mongodb: ssl connection (#6546)
* mongodb ssl connection support
Ilya Mashchenko committed
Aug 6, 2019 at 16:23 UTC
32451c28c7a8083438cbb721b60a41dd29feaf7b
2 files changed
+72
-8
collectors/python.d.plugin/mongodb/mongodb.chart.py
+62
-8
@@ -3,6 +3,8 @@
3
# Author: ilyam8
4
# SPDX-License-Identifier: GPL-3.0-or-later
5
6
+import ssl
7
+
8
from copy import deepcopy
9
from datetime import datetime
10
from sys import exc_info
@@ -418,18 +420,31 @@ CHARTS = {
420
}
421
}
422
423
+DEFAULT_HOST = '127.0.0.1'
424
+DEFAULT_PORT = 27017
425
+DEFAULT_TIMEOUT = 100
426
+DEFAULT_AUTHDB = 'admin'
427
+
428
+CONN_PARAM_HOST = 'host'
429
+CONN_PARAM_PORT = 'port'
430
+CONN_PARAM_SERVER_SELECTION_TIMEOUT_MS = 'serverselectiontimeoutms'
431
+CONN_PARAM_SSL_SSL = 'ssl'
432
+CONN_PARAM_SSL_CERT_REQS = 'ssl_cert_reqs'
433
+CONN_PARAM_SSL_CA_CERTS = 'ssl_ca_certs'
434
+CONN_PARAM_SSL_CRL_FILE = 'ssl_crlfile'
435
+CONN_PARAM_SSL_CERT_FILE = 'ssl_certfile'
436
+CONN_PARAM_SSL_KEY_FILE = 'ssl_keyfile'
437
+CONN_PARAM_SSL_PEM_PASSPHRASE = 'ssl_pem_passphrase'
438
+
439
440
class Service(SimpleService):
441
def __init__(self, configuration=None, name=None):
442
SimpleService.__init__(self, configuration=configuration, name=name)
443
self.order = ORDER[:]
444
self.definitions = deepcopy(CHARTS)
427
- self.authdb = self.configuration.get('authdb', 'admin')
445
+ self.authdb = self.configuration.get('authdb', DEFAULT_AUTHDB)
446
self.user = self.configuration.get('user')
447
self.password = self.configuration.get('pass')
430
- self.host = self.configuration.get('host', '127.0.0.1')
431
- self.port = self.configuration.get('port', 27017)
432
- self.timeout = self.configuration.get('timeout', 100)
448
self.metrics_to_collect = deepcopy(DEFAULT_METRICS)
449
self.connection = None
450
self.do_replica = None
@@ -705,14 +720,53 @@ class Service(SimpleService):
720
721
return data
722
708
- def _create_connection(self):
709
- conn_vars = {'host': self.host, 'port': self.port}
723
+ def build_ssl_connection_params(self):
724
+ conf = self.configuration
725
+
726
+ def cert_req(v):
727
+ if v is None:
728
+ return None
729
+ if not v:
730
+ return ssl.CERT_NONE
731
+ return ssl.CERT_REQUIRED
732
+
733
+ ssl_params = {
734
+ CONN_PARAM_SSL_SSL: conf.get(CONN_PARAM_SSL_SSL),
735
+ CONN_PARAM_SSL_CERT_REQS: cert_req(conf.get(CONN_PARAM_SSL_CERT_REQS)),
736
+ CONN_PARAM_SSL_CA_CERTS: conf.get(CONN_PARAM_SSL_CA_CERTS),
737
+ CONN_PARAM_SSL_CRL_FILE: conf.get(CONN_PARAM_SSL_CRL_FILE),
738
+ CONN_PARAM_SSL_CERT_FILE: conf.get(CONN_PARAM_SSL_CERT_FILE),
739
+ CONN_PARAM_SSL_KEY_FILE: conf.get(CONN_PARAM_SSL_KEY_FILE),
740
+ CONN_PARAM_SSL_PEM_PASSPHRASE: conf.get(CONN_PARAM_SSL_PEM_PASSPHRASE),
741
+ }
742
+
743
+ ssl_params = dict((k, v) for k, v in ssl_params.items() if v is not None)
744
+
745
+ return ssl_params
746
+
747
+ def build_connection_params(self):
748
+ conf = self.configuration
749
+ params = {
750
+ CONN_PARAM_HOST: conf.get(CONN_PARAM_HOST, DEFAULT_HOST),
751
+ CONN_PARAM_PORT: conf.get(CONN_PARAM_PORT, DEFAULT_PORT),
752
+ }
753
if hasattr(MongoClient, 'server_selection_timeout'):
711
- conn_vars.update({'serverselectiontimeoutms': self.timeout})
754
+ params[CONN_PARAM_SERVER_SELECTION_TIMEOUT_MS] = conf.get('timeout', DEFAULT_TIMEOUT)
755
+
756
+ params.update(self.build_ssl_connection_params())
757
+ return params
758
+
759
+ def _create_connection(self):
760
+ params = self.build_connection_params()
761
+ self.debug('creating connection, connection params: {0}'.format(sorted(params)))
762
+
763
try:
713
- connection = MongoClient(**conn_vars)
764
+ connection = MongoClient(**params)
765
if self.user and self.password:
766
+ self.debug('authenticating, user: {0}, password: {1}'.format(self.user, self.password))
767
getattr(connection, self.authdb).authenticate(name=self.user, password=self.password)
768
+ else:
769
+ self.debug('skip authenticating, user and password are not set')
770
# elif self.user:
771
# connection.admin.authenticate(name=self.user, mechanism='MONGODB-X509')
772
server_status = connection.admin.command('serverStatus')
collectors/python.d.plugin/mongodb/mongodb.conf
+10
@@ -71,6 +71,16 @@
71
# user: 'username' # the mongodb username to use
72
# pass: 'password' # the mongodb password to use
73
#
74
+# SSL connection parameters (https://api.mongodb.com/python/current/examples/tls.html):
75
+#
76
+# ssl: yes # connect to the server using TLS
77
+# ssl_cert_reqs: yes # require a certificate from the server when TLS is enabled
78
+# ssl_ca_certs: '/path/to/ca.pem' # use a specific set of CA certificates
79
+# ssl_crlfile: '/path/to/crl.pem' # use a certificate revocation lists
80
+# ssl_certfile: '/path/to/client.pem' # use a client certificate
81
+# ssl_keyfile: '/path/to/key.pem' # use a specific client certificate key
82
+# ssl_pem_passphrase: 'passphrase' # use a passphrase to decrypt encrypted private keys
83
+#
84
85
# ----------------------------------------------------------------------
86
# to connect to the mongodb on localhost, without a password: