xxx
This commit is contained in:
+17
-9
@@ -139,14 +139,14 @@ func applyFlagOverrides(cfg *Config, host string, port int, password string, tls
|
||||
return nil
|
||||
}
|
||||
|
||||
func optionsFromConn(host string, port int, password string, db int, useTLS bool) *redis.Options {
|
||||
func optionsFromConn(host string, port int, password string, db int, useTLS bool, tlsServerName string) *redis.Options {
|
||||
opts := &redis.Options{
|
||||
Addr: fmt.Sprintf("%s:%d", host, port),
|
||||
Password: password,
|
||||
DB: db,
|
||||
}
|
||||
if useTLS {
|
||||
opts.TLSConfig = &tls.Config{MinVersion: tls.VersionTLS12, RootCAs: tlsRootCAs}
|
||||
opts.TLSConfig = &tls.Config{MinVersion: tls.VersionTLS12, RootCAs: tlsRootCAs, ServerName: tlsServerName}
|
||||
}
|
||||
return opts
|
||||
}
|
||||
@@ -155,13 +155,20 @@ func optionsFromConn(host string, port int, password string, db int, useTLS bool
|
||||
// --flush/--inspect modes from either a --conn string or the override flags.
|
||||
// A conn string carries host/port/password/db/TLS, so it stands in for the
|
||||
// override flags; redis.ParseURL maps rediss:// to a TLS config. --tls-ca is
|
||||
// honoured in both paths so a local run can trust a non-system CA.
|
||||
func buildConnOptions(conn, host string, port int, password string, tlsEnable bool, tlsCAPath string) (*redis.Options, error) {
|
||||
// honoured in both paths so a local run can trust a non-system CA. --tls-servername
|
||||
// overrides the name TLS verifies against, which is needed when dialing a Zerops
|
||||
// public-port IP whose cert only carries internal DNS SANs (e.g. valkey1.zerops).
|
||||
func buildConnOptions(conn, host string, port int, password string, tlsEnable bool, tlsCAPath, tlsServerName string) (*redis.Options, error) {
|
||||
if conn != "" {
|
||||
parsed, err := redis.ParseURL(conn)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("--conn parse error: %w", err)
|
||||
}
|
||||
if tlsCAPath != "" || tlsServerName != "" {
|
||||
if parsed.TLSConfig == nil {
|
||||
parsed.TLSConfig = &tls.Config{MinVersion: tls.VersionTLS12}
|
||||
}
|
||||
}
|
||||
if tlsCAPath != "" {
|
||||
pem, err := os.ReadFile(tlsCAPath)
|
||||
if err != nil {
|
||||
@@ -171,11 +178,11 @@ func buildConnOptions(conn, host string, port int, password string, tlsEnable bo
|
||||
if !pool.AppendCertsFromPEM(pem) {
|
||||
return nil, fmt.Errorf("tls-ca: no certificates parsed from %s", tlsCAPath)
|
||||
}
|
||||
if parsed.TLSConfig == nil {
|
||||
parsed.TLSConfig = &tls.Config{MinVersion: tls.VersionTLS12}
|
||||
}
|
||||
parsed.TLSConfig.RootCAs = pool
|
||||
}
|
||||
if tlsServerName != "" {
|
||||
parsed.TLSConfig.ServerName = tlsServerName
|
||||
}
|
||||
return parsed, nil
|
||||
}
|
||||
cfg := &Config{}
|
||||
@@ -188,7 +195,7 @@ func buildConnOptions(conn, host string, port int, password string, tlsEnable bo
|
||||
if cfg.Port == 0 {
|
||||
cfg.Port = 6379
|
||||
}
|
||||
return optionsFromConn(cfg.Host, cfg.Port, cfg.Password, cfg.DB, cfg.TLS), nil
|
||||
return optionsFromConn(cfg.Host, cfg.Port, cfg.Password, cfg.DB, cfg.TLS, tlsServerName), nil
|
||||
}
|
||||
|
||||
func redactPassword(pw string) string {
|
||||
@@ -218,6 +225,7 @@ func main() {
|
||||
passwordOverride := flag.String("password", "", "override password for all workers (local testing)")
|
||||
tlsEnable := flag.Bool("tls", false, "enable TLS for all workers using system root CAs (local testing)")
|
||||
tlsCAPath := flag.String("tls-ca", "", "path to TLS CA cert PEM; enables TLS for all workers (local testing)")
|
||||
tlsServerName := flag.String("tls-servername", "", "override the hostname TLS verifies against (e.g. valkey1.zerops) when dialing a Zerops public-port IP whose cert has no IP SANs")
|
||||
seedConn := flag.String("conn", "", "Valkey connection string for the cli tool (default test suite, --watch, --seed/--verify/--flush/--inspect) — e.g. redis://default:pw@valkey1:6379 or rediss://...:6380 for TLS; overrides --host/--port/--password/--tls")
|
||||
watchMode := flag.Bool("watch", false, "PING the target on --interval until Ctrl+C, printing each outage's start/recovery/duration and a summary on exit")
|
||||
watchInterval := flag.Duration("interval", 500*time.Millisecond, "probe interval for --watch")
|
||||
@@ -260,7 +268,7 @@ func main() {
|
||||
// One-time commands against a single Valkey, resolved from --conn or the
|
||||
// split --host/--port/--password/--tls[-ca] flags. Covers the default test
|
||||
// suite plus --seed/--verify/--flush/--inspect.
|
||||
opts, err := buildConnOptions(*seedConn, *hostOverride, *portOverride, *passwordOverride, *tlsEnable, *tlsCAPath)
|
||||
opts, err := buildConnOptions(*seedConn, *hostOverride, *portOverride, *passwordOverride, *tlsEnable, *tlsCAPath, *tlsServerName)
|
||||
if err != nil {
|
||||
log.Fatalf("connection error: %v", err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user