derak.go raw

   1  // Package derak implements a DNS provider for solving the DNS-01 challenge using Derak Cloud.
   2  package derak
   3  
   4  import (
   5  	"context"
   6  	"errors"
   7  	"fmt"
   8  	"net/http"
   9  	"strings"
  10  	"sync"
  11  	"time"
  12  
  13  	"github.com/go-acme/lego/v4/challenge"
  14  	"github.com/go-acme/lego/v4/challenge/dns01"
  15  	"github.com/go-acme/lego/v4/platform/config/env"
  16  	"github.com/go-acme/lego/v4/providers/dns/derak/internal"
  17  	"github.com/go-acme/lego/v4/providers/dns/internal/clientdebug"
  18  	"github.com/miekg/dns"
  19  )
  20  
  21  // Environment variables names.
  22  const (
  23  	envNamespace = "DERAK_"
  24  
  25  	EnvAPIKey    = envNamespace + "API_KEY"
  26  	EnvWebsiteID = envNamespace + "WEBSITE_ID"
  27  
  28  	EnvTTL                = envNamespace + "TTL"
  29  	EnvPropagationTimeout = envNamespace + "PROPAGATION_TIMEOUT"
  30  	EnvPollingInterval    = envNamespace + "POLLING_INTERVAL"
  31  	EnvHTTPTimeout        = envNamespace + "HTTP_TIMEOUT"
  32  )
  33  
  34  var _ challenge.ProviderTimeout = (*DNSProvider)(nil)
  35  
  36  // Config is used to configure the creation of the DNSProvider.
  37  type Config struct {
  38  	APIKey             string
  39  	WebsiteID          string
  40  	PropagationTimeout time.Duration
  41  	PollingInterval    time.Duration
  42  	TTL                int
  43  	HTTPClient         *http.Client
  44  }
  45  
  46  // NewDefaultConfig returns a default configuration for the DNSProvider.
  47  func NewDefaultConfig() *Config {
  48  	return &Config{
  49  		TTL:                env.GetOrDefaultInt(EnvTTL, dns01.DefaultTTL),
  50  		PropagationTimeout: env.GetOrDefaultSecond(EnvPropagationTimeout, 2*time.Minute),
  51  		PollingInterval:    env.GetOrDefaultSecond(EnvPollingInterval, 5*time.Second),
  52  		HTTPClient: &http.Client{
  53  			Timeout: env.GetOrDefaultSecond(EnvHTTPTimeout, 30*time.Second),
  54  		},
  55  	}
  56  }
  57  
  58  // DNSProvider implements the challenge.Provider interface.
  59  type DNSProvider struct {
  60  	config *Config
  61  	client *internal.Client
  62  
  63  	recordIDs   map[string]string
  64  	recordIDsMu sync.Mutex
  65  }
  66  
  67  // NewDNSProvider returns a DNSProvider instance configured for Derak Cloud.
  68  // Credentials must be passed in the environment variable: DERAK_API_KEY.
  69  func NewDNSProvider() (*DNSProvider, error) {
  70  	values, err := env.Get(EnvAPIKey)
  71  	if err != nil {
  72  		return nil, fmt.Errorf("derak: %w", err)
  73  	}
  74  
  75  	config := NewDefaultConfig()
  76  	config.APIKey = values[EnvAPIKey]
  77  	config.WebsiteID = env.GetOrDefaultString(EnvWebsiteID, "")
  78  
  79  	return NewDNSProviderConfig(config)
  80  }
  81  
  82  // NewDNSProviderConfig return a DNSProvider instance configured for Derak Cloud.
  83  func NewDNSProviderConfig(config *Config) (*DNSProvider, error) {
  84  	if config == nil {
  85  		return nil, errors.New("derak: the configuration of the DNS provider is nil")
  86  	}
  87  
  88  	if config.APIKey == "" {
  89  		return nil, errors.New("derak: missing credentials")
  90  	}
  91  
  92  	client := internal.NewClient(config.APIKey)
  93  
  94  	if config.HTTPClient != nil {
  95  		client.HTTPClient = config.HTTPClient
  96  	}
  97  
  98  	client.HTTPClient = clientdebug.Wrap(client.HTTPClient)
  99  
 100  	return &DNSProvider{
 101  		config:    config,
 102  		client:    client,
 103  		recordIDs: make(map[string]string),
 104  	}, nil
 105  }
 106  
 107  // Timeout returns the timeout and interval to use when checking for DNS propagation.
 108  // Adjusting here to cope with spikes in propagation times.
 109  func (d *DNSProvider) Timeout() (timeout, interval time.Duration) {
 110  	return d.config.PropagationTimeout, d.config.PollingInterval
 111  }
 112  
 113  // Present creates a TXT record using the specified parameters.
 114  func (d *DNSProvider) Present(domain, token, keyAuth string) error {
 115  	ctx := context.Background()
 116  	info := dns01.GetChallengeInfo(domain, keyAuth)
 117  
 118  	authZone, err := dns01.FindZoneByFqdn(info.EffectiveFQDN)
 119  	if err != nil {
 120  		return fmt.Errorf("derak: could not find zone for domain %q: %w", domain, err)
 121  	}
 122  
 123  	recordName, err := dns01.ExtractSubDomain(info.EffectiveFQDN, authZone)
 124  	if err != nil {
 125  		return fmt.Errorf("derak: %w", err)
 126  	}
 127  
 128  	zoneID, err := d.getZoneID(ctx, info)
 129  	if err != nil {
 130  		return fmt.Errorf("derak: get zone ID: %w", err)
 131  	}
 132  
 133  	r := internal.Record{
 134  		Type:    "TXT",
 135  		Host:    recordName,
 136  		Content: info.Value,
 137  		TTL:     d.config.TTL,
 138  	}
 139  
 140  	record, err := d.client.CreateRecord(ctx, zoneID, r)
 141  	if err != nil {
 142  		return fmt.Errorf("derak: create record: %w", err)
 143  	}
 144  
 145  	d.recordIDsMu.Lock()
 146  	d.recordIDs[token] = record.ID
 147  	d.recordIDsMu.Unlock()
 148  
 149  	return nil
 150  }
 151  
 152  // CleanUp removes the TXT record matching the specified parameters.
 153  func (d *DNSProvider) CleanUp(domain, token, keyAuth string) error {
 154  	ctx := context.Background()
 155  	info := dns01.GetChallengeInfo(domain, keyAuth)
 156  
 157  	zoneID, err := d.getZoneID(ctx, info)
 158  	if err != nil {
 159  		return fmt.Errorf("derak: get zone ID: %w", err)
 160  	}
 161  
 162  	// gets the record's unique ID
 163  	d.recordIDsMu.Lock()
 164  	recordID, ok := d.recordIDs[token]
 165  	d.recordIDsMu.Unlock()
 166  
 167  	if !ok {
 168  		return fmt.Errorf("derak: unknown record ID for '%s' '%s'", info.EffectiveFQDN, token)
 169  	}
 170  
 171  	err = d.client.DeleteRecord(ctx, zoneID, recordID)
 172  	if err != nil {
 173  		return fmt.Errorf("derak: delete record: %w", err)
 174  	}
 175  
 176  	// deletes record ID from map
 177  	d.recordIDsMu.Lock()
 178  	delete(d.recordIDs, token)
 179  	d.recordIDsMu.Unlock()
 180  
 181  	return nil
 182  }
 183  
 184  func (d *DNSProvider) getZoneID(ctx context.Context, info dns01.ChallengeInfo) (string, error) {
 185  	zoneID := d.config.WebsiteID
 186  	if zoneID != "" {
 187  		return zoneID, nil
 188  	}
 189  
 190  	zones, err := d.client.GetZones(ctx)
 191  	if err != nil {
 192  		return "", fmt.Errorf("get zones: %w", err)
 193  	}
 194  
 195  	for _, zone := range zones {
 196  		if strings.HasSuffix(info.EffectiveFQDN, dns.Fqdn(zone.HumanReadable)) {
 197  			return zone.ID, nil
 198  		}
 199  	}
 200  
 201  	return "", fmt.Errorf("zone/website not found %s", info.EffectiveFQDN)
 202  }
 203