2020-09-02 23:04:12 +01:00
|
|
|
"""Gunicorn config"""
|
2020-11-11 13:48:19 +00:00
|
|
|
import os
|
2021-09-13 16:54:23 +01:00
|
|
|
import pwd
|
2022-02-01 14:01:39 +00:00
|
|
|
from hashlib import sha512
|
2020-09-11 22:21:11 +01:00
|
|
|
from multiprocessing import cpu_count
|
2022-05-29 20:45:25 +01:00
|
|
|
from os import makedirs
|
|
|
|
from pathlib import Path
|
2022-04-28 20:50:03 +01:00
|
|
|
from tempfile import gettempdir
|
2022-05-29 20:45:25 +01:00
|
|
|
from typing import TYPE_CHECKING
|
2020-09-11 22:21:11 +01:00
|
|
|
|
2020-09-02 23:04:12 +01:00
|
|
|
import structlog
|
2021-04-07 15:16:17 +01:00
|
|
|
from kubernetes.config.incluster_config import SERVICE_HOST_ENV_NAME
|
2022-05-29 20:45:25 +01:00
|
|
|
from prometheus_client.values import MultiProcessValue
|
2020-09-02 23:04:12 +01:00
|
|
|
|
2022-02-01 14:01:39 +00:00
|
|
|
from authentik import get_full_version
|
|
|
|
from authentik.lib.config import CONFIG
|
|
|
|
from authentik.lib.utils.http import get_http_session
|
|
|
|
from authentik.lib.utils.reflection import get_env
|
2022-05-29 20:45:25 +01:00
|
|
|
from lifecycle.worker import DjangoUvicornWorker
|
|
|
|
|
|
|
|
if TYPE_CHECKING:
|
|
|
|
from gunicorn.arbiter import Arbiter
|
2022-02-01 14:01:39 +00:00
|
|
|
|
2021-05-04 16:49:21 +01:00
|
|
|
bind = "127.0.0.1:8000"
|
2020-09-02 23:04:12 +01:00
|
|
|
|
2021-09-13 16:54:23 +01:00
|
|
|
try:
|
|
|
|
pwd.getpwnam("authentik")
|
|
|
|
user = "authentik"
|
|
|
|
group = "authentik"
|
|
|
|
except KeyError:
|
|
|
|
pass
|
2020-09-02 23:04:12 +01:00
|
|
|
|
2022-05-29 20:45:25 +01:00
|
|
|
_tmp = Path(gettempdir())
|
2021-12-11 18:55:09 +00:00
|
|
|
worker_class = "lifecycle.worker.DjangoUvicornWorker"
|
2022-05-29 20:45:25 +01:00
|
|
|
worker_tmp_dir = str(_tmp.joinpath("authentik_worker_tmp"))
|
|
|
|
prometheus_tmp_dir = str(_tmp.joinpath("authentik_prometheus_tmp"))
|
2020-09-02 23:04:12 +01:00
|
|
|
|
2020-12-05 21:08:42 +00:00
|
|
|
os.environ.setdefault("DJANGO_SETTINGS_MODULE", "authentik.root.settings")
|
2022-05-29 20:45:25 +01:00
|
|
|
os.environ.setdefault("PROMETHEUS_MULTIPROC_DIR", prometheus_tmp_dir)
|
|
|
|
|
|
|
|
makedirs(worker_tmp_dir, exist_ok=True)
|
|
|
|
makedirs(prometheus_tmp_dir, exist_ok=True)
|
2020-11-11 13:48:19 +00:00
|
|
|
|
2022-01-26 09:04:58 +00:00
|
|
|
max_requests = 1000
|
|
|
|
max_requests_jitter = 50
|
|
|
|
|
2022-05-29 20:45:25 +01:00
|
|
|
_debug = CONFIG.y_bool("DEBUG", False)
|
|
|
|
|
2020-09-02 23:04:12 +01:00
|
|
|
logconfig_dict = {
|
|
|
|
"version": 1,
|
|
|
|
"disable_existing_loggers": False,
|
|
|
|
"formatters": {
|
2022-05-29 20:45:25 +01:00
|
|
|
"json": {
|
2020-09-02 23:04:12 +01:00
|
|
|
"()": structlog.stdlib.ProcessorFormatter,
|
|
|
|
"processor": structlog.processors.JSONRenderer(),
|
|
|
|
"foreign_pre_chain": [
|
|
|
|
structlog.stdlib.add_log_level,
|
|
|
|
structlog.stdlib.add_logger_name,
|
|
|
|
structlog.processors.TimeStamper(),
|
|
|
|
structlog.processors.StackInfoRenderer(),
|
|
|
|
],
|
2022-05-29 20:45:25 +01:00
|
|
|
},
|
|
|
|
"console": {
|
|
|
|
"()": structlog.stdlib.ProcessorFormatter,
|
|
|
|
"processor": structlog.dev.ConsoleRenderer(colors=True),
|
|
|
|
"foreign_pre_chain": [
|
|
|
|
structlog.stdlib.add_log_level,
|
|
|
|
structlog.stdlib.add_logger_name,
|
|
|
|
structlog.processors.TimeStamper(),
|
|
|
|
structlog.processors.StackInfoRenderer(),
|
|
|
|
],
|
|
|
|
},
|
2020-09-02 23:04:12 +01:00
|
|
|
},
|
|
|
|
"handlers": {
|
2022-05-29 20:45:25 +01:00
|
|
|
"console": {"class": "logging.StreamHandler", "formatter": "json" if _debug else "console"},
|
2020-09-02 23:04:12 +01:00
|
|
|
},
|
2020-09-06 14:52:48 +01:00
|
|
|
"loggers": {
|
2020-09-06 15:12:17 +01:00
|
|
|
"uvicorn": {"handlers": ["console"], "level": "WARNING", "propagate": False},
|
|
|
|
"gunicorn": {"handlers": ["console"], "level": "INFO", "propagate": False},
|
2020-09-06 14:52:48 +01:00
|
|
|
},
|
2020-09-02 23:04:12 +01:00
|
|
|
}
|
2020-09-11 22:21:11 +01:00
|
|
|
|
|
|
|
# if we're running in kubernetes, use fixed workers because we can scale with more pods
|
|
|
|
# otherwise (assume docker-compose), use as much as we can
|
2021-04-07 15:16:17 +01:00
|
|
|
if SERVICE_HOST_ENV_NAME in os.environ:
|
2021-11-29 13:27:55 +00:00
|
|
|
default_workers = 2
|
2020-09-11 22:21:11 +01:00
|
|
|
else:
|
2021-08-05 09:15:31 +01:00
|
|
|
default_workers = max(cpu_count() * 0.25, 1) + 1 # Minimum of 2 workers
|
2021-11-29 13:27:55 +00:00
|
|
|
|
2022-09-21 08:59:03 +01:00
|
|
|
workers = int(CONFIG.y("web.workers", default_workers))
|
|
|
|
threads = int(CONFIG.y("web.threads", 4))
|
2022-01-16 12:57:07 +00:00
|
|
|
|
|
|
|
# pylint: disable=unused-argument
|
2022-05-29 20:45:25 +01:00
|
|
|
def post_fork(server: "Arbiter", worker: DjangoUvicornWorker):
|
|
|
|
"""Tell prometheus to use worker number instead of process ID for multiprocess"""
|
|
|
|
from prometheus_client import values
|
|
|
|
|
|
|
|
values.ValueClass = MultiProcessValue(lambda: worker._worker_id)
|
|
|
|
|
|
|
|
|
|
|
|
# pylint: disable=unused-argument
|
|
|
|
def worker_exit(server: "Arbiter", worker: DjangoUvicornWorker):
|
2022-01-16 12:57:07 +00:00
|
|
|
"""Remove pid dbs when worker is shutdown"""
|
|
|
|
from prometheus_client import multiprocess
|
|
|
|
|
2022-05-29 20:45:25 +01:00
|
|
|
multiprocess.mark_process_dead(worker._worker_id)
|
|
|
|
|
|
|
|
|
|
|
|
def on_starting(server: "Arbiter"):
|
|
|
|
"""Attach a set of IDs that can be temporarily re-used.
|
|
|
|
Used on reloads when each worker exists twice."""
|
|
|
|
server._worker_id_overload = set()
|
|
|
|
|
|
|
|
|
|
|
|
def nworkers_changed(server: "Arbiter", new_value, old_value):
|
|
|
|
"""Gets called on startup too.
|
|
|
|
Set the current number of workers. Required if we raise the worker count
|
|
|
|
temporarily using TTIN because server.cfg.workers won't be updated and if
|
|
|
|
one of those workers dies, we wouldn't know the ids go that far."""
|
|
|
|
server._worker_id_current_workers = new_value
|
|
|
|
|
|
|
|
|
|
|
|
def _next_worker_id(server: "Arbiter"):
|
|
|
|
"""If there are IDs open for re-use, take one. Else look for a free one."""
|
|
|
|
if server._worker_id_overload:
|
|
|
|
return server._worker_id_overload.pop()
|
|
|
|
|
|
|
|
in_use = set(w._worker_id for w in tuple(server.WORKERS.values()) if w.alive)
|
|
|
|
free = set(range(1, server._worker_id_current_workers + 1)) - in_use
|
|
|
|
|
|
|
|
return free.pop()
|
|
|
|
|
|
|
|
|
|
|
|
def on_reload(server: "Arbiter"):
|
|
|
|
"""Add a full set of ids into overload so it can be re-used once."""
|
|
|
|
server._worker_id_overload = set(range(1, server.cfg.workers + 1))
|
|
|
|
|
|
|
|
|
|
|
|
def pre_fork(server: "Arbiter", worker: DjangoUvicornWorker):
|
|
|
|
"""Attach the next free worker_id before forking off."""
|
|
|
|
worker._worker_id = _next_worker_id(server)
|
2022-02-01 14:01:39 +00:00
|
|
|
|
|
|
|
|
|
|
|
if not CONFIG.y_bool("disable_startup_analytics", False):
|
|
|
|
env = get_env()
|
|
|
|
should_send = env not in ["dev", "ci"]
|
|
|
|
if should_send:
|
|
|
|
try:
|
|
|
|
get_http_session().post(
|
|
|
|
"https://goauthentik.io/api/event",
|
|
|
|
json={
|
|
|
|
"domain": "authentik",
|
|
|
|
"name": "pageview",
|
|
|
|
"referrer": get_full_version(),
|
|
|
|
"url": (
|
|
|
|
f"http://localhost/{env}?utm_source={get_full_version()}&utm_medium={env}"
|
|
|
|
),
|
|
|
|
},
|
|
|
|
headers={
|
|
|
|
"User-Agent": sha512(str(CONFIG.y("secret_key")).encode("ascii")).hexdigest()[
|
|
|
|
:16
|
|
|
|
],
|
|
|
|
"Content-Type": "application/json",
|
|
|
|
},
|
|
|
|
timeout=5,
|
|
|
|
)
|
|
|
|
# pylint: disable=bare-except
|
|
|
|
except: # nosec
|
|
|
|
pass
|