAlerts []dto.AlertDTO) {
func handleBaseAlertsLocked(baseAlerts []dto.AlertDTO) {
if len(baseAlerts) == 0 {
stopBaseJob()
stopBaseJobLocked()
return
}
if global.AlertBaseJobID == 0 {
baseTask(baseAlerts)
jobID, err := global.Cron.AddFunc("*/30 * * * *", func() {
jobID, err := global.Cron.AddFunc("@every 30m", func() {
baseTask(baseAlerts)
})
if err != nil {
@@ -129,9 +149,9 @@ func handleBaseAlerts(baseAlerts []dto.AlertDTO) {
}
}
func handleResourceAlerts(resourceAlerts []dto.AlertDTO) {
func handleResourceAlertsLocked(resourceAlerts []dto.AlertDTO) {
if len(resourceAlerts) == 0 {
stopResourceJob()
stopResourceJobLocked()
return
}
if global.AlertResourceJobID == 0 {
@@ -147,7 +167,7 @@ func handleResourceAlerts(resourceAlerts []dto.AlertDTO) {
}
}
func stopBaseJob() {
func stopBaseJobLocked() {
if global.AlertBaseJobID != 0 {
global.Cron.Remove(global.AlertBaseJobID)
global.AlertBaseJobID = 0
@@ -155,7 +175,7 @@ func stopBaseJob() {
}
}
func stopResourceJob() {
func stopResourceJobLocked() {
if global.AlertResourceJobID != 0 {
global.Cron.Remove(global.AlertResourceJobID)
global.AlertResourceJobID = 0
@@ -174,10 +194,16 @@ func baseTask(baseAlert []dto.AlertDTO) {
case "siteEndTime":
loadWebsiteInfo(alert)
case "panelPwdEndTime":
if global.CONF.Base.IsEnterprise {
continue
}
if global.IsMaster {
loadPanelPwd(alert)
}
case "panelUpdate":
if global.CONF.Base.IsEnterprise {
continue
}
if global.IsMaster {
loadPanelUpdate(alert)
}
@@ -210,6 +236,9 @@ func resourceTask(resourceAlert []dto.AlertDTO) {
loadNodeException(alert)
}
case "licenseException":
if global.CONF.Base.IsEnterprise {
continue
}
if execute && global.IsMaster {
loadLicenseException(alert)
}
@@ -457,6 +486,7 @@ func loadPanelLogin(alert dto.AlertDTO) {
if err != nil {
global.LOG.Errorf("Failed to check recent failed ip login logs: %v", err)
}
records = filterLoginLogsNotInWhitelist(records, whitelist)
if len(records) > 0 {
quota := strings.Join(func() []string {
var ips []string
@@ -506,6 +536,7 @@ func loadSSHLogin(alert dto.AlertDTO) {
if err != nil {
global.LOG.Errorf("Failed to check recent failed ip ssh login logs: %v", err)
}
records = filterSSHLoginEntriesNotInWhitelist(records, whitelist)
if len(records) > 0 {
quota := strings.Join(records, "\n")
params := []dto.Param{
@@ -524,9 +555,63 @@ func loadSSHLogin(alert dto.AlertDTO) {
}
}
func filterLoginLogsNotInWhitelist(records []model.LoginLog, whitelist []string) []model.LoginLog {
filtered := make([]model.LoginLog, 0, len(records))
for _, record := range records {
if !isIPInWhitelist(record.IP, whitelist) {
filtered = append(filtered, record)
}
}
return filtered
}
func filterSSHLoginEntriesNotInWhitelist(records []string, whitelist []string) []string {
filtered := make([]string, 0, len(records))
for _, record := range records {
ip := record
if idx := strings.Index(record, "-"); idx >= 0 {
ip = record[:idx]
}
if !isIPInWhitelist(ip, whitelist) {
filtered = append(filtered, record)
}
}
return filtered
}
func isIPInWhitelist(ip string, whitelist []string) bool {
targetIP := net.ParseIP(strings.TrimSpace(ip))
if targetIP == nil {
return false
}
for _, item := range whitelist {
item = strings.TrimSpace(item)
if item == "" {
continue
}
if item == ip {
return true
}
if whiteIP := net.ParseIP(item); whiteIP != nil {
if whiteIP.Equal(targetIP) {
return true
}
continue
}
_, ipNet, err := net.ParseCIDR(item)
if err != nil {
continue
}
if ipNet.Contains(targetIP) {
return true
}
}
return false
}
func loadNodeException(alert dto.AlertDTO) {
// only master alert
failCount, err := xpack.GetNodeErrorAlert()
failCount, err := xpack.AlertProvider.GetNodeErrorAlert()
if err != nil {
global.LOG.Errorf("error getting node, err: %s", err)
return
@@ -555,7 +640,7 @@ func loadNodeException(alert dto.AlertDTO) {
func loadLicenseException(alert dto.AlertDTO) {
// only master alert
failCount, err := xpack.GetLicenseErrorAlert()
failCount, err := xpack.AlertProvider.GetLicenseErrorAlert()
if err != nil {
global.LOG.Errorf("error getting license, err: %s", err)
return
@@ -590,94 +675,139 @@ func sendAlerts(alert dto.AlertDTO, alertType, quota, quotaType string, params [
if newDate.IsZero() || calculateMinutesDifference(newDate) > ResourceAlertInterval {
for _, m := range methods {
m = strings.TrimSpace(m)
switch m {
case constant.SMS:
if !alertUtil.CheckSMSSendLimit(constant.SMS) {
continue
}
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, constant.SMS)
if !isValid {
continue
}
create := dto.AlertLogCreate{
Type: alertType,
AlertId: alert.ID,
Count: todayCount + 1,
}
alertErr := xpack.CreateSMSAlertLog(alertType, alert, create, quotaType, params, constant.SMS)
if alertErr != nil {
global.LOG.Infof("%s alert sms push faild, err: %v", alertType, alertErr.Error())
continue
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, constant.SMS)
case constant.Email:
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, constant.Email)
if !isValid {
continue
}
create := dto.AlertLogCreate{
Type: alertType,
AlertId: alert.ID,
Count: todayCount + 1,
}
alertInfo := alert
alertInfo.Type = alertType
create.AlertRule = alertUtil.ProcessAlertRule(alert)
create.AlertDetail = alertUtil.ProcessAlertDetail(alertInfo, quotaType, params, constant.Email)
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
alertErr := alertUtil.CreateEmailAlertLog(create, alertInfo, params, transport, agentInfo)
if alertErr != nil {
global.LOG.Infof("%s alert email push faild, err: %v", alertType, alertErr.Error())
continue
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, constant.Email)
case constant.WeCom, constant.DingTalk, constant.FeiShu:
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, m)
if !isValid {
continue
}
var create = dto.AlertLogCreate{
Type: alertUtil.GetCronJobType(alert.Type),
AlertId: alert.ID,
Count: todayCount + 1,
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
err := xpack.CreateWebhookAlertLog(alertType, alert, create, quotaType, params, m, transport, agentInfo)
if err != nil {
global.LOG.Infof("%s alert webhook %s push faild, err: %v", alertType, m, err)
continue
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, m)
case constant.Bark:
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, m)
if !isValid {
continue
}
var create = dto.AlertLogCreate{
Type: alertUtil.GetCronJobType(alert.Type),
AlertId: alert.ID,
Count: todayCount + 1,
}
alertInfo := alert
alertInfo.Type = alertType
create.AlertRule = alertUtil.ProcessAlertRule(alert)
create.AlertDetail = alertUtil.ProcessAlertDetail(alertInfo, quotaType, params, m)
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
alertErr := alertUtil.CreateBarkAlertLog(create, alertInfo, params, transport, agentInfo)
if alertErr != nil {
global.LOG.Infof("%s alert %s push failed, err: %v", alertType, m, alertErr.Error())
continue
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, m)
default:
if configId, err := strconv.ParseUint(m, 10, 64); err == nil {
sendAlertsByConfigId(alert, alertType, quota, quotaType, params, uint(configId))
} else {
sendAlertsByLegacyMethod(alert, alertType, quota, quotaType, params, m)
}
}
}
}
func sendAlertsByConfigId(alert dto.AlertDTO, alertType, quota, quotaType string, params []dto.Param, configId uint) {
config, err := alertRepo.GetConfigById(configId)
if err != nil {
global.LOG.Errorf("alert config not found for id %d: %v", configId, err)
return
}
doSendAlert(alert, alertType, quota, quotaType, params, config)
}
func sendAlertsByLegacyMethod(alert dto.AlertDTO, alertType, quota, quotaType string, params []dto.Param, method string) {
typeMap := map[string]string{
"mail": constant.Email,
constant.Bark: constant.Bark,
constant.SMS: constant.SMS,
}
configType, ok := typeMap[method]
if !ok {
configType = method
}
config, err := alertRepo.GetConfig(alertRepo.WithByType(configType))
if err != nil {
global.LOG.Errorf("alert config not found for type %s: %v", configType, err)
return
}
doSendAlert(alert, alertType, quota, quotaType, params, config)
}
func doSendAlert(alert dto.AlertDTO, alertType, quota, quotaType string, params []dto.Param, config model.AlertConfig) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
methodStr := strconv.Itoa(int(config.ID))
switch config.Type {
case constant.SMS:
if !alertUtil.CheckSMSSendLimit(config, methodStr) {
return
}
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, methodStr)
if !isValid {
return
}
create := dto.AlertLogCreate{
Type: alertType,
AlertId: alert.ID,
Count: todayCount + 1,
Method: methodStr,
}
alertErr := xpack.AlertProvider.CreateSMSAlertLog(alertType, alert, create, quotaType, params, config, methodStr)
if alertErr != nil {
global.LOG.Infof("%s alert sms push faild, err: %v", alertType, alertErr.Error())
return
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, methodStr)
case constant.Email:
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, methodStr)
if !isValid {
return
}
create := dto.AlertLogCreate{
Type: alertType,
AlertId: alert.ID,
Count: todayCount + 1,
Method: methodStr,
}
alertInfo := alert
alertInfo.Type = alertType
create.AlertRule = alertUtil.ProcessAlertRule(alert)
create.AlertDetail = alertUtil.ProcessAlertDetail(alertInfo, quotaType, params, constant.Email)
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
alertErr := alertUtil.CreateEmailAlertLog(create, alertInfo, params, transport, agentInfo, config)
if alertErr != nil {
global.LOG.Infof("%s alert email push faild, err: %v", alertType, alertErr.Error())
return
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, methodStr)
case constant.Bark:
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, methodStr)
if !isValid {
return
}
create := dto.AlertLogCreate{
Type: alertType,
AlertId: alert.ID,
Count: todayCount + 1,
Method: methodStr,
}
alertInfo := alert
alertInfo.Type = alertType
create.AlertRule = alertUtil.ProcessAlertRule(alert)
create.AlertDetail = alertUtil.ProcessAlertDetail(alertInfo, quotaType, params, constant.Bark)
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
alertErr := alertUtil.CreateBarkAlertLog(create, alertInfo, params, transport, agentInfo, config)
if alertErr != nil {
global.LOG.Infof("%s alert %s push failed, err: %v", alertType, methodStr, alertErr.Error())
return
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, methodStr)
case constant.WeCom, constant.DingTalk, constant.FeiShu:
todayCount, isValid := canSendAlertToday(alertType, quotaType, alert.SendCount, methodStr)
if !isValid {
return
}
create := dto.AlertLogCreate{
Type: alertType,
AlertId: alert.ID,
Count: todayCount + 1,
Method: methodStr,
}
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
alertErr := xpack.AlertProvider.CreateWebhookAlertLog(alertType, alert, create, quotaType, params, config, transport, agentInfo)
if alertErr != nil {
global.LOG.Infof("%s alert webhook %s push faild, err: %v", alertType, methodStr, alertErr)
return
}
alertUtil.CreateNewAlertTask(quota, alertType, quotaType, methodStr)
}
}
// ------------------------------
func getRepoOptionsByProject(project string) []repo.DBOption {
var opts []repo.DBOption
+277 -124
View File
@@ -1,12 +1,16 @@
package service
import (
"strconv"
"strings"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/app/repo"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
alertUtil "github.com/1Panel-dev/1Panel/agent/utils/alert"
"github.com/1Panel-dev/1Panel/agent/utils/xpack"
"strings"
)
type AlertSender struct {
@@ -22,115 +26,91 @@ func NewAlertSender(alert dto.AlertDTO, quotaType string) *AlertSender {
}
func (s *AlertSender) Send(quota string, params []dto.Param) {
methods := strings.Split(s.alert.Method, ",")
for _, method := range methods {
method = strings.TrimSpace(method)
switch method {
case constant.SMS:
s.sendSMS(quota, params)
case constant.Email:
s.sendEmail(quota, params)
case constant.Bark:
s.sendBark(quota, params)
case constant.WeCom, constant.DingTalk, constant.FeiShu:
s.sendWebhook(quota, params, method)
}
}
s.sendByConfigIds(s.alert.Method, quota, params, false)
}
func (s *AlertSender) ResourceSend(quota string, params []dto.Param) {
methods := strings.Split(s.alert.Method, ",")
for _, method := range methods {
method = strings.TrimSpace(method)
switch method {
case constant.SMS:
s.sendResourceSMS(quota, params)
case constant.Email:
s.sendResourceEmail(quota, params)
case constant.Bark:
s.sendResourceBark(quota, params)
case constant.WeCom, constant.DingTalk, constant.FeiShu:
s.sendResourceWebhook(quota, params, method)
s.sendByConfigIds(s.alert.Method, quota, params, true)
}
func (s *AlertSender) sendByConfigIds(methodStr string, quota string, params []dto.Param, isResource bool) {
alertRepo := repo.NewIAlertRepo()
configIds := strings.Split(methodStr, ",")
for _, idStr := range configIds {
idStr = strings.TrimSpace(idStr)
configId, err := strconv.ParseUint(idStr, 10, 64)
if err != nil {
s.sendByLegacyMethod(idStr, quota, params, isResource)
continue
}
config, err := alertRepo.GetConfigById(uint(configId))
if err != nil {
global.LOG.Errorf("alert config not found for id %d: %v", configId, err)
continue
}
s.sendByConfig(config, quota, params, isResource)
}
}
func (s *AlertSender) sendByConfig(config model.AlertConfig, quota string, params []dto.Param, isResource bool) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
switch config.Type {
case constant.SMS:
if isResource {
s.sendResourceSMSWithConfig(config, quota, params)
} else {
s.sendSMSWithConfig(config, quota, params)
}
case constant.Email:
if isResource {
s.sendResourceEmailWithConfig(config, quota, params)
} else {
s.sendEmailWithConfig(config, quota, params)
}
case constant.Bark:
if isResource {
s.sendResourceBarkWithConfig(config, quota, params)
} else {
s.sendBarkWithConfig(config, quota, params)
}
case constant.WeCom, constant.DingTalk, constant.FeiShu:
if isResource {
s.sendResourceWebhookWithConfig(config, quota, params)
} else {
s.sendWebhookWithConfig(config, quota, params)
}
}
}
func (s *AlertSender) sendSMS(quota string, params []dto.Param) {
if !alertUtil.CheckSMSSendLimit(constant.SMS) {
return
func (s *AlertSender) sendByLegacyMethod(method string, quota string, params []dto.Param, isResource bool) {
alertRepo := repo.NewIAlertRepo()
typeMap := map[string]string{"mail": constant.Email, constant.Bark: constant.Bark, constant.SMS: constant.SMS}
configType := method
if mapped, ok := typeMap[method]; ok {
configType = mapped
}
totalCount, isValid := s.canSendAlert(constant.SMS)
if !isValid {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
}
err := xpack.CreateSMSAlertLog(s.alert.Type, s.alert, create, quota, params, constant.SMS)
config, err := alertRepo.GetConfig(alertRepo.WithByType(configType))
if err != nil {
global.LOG.Errorf("%s alert sms push failed: %v", s.alert.Type, err)
global.LOG.Errorf("alert config not found for type %s: %v", configType, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, constant.SMS)
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
s.sendByConfig(config, quota, params, isResource)
}
func (s *AlertSender) sendEmail(quota string, params []dto.Param) {
totalCount, isValid := s.canSendAlert(constant.Email)
if !isValid {
func (s *AlertSender) sendSMSWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
method := strconv.Itoa(int(config.ID))
if !alertUtil.CheckSMSSendLimit(config, method) {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
AlertRule: alertUtil.ProcessAlertRule(s.alert),
AlertDetail: alertUtil.ProcessAlertDetail(s.alert, quota, params, constant.Email),
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
err := alertUtil.CreateEmailAlertLog(create, s.alert, params, transport, agentInfo)
if err != nil {
global.LOG.Errorf("%s alert email push failed: %v", s.alert.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, constant.Email)
}
func (s *AlertSender) sendBark(quota string, params []dto.Param) {
totalCount, isValid := s.canSendAlert(constant.Bark)
if !isValid {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
AlertRule: alertUtil.ProcessAlertRule(s.alert),
AlertDetail: alertUtil.ProcessAlertDetail(s.alert, quota, params, constant.Bark),
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
err := alertUtil.CreateBarkAlertLog(create, s.alert, params, transport, agentInfo)
if err != nil {
global.LOG.Errorf("%s alert bark push failed: %v", s.alert.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, constant.Bark)
}
func (s *AlertSender) sendWebhook(quota string, params []dto.Param, method string) {
totalCount, isValid := s.canSendAlert(method)
if !isValid {
return
@@ -141,43 +121,60 @@ func (s *AlertSender) sendWebhook(quota string, params []dto.Param, method strin
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
Method: method,
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
err := xpack.CreateWebhookAlertLog(s.alert.Type, s.alert, create, quota, params, method, transport, agentInfo)
err := xpack.AlertProvider.CreateSMSAlertLog(s.alert.Type, s.alert, create, quota, params, config, method)
if err != nil {
global.LOG.Errorf("%s alert %s webhook push failed: %v", s.alert.Type, method, err)
global.LOG.Errorf("%s alert sms push failed: %v", s.alert.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, method)
}
func (s *AlertSender) sendResourceSMS(quota string, params []dto.Param) {
if !alertUtil.CheckSMSSendLimit(constant.SMS) {
func (s *AlertSender) sendSMS(quota string, params []dto.Param) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(constant.SMS))
if err != nil {
return
}
s.sendSMSWithConfig(config, quota, params)
}
todayCount, isValid := s.canResourceSendAlert(constant.SMS)
func (s *AlertSender) sendEmailWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
totalCount, isValid := s.canSendAlert(strconv.Itoa(int(config.ID)))
if !isValid {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: todayCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
Status: constant.AlertSuccess,
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
AlertRule: alertUtil.ProcessAlertRule(s.alert),
AlertDetail: alertUtil.ProcessAlertDetail(s.alert, quota, params, constant.Email),
Method: strconv.Itoa(int(config.ID)),
}
if err := xpack.CreateSMSAlertLog(s.alert.Type, s.alert, create, quota, params, constant.SMS); err != nil {
global.LOG.Errorf("failed to send SMS alert: %v", err)
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
err := alertUtil.CreateEmailAlertLog(create, s.alert, params, transport, agentInfo, config)
if err != nil {
global.LOG.Errorf("%s alert email push failed: %v", s.alert.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, constant.SMS)
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, strconv.Itoa(int(config.ID)))
}
func (s *AlertSender) sendResourceEmail(quota string, params []dto.Param) {
todayCount, isValid := s.canResourceSendAlert(constant.Email)
func (s *AlertSender) sendResourceEmailWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
todayCount, isValid := s.canResourceSendAlert(strconv.Itoa(int(config.ID)))
if !isValid {
return
}
@@ -189,19 +186,70 @@ func (s *AlertSender) sendResourceEmail(quota string, params []dto.Param) {
Type: s.alert.Type,
AlertRule: alertUtil.ProcessAlertRule(s.alert),
AlertDetail: alertUtil.ProcessAlertDetail(s.alert, quota, params, constant.Email),
Method: strconv.Itoa(int(config.ID)),
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
if err := alertUtil.CreateEmailAlertLog(create, s.alert, params, transport, agentInfo); err != nil {
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
if err := alertUtil.CreateEmailAlertLog(create, s.alert, params, transport, agentInfo, config); err != nil {
global.LOG.Errorf("failed to send Email alert: %v", err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, constant.Email)
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, strconv.Itoa(int(config.ID)))
}
func (s *AlertSender) sendResourceBark(quota string, params []dto.Param) {
todayCount, isValid := s.canResourceSendAlert(constant.Bark)
func (s *AlertSender) sendEmail(quota string, params []dto.Param) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(constant.EmailConfig))
if err != nil {
return
}
s.sendEmailWithConfig(config, quota, params)
}
func (s *AlertSender) sendResourceEmail(quota string, params []dto.Param) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(constant.EmailConfig))
if err != nil {
return
}
s.sendResourceEmailWithConfig(config, quota, params)
}
func (s *AlertSender) sendBarkWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
totalCount, isValid := s.canSendAlert(strconv.Itoa(int(config.ID)))
if !isValid {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
AlertRule: alertUtil.ProcessAlertRule(s.alert),
AlertDetail: alertUtil.ProcessAlertDetail(s.alert, quota, params, constant.Bark),
Method: strconv.Itoa(int(config.ID)),
}
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
err := alertUtil.CreateBarkAlertLog(create, s.alert, params, transport, agentInfo, config)
if err != nil {
global.LOG.Errorf("%s alert bark push failed: %v", s.alert.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, strconv.Itoa(int(config.ID)))
}
func (s *AlertSender) sendResourceBarkWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
todayCount, isValid := s.canResourceSendAlert(strconv.Itoa(int(config.ID)))
if !isValid {
return
}
@@ -213,18 +261,114 @@ func (s *AlertSender) sendResourceBark(quota string, params []dto.Param) {
Type: s.alert.Type,
AlertRule: alertUtil.ProcessAlertRule(s.alert),
AlertDetail: alertUtil.ProcessAlertDetail(s.alert, quota, params, constant.Bark),
Method: strconv.Itoa(int(config.ID)),
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
if err := alertUtil.CreateBarkAlertLog(create, s.alert, params, transport, agentInfo); err != nil {
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
if err := alertUtil.CreateBarkAlertLog(create, s.alert, params, transport, agentInfo, config); err != nil {
global.LOG.Errorf("failed to send Bark alert: %v", err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, constant.Bark)
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, strconv.Itoa(int(config.ID)))
}
func (s *AlertSender) sendBark(quota string, params []dto.Param) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(constant.Bark))
if err != nil {
return
}
s.sendBarkWithConfig(config, quota, params)
}
func (s *AlertSender) sendResourceBark(quota string, params []dto.Param) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(constant.Bark))
if err != nil {
return
}
s.sendResourceBarkWithConfig(config, quota, params)
}
func (s *AlertSender) sendWebhookWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
totalCount, isValid := s.canSendAlert(strconv.Itoa(int(config.ID)))
if !isValid {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: totalCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
Method: strconv.Itoa(int(config.ID)),
}
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
err := xpack.AlertProvider.CreateWebhookAlertLog(s.alert.Type, s.alert, create, quota, params, config, transport, agentInfo)
if err != nil {
global.LOG.Errorf("%s alert %s webhook push failed: %v", s.alert.Type, config.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, strconv.Itoa(int(config.ID)))
}
func (s *AlertSender) sendResourceWebhookWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
todayCount, isValid := s.canResourceSendAlert(strconv.Itoa(int(config.ID)))
if !isValid {
return
}
create := dto.AlertLogCreate{
Status: constant.AlertSuccess,
Count: todayCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
Method: strconv.Itoa(int(config.ID)),
}
transport := xpack.MultiNodeProvider.LoadRequestTransport()
agentInfo, _ := xpack.MultiNodeProvider.GetAgentInfo()
if err := xpack.AlertProvider.CreateWebhookAlertLog(s.alert.Type, s.alert, create, quota, params, config, transport, agentInfo); err != nil {
global.LOG.Errorf("%s alert %s webhook push failed: %v", s.alert.Type, config.Type, err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, strconv.Itoa(int(config.ID)))
}
func (s *AlertSender) sendWebhook(quota string, params []dto.Param, method string) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(method))
if err != nil {
return
}
s.sendWebhookWithConfig(config, quota, params)
}
func (s *AlertSender) sendResourceWebhook(quota string, params []dto.Param, method string) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(method))
if err != nil {
return
}
s.sendResourceWebhookWithConfig(config, quota, params)
}
func (s *AlertSender) sendResourceSMSWithConfig(config model.AlertConfig, quota string, params []dto.Param) {
if !alertUtil.IsAlertConfigEnabled(config) {
return
}
method := strconv.Itoa(int(config.ID))
if !alertUtil.CheckSMSSendLimit(config, method) {
return
}
todayCount, isValid := s.canResourceSendAlert(method)
if !isValid {
return
@@ -235,16 +379,25 @@ func (s *AlertSender) sendResourceWebhook(quota string, params []dto.Param, meth
Count: todayCount + 1,
AlertId: s.alert.ID,
Type: s.alert.Type,
Method: method,
}
transport := xpack.LoadRequestTransport()
agentInfo, _ := xpack.GetAgentInfo()
if err := xpack.CreateWebhookAlertLog(s.alert.Type, s.alert, create, quota, params, method, transport, agentInfo); err != nil {
global.LOG.Errorf("%s alert %s webhook push failed: %v", s.alert.Type, method, err)
if err := xpack.AlertProvider.CreateSMSAlertLog(s.alert.Type, s.alert, create, quota, params, config, method); err != nil {
global.LOG.Errorf("failed to send SMS alert: %v", err)
return
}
alertUtil.CreateNewAlertTask(quota, s.alert.Type, s.quotaType, method)
}
func (s *AlertSender) sendResourceSMS(quota string, params []dto.Param) {
alertRepo := repo.NewIAlertRepo()
config, err := alertRepo.GetConfig(alertRepo.WithByType(constant.SMSConfig))
if err != nil {
return
}
s.sendResourceSMSWithConfig(config, quota, params)
}
func (s *AlertSender) canSendAlert(method string) (uint, bool) {
todayCount, totalCount, err := alertRepo.LoadTaskCount(s.alert.Type, s.quotaType, method)
if err != nil {
+2 -2
View File
@@ -126,7 +126,7 @@ func (a AppService) PageApp(ctx *gin.Context, req request.AppSearch) (*response.
lang := strings.ToLower(common.GetLang(ctx))
for _, ap := range apps {
if req.Type == "php" {
if !global.CONF.Base.IsOffLine && (ap.RequiredPanelVersion == 0 || !common.CompareAppVersion(common.GetSystemVersion(info.SystemVersion), fmt.Sprintf("%f", ap.RequiredPanelVersion))) {
if !global.CONF.Base.IsOffline && (ap.RequiredPanelVersion == 0 || !common.CompareAppVersion(common.GetSystemVersion(info.SystemVersion), fmt.Sprintf("%f", ap.RequiredPanelVersion))) {
continue
}
}
@@ -966,7 +966,7 @@ func deleteCustomApp() {
}
func (a AppService) SyncAppListFromRemote(taskID string) (err error) {
if xpack.IsUseCustomApp() {
if xpack.MultiNodeProvider.IsUseCustomApp() {
return nil
}
+6 -1
View File
@@ -589,7 +589,12 @@ func (a *AppInstallService) GetUpdateVersions(req request.AppUpdateVersion) ([]d
if common.IsCrossVersion(install.Version, detail.Version) && !app.CrossVersionUpdate {
continue
}
if common.CompareVersion(detail.Version, install.Version) {
canUpgrade := common.CompareVersion(detail.Version, install.Version)
if app.Key == vllmAppKeyForUpgrade {
currentImage := loadVllmImageFromEnv(install.Env)
canUpgrade = isVllmUpgradeCandidate(install.Version, detail.Version, currentImage)
}
if canUpgrade {
var newCompose string
if req.UpdateVersion != "" && req.UpdateVersion == detail.Version && detail.DockerCompose == "" && !app.IsLocalApp() {
filename := filepath.Base(detail.DownloadUrl)
+4 -4
View File
@@ -82,7 +82,7 @@ func (a AppService) createSyncAppStoreTask(sharedCtx **appSyncContext) func(t *t
ctx := &appSyncContext{
task: t,
httpClient: http.Client{Timeout: time.Duration(constant.TimeOut20s) * time.Second, Transport: xpack.LoadRequestTransport()},
httpClient: http.Client{Timeout: time.Duration(constant.TimeOut20s) * time.Second, Transport: xpack.MultiNodeProvider.LoadRequestTransport()},
baseRemoteUrl: fmt.Sprintf("%s/%s/1panel", global.AppRepoURL(), global.CONF.Base.Mode),
systemVersion: setting.SystemVersion,
settingService: settingService,
@@ -279,9 +279,9 @@ func (c *appSyncContext) syncAppIconsAndDetails() error {
}()
var (
completed int
icon200Count int
icon304Count int
completed int
icon200Count int
icon304Count int
iconFailCount int
)
milestones := [4]int{totalWork / 4, totalWork / 2, totalWork * 3 / 4, totalWork}
+82 -12
View File
@@ -665,7 +665,7 @@ func buildNginx(parentTask *task.Task) error {
logStr := fmt.Sprintf("%s %s", i18n.GetMsgByKey("TaskBuild"), i18n.GetMsgByKey("Image"))
parentTask.LogStart(logStr)
cmdMgr := cmd.NewCommandMgr(cmd.WithTask(*parentTask), cmd.WithTimeout(60*time.Minute))
if err = cmdMgr.RunBashCf("docker compose -f %s build", nginxInstall.GetComposePath()); err != nil {
if err = cmdMgr.Run("docker", "compose", "-f", nginxInstall.GetComposePath(), "build"); err != nil {
return err
}
parentTask.LogSuccess(logStr)
@@ -682,6 +682,9 @@ func upgradeInstall(req request.AppInstallUpgrade) error {
if err != nil {
return err
}
if install.App.Key == vllmAppKeyForUpgrade && !isVllmUpgradeVersionAllowed(install.Version, detail.Version, loadVllmImageFromEnv(install.Env)) {
return errors.New("vLLM can only upgrade within the same image type")
}
if install.Version == detail.Version {
return errors.New("two version is same")
}
@@ -748,9 +751,25 @@ func upgradeInstall(req request.AppInstallUpgrade) error {
if err != nil {
return err
}
dockerCLi, _ := docker.NewClient()
if install.App.Key == vllmAppKeyForUpgrade {
envs := make(map[string]interface{})
if err = json.Unmarshal([]byte(install.Env), &envs); err != nil {
return err
}
image := buildVllmUpgradeImage(loadVllmImageFromEnv(install.Env), oldVersion, detail.Version)
envs[vllmImageEnvKey] = image
paramByte, err := json.Marshal(envs)
if err != nil {
return err
}
install.Env = string(paramByte)
content = setVllmImageInEnvContent(content, image)
}
if req.PullImage {
composeContent := []byte(detail.DockerCompose)
if install.App.Key == vllmAppKeyForUpgrade {
composeContent = []byte(install.DockerCompose)
}
if req.DockerCompose != "" {
composeContent = []byte(req.DockerCompose)
}
@@ -758,18 +777,31 @@ func upgradeInstall(req request.AppInstallUpgrade) error {
if err != nil {
return err
}
dockerCLi, err := docker.NewClient()
if err != nil {
return err
}
defer dockerCLi.Close()
for _, image := range images {
t.Log(i18n.GetWithName("PullImageStart", image))
if err = dockerCLi.PullImageWithProcess(t, image); err != nil {
err = buserr.WithNameAndErr("ErrDockerPullImage", "", err)
return err
}
exist, err := dockerCLi.ImageExists(image)
if err != nil {
err = buserr.WithNameAndErr("ErrDockerPullImage", "", err)
return err
}
if !exist {
err = buserr.WithNameAndErr("ErrDockerPullImage", "", fmt.Errorf("image %s not found", image))
return err
}
t.LogSuccess(i18n.GetMsgByKey("PullImage"))
}
}
command := exec.Command("/bin/bash", "-c", fmt.Sprintf("cp -rn %s/* %s || true", detailDir, install.GetPath()))
_, _ = command.CombinedOutput()
_ = copyAppDetailMissing(fileOp, detailDir, install.GetPath())
if install.App.Key == constant.AppOpenresty {
installBuildDir := path.Join(install.GetPath(), "build")
detailBuildDir := path.Join(detailDir, "build")
@@ -808,9 +840,13 @@ func upgradeInstall(req request.AppInstallUpgrade) error {
return err
}
if req.DockerCompose == "" {
newCompose, err = getUpgradeCompose(install, detail)
if err != nil {
return err
if install.App.Key == vllmAppKeyForUpgrade {
newCompose = install.DockerCompose
} else {
newCompose, err = getUpgradeCompose(install, detail)
if err != nil {
return err
}
}
} else {
newCompose = req.DockerCompose
@@ -885,7 +921,7 @@ func upgradeInstall(req request.AppInstallUpgrade) error {
}
}
upgradeTask.AddSubTaskWithOps(task.GetTaskName(install.Name, task.TaskScopeApp, task.TaskUpgrade), upgradeApp, rollBackApp, 0, 1*time.Hour)
upgradeTask.AddSubTaskWithOps(task.GetTaskName(install.Name, task.TaskUpgrade, task.TaskScopeApp), upgradeApp, rollBackApp, 0, 1*time.Hour)
go func() {
err = upgradeTask.Execute()
@@ -1129,7 +1165,7 @@ func runScript(task *task.Task, appInstall *model.AppInstall, operate string) er
task.LogStart(logStr)
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(10*time.Minute), cmd.WithWorkDir(workDir))
if err := cmdMgr.RunBashC(scriptPath); err != nil {
if err := cmdMgr.Run("bash", scriptPath); err != nil {
task.LogFailedWithErr(logStr, err)
return err
}
@@ -1178,11 +1214,12 @@ func upApp(task *task.Task, appInstall *model.AppInstall, pullImages bool) error
if err != nil {
return err
}
imagePrefix := xpack.GetImagePrefix()
imagePrefix := xpack.MultiNodeProvider.GetImagePrefix()
dockerCLi, err := docker.NewClient()
if err != nil {
return err
}
defer dockerCLi.Close()
for _, image := range images {
if imagePrefix != "" {
lastSlashIndex := strings.LastIndex(image, "/")
@@ -1778,7 +1815,7 @@ func addDockerComposeCommonParam(composeMap map[string]interface{}, serviceName
if !serviceValid {
return buserr.New("ErrFileParse")
}
imagePreFix := xpack.GetImagePrefix()
imagePreFix := xpack.MultiNodeProvider.GetImagePrefix()
if imagePreFix != "" {
for _, service := range services {
serviceValue := service.(map[string]interface{})
@@ -1935,6 +1972,39 @@ func isHostModel(dockerCompose string) bool {
return false
}
func copyAppDetailMissing(fileOp files.FileOp, srcDir, dstDir string) error {
entries, err := os.ReadDir(srcDir)
if err != nil {
return err
}
for _, entry := range entries {
if strings.HasPrefix(entry.Name(), ".") {
continue
}
srcPath := path.Join(srcDir, entry.Name())
dstPath := path.Join(dstDir, entry.Name())
if !fileOp.Stat(dstPath) {
if entry.IsDir() {
if err := fileOp.CopyDir(srcPath, dstDir); err != nil {
return err
}
continue
}
if err := fileOp.CopyFile(srcPath, dstDir); err != nil {
return err
}
continue
}
if !entry.IsDir() {
continue
}
if err := copyAppDetailMissing(fileOp, srcPath, dstPath); err != nil {
return err
}
}
return nil
}
func getRestartPolicy(yml string) string {
var project docker.ComposeProject
if err := yaml.Unmarshal([]byte(yml), &project); err != nil {
@@ -2121,7 +2191,7 @@ func handleSSLConfig(appInstall *model.AppInstall, hasDefaultWebsite bool, sslRe
caRequest := request.WebsiteCAObtain{
ID: ca.ID,
Domains: "localhost",
KeyType: "4096",
KeyType: "RSA4096",
Time: 99,
Unit: "year",
Dir: sslDir,
+57 -20
View File
@@ -5,6 +5,7 @@ import (
"encoding/json"
"fmt"
"io/fs"
"net/netip"
"os"
"path"
"sort"
@@ -595,35 +596,22 @@ func stepRecreateContainer(recoverCtx *containerRecoverContext, taskItem *task.T
return err
}
networkConfig, extraNetworks := buildContainerRecoverNetworkConfig(recoverCtx.inspectInfo.NetworkSettings, hostConfig)
removeBridgeDriverIPAM(recoverCtx.client, networkConfig, extraNetworks)
createRes, err := recoverCtx.client.ContainerCreate(ctx, config, hostConfig, networkConfig, nil, recoverCtx.targetName)
createRes, err := createContainerWithOldNetworks(ctx, recoverCtx.client, config, hostConfig, recoverCtx.inspectInfo.NetworkSettings, recoverCtx.targetName)
if err != nil {
return err
}
recoverCtx.createdContainerID = createRes.ID
extraNames := make([]string, 0, len(extraNetworks))
for name := range extraNetworks {
extraNames = append(extraNames, name)
}
sort.Strings(extraNames)
for _, item := range extraNames {
if err := recoverCtx.client.NetworkConnect(ctx, item, recoverCtx.createdContainerID, extraNetworks[item]); err != nil {
return err
}
}
return nil
}
func removeBridgeDriverIPAM(cli *client.Client, primary *network.NetworkingConfig, extras map[string]*network.EndpointSettings) {
func removeUnsupportedEndpointStaticIPAM(cli *client.Client, primary *network.NetworkingConfig, extras map[string]*network.EndpointSettings) {
if primary != nil {
removeBridgeDriverIPAMFromEndpoints(cli, primary.EndpointsConfig)
removeUnsupportedEndpointStaticIPAMFromEndpoints(cli, primary.EndpointsConfig)
}
removeBridgeDriverIPAMFromEndpoints(cli, extras)
removeUnsupportedEndpointStaticIPAMFromEndpoints(cli, extras)
}
func removeBridgeDriverIPAMFromEndpoints(cli *client.Client, endpoints map[string]*network.EndpointSettings) {
func removeUnsupportedEndpointStaticIPAMFromEndpoints(cli *client.Client, endpoints map[string]*network.EndpointSettings) {
for netName, endpoint := range endpoints {
if endpoint == nil || endpoint.IPAMConfig == nil {
continue
@@ -632,10 +620,59 @@ func removeBridgeDriverIPAMFromEndpoints(cli *client.Client, endpoints map[strin
if err != nil {
continue
}
if info.Driver == "bridge" {
endpoint.IPAMConfig = nil
removeUnsupportedEndpointStaticIP(netName, info, endpoint)
}
}
func removeUnsupportedEndpointStaticIP(netName string, info network.Inspect, endpoint *network.EndpointSettings) {
if endpoint == nil || endpoint.IPAMConfig == nil {
return
}
if isDefaultBridgeNetwork(netName, info) {
endpoint.IPAMConfig = nil
return
}
if endpoint.IPAMConfig.IPv4Address != "" && !networkSupportsStaticIP(info, endpoint.IPAMConfig.IPv4Address, false) {
endpoint.IPAMConfig.IPv4Address = ""
}
if endpoint.IPAMConfig.IPv6Address != "" && !networkSupportsStaticIP(info, endpoint.IPAMConfig.IPv6Address, true) {
endpoint.IPAMConfig.IPv6Address = ""
}
if endpoint.IPAMConfig.IPv4Address == "" && endpoint.IPAMConfig.IPv6Address == "" {
endpoint.IPAMConfig = nil
}
}
func isDefaultBridgeNetwork(netName string, info network.Inspect) bool {
return info.Driver == "bridge" && (netName == "bridge" || info.Name == "bridge")
}
func networkSupportsStaticIP(info network.Inspect, ip string, isIPv6 bool) bool {
if ip == "" {
return true
}
addr, err := netip.ParseAddr(ip)
if err != nil {
return false
}
if addr.Is6() != isIPv6 {
return false
}
for _, item := range info.IPAM.Config {
if item.Subnet == "" {
continue
}
subnet, err := netip.ParsePrefix(item.Subnet)
if err != nil || subnet.Addr().Is6() != isIPv6 {
continue
}
if subnet.Contains(addr) {
return true
}
}
return false
}
func ensureContainerRecoverNetworks(recoverCtx *containerRecoverContext) error {
+4 -3
View File
@@ -97,7 +97,8 @@ func handleRedisBackup(redisInfo *repo.RootInfo, parentTask *task.Task, recordID
}
}
if err := cmd.RunDefaultBashCf("docker exec %s redis-cli -a %s --no-auth-warning save", redisInfo.ContainerName, redisInfo.Password); err != nil {
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(30 * time.Minute))
if err := cmdMgr.Run("docker", "exec", redisInfo.ContainerName, "redis-cli", "-a", redisInfo.Password, "--no-auth-warning", "save"); err != nil {
return err
}
@@ -109,13 +110,13 @@ func handleRedisBackup(redisInfo *repo.RootInfo, parentTask *task.Task, recordID
return nil
}
if strings.HasSuffix(fileName, ".aof") {
if err := cmd.RunDefaultBashCf("docker cp %s:/data/appendonly.aof %s/%s", redisInfo.ContainerName, backupDir, fileName); err != nil {
if err := cmdMgr.Run("docker", "cp", redisInfo.ContainerName+":/data/appendonly.aof", path.Join(backupDir, fileName)); err != nil {
return err
}
return nil
}
if err := cmd.RunDefaultBashCf("docker cp %s:/data/dump.rdb %s/%s", redisInfo.ContainerName, backupDir, fileName); err != nil {
if err := cmdMgr.Run("docker", "cp", redisInfo.ContainerName+":/data/dump.rdb", path.Join(backupDir, fileName)); err != nil {
return err
}
return nil
+1 -1
View File
@@ -178,7 +178,7 @@ func handleWebsiteRecover(website *model.Website, parentTask *task.Task, recover
if err = fileOp.TarGzExtractPro(fmt.Sprintf("%s/%s.web.tar.gz", tmpPath, website.Alias), GetOpenrestyDir(SitesRootDir), ""); err != nil {
return err
}
if err := cmd.RunDefaultBashCf("docker exec -i %s nginx -s reload", nginxInfo.ContainerName); err != nil {
if err := cmd.NewCommandMgr().Run("docker", "exec", "-i", nginxInfo.ContainerName, "nginx", "-s", "reload"); err != nil {
return err
}
oldWebsite.ID = website.ID
+13 -12
View File
@@ -36,8 +36,8 @@ type IClamService interface {
LoadBaseInfo() (dto.ClamBaseInfo, error)
Operate(operate string) error
SearchWithPage(search dto.SearchClamWithPage) (int64, interface{}, error)
Create(req dto.ClamCreate) error
Update(req dto.ClamUpdate) error
Create(req dto.ClamCreate, operator string) error
Update(req dto.ClamUpdate, operator string) error
UpdateStatus(id uint, status string) error
Delete(req dto.ClamDelete) error
HandleOnce(id uint) error
@@ -86,8 +86,9 @@ func (c *ClamService) LoadBaseInfo() (dto.ClamBaseInfo, error) {
baseInfo.IsActive = false
}
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(20 * time.Second))
if baseInfo.IsActive {
version, err := cmd.RunDefaultWithStdoutBashC("clamdscan --version")
version, err := cmdMgr.RunWithStdout("clamdscan", "--version")
if err == nil {
if strings.Contains(version, "/") {
baseInfo.Version = strings.TrimPrefix(strings.Split(version, "/")[0], "ClamAV ")
@@ -99,7 +100,7 @@ func (c *ClamService) LoadBaseInfo() (dto.ClamBaseInfo, error) {
_ = clam.CheckWithStopAll(false, clamRepo)
}
if baseInfo.FreshIsActive {
version, err := cmd.RunDefaultWithStdoutBashC("freshclam --version")
version, err := cmdMgr.RunWithStdout("freshclam", "--version")
if err == nil {
if strings.Contains(version, "/") {
baseInfo.FreshVersion = strings.TrimPrefix(strings.Split(version, "/")[0], "ClamAV ")
@@ -164,7 +165,7 @@ func (c *ClamService) SearchWithPage(req dto.SearchClamWithPage) (int64, interfa
return total, datas, err
}
func (c *ClamService) Create(req dto.ClamCreate) error {
func (c *ClamService) Create(req dto.ClamCreate, operator string) error {
clam, _ := clamRepo.Get(repo.WithByName(req.Name))
if clam.ID != 0 {
return buserr.New("ErrRecordExist")
@@ -179,7 +180,7 @@ func (c *ClamService) Create(req dto.ClamCreate) error {
clam.InfectedDir = ""
}
if len(req.Spec) != 0 {
entryID, err := xpack.StartClam(&clam, false)
entryID, err := xpack.MultiNodeProvider.StartClam(&clam, false)
if err != nil {
return err
}
@@ -198,7 +199,7 @@ func (c *ClamService) Create(req dto.ClamCreate) error {
Project: strconv.Itoa(int(clam.ID)),
Status: constant.AlertEnable,
}
err := NewIAlertService().CreateAlert(createAlert)
err := NewIAlertService().CreateAlert(createAlert, operator)
if err != nil {
return err
}
@@ -206,7 +207,7 @@ func (c *ClamService) Create(req dto.ClamCreate) error {
return nil
}
func (c *ClamService) Update(req dto.ClamUpdate) error {
func (c *ClamService) Update(req dto.ClamUpdate, operator string) error {
if cmd.CheckIllegal(req.Path) {
return buserr.New("ErrCmdIllegal")
}
@@ -232,7 +233,7 @@ func (c *ClamService) Update(req dto.ClamUpdate) error {
upMap["entry_id"] = 0
}
if len(req.Spec) != 0 && clam.Status != constant.StatusDisable {
newEntryID, err := xpack.StartClam(&clamItem, true)
newEntryID, err := xpack.MultiNodeProvider.StartClam(&clamItem, true)
if err != nil {
return err
}
@@ -259,7 +260,7 @@ func (c *ClamService) Update(req dto.ClamUpdate) error {
Type: "clams",
Project: strconv.Itoa(int(clam.ID)),
}
err := NewIAlertService().ExternalUpdateAlert(updateAlert)
err := NewIAlertService().ExternalUpdateAlert(updateAlert, operator)
if err != nil {
return err
}
@@ -276,7 +277,7 @@ func (c *ClamService) UpdateStatus(id uint, status string) error {
err error
)
if status == constant.StatusEnable {
entryID, err = xpack.StartClam(&clam, true)
entryID, err = xpack.MultiNodeProvider.StartClam(&clam, true)
if err != nil {
return err
}
@@ -493,7 +494,7 @@ func (c *ClamService) loadConfigPath(confType string) string {
func handleAlert(infectedFiles, clamName string, clamId uint) {
itemInfected, _ := strconv.Atoi(strings.TrimSpace(infectedFiles))
if itemInfected < 0 {
if itemInfected <= 0 {
return
}
pushAlert := dto.PushAlert{
+35 -26
View File
@@ -297,14 +297,14 @@ func (u *ContainerService) ContainerListStats() ([]dto.ContainerListStats, error
if err != nil {
return nil, err
}
var datas []dto.ContainerListStats
datas := make([]dto.ContainerListStats, len(list))
var wg sync.WaitGroup
wg.Add(len(list))
for i := 0; i < len(list); i++ {
go func(item container.Summary) {
datas = append(datas, loadCpuAndMem(client, item.ID))
go func(index int, item container.Summary) {
datas[index] = loadCpuAndMem(client, item.ID)
wg.Done()
}(list[i])
}(i, list[i])
}
wg.Wait()
return datas, nil
@@ -527,6 +527,7 @@ func (u *ContainerService) ContainerCreate(req dto.ContainerOperate, inThread bo
if err != nil {
return err
}
removeUnsupportedEndpointStaticIPAM(client, networkConf, nil)
con, err := client.ContainerCreate(ctx, config, hostConf, networkConf, &v1.Platform{}, req.Name)
if err != nil {
taskItem.Log(i18n.GetMsgByKey("ContainerCreateFailed"))
@@ -675,6 +676,7 @@ func (u *ContainerService) ContainerUpdate(req dto.ContainerOperate) error {
reCreateAfterUpdate(req.Name, client, oldContainer.Config, oldContainer.HostConfig, oldContainer.NetworkSettings)
return err
}
removeUnsupportedEndpointStaticIPAM(client, networkConf, nil)
con, err := client.ContainerCreate(ctx, config, hostConf, networkConf, &v1.Platform{}, req.Name)
if err != nil {
@@ -738,20 +740,13 @@ func (u *ContainerService) ContainerUpgrade(req dto.ContainerUpgrade) error {
config := oldContainer.Config
config.Image = req.Image
hostConf := oldContainer.HostConfig
var networkConf network.NetworkingConfig
if oldContainer.NetworkSettings != nil {
for networkKey := range oldContainer.NetworkSettings.Networks {
networkConf.EndpointsConfig = map[string]*network.EndpointSettings{networkKey: {}}
break
}
}
err := client.ContainerRemove(ctx, item, container.RemoveOptions{Force: true})
taskItem.LogWithStatus(i18n.GetWithName("ContainerRemoveOld", item), err)
if err != nil {
return err
}
con, err := client.ContainerCreate(ctx, config, hostConf, &networkConf, &v1.Platform{}, item)
con, err := createContainerWithOldNetworks(ctx, client, config, hostConf, oldContainer.NetworkSettings, item)
if err != nil {
taskItem.Log(i18n.GetMsgByKey("ContainerRecreate"))
reCreateAfterUpdate(item, client, oldContainer.Config, oldContainer.HostConfig, oldContainer.NetworkSettings)
@@ -1167,7 +1162,7 @@ func (u *ContainerService) ContainerStats(id string) (*dto.ContainerStats, error
func (u *ContainerService) LoadUsers(req dto.OperationWithName) []string {
var users []string
std, err := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("docker", "exec", req.Name, "cat", "/etc/passwd")
std, err := cmd.RunDockerExecWithStdout(20*time.Second, req.Name, "cat", "/etc/passwd")
if err != nil {
return users
}
@@ -1440,7 +1435,7 @@ func (u *ContainerService) DownloadContainerFile(req dto.ContainerFileReq) (io.R
fileName = "container-file"
}
if stat.Mode.IsDir() {
if _, err := runContainerCommand(cli, req.ContainerID, []string{"sh", "-c", "command -v tar >/dev/null 2>&1"}); err != nil {
if _, err := runContainerCommand(cli, req.ContainerID, []string{"tar", "--help"}); err != nil {
_ = cli.Close()
return nil, "", "", fmt.Errorf("tar command not found in container")
}
@@ -1620,9 +1615,8 @@ func toContainerFileInfo(filePath string, stat container.PathStat, isDir bool) d
}
func isContainerDir(cli *client.Client, containerID, targetPath string) (bool, error) {
_, err := runContainerCommand(cli, containerID, []string{
"sh", "-c", "[ -d \"$1\" ]", "sh", targetPath,
})
checkPath := strings.TrimSuffix(targetPath, "/") + "/."
_, err := runContainerCommand(cli, containerID, []string{"ls", "-d", "--", checkPath})
if err != nil {
return false, err
}
@@ -1952,15 +1946,7 @@ func loadConfigInfo(isCreate bool, req dto.ContainerOperate, oldContainer *conta
func reCreateAfterUpdate(name string, client *client.Client, config *container.Config, hostConf *container.HostConfig, networkConf *container.NetworkSettings) {
ctx := context.Background()
var oldNetworkConf network.NetworkingConfig
if networkConf != nil {
for networkKey := range networkConf.Networks {
oldNetworkConf.EndpointsConfig = map[string]*network.EndpointSettings{networkKey: {}}
break
}
}
oldContainer, err := client.ContainerCreate(ctx, config, hostConf, &oldNetworkConf, &v1.Platform{}, name)
oldContainer, err := createContainerWithOldNetworks(ctx, client, config, hostConf, networkConf, name)
if err != nil {
global.LOG.Errorf("recreate after container update failed, err: %v", err)
return
@@ -1971,6 +1957,29 @@ func reCreateAfterUpdate(name string, client *client.Client, config *container.C
global.LOG.Info("recreate after container update successful")
}
func createContainerWithOldNetworks(ctx context.Context, client *client.Client, config *container.Config, hostConf *container.HostConfig, networkSettings *container.NetworkSettings, name string) (container.CreateResponse, error) {
networkConf, extraNetworks := buildContainerRecoverNetworkConfig(networkSettings, hostConf)
removeUnsupportedEndpointStaticIPAM(client, networkConf, extraNetworks)
created, err := client.ContainerCreate(ctx, config, hostConf, networkConf, nil, name)
if err != nil {
return created, err
}
extraNames := make([]string, 0, len(extraNetworks))
for item := range extraNetworks {
extraNames = append(extraNames, item)
}
sort.Strings(extraNames)
for _, item := range extraNames {
if err := client.NetworkConnect(ctx, item, created.ID, extraNetworks[item]); err != nil {
_ = client.ContainerRemove(ctx, created.ID, container.RemoveOptions{Force: true})
return created, err
}
}
return created, nil
}
func loadVolumeBinds(binds []container.MountPoint) []dto.VolumeHelper {
var datas []dto.VolumeHelper
for _, bind := range binds {
+9 -9
View File
@@ -27,10 +27,10 @@ type CronjobService struct{}
type ICronjobService interface {
SearchWithPage(search dto.PageCronjob) (int64, interface{}, error)
SearchRecords(search dto.SearchRecord) (int64, interface{}, error)
Create(cronjobDto dto.CronjobOperate) error
Create(cronjobDto dto.CronjobOperate, operator string) error
LoadNextHandle(spec string) ([]string, error)
HandleOnce(id uint) error
Update(id uint, req dto.CronjobOperate) error
Update(id uint, req dto.CronjobOperate, operator string) error
UpdateStatus(id uint, status string) error
UpdateGroup(req dto.ChangeGroup) error
Delete(req dto.CronjobBatchDelete) error
@@ -39,7 +39,7 @@ type ICronjobService interface {
HandleStop(id uint) error
Export(req dto.OperateByIDs) (string, error)
Import(req []dto.CronjobTrans) error
Import(req []dto.CronjobTrans, operator string) error
LoadScriptOptions() []dto.ScriptOptions
LoadInfo(req dto.OperateByID) (*dto.CronjobOperate, error)
@@ -212,7 +212,7 @@ func (u *CronjobService) Export(req dto.OperateByIDs) (string, error) {
return string(itemJson), nil
}
func (u *CronjobService) Import(req []dto.CronjobTrans) error {
func (u *CronjobService) Import(req []dto.CronjobTrans, operator string) error {
for _, item := range req {
cronjobItem, _ := cronjobRepo.Get(repo.WithByName(item.Name))
if cronjobItem.ID != 0 {
@@ -405,7 +405,7 @@ func (u *CronjobService) Import(req []dto.CronjobTrans) error {
Project: strconv.Itoa(int(cronjob.ID)),
Status: constant.AlertEnable,
}
_ = NewIAlertService().CreateAlert(createAlert)
_ = NewIAlertService().CreateAlert(createAlert, operator)
}
}
return nil
@@ -558,7 +558,7 @@ func (u *CronjobService) HandleOnce(id uint) error {
return nil
}
func (u *CronjobService) Create(req dto.CronjobOperate) error {
func (u *CronjobService) Create(req dto.CronjobOperate, operator string) error {
cronjob, _ := cronjobRepo.Get(repo.WithByName(req.Name))
if cronjob.ID != 0 {
return buserr.New("ErrRecordExist")
@@ -607,7 +607,7 @@ func (u *CronjobService) Create(req dto.CronjobOperate) error {
Project: strconv.Itoa(int(cronjob.ID)),
Status: constant.AlertEnable,
}
err := NewIAlertService().CreateAlert(createAlert)
err := NewIAlertService().CreateAlert(createAlert, operator)
if err != nil {
return err
}
@@ -678,7 +678,7 @@ func (u *CronjobService) Delete(req dto.CronjobBatchDelete) error {
return nil
}
func (u *CronjobService) Update(id uint, req dto.CronjobOperate) error {
func (u *CronjobService) Update(id uint, req dto.CronjobOperate, operator string) error {
var cronjob model.Cronjob
if err := copier.Copy(&cronjob, &req); err != nil {
return buserr.WithDetail("ErrStructTransform", err.Error(), nil)
@@ -756,7 +756,7 @@ func (u *CronjobService) Update(id uint, req dto.CronjobOperate) error {
Type: cronjob.Type,
Project: strconv.Itoa(int(cronModel.ID)),
}
err = NewIAlertService().ExternalUpdateAlert(updateAlert)
err = NewIAlertService().ExternalUpdateAlert(updateAlert, operator)
if err != nil {
return err
}
+2 -2
View File
@@ -391,7 +391,7 @@ func (u *CronjobService) handleCutWebsiteLog(cronjob *model.Cronjob, startTime t
func backupLogFile(dstFilePath, websiteLogDir string, fileOp files.FileOp) error {
cmdMgr := cmd.NewCommandMgr()
if err := cmdMgr.RunBashCf("tar -czf %s -C %s %s", dstFilePath, websiteLogDir, strings.Join([]string{"access.log", "error.log"}, " ")); err != nil {
if err := cmdMgr.Run("tar", "-czf", dstFilePath, "-C", websiteLogDir, "access.log", "error.log"); err != nil {
dstDir := pathUtils.Dir(dstFilePath)
if err = fileOp.Copy(pathUtils.Join(websiteLogDir, "access.log"), dstDir); err != nil {
return err
@@ -399,7 +399,7 @@ func backupLogFile(dstFilePath, websiteLogDir string, fileOp files.FileOp) error
if err = fileOp.Copy(pathUtils.Join(websiteLogDir, "error.log"), dstDir); err != nil {
return err
}
if err = cmdMgr.RunBashCf("tar -czf %s -C %s %s", dstFilePath, dstDir, strings.Join([]string{"access.log", "error.log"}, " ")); err != nil {
if err = cmdMgr.Run("tar", "-czf", dstFilePath, "-C", dstDir, "access.log", "error.log"); err != nil {
return err
}
_ = fileOp.DeleteFile(pathUtils.Join(dstDir, "access.log"))
+12 -4
View File
@@ -60,7 +60,9 @@ func (u *DashboardService) Restart(operation string) error {
case "system":
{
go func() {
if err := cmd.RunDefaultBashCf("%s reboot", cmd.SudoHandleCmd()); err != nil {
cmdMgr := cmd.NewCommandMgr()
err := cmdMgr.RunWithOptionalSudo("reboot")
if err != nil {
global.LOG.Errorf("handle reboot failed, %v", err)
}
}()
@@ -429,11 +431,17 @@ type diskInfo struct {
func loadDiskInfo() []dto.DiskInfo {
var datas []dto.DiskInfo
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(2 * time.Second))
format := `awk 'NR>1 && !/tmpfs|snap\/core|udev/ {printf "%s\t%s\t%s\t%s\t%s\t%s\t%s\n", $1, $2, $3, $4, $5, $6, $7}'`
stdout, err := cmdMgr.RunWithStdout("bash", "-c", `timeout 2 df -hT -P | `+format)
format := `NR>1 && !/tmpfs|snap\/core|udev/ {printf "%s\t%s\t%s\t%s\t%s\t%s\t%s\n", $1, $2, $3, $4, $5, $6, $7}`
stdout, err := cmdMgr.RunPipe(
cmd.PipeCommand{Name: "df", Args: []string{"-hT", "-P"}},
cmd.PipeCommand{Name: "awk", Args: []string{format}},
)
if err != nil {
cmdMgr2 := cmd.NewCommandMgr(cmd.WithTimeout(1 * time.Second))
stdout, err = cmdMgr2.RunWithStdout("bash", "-c", `timeout 1 df -lhT -P | `+format)
stdout, err = cmdMgr2.RunPipe(
cmd.PipeCommand{Name: "df", Args: []string{"-lhT", "-P"}},
cmd.PipeCommand{Name: "awk", Args: []string{format}},
)
if err != nil {
return datas
}
+1 -1
View File
@@ -17,7 +17,7 @@ import (
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/encrypt"
"github.com/jinzhu/copier"
"go.mongodb.org/mongo-driver/bson"
"go.mongodb.org/mongo-driver/v2/bson"
)
type MongodbService struct{}
+8 -5
View File
@@ -82,7 +82,7 @@ func (u *DeviceService) LoadBaseInfo() (dto.DeviceBaseInfo, error) {
}
func (u *DeviceService) LoadTimeZone() ([]string, error) {
std, err := cmd.NewCommandMgr(cmd.WithTimeout(10 * time.Minute)).RunWithStdoutBashC("timedatectl list-timezones")
std, err := cmd.NewCommandMgr(cmd.WithTimeout(10*time.Minute)).RunWithStdout("timedatectl", "list-timezones")
if err != nil {
return []string{}, err
}
@@ -223,7 +223,9 @@ func (u *DeviceService) UpdatePasswd(req dto.ChangePasswd) error {
if cmd.CheckIllegal(req.User, req.Passwd) {
return buserr.New("ErrCmdIllegal")
}
if err := cmd.RunDefaultBashCf("%s echo '%s:%s' | %s chpasswd", cmd.SudoHandleCmd(), req.User, req.Passwd, cmd.SudoHandleCmd()); err != nil {
cmdItem := cmd.ExecCommandWithOptionalSudo("chpasswd")
cmdItem.Stdin = strings.NewReader(req.User + ":" + req.Passwd)
if err := cmdItem.Run(); err != nil {
if strings.Contains(err.Error(), "does not exist") {
return buserr.New("ErrNotExistUser")
}
@@ -393,7 +395,7 @@ func loadHosts() []dto.HostHelper {
}
func loadHostname() string {
std, err := cmd.RunDefaultWithStdoutBashC("hostname")
std, err := cmd.NewCommandMgr(cmd.WithTimeout(20 * time.Second)).RunWithStdout("hostname")
if err != nil {
return ""
}
@@ -401,7 +403,7 @@ func loadHostname() string {
}
func loadUser() string {
std, err := cmd.RunDefaultWithStdoutBashC("whoami")
std, err := cmd.NewCommandMgr(cmd.WithTimeout(20 * time.Second)).RunWithStdout("whoami")
if err != nil {
return ""
}
@@ -410,7 +412,8 @@ func loadUser() string {
func loadSwap() []dto.SwapHelper {
var data []dto.SwapHelper
std, err := cmd.RunDefaultWithStdoutBashCf("%s swapon --summary", cmd.SudoHandleCmd())
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(20 * time.Second))
std, err := cmdMgr.RunWithOptionalSudoAndStdout("swapon", "--summary")
if err != nil {
return data
}
+2 -2
View File
@@ -223,7 +223,7 @@ func doSystemClean(taskItem *task.Task) func(t *task.Task) error {
}
}
dropWithExclude(path.Join(global.Dir.BaseDir, uploadPath), []string{"theme"}, taskItem, &size, &fileCount)
dropWithExclude(path.Join(global.Dir.BaseDir, uploadPath), []string{"theme", "skills-hub"}, taskItem, &size, &fileCount)
dropWithTask(path.Join(global.Dir.BaseDir, downloadPath), taskItem, &size, &fileCount)
logFiles, _ := os.ReadDir(global.Dir.LogDir)
@@ -863,7 +863,7 @@ func loadTreeWithAllFile(isCheck bool, originalPath, treeType, pathItem string,
return lists
}
for _, file := range files {
if treeType == "upload" && (file.Name() == "theme" && file.IsDir()) {
if treeType == "upload" && ((file.Name() == "theme" || file.Name() == "skills-hub") && file.IsDir()) {
continue
}
if treeType == "system_log" && (file.Name() == "1Panel-Core.log" || file.Name() == "1Panel.log" || file.IsDir()) {
+3 -2
View File
@@ -30,7 +30,8 @@ func NewIDiskService() IDiskService {
func (s *DiskService) GetCompleteDiskInfo() (*response.CompleteDiskInfo, error) {
var diskInfos []response.DiskBasicInfo
output, err := cmd.RunDefaultWithStdoutBashC("lsblk -J -o NAME,SIZE,TYPE,MOUNTPOINT,FSTYPE,MODEL,SERIAL,TRAN,ROTA")
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(20 * time.Second))
output, err := cmdMgr.RunWithStdout("lsblk", "-J", "-o", "NAME,SIZE,TYPE,MOUNTPOINT,FSTYPE,MODEL,SERIAL,TRAN,ROTA")
if err == nil {
diskInfos, err = parseLsblkJsonOutput(output)
if err == nil {
@@ -38,7 +39,7 @@ func (s *DiskService) GetCompleteDiskInfo() (*response.CompleteDiskInfo, error)
return &result, nil
}
}
output, err = cmd.RunDefaultWithStdoutBashC("lsblk -P -o NAME,SIZE,TYPE,MOUNTPOINT,FSTYPE,MODEL,SERIAL,TRAN,ROTA")
output, err = cmdMgr.RunWithStdout("lsblk", "-P", "-o", "NAME,SIZE,TYPE,MOUNTPOINT,FSTYPE,MODEL,SERIAL,TRAN,ROTA")
if err != nil {
return nil, fmt.Errorf("failed to run lsblk command: %v", err)
}
+10 -4
View File
@@ -4,11 +4,13 @@ import (
"bufio"
"encoding/json"
"fmt"
"github.com/1Panel-dev/1Panel/agent/utils/re"
"os"
"os/exec"
"strconv"
"strings"
"time"
"github.com/1Panel-dev/1Panel/agent/utils/re"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/dto/response"
@@ -386,10 +388,14 @@ func getParentDevice(device string) string {
}
func getDiskUsageInfo(device string) (size, used, avail string, usePercent int, err error) {
output, err := cmd.RunDefaultWithStdoutBashC(fmt.Sprintf("df -h %s | tail -1", device))
output, err := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("df", "-h", device)
if err != nil {
return "", "", "", 0, nil
}
lines := strings.Split(strings.TrimSpace(output), "\n")
if len(lines) > 1 {
output = lines[len(lines)-1]
}
fields := strings.Fields(output)
if len(fields) >= 5 {
@@ -515,7 +521,7 @@ func removeFromFstab(mountPoint string) error {
}
func getFilesystemType(device string) (string, error) {
output, err := cmd.RunDefaultWithStdoutBashC(fmt.Sprintf("blkid -o value -s TYPE %s", device))
output, err := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("blkid", "-o", "value", "-s", "TYPE", device)
if err != nil {
return "", err
}
@@ -575,7 +581,7 @@ func parseSizeToBytes(sizeStr string) int64 {
}
func getDeviceUUID(device string) (string, error) {
output, err := cmd.RunDefaultWithStdoutBashC(fmt.Sprintf("blkid -s UUID -o value %s", device))
output, err := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("blkid", "-s", "UUID", "-o", "value", device)
if err != nil {
return "", err
}
+4 -3
View File
@@ -8,6 +8,7 @@ import (
"os"
"path"
"strings"
"time"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/constant"
@@ -89,8 +90,8 @@ func (u *DockerService) LoadDockerConf() (*dto.DaemonJsonConf, error) {
data.Version = itemVersion.Version
}
data.IsSwarm = false
stdout2, _ := cmd.RunDefaultWithStdoutBashC("docker info | grep Swarm")
if string(stdout2) == " Swarm: active\n" {
stdout2, _ := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("docker", "info")
if strings.Contains(stdout2, "Swarm: active") {
data.IsSwarm = true
}
if _, err := os.Stat(constant.DaemonJsonPath); err != nil {
@@ -423,7 +424,7 @@ func validateDockerConfig() error {
if !cmd.Which("dockerd") {
return nil
}
stdout, err := cmd.RunDefaultWithStdoutBashC("dockerd --validate")
stdout, err := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("dockerd", "--validate")
if strings.Contains(stdout, "unknown flag: --validate") {
return nil
}
+207 -33
View File
@@ -40,7 +40,6 @@ import (
"golang.org/x/text/transform"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/common"
"github.com/1Panel-dev/1Panel/agent/utils/files"
terminalai "github.com/1Panel-dev/1Panel/agent/utils/terminal/ai"
@@ -50,6 +49,8 @@ import (
type FileService struct {
}
const fileHistorySnapshotMaxSize = 10 * 1024 * 1024
type IFileService interface {
GetFileList(op request.FileOption) (response.FileInfo, error)
SearchUploadWithPage(req request.SearchUploadWithPage) (int64, interface{}, error)
@@ -75,7 +76,6 @@ type IFileService interface {
BatchChangeModeAndOwner(op request.FileRoleReq) error
ReadLogByLine(req request.FileReadByLineReq) (*response.FileLineContent, error)
GetPathByType(pathType string) string
BatchCheckFiles(req request.FilePathsCheck) []response.ExistFileInfo
GetHostMount() []dto.DiskInfo
GetUsersAndGroups() (*response.UserGroupResponse, error)
@@ -476,7 +476,7 @@ func preflightCompressTool(compressType files.CompressType) error {
func preflightDecompressTool(decompressType files.CompressType) error {
switch decompressType {
case files.Tar, files.Zip, files.TarGz, files.Rar, files.X7z:
case files.Rar, files.X7z:
_, err := files.NewExtractShellArchiver(decompressType)
return err
default:
@@ -539,7 +539,7 @@ func (f *FileService) DeCompress(c request.FileDeCompress) error {
if err := fo.CreateDir(c.Dst, constant.DirPerm); err != nil {
return err
}
if err := cmd.NewCommandMgr(cmd.WithContext(t.TaskCtx)).RunBashCf("cp -rfp '%s'/. '%s'", tempDst, c.Dst); err != nil {
if err := copyDecompressTree(t.TaskCtx, tempDst, c.Dst); err != nil {
return err
}
success = true
@@ -550,7 +550,128 @@ func (f *FileService) DeCompress(c request.FileDeCompress) error {
return nil
}
func copyDecompressTree(ctx context.Context, srcDir, dstDir string) error {
entries, err := os.ReadDir(srcDir)
if err != nil {
return err
}
for _, entry := range entries {
if err := copyDecompressEntry(ctx, filepath.Join(srcDir, entry.Name()), filepath.Join(dstDir, entry.Name())); err != nil {
return err
}
}
return nil
}
func copyDecompressEntry(ctx context.Context, srcPath, dstPath string) (retErr error) {
if err := ctx.Err(); err != nil {
return err
}
info, err := os.Lstat(srcPath)
if err != nil {
return err
}
if info.Mode()&os.ModeSymlink != 0 {
if err := os.RemoveAll(dstPath); err != nil {
return err
}
if err := os.MkdirAll(filepath.Dir(dstPath), constant.DirPerm); err != nil {
return err
}
target, err := os.Readlink(srcPath)
if err != nil {
return err
}
if err := os.Symlink(target, dstPath); err != nil {
return err
}
return applyDecompressOwnership(srcPath, dstPath)
}
if info.IsDir() {
dstInfo, err := os.Lstat(dstPath)
keepExistingDir := err == nil && dstInfo.IsDir() && dstInfo.Mode()&os.ModeSymlink == 0
if err != nil && !os.IsNotExist(err) {
return err
}
if !keepExistingDir {
if err := os.RemoveAll(dstPath); err != nil {
return err
}
if err := os.MkdirAll(dstPath, info.Mode().Perm()); err != nil {
return err
}
if err := applyDecompressOwnership(srcPath, dstPath); err != nil {
return err
}
}
entries, err := os.ReadDir(srcPath)
if err != nil {
return err
}
for _, entry := range entries {
if err := copyDecompressEntry(ctx, filepath.Join(srcPath, entry.Name()), filepath.Join(dstPath, entry.Name())); err != nil {
return err
}
}
if keepExistingDir {
return nil
}
return os.Chtimes(dstPath, info.ModTime(), info.ModTime())
}
if err := os.RemoveAll(dstPath); err != nil {
return err
}
if err := os.MkdirAll(filepath.Dir(dstPath), constant.DirPerm); err != nil {
return err
}
srcFile, err := os.Open(srcPath)
if err != nil {
return err
}
defer srcFile.Close()
dstFile, err := os.OpenFile(dstPath, os.O_CREATE|os.O_RDWR|os.O_TRUNC, info.Mode().Perm())
if err != nil {
return err
}
defer func() {
if cerr := dstFile.Close(); cerr != nil && retErr == nil {
retErr = cerr
}
}()
if _, err := io.Copy(dstFile, srcFile); err != nil {
return err
}
if err := applyDecompressOwnership(srcPath, dstPath); err != nil {
return err
}
return os.Chtimes(dstPath, info.ModTime(), info.ModTime())
}
func applyDecompressOwnership(srcPath, dstPath string) error {
info, err := os.Lstat(srcPath)
if err != nil {
return err
}
stat, ok := info.Sys().(*unix.Stat_t)
if !ok {
return nil
}
if info.Mode()&os.ModeSymlink != 0 {
return os.Lchown(dstPath, int(stat.Uid), int(stat.Gid))
}
return os.Chown(dstPath, int(stat.Uid), int(stat.Gid))
}
func (f *FileService) GetContent(op request.FileContentReq) (response.FileInfo, error) {
if files.ShouldDenySensitiveFileRead(op.Path) {
return response.FileInfo{}, buserr.New("ErrSensitiveFileRead")
}
info, err := files.NewFileInfo(files.FileOption{
Path: op.Path,
Expand: true,
@@ -587,6 +708,9 @@ func (f *FileService) GetContent(op request.FileContentReq) (response.FileInfo,
}
func (f *FileService) GetPreviewContent(op request.FileContentReq) (response.FileInfo, error) {
if files.ShouldDenySensitiveFileRead(op.Path) {
return response.FileInfo{}, buserr.New("ErrSensitiveFileRead")
}
info, err := files.NewFileInfo(files.FileOption{
Path: op.Path,
Expand: false,
@@ -596,6 +720,9 @@ func (f *FileService) GetPreviewContent(op request.FileContentReq) (response.Fil
return response.FileInfo{}, err
}
if files.IsBinaryPreviewFile(info.MimeType, info.Extension) {
return response.FileInfo{}, buserr.New("ErrFileCanNotRead")
}
if files.IsBlockDevice(info.FileMode) {
return response.FileInfo{FileInfo: *info}, nil
}
@@ -691,13 +818,12 @@ func (f *FileService) ChangeName(req request.FileRename) error {
return buserr.New("ErrInvalidChar")
}
fo := files.NewFileOp()
info, _ := files.NewFileInfo(files.FileOption{Path: req.OldName, Expand: false})
content, _ := os.ReadFile(req.OldName)
content, mode, shouldRecordHistory := readEditableFileHistoryContent(req.OldName)
if err := fo.Rename(req.OldName, req.NewName); err != nil {
return err
}
if info != nil && !info.IsDir {
if histErr := historyService.RecordOperation(fileHistoryOpRename, req.OldName, content, info.FileMode, req.OldName, req.NewName); histErr != nil {
if shouldRecordHistory {
if histErr := historyService.RecordOperation(fileHistoryOpRename, req.OldName, content, mode, req.OldName, req.NewName); histErr != nil {
global.LOG.Warnf("record file rename history failed for %s: %v", req.OldName, histErr)
}
}
@@ -707,7 +833,23 @@ func (f *FileService) ChangeName(req request.FileRename) error {
func (f *FileService) Wget(w request.FileWget) (string, error) {
fo := files.NewFileOp()
key := "file-wget-" + common.GetUuid()
return key, fo.DownloadFileWithProcess(w.Url, filepath.Join(w.Path, w.Name), key, w.IgnoreCertificate)
options := files.DownloadOptions{
IgnoreCertificate: w.IgnoreCertificate,
}
if w.UseProxy {
systemProxy, err := NewISettingService().GetSystemProxy()
if err != nil {
return "", err
}
options.Proxy = &files.DownloadProxyConfig{
Type: systemProxy.Type,
URL: systemProxy.URL,
Port: systemProxy.Port,
User: systemProxy.User,
Password: systemProxy.Password,
}
}
return key, fo.DownloadFileWithProcess(w.Url, filepath.Join(w.Path, w.Name), key, options)
}
func (f *FileService) MvFile(m request.FileMove) error {
@@ -727,21 +869,15 @@ func (f *FileService) MvFile(m request.FileMove) error {
path string
content []byte
mode os.FileMode
isDir bool
}
snapshots := make([]moveSnapshot, 0, len(m.OldPaths))
for _, oldPath := range m.OldPaths {
content, _ := os.ReadFile(oldPath)
mode := os.FileMode(0640)
isDir := false
if info, err := files.NewFileInfo(files.FileOption{Path: oldPath, Expand: false}); err == nil {
mode = info.FileMode
isDir = info.IsDir
}
snapshots = append(snapshots, moveSnapshot{path: oldPath, content: content, mode: mode, isDir: isDir})
record bool
}
var errs []error
if m.Type == "cut" {
snapshots := make([]moveSnapshot, 0, len(m.OldPaths))
for _, oldPath := range m.OldPaths {
content, mode, record := readEditableFileHistoryContent(oldPath)
snapshots = append(snapshots, moveSnapshot{path: oldPath, content: content, mode: mode, record: record})
}
if len(m.CoverPaths) > 0 {
for _, src := range m.CoverPaths {
if err := fo.CopyAndReName(src, m.NewPath, "", true); err != nil {
@@ -754,7 +890,7 @@ func (f *FileService) MvFile(m request.FileMove) error {
return err
}
for _, snapshot := range snapshots {
if !snapshot.isDir {
if snapshot.record {
targetPath := buildHistoryMoveTargetPath(m.NewPath, m.Name, snapshot.path, len(m.OldPaths))
if histErr := historyService.RecordOperation(fileHistoryOpMove, snapshot.path, snapshot.content, snapshot.mode, snapshot.path, targetPath); histErr != nil {
global.LOG.Warnf("record file move history failed for %s: %v", snapshot.path, histErr)
@@ -790,6 +926,42 @@ func (f *FileService) MvFile(m request.FileMove) error {
return nil
}
func readEditableFileHistoryContent(filePath string) ([]byte, os.FileMode, bool) {
info, err := os.Lstat(filePath)
if err != nil {
return nil, 0640, false
}
mode := info.Mode()
if mode.IsDir() || mode&os.ModeSymlink != 0 || !mode.IsRegular() || files.IsBlockDevice(mode) || info.Size() > fileHistorySnapshotMaxSize {
return nil, mode, false
}
if files.IsBinaryPreviewFile(files.GetMimeType(filePath), filepath.Ext(info.Name())) {
return nil, mode, false
}
file, err := os.Open(filePath)
if err != nil {
return nil, mode, false
}
defer file.Close()
headBuf := make([]byte, 1024)
n, err := file.Read(headBuf)
if err != nil && err != io.EOF {
return nil, mode, false
}
if n > 0 && files.DetectBinary(headBuf[:n]) {
return nil, mode, false
}
if _, err := file.Seek(0, 0); err != nil {
return nil, mode, false
}
content, err := io.ReadAll(io.LimitReader(file, fileHistorySnapshotMaxSize+1))
if err != nil || int64(len(content)) > fileHistorySnapshotMaxSize {
return nil, mode, false
}
return content, mode, true
}
func buildHistoryMoveTargetPath(dst, name, sourcePath string, sourceCount int) string {
if strings.TrimSpace(dst) == "" {
return sourcePath
@@ -801,6 +973,11 @@ func buildHistoryMoveTargetPath(dst, name, sourcePath string, sourceCount int) s
}
func (f *FileService) FileDownload(d request.FileDownload) (string, error) {
for _, p := range d.Paths {
if files.ShouldDenySensitiveFileRead(p) {
return "", buserr.New("ErrSensitiveFileRead")
}
}
filePath := d.Paths[0]
if d.Compress {
tempPath := filepath.Join(os.TempDir(), fmt.Sprintf("%d", time.Now().UnixNano()))
@@ -932,6 +1109,14 @@ func (f *FileService) ReadLogByLine(req request.FileReadByLineReq) (*response.Fi
logFilePath, _ = ini_conf.GetIniValue(configPath, "supervisord", "logfile")
case constant.Supervisor:
logFilePath = path.Join(global.Dir.DataDir, "tools", "supervisord", "log", req.Name)
case "ai-proxy":
safeName := path.Base(req.Name)
if safeName != req.Name || strings.Contains(safeName, "..") {
return nil, buserr.New("ErrInvalidParams")
}
logFilePath = path.Join(global.Dir.LogDir, "ai", safeName)
default:
return nil, buserr.New("ErrNotSupportType")
}
file, err := os.Open(logFilePath)
@@ -977,17 +1162,6 @@ func (f *FileService) ReadLogByLine(req request.FileReadByLineReq) (*response.Fi
return res, nil
}
func (f *FileService) GetPathByType(pathType string) string {
if pathType == "websiteDir" {
value, _ := settingRepo.GetValueByKey("WEBSITE_DIR")
if value == "" {
return path.Join(global.Dir.BaseDir, "1panel", "www")
}
return value
}
return ""
}
func (f *FileService) BatchCheckFiles(req request.FilePathsCheck) []response.ExistFileInfo {
fileList := make([]response.ExistFileInfo, 0, len(req.Paths))
for _, filePath := range req.Paths {
+4
View File
@@ -20,6 +20,7 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/repo"
"github.com/1Panel-dev/1Panel/agent/buserr"
"github.com/1Panel-dev/1Panel/agent/utils/encrypt"
"github.com/1Panel-dev/1Panel/agent/utils/files"
"gorm.io/gorm"
)
@@ -131,6 +132,9 @@ func (s *FileShareService) Create(req request.FileShareCreate) (*response.FileSh
if path == "" || strings.Contains(path, "..") {
return nil, buserr.New("ErrFileSharePath")
}
if files.ShouldDenySensitiveFileRead(path) {
return nil, buserr.New("ErrSensitiveFileRead")
}
info, err := os.Stat(path)
if err != nil || info.IsDir() {
return nil, buserr.New("ErrFileSharePath")
+16 -22
View File
@@ -186,6 +186,9 @@ func (u *FirewallService) OperateFirewall(req dto.FirewallOperation) error {
if err := client.Restart(); err != nil {
return err
}
if err := u.addPortsBeforeStart(client); err != nil {
return err
}
needRestartDocker = true
case "disableBanPing":
if err := firewall.UpdatePingStatus("0"); err != nil {
@@ -579,30 +582,21 @@ func (u *FirewallService) cleanUnUsedData(client firewall.FirewallClient) {
}
func (u *FirewallService) addPortsBeforeStart(client firewall.FirewallClient) error {
if !global.IsMaster {
if err := client.Port(fireClient.FireInfo{Port: global.CONF.Base.Port, Protocol: "tcp", Strategy: "accept"}, "add"); err != nil {
if client.Name() == "iptables" {
isInit, _ := iptables.LoadInitStatus("iptables", "base")
if !isInit {
return nil
}
return syncIptablesFirewallPortWhiteList(true)
}
portWhiteList, err := loadFirewallPortWhiteList()
if err != nil {
return err
}
for _, item := range portWhiteList {
if err := client.Port(fireClient.FireInfo{Port: item.Port, Protocol: item.Protocol, Strategy: "accept"}, "add"); err != nil {
return err
}
} else {
var portSetting model.Setting
_ = global.CoreDB.Where("key = ?", "ServerPort").First(&portSetting).Error
if len(portSetting.Value) != 0 {
if err := client.Port(fireClient.FireInfo{Port: portSetting.Value, Protocol: "tcp", Strategy: "accept"}, "add"); err != nil {
return err
}
}
}
if err := client.Port(fireClient.FireInfo{Port: loadSSHPort(), Protocol: "tcp", Strategy: "accept"}, "add"); err != nil {
return err
}
if err := client.Port(fireClient.FireInfo{Port: "80", Protocol: "tcp", Strategy: "accept"}, "add"); err != nil {
return err
}
if err := client.Port(fireClient.FireInfo{Port: "443", Protocol: "tcp", Strategy: "accept"}, "add"); err != nil {
return err
}
if err := client.Port(fireClient.FireInfo{Port: "443", Protocol: "udp", Strategy: "accept"}, "add"); err != nil {
return err
}
return client.Reload()
+175
View File
@@ -0,0 +1,175 @@
package service
import (
"fmt"
"strconv"
"strings"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/utils/firewall"
fireClient "github.com/1Panel-dev/1Panel/agent/utils/firewall/client"
"github.com/1Panel-dev/1Panel/agent/utils/firewall/client/iptables"
)
type firewallPortWhitelist struct {
Port string
Protocol string
}
func loadConfiguredFirewallPortWhiteList() ([]firewallPortWhitelist, error) {
value, err := settingRepo.GetValueByKey(constant.FirewallPortWhiteList)
if err != nil {
value = constant.FirewallPortWhiteListValue
if err := settingRepo.UpdateOrCreate(constant.FirewallPortWhiteList, value); err != nil {
return nil, err
}
}
return parseFirewallPortWhiteList(value)
}
func loadFirewallPortWhiteList() ([]firewallPortWhitelist, error) {
portWhiteList, err := loadConfiguredFirewallPortWhiteList()
if err != nil {
return nil, err
}
requiredPorts, err := loadRequiredFirewallPortWhiteList()
if err != nil {
return nil, err
}
return normalizeFirewallPortWhiteList(append(portWhiteList, requiredPorts...)), nil
}
func loadRequiredFirewallPortWhiteList() ([]firewallPortWhitelist, error) {
panelPort := LoadPanelPort()
if panelPort == "" {
return nil, fmt.Errorf("find 1panel service port failed")
}
return normalizeFirewallPortWhiteList([]firewallPortWhitelist{
{Port: panelPort, Protocol: "tcp"},
{Port: loadSSHPort(), Protocol: "tcp"},
}), nil
}
func parseFirewallPortWhiteList(value string) ([]firewallPortWhitelist, error) {
items := strings.FieldsFunc(value, func(r rune) bool {
return r == ',' || r == '\n' || r == ';' || r == ' '
})
ports := make([]firewallPortWhitelist, 0, len(items))
exists := make(map[string]struct{})
for _, item := range items {
item = strings.TrimSpace(item)
if item == "" {
continue
}
port, protocol, ok := strings.Cut(item, "/")
if !ok {
protocol = "tcp"
}
port = strings.TrimSpace(port)
protocol = strings.ToLower(strings.TrimSpace(protocol))
if protocol != "tcp" && protocol != "udp" {
return nil, fmt.Errorf("invalid firewall port whitelist protocol: %s", item)
}
portNum, err := strconv.Atoi(port)
if err != nil || portNum < 1 || portNum > 65535 {
return nil, fmt.Errorf("invalid firewall port whitelist: %s", item)
}
key := fmt.Sprintf("%d/%s", portNum, protocol)
if _, ok := exists[key]; ok {
continue
}
exists[key] = struct{}{}
ports = append(ports, firewallPortWhitelist{Port: strconv.Itoa(portNum), Protocol: protocol})
}
return ports, nil
}
func normalizeFirewallPortWhiteList(portWhiteList []firewallPortWhitelist) []firewallPortWhitelist {
ports := make([]firewallPortWhitelist, 0, len(portWhiteList))
exists := make(map[string]struct{})
for _, item := range portWhiteList {
if item.Port == "" {
continue
}
key := fmt.Sprintf("%s/%s", item.Port, item.Protocol)
if _, ok := exists[key]; ok {
continue
}
exists[key] = struct{}{}
ports = append(ports, item)
}
return ports
}
func syncFirewallPortWhiteListAfterUpdate(oldValue string) error {
client, err := firewall.NewFirewallClient()
if err != nil {
return err
}
if client.Name() == "iptables" {
isInit, _ := iptables.LoadInitStatus("iptables", "base")
if !isInit {
return nil
}
oldPortWhiteList, err := parseFirewallPortWhiteList(oldValue)
if err != nil {
return err
}
return syncIptablesFirewallPortWhiteList(true, oldPortWhiteList)
}
isActive, _ := client.Status()
if !isActive {
return nil
}
portWhiteList, err := loadFirewallPortWhiteList()
if err != nil {
return err
}
oldPortWhiteList, err := parseFirewallPortWhiteList(oldValue)
if err != nil {
return err
}
requiredPorts, err := loadRequiredFirewallPortWhiteList()
if err != nil {
return err
}
oldPortWhiteList = normalizeFirewallPortWhiteList(append(oldPortWhiteList, requiredPorts...))
return syncFirewallClientPortWhiteList(client, oldPortWhiteList, portWhiteList)
}
func syncFirewallClientPortWhiteList(client firewall.FirewallClient, oldPortWhiteList, portWhiteList []firewallPortWhitelist) error {
oldPorts := firewallPortWhiteListMap(oldPortWhiteList)
newPorts := firewallPortWhiteListMap(portWhiteList)
for _, item := range oldPortWhiteList {
key := firewallPortWhiteListKey(item)
if _, ok := newPorts[key]; ok {
continue
}
if err := client.Port(fireClient.FireInfo{Port: item.Port, Protocol: item.Protocol, Strategy: "accept"}, "remove"); err != nil {
return err
}
}
for _, item := range portWhiteList {
key := firewallPortWhiteListKey(item)
if _, ok := oldPorts[key]; ok {
continue
}
if err := client.Port(fireClient.FireInfo{Port: item.Port, Protocol: item.Protocol, Strategy: "accept"}, "add"); err != nil {
return err
}
}
return client.Reload()
}
func firewallPortWhiteListMap(portWhiteList []firewallPortWhitelist) map[string]struct{} {
ports := make(map[string]struct{})
for _, item := range portWhiteList {
ports[firewallPortWhiteListKey(item)] = struct{}{}
}
return ports
}
func firewallPortWhiteListKey(item firewallPortWhitelist) string {
return item.Port + "/" + item.Protocol
}
+82 -44
View File
@@ -27,12 +27,14 @@ import (
type HostToolService struct{}
type IHostToolService interface {
GetToolStatus(req request.HostToolReq) (*response.HostToolRes, error)
GetToolStatus(req request.HostToolTypeReq) (*response.HostToolRes, error)
CreateToolConfig(req request.HostToolCreate) error
OperateTool(req request.HostToolReq) error
OperateToolConfig(req request.HostToolConfig) (*response.HostToolConfig, error)
OperateTool(req request.HostToolOperateReq) error
GetToolConfig(req request.HostToolTypeReq) (*response.HostToolConfig, error)
UpdateToolConfig(req request.HostToolConfigUpdate) error
OperateSupervisorProcess(req request.SupervisorProcessConfig) error
GetSupervisorProcessConfig() ([]response.SupervisorProcessConfig, error)
GetSupervisorProcessFile(req request.HostSupervisorProcessFileGetReq) (string, error)
OperateSupervisorProcessFile(req request.SupervisorProcessFileReq) (string, error)
}
@@ -40,7 +42,7 @@ func NewIHostToolService() IHostToolService {
return &HostToolService{}
}
func (h *HostToolService) GetToolStatus(req request.HostToolReq) (*response.HostToolRes, error) {
func (h *HostToolService) GetToolStatus(req request.HostToolTypeReq) (*response.HostToolRes, error) {
res := &response.HostToolRes{}
res.Type = req.Type
switch req.Type {
@@ -71,7 +73,7 @@ func (h *HostToolService) GetToolStatus(req request.HostToolReq) (*response.Host
supervisorConfig.ServiceName = serviceNameSet.Value
}
versionRes, _ := cmd.RunDefaultWithStdoutBashC("supervisord -v")
versionRes, _ := cmd.NewCommandMgr(cmd.WithTimeout(20*time.Second)).RunWithStdout("supervisord", "-v")
supervisorConfig.Version = strings.TrimSuffix(versionRes, "\n")
_, ctlRrr := exec.LookPath("supervisorctl")
supervisorConfig.CtlExist = ctlRrr == nil
@@ -201,7 +203,7 @@ func (h *HostToolService) CreateToolConfig(req request.HostToolCreate) error {
return nil
}
func (h *HostToolService) OperateTool(req request.HostToolReq) error {
func (h *HostToolService) OperateTool(req request.HostToolOperateReq) error {
serviceName := req.Type
if req.Type == constant.Supervisord {
serviceNameSet, _ := settingRepo.Get(settingRepo.WithByKey(constant.SupervisorServiceName))
@@ -212,12 +214,10 @@ func (h *HostToolService) OperateTool(req request.HostToolReq) error {
return controller.Handle(req.Operate, serviceName)
}
func (h *HostToolService) OperateToolConfig(req request.HostToolConfig) (*response.HostToolConfig, error) {
fileOp := files.NewFileOp()
res := &response.HostToolConfig{}
func (h *HostToolService) loadToolConfigInfo(toolType string) (string, string) {
configPath := ""
serviceName := "supervisord"
switch req.Type {
switch toolType {
case constant.Supervisord:
pathSet, _ := settingRepo.Get(settingRepo.WithByKey(constant.SupervisorConfigPath))
if pathSet.ID != 0 || pathSet.Value != "" {
@@ -227,37 +227,48 @@ func (h *HostToolService) OperateToolConfig(req request.HostToolConfig) (*respon
if serviceNameSet.ID != 0 || serviceNameSet.Value != "" {
serviceName = serviceNameSet.Value
}
default:
return "", ""
}
switch req.Operate {
case "get":
content, err := fileOp.GetContent(configPath)
if err != nil {
return nil, err
}
res.Content = string(content)
case "set":
file, err := fileOp.OpenFile(configPath)
if err != nil {
return nil, err
}
oldContent, err := fileOp.GetContent(configPath)
if err != nil {
return nil, err
}
fileInfo, err := file.Stat()
if err != nil {
return nil, err
}
if err = fileOp.WriteFile(configPath, strings.NewReader(req.Content), fileInfo.Mode()); err != nil {
return nil, err
}
if err = controller.HandleRestart(serviceName); err != nil {
_ = fileOp.WriteFile(configPath, bytes.NewReader(oldContent), fileInfo.Mode())
return nil, err
}
return configPath, serviceName
}
func (h *HostToolService) GetToolConfig(req request.HostToolTypeReq) (*response.HostToolConfig, error) {
fileOp := files.NewFileOp()
res := &response.HostToolConfig{}
configPath, _ := h.loadToolConfigInfo(req.Type)
content, err := fileOp.GetContent(configPath)
if err != nil {
return nil, err
}
res.Content = string(content)
return res, nil
}
func (h *HostToolService) UpdateToolConfig(req request.HostToolConfigUpdate) error {
fileOp := files.NewFileOp()
configPath, serviceName := h.loadToolConfigInfo(req.Type)
file, err := fileOp.OpenFile(configPath)
if err != nil {
return err
}
oldContent, err := fileOp.GetContent(configPath)
if err != nil {
return err
}
fileInfo, err := file.Stat()
if err != nil {
return err
}
if err = fileOp.WriteFile(configPath, strings.NewReader(req.Content), fileInfo.Mode()); err != nil {
return err
}
if err = controller.HandleRestart(serviceName); err != nil {
_ = fileOp.WriteFile(configPath, bytes.NewReader(oldContent), fileInfo.Mode())
return err
}
return res, nil
return nil
}
func (h *HostToolService) OperateSupervisorProcess(req request.SupervisorProcessConfig) error {
@@ -451,7 +462,19 @@ func (h *HostToolService) OperateSupervisorProcessFile(req request.SupervisorPro
return handleSupervisorFile(req, includeDir, "", "")
}
func (h *HostToolService) GetSupervisorProcessFile(req request.HostSupervisorProcessFileGetReq) (string, error) {
return h.OperateSupervisorProcessFile(request.SupervisorProcessFileReq{
Name: req.Name,
Operate: "get",
File: req.File,
})
}
func handleSupervisorFile(req request.SupervisorProcessFileReq, includeDir, containerName, logFile string) (string, error) {
safeName := path.Base(req.Name)
if safeName != req.Name || strings.Contains(safeName, "..") {
return "", buserr.New("ErrInvalidParams")
}
var (
fileOp = files.NewFileOp()
group = fmt.Sprintf("program:%s", req.Name)
@@ -550,8 +573,8 @@ func operateSupervisorCtl(operate, name, group, includeDir, containerName string
err error
)
if containerName != "" {
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(30 * time.Second))
output, err = cmdMgr.RunWithStdoutBashCf("docker exec %s supervisorctl %s", containerName, strings.Join(processNames, " "))
args := append([]string{"supervisorctl"}, processNames...)
output, err = cmd.RunDockerExecWithStdout(30*time.Second, containerName, args...)
} else {
var out []byte
out, err = exec.Command("supervisorctl", processNames...).Output()
@@ -593,8 +616,8 @@ func getProcessStatus(config *response.SupervisorProcessConfig, containerName st
)
processNames = append(processNames, getProcessName(config.Name, config.Numprocs)...)
if containerName != "" {
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(3 * time.Second))
output, err = cmdMgr.RunWithStdoutBashCf("docker exec %s supervisorctl %s", containerName, strings.Join(processNames, " "))
args := append([]string{"supervisorctl"}, processNames...)
output, err = cmd.RunDockerExecWithStdout(3*time.Second, containerName, args...)
} else {
var out []byte
out, err = exec.Command("supervisorctl", processNames...).Output()
@@ -613,8 +636,7 @@ func getProcessStatus(config *response.SupervisorProcessConfig, containerName st
Status: fields[1],
}
if fields[1] == "RUNNING" {
status.PID = strings.TrimSuffix(fields[3], ",")
status.Uptime = fields[5]
status.PID, status.Uptime = parseSupervisorRunningDetails(fields)
} else {
status.Msg = strings.Join(fields[2:], " ")
}
@@ -623,3 +645,19 @@ func getProcessStatus(config *response.SupervisorProcessConfig, containerName st
}
return nil
}
func parseSupervisorRunningDetails(fields []string) (string, string) {
var pid, uptime string
if len(fields) > 3 && fields[2] == "pid" {
pid = strings.TrimSuffix(fields[3], ",")
}
for i := 4; i < len(fields); i++ {
if strings.TrimSuffix(fields[i], ",") == "uptime" {
if i+1 < len(fields) {
uptime = strings.Join(fields[i+1:], " ")
}
break
}
}
return pid, uptime
}
+3 -3
View File
@@ -198,10 +198,10 @@ func (u *ImageRepoService) Update(req dto.ImageRepoUpdate) error {
}
func (u *ImageRepoService) CheckConn(host, user, password string) error {
cmdMgr := cmd.NewCommandMgr()
stdout, err := cmdMgr.RunWithStdout("docker", "login", "-u", user, "-p", password, host)
cmdMgr := cmd.NewCommandMgr(cmd.WithStdin(strings.NewReader(password)))
stdout, err := cmdMgr.RunWithStdout("docker", "login", "-u", user, "--password-stdin", host)
if err != nil {
return fmt.Errorf("stdout: %s, stderr: %v", stdout, err)
return fmt.Errorf("docker login failed: %v", err)
}
if strings.Contains(string(stdout), "Login Succeeded") {
return nil
+123 -11
View File
@@ -187,6 +187,9 @@ func (s *IptablesService) Operate(req dto.IptablesOp) error {
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasicBefore, iptables.BasicBeforeFileName); err != nil {
return err
}
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasic, iptables.BasicFileName); err != nil {
return err
}
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasicAfter, iptables.BasicAfterFileName); err != nil {
return err
}
@@ -228,6 +231,15 @@ func (s *IptablesService) Operate(req dto.IptablesOp) error {
if err := iptables.BindChain(iptables.FilterTab, iptables.ChainInput, iptables.Chain1PanelBasicAfter, 3); err != nil {
return err
}
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasicBefore, iptables.BasicBeforeFileName); err != nil {
return err
}
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasic, iptables.BasicFileName); err != nil {
return err
}
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasicAfter, iptables.BasicAfterFileName); err != nil {
return err
}
_ = settingRepo.Update("IptablesStatus", constant.StatusEnable)
return nil
case "bind-base-without-init":
@@ -359,31 +371,131 @@ func loadBindNumber(chain string) int {
}
func initPreRules() error {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicBefore, iptables.IoRuleIn); err != nil {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicBefore, "-i", "lo", "-j", "ACCEPT", "-m", "comment", "--comment", "Loopback Whitelist"); err != nil {
return err
}
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicBefore, iptables.EstablishedRule); err != nil {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicBefore, "-m", "conntrack", "--ctstate", "RELATED,ESTABLISHED", "-j", "ACCEPT", "-m", "comment", "--comment", "ESTABLISHED Whitelist"); err != nil {
return err
}
panelPort := LoadPanelPort()
if len(panelPort) == 0 {
return errors.New("find 1panel service port failed")
if err := syncIptablesFirewallPortWhiteList(false); err != nil {
return err
}
ports := []string{"80", "443", panelPort, loadSSHPort()}
for _, item := range ports {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicBefore, fmt.Sprintf("-p tcp -m tcp --dport %v -j ACCEPT", item)); err != nil {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicAfter, "-p", "tcp", "-j", "DROP"); err != nil {
return err
}
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicAfter, "-p", "udp", "-j", "DROP"); err != nil {
return err
}
return nil
}
func syncIptablesFirewallPortWhiteList(withSave bool, oldConfiguredPortWhiteList ...[]firewallPortWhitelist) error {
requiredPorts, err := loadRequiredFirewallPortWhiteList()
if err != nil {
return err
}
if err := applyRequiredFirewallPortWhiteListRules(requiredPorts, withSave); err != nil {
return err
}
portWhiteList, err := loadConfiguredFirewallPortWhiteList()
if err != nil {
return err
}
return applyFirewallPortWhiteListRules(portWhiteList, withSave, oldConfiguredPortWhiteList...)
}
func applyRequiredFirewallPortWhiteListRules(portWhiteList []firewallPortWhitelist, withSave bool) error {
if err := syncRequiredFirewallPortWhiteListRules(portWhiteList); err != nil {
return err
}
for _, item := range portWhiteList {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicBefore, "-p", item.Protocol, "-m", item.Protocol, "--dport", item.Port, "-j", "ACCEPT"); err != nil {
return err
}
}
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicAfter, "-p udp -m udp --dport 443 -j ACCEPT"); err != nil {
if !withSave {
return nil
}
if err := iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasicBefore, iptables.BasicBeforeFileName); err != nil {
return err
}
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicAfter, iptables.DropAllTcp); err != nil {
return iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasicAfter, iptables.BasicAfterFileName)
}
func applyFirewallPortWhiteListRules(portWhiteList []firewallPortWhitelist, withSave bool, oldConfiguredPortWhiteList ...[]firewallPortWhitelist) error {
if err := syncFirewallPortWhiteListRules(portWhiteList, oldConfiguredPortWhiteList...); err != nil {
return err
}
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasicAfter, iptables.DropAllUdp); err != nil {
for _, item := range portWhiteList {
if err := iptables.AddRule(iptables.FilterTab, iptables.Chain1PanelBasic, "-p", item.Protocol, "-m", item.Protocol, "--dport", item.Port, "-j", "ACCEPT"); err != nil {
return err
}
}
if !withSave {
return nil
}
return iptables.SaveRulesToFile(iptables.FilterTab, iptables.Chain1PanelBasic, iptables.BasicFileName)
}
func syncRequiredFirewallPortWhiteListRules(portWhiteList []firewallPortWhitelist) error {
tcpWhitelist := make(map[string]struct{})
udpWhitelist := make(map[string]struct{})
for _, item := range portWhiteList {
if item.Protocol == "udp" {
udpWhitelist[item.Port] = struct{}{}
continue
}
tcpWhitelist[item.Port] = struct{}{}
}
if err := cleanExtraFirewallPortRules(iptables.Chain1PanelBasicBefore, "tcp", tcpWhitelist); err != nil {
return err
}
if err := cleanExtraFirewallPortRules(iptables.Chain1PanelBasicBefore, "udp", udpWhitelist); err != nil {
return err
}
return cleanExtraFirewallPortRules(iptables.Chain1PanelBasicAfter, "udp", map[string]struct{}{})
}
func syncFirewallPortWhiteListRules(portWhiteList []firewallPortWhitelist, oldConfiguredPortWhiteList ...[]firewallPortWhitelist) error {
portWhitelist := firewallPortWhiteListMap(portWhiteList)
if len(oldConfiguredPortWhiteList) == 0 {
return nil
}
for _, item := range oldConfiguredPortWhiteList[0] {
if _, ok := portWhitelist[firewallPortWhiteListKey(item)]; ok {
continue
}
if !iptables.CheckRuleExist(iptables.FilterTab, iptables.Chain1PanelBasic, "-p", item.Protocol, "--dport", item.Port, "-j", "ACCEPT") {
continue
}
if err := iptables.DeleteRule(iptables.FilterTab, iptables.Chain1PanelBasic, "-p", item.Protocol, "--dport", item.Port, "-j", "ACCEPT"); err != nil {
return err
}
}
return nil
}
func cleanExtraFirewallPortRules(chain, protocol string, whitelist map[string]struct{}) error {
rules, err := iptables.ReadFilterRulesByChain(chain)
if err != nil {
return err
}
kept := make(map[string]struct{})
for _, rule := range rules {
if rule.Strategy != "accept" || rule.Protocol != protocol || rule.DstPort == "" || rule.SrcIP != "" || rule.DstIP != "" || rule.SrcPort != "" {
continue
}
if _, ok := whitelist[rule.DstPort]; ok {
if _, seen := kept[rule.DstPort]; !seen {
kept[rule.DstPort] = struct{}{}
continue
}
}
if err := iptables.DeleteRule(iptables.FilterTab, chain, "-p", protocol, "-m", protocol, "--dport", rule.DstPort, "-j", "ACCEPT"); err != nil {
return err
}
}
return nil
}
+1 -1
View File
@@ -681,7 +681,7 @@ func GetWebsiteID() uint {
}
func pullImage(imageType string) {
if global.CONF.Base.IsOffLine {
if global.CONF.Base.IsOffline {
return
}
if imageType == "npx" {
+4 -4
View File
@@ -13,9 +13,9 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/app/repo"
"go.mongodb.org/mongo-driver/mongo"
"go.mongodb.org/mongo-driver/mongo/options"
"go.mongodb.org/mongo-driver/mongo/readpref"
"go.mongodb.org/mongo-driver/v2/mongo"
"go.mongodb.org/mongo-driver/v2/mongo/options"
"go.mongodb.org/mongo-driver/v2/mongo/readpref"
)
type mongodbConnectionInfo struct {
@@ -90,7 +90,7 @@ func newRemoteMongodbClient(info mongodbConnectionInfo) (*mongo.Client, context.
}
ctx, cancel := context.WithTimeout(context.Background(), timeout)
client, err := mongo.Connect(ctx, clientOptions)
client, err := mongo.Connect(clientOptions)
if err != nil {
cancel()
return nil, nil, nil, err
+3 -2
View File
@@ -39,12 +39,13 @@ var monitorCancel context.CancelFunc
type IMonitorService interface {
Run()
LoadMonitorData(req dto.MonitorSearch) ([]dto.MonitorData, error)
LoadGPUOptions() dto.MonitorGPUOptions
LoadGPUMonitorData(req dto.MonitorGPUSearch) (dto.MonitorGPUData, error)
LoadSetting() (*dto.MonitorSetting, error)
UpdateSetting(key, value string) error
CleanData() error
LoadGPUOptions() dto.MonitorGPUOptions
LoadGPUMonitorData(req dto.MonitorGPUSearch) (dto.MonitorGPUData, error)
saveIODataToDB(ctx context.Context, interval float64)
saveNetDataToDB(ctx context.Context, interval float64)
}
+1 -1
View File
@@ -241,7 +241,7 @@ func (n NginxService) Build(req request.NginxBuildReq) error {
}
buildTask.AddSubTaskWithOps("", func(t *task.Task) error {
cmdMgr := cmd.NewCommandMgr(cmd.WithTask(*buildTask), cmd.WithTimeout(120*time.Minute))
if err = cmdMgr.RunBashCf("docker compose -f %s build", nginxInstall.GetComposePath()); err != nil {
if err = cmdMgr.Run("docker", "compose", "-f", nginxInstall.GetComposePath(), "build"); err != nil {
return err
}
_, err = compose.DownAndUp(nginxInstall.GetComposePath())
+2 -8
View File
@@ -240,16 +240,10 @@ func getNginxParamsFromStaticFile(scope dto.NginxKey, newParams []dto.NginxParam
func opNginx(containerName, operate string) error {
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(20 * time.Second))
cmdStr := fmt.Sprintf("docker exec -i %s nginx ", containerName)
if operate == constant.NginxCheck {
cmdStr = cmdStr + "-t"
} else {
cmdStr = cmdStr + "-s reload"
return cmdMgr.Run("docker", "exec", "-i", containerName, "nginx", "-t")
}
if err := cmdMgr.RunBashC(cmdStr); err != nil {
return err
}
return nil
return cmdMgr.Run("docker", "exec", "-i", containerName, "nginx", "-s", "reload")
}
func nginxCheckAndReload(oldContent string, filePath string, containerName string) error {
+5 -2
View File
@@ -630,11 +630,14 @@ func (r *RuntimeService) OperateNodeModules(req request.NodeModuleOperateReq) er
return err
}
operation := getOperation(req.Operate, req.PkgManager)
execScript := fmt.Sprintf("%s %s %s", req.PkgManager, operation, req.Module)
execArgs := []string{"exec", "-i", containerName, req.PkgManager, operation}
if strings.TrimSpace(req.Module) != "" {
execArgs = append(execArgs, req.Module)
}
ctx, cancel := context.WithTimeout(context.Background(), 20*time.Minute)
defer cancel()
installCmd := exec.CommandContext(ctx, "docker", "exec", "-i", containerName, "bash", "-c", execScript)
installCmd := exec.CommandContext(ctx, "docker", execArgs...)
output, err := installCmd.CombinedOutput()
if err != nil {
return fmt.Errorf("failed to execute command: %s, error: %w", string(output), err)
+33 -4
View File
@@ -41,19 +41,24 @@ import (
func handleRuntime(create request.RuntimeCreate, runtime *model.Runtime, fileOp files.FileOp, appVersionDir string) (err error) {
runtimeDir := path.Join(global.Dir.RuntimeDir, create.Type)
projectDir := path.Join(runtimeDir, create.Name)
if create.CodeDir != "" && isPathInsideOrEqual(projectDir, create.CodeDir) {
return buserr.New("ErrRuntimeProjectDirContainsCodeDir")
}
if err = fileOp.CopyDir(appVersionDir, runtimeDir); err != nil {
return
}
versionDir := path.Join(runtimeDir, filepath.Base(appVersionDir))
projectDir := path.Join(runtimeDir, create.Name)
cleanupTarget := versionDir
defer func() {
if err != nil {
_ = fileOp.DeleteDir(projectDir)
_ = fileOp.DeleteDir(cleanupTarget)
}
}()
if err = fileOp.Rename(versionDir, projectDir); err != nil {
return
}
cleanupTarget = projectDir
composeContent, envContent, _, err := handleParams(create, projectDir)
if err != nil {
return
@@ -76,12 +81,36 @@ func handleRuntime(create request.RuntimeCreate, runtime *model.Runtime, fileOp
return
}
func isPathInsideOrEqual(baseDir, targetDir string) bool {
baseAbs := resolveRuntimePath(baseDir)
targetAbs := resolveRuntimePath(targetDir)
rel, err := filepath.Rel(baseAbs, targetAbs)
if err != nil {
return false
}
return rel == "." || (rel != ".." && !strings.HasPrefix(rel, ".."+string(os.PathSeparator)))
}
func resolveRuntimePath(dir string) string {
cleanDir := filepath.Clean(dir)
if realDir, err := filepath.EvalSymlinks(cleanDir); err == nil {
return realDir
}
if absDir, err := filepath.Abs(cleanDir); err == nil {
return absDir
}
return cleanDir
}
func handlePHP(create request.RuntimeCreate, runtime *model.Runtime, fileOp files.FileOp, appVersionDir string) (err error) {
runtimeDir := path.Join(global.Dir.RuntimeDir, create.Type)
projectDir := path.Join(runtimeDir, create.Name)
if create.CodeDir != "" && isPathInsideOrEqual(projectDir, create.CodeDir) {
return buserr.New("ErrRuntimeProjectDirContainsCodeDir")
}
if err = fileOp.CopyDirWithNewName(appVersionDir, runtimeDir, create.Name); err != nil {
return
}
projectDir := path.Join(runtimeDir, create.Name)
defer func() {
if err != nil {
_ = fileOp.DeleteDir(projectDir)
@@ -640,7 +669,7 @@ func handleCompose(env gotenv.Env, composeContent []byte, create request.Runtime
for _, host := range create.ExtraHosts {
extraHosts = append(extraHosts, fmt.Sprintf("%s:%s", host.Hostname, host.IP))
}
delete(serviceValue, "extraHosts")
delete(serviceValue, "extra_hosts")
if len(extraHosts) > 0 {
serviceValue["extra_hosts"] = extraHosts
}
+44 -17
View File
@@ -3,6 +3,8 @@ package service
import (
"encoding/base64"
"encoding/json"
"errors"
"path"
"strconv"
"strings"
"time"
@@ -14,6 +16,7 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/repo"
"github.com/1Panel-dev/1Panel/agent/buserr"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/encrypt"
"github.com/1Panel-dev/1Panel/agent/utils/ssh"
terminalai "github.com/1Panel-dev/1Panel/agent/utils/terminal/ai"
@@ -27,6 +30,7 @@ type ISettingService interface {
GetTerminalAIInfo() (*dto.TerminalAIInfo, error)
GetFileManageAIInfo() (*dto.FileManageAIInfo, error)
GetFileHistorySettingInfo() (*response.FileHistorySettingInfo, error)
GetWebsiteDir() string
Update(key, value string) error
UpdateTerminalAI(req dto.TerminalAIInfo) error
UpdateFileManageAI(req dto.FileManageAIInfo) error
@@ -37,7 +41,7 @@ type ISettingService interface {
SetDefaultIsConn(req dto.SSHDefaultConn) error
GetSystemProxy() (*dto.SystemProxy, error)
GetLocalConn() dto.SSHConnData
GetSettingByKey(key string) string
GetLocalConnForSSH() (dto.SSHConnData, error)
SaveDescription(req dto.CommonDescription) error
}
@@ -111,8 +115,31 @@ func (u *SettingService) GetFileHistorySettingInfo() (*response.FileHistorySetti
return historyService.GetSettingInfo()
}
func (u *SettingService) GetWebsiteDir() string {
value, _ := settingRepo.GetValueByKey("WEBSITE_DIR")
if value == "" {
return path.Join(global.Dir.BaseDir, "1panel", "www")
}
return value
}
func (u *SettingService) Update(key, value string) error {
return settingRepo.UpdateOrCreate(key, value)
oldValue := constant.FirewallPortWhiteListValue
if key == constant.FirewallPortWhiteList {
if _, err := parseFirewallPortWhiteList(value); err != nil {
return err
}
if val, err := settingRepo.GetValueByKey(key); err == nil {
oldValue = val
}
}
if err := settingRepo.UpdateOrCreate(key, value); err != nil {
return err
}
if key == constant.FirewallPortWhiteList {
return syncFirewallPortWhiteListAfterUpdate(oldValue)
}
return nil
}
func (u *SettingService) UpdateTerminalAI(req dto.TerminalAIInfo) error {
@@ -267,18 +294,25 @@ func (u *SettingService) GetSystemProxy() (*dto.SystemProxy, error) {
return &systemProxy, nil
}
func (u *SettingService) GetLocalConn() dto.SSHConnData {
func (u *SettingService) loadLocalConn() dto.SSHConnData {
var data dto.SSHConnData
data.LocalSSHConnShow, _ = settingRepo.GetValueByKey("LocalSSHConnShow")
localSSHConnShow, _ := settingRepo.GetValueByKey("LocalSSHConnShow")
data.LocalSSHConnShow = localSSHConnShow
connItem, _ := settingRepo.GetValueByKey("LocalSSHConn")
if len(connItem) == 0 {
return data
}
connInfoInDB, _ := encrypt.StringDecrypt(connItem)
data.LocalSSHConnShow, _ = settingRepo.GetValueByKey("LocalSSHConnShow")
if err := json.Unmarshal([]byte(connInfoInDB), &data); err != nil {
data.LocalSSHConnShow = localSSHConnShow
return data
}
data.LocalSSHConnShow = localSSHConnShow
return data
}
func (u *SettingService) GetLocalConn() dto.SSHConnData {
data := u.loadLocalConn()
if len(data.Password) != 0 {
data.Password = base64.StdEncoding.EncodeToString([]byte(data.Password))
}
@@ -291,19 +325,12 @@ func (u *SettingService) GetLocalConn() dto.SSHConnData {
return data
}
func (u *SettingService) GetSettingByKey(key string) string {
switch key {
case "LocalSSHConn":
value, _ := settingRepo.GetValueByKey(key)
if len(value) == 0 {
return ""
}
itemStr, _ := encrypt.StringDecrypt(value)
return itemStr
default:
value, _ := settingRepo.GetValueByKey(key)
return value
func (u *SettingService) GetLocalConnForSSH() (dto.SSHConnData, error) {
data := u.loadLocalConn()
if len(data.Addr) == 0 {
return data, errors.New("no such ssh conn info in db")
}
return data, nil
}
func (u *SettingService) SaveDescription(req dto.CommonDescription) error {
+10 -3
View File
@@ -15,7 +15,6 @@ import (
"github.com/1Panel-dev/1Panel/agent/app/model"
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/docker"
fileUtils "github.com/1Panel-dev/1Panel/agent/utils/files"
"github.com/docker/docker/api/types/image"
@@ -303,12 +302,20 @@ func loadAppImage(list []dto.DataTree) []dto.DataTree {
if list[i].IsLocal {
appPath = path.Join(global.Dir.AppDir, "local", strings.TrimPrefix(list[i].Key, "local"), list[i].Name)
}
stdout, err := cmd.RunDefaultWithStdoutBashCf("cat %s | grep image: ", path.Join(appPath, "docker-compose.yml"))
composePath := path.Join(appPath, "docker-compose.yml")
content, err := os.ReadFile(composePath)
if err != nil {
list[i].Children = append(list[i].Children, itemAppImage)
continue
}
itemAppImage.Name = strings.ReplaceAll(strings.ReplaceAll(strings.TrimSpace(stdout), "\n", ""), "image: ", "")
for _, line := range strings.Split(string(content), "\n") {
trimmed := strings.TrimSpace(line)
if !strings.HasPrefix(trimmed, "image:") {
continue
}
itemAppImage.Name = strings.TrimSpace(strings.TrimPrefix(trimmed, "image:"))
break
}
for _, imageItem := range imageList {
for _, tag := range imageItem.RepoTags {
if tag == itemAppImage.Name {
+7 -1
View File
@@ -377,6 +377,7 @@ func snapAppImage(snap snapHelper, req dto.SnapshotCreate, targetDir string) err
snap.Task.Log("load docker client failed, skip save app images")
return nil
}
defer client.Close()
images, err := client.ImageList(context.Background(), image.ListOptions{})
if err != nil {
snap.Task.Log("list docker images failed, skip save app images")
@@ -405,7 +406,12 @@ func snapAppImage(snap snapHelper, req dto.SnapshotCreate, targetDir string) err
if len(imageList) != 0 {
snap.Task.Log(strings.Join(imageList, " "))
snap.Task.Logf("docker save %s | gzip -c > %s", strings.Join(imageList, " "), path.Join(targetDir, "images.tar.gz"))
if err := cmd.RunDefaultBashCf("docker save %s | gzip -c > %s", strings.Join(imageList, " "), path.Join(targetDir, "images.tar.gz")); err != nil {
outputPath := path.Join(targetDir, "images.tar.gz")
cmdMgr := cmd.NewCommandMgr()
if _, err := cmdMgr.RunPipeToFile(outputPath,
cmd.PipeCommand{Name: "docker", Args: append([]string{"save"}, imageList...)},
cmd.PipeCommand{Name: "gzip", Args: []string{"-c"}},
); err != nil {
snap.Task.LogFailedWithErr(i18n.GetMsgByKey("SnapDockerSave"), err)
return err
}
+11 -3
View File
@@ -4,6 +4,7 @@ import (
"encoding/json"
"fmt"
"os"
"os/exec"
"path"
"strings"
"time"
@@ -376,7 +377,15 @@ func recoverAppData(src string, itemHelper *snapRecoverHelper) error {
itemHelper.Task.Log(i18n.GetMsgByKey("RecoverAppEmpty"))
return nil
}
if err := cmd.NewCommandMgr(cmd.WithTimeout(10*time.Minute)).RunBashCf("docker load < %s", path.Join(src, "images.tar.gz")); err != nil {
imageFile, err := os.Open(path.Join(src, "images.tar.gz"))
if err != nil {
itemHelper.Task.LogFailedWithErr(i18n.GetMsgByKey("RecoverAppImage"), err)
return fmt.Errorf("docker load images failed, %v", err)
}
defer func() { _ = imageFile.Close() }()
loadCmd := exec.Command("docker", "load")
loadCmd.Stdin = imageFile
if err := loadCmd.Run(); err != nil {
itemHelper.Task.LogFailedWithErr(i18n.GetMsgByKey("RecoverAppImage"), err)
return fmt.Errorf("docker load images failed, %v", err)
}
@@ -457,8 +466,7 @@ func restartCompose(composePath string, itemHelper *snapRecoverHelper) error {
if _, err := os.Stat(pathItem); err != nil {
continue
}
upCmd := fmt.Sprintf("docker compose -f %s up -d", pathItem)
if err := cmd.RunDefaultBashC(upCmd); err != nil {
if err := cmd.NewCommandMgr(cmd.WithTimeout(10*time.Minute)).Run("docker", "compose", "-f", pathItem, "up", "-d"); err != nil {
itemHelper.Task.LogFailedWithErr(i18n.GetMsgByKey("RecoverCompose"), err)
continue
}
+424 -160
View File
@@ -1,10 +1,13 @@
package service
import (
"bufio"
"bytes"
"compress/gzip"
"encoding/base64"
"encoding/json"
"fmt"
"io"
"net"
"os"
"os/user"
@@ -30,6 +33,7 @@ import (
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/common"
"github.com/1Panel-dev/1Panel/agent/utils/re"
"github.com/pkg/errors"
)
@@ -106,16 +110,30 @@ func (u *SSHService) OperateSSH(operation string) error {
if err != nil {
return err
}
if operation == "enable" || operation == "disable" {
serviceName += ".service"
}
if operation == "stop" {
isSocketActive, _ := controller.CheckActive(serviceName + ".socket")
if isSocketActive {
if err := controller.HandleStop(serviceName + ".socket"); err != nil {
global.LOG.Errorf("handle stop %s.socket failed, err: %v", serviceName, err)
}
switch operation {
case "start", "restart":
if err := stopSSHSocketIfActive(serviceName); err != nil {
return err
}
case "stop":
if err := stopSSHSocketIfActive(serviceName); err != nil {
return err
}
case "enable", "disable":
if operation == "disable" {
if err := disableSSHSocket(serviceName, false); err != nil {
return err
}
} else {
if err := disableSSHSocket(serviceName, true); err != nil {
return err
}
if err := controller.Handle("enable", serviceName+".service"); err != nil {
return fmt.Errorf("enable %s.service failed, err: %v", serviceName, err)
}
return nil
}
serviceName += ".service"
}
if err := controller.Handle(operation, serviceName); err != nil {
@@ -124,6 +142,68 @@ func (u *SSHService) OperateSSH(operation string) error {
return nil
}
func restartSSHService(serviceName string) error {
if err := stopSSHSocketIfActive(serviceName); err != nil {
return err
}
if err := controller.HandleRestart(serviceName); err != nil {
return fmt.Errorf("restart %s failed, err: %v", serviceName, err)
}
return nil
}
func stopSSHSocketIfActive(serviceName string) error {
for _, socketName := range loadSSHSocketNames(serviceName) {
active, _ := controller.CheckActive(socketName)
if !active {
continue
}
if err := controller.HandleStop(socketName); err != nil {
return fmt.Errorf("stop %s failed, err: %v", socketName, err)
}
}
return nil
}
func disableSSHSocket(serviceName string, stopActive bool) error {
if stopActive {
if err := stopSSHSocketIfActive(serviceName); err != nil {
return err
}
}
for _, socketName := range loadSSHSocketNames(serviceName) {
if err := controller.Handle("disable", socketName); err != nil {
return fmt.Errorf("disable %s failed, err: %v", socketName, err)
}
}
return nil
}
func loadSSHSocketNames(serviceName string) []string {
baseName := strings.TrimSuffix(serviceName, ".service")
candidates := []string{baseName + ".socket"}
switch baseName {
case "ssh":
candidates = append(candidates, "sshd.socket")
case "sshd":
candidates = append(candidates, "ssh.socket")
}
seen := map[string]struct{}{}
var sockets []string
for _, candidate := range candidates {
if _, ok := seen[candidate]; ok {
continue
}
seen[candidate] = struct{}{}
exist, _ := controller.CheckExist(candidate)
if exist {
sockets = append(sockets, candidate)
}
}
return sockets
}
func (u *SSHService) Update(req dto.SSHUpdate) error {
serviceName, err := loadServiceName()
if err != nil {
@@ -142,8 +222,7 @@ func (u *SSHService) Update(req dto.SSHUpdate) error {
handleSSHPortUpdate(oldPortValue, req.NewValue)
}
_ = controller.HandleRestart(serviceName)
return nil
return restartSSHService(serviceName)
}
func loadSSHServiceStatus(data *dto.SSHInfo) {
@@ -155,17 +234,37 @@ func loadSSHServiceStatus(data *dto.SSHInfo) {
}
active, err := controller.CheckActive(serviceName)
data.IsActive = active
data.IsActive = active || hasActiveSSHSocket(serviceName)
if !active && err != nil {
data.Message = err.Error()
}
enable, err := controller.CheckEnable(serviceName)
if err != nil {
data.AutoStart = false
data.AutoStart = hasEnabledSSHSocket(serviceName)
return
}
data.AutoStart = enable
data.AutoStart = enable || hasEnabledSSHSocket(serviceName)
}
func hasActiveSSHSocket(serviceName string) bool {
for _, socketName := range loadSSHSocketNames(serviceName) {
active, _ := controller.CheckActive(socketName)
if active {
return true
}
}
return false
}
func hasEnabledSSHSocket(serviceName string) bool {
for _, socketName := range loadSSHSocketNames(serviceName) {
enable, _ := controller.CheckEnable(socketName)
if enable {
return true
}
}
return false
}
func loadSSHConfigInfo(data *dto.SSHInfo) {
@@ -568,30 +667,26 @@ func (u *SSHService) LoadLog(ctx *gin.Context, req dto.SearchSSHLog) (int64, []d
return 0, data, err
}
for _, item := range fileItems {
if item.IsDir() || (!strings.HasPrefix(item.Name(), "secure") && !strings.HasPrefix(item.Name(), "auth")) {
if item.IsDir() || (!strings.HasPrefix(item.Name(), "secure") && !strings.HasPrefix(item.Name(), "auth.log")) {
continue
}
info, _ := item.Info()
itemPath := path.Join(baseDir, info.Name())
if !strings.HasSuffix(item.Name(), ".gz") {
fileList = append(fileList, sshFileItem{Name: itemPath, Year: info.ModTime().Year()})
continue
}
itemFileName := strings.TrimSuffix(itemPath, ".gz")
if _, err := os.Stat(itemFileName); err != nil && os.IsNotExist(err) {
if err := handleGunzip(itemPath); err == nil {
fileList = append(fileList, sshFileItem{Name: itemFileName, Year: info.ModTime().Year()})
if strings.HasSuffix(itemPath, ".gz") {
if _, err := os.Stat(strings.TrimSuffix(itemPath, ".gz")); err == nil {
continue
}
}
fileList = append(fileList, sshFileItem{Name: itemPath, Year: info.ModTime().Year()})
}
fileList = sortFileList(fileList)
command := ""
filter := ""
if len(req.Info) != 0 {
if cmd.CheckIllegal(req.Info) {
return 0, data, buserr.New("ErrCmdIllegal")
}
command = fmt.Sprintf(" | grep '%s'", req.Info)
filter = req.Info
}
showCountFrom := (req.Page - 1) * req.PageSize
@@ -599,28 +694,18 @@ func (u *SSHService) LoadLog(ctx *gin.Context, req dto.SearchSSHLog) (int64, []d
nyc, _ := time.LoadLocation(common.LoadTimeZoneByCmd())
itemFailed, itemTotal := 0, 0
for _, file := range fileList {
commandItem := ""
if strings.HasPrefix(path.Base(file.Name), "secure") {
switch req.Status {
case constant.StatusSuccess:
commandItem = fmt.Sprintf("cat %s | grep -a Accepted %s", file.Name, command)
case constant.StatusFailed:
commandItem = fmt.Sprintf("cat %s | grep -a 'Failed password for' %s", file.Name, command)
default:
commandItem = fmt.Sprintf("cat %s | grep -aE '(Failed password for|Accepted)' %s", file.Name, command)
}
}
if strings.HasPrefix(path.Base(file.Name), "auth.log") {
switch req.Status {
case constant.StatusSuccess:
commandItem = fmt.Sprintf("cat %s | grep -a Accepted %s", file.Name, command)
case constant.StatusFailed:
commandItem = fmt.Sprintf("cat %s | grep -aE 'Failed password for|Connection closed by authenticating user' %s", file.Name, command)
default:
commandItem = fmt.Sprintf("cat %s | grep -aE \"(Failed password for|Connection closed by authenticating user|Accepted)\" %s", file.Name, command)
}
}
dataItem, successCount, failedCount := loadSSHData(ctx, commandItem, showCountFrom, showCountTo, file.Year, nyc)
dataItem, successCount, failedCount := loadSSHData(
ctx,
file.Name,
req.Status,
filter,
req.StartTime,
req.EndTime,
showCountFrom,
showCountTo,
file.Year,
nyc,
)
itemFailed += failedCount
itemTotal += successCount + failedCount
showCountFrom = showCountFrom - (successCount + failedCount)
@@ -733,8 +818,7 @@ func (u *SSHService) UpdateByFile(req dto.SSHConfUpdate) error {
if err != nil {
return err
}
_ = controller.HandleRestart(serviceName)
return nil
return restartSSHService(serviceName)
}
func sortFileList(fileNames []sshFileItem) []sshFileItem {
@@ -1124,7 +1208,28 @@ func isSSHConfigPathAllowed(fileName string) bool {
return false
}
func loadSSHData(ctx *gin.Context, command string, showCountFrom, showCountTo, currentYear int, nyc *time.Location) ([]dto.SSHHistory, int, int) {
type sshLogHeader struct {
DateStr string
Process string
PID string
Message string
}
type sshParsedLog struct {
History dto.SSHHistory
SessionKey string
Raw string
Search string
Index int
}
func loadSSHData(
ctx *gin.Context,
filePath, status, filter string,
startTime, endTime time.Time,
showCountFrom, showCountTo, currentYear int,
nyc *time.Location,
) ([]dto.SSHHistory, int, int) {
var (
datas []dto.SSHHistory
successCount int
@@ -1134,117 +1239,298 @@ func loadSSHData(ctx *gin.Context, command string, showCountFrom, showCountTo, c
if err != nil {
return datas, 0, 0
}
stdout, err := cmd.RunDefaultWithStdoutBashC(command)
lines, err := loadSSHLogLines(filePath)
if err != nil {
return datas, 0, 0
}
lines := strings.Split(stdout, "\n")
for i := len(lines) - 1; i >= 0; i-- {
var itemData dto.SSHHistory
switch {
case strings.Contains(lines[i], "Failed password for"):
itemData = loadFailedSecureDatas(lines[i])
if checkIsStandard(itemData) {
if successCount+failedCount >= showCountFrom && (showCountTo == -1 || successCount+failedCount < showCountTo) {
itemData.Area, _ = geo.GetIPLocation(getLoc, itemData.Address, common.GetLang(ctx))
itemData.Date = loadDate(currentYear, itemData.DateStr, nyc)
datas = append(datas, itemData)
}
failedCount++
}
case strings.Contains(lines[i], "Connection closed by authenticating user"):
itemData = loadFailedAuthDatas(lines[i])
if checkIsStandard(itemData) {
if successCount+failedCount >= showCountFrom && (showCountTo == -1 || successCount+failedCount < showCountTo) {
itemData.Area, _ = geo.GetIPLocation(getLoc, itemData.Address, common.GetLang(ctx))
itemData.Date = loadDate(currentYear, itemData.DateStr, nyc)
datas = append(datas, itemData)
}
failedCount++
}
case strings.Contains(lines[i], "Accepted "):
itemData = loadSuccessDatas(lines[i])
if checkIsStandard(itemData) {
if successCount+failedCount >= showCountFrom && (showCountTo == -1 || successCount+failedCount < showCountTo) {
itemData.Area, _ = geo.GetIPLocation(getLoc, itemData.Address, common.GetLang(ctx))
itemData.Date = loadDate(currentYear, itemData.DateStr, nyc)
datas = append(datas, itemData)
}
successCount++
}
items := collectSSHLogItems(lines, filter, status)
for i := len(items) - 1; i >= 0; i-- {
itemData := items[i].History
if !matchSSHLogStatus(status, itemData.Status) || !checkIsStandard(itemData) {
continue
}
itemData.Date = loadDate(currentYear, itemData.DateStr, nyc)
if !isSSHLogWithinTimeRange(itemData.Date, startTime, endTime) {
continue
}
if successCount+failedCount >= showCountFrom && (showCountTo == -1 || successCount+failedCount < showCountTo) {
itemData.Area, _ = geo.GetIPLocation(getLoc, itemData.Address, common.GetLang(ctx))
datas = append(datas, itemData)
}
if itemData.Status == constant.StatusSuccess {
successCount++
} else {
failedCount++
}
}
return datas, successCount, failedCount
}
func loadSuccessDatas(line string) dto.SSHHistory {
var data dto.SSHHistory
parts := strings.Fields(line)
index, dataStr := analyzeDateStr(parts)
if dataStr == "" {
return data
func isSSHLogWithinTimeRange(itemTime, startTime, endTime time.Time) bool {
if startTime.IsZero() || endTime.IsZero() {
return true
}
data.DateStr = dataStr
data.AuthMode = parts[4+index]
data.User = parts[6+index]
data.Address = parts[8+index]
data.Port = parts[10+index]
data.Status = constant.StatusSuccess
return data
return itemTime.After(startTime) && itemTime.Before(endTime)
}
func loadFailedAuthDatas(line string) dto.SSHHistory {
var data dto.SSHHistory
parts := strings.Fields(line)
index, dataStr := analyzeDateStr(parts)
if dataStr == "" {
return data
func collectSSHLogItems(lines []string, filter, status string) []sshParsedLog {
var items []sshParsedLog
auxiliaryIndex := make(map[string]int)
sessionHasAuthEvent := make(map[string]bool)
for lineIndex, line := range lines {
if !shouldParseSSHLogLine(line, status, filter) {
continue
}
item, ok := parseSSHLogLine(line)
if !ok || !checkIsStandard(item.History) {
continue
}
item.Index = lineIndex
item.Search = line
if isSSHAuthEvent(item) && item.SessionKey != "" {
sessionHasAuthEvent[item.SessionKey] = true
items = append(items, item)
continue
}
if index, ok := auxiliaryIndex[item.SessionKey]; ok {
items[index].Search += "\n" + line
continue
}
auxiliaryIndex[item.SessionKey] = len(items)
items = append(items, item)
}
data.DateStr = dataStr
switch index {
case 1:
data.User = parts[9]
case 2:
data.User = parts[10]
items = filterRedundantSSHSessionItems(items, sessionHasAuthEvent)
if filter != "" {
filteredItems := make([]sshParsedLog, 0, len(items))
for _, item := range items {
if strings.Contains(item.Search, filter) {
filteredItems = append(filteredItems, item)
}
}
items = filteredItems
}
sort.SliceStable(items, func(i, j int) bool {
return items[i].Index < items[j].Index
})
return items
}
func filterRedundantSSHSessionItems(items []sshParsedLog, sessionHasAuthEvent map[string]bool) []sshParsedLog {
filteredItems := make([]sshParsedLog, 0, len(items))
for _, item := range items {
if !isSSHAuthEvent(item) && item.SessionKey != "" && sessionHasAuthEvent[item.SessionKey] {
continue
}
filteredItems = append(filteredItems, item)
}
return filteredItems
}
func isSSHAuthEvent(item sshParsedLog) bool {
return item.History.Status == constant.StatusSuccess || item.History.AuthMode != ""
}
func shouldParseSSHLogLine(line, status, filter string) bool {
if !strings.Contains(line, "sshd") {
return false
}
if filter != "" {
return containsKnownSSHLogMessage(line)
}
switch status {
case constant.StatusSuccess:
return strings.Contains(line, "Accepted ")
case constant.StatusFailed:
// Accepted lines are still needed here to suppress redundant session failure records from the same SSH session.
return containsFailedSSHLogMessage(line) || strings.Contains(line, "Accepted ")
default:
data.User = parts[7]
return containsKnownSSHLogMessage(line)
}
data.AuthMode = parts[6+index]
data.Address = parts[9+index]
data.Port = parts[11+index]
data.Status = constant.StatusFailed
if strings.Contains(line, ": ") {
data.Message = strings.Split(line, ": ")[1]
}
return data
}
func loadFailedSecureDatas(line string) dto.SSHHistory {
var data dto.SSHHistory
parts := strings.Fields(line)
index, dataStr := analyzeDateStr(parts)
if dataStr == "" {
return data
func containsKnownSSHLogMessage(line string) bool {
return strings.Contains(line, "Accepted ") || containsFailedSSHLogMessage(line)
}
func containsFailedSSHLogMessage(line string) bool {
return strings.Contains(line, "Failed ") ||
strings.Contains(line, "Invalid user ") ||
strings.Contains(line, "Connection closed by ") ||
strings.Contains(line, "Disconnected from ") ||
strings.Contains(line, "Received disconnect from ") ||
strings.Contains(line, "maximum authentication attempts exceeded") ||
strings.Contains(line, " not allowed")
}
func loadSSHLogLines(filePath string) ([]string, error) {
file, err := os.Open(filePath)
if err != nil {
return nil, err
}
data.DateStr = dataStr
if strings.Contains(line, " invalid ") {
data.AuthMode = parts[4+index]
index += 2
} else {
data.AuthMode = parts[4+index]
defer file.Close()
var reader io.Reader = file
if strings.HasSuffix(filePath, ".gz") {
gzipReader, err := gzip.NewReader(file)
if err != nil {
return nil, err
}
defer gzipReader.Close()
reader = gzipReader
}
data.User = parts[6+index]
data.Address = parts[8+index]
data.Port = parts[10+index]
data.Status = constant.StatusFailed
if strings.Contains(line, ": ") {
data.Message = strings.Split(line, ": ")[1]
var lines []string
scanner := bufio.NewScanner(reader)
buf := make([]byte, 0, 64*1024)
scanner.Buffer(buf, 1024*1024)
for scanner.Scan() {
lines = append(lines, scanner.Text())
}
return data
return lines, scanner.Err()
}
func matchSSHLogStatus(requestStatus, itemStatus string) bool {
switch requestStatus {
case constant.StatusSuccess:
return itemStatus == constant.StatusSuccess
case constant.StatusFailed:
return itemStatus == constant.StatusFailed
default:
return true
}
}
func parseSSHLogLine(line string) (sshParsedLog, bool) {
header, ok := parseSSHLogHeader(line)
if !ok {
return sshParsedLog{}, false
}
data, ok := parseSSHLogMessage(header.Message)
if !ok {
return sshParsedLog{}, false
}
data.DateStr = header.DateStr
data.Message = header.Message
sessionKey := loadSSHLogSessionKey(header, data, line)
return sshParsedLog{History: data, SessionKey: sessionKey, Raw: line}, true
}
func parseSSHLogHeader(line string) (sshLogHeader, bool) {
for _, pattern := range []string{re.SSHRFC3339LinePattern, re.SSHDateTimeLinePattern, re.SSHSyslogLinePattern} {
matches := re.GetRegex(pattern).FindStringSubmatch(line)
if len(matches) != 5 {
continue
}
dateStr := normalizeSSHLogDate(matches[1])
if dateStr == "" {
return sshLogHeader{}, false
}
return sshLogHeader{DateStr: dateStr, Process: matches[2], PID: matches[3], Message: matches[4]}, true
}
return sshLogHeader{}, false
}
func loadSSHLogSessionKey(header sshLogHeader, data dto.SSHHistory, line string) string {
if header.Process == "sshd-session" && data.Address != "" && data.Port != "" {
return data.Address + ":" + data.Port
}
if header.PID != "" {
return "pid:" + header.PID
}
if data.Address != "" && data.Port != "" {
return data.Address + ":" + data.Port
}
return line
}
func normalizeSSHLogDate(dateStr string) string {
if t, err := time.Parse(time.RFC3339Nano, dateStr); err == nil {
return t.Format("2006 Jan 2 15:04:05")
}
if t, err := time.Parse(constant.DateTimeLayout, dateStr); err == nil {
return t.Format("2006 Jan 2 15:04:05")
}
if _, err := time.Parse("Jan 2 15:04:05", dateStr); err == nil {
return dateStr
}
return ""
}
func parseSSHLogMessage(message string) (dto.SSHHistory, bool) {
if matches := re.GetRegex(re.SSHAcceptedPattern).FindStringSubmatch(message); len(matches) == 5 {
return dto.SSHHistory{
AuthMode: matches[1],
User: matches[2],
Address: matches[3],
Port: matches[4],
Status: constant.StatusSuccess,
}, true
}
if matches := re.GetRegex(re.SSHFailedPattern).FindStringSubmatch(message); len(matches) == 6 {
return dto.SSHHistory{
AuthMode: matches[1],
User: matches[3],
Address: matches[4],
Port: matches[5],
Status: constant.StatusFailed,
}, true
}
if matches := re.GetRegex(re.SSHInvalidUserPattern).FindStringSubmatch(message); len(matches) == 4 {
return dto.SSHHistory{
User: matches[1],
Address: matches[2],
Port: matches[3],
Status: constant.StatusFailed,
}, true
}
if matches := re.GetRegex(re.SSHClosedPattern).FindStringSubmatch(message); len(matches) == 4 {
return dto.SSHHistory{
User: matches[1],
Address: matches[2],
Port: matches[3],
Status: constant.StatusFailed,
}, true
}
if matches := re.GetRegex(re.SSHDisconnectedPattern).FindStringSubmatch(message); len(matches) == 4 {
return dto.SSHHistory{
User: matches[1],
Address: matches[2],
Port: matches[3],
Status: constant.StatusFailed,
}, true
}
if matches := re.GetRegex(re.SSHDisconnectPattern).FindStringSubmatch(message); len(matches) == 3 {
return dto.SSHHistory{
Address: matches[1],
Port: matches[2],
Status: constant.StatusFailed,
}, true
}
if matches := re.GetRegex(re.SSHMaxAuthPattern).FindStringSubmatch(message); len(matches) == 4 {
return dto.SSHHistory{
User: matches[1],
Address: matches[2],
Port: matches[3],
Status: constant.StatusFailed,
}, true
}
if matches := re.GetRegex(re.SSHNotAllowedPattern).FindStringSubmatch(message); len(matches) == 3 {
return dto.SSHHistory{
User: matches[1],
Address: matches[2],
Status: constant.StatusFailed,
}, true
}
return dto.SSHHistory{}, false
}
func checkIsStandard(item dto.SSHHistory) bool {
if len(item.Address) == 0 || net.ParseIP(item.Address) == nil {
return false
}
if item.Port == "" {
return true
}
portItem, _ := strconv.Atoi(item.Port)
return portItem > 0 && portItem < 65536
}
@@ -1274,28 +1560,6 @@ func loadDate(currentYear int, DateStr string, nyc *time.Location) time.Time {
return itemDate
}
func analyzeDateStr(parts []string) (int, string) {
t, err := time.Parse(time.RFC3339Nano, parts[0])
if err == nil {
if len(parts) < 12 {
return 0, ""
}
return 0, t.Format("2006 Jan 2 15:04:05")
}
t, err = time.Parse(constant.DateTimeLayout, fmt.Sprintf("%s %s", parts[0], parts[1]))
if err == nil {
if len(parts) < 14 {
return 0, ""
}
return 1, t.Format("2006 Jan 2 15:04:05")
}
if len(parts) < 14 {
return 0, ""
}
return 2, fmt.Sprintf("%s %s %s", parts[0], parts[1], parts[2])
}
func loadEncryptioMode(content string) string {
if strings.HasPrefix(content, "ssh-rsa") {
return "rsa"
+62
View File
@@ -1,14 +1,20 @@
package service
import (
"os"
"github.com/1Panel-dev/1Panel/agent/app/dto"
"github.com/1Panel-dev/1Panel/agent/app/dto/request"
"github.com/1Panel-dev/1Panel/agent/app/dto/response"
"github.com/1Panel-dev/1Panel/agent/app/repo"
"github.com/1Panel-dev/1Panel/agent/utils/files"
)
type TaskLogService struct{}
type ITaskLogService interface {
Page(req dto.SearchTaskLogReq) (int64, []dto.TaskDTO, error)
ReadByLine(req request.TaskLogReadReq) (*response.FileLineContent, error)
SyncForRestart() error
CountExecutingTask() (int64, error)
}
@@ -46,6 +52,62 @@ func (u *TaskLogService) Page(req dto.SearchTaskLogReq) (int64, []dto.TaskDTO, e
return total, items, err
}
func (u *TaskLogService) ReadByLine(req request.TaskLogReadReq) (*response.FileLineContent, error) {
opts := []repo.DBOption{}
if req.TaskID != "" {
opts = append(opts, taskRepo.WithByID(req.TaskID))
} else {
opts = append(opts, repo.WithOrderRuleBy("created_at", "desc"), repo.WithByType(req.TaskType), taskRepo.WithOperate(req.TaskOperate), taskRepo.WithResourceID(req.ResourceID))
}
taskModel, err := taskRepo.GetFirst(opts...)
if err != nil {
return nil, err
}
file, err := os.Open(taskModel.LogFile)
if err != nil {
return nil, err
}
defer file.Close()
stat, err := file.Stat()
if err != nil {
return nil, err
}
var (
lines []string
isEndOfFile bool
scope string
logFileRes *dto.LogFileRes
)
if stat.Size() > files.MaxReadFileSize {
lines, _ = files.TailFromEnd(taskModel.LogFile, req.PageSize)
isEndOfFile = true
scope = "tail"
} else {
logFileRes, err = files.ReadFileByLine(taskModel.LogFile, req.Page, req.PageSize, req.Latest)
if err != nil {
return nil, err
}
scope = "page"
lines = logFileRes.Lines
}
res := &response.FileLineContent{
End: isEndOfFile,
Path: taskModel.LogFile,
TaskStatus: taskModel.Status,
Lines: lines,
Scope: scope,
}
if logFileRes != nil {
res.TotalLines = logFileRes.TotalLines
res.Total = logFileRes.TotalPages
res.End = logFileRes.IsEndOfFile
}
return res, nil
}
func (u *TaskLogService) SyncForRestart() error {
return taskRepo.UpdateRunningTaskToFailed()
}
+126
View File
@@ -0,0 +1,126 @@
package service
import (
"encoding/json"
"strings"
"github.com/1Panel-dev/1Panel/agent/utils/common"
)
const (
vllmAppKeyForUpgrade = "vllm"
vllmImageEnvKey = "IMAGE"
vllmImageTypeNvidia = "nvidia"
vllmImageTypeIntel = "intel"
)
func resolveVllmVersionFamily(version, image string) string {
normalizedVersion := strings.ToLower(strings.TrimSpace(version))
if strings.HasPrefix(normalizedVersion, vllmImageTypeIntel+"-") {
return vllmImageTypeIntel
}
if strings.HasPrefix(normalizedVersion, vllmImageTypeNvidia+"-") {
return vllmImageTypeNvidia
}
normalizedImage := strings.ToLower(strings.TrimSpace(image))
if strings.Contains(normalizedImage, "intel/") || strings.Contains(normalizedImage, "llm-scaler-vllm") {
return vllmImageTypeIntel
}
return vllmImageTypeNvidia
}
func trimVllmVersionFamily(version string) string {
trimmed := strings.TrimSpace(version)
normalized := strings.ToLower(trimmed)
for _, family := range []string{vllmImageTypeNvidia, vllmImageTypeIntel} {
prefix := family + "-"
if strings.HasPrefix(normalized, prefix) {
return strings.TrimSpace(trimmed[len(prefix):])
}
}
return trimmed
}
func buildDefaultVllmImageByVersion(version string) string {
tag := trimVllmVersionFamily(version)
if resolveVllmVersionFamily(version, "") == vllmImageTypeIntel {
return "intel/llm-scaler-vllm:" + tag
}
if tag != "" && !strings.HasPrefix(strings.ToLower(tag), "v") {
tag = "v" + tag
}
return "vllm/vllm-openai:" + tag
}
func isVllmUpgradeVersionAllowed(currentVersion, targetVersion, currentImage string) bool {
currentFamily := resolveVllmVersionFamily(currentVersion, currentImage)
targetFamily := resolveVllmVersionFamily(targetVersion, "")
return currentFamily == targetFamily
}
func hasVllmVersionFamilyPrefix(version string) bool {
normalized := strings.ToLower(strings.TrimSpace(version))
return strings.HasPrefix(normalized, vllmImageTypeNvidia+"-") || strings.HasPrefix(normalized, vllmImageTypeIntel+"-")
}
func isVllmUpgradeCandidate(currentVersion, targetVersion, currentImage string) bool {
if strings.TrimSpace(currentVersion) == strings.TrimSpace(targetVersion) {
return false
}
if !isVllmUpgradeVersionAllowed(currentVersion, targetVersion, currentImage) {
return false
}
if common.CompareVersion(targetVersion, currentVersion) {
return true
}
return !hasVllmVersionFamilyPrefix(currentVersion) &&
resolveVllmVersionFamily(targetVersion, "") == vllmImageTypeNvidia &&
trimVllmVersionFamily(currentVersion) == trimVllmVersionFamily(targetVersion)
}
func buildVllmUpgradeImage(currentImage, currentVersion, targetVersion string) string {
trimmedImage := strings.TrimSpace(currentImage)
if trimmedImage == "" || trimmedImage == buildDefaultVllmImageByVersion(currentVersion) {
return buildDefaultVllmImageByVersion(targetVersion)
}
return trimmedImage
}
func loadVllmImageFromEnv(raw string) string {
envs := make(map[string]interface{})
if strings.TrimSpace(raw) == "" {
return ""
}
if err := json.Unmarshal([]byte(raw), &envs); err != nil {
return ""
}
if image, ok := envs[vllmImageEnvKey].(string); ok {
return strings.TrimSpace(image)
}
return ""
}
func setVllmImageInEnvContent(content []byte, image string) []byte {
normalizedImage := strings.TrimSpace(image)
if normalizedImage == "" {
return content
}
lines := strings.Split(string(content), "\n")
replaced := false
for index, line := range lines {
if strings.HasPrefix(line, vllmImageEnvKey+"=") {
lines[index] = vllmImageEnvKey + "=" + normalizedImage
replaced = true
break
}
}
if !replaced {
if len(lines) > 0 && lines[len(lines)-1] == "" {
lines[len(lines)-1] = vllmImageEnvKey + "=" + normalizedImage
lines = append(lines, "")
} else {
lines = append(lines, vllmImageEnvKey+"="+normalizedImage)
}
}
return []byte(strings.Join(lines, "\n"))
}
+49 -38
View File
@@ -85,7 +85,8 @@ type IWebsiteService interface {
ChangeGroup(group, newGroup uint) error
ChangeDefaultServer(id uint) error
PreInstallCheck(req request.WebsiteInstallCheckReq) ([]response.WebsitePreInstallCheck, error)
OpWebsiteLog(req request.WebsiteLogReq) (*response.WebsiteLog, error)
GetWebsiteLog(req request.WebsiteLogSearchReq) (*response.WebsiteLog, error)
OpWebsiteLog(req request.WebsiteLogReq) error
UpdateStream(req request.StreamUpdate) error
GetNginxConfigByScope(req request.NginxScopeReq) (*response.WebsiteNginxConfig, error)
@@ -1124,7 +1125,7 @@ func (w WebsiteService) UpdateNginxConfigFile(req request.WebsiteNginxUpdate) er
return nginxCheckAndReload(nginxFull.SiteConfig.OldContent, filePath, nginxFull.Install.ContainerName)
}
func (w WebsiteService) OpWebsiteLog(req request.WebsiteLogReq) (*response.WebsiteLog, error) {
func (w WebsiteService) GetWebsiteLog(req request.WebsiteLogSearchReq) (*response.WebsiteLog, error) {
website, err := websiteRepo.GetFirst(repo.WithByID(req.ID))
if err != nil {
return nil, err
@@ -1133,29 +1134,36 @@ func (w WebsiteService) OpWebsiteLog(req request.WebsiteLogReq) (*response.Websi
res := &response.WebsiteLog{
Content: "",
}
switch req.LogType {
case constant.AccessLog:
res.Enable = website.AccessLog
if !website.AccessLog {
return res, nil
}
case constant.ErrorLog:
res.Enable = website.ErrorLog
if !website.ErrorLog {
return res, nil
}
}
filePath := path.Join(sitePath, "log", req.LogType)
logFileRes, err := files.ReadFileByLine(filePath, req.Page, req.PageSize, false)
if err != nil {
return nil, err
}
res.End = logFileRes.IsEndOfFile
res.Path = filePath
res.Content = strings.Join(logFileRes.Lines, "\n")
return res, nil
}
func (w WebsiteService) OpWebsiteLog(req request.WebsiteLogReq) error {
website, err := websiteRepo.GetFirst(repo.WithByID(req.ID))
if err != nil {
return err
}
sitePath := GetSitePath(website, SiteDir)
switch req.Operate {
case constant.GetLog:
switch req.LogType {
case constant.AccessLog:
res.Enable = website.AccessLog
if !website.AccessLog {
return res, nil
}
case constant.ErrorLog:
res.Enable = website.ErrorLog
if !website.ErrorLog {
return res, nil
}
}
filePath := path.Join(sitePath, "log", req.LogType)
logFileRes, err := files.ReadFileByLine(filePath, req.Page, req.PageSize, false)
if err != nil {
return nil, err
}
res.End = logFileRes.IsEndOfFile
res.Path = filePath
res.Content = strings.Join(logFileRes.Lines, "\n")
return res, nil
case constant.DisableLog:
params := dto.NginxParam{}
switch req.LogType {
@@ -1172,10 +1180,10 @@ func (w WebsiteService) OpWebsiteLog(req request.WebsiteLogReq) (*response.Websi
nginxParams = append(nginxParams, params)
if err := updateNginxConfig(constant.NginxScopeServer, nginxParams, &website); err != nil {
return nil, err
return err
}
if err := websiteRepo.Save(context.Background(), &website); err != nil {
return nil, err
return err
}
case constant.EnableLog:
key := "access_log"
@@ -1194,18 +1202,18 @@ func (w WebsiteService) OpWebsiteLog(req request.WebsiteLogReq) (*response.Websi
website.ErrorLog = true
}
if err := updateNginxConfig(constant.NginxScopeServer, []dto.NginxParam{{Name: key, Params: params}}, &website); err != nil {
return nil, err
return err
}
if err := websiteRepo.Save(context.Background(), &website); err != nil {
return nil, err
return err
}
case constant.DeleteLog:
logPath := path.Join(sitePath, "log", req.LogType)
if err := files.NewFileOp().WriteFile(logPath, strings.NewReader(""), constant.DirPerm); err != nil {
return nil, err
return err
}
}
return res, nil
return nil
}
func (w WebsiteService) ChangeDefaultServer(id uint) error {
@@ -2359,13 +2367,14 @@ func (w WebsiteService) ExecComposer(req request.ExecComposerReq) error {
if err != nil {
return err
}
var command string
var composerArgs []string
if req.Command != "custom" {
command = fmt.Sprintf("%s %s", req.Command, req.ExtCommand)
composerArgs = append(composerArgs, req.Command)
composerArgs = append(composerArgs, strings.Fields(req.ExtCommand)...)
} else {
command = req.ExtCommand
composerArgs = strings.Fields(req.ExtCommand)
}
command = strings.TrimSpace(command)
command := strings.Join(composerArgs, " ")
resourceName := fmt.Sprintf("composer %s", command)
composerTask, err := task.NewTaskWithOps(resourceName, task.TaskExec, req.Command, req.TaskID, website.ID)
if err != nil {
@@ -2387,13 +2396,15 @@ func (w WebsiteService) ExecComposer(req request.ExecComposerReq) error {
return err
}
if err := cmdMgr.Run("docker", "exec",
execArgs := []string{
"exec",
"-u", req.User,
runtime.ContainerName,
"composer",
command,
"--working-dir="+execDir,
); err != nil {
}
execArgs = append(execArgs, composerArgs...)
execArgs = append(execArgs, "--working-dir="+execDir)
if err := cmdMgr.Run("docker", execArgs...); err != nil {
return err
}
return nil
+7 -3
View File
@@ -59,8 +59,12 @@ func (w WebsiteAcmeAccountService) Create(create request.WebsiteAcmeAccountCreat
acmeAccount.CaDirURL = create.CaDirURL
}
client, err := ssl.NewAcmeClient(acmeAccount, getSystemProxy(acmeAccount.UseProxy))
if err != nil {
var client *ssl.AcmeClient
if err := withLegoLogger(nil, func() error {
var err error
client, err = ssl.NewRegisterClient(acmeAccount, getSystemProxy(acmeAccount.UseProxy))
return err
}); err != nil {
return nil, err
}
privateKey, err := ssl.GetPrivateKey(client.User.GetPrivateKey(), ssl.KeyType(create.KeyType))
@@ -68,7 +72,7 @@ func (w WebsiteAcmeAccountService) Create(create request.WebsiteAcmeAccountCreat
return nil, err
}
acmeAccount.PrivateKey = string(privateKey)
acmeAccount.URL = client.User.Registration.URI
acmeAccount.URL = client.User.Registration.Location
if err := websiteAcmeRepo.Create(*acmeAccount); err != nil {
return nil, err
+2 -4
View File
@@ -28,10 +28,9 @@ import (
"github.com/1Panel-dev/1Panel/agent/constant"
"github.com/1Panel-dev/1Panel/agent/global"
"github.com/1Panel-dev/1Panel/agent/i18n"
"github.com/1Panel-dev/1Panel/agent/utils/cmd"
"github.com/1Panel-dev/1Panel/agent/utils/files"
"github.com/1Panel-dev/1Panel/agent/utils/ssl"
"github.com/go-acme/lego/v4/certcrypto"
"github.com/go-acme/lego/v5/certcrypto"
)
type WebsiteCAService struct {
@@ -378,8 +377,7 @@ func (w WebsiteCAService) ObtainSSL(req request.WebsiteCAObtain) (*model.Website
workDir = websiteSSL.Dir
}
logger.Println(i18n.GetMsgByKey("ExecShellStart"))
cmdMgr := cmd.NewCommandMgr(cmd.WithTimeout(30*time.Minute), cmd.WithLogger(logger), cmd.WithWorkDir(workDir))
if err = cmdMgr.RunBashC(websiteSSL.Shell); err != nil {
if err = runShellScriptFile(workDir, websiteSSL.Shell, logger); err != nil {
logger.Println(i18n.GetMsgWithMap("ErrExecShell", map[string]interface{}{"err": err.Error()}))
} else {
logger.Println(i18n.GetMsgByKey("ExecShellSuccess"))
+49 -14
View File
@@ -70,16 +70,16 @@ func (w WebsiteService) GetRewriteConfig(req request.NginxRewriteReq) (*response
}
}
} else {
rewriteFile := fmt.Sprintf("rewrite/%s.conf", strings.ToLower(req.Name))
contentByte, _ = nginx_conf.Rewrites.ReadFile(rewriteFile)
if contentByte == nil {
customRewriteDir := GetOpenrestyDir(DefaultRewriteDir)
safeName := path.Base(req.Name)
if safeName != req.Name || strings.Contains(safeName, "..") {
return nil, buserr.New("ErrInvalidParams")
}
customRewriteFile := path.Join(customRewriteDir, fmt.Sprintf("%s.conf", strings.ToLower(req.Name)))
safeName, err := getSafeRewriteName(req.Name)
if err != nil {
return nil, err
}
customRewriteFile := path.Join(GetOpenrestyDir(DefaultRewriteDir), fmt.Sprintf("%s.conf", safeName))
if files.NewFileOp().Stat(customRewriteFile) {
contentByte, err = files.NewFileOp().GetContent(customRewriteFile)
} else {
rewriteFile := fmt.Sprintf("rewrite/%s.conf", strings.ToLower(safeName))
contentByte, _ = nginx_conf.Rewrites.ReadFile(rewriteFile)
}
}
return &response.NginxRewriteRes{
@@ -95,14 +95,18 @@ func (w WebsiteService) OperateCustomRewrite(req request.CustomRewriteOperate) e
return err
}
}
safeName := path.Base(req.Name)
if safeName != req.Name || strings.Contains(safeName, "..") {
return buserr.New("ErrInvalidParams")
safeName, err := getSafeRewriteName(req.Name)
if err != nil {
return err
}
rewriteFile := path.Join(rewriteDir, fmt.Sprintf("%s.conf", req.Name))
rewriteFile := path.Join(rewriteDir, fmt.Sprintf("%s.conf", safeName))
switch req.Operate {
case "create":
if fileOp.Stat(rewriteFile) {
exist, err := customRewriteNameExist(rewriteDir, safeName)
if err != nil {
return err
}
if exist || builtinRewriteNameExist(safeName) {
return buserr.New("ErrNameIsExist")
}
return fileOp.WriteFile(rewriteFile, strings.NewReader(req.Content), constant.DirPerm)
@@ -112,6 +116,37 @@ func (w WebsiteService) OperateCustomRewrite(req request.CustomRewriteOperate) e
return nil
}
func getSafeRewriteName(name string) (string, error) {
safeName := path.Base(name)
if safeName != name || strings.Contains(safeName, "..") {
return "", buserr.New("ErrInvalidParams")
}
return safeName, nil
}
func builtinRewriteNameExist(name string) bool {
rewriteFile := fmt.Sprintf("rewrite/%s.conf", strings.ToLower(name))
contentByte, _ := nginx_conf.Rewrites.ReadFile(rewriteFile)
return contentByte != nil
}
func customRewriteNameExist(rewriteDir, name string) (bool, error) {
entries, err := os.ReadDir(rewriteDir)
if err != nil {
return false, err
}
for _, entry := range entries {
if entry.IsDir() {
continue
}
entryName := strings.TrimSuffix(entry.Name(), ".conf")
if strings.EqualFold(entryName, name) {
return true, nil
}
}
return false, nil
}
func (w WebsiteService) ListCustomRewrite() ([]string, error) {
rewriteDir := GetOpenrestyDir(DefaultRewriteDir)
fileOp := files.NewFileOp()

Some files were not shown because too many files have changed in this diff Show More