|
4 | 4 | from inspect import currentframe, getframeinfo |
5 | 5 | from pymongo import DESCENDING, CursorType, MongoClient |
6 | 6 | from pymongo.errors import ConnectionFailure, OperationFailure, ServerSelectionTimeoutError |
| 7 | +from ssl import CERT_REQUIRED, CERT_NONE |
7 | 8 | from time import sleep |
8 | 9 |
|
| 10 | +from mongodb_consistent_backup.Common import parse_config_bool |
9 | 11 | from mongodb_consistent_backup.Errors import DBAuthenticationError, DBConnectionError, DBOperationError, Error |
10 | 12 |
|
11 | 13 |
|
12 | 14 | class DB: |
13 | 15 | def __init__(self, uri, config, do_replset=False, read_pref='primaryPreferred', do_connect=True, conn_timeout=5000, retries=5): |
14 | | - self.uri = uri |
15 | | - self.username = config.username |
16 | | - self.password = config.password |
17 | | - self.authdb = config.authdb |
18 | | - self.do_replset = do_replset |
19 | | - self.read_pref = read_pref |
20 | | - self.do_connect = do_connect |
21 | | - self.conn_timeout = conn_timeout |
22 | | - self.retries = retries |
| 16 | + self.uri = uri |
| 17 | + self.config = config |
| 18 | + self.do_replset = do_replset |
| 19 | + self.read_pref = read_pref |
| 20 | + self.do_connect = do_connect |
| 21 | + self.conn_timeout = conn_timeout |
| 22 | + self.retries = retries |
| 23 | + |
| 24 | + self.username = self.config.username |
| 25 | + self.password = self.config.password |
| 26 | + self.authdb = self.config.authdb |
| 27 | + self.ssl_ca_file = self.config.ssl.ca_file |
| 28 | + self.ssl_crl_file = self.config.ssl.crl_file |
| 29 | + self.ssl_client_cert_file = self.config.ssl.client_cert_file |
| 30 | + self.read_pref_tags = self.config.replication.read_pref_tags.replace(" ", "") |
23 | 31 |
|
24 | 32 | self.replset = None |
25 | 33 | self._conn = None |
26 | 34 | self._is_master = None |
| 35 | + |
27 | 36 | self.connect() |
28 | 37 | self.auth_if_required() |
29 | 38 |
|
| 39 | + def do_ssl(self): |
| 40 | + return parse_config_bool(self.config.ssl.enabled) |
| 41 | + |
| 42 | + def do_ssl_insecure(self): |
| 43 | + return parse_config_bool(self.config.ssl.insecure) |
| 44 | + |
| 45 | + def client_opts(self): |
| 46 | + opts = { |
| 47 | + "connect": self.do_connect, |
| 48 | + "host": self.uri.hosts(), |
| 49 | + "connectTimeoutMS": self.conn_timeout, |
| 50 | + "serverSelectionTimeoutMS": self.conn_timeout, |
| 51 | + "maxPoolSize": 1, |
| 52 | + } |
| 53 | + if self.do_replset: |
| 54 | + self.replset = self.uri.replset |
| 55 | + opts.update({ |
| 56 | + "replicaSet": self.replset, |
| 57 | + "readPreference": self.read_pref, |
| 58 | + "readPreferenceTags": self.read_pref_tags, |
| 59 | + "w": "majority" |
| 60 | + }) |
| 61 | + if self.do_ssl(): |
| 62 | + logging.debug("Using SSL-secured mongodb connection (ca_cert=%s, client_cert=%s, crl_file=%s, insecure=%s)" % ( |
| 63 | + self.ssl_ca_file, |
| 64 | + self.ssl_client_cert_file, |
| 65 | + self.ssl_crl_file, |
| 66 | + self.do_ssl_insecure() |
| 67 | + )) |
| 68 | + opts.update({ |
| 69 | + "ssl": True, |
| 70 | + "ssl_ca_certs": self.ssl_ca_file, |
| 71 | + "ssl_crlfile": self.ssl_crl_file, |
| 72 | + "ssl_certfile": self.ssl_client_cert_file, |
| 73 | + "ssl_cert_reqs": CERT_REQUIRED, |
| 74 | + }) |
| 75 | + if self.do_ssl_insecure(): |
| 76 | + opts["ssl_cert_reqs"] = CERT_NONE |
| 77 | + return opts |
| 78 | + |
30 | 79 | def connect(self): |
31 | 80 | try: |
32 | | - if self.do_replset: |
33 | | - self.replset = self.uri.replset |
34 | | - logging.debug("Getting MongoDB connection to %s (replicaSet=%s, readPreference=%s)" % ( |
35 | | - self.uri, self.replset, self.read_pref |
| 81 | + logging.debug("Getting MongoDB connection to %s (replicaSet=%s, readPreference=%s, readPreferenceTags=%s, ssl=%s)" % ( |
| 82 | + self.uri, |
| 83 | + self.replset, |
| 84 | + self.read_pref, |
| 85 | + self.read_pref_tags, |
| 86 | + self.do_ssl(), |
36 | 87 | )) |
37 | | - conn = MongoClient( |
38 | | - connect=self.do_connect, |
39 | | - host=self.uri.hosts(), |
40 | | - replicaSet=self.replset, |
41 | | - readPreference=self.read_pref, |
42 | | - connectTimeoutMS=self.conn_timeout, |
43 | | - serverSelectionTimeoutMS=self.conn_timeout, |
44 | | - maxPoolSize=1, |
45 | | - w="majority" |
46 | | - ) |
| 88 | + conn = MongoClient(**self.client_opts()) |
47 | 89 | if self.do_connect: |
48 | 90 | conn['admin'].command({"ping": 1}) |
49 | 91 | except (ConnectionFailure, OperationFailure, ServerSelectionTimeoutError), e: |
|
0 commit comments