File: cert.go

package info (click to toggle)
golang-golang-x-tools 1%3A0.0~git20190125.d66bd3c%2Bds-4
  • links: PTS, VCS
  • area: main
  • in suites: buster, buster-backports
  • size: 8,912 kB
  • sloc: asm: 1,394; yacc: 155; makefile: 109; sh: 108; ansic: 17; xml: 11
file content (64 lines) | stat: -rw-r--r-- 1,589 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
// Copyright 2017 The Go Authors. All rights reserved.
// Use of this source code is governed by the Apache 2.0
// license that can be found in the LICENSE file.

// +build autocert

// This file contains autocert and cloud.google.com/go/storage
// dependencies we want to hide by default from the Go build system,
// which currently doesn't know how to fetch non-golang.org/x/*
// dependencies. The Dockerfile builds the production binary
// with this code using --tags=autocert.

package main

import (
	"context"
	"crypto/tls"
	"log"
	"net/http"
	"strings"

	"cloud.google.com/go/storage"
	"golang.org/x/build/autocertcache"
	"golang.org/x/crypto/acme/autocert"
)

func init() {
	runHTTPS = runHTTPSAutocert
	certInit = certInitAutocert
	wrapHTTPMux = wrapHTTPMuxAutocert
}

var autocertManager *autocert.Manager

func certInitAutocert() {
	var cache autocert.Cache
	if b := *autoCertCacheBucket; b != "" {
		sc, err := storage.NewClient(context.Background())
		if err != nil {
			log.Fatalf("storage.NewClient: %v", err)
		}
		cache = autocertcache.NewGoogleCloudStorageCache(sc, b)
	}
	autocertManager = &autocert.Manager{
		Prompt:     autocert.AcceptTOS,
		HostPolicy: autocert.HostWhitelist(strings.Split(*autoCertDomain, ",")...),
		Cache:      cache,
	}
}

func runHTTPSAutocert(h http.Handler) error {
	s := &http.Server{
		Addr:    ":https",
		Handler: h,
		TLSConfig: &tls.Config{
			GetCertificate: autocertManager.GetCertificate,
		},
	}
	return s.ListenAndServeTLS("", "")
}

func wrapHTTPMuxAutocert(h http.Handler) http.Handler {
	return autocertManager.HTTPHandler(h)
}