main.go 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218
  1. package main
  2. import (
  3. "embed"
  4. "flag"
  5. "fmt"
  6. "log"
  7. "net/http"
  8. "os"
  9. "os/signal"
  10. "syscall"
  11. "time"
  12. "github.com/google/uuid"
  13. "github.com/gorilla/csrf"
  14. "imuslab.com/zoraxy/mod/access"
  15. "imuslab.com/zoraxy/mod/acme"
  16. "imuslab.com/zoraxy/mod/auth"
  17. "imuslab.com/zoraxy/mod/auth/sso"
  18. "imuslab.com/zoraxy/mod/database"
  19. "imuslab.com/zoraxy/mod/dockerux"
  20. "imuslab.com/zoraxy/mod/dynamicproxy/loadbalance"
  21. "imuslab.com/zoraxy/mod/dynamicproxy/redirection"
  22. "imuslab.com/zoraxy/mod/email"
  23. "imuslab.com/zoraxy/mod/forwardproxy"
  24. "imuslab.com/zoraxy/mod/ganserv"
  25. "imuslab.com/zoraxy/mod/geodb"
  26. "imuslab.com/zoraxy/mod/info/logger"
  27. "imuslab.com/zoraxy/mod/info/logviewer"
  28. "imuslab.com/zoraxy/mod/mdns"
  29. "imuslab.com/zoraxy/mod/netstat"
  30. "imuslab.com/zoraxy/mod/pathrule"
  31. "imuslab.com/zoraxy/mod/sshprox"
  32. "imuslab.com/zoraxy/mod/statistic"
  33. "imuslab.com/zoraxy/mod/statistic/analytic"
  34. "imuslab.com/zoraxy/mod/streamproxy"
  35. "imuslab.com/zoraxy/mod/tlscert"
  36. "imuslab.com/zoraxy/mod/update"
  37. "imuslab.com/zoraxy/mod/uptime"
  38. "imuslab.com/zoraxy/mod/utils"
  39. "imuslab.com/zoraxy/mod/webserv"
  40. )
  41. // General flags
  42. var webUIPort = flag.String("port", ":8000", "Management web interface listening port")
  43. var noauth = flag.Bool("noauth", false, "Disable authentication for management interface")
  44. var showver = flag.Bool("version", false, "Show version of this server")
  45. var allowSshLoopback = flag.Bool("sshlb", false, "Allow loopback web ssh connection (DANGER)")
  46. var allowMdnsScanning = flag.Bool("mdns", true, "Enable mDNS scanner and transponder")
  47. var mdnsName = flag.String("mdnsname", "", "mDNS name, leave empty to use default (zoraxy_{node-uuid}.local)")
  48. var ztAuthToken = flag.String("ztauth", "", "ZeroTier authtoken for the local node")
  49. var ztAPIPort = flag.Int("ztport", 9993, "ZeroTier controller API port")
  50. var runningInDocker = flag.Bool("docker", false, "Run Zoraxy in docker compatibility mode")
  51. var acmeAutoRenewInterval = flag.Int("autorenew", 86400, "ACME auto TLS/SSL certificate renew check interval (seconds)")
  52. var acmeCertAutoRenewDays = flag.Int("earlyrenew", 30, "Number of days to early renew a soon expiring certificate (days)")
  53. var enableHighSpeedGeoIPLookup = flag.Bool("fastgeoip", false, "Enable high speed geoip lookup, require 1GB extra memory (Not recommend for low end devices)")
  54. var staticWebServerRoot = flag.String("webroot", "./www", "Static web server root folder. Only allow chnage in start paramters")
  55. var allowWebFileManager = flag.Bool("webfm", true, "Enable web file manager for static web server root folder")
  56. var enableAutoUpdate = flag.Bool("cfgupgrade", true, "Enable auto config upgrade if breaking change is detected")
  57. var (
  58. name = "Zoraxy"
  59. version = "3.1.2"
  60. nodeUUID = "generic" //System uuid, in uuidv4 format
  61. development = true //Set this to false to use embedded web fs
  62. bootTime = time.Now().Unix()
  63. /*
  64. Binary Embedding File System
  65. */
  66. //go:embed web/*
  67. webres embed.FS
  68. /*
  69. Handler Modules
  70. */
  71. sysdb *database.Database //System database
  72. authAgent *auth.AuthAgent //Authentication agent
  73. tlsCertManager *tlscert.Manager //TLS / SSL management
  74. redirectTable *redirection.RuleTable //Handle special redirection rule sets
  75. webminPanelMux *http.ServeMux //Server mux for handling webmin panel APIs
  76. csrfMiddleware func(http.Handler) http.Handler //CSRF protection middleware
  77. pathRuleHandler *pathrule.Handler //Handle specific path blocking or custom headers
  78. geodbStore *geodb.Store //GeoIP database, for resolving IP into country code
  79. accessController *access.Controller //Access controller, handle black list and white list
  80. netstatBuffers *netstat.NetStatBuffers //Realtime graph buffers
  81. statisticCollector *statistic.Collector //Collecting statistic from visitors
  82. uptimeMonitor *uptime.Monitor //Uptime monitor service worker
  83. mdnsScanner *mdns.MDNSHost //mDNS discovery services
  84. ganManager *ganserv.NetworkManager //Global Area Network Manager
  85. webSshManager *sshprox.Manager //Web SSH connection service
  86. streamProxyManager *streamproxy.Manager //Stream Proxy Manager for TCP / UDP forwarding
  87. acmeHandler *acme.ACMEHandler //Handler for ACME Certificate renew
  88. acmeAutoRenewer *acme.AutoRenewer //Handler for ACME auto renew ticking
  89. staticWebServer *webserv.WebServer //Static web server for hosting simple stuffs
  90. forwardProxy *forwardproxy.Handler //HTTP Forward proxy, basically VPN for web browser
  91. loadBalancer *loadbalance.RouteManager //Global scope loadbalancer, store the state of the lb routing
  92. ssoHandler *sso.SSOHandler //Single Sign On handler
  93. //Helper modules
  94. EmailSender *email.Sender //Email sender that handle email sending
  95. AnalyticLoader *analytic.DataLoader //Data loader for Zoraxy Analytic
  96. DockerUXOptimizer *dockerux.UXOptimizer //Docker user experience optimizer, community contribution only
  97. SystemWideLogger *logger.Logger //Logger for Zoraxy
  98. LogViewer *logviewer.Viewer
  99. )
  100. // Kill signal handler. Do something before the system the core terminate.
  101. func SetupCloseHandler() {
  102. c := make(chan os.Signal, 2)
  103. signal.Notify(c, os.Interrupt, syscall.SIGTERM)
  104. go func() {
  105. <-c
  106. ShutdownSeq()
  107. os.Exit(0)
  108. }()
  109. }
  110. func ShutdownSeq() {
  111. SystemWideLogger.Println("Shutting down " + name)
  112. //SystemWideLogger.Println("Closing GeoDB")
  113. //geodbStore.Close()
  114. SystemWideLogger.Println("Closing Netstats Listener")
  115. netstatBuffers.Close()
  116. SystemWideLogger.Println("Closing Statistic Collector")
  117. statisticCollector.Close()
  118. if mdnsTickerStop != nil {
  119. SystemWideLogger.Println("Stopping mDNS Discoverer (might take a few minutes)")
  120. // Stop the mdns service
  121. mdnsTickerStop <- true
  122. }
  123. mdnsScanner.Close()
  124. SystemWideLogger.Println("Shutting down load balancer")
  125. loadBalancer.Close()
  126. SystemWideLogger.Println("Closing Certificates Auto Renewer")
  127. acmeAutoRenewer.Close()
  128. //Remove the tmp folder
  129. SystemWideLogger.Println("Cleaning up tmp files")
  130. os.RemoveAll("./tmp")
  131. //Close database
  132. SystemWideLogger.Println("Stopping system database")
  133. sysdb.Close()
  134. //Close logger
  135. SystemWideLogger.Println("Closing system wide logger")
  136. SystemWideLogger.Close()
  137. }
  138. func main() {
  139. //Parse startup flags
  140. flag.Parse()
  141. if *showver {
  142. fmt.Println(name + " - Version " + version)
  143. os.Exit(0)
  144. }
  145. if !utils.ValidateListeningAddress(*webUIPort) {
  146. fmt.Println("Malformed -port (listening address) paramter. Do you mean -port=:" + *webUIPort + "?")
  147. os.Exit(0)
  148. }
  149. if *enableAutoUpdate {
  150. fmt.Println("Checking required config update")
  151. update.RunConfigUpdate(0, update.GetVersionIntFromVersionNumber(version))
  152. }
  153. SetupCloseHandler()
  154. //Read or create the system uuid
  155. uuidRecord := "./sys.uuid"
  156. if !utils.FileExists(uuidRecord) {
  157. newSystemUUID := uuid.New().String()
  158. os.WriteFile(uuidRecord, []byte(newSystemUUID), 0775)
  159. }
  160. uuidBytes, err := os.ReadFile(uuidRecord)
  161. if err != nil {
  162. SystemWideLogger.PrintAndLog("ZeroTier", "Unable to read system uuid from file system", nil)
  163. panic(err)
  164. }
  165. nodeUUID = string(uuidBytes)
  166. //Create a new webmin mux and csrf middleware layer
  167. webminPanelMux = http.NewServeMux()
  168. csrfMiddleware = csrf.Protect(
  169. []byte(nodeUUID),
  170. csrf.CookieName("zoraxy-csrf"),
  171. csrf.Secure(false),
  172. csrf.Path("/"),
  173. csrf.SameSite(csrf.SameSiteLaxMode),
  174. )
  175. //Startup all modules
  176. startupSequence()
  177. //Initiate management interface APIs
  178. requireAuth = !(*noauth)
  179. initAPIs(webminPanelMux)
  180. //Start the reverse proxy server in go routine
  181. go func() {
  182. ReverseProxtInit()
  183. }()
  184. time.Sleep(500 * time.Millisecond)
  185. //Start the finalize sequences
  186. finalSequence()
  187. SystemWideLogger.Println("Zoraxy started. Visit control panel at http://localhost" + *webUIPort)
  188. err = http.ListenAndServe(*webUIPort, csrfMiddleware(webminPanelMux))
  189. if err != nil {
  190. log.Fatal(err)
  191. }
  192. }