Compare commits
1173 Commits
v1.0.0-bet
...
feat/frame
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
07edec5d55 | ||
|
|
c2a07672d9 | ||
|
|
f64cdfd605 | ||
|
|
af5d728921 | ||
|
|
b6c8855595 | ||
|
|
23ffb19b4d | ||
|
|
7849f34386 | ||
|
|
50a77b4591 | ||
|
|
0ed64edb19 | ||
|
|
e9ef597442 | ||
|
|
e4703fedc3 | ||
|
|
80431b737c | ||
|
|
42eeb9e078 | ||
|
|
052f8a5aa7 | ||
|
|
fd9a5ae311 | ||
|
|
af6bd53cc8 | ||
|
|
026ccb9c06 | ||
|
|
f04d99fa71 | ||
|
|
e9712b5ccd | ||
|
|
a50ed84163 | ||
|
|
ed5c0c06c5 | ||
|
|
3e50268947 | ||
|
|
e2f6782499 | ||
|
|
c825a11b92 | ||
|
|
96ac9b80e6 | ||
|
|
82c3eea1e1 | ||
|
|
c5a9467ffc | ||
|
|
e5902349b5 | ||
|
|
3f2880940f | ||
|
|
2bb389bf1b | ||
|
|
bfa3c3f995 | ||
|
|
03c1458fd8 | ||
|
|
4e8fd673a8 | ||
|
|
2a3f4baa8c | ||
|
|
203d7b5518 | ||
|
|
d0a7efff85 | ||
|
|
95ea92b9ce | ||
|
|
6890d1889c | ||
|
|
6c71ff5039 | ||
|
|
efc90c76c9 | ||
|
|
7459eb02ee | ||
|
|
fc46da1398 | ||
|
|
51a11edb71 | ||
|
|
29e7f26c0e | ||
|
|
01d270fcfa | ||
|
|
92d3311192 | ||
|
|
97a8c1fcaf | ||
|
|
de5b0666bd | ||
|
|
ffdb8b6f22 | ||
|
|
250e3b0b20 | ||
|
|
2bb8144e79 | ||
|
|
72d4fca63c | ||
|
|
81cd95379b | ||
|
|
cd50f58138 | ||
|
|
b2f029117e | ||
|
|
db135acea9 | ||
|
|
7b589b53f9 | ||
|
|
c1740c752e | ||
|
|
5862786381 | ||
|
|
e8dd64f54b | ||
|
|
ba96b63002 | ||
|
|
c7c6bcbdf2 | ||
|
|
faa3b4eabb | ||
|
|
f0a6eb7d98 | ||
|
|
33a58cddf7 | ||
|
|
fea6d81246 | ||
|
|
dbff9fbc8e | ||
|
|
63b352b5e2 | ||
|
|
2ffb210ccb | ||
|
|
ff643d21ef | ||
|
|
8f04a6d42f | ||
|
|
4395fe2417 | ||
|
|
18392e136e | ||
|
|
ed916eb042 | ||
|
|
72b8160dc4 | ||
|
|
4f41786038 | ||
|
|
8fb186fd6d | ||
|
|
420b8b8a01 | ||
|
|
5a13416bed | ||
|
|
704011c20b | ||
|
|
6683c9b994 | ||
|
|
2092f3e49d | ||
|
|
d815e39e1d | ||
|
|
e2e1f8cfa8 | ||
|
|
ba5992378e | ||
|
|
2163a8e146 | ||
|
|
1fec49500e | ||
|
|
8175908073 | ||
|
|
1bcce4694d | ||
|
|
b26f0190c6 | ||
|
|
91194f5c1a | ||
|
|
57cfc90c4b | ||
|
|
357cc719a5 | ||
|
|
4f2a96b5e1 | ||
|
|
ed85261c8e | ||
|
|
5a58808f20 | ||
|
|
94b26cf096 | ||
|
|
57ef7ebaaf | ||
|
|
ddf58fe633 | ||
|
|
6f2d35cdf1 | ||
|
|
c836cef28d | ||
|
|
c97bb70cb5 | ||
|
|
96b145b046 | ||
|
|
09a697e00b | ||
|
|
1d0714f199 | ||
|
|
42e91867ec | ||
|
|
155c4a7e44 | ||
|
|
4fe4977559 | ||
|
|
67e66e863a | ||
|
|
bd34e9d836 | ||
|
|
1a0e6bf153 | ||
|
|
52aef0870e | ||
|
|
012ed3b658 | ||
|
|
7ced8a3044 | ||
|
|
f043be5371 | ||
|
|
b85d9858d1 | ||
|
|
434730b970 | ||
|
|
94df7298e3 | ||
|
|
0f76baec1f | ||
|
|
6ae61ea046 | ||
|
|
93e17ac73e | ||
|
|
0037f5a0ab | ||
|
|
79f225ad3c | ||
|
|
b6358ab56f | ||
|
|
bde5cf58eb | ||
|
|
6725411e8f | ||
|
|
675a8a4fb9 | ||
|
|
a77843fffc | ||
|
|
2dd9d50954 | ||
|
|
9c0a9452a7 | ||
|
|
61692e8346 | ||
|
|
e12f403fb9 | ||
|
|
484de49689 | ||
|
|
450d10acf7 | ||
|
|
8a0b5337f3 | ||
|
|
3590a0b39e | ||
|
|
976834cdfd | ||
|
|
d3ede93053 | ||
|
|
58a79f8278 | ||
|
|
422279985f | ||
|
|
99ff750c40 | ||
|
|
13c84a0f36 | ||
|
|
cb6bbe1609 | ||
|
|
b839cd985b | ||
|
|
476207c1bf | ||
|
|
fcd8ef8ff4 | ||
|
|
645b6aa0be | ||
|
|
67ee78dab5 | ||
|
|
5936c6eaae | ||
|
|
dafcd06696 | ||
|
|
02d60c71e4 | ||
|
|
52647d7f1d | ||
|
|
e1fa7d9d7e | ||
|
|
06e2694763 | ||
|
|
c0971ca3b2 | ||
|
|
1a788ebe6c | ||
|
|
a1b4026b4b | ||
|
|
9bc9825bb1 | ||
|
|
e9d2afa228 | ||
|
|
4b0e0eae9c | ||
|
|
e0204e1949 | ||
|
|
3c2a0ce0cf | ||
|
|
a5def2ccd8 | ||
|
|
6ede3c3add | ||
|
|
d5de6ae271 | ||
|
|
2035deaa31 | ||
|
|
5973ba025d | ||
|
|
52a54fbae1 | ||
|
|
5f828262eb | ||
|
|
17c1c5b04b | ||
|
|
bd5df30de3 | ||
|
|
2c063c39c6 | ||
|
|
2f0f29ce8c | ||
|
|
a05acb7fc8 | ||
|
|
2b88c0ff93 | ||
|
|
4aa2b6e51a | ||
|
|
0c439e34c7 | ||
|
|
d57bea3079 | ||
|
|
46a48db080 | ||
|
|
b7fe9947c2 | ||
|
|
f214a09826 | ||
|
|
7059503ac1 | ||
|
|
7ee79cc063 | ||
|
|
9bfbe4ee0f | ||
|
|
b8c05aa3e2 | ||
|
|
5f7ede40ca | ||
|
|
0ef84c5288 | ||
|
|
1a477bf42d | ||
|
|
22c352e946 | ||
|
|
55b0eb54fe | ||
|
|
68a4ca6bb9 | ||
|
|
baaa3f615a | ||
|
|
aeb214689b | ||
|
|
e353d46e73 | ||
|
|
4d163c4b53 | ||
|
|
014f0e312e | ||
|
|
195750a01d | ||
|
|
d203321770 | ||
|
|
51f1a52e17 | ||
|
|
6318c61323 | ||
|
|
5323105a60 | ||
|
|
af6e75426a | ||
|
|
6c2f38679b | ||
|
|
9b60223300 | ||
|
|
efdf8396ab | ||
|
|
d0f13187a1 | ||
|
|
bf46b55c92 | ||
|
|
88edcabf98 | ||
|
|
e77af9e2c0 | ||
|
|
cc5c0253ed | ||
|
|
4c5a107d29 | ||
|
|
3b07c754f8 | ||
|
|
d151d0ce24 | ||
|
|
a32af4fe50 | ||
|
|
434cdf8a7f | ||
|
|
d3f53e4b6b | ||
|
|
8ea84d87db | ||
|
|
860acd3a6e | ||
|
|
c7122ca025 | ||
|
|
3d4e37dfb9 | ||
|
|
36d6591271 | ||
|
|
e8fc4e674b | ||
|
|
011bd9936f | ||
|
|
791add83f9 | ||
|
|
4b935d97c8 | ||
|
|
8657765e5d | ||
|
|
76a136abc9 | ||
|
|
5475b79459 | ||
|
|
2ad768780f | ||
|
|
f64b5fb65b | ||
|
|
bb773316a2 | ||
|
|
fc6fa9d425 | ||
|
|
aa183ee0fb | ||
|
|
730b1b2a40 | ||
|
|
4efc80fecb | ||
|
|
4fbee60e9f | ||
|
|
d6c25df280 | ||
|
|
72a2d28e1e | ||
|
|
eb0972084f | ||
|
|
41a1d221fc | ||
|
|
eaacc93d2f | ||
|
|
0e6a004c23 | ||
|
|
617f854534 | ||
|
|
1bf8006055 | ||
|
|
ca0e426382 | ||
|
|
726d0722d9 | ||
|
|
d8f320b040 | ||
|
|
0131b87692 | ||
|
|
54e8198b65 | ||
|
|
3bfb68f950 | ||
|
|
c05e59c936 | ||
|
|
b42d63b668 | ||
|
|
0ca007e424 | ||
|
|
229d085de7 | ||
|
|
30e2b8318d | ||
|
|
dbcf4e242c | ||
|
|
ccf4034cc8 | ||
|
|
a34836e8f4 | ||
|
|
dd1464d1be | ||
|
|
2c02e0aeb1 | ||
|
|
d5464362bb | ||
|
|
5bcefd0015 | ||
|
|
5bb9def42d | ||
|
|
ff38ccbadf | ||
|
|
f64e899de9 | ||
|
|
b8a81d18af | ||
|
|
8c2e3e4cdd | ||
|
|
11c4ee518d | ||
|
|
51b9d76973 | ||
|
|
f3c1cb9b82 | ||
|
|
a1368361e4 | ||
|
|
abfdea0179 | ||
|
|
8aaeb62fa3 | ||
|
|
e30dd7d4a0 | ||
|
|
ac3f9aa4e8 | ||
|
|
04c568f488 | ||
|
|
e270223968 | ||
|
|
01ab1a9218 | ||
|
|
6f0794b09c | ||
|
|
1ae6a46d88 | ||
|
|
9d83cab5cc | ||
|
|
6f559c2f00 | ||
|
|
c147944f5a | ||
|
|
e8ca776e4e | ||
|
|
de5c4b6e0a | ||
|
|
9ba64de090 | ||
|
|
7ceeebe76e | ||
|
|
bd7dbcfcf2 | ||
|
|
8c7a46e3ae | ||
|
|
57ccfaabf5 | ||
|
|
4a9cb51e95 | ||
|
|
ab6f621e76 | ||
|
|
c365ae5af2 | ||
|
|
b05c3d1baa | ||
|
|
c7c7203fad | ||
|
|
d93f85b4f3 | ||
|
|
031212b98c | ||
|
|
a4837b3cb3 | ||
|
|
77629ac9b8 | ||
|
|
59608394af | ||
|
|
9dfcaa466f | ||
|
|
88442e4525 | ||
|
|
891ae2e5d5 | ||
|
|
32b471f570 | ||
|
|
5d745fc989 | ||
|
|
edfa6ec4c6 | ||
|
|
0c460efea6 | ||
|
|
96df049e59 | ||
|
|
2cb454e618 | ||
|
|
7f2ebb655e | ||
|
|
63857fb5cc | ||
|
|
f4c75f9aa9 | ||
|
|
c3936dc884 | ||
|
|
2868ddc499 | ||
|
|
176610a694 | ||
|
|
f60aff4fd6 | ||
|
|
847f62303a | ||
|
|
f174e2697e | ||
|
|
acac2d5d42 | ||
|
|
f304c2ed3e | ||
|
|
2003a38cdc | ||
|
|
a67c5a1f39 | ||
|
|
b7a87f95e5 | ||
|
|
0aa0b8ad8f | ||
|
|
2bff868de6 | ||
|
|
8b59828126 | ||
|
|
f55e25db07 | ||
|
|
243c969666 | ||
|
|
ec7f2e0303 | ||
|
|
a4a032d994 | ||
|
|
0a84744e49 | ||
|
|
1425430376 | ||
|
|
ca8d88ffce | ||
|
|
af3f8bb639 | ||
|
|
1f9772d472 | ||
|
|
94cf361b55 | ||
|
|
6acdf258e7 | ||
|
|
cc0a810ab3 | ||
|
|
c19bfbe552 | ||
|
|
39aaf5ad6c | ||
|
|
6fba2ff05d | ||
|
|
d78e682759 | ||
|
|
ed582a9d57 | ||
|
|
aa925d5c9b | ||
|
|
08d191e542 | ||
|
|
cc075d7237 | ||
|
|
1974bddfbe | ||
|
|
12cb88e1c1 | ||
|
|
c054526998 | ||
|
|
ffa97598b8 | ||
|
|
f5afbf3a63 | ||
|
|
e666695c96 | ||
|
|
55816e4b7b | ||
|
|
016fb51951 | ||
|
|
550a444650 | ||
|
|
4332e43f27 | ||
|
|
fdc3bfb4a4 | ||
|
|
c17d6b7117 | ||
|
|
5d7a8103c0 | ||
|
|
5d7cb98b8f | ||
|
|
f6046c6a6c | ||
|
|
f59f9d71a9 | ||
|
|
ff72f9647d | ||
|
|
fa604b16cf | ||
|
|
0342869733 | ||
|
|
8685ce31a2 | ||
|
|
0e259f0e7a | ||
|
|
5823abed95 | ||
|
|
86acff58f0 | ||
|
|
d3fc5d4c29 | ||
|
|
50bb40938c | ||
|
|
1977d98ad9 | ||
|
|
448d4a946d | ||
|
|
61ac314bb7 | ||
|
|
c1b144ca28 | ||
|
|
e16987bf9d | ||
|
|
9991597984 | ||
|
|
2c0314cea4 | ||
|
|
0584e52b98 | ||
|
|
1fc90eaee2 | ||
|
|
aef3eacbc9 | ||
|
|
2843568473 | ||
|
|
53ffc8cae0 | ||
|
|
86e654fe19 | ||
|
|
46d57f7664 | ||
|
|
963d8672eb | ||
|
|
9b7a62816a | ||
|
|
237134fe0e | ||
|
|
c8730e8f26 | ||
|
|
acbbe8b444 | ||
|
|
f690016aa5 | ||
|
|
396cfe5d8b | ||
|
|
39fe640ccf | ||
|
|
d389c9b0b6 | ||
|
|
b149686db8 | ||
|
|
c4358cbfad | ||
|
|
cfc5bd3dfe | ||
|
|
c29c1b6a92 | ||
|
|
0f45a2a4b4 | ||
|
|
92edcc13c0 | ||
|
|
5392e2ba90 | ||
|
|
79e1f659c7 | ||
|
|
bf35e5efb6 | ||
|
|
c50137f255 | ||
|
|
f12da749b2 | ||
|
|
a166083423 | ||
|
|
b400d4e773 | ||
|
|
120054d3e5 | ||
|
|
620117c31b | ||
|
|
4e371488c1 | ||
|
|
b154b56308 | ||
|
|
6d92817237 | ||
|
|
b8c1855830 | ||
|
|
a9f7ff4b72 | ||
|
|
b3cd080e14 | ||
|
|
bfde87f888 | ||
|
|
c4453bb8b3 | ||
|
|
40f65a30b3 | ||
|
|
5361de63e0 | ||
|
|
3a8552d362 | ||
|
|
d3840103fc | ||
|
|
d12a9f0612 | ||
|
|
c0d74f7e09 | ||
|
|
8ebea9e4c5 | ||
|
|
89269caf92 | ||
|
|
0c83170f51 | ||
|
|
6081cb4be9 | ||
|
|
ea1dbb3087 | ||
|
|
0523208d36 | ||
|
|
919f21b48b | ||
|
|
2c1c10a2ac | ||
|
|
7e3320b252 | ||
|
|
35ccac8b65 | ||
|
|
dad8165d11 | ||
|
|
ba54188de2 | ||
|
|
3b440c9905 | ||
|
|
42b98b7f20 | ||
|
|
ba3312b57c | ||
|
|
223ba255e9 | ||
|
|
a1df2be207 | ||
|
|
d7f225ca73 | ||
|
|
b3cfabb5df | ||
|
|
5310dd4550 | ||
|
|
cde7dbb58a | ||
|
|
65e68231c7 | ||
|
|
5502555869 | ||
|
|
ad6e7e752f | ||
|
|
63af4660ef | ||
|
|
24fc340001 | ||
|
|
78d786b69d | ||
|
|
756aeaa0eb | ||
|
|
055fb67d7a | ||
|
|
bee522a6bf | ||
|
|
3fbf59c622 | ||
|
|
abd8b8b605 | ||
|
|
abdad47bf3 | ||
|
|
d2c24edf5d | ||
|
|
22f4a7f119 | ||
|
|
a25d3d32e4 | ||
|
|
ed68c32e04 | ||
|
|
4114b3839a | ||
|
|
3f73c009fd | ||
|
|
02fb70c76e | ||
|
|
aaddcb854d | ||
|
|
e73c7a6ecc | ||
|
|
1dc2202f37 | ||
|
|
ac710ae1f5 | ||
|
|
f5ea82ff03 | ||
|
|
ef52325240 | ||
|
|
354855feb1 | ||
|
|
c4cd25b588 | ||
|
|
dbb870229e | ||
|
|
a66fe8c054 | ||
|
|
2352431c79 | ||
|
|
49bc168812 | ||
|
|
98f1ebf20a | ||
|
|
65feb6d182 | ||
|
|
58555d352f | ||
|
|
839a177cf0 | ||
|
|
404517ec40 | ||
|
|
035bd18bc2 | ||
|
|
8bf7a0d244 | ||
|
|
607d8fd0d1 | ||
|
|
12807e289c | ||
|
|
3a984f1c73 | ||
|
|
b84e34da06 | ||
|
|
541d151570 | ||
|
|
4ad97e1286 | ||
|
|
a80b375e89 | ||
|
|
91cb390f6e | ||
|
|
90780dae28 | ||
|
|
ddb08e90e1 | ||
|
|
0d95026819 | ||
|
|
79db3a9dfe | ||
|
|
9f63ffd540 | ||
|
|
9c7116a462 | ||
|
|
dd9b4d43ac | ||
|
|
aa63eca24c | ||
|
|
6df97171d9 | ||
|
|
56f7d69b3d | ||
|
|
3e2b29284e | ||
|
|
18ceca7510 | ||
|
|
5a08d1f3de | ||
|
|
18af6db00c | ||
|
|
6d170c8dc0 | ||
|
|
9c4c3c654d | ||
|
|
6952e387f4 | ||
|
|
66c9ae5c27 | ||
|
|
0fb7601dcb | ||
|
|
07c6e680d1 | ||
|
|
b972bc3040 | ||
|
|
969d42dbca | ||
|
|
6680df9382 | ||
|
|
8877157db5 | ||
|
|
ac814dc357 | ||
|
|
4fcb12c3a3 | ||
|
|
7bcc30f4b7 | ||
|
|
481f917fcf | ||
|
|
700a32e4c8 | ||
|
|
b5a72d904e | ||
|
|
cf3e491462 | ||
|
|
6068705c07 | ||
|
|
37beaa64d7 | ||
|
|
8c5b03487b | ||
|
|
360ae0c0db | ||
|
|
6aad8b7b35 | ||
|
|
9ce037fdc0 | ||
|
|
0eb77ccd16 | ||
|
|
fb876bd216 | ||
|
|
865aec88fc | ||
|
|
9792bdf494 | ||
|
|
d836e89e7f | ||
|
|
53a52b3594 | ||
|
|
ba6ce25b21 | ||
|
|
8c9e18475f | ||
|
|
4548d5328b | ||
|
|
da870fe890 | ||
|
|
66b660e688 | ||
|
|
08f8ca78d6 | ||
|
|
1e61e99005 | ||
|
|
c272e1ab5c | ||
|
|
5cff11c0af | ||
|
|
28b213779f | ||
|
|
666ff202ad | ||
|
|
9cb3c9753a | ||
|
|
c4577e94b1 | ||
|
|
9756183d3b | ||
|
|
83c65fe3d8 | ||
|
|
e6717c87cd | ||
|
|
5a3c1d6c9d | ||
|
|
81045ea955 | ||
|
|
9f9fe3bd37 | ||
|
|
84f7f844c9 | ||
|
|
4fde419db9 | ||
|
|
78cad6cf06 | ||
|
|
4763e5a92e | ||
|
|
50939ee4ce | ||
|
|
884bc2acc1 | ||
|
|
11fd041fa9 | ||
|
|
a6d5c2b614 | ||
|
|
9e3d705c6f | ||
|
|
1004731903 | ||
|
|
9f2ec91688 | ||
|
|
185135ed94 | ||
|
|
27e7d98c68 | ||
|
|
79f56771e3 | ||
|
|
a7839147d6 | ||
|
|
834d82d532 | ||
|
|
989f2f5943 | ||
|
|
3af1df5b19 | ||
|
|
acf06e6e63 | ||
|
|
3f43e15cc2 | ||
|
|
c14683ec0d | ||
|
|
213aaa5c15 | ||
|
|
9fb00c32d5 | ||
|
|
57ec08066c | ||
|
|
e0c6375261 | ||
|
|
79205abe29 | ||
|
|
24326558d0 | ||
|
|
3f981c0f2f | ||
|
|
b6eb7b8317 | ||
|
|
4267ae6305 | ||
|
|
0cb40bd93a | ||
|
|
d2a8890a43 | ||
|
|
e5a5a5326b | ||
|
|
61febd55c8 | ||
|
|
3eac752654 | ||
|
|
df4f1863fc | ||
|
|
acee2784d3 | ||
|
|
8ecb2f94a9 | ||
|
|
8657baf641 | ||
|
|
13d1948c9f | ||
|
|
8e8d51b719 | ||
|
|
ca2413363e | ||
|
|
b067758915 | ||
|
|
b2b8485b28 | ||
|
|
c69d635431 | ||
|
|
a305ca36ce | ||
|
|
a6a97b09f0 | ||
|
|
4d17a15633 | ||
|
|
5fdb4b712e | ||
|
|
3d39251ac6 | ||
|
|
9e59cd1596 | ||
|
|
0ada943699 | ||
|
|
ecadf7a4db | ||
|
|
413ed12fe2 | ||
|
|
6195fa5b9c | ||
|
|
d31524ae52 | ||
|
|
472a40a5f6 | ||
|
|
fb9de04002 | ||
|
|
3f29d1c46f | ||
|
|
b67a72ba9a | ||
|
|
8fc9bc264d | ||
|
|
b2589f498d | ||
|
|
b1ff5134f2 | ||
|
|
3551d02d50 | ||
|
|
4c413012a4 | ||
|
|
74ea2f6cdd | ||
|
|
2a7d9b62d4 | ||
|
|
21d81b94dd | ||
|
|
091662ff26 | ||
|
|
803e8f55ef | ||
|
|
14d38ecf08 | ||
|
|
34d945055b | ||
|
|
8c44da8233 | ||
|
|
a8b79947ef | ||
|
|
7c653f809d | ||
|
|
49f1603f40 | ||
|
|
b4369ea932 | ||
|
|
83ba7baa4b | ||
|
|
9339ae30fd | ||
|
|
c18f2bd445 | ||
|
|
319876bbb0 | ||
|
|
442ba97c61 | ||
|
|
00e0b0b547 | ||
|
|
145f478249 | ||
|
|
aac2150a3a | ||
|
|
9b713637b9 | ||
|
|
699660d472 | ||
|
|
751aa17534 | ||
|
|
2681bd2fe3 | ||
|
|
93adb3dabc | ||
|
|
0e15e58a88 | ||
|
|
ef2ea999df | ||
|
|
ca367611d7 | ||
|
|
eb8f073856 | ||
|
|
3ae43eba16 | ||
|
|
9719a08eaa | ||
|
|
1e165cbeb8 | ||
|
|
8be8cafd00 | ||
|
|
e74d2aadb5 | ||
|
|
9c97422f43 | ||
|
|
deb0a3ff1f | ||
|
|
95ed1f0e97 | ||
|
|
6a111dadd6 | ||
|
|
95b3623c04 | ||
|
|
326d62a640 | ||
|
|
9d990650f3 | ||
|
|
4bc891b640 | ||
|
|
1f133afb89 | ||
|
|
8da34a6a1a | ||
|
|
57c49a8325 | ||
|
|
f739d52505 | ||
|
|
793022eb0f | ||
|
|
6b1fd739f4 | ||
|
|
4efa7048dc | ||
|
|
4931700d06 | ||
|
|
4bd49dbee1 | ||
|
|
c278a66f0e | ||
|
|
d64e6b631c | ||
|
|
fa91e84977 | ||
|
|
8c231d3b63 | ||
|
|
775c1b7051 | ||
|
|
fb23815210 | ||
|
|
5261c1cbfc | ||
|
|
f2aa3d9176 | ||
|
|
113b02d665 | ||
|
|
957d2fd095 | ||
|
|
78e7fb595a | ||
|
|
b5415284e2 | ||
|
|
e94a9a1000 | ||
|
|
60bb9a521c | ||
|
|
3ac34a366f | ||
|
|
77449a29e7 | ||
|
|
242ff48ab6 | ||
|
|
b71dbddc1a | ||
|
|
6407f3da3d | ||
|
|
776571c7b3 | ||
|
|
2df35a1999 | ||
|
|
b1ab6bf522 | ||
|
|
e7fd0bd8a3 | ||
|
|
4f5597c441 | ||
|
|
400457af9f | ||
|
|
c48e3a5683 | ||
|
|
67064879e4 | ||
|
|
698b9c6b54 | ||
|
|
0e8a89c4c3 | ||
|
|
b0bcf73b52 | ||
|
|
15a51e7987 | ||
|
|
b5f5567bcf | ||
|
|
9151b38e7f | ||
|
|
898b3a52c2 | ||
|
|
be6eb6165c | ||
|
|
e95f545bf4 | ||
|
|
fd01fc640e | ||
|
|
8cfcfe4643 | ||
|
|
60d7b4b356 | ||
|
|
9b796c049d | ||
|
|
c8c9f6dff1 | ||
|
|
8293d29ee8 | ||
|
|
34a0d8f5c4 | ||
|
|
0a195a0dfb | ||
|
|
c82ead31f2 | ||
|
|
3ab4b5b54b | ||
|
|
5765f7c4f6 | ||
|
|
d1dd30577b | ||
|
|
1145008c62 | ||
|
|
3f1e01e665 | ||
|
|
ced9355b78 | ||
|
|
6e7ade036e | ||
|
|
976fbb65aa | ||
|
|
ba7f870d4b | ||
|
|
cb3dce5ffd | ||
|
|
b317a6a9db | ||
|
|
e42f430bb8 | ||
|
|
bd984ea1c7 | ||
|
|
6798569b7f | ||
|
|
df3183ec1c | ||
|
|
25c35ba91b | ||
|
|
68b9c5f679 | ||
|
|
9757bc9b18 | ||
|
|
1e4affbf5c | ||
|
|
22f4a7e08a | ||
|
|
044e167dd2 | ||
|
|
bffd377461 | ||
|
|
677c9e334b | ||
|
|
df38784a8d | ||
|
|
dae2c1b5c4 | ||
|
|
fd6449b377 | ||
|
|
cd09ed3321 | ||
|
|
e7dc9aa64d | ||
|
|
fec2587b6d | ||
|
|
7c285d36a1 | ||
|
|
ed46cbe35a | ||
|
|
0a8f097c76 | ||
|
|
bce5d443d5 | ||
|
|
19bf456bda | ||
|
|
1359858e42 | ||
|
|
55b1abe243 | ||
|
|
c6428d8c5a | ||
|
|
e241a03fc4 | ||
|
|
ac2b99a3dd | ||
|
|
341a6a7fae | ||
|
|
e74facfb7f | ||
|
|
54bc1989f9 | ||
|
|
94b71a0868 | ||
|
|
c071057eec | ||
|
|
e8a355d992 | ||
|
|
ca84664071 | ||
|
|
dd7fcb31b1 | ||
|
|
324fffde6b | ||
|
|
cd8347d20f | ||
|
|
efcbf52b06 | ||
|
|
c33469a7b3 | ||
|
|
3717535f0b | ||
|
|
8eb2de5e28 | ||
|
|
96f6bcb1dd | ||
|
|
860077a3eb | ||
|
|
8be9343314 | ||
|
|
dac04fbb57 | ||
|
|
b9acf4c150 | ||
|
|
6608018f86 | ||
|
|
552f5dbea6 | ||
|
|
2844a5a419 | ||
|
|
c4b9610f58 | ||
|
|
6a44498730 | ||
|
|
a2cebaf90b | ||
|
|
3f58f26dfd | ||
|
|
a8d5f56f1e | ||
|
|
1eb62d80c7 | ||
|
|
e474a62dbc | ||
|
|
f29b952001 | ||
|
|
38247ac9f6 | ||
|
|
580f17028a | ||
|
|
48d933a561 | ||
|
|
0c70ab6158 | ||
|
|
839185dac8 | ||
|
|
ba6cdef9d5 | ||
|
|
bedb3c0d7f | ||
|
|
2539255940 | ||
|
|
24136f8b15 | ||
|
|
910bb3c079 | ||
|
|
47f4c19617 | ||
|
|
280a81809a | ||
|
|
59358acb30 | ||
|
|
ebd655ac73 | ||
|
|
6325e37aae | ||
|
|
ecabc47847 | ||
|
|
31cc3d8939 | ||
|
|
c71cb71d08 | ||
|
|
65a739ea75 | ||
|
|
410a62e9ef | ||
|
|
aa76dd1ec8 | ||
|
|
384448d123 | ||
|
|
414f74758c | ||
|
|
25403ccdab | ||
|
|
4c03132b83 | ||
|
|
470f8f1cb6 | ||
|
|
5308376a67 | ||
|
|
2b112d29cf | ||
|
|
20d2517e74 | ||
|
|
12902e2482 | ||
|
|
baca44beef | ||
|
|
d7580744e2 | ||
|
|
04f4bc9bf2 | ||
|
|
d879174f4c | ||
|
|
5a1a62a723 | ||
|
|
c519b01092 | ||
|
|
c2ff7ff785 | ||
|
|
44ec8c0534 | ||
|
|
21c0e01137 | ||
|
|
f7ced6056d | ||
|
|
00917e3f88 | ||
|
|
bcfed04a07 | ||
|
|
bf97bd72f1 | ||
|
|
4b8b6bf66a | ||
|
|
4b6c25bb85 | ||
|
|
729b38999e | ||
|
|
4cbf0323f1 | ||
|
|
1f5cb8ca88 | ||
|
|
8be0a04502 | ||
|
|
bdc0039a24 | ||
|
|
756b893ecd | ||
|
|
36323b076f | ||
|
|
95f43b6444 | ||
|
|
5c23a62ac3 | ||
|
|
2b425a2ddd | ||
|
|
abeeb95204 | ||
|
|
6aed20c466 | ||
|
|
d2dd3dfa62 | ||
|
|
6672535544 | ||
|
|
ed397b6ecc | ||
|
|
530e4c654e | ||
|
|
913bd1ba12 | ||
|
|
84e532be47 | ||
|
|
3341e99af1 | ||
|
|
ced6e678ec | ||
|
|
340a5d7ef6 | ||
|
|
60e8edc876 | ||
|
|
9cf9babd73 | ||
|
|
229c246e1c | ||
|
|
15d9bcda4f | ||
|
|
068063695e | ||
|
|
b1722844f3 | ||
|
|
eb5ab48d6c | ||
|
|
b64f1039d7 | ||
|
|
6fcd6e53a1 | ||
|
|
25537b5f02 | ||
|
|
2fad541e06 | ||
|
|
afefd32a1f | ||
|
|
89e01e065c | ||
|
|
02f3e6a1e2 | ||
|
|
ec5a00f3df | ||
|
|
2860775954 | ||
|
|
d2e8e04833 | ||
|
|
fad90390a6 | ||
|
|
d6ba875473 | ||
|
|
e9ea34c20f | ||
|
|
99cc7d419f | ||
|
|
1a6dc27535 | ||
|
|
93f40a8d34 | ||
|
|
d7f7de97b4 | ||
|
|
50babedcbf | ||
|
|
4352d993ed | ||
|
|
1e144e1c60 | ||
|
|
d4e37e0bae | ||
|
|
026bf93980 | ||
|
|
43c166666c | ||
|
|
f3bda88f3e | ||
|
|
b0af6b2e2b | ||
|
|
2925e19b90 | ||
|
|
e67b6a1800 | ||
|
|
bbbed49887 | ||
|
|
65fd400d4d | ||
|
|
87f681cfe1 | ||
|
|
f935360fda | ||
|
|
71cd315142 | ||
|
|
d9694ac1a3 | ||
|
|
08f589586d | ||
|
|
192f78ae78 | ||
|
|
ef20d4c0b1 | ||
|
|
af95c0f798 | ||
|
|
0e32a10ff5 | ||
|
|
e59c2b179d | ||
|
|
e5d03f19de | ||
|
|
58c3e73f6f | ||
|
|
8ca2c44422 | ||
|
|
a2e584a225 | ||
|
|
c4cda0afb0 | ||
|
|
adbb923e92 | ||
|
|
f444ae4ad6 | ||
|
|
9fa9538320 | ||
|
|
943e81000e | ||
|
|
b16d028293 | ||
|
|
07646e483d | ||
|
|
36b93a34b4 | ||
|
|
b0d2409524 | ||
|
|
be7a231950 | ||
|
|
31a0b9efa4 | ||
|
|
d70a3ed343 | ||
|
|
56cebb6451 | ||
|
|
99f61bc5e8 | ||
|
|
a5d02e3275 | ||
|
|
354ab7db05 | ||
|
|
dc817f8c26 | ||
|
|
a90097731c | ||
|
|
5b3bbbb37e | ||
|
|
4a4aabd71c | ||
|
|
b058c1e742 | ||
|
|
7671b1c2c3 | ||
|
|
4cc8135e1a | ||
|
|
3cb38099ea | ||
|
|
deb0308dc4 | ||
|
|
24c729eea3 | ||
|
|
c59d511ea3 | ||
|
|
6f8745dc3a | ||
|
|
65d3d649b9 | ||
|
|
b4a8028c04 | ||
|
|
9d7077813a | ||
|
|
2feda33808 | ||
|
|
ec42b9ea85 | ||
|
|
a2b4ee12ec | ||
|
|
a0f99a5167 | ||
|
|
9aff467afc | ||
|
|
926f9ea32c | ||
|
|
43d12ee82f | ||
|
|
677c985b3d | ||
|
|
24a5ca04ca | ||
|
|
f81ae57395 | ||
|
|
7e6b69819e | ||
|
|
4aa8ce7513 | ||
|
|
30d59f2613 | ||
|
|
be0277432b | ||
|
|
a3006f3b9f | ||
|
|
d4e10083c4 | ||
|
|
898a11868e | ||
|
|
a098052ee8 | ||
|
|
6f79086a27 | ||
|
|
6ee07d4c12 | ||
|
|
a69869440f | ||
|
|
dcd4e08c6f | ||
|
|
22e7a0fec9 | ||
|
|
8daebd434d | ||
|
|
8381cd1a5c | ||
|
|
051299f331 | ||
|
|
20f2c764fe | ||
|
|
07619c2bce | ||
|
|
fb86efe715 | ||
|
|
4eafe6db84 | ||
|
|
797f986d5d | ||
|
|
864a8ecffa | ||
|
|
7e48be06e3 | ||
|
|
27861aa0a5 | ||
|
|
6d45cb7e6d | ||
|
|
1964b893a5 | ||
|
|
e30c8fe39c | ||
|
|
b183561dc6 | ||
|
|
caa4952e99 | ||
|
|
5e15b9ac75 | ||
|
|
4fadd770f8 | ||
|
|
7ac2f71de1 | ||
|
|
b49eef2d1c | ||
|
|
b8735aba01 | ||
|
|
c73584a743 | ||
|
|
ef4fc0a184 | ||
|
|
8cada20b1e | ||
|
|
ba4ac215b5 | ||
|
|
947ff473a0 | ||
|
|
14dc1a2fa3 | ||
|
|
df69cdc6a4 | ||
|
|
dd54e08e10 | ||
|
|
7e3bb2359e | ||
|
|
5d00053b6f | ||
|
|
d573c2b829 | ||
|
|
eda9eb90d8 | ||
|
|
34849e8250 | ||
|
|
d069a606d7 | ||
|
|
f0b042a2d1 | ||
|
|
8a3ec65ec1 | ||
|
|
e53715b9b0 | ||
|
|
9ef1339f8f | ||
|
|
afaa51aac3 | ||
|
|
fb803df15e | ||
|
|
de0c4fa657 | ||
|
|
18484f407c | ||
|
|
f4a7bc5650 | ||
|
|
9410289b4f | ||
|
|
8eecae6f9a | ||
|
|
63cf88b88d | ||
|
|
cb9403cbf9 | ||
|
|
27da1dbc74 | ||
|
|
98d9185c20 | ||
|
|
dec367a8f5 | ||
|
|
8a3c1e8f08 | ||
|
|
89c385ae2f | ||
|
|
e920cb2a6b | ||
|
|
3f6204e2eb | ||
|
|
ae9d42e821 | ||
|
|
31400bd5e7 | ||
|
|
7973559502 | ||
|
|
d4bfc8677a | ||
|
|
155f1c7cdf | ||
|
|
9643a79603 | ||
|
|
3cc67b485e | ||
|
|
2175d76f94 | ||
|
|
2a069f8881 | ||
|
|
c46765ee8f | ||
|
|
427fad262c | ||
|
|
a895b24425 | ||
|
|
659ba3e67d | ||
|
|
7e394e1c93 | ||
|
|
886522039a | ||
|
|
155f99597a | ||
|
|
d67ac25e87 | ||
|
|
1fdfddeb43 | ||
|
|
770192ac57 | ||
|
|
228cfd844a | ||
|
|
4fbcfbc99d | ||
|
|
bfb72e8268 | ||
|
|
e375c107ef | ||
|
|
99ce644e5d | ||
|
|
05c2d4c583 | ||
|
|
2265eb88e7 | ||
|
|
926e392076 | ||
|
|
7c0cbd4771 | ||
|
|
70d27dc502 | ||
|
|
fece388ae9 | ||
|
|
5543be51da | ||
|
|
cf28d69cce | ||
|
|
9ea4a96165 | ||
|
|
7bd4934ee7 | ||
|
|
fb5919af99 | ||
|
|
8cf8a2e253 | ||
|
|
8dfd15bc3a | ||
|
|
05fab6c7f7 | ||
|
|
9ec52d445d | ||
|
|
a68aaaa214 | ||
|
|
97d2f8fb26 | ||
|
|
b2bc10865c | ||
|
|
7b6ac61a71 | ||
|
|
27b2842481 | ||
|
|
8507e84ea0 | ||
|
|
66df22709f | ||
|
|
c8c9a0fd6e | ||
|
|
f6b95ce7f3 | ||
|
|
6b31ddcbfc | ||
|
|
73892ee86f | ||
|
|
1a0458de11 | ||
|
|
42647172b9 | ||
|
|
e29577e1c5 | ||
|
|
9012bf2bf0 | ||
|
|
0fa1943701 | ||
|
|
a0c1acfd85 | ||
|
|
6413cc82c7 | ||
|
|
e57908c9b4 | ||
|
|
c36007ab27 | ||
|
|
928604e12b | ||
|
|
e33ee6cfa6 | ||
|
|
517b4b26f2 | ||
|
|
06b3d7e67f | ||
|
|
508422d461 | ||
|
|
528638f69c | ||
|
|
70e7507a15 | ||
|
|
df019cf347 | ||
|
|
e88a786116 | ||
|
|
7242212dd0 | ||
|
|
e3dd5fd34b | ||
|
|
2b90bdbc0b | ||
|
|
cd4e9eed3d | ||
|
|
0658f9afbb | ||
|
|
541630a65f | ||
|
|
4e46f7f4bd | ||
|
|
4da3c7a50c | ||
|
|
47fb5b81ab | ||
|
|
b27b2f011b | ||
|
|
40ea660609 | ||
|
|
d70314d4ab | ||
|
|
8867c1dde5 | ||
|
|
a36d53a89b | ||
|
|
f634b98552 | ||
|
|
3942eb5ec1 | ||
|
|
f45413dab9 | ||
|
|
5795a41f92 | ||
|
|
ddc6491058 | ||
|
|
9c940e18d7 | ||
|
|
80b12e229a | ||
|
|
b9a81a31c9 | ||
|
|
1bc063fdbb | ||
|
|
98b897e4fe | ||
|
|
312e501da4 | ||
|
|
0d2e68af3f | ||
|
|
e16d933e56 | ||
|
|
8ee5b42fde | ||
|
|
05447abe93 | ||
|
|
6c91f233e3 | ||
|
|
feaba1afb5 | ||
|
|
e70a66f7b4 | ||
|
|
a78ccd023c | ||
|
|
87ac0932c3 | ||
|
|
8e1dcd7002 | ||
|
|
1b96d01964 | ||
|
|
c013308afe | ||
|
|
e28d133ef0 | ||
|
|
e8f03cd7d7 | ||
|
|
31f7eb5a9a | ||
|
|
89c39aa853 | ||
|
|
f349926c77 | ||
|
|
bf0ae4cb64 | ||
|
|
fb666bb622 | ||
|
|
b69b52d292 | ||
|
|
d11180f26e | ||
|
|
69461c8c7a | ||
|
|
8a373adc2c | ||
|
|
eb3355da9a | ||
|
|
2cda3ad929 | ||
|
|
7a344a987e | ||
|
|
3ce9adc95c | ||
|
|
e5c71bb6b2 | ||
|
|
a021a9e332 | ||
|
|
d3bd8031a7 | ||
|
|
bb18fff7d9 | ||
|
|
9ed2873adb | ||
|
|
f891ac375b | ||
|
|
630b34ca27 | ||
|
|
ecc7514d2b | ||
|
|
9e395bb8a7 | ||
|
|
85fe51f0f7 | ||
|
|
cb247e0312 | ||
|
|
9f933ac9ed | ||
|
|
b0455c6bda | ||
|
|
bac247f15e | ||
|
|
50823c8f8a | ||
|
|
2b81efb2c5 | ||
|
|
013e93be67 | ||
|
|
934ea927b2 | ||
|
|
e54a4097a1 | ||
|
|
bc98b87dc2 | ||
|
|
1c7883b76a | ||
|
|
3850a91737 | ||
|
|
6e8599efda | ||
|
|
1f66eceb3d | ||
|
|
5b551d128f | ||
|
|
77373dfd1d | ||
|
|
c4fdf7de01 | ||
|
|
89875358b1 | ||
|
|
70bc2a3af1 | ||
|
|
b228d808db | ||
|
|
7fe3f5fb0f | ||
|
|
4daf48a39c | ||
|
|
20a1802bdd | ||
|
|
b812b49e11 | ||
|
|
30fb0b675b | ||
|
|
e6257f4ec6 | ||
|
|
38b28b965c | ||
|
|
16e4c68fb3 | ||
|
|
784fe73a55 | ||
|
|
3a83ffc7b1 | ||
|
|
b6ef1249b3 | ||
|
|
c8a863a88d | ||
|
|
da1f7ab574 | ||
|
|
6938ecfca2 | ||
|
|
9461fe8874 | ||
|
|
a770825648 |
@@ -1,32 +0,0 @@
|
||||
# Golang CircleCI 2.0 configuration file
|
||||
#
|
||||
# Check https://circleci.com/docs/2.0/language-go/ for more details
|
||||
version: 2
|
||||
jobs:
|
||||
machinery:
|
||||
docker:
|
||||
- image: kerberos/base:6e68480
|
||||
working_directory: /go/src/github.com/{{ORG_NAME}}/{{REPO_NAME}}
|
||||
steps:
|
||||
- checkout
|
||||
- run: apt-get install -y --no-install-recommends libavcodec-dev libavformat-dev libswscale-dev
|
||||
- run: cd machinery && go mod download
|
||||
- run: cd machinery && go test -v ./...
|
||||
- run: cd machinery && go vet
|
||||
|
||||
ui:
|
||||
docker:
|
||||
- image: cimg/python:3.9.13-node
|
||||
steps:
|
||||
- checkout
|
||||
- run: node --version
|
||||
- run: cd ui && yarn
|
||||
- run: cd ui && yarn test --passWithNoTests
|
||||
- run: cd ui && yarn build
|
||||
|
||||
workflows:
|
||||
version: 2
|
||||
build:
|
||||
jobs:
|
||||
- machinery
|
||||
- ui
|
||||
26
.devcontainer/Dockerfile
Normal file
@@ -0,0 +1,26 @@
|
||||
FROM mcr.microsoft.com/devcontainers/go:1.25-trixie
|
||||
|
||||
# Install node environment
|
||||
RUN apt-get update && \
|
||||
apt-get install -y --no-install-recommends \
|
||||
nodejs \
|
||||
npm \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Install ffmpeg
|
||||
RUN apt-get update && \
|
||||
apt-get install -y --no-install-recommends \
|
||||
ffmpeg \
|
||||
libavcodec-extra \
|
||||
libavutil-dev \
|
||||
libavformat-dev \
|
||||
libavfilter-dev \
|
||||
libavdevice-dev \
|
||||
libswscale-dev \
|
||||
libswresample-dev \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
USER vscode
|
||||
|
||||
# Install go swagger
|
||||
RUN go install github.com/swaggo/swag/cmd/swag@latest
|
||||
24
.devcontainer/devcontainer.json
Normal file
@@ -0,0 +1,24 @@
|
||||
// For format details, see https://aka.ms/devcontainer.json. For config options, see the
|
||||
// README at: https://github.com/devcontainers/templates/tree/main/src/python
|
||||
{
|
||||
"name": "go:1.24-trixie",
|
||||
"runArgs": [
|
||||
"--name=agent",
|
||||
"--network=host"
|
||||
],
|
||||
"dockerFile": "Dockerfile",
|
||||
"customizations": {
|
||||
"vscode": {
|
||||
"extensions": [
|
||||
"GitHub.copilot",
|
||||
"ms-azuretools.vscode-docker",
|
||||
"mongodb.mongodb-vscode"
|
||||
]
|
||||
}
|
||||
},
|
||||
"forwardPorts": [
|
||||
3000,
|
||||
8080
|
||||
],
|
||||
"postCreateCommand": "cd ui && yarn install && yarn build && cd ../machinery && go mod download && bash ./verify-moq-devcontainer.sh"
|
||||
}
|
||||
57
.github/workflows/docker-dev.yml
vendored
@@ -1,57 +0,0 @@
|
||||
name: Docker Development build
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ develop ]
|
||||
|
||||
jobs:
|
||||
build-amd64:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [amd64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --platform linux/${{matrix.architecture}} -t kerberos/agent-dev:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create -t kerberos/agent-dev:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent-dev:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
- name: Create new and append to latest manifest
|
||||
run: docker buildx imagetools create -t kerberos/agent-dev:latest kerberos/agent-dev:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
build-other:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [arm64, arm/v7]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --platform linux/${{matrix.architecture}} -t kerberos/agent-dev:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create --append -t kerberos/agent-dev:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent-dev:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
- name: Create new and append to manifest latest
|
||||
run: docker buildx imagetools create --append -t kerberos/agent-dev:latest kerberos/agent-dev:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
54
.github/workflows/docker-nightly.yml
vendored
@@ -1,54 +0,0 @@
|
||||
name: Docker Nightly build
|
||||
|
||||
on:
|
||||
# Triggers the workflow every day at 9PM (CET).
|
||||
schedule:
|
||||
- cron: "0 22 * * *"
|
||||
|
||||
jobs:
|
||||
build-amd64:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [amd64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --platform linux/${{matrix.architecture}} -t kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create -t kerberos/agent-nightly:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
build-other:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [arm64, arm/v7]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --platform linux/${{matrix.architecture}} -t kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create --append -t kerberos/agent-nightly:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
57
.github/workflows/docker.yml
vendored
@@ -1,57 +0,0 @@
|
||||
name: Docker Production build
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ master ]
|
||||
|
||||
jobs:
|
||||
build-amd64:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [amd64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --platform linux/${{matrix.architecture}} -t kerberos/agent:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create -t kerberos/agent:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
- name: Create new and append to manifest latest
|
||||
run: docker buildx imagetools create -t kerberos/agent:latest kerberos/agent:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
build-other:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [arm64, arm/v7]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v2
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v3
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v2
|
||||
- name: Set up Docker Buildx
|
||||
uses: docker/setup-buildx-action@v2
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --platform linux/${{matrix.architecture}} -t kerberos/agent:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create --append -t kerberos/agent:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
- name: Create new and append to manifest latest
|
||||
run: docker buildx imagetools create --append -t kerberos/agent:latest kerberos/agent:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
58
.github/workflows/go.yml
vendored
@@ -2,36 +2,44 @@ name: Go
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ develop, master ]
|
||||
branches: [develop, master]
|
||||
pull_request:
|
||||
branches: [ develop, master ]
|
||||
branches: [develop, master]
|
||||
|
||||
jobs:
|
||||
|
||||
build:
|
||||
name: Build
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: kerberos/base:6e68480
|
||||
|
||||
strategy:
|
||||
matrix:
|
||||
go-version: [1.17, 1.18]
|
||||
|
||||
steps:
|
||||
- name: Set up Go ${{ matrix.go-version }}
|
||||
uses: actions/setup-go@v2
|
||||
with:
|
||||
go-version: ${{ matrix.go-version }}
|
||||
- name: Check out code into the Go module directory
|
||||
uses: actions/checkout@v2
|
||||
- name: Install dependencies
|
||||
run: apt update -y && apt install -y --no-install-recommends git build-essential cmake pkg-config unzip libgtk2.0-dev curl ca-certificates libcurl4-openssl-dev libssl-dev libavcodec-dev libavformat-dev libswscale-dev libtbb2 libtbb-dev libjpeg-dev libpng-dev libtiff-dev libdc1394-22-dev
|
||||
- name: Get dependencies
|
||||
run: cd machinery && go mod download
|
||||
- name: Build
|
||||
run: cd machinery && go build -v ./...
|
||||
- name: Vet
|
||||
run: cd machinery && go vet -v ./...
|
||||
- name: Test
|
||||
run: cd machinery && go test -v ./...
|
||||
- name: Check out code into the Go module directory
|
||||
uses: actions/checkout@v4
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@v5
|
||||
with:
|
||||
go-version: "1.25.x"
|
||||
check-latest: true
|
||||
cache: true
|
||||
cache-dependency-path: |
|
||||
machinery/go.sum
|
||||
examples/frame-processor/go.sum
|
||||
- name: Install native dependencies
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends \
|
||||
build-essential \
|
||||
libavcodec-dev \
|
||||
libavutil-dev \
|
||||
libswresample-dev \
|
||||
libswscale-dev \
|
||||
pkg-config
|
||||
- name: Get dependencies
|
||||
run: cd machinery && go mod download
|
||||
- name: Build
|
||||
run: cd machinery && go build -v ./...
|
||||
- name: Vet
|
||||
run: cd machinery && go vet -v ./...
|
||||
- name: Test
|
||||
run: cd machinery && go test -v ./...
|
||||
- name: Test frame processor example
|
||||
run: cd examples/frame-processor && GOWORK=off go test -v ./...
|
||||
|
||||
51
.github/workflows/issue-userstory-create.yml
vendored
Normal file
@@ -0,0 +1,51 @@
|
||||
name: Create User Story Issue
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
issue_title:
|
||||
description: 'Title for the issue'
|
||||
required: true
|
||||
issue_description:
|
||||
description: 'Brief description of the feature'
|
||||
required: true
|
||||
complexity:
|
||||
description: 'Complexity of the feature'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- 'Low'
|
||||
- 'Medium'
|
||||
- 'High'
|
||||
default: 'Medium'
|
||||
duration:
|
||||
description: 'Estimated duration'
|
||||
required: true
|
||||
type: choice
|
||||
options:
|
||||
- '1 day'
|
||||
- '3 days'
|
||||
- '1 week'
|
||||
- '2 weeks'
|
||||
- '1 month'
|
||||
default: '1 week'
|
||||
|
||||
jobs:
|
||||
create-issue:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
issues: write
|
||||
steps:
|
||||
- name: Create Issue with User Story
|
||||
uses: cedricve/llm-create-issue-user-story@main
|
||||
with:
|
||||
github_token: ${{ secrets.GITHUB_TOKEN }}
|
||||
azure_openai_api_key: ${{ secrets.AZURE_OPENAI_API_KEY }}
|
||||
azure_openai_endpoint: ${{ secrets.AZURE_OPENAI_ENDPOINT }}
|
||||
azure_openai_version: ${{ secrets.AZURE_OPENAI_VERSION }}
|
||||
openai_model: ${{ secrets.OPENAI_MODEL }}
|
||||
issue_title: ${{ github.event.inputs.issue_title }}
|
||||
issue_description: ${{ github.event.inputs.issue_description }}
|
||||
complexity: ${{ github.event.inputs.complexity }}
|
||||
duration: ${{ github.event.inputs.duration }}
|
||||
labels: 'user-story,feature'
|
||||
assignees: ${{ github.actor }}
|
||||
62
.github/workflows/nightly-build.yml
vendored
Normal file
@@ -0,0 +1,62 @@
|
||||
name: Nightly build
|
||||
|
||||
on:
|
||||
# Triggers the workflow every day at 9PM (CET).
|
||||
schedule:
|
||||
- cron: "0 22 * * *"
|
||||
# Allows manual triggering from the Actions tab.
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
nightly-build-amd64:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [amd64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: master
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
id: buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --build-arg VERSION=$(echo $GITHUB_SHA | cut -c1-7) --platform linux/${{matrix.architecture}} -t kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create -t kerberos/agent-nightly:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
nightly-build-other:
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [arm64, arm/v7, arm/v6]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: master
|
||||
- name: Set up QEMU
|
||||
uses: docker/setup-qemu-action@v3
|
||||
- name: Set up Docker Buildx
|
||||
id: buildx
|
||||
uses: docker/setup-buildx-action@v3
|
||||
- name: Available platforms
|
||||
run: echo ${{ steps.buildx.outputs.platforms }}
|
||||
- name: Run Buildx
|
||||
run: docker buildx build --build-arg VERSION=$(echo $GITHUB_SHA | cut -c1-7) --platform linux/${{matrix.architecture}} -t kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7) --push .
|
||||
- name: Create new and append to manifest
|
||||
run: docker buildx imagetools create --append -t kerberos/agent-nightly:$(echo $GITHUB_SHA | cut -c1-7) kerberos/agent-nightly:arch-$(echo ${{matrix.architecture}} | tr / -)-$(echo $GITHUB_SHA | cut -c1-7)
|
||||
41
.github/workflows/pr-build.yml
vendored
Normal file
@@ -0,0 +1,41 @@
|
||||
name: Build pull request
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, synchronize]
|
||||
|
||||
env:
|
||||
REPO: kerberos/agent
|
||||
|
||||
jobs:
|
||||
build:
|
||||
runs-on: ${{ matrix.runner }}
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
include:
|
||||
- architecture: amd64
|
||||
runner: ubuntu-24.04
|
||||
- architecture: arm64
|
||||
runner: ubuntu-24.04-arm
|
||||
steps:
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Run Build
|
||||
run: |
|
||||
docker build --build-arg VERSION=$(echo "${{ github.event.pull_request.head.sha }}" | cut -c1-7) -t ${{ matrix.architecture }} .
|
||||
CID=$(docker create ${{matrix.architecture}})
|
||||
docker cp ${CID}:/home/agent ./output-${{matrix.architecture}}
|
||||
docker rm ${CID}
|
||||
- name: Strip binary
|
||||
run: tar -cf agent-${{matrix.architecture}}.tar -C output-${{matrix.architecture}} . && rm -rf output-${{matrix.architecture}}
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: agent-${{matrix.architecture}}.tar
|
||||
path: agent-${{matrix.architecture}}.tar
|
||||
17
.github/workflows/pr-description.yaml
vendored
Normal file
@@ -0,0 +1,17 @@
|
||||
name: Autofill PR description
|
||||
|
||||
on: pull_request
|
||||
|
||||
jobs:
|
||||
openai-pr-description:
|
||||
uses: uug-ai/workflows/.github/workflows/pr-description.yml@main
|
||||
with:
|
||||
pr_number: ${{ github.event.number }}
|
||||
pull_request_url: ""
|
||||
overwrite_description: true
|
||||
secrets:
|
||||
TOKEN: ${{ secrets.TOKEN }}
|
||||
AZURE_OPENAI_API_KEY: ${{ secrets.AZURE_OPENAI_API_KEY }}
|
||||
OPENAI_MODEL: ${{ secrets.OPENAI_MODEL }}
|
||||
AZURE_OPENAI_ENDPOINT: ${{ secrets.AZURE_OPENAI_ENDPOINT }}
|
||||
AZURE_OPENAI_VERSION: ${{ secrets.AZURE_OPENAI_VERSION }}
|
||||
11
.github/workflows/react.yml
vendored
@@ -11,21 +11,22 @@ on:
|
||||
|
||||
jobs:
|
||||
build:
|
||||
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
strategy:
|
||||
matrix:
|
||||
node-version: [14.x, 16.x]
|
||||
node-version: [22.x]
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v2
|
||||
- uses: actions/checkout@v4
|
||||
- name: Use Node.js ${{ matrix.node-version }}
|
||||
uses: actions/setup-node@v2
|
||||
uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: ${{ matrix.node-version }}
|
||||
cache: yarn
|
||||
cache-dependency-path: ui/yarn.lock
|
||||
- name: Yarn install
|
||||
run: cd ui && yarn
|
||||
run: cd ui && yarn --frozen-lockfile
|
||||
- name: Yarn test
|
||||
run: cd ui && yarn test --passWithNoTests
|
||||
- name: Yarn build
|
||||
|
||||
160
.github/workflows/release-bump.yml
vendored
Normal file
@@ -0,0 +1,160 @@
|
||||
name: Bump release
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
bump:
|
||||
description: "Which part of the version to bump"
|
||||
required: true
|
||||
default: patch
|
||||
type: choice
|
||||
options:
|
||||
- major
|
||||
- minor
|
||||
- patch
|
||||
|
||||
permissions:
|
||||
contents: write
|
||||
|
||||
env:
|
||||
REPO: kerberos/agent
|
||||
|
||||
jobs:
|
||||
# Determine the next version, create the GitHub release and expose the tag.
|
||||
bump-release:
|
||||
uses: uug-ai/workflows/.github/workflows/release-bump.yml@main
|
||||
with:
|
||||
bump: ${{ github.event.inputs.bump }}
|
||||
secrets: inherit
|
||||
|
||||
# Publish the platform image to the uug-ai GitHub Container Registry
|
||||
# (ghcr.io/uug-ai/agent-platform).
|
||||
#release:
|
||||
# needs: bump-release
|
||||
# uses: uug-ai/workflows/.github/workflows/release-create.yml@main
|
||||
# with:
|
||||
# organization: uug-ai
|
||||
# project: ${{ github.event.repository.name }}
|
||||
# tag: ${{ needs.bump-release.outputs.tag }}
|
||||
# docker_context: "."
|
||||
# create_gitops_pr: false
|
||||
# runner_matrix: >-
|
||||
# [
|
||||
# {"architecture":"amd64","runner":"ubuntu-24.04"},
|
||||
# {"architecture":"arm64","runner":"ubuntu-24.04-arm"}
|
||||
# ]
|
||||
# secrets: inherit
|
||||
|
||||
# Everything below mirrors the agent's own release-create.yml pipeline and
|
||||
# publishes the multi-arch image to the kerberos/agent Docker Hub repo, driven
|
||||
# by the freshly bumped tag instead of a `release: created` event.
|
||||
build-amd64:
|
||||
needs: bump-release
|
||||
runs-on: ubuntu-24.04
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [amd64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
- name: Run Build
|
||||
run: |
|
||||
docker build --provenance=false --build-arg VERSION=${{ needs.bump-release.outputs.tag }} -t ${{matrix.architecture}} .
|
||||
CID=$(docker create ${{matrix.architecture}})
|
||||
docker cp ${CID}:/home/agent ./output-${{matrix.architecture}}
|
||||
docker rm ${CID}
|
||||
- name: Strip binary
|
||||
run: tar -cf agent-${{matrix.architecture}}.tar -C output-${{matrix.architecture}} . && rm -rf output-${{matrix.architecture}}
|
||||
- name: Build and push Docker image
|
||||
run: |
|
||||
docker tag ${{matrix.architecture}} $REPO-arch:arch-${{matrix.architecture}}-${{ needs.bump-release.outputs.tag }}
|
||||
docker push $REPO-arch:arch-${{matrix.architecture}}-${{ needs.bump-release.outputs.tag }}
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: agent-${{matrix.architecture}}.tar
|
||||
path: agent-${{matrix.architecture}}.tar
|
||||
|
||||
build-arm64:
|
||||
needs: bump-release
|
||||
runs-on: ubuntu-24.04-arm
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [arm64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
- name: Run Build
|
||||
run: |
|
||||
docker build --provenance=false --build-arg VERSION=${{ needs.bump-release.outputs.tag }} -t ${{matrix.architecture}} .
|
||||
CID=$(docker create ${{matrix.architecture}})
|
||||
docker cp ${CID}:/home/agent ./output-${{matrix.architecture}}
|
||||
docker rm ${CID}
|
||||
- name: Strip binary
|
||||
run: tar -cf agent-${{matrix.architecture}}.tar -C output-${{matrix.architecture}} . && rm -rf output-${{matrix.architecture}}
|
||||
- name: Build and push Docker image
|
||||
run: |
|
||||
docker tag ${{matrix.architecture}} $REPO-arch:arch-${{matrix.architecture}}-${{ needs.bump-release.outputs.tag }}
|
||||
docker push $REPO-arch:arch-${{matrix.architecture}}-${{ needs.bump-release.outputs.tag }}
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: agent-${{matrix.architecture}}.tar
|
||||
path: agent-${{matrix.architecture}}.tar
|
||||
|
||||
create-manifest:
|
||||
runs-on: ubuntu-24.04
|
||||
needs: [bump-release, build-amd64, build-arm64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Create and push multi-arch manifest
|
||||
run: |
|
||||
docker manifest create $REPO:${{ needs.bump-release.outputs.tag }} \
|
||||
$REPO-arch:arch-amd64-${{ needs.bump-release.outputs.tag }} \
|
||||
$REPO-arch:arch-arm64-${{ needs.bump-release.outputs.tag }}
|
||||
docker manifest push $REPO:${{ needs.bump-release.outputs.tag }}
|
||||
- name: Create and push latest manifest
|
||||
run: |
|
||||
docker manifest create $REPO:latest \
|
||||
$REPO-arch:arch-amd64-${{ needs.bump-release.outputs.tag }} \
|
||||
$REPO-arch:arch-arm64-${{ needs.bump-release.outputs.tag }}
|
||||
docker manifest push $REPO:latest
|
||||
|
||||
create-release:
|
||||
runs-on: ubuntu-24.04
|
||||
needs: [bump-release, build-amd64, build-arm64]
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- name: Download all artifacts
|
||||
uses: actions/download-artifact@v4
|
||||
- name: Create a release
|
||||
uses: ncipollo/release-action@v1
|
||||
with:
|
||||
latest: true
|
||||
allowUpdates: true
|
||||
name: ${{ needs.bump-release.outputs.tag }}
|
||||
tag: ${{ needs.bump-release.outputs.tag }}
|
||||
generateReleaseNotes: false
|
||||
omitBodyDuringUpdate: true
|
||||
artifacts: "agent-*.tar/agent-*.tar"
|
||||
|
||||
|
||||
122
.github/workflows/release-create.yml
vendored
Normal file
@@ -0,0 +1,122 @@
|
||||
name: Create a new release
|
||||
on:
|
||||
release:
|
||||
types: [created]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
tag:
|
||||
description: "Tag for the Docker image"
|
||||
required: true
|
||||
default: "test"
|
||||
|
||||
env:
|
||||
REPO: kerberos/agent
|
||||
|
||||
jobs:
|
||||
build-amd64:
|
||||
runs-on: ubuntu-24.04
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [amd64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
- name: Run Build
|
||||
run: |
|
||||
docker build --provenance=false --build-arg VERSION=${{github.event.inputs.tag || github.ref_name}} -t ${{matrix.architecture}} .
|
||||
CID=$(docker create ${{matrix.architecture}})
|
||||
docker cp ${CID}:/home/agent ./output-${{matrix.architecture}}
|
||||
docker rm ${CID}
|
||||
- name: Strip binary
|
||||
run: tar -cf agent-${{matrix.architecture}}.tar -C output-${{matrix.architecture}} . && rm -rf output-${{matrix.architecture}}
|
||||
- name: Build and push Docker image
|
||||
run: |
|
||||
docker tag ${{matrix.architecture}} $REPO-arch:arch-${{matrix.architecture}}-${{github.event.inputs.tag || github.ref_name}}
|
||||
docker push $REPO-arch:arch-${{matrix.architecture}}-${{github.event.inputs.tag || github.ref_name}}
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: agent-${{matrix.architecture}}.tar
|
||||
path: agent-${{matrix.architecture}}.tar
|
||||
|
||||
build-arm64:
|
||||
runs-on: ubuntu-24.04-arm
|
||||
permissions:
|
||||
contents: write
|
||||
strategy:
|
||||
matrix:
|
||||
architecture: [arm64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Checkout
|
||||
uses: actions/checkout@v4
|
||||
- name: Run Build
|
||||
run: |
|
||||
docker build --provenance=false --build-arg VERSION=${{github.event.inputs.tag || github.ref_name}} -t ${{matrix.architecture}} .
|
||||
CID=$(docker create ${{matrix.architecture}})
|
||||
docker cp ${CID}:/home/agent ./output-${{matrix.architecture}}
|
||||
docker rm ${CID}
|
||||
- name: Strip binary
|
||||
run: tar -cf agent-${{matrix.architecture}}.tar -C output-${{matrix.architecture}} . && rm -rf output-${{matrix.architecture}}
|
||||
- name: Build and push Docker image
|
||||
run: |
|
||||
docker tag ${{matrix.architecture}} $REPO-arch:arch-${{matrix.architecture}}-${{github.event.inputs.tag || github.ref_name}}
|
||||
docker push $REPO-arch:arch-${{matrix.architecture}}-${{github.event.inputs.tag || github.ref_name}}
|
||||
- name: Upload artifact
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: agent-${{matrix.architecture}}.tar
|
||||
path: agent-${{matrix.architecture}}.tar
|
||||
|
||||
create-manifest:
|
||||
runs-on: ubuntu-24.04
|
||||
needs: [build-amd64, build-arm64]
|
||||
steps:
|
||||
- name: Login to DockerHub
|
||||
uses: docker/login-action@v3
|
||||
with:
|
||||
username: ${{ secrets.DOCKER_USERNAME }}
|
||||
password: ${{ secrets.DOCKER_PASSWORD }}
|
||||
- name: Create and push multi-arch manifest
|
||||
run: |
|
||||
docker manifest create $REPO:${{ github.event.inputs.tag || github.ref_name }} \
|
||||
$REPO-arch:arch-amd64-${{github.event.inputs.tag || github.ref_name}} \
|
||||
$REPO-arch:arch-arm64-${{github.event.inputs.tag || github.ref_name}}
|
||||
docker manifest push $REPO:${{ github.event.inputs.tag || github.ref_name }}
|
||||
- name: Create and push latest manifest
|
||||
run: |
|
||||
docker manifest create $REPO:latest \
|
||||
$REPO-arch:arch-amd64-${{github.event.inputs.tag || github.ref_name}} \
|
||||
$REPO-arch:arch-arm64-${{github.event.inputs.tag || github.ref_name}}
|
||||
docker manifest push $REPO:latest
|
||||
if: github.event.inputs.tag == 'test'
|
||||
|
||||
create-release:
|
||||
runs-on: ubuntu-24.04
|
||||
needs: [build-amd64, build-arm64]
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- name: Download all artifacts
|
||||
uses: actions/download-artifact@v4
|
||||
- name: Create a release
|
||||
uses: ncipollo/release-action@v1
|
||||
with:
|
||||
latest: true
|
||||
allowUpdates: true
|
||||
name: ${{ github.event.inputs.tag || github.ref_name }}
|
||||
tag: ${{ github.event.inputs.tag || github.ref_name }}
|
||||
generateReleaseNotes: false
|
||||
omitBodyDuringUpdate: true
|
||||
artifacts: "agent-*.tar/agent-*.tar"
|
||||
11
.gitignore
vendored
@@ -1,6 +1,8 @@
|
||||
ui/node_modules
|
||||
ui/build
|
||||
ui/public/assets/env.js
|
||||
.DS_Store
|
||||
__debug*
|
||||
.idea
|
||||
machinery/www
|
||||
yarn.lock
|
||||
@@ -8,4 +10,11 @@ machinery/data/config
|
||||
machinery/data/cloud
|
||||
machinery/data/recordings
|
||||
machinery/data/snapshots
|
||||
machinery/test*
|
||||
machinery/test*
|
||||
machinery/init-dev.sh
|
||||
machinery/.env.local
|
||||
machinery/vendor
|
||||
machinery/go.work
|
||||
machinery/go.work.sum
|
||||
deployments/docker/private-docker-compose.yaml
|
||||
video.mp4
|
||||
19
.travis.yml
@@ -1,19 +0,0 @@
|
||||
language: go
|
||||
|
||||
go:
|
||||
- 1.12.x
|
||||
- 1.13.x
|
||||
- 1.14.x
|
||||
- 1.15.x
|
||||
- tip
|
||||
|
||||
before_install:
|
||||
- cd machinery
|
||||
- go mod download
|
||||
|
||||
script:
|
||||
- go vet
|
||||
- go test -race -coverprofile=coverage.txt -covermode=atomic
|
||||
|
||||
after_success:
|
||||
- bash <(curl -s https://codecov.io/bash)
|
||||
25
.vscode/launch.json
vendored
@@ -5,11 +5,32 @@
|
||||
"version": "0.2.0",
|
||||
"configurations": [
|
||||
{
|
||||
"name": "Launch Package",
|
||||
"name": "Launch Golang",
|
||||
"type": "go",
|
||||
"request": "launch",
|
||||
"mode": "auto",
|
||||
"program": "${fileDirname}"
|
||||
"program": "${workspaceFolder}/machinery/main.go",
|
||||
"args": [
|
||||
"-action",
|
||||
"run",
|
||||
"-port",
|
||||
"8080"
|
||||
],
|
||||
"envFile": "${workspaceFolder}/machinery/.env.local",
|
||||
"buildFlags": "--tags dynamic,moq",
|
||||
"env": {
|
||||
"GOWORK": "off"
|
||||
},
|
||||
},
|
||||
{
|
||||
"name": "Launch React",
|
||||
"type": "node",
|
||||
"request": "launch",
|
||||
"cwd": "${workspaceFolder}/ui",
|
||||
"runtimeExecutable": "yarn",
|
||||
"runtimeArgs": [
|
||||
"start"
|
||||
],
|
||||
}
|
||||
]
|
||||
}
|
||||
14
.vscode/tasks.json
vendored
Normal file
@@ -0,0 +1,14 @@
|
||||
{
|
||||
"version": "2.0.0",
|
||||
"tasks": [
|
||||
{
|
||||
"label": "agent: moq verify",
|
||||
"type": "shell",
|
||||
"command": "bash ./verify-moq-devcontainer.sh",
|
||||
"options": {
|
||||
"cwd": "${workspaceFolder}/machinery"
|
||||
},
|
||||
"problemMatcher": []
|
||||
}
|
||||
]
|
||||
}
|
||||
148
Dockerfile
@@ -1,5 +1,15 @@
|
||||
FROM kerberos/base:977706d AS builder
|
||||
LABEL AUTHOR=Kerberos.io
|
||||
|
||||
ARG GO_IMAGE=golang:1.25-trixie
|
||||
ARG RUNTIME_IMAGE=debian:trixie-slim
|
||||
ARG VERSION=0.0.0
|
||||
FROM ${GO_IMAGE} AS build-machinery
|
||||
LABEL AUTHOR=uug.ai
|
||||
|
||||
# Re-declare VERSION inside this stage so the value passed via
|
||||
# `--build-arg VERSION=...` (e.g. the release tag) is available below.
|
||||
# ARGs declared before the first FROM are not visible inside build stages.
|
||||
ARG VERSION
|
||||
ARG TARGETARCH
|
||||
|
||||
ENV GOROOT=/usr/local/go
|
||||
ENV GOPATH=/go
|
||||
@@ -9,51 +19,44 @@ ENV GOSUMDB=off
|
||||
##########################################
|
||||
# Installing some additional dependencies.
|
||||
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
RUN apt-get update && apt-get install -y --fix-missing --no-install-recommends \
|
||||
git build-essential cmake pkg-config unzip libgtk2.0-dev \
|
||||
curl ca-certificates libcurl4-openssl-dev libssl-dev \
|
||||
libavcodec-dev libavformat-dev libswscale-dev libtbb2 libtbb-dev \
|
||||
libjpeg-dev libpng-dev libtiff-dev libdc1394-22-dev && \
|
||||
curl ca-certificates libavcodec-dev libavutil-dev libcurl4-openssl-dev \
|
||||
libssl-dev libjpeg62-turbo-dev libswscale-dev && \
|
||||
rm -rf /var/lib/apt/lists/*
|
||||
|
||||
##############################################################################
|
||||
# Copy all the relevant source code in the Docker image, so we can build this.
|
||||
# Copy dependency metadata first so module downloads can be cached separately.
|
||||
|
||||
RUN mkdir -p /go/src/github.com/kerberos-io/agent
|
||||
COPY machinery /go/src/github.com/kerberos-io/agent/machinery
|
||||
COPY ui /go/src/github.com/kerberos-io/agent/ui
|
||||
WORKDIR /go/src/github.com/kerberos-io/agent/machinery
|
||||
COPY machinery/go.mod machinery/go.sum ./
|
||||
RUN go mod download
|
||||
|
||||
########################
|
||||
# Download NPM and Yarns
|
||||
##############################################################################
|
||||
# Copy the rest of the source after dependencies are primed.
|
||||
|
||||
RUN apt-get update && apt-get install -y curl && curl -sL https://deb.nodesource.com/setup_16.x | bash - && \
|
||||
curl -sS https://dl.yarnpkg.com/debian/pubkey.gpg | apt-key add - && \
|
||||
echo "deb https://dl.yarnpkg.com/debian/ stable main" | tee /etc/apt/sources.list.d/yarn.list && \
|
||||
apt update && apt install yarn -y
|
||||
|
||||
##################################################################
|
||||
# Build Web
|
||||
# this will move the /build directory to ../machinery/www
|
||||
|
||||
RUN cd /go/src/github.com/kerberos-io/agent/ui && yarn && yarn build
|
||||
COPY machinery ./
|
||||
RUN rm -rf .env
|
||||
|
||||
##################
|
||||
# Build Machinery
|
||||
|
||||
RUN cd /go/src/github.com/kerberos-io/agent/machinery && \
|
||||
go mod download && \
|
||||
go build main.go && \
|
||||
RUN RESOLVED_VERSION="${VERSION:-0.0.0}" && \
|
||||
printf '%s' "${RESOLVED_VERSION}" > version && \
|
||||
BUILD_TAGS=timetzdata,netgo,osusergo && \
|
||||
case "${TARGETARCH:-$(go env GOARCH)}" in amd64|arm64) BUILD_TAGS="moq,${BUILD_TAGS}" ;; esac && \
|
||||
go build -o main -tags "${BUILD_TAGS}" --ldflags "-s -w -X github.com/kerberos-io/agent/machinery/src/utils.VERSION=${RESOLVED_VERSION}" . && \
|
||||
mkdir -p /agent && \
|
||||
mv main /agent && \
|
||||
mv www /agent && \
|
||||
mv version /agent && \
|
||||
mv data /agent && \
|
||||
mkdir -p /agent/data/cloud && \
|
||||
mkdir -p /agent/data/snapshots && \
|
||||
mkdir -p /agent/data/log && \
|
||||
mkdir -p /agent/data/recordings && \
|
||||
mkdir -p /agent/data/capture-test && \
|
||||
mkdir -p /agent/data/config && \
|
||||
rm -rf /go/src/gitlab.com/
|
||||
mkdir -p /agent/data/config
|
||||
|
||||
####################################
|
||||
# Let's create a /dist folder containing just the files necessary for runtime.
|
||||
@@ -65,68 +68,49 @@ RUN cp -r /agent ./
|
||||
####################################################################################
|
||||
# This will collect dependent libraries so they're later copied to the final image.
|
||||
|
||||
RUN /agent/main version
|
||||
RUN ldd /agent/main | tr -s '[:blank:]' '\n'
|
||||
RUN ldd /agent/main | tr -s '[:blank:]' '\n' | grep '^/' | \
|
||||
xargs -I % sh -c 'mkdir -p $(dirname ./%); cp % ./%;'
|
||||
RUN /dist/agent/main version
|
||||
|
||||
##########################################################
|
||||
# LDD doesnt always work in docker buildx (no idea why..)
|
||||
# Therefore we are moving some libraries manually
|
||||
FROM node:22-alpine AS build-ui
|
||||
|
||||
RUN mkdir -p ./usr/lib
|
||||
RUN apk update && apk upgrade --available && sync
|
||||
|
||||
RUN [ -f /lib64/ld-linux-x86-64.so.2 ] && $(mkdir -p lib64 && \
|
||||
cp /lib64/ld-linux-x86-64.so.2 lib64/) || echo "nothing to do here x86"
|
||||
########################
|
||||
# Build Web (React app)
|
||||
|
||||
RUN [ -f /lib/ld-linux-aarch64.so.1 ] && $(mkdir -p lib/aarch64-linux-gnu && \
|
||||
cp /lib/ld-linux-aarch64.so.1 lib/ && \
|
||||
cp /lib/aarch64-linux-gnu/lib* lib/aarch64-linux-gnu/ && \
|
||||
cp /usr/lib/aarch64-linux-gnu/libopencv* usr/lib && \
|
||||
cp /usr/lib/aarch64-linux-gnu/libstdc* usr/lib && \
|
||||
cp /usr/lib/aarch64-linux-gnu/libx264* usr/lib ) || echo "nothing to do here arm64"
|
||||
RUN mkdir -p /go/src/github.com/kerberos-io/agent/machinery/www
|
||||
WORKDIR /go/src/github.com/kerberos-io/agent/ui
|
||||
COPY ui/package.json ui/yarn.lock ./
|
||||
RUN yarn config set network-timeout 300000 && yarn --frozen-lockfile
|
||||
COPY ui ./
|
||||
RUN yarn build
|
||||
|
||||
RUN [ -f /usr/lib/arm-linux-gnueabihf/vfp/neon/libvpx.so.6 ] && \
|
||||
$(cp /usr/lib/arm-linux-gnueabihf/vfp/neon/libvpx.so.6 ./usr/lib/) || echo "nothing to do here armv7"
|
||||
####################################
|
||||
# Let's create a /dist folder containing just the files necessary for runtime.
|
||||
# Later, it will be copied as the / (root) of the output image.
|
||||
|
||||
RUN cp -r /usr/local/lib/libavcodec* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libavformat* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libavfilter* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libavutil* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libavresample* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libavdevice* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libswscale* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libswresample* ./usr/lib && \
|
||||
cp -r /usr/local/lib/libpostproc* ./usr/lib
|
||||
WORKDIR /dist
|
||||
RUN mkdir -p ./agent && cp -r /go/src/github.com/kerberos-io/agent/machinery/www ./agent/
|
||||
|
||||
# As mentioned before, above is really a hack as LDD
|
||||
# doesn't work always in docker buildx. You might not need this
|
||||
# when doing a local build.
|
||||
################################################################
|
||||
############################################
|
||||
# Publish main binary to GitHub release
|
||||
|
||||
FROM alpine:latest
|
||||
FROM ${RUNTIME_IMAGE}
|
||||
|
||||
############################
|
||||
# Protect by non-root user.
|
||||
|
||||
RUN addgroup -S kerberosio && adduser -S agent -G kerberosio && addgroup agent video
|
||||
RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
ca-certificates curl ffmpeg libatomic1 libcap2-bin libstdc++6 && \
|
||||
rm -rf /var/lib/apt/lists/* && \
|
||||
groupadd --system kerberosio && \
|
||||
useradd --system --gid kerberosio --groups video --create-home agent && \
|
||||
chmod 0755 /home/agent
|
||||
|
||||
#################################
|
||||
# Copy files from previous images
|
||||
|
||||
COPY --chown=0:0 --from=builder /dist /
|
||||
COPY --chown=0:0 --from=builder /usr/local/go/lib/time/zoneinfo.zip /zoneinfo.zip
|
||||
|
||||
ENV ZONEINFO=/zoneinfo.zip
|
||||
|
||||
RUN apk update && apk add ca-certificates --no-cache && \
|
||||
apk add tzdata curl --no-cache && rm -rf /var/cache/apk/*
|
||||
|
||||
#################
|
||||
# Install Bento4
|
||||
RUN cd && wget https://www.bok.net/Bento4/binaries/Bento4-SDK-1-6-0-639.x86_64-unknown-linux.zip && \
|
||||
unzip Bento4-SDK-1-6-0-639.x86_64-unknown-linux.zip && rm Bento4-SDK-1-6-0-639.x86_64-unknown-linux.zip && \
|
||||
cp ~/Bento4-SDK-1-6-0-639.x86_64-unknown-linux/bin/mp4fragment /usr/bin/
|
||||
COPY --chown=0:0 --from=build-machinery /dist /
|
||||
COPY --chown=0:0 --from=build-ui /dist /
|
||||
|
||||
##################
|
||||
# Try running agent
|
||||
@@ -134,10 +118,20 @@ RUN cd && wget https://www.bok.net/Bento4/binaries/Bento4-SDK-1-6-0-639.x86_64-u
|
||||
RUN mv /agent/* /home/agent/
|
||||
RUN /home/agent/main version
|
||||
|
||||
#######################
|
||||
# Make template config
|
||||
|
||||
RUN cp /home/agent/data/config/config.json /home/agent/data/config.template.json
|
||||
|
||||
###########################
|
||||
# Set permissions correctly
|
||||
|
||||
RUN chown -R agent:kerberosio /home/agent/data
|
||||
RUN chown -R agent:kerberosio /home/agent/www
|
||||
|
||||
###########################
|
||||
# Grant the necessary root capabilities to the process trying to bind to the privileged port
|
||||
RUN setcap 'cap_net_bind_service=+ep' /home/agent/main
|
||||
|
||||
###################
|
||||
# Run non-root user
|
||||
@@ -145,17 +139,17 @@ RUN chown -R agent:kerberosio /home/agent/data
|
||||
USER agent
|
||||
|
||||
######################################
|
||||
# By default the app runs on port 8080
|
||||
# By default the app runs on port 80
|
||||
|
||||
EXPOSE 8080
|
||||
EXPOSE 80
|
||||
|
||||
######################################
|
||||
# Check if agent is still running
|
||||
|
||||
HEALTHCHECK CMD curl --fail http://localhost:8080 || exit 1
|
||||
HEALTHCHECK CMD curl --fail "http://localhost:${AGENT_PORT:-80}/health" || exit 1
|
||||
|
||||
###################################################
|
||||
# Leeeeettttt'ssss goooooo!!!
|
||||
# Run the shizzle from the right working directory.
|
||||
WORKDIR /home/agent
|
||||
CMD ["./main", "run", "opensource", "8080"]
|
||||
CMD ["./main", "-action", "run"]
|
||||
645
README-RTSPS-TLS.md
Normal file
@@ -0,0 +1,645 @@
|
||||
# RTSPS and TLS certificates
|
||||
|
||||
This guide explains how Kerberos Agent connects to an IP camera over RTSPS,
|
||||
how to issue a camera certificate with a private CA, and how to validate the
|
||||
complete trust path. It also explains why some apparently corrupted trust
|
||||
bundles can still allow a connection.
|
||||
|
||||
The camera-specific steps were verified with a Bosch FLEXIDOME micro 3100i.
|
||||
Other Bosch firmware versions may use different labels or ports.
|
||||
|
||||
The commands were tested with Smallstep CLI `0.30.6` and OpenSSL `3.5.6` on
|
||||
Debian. Check `step certificate sign --help` when using an older Smallstep CLI.
|
||||
The OpenSSL isolation flags `-no-CApath` and `-no-CAstore` require a version that
|
||||
lists them in `openssl s_client -help`.
|
||||
|
||||
## Tested configuration
|
||||
|
||||
| Setting | Value |
|
||||
| --- | --- |
|
||||
| Camera | Bosch FLEXIDOME micro 3100i |
|
||||
| Example camera address | `10.0.30.11` |
|
||||
| RTSPS port | `9554` |
|
||||
| Main stream | `rtsps://<user>:<password>@10.0.30.11:9554/?inst=1` |
|
||||
| Sub stream | `rtsps://<user>:<password>@10.0.30.11:9554/?inst=2` |
|
||||
| Certificate SAN | `IP Address:10.0.30.11` |
|
||||
| Bosch certificate usage | `HTTPS` |
|
||||
| Agent trust input | Issuing intermediate plus root CA |
|
||||
|
||||
Replace the example address and certificate names throughout this guide. Keep
|
||||
camera credentials out of source control and percent-encode reserved URL
|
||||
characters in usernames and passwords.
|
||||
|
||||
## Mental model
|
||||
|
||||
### RTSPS, SRTSP, TLS, and SRTP
|
||||
|
||||
- The standard URL scheme is `rtsps://`. Do not use `srtsp://`.
|
||||
- Bosch interfaces and documentation may use SRTSP or Secure RTSP as product
|
||||
terminology.
|
||||
- RTSPS carries the RTSP control connection over TLS. With gortsplib, media is
|
||||
normally interleaved over the same TCP/TLS connection for this camera.
|
||||
- SRTP is a separate media protection mechanism and is negotiated only when the
|
||||
camera advertises an appropriate secure RTP profile.
|
||||
|
||||
Encryption alone does not prove which camera the Agent reached. Verified TLS
|
||||
also checks that:
|
||||
|
||||
1. The camera certificate is signed by a trusted authority.
|
||||
2. The certificate is valid at the current time.
|
||||
3. The URL host matches a certificate Subject Alternative Name (SAN).
|
||||
|
||||
Modern Go verification uses SANs for identity. A Common Name alone is not
|
||||
sufficient. Connecting to `10.0.30.11` requires an IP SAN with that exact value,
|
||||
not `DNS:10.0.30.11` and not only a device-name DNS SAN.
|
||||
|
||||
### Agent behavior
|
||||
|
||||
Kerberos Agent uses gortsplib for RTSP and RTSPS. With the normal configuration,
|
||||
gortsplib receives a nil custom TLS configuration and Go performs standard
|
||||
certificate and hostname verification with the process trust pool.
|
||||
|
||||
`AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=true` is an explicit escape hatch that
|
||||
sets `InsecureSkipVerify` for camera clients. It should be false in a verified
|
||||
deployment.
|
||||
|
||||
## Communication and certificate flow
|
||||
|
||||
The certificate is used during the TLS handshake, before the first RTSP command
|
||||
is exchanged. It is not attached to `DESCRIBE`, `SETUP`, or `PLAY`, and the CA
|
||||
trust bundle is never sent to the camera.
|
||||
|
||||
```mermaid
|
||||
sequenceDiagram
|
||||
participant Agent as Kerberos Agent
|
||||
participant Trust as Go trust pool
|
||||
participant Camera as Camera RTSPS :9554
|
||||
|
||||
Agent->>Trust: Load system roots and append AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE
|
||||
Agent->>Camera: Open TCP connection
|
||||
Agent->>Camera: Send TLS ClientHello
|
||||
Camera-->>Agent: Send TLS ServerHello and camera certificate
|
||||
Agent->>Trust: Verify chain, validity, serverAuth, and URL host against SAN
|
||||
Trust-->>Agent: Accept or reject the camera identity
|
||||
Agent->>Camera: Complete TLS handshake
|
||||
Note over Agent,Camera: All following traffic is encrypted by TLS
|
||||
Agent->>Camera: DESCRIBE with RTSP authentication
|
||||
Camera-->>Agent: Return SDP and available media tracks
|
||||
Agent->>Camera: SETUP selected video and audio tracks over TCP
|
||||
Agent->>Camera: PLAY
|
||||
Camera-->>Agent: Send interleaved RTP and RTCP media over TLS
|
||||
```
|
||||
|
||||
The files and keys have distinct roles:
|
||||
|
||||
| Material | Location | Purpose | Sent over the connection |
|
||||
| --- | --- | --- | --- |
|
||||
| Camera leaf certificate | Camera | Identifies the camera and binds its public key to its SAN | Yes, by the camera during the TLS handshake |
|
||||
| Camera private key | Camera | Proves that the camera owns the presented certificate | No |
|
||||
| Intermediate and root CA PEM bundle | Agent | Lets Go build and trust the camera certificate chain | No |
|
||||
| RTSP username and password | Agent configuration or URL | Authenticates the Agent to the RTSP service after TLS succeeds | An authentication response is sent inside TLS; its form depends on the RTSP authentication method |
|
||||
|
||||
For an `rtsps://` URL, the Agent parses the URL and gives gortsplib the host and
|
||||
TLS settings. gortsplib opens the TCP connection and starts TLS. Go compares the
|
||||
certificate presented by the camera with the local trust pool, checks its
|
||||
validity period and server usage, and matches the URL hostname or IP address to
|
||||
the certificate SAN. Only a successful handshake creates the encrypted channel
|
||||
needed for the RTSP exchange.
|
||||
|
||||
The Agent then sends `DESCRIBE`, selects the advertised video and audio tracks,
|
||||
sends `SETUP`, and starts delivery with `PLAY`. For the tested camera, gortsplib
|
||||
uses interleaved TCP, so the RTSP control messages and RTP/RTCP media remain
|
||||
inside the same encrypted TLS connection. Main stream, sub stream, and enabled
|
||||
audio backchannel clients each establish and verify their own connection.
|
||||
|
||||
If certificate verification fails, the TLS handshake does not complete and no
|
||||
usable RTSP session is established. Setting
|
||||
`AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=true` keeps traffic encrypted but skips
|
||||
certificate-chain and hostname verification, so an attacker could impersonate
|
||||
the camera. It is not equivalent to trusting the camera certificate.
|
||||
|
||||
## Decide the certificate identity first
|
||||
|
||||
Choose the stable name used in every Agent URL before creating the certificate:
|
||||
|
||||
- For an IP URL, add that address as an IP SAN.
|
||||
- For a DNS URL, add the exact hostname as a DNS SAN.
|
||||
- Add both when clients legitimately use both forms.
|
||||
|
||||
A certificate stops matching if the camera IP changes. Use a static address,
|
||||
DHCP reservation, or stable DNS name.
|
||||
|
||||
## Configure RTSPS in the Bosch UI
|
||||
|
||||
1. Sign in to the camera as an administrator.
|
||||
2. Open **Configuration**.
|
||||
3. Open **Network > Network Services**.
|
||||
4. Enable **RTSPS**.
|
||||
5. Confirm port `9554`, or record the configured alternative.
|
||||
6. Click **Set**.
|
||||
|
||||
RTSP on port `554` and RTSPS on port `9554` are separate services. Enabling
|
||||
RTSPS does not make an `rtsp://` URL secure.
|
||||
|
||||
## Generate the private key and CSR on the camera
|
||||
|
||||
Keeping the TLS private key on the camera avoids exporting it to an operator
|
||||
workstation or deployment system.
|
||||
|
||||
1. Open **Service > Certificates**.
|
||||
2. Click **Add**.
|
||||
3. Select **Generate signing request**.
|
||||
4. Select `RSA 2048bit` or the stronger option supported by all clients.
|
||||
5. Enter a unique file name, such as `agent-rtsps`.
|
||||
6. Enter a descriptive Common Name and any required organization fields.
|
||||
7. Click **Generate**.
|
||||
8. Download the resulting CSR from the certificate table.
|
||||
|
||||
On the tested firmware, this form contains no SAN field. The downloaded CSR
|
||||
therefore has no IP SAN. The CA must add the SAN while signing.
|
||||
|
||||
Inspect the CSR before signing:
|
||||
|
||||
```bash
|
||||
openssl req -in camera.csr.pem -noout -verify -subject
|
||||
openssl req -in camera.csr.pem -noout -text
|
||||
```
|
||||
|
||||
The first command must report `Certificate request self-signature verify OK`.
|
||||
An absent `Subject Alternative Name` section is expected for this firmware.
|
||||
|
||||
## Prepare Smallstep
|
||||
|
||||
Use an existing organizational CA when one is available. Creating a new CA
|
||||
creates a new long-lived trust domain that must be distributed, protected,
|
||||
backed up, and eventually rotated.
|
||||
|
||||
### Install the CLI on Debian amd64
|
||||
|
||||
```bash
|
||||
curl -fsSL \
|
||||
https://dl.smallstep.com/cli/docs-ca-install/latest/step-cli_amd64.deb \
|
||||
-o /tmp/step-cli_amd64.deb
|
||||
sudo dpkg -i /tmp/step-cli_amd64.deb
|
||||
rm /tmp/step-cli_amd64.deb
|
||||
step version
|
||||
```
|
||||
|
||||
Use the official package matching the host architecture on other systems.
|
||||
|
||||
### Create a dedicated offline CA
|
||||
|
||||
Skip this section when using an existing CA.
|
||||
|
||||
```bash
|
||||
umask 077
|
||||
mkdir -p "$HOME/.step/secrets" "$HOME/.step/camera"
|
||||
|
||||
openssl rand -base64 48 > "$HOME/.step/secrets/camera_ca_password"
|
||||
chmod 600 "$HOME/.step/secrets/camera_ca_password"
|
||||
|
||||
step ca init \
|
||||
--pki \
|
||||
--name "UUG Camera CA" \
|
||||
--password-file "$HOME/.step/secrets/camera_ca_password"
|
||||
```
|
||||
|
||||
This produces:
|
||||
|
||||
```text
|
||||
$HOME/.step/certs/root_ca.crt
|
||||
$HOME/.step/certs/intermediate_ca.crt
|
||||
$HOME/.step/secrets/root_ca_key
|
||||
$HOME/.step/secrets/intermediate_ca_key
|
||||
$HOME/.step/secrets/camera_ca_password
|
||||
```
|
||||
|
||||
The files under `secrets/` are sensitive. Keep them mode `600`, never commit
|
||||
them, and back them up to encrypted persistent storage. A devcontainer can be
|
||||
rebuilt or deleted; it is not sufficient as the only CA backup.
|
||||
|
||||
## Add the SAN while signing
|
||||
|
||||
Copy the camera CSR into a protected working directory:
|
||||
|
||||
```bash
|
||||
cp camera.csr.pem "$HOME/.step/camera/camera.csr.pem"
|
||||
```
|
||||
|
||||
Create `$HOME/.step/camera/bosch-rtsps.tpl`:
|
||||
|
||||
```json
|
||||
{
|
||||
"subject": {
|
||||
"commonName": {{ toJson .Insecure.CR.Subject.CommonName }}
|
||||
},
|
||||
"ipAddresses": ["10.0.30.11"],
|
||||
"keyUsage": ["keyEncipherment", "digitalSignature"],
|
||||
"extKeyUsage": ["serverAuth", "clientAuth"]
|
||||
}
|
||||
```
|
||||
|
||||
The template preserves the camera CSR public key, sets the IP identity, and
|
||||
creates a TLS leaf rather than a CA certificate.
|
||||
|
||||
Sign it with a validity period that ends before the intermediate CA expires.
|
||||
A one-year leaf is preferable to a ten-year leaf when automated renewal is
|
||||
available:
|
||||
|
||||
```bash
|
||||
step certificate sign \
|
||||
--template "$HOME/.step/camera/bosch-rtsps.tpl" \
|
||||
--bundle \
|
||||
--not-after 8760h \
|
||||
--password-file "$HOME/.step/secrets/camera_ca_password" \
|
||||
"$HOME/.step/camera/camera.csr.pem" \
|
||||
"$HOME/.step/certs/intermediate_ca.crt" \
|
||||
"$HOME/.step/secrets/intermediate_ca_key" \
|
||||
> "$HOME/.step/camera/bosch-rtsps-chain.pem"
|
||||
```
|
||||
|
||||
For an online `step-ca`, do not assume `step ca sign` accepts a `--san` flag. It
|
||||
does not. Authorize SANs in the one-time token or configure a provisioner
|
||||
template that produces the required SANs.
|
||||
|
||||
## Validate before upload
|
||||
|
||||
Inspect the leaf certificate, which is the first PEM block in the chain file:
|
||||
|
||||
```bash
|
||||
openssl x509 \
|
||||
-in "$HOME/.step/camera/bosch-rtsps-chain.pem" \
|
||||
-noout -subject -issuer -dates -ext subjectAltName -ext extendedKeyUsage
|
||||
```
|
||||
|
||||
Confirm the SAN separately because some OpenSSL versions display only the last
|
||||
requested extension:
|
||||
|
||||
```bash
|
||||
openssl x509 \
|
||||
-in "$HOME/.step/camera/bosch-rtsps-chain.pem" \
|
||||
-noout -ext subjectAltName
|
||||
```
|
||||
|
||||
Verify the path and IP identity:
|
||||
|
||||
```bash
|
||||
openssl verify \
|
||||
-CAfile "$HOME/.step/certs/root_ca.crt" \
|
||||
-untrusted "$HOME/.step/certs/intermediate_ca.crt" \
|
||||
-verify_ip 10.0.30.11 \
|
||||
"$HOME/.step/camera/bosch-rtsps-chain.pem"
|
||||
```
|
||||
|
||||
Confirm that the signed leaf uses the exact public key from the camera CSR:
|
||||
|
||||
```bash
|
||||
csr_key=$(
|
||||
openssl req -in "$HOME/.step/camera/camera.csr.pem" -pubkey -noout |
|
||||
openssl pkey -pubin -outform DER 2>/dev/null |
|
||||
sha256sum | cut -d' ' -f1
|
||||
)
|
||||
|
||||
cert_key=$(
|
||||
openssl x509 -in "$HOME/.step/camera/bosch-rtsps-chain.pem" -pubkey -noout |
|
||||
openssl pkey -pubin -outform DER 2>/dev/null |
|
||||
sha256sum | cut -d' ' -f1
|
||||
)
|
||||
|
||||
test "$csr_key" = "$cert_key"
|
||||
```
|
||||
|
||||
Do not upload a certificate when any of these checks fail.
|
||||
|
||||
## Upload and assign the certificate
|
||||
|
||||
1. Return to **Service > Certificates**.
|
||||
2. Click **Add > Upload certificate**.
|
||||
3. Select the leaf-plus-intermediate PEM chain.
|
||||
4. Click **Upload** and wait for `100%`.
|
||||
5. Confirm that the former CSR row is now a `Certificate`.
|
||||
6. Confirm that the key icon is present. It proves that the camera associated
|
||||
the certificate with its retained private key.
|
||||
7. Open the new certificate's **Usage** selector.
|
||||
8. Select only **HTTPS**.
|
||||
9. Leave **CBS client** assigned to the original Bosch `DeviceCertificate`.
|
||||
10. Click **Set** and wait for the table to reload.
|
||||
|
||||
On the tested firmware, there is no separate SRTSP usage. RTSPS presents the
|
||||
certificate assigned to HTTPS. Reassigning HTTPS therefore changes both the
|
||||
web interface and RTSPS certificate.
|
||||
|
||||
After saving, the expected split is:
|
||||
|
||||
| Certificate | Usage |
|
||||
| --- | --- |
|
||||
| Private-CA camera certificate | `HTTPS` |
|
||||
| Bosch `DeviceCertificate` | `CBS client` |
|
||||
|
||||
The browser may warn about the new HTTPS certificate until the private root CA
|
||||
is trusted by the workstation.
|
||||
|
||||
## Account for the Bosch chain behavior
|
||||
|
||||
The tested firmware served only the leaf certificate on ports `443` and `9554`,
|
||||
even when the uploaded file contained the leaf and intermediate. Uploading the
|
||||
intermediate separately as a trusted camera certificate did not change the
|
||||
served chain.
|
||||
|
||||
Confirm the behavior:
|
||||
|
||||
```bash
|
||||
openssl s_client \
|
||||
-connect 10.0.30.11:9554 \
|
||||
-showcerts </dev/null 2>/dev/null |
|
||||
grep -c '^-----BEGIN CERTIFICATE-----$'
|
||||
```
|
||||
|
||||
A result of `1` means the client must already have the issuing intermediate.
|
||||
Create a portable trust bundle containing the intermediate and root:
|
||||
|
||||
```bash
|
||||
step certificate bundle \
|
||||
"$HOME/.step/certs/intermediate_ca.crt" \
|
||||
"$HOME/.step/certs/root_ca.crt" \
|
||||
"$HOME/.step/camera/uug-camera-trust-bundle.pem"
|
||||
|
||||
chmod 644 "$HOME/.step/camera/uug-camera-trust-bundle.pem"
|
||||
```
|
||||
|
||||
The trust bundle is public material. The CA private keys and password are not.
|
||||
|
||||
## Configure Kerberos Agent
|
||||
|
||||
For a process running directly in the same environment:
|
||||
|
||||
```dotenv
|
||||
AGENT_CAPTURE_IPCAMERA_RTSP="rtsps://<user>:<password>@10.0.30.11:9554/?inst=1"
|
||||
AGENT_CAPTURE_IPCAMERA_SUB_RTSP="rtsps://<user>:<password>@10.0.30.11:9554/?inst=2"
|
||||
AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=false
|
||||
AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE=/home/agent/data/config/uug-camera-trust-bundle.pem
|
||||
```
|
||||
|
||||
For a container, mount the public bundle read-only at the exact path visible
|
||||
inside the container. The Agent image creates `/home/agent/data/config` and
|
||||
includes Debian's `ca-certificates` package:
|
||||
|
||||
```bash
|
||||
docker run \
|
||||
-v /secure/config/uug-camera-trust-bundle.pem:/home/agent/data/config/uug-camera-trust-bundle.pem:ro \
|
||||
-e AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE=/home/agent/data/config/uug-camera-trust-bundle.pem \
|
||||
-e AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=false \
|
||||
-e 'AGENT_CAPTURE_IPCAMERA_RTSP=rtsps://<user>:<password>@10.0.30.11:9554/?inst=1' \
|
||||
-e 'AGENT_CAPTURE_IPCAMERA_SUB_RTSP=rtsps://<user>:<password>@10.0.30.11:9554/?inst=2' \
|
||||
kerberos/agent:latest
|
||||
```
|
||||
|
||||
`AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE` starts with the operating system's roots
|
||||
and appends the camera bundle only to the gortsplib TLS configuration. Other
|
||||
clients, including MoQ, Hub, and Vault, retain the normal public CA chain.
|
||||
Restart the Agent after changing trust files.
|
||||
|
||||
Do not set `SSL_CERT_FILE` or `SSL_CERT_DIR` in production solely for camera
|
||||
trust. They are process-wide and can prevent other clients from validating
|
||||
public services. For a deliberate process-wide isolation test, mount an empty
|
||||
directory and set `SSL_CERT_DIR` to its path:
|
||||
|
||||
```bash
|
||||
-v /secure/config/empty-ca-dir:/home/agent/data/config/empty-ca-dir:ro \
|
||||
-e SSL_CERT_DIR=/home/agent/data/config/empty-ca-dir
|
||||
```
|
||||
|
||||
Do not use `SSL_CERT_DIR=`. Go treats an empty value as unset and scans its
|
||||
default certificate directories.
|
||||
|
||||
Only use that mode when the Agent does not need public roots for other TLS
|
||||
connections.
|
||||
|
||||
## Validate the live endpoints
|
||||
|
||||
### Strict TLS and identity check
|
||||
|
||||
Use only the specified bundle, without OpenSSL's default CA locations:
|
||||
|
||||
```bash
|
||||
openssl s_client \
|
||||
-brief \
|
||||
-connect 10.0.30.11:9554 \
|
||||
-verify_ip 10.0.30.11 \
|
||||
-verify_return_error \
|
||||
-CAfile "$HOME/.step/camera/uug-camera-trust-bundle.pem" \
|
||||
-no-CApath \
|
||||
-no-CAstore \
|
||||
</dev/null
|
||||
```
|
||||
|
||||
Repeat with port `443`. Both must report `Verification: OK`.
|
||||
|
||||
Confirm that identity checking is active by repeating the command with a wrong
|
||||
address, such as `-verify_ip 10.0.30.12`. It must fail with an IP address
|
||||
mismatch.
|
||||
|
||||
### Confirm the live leaf is the generated leaf
|
||||
|
||||
```bash
|
||||
live_fingerprint=$(
|
||||
openssl s_client -connect 10.0.30.11:9554 -showcerts </dev/null 2>/dev/null |
|
||||
openssl x509 -noout -fingerprint -sha256 |
|
||||
cut -d= -f2
|
||||
)
|
||||
|
||||
local_fingerprint=$(
|
||||
openssl x509 \
|
||||
-in "$HOME/.step/camera/bosch-rtsps-chain.pem" \
|
||||
-noout -fingerprint -sha256 |
|
||||
cut -d= -f2
|
||||
)
|
||||
|
||||
test "$live_fingerprint" = "$local_fingerprint"
|
||||
```
|
||||
|
||||
### Validate the media path
|
||||
|
||||
A successful TLS handshake does not prove that RTSP authentication, DESCRIBE,
|
||||
SETUP, PLAY, and RTP delivery work. Start a fresh Agent with verified TLS and
|
||||
confirm that it connects without an x509 error and receives frames. During the
|
||||
verified setup described here, a gortsplib probe completed all RTSP operations
|
||||
and received an RTP packet over TCP.
|
||||
|
||||
## Why a tampered bundle may still connect
|
||||
|
||||
Editing PEM text is not always a useful negative TLS test.
|
||||
|
||||
### A certificate can still parse after a byte change
|
||||
|
||||
Base64 can remain syntactically valid when one character changes. OpenSSL may
|
||||
still list the certificate subject and issuer even though a signature is now
|
||||
invalid. Parsing and signature verification are different operations.
|
||||
|
||||
### Trust anchors are not validated through a parent
|
||||
|
||||
Every certificate loaded into Go's root pool is a trust anchor, including a
|
||||
non-self-signed intermediate CA. Verification can terminate at that certificate.
|
||||
|
||||
If tampering changes only the intermediate's signature from its parent root,
|
||||
but does not change its public key, that intermediate can still validate the
|
||||
camera leaf when it is trusted directly. Its now-invalid parent signature is
|
||||
not consulted at the trust boundary.
|
||||
|
||||
This is equivalent to OpenSSL's partial-chain behavior:
|
||||
|
||||
```bash
|
||||
openssl s_client \
|
||||
-connect 10.0.30.11:9554 \
|
||||
-verify_ip 10.0.30.11 \
|
||||
-verify_return_error \
|
||||
-partial_chain \
|
||||
-CAfile tampered-bundle.pem \
|
||||
-no-CApath \
|
||||
-no-CAstore \
|
||||
</dev/null
|
||||
```
|
||||
|
||||
### `SSL_CERT_FILE` does not isolate Go from CA directories
|
||||
|
||||
On Unix, Go uses `SSL_CERT_FILE` instead of its default aggregate CA file, but it
|
||||
still scans default certificate directories such as `/etc/ssl/certs`. Setting
|
||||
`SSL_CERT_FILE` alone therefore does not remove CA certificates installed with
|
||||
`update-ca-certificates`. `AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE` is appended
|
||||
after this system pool is loaded; it does not replace the system roots.
|
||||
|
||||
Blank values do not select empty trust sources. Both `SSL_CERT_FILE=` and
|
||||
`SSL_CERT_DIR=` are treated as unset, so Go falls back to its default aggregate
|
||||
CA file and certificate directories. To test with no trusted certificates on
|
||||
Linux, use a non-empty file path that contains no certificates and a non-empty
|
||||
directory path that contains no certificates:
|
||||
|
||||
```bash
|
||||
mkdir -p /tmp/empty-ca-dir
|
||||
SSL_CERT_FILE=/dev/null \
|
||||
SSL_CERT_DIR=/tmp/empty-ca-dir \
|
||||
AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE= \
|
||||
AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=false \
|
||||
GOWORK=off \
|
||||
go run -tags moq . -action run -port 8080
|
||||
```
|
||||
|
||||
That fresh process must fail with `x509: certificate signed by unknown
|
||||
authority`.
|
||||
|
||||
Use exactly one camera trust-distribution approach when possible:
|
||||
|
||||
1. Mount a private trust bundle and set
|
||||
`AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE`; or
|
||||
2. Install the CA certificates into the operating-system trust store.
|
||||
|
||||
Using both is valid, but makes isolation tests less obvious.
|
||||
|
||||
### Running processes can retain old roots
|
||||
|
||||
A long-running Go process may already have loaded and cached the trust pool.
|
||||
Always start a new process after changing trust configuration during a negative
|
||||
test.
|
||||
|
||||
## Perform a meaningful negative test
|
||||
|
||||
Do not corrupt only the root or intermediate signature. Instead, give a fresh
|
||||
Agent process a completely unrelated CA and hide the default CA directories.
|
||||
|
||||
```bash
|
||||
mkdir -p /tmp/empty-ca-dir
|
||||
|
||||
openssl req \
|
||||
-x509 -newkey rsa:2048 -nodes -days 1 \
|
||||
-subj '/CN=Unrelated Test Root' \
|
||||
-keyout /tmp/unrelated-test-root.key \
|
||||
-out /tmp/unrelated-test-root.crt
|
||||
|
||||
SSL_CERT_FILE=/dev/null \
|
||||
SSL_CERT_DIR=/tmp/empty-ca-dir \
|
||||
AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE=/tmp/unrelated-test-root.crt \
|
||||
AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=false \
|
||||
GOWORK=off \
|
||||
go run -tags moq . -action run -port 8080
|
||||
```
|
||||
|
||||
The connection must fail with an unknown-authority or chain-building error.
|
||||
Delete the temporary test key and certificate afterward.
|
||||
|
||||
To test bundle integrity rather than client distrust, validate the intermediate
|
||||
against the root explicitly:
|
||||
|
||||
```bash
|
||||
openssl verify \
|
||||
-CAfile "$HOME/.step/certs/root_ca.crt" \
|
||||
-no-CApath \
|
||||
-no-CAstore \
|
||||
"$HOME/.step/certs/intermediate_ca.crt"
|
||||
```
|
||||
|
||||
Store and compare approved SHA-256 fingerprints when detecting unauthorized
|
||||
certificate-file changes is a requirement.
|
||||
|
||||
Restore an accidentally edited bundle from the protected CA certificates, then
|
||||
restart the Agent:
|
||||
|
||||
```bash
|
||||
step certificate bundle -f \
|
||||
"$HOME/.step/certs/intermediate_ca.crt" \
|
||||
"$HOME/.step/certs/root_ca.crt" \
|
||||
"$HOME/.step/camera/uug-camera-trust-bundle.pem"
|
||||
|
||||
openssl verify \
|
||||
-CAfile "$HOME/.step/certs/root_ca.crt" \
|
||||
-no-CApath \
|
||||
-no-CAstore \
|
||||
"$HOME/.step/certs/intermediate_ca.crt"
|
||||
```
|
||||
|
||||
## Optional system trust installation
|
||||
|
||||
On Debian, install both public CA certificates when every process in the system
|
||||
should trust this camera PKI:
|
||||
|
||||
```bash
|
||||
sudo install -m 0644 \
|
||||
"$HOME/.step/certs/root_ca.crt" \
|
||||
/usr/local/share/ca-certificates/uug-camera-ca.crt
|
||||
|
||||
sudo install -m 0644 \
|
||||
"$HOME/.step/certs/intermediate_ca.crt" \
|
||||
/usr/local/share/ca-certificates/uug-camera-intermediate-ca.crt
|
||||
|
||||
sudo update-ca-certificates
|
||||
```
|
||||
|
||||
This creates links below `/etc/ssl/certs`. Remove those files and rerun
|
||||
`update-ca-certificates` before attempting an isolated trust-bundle test.
|
||||
|
||||
## Renewal and recovery
|
||||
|
||||
- Renew before the leaf or intermediate expires.
|
||||
- Generate a new camera CSR if the firmware cannot renew the existing key.
|
||||
- Sign the new CSR with all required SANs.
|
||||
- Upload and validate the new certificate before deleting the old one.
|
||||
- Preserve an alternate administrative access path while changing HTTPS usage.
|
||||
- Back up the CA certificates, encrypted CA keys, and password separately.
|
||||
- If the CA private keys are lost, create a new CA and redistribute its trust
|
||||
before replacing camera certificates.
|
||||
|
||||
## Production checklist
|
||||
|
||||
- [ ] The Agent URL uses `rtsps://`, not `rtsp://` or `srtsp://`.
|
||||
- [ ] RTSPS is enabled on the camera and the configured port is reachable.
|
||||
- [ ] The certificate SAN exactly matches the Agent URL host.
|
||||
- [ ] The leaf public key matches the camera-generated CSR.
|
||||
- [ ] The certificate has `serverAuth` extended key usage.
|
||||
- [ ] The certificate expires before its issuer.
|
||||
- [ ] HTTPS is assigned to the private-CA certificate.
|
||||
- [ ] CBS client remains assigned to the Bosch device certificate.
|
||||
- [ ] The Agent has the intermediate and root CA certificates it needs.
|
||||
- [ ] `AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=false`.
|
||||
- [ ] The Agent was restarted after trust changes.
|
||||
- [ ] A strict TLS check reports `Verification: OK`.
|
||||
- [ ] A real Agent connection receives RTP packets.
|
||||
- [ ] CA private keys and passwords are backed up outside the devcontainer.
|
||||
621
README.md
@@ -2,10 +2,7 @@
|
||||
|
||||
<a target="_blank" href="https://kerberos.io"><img src="https://img.shields.io/badge/kerberos-website-gray.svg?longCache=true&colorB=brightgreen" alt="Kerberos Agent"></a>
|
||||
<a target="_blank" href="https://doc.kerberos.io"><img src="https://img.shields.io/badge/kerberos-documentation-gray.svg?longCache=true&colorB=brightgreen" alt="Kerberos Agent"></a>
|
||||
<a target="_blank" href="https://twitter.com/kerberosio?ref_src=twsrc%5Etfw"><img src="https://img.shields.io/twitter/url.svg?label=Follow%20%40kerberosio&style=social&url=https%3A%2F%2Ftwitter.com%2Fkerberosio" alt="Twitter Widget"></a>
|
||||
<a target="_blank" href="https://join.slack.com/t/kerberosio/shared_invite/zt-1a5oj4pwm-O4qCAN9c5r2um0Ns0ge8ww"><img src="https://img.shields.io/badge/slack-@kerberosio-yellow.svg?logo=slack " alt="Kerberos.io"></a>
|
||||
|
||||
<a target="_blank" href="https://circleci.com/gh/kerberos-io/agent"><img src="https://circleci.com/gh/kerberos-io/agent.svg?style=svg"/></a>
|
||||
<img src="https://github.com/kerberos-io/agent/workflows/Go/badge.svg"/>
|
||||
<img src="https://github.com/kerberos-io/agent/workflows/React/badge.svg"/>
|
||||
<img src="https://github.com/kerberos-io/agent/workflows/CodeQL/badge.svg"/>
|
||||
@@ -17,100 +14,495 @@
|
||||
<a target="_blank" href="https://www.figma.com/proto/msuYC6sv2cOCqZeDtBxNy7/%5BNEW%5D-Kerberos.io-Apps?node-id=1%3A1788&viewport=-490%2C191%2C0.34553584456443787&scaling=min-zoom&page-id=1%3A2%3Ffuid%3D449684443467913607" alt="Kerberos Agent"></a>
|
||||
|
||||
<a href="LICENSE"><img src="https://img.shields.io/badge/License-MIT-yellow.svg" alt="License: MIT"></a>
|
||||
[](
|
||||
https://brianmacdonald.github.io/Ethonate/address#0xf4a759C9436E2280Ea9cdd23d3144D95538fF4bE)
|
||||
[](https://brianmacdonald.github.io/Ethonate/address#0xf4a759C9436E2280Ea9cdd23d3144D95538fF4bE)
|
||||
<a target="_blank" href="https://twitter.com/kerberosio?ref_src=twsrc%5Etfw"><img src="https://img.shields.io/twitter/url.svg?label=Follow%20%40kerberosio&style=social&url=https%3A%2F%2Ftwitter.com%2Fkerberosio" alt="Twitter Widget"></a>
|
||||
[](https://snapcraft.io/kerberosio)
|
||||
|
||||
[**Docker Hub**](https://hub.docker.com/r/kerberos/agent) | [**Documentation**](https://doc.kerberos.io) | [**Website**](https://kerberos.io)
|
||||
[](https://joinslack.kerberos.io/)
|
||||
|
||||
Kerberos Agent is a cutting edge video surveillance management system made available as Open Source under the MIT License. This means that all the source code is available for you or your company, and you can use, transform and distribute the source code; as long you keep a reference of the original license. Kerberos Agent can be used for commercial usage (which was not the case for v2). Read more [about the license here](LICENSE).
|
||||
[**Docker Hub**](https://hub.docker.com/r/kerberos/agent) | [**Documentation**](https://doc.kerberos.io) | [**Website**](https://kerberos.io) | [**View Demo**](https://demo.kerberos.io)
|
||||
|
||||
> Before you continue, this repository discusses one of the components of the Kerberos.io stack, the Kerberos Agent, in depth. If you are [looking for an end-to-end deployment guide have a look here](https://github.com/kerberos-io/deployment).
|
||||
|
||||
Kerberos Agent is an isolated and scalable video (surveillance) management agent made available as Open Source under the MIT License. This means that all the source code is available for you or your company, and you can use, transform and distribute the source code; as long you keep a reference of the original license. Kerberos Agent can be used for commercial usage (which was not the case for v2). Read more [about the license here](LICENSE).
|
||||
|
||||

|
||||
|
||||
## :thinking: Prerequisites
|
||||
|
||||
- An IP camera which supports a RTSP H264 or H265 encoded stream,
|
||||
- (or) a USB camera, Raspberry Pi camera or other camera, that [you can transform to a valid RTSP H264 or H265 stream](https://github.com/kerberos-io/camera-to-rtsp).
|
||||
- Any hardware (ARMv6, ARMv7, ARM64, AMD64) that can run a binary or container, for example: a Raspberry Pi, NVidia Jetson, Intel NUC, a VM, Bare metal machine or a full blown Kubernetes cluster.
|
||||
|
||||
## :video_camera: Is my camera working?
|
||||
|
||||
There are a myriad of cameras out there (USB, IP and other cameras), and it might be daunting to know if Kerberos Agent will work for your camera. [Therefore we are listing all the camera models that are acknowlegded by the community](https://github.com/kerberos-io/agent/issues/59). Feel free to add your camera to the list as well!
|
||||
|
||||
## :books: Overview
|
||||
|
||||
### Up and running in no time
|
||||
|
||||
1. [Quickstart - Docker](#quickstart---docker)
|
||||
2. [Quickstart - Balena](#quickstart---balena)
|
||||
3. [Quickstart - Snap](#quickstart---snap)
|
||||
|
||||
### Introduction
|
||||
|
||||
1. [A world of Kerberos Agents](#a-world-of-kerberos-agents)
|
||||
|
||||
### Running and automation
|
||||
|
||||
1. [How to run and deploy a Kerberos Agent](#how-to-run-and-deploy-a-kerberos-agent)
|
||||
2. [Access the Kerberos Agent](#access-the-kerberos-agent)
|
||||
3. [Configure and persist with volume mounts](#configure-and-persist-with-volume-mounts)
|
||||
4. [Configure with environment variables](#configure-with-environment-variables)
|
||||
|
||||
### Insights
|
||||
|
||||
1. [Encryption](#encryption)
|
||||
2. [H264 vs H265](#h264-vs-h265)
|
||||
|
||||
### Contributing
|
||||
|
||||
1. [Security vulnerability reporting](#security-vulnerability-reporting)
|
||||
1. [Contribute with Codespaces](#contribute-with-codespaces)
|
||||
2. [Develop and build](#develop-and-build)
|
||||
3. [Building from source](#building-from-source)
|
||||
4. [Building for Docker](#building-for-docker)
|
||||
|
||||
### Varia
|
||||
|
||||
1. [Support our project](#support-our-project)
|
||||
1. [What is new?](#what-is-new)
|
||||
1. [Contributors](#contributors)
|
||||
|
||||
## Quickstart - Docker
|
||||
|
||||
The easiest to get your Kerberos Agent up and running is to use our Docker image on [Docker hub](https://hub.docker.com/r/kerberos/agent). Once you selected a specific tag, run below command, which will open the web interface of your Kerberos agent on port `8080`. For persisting your configuration and/or recordings [attach a volume](#attach-a-volume).
|
||||
|
||||
docker run -p 8080:8080 --name mycamera -d kerberos/agent:latest
|
||||
The easiest way to get your Kerberos Agent up and running is to use our public image on [Docker hub](https://hub.docker.com/r/kerberos/agent). Once you have selected a specific tag, run `docker` command below, which will open the web interface of your Kerberos agent on port `80`, and off you go. For a more configurable and persistent deployment have a look at [Running and automating a Kerberos Agent](#running-and-automating-a-kerberos-agent).
|
||||
|
||||
docker run -p 80:80 --name mycamera -d --restart=always kerberos/agent:latest
|
||||
|
||||
If you want to connect to a USB or Raspberry Pi camera, [you'll need to run our side car container](https://github.com/kerberos-io/camera-to-rtsp) which proxies the camera to an RTSP stream. In that case you'll want to configure the Kerberos Agent container to run in the host network, so it can connect directly to the RTSP sidecar.
|
||||
|
||||
docker run --network=host --name mycamera -d --restart=always kerberos/agent:latest
|
||||
|
||||
## Quickstart - Balena
|
||||
|
||||
To be written
|
||||
|
||||
Run Kerberos Agent with [Balena Cloud](https://www.balena.io/) super powers. Monitor your Kerberos Agent with seamless remote access, over the air updates, an encrypted public `https` endpoint and much more. Checkout our application `video-surveillance` on [Balena Hub](https://hub.balena.io/apps/2064752/video-surveillance), and create your first or fleet of Kerberos Agent(s).
|
||||
|
||||
[](https://dashboard.balena-cloud.com/deploy?repoUrl=https://github.com/kerberos-io/balena-agent)
|
||||
|
||||
## Quickstart - Snap
|
||||
|
||||
To be written
|
||||
Run Kerberos Agent with our [Snapcraft package](https://snapcraft.io/kerberosio).
|
||||
|
||||
## Introduction
|
||||
snap install kerberosio
|
||||
|
||||
Kerberos.io is a cutting edge video surveillance system with a strong focus on user experience, scalability, resilience, extension and integration. Kerberos.io provides different solutions, but from a high level point of view it comes into two flavours: Kerberos Agent and Kerberos Enterprise Suite. Bottom line Kerberos Enterprise Suite extends Kerberos Agent with additional components such as Kerberos Factory, Kerberos Vault and Kerberos Hub.
|
||||
Once installed you can find your Kerberos Agent configration at `/var/snap/kerberosio/common`. Run the Kerberos Agent as following
|
||||
|
||||
### Kerberos Agent
|
||||
sudo kerberosio.agent -action=run -port=80
|
||||
|
||||
- Installation in seconds (Docker, Balena, Snap, etc).
|
||||
## A world of Kerberos Agents
|
||||
|
||||
The Kerberos Agent is an isolated and scalable video (surveillance) management agent with a strong focus on user experience, scalability, resilience, extension and integration. Next to the Kerberos Agent, Kerberos.io provides many other tools such as [Kerberos Factory](https://github.com/kerberos-io/factory), [Kerberos Vault](https://github.com/kerberos-io/vault), and [Kerberos Hub](https://github.com/kerberos-io/hub) to provide additional capabilities: bring your own cloud, bring your own storage, central overview, live streaming, machine learning, etc.
|
||||
|
||||
[](https://github.com/kerberos-io/deployment)
|
||||
|
||||
As mentioned above Kerberos.io applies the concept of agents. An agent is running next to (or on) your camera, and is processing a single camera feed. It applies motion based or continuous recording and makes those recordings available through a user friendly web interface. A Kerberos Agent allows you to connect to other cloud services or integrate with custom applications. Kerberos Agent is used for personal applications and scales to enterprise production level deployments. Learn more about the [deployment strategies here](<(https://github.com/kerberos-io/deployment)>).
|
||||
|
||||
This repository contains everything you'll need to know about our core product, Kerberos Agent. Below you'll find a brief list of features and functions.
|
||||
|
||||
- Low memory and CPU usage.
|
||||
- Simplified and modern user interface.
|
||||
- Multi architecture (ARMv7, ARMv8, amd64, etc).
|
||||
- Multi camera support: IP Cameras (MJPEG/H264), USB cameras and Raspberry Pi Cameras through a RTSP proxy.
|
||||
- Single camera per instance (e.g. One Docker container per camera).
|
||||
- Integrations (Webhooks, MQTT, Script, etc).
|
||||
- Cloud storage (Kerberos Hub, Kerberos Vault, Minio, Storj, etc).
|
||||
- Multi architecture (ARMv6, ARMv7, ARM64, AMD64)
|
||||
- Multi stream, for example recording in H265, live streaming and motion detection in H264.
|
||||
- Multi camera support: IP Cameras (H264 and H265), USB cameras and Raspberry Pi Cameras [through a RTSP proxy](https://github.com/kerberos-io/camera-to-rtsp).
|
||||
- Single camera per instance (e.g. one container per camera).
|
||||
- Low resolution streaming through MQTT and high resolution streaming through WebRTC (only supports H264/PCM).
|
||||
- Backchannel audio from Kerberos Hub to IP camera (requires PCM ULAW codec)
|
||||
- Audio (AAC) and video (H264/H265) recording in MP4 container.
|
||||
- End-to-end encryption through MQTT using RSA and AES (livestreaming, ONVIF, remote configuration, etc)
|
||||
- Conditional recording: offline mode, motion region, time table, continuous recording, webhook condition etc.
|
||||
- Post- and pre-recording for motion detection.
|
||||
- Encryption at rest using AES-256-CBC.
|
||||
- Ability to create fragmented recordings, and streaming through HLS fMP4.
|
||||
- [Deploy where you want](#how-to-run-and-deploy-a-kerberos-agent) with the tools you use: `docker`, `docker compose`, `ansible`, `terraform`, `kubernetes`, etc.
|
||||
- Cloud storage/persistance: Kerberos Hub, Kerberos Vault and Dropbox. [(WIP: Minio, Storj, Google Drive, FTP etc.)](https://github.com/kerberos-io/agent/issues/95)
|
||||
- Outputs: trigger an integration (Webhooks, MQTT, Script, etc) when a specific event (motion detection or start recording ) occurs
|
||||
- REST API access and documentation through Swagger (trigger recording, update configuration, etc).
|
||||
- MIT License
|
||||
|
||||
### Kerberos Factory (part of [Kerberos Enterprise suite](https://doc.kerberos.io/enterprise/first-things-first/))
|
||||
## How to run and deploy a Kerberos Agent
|
||||
|
||||
- Installation on top of Kubernetes (K8S).
|
||||
- Camera support for IP camera only (RTSP/H264).
|
||||
- Massive horizontal scaling, thanks to Kubernetes.
|
||||
- Management of multiple Kerberos Agents through a single pane of glass.
|
||||
- Low memory and CPU intensive.
|
||||
- Modular and extensible design for building own extensions and integrations (e.g. a video analytics platform).
|
||||
- Commercial licensed and closed source.
|
||||
A Kerberos Agent, as previously mentioned, is a container. You can deploy it using various methods and automation tools, including `docker`, `docker compose`, `kubernetes` and more. To streamline your Kerberos.io experience, we provide concrete deployment examples to speed up your Kerberos.io journey”
|
||||
|
||||
## How it works: A world of Agents 🕵🏼♂️
|
||||
We have documented the different deployment models [in the `deployments` directory](https://github.com/kerberos-io/agent/tree/master/deployments) of this repository. There you'll learn and find how to deploy using:
|
||||
|
||||
Kerberos.io applies the concept of agents. An agent is running next to or on your camera, and is processing a single camera feed. It applies motion based recording and make those recordings available through a user friendly web interface. Kerberos Agent allows you to connect to other cloud services or custom applications. Kerberos Agent is perfect for personal usage and/or is a great tool if you only have a couple of surveillance cameras to be processed.
|
||||
- [Static binary](https://github.com/kerberos-io/agent/tree/master/deployments#0-static-binary)
|
||||
- [Docker](https://github.com/kerberos-io/agent/tree/master/deployments#1-docker)
|
||||
- [Docker Compose](https://github.com/kerberos-io/agent/tree/master/deployments#2-docker-compose)
|
||||
- [Kubernetes](https://github.com/kerberos-io/agent/tree/master/deployments#3-kubernetes)
|
||||
- [Red Hat OpenShift with Ansible](https://github.com/kerberos-io/agent/tree/master/deployments#4-red-hat-ansible-and-openshift)
|
||||
- [Terraform](https://github.com/kerberos-io/agent/tree/master/deployments#5-terraform)
|
||||
- [Salt](https://github.com/kerberos-io/agent/tree/master/deployments#6-salt)
|
||||
- [Balena](https://github.com/kerberos-io/agent/tree/master/deployments#8-balena)
|
||||
- [Snap](https://github.com/kerberos-io/agent/tree/master/deployments#9-snap)
|
||||
|
||||
If you are looking for a solution that scales better with your video surveillance and/or video analytics requirements, [Kerberos Enterprise Suite might be a better fit](https://doc.kerberos.io/enterprise/first-things-first).
|
||||
By default, your Kerberos Agents store all configuration and recordings within the container. To help you automate and have a more consistent data governance, you can attach volumes to configure and persist data of your Kerberos Agents and/or configure each Kerberos Agent through environment variables.
|
||||
|
||||
## Running as a container
|
||||
## Access the Kerberos Agent
|
||||
|
||||
We are creating Docker images as part of our CI/CD process. You'll find our Docker images on [Docker hub](https://hub.docker.com/r/kerberos/agent). Pick a specific tag of choice, or use latest. Once done run below command, this will open the web interface of your Kerberos agent on port 8080.
|
||||
|
||||
docker run -p 8080:8080 --name mycamera -d kerberos/agent:latest
|
||||
Once you have deployed the Kerberos Agent, using one of the deployment models described above, you will be able to access the Kerberos Agent user interface. A login page is presented asking for some credentials.
|
||||
|
||||
Or for a develop build:
|
||||
The default username and password for the Kerberos Agent is:
|
||||
|
||||
docker run -p 8080:8080 --name mycamera -d kerberos/agent-dev:latest
|
||||
- Username: `root`
|
||||
- Password: `root`
|
||||
|
||||
Feel free to use another port if your host system already has a workload running on `8080`. For example `8082`.
|
||||
**_Please note that you change the username and password for a final installation, see [Configure with environment variables](#configure-with-environment-variables) below._**
|
||||
|
||||
docker run -p 8082:8080 --name mycamera -d kerberos/agent:latest
|
||||
## Configure and persist with volume mounts
|
||||
|
||||
## Attach a volume
|
||||
An example of how to mount a host directory is shown below using `docker`, but is applicable for [all of the deployment models and tools described above](#running-and-automating-a-kerberos-agent).
|
||||
|
||||
By default your Kerberos agent will store all its configuration and recordings inside the container. It might be interesting to store both configuration and your recordings outside the container, on your local disk. This helps persisting your storage even after you decide to wipe out your Kerberos agent.
|
||||
You attach a volume to your container by leveraging the `-v` option. To mount your own configuration file and recordings folder, run the following commands:
|
||||
|
||||
You attach a volume to your container by leveraging the `-v` option. To mount your own configuration file, execute as following:
|
||||
docker run -p 80:80 --name mycamera \
|
||||
-v $(pwd)/agent/config:/home/agent/data/config \
|
||||
-v $(pwd)/agent/recordings:/home/agent/data/recordings \
|
||||
-d --restart=always kerberos/agent:latest
|
||||
|
||||
1. Decide where you would like to store your configuration and recordings; create a new directory for the config file and recordings folder accordingly.
|
||||
More examples for each deployment and automation tool [can be found in the deployment section](https://github.com/kerberos-io/agent/tree/master/deployments). Be sure to verify the permissions of the directory/volume you are attaching. More information in [this issue](https://github.com/kerberos-io/agent/issues/80).
|
||||
|
||||
mkdir agent
|
||||
mkdir agent/config
|
||||
mkdir agent/recordings
|
||||
chmod -R 755 kerberos-agent/
|
||||
chown 100:101 kerberos-agent/ -R
|
||||
|
||||
2. Once you have located your desired directory, copy the latest [`config.json`](https://github.com/kerberos-io/agent/blob/master/machinery/data/config/config.json) file into your config directory.
|
||||
## Configure with environment variables
|
||||
|
||||
wget https://raw.githubusercontent.com/kerberos-io/agent/master/machinery/data/config/config.json -O agent/config/config.json
|
||||
Next to attaching the configuration file, it is also possible to override the configuration with environment variables. This makes deploying with `docker compose` or `kubernetes` much easier and more scalable. Using this approach, we simplify automation through `ansible` and `terraform`.
|
||||
|
||||
3. Run the docker command as following to attach your config directory and recording directory.
|
||||
docker run -p 80:80 --name mycamera \
|
||||
-e AGENT_NAME=mycamera \
|
||||
-e AGENT_TIMEZONE=Europe/Brussels \
|
||||
-e AGENT_CAPTURE_IPCAMERA_RTSP=rtsp://fake.kerberos.io/stream \
|
||||
-e AGENT_CAPTURE_CONTINUOUS=true \
|
||||
-d --restart=always kerberos/agent:latest
|
||||
|
||||
Set `AGENT_PORT` to change the Agent's internal HTTP port. The environment
|
||||
variable takes precedence over `-port`. When using Docker, publish the same
|
||||
container port:
|
||||
|
||||
```bash
|
||||
docker run -p 8082:8082 \
|
||||
-e AGENT_PORT=8082 \
|
||||
--name mycamera \
|
||||
-d --restart=always kerberos/agent:latest
|
||||
```
|
||||
|
||||
### Health checks and API responses
|
||||
|
||||
`GET /health` is an unauthenticated liveness and diagnostics endpoint for
|
||||
container orchestrators and external monitors. `healthy` means that the Agent
|
||||
HTTP process can serve requests. Camera streams and Hub connectivity are
|
||||
reported independently in the response, so an external camera or Hub outage
|
||||
does not make Docker restart an otherwise functioning Agent process. Successful
|
||||
probes return `200 OK` and are logged at debug level to avoid periodic health
|
||||
checks filling production logs.
|
||||
|
||||
```bash
|
||||
curl http://localhost:8082/health
|
||||
```
|
||||
|
||||
```json
|
||||
{
|
||||
"httpStatusCode": 200,
|
||||
"applicationStatusCode": "get_success",
|
||||
"entityStatusCode": "healthy",
|
||||
"message": "Healthy",
|
||||
"metadata": {
|
||||
"applicationName": "agent",
|
||||
"applicationVersion": "0.0.0",
|
||||
"timestamp": 1788710400,
|
||||
"path": "/health"
|
||||
},
|
||||
"data": {
|
||||
"health": {
|
||||
"description": "Agent HTTP service is healthy",
|
||||
"cameraConnected": true,
|
||||
"mainStream": {
|
||||
"configured": true,
|
||||
"connected": true,
|
||||
"packagesProcessed": 183421,
|
||||
"fps": 29.97,
|
||||
"resolution": {
|
||||
"width": 1920,
|
||||
"height": 1080
|
||||
},
|
||||
"lastPacketAt": 1788710399
|
||||
},
|
||||
"subStream": {
|
||||
"configured": true,
|
||||
"connected": true,
|
||||
"packagesProcessed": 91710,
|
||||
"fps": 15,
|
||||
"resolution": {
|
||||
"width": 640,
|
||||
"height": 360
|
||||
},
|
||||
"lastPacketAt": 1788710399
|
||||
},
|
||||
"hub": {
|
||||
"configured": true,
|
||||
"connected": true,
|
||||
"lastHeartbeatAttemptAt": 1788710398,
|
||||
"lastSuccessfulHeartbeatAt": 1788710398
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
Stream `packagesProcessed` counts complete encoded video access units processed
|
||||
since the Agent process started; it does not count individual fragmented RTP
|
||||
packets. `fps` is the latest PTS-derived frame-rate estimate. Resolution is the
|
||||
most recently observed encoded width and height. `lastPacketAt`, Hub heartbeat
|
||||
timestamps, and response metadata timestamps are Unix seconds; `0` means that
|
||||
no value has been observed yet. A stream can be configured but temporarily
|
||||
disconnected.
|
||||
|
||||
Hub `configured` means heartbeat delivery is enabled and has the required URI
|
||||
and key. Hub `connected` means the most recent heartbeat succeeded and the last
|
||||
success is no more than three minutes old. A failed heartbeat marks it
|
||||
disconnected immediately while retaining the last-success timestamp for
|
||||
diagnosis.
|
||||
|
||||
New JSON endpoints should use this Hub-compatible response envelope rather than
|
||||
adding unrelated top-level response shapes. HTTP status describes the transport
|
||||
result, `applicationStatusCode` describes the operation, `entityStatusCode` and
|
||||
`message` describe the domain outcome, `metadata` carries request/application
|
||||
context, and endpoint-specific content belongs in a typed `data` object. Client
|
||||
responses must contain safe messages only; detailed internal errors belong in
|
||||
structured logs. Existing endpoints retain their legacy response shapes until
|
||||
they are migrated deliberately.
|
||||
|
||||
### Secure camera streams (RTSPS)
|
||||
|
||||
The Agent accepts `rtsps://` camera URLs. Do not use `srtsp://`; RTSPS is RTSP over TLS. For a Bosch FLEXIDOME micro 3100i, enable **Secure RTSP** under **Network > Network Services** and use port `9554`:
|
||||
|
||||
```bash
|
||||
AGENT_CAPTURE_IPCAMERA_RTSP='rtsps://username:password@camera.example:9554/?inst=1'
|
||||
AGENT_CAPTURE_IPCAMERA_SUB_RTSP='rtsps://username:password@camera.example:9554/?inst=2'
|
||||
```
|
||||
|
||||
Certificate verification is enabled by default. The URL hostname or IP address must match the camera certificate SAN. On this Bosch firmware, RTSPS presents the certificate assigned to **HTTPS**; there is no separate SRTSP certificate usage. Leave **CBS client** assigned to the Bosch device certificate.
|
||||
|
||||
For a private CA, mount a PEM trust bundle containing every CA certificate needed to build the camera certificate chain and set `AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE` to its path inside the Agent. The bundle is appended to the system roots for camera RTSPS connections only. This Bosch firmware presents only its leaf certificate, so include both the issuing intermediate and root certificates in the bundle. As a temporary fallback, `AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE=true` disables certificate verification for camera streams only.
|
||||
|
||||
See [RTSPS and TLS certificates](README-RTSPS-TLS.md) for the complete Bosch UI, private-CA, deployment, validation, and troubleshooting procedure.
|
||||
|
||||
| Name | Description | Default Value |
|
||||
| --------------------------------------- | ----------------------------------------------------------------------------------------------- | ------------------------------ |
|
||||
| `LOG_LEVEL` | Level for logging, could be "info", "warning", "debug", "error" or "fatal". | "info" |
|
||||
| `LOG_OUTPUT` | Logging output format "json" or "text". | "text" |
|
||||
| `AGENT_PORT` | HTTP web server port. Overrides the `-port` command-line value and must be between 1 and 65535. | "80" |
|
||||
| `AGENT_MODE` | You can choose to run this in 'release' for production, and or 'demo' for showcasing. | "release" |
|
||||
| `AGENT_TLS_INSECURE` | Specify if you want to use `InsecureSkipVerify` for the internal HTTP client. | "false" |
|
||||
| `AGENT_USERNAME` | The username used to authenticate against the Kerberos Agent login page. | "root" |
|
||||
| `AGENT_PASSWORD` | The password used to authenticate against the Kerberos Agent login page. | "root" |
|
||||
| `AGENT_KEY` | A unique identifier for your Kerberos Agent, this is auto-generated but can be overriden. | "" |
|
||||
| `AGENT_NAME` | The agent friendly-name. | "agent" |
|
||||
| `AGENT_TIMEZONE` | Timezone which is used for converting time. | "Africa/Ceuta" |
|
||||
| `AGENT_REMOVE_AFTER_UPLOAD` | When enabled, recordings uploaded successfully to a storage will be removed from disk. | "true" |
|
||||
| `AGENT_OFFLINE` | Makes sure no external connection is made. | "false" |
|
||||
| `AGENT_AUTO_CLEAN` | Cleans up the recordings directory. | "true" |
|
||||
| `AGENT_AUTO_CLEAN_MAX_SIZE` | If `AUTO_CLEAN` enabled, cap the recordings directory at this size (in MB). When unset/0, recordings may use the whole disk instead (see `AGENT_AUTO_CLEAN_MIN_FREE_SPACE`). | "100" |
|
||||
| `AGENT_AUTO_CLEAN_MIN_FREE_SPACE` | When `AUTO_CLEAN` is enabled and no `MAX_SIZE` is set, keep at least this much free space (in MB) on the recordings disk before deleting the oldest (already-uploaded first) recordings. Defaults to 5% of the disk. | "" |
|
||||
| `AGENT_TIME` | Enable the timetable for Kerberos Agent | "false" |
|
||||
| `AGENT_TIMETABLE` | A (weekly) time table to specify when to make recordings "start1,end1,start2,end2;start1.. | "" |
|
||||
| `AGENT_REGION_POLYGON` | A single polygon set for motion detection: "x1,y1;x2,y2;x3,y3;... | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_RTSP` | Full-HD RTSP or RTSPS endpoint for the target camera. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_SUB_RTSP` | RTSP or RTSPS sub-stream endpoint used for livestreaming (WebRTC). | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_RTSPS_CA_FILE` | PEM CA bundle appended to the system roots for RTSPS camera certificate verification. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_RTSPS_INSECURE` | Disable RTSPS camera certificate verification; use only when a trusted CA cannot be installed. | "false" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_BASE_WIDTH` | Force a specific width resolution for live view processing. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_BASE_HEIGHT` | Force a specific height resolution for live view processing. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_ONVIF` | Mark as a compliant ONVIF device. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_ONVIF_XADDR` | ONVIF endpoint/address running on the camera. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_ONVIF_USERNAME` | ONVIF username to authenticate against. | "" |
|
||||
| `AGENT_CAPTURE_IPCAMERA_ONVIF_PASSWORD` | ONVIF password to authenticate against. | "" |
|
||||
| `AGENT_CAPTURE_MOTION` | Toggle for enabling or disabling motion. | "true" |
|
||||
| `AGENT_CAPTURE_LIVEVIEW` | Toggle for enabling or disabling liveview. | "true" |
|
||||
| `AGENT_CAPTURE_SNAPSHOTS` | Toggle for enabling or disabling snapshot generation. | "true" |
|
||||
| `AGENT_CAPTURE_RECORDING` | Toggle for enabling making recordings. | "true" |
|
||||
| `AGENT_CAPTURE_CONTINUOUS` | Toggle for enabling continuous "true" or motion "false". | "false" |
|
||||
| `AGENT_CAPTURE_PRERECORDING` | If `CONTINUOUS` set to `false`, specify the recording time (seconds) before/after motion event. | "10" |
|
||||
| `AGENT_CAPTURE_POSTRECORDING` | If `CONTINUOUS` set to `false`, specify the recording time (seconds) after motion event. | "20" |
|
||||
| `AGENT_CAPTURE_MAXLENGTH` | The maximum length of a single recording (seconds). | "30" |
|
||||
| `AGENT_CAPTURE_PIXEL_CHANGE` | If `CONTINUOUS` set to `false`, the number of pixel require to change before motion triggers. | "150" |
|
||||
| `AGENT_CAPTURE_FRAGMENTED` | Set the format of the recorded MP4 to fragmented (suitable for HLS). | "false" |
|
||||
| `AGENT_CAPTURE_FRAGMENTED_DURATION` | If `AGENT_CAPTURE_FRAGMENTED` set to `true`, define the duration (seconds) of a fragment. | "8" |
|
||||
| `AGENT_MQTT_URI` | MQTT broker endpoint for bi-directional communication. Accepts ActiveMQ `mqtt+ssl://` URLs. | "tcp://mqtt.kerberos.io:1883" |
|
||||
| `AGENT_MQTT_USERNAME` | Username of the MQTT broker. | "" |
|
||||
| `AGENT_MQTT_PASSWORD` | Password of the MQTT broker. | "" |
|
||||
| `AGENT_REMOTE_ACCESS_ENABLED` | Allow encrypted Hub MQTT sessions to stream Agent logs and open an interactive shell. Enable only for trusted deployments. | "false" |
|
||||
| `AGENT_REALTIME_PROCESSING` | If `AGENT_REALTIME_PROCESSING` set to `true`, the agent will send key frames to the topic | "" |
|
||||
| `AGENT_REALTIME_PROCESSING_TOPIC` | The topic to which keyframes will be sent in base64 encoded format. | "" |
|
||||
| `AGENT_STUN_URI` | When using WebRTC, you'll need to provide a STUN server. | "stun:turn-fra1.kerberos.io:3478"|
|
||||
| `AGENT_FORCE_TURN` | Force using a TURN server, by generating relay candidates only. | "false" |
|
||||
| `AGENT_TURN_URI` | When using WebRTC, you'll need to provide a TURN server. | "turn:turn-fra1.kerberos.io:3478"|
|
||||
| `AGENT_TURN_USERNAME` | TURN username used for WebRTC. | "username1" |
|
||||
| `AGENT_TURN_PASSWORD` | TURN password used for WebRTC. | "password1" |
|
||||
| `AGENT_CLOUD` | Store recordings in Kerberos Hub (s3), Kerberos Vault (kstorage), or Dropbox (dropbox). | "s3" |
|
||||
| `AGENT_HUB_ENCRYPTION` | Turning on/off encryption of traffic from your Kerberos Agent to Kerberos Hub. | "true" |
|
||||
| `AGENT_HUB_URI` | The Kerberos Hub API, defaults to our Kerberos Hub SAAS. | "https://api.hub.domain.com" |
|
||||
| `AGENT_HUB_KEY` | The access key linked to your account in Kerberos Hub. | "" |
|
||||
| `AGENT_HUB_PRIVATE_KEY` | The secret access key linked to your account in Kerberos Hub. | "" |
|
||||
| `AGENT_HUB_REGION` | The Kerberos Hub region, to which you want to upload. | "" |
|
||||
| `AGENT_HUB_SITE` | The site ID of a site you've created in your Kerberos Hub account. | "" |
|
||||
| `AGENT_TUS_CHUNK_SIZE_BYTES` | Bytes sent in each resumable-upload PATCH. Set to `0` or a negative value to send all remaining bytes in one PATCH. | "8388608" (8 MiB) |
|
||||
| `AGENT_KERBEROSVAULT_URI` | The Kerberos Vault API url. | "https://vault.domain.com/api" |
|
||||
| `AGENT_KERBEROSVAULT_ACCESS_KEY` | The access key of a Kerberos Vault account. | "" |
|
||||
| `AGENT_KERBEROSVAULT_SECRET_KEY` | The secret key of a Kerberos Vault account. | "" |
|
||||
| `AGENT_KERBEROSVAULT_PROVIDER` | A Kerberos Vault provider you have created (optional). | "" |
|
||||
| `AGENT_KERBEROSVAULT_DIRECTORY` | The directory, in the Kerberos vault, where the recordings will be stored. | "" |
|
||||
| `AGENT_KERBEROSVAULT_SECONDARY_URI` | The Kerberos Vault API url. | "https://vault.domain.com/api" |
|
||||
| `AGENT_KERBEROSVAULT_SECONDARY_ACCESS_KEY` | The access key of a secondary Kerberos Vault account. | "" |
|
||||
| `AGENT_KERBEROSVAULT_SECONDARY_SECRET_KEY` | The secret key of a secondary Kerberos Vault account. | "" |
|
||||
| `AGENT_KERBEROSVAULT_SECONDARY_PROVIDER` | A secondary Kerberos Vault provider you have created (optional). | "" |
|
||||
| `AGENT_KERBEROSVAULT_SECONDARY_DIRECTORY` | The directory, in the secondary Kerberos vault, where the recordings will be stored. | "" |
|
||||
| `AGENT_DROPBOX_ACCESS_TOKEN` | The Access Token from your Dropbox app, that is used to leverage the Dropbox SDK. | "" |
|
||||
| `AGENT_DROPBOX_DIRECTORY` | The directory, in Dropbox, where the recordings will be stored. | "" |
|
||||
| `AGENT_ENCRYPTION` | Enable 'true' or disable 'false' end-to-end encryption for MQTT messages. | "false" |
|
||||
| `AGENT_ENCRYPTION_RECORDINGS` | Enable 'true' or disable 'false' end-to-end encryption for recordings. | "false" |
|
||||
| `AGENT_ENCRYPTION_FINGERPRINT` | The fingerprint of the keypair (public/private keys), so you know which one to use. | "" |
|
||||
| `AGENT_ENCRYPTION_PRIVATE_KEY` | The private key (assymetric/RSA) to decrypt and sign requests send over MQTT. | "" |
|
||||
| `AGENT_ENCRYPTION_SYMMETRIC_KEY` | The symmetric key (AES) to encrypt and decrypt requests sent over MQTT. | "" |
|
||||
| `AGENT_SIGNING` | Enable 'true' or disable 'false' for signing recordings. | "true" |
|
||||
| `AGENT_SIGNING_PRIVATE_KEY` | The private key (RSA) to sign the recordings fingerprint to validate origin. | "" - uses default one if empty |
|
||||
|
||||
Remote console access is disabled unless `AGENT_REMOTE_ACCESS_ENABLED=true`.
|
||||
The Agent also rejects remote session messages unless Hub encryption or
|
||||
end-to-end MQTT encryption is configured and used. A remote shell runs inside
|
||||
the Agent process environment as the Agent operating-system user; it is not an
|
||||
SSH server and does not expose a new network port. Keep the feature disabled on
|
||||
deployments where Hub owners should not have operating-system access.
|
||||
|
||||
### Resumable upload chunk size
|
||||
|
||||
Hub and Vault resumable uploads use `AGENT_TUS_CHUNK_SIZE_BYTES` as the maximum
|
||||
body size of each tus `PATCH` request. The value is a number of bytes, not a
|
||||
number of chunks. If the variable is unset or invalid, the Agent uses 8 MiB:
|
||||
|
||||
```dotenv
|
||||
# 8 MiB (default)
|
||||
AGENT_TUS_CHUNK_SIZE_BYTES=8388608
|
||||
|
||||
# 4 MiB: more frequent checkpoints on unstable connections
|
||||
AGENT_TUS_CHUNK_SIZE_BYTES=4194304
|
||||
|
||||
# Disable chunking and send all remaining bytes in one PATCH
|
||||
AGENT_TUS_CHUNK_SIZE_BYTES=0
|
||||
```
|
||||
|
||||
Smaller chunks provide more frequent resumable checkpoints but create more HTTP
|
||||
requests. Larger chunks reduce request overhead but require more data to be
|
||||
retransmitted when a request fails.
|
||||
|
||||
|
||||
## Encryption
|
||||
|
||||
You can encrypt your recordings and outgoing MQTT messages with your own AES and RSA keys by enabling the encryption settings. Once enabled, all your recordings will be encrypted using AES-256-CBC and your symmetric key. You can use the default `openssl` toolchain to decrypt the recordings with your AES key, as following:
|
||||
|
||||
openssl aes-256-cbc -d -md md5 -in encrypted.mp4 -out decrypted.mp4 -k your-key-96ab185xxxxxxxcxxxxxxxx6a59c62e8
|
||||
|
||||
Or you can decrypt a folder of recordings, using the Kerberos Agent binary as following:
|
||||
|
||||
go run main.go -action decrypt ./data/recordings your-key-96ab185xxxxxxxcxxxxxxxx6a59c62e8
|
||||
|
||||
Or for a single file:
|
||||
|
||||
go run main.go -action decrypt ./data/recordings/video.mp4 your-key-96ab185xxxxxxxcxxxxxxxx6a59c62e8
|
||||
|
||||
## H264 vs H265
|
||||
|
||||
If we talk about video encoders and decoders (codecs) there are 2 major video codecs on the market: H264 and H265. Taking into account your use case, you might use one over the other. We will provide an (not complete) overview of the advantages and disadvantages of each codec in the field of video surveillance and video analytics. If you would like to know more, you should look for additional resources on the internet (or if you like to read physical items, books still exists nowadays).
|
||||
|
||||
- H264 (also known as AVC or MPEG-4 Part 10)
|
||||
|
||||
- Is the most common one and most widely supported for IP cameras.
|
||||
- Supported in the majority of browsers, operating system, and third-party applications.
|
||||
- Can be embedded in commercial and 3rd party applications.
|
||||
- Different levels of compression (high, medium, low, ..)
|
||||
- Better quality / compression ratio, shows less artifacts at medium compression ratios.
|
||||
- Does support technologies such as WebRTC
|
||||
|
||||
- H265 (also known as HEVC)
|
||||
- Is not supported on legacy cameras, though becoming rapidly available on "newer" IP cameras.
|
||||
- Might not always be supported due to licensing. For example not supported in browers on a Linux distro.
|
||||
- Requires licensing when embedding in a commercial product (be careful).
|
||||
- Higher levels of compression (50% more than H264).
|
||||
- H265 shows artifacts in motion based environments (which is less with H264).
|
||||
- Recording the same video (resolution, duration and FPS) in H264 and H265 will result in approx 50% the file size.
|
||||
- Not supported in technologies such as WebRTC
|
||||
|
||||
Conclusion: depending on the use case you might choose one over the other, and you can use both at the same time. For example you can use H264 (main stream) for livestreaming, and H265 (sub stream) for recording. If you wish to play recordings in a cross-platform and cross-browser environment, you might opt for H264 for better support.
|
||||
|
||||
## Security vulnerability reporting
|
||||
|
||||
If you found a potential security vulnerability, please use the private channels described in [SECURITY.md](SECURITY.md). Avoid opening public GitHub issues for sensitive findings.
|
||||
|
||||
## Contribute with Codespaces
|
||||
|
||||
One of the major blockers for letting you contribute to an Open Source project is to set up your local development machine. Why? Because you might already have some tools and libraries installed that are used for other projects, and the libraries you would need for Kerberos Agent, for example FFmpeg, might require a different version. Welcome to dependency hell...
|
||||
|
||||
By leveraging codespaces, which the Kerberos Agent repo supports, you will be able to set up the required development environment in a few minutes. By opening the `<> Code` tab on the top of the page, you will be able to create a codespace, [using the Kerberos Devcontainer](https://github.com/kerberos-io/devcontainer) base image. This image requires all the relevant dependencies: FFmpeg, OpenCV, Golang, Node, Yarn, etc.
|
||||
|
||||

|
||||
|
||||
After a few minutes, you will see a beautiful `Visual Studio Code` shown in your browser, and you are ready to code!
|
||||
|
||||

|
||||
|
||||
On opening of the GitHub Codespace, some dependencies will be installed. Once this is done go ahead to the `ui/src/config.json` file, and (un)comment following section. Make sure to replace the `externalHost` variable with the DNS name you will retrieve from the next step.
|
||||
|
||||
// Uncomment this when using codespaces or other special DNS names (which you can't control)
|
||||
// replace this with the DNS name of the kerberos agent server (the codespace url)
|
||||
const externalHost = 'cedricve-automatic-computing-machine-v647rxvj4whx9qp-80.preview.app.github.dev';
|
||||
|
||||
const dev = {
|
||||
ENV: 'dev',
|
||||
HOSTNAME: externalHost,
|
||||
//API_URL: `${protocol}//${hostname}:80/api`,
|
||||
//URL: `${protocol}//${hostname}:80`,
|
||||
//WS_URL: `${websocketprotocol}//${hostname}:80/ws`,
|
||||
|
||||
// Uncomment, and comment the above lines, when using codespaces or other special DNS names (which you can't control)
|
||||
API_URL: `${protocol}//${externalHost}/api`,
|
||||
URL: `${protocol}//${externalHost}`,
|
||||
WS_URL: `${websocketprotocol}//${externalHost}/ws`,
|
||||
};
|
||||
|
||||
Go and open two terminals: one for the `ui` project and one for the `machinery` project.
|
||||
|
||||
1. Terminal A:
|
||||
|
||||
cd machinery/
|
||||
go run main.go -action run -port 80
|
||||
|
||||
2. Terminal B:
|
||||
|
||||
cd ui/
|
||||
yarn start
|
||||
|
||||
Once executed, a popup will show up mentioning `portforwarding`. You should see two ports being opened, one for the ui `3000` and one for the machinery `80`. `Right-click` on the port `80` and change visibility from `private` to `public`, this is required to avoid `CORS` errors.
|
||||
|
||||

|
||||
|
||||
As mentioned above, copy the hostname of the `machinery` DNS name, and paste it in the `ui/src/config.json` file. Once done, reload the `ui` page in your browser, and you should be able to access the login page with the default credentials `root` and `root`.
|
||||
|
||||
docker run -p 8080:8080 --name mycamera -v $(pwd)/agent/config:/home/agent/data/config -v $(pwd)/agent/recordings:/home/agent/data/recordings -d kerberos/agent:latest
|
||||
|
||||
## Develop and build
|
||||
|
||||
Kerberos Agent is divided in two parts a `machinery` and `web`. Both parts live in this repository in their relative folders. For development or running the application on your local machine, you have to run both the `machinery` and the `web` as described below. When running in production everything is shipped as only one artifact, read more about this at [Building for production](#building-for-production).
|
||||
The Kerberos Agent is divided in two parts: a `machinery` and `web` part. Both parts live in this repository in their relative folders. For development or running the application on your local machine, you have to run both the `machinery` and the `web` as described below. When running in production everything is shipped as only one artifact, read more about this at [Building for production](#building-for-production).
|
||||
|
||||
### UI
|
||||
|
||||
@@ -124,27 +516,32 @@ This will start a webserver and launches the web app on port `3000`.
|
||||
|
||||

|
||||
|
||||
Once signed in you'll see the dashboard page showing up. After successfull configuration of your agent, you'll should see a live view and possible events recorded to disk.
|
||||
Once signed in you'll see the dashboard page. After successfull configuration of your agent, you'll should see a live view and possible events recorded to disk.
|
||||
|
||||

|
||||
|
||||
### Machinery
|
||||
|
||||
The `machinery` is a **Golang** project which delivers two functions: it acts as the Kerberos Agent which is doing all the heavy lifting with camera processing and other kinds of logic, on the other hand it acts as a webserver (Rest API) that allows communication from the web (React) or any other custom application. The API is documented using `swagger`.
|
||||
The `machinery` is a **Golang** project which delivers two functions: it acts as the Kerberos Agent which is doing all the heavy lifting with camera processing and other kinds of logic and on the other hand it acts as a webserver (Rest API) that allows communication from the web (React) or any other custom application. The API is documented using `swagger`.
|
||||
|
||||
An executable reference for the Agent frame-processing HTTP and MQTT contracts is
|
||||
available in [`examples/frame-processor`](examples/frame-processor). It provides
|
||||
deterministic processing profiles for integration testing without requiring a
|
||||
machine-learning runtime.
|
||||
|
||||
You can simply run the `machinery` using following commands.
|
||||
|
||||
git clone https://github.com/kerberos-io/agent
|
||||
cd machinery
|
||||
go run main.go run mycameraname 8080
|
||||
go run main.go -action run -port 80
|
||||
|
||||
This will launch the Kerberos Agent and run a webserver on port `8080`. You can change the port by your own preference. We strongly support the usage of [Goland](https://www.jetbrains.com/go/) or [Visual Studio Code](https://code.visualstudio.com/), as it comes with all the debugging and linting features builtin.
|
||||
This will launch the Kerberos Agent and run a webserver on port `80`. You can change the port by your own preference. We strongly support the usage of [Goland](https://www.jetbrains.com/go/) or [Visual Studio Code](https://code.visualstudio.com/), as it comes with all the debugging and linting features built in.
|
||||
|
||||

|
||||

|
||||
|
||||
## Building for Production
|
||||
## Building from source
|
||||
|
||||
Running Kerberos Agent in production only require a single binary to run. Nevertheless, we have two parts, the `machinery` and the `web`, we merge them during build time. So this is what happens.
|
||||
Running Kerberos Agent in production only requires a single binary to run. Nevertheless, we have two parts: the `machinery` and the `web`, we merge them during build time. So this is what happens.
|
||||
|
||||
### UI
|
||||
|
||||
@@ -155,31 +552,79 @@ To build the Kerberos Agent web app, you simply have to run the `build` command
|
||||
|
||||
### Machinery
|
||||
|
||||
Building the `machinery` is also super easy 🚀, by using `go build` you can create a single binary which ships it all; thank you Golang. After building you will endup with a binary called `main`, this is what contains everything you need to run Kerberos Agent.
|
||||
Building the `machinery` is also super easy 🚀, by using `go build` you can create a single binary which ships it all; thank you Golang. After building you will end up with a binary called `main`, this is what contains everything you need to run Kerberos Agent.
|
||||
|
||||
Remember the build step of the `web` part, during build time we move the build directory to the `machinery` directory. Inside the `machinery` web server [we reference the](https://github.com/kerberos-io/agent/blob/master/machinery/src/routers/http/Server.go#L44) `build` directory. This makes it possible to just a have single web server that runs it all.
|
||||
Remember the build step of the `web` part, during build time we move the build directory to the `machinery` directory. Inside the `machinery` web server [we reference the](https://github.com/kerberos-io/agent/blob/master/machinery/src/routers/http/Server.go#L44) `build` directory. This makes it possible to just a have single web server that runs it all.
|
||||
|
||||
cd machinery
|
||||
go build
|
||||
|
||||
## Building for Docker
|
||||
|
||||
Inside the root of this `agent` repository, you will find a `Dockerfile`. This file contains the instructions for building and shipping **Kerberos Agent**. Important to note is that start from a prebuild base image, `kerberos/debian-opencv-ffmpeg:1.0.xxx`.
|
||||
This base image contains already a couple of tools, such as Golang, FFmpeg and OpenCV. We do this for faster compilation times.
|
||||
Inside the root of this `agent` repository, you will find a `Dockerfile`. This file contains the instructions for building and shipping a **Kerberos Agent**. It uses Debian Trixie to support the native dependencies used by the Agent, including Media over QUIC.
|
||||
|
||||
By running the `docker build` command, you will create the Kerberos Agent Docker image. After building you can simply run the image as a Docker container.
|
||||
|
||||
docker build -t kerberos/agent .
|
||||
|
||||
## Support our project
|
||||
### Media over QUIC
|
||||
|
||||
If you like our product please feel free to execute an Ethereum donation. All donations will flow back and split to our Open Source contributors, as they are the heart of this community.
|
||||
|
||||
<img width="272" alt="Ethereum donation linke" src="https://user-images.githubusercontent.com/1546779/173443671-3d773068-ae10-4862-a990-dc7c89f3d9c2.png">
|
||||
The standard AMD64 and ARM64 images include the optional MoQ publisher. Its Rust
|
||||
FFI archive requires CGO and glibc 2.38 or newer, which is why the standard image
|
||||
uses Debian Trixie. The publisher is disabled unless explicitly enabled at runtime:
|
||||
|
||||
Ethereum Address: `0xf4a759C9436E2280Ea9cdd23d3144D95538fF4bE`
|
||||
|
||||
## Previous releases
|
||||
docker run --rm -p 80:80 \
|
||||
-e AGENT_LIVE_MOQ_ENABLED=true \
|
||||
-e AGENT_LIVE_MOQ_URL=https://relay.uug.ai/anon \
|
||||
kerberos/agent
|
||||
|
||||
`AGENT_LIVE_MOQ_BROADCAST_PREFIX` defaults to `devices`. MoQ viewers subscribe to
|
||||
a relay and never negotiate with the Agent, so every quality tier is published as
|
||||
its own broadcast and switching quality is simply a resubscribe:
|
||||
|
||||
| Tier | Broadcast | Source |
|
||||
| ------ | ------------------------------------- | ------------------------------------------ |
|
||||
| `high` | `devices/<agent-key>/live.hang` | highest-resolution camera stream |
|
||||
| `low` | `devices/<agent-key>/live-low.hang` | sub stream (main stream when none is set) |
|
||||
|
||||
Each tier uploads every frame while it has subscribers. While idle, it continues
|
||||
to upload fresh keyframes only. This keeps the relay's latest cached GOP current,
|
||||
so a new viewer does not initially render the final frame from the previous
|
||||
viewer session, while avoiding the bandwidth cost of continuously sending every
|
||||
delta frame. `AGENT_LIVE_MOQ_QUALITY` accepts `high` or `low` to pin the Agent to
|
||||
a single tier; viewers requesting the other tier then find no broadcast. Any
|
||||
other value (including the default) publishes both. The initial implementation
|
||||
publishes H.264 video only.
|
||||
|
||||
Two bounded duration settings tune recovery for unusual network conditions:
|
||||
|
||||
| Variable | Default | Allowed range |
|
||||
| -------- | ------- | ------------- |
|
||||
| `AGENT_LIVE_MOQ_MAX_PACKET_AGE` | `1.5s` | `250ms` to `30s` |
|
||||
| `AGENT_LIVE_MOQ_WRITE_TIMEOUT` | `5s` | `1s` to `1m` |
|
||||
|
||||
Values use Go duration syntax and are clamped to the documented range. The
|
||||
dashboard API's `recovery` object reports per-tier reconnects, last successful
|
||||
frame/write timing, native write timeouts, watchdog restarts/cooldown, dropped
|
||||
run-channel events, and run-worker shutdown timeouts.
|
||||
|
||||
The `/anon` relay route is intended for interoperability testing. Production
|
||||
deployments must set `AGENT_LIVE_MOQ_URL` to a short-lived, device-scoped
|
||||
publisher URL issued by Hub API.
|
||||
|
||||
To verify the native SDK in a development container, rebuild the Agent or shared
|
||||
monorepo devcontainer so it uses the Trixie base, then run the VS Code task
|
||||
`agent: moq verify`. The same check is available from a terminal:
|
||||
|
||||
cd machinery
|
||||
bash ./verify-moq-devcontainer.sh
|
||||
|
||||
The check requires glibc 2.38 or newer, runs the tagged package and in-process
|
||||
native QUIC lifecycle tests, links the complete Agent with `-tags moq`, and
|
||||
executes the resulting binary's version
|
||||
command. Both devcontainers also run this check during their post-create setup.
|
||||
|
||||
## What is new?
|
||||
|
||||
This repository contains the next generation of Kerberos.io, **Kerberos Agent (v3)**, and is the successor of the machinery and web repositories. A switch in technologies and architecture has been made. This version is still under active development and can be followed on the [develop branch](https://github.com/kerberos-io/agent/tree/develop) and [project overview](https://github.com/kerberos-io/agent/projects/1).
|
||||
|
||||
@@ -187,37 +632,9 @@ Read more about this [at the FAQ](#faq) below.
|
||||
|
||||

|
||||
|
||||
## FAQ
|
||||
|
||||
#### 1. Why a mono repo?
|
||||
|
||||
We have noticed in the past (v1 and v2) splitting the repositories (machinery and web), created a lot of confusion within our community. People didn't understand the different versions and so on. This caused a lack of collaboration, and made it impossible for some people to collaborate and contribute.
|
||||
|
||||
Having a mono repo, which is well organised, simplifies the entry point for new people who would like to use, understand and/or contribute to Kerberos Agent.
|
||||
|
||||
#### 2. Why a change in technologies?
|
||||
|
||||
In previous versions (v1 and v2) we used technologies like C++, PHP and BackboneJS. 7 years ago this was still acceptable, however time has changed and new technologies such as React and Golang became very popular.
|
||||
|
||||
Due to previous reason we have decided to rebuild the Kerberos Agent technology from scratch, taking into account all the feedback we acquired over the years. Having these technologies available, we will enable more people to contribute and use our technology.
|
||||
|
||||
#### 3. What is the difference with Kerberos Enterprise?
|
||||
|
||||
We started the developments of Kerberos Enterprise a year ago (January, 2020), our focus here was scalability, and fast development and easy deployment. We noticed that with technologies such as Golang and React, we can still provide a highly performant video surveillance system.
|
||||
|
||||
Kerberos Agent uses the same technology stack, and some code pieces, of Kerberos Enterprise which we have already build. We have a very clear now, of how a well developed and documented video surveillance system needs to look like.
|
||||
|
||||
#### 4. When are we going to be able to install the first version?
|
||||
|
||||
We plan to ship the first version by the end of Q1, afterwards we will add more and more features as usual.
|
||||
|
||||
#### 5. Change in License
|
||||
|
||||
Kerberos Agent (v3) is now available under the MIT license.
|
||||
|
||||
## Contributors
|
||||
|
||||
This project exists thanks to all the people who contribute.
|
||||
This project exists thanks to all the people who contribute. Bravo!
|
||||
|
||||
<a href="https://github.com/kerberos-io/agent/graphs/contributors">
|
||||
<img src="https://contrib.rocks/image?repo=kerberos-io/agent" />
|
||||
|
||||
40
SECURITY.md
Normal file
@@ -0,0 +1,40 @@
|
||||
# Security Policy
|
||||
|
||||
## Supported Versions
|
||||
|
||||
We only provide security fixes for the latest release series on the `master` branch.
|
||||
|
||||
## Reporting a Vulnerability
|
||||
|
||||
Please do **not** open a public GitHub issue for potential security vulnerabilities.
|
||||
|
||||
Use one of the private channels below:
|
||||
|
||||
1. Preferred: GitHub private vulnerability reporting
|
||||
- https://github.com/kerberos-io/agent/security/advisories/new
|
||||
2. Fallback: Email
|
||||
- support@kerberos.io
|
||||
- Optional CC: support@uug.ai
|
||||
|
||||
Please include:
|
||||
|
||||
- A short summary and impact.
|
||||
- Reproduction steps or proof of concept.
|
||||
- Affected version(s), commit hash, or deployment details.
|
||||
- Any proposed mitigation/workaround.
|
||||
- Your preferred attribution name.
|
||||
|
||||
For faster triage, use this subject format in email:
|
||||
|
||||
`[Security][Kerberos Agent] <short title>`
|
||||
|
||||
## Response Expectations
|
||||
|
||||
- Acknowledgement target: within 3 business days.
|
||||
- Triage/update target: within 7 business days after acknowledgement.
|
||||
|
||||
If you do not receive a response in time, please resend your report and include your original timestamp.
|
||||
|
||||
## Disclosure and Credits
|
||||
|
||||
We follow coordinated disclosure. After a fix is available, we will credit reporters unless they prefer to stay anonymous.
|
||||
BIN
assets/img/codespace-make-public.png
Normal file
|
After Width: | Height: | Size: 138 KiB |
BIN
assets/img/codespace-vscode.png
Normal file
|
After Width: | Height: | Size: 769 KiB |
BIN
assets/img/codespace.png
Normal file
|
After Width: | Height: | Size: 286 KiB |
2958
assets/img/edge-deployment-agent.svg
Normal file
|
After Width: | Height: | Size: 696 KiB |
BIN
assets/img/logo.png
Normal file
|
After Width: | Height: | Size: 25 KiB |
BIN
assets/img/vscode-desktop.png
Normal file
|
After Width: | Height: | Size: 966 KiB |
10
build.sh
@@ -1,10 +0,0 @@
|
||||
export version=0.0.1
|
||||
export name=agent
|
||||
|
||||
docker build -t $name .
|
||||
|
||||
docker tag $name kerberos/$name:$version
|
||||
docker push kerberos/$name:$version
|
||||
|
||||
docker tag $name kerberos/$name:latest
|
||||
docker push kerberos/$name:latest
|
||||
79
deployments/README.md
Normal file
@@ -0,0 +1,79 @@
|
||||
# Kerberos Agent Deployments
|
||||
|
||||
Great to see you here, you just arrived at the real stuff! As you may have understood Kerberos Agent is a containerized solution. A Kerberos Agent, or container equivalent, is running for each camera. This approach makes it scalable, isolated and probably the most important thing an exceptional workload governance.
|
||||
|
||||
Due to it's nature, of acting as a micro service, there are many different ways how to get this Kerberos Agent up and running. This part of the Kerberos Agent repository contains example configurations, for all the different deployments and automations you can leverage to deploy and scale your video landscape.
|
||||
|
||||
We will discuss following deployment models.
|
||||
|
||||
- [0. Static binary](#0-static-binary)
|
||||
- [1. Docker](#1-docker)
|
||||
- [2. Docker Compose](#2-docker-compose)
|
||||
- [3. Kubernetes](#3-kubernetes)
|
||||
- [4. Red Hat Ansible and OpenShift](#4-red-hat-ansible-and-openshift)
|
||||
- [5. Kerberos Factory](#5-kerberos-factory)
|
||||
- [6. Terraform](#6-terraform)
|
||||
- [7. Salt](#7-salt)
|
||||
- [8. Balena](#8-balena)
|
||||
|
||||
## 0. Static binary
|
||||
|
||||
Kerberos Agents are now also shipped as static binaries. Within the Docker image build, we are extracting the Kerberos Agent binary and are [uploading them to the releases page](https://github.com/kerberos-io/agent/releases) in the repository. By opening a release you'll find a `.tar` with the relevant files.
|
||||
|
||||
> Learn more [about the Kerberos Agent binary here](https://github.com/kerberos-io/agent/tree/master/deployments/binary).
|
||||
|
||||
## 1. Docker
|
||||
|
||||
Leveraging `docker` is probably one of the easiest way to run and test the Kerberos Agent. Thanks to it's multi-architecture images you could run it on almost every machine. The `docker` approach is perfect for running one or two cameras in a (single machine) home deployment, a POC to verify its capabilities, or testing if your old/new IP camera is operational with our Kerberos Agent.
|
||||
|
||||
> Learn more [about Kerberos Agent on Docker here](https://github.com/kerberos-io/agent/tree/master/deployments/docker#1-running-a-single-container).
|
||||
|
||||
## 2. Docker Compose
|
||||
|
||||
If you consider `docker` as "your way to go", but require to run a bigger (single machine) deployment at home or inside your store then `docker compose` would be more suitable. By specifying a single `docker-compose.yaml` file, you can define all your Kerberos Agents (and thus cameras) in a single file, with a custom configuration to fit your needs.
|
||||
|
||||
> Learn more [about Kerberos Agent with Docker Compose here](https://github.com/kerberos-io/agent/tree/master/deployments/docker#2-running-multiple-containers-with-docker-compose).
|
||||
|
||||
## 3. Kubernetes
|
||||
|
||||
As described above, `docker` is a great tool for smaller deployments, where you are just running on a single machine and want to ramp up quickly. As you might expect, this is a not an ideal situation for production deployments. Kubernetes can help you to build a scalable, flexible and resilient deployment.
|
||||
|
||||
> Learn more [about Kerberos Agent in a Kubernetes cluster here](https://github.com/kerberos-io/agent/tree/master/deployments/kubernetes).
|
||||
|
||||
## 4. Red Hat Ansible and OpenShift
|
||||
|
||||
If you running an alternative distribution such as Red Hat OpenShift, things will work out exactly as mentioned before with the `Kubernetes` deployment. You'll have all the benefints of Red Hat OpenShift on top. One of the things we provide here is an Ansible playbook to deploy the Kerberos Agent in the OpenShift cluster.
|
||||
|
||||
> Learn more [about Kerberos Agent in OpenShift with Ansible](https://github.com/kerberos-io/agent/tree/master/deployments/ansible-openshift).
|
||||
|
||||
## 5. Kerberos Factory
|
||||
|
||||
All of the previously deployments, `docker`, `kubernetes` and `openshift` are great for a technical audience. However for business users, it might be more convenient to have a clean web ui, that one can leverage to add one or more cameras (Kerberos Agents), without the hassle of the technical resources.
|
||||
|
||||
> Learn more [about Kerberos Agent with Kerberos Factory](https://github.com/kerberos-io/agent/tree/master/deployments/factory).
|
||||
|
||||
## 6. Terraform
|
||||
|
||||
Terraform is a tool for infrastructure provisioning to build infrastructure through code, often called Infrastructure as Code. So, Terraform allows you to automate and manage your infrastructure, your platform, and the services that run on that platform. By using Terraform you can deploy your Kerberos Agents remotely at scale.
|
||||
|
||||
> Learn more [about Kerberos Agent with Terraform](https://github.com/kerberos-io/agent/tree/master/deployments/terraform).
|
||||
|
||||
## 7. Salt
|
||||
|
||||
To be written
|
||||
|
||||
## 8. Balena
|
||||
|
||||
Balena Cloud provide a seamless way of building and deploying applications at scale through the conceps of `blocks`, `apps` and `fleets`. Once you have your `app` deployed, for example our Kerberos Agent, you can benefit from features such as: remote access, over the air updates, an encrypted public `https` endpoint and many more.
|
||||
|
||||
Together with the Balena.io team we've build a Balena App, called [`video-surveillance`](https://hub.balena.io/apps/2064752/video-surveillance), which any can use to deploy a video surveillance system in a matter of minutes with all the expected management features you can think of.
|
||||
|
||||
> Learn more [about Kerberos Agent with Balena](https://github.com/kerberos-io/agent/tree/master/deployments/balena).
|
||||
|
||||
## 9. Snap
|
||||
|
||||
The Snap Store, also known as the Ubuntu Store , is a commercial centralized software store operated by Canonical. Similar to AppImage or Flatpak the Snap Store is able to provide up to date software no matter what version of Linux you are running and how old your libraries are.
|
||||
|
||||
We have published our own snap `Kerberos Agent` on the Snap Store, allowing you to seamless install a Kerberos Agent on your Linux devive.
|
||||
|
||||
> Learn more [about Kerberos Agent with Snap](https://github.com/kerberos-io/agent/tree/master/deployments/snap).
|
||||
49
deployments/ansible-openshift/README.md
Normal file
@@ -0,0 +1,49 @@
|
||||
# Deploy to a Red Hat OpenShift cluster with Ansible
|
||||
|
||||
Kubernetes is great, but you might love OpenShift even more. In this directory you'll find some resources to deploy your Kerberos Agent in an OpenShift cluster using Ansible playbook. We'll review the different tasks of the Ansible playbook step by step; find the complete `playbook.yaml` here.
|
||||
|
||||
## Variabeles
|
||||
|
||||
We'll have a few `variables` in our `playbook.yml` that will help us to setup secure connection with the OpenShift cluster. We need the `cluster_url` and the `username` and `password` of the OpenShift cluster. If you don't know where to find this, you can find this in the OpenShift web ui.
|
||||
|
||||
vars:
|
||||
- oc_cluster_url: ""
|
||||
- oc_username: ""
|
||||
- oc_password: ""
|
||||
|
||||
## Tasks
|
||||
|
||||
Once we have supplied the `variables` we will define following tasks:
|
||||
|
||||
- name: Print Variables
|
||||
- name: Try to login to OCP cluster
|
||||
- name: Create a Namespace
|
||||
- name: Create a Persistent volume claim
|
||||
- name: Deploy Kerberos Agent
|
||||
- name: Expose Kerberos Agent
|
||||
|
||||
1. Print variables: this is a validation step, where we make sure we have the correct variables supplied to the `ansible-playbook` command. This confirms we are using the right credentials to setup a secure connection with the OpenShift cluster.
|
||||
|
||||
2. Setup a connection with OpenShift using the defined variabeles. If successfull an `api_key` will become available in the `k8s_auth_result` variable. This variabele will be used with every subsequent operation against the OpenShift cluster.
|
||||
|
||||
3. A best practice is to isolate your workloads in namespaces. Therefore we'll create a new namespace in our OpenShift cluster.
|
||||
|
||||
4. (Optional) Create a persistent volume to persist the configuration file and recordings in a volume.
|
||||
|
||||
5. Deploy Kerberos Agent through a `deployment`.
|
||||
|
||||
6. Expose the Kerberos Agent web interface through a `LoadBalancer`; public internet accessible IP address.
|
||||
|
||||
## Run the playbook
|
||||
|
||||
Now you understand what is happening in the playbook, let's run it. Make sure you have `ansible` install on your `host` or `deploy` machine.
|
||||
|
||||
Specify the `environment` input variable as a `JSON` with all required variables defined in step 1. Reference the `playbook.yml` file and execute.
|
||||
|
||||
ansible-playbook -e '{ \
|
||||
"oc_cluster_url":"https://api.j5z0adui.westeurope.aroapp.io:6443", \
|
||||
"oc_username":"kubeadmin",\
|
||||
"oc_password":"xxx" \
|
||||
}' playbook.yml
|
||||
|
||||
If everything runs as expected you should see you Kerberos Agent deployed, together with an assigned public ip address. Paste the ip address in your browser, the Kerberos Agent web interface will show up. You can use [the default username and password to sign-in](https://github.com/kerberos-io/agent#access-the-kerberos-agent), or if changed to your own (which is recommended).
|
||||
140
deployments/ansible-openshift/playbook.yml
Normal file
@@ -0,0 +1,140 @@
|
||||
- hosts: localhost
|
||||
vars:
|
||||
- oc_cluster_url: ""
|
||||
- oc_username: ""
|
||||
- oc_password: ""
|
||||
tasks:
|
||||
- name: Print Variables
|
||||
debug:
|
||||
msg: "OpenShift url: {{ oc_cluster_url }}, OpenShift username: {{ oc_username }}, OpenShift password: {{ oc_password }}"
|
||||
|
||||
- name: Try to login to OCP cluster
|
||||
k8s_auth:
|
||||
host: "{{ oc_cluster_url }}"
|
||||
username: "{{ oc_username }}"
|
||||
password: "{{ oc_password }}"
|
||||
validate_certs: no
|
||||
register: k8s_auth_result
|
||||
|
||||
- name: Create a Namespace
|
||||
k8s:
|
||||
state: present
|
||||
host: "{{ oc_cluster_url }}"
|
||||
api_key: "{{ k8s_auth_result.k8s_auth.api_key }}"
|
||||
validate_certs: no
|
||||
definition:
|
||||
apiVersion: v1
|
||||
kind: Namespace
|
||||
metadata:
|
||||
name: kerberos
|
||||
register: k8s_namespace_result
|
||||
|
||||
- name: Create a Persistent volume claim
|
||||
k8s:
|
||||
state: present
|
||||
host: "{{ oc_cluster_url }}"
|
||||
api_key: "{{ k8s_auth_result.k8s_auth.api_key }}"
|
||||
validate_certs: no
|
||||
namespace: kerberos
|
||||
definition:
|
||||
apiVersion: v1
|
||||
kind: PersistentVolumeClaim
|
||||
metadata:
|
||||
name: kerberos-data
|
||||
spec:
|
||||
accessModes:
|
||||
- ReadWriteOnce
|
||||
resources:
|
||||
requests:
|
||||
storage: 2Gi
|
||||
storageClassName: managed-premium
|
||||
register: pvc_result
|
||||
|
||||
- name: Deploy Kerberos Agent
|
||||
k8s:
|
||||
state: present
|
||||
apply: yes
|
||||
namespace: kerberos
|
||||
host: "{{ oc_cluster_url }}"
|
||||
api_key: "{{ k8s_auth_result.k8s_auth.api_key }}"
|
||||
validate_certs: no
|
||||
definition:
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: agent
|
||||
labels:
|
||||
name: agent
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: agent
|
||||
replicas: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: agent
|
||||
spec:
|
||||
volumes:
|
||||
- name: kerberos-data
|
||||
persistentVolumeClaim:
|
||||
claimName: kerberos-data
|
||||
|
||||
initContainers:
|
||||
- name: download-config
|
||||
image: kerberos/agent:latest
|
||||
volumeMounts:
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/config
|
||||
subPath: config
|
||||
command:
|
||||
[
|
||||
"cp",
|
||||
"/home/agent/data/config.template.json",
|
||||
"/home/agent/data/config/config.json",
|
||||
]
|
||||
|
||||
containers:
|
||||
- name: agent
|
||||
image: kerberos/agent:latest
|
||||
volumeMounts:
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/config
|
||||
subPath: config
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/recordings
|
||||
subPath: recordings
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/snapshots
|
||||
subPath: snapshots
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/cloud
|
||||
subPath: cloud
|
||||
ports:
|
||||
- containerPort: 80
|
||||
protocol: TCP
|
||||
|
||||
- name: Expose Kerberos Agent
|
||||
k8s:
|
||||
state: present
|
||||
apply: yes
|
||||
namespace: kerberos
|
||||
host: "{{ oc_cluster_url }}"
|
||||
api_key: "{{ k8s_auth_result.k8s_auth.api_key }}"
|
||||
validate_certs: no
|
||||
definition:
|
||||
kind: Service
|
||||
apiVersion: v1
|
||||
metadata:
|
||||
name: agent-svc
|
||||
labels:
|
||||
name: agent-svc
|
||||
spec:
|
||||
selector:
|
||||
app: agent
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- name: http
|
||||
port: 80
|
||||
targetPort: 80
|
||||
protocol: TCP
|
||||
31
deployments/balena/README.md
Normal file
@@ -0,0 +1,31 @@
|
||||
# Deployment with Balena
|
||||
|
||||
Balena Cloud provide a seamless way of building and deploying applications at scale through the conceps of `blocks`, `apps` and `fleets`. Once you have your `app` deployed, for example our Kerberos Agent, you can benefit from features such as: remote access, over the air updates, an encrypted public `https` endpoint and many more.
|
||||
|
||||
We provide two mechanisms to deploy Kerberos Agent to a Balena Cloud fleet:
|
||||
|
||||
1. Use Kerberos Agent as [a block part of your application](https://github.com/kerberos-io/balena-agent-block).
|
||||
2. Use Kerberos Agent as [a stand-alone application](https://github.com/kerberos-io/balena-agent).
|
||||
|
||||
## Block
|
||||
|
||||
Within Balena you can build the concept of a block, which is the equivalent of container image or a function in a typical programming language. The idea of blocks, you can find a more thorough explanation [here](https://docs.balena.io/learn/develop/blocks/), is that you can compose and combine multiple `blocks` to level up to the concept an `app`.
|
||||
|
||||
You as a developer can choose which `blocks` you would like to use, to build the desired `application` state you prefer. For example you can use the [Kerberos Agent block](https://hub.balena.io/blocks/2064662/agent) to compose a video surveillance system as part of your existing set of blocks.
|
||||
|
||||
You can the `Kerberos Agent` block by defining following elements in your `compose` file.
|
||||
|
||||
agent:
|
||||
image: bh.cr/kerberos_io/agent
|
||||
|
||||
## App
|
||||
|
||||
Next to building individual `blocks` you as a developer can also decide to build up an application, composed of one or more `blocks` or third-party containers, and publish it as an `app` to the Balena Hub. This is exactly [what we've done..](https://hub.balena.io/apps/2064752/video-surveillance)
|
||||
|
||||
On Balena Hub we have created the []`video-surveillance` application](https://hub.balena.io/apps/2064752/video-surveillance) that utilises the [Kerberos Agent `block`](https://hub.balena.io/blocks/2064662/agent). The idea of this application is that utilises the foundation of our Kerberos Agent, but that it might include more `blocks` over time to increase and improve functionalities from other community projects.
|
||||
|
||||
To deploy the application you can simply press below `Deploy button` or you can navigate to the [Balena Hub apps page](https://hub.balena.io/apps/2064752/video-surveillance).
|
||||
|
||||
[](https://dashboard.balena-cloud.com/deploy?repoUrl=https://github.com/kerberos-io/agent)
|
||||
|
||||
You can find the source code, `balena.yaml` and `docker-compose.yaml` files in the [`balena-agent` repository](https://github.com/kerberos-io/balena-agent).
|
||||
34
deployments/binary/README.md
Normal file
@@ -0,0 +1,34 @@
|
||||
# Binary
|
||||
|
||||
Kerberos Agents are now also shipped as static binaries. Within the Docker image build, we are extracting the Kerberos Agent binary and are [uploading them to the releases page](https://github.com/kerberos-io/agent/releases) in the repository. By opening a release you'll find a `.tar` with the relevant files.
|
||||
|
||||
- `main`: this is the Kerberos Agent binary.
|
||||
- `data`: the folder containing the recorded video, configuration, etc.
|
||||
- `mp4fragment`: a binary to transform MP4s to Fragmented MP4s.
|
||||
- `www`: the Kerberos Agent ui (compiled React app).
|
||||
|
||||
You can run the binary as following on port `8080`:
|
||||
|
||||
main -action=run -port=80
|
||||
|
||||
## Systemd
|
||||
|
||||
When running on a Linux OS you might consider to auto-start the Kerberos Agent using systemd. Create a file called `/etc/systemd/system/kerberos-agent.service` and copy-paste following configuration. Update the `WorkingDirectory` and `ExecStart` accordingly.
|
||||
|
||||
[Unit]
|
||||
Wants=network.target
|
||||
[Service]
|
||||
ExecStart=/home/pi/agent/main -action=run -port=80
|
||||
WorkingDirectory=/home/pi/agent/
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
|
||||
To load your new service, we'll execute following commands.
|
||||
|
||||
sudo systemctl daemon-reload
|
||||
sudo systemctl enable kerberos-agent
|
||||
sudo systemctl start kerberos-agent
|
||||
|
||||
Confirm the service is running:
|
||||
|
||||
sudo systemctl status kerberos-agent
|
||||
92
deployments/docker/README.md
Normal file
@@ -0,0 +1,92 @@
|
||||
# Deployment with Docker
|
||||
|
||||
The easiest, and let's say most natural, deployment is done [by utilising `docker`](#1-running-a-single-container). Docker can run a stand-alone, single, Kerberos Agent (or container) and a bigger set of Kerberos Agents (or containers) [through `docker compose`](#2-running-multiple-containers-with-docker-compose).
|
||||
|
||||
## 1. Running a single container
|
||||
|
||||
We are creating Docker images as part of our CI/CD process. You'll find our Docker images on [Docker hub](https://hub.docker.com/r/kerberos/agent). Pick a specific tag of choice, or use latest. Once done run below command, this will open the web interface of your Kerberos agent on port 80.
|
||||
|
||||
docker run -p 80:80 --name mycamera -d kerberos/agent:latest
|
||||
|
||||
Or for a develop build:
|
||||
|
||||
docker run -p 80:80 --name mycamera -d kerberos/agent-dev:latest
|
||||
|
||||
Feel free to use another port if your host system already has a workload running on `80`. For example `8082`.
|
||||
|
||||
docker run -p 8082:80 --name mycamera -d kerberos/agent:latest
|
||||
|
||||
### Attach a volume
|
||||
|
||||
By default your Kerberos agent will store all its configuration and recordings inside the container. It might be interesting to store both configuration and your recordings outside the container, on your local disk. This helps persisting your storage even after you decide to wipe out your Kerberos agent.
|
||||
|
||||
You attach a volume to your container by leveraging the `-v` option. To mount your own configuration file, execute as following:
|
||||
|
||||
1. Decide where you would like to store your configuration and recordings; create a new directory for the config file and recordings folder accordingly.
|
||||
|
||||
mkdir agent
|
||||
mkdir agent/config
|
||||
mkdir agent/recordings
|
||||
|
||||
2. Once you have located your desired directory, copy the latest [`config.json`](https://github.com/kerberos-io/agent/blob/master/machinery/data/config/config.json) file into your config directory.
|
||||
|
||||
wget https://raw.githubusercontent.com/kerberos-io/agent/master/machinery/data/config/config.json -O agent/config/config.json
|
||||
|
||||
3. Run the docker command as following to attach your config directory and recording directory.
|
||||
|
||||
docker run -p 80:80 --name mycamera \
|
||||
-v $(pwd)/agent/config:/home/agent/data/config \
|
||||
-v $(pwd)/agent/recordings:/home/agent/data/recordings \
|
||||
-d --restart=always kerberos/agent:latest
|
||||
|
||||
### Override with environment variables
|
||||
|
||||
Next to attaching the configuration file, it is also possible to override the configuration with environment variables. This makes deployments when leveraging `docker compose` or `kubernetes` much easier and more scalable. Using this approach we simplify automation through `ansible` and `terraform`. You'll find [the full list of environment variables on the main README.md file](https://github.com/kerberos-io/agent#override-with-environment-variables).
|
||||
|
||||
### 2. Running multiple containers with Docker compose
|
||||
|
||||
When running multiple containers, you could execute the above process multiple times, or a better way is to run a `docker compose` with predefined configuration file, a `docker-compose.yaml`.
|
||||
|
||||
You'll find [an example `docker-compose.yaml` file here](https://github.com/kerberos-io/agent/blob/master/deployments/docker/docker-compose.yaml). This configuration file includes a definition for running 3 Kerberos Agents (or containers). By specifying environment variables you can override the internal configuration. To add more Kerberos Agents to your deployment, just `copy-paste` a `service` block and modify the name, exposed port, and settings accordingly.
|
||||
|
||||
kerberos-agent2:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8082:80"
|
||||
environment:
|
||||
- AGENT_NAME=agent2
|
||||
- AGENT_CAPTURE_IPCAMERA_RTSP=rtsp://x.x.x.x:554/Streaming/Channels/101
|
||||
- AGENT_HUB_KEY=yyy
|
||||
- AGENT_HUB_PRIVATE_KEY=yyy
|
||||
|
||||
#### Attaching volumes
|
||||
|
||||
As described in [1. Running a single container](#1-running-a-single-container) you can also assign volumes to your `docker compose` services. A volume can be added to persist the recordings of your Kerberos Agents on the host machine, or to provide more accurate configurations.
|
||||
|
||||
When attaching a volume for persisting recordings or mounting configuration files from the host system. the `docker-compose.yaml` would look like this.
|
||||
|
||||
Let's start by creating some directories on your host system. We'll consider 3 Kerberos Agents in this example.
|
||||
|
||||
mkdir -p agent1/config agent1/recordings
|
||||
mkdir -p agent2/config agent2/recordings
|
||||
mkdir -p agent3/config agent3/recordings
|
||||
|
||||
Download the configuration file in each Kerberos Agent configuration directory.
|
||||
|
||||
wget https://raw.githubusercontent.com/kerberos-io/agent/master/machinery/data/config/config.json -O agent1/config/config.json
|
||||
wget https://raw.githubusercontent.com/kerberos-io/agent/master/machinery/data/config/config.json -O agent2/config/config.json
|
||||
wget https://raw.githubusercontent.com/kerberos-io/agent/master/machinery/data/config/config.json -O agent3/config/config.json
|
||||
|
||||
Next we'll add a `volumes:` section to each Kerberos Agent (service) in the `docker-compose-with-volumes.yaml` file.
|
||||
|
||||
volumes:
|
||||
- ./agent1/config:/home/agent/data/config
|
||||
- ./agent1/recordings:/home/agent/data/recordings
|
||||
|
||||
We'll repeat that for the other Kerberos Agents as well. You can review [the final result over here](https://github.com/kerberos-io/agent/blob/master/deployments/docker/docker-compose-with-volumes.yaml).
|
||||
|
||||
Run the `docker compose` command by providing a different configuration file name.
|
||||
|
||||
docker compose -f docker-compose-with-volumes.yaml up
|
||||
|
||||
Please note that you can use a combination of using a configuration file and environment variables at the same time. However environment variables will always override the setting in your configuration file.
|
||||
27
deployments/docker/docker-compose-with-volumes.yaml
Normal file
@@ -0,0 +1,27 @@
|
||||
version: "3.9"
|
||||
services:
|
||||
kerberos-agent1:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8081:80"
|
||||
environment:
|
||||
- AGENT_NAME=agent1
|
||||
# You can still override the configuration with environment variables, but might not makes sense if you are attaching a host config.
|
||||
# find full list of environment variables here: https://github.com/kerberos-io/agent#override-with-environment-variables
|
||||
volumes:
|
||||
- ./agent1/config:/home/agent/data/config
|
||||
- ./agent1/recordings:/home/agent/data/recordings
|
||||
kerberos-agent2:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8082:80"
|
||||
volumes:
|
||||
- ./agent2/config:/home/agent/data/config
|
||||
- ./agent2/recordings:/home/agent/data/recordings
|
||||
kerberos-agent3:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8083:80"
|
||||
volumes:
|
||||
- ./agent3/config:/home/agent/data/config
|
||||
- ./agent3/recordings:/home/agent/data/recordings
|
||||
38
deployments/docker/docker-compose.yaml
Normal file
@@ -0,0 +1,38 @@
|
||||
version: "3.9"
|
||||
x-common-variables: &common-variables
|
||||
# Add variables here to add them to all agents
|
||||
AGENT_HUB_KEY: "xxxxx" # The access key linked to your account in Kerberos Hub.
|
||||
AGENT_HUB_PRIVATE_KEY: "xxxxx" # The secret access key linked to your account in Kerberos Hub.
|
||||
# find full list of environment variables here: https://github.com/kerberos-io/agent#override-with-environment-variables
|
||||
services:
|
||||
kerberos-agent1:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8081:80"
|
||||
environment:
|
||||
<<: *common-variables
|
||||
AGENT_NAME: agent1
|
||||
AGENT_CAPTURE_IPCAMERA_RTSP: rtsp://username:password@x.x.x.x/Streaming/Channels/101 # Hikvision camera RTSP url example
|
||||
AGENT_KEY: "1"
|
||||
kerberos-agent2:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8082:80"
|
||||
environment:
|
||||
<<: *common-variables
|
||||
AGENT_NAME: agent2
|
||||
AGENT_CAPTURE_IPCAMERA_RTSP: rtsp://username:password@x.x.x.x/channel1 # Linksys camera RTSP url example
|
||||
AGENT_KEY: "2"
|
||||
kerberos-agent3:
|
||||
image: "kerberos/agent:latest"
|
||||
ports:
|
||||
- "8083:80"
|
||||
environment:
|
||||
<<: *common-variables
|
||||
AGENT_NAME: agent3
|
||||
AGENT_CAPTURE_IPCAMERA_RTSP: rtsp://username:password@x.x.x.x/cam/realmonitor?channel=1&subtype=1 # Dahua camera RTSP url example
|
||||
AGENT_KEY: "3"
|
||||
networks:
|
||||
default:
|
||||
name: cluster-net
|
||||
external: true
|
||||
9
deployments/factory/README.md
Normal file
@@ -0,0 +1,9 @@
|
||||
# Deploy with Kerberos Factory
|
||||
|
||||
All of the previously deployments, `docker`, `kubernetes` and `openshift` are great for a technical audience. However for business users, it might be more convenient to have a clean web ui, that one can leverage to add one or more cameras (Kerberos Agents), without the hassle of the technical resources.
|
||||
|
||||
That's exactly why we have build [Kerberos Factory](https://github.com/kerberos-io/factory). It's a web ui on top of a Kubernetes cluster, which allows a non-technical users to administer and configure a video landscape.
|
||||
|
||||

|
||||
|
||||
The idea of [Kerberos Factory](https://github.com/kerberos-io/factory) is that one can configure and deploy a camera, by filling-in some basic input fields. Once done [Kerberos Factory](https://github.com/kerberos-io/factory), will create the relevant resources in your Kubernetes cluster.
|
||||
BIN
deployments/factory/factory-login.gif
Normal file
|
After Width: | Height: | Size: 1.4 MiB |
111
deployments/kubernetes/README.md
Normal file
@@ -0,0 +1,111 @@
|
||||
# Deployment with Kubernetes
|
||||
|
||||
As described in the [Deployment with Docker](https://github.com/kerberos-io/agent/tree/master/deployments/docker), `docker` is a great tool for smaller deployments, where you are just running on a single machine and want to ramp up quickly. As you might expect, this is a not an ideal situation for production deployments.
|
||||
|
||||
Kubernetes can help you to build a scalable, flexible and resilient deployment. By introducing the concept of multi-nodes and deployments, you can make sure your Kerberos Agents are evenly distributed across your different machines, and you can add more nodes when you need to scale out.
|
||||
|
||||
We've provided an example deployment `deployment-agent.yml` in this directory, which show case you have to create a deployment (and under the hood a pod), to run a Kerberos Agent workload.
|
||||
|
||||
## Create a Kerberos Agent deployment
|
||||
|
||||
It's always a best practices to isolate and structure your workloads in Kubernetes. To achieve this we are utilising the concept of namespaces. For this example we will create a new namespace `demo`.
|
||||
|
||||
kubectl create namespace demo
|
||||
|
||||
Now we have a namespace, have a look at `deployment-agent.yml` in this folder. This configuration file describes the Kubernetes resources we would like to create, and how the Kerberos Agent needs to behave: environment variables, container ports, etc. At the bottom of the file, we find a `service` part, this tells Kubernetes to expose the Kerberos Agent user interface on a publicly accessible IP address. **_Please note that you don't need to expose this, as you can configure the Kerberos Agent with a volume and/or environment variables._**
|
||||
|
||||
Let's move on, and apply the Kerberos Agent deployment and service.
|
||||
|
||||
kubectl apply -f deployment-agent.yml -n demo
|
||||
|
||||
Watch deployment and service to be ready.
|
||||
|
||||
watch kubectl get all -n demo
|
||||
|
||||
When the deployment and service is created successfully, you should see something like this.
|
||||
|
||||
Every 2.0s: kubectl get all -n demo Fri Dec 9 16:33:17 2022
|
||||
|
||||
NAME READY STATUS RESTARTS AGE
|
||||
pod/agent-7c75c4dbcf-zxrb5 1/1 Running 0 19s
|
||||
|
||||
NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE
|
||||
service/agent-svc LoadBalancer 10.x.x.x 108.x.x.x 80:32664/TCP 20s
|
||||
|
||||
NAME READY UP-TO-DATE AVAILABLE AGE
|
||||
deployment.apps/agent 1/1 1 1 20s
|
||||
|
||||
NAME DESIRED CURRENT READY AGE
|
||||
replicaset.apps/agent-7c75c4dbcf 1 1 1 20s
|
||||
|
||||
When copying the `EXTERNAL-IP` and pasting it in your browser, you should see the Kerberos Agent user interface. You can use [the default username and password to sign-in](https://github.com/kerberos-io/agent#access-the-kerberos-agent), or if changed to your own (which is recommended).
|
||||
|
||||
## Configure with volumes
|
||||
|
||||
Just like with `docker`, you can also attach `volumes` to the Kerberos Agent deployment, by creating a `Persistent Volume` and mount it to a specific directory.
|
||||
|
||||
Depending on where and how you are hosting the Kubernetes cluster, you may need to create a new `storageClass` or use a predefined `storageClass` from your cloud provider (Azure, GCP, AWS, ..). Have a look at `deployment-agent-volume.yml` to review a complete example.
|
||||
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: agent
|
||||
spec:
|
||||
volumes:
|
||||
- name: kerberos-data
|
||||
persistentVolumeClaim:
|
||||
claimName: kerberos-data
|
||||
...
|
||||
containers:
|
||||
- name: agent
|
||||
image: kerberos/agent:latest
|
||||
volumeMounts:
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/config
|
||||
subPath: config
|
||||
...
|
||||
|
||||
## Expose with Ingress
|
||||
|
||||
In the first example `deployment-agent.yml` we are using a `LoadBalancer` to expose the Kerberos Agent user interface; as shown below. If you are a bit more experienced with Kubernetes, you will know there are other `service types` as well.
|
||||
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
...
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- port: 80
|
||||
...
|
||||
|
||||
An alternative to `LoadBalancer` is `Ingress`. By leveraging an ingress such as `ingress-nginx` or `traefik` you setup a gateway (single point of contact), through which all communication to your apps (services) will flow.
|
||||
|
||||
A huge benefit (there are many others), is that you only allocate 1 public IP address for all your services. So instead of creating a `LoadBalancer` and thus a public IP address for every agent, you will create an `Ingress` service for each agent. Review the complete example at `deployment-agent-with-ingress.yml`.
|
||||
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: agent-ingress
|
||||
labels:
|
||||
name: agent-ingress
|
||||
annotations:
|
||||
kubernetes.io/ingress.class: nginx
|
||||
kubernetes.io/tls-acme: "true"
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
cert-manager.io/cluster-issuer: "letsencrypt-prod"
|
||||
spec:
|
||||
tls:
|
||||
- hosts:
|
||||
- "myagent.kerberos.io"
|
||||
secretName: agent-secret
|
||||
rules:
|
||||
- host: myagent.kerberos.io
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: agent-svc
|
||||
port:
|
||||
number: 80
|
||||
54
deployments/kubernetes/deployment-agent-volume.yml
Normal file
@@ -0,0 +1,54 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: agent
|
||||
labels:
|
||||
name: agent
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: agent
|
||||
replicas: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: agent
|
||||
spec:
|
||||
volumes:
|
||||
- name: kerberos-data
|
||||
persistentVolumeClaim:
|
||||
claimName: kerberos-data
|
||||
|
||||
initContainers:
|
||||
- name: download-config
|
||||
image: kerberos/agent:latest
|
||||
volumeMounts:
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/config
|
||||
subPath: config
|
||||
command:
|
||||
[
|
||||
"cp",
|
||||
"/home/agent/data/config.template.json",
|
||||
"/home/agent/data/config/config.json",
|
||||
]
|
||||
|
||||
containers:
|
||||
- name: agent
|
||||
image: kerberos/agent:latest
|
||||
volumeMounts:
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/config
|
||||
subPath: config
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/recordings
|
||||
subPath: recordings
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/snapshots
|
||||
subPath: snapshots
|
||||
- name: kerberos-data
|
||||
mountPath: /home/agent/data/cloud
|
||||
subPath: cloud
|
||||
ports:
|
||||
- containerPort: 80
|
||||
protocol: TCP
|
||||
82
deployments/kubernetes/deployment-agent-with-ingress.yml
Normal file
@@ -0,0 +1,82 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: agent
|
||||
labels:
|
||||
name: agent
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: agent
|
||||
replicas: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: agent
|
||||
spec:
|
||||
containers:
|
||||
- name: agent
|
||||
image: kerberos/agent:latest
|
||||
ports:
|
||||
- containerPort: 80
|
||||
protocol: TCP
|
||||
resources:
|
||||
limits:
|
||||
cpu: 1000m
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
env:
|
||||
- name: AGENT_NAME
|
||||
value: demo-agent
|
||||
- name: AGENT_CAPTURE_IPCAMERA_RTSP
|
||||
value: rtsp://fake.kerberos.io/stream
|
||||
- name: AGENT_HUB_KEY
|
||||
value: yyy
|
||||
- name: AGENT_HUB_PRIVATE_KEY
|
||||
value: yyy
|
||||
# find full list of environment variables here: https://github.com/kerberos-io/agent#override-with-environment-variables
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: agent-svc
|
||||
labels:
|
||||
name: agent-svc
|
||||
spec:
|
||||
#type: LoadBalancer
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
selector:
|
||||
app: agent
|
||||
---
|
||||
apiVersion: networking.k8s.io/v1
|
||||
kind: Ingress
|
||||
metadata:
|
||||
name: agent-ingress
|
||||
labels:
|
||||
name: agent-ingress
|
||||
annotations:
|
||||
kubernetes.io/ingress.class: nginx
|
||||
kubernetes.io/tls-acme: "true"
|
||||
nginx.ingress.kubernetes.io/ssl-redirect: "true"
|
||||
cert-manager.io/cluster-issuer: "letsencrypt-prod"
|
||||
spec:
|
||||
tls:
|
||||
- hosts:
|
||||
- "demo.kerberos.io"
|
||||
secretName: agent-secret
|
||||
rules:
|
||||
- host: demo.kerberos.io
|
||||
http:
|
||||
paths:
|
||||
- pathType: Prefix
|
||||
path: "/"
|
||||
backend:
|
||||
service:
|
||||
name: agent-svc
|
||||
port:
|
||||
number: 80
|
||||
|
||||
53
deployments/kubernetes/deployment-agent.yml
Normal file
@@ -0,0 +1,53 @@
|
||||
apiVersion: apps/v1
|
||||
kind: Deployment
|
||||
metadata:
|
||||
name: agent
|
||||
labels:
|
||||
name: agent
|
||||
spec:
|
||||
selector:
|
||||
matchLabels:
|
||||
app: agent
|
||||
replicas: 1
|
||||
template:
|
||||
metadata:
|
||||
labels:
|
||||
app: agent
|
||||
spec:
|
||||
containers:
|
||||
- name: agent
|
||||
image: kerberos/agent:3.2.3
|
||||
ports:
|
||||
- containerPort: 80
|
||||
protocol: TCP
|
||||
resources:
|
||||
limits:
|
||||
cpu: 1000m
|
||||
memory: 512Mi
|
||||
requests:
|
||||
cpu: 100m
|
||||
memory: 128Mi
|
||||
env:
|
||||
- name: AGENT_NAME
|
||||
value: demo-agent
|
||||
- name: AGENT_CAPTURE_IPCAMERA_RTSP
|
||||
value: rtsp://fake.kerberos.io/stream
|
||||
- name: AGENT_HUB_KEY
|
||||
value: yyy
|
||||
- name: AGENT_HUB_PRIVATE_KEY
|
||||
value: yyy
|
||||
# find full list of environment variables here: https://github.com/kerberos-io/agent#override-with-environment-variables
|
||||
---
|
||||
apiVersion: v1
|
||||
kind: Service
|
||||
metadata:
|
||||
name: agent-svc
|
||||
labels:
|
||||
name: agent-svc
|
||||
spec:
|
||||
type: LoadBalancer
|
||||
ports:
|
||||
- port: 80
|
||||
targetPort: 80
|
||||
selector:
|
||||
app: agent
|
||||
15
deployments/snap/README.md
Normal file
@@ -0,0 +1,15 @@
|
||||
# Deployment with Snap Store
|
||||
|
||||
By browsing to the Snap Store, you'll be able [to find our own snap `Kerberos Agent`](https://snapcraft.io/kerberosio). You can either install the `Kerberos Agent` through the command line.
|
||||
|
||||
snap install kerberosio
|
||||
|
||||
Or use the Desktop client to have a visual interface.
|
||||
|
||||

|
||||
|
||||
Once installed you can find your Kerberos Agent configration at `/var/snap/kerberosio/common`. Run the Kerberos Agent as following.
|
||||
|
||||
sudo kerberosio.agent -action=run -port=80
|
||||
|
||||
If successfull you'll be able to browse to port `80` or if you defined a different port. This will open the Kerberos Agent interface.
|
||||
BIN
deployments/snap/snapstore.png
Normal file
|
After Width: | Height: | Size: 616 KiB |
41
deployments/terraform/README.md
Normal file
@@ -0,0 +1,41 @@
|
||||
# Deployment with Terraform
|
||||
|
||||
If you are using Terraform as part of your DevOps stack, you might utilise it to deploy your Kerberos Agents. Within this deployment folder we have added an example Terraform file `docker.tf`, which installs the Kerberos Agent `docker` container on a remote system over `SSH`. We might create our own provider in the future, or add additional examples for example `snap`, `kubernetes`, etc.
|
||||
|
||||
For this example we will install Kerberos Agent using `docker` on a remote `linux` machine. Therefore we'll make sure we have the `TelkomIndonesia/linux` provider initialised.
|
||||
|
||||
terraform init
|
||||
|
||||
Once initialised you should see similar output:
|
||||
|
||||
Initializing the backend...
|
||||
|
||||
Initializing provider plugins...
|
||||
- Reusing previous version of telkomindonesia/linux from the dependency lock file
|
||||
- Using previously-installed telkomindonesia/linux v0.7.0
|
||||
|
||||
Go and open the `docker.tf` file and locate the `linux` provider, modify following credentials accordingly. Make sure they match for creating an `SSH` connection.
|
||||
|
||||
provider "linux" {
|
||||
host = "x.y.z.u"
|
||||
port = 22
|
||||
user = "root"
|
||||
password = "password"
|
||||
}
|
||||
|
||||
Apply the `docker.tf` file, to install `docker` and the `kerberos/agent` docker container.
|
||||
|
||||
terraform apply
|
||||
|
||||
Once done you should see following output, and you should be able to reach the remote machine on port `80` or if configured differently the specified port you've defined.
|
||||
|
||||
Do you want to perform these actions?
|
||||
Terraform will perform the actions described above.
|
||||
Only 'yes' will be accepted to approve.
|
||||
|
||||
Enter a value: yes
|
||||
|
||||
linux_script.install_docker_kerberos_agent: Modifying... [id=a56cf7b0-db66-4f9b-beec-8a4dcef2a0c7]
|
||||
linux_script.install_docker_kerberos_agent: Modifications complete after 3s [id=a56cf7b0-db66-4f9b-beec-8a4dcef2a0c7]
|
||||
|
||||
Apply complete! Resources: 0 added, 1 changed, 0 destroyed.
|
||||
47
deployments/terraform/docker.tf
Normal file
@@ -0,0 +1,47 @@
|
||||
terraform {
|
||||
required_providers {
|
||||
linux = {
|
||||
source = "TelkomIndonesia/linux"
|
||||
version = "0.7.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
provider "linux" {
|
||||
host = "x.y.z.u"
|
||||
port = 22
|
||||
user = "root"
|
||||
password = "password"
|
||||
}
|
||||
|
||||
locals {
|
||||
image = "kerberos/agent"
|
||||
version = "latest"
|
||||
port = 80
|
||||
}
|
||||
|
||||
resource "linux_script" "install_docker" {
|
||||
lifecycle_commands {
|
||||
create = "apt update && apt install -y $PACKAGE_NAME"
|
||||
read = "apt-cache policy $PACKAGE_NAME | grep 'Installed:' | grep -v '(none)' | awk '{ print $2 }' | xargs | tr -d '\n'"
|
||||
update = "apt update && apt install -y $PACKAGE_NAME"
|
||||
delete = "apt remove -y $PACKAGE_NAME"
|
||||
}
|
||||
environment = {
|
||||
PACKAGE_NAME = "docker"
|
||||
}
|
||||
}
|
||||
|
||||
resource "linux_script" "install_docker_kerberos_agent" {
|
||||
lifecycle_commands {
|
||||
create = "docker pull $IMAGE:$VERSION && docker run -d -p $PORT:80 --name agent $IMAGE:$VERSION"
|
||||
read = "docker inspect agent"
|
||||
update = "docker pull $IMAGE:$VERSION && docker rm agent --force && docker run -d -p $PORT:80 --name agent $IMAGE:$VERSION"
|
||||
delete = "docker rm agent --force"
|
||||
}
|
||||
environment = {
|
||||
IMAGE = local.image
|
||||
VERSION = local.version
|
||||
PORT = local.port
|
||||
}
|
||||
}
|
||||
12
examples/frame-processor/Dockerfile
Normal file
@@ -0,0 +1,12 @@
|
||||
FROM golang:1.24-bookworm AS build
|
||||
|
||||
WORKDIR /src
|
||||
COPY go.mod go.sum ./
|
||||
RUN go mod download
|
||||
COPY . .
|
||||
RUN CGO_ENABLED=0 go build -trimpath -o /frame-processor .
|
||||
|
||||
FROM gcr.io/distroless/static-debian12:nonroot
|
||||
COPY --from=build /frame-processor /frame-processor
|
||||
EXPOSE 8080
|
||||
ENTRYPOINT ["/frame-processor"]
|
||||
88
examples/frame-processor/MQTT.md
Normal file
@@ -0,0 +1,88 @@
|
||||
# MQTT control contract
|
||||
|
||||
The Frame Processor publishes control messages to
|
||||
`kerberos/agent/<hubKey>`. Each message targets one Agent through the envelope's
|
||||
`device_id`. It subscribes to `kerberos/hub/<hubKey>` for correlated status
|
||||
events.
|
||||
|
||||
MQTT transports control data only. JPEG frames use `POST /v1/frames` and full
|
||||
recordings use the Agent's existing Vault upload path.
|
||||
|
||||
## Envelope
|
||||
|
||||
```json
|
||||
{
|
||||
"mid": "0c556fc7-637b-4b2a-8a90-2d1cf8450956",
|
||||
"device_id": "camera-1",
|
||||
"timestamp": 1789380000,
|
||||
"encrypted": false,
|
||||
"hidden": false,
|
||||
"public_key": "",
|
||||
"fingerprint": "",
|
||||
"payload": {
|
||||
"version": "1.0",
|
||||
"action": "capture-frame",
|
||||
"device_id": "camera-1",
|
||||
"signature": "",
|
||||
"encrypted_value": "",
|
||||
"hidden_value": "",
|
||||
"value": {}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
The reference service publishes plaintext envelopes for local contract testing.
|
||||
Production deployment must use a trusted broker and should adopt the Agent's
|
||||
encrypted-message packaging before commands cross an untrusted broker.
|
||||
|
||||
## `capture-frame`
|
||||
|
||||
```json
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"requestId": "request-1",
|
||||
"processingProfile": "always-trigger",
|
||||
"expiresAt": 1789380030000,
|
||||
"traceId": "optional-trace-id"
|
||||
}
|
||||
```
|
||||
|
||||
## `request-recording-window`
|
||||
|
||||
```json
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"requestId": "request-1",
|
||||
"frameId": "frame-1",
|
||||
"capturedAt": 1789380000123,
|
||||
"preRollSeconds": 10,
|
||||
"eventClipSeconds": 30,
|
||||
"expiresAt": 1789380030000,
|
||||
"processingProfile": "always-trigger",
|
||||
"traceId": "optional-trace-id"
|
||||
}
|
||||
```
|
||||
|
||||
`capturedAt` is generated by the Agent and must be echoed unchanged. The Agent
|
||||
uses `requestId` for command idempotency and selects the local recording that
|
||||
contains `capturedAt`.
|
||||
|
||||
## `frame-processing-status`
|
||||
|
||||
```json
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"requestId": "request-1",
|
||||
"frameId": "frame-1",
|
||||
"deviceId": "camera-1",
|
||||
"status": "queued",
|
||||
"occurredAt": 1789380001000,
|
||||
"retryable": false,
|
||||
"message": "",
|
||||
"traceId": "optional-trace-id"
|
||||
}
|
||||
```
|
||||
|
||||
Expected statuses are `accepted`, `captured`, `submitted`, `no-event`, `event`,
|
||||
`pending-finalisation`, `queued`, `uploaded`, `expired`, `not-found`, `rejected`,
|
||||
and `failed`.
|
||||
74
examples/frame-processor/README.md
Normal file
@@ -0,0 +1,74 @@
|
||||
# Example Frame Processor
|
||||
|
||||
This reference service defines and exercises the Kerberos Agent frame-processing
|
||||
contract. It accepts Agent JPEGs over HTTP, makes a deterministic decision, and
|
||||
publishes Agent control commands over MQTT. It has no RabbitMQ or machine-learning
|
||||
runtime dependency.
|
||||
|
||||
## Endpoints
|
||||
|
||||
- `GET /health`
|
||||
- `POST /v1/frames` with multipart `metadata` JSON and `frame` JPEG parts
|
||||
- `POST /v1/frame-requests` with JSON to request capture from one or more Agents
|
||||
|
||||
See [openapi.yaml](openapi.yaml) and [MQTT.md](MQTT.md) for the versioned wire
|
||||
contracts.
|
||||
|
||||
## Run
|
||||
|
||||
```bash
|
||||
export FRAME_PROCESSOR_API_TOKEN=development-token
|
||||
export FRAME_PROCESSOR_MQTT_URI=tcp://localhost:1883
|
||||
export FRAME_PROCESSOR_HUB_KEY=development-hub
|
||||
export FRAME_PROCESSOR_PROFILE=never-trigger
|
||||
go run .
|
||||
```
|
||||
|
||||
The broker credentials are optional when the local broker permits anonymous
|
||||
connections:
|
||||
|
||||
```bash
|
||||
export FRAME_PROCESSOR_MQTT_USERNAME=...
|
||||
export FRAME_PROCESSOR_MQTT_PASSWORD=...
|
||||
```
|
||||
|
||||
Request a frame from an Agent:
|
||||
|
||||
```bash
|
||||
curl --fail-with-body \
|
||||
-H 'Authorization: Bearer development-token' \
|
||||
-H 'Content-Type: application/json' \
|
||||
--data @testdata/frame-request.json \
|
||||
http://localhost:8080/v1/frame-requests
|
||||
```
|
||||
|
||||
## Profiles
|
||||
|
||||
- `never-trigger`
|
||||
- `always-trigger`
|
||||
- `every-nth-frame`
|
||||
- `brightness-threshold`
|
||||
|
||||
Use `FRAME_PROCESSOR_EVERY_N` and `FRAME_PROCESSOR_BRIGHTNESS_THRESHOLD` to tune
|
||||
the last two profiles. `FRAME_PROCESSOR_DELAY_MILLISECONDS` and
|
||||
`FRAME_PROCESSOR_FORCE_ERROR` provide deterministic latency and failure
|
||||
simulation.
|
||||
|
||||
Recording commands default to a 30-second event clip with 10 seconds of pre-roll.
|
||||
Configure them with `FRAME_PROCESSOR_EVENT_CLIP_SECONDS` and
|
||||
`FRAME_PROCESSOR_PRE_ROLL_SECONDS`.
|
||||
|
||||
The reference MQTT publisher emits plaintext Agent envelopes for local contract
|
||||
testing. Use a trusted broker. Production support for untrusted brokers requires
|
||||
the same encrypted-message packaging used by Hub and Agent.
|
||||
|
||||
Frame idempotency is guaranteed until the submitted frame's `expiresAt`. The
|
||||
service rejects frame TTLs longer than `FRAME_PROCESSOR_MAX_FRAME_TTL_SECONDS`
|
||||
(five minutes by default), then evicts the cached result at expiry.
|
||||
|
||||
## Verify
|
||||
|
||||
```bash
|
||||
GOWORK=off go test ./...
|
||||
GOWORK=off go vet ./...
|
||||
```
|
||||
162
examples/frame-processor/contract/contract.go
Normal file
@@ -0,0 +1,162 @@
|
||||
package contract
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
)
|
||||
|
||||
const (
|
||||
SchemaVersion = "1.0"
|
||||
MaxImageDimension = 8192
|
||||
|
||||
ActionCaptureFrame = "capture-frame"
|
||||
ActionRequestRecordingWindow = "request-recording-window"
|
||||
ActionFrameStatus = "frame-processing-status"
|
||||
)
|
||||
|
||||
type FrameMetadata struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId"`
|
||||
FrameID string `json:"frameId"`
|
||||
DeviceID string `json:"deviceId"`
|
||||
CapturedAt int64 `json:"capturedAt"`
|
||||
ExpiresAt int64 `json:"expiresAt"`
|
||||
ProcessingProfile string `json:"processingProfile"`
|
||||
SourceStream string `json:"sourceStream"`
|
||||
Width int `json:"width"`
|
||||
Height int `json:"height"`
|
||||
TraceID string `json:"traceId,omitempty"`
|
||||
}
|
||||
|
||||
func (m FrameMetadata) Validate(nowMillis int64) error {
|
||||
if m.SchemaVersion != SchemaVersion {
|
||||
return fmt.Errorf("unsupported schemaVersion %q", m.SchemaVersion)
|
||||
}
|
||||
if m.RequestID == "" || m.FrameID == "" || m.DeviceID == "" {
|
||||
return errors.New("requestId, frameId, and deviceId are required")
|
||||
}
|
||||
if m.CapturedAt <= 0 {
|
||||
return errors.New("capturedAt must be a positive Unix millisecond timestamp")
|
||||
}
|
||||
if m.ExpiresAt <= m.CapturedAt {
|
||||
return errors.New("expiresAt must be later than capturedAt")
|
||||
}
|
||||
if nowMillis > 0 && m.ExpiresAt <= nowMillis {
|
||||
return errors.New("frame has expired")
|
||||
}
|
||||
if m.ProcessingProfile == "" {
|
||||
return errors.New("processingProfile is required")
|
||||
}
|
||||
if m.SourceStream != "main" && m.SourceStream != "sub" {
|
||||
return errors.New("sourceStream must be main or sub")
|
||||
}
|
||||
if m.Width <= 0 || m.Height <= 0 || m.Width > MaxImageDimension || m.Height > MaxImageDimension {
|
||||
return fmt.Errorf("width and height must be between 1 and %d", MaxImageDimension)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type FrameRequest struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId,omitempty"`
|
||||
DeviceIDs []string `json:"deviceIds"`
|
||||
ProcessingProfile string `json:"processingProfile"`
|
||||
ExpiresAt int64 `json:"expiresAt"`
|
||||
TraceID string `json:"traceId,omitempty"`
|
||||
}
|
||||
|
||||
func (r FrameRequest) Validate(nowMillis int64) error {
|
||||
if r.SchemaVersion != SchemaVersion {
|
||||
return fmt.Errorf("unsupported schemaVersion %q", r.SchemaVersion)
|
||||
}
|
||||
if len(r.DeviceIDs) == 0 {
|
||||
return errors.New("at least one deviceId is required")
|
||||
}
|
||||
for _, deviceID := range r.DeviceIDs {
|
||||
if deviceID == "" {
|
||||
return errors.New("deviceIds cannot contain empty values")
|
||||
}
|
||||
}
|
||||
if r.ProcessingProfile == "" {
|
||||
return errors.New("processingProfile is required")
|
||||
}
|
||||
if r.ExpiresAt <= nowMillis {
|
||||
return errors.New("expiresAt must be in the future")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type CaptureFrameCommand struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId"`
|
||||
ProcessingProfile string `json:"processingProfile"`
|
||||
ExpiresAt int64 `json:"expiresAt"`
|
||||
TraceID string `json:"traceId,omitempty"`
|
||||
}
|
||||
|
||||
type RecordingWindowCommand struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId"`
|
||||
FrameID string `json:"frameId"`
|
||||
CapturedAt int64 `json:"capturedAt"`
|
||||
PreRollSeconds int64 `json:"preRollSeconds"`
|
||||
EventClipSeconds int64 `json:"eventClipSeconds"`
|
||||
ExpiresAt int64 `json:"expiresAt"`
|
||||
ProcessingProfile string `json:"processingProfile"`
|
||||
TraceID string `json:"traceId,omitempty"`
|
||||
}
|
||||
|
||||
func (c RecordingWindowCommand) Validate(nowMillis int64) error {
|
||||
if c.SchemaVersion != SchemaVersion {
|
||||
return fmt.Errorf("unsupported schemaVersion %q", c.SchemaVersion)
|
||||
}
|
||||
if c.RequestID == "" || c.FrameID == "" {
|
||||
return errors.New("requestId and frameId are required")
|
||||
}
|
||||
if c.CapturedAt <= 0 {
|
||||
return errors.New("capturedAt must be a positive Unix millisecond timestamp")
|
||||
}
|
||||
if c.EventClipSeconds <= 0 {
|
||||
return errors.New("eventClipSeconds must be positive")
|
||||
}
|
||||
if c.PreRollSeconds < 0 || c.PreRollSeconds > c.EventClipSeconds {
|
||||
return errors.New("preRollSeconds must be between zero and eventClipSeconds")
|
||||
}
|
||||
if c.ExpiresAt <= nowMillis {
|
||||
return errors.New("expiresAt must be in the future")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type StatusEvent struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId"`
|
||||
FrameID string `json:"frameId,omitempty"`
|
||||
DeviceID string `json:"deviceId"`
|
||||
Status string `json:"status"`
|
||||
OccurredAt int64 `json:"occurredAt"`
|
||||
Retryable bool `json:"retryable,omitempty"`
|
||||
Message string `json:"message,omitempty"`
|
||||
TraceID string `json:"traceId,omitempty"`
|
||||
}
|
||||
|
||||
type MQTTMessage struct {
|
||||
MID string `json:"mid"`
|
||||
DeviceID string `json:"device_id"`
|
||||
Timestamp int64 `json:"timestamp"`
|
||||
Encrypted bool `json:"encrypted"`
|
||||
Hidden bool `json:"hidden"`
|
||||
PublicKey string `json:"public_key"`
|
||||
Fingerprint string `json:"fingerprint"`
|
||||
Payload MQTTPayload `json:"payload"`
|
||||
}
|
||||
|
||||
type MQTTPayload struct {
|
||||
Version string `json:"version"`
|
||||
Action string `json:"action"`
|
||||
DeviceID string `json:"device_id"`
|
||||
Signature string `json:"signature"`
|
||||
EncryptedValue string `json:"encrypted_value"`
|
||||
HiddenValue string `json:"hidden_value"`
|
||||
Value any `json:"value"`
|
||||
}
|
||||
73
examples/frame-processor/contract/contract_test.go
Normal file
@@ -0,0 +1,73 @@
|
||||
package contract
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"os"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestFrameMetadataValidate(t *testing.T) {
|
||||
now := int64(1_000)
|
||||
metadata := FrameMetadata{
|
||||
SchemaVersion: SchemaVersion,
|
||||
RequestID: "request-1",
|
||||
FrameID: "frame-1",
|
||||
DeviceID: "device-1",
|
||||
CapturedAt: 900,
|
||||
ExpiresAt: 1_100,
|
||||
ProcessingProfile: "always-trigger",
|
||||
SourceStream: "sub",
|
||||
Width: 640,
|
||||
Height: 480,
|
||||
}
|
||||
|
||||
if err := metadata.Validate(now); err != nil {
|
||||
t.Fatalf("Validate() error = %v", err)
|
||||
}
|
||||
|
||||
metadata.ExpiresAt = now
|
||||
if err := metadata.Validate(now); err == nil {
|
||||
t.Fatal("Validate() accepted an expired frame")
|
||||
}
|
||||
}
|
||||
|
||||
func TestRecordingWindowCommandValidate(t *testing.T) {
|
||||
command := RecordingWindowCommand{
|
||||
SchemaVersion: SchemaVersion,
|
||||
RequestID: "request-1",
|
||||
FrameID: "frame-1",
|
||||
CapturedAt: 900,
|
||||
PreRollSeconds: 10,
|
||||
EventClipSeconds: 30,
|
||||
ExpiresAt: 2_000,
|
||||
}
|
||||
|
||||
if err := command.Validate(1_000); err != nil {
|
||||
t.Fatalf("Validate() error = %v", err)
|
||||
}
|
||||
|
||||
command.PreRollSeconds = 31
|
||||
if err := command.Validate(1_000); err == nil {
|
||||
t.Fatal("Validate() accepted pre-roll longer than the event clip")
|
||||
}
|
||||
}
|
||||
|
||||
func TestContractFixturesDecode(t *testing.T) {
|
||||
tests := []struct {
|
||||
path string
|
||||
target any
|
||||
}{
|
||||
{"../testdata/frame-request.json", &FrameRequest{}},
|
||||
{"../testdata/capture-frame.json", &CaptureFrameCommand{}},
|
||||
{"../testdata/request-recording-window.json", &RecordingWindowCommand{}},
|
||||
}
|
||||
for _, test := range tests {
|
||||
value, err := os.ReadFile(test.path)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := json.Unmarshal(value, test.target); err != nil {
|
||||
t.Fatalf("decode %s: %v", test.path, err)
|
||||
}
|
||||
}
|
||||
}
|
||||
11
examples/frame-processor/go.mod
Normal file
@@ -0,0 +1,11 @@
|
||||
module github.com/kerberos-io/agent/examples/frame-processor
|
||||
|
||||
go 1.24.2
|
||||
|
||||
require github.com/eclipse/paho.mqtt.golang v1.5.0
|
||||
|
||||
require (
|
||||
github.com/gorilla/websocket v1.5.3 // indirect
|
||||
golang.org/x/net v0.27.0 // indirect
|
||||
golang.org/x/sync v0.7.0 // indirect
|
||||
)
|
||||
8
examples/frame-processor/go.sum
Normal file
@@ -0,0 +1,8 @@
|
||||
github.com/eclipse/paho.mqtt.golang v1.5.0 h1:EH+bUVJNgttidWFkLLVKaQPGmkTUfQQqjOsyvMGvD6o=
|
||||
github.com/eclipse/paho.mqtt.golang v1.5.0/go.mod h1:du/2qNQVqJf/Sqs4MEL77kR8QTqANF7XU7Fk0aOTAgk=
|
||||
github.com/gorilla/websocket v1.5.3 h1:saDtZ6Pbx/0u+bgYQ3q96pZgCzfhKXGPqt7kZ72aNNg=
|
||||
github.com/gorilla/websocket v1.5.3/go.mod h1:YR8l580nyteQvAITg2hZ9XVh4b55+EU/adAjf1fMHhE=
|
||||
golang.org/x/net v0.27.0 h1:5K3Njcw06/l2y9vpGCSdcxWOYHOUk3dVNGDXN+FvAys=
|
||||
golang.org/x/net v0.27.0/go.mod h1:dDi0PyhWNoiUOrAS8uXv/vnScO4wnHQO4mj9fn/RytE=
|
||||
golang.org/x/sync v0.7.0 h1:YsImfSBoP9QPYL0xyKJPq0gcaJdG3rInoqxTWbfQu9M=
|
||||
golang.org/x/sync v0.7.0/go.mod h1:Czt+wKu1gCyEFDUtn0jG5QVvpJ6rzVqr5aXyt9drQfk=
|
||||
184
examples/frame-processor/main.go
Normal file
@@ -0,0 +1,184 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"os"
|
||||
"os/signal"
|
||||
"strconv"
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/mqttpublisher"
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/processor"
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/service"
|
||||
)
|
||||
|
||||
func main() {
|
||||
config, err := loadConfig()
|
||||
if err != nil {
|
||||
slog.Error("invalid configuration", "error", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
publisher, err := mqttpublisher.New(config.mqtt, func(status contract.StatusEvent) {
|
||||
slog.Info("Agent frame-processing status",
|
||||
"deviceId", status.DeviceID,
|
||||
"requestId", status.RequestID,
|
||||
"frameId", status.FrameID,
|
||||
"status", status.Status,
|
||||
)
|
||||
})
|
||||
if err != nil {
|
||||
slog.Error("failed to initialize MQTT", "error", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
defer publisher.Close()
|
||||
|
||||
engine := processor.New(config.processor)
|
||||
application := service.New(config.service, engine, publisher, nil)
|
||||
server := &http.Server{
|
||||
Addr: config.address,
|
||||
Handler: application.Handler(),
|
||||
ReadHeaderTimeout: 5 * time.Second,
|
||||
IdleTimeout: 60 * time.Second,
|
||||
}
|
||||
|
||||
ctx, stop := signal.NotifyContext(context.Background(), syscall.SIGINT, syscall.SIGTERM)
|
||||
defer stop()
|
||||
go func() {
|
||||
<-ctx.Done()
|
||||
shutdownContext, cancel := context.WithTimeout(context.Background(), 10*time.Second)
|
||||
defer cancel()
|
||||
_ = server.Shutdown(shutdownContext)
|
||||
}()
|
||||
|
||||
slog.Info("Frame Processor listening", "address", config.address, "profile", config.processor.DefaultProfile)
|
||||
if err := server.ListenAndServe(); err != nil && !errors.Is(err, http.ErrServerClosed) {
|
||||
slog.Error("Frame Processor stopped", "error", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
}
|
||||
|
||||
type applicationConfig struct {
|
||||
address string
|
||||
mqtt mqttpublisher.Config
|
||||
processor processor.Config
|
||||
service service.Config
|
||||
}
|
||||
|
||||
func loadConfig() (applicationConfig, error) {
|
||||
brightnessThreshold := envInt("FRAME_PROCESSOR_BRIGHTNESS_THRESHOLD", 200)
|
||||
config := applicationConfig{
|
||||
address: envString("FRAME_PROCESSOR_ADDRESS", ":8080"),
|
||||
mqtt: mqttpublisher.Config{
|
||||
BrokerURI: os.Getenv("FRAME_PROCESSOR_MQTT_URI"),
|
||||
Username: os.Getenv("FRAME_PROCESSOR_MQTT_USERNAME"),
|
||||
Password: os.Getenv("FRAME_PROCESSOR_MQTT_PASSWORD"),
|
||||
HubKey: os.Getenv("FRAME_PROCESSOR_HUB_KEY"),
|
||||
ClientID: os.Getenv("FRAME_PROCESSOR_MQTT_CLIENT_ID"),
|
||||
Timeout: envDurationSeconds("FRAME_PROCESSOR_MQTT_TIMEOUT_SECONDS", 10),
|
||||
},
|
||||
processor: processor.Config{
|
||||
DefaultProfile: envString("FRAME_PROCESSOR_PROFILE", processor.ProfileNeverTrigger),
|
||||
EveryN: envInt("FRAME_PROCESSOR_EVERY_N", 2),
|
||||
BrightnessThreshold: uint8(brightnessThreshold),
|
||||
Delay: envDurationMillis("FRAME_PROCESSOR_DELAY_MILLISECONDS", 0),
|
||||
ForceError: envBool("FRAME_PROCESSOR_FORCE_ERROR", false),
|
||||
},
|
||||
service: service.Config{
|
||||
APIToken: os.Getenv("FRAME_PROCESSOR_API_TOKEN"),
|
||||
MaxFrameBytes: int64(envInt("FRAME_PROCESSOR_MAX_FRAME_BYTES", 4<<20)),
|
||||
MaxFrameTTL: envDurationSeconds("FRAME_PROCESSOR_MAX_FRAME_TTL_SECONDS", 300),
|
||||
CommandTTL: envDurationSeconds("FRAME_PROCESSOR_COMMAND_TTL_SECONDS", 30),
|
||||
PreRollSeconds: int64(envInt("FRAME_PROCESSOR_PRE_ROLL_SECONDS", 10)),
|
||||
EventClipSeconds: int64(envInt("FRAME_PROCESSOR_EVENT_CLIP_SECONDS", 30)),
|
||||
},
|
||||
}
|
||||
if config.service.APIToken == "" {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_API_TOKEN is required")
|
||||
}
|
||||
if config.mqtt.BrokerURI == "" || config.mqtt.HubKey == "" {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_MQTT_URI and FRAME_PROCESSOR_HUB_KEY are required")
|
||||
}
|
||||
if config.processor.EveryN <= 0 {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_EVERY_N must be positive")
|
||||
}
|
||||
if !processor.IsProfileSupported(config.processor.DefaultProfile) {
|
||||
return applicationConfig{}, fmt.Errorf("unsupported FRAME_PROCESSOR_PROFILE %q", config.processor.DefaultProfile)
|
||||
}
|
||||
if brightnessThreshold < 0 || brightnessThreshold > 255 {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_BRIGHTNESS_THRESHOLD must be between 0 and 255")
|
||||
}
|
||||
if config.processor.Delay < 0 || config.processor.Delay > time.Minute {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_DELAY_MILLISECONDS must be between 0 and 60000")
|
||||
}
|
||||
if config.service.MaxFrameBytes <= 0 || config.service.MaxFrameBytes > 100<<20 {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_MAX_FRAME_BYTES must be between 1 and 104857600")
|
||||
}
|
||||
if config.service.MaxFrameTTL <= 0 || config.service.MaxFrameTTL > time.Hour {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_MAX_FRAME_TTL_SECONDS must be between 1 and 3600")
|
||||
}
|
||||
if config.service.PreRollSeconds < 0 || config.service.PreRollSeconds > config.service.EventClipSeconds {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_PRE_ROLL_SECONDS must be between zero and FRAME_PROCESSOR_EVENT_CLIP_SECONDS")
|
||||
}
|
||||
if config.service.CommandTTL <= 0 || config.service.CommandTTL > time.Hour {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_COMMAND_TTL_SECONDS must be between 1 and 3600")
|
||||
}
|
||||
if config.service.EventClipSeconds <= 0 || config.service.EventClipSeconds > 24*60*60 {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_EVENT_CLIP_SECONDS must be between 1 and 86400")
|
||||
}
|
||||
if config.mqtt.Timeout <= 0 || config.mqtt.Timeout > time.Minute {
|
||||
return applicationConfig{}, errors.New("FRAME_PROCESSOR_MQTT_TIMEOUT_SECONDS must be between 1 and 60")
|
||||
}
|
||||
return config, nil
|
||||
}
|
||||
|
||||
func envString(name, fallback string) string {
|
||||
if value := os.Getenv(name); value != "" {
|
||||
return value
|
||||
}
|
||||
return fallback
|
||||
}
|
||||
|
||||
func envInt(name string, fallback int) int {
|
||||
value := os.Getenv(name)
|
||||
if value == "" {
|
||||
return fallback
|
||||
}
|
||||
parsed, err := strconv.Atoi(value)
|
||||
if err != nil {
|
||||
slog.Warn("invalid integer environment value, using default", "name", name)
|
||||
return fallback
|
||||
}
|
||||
return parsed
|
||||
}
|
||||
|
||||
func envBool(name string, fallback bool) bool {
|
||||
value := os.Getenv(name)
|
||||
if value == "" {
|
||||
return fallback
|
||||
}
|
||||
parsed, err := strconv.ParseBool(value)
|
||||
if err != nil {
|
||||
slog.Warn("invalid boolean environment value, using default", "name", name)
|
||||
return fallback
|
||||
}
|
||||
return parsed
|
||||
}
|
||||
|
||||
func envDurationSeconds(name string, fallback int) time.Duration {
|
||||
return time.Duration(envInt(name, fallback)) * time.Second
|
||||
}
|
||||
|
||||
func envDurationMillis(name string, fallback int) time.Duration {
|
||||
return time.Duration(envInt(name, fallback)) * time.Millisecond
|
||||
}
|
||||
|
||||
func (c applicationConfig) String() string {
|
||||
return fmt.Sprintf("address=%s profile=%s", c.address, c.processor.DefaultProfile)
|
||||
}
|
||||
25
examples/frame-processor/main_test.go
Normal file
@@ -0,0 +1,25 @@
|
||||
package main
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestLoadConfigRejectsInvalidBounds(t *testing.T) {
|
||||
t.Setenv("FRAME_PROCESSOR_API_TOKEN", "secret")
|
||||
t.Setenv("FRAME_PROCESSOR_MQTT_URI", "tcp://localhost:1883")
|
||||
t.Setenv("FRAME_PROCESSOR_HUB_KEY", "hub")
|
||||
t.Setenv("FRAME_PROCESSOR_BRIGHTNESS_THRESHOLD", "256")
|
||||
|
||||
if _, err := loadConfig(); err == nil {
|
||||
t.Fatal("loadConfig() accepted an invalid brightness threshold")
|
||||
}
|
||||
}
|
||||
|
||||
func TestLoadConfigRejectsUnknownProfile(t *testing.T) {
|
||||
t.Setenv("FRAME_PROCESSOR_API_TOKEN", "secret")
|
||||
t.Setenv("FRAME_PROCESSOR_MQTT_URI", "tcp://localhost:1883")
|
||||
t.Setenv("FRAME_PROCESSOR_HUB_KEY", "hub")
|
||||
t.Setenv("FRAME_PROCESSOR_PROFILE", "unknown")
|
||||
|
||||
if _, err := loadConfig(); err == nil {
|
||||
t.Fatal("loadConfig() accepted an unknown profile")
|
||||
}
|
||||
}
|
||||
171
examples/frame-processor/mqttpublisher/publisher.go
Normal file
@@ -0,0 +1,171 @@
|
||||
package mqttpublisher
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
mqtt "github.com/eclipse/paho.mqtt.golang"
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
)
|
||||
|
||||
const (
|
||||
commandQoS = byte(1)
|
||||
statusQoS = byte(1)
|
||||
)
|
||||
|
||||
type Config struct {
|
||||
BrokerURI string
|
||||
Username string
|
||||
Password string
|
||||
HubKey string
|
||||
ClientID string
|
||||
Timeout time.Duration
|
||||
}
|
||||
|
||||
type StatusHandler func(contract.StatusEvent)
|
||||
|
||||
type Publisher struct {
|
||||
client mqtt.Client
|
||||
commandTopic string
|
||||
timeout time.Duration
|
||||
}
|
||||
|
||||
func New(config Config, handler StatusHandler) (*Publisher, error) {
|
||||
if config.BrokerURI == "" || config.HubKey == "" {
|
||||
return nil, errors.New("MQTT broker URI and Hub key are required")
|
||||
}
|
||||
if config.Timeout <= 0 {
|
||||
config.Timeout = 10 * time.Second
|
||||
}
|
||||
if config.ClientID == "" {
|
||||
config.ClientID = "frame-processor-" + randomID()
|
||||
}
|
||||
|
||||
statusTopic := "kerberos/hub/" + config.HubKey
|
||||
options := mqtt.NewClientOptions().
|
||||
AddBroker(config.BrokerURI).
|
||||
SetClientID(config.ClientID).
|
||||
SetUsername(config.Username).
|
||||
SetPassword(config.Password).
|
||||
SetCleanSession(false).
|
||||
SetResumeSubs(true).
|
||||
SetAutoReconnect(true).
|
||||
SetConnectRetry(true).
|
||||
SetConnectRetryInterval(5 * time.Second).
|
||||
SetMaxReconnectInterval(time.Minute).
|
||||
SetKeepAlive(30 * time.Second).
|
||||
SetPingTimeout(10 * time.Second)
|
||||
if handler != nil {
|
||||
options.SetOnConnectHandler(func(client mqtt.Client) {
|
||||
token := client.Subscribe(statusTopic, statusQoS, statusMessageHandler(handler))
|
||||
if !token.WaitTimeout(config.Timeout) || token.Error() != nil {
|
||||
slog.Error("failed to subscribe to Agent status events", "topic", statusTopic, "error", token.Error())
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
client := mqtt.NewClient(options)
|
||||
token := client.Connect()
|
||||
if !token.WaitTimeout(config.Timeout) {
|
||||
return nil, errors.New("MQTT connection timed out")
|
||||
}
|
||||
if err := token.Error(); err != nil {
|
||||
return nil, fmt.Errorf("connect MQTT: %w", err)
|
||||
}
|
||||
return &Publisher{
|
||||
client: client, commandTopic: "kerberos/agent/" + config.HubKey,
|
||||
timeout: config.Timeout,
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (p *Publisher) Close() {
|
||||
if p != nil && p.client != nil && p.client.IsConnected() {
|
||||
p.client.Disconnect(250)
|
||||
}
|
||||
}
|
||||
|
||||
func (p *Publisher) PublishCaptureFrame(ctx context.Context, deviceID string, command contract.CaptureFrameCommand) error {
|
||||
return p.publish(ctx, deviceID, contract.ActionCaptureFrame, command)
|
||||
}
|
||||
|
||||
func (p *Publisher) PublishRecordingWindow(ctx context.Context, deviceID string, command contract.RecordingWindowCommand) error {
|
||||
return p.publish(ctx, deviceID, contract.ActionRequestRecordingWindow, command)
|
||||
}
|
||||
|
||||
func (p *Publisher) publish(ctx context.Context, deviceID, action string, value any) error {
|
||||
message := newMessage(deviceID, action, value, time.Now())
|
||||
payload, err := json.Marshal(message)
|
||||
if err != nil {
|
||||
return fmt.Errorf("marshal MQTT command: %w", err)
|
||||
}
|
||||
token := p.client.Publish(p.commandTopic, commandQoS, false, payload)
|
||||
timer := time.NewTimer(p.timeout)
|
||||
defer timer.Stop()
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return ctx.Err()
|
||||
case <-timer.C:
|
||||
return errors.New("MQTT publish timed out")
|
||||
case <-token.Done():
|
||||
if err := token.Error(); err != nil {
|
||||
return fmt.Errorf("publish MQTT command: %w", err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
}
|
||||
|
||||
func newMessage(deviceID, action string, value any, now time.Time) contract.MQTTMessage {
|
||||
return contract.MQTTMessage{
|
||||
MID: randomID(),
|
||||
DeviceID: deviceID,
|
||||
Timestamp: now.Unix(),
|
||||
Payload: contract.MQTTPayload{
|
||||
Version: contract.SchemaVersion,
|
||||
Action: action,
|
||||
DeviceID: deviceID,
|
||||
Value: value,
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
func randomID() string {
|
||||
value := make([]byte, 16)
|
||||
if _, err := rand.Read(value); err != nil {
|
||||
return fmt.Sprintf("%d", time.Now().UnixNano())
|
||||
}
|
||||
value[6] = (value[6] & 0x0f) | 0x40
|
||||
value[8] = (value[8] & 0x3f) | 0x80
|
||||
encoded := hex.EncodeToString(value)
|
||||
return strings.Join([]string{encoded[0:8], encoded[8:12], encoded[12:16], encoded[16:20], encoded[20:32]}, "-")
|
||||
}
|
||||
|
||||
func statusMessageHandler(handler StatusHandler) mqtt.MessageHandler {
|
||||
return func(_ mqtt.Client, message mqtt.Message) {
|
||||
var envelope contract.MQTTMessage
|
||||
if err := json.Unmarshal(message.Payload(), &envelope); err != nil {
|
||||
slog.Warn("discarding malformed Agent status envelope", "error", err)
|
||||
return
|
||||
}
|
||||
if envelope.Payload.Action != contract.ActionFrameStatus {
|
||||
return
|
||||
}
|
||||
value, err := json.Marshal(envelope.Payload.Value)
|
||||
if err != nil {
|
||||
slog.Warn("discarding unencodable Agent status value", "error", err)
|
||||
return
|
||||
}
|
||||
var status contract.StatusEvent
|
||||
if err := json.Unmarshal(value, &status); err != nil {
|
||||
slog.Warn("discarding malformed Agent status value", "error", err)
|
||||
return
|
||||
}
|
||||
handler(status)
|
||||
}
|
||||
}
|
||||
54
examples/frame-processor/mqttpublisher/publisher_test.go
Normal file
@@ -0,0 +1,54 @@
|
||||
package mqttpublisher
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
)
|
||||
|
||||
func TestNewMessageMatchesAgentEnvelope(t *testing.T) {
|
||||
command := contract.CaptureFrameCommand{
|
||||
SchemaVersion: contract.SchemaVersion,
|
||||
RequestID: "request-1",
|
||||
ProcessingProfile: "always-trigger",
|
||||
ExpiresAt: 2_000,
|
||||
}
|
||||
message := newMessage("device-1", contract.ActionCaptureFrame, command, time.Unix(1_000, 0))
|
||||
payload, err := json.Marshal(message)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
var decoded map[string]any
|
||||
if err := json.Unmarshal(payload, &decoded); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if decoded["device_id"] != "device-1" || decoded["timestamp"] != float64(1_000) {
|
||||
t.Fatalf("envelope = %s", payload)
|
||||
}
|
||||
inner := decoded["payload"].(map[string]any)
|
||||
if inner["action"] != contract.ActionCaptureFrame || inner["device_id"] != "device-1" {
|
||||
t.Fatalf("payload = %#v", inner)
|
||||
}
|
||||
}
|
||||
|
||||
func TestStatusMessageHandlerIgnoresOtherActions(t *testing.T) {
|
||||
called := false
|
||||
handler := statusMessageHandler(func(contract.StatusEvent) { called = true })
|
||||
handler(nil, fakeMessage(`{"payload":{"action":"motion","value":{}}}`))
|
||||
if called {
|
||||
t.Fatal("handler accepted an unrelated action")
|
||||
}
|
||||
}
|
||||
|
||||
type fakeMessage string
|
||||
|
||||
func (m fakeMessage) Duplicate() bool { return false }
|
||||
func (m fakeMessage) Qos() byte { return 1 }
|
||||
func (m fakeMessage) Retained() bool { return false }
|
||||
func (m fakeMessage) Topic() string { return "test" }
|
||||
func (m fakeMessage) MessageID() uint16 { return 1 }
|
||||
func (m fakeMessage) Payload() []byte { return []byte(m) }
|
||||
func (m fakeMessage) Ack() {}
|
||||
216
examples/frame-processor/openapi.yaml
Normal file
@@ -0,0 +1,216 @@
|
||||
openapi: 3.0.3
|
||||
info:
|
||||
title: Kerberos Frame Processing API
|
||||
version: 1.0.0
|
||||
description: Reference contract for Agent frame submission and externally requested capture.
|
||||
servers:
|
||||
- url: http://localhost:8080
|
||||
security:
|
||||
- bearerAuth: []
|
||||
paths:
|
||||
/health:
|
||||
get:
|
||||
security: []
|
||||
summary: Check service liveness
|
||||
responses:
|
||||
"200":
|
||||
description: Service is healthy
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
type: object
|
||||
required: [status]
|
||||
properties:
|
||||
status:
|
||||
type: string
|
||||
enum: [healthy]
|
||||
/v1/frames:
|
||||
post:
|
||||
summary: Process one Agent frame
|
||||
requestBody:
|
||||
required: true
|
||||
content:
|
||||
multipart/form-data:
|
||||
schema:
|
||||
type: object
|
||||
required: [metadata, frame]
|
||||
properties:
|
||||
metadata:
|
||||
$ref: "#/components/schemas/FrameMetadata"
|
||||
frame:
|
||||
type: string
|
||||
format: binary
|
||||
encoding:
|
||||
metadata:
|
||||
contentType: application/json
|
||||
frame:
|
||||
contentType: image/jpeg
|
||||
responses:
|
||||
"200":
|
||||
description: Frame processed
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: "#/components/schemas/FrameResponse"
|
||||
"400":
|
||||
$ref: "#/components/responses/BadRequest"
|
||||
"401":
|
||||
$ref: "#/components/responses/Unauthorized"
|
||||
"413":
|
||||
description: Frame exceeds the configured request limit
|
||||
"415":
|
||||
description: Frame is not a valid JPEG
|
||||
"422":
|
||||
description: Metadata is invalid or expired
|
||||
"502":
|
||||
description: Processing or MQTT command publication failed
|
||||
/v1/frame-requests:
|
||||
post:
|
||||
summary: Request a new frame from one or more Agents
|
||||
requestBody:
|
||||
required: true
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: "#/components/schemas/FrameRequest"
|
||||
responses:
|
||||
"202":
|
||||
description: Capture commands accepted for publication
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: "#/components/schemas/FrameRequestResponse"
|
||||
"400":
|
||||
$ref: "#/components/responses/BadRequest"
|
||||
"401":
|
||||
$ref: "#/components/responses/Unauthorized"
|
||||
"422":
|
||||
description: Request is invalid or expired
|
||||
"502":
|
||||
description: MQTT command publication failed
|
||||
components:
|
||||
securitySchemes:
|
||||
bearerAuth:
|
||||
type: http
|
||||
scheme: bearer
|
||||
responses:
|
||||
BadRequest:
|
||||
description: Malformed request
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: "#/components/schemas/Error"
|
||||
Unauthorized:
|
||||
description: Missing or invalid bearer token
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: "#/components/schemas/Error"
|
||||
schemas:
|
||||
FrameMetadata:
|
||||
type: object
|
||||
required:
|
||||
- schemaVersion
|
||||
- requestId
|
||||
- frameId
|
||||
- deviceId
|
||||
- capturedAt
|
||||
- expiresAt
|
||||
- processingProfile
|
||||
- sourceStream
|
||||
- width
|
||||
- height
|
||||
properties:
|
||||
schemaVersion:
|
||||
type: string
|
||||
enum: ["1.0"]
|
||||
requestId:
|
||||
type: string
|
||||
frameId:
|
||||
type: string
|
||||
deviceId:
|
||||
type: string
|
||||
capturedAt:
|
||||
type: integer
|
||||
format: int64
|
||||
description: Agent wall-clock capture time in Unix milliseconds.
|
||||
expiresAt:
|
||||
type: integer
|
||||
format: int64
|
||||
description: Unix milliseconds after which the frame must not be processed.
|
||||
processingProfile:
|
||||
type: string
|
||||
sourceStream:
|
||||
type: string
|
||||
enum: [main, sub]
|
||||
width:
|
||||
type: integer
|
||||
minimum: 1
|
||||
height:
|
||||
type: integer
|
||||
minimum: 1
|
||||
traceId:
|
||||
type: string
|
||||
FrameRequest:
|
||||
type: object
|
||||
required: [schemaVersion, deviceIds, processingProfile, expiresAt]
|
||||
properties:
|
||||
schemaVersion:
|
||||
type: string
|
||||
enum: ["1.0"]
|
||||
requestId:
|
||||
type: string
|
||||
description: Generated by the service when omitted.
|
||||
deviceIds:
|
||||
type: array
|
||||
minItems: 1
|
||||
items:
|
||||
type: string
|
||||
processingProfile:
|
||||
type: string
|
||||
expiresAt:
|
||||
type: integer
|
||||
format: int64
|
||||
traceId:
|
||||
type: string
|
||||
FrameResponse:
|
||||
type: object
|
||||
required: [schemaVersion, requestId, frameId, decision, reason]
|
||||
properties:
|
||||
schemaVersion:
|
||||
type: string
|
||||
enum: ["1.0"]
|
||||
requestId:
|
||||
type: string
|
||||
frameId:
|
||||
type: string
|
||||
decision:
|
||||
type: string
|
||||
enum: [no-event, event]
|
||||
reason:
|
||||
type: string
|
||||
FrameRequestResponse:
|
||||
type: object
|
||||
required: [schemaVersion, requestId, deviceIds, status]
|
||||
properties:
|
||||
schemaVersion:
|
||||
type: string
|
||||
enum: ["1.0"]
|
||||
requestId:
|
||||
type: string
|
||||
deviceIds:
|
||||
type: array
|
||||
items:
|
||||
type: string
|
||||
status:
|
||||
type: string
|
||||
enum: [accepted]
|
||||
Error:
|
||||
type: object
|
||||
required: [schemaVersion, error]
|
||||
properties:
|
||||
schemaVersion:
|
||||
type: string
|
||||
enum: ["1.0"]
|
||||
error:
|
||||
type: string
|
||||
117
examples/frame-processor/processor/processor.go
Normal file
@@ -0,0 +1,117 @@
|
||||
package processor
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"image/jpeg"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
)
|
||||
|
||||
const (
|
||||
ProfileNeverTrigger = "never-trigger"
|
||||
ProfileAlwaysTrigger = "always-trigger"
|
||||
ProfileEveryNthFrame = "every-nth-frame"
|
||||
ProfileBrightnessThreshold = "brightness-threshold"
|
||||
)
|
||||
|
||||
type Decision struct {
|
||||
Triggered bool `json:"triggered"`
|
||||
Reason string `json:"reason"`
|
||||
}
|
||||
|
||||
type Config struct {
|
||||
DefaultProfile string
|
||||
EveryN int
|
||||
BrightnessThreshold uint8
|
||||
Delay time.Duration
|
||||
ForceError bool
|
||||
}
|
||||
|
||||
type Engine struct {
|
||||
config Config
|
||||
mu sync.Mutex
|
||||
counts map[string]int
|
||||
}
|
||||
|
||||
func IsProfileSupported(profile string) bool {
|
||||
switch profile {
|
||||
case ProfileNeverTrigger, ProfileAlwaysTrigger, ProfileEveryNthFrame, ProfileBrightnessThreshold:
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
|
||||
func New(config Config) *Engine {
|
||||
if config.DefaultProfile == "" {
|
||||
config.DefaultProfile = ProfileNeverTrigger
|
||||
}
|
||||
if config.EveryN <= 0 {
|
||||
config.EveryN = 2
|
||||
}
|
||||
return &Engine{config: config, counts: make(map[string]int)}
|
||||
}
|
||||
|
||||
func (e *Engine) Process(ctx context.Context, metadata contract.FrameMetadata, frame []byte) (Decision, error) {
|
||||
if e.config.Delay > 0 {
|
||||
timer := time.NewTimer(e.config.Delay)
|
||||
defer timer.Stop()
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return Decision{}, ctx.Err()
|
||||
case <-timer.C:
|
||||
}
|
||||
}
|
||||
if e.config.ForceError {
|
||||
return Decision{}, errors.New("configured processing failure")
|
||||
}
|
||||
|
||||
profile := metadata.ProcessingProfile
|
||||
if profile == "" {
|
||||
profile = e.config.DefaultProfile
|
||||
}
|
||||
switch profile {
|
||||
case ProfileNeverTrigger:
|
||||
return Decision{Reason: ProfileNeverTrigger}, nil
|
||||
case ProfileAlwaysTrigger:
|
||||
return Decision{Triggered: true, Reason: ProfileAlwaysTrigger}, nil
|
||||
case ProfileEveryNthFrame:
|
||||
e.mu.Lock()
|
||||
e.counts[metadata.DeviceID]++
|
||||
count := e.counts[metadata.DeviceID]
|
||||
e.mu.Unlock()
|
||||
return Decision{
|
||||
Triggered: count%e.config.EveryN == 0,
|
||||
Reason: fmt.Sprintf("frame %d of every %d", count, e.config.EveryN),
|
||||
}, nil
|
||||
case ProfileBrightnessThreshold:
|
||||
image, err := jpeg.Decode(bytes.NewReader(frame))
|
||||
if err != nil {
|
||||
return Decision{}, fmt.Errorf("decode JPEG: %w", err)
|
||||
}
|
||||
bounds := image.Bounds()
|
||||
var total uint64
|
||||
for y := bounds.Min.Y; y < bounds.Max.Y; y++ {
|
||||
for x := bounds.Min.X; x < bounds.Max.X; x++ {
|
||||
gray, _, _, _ := image.At(x, y).RGBA()
|
||||
total += uint64(gray >> 8)
|
||||
}
|
||||
}
|
||||
pixels := uint64(bounds.Dx() * bounds.Dy())
|
||||
if pixels == 0 {
|
||||
return Decision{}, errors.New("JPEG has no pixels")
|
||||
}
|
||||
average := uint8(total / pixels)
|
||||
return Decision{
|
||||
Triggered: average >= e.config.BrightnessThreshold,
|
||||
Reason: fmt.Sprintf("average brightness %d, threshold %d", average, e.config.BrightnessThreshold),
|
||||
}, nil
|
||||
default:
|
||||
return Decision{}, fmt.Errorf("unknown processing profile %q", profile)
|
||||
}
|
||||
}
|
||||
41
examples/frame-processor/processor/processor_test.go
Normal file
@@ -0,0 +1,41 @@
|
||||
package processor
|
||||
|
||||
import (
|
||||
"context"
|
||||
"testing"
|
||||
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
)
|
||||
|
||||
func TestEveryNthFrameIsTrackedPerDevice(t *testing.T) {
|
||||
engine := New(Config{EveryN: 2})
|
||||
metadata := contract.FrameMetadata{ProcessingProfile: ProfileEveryNthFrame, DeviceID: "device-1"}
|
||||
|
||||
first, err := engine.Process(context.Background(), metadata, nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
second, err := engine.Process(context.Background(), metadata, nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
metadata.DeviceID = "device-2"
|
||||
otherDevice, err := engine.Process(context.Background(), metadata, nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
if first.Triggered || !second.Triggered || otherDevice.Triggered {
|
||||
t.Fatalf("decisions = first:%t second:%t other:%t", first.Triggered, second.Triggered, otherDevice.Triggered)
|
||||
}
|
||||
}
|
||||
|
||||
func TestUnknownProfileFails(t *testing.T) {
|
||||
engine := New(Config{})
|
||||
_, err := engine.Process(context.Background(), contract.FrameMetadata{
|
||||
ProcessingProfile: "missing-profile",
|
||||
}, nil)
|
||||
if err == nil {
|
||||
t.Fatal("Process() accepted an unknown profile")
|
||||
}
|
||||
}
|
||||
358
examples/frame-processor/service/service.go
Normal file
@@ -0,0 +1,358 @@
|
||||
package service
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"crypto/subtle"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"image"
|
||||
_ "image/jpeg"
|
||||
"io"
|
||||
"log/slog"
|
||||
"mime/multipart"
|
||||
"net/http"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/processor"
|
||||
)
|
||||
|
||||
const maxMetadataBytes = 64 << 10
|
||||
|
||||
var errRequestTooLarge = errors.New("request exceeds maximum size")
|
||||
|
||||
type Publisher interface {
|
||||
PublishCaptureFrame(context.Context, string, contract.CaptureFrameCommand) error
|
||||
PublishRecordingWindow(context.Context, string, contract.RecordingWindowCommand) error
|
||||
}
|
||||
|
||||
type Processor interface {
|
||||
Process(context.Context, contract.FrameMetadata, []byte) (processor.Decision, error)
|
||||
}
|
||||
|
||||
type Config struct {
|
||||
APIToken string
|
||||
MaxFrameBytes int64
|
||||
MaxFrameTTL time.Duration
|
||||
CommandTTL time.Duration
|
||||
PreRollSeconds int64
|
||||
EventClipSeconds int64
|
||||
}
|
||||
|
||||
type Service struct {
|
||||
config Config
|
||||
processor Processor
|
||||
publisher Publisher
|
||||
now func() time.Time
|
||||
newID func() string
|
||||
|
||||
resultsMu sync.Mutex
|
||||
results map[string]*frameResult
|
||||
}
|
||||
|
||||
type frameResult struct {
|
||||
done chan struct{}
|
||||
expiresAt int64
|
||||
response FrameResponse
|
||||
err error
|
||||
}
|
||||
|
||||
type FrameResponse struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId"`
|
||||
FrameID string `json:"frameId"`
|
||||
Decision string `json:"decision"`
|
||||
Reason string `json:"reason"`
|
||||
}
|
||||
|
||||
type FrameRequestResponse struct {
|
||||
SchemaVersion string `json:"schemaVersion"`
|
||||
RequestID string `json:"requestId"`
|
||||
DeviceIDs []string `json:"deviceIds"`
|
||||
Status string `json:"status"`
|
||||
}
|
||||
|
||||
func New(config Config, frameProcessor Processor, publisher Publisher, newID func() string) *Service {
|
||||
if config.MaxFrameBytes <= 0 {
|
||||
config.MaxFrameBytes = 4 << 20
|
||||
}
|
||||
if config.CommandTTL <= 0 {
|
||||
config.CommandTTL = 30 * time.Second
|
||||
}
|
||||
if config.MaxFrameTTL <= 0 {
|
||||
config.MaxFrameTTL = 5 * time.Minute
|
||||
}
|
||||
if config.EventClipSeconds <= 0 {
|
||||
config.EventClipSeconds = 30
|
||||
}
|
||||
if newID == nil {
|
||||
newID = func() string { return fmt.Sprintf("request-%d", time.Now().UnixNano()) }
|
||||
}
|
||||
return &Service{
|
||||
config: config, processor: frameProcessor, publisher: publisher,
|
||||
now: time.Now, newID: newID, results: make(map[string]*frameResult),
|
||||
}
|
||||
}
|
||||
|
||||
func (s *Service) Handler() http.Handler {
|
||||
mux := http.NewServeMux()
|
||||
mux.HandleFunc("GET /health", s.handleHealth)
|
||||
mux.HandleFunc("POST /v1/frames", s.authorize(s.handleFrame))
|
||||
mux.HandleFunc("POST /v1/frame-requests", s.authorize(s.handleFrameRequest))
|
||||
return mux
|
||||
}
|
||||
|
||||
func (s *Service) authorize(next http.HandlerFunc) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
if s.config.APIToken == "" {
|
||||
writeError(w, http.StatusServiceUnavailable, "service authentication is not configured")
|
||||
return
|
||||
}
|
||||
provided := strings.TrimPrefix(r.Header.Get("Authorization"), "Bearer ")
|
||||
if subtle.ConstantTimeCompare([]byte(provided), []byte(s.config.APIToken)) != 1 {
|
||||
writeError(w, http.StatusUnauthorized, "unauthorized")
|
||||
return
|
||||
}
|
||||
next(w, r)
|
||||
}
|
||||
}
|
||||
|
||||
func (s *Service) handleHealth(w http.ResponseWriter, _ *http.Request) {
|
||||
writeJSON(w, http.StatusOK, map[string]string{"status": "healthy"})
|
||||
}
|
||||
|
||||
func (s *Service) handleFrame(w http.ResponseWriter, r *http.Request) {
|
||||
metadata, frame, err := readFrame(w, r, s.config.MaxFrameBytes)
|
||||
if err != nil {
|
||||
if errors.Is(err, errRequestTooLarge) {
|
||||
writeError(w, http.StatusRequestEntityTooLarge, err.Error())
|
||||
return
|
||||
}
|
||||
writeError(w, http.StatusBadRequest, err.Error())
|
||||
return
|
||||
}
|
||||
nowMillis := s.now().UnixMilli()
|
||||
if err := metadata.Validate(nowMillis); err != nil {
|
||||
writeError(w, http.StatusUnprocessableEntity, err.Error())
|
||||
return
|
||||
}
|
||||
if time.Duration(metadata.ExpiresAt-nowMillis)*time.Millisecond > s.config.MaxFrameTTL {
|
||||
writeError(w, http.StatusUnprocessableEntity, "expiresAt exceeds maximum frame TTL")
|
||||
return
|
||||
}
|
||||
imageConfig, _, err := image.DecodeConfig(bytes.NewReader(frame))
|
||||
if err != nil {
|
||||
writeError(w, http.StatusUnsupportedMediaType, "frame must be a valid JPEG")
|
||||
return
|
||||
}
|
||||
if imageConfig.Width != metadata.Width || imageConfig.Height != metadata.Height {
|
||||
writeError(w, http.StatusUnprocessableEntity, "frame dimensions do not match metadata")
|
||||
return
|
||||
}
|
||||
|
||||
result, owner := s.beginFrame(metadata.FrameID, metadata.ExpiresAt, nowMillis)
|
||||
if !owner {
|
||||
select {
|
||||
case <-r.Context().Done():
|
||||
writeError(w, http.StatusRequestTimeout, "request cancelled")
|
||||
return
|
||||
case <-result.done:
|
||||
}
|
||||
if result.err != nil {
|
||||
writeError(w, http.StatusBadGateway, result.err.Error())
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, result.response)
|
||||
return
|
||||
}
|
||||
|
||||
response, processErr := s.processFrame(r.Context(), metadata, frame)
|
||||
s.finishFrame(result, response, processErr)
|
||||
if processErr != nil {
|
||||
writeError(w, http.StatusBadGateway, processErr.Error())
|
||||
return
|
||||
}
|
||||
writeJSON(w, http.StatusOK, response)
|
||||
}
|
||||
|
||||
func (s *Service) processFrame(ctx context.Context, metadata contract.FrameMetadata, frame []byte) (FrameResponse, error) {
|
||||
decision, err := s.processor.Process(ctx, metadata, frame)
|
||||
if err != nil {
|
||||
return FrameResponse{}, fmt.Errorf("process frame: %w", err)
|
||||
}
|
||||
response := FrameResponse{
|
||||
SchemaVersion: contract.SchemaVersion,
|
||||
RequestID: metadata.RequestID,
|
||||
FrameID: metadata.FrameID,
|
||||
Decision: "no-event",
|
||||
Reason: decision.Reason,
|
||||
}
|
||||
if !decision.Triggered {
|
||||
return response, nil
|
||||
}
|
||||
command := contract.RecordingWindowCommand{
|
||||
SchemaVersion: contract.SchemaVersion,
|
||||
RequestID: metadata.RequestID,
|
||||
FrameID: metadata.FrameID,
|
||||
CapturedAt: metadata.CapturedAt,
|
||||
PreRollSeconds: s.config.PreRollSeconds,
|
||||
EventClipSeconds: s.config.EventClipSeconds,
|
||||
ExpiresAt: s.now().Add(s.config.CommandTTL).UnixMilli(),
|
||||
ProcessingProfile: metadata.ProcessingProfile,
|
||||
TraceID: metadata.TraceID,
|
||||
}
|
||||
if err := command.Validate(s.now().UnixMilli()); err != nil {
|
||||
return FrameResponse{}, fmt.Errorf("build recording command: %w", err)
|
||||
}
|
||||
if err := s.publisher.PublishRecordingWindow(ctx, metadata.DeviceID, command); err != nil {
|
||||
return FrameResponse{}, fmt.Errorf("publish recording command: %w", err)
|
||||
}
|
||||
response.Decision = "event"
|
||||
return response, nil
|
||||
}
|
||||
|
||||
func (s *Service) handleFrameRequest(w http.ResponseWriter, r *http.Request) {
|
||||
var request contract.FrameRequest
|
||||
decoder := json.NewDecoder(http.MaxBytesReader(w, r.Body, maxMetadataBytes))
|
||||
decoder.DisallowUnknownFields()
|
||||
if err := decoder.Decode(&request); err != nil {
|
||||
writeError(w, http.StatusBadRequest, "invalid JSON request")
|
||||
return
|
||||
}
|
||||
if request.RequestID == "" {
|
||||
request.RequestID = s.newID()
|
||||
}
|
||||
nowMillis := s.now().UnixMilli()
|
||||
if err := request.Validate(nowMillis); err != nil {
|
||||
writeError(w, http.StatusUnprocessableEntity, err.Error())
|
||||
return
|
||||
}
|
||||
if time.Duration(request.ExpiresAt-nowMillis)*time.Millisecond > s.config.MaxFrameTTL {
|
||||
writeError(w, http.StatusUnprocessableEntity, "expiresAt exceeds maximum frame TTL")
|
||||
return
|
||||
}
|
||||
for _, deviceID := range request.DeviceIDs {
|
||||
command := contract.CaptureFrameCommand{
|
||||
SchemaVersion: contract.SchemaVersion,
|
||||
RequestID: request.RequestID,
|
||||
ProcessingProfile: request.ProcessingProfile,
|
||||
ExpiresAt: request.ExpiresAt,
|
||||
TraceID: request.TraceID,
|
||||
}
|
||||
if err := s.publisher.PublishCaptureFrame(r.Context(), deviceID, command); err != nil {
|
||||
writeError(w, http.StatusBadGateway, "failed to publish capture command")
|
||||
return
|
||||
}
|
||||
}
|
||||
writeJSON(w, http.StatusAccepted, FrameRequestResponse{
|
||||
SchemaVersion: contract.SchemaVersion,
|
||||
RequestID: request.RequestID,
|
||||
DeviceIDs: request.DeviceIDs,
|
||||
Status: "accepted",
|
||||
})
|
||||
}
|
||||
|
||||
func (s *Service) beginFrame(frameID string, expiresAt, nowMillis int64) (*frameResult, bool) {
|
||||
s.resultsMu.Lock()
|
||||
defer s.resultsMu.Unlock()
|
||||
for id, result := range s.results {
|
||||
if result.expiresAt <= nowMillis {
|
||||
delete(s.results, id)
|
||||
}
|
||||
}
|
||||
if result, ok := s.results[frameID]; ok {
|
||||
return result, false
|
||||
}
|
||||
result := &frameResult{done: make(chan struct{}), expiresAt: expiresAt}
|
||||
s.results[frameID] = result
|
||||
delay := time.Duration(expiresAt-nowMillis) * time.Millisecond
|
||||
time.AfterFunc(delay, func() {
|
||||
s.resultsMu.Lock()
|
||||
if s.results[frameID] == result {
|
||||
delete(s.results, frameID)
|
||||
}
|
||||
s.resultsMu.Unlock()
|
||||
})
|
||||
return result, true
|
||||
}
|
||||
|
||||
func (s *Service) finishFrame(result *frameResult, response FrameResponse, err error) {
|
||||
s.resultsMu.Lock()
|
||||
result.response = response
|
||||
result.err = err
|
||||
close(result.done)
|
||||
s.resultsMu.Unlock()
|
||||
}
|
||||
|
||||
func readFrame(w http.ResponseWriter, r *http.Request, maxFrameBytes int64) (contract.FrameMetadata, []byte, error) {
|
||||
r.Body = http.MaxBytesReader(w, r.Body, maxFrameBytes+maxMetadataBytes)
|
||||
reader, err := r.MultipartReader()
|
||||
if err != nil {
|
||||
return contract.FrameMetadata{}, nil, errors.New("content type must be multipart/form-data")
|
||||
}
|
||||
var metadata contract.FrameMetadata
|
||||
var frame []byte
|
||||
for {
|
||||
part, err := reader.NextPart()
|
||||
if errors.Is(err, io.EOF) {
|
||||
break
|
||||
}
|
||||
if err != nil {
|
||||
var tooLarge *http.MaxBytesError
|
||||
if errors.As(err, &tooLarge) {
|
||||
return contract.FrameMetadata{}, nil, errRequestTooLarge
|
||||
}
|
||||
return contract.FrameMetadata{}, nil, errors.New("invalid multipart body")
|
||||
}
|
||||
switch part.FormName() {
|
||||
case "metadata":
|
||||
if err := decodeMetadataPart(part, &metadata); err != nil {
|
||||
return contract.FrameMetadata{}, nil, err
|
||||
}
|
||||
case "frame":
|
||||
if part.Header.Get("Content-Type") != "image/jpeg" {
|
||||
return contract.FrameMetadata{}, nil, errors.New("frame content type must be image/jpeg")
|
||||
}
|
||||
frame, err = io.ReadAll(io.LimitReader(part, maxFrameBytes+1))
|
||||
if err != nil || int64(len(frame)) > maxFrameBytes {
|
||||
return contract.FrameMetadata{}, nil, errRequestTooLarge
|
||||
}
|
||||
}
|
||||
}
|
||||
if metadata.FrameID == "" || len(frame) == 0 {
|
||||
return contract.FrameMetadata{}, nil, errors.New("metadata and frame parts are required")
|
||||
}
|
||||
return metadata, frame, nil
|
||||
}
|
||||
|
||||
func decodeMetadataPart(part *multipart.Part, target *contract.FrameMetadata) error {
|
||||
value, err := io.ReadAll(io.LimitReader(part, maxMetadataBytes+1))
|
||||
if err != nil || len(value) > maxMetadataBytes {
|
||||
return errRequestTooLarge
|
||||
}
|
||||
decoder := json.NewDecoder(bytes.NewReader(value))
|
||||
decoder.DisallowUnknownFields()
|
||||
if err := decoder.Decode(target); err != nil {
|
||||
return errors.New("invalid metadata JSON")
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func writeError(w http.ResponseWriter, status int, message string) {
|
||||
writeJSON(w, status, map[string]any{
|
||||
"schemaVersion": contract.SchemaVersion,
|
||||
"error": message,
|
||||
})
|
||||
}
|
||||
|
||||
func writeJSON(w http.ResponseWriter, status int, value any) {
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.WriteHeader(status)
|
||||
if err := json.NewEncoder(w).Encode(value); err != nil {
|
||||
slog.Error("failed to encode HTTP response", "error", err)
|
||||
}
|
||||
}
|
||||
267
examples/frame-processor/service/service_test.go
Normal file
@@ -0,0 +1,267 @@
|
||||
package service
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/json"
|
||||
"image"
|
||||
"image/color"
|
||||
"image/jpeg"
|
||||
"mime/multipart"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"net/textproto"
|
||||
"strings"
|
||||
"sync"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/contract"
|
||||
"github.com/kerberos-io/agent/examples/frame-processor/processor"
|
||||
)
|
||||
|
||||
type recordingPublish struct {
|
||||
deviceID string
|
||||
command contract.RecordingWindowCommand
|
||||
}
|
||||
|
||||
type fakePublisher struct {
|
||||
mu sync.Mutex
|
||||
captures []contract.CaptureFrameCommand
|
||||
recordings []recordingPublish
|
||||
}
|
||||
|
||||
type blockingProcessor struct {
|
||||
started chan struct{}
|
||||
release chan struct{}
|
||||
mu sync.Mutex
|
||||
calls int
|
||||
}
|
||||
|
||||
func (p *blockingProcessor) Process(ctx context.Context, _ contract.FrameMetadata, _ []byte) (processor.Decision, error) {
|
||||
p.mu.Lock()
|
||||
p.calls++
|
||||
if p.calls == 1 {
|
||||
close(p.started)
|
||||
}
|
||||
p.mu.Unlock()
|
||||
select {
|
||||
case <-ctx.Done():
|
||||
return processor.Decision{}, ctx.Err()
|
||||
case <-p.release:
|
||||
return processor.Decision{Triggered: true, Reason: "test"}, nil
|
||||
}
|
||||
}
|
||||
|
||||
func (p *fakePublisher) PublishCaptureFrame(_ context.Context, _ string, command contract.CaptureFrameCommand) error {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
p.captures = append(p.captures, command)
|
||||
return nil
|
||||
}
|
||||
|
||||
func (p *fakePublisher) PublishRecordingWindow(_ context.Context, deviceID string, command contract.RecordingWindowCommand) error {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
p.recordings = append(p.recordings, recordingPublish{deviceID: deviceID, command: command})
|
||||
return nil
|
||||
}
|
||||
|
||||
func TestFrameAlwaysTriggerPublishesOneIdempotentRecordingCommand(t *testing.T) {
|
||||
publisher := &fakePublisher{}
|
||||
service := New(Config{
|
||||
APIToken: "secret", CommandTTL: time.Minute,
|
||||
PreRollSeconds: 10, EventClipSeconds: 30,
|
||||
}, processor.New(processor.Config{}), publisher, nil)
|
||||
service.now = func() time.Time { return time.UnixMilli(1_000) }
|
||||
server := httptest.NewServer(service.Handler())
|
||||
defer server.Close()
|
||||
|
||||
metadata := validMetadata()
|
||||
for range 2 {
|
||||
response := postFrame(t, server.URL, "secret", metadata, jpegFrame(t, 2, 2, 255))
|
||||
if response.StatusCode != http.StatusOK {
|
||||
t.Fatalf("POST /v1/frames status = %d", response.StatusCode)
|
||||
}
|
||||
response.Body.Close()
|
||||
}
|
||||
|
||||
if got := len(publisher.recordings); got != 1 {
|
||||
t.Fatalf("recording commands = %d, want 1", got)
|
||||
}
|
||||
published := publisher.recordings[0]
|
||||
if published.deviceID != metadata.DeviceID || published.command.CapturedAt != metadata.CapturedAt {
|
||||
t.Fatalf("published command = %#v", published)
|
||||
}
|
||||
}
|
||||
|
||||
func TestFrameRequestPublishesCaptureCommand(t *testing.T) {
|
||||
publisher := &fakePublisher{}
|
||||
service := New(Config{APIToken: "secret"}, processor.New(processor.Config{}), publisher, func() string { return "generated-request" })
|
||||
service.now = func() time.Time { return time.UnixMilli(1_000) }
|
||||
server := httptest.NewServer(service.Handler())
|
||||
defer server.Close()
|
||||
|
||||
body := `{"schemaVersion":"1.0","deviceIds":["device-1"],"processingProfile":"always-trigger","expiresAt":2000}`
|
||||
request, err := http.NewRequest(http.MethodPost, server.URL+"/v1/frame-requests", strings.NewReader(body))
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
request.Header.Set("Authorization", "Bearer secret")
|
||||
request.Header.Set("Content-Type", "application/json")
|
||||
response, err := http.DefaultClient.Do(request)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer response.Body.Close()
|
||||
if response.StatusCode != http.StatusAccepted {
|
||||
t.Fatalf("POST /v1/frame-requests status = %d", response.StatusCode)
|
||||
}
|
||||
if got := len(publisher.captures); got != 1 || publisher.captures[0].RequestID != "generated-request" {
|
||||
t.Fatalf("capture commands = %#v", publisher.captures)
|
||||
}
|
||||
}
|
||||
|
||||
func TestFrameRejectsUnauthorizedRequest(t *testing.T) {
|
||||
service := New(Config{APIToken: "secret"}, processor.New(processor.Config{}), &fakePublisher{}, nil)
|
||||
server := httptest.NewServer(service.Handler())
|
||||
defer server.Close()
|
||||
|
||||
response := postFrame(t, server.URL, "wrong", validMetadata(), jpegFrame(t, 2, 2, 255))
|
||||
defer response.Body.Close()
|
||||
if response.StatusCode != http.StatusUnauthorized {
|
||||
t.Fatalf("POST /v1/frames status = %d", response.StatusCode)
|
||||
}
|
||||
}
|
||||
|
||||
func TestFrameFailsClosedWithoutConfiguredToken(t *testing.T) {
|
||||
application := New(Config{}, processor.New(processor.Config{}), &fakePublisher{}, nil)
|
||||
server := httptest.NewServer(application.Handler())
|
||||
defer server.Close()
|
||||
|
||||
response := postFrame(t, server.URL, "", validMetadata(), jpegFrame(t, 2, 2, 255))
|
||||
defer response.Body.Close()
|
||||
if response.StatusCode != http.StatusServiceUnavailable {
|
||||
t.Fatalf("POST /v1/frames status = %d", response.StatusCode)
|
||||
}
|
||||
}
|
||||
|
||||
func TestConcurrentDuplicateFramesPublishOneRecordingCommand(t *testing.T) {
|
||||
publisher := &fakePublisher{}
|
||||
frameProcessor := &blockingProcessor{started: make(chan struct{}), release: make(chan struct{})}
|
||||
application := New(Config{
|
||||
APIToken: "secret", CommandTTL: time.Minute,
|
||||
PreRollSeconds: 10, EventClipSeconds: 30,
|
||||
}, frameProcessor, publisher, nil)
|
||||
application.now = func() time.Time { return time.UnixMilli(1_000) }
|
||||
server := httptest.NewServer(application.Handler())
|
||||
defer server.Close()
|
||||
|
||||
metadata := validMetadata()
|
||||
statuses := make(chan int, 2)
|
||||
go func() {
|
||||
response := postFrame(t, server.URL, "secret", metadata, jpegFrame(t, 2, 2, 255))
|
||||
defer response.Body.Close()
|
||||
statuses <- response.StatusCode
|
||||
}()
|
||||
<-frameProcessor.started
|
||||
go func() {
|
||||
response := postFrame(t, server.URL, "secret", metadata, jpegFrame(t, 2, 2, 255))
|
||||
defer response.Body.Close()
|
||||
statuses <- response.StatusCode
|
||||
}()
|
||||
close(frameProcessor.release)
|
||||
|
||||
for range 2 {
|
||||
if status := <-statuses; status != http.StatusOK {
|
||||
t.Fatalf("POST /v1/frames status = %d", status)
|
||||
}
|
||||
}
|
||||
if got := len(publisher.recordings); got != 1 {
|
||||
t.Fatalf("recording commands = %d, want 1", got)
|
||||
}
|
||||
frameProcessor.mu.Lock()
|
||||
defer frameProcessor.mu.Unlock()
|
||||
if frameProcessor.calls != 1 {
|
||||
t.Fatalf("processor calls = %d, want 1", frameProcessor.calls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestFrameRejectsTTLAboveConfiguredMaximum(t *testing.T) {
|
||||
application := New(Config{APIToken: "secret", MaxFrameTTL: time.Second}, processor.New(processor.Config{}), &fakePublisher{}, nil)
|
||||
application.now = func() time.Time { return time.UnixMilli(1_000) }
|
||||
server := httptest.NewServer(application.Handler())
|
||||
defer server.Close()
|
||||
|
||||
metadata := validMetadata()
|
||||
metadata.ExpiresAt = 2_001
|
||||
response := postFrame(t, server.URL, "secret", metadata, jpegFrame(t, 2, 2, 255))
|
||||
defer response.Body.Close()
|
||||
if response.StatusCode != http.StatusUnprocessableEntity {
|
||||
t.Fatalf("POST /v1/frames status = %d", response.StatusCode)
|
||||
}
|
||||
}
|
||||
|
||||
func validMetadata() contract.FrameMetadata {
|
||||
return contract.FrameMetadata{
|
||||
SchemaVersion: contract.SchemaVersion,
|
||||
RequestID: "request-1", FrameID: "frame-1", DeviceID: "device-1",
|
||||
CapturedAt: 900, ExpiresAt: 2_000, ProcessingProfile: processor.ProfileAlwaysTrigger,
|
||||
SourceStream: "sub", Width: 2, Height: 2,
|
||||
}
|
||||
}
|
||||
|
||||
func jpegFrame(t *testing.T, width, height int, brightness uint8) []byte {
|
||||
t.Helper()
|
||||
frame := image.NewGray(image.Rect(0, 0, width, height))
|
||||
for index := range frame.Pix {
|
||||
frame.Pix[index] = brightness
|
||||
}
|
||||
frame.SetGray(0, 0, color.Gray{Y: brightness})
|
||||
var output bytes.Buffer
|
||||
if err := jpeg.Encode(&output, frame, nil); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
return output.Bytes()
|
||||
}
|
||||
|
||||
func postFrame(t *testing.T, baseURL, token string, metadata contract.FrameMetadata, frame []byte) *http.Response {
|
||||
t.Helper()
|
||||
var body bytes.Buffer
|
||||
writer := multipart.NewWriter(&body)
|
||||
metadataHeader := make(textproto.MIMEHeader)
|
||||
metadataHeader.Set("Content-Disposition", `form-data; name="metadata"`)
|
||||
metadataHeader.Set("Content-Type", "application/json")
|
||||
part, err := writer.CreatePart(metadataHeader)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := json.NewEncoder(part).Encode(metadata); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
frameHeader := make(textproto.MIMEHeader)
|
||||
frameHeader.Set("Content-Disposition", `form-data; name="frame"; filename="frame.jpg"`)
|
||||
frameHeader.Set("Content-Type", "image/jpeg")
|
||||
part, err = writer.CreatePart(frameHeader)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := part.Write(frame); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := writer.Close(); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
request, err := http.NewRequest(http.MethodPost, baseURL+"/v1/frames", &body)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
request.Header.Set("Authorization", "Bearer "+token)
|
||||
request.Header.Set("Content-Type", writer.FormDataContentType())
|
||||
response, err := http.DefaultClient.Do(request)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
return response
|
||||
}
|
||||
7
examples/frame-processor/testdata/capture-frame.json
vendored
Normal file
@@ -0,0 +1,7 @@
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"requestId": "request-example-1",
|
||||
"processingProfile": "always-trigger",
|
||||
"expiresAt": 4102444800000,
|
||||
"traceId": "trace-example-1"
|
||||
}
|
||||
8
examples/frame-processor/testdata/frame-request.json
vendored
Normal file
@@ -0,0 +1,8 @@
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"requestId": "request-example-1",
|
||||
"deviceIds": ["camera-1"],
|
||||
"processingProfile": "always-trigger",
|
||||
"expiresAt": 4102444800000,
|
||||
"traceId": "trace-example-1"
|
||||
}
|
||||
11
examples/frame-processor/testdata/request-recording-window.json
vendored
Normal file
@@ -0,0 +1,11 @@
|
||||
{
|
||||
"schemaVersion": "1.0",
|
||||
"requestId": "request-example-1",
|
||||
"frameId": "frame-example-1",
|
||||
"capturedAt": 1789380000123,
|
||||
"preRollSeconds": 10,
|
||||
"eventClipSeconds": 30,
|
||||
"expiresAt": 4102444800000,
|
||||
"processingProfile": "always-trigger",
|
||||
"traceId": "trace-example-1"
|
||||
}
|
||||
BIN
machinery/.DS_Store
vendored
Normal file
38
machinery/.env
Normal file
@@ -0,0 +1,38 @@
|
||||
AGENT_NAME=camera-name
|
||||
AGENT_KEY=uniq-camera-id
|
||||
AGENT_TIMEZONE=Europe/Brussels
|
||||
#AGENT_CAPTURE_CONTINUOUS=true
|
||||
#AGENT_CAPTURE_IPCAMERA_RTSP=rtsp://fake.kerberos.io/stream
|
||||
#AGENT_CAPTURE_IPCAMERA_SUB_RTSP=rtsp://fake.kerberos.io/stream
|
||||
AGENT_CAPTURE_IPCAMERA_ONVIF_XADDR=x.x.x.x
|
||||
AGENT_CAPTURE_IPCAMERA_ONVIF_USERNAME=xxx
|
||||
AGENT_CAPTURE_IPCAMERA_ONVIF_PASSWORD=xxx
|
||||
AGENT_HUB_URI=https://api.cloud.kerberos.io
|
||||
AGENT_HUB_KEY=AKIXxxx4JBEI
|
||||
AGENT_HUB_PRIVATE_KEY=DIOXxxxAlYpaxxxxXioL0txxx
|
||||
AGENT_HUB_SITE=681xxxxxxx9bcda5
|
||||
|
||||
# By default will send to Hub (=S3), if you wish to send to Kerberos Vault, set to "kstorage"
|
||||
AGENT_CLOUD=s3
|
||||
AGENT_KERBEROSVAULT_URI=
|
||||
AGENT_KERBEROSVAULT_PROVIDER=
|
||||
AGENT_KERBEROSVAULT_DIRECTORY=
|
||||
AGENT_KERBEROSVAULT_ACCESS_KEY=
|
||||
AGENT_KERBEROSVAULT_SECRET_KEY=
|
||||
AGENT_KERBEROSVAULT_MAX_RETRIES=10
|
||||
AGENT_KERBEROSVAULT_TIMEOUT=120
|
||||
AGENT_KERBEROSVAULT_SECONDARY_URI=
|
||||
AGENT_KERBEROSVAULT_SECONDARY_PROVIDER=
|
||||
AGENT_KERBEROSVAULT_SECONDARY_DIRECTORY=
|
||||
AGENT_KERBEROSVAULT_SECONDARY_ACCESS_KEY=
|
||||
AGENT_KERBEROSVAULT_SECONDARY_SECRET_KEY=
|
||||
|
||||
# Resumable (tus) uploads to Kerberos Vault are enabled by default.
|
||||
# Set to true to fall back to the legacy single-shot POST /storage upload.
|
||||
#AGENT_DISABLE_RESUMABLE_UPLOAD=true
|
||||
# Bytes sent per PATCH request (default 1 MiB = 1048576). 0 disables chunking
|
||||
# and sends the whole file in a single PATCH.
|
||||
AGENT_TUS_CHUNK_SIZE_BYTES=1048576
|
||||
|
||||
# Open telemetry tracing endpoint
|
||||
OTEL_EXPORTER_OTLP_ENDPOINT=
|
||||
@@ -5,7 +5,6 @@
|
||||
<a target="_blank" href="https://twitter.com/kerberosio?ref_src=twsrc%5Etfw"><img src="https://img.shields.io/twitter/url.svg?label=Follow%20%40kerberosio&style=social&url=https%3A%2F%2Ftwitter.com%2Fkerberosio" alt="Twitter Widget"></a>
|
||||
<a target="_blank" href="https://join.slack.com/t/kerberosio/shared_invite/zt-1a5oj4pwm-O4qCAN9c5r2um0Ns0ge8ww"><img src="https://img.shields.io/badge/slack-@kerberosio-yellow.svg?logo=slack " alt="Kerberos.io"></a>
|
||||
|
||||
<a target="_blank" href="https://circleci.com/gh/kerberos-io/agent"><img src="https://circleci.com/gh/kerberos-io/agent.svg?style=svg"/></a>
|
||||
<img src="https://github.com/kerberos-io/agent/workflows/Go/badge.svg"/>
|
||||
<img src="https://github.com/kerberos-io/agent/workflows/CodeQL/badge.svg"/>
|
||||
|
||||
@@ -22,4 +21,8 @@ https://brianmacdonald.github.io/Ethonate/address#0xf4a759C9436E2280Ea9cdd23d314
|
||||
|
||||
[**Docker Hub**](https://hub.docker.com/r/kerberos/agent) | [**Documentation**](https://doc.kerberos.io) | [**Website**](https://kerberos.io)
|
||||
|
||||
Kerberos Open source (v3) is a cutting edge video surveillance management system made available as Open Source under the MIT License. This means that all the source code is available for you or your company, and you can use, transform and distribute the source code; as long you keep a reference of the original license. Kerberos Open Source (v3) can be used for commercial usage (which was not the case for v2). Read more [about the license here](LICENSE).
|
||||
Kerberos Open source (v3) is a cutting edge video surveillance management system made available as Open Source under the MIT License. This means that all the source code is available for you or your company, and you can use, transform and distribute the source code; as long you keep a reference of the original license. Kerberos Open Source (v3) can be used for commercial usage (which was not the case for v2). Read more [about the license here](LICENSE).
|
||||
|
||||
## Security reporting
|
||||
|
||||
For sensitive vulnerabilities, use private disclosure channels documented in [../SECURITY.md](../SECURITY.md).
|
||||
|
||||
636
machinery/cmd/mp4analyze/main.go
Normal file
@@ -0,0 +1,636 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"flag"
|
||||
"fmt"
|
||||
"os"
|
||||
"sort"
|
||||
|
||||
"github.com/Eyevinn/mp4ff/avc"
|
||||
mp4ff "github.com/Eyevinn/mp4ff/mp4"
|
||||
)
|
||||
|
||||
func main() {
|
||||
fromFlag := flag.Int64("from", -1, "start of the detailed inspection window (track timescale units); default auto-detects the largest keyframe gap")
|
||||
toFlag := flag.Int64("to", -1, "end of the detailed inspection window (track timescale units); default auto-detected")
|
||||
flag.Parse()
|
||||
if flag.NArg() < 1 {
|
||||
fmt.Println("usage: mp4analyze [-from N] [-to N] <file.mp4>")
|
||||
os.Exit(1)
|
||||
}
|
||||
f, err := os.Open(flag.Arg(0))
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
defer f.Close()
|
||||
parsed, err := mp4ff.DecodeFile(f)
|
||||
if err != nil {
|
||||
panic(err)
|
||||
}
|
||||
|
||||
// Movie-level info
|
||||
if parsed.Init != nil && parsed.Init.Moov != nil {
|
||||
moov := parsed.Init.Moov
|
||||
fmt.Printf("ftyp/moov present. timescale(mvhd)=%d duration(mvhd)=%d\n",
|
||||
moov.Mvhd.Timescale, moov.Mvhd.Duration)
|
||||
for _, trak := range moov.Traks {
|
||||
ts := trak.Mdia.Mdhd.Timescale
|
||||
fmt.Printf(" trak id=%d handler=%s mdhd.timescale=%d mdhd.duration=%d\n",
|
||||
trak.Tkhd.TrackID, trak.Mdia.Hdlr.HandlerType, ts, trak.Mdia.Mdhd.Duration)
|
||||
}
|
||||
} else {
|
||||
fmt.Println("no Init/Moov (pure fragmented stream?)")
|
||||
}
|
||||
|
||||
// sidx vs actual segment layout. MSE players use sidx to map presentation
|
||||
// time -> byte ranges; if sidx references disagree with the real segment
|
||||
// sizes/durations (e.g. after an early/short flush) the player fetches the
|
||||
// wrong bytes and fails to decode — a failure that "heals" on seek.
|
||||
fmt.Println("=== sidx references vs actual segments ===")
|
||||
var sidxRefs []mp4ff.SidxRef
|
||||
for _, c := range parsed.Children {
|
||||
if s, ok := c.(*mp4ff.SidxBox); ok {
|
||||
fmt.Printf(" sidx: timescale=%d earliestPresTime=%d firstOffset=%d refCount=%d anchor(after sidx)=%d\n",
|
||||
s.Timescale, s.EarliestPresentationTime, s.FirstOffset, len(s.SidxRefs), s.AnchorPoint)
|
||||
sidxRefs = s.SidxRefs
|
||||
}
|
||||
}
|
||||
// Actual segment sizes (styp+moof+mdat) and fragment durations.
|
||||
type segInfo struct {
|
||||
size uint64
|
||||
dur uint64
|
||||
}
|
||||
var actual []segInfo
|
||||
for _, seg := range parsed.Segments {
|
||||
var sz uint64
|
||||
if seg.Styp != nil {
|
||||
sz += seg.Styp.Size()
|
||||
}
|
||||
if seg.Sidx != nil {
|
||||
sz += seg.Sidx.Size()
|
||||
}
|
||||
var dur uint64
|
||||
for _, fr := range seg.Fragments {
|
||||
sz += fr.Moof.Size()
|
||||
if fr.Mdat != nil {
|
||||
sz += fr.Mdat.Size()
|
||||
}
|
||||
for _, traf := range fr.Moof.Trafs {
|
||||
if traf.Tfhd.TrackID != 1 {
|
||||
continue
|
||||
}
|
||||
for _, trun := range traf.Truns {
|
||||
for _, s := range trun.Samples {
|
||||
dur += uint64(s.Dur)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
actual = append(actual, segInfo{size: sz, dur: dur})
|
||||
}
|
||||
for i := range actual {
|
||||
refStr := "(no sidx ref)"
|
||||
if i < len(sidxRefs) {
|
||||
r := sidxRefs[i]
|
||||
mark := ""
|
||||
if uint64(r.ReferencedSize) != actual[i].size {
|
||||
mark += fmt.Sprintf(" SIZE MISMATCH actual=%d", actual[i].size)
|
||||
}
|
||||
if uint64(r.SubSegmentDuration) != actual[i].dur {
|
||||
mark += fmt.Sprintf(" DUR MISMATCH actual=%d", actual[i].dur)
|
||||
}
|
||||
refStr = fmt.Sprintf("sidx.size=%d sidx.dur=%d type=%d sap=%d/%d%s",
|
||||
r.ReferencedSize, r.SubSegmentDuration, r.ReferenceType, r.StartsWithSAP, r.SAPType, mark)
|
||||
}
|
||||
fmt.Printf(" seg%02d actual.size=%d actual.dur=%d | %s\n", i, actual[i].size, actual[i].dur, refStr)
|
||||
}
|
||||
|
||||
fmt.Println("=== fragments ===")
|
||||
fragIdx := 0
|
||||
var allKeyGlobal []uint64 // global keyframe decode times (track timescale units)
|
||||
var prevTfdtEnd = map[uint32]uint64{}
|
||||
for si, seg := range parsed.Segments {
|
||||
for _, fr := range seg.Fragments {
|
||||
for _, traf := range fr.Moof.Trafs {
|
||||
tid := traf.Tfhd.TrackID
|
||||
tfdt := traf.Tfdt.BaseMediaDecodeTime()
|
||||
offset := uint64(0)
|
||||
var keys []uint64 // keyframe offset-from-tfdt
|
||||
var durs []uint64
|
||||
zeroDur := 0
|
||||
nSamples := 0
|
||||
for _, trun := range traf.Truns {
|
||||
for _, s := range trun.Samples {
|
||||
nSamples++
|
||||
if (s.Flags>>24)&0x03 == 0x02 { // sample_depends_on==2 => IDR/sync
|
||||
keys = append(keys, offset)
|
||||
if tid == 1 {
|
||||
allKeyGlobal = append(allKeyGlobal, tfdt+offset)
|
||||
}
|
||||
}
|
||||
if s.Dur == 0 {
|
||||
zeroDur++
|
||||
}
|
||||
durs = append(durs, uint64(s.Dur))
|
||||
offset += uint64(s.Dur)
|
||||
}
|
||||
}
|
||||
cont := ""
|
||||
if pe, ok := prevTfdtEnd[tid]; ok {
|
||||
if tfdt != pe {
|
||||
cont = fmt.Sprintf(" <-- tfdt GAP/JUMP prev_end=%d delta=%d", pe, int64(tfdt)-int64(pe))
|
||||
}
|
||||
}
|
||||
prevTfdtEnd[tid] = tfdt + offset
|
||||
if tid == 1 {
|
||||
// in-fragment keyframe gaps
|
||||
var gaps []int64
|
||||
for i := 1; i < len(keys); i++ {
|
||||
gaps = append(gaps, int64(keys[i])-int64(keys[i-1]))
|
||||
}
|
||||
fmt.Printf("seg%d frag%d trk%d tfdt=%d dur=%d nSamp=%d zeroDur=%d keys=%v inFragKeyGaps=%v%s\n",
|
||||
si, fragIdx, tid, tfdt, offset, nSamples, zeroDur, keys, gaps, cont)
|
||||
}
|
||||
}
|
||||
fragIdx++
|
||||
}
|
||||
}
|
||||
|
||||
fmt.Println("=== global video keyframe decode times & gaps ===")
|
||||
for i, k := range allKeyGlobal {
|
||||
gap := int64(0)
|
||||
if i > 0 {
|
||||
gap = int64(k) - int64(allKeyGlobal[i-1])
|
||||
}
|
||||
seam := ""
|
||||
if i > 1 {
|
||||
prevGap := int64(allKeyGlobal[i-1]) - int64(allKeyGlobal[i-2])
|
||||
if gap > 0 && prevGap > 0 && gap*2 < prevGap {
|
||||
seam = fmt.Sprintf(" <== SEAM? gap=%d < prevGap/2=%d", gap, prevGap/2)
|
||||
}
|
||||
}
|
||||
fmt.Printf(" kf#%02d dt=%d gap=%d%s\n", i, k, gap, seam)
|
||||
}
|
||||
|
||||
// Choose the detailed-inspection window. By default centre it on the largest
|
||||
// keyframe gap (the most likely artifact location); -from/-to override.
|
||||
winLo, winHi := inspectWindow(allKeyGlobal, *fromFlag, *toFlag)
|
||||
fmt.Printf("=== detailed inspection window: dts %d..%d ===\n", winLo, winHi)
|
||||
|
||||
// Full sample timeline: DTS, CTS (=DTS+cto), composition offset, NAL types,
|
||||
// to detect PTS non-monotonicity / gaps / param-set changes at the seam.
|
||||
fmt.Println("=== per-sample timeline (full) — checking PTS monotonicity & nal types ===")
|
||||
var trex *mp4ff.TrexBox
|
||||
if parsed.Init != nil && parsed.Init.Moov != nil && parsed.Init.Moov.Mvex != nil {
|
||||
for _, t := range parsed.Init.Moov.Mvex.Trexs {
|
||||
if t.TrackID == 1 {
|
||||
trex = t
|
||||
}
|
||||
}
|
||||
}
|
||||
var lastCTS int64 = -1
|
||||
var lastDTS int64 = -1
|
||||
sampIdx := 0
|
||||
fragIdx = 0
|
||||
for _, seg := range parsed.Segments {
|
||||
for _, fr := range seg.Fragments {
|
||||
fs, err := fr.GetFullSamples(trex)
|
||||
if err != nil {
|
||||
fmt.Printf(" frag%d GetFullSamples err: %v\n", fragIdx, err)
|
||||
fragIdx++
|
||||
continue
|
||||
}
|
||||
for _, s := range fs {
|
||||
dts := int64(s.DecodeTime)
|
||||
cts := dts + int64(s.CompositionTimeOffset)
|
||||
nals := nalTypes(s.Data)
|
||||
anomaly := ""
|
||||
if lastCTS >= 0 && cts < lastCTS {
|
||||
anomaly += fmt.Sprintf(" <== CTS BACKWARDS (prev=%d)", lastCTS)
|
||||
}
|
||||
if lastDTS >= 0 && dts < lastDTS {
|
||||
anomaly += fmt.Sprintf(" <== DTS BACKWARDS (prev=%d)", lastDTS)
|
||||
}
|
||||
// sample_is_non_sync_sample is bit 16 (0x00010000); a sync sample
|
||||
// has it clear and sample_depends_on==2 (i.e. an I-frame).
|
||||
isSync := s.Flags&0x00010000 == 0 && (s.Flags>>24)&0x03 == 0x02
|
||||
// Only print inside the inspection window and any anomalies, to keep output small.
|
||||
near := dts >= winLo && dts <= winHi
|
||||
if near || anomaly != "" {
|
||||
fmt.Printf(" s%04d frag%d dts=%d cts=%d cto=%d dur=%d size=%d sync=%v nal=%v%s\n",
|
||||
sampIdx, fragIdx, dts, cts, s.CompositionTimeOffset, s.Dur, len(s.Data), isSync, nals, anomaly)
|
||||
}
|
||||
lastCTS = cts
|
||||
lastDTS = dts
|
||||
sampIdx++
|
||||
}
|
||||
fragIdx++
|
||||
}
|
||||
}
|
||||
|
||||
// Compare parameter sets: avcC (in moov) vs inline SPS/PPS at every IDR.
|
||||
// A looping source that restarts may re-emit SPS/PPS that differ from the
|
||||
// ones the player configured its decoder with from avcC — a classic cause
|
||||
// of a freeze that "heals" when you seek past the seam.
|
||||
fmt.Println("=== parameter set comparison (avcC vs inline IDR) ===")
|
||||
var avccSPS, avccPPS [][]byte
|
||||
if parsed.Init != nil && parsed.Init.Moov != nil {
|
||||
for _, trak := range parsed.Init.Moov.Traks {
|
||||
if trak.Mdia == nil || trak.Mdia.Minf == nil || trak.Mdia.Minf.Stbl == nil {
|
||||
continue
|
||||
}
|
||||
stsd := trak.Mdia.Minf.Stbl.Stsd
|
||||
if stsd == nil || stsd.AvcX == nil || stsd.AvcX.AvcC == nil {
|
||||
continue
|
||||
}
|
||||
avccSPS = stsd.AvcX.AvcC.SPSnalus
|
||||
avccPPS = stsd.AvcX.AvcC.PPSnalus
|
||||
}
|
||||
}
|
||||
for i, s := range avccSPS {
|
||||
fmt.Printf(" avcC SPS[%d] = %x\n", i, s)
|
||||
}
|
||||
for i, p := range avccPPS {
|
||||
fmt.Printf(" avcC PPS[%d] = %x\n", i, p)
|
||||
}
|
||||
fragIdx = 0
|
||||
sampIdx = 0
|
||||
var baseSPS, basePPS []byte
|
||||
if len(avccSPS) > 0 {
|
||||
baseSPS = avccSPS[0]
|
||||
}
|
||||
if len(avccPPS) > 0 {
|
||||
basePPS = avccPPS[0]
|
||||
}
|
||||
for _, seg := range parsed.Segments {
|
||||
for _, fr := range seg.Fragments {
|
||||
fs, err := fr.GetFullSamples(trex)
|
||||
if err != nil {
|
||||
fragIdx++
|
||||
continue
|
||||
}
|
||||
for _, s := range fs {
|
||||
spsList := nalsByType(s.Data, 7)
|
||||
ppsList := nalsByType(s.Data, 8)
|
||||
if len(spsList) > 0 || len(ppsList) > 0 {
|
||||
dts := int64(s.DecodeTime)
|
||||
note := ""
|
||||
if len(spsList) > 0 {
|
||||
if baseSPS == nil {
|
||||
baseSPS = spsList[0]
|
||||
} else if !bytesEqual(baseSPS, spsList[0]) {
|
||||
note += " <== SPS CHANGED vs base/avcC"
|
||||
}
|
||||
}
|
||||
if len(ppsList) > 0 {
|
||||
if basePPS == nil {
|
||||
basePPS = ppsList[0]
|
||||
} else if !bytesEqual(basePPS, ppsList[0]) {
|
||||
note += " <== PPS CHANGED vs base/avcC"
|
||||
}
|
||||
}
|
||||
var spsHex, ppsHex string
|
||||
if len(spsList) > 0 {
|
||||
spsHex = fmt.Sprintf("%x", spsList[0])
|
||||
}
|
||||
if len(ppsList) > 0 {
|
||||
ppsHex = fmt.Sprintf("%x", ppsList[0])
|
||||
}
|
||||
fmt.Printf(" IDR s%04d frag%d dts=%d SPS=%s PPS=%s%s\n",
|
||||
sampIdx, fragIdx, dts, spsHex, ppsHex, note)
|
||||
}
|
||||
sampIdx++
|
||||
}
|
||||
fragIdx++
|
||||
}
|
||||
}
|
||||
|
||||
sliceHeaders(parsed, trex, winLo, winHi)
|
||||
|
||||
summary(parsed, trex)
|
||||
}
|
||||
|
||||
func sliceHeaders(parsed *mp4ff.File, trex *mp4ff.TrexBox, winLo, winHi int64) {
|
||||
// Build SPS/PPS maps from avcC.
|
||||
spsMap := map[uint32]*avc.SPS{}
|
||||
ppsMap := map[uint32]*avc.PPS{}
|
||||
if parsed.Init != nil && parsed.Init.Moov != nil {
|
||||
for _, trak := range parsed.Init.Moov.Traks {
|
||||
if trak.Mdia == nil || trak.Mdia.Minf == nil || trak.Mdia.Minf.Stbl == nil {
|
||||
continue
|
||||
}
|
||||
stsd := trak.Mdia.Minf.Stbl.Stsd
|
||||
if stsd == nil || stsd.AvcX == nil || stsd.AvcX.AvcC == nil {
|
||||
continue
|
||||
}
|
||||
for _, s := range stsd.AvcX.AvcC.SPSnalus {
|
||||
if sps, err := avc.ParseSPSNALUnit(s, true); err == nil {
|
||||
spsMap[uint32(sps.ParameterID)] = sps
|
||||
}
|
||||
}
|
||||
for _, p := range stsd.AvcX.AvcC.PPSnalus {
|
||||
if pps, err := avc.ParsePPSNALUnit(p, spsMap); err == nil {
|
||||
ppsMap[pps.PicParameterSetID] = pps
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
fmt.Println("=== slice headers in inspection window (frame_num / poc / idr_pic_id) ===")
|
||||
fragIdx := 0
|
||||
sampIdx := 0
|
||||
for _, seg := range parsed.Segments {
|
||||
for _, fr := range seg.Fragments {
|
||||
fs, err := fr.GetFullSamples(trex)
|
||||
if err != nil {
|
||||
fragIdx++
|
||||
continue
|
||||
}
|
||||
for _, s := range fs {
|
||||
dts := int64(s.DecodeTime)
|
||||
if dts < winLo || dts > winHi {
|
||||
sampIdx++
|
||||
continue
|
||||
}
|
||||
for _, nal := range splitAVCC(s.Data) {
|
||||
t := nal[0] & 0x1f
|
||||
if t == 1 || t == 5 { // non-IDR or IDR slice
|
||||
sh, err := avc.ParseSliceHeader(nal, spsMap, ppsMap)
|
||||
if err != nil {
|
||||
fmt.Printf(" s%04d frag%d dts=%d nalType=%d sliceHeader ERR: %v\n", sampIdx, fragIdx, dts, t, err)
|
||||
break
|
||||
}
|
||||
fmt.Printf(" s%04d frag%d dts=%d nalType=%d sliceType=%v frameNum=%d idrPicId=%d pocLsb=%d\n",
|
||||
sampIdx, fragIdx, dts, t, sh.SliceType, sh.FrameNum, sh.IDRPicID, sh.PicOrderCntLsb)
|
||||
break
|
||||
}
|
||||
}
|
||||
sampIdx++
|
||||
}
|
||||
fragIdx++
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// splitAVCC splits a length-prefixed (4-byte) AVCC buffer into NAL units.
|
||||
func splitAVCC(b []byte) [][]byte {
|
||||
var out [][]byte
|
||||
i := 0
|
||||
for i+4 <= len(b) {
|
||||
n := int(uint32(b[i])<<24 | uint32(b[i+1])<<16 | uint32(b[i+2])<<8 | uint32(b[i+3]))
|
||||
i += 4
|
||||
if n <= 0 || i+n > len(b) {
|
||||
break
|
||||
}
|
||||
out = append(out, b[i:i+n])
|
||||
i += n
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
func bytesEqual(a, b []byte) bool {
|
||||
if len(a) != len(b) {
|
||||
return false
|
||||
}
|
||||
for i := range a {
|
||||
if a[i] != b[i] {
|
||||
return false
|
||||
}
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
// nalTypes returns the list of H.264 NAL unit types present in an AVCC
|
||||
// (length-prefixed) sample buffer.
|
||||
func nalTypes(b []byte) []int {
|
||||
var out []int
|
||||
i := 0
|
||||
for i+4 <= len(b) {
|
||||
n := int(uint32(b[i])<<24 | uint32(b[i+1])<<16 | uint32(b[i+2])<<8 | uint32(b[i+3]))
|
||||
i += 4
|
||||
if n <= 0 || i+n > len(b) {
|
||||
break
|
||||
}
|
||||
out = append(out, int(b[i]&0x1f))
|
||||
i += n
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// nalsByType returns the raw NAL payloads (without length prefix) of the given
|
||||
// type from an AVCC (length-prefixed) sample buffer.
|
||||
func nalsByType(b []byte, want int) [][]byte {
|
||||
var out [][]byte
|
||||
i := 0
|
||||
for i+4 <= len(b) {
|
||||
n := int(uint32(b[i])<<24 | uint32(b[i+1])<<16 | uint32(b[i+2])<<8 | uint32(b[i+3]))
|
||||
i += 4
|
||||
if n <= 0 || i+n > len(b) {
|
||||
break
|
||||
}
|
||||
if int(b[i]&0x1f) == want {
|
||||
nal := make([]byte, n)
|
||||
copy(nal, b[i:i+n])
|
||||
out = append(out, nal)
|
||||
}
|
||||
i += n
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// inspectWindow returns the [lo,hi] decode-time range (track timescale units)
|
||||
// for which sample-level detail is printed. Explicit -from/-to win; otherwise
|
||||
// the window auto-centres on the largest gap between consecutive video
|
||||
// keyframes — the most likely location of a visible artifact — with a margin on
|
||||
// each side so the frames leading into and out of the gap are shown too.
|
||||
func inspectWindow(keyDecodeTimes []uint64, from, to int64) (int64, int64) {
|
||||
if from >= 0 || to >= 0 {
|
||||
if from < 0 {
|
||||
from = 0
|
||||
}
|
||||
if to < 0 {
|
||||
to = from + 2000
|
||||
}
|
||||
return from, to
|
||||
}
|
||||
if len(keyDecodeTimes) < 2 {
|
||||
return 0, 1 << 62
|
||||
}
|
||||
worstIdx, worstGap := 1, uint64(0)
|
||||
for i := 1; i < len(keyDecodeTimes); i++ {
|
||||
if g := keyDecodeTimes[i] - keyDecodeTimes[i-1]; g > worstGap {
|
||||
worstGap = g
|
||||
worstIdx = i
|
||||
}
|
||||
}
|
||||
const margin = 500
|
||||
lo := int64(keyDecodeTimes[worstIdx-1]) - margin
|
||||
if lo < 0 {
|
||||
lo = 0
|
||||
}
|
||||
return lo, int64(keyDecodeTimes[worstIdx]) + margin
|
||||
}
|
||||
|
||||
// summary prints a compact, generic health report so a recording can be
|
||||
// validated at a glance without reading the full per-sample dump above.
|
||||
func summary(parsed *mp4ff.File, trex *mp4ff.TrexBox) {
|
||||
fmt.Println("=== SUMMARY (health checks) ===")
|
||||
|
||||
videoTracks, audioTracks := 0, 0
|
||||
var videoTimescale uint64 = 1
|
||||
if parsed.Init != nil && parsed.Init.Moov != nil {
|
||||
for _, trak := range parsed.Init.Moov.Traks {
|
||||
switch trak.Mdia.Hdlr.HandlerType {
|
||||
case "vide":
|
||||
videoTracks++
|
||||
if trak.Mdia.Mdhd.Timescale != 0 {
|
||||
videoTimescale = uint64(trak.Mdia.Mdhd.Timescale)
|
||||
}
|
||||
case "soun":
|
||||
audioTracks++
|
||||
}
|
||||
}
|
||||
}
|
||||
fmt.Printf(" tracks: %d video, %d audio\n", videoTracks, audioTracks)
|
||||
if audioTracks == 0 {
|
||||
fmt.Println(" note: no audio track is embedded in this file")
|
||||
}
|
||||
|
||||
type fragStat struct {
|
||||
idx int
|
||||
tfdt uint64
|
||||
dur uint64
|
||||
nSamp int
|
||||
nKeys int
|
||||
zeroDur int
|
||||
fps float64
|
||||
}
|
||||
var stats []fragStat
|
||||
var keyTimes []uint64
|
||||
var fpsArr []float64
|
||||
tfdtGaps := 0
|
||||
var prevEnd uint64
|
||||
havePrev := false
|
||||
fi := 0
|
||||
for _, seg := range parsed.Segments {
|
||||
for _, fr := range seg.Fragments {
|
||||
for _, traf := range fr.Moof.Trafs {
|
||||
if traf.Tfhd.TrackID != 1 {
|
||||
continue
|
||||
}
|
||||
st := fragStat{idx: fi, tfdt: traf.Tfdt.BaseMediaDecodeTime()}
|
||||
off := uint64(0)
|
||||
for _, trun := range traf.Truns {
|
||||
for _, s := range trun.Samples {
|
||||
st.nSamp++
|
||||
if (s.Flags>>24)&0x03 == 0x02 {
|
||||
st.nKeys++
|
||||
keyTimes = append(keyTimes, st.tfdt+off)
|
||||
}
|
||||
if s.Dur == 0 {
|
||||
st.zeroDur++
|
||||
}
|
||||
off += uint64(s.Dur)
|
||||
}
|
||||
}
|
||||
st.dur = off
|
||||
d := st.dur
|
||||
if d == 0 {
|
||||
d = 1
|
||||
}
|
||||
st.fps = float64(st.nSamp) * float64(videoTimescale) / float64(d)
|
||||
fpsArr = append(fpsArr, st.fps)
|
||||
if havePrev && st.tfdt != prevEnd {
|
||||
tfdtGaps++
|
||||
}
|
||||
prevEnd = st.tfdt + st.dur
|
||||
havePrev = true
|
||||
stats = append(stats, st)
|
||||
}
|
||||
fi++
|
||||
}
|
||||
}
|
||||
|
||||
medFps := medianFloat(fpsArr)
|
||||
fmt.Printf(" fragments: %d (video timescale=%d, median %.1f fps)\n", len(stats), videoTimescale, medFps)
|
||||
lowFps := 0
|
||||
totalZero := 0
|
||||
for _, st := range stats {
|
||||
totalZero += st.zeroDur
|
||||
flagStr := ""
|
||||
if medFps > 0 && st.fps < medFps*0.9 {
|
||||
lowFps++
|
||||
flagStr = " <== LOW FRAME RATE — likely dropped frames"
|
||||
}
|
||||
fmt.Printf(" frag%02d tfdt=%-6d dur=%-5d samples=%-3d keyframes=%d zeroDur=%d fps=%.1f%s\n",
|
||||
st.idx, st.tfdt, st.dur, st.nSamp, st.nKeys, st.zeroDur, st.fps, flagStr)
|
||||
}
|
||||
|
||||
var gaps []uint64
|
||||
for i := 1; i < len(keyTimes); i++ {
|
||||
gaps = append(gaps, keyTimes[i]-keyTimes[i-1])
|
||||
}
|
||||
irregular := 0
|
||||
if len(gaps) > 0 {
|
||||
med := medianUint(gaps)
|
||||
mn, mx := gaps[0], gaps[0]
|
||||
for _, g := range gaps {
|
||||
if g < mn {
|
||||
mn = g
|
||||
}
|
||||
if g > mx {
|
||||
mx = g
|
||||
}
|
||||
// Flag intervals that deviate by more than ~50% from the median GOP.
|
||||
if med > 0 && (g*2 > med*3 || g*2 < med) {
|
||||
irregular++
|
||||
}
|
||||
}
|
||||
fmt.Printf(" keyframe gaps: min=%d median=%d max=%d irregular=%d/%d\n", mn, med, mx, irregular, len(gaps))
|
||||
}
|
||||
fmt.Printf(" tfdt discontinuities: %d\n", tfdtGaps)
|
||||
fmt.Printf(" zero-duration samples: %d\n", totalZero)
|
||||
|
||||
fmt.Println(" verdict:")
|
||||
clean := true
|
||||
if audioTracks == 0 {
|
||||
fmt.Println(" - no audio track (expected if this recording is video-only)")
|
||||
}
|
||||
if lowFps > 0 {
|
||||
clean = false
|
||||
fmt.Printf(" - %d fragment(s) have a reduced frame rate (dropped frames) — likely source of the artifacts\n", lowFps)
|
||||
}
|
||||
if irregular > 0 {
|
||||
clean = false
|
||||
fmt.Printf(" - %d irregular keyframe interval(s)\n", irregular)
|
||||
}
|
||||
if tfdtGaps > 0 {
|
||||
clean = false
|
||||
fmt.Printf(" - %d timeline (tfdt) discontinuity(ies)\n", tfdtGaps)
|
||||
}
|
||||
if totalZero > 0 {
|
||||
clean = false
|
||||
fmt.Printf(" - %d zero-duration sample(s)\n", totalZero)
|
||||
}
|
||||
if clean {
|
||||
fmt.Println(" - container structure looks healthy")
|
||||
}
|
||||
}
|
||||
|
||||
func medianUint(v []uint64) uint64 {
|
||||
if len(v) == 0 {
|
||||
return 0
|
||||
}
|
||||
c := append([]uint64(nil), v...)
|
||||
sort.Slice(c, func(i, j int) bool { return c[i] < c[j] })
|
||||
return c[len(c)/2]
|
||||
}
|
||||
|
||||
func medianFloat(v []float64) float64 {
|
||||
if len(v) == 0 {
|
||||
return 0
|
||||
}
|
||||
c := append([]float64(nil), v...)
|
||||
sort.Float64s(c)
|
||||
return c[len(c)/2]
|
||||
}
|
||||
@@ -1,3 +1,4 @@
|
||||
|
||||
{
|
||||
"type": "",
|
||||
"key": "",
|
||||
@@ -5,14 +6,17 @@
|
||||
"time": "false",
|
||||
"offline": "false",
|
||||
"auto_clean": "true",
|
||||
"max_directory_size": 100,
|
||||
"remove_after_upload": "true",
|
||||
"max_directory_size": 0,
|
||||
"timezone": "Africa/Ceuta",
|
||||
"capture": {
|
||||
"name": "",
|
||||
"ipcamera": {
|
||||
"rtsp": "",
|
||||
"sub_rtsp": "",
|
||||
"fps": ""
|
||||
"fps": "",
|
||||
"base_width": 640,
|
||||
"base_height": 0
|
||||
},
|
||||
"usbcamera": {
|
||||
"device": ""
|
||||
@@ -21,6 +25,11 @@
|
||||
"device": ""
|
||||
},
|
||||
"continuous": "false",
|
||||
"recording": "true",
|
||||
"snapshots": "true",
|
||||
"liveview": "true",
|
||||
"liveview_chunking": "false",
|
||||
"motion": "true",
|
||||
"postrecording": 20,
|
||||
"prerecording": 10,
|
||||
"maxlengthrecording": 30,
|
||||
@@ -89,20 +98,28 @@
|
||||
"s3": {
|
||||
"proxyuri": "http://proxy.kerberos.io",
|
||||
"bucket": "kerberosaccept",
|
||||
"region": "eu-west1"
|
||||
"region": "eu-west-1"
|
||||
},
|
||||
"kstorage": {},
|
||||
"kstorage_secondary": {},
|
||||
"dropbox": {},
|
||||
"mqtturi": "tcp://mqtt.kerberos.io:1883",
|
||||
"mqtt_username": "",
|
||||
"mqtt_password": "",
|
||||
"stunuri": "stun:turn.kerberos.io:8443",
|
||||
"turnuri": "turn:turn.kerberos.io:8443",
|
||||
"turn_force": "false",
|
||||
"stunuri": "stun:turn-fra1.kerberos.io:3478",
|
||||
"turnuri": "turn:turn-fra1.kerberos.io:3478",
|
||||
"turn_username": "username1",
|
||||
"turn_password": "password1",
|
||||
"heartbeaturi": "",
|
||||
"hub_encryption": "true",
|
||||
"hub_uri": "https://api.cloud.kerberos.io",
|
||||
"hub_key": "",
|
||||
"hub_private_key": "",
|
||||
"hub_site": "",
|
||||
"condition_uri": ""
|
||||
"condition_uri": "",
|
||||
"encryption": {},
|
||||
"signing": {},
|
||||
"realtimeprocessing": "false",
|
||||
"realtimeprocessing_topic": ""
|
||||
}
|
||||
0
machinery/data/snapshots/.empty
Normal file
BIN
machinery/data/test-480p.mp4
Normal file
@@ -0,0 +1 @@
|
||||
{"upload_url":"https://vault.kerberos.io/api/storage/tus/19e42fbc666a38064904caf8c46d182a","vault_uri":"https://vault.kerberos.io/api/storage/tus/","size":1591581}
|
||||
@@ -0,0 +1 @@
|
||||
{"upload_url":"https://vault.kerberos.io/api/storage/tus/bd3be0f9ecd3873d381f57cb8b4a7e96","vault_uri":"https://vault.kerberos.io/api/storage/tus/","size":2560480}
|
||||
@@ -1,8 +1,120 @@
|
||||
basePath: /
|
||||
definitions:
|
||||
http.Health:
|
||||
properties:
|
||||
cameraConnected:
|
||||
type: boolean
|
||||
description:
|
||||
type: string
|
||||
hub:
|
||||
$ref: '#/definitions/http.HubHealth'
|
||||
mainStream:
|
||||
$ref: '#/definitions/http.StreamHealth'
|
||||
subStream:
|
||||
$ref: '#/definitions/http.StreamHealth'
|
||||
type: object
|
||||
http.HealthResponse:
|
||||
properties:
|
||||
applicationStatusCode:
|
||||
type: string
|
||||
data:
|
||||
$ref: '#/definitions/http.HealthResponseData'
|
||||
entityStatusCode:
|
||||
type: string
|
||||
httpStatusCode:
|
||||
type: integer
|
||||
message:
|
||||
type: string
|
||||
metadata:
|
||||
$ref: '#/definitions/http.ResponseMetadata'
|
||||
type: object
|
||||
http.HealthResponseData:
|
||||
properties:
|
||||
health:
|
||||
$ref: '#/definitions/http.Health'
|
||||
type: object
|
||||
http.HubHealth:
|
||||
properties:
|
||||
configured:
|
||||
type: boolean
|
||||
connected:
|
||||
type: boolean
|
||||
lastHeartbeatAttemptAt:
|
||||
type: integer
|
||||
lastSuccessfulHeartbeatAt:
|
||||
type: integer
|
||||
type: object
|
||||
http.ResponseMetadata:
|
||||
properties:
|
||||
applicationName:
|
||||
type: string
|
||||
applicationVersion:
|
||||
type: string
|
||||
path:
|
||||
type: string
|
||||
timestamp:
|
||||
type: integer
|
||||
traceId:
|
||||
type: string
|
||||
type: object
|
||||
http.StreamHealth:
|
||||
properties:
|
||||
configured:
|
||||
type: boolean
|
||||
connected:
|
||||
type: boolean
|
||||
fps:
|
||||
type: number
|
||||
lastPacketAt:
|
||||
type: integer
|
||||
packagesProcessed:
|
||||
type: integer
|
||||
resolution:
|
||||
$ref: '#/definitions/http.StreamResolution'
|
||||
type: object
|
||||
http.StreamResolution:
|
||||
properties:
|
||||
height:
|
||||
type: integer
|
||||
width:
|
||||
type: integer
|
||||
type: object
|
||||
models.APIResponse:
|
||||
properties:
|
||||
can_pan_tilt:
|
||||
type: boolean
|
||||
can_zoom:
|
||||
type: boolean
|
||||
data: {}
|
||||
message: {}
|
||||
ptz_functions: {}
|
||||
type: object
|
||||
models.Authentication:
|
||||
properties:
|
||||
password:
|
||||
type: string
|
||||
username:
|
||||
type: string
|
||||
type: object
|
||||
models.Authorization:
|
||||
properties:
|
||||
code:
|
||||
type: integer
|
||||
expire:
|
||||
type: string
|
||||
role:
|
||||
type: string
|
||||
token:
|
||||
type: string
|
||||
username:
|
||||
type: string
|
||||
type: object
|
||||
models.CameraStreams:
|
||||
properties:
|
||||
rtsp:
|
||||
type: string
|
||||
sub_rtsp:
|
||||
type: string
|
||||
type: object
|
||||
models.Capture:
|
||||
properties:
|
||||
@@ -14,12 +126,31 @@ definitions:
|
||||
type: string
|
||||
fragmentedduration:
|
||||
type: integer
|
||||
gopsize:
|
||||
description: GOP size in seconds, used for pre-recording
|
||||
type: integer
|
||||
ipcamera:
|
||||
$ref: '#/definitions/models.IPCamera'
|
||||
liveview:
|
||||
type: string
|
||||
liveview_chunking:
|
||||
type: string
|
||||
maxlengthrecording:
|
||||
type: integer
|
||||
motion:
|
||||
type: string
|
||||
name:
|
||||
type: string
|
||||
onvif_motion:
|
||||
description: |-
|
||||
ONVIFMotion routes the camera's ONVIF motion events into the
|
||||
agent's motion-triggered recording pipeline. When "true" the
|
||||
agent opens an event/stream against the configured ONVIF
|
||||
endpoint and forwards Motion+Active events to HandleMotion.
|
||||
Requires Capture.IPCamera.ONVIFXAddr / ONVIFUsername /
|
||||
ONVIFPassword to be set. Default empty (disabled) keeps the
|
||||
existing pixel-diff motion detection as the only source.
|
||||
type: string
|
||||
pixelChangeThreshold:
|
||||
type: integer
|
||||
postrecording:
|
||||
@@ -28,6 +159,10 @@ definitions:
|
||||
type: integer
|
||||
raspicamera:
|
||||
$ref: '#/definitions/models.RaspiCamera'
|
||||
recording:
|
||||
type: string
|
||||
snapshots:
|
||||
type: string
|
||||
transcodingresolution:
|
||||
type: integer
|
||||
transcodingwebrtc:
|
||||
@@ -37,15 +172,25 @@ definitions:
|
||||
type: object
|
||||
models.Config:
|
||||
properties:
|
||||
auto_clean:
|
||||
type: string
|
||||
capture:
|
||||
$ref: '#/definitions/models.Capture'
|
||||
cloud:
|
||||
type: string
|
||||
condition_uri:
|
||||
type: string
|
||||
dropbox:
|
||||
$ref: '#/definitions/models.Dropbox'
|
||||
encryption:
|
||||
$ref: '#/definitions/models.Encryption'
|
||||
friendly_name:
|
||||
type: string
|
||||
heartbeaturi:
|
||||
description: obsolete
|
||||
type: string
|
||||
hub_encryption:
|
||||
type: string
|
||||
hub_key:
|
||||
type: string
|
||||
hub_private_key:
|
||||
@@ -58,6 +203,12 @@ definitions:
|
||||
type: string
|
||||
kstorage:
|
||||
$ref: '#/definitions/models.KStorage'
|
||||
kstorage_secondary:
|
||||
$ref: '#/definitions/models.KStorage'
|
||||
max_directory_size:
|
||||
type: integer
|
||||
min_free_space:
|
||||
type: integer
|
||||
mqtt_password:
|
||||
type: string
|
||||
mqtt_username:
|
||||
@@ -68,10 +219,18 @@ definitions:
|
||||
type: string
|
||||
offline:
|
||||
type: string
|
||||
realtimeprocessing:
|
||||
type: string
|
||||
realtimeprocessing_topic:
|
||||
type: string
|
||||
region:
|
||||
$ref: '#/definitions/models.Region'
|
||||
remove_after_upload:
|
||||
type: string
|
||||
s3:
|
||||
$ref: '#/definitions/models.S3'
|
||||
signing:
|
||||
$ref: '#/definitions/models.Signing'
|
||||
stunuri:
|
||||
type: string
|
||||
time:
|
||||
@@ -82,6 +241,8 @@ definitions:
|
||||
type: array
|
||||
timezone:
|
||||
type: string
|
||||
turn_force:
|
||||
type: string
|
||||
turn_password:
|
||||
type: string
|
||||
turn_username:
|
||||
@@ -98,38 +259,168 @@ definitions:
|
||||
"y":
|
||||
type: number
|
||||
type: object
|
||||
models.Dropbox:
|
||||
properties:
|
||||
access_token:
|
||||
type: string
|
||||
directory:
|
||||
type: string
|
||||
type: object
|
||||
models.Encryption:
|
||||
properties:
|
||||
enabled:
|
||||
type: string
|
||||
fingerprint:
|
||||
type: string
|
||||
private_key:
|
||||
type: string
|
||||
recordings:
|
||||
type: string
|
||||
symmetric_key:
|
||||
type: string
|
||||
type: object
|
||||
models.EventFilter:
|
||||
properties:
|
||||
number_of_elements:
|
||||
type: integer
|
||||
timestamp_offset_end:
|
||||
type: integer
|
||||
timestamp_offset_start:
|
||||
type: integer
|
||||
type: object
|
||||
models.IPCamera:
|
||||
properties:
|
||||
base_height:
|
||||
type: integer
|
||||
base_width:
|
||||
type: integer
|
||||
channels:
|
||||
type: integer
|
||||
fps:
|
||||
type: string
|
||||
height:
|
||||
type: integer
|
||||
onvif:
|
||||
type: boolean
|
||||
type: string
|
||||
onvif_password:
|
||||
type: string
|
||||
onvif_username:
|
||||
type: string
|
||||
onvif_xaddr:
|
||||
type: string
|
||||
pps_nalus:
|
||||
items:
|
||||
items:
|
||||
format: int32
|
||||
type: integer
|
||||
type: array
|
||||
type: array
|
||||
rtsp:
|
||||
type: string
|
||||
sample_rate:
|
||||
type: integer
|
||||
sps_nalus:
|
||||
items:
|
||||
items:
|
||||
format: int32
|
||||
type: integer
|
||||
type: array
|
||||
type: array
|
||||
sub_fps:
|
||||
type: string
|
||||
sub_height:
|
||||
type: integer
|
||||
sub_pps_nalus:
|
||||
items:
|
||||
items:
|
||||
format: int32
|
||||
type: integer
|
||||
type: array
|
||||
type: array
|
||||
sub_rtsp:
|
||||
type: string
|
||||
sub_sps_nalus:
|
||||
description: |-
|
||||
Sub stream parameter sets, captured separately from the main stream so the
|
||||
live HLS muxer can build a correct init segment when a viewer switches the
|
||||
live view to the sub (low-resolution) stream.
|
||||
items:
|
||||
items:
|
||||
format: int32
|
||||
type: integer
|
||||
type: array
|
||||
type: array
|
||||
sub_vps_nalus:
|
||||
items:
|
||||
items:
|
||||
format: int32
|
||||
type: integer
|
||||
type: array
|
||||
type: array
|
||||
sub_width:
|
||||
type: integer
|
||||
vps_nalus:
|
||||
items:
|
||||
items:
|
||||
format: int32
|
||||
type: integer
|
||||
type: array
|
||||
type: array
|
||||
width:
|
||||
type: integer
|
||||
type: object
|
||||
models.KStorage:
|
||||
properties:
|
||||
access_key:
|
||||
type: string
|
||||
cloud_key:
|
||||
description: old way, remove this
|
||||
type: string
|
||||
directory:
|
||||
type: string
|
||||
max_retries:
|
||||
type: integer
|
||||
provider:
|
||||
type: string
|
||||
secret_access_key:
|
||||
type: string
|
||||
timeout:
|
||||
type: integer
|
||||
uri:
|
||||
type: string
|
||||
type: object
|
||||
models.OnvifCredentials:
|
||||
properties:
|
||||
onvif_password:
|
||||
type: string
|
||||
onvif_username:
|
||||
type: string
|
||||
onvif_xaddr:
|
||||
type: string
|
||||
type: object
|
||||
models.OnvifPanTilt:
|
||||
properties:
|
||||
onvif_credentials:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
pan:
|
||||
type: number
|
||||
tilt:
|
||||
type: number
|
||||
type: object
|
||||
models.OnvifPreset:
|
||||
properties:
|
||||
onvif_credentials:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
preset:
|
||||
type: string
|
||||
type: object
|
||||
models.OnvifZoom:
|
||||
properties:
|
||||
onvif_credentials:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
zoom:
|
||||
type: number
|
||||
type: object
|
||||
models.Polygon:
|
||||
properties:
|
||||
coordinates:
|
||||
@@ -183,6 +474,13 @@ definitions:
|
||||
username:
|
||||
type: string
|
||||
type: object
|
||||
models.Signing:
|
||||
properties:
|
||||
enabled:
|
||||
type: string
|
||||
private_key:
|
||||
type: string
|
||||
type: object
|
||||
models.Timetable:
|
||||
properties:
|
||||
end1:
|
||||
@@ -212,6 +510,363 @@ info:
|
||||
title: Swagger Kerberos Agent API
|
||||
version: "1.0"
|
||||
paths:
|
||||
/api/camera/discover:
|
||||
get:
|
||||
description: Runs an advanced Fing/WiFiman-style scan (ONVIF WS-Discovery +
|
||||
TCP port scan + MAC/vendor lookup) and returns the devices found on the local
|
||||
network.
|
||||
operationId: camera-discover
|
||||
parameters:
|
||||
- description: Discovery timeout in milliseconds (default 2000)
|
||||
in: query
|
||||
name: timeout
|
||||
type: integer
|
||||
- description: Optional subnet(s) to scan, e.g. '192.168.1.0/24' (comma-separated).
|
||||
Defaults to the local interfaces.
|
||||
in: query
|
||||
name: subnet
|
||||
type: string
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Discover cameras and other devices on the local network.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/capabilities:
|
||||
post:
|
||||
description: Will return the ONVIF capabilities for the specific camera.
|
||||
operationId: camera-onvif-capabilities
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Will return the ONVIF capabilities for the specific camera.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/gotopreset:
|
||||
post:
|
||||
description: Will activate the desired ONVIF preset.
|
||||
operationId: camera-onvif-gotopreset
|
||||
parameters:
|
||||
- description: OnvifPreset
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifPreset'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Will activate the desired ONVIF preset.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/inputs:
|
||||
post:
|
||||
description: Will get the digital inputs from the ONVIF device.
|
||||
operationId: get-digital-inputs
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
security:
|
||||
- Bearer: []
|
||||
summary: Will get the digital inputs from the ONVIF device.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/login:
|
||||
post:
|
||||
description: Try to login into ONVIF supported camera.
|
||||
operationId: camera-onvif-login
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Try to login into ONVIF supported camera.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/outputs:
|
||||
post:
|
||||
description: Will get the relay outputs from the ONVIF device.
|
||||
operationId: get-relay-outputs
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
security:
|
||||
- Bearer: []
|
||||
summary: Will get the relay outputs from the ONVIF device.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/outputs/{output}:
|
||||
post:
|
||||
description: Will trigger the relay output from the ONVIF device.
|
||||
operationId: trigger-relay-output
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
- description: Output
|
||||
in: path
|
||||
name: output
|
||||
required: true
|
||||
type: string
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
security:
|
||||
- Bearer: []
|
||||
summary: Will trigger the relay output from the ONVIF device.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/pantilt:
|
||||
post:
|
||||
description: Panning or/and tilting the camera using a direction (x,y).
|
||||
operationId: camera-onvif-pantilt
|
||||
parameters:
|
||||
- description: OnvifPanTilt
|
||||
in: body
|
||||
name: panTilt
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifPanTilt'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Panning or/and tilting the camera.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/presets:
|
||||
post:
|
||||
description: Will return the ONVIF presets for the specific camera.
|
||||
operationId: camera-onvif-presets
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Will return the ONVIF presets for the specific camera.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/verify:
|
||||
post:
|
||||
description: Will verify the ONVIF connectivity.
|
||||
operationId: verify-onvif
|
||||
parameters:
|
||||
- description: OnvifCredentials
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifCredentials'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
security:
|
||||
- Bearer: []
|
||||
summary: Will verify the ONVIF connectivity.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/onvif/zoom:
|
||||
post:
|
||||
description: Zooming in or out the camera.
|
||||
operationId: camera-onvif-zoom
|
||||
parameters:
|
||||
- description: OnvifZoom
|
||||
in: body
|
||||
name: zoom
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.OnvifZoom'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Zooming in or out the camera.
|
||||
tags:
|
||||
- onvif
|
||||
/api/camera/record:
|
||||
post:
|
||||
description: Make a recording.
|
||||
operationId: camera-record
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Make a recording.
|
||||
tags:
|
||||
- camera
|
||||
/api/camera/restart:
|
||||
post:
|
||||
description: Restart the agent.
|
||||
operationId: camera-restart
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Restart the agent.
|
||||
tags:
|
||||
- camera
|
||||
/api/camera/snapshot/base64:
|
||||
get:
|
||||
description: Get a snapshot from the camera in base64.
|
||||
operationId: snapshot-base64
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Get a snapshot from the camera in base64.
|
||||
tags:
|
||||
- camera
|
||||
/api/camera/snapshot/jpeg:
|
||||
get:
|
||||
description: Get a snapshot from the camera in jpeg format.
|
||||
operationId: snapshot-jpeg
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Get a snapshot from the camera in jpeg format.
|
||||
tags:
|
||||
- camera
|
||||
/api/camera/stop:
|
||||
post:
|
||||
description: Stop the agent.
|
||||
operationId: camera-stop
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Stop the agent.
|
||||
tags:
|
||||
- camera
|
||||
/api/camera/verify/{streamType}:
|
||||
post:
|
||||
description: This method will validate a specific profile connection from an
|
||||
RTSP camera, and try to get the codec.
|
||||
operationId: verify-camera
|
||||
parameters:
|
||||
- description: Stream Type
|
||||
enum:
|
||||
- primary
|
||||
- secondary
|
||||
in: path
|
||||
name: streamType
|
||||
required: true
|
||||
type: string
|
||||
- description: Camera Streams
|
||||
in: body
|
||||
name: cameraStreams
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.CameraStreams'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
summary: Validate a specific RTSP profile camera connection.
|
||||
tags:
|
||||
- camera
|
||||
/api/config:
|
||||
get:
|
||||
description: Get the current configuration.
|
||||
operationId: config
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Get the current configuration.
|
||||
tags:
|
||||
- config
|
||||
post:
|
||||
description: Update the current configuration.
|
||||
operationId: config
|
||||
parameters:
|
||||
- description: Configuration
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.Config'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Update the current configuration.
|
||||
tags:
|
||||
- config
|
||||
/api/dashboard:
|
||||
get:
|
||||
description: Get all information showed on the dashboard.
|
||||
operationId: dashboard
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Get all information showed on the dashboard.
|
||||
tags:
|
||||
- general
|
||||
/api/days:
|
||||
get:
|
||||
description: Get all days stored in the recordings directory.
|
||||
operationId: days
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Get all days stored in the recordings directory.
|
||||
tags:
|
||||
- general
|
||||
/api/hub/verify:
|
||||
post:
|
||||
description: Will verify the hub connectivity.
|
||||
@@ -232,7 +887,64 @@ paths:
|
||||
- Bearer: []
|
||||
summary: Will verify the hub connectivity.
|
||||
tags:
|
||||
- config
|
||||
- persistence
|
||||
/api/latest-events:
|
||||
post:
|
||||
description: Get the latest recordings (events) from the recordings directory.
|
||||
operationId: latest-events
|
||||
parameters:
|
||||
- description: Event filter
|
||||
in: body
|
||||
name: eventFilter
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.EventFilter'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
summary: Get the latest recordings (events) from the recordings directory.
|
||||
tags:
|
||||
- general
|
||||
/api/login:
|
||||
post:
|
||||
description: Get Authorization token.
|
||||
operationId: login
|
||||
parameters:
|
||||
- description: Credentials
|
||||
in: body
|
||||
name: credentials
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.Authentication'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.Authorization'
|
||||
summary: Get Authorization token.
|
||||
tags:
|
||||
- authentication
|
||||
/api/persistence/secondary/verify:
|
||||
post:
|
||||
description: Will verify the secondary persistence.
|
||||
operationId: verify-secondary-persistence
|
||||
parameters:
|
||||
- description: Config
|
||||
in: body
|
||||
name: config
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/definitions/models.Config'
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/models.APIResponse'
|
||||
security:
|
||||
- Bearer: []
|
||||
summary: Will verify the secondary persistence.
|
||||
tags:
|
||||
- persistence
|
||||
/api/persistence/verify:
|
||||
post:
|
||||
description: Will verify the persistence.
|
||||
@@ -253,7 +965,22 @@ paths:
|
||||
- Bearer: []
|
||||
summary: Will verify the persistence.
|
||||
tags:
|
||||
- config
|
||||
- persistence
|
||||
/health:
|
||||
get:
|
||||
description: Confirms that the Agent HTTP process can serve requests and reports
|
||||
current camera stream and Hub heartbeat diagnostics. Operational dependency
|
||||
failures do not change the liveness HTTP status.
|
||||
produces:
|
||||
- application/json
|
||||
responses:
|
||||
"200":
|
||||
description: OK
|
||||
schema:
|
||||
$ref: '#/definitions/http.HealthResponse'
|
||||
summary: Check Agent health
|
||||
tags:
|
||||
- health
|
||||
securityDefinitions:
|
||||
Bearer:
|
||||
in: header
|
||||
|
||||
188
machinery/go.mod
@@ -1,100 +1,144 @@
|
||||
module github.com/kerberos-io/agent/machinery
|
||||
|
||||
go 1.18
|
||||
go 1.25.0
|
||||
|
||||
//replace github.com/kerberos-io/joy4 v1.0.33 => ../../../../github.com/kerberos-io/joy4
|
||||
replace google.golang.org/genproto => google.golang.org/genproto v0.0.0-20250519155744-55703ea1f237
|
||||
|
||||
require (
|
||||
github.com/Eyevinn/mp4ff v0.48.0
|
||||
github.com/InVisionApp/conjungo v1.1.0
|
||||
github.com/appleboy/gin-jwt/v2 v2.8.0
|
||||
github.com/appleboy/gin-jwt/v2 v2.10.3
|
||||
github.com/bluenviron/gortsplib/v5 v5.6.3
|
||||
github.com/bluenviron/mediacommon v1.14.0
|
||||
github.com/cedricve/go-onvif v0.0.0-20200222191200-567e8ce298f6
|
||||
github.com/deepch/vdk v0.0.19
|
||||
github.com/eclipse/paho.mqtt.golang v1.4.1
|
||||
github.com/gin-contrib/cors v1.4.0
|
||||
github.com/gin-contrib/pprof v1.4.0
|
||||
github.com/gin-gonic/contrib v0.0.0-20201101042839-6a891bf89f19
|
||||
github.com/gin-gonic/gin v1.8.1
|
||||
github.com/golang-jwt/jwt/v4 v4.4.2
|
||||
github.com/creack/pty v1.1.24
|
||||
github.com/dromara/carbon/v2 v2.6.8
|
||||
github.com/dropbox/dropbox-sdk-go-unofficial/v6 v6.0.5
|
||||
github.com/eclipse/paho.mqtt.golang v1.5.0
|
||||
github.com/elastic/go-sysinfo v1.15.3
|
||||
github.com/gin-contrib/cors v1.7.5
|
||||
github.com/gin-contrib/pprof v1.5.3
|
||||
github.com/gin-gonic/contrib v0.0.0-20250521004450-2b1292699c15
|
||||
github.com/gin-gonic/gin v1.10.1
|
||||
github.com/gofrs/uuid v4.4.0+incompatible
|
||||
github.com/golang-jwt/jwt/v4 v4.5.2
|
||||
github.com/gorilla/websocket v1.5.3
|
||||
github.com/kellydunn/golang-geo v0.7.0
|
||||
github.com/kerberos-io/joy4 v1.0.33
|
||||
github.com/kerberos-io/onvif v0.0.3
|
||||
github.com/kerberos-io/joy4 v1.0.64
|
||||
github.com/kerberos-io/onvif v1.2.2
|
||||
github.com/minio/minio-go/v6 v6.0.57
|
||||
github.com/nsmith5/mjpeg v0.0.0-20200913181537-54b8ada0e53e
|
||||
github.com/op/go-logging v0.0.0-20160315200505-970db520ece7
|
||||
github.com/pion/webrtc/v3 v3.1.43
|
||||
github.com/shirou/gopsutil v3.21.11+incompatible
|
||||
github.com/sirupsen/logrus v1.9.0
|
||||
github.com/swaggo/files v0.0.0-20220728132757-551d4a08d97a
|
||||
github.com/swaggo/gin-swagger v1.5.2
|
||||
github.com/swaggo/swag v1.8.4
|
||||
github.com/moq-dev/moq-go v0.5.7
|
||||
github.com/nfnt/resize v0.0.0-20180221191011-83c6a9932646
|
||||
github.com/pion/interceptor v0.1.47
|
||||
github.com/pion/rtp v1.10.5
|
||||
github.com/pion/webrtc/v4 v4.2.18
|
||||
github.com/sirupsen/logrus v1.9.3
|
||||
github.com/stretchr/testify v1.11.1
|
||||
github.com/swaggo/files v1.0.1
|
||||
github.com/swaggo/gin-swagger v1.6.0
|
||||
github.com/swaggo/swag v1.16.4
|
||||
github.com/tevino/abool v1.2.0
|
||||
gocv.io/x/gocv v0.31.0
|
||||
gopkg.in/mgo.v2 v2.0.0-20190816093944-a6b53ec6cb22
|
||||
gopkg.in/natefinch/lumberjack.v2 v2.0.0
|
||||
github.com/zaf/g711 v1.4.0
|
||||
go.mongodb.org/mongo-driver v1.17.3
|
||||
go.opentelemetry.io/otel v1.36.0
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.36.0
|
||||
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.36.0
|
||||
go.opentelemetry.io/otel/sdk v1.36.0
|
||||
go.opentelemetry.io/otel/trace v1.36.0
|
||||
)
|
||||
|
||||
require (
|
||||
github.com/KyleBanks/depth v1.2.1 // indirect
|
||||
github.com/beevik/etree v1.1.0 // indirect
|
||||
github.com/PuerkitoBio/purell v1.1.1 // indirect
|
||||
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 // indirect
|
||||
github.com/beevik/etree v1.2.0 // indirect
|
||||
github.com/bluenviron/mediacommon/v2 v2.9.2 // indirect
|
||||
github.com/bytedance/sonic v1.13.2 // indirect
|
||||
github.com/bytedance/sonic/loader v0.2.4 // indirect
|
||||
github.com/cenkalti/backoff/v5 v5.0.2 // indirect
|
||||
github.com/clbanning/mxj v1.8.4 // indirect
|
||||
github.com/elgs/gostrgen v0.0.0-20220325073726-0c3e00d082f6 // indirect
|
||||
github.com/clbanning/mxj/v2 v2.7.0 // indirect
|
||||
github.com/cloudwego/base64x v0.1.5 // indirect
|
||||
github.com/davecgh/go-spew v1.1.1 // indirect
|
||||
github.com/elastic/go-windows v1.0.2 // indirect
|
||||
github.com/elgs/gostrgen v0.0.0-20161222160715-9d61ae07eeae // indirect
|
||||
github.com/erikstmartin/go-testdb v0.0.0-20160219214506-8d10e4a1bae5 // indirect
|
||||
github.com/gin-contrib/sse v0.1.0 // indirect
|
||||
github.com/go-ole/go-ole v1.2.6 // indirect
|
||||
github.com/gabriel-vasile/mimetype v1.4.8 // indirect
|
||||
github.com/gin-contrib/sse v1.0.0 // indirect
|
||||
github.com/go-logr/logr v1.4.2 // indirect
|
||||
github.com/go-logr/stdr v1.2.2 // indirect
|
||||
github.com/go-openapi/jsonpointer v0.19.5 // indirect
|
||||
github.com/go-openapi/jsonreference v0.20.0 // indirect
|
||||
github.com/go-openapi/spec v0.20.6 // indirect
|
||||
github.com/go-openapi/swag v0.22.0 // indirect
|
||||
github.com/go-playground/locales v0.14.0 // indirect
|
||||
github.com/go-playground/universal-translator v0.18.0 // indirect
|
||||
github.com/go-playground/validator/v10 v10.11.0 // indirect
|
||||
github.com/goccy/go-json v0.9.10 // indirect
|
||||
github.com/gofrs/uuid v4.2.0+incompatible // indirect
|
||||
github.com/google/uuid v1.3.0 // indirect
|
||||
github.com/gorilla/websocket v1.5.0 // indirect
|
||||
github.com/go-openapi/jsonreference v0.19.6 // indirect
|
||||
github.com/go-openapi/spec v0.20.4 // indirect
|
||||
github.com/go-openapi/swag v0.19.15 // indirect
|
||||
github.com/go-playground/locales v0.14.1 // indirect
|
||||
github.com/go-playground/universal-translator v0.18.1 // indirect
|
||||
github.com/go-playground/validator/v10 v10.26.0 // indirect
|
||||
github.com/goccy/go-json v0.10.5 // indirect
|
||||
github.com/golang/snappy v0.0.4 // indirect
|
||||
github.com/google/uuid v1.6.0 // indirect
|
||||
github.com/grpc-ecosystem/grpc-gateway/v2 v2.26.3 // indirect
|
||||
github.com/josharian/intern v1.0.0 // indirect
|
||||
github.com/json-iterator/go v1.1.12 // indirect
|
||||
github.com/klauspost/cpuid/v2 v2.1.0 // indirect
|
||||
github.com/juju/errors v1.0.0 // indirect
|
||||
github.com/klauspost/compress v1.16.7 // indirect
|
||||
github.com/klauspost/cpuid v1.2.3 // indirect
|
||||
github.com/klauspost/cpuid/v2 v2.2.10 // indirect
|
||||
github.com/kylelemons/go-gypsy v1.0.0 // indirect
|
||||
github.com/leodido/go-urn v1.2.1 // indirect
|
||||
github.com/lib/pq v1.10.6 // indirect
|
||||
github.com/mailru/easyjson v0.7.7 // indirect
|
||||
github.com/mattn/go-isatty v0.0.14 // indirect
|
||||
github.com/minio/md5-simd v1.1.2 // indirect
|
||||
github.com/minio/sha256-simd v1.0.0 // indirect
|
||||
github.com/leodido/go-urn v1.4.0 // indirect
|
||||
github.com/lib/pq v1.10.9 // indirect
|
||||
github.com/mailru/easyjson v0.7.6 // indirect
|
||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||
github.com/minio/md5-simd v1.1.0 // indirect
|
||||
github.com/minio/sha256-simd v0.1.1 // indirect
|
||||
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
||||
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
|
||||
github.com/modern-go/reflect2 v1.0.2 // indirect
|
||||
github.com/pelletier/go-toml/v2 v2.0.2 // indirect
|
||||
github.com/pion/datachannel v1.5.2 // indirect
|
||||
github.com/pion/dtls/v2 v2.1.5 // indirect
|
||||
github.com/pion/ice/v2 v2.2.7 // indirect
|
||||
github.com/pion/interceptor v0.1.12 // indirect
|
||||
github.com/pion/logging v0.2.2 // indirect
|
||||
github.com/pion/mdns v0.0.5 // indirect
|
||||
github.com/montanaflynn/stats v0.7.1 // indirect
|
||||
github.com/moq-dev/moq-go-ffi v0.3.7 // indirect
|
||||
github.com/nxadm/tail v1.4.11 // indirect
|
||||
github.com/pelletier/go-toml/v2 v2.2.3 // indirect
|
||||
github.com/pion/datachannel v1.6.2 // indirect
|
||||
github.com/pion/dtls/v3 v3.1.5 // indirect
|
||||
github.com/pion/ice/v4 v4.4.0 // indirect
|
||||
github.com/pion/logging v0.2.4 // indirect
|
||||
github.com/pion/mdns/v2 v2.1.0 // indirect
|
||||
github.com/pion/randutil v0.1.0 // indirect
|
||||
github.com/pion/rtcp v1.2.10 // indirect
|
||||
github.com/pion/rtp v1.7.13 // indirect
|
||||
github.com/pion/sctp v1.8.2 // indirect
|
||||
github.com/pion/sdp/v3 v3.0.6 // indirect
|
||||
github.com/pion/srtp/v2 v2.0.10 // indirect
|
||||
github.com/pion/stun v0.3.5 // indirect
|
||||
github.com/pion/transport v0.13.1 // indirect
|
||||
github.com/pion/turn/v2 v2.0.8 // indirect
|
||||
github.com/pion/udp v0.1.1 // indirect
|
||||
github.com/tklauser/go-sysconf v0.3.10 // indirect
|
||||
github.com/tklauser/numcpus v0.5.0 // indirect
|
||||
github.com/ugorji/go/codec v1.2.7 // indirect
|
||||
github.com/yusufpapurcu/wmi v1.2.2 // indirect
|
||||
github.com/pion/rtcp v1.2.17 // indirect
|
||||
github.com/pion/sctp v1.11.1 // indirect
|
||||
github.com/pion/sdp/v3 v3.0.19 // indirect
|
||||
github.com/pion/srtp/v3 v3.0.12 // indirect
|
||||
github.com/pion/stun/v3 v3.1.6 // indirect
|
||||
github.com/pion/transport/v4 v4.0.2 // indirect
|
||||
github.com/pion/turn/v5 v5.0.12 // indirect
|
||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||
github.com/prometheus/procfs v0.15.1 // indirect
|
||||
github.com/twitchyliquid64/golang-asm v0.15.1 // indirect
|
||||
github.com/ugorji/go/codec v1.2.12 // indirect
|
||||
github.com/wlynxg/anet v0.0.5 // indirect
|
||||
github.com/xdg-go/pbkdf2 v1.0.0 // indirect
|
||||
github.com/xdg-go/scram v1.1.2 // indirect
|
||||
github.com/xdg-go/stringprep v1.0.4 // indirect
|
||||
github.com/youmark/pkcs8 v0.0.0-20240726163527-a2c0da244d78 // indirect
|
||||
github.com/ziutek/mymysql v1.5.4 // indirect
|
||||
golang.org/x/crypto v0.0.0-20220722155217-630584e8d5aa // indirect
|
||||
golang.org/x/net v0.0.0-20220812174116-3211cb980234 // indirect
|
||||
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4 // indirect
|
||||
golang.org/x/sys v0.0.0-20220811171246-fbc7d0a398ab // indirect
|
||||
golang.org/x/text v0.3.7 // indirect
|
||||
golang.org/x/tools v0.1.12 // indirect
|
||||
google.golang.org/protobuf v1.28.1 // indirect
|
||||
gopkg.in/ini.v1 v1.67.0 // indirect
|
||||
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
|
||||
go.opentelemetry.io/otel/metric v1.36.0 // indirect
|
||||
go.opentelemetry.io/proto/otlp v1.6.0 // indirect
|
||||
golang.org/x/arch v0.16.0 // indirect
|
||||
golang.org/x/crypto v0.54.0 // indirect
|
||||
golang.org/x/net v0.57.0 // indirect
|
||||
golang.org/x/oauth2 v0.30.0 // indirect
|
||||
golang.org/x/sync v0.22.0 // indirect
|
||||
golang.org/x/sys v0.47.0 // indirect
|
||||
golang.org/x/text v0.40.0 // indirect
|
||||
golang.org/x/time v0.14.0 // indirect
|
||||
golang.org/x/tools v0.47.0 // indirect
|
||||
google.golang.org/genproto/googleapis/api v0.0.0-20250519155744-55703ea1f237 // indirect
|
||||
google.golang.org/genproto/googleapis/rpc v0.0.0-20250519155744-55703ea1f237 // indirect
|
||||
google.golang.org/grpc v1.72.1 // indirect
|
||||
google.golang.org/protobuf v1.36.6 // indirect
|
||||
gopkg.in/ini.v1 v1.42.0 // indirect
|
||||
gopkg.in/yaml.v2 v2.4.0 // indirect
|
||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||
howett.net/plist v0.0.0-20181124034731-591f970eefbb // indirect
|
||||
)
|
||||
|
||||
2194
machinery/go.sum
160
machinery/logging.go
Normal file
@@ -0,0 +1,160 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
log "github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
const (
|
||||
defaultLogLevel = log.InfoLevel
|
||||
defaultLogOutput = "text"
|
||||
)
|
||||
|
||||
type localTimeFormatter struct {
|
||||
timezone *time.Location
|
||||
formatter log.Formatter
|
||||
}
|
||||
|
||||
func (f localTimeFormatter) Format(entry *log.Entry) ([]byte, error) {
|
||||
entry.Time = entry.Time.In(f.timezone)
|
||||
return f.formatter.Format(entry)
|
||||
}
|
||||
|
||||
type componentHook struct{}
|
||||
|
||||
func (componentHook) Levels() []log.Level {
|
||||
return log.AllLevels
|
||||
}
|
||||
|
||||
func (componentHook) Fire(entry *log.Entry) error {
|
||||
if _, exists := entry.Data["component"]; exists {
|
||||
return nil
|
||||
}
|
||||
entry.Data["component"] = componentFromCaller(entry.Caller)
|
||||
return nil
|
||||
}
|
||||
|
||||
func configureLogging(levelValue string, outputValue string, timezone *time.Location) {
|
||||
configureLogger(log.StandardLogger(), levelValue, outputValue, timezone)
|
||||
}
|
||||
|
||||
func configureLogger(logger *log.Logger, levelValue string, outputValue string, timezone *time.Location) {
|
||||
if timezone == nil {
|
||||
timezone = time.Local
|
||||
}
|
||||
|
||||
level, levelErr := parseLogLevel(levelValue)
|
||||
output, outputErr := parseLogOutput(outputValue)
|
||||
|
||||
logger.SetOutput(os.Stdout)
|
||||
logger.SetLevel(level)
|
||||
logger.SetReportCaller(true)
|
||||
logger.SetFormatter(localTimeFormatter{
|
||||
timezone: timezone,
|
||||
formatter: newLogFormatter(output),
|
||||
})
|
||||
installComponentHook(logger)
|
||||
|
||||
if levelErr != nil {
|
||||
logger.WithFields(log.Fields{
|
||||
"configured_level": levelValue,
|
||||
"effective_level": level.String(),
|
||||
}).WithError(levelErr).Warn("invalid log level; using default")
|
||||
}
|
||||
if outputErr != nil {
|
||||
logger.WithFields(log.Fields{
|
||||
"configured_output": outputValue,
|
||||
"effective_output": output,
|
||||
}).WithError(outputErr).Warn("invalid log output; using default")
|
||||
}
|
||||
|
||||
logger.WithFields(log.Fields{
|
||||
"event": "logger_configured",
|
||||
"log_level": level.String(),
|
||||
"output": output,
|
||||
"report_caller": logger.ReportCaller,
|
||||
"timezone": timezone.String(),
|
||||
}).Debug("logging configured")
|
||||
}
|
||||
|
||||
func installComponentHook(logger *log.Logger) {
|
||||
for _, hooks := range logger.Hooks {
|
||||
for _, hook := range hooks {
|
||||
if _, ok := hook.(componentHook); ok {
|
||||
return
|
||||
}
|
||||
}
|
||||
}
|
||||
logger.AddHook(componentHook{})
|
||||
}
|
||||
|
||||
func componentFromCaller(frame *runtime.Frame) string {
|
||||
if frame == nil {
|
||||
return "unknown"
|
||||
}
|
||||
|
||||
const sourceMarker = "/machinery/src/"
|
||||
normalizedFile := filepath.ToSlash(frame.File)
|
||||
if markerIndex := strings.Index(normalizedFile, sourceMarker); markerIndex >= 0 {
|
||||
relativeFile := normalizedFile[markerIndex+len(sourceMarker):]
|
||||
if directory := filepath.ToSlash(filepath.Dir(relativeFile)); directory != "." {
|
||||
return directory
|
||||
}
|
||||
}
|
||||
if strings.Contains(normalizedFile, "/machinery/") {
|
||||
return "agent"
|
||||
}
|
||||
return "unknown"
|
||||
}
|
||||
|
||||
func parseLogLevel(value string) (log.Level, error) {
|
||||
normalized := strings.ToLower(strings.TrimSpace(value))
|
||||
if normalized == "" {
|
||||
return defaultLogLevel, nil
|
||||
}
|
||||
if normalized == "warning" {
|
||||
normalized = "warn"
|
||||
}
|
||||
|
||||
level, err := log.ParseLevel(normalized)
|
||||
if err != nil {
|
||||
return defaultLogLevel, fmt.Errorf("parse LOG_LEVEL: %w", err)
|
||||
}
|
||||
return level, nil
|
||||
}
|
||||
|
||||
func parseLogOutput(value string) (string, error) {
|
||||
normalized := strings.ToLower(strings.TrimSpace(value))
|
||||
if normalized == "" {
|
||||
return defaultLogOutput, nil
|
||||
}
|
||||
switch normalized {
|
||||
case "json", "text":
|
||||
return normalized, nil
|
||||
default:
|
||||
return defaultLogOutput, fmt.Errorf("unsupported LOG_OUTPUT %q", value)
|
||||
}
|
||||
}
|
||||
|
||||
func newLogFormatter(output string) log.Formatter {
|
||||
callerPrettyfier := func(frame *runtime.Frame) (string, string) {
|
||||
return filepath.Base(frame.Function), fmt.Sprintf("%s:%d", filepath.Base(frame.File), frame.Line)
|
||||
}
|
||||
if output == "json" {
|
||||
return &log.JSONFormatter{
|
||||
CallerPrettyfier: callerPrettyfier,
|
||||
TimestampFormat: time.RFC3339Nano,
|
||||
}
|
||||
}
|
||||
return &log.TextFormatter{
|
||||
CallerPrettyfier: callerPrettyfier,
|
||||
FullTimestamp: true,
|
||||
TimestampFormat: time.RFC3339Nano,
|
||||
}
|
||||
}
|
||||
165
machinery/logging_test.go
Normal file
@@ -0,0 +1,165 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"runtime"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
log "github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
func TestConfigureLoggingDebugIncludesStructuredContext(t *testing.T) {
|
||||
logger := log.New()
|
||||
var output bytes.Buffer
|
||||
configureLogger(logger, "debug", "json", time.UTC)
|
||||
logger.SetOutput(&output)
|
||||
logger.WithField("event", "test_event").Debug("structured debug test")
|
||||
|
||||
lines := strings.Split(strings.TrimSpace(output.String()), "\n")
|
||||
var entry map[string]interface{}
|
||||
if err := json.Unmarshal([]byte(lines[len(lines)-1]), &entry); err != nil {
|
||||
t.Fatalf("decode debug log: %v; output=%q", err, output.String())
|
||||
}
|
||||
for key, want := range map[string]interface{}{
|
||||
"component": "agent",
|
||||
"event": "test_event",
|
||||
"level": "debug",
|
||||
"msg": "structured debug test",
|
||||
} {
|
||||
if got := entry[key]; got != want {
|
||||
t.Fatalf("%s = %v, want %v", key, got, want)
|
||||
}
|
||||
}
|
||||
if entry["file"] == nil || entry["func"] == nil {
|
||||
t.Fatalf("debug log is missing caller metadata: %v", entry)
|
||||
}
|
||||
}
|
||||
|
||||
func TestConfigureLoggerInstallsComponentHookOnce(t *testing.T) {
|
||||
logger := log.New()
|
||||
configureLogger(logger, "info", "text", time.UTC)
|
||||
configureLogger(logger, "debug", "json", time.UTC)
|
||||
|
||||
var componentHooks int
|
||||
for _, hooks := range logger.Hooks {
|
||||
for _, hook := range hooks {
|
||||
if _, ok := hook.(componentHook); ok {
|
||||
componentHooks++
|
||||
}
|
||||
}
|
||||
}
|
||||
if componentHooks != len(log.AllLevels) {
|
||||
t.Fatalf("component hook registrations = %d, want %d", componentHooks, len(log.AllLevels))
|
||||
}
|
||||
}
|
||||
|
||||
func TestComponentFromCaller(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
frame *runtime.Frame
|
||||
want string
|
||||
}{
|
||||
{
|
||||
name: "nested runtime package",
|
||||
frame: &runtime.Frame{File: "/workspace/agent/machinery/src/routers/mqtt/main.go"},
|
||||
want: "routers/mqtt",
|
||||
},
|
||||
{
|
||||
name: "top-level runtime package",
|
||||
frame: &runtime.Frame{File: "/workspace/agent/machinery/src/capture/main.go"},
|
||||
want: "capture",
|
||||
},
|
||||
{
|
||||
name: "executable",
|
||||
frame: &runtime.Frame{File: "/workspace/agent/machinery/main.go"},
|
||||
want: "agent",
|
||||
},
|
||||
{name: "missing caller", want: "unknown"},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
if got := componentFromCaller(test.frame); got != test.want {
|
||||
t.Fatalf("componentFromCaller() = %q, want %q", got, test.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestComponentHookAddsAndPreservesComponent(t *testing.T) {
|
||||
hook := componentHook{}
|
||||
|
||||
entry := log.NewEntry(log.New())
|
||||
entry.Caller = &runtime.Frame{File: "/workspace/agent/machinery/src/cloud/livehls/session.go"}
|
||||
if err := hook.Fire(entry); err != nil {
|
||||
t.Fatalf("componentHook.Fire() error = %v", err)
|
||||
}
|
||||
if got := entry.Data["component"]; got != "cloud/livehls" {
|
||||
t.Fatalf("component = %v, want cloud/livehls", got)
|
||||
}
|
||||
|
||||
entry.Data["component"] = "explicit"
|
||||
if err := hook.Fire(entry); err != nil {
|
||||
t.Fatalf("componentHook.Fire() preserving field error = %v", err)
|
||||
}
|
||||
if got := entry.Data["component"]; got != "explicit" {
|
||||
t.Fatalf("component = %v, want explicit", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestParseLogLevel(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
value string
|
||||
want log.Level
|
||||
wantErr bool
|
||||
}{
|
||||
{name: "default", want: log.InfoLevel},
|
||||
{name: "info", value: "INFO", want: log.InfoLevel},
|
||||
{name: "warning alias", value: "warning", want: log.WarnLevel},
|
||||
{name: "debug", value: "debug", want: log.DebugLevel},
|
||||
{name: "trace", value: "trace", want: log.TraceLevel},
|
||||
{name: "invalid", value: "verbose", want: log.InfoLevel, wantErr: true},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
got, err := parseLogLevel(test.value)
|
||||
if (err != nil) != test.wantErr {
|
||||
t.Fatalf("parseLogLevel(%q) error = %v, wantErr %t", test.value, err, test.wantErr)
|
||||
}
|
||||
if got != test.want {
|
||||
t.Fatalf("parseLogLevel(%q) = %s, want %s", test.value, got, test.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestParseLogOutput(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
value string
|
||||
want string
|
||||
wantErr bool
|
||||
}{
|
||||
{name: "default", want: "text"},
|
||||
{name: "text", value: "TEXT", want: "text"},
|
||||
{name: "json", value: "json", want: "json"},
|
||||
{name: "invalid", value: "console", want: "text", wantErr: true},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
got, err := parseLogOutput(test.value)
|
||||
if (err != nil) != test.wantErr {
|
||||
t.Fatalf("parseLogOutput(%q) error = %v, wantErr %t", test.value, err, test.wantErr)
|
||||
}
|
||||
if got != test.want {
|
||||
t.Fatalf("parseLogOutput(%q) = %q, want %q", test.value, got, test.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -1,48 +1,197 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"flag"
|
||||
"fmt"
|
||||
"os"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/capture"
|
||||
"github.com/kerberos-io/agent/machinery/src/components"
|
||||
"github.com/kerberos-io/agent/machinery/src/log"
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
"github.com/kerberos-io/agent/machinery/src/onvif"
|
||||
log "github.com/sirupsen/logrus"
|
||||
"go.opentelemetry.io/otel"
|
||||
"go.opentelemetry.io/otel/attribute"
|
||||
"go.opentelemetry.io/otel/exporters/otlp/otlptrace"
|
||||
"go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp"
|
||||
"go.opentelemetry.io/otel/sdk/resource"
|
||||
"go.opentelemetry.io/otel/sdk/trace"
|
||||
semconv "go.opentelemetry.io/otel/semconv/v1.4.0"
|
||||
|
||||
configService "github.com/kerberos-io/agent/machinery/src/config"
|
||||
"github.com/kerberos-io/agent/machinery/src/routers"
|
||||
"github.com/kerberos-io/agent/machinery/src/utils"
|
||||
)
|
||||
|
||||
var VERSION = utils.VERSION
|
||||
|
||||
func resolveServerPort(flagValue, environmentValue string) (string, error) {
|
||||
value := strings.TrimSpace(environmentValue)
|
||||
if value == "" {
|
||||
value = strings.TrimSpace(flagValue)
|
||||
}
|
||||
if value == "" {
|
||||
value = "80"
|
||||
}
|
||||
|
||||
port, err := strconv.Atoi(value)
|
||||
if err != nil || port < 1 || port > 65535 {
|
||||
return "", fmt.Errorf("port must be an integer between 1 and 65535, got %q", value)
|
||||
}
|
||||
return strconv.Itoa(port), nil
|
||||
}
|
||||
|
||||
func startTracing(agentKey string, otelEndpoint string) (*trace.TracerProvider, error) {
|
||||
serviceName := "agent-" + agentKey
|
||||
headers := map[string]string{
|
||||
"content-type": "application/json",
|
||||
}
|
||||
|
||||
exporter, err := otlptrace.New(
|
||||
context.Background(),
|
||||
otlptracehttp.NewClient(
|
||||
otlptracehttp.WithEndpoint(otelEndpoint),
|
||||
otlptracehttp.WithHeaders(headers),
|
||||
otlptracehttp.WithInsecure(),
|
||||
),
|
||||
)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("creating new exporter: %w", err)
|
||||
}
|
||||
|
||||
tracerprovider := trace.NewTracerProvider(
|
||||
trace.WithBatcher(
|
||||
exporter,
|
||||
trace.WithMaxExportBatchSize(trace.DefaultMaxExportBatchSize),
|
||||
trace.WithBatchTimeout(trace.DefaultScheduleDelay*time.Millisecond),
|
||||
trace.WithMaxExportBatchSize(trace.DefaultMaxExportBatchSize),
|
||||
),
|
||||
trace.WithResource(
|
||||
resource.NewWithAttributes(
|
||||
semconv.SchemaURL,
|
||||
semconv.ServiceNameKey.String(serviceName),
|
||||
attribute.String("environment", "develop"),
|
||||
),
|
||||
),
|
||||
)
|
||||
|
||||
otel.SetTracerProvider(tracerprovider)
|
||||
|
||||
return tracerprovider, nil
|
||||
}
|
||||
|
||||
func main() {
|
||||
|
||||
const VERSION = "3.0"
|
||||
action := os.Args[1]
|
||||
// Start the show ;)
|
||||
// We'll parse the flags (named variables), and start the agent.
|
||||
|
||||
var action string
|
||||
var configDirectory string
|
||||
var name string
|
||||
var port string
|
||||
var timeout string
|
||||
var subnet string
|
||||
|
||||
flag.StringVar(&action, "action", "version", "Tell us what you want do 'run' or 'version'")
|
||||
flag.StringVar(&configDirectory, "config", ".", "Where is the configuration stored")
|
||||
flag.StringVar(&name, "name", "agent", "Provide a name for the agent")
|
||||
flag.StringVar(&port, "port", "80", "On which port should the agent run")
|
||||
flag.StringVar(&timeout, "timeout", "2000", "Number of milliseconds to wait for the ONVIF discovery to complete")
|
||||
flag.StringVar(&subnet, "subnet", "", "Optional subnet(s) to scan for discovery, e.g. '192.168.1.0/24' (comma-separated). Defaults to the local interfaces.")
|
||||
flag.Parse()
|
||||
|
||||
// Specify the level of loggin: "info", "warning", "debug", "error" or "fatal."
|
||||
logLevel := os.Getenv("LOG_LEVEL")
|
||||
if logLevel == "" {
|
||||
logLevel = "info"
|
||||
}
|
||||
// Specify the output formatter of the log: "text" or "json".
|
||||
logOutput := os.Getenv("LOG_OUTPUT")
|
||||
if logOutput == "" {
|
||||
logOutput = "text"
|
||||
}
|
||||
// Specify the timezone of the log: "UTC" or "Local".
|
||||
timezone, _ := time.LoadLocation("CET")
|
||||
log.Log.Init(timezone)
|
||||
configureLogging(logLevel, logOutput, timezone)
|
||||
if action == "run" {
|
||||
resolvedPort, err := resolveServerPort(port, os.Getenv("AGENT_PORT"))
|
||||
if err != nil {
|
||||
log.WithError(err).WithFields(log.Fields{
|
||||
"component": "http",
|
||||
"event": "server_port_invalid",
|
||||
}).Fatal("Invalid HTTP server port")
|
||||
return
|
||||
}
|
||||
port = resolvedPort
|
||||
}
|
||||
log.WithFields(log.Fields{
|
||||
"action": action,
|
||||
"component": "agent",
|
||||
"config_directory": configDirectory,
|
||||
"event": "command_parsed",
|
||||
"port": port,
|
||||
"version": VERSION,
|
||||
}).Debug("Agent command parsed")
|
||||
|
||||
switch action {
|
||||
|
||||
case "version":
|
||||
log.Log.Info("You are currrently running Kerberos Agent " + VERSION)
|
||||
|
||||
case "pending-upload":
|
||||
name := os.Args[2]
|
||||
fmt.Println(name)
|
||||
|
||||
{
|
||||
log.WithFields(log.Fields{
|
||||
"component": "agent",
|
||||
"event": "version",
|
||||
"version": VERSION,
|
||||
}).Info("Kerberos Agent version")
|
||||
}
|
||||
case "discover":
|
||||
timeout := os.Args[2]
|
||||
fmt.Println(timeout)
|
||||
{
|
||||
// Convert duration to int
|
||||
timeout, err := time.ParseDuration(timeout + "ms")
|
||||
if err != nil {
|
||||
log.WithError(err).WithField("component", "onvif").
|
||||
Fatal("invalid ONVIF discovery timeout")
|
||||
return
|
||||
}
|
||||
var subnets []string
|
||||
for _, part := range strings.Split(subnet, ",") {
|
||||
if trimmed := strings.TrimSpace(part); trimmed != "" {
|
||||
subnets = append(subnets, trimmed)
|
||||
}
|
||||
}
|
||||
onvif.Discover(timeout, subnets...)
|
||||
}
|
||||
case "decrypt":
|
||||
{
|
||||
log.WithFields(log.Fields{
|
||||
"component": "encryption",
|
||||
"event": "decrypt_started",
|
||||
"path": flag.Arg(0),
|
||||
}).Info("Decrypting recording")
|
||||
symmetricKey := []byte(flag.Arg(1))
|
||||
|
||||
case "usbcamera-test":
|
||||
if len(symmetricKey) == 0 {
|
||||
log.Fatal("main.Main(): symmetric key should not be empty")
|
||||
return
|
||||
}
|
||||
if len(symmetricKey) != 32 {
|
||||
log.Fatal("main.Main(): symmetric key should be 32 bytes")
|
||||
return
|
||||
}
|
||||
|
||||
deviceID := os.Args[2]
|
||||
capture.TestUSBCamera(deviceID)
|
||||
utils.Decrypt(flag.Arg(0), symmetricKey)
|
||||
}
|
||||
|
||||
case "run":
|
||||
{
|
||||
name := os.Args[2]
|
||||
port := os.Args[3]
|
||||
// Print Agent ASCII art
|
||||
utils.PrintASCIIArt()
|
||||
|
||||
// Print the environment variables which include "AGENT_" as prefix.
|
||||
utils.PrintEnvironmentVariables()
|
||||
|
||||
// Read the config on start, and pass it to the other
|
||||
// function and features. Please note that this might be changed
|
||||
@@ -51,35 +200,100 @@ func main() {
|
||||
configuration.Name = name
|
||||
configuration.Port = port
|
||||
|
||||
// Open this configuration either from Kerberos Agent or Kerberos Factory.
|
||||
components.OpenConfig(&configuration)
|
||||
// Open this configuration either from Agent or Factory.
|
||||
configService.OpenConfig(configDirectory, &configuration)
|
||||
|
||||
timezone, _ := time.LoadLocation(configuration.Config.Timezone)
|
||||
log.Log.Init(timezone)
|
||||
// We will override the configuration with the environment variables
|
||||
configService.OverrideWithEnvironmentVariables(&configuration)
|
||||
|
||||
// Start OpenTelemetry tracing
|
||||
if otelEndpoint := os.Getenv("OTEL_EXPORTER_OTLP_ENDPOINT"); otelEndpoint == "" {
|
||||
log.WithFields(log.Fields{
|
||||
"component": "tracing",
|
||||
"event": "tracing_disabled",
|
||||
}).Debug("OpenTelemetry tracing disabled")
|
||||
} else {
|
||||
log.WithFields(log.Fields{
|
||||
"component": "tracing",
|
||||
"event": "tracing_starting",
|
||||
}).Info("Starting OpenTelemetry tracing")
|
||||
agentKey := configuration.Config.Key
|
||||
traceProvider, err := startTracing(agentKey, otelEndpoint)
|
||||
if err != nil {
|
||||
log.WithError(err).WithField("component", "tracing").
|
||||
Error("Failed to start OpenTelemetry tracing")
|
||||
} else {
|
||||
defer func() {
|
||||
if err := traceProvider.Shutdown(context.Background()); err != nil {
|
||||
log.WithError(err).WithField("component", "tracing").
|
||||
Error("Failed to shut down OpenTelemetry tracing")
|
||||
}
|
||||
}()
|
||||
}
|
||||
}
|
||||
|
||||
// Printing final configuration
|
||||
utils.PrintConfiguration(&configuration)
|
||||
|
||||
// Check the folder permissions, it might be that we do not have permissions to write
|
||||
// recordings, update the configuration or save snapshots.
|
||||
utils.CheckDataDirectoryPermissions(configDirectory)
|
||||
|
||||
// Set timezone
|
||||
timezone, err := time.LoadLocation(configuration.Config.Timezone)
|
||||
if err != nil {
|
||||
log.WithError(err).WithField("timezone", configuration.Config.Timezone).
|
||||
Warn("invalid Agent timezone; using the host timezone for logs")
|
||||
timezone = time.Local
|
||||
}
|
||||
configureLogging(logLevel, logOutput, timezone)
|
||||
|
||||
// Check if we have a device Key or not, if not
|
||||
// we will generate one.
|
||||
if configuration.Config.Key == "" {
|
||||
key := utils.RandStringBytesMaskImpr(30)
|
||||
configuration.Config.Key = key
|
||||
err := components.StoreConfig(configuration.Config)
|
||||
err := configService.StoreConfig(configDirectory, configuration.Config)
|
||||
if err == nil {
|
||||
log.Log.Info("Main: updated unique key for agent to: " + key)
|
||||
log.WithFields(log.Fields{
|
||||
"component": "configuration",
|
||||
"event": "agent_key_generated",
|
||||
}).Info("Generated and stored a unique Agent key")
|
||||
} else {
|
||||
log.Log.Info("Main: something went wrong while trying to store key: " + key)
|
||||
log.WithError(err).WithFields(log.Fields{
|
||||
"component": "configuration",
|
||||
"event": "agent_key_store_failed",
|
||||
}).Error("Failed to store the generated Agent key")
|
||||
}
|
||||
}
|
||||
|
||||
// Create a cancelable context, which will be used to cancel and restart.
|
||||
// This is used to restart the agent when the configuration is updated.
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
defer cancel()
|
||||
|
||||
// We create a capture object, this will contain all the streaming clients.
|
||||
// And allow us to extract media from within difference places in the agent.
|
||||
capture := capture.Capture{}
|
||||
|
||||
// Bootstrapping the agent
|
||||
communication := models.Communication{
|
||||
HandleBootstrap: make(chan string, 1),
|
||||
}
|
||||
go components.Bootstrap(&configuration, &communication)
|
||||
|
||||
log.WithFields(log.Fields{
|
||||
"component": "agent",
|
||||
"event": "runtime_starting",
|
||||
"port": configuration.Port,
|
||||
}).Info("Starting Agent runtime")
|
||||
go components.Bootstrap(ctx, configDirectory, &configuration, &communication, &capture)
|
||||
|
||||
// Start the REST API.
|
||||
routers.StartWebserver(&configuration, &communication)
|
||||
routers.StartWebserver(configDirectory, &configuration, &communication, &capture)
|
||||
}
|
||||
default:
|
||||
fmt.Println("Sorry I don't understand :(")
|
||||
{
|
||||
log.Error("main.Main(): Sorry I don't understand :(")
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
33
machinery/main_test.go
Normal file
@@ -0,0 +1,33 @@
|
||||
package main
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestResolveServerPort(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
flagValue string
|
||||
envValue string
|
||||
want string
|
||||
wantError bool
|
||||
}{
|
||||
{name: "flag default", flagValue: "80", want: "80"},
|
||||
{name: "environment overrides flag", flagValue: "80", envValue: "8082", want: "8082"},
|
||||
{name: "trims environment", flagValue: "80", envValue: " 9090 ", want: "9090"},
|
||||
{name: "empty values use default", want: "80"},
|
||||
{name: "invalid text", flagValue: "80", envValue: "http", wantError: true},
|
||||
{name: "zero", flagValue: "80", envValue: "0", wantError: true},
|
||||
{name: "above maximum", flagValue: "80", envValue: "65536", wantError: true},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
got, err := resolveServerPort(test.flagValue, test.envValue)
|
||||
if (err != nil) != test.wantError {
|
||||
t.Fatalf("resolveServerPort(%q, %q) error = %v, wantError %t", test.flagValue, test.envValue, err, test.wantError)
|
||||
}
|
||||
if got != test.want {
|
||||
t.Fatalf("resolveServerPort(%q, %q) = %q, want %q", test.flagValue, test.envValue, got, test.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -1,97 +0,0 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"strconv"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/log"
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
"github.com/kerberos-io/joy4/av/pubsub"
|
||||
|
||||
"github.com/kerberos-io/joy4/av"
|
||||
"github.com/kerberos-io/joy4/av/avutil"
|
||||
"github.com/kerberos-io/joy4/cgo/ffmpeg"
|
||||
"github.com/kerberos-io/joy4/format"
|
||||
)
|
||||
|
||||
func OpenRTSP(url string) (av.DemuxCloser, []av.CodecData, error) {
|
||||
format.RegisterAll()
|
||||
infile, err := avutil.Open(url)
|
||||
if err == nil {
|
||||
streams, errstreams := infile.Streams()
|
||||
return infile, streams, errstreams
|
||||
}
|
||||
return nil, []av.CodecData{}, err
|
||||
}
|
||||
|
||||
func GetVideoDecoder(streams []av.CodecData) *ffmpeg.VideoDecoder {
|
||||
// Load video codec
|
||||
var vstream av.VideoCodecData
|
||||
for _, stream := range streams {
|
||||
if stream.Type().IsAudio() {
|
||||
//astream := stream.(av.AudioCodecData)
|
||||
} else if stream.Type().IsVideo() {
|
||||
vstream = stream.(av.VideoCodecData)
|
||||
}
|
||||
}
|
||||
dec, _ := ffmpeg.NewVideoDecoder(vstream)
|
||||
return dec
|
||||
}
|
||||
|
||||
func DecodeImage(pkt av.Packet, decoder *ffmpeg.VideoDecoder, decoderMutex *sync.Mutex) (*ffmpeg.VideoFrame, error) {
|
||||
decoderMutex.Lock()
|
||||
img, err := decoder.Decode(pkt.Data)
|
||||
decoderMutex.Unlock()
|
||||
return img, err
|
||||
}
|
||||
|
||||
func HandleStream(infile av.DemuxCloser, queue *pubsub.Queue, communication *models.Communication) { //, wg *sync.WaitGroup) {
|
||||
|
||||
log.Log.Debug("HandleStream: started")
|
||||
var err error
|
||||
loop:
|
||||
for {
|
||||
|
||||
// This will check if we need to stop the thread,
|
||||
// because of a reconfiguration.
|
||||
select {
|
||||
case <-communication.HandleStream:
|
||||
break loop
|
||||
default:
|
||||
}
|
||||
|
||||
var pkt av.Packet
|
||||
if pkt, err = infile.ReadPacket(); err != nil { // sometimes this throws an end of file..
|
||||
log.Log.Error("HandleStream: " + err.Error())
|
||||
time.Sleep(1 * time.Second)
|
||||
}
|
||||
|
||||
// Could be that a decode is throwing errors.
|
||||
if len(pkt.Data) > 0 {
|
||||
|
||||
queue.WritePacket(pkt)
|
||||
|
||||
// This will check if we need to stop the thread,
|
||||
// because of a reconfiguration.
|
||||
select {
|
||||
case <-communication.HandleStream:
|
||||
break loop
|
||||
default:
|
||||
}
|
||||
|
||||
if pkt.IsKeyFrame {
|
||||
|
||||
// Increment packets, so we know the device
|
||||
// is not blocking.
|
||||
r := communication.PackageCounter.Load().(int64)
|
||||
log.Log.Info("HandleStream: packet size " + strconv.Itoa(len(pkt.Data)))
|
||||
communication.PackageCounter.Store((r + 1) % 1000)
|
||||
communication.LastPacketTimer.Store(time.Now().Unix())
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
queue.Close()
|
||||
log.Log.Debug("HandleStream: finished")
|
||||
}
|
||||
@@ -1,55 +0,0 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"strconv"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/log"
|
||||
"gocv.io/x/gocv"
|
||||
)
|
||||
|
||||
func TestUSBCamera(deviceID string) {
|
||||
webcam, err := gocv.OpenVideoCapture(deviceID)
|
||||
if err != nil {
|
||||
log.Log.Error("Error opening video capture device: " + deviceID)
|
||||
return
|
||||
}
|
||||
defer webcam.Close()
|
||||
buf := gocv.NewMat()
|
||||
defer buf.Close()
|
||||
|
||||
ok := webcam.Read(&buf)
|
||||
|
||||
if ok {
|
||||
|
||||
now := time.Now().Unix()
|
||||
saveFile := "./data/capture-test/" + strconv.FormatInt(now, 10) + ".mp4"
|
||||
fps := 20.0 // webcam.Get(gocv.VideoCaptureFPS)
|
||||
writer, err := gocv.VideoWriterFile(saveFile, "X264", fps, buf.Cols(), buf.Rows(), true)
|
||||
if err != nil {
|
||||
log.Log.Error("error opening video writer device: " + saveFile)
|
||||
return
|
||||
}
|
||||
defer writer.Close()
|
||||
|
||||
//window := gocv.NewWindow("Hello")
|
||||
log.Log.Info("Start reading device: " + deviceID)
|
||||
for i := 0; i < 100; i++ {
|
||||
if ok := webcam.Read(&buf); !ok {
|
||||
log.Log.Error("Device closed: " + deviceID)
|
||||
return
|
||||
}
|
||||
if buf.Empty() {
|
||||
continue
|
||||
}
|
||||
|
||||
writer.Write(buf)
|
||||
//window.IMShow(buf)
|
||||
//window.WaitKey(1)
|
||||
|
||||
log.Log.Info("Read frame")
|
||||
}
|
||||
|
||||
}
|
||||
log.Log.Info("Done. Close videocapture and recording file.")
|
||||
}
|
||||
238
machinery/src/capture/cleanup_test.go
Normal file
@@ -0,0 +1,238 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
)
|
||||
|
||||
// writeRecording creates a file under recordingsDir and sets its modtime so the
|
||||
// tests can control the "oldest" ordering deterministically.
|
||||
func writeRecording(t *testing.T, recordingsDir, name string, ageMinutes int) {
|
||||
t.Helper()
|
||||
full := filepath.Join(recordingsDir, name)
|
||||
if err := os.WriteFile(full, []byte("data"), 0o644); err != nil {
|
||||
t.Fatalf("write recording %s: %v", name, err)
|
||||
}
|
||||
mod := time.Now().Add(-time.Duration(ageMinutes) * time.Minute)
|
||||
if err := os.Chtimes(full, mod, mod); err != nil {
|
||||
t.Fatalf("chtimes %s: %v", name, err)
|
||||
}
|
||||
}
|
||||
|
||||
// markPending creates the upload marker in cloudDir for the given recording,
|
||||
// marking it as still queued for upload.
|
||||
func markPending(t *testing.T, cloudDir, name string) {
|
||||
t.Helper()
|
||||
markerName := models.RecordingUploadMetadataFileName(name)
|
||||
if err := os.WriteFile(filepath.Join(cloudDir, markerName), nil, 0o644); err != nil {
|
||||
t.Fatalf("write marker %s: %v", name, err)
|
||||
}
|
||||
}
|
||||
|
||||
func newCleanupDirs(t *testing.T) (string, string) {
|
||||
t.Helper()
|
||||
base := t.TempDir()
|
||||
recordingsDir := filepath.Join(base, "data", "recordings")
|
||||
cloudDir := filepath.Join(base, "data", "cloud")
|
||||
if err := os.MkdirAll(recordingsDir, 0o755); err != nil {
|
||||
t.Fatalf("mkdir recordings: %v", err)
|
||||
}
|
||||
if err := os.MkdirAll(cloudDir, 0o755); err != nil {
|
||||
t.Fatalf("mkdir cloud: %v", err)
|
||||
}
|
||||
return recordingsDir, cloudDir
|
||||
}
|
||||
|
||||
// The core regression: when the oldest recording is still pending upload but a
|
||||
// newer one has already been uploaded, cleanup must delete the uploaded (safe)
|
||||
// one and leave the pending recording on disk so it can still be uploaded.
|
||||
func TestPickRecordingToCleanup_PrefersUploaded(t *testing.T) {
|
||||
recordingsDir, cloudDir := newCleanupDirs(t)
|
||||
|
||||
// oldest is still pending upload (marker present).
|
||||
writeRecording(t, recordingsDir, "oldest_pending.mp4", 30)
|
||||
markPending(t, cloudDir, "oldest_pending.mp4")
|
||||
// newer one has already been uploaded (no marker).
|
||||
writeRecording(t, recordingsDir, "newer_uploaded.mp4", 10)
|
||||
|
||||
name, pending, err := pickRecordingToCleanup(recordingsDir, cloudDir)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if pending {
|
||||
t.Fatalf("expected a safe (already-uploaded) deletion, got pending=true")
|
||||
}
|
||||
if name != "newer_uploaded.mp4" {
|
||||
t.Fatalf("cleanup picked %q, want the uploaded recording newer_uploaded.mp4", name)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPickRecordingToCleanup_RecognizesLegacyMarkerName(t *testing.T) {
|
||||
recordingsDir, cloudDir := newCleanupDirs(t)
|
||||
|
||||
writeRecording(t, recordingsDir, "legacy_pending.mp4", 30)
|
||||
if err := os.WriteFile(filepath.Join(cloudDir, "legacy_pending.mp4"), nil, 0o644); err != nil {
|
||||
t.Fatalf("write legacy marker: %v", err)
|
||||
}
|
||||
writeRecording(t, recordingsDir, "uploaded.mp4", 10)
|
||||
|
||||
name, pending, err := pickRecordingToCleanup(recordingsDir, cloudDir)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if pending || name != "uploaded.mp4" {
|
||||
t.Fatalf("cleanup picked name=%q pending=%v, want uploaded.mp4 pending=false", name, pending)
|
||||
}
|
||||
}
|
||||
|
||||
// Among several already-uploaded recordings, the oldest uploaded one is chosen.
|
||||
func TestPickRecordingToCleanup_OldestUploadedFirst(t *testing.T) {
|
||||
recordingsDir, cloudDir := newCleanupDirs(t)
|
||||
|
||||
writeRecording(t, recordingsDir, "old_uploaded.mp4", 40)
|
||||
writeRecording(t, recordingsDir, "mid_uploaded.mp4", 20)
|
||||
// pending one must be ignored even though it is not the oldest.
|
||||
writeRecording(t, recordingsDir, "pending.mp4", 30)
|
||||
markPending(t, cloudDir, "pending.mp4")
|
||||
|
||||
name, pending, err := pickRecordingToCleanup(recordingsDir, cloudDir)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if pending {
|
||||
t.Fatalf("expected pending=false, got true")
|
||||
}
|
||||
if name != "old_uploaded.mp4" {
|
||||
t.Fatalf("cleanup picked %q, want old_uploaded.mp4", name)
|
||||
}
|
||||
}
|
||||
|
||||
// Last resort: when every recording is still pending upload, cleanup returns the
|
||||
// oldest one with pending=true so the caller can drop it (and its marker) to keep
|
||||
// the disk bounded.
|
||||
func TestPickRecordingToCleanup_AllPendingFallsBackToOldest(t *testing.T) {
|
||||
recordingsDir, cloudDir := newCleanupDirs(t)
|
||||
|
||||
writeRecording(t, recordingsDir, "a_old.mp4", 50)
|
||||
markPending(t, cloudDir, "a_old.mp4")
|
||||
writeRecording(t, recordingsDir, "b_new.mp4", 5)
|
||||
markPending(t, cloudDir, "b_new.mp4")
|
||||
|
||||
name, pending, err := pickRecordingToCleanup(recordingsDir, cloudDir)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if !pending {
|
||||
t.Fatalf("expected pending=true when every recording is queued for upload")
|
||||
}
|
||||
if name != "a_old.mp4" {
|
||||
t.Fatalf("cleanup picked %q, want the oldest pending a_old.mp4", name)
|
||||
}
|
||||
}
|
||||
|
||||
// An empty recordings directory yields os.ErrNotExist so the caller does nothing.
|
||||
func TestPickRecordingToCleanup_Empty(t *testing.T) {
|
||||
recordingsDir, cloudDir := newCleanupDirs(t)
|
||||
|
||||
if _, _, err := pickRecordingToCleanup(recordingsDir, cloudDir); err != os.ErrNotExist {
|
||||
t.Fatalf("expected os.ErrNotExist for an empty directory, got %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// writeSizedRecording writes a recording of an exact byte size so tests can
|
||||
// exercise the megabyte-based directory-cap threshold.
|
||||
func writeSizedRecording(t *testing.T, dir, name string, size int) {
|
||||
t.Helper()
|
||||
if err := os.WriteFile(filepath.Join(dir, name), make([]byte, size), 0o644); err != nil {
|
||||
t.Fatalf("write sized recording %s: %v", name, err)
|
||||
}
|
||||
}
|
||||
|
||||
// When AGENT_AUTO_CLEAN_MAX_SIZE (MaxDirectorySize) is set, cleanup triggers once
|
||||
// the recordings directory grows past that many megabytes.
|
||||
func TestRecordingsNeedCleanup_FixedCap(t *testing.T) {
|
||||
recordingsDir, _ := newCleanupDirs(t)
|
||||
// ~2 MB of recordings on disk.
|
||||
writeSizedRecording(t, recordingsDir, "big.mp4", 2*1000*1000)
|
||||
|
||||
over := &models.Configuration{Config: models.Config{MaxDirectorySize: 1}}
|
||||
need, err := recordingsNeedCleanup(recordingsDir, over)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if !need {
|
||||
t.Fatalf("expected cleanup when 2MB of recordings exceed the 1MB cap")
|
||||
}
|
||||
|
||||
under := &models.Configuration{Config: models.Config{MaxDirectorySize: 100}}
|
||||
need, err = recordingsNeedCleanup(recordingsDir, under)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if need {
|
||||
t.Fatalf("expected no cleanup when 2MB of recordings stay under the 100MB cap")
|
||||
}
|
||||
}
|
||||
|
||||
// With no fixed cap (the default), cleanup is driven by the free space left on
|
||||
// the recordings filesystem versus the reserve.
|
||||
func TestRecordingsNeedCleanup_DefaultDiskReserve(t *testing.T) {
|
||||
if runtime.GOOS != "linux" {
|
||||
t.Skip("disk usage stats are only implemented on linux")
|
||||
}
|
||||
recordingsDir, _ := newCleanupDirs(t)
|
||||
|
||||
totalMB, availableMB, err := diskUsageMB(recordingsDir)
|
||||
if err != nil {
|
||||
t.Fatalf("diskUsageMB: %v", err)
|
||||
}
|
||||
if totalMB <= 0 || availableMB <= 0 {
|
||||
t.Skipf("unexpected disk stats total=%dMB available=%dMB", totalMB, availableMB)
|
||||
}
|
||||
|
||||
// A reserve larger than the whole disk means free space is always below it.
|
||||
over := &models.Configuration{Config: models.Config{MinFreeSpace: totalMB + availableMB}}
|
||||
need, err := recordingsNeedCleanup(recordingsDir, over)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if !need {
|
||||
t.Fatalf("expected cleanup when free space (%dMB) is below the reserve", availableMB)
|
||||
}
|
||||
|
||||
// A 1 MB reserve leaves plenty of free space, so nothing should be cleaned.
|
||||
under := &models.Configuration{Config: models.Config{MinFreeSpace: 1}}
|
||||
need, err = recordingsNeedCleanup(recordingsDir, under)
|
||||
if err != nil {
|
||||
t.Fatalf("unexpected error: %v", err)
|
||||
}
|
||||
if need {
|
||||
t.Fatalf("expected no cleanup when free space (%dMB) exceeds the 1MB reserve", availableMB)
|
||||
}
|
||||
}
|
||||
|
||||
// The default 5% reserve must never truncate to 0MB on small disks, otherwise
|
||||
// cleanup would only trigger once the disk is completely full.
|
||||
func TestDefaultReserveMB(t *testing.T) {
|
||||
cases := []struct {
|
||||
totalMB int64
|
||||
want int64
|
||||
}{
|
||||
{totalMB: 0, want: 1}, // no/unknown disk size still reserves 1MB
|
||||
{totalMB: 10, want: 1}, // 5% = 0MB -> floored to 1MB
|
||||
{totalMB: 19, want: 1}, // 5% = 0MB -> floored to 1MB
|
||||
{totalMB: 20, want: 1}, // 5% = exactly 1MB
|
||||
{totalMB: 100, want: 5}, // 5% = 5MB
|
||||
{totalMB: 1000, want: 50},
|
||||
}
|
||||
for _, c := range cases {
|
||||
if got := defaultReserveMB(c.totalMB); got != c.want {
|
||||
t.Errorf("defaultReserveMB(%d) = %d, want %d", c.totalMB, got, c.want)
|
||||
}
|
||||
}
|
||||
}
|
||||
23
machinery/src/capture/disk_linux.go
Normal file
@@ -0,0 +1,23 @@
|
||||
//go:build linux
|
||||
|
||||
package capture
|
||||
|
||||
import "syscall"
|
||||
|
||||
// diskUsageMB returns the total capacity and the currently available space (both
|
||||
// in megabytes, decimal) of the filesystem that contains path. Auto-clean uses
|
||||
// it to default its cleanup threshold to the real disk capacity instead of a
|
||||
// fixed size, so recordings can grow to fill the disk while keeping a reserve
|
||||
// free. Linux is the agent's deployment target (amd64/arm64 containers).
|
||||
func diskUsageMB(path string) (totalMB int64, availableMB int64, err error) {
|
||||
var stat syscall.Statfs_t
|
||||
if err = syscall.Statfs(path, &stat); err != nil {
|
||||
return 0, 0, err
|
||||
}
|
||||
blockSize := int64(stat.Bsize)
|
||||
totalMB = int64(stat.Blocks) * blockSize / 1000 / 1000
|
||||
// Bavail is the free space available to unprivileged users, which is the
|
||||
// space we can actually keep writing recordings into.
|
||||
availableMB = int64(stat.Bavail) * blockSize / 1000 / 1000
|
||||
return totalMB, availableMB, nil
|
||||
}
|
||||
13
machinery/src/capture/disk_other.go
Normal file
@@ -0,0 +1,13 @@
|
||||
//go:build !linux
|
||||
|
||||
package capture
|
||||
|
||||
import "errors"
|
||||
|
||||
// diskUsageMB is only implemented on Linux (the agent's deployment target). On
|
||||
// other platforms (e.g. local macOS/Windows dev builds) auto-clean falls back to
|
||||
// its historical fixed-size directory cap, so this reports the capability as
|
||||
// unavailable.
|
||||
func diskUsageMB(path string) (totalMB int64, availableMB int64, err error) {
|
||||
return 0, 0, errors.New("disk usage stats are not supported on this platform")
|
||||
}
|
||||
1870
machinery/src/capture/gortsplib.go
Normal file
136
machinery/src/capture/gortsplib_test.go
Normal file
@@ -0,0 +1,136 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"encoding/pem"
|
||||
"errors"
|
||||
"math"
|
||||
"net/http/httptest"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestPreRecordingGOPCount(t *testing.T) {
|
||||
maxInt := int64(^uint(0) >> 1)
|
||||
tests := []struct {
|
||||
name string
|
||||
preRecording int64
|
||||
gopDuration float64
|
||||
want int
|
||||
wantOK bool
|
||||
}{
|
||||
{name: "normal duration", preRecording: 10, gopDuration: 2.9, want: 6, wantOK: true},
|
||||
{name: "duration longer than buffer", preRecording: 1, gopDuration: 2, want: 1, wantOK: true},
|
||||
{name: "largest representable result", preRecording: maxInt - 1, gopDuration: 1, want: int(maxInt), wantOK: true},
|
||||
{name: "result exceeds int", preRecording: maxInt, gopDuration: 1, wantOK: false},
|
||||
{name: "non-positive pre-recording", preRecording: 0, gopDuration: 1, wantOK: false},
|
||||
{name: "sub-second GOP", preRecording: 10, gopDuration: 0.9, wantOK: false},
|
||||
{name: "NaN GOP", preRecording: 10, gopDuration: math.NaN(), wantOK: false},
|
||||
{name: "infinite GOP", preRecording: 10, gopDuration: math.Inf(1), wantOK: false},
|
||||
{name: "GOP exceeds int64", preRecording: 10, gopDuration: float64(math.MaxInt64), wantOK: false},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
got, ok := preRecordingGOPCount(tt.preRecording, tt.gopDuration)
|
||||
if ok != tt.wantOK || got != tt.want {
|
||||
t.Fatalf("preRecordingGOPCount(%d, %v) = (%d, %t), want (%d, %t)",
|
||||
tt.preRecording, tt.gopDuration, got, ok, tt.want, tt.wantOK)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestGolibrtspCloseBeforeClientStart(t *testing.T) {
|
||||
client := &Golibrtsp{}
|
||||
|
||||
if err := client.Close(context.Background()); err != nil {
|
||||
t.Fatalf("Close() error = %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestSanitizeRTSPErrorRemovesCredentialsAndQuery(t *testing.T) {
|
||||
rawURL := "rtsp://camera-user:camera-password@10.0.20.15/live?access_token=secret"
|
||||
got := sanitizeRTSPError(errors.New("describe "+rawURL+": bad status code"), rawURL)
|
||||
|
||||
for _, secret := range []string{"camera-user", "camera-password", "access_token", "secret"} {
|
||||
if strings.Contains(got.Error(), secret) {
|
||||
t.Fatalf("sanitizeRTSPError() exposed %q in %q", secret, got)
|
||||
}
|
||||
}
|
||||
if !strings.Contains(got.Error(), "rtsp://10.0.20.15/live") {
|
||||
t.Fatalf("sanitizeRTSPError() removed useful host/path context: %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRTSPSTLSConfig(t *testing.T) {
|
||||
t.Run("verifies certificates by default", func(t *testing.T) {
|
||||
t.Setenv(rtspsCAFileEnv, "")
|
||||
t.Setenv(rtspsInsecureEnv, "")
|
||||
|
||||
got, err := rtspsTLSConfig()
|
||||
if err != nil {
|
||||
t.Fatalf("rtspsTLSConfig() error = %v", err)
|
||||
}
|
||||
if got != nil {
|
||||
t.Fatalf("rtspsTLSConfig() = %#v, want nil", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("allows explicit insecure mode", func(t *testing.T) {
|
||||
t.Setenv(rtspsCAFileEnv, "/missing/ignored-in-insecure-mode.pem")
|
||||
t.Setenv(rtspsInsecureEnv, "true")
|
||||
|
||||
got, err := rtspsTLSConfig()
|
||||
if err != nil {
|
||||
t.Fatalf("rtspsTLSConfig() error = %v", err)
|
||||
}
|
||||
if got == nil || !got.InsecureSkipVerify {
|
||||
t.Fatalf("rtspsTLSConfig() = %#v, want InsecureSkipVerify enabled", got)
|
||||
}
|
||||
})
|
||||
|
||||
t.Run("adds a camera CA to system roots", func(t *testing.T) {
|
||||
t.Setenv(rtspsInsecureEnv, "")
|
||||
server := httptest.NewTLSServer(nil)
|
||||
defer server.Close()
|
||||
|
||||
certificate := server.Certificate()
|
||||
caFile := filepath.Join(t.TempDir(), "camera-ca.pem")
|
||||
caPEM := pem.EncodeToMemory(&pem.Block{Type: "CERTIFICATE", Bytes: certificate.Raw})
|
||||
if err := os.WriteFile(caFile, caPEM, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv(rtspsCAFileEnv, caFile)
|
||||
|
||||
got, err := rtspsTLSConfig()
|
||||
if err != nil {
|
||||
t.Fatalf("rtspsTLSConfig() error = %v", err)
|
||||
}
|
||||
if got == nil || got.RootCAs == nil {
|
||||
t.Fatalf("rtspsTLSConfig() = %#v, want custom RootCAs", got)
|
||||
}
|
||||
for _, subject := range got.RootCAs.Subjects() {
|
||||
if bytes.Equal(subject, certificate.RawSubject) {
|
||||
return
|
||||
}
|
||||
}
|
||||
t.Fatal("camera CA was not added to RootCAs")
|
||||
})
|
||||
|
||||
t.Run("rejects an invalid camera CA file", func(t *testing.T) {
|
||||
t.Setenv(rtspsInsecureEnv, "")
|
||||
caFile := filepath.Join(t.TempDir(), "camera-ca.pem")
|
||||
if err := os.WriteFile(caFile, []byte("not a certificate"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv(rtspsCAFileEnv, caFile)
|
||||
|
||||
if _, err := rtspsTLSConfig(); err == nil {
|
||||
t.Fatal("rtspsTLSConfig() error = nil, want invalid CA error")
|
||||
}
|
||||
})
|
||||
}
|
||||
88
machinery/src/capture/main_test.go
Normal file
@@ -0,0 +1,88 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"math"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
"github.com/kerberos-io/agent/machinery/src/video"
|
||||
)
|
||||
|
||||
func TestPTSToDuration(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
pts int64
|
||||
clockRate int
|
||||
want time.Duration
|
||||
}{
|
||||
{name: "one video second", pts: 90_000, clockRate: 90_000, want: time.Second},
|
||||
{name: "one audio frame", pts: 1_024, clockRate: 8_000, want: 128 * time.Millisecond},
|
||||
{name: "fractional millisecond", pts: 45_045, clockRate: 90_000, want: 500*time.Millisecond + 500*time.Microsecond},
|
||||
{name: "negative timestamp", pts: -45_045, clockRate: 90_000, want: -500*time.Millisecond - 500*time.Microsecond},
|
||||
{name: "large timestamp", pts: 90_000 * 60 * 60 * 24, clockRate: 90_000, want: 24 * time.Hour},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
if got := ptsToDuration(test.pts, test.clockRate); got != test.want {
|
||||
t.Fatalf("ptsToDuration(%d, %d) = %s, want %s", test.pts, test.clockRate, got, test.want)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func TestQueueRecordingForUploadStoresFinalizedMetadata(t *testing.T) {
|
||||
configDirectory := t.TempDir()
|
||||
if err := os.MkdirAll(filepath.Join(configDirectory, "data", "cloud"), 0o755); err != nil {
|
||||
t.Fatalf("mkdir cloud queue: %v", err)
|
||||
}
|
||||
|
||||
mp4Video := &video.MP4{VideoTotalDuration: 20452, SampleCount: 613}
|
||||
metadata := recordingUploadMetadata("recording.mp4", "device-key", 1785934709414, mp4Video, true)
|
||||
queueRecordingForUpload(configDirectory, metadata)
|
||||
|
||||
got, err := os.ReadFile(filepath.Join(configDirectory, "data", "cloud", "recording.metadata"))
|
||||
if err != nil {
|
||||
t.Fatalf("read upload marker: %v", err)
|
||||
}
|
||||
var stored models.RecordingUploadMetadata
|
||||
if err := json.Unmarshal(got, &stored); err != nil {
|
||||
t.Fatalf("decode upload marker: %v", err)
|
||||
}
|
||||
expectedFPS := mp4Video.AverageFPS()
|
||||
if stored.FileName != "recording.mp4" || stored.DeviceKey != "device-key" || stored.Timestamp != 1785934709414 || stored.Duration != 20452 || math.Abs(stored.FPS-expectedFPS) > 1e-9 || !stored.Encrypted {
|
||||
t.Fatalf("upload marker = %+v", stored)
|
||||
}
|
||||
if stored.FPS == math.Floor(stored.FPS) {
|
||||
t.Fatalf("upload marker FPS = %v, want fractional precision", stored.FPS)
|
||||
}
|
||||
}
|
||||
|
||||
func TestQueueRecordingForUploadKeepsUnknownFPSCompatible(t *testing.T) {
|
||||
for _, fps := range []float64{0, 0.99, -1, math.NaN(), math.Inf(1), 241} {
|
||||
t.Run("invalid FPS", func(t *testing.T) {
|
||||
configDirectory := t.TempDir()
|
||||
if err := os.MkdirAll(filepath.Join(configDirectory, "data", "cloud"), 0o755); err != nil {
|
||||
t.Fatalf("mkdir cloud queue: %v", err)
|
||||
}
|
||||
|
||||
metadata := models.RecordingUploadMetadata{FileName: "recording.mp4"}
|
||||
if fps >= 1 && fps <= 240 && !math.IsNaN(fps) && !math.IsInf(fps, 0) {
|
||||
metadata.FPS = fps
|
||||
}
|
||||
queueRecordingForUpload(configDirectory, metadata)
|
||||
|
||||
got, err := os.ReadFile(filepath.Join(configDirectory, "data", "cloud", "recording.metadata"))
|
||||
if err != nil {
|
||||
t.Fatalf("read upload marker: %v", err)
|
||||
}
|
||||
if string(got) != `{"filename":"recording.mp4","device_key":"","timestamp":0,"duration":0}` {
|
||||
t.Fatalf("upload marker = %q, want metadata without FPS", got)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
109
machinery/src/capture/rtsp_client.go
Normal file
@@ -0,0 +1,109 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"context"
|
||||
"image"
|
||||
"sync"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
"github.com/kerberos-io/agent/machinery/src/packets"
|
||||
)
|
||||
|
||||
type Capture struct {
|
||||
clientsMu sync.RWMutex
|
||||
rtspClient *Golibrtsp
|
||||
rtspSubClient *Golibrtsp
|
||||
rtspBackChannelClient *Golibrtsp
|
||||
}
|
||||
|
||||
func (c *Capture) SetMainClient(rtspUrl string) *Golibrtsp {
|
||||
client := &Golibrtsp{
|
||||
Url: rtspUrl,
|
||||
}
|
||||
c.clientsMu.Lock()
|
||||
c.rtspClient = client
|
||||
c.clientsMu.Unlock()
|
||||
return client
|
||||
}
|
||||
|
||||
func (c *Capture) SetSubClient(rtspUrl string) *Golibrtsp {
|
||||
client := &Golibrtsp{
|
||||
Url: rtspUrl,
|
||||
}
|
||||
c.clientsMu.Lock()
|
||||
c.rtspSubClient = client
|
||||
c.clientsMu.Unlock()
|
||||
return client
|
||||
}
|
||||
|
||||
func (c *Capture) SetBackChannelClient(rtspUrl string) *Golibrtsp {
|
||||
client := &Golibrtsp{
|
||||
Url: rtspUrl,
|
||||
}
|
||||
c.clientsMu.Lock()
|
||||
c.rtspBackChannelClient = client
|
||||
c.clientsMu.Unlock()
|
||||
return client
|
||||
}
|
||||
|
||||
func (c *Capture) MainClient() *Golibrtsp {
|
||||
c.clientsMu.RLock()
|
||||
defer c.clientsMu.RUnlock()
|
||||
return c.rtspClient
|
||||
}
|
||||
|
||||
func (c *Capture) SubClient() *Golibrtsp {
|
||||
c.clientsMu.RLock()
|
||||
defer c.clientsMu.RUnlock()
|
||||
return c.rtspSubClient
|
||||
}
|
||||
|
||||
func (c *Capture) ClearClients(main, sub, backchannel *Golibrtsp) {
|
||||
c.clientsMu.Lock()
|
||||
defer c.clientsMu.Unlock()
|
||||
if c.rtspClient == main {
|
||||
c.rtspClient = nil
|
||||
}
|
||||
if c.rtspSubClient == sub {
|
||||
c.rtspSubClient = nil
|
||||
}
|
||||
if c.rtspBackChannelClient == backchannel {
|
||||
c.rtspBackChannelClient = nil
|
||||
}
|
||||
}
|
||||
|
||||
// RTSPClient is a interface that abstracts the RTSP client implementation.
|
||||
type RTSPClient interface {
|
||||
// Connect to the RTSP server.
|
||||
Connect(ctx context.Context, otelContext context.Context) error
|
||||
|
||||
// Connect to a backchannel RTSP server.
|
||||
ConnectBackChannel(ctx context.Context, otelContext context.Context) error
|
||||
|
||||
// Start the RTSP client, and start reading packets.
|
||||
Start(ctx context.Context, streamType string, queue *packets.Queue, configuration *models.Configuration, communication *models.Communication) error
|
||||
|
||||
// Start the RTSP client, and start reading packets.
|
||||
StartBackChannel(ctx context.Context, otelContext context.Context) error
|
||||
|
||||
// Decode a packet into a image.
|
||||
DecodePacket(pkt packets.Packet) (image.YCbCr, error)
|
||||
|
||||
// Decode a packet into a image.
|
||||
DecodePacketRaw(pkt packets.Packet) (image.Gray, error)
|
||||
|
||||
// Write a packet to the RTSP server.
|
||||
WritePacket(pkt packets.Packet) error
|
||||
|
||||
// Close the connection to the RTSP server.
|
||||
Close(ctx context.Context) error
|
||||
|
||||
// Get a list of streams from the RTSP server.
|
||||
GetStreams() ([]packets.Stream, error)
|
||||
|
||||
// Get a list of video streams from the RTSP server.
|
||||
GetVideoStreams() ([]packets.Stream, error)
|
||||
|
||||
// Get a list of audio streams from the RTSP server.
|
||||
GetAudioStreams() ([]packets.Stream, error)
|
||||
}
|
||||
62
machinery/src/capture/rtsp_client_test.go
Normal file
@@ -0,0 +1,62 @@
|
||||
package capture
|
||||
|
||||
import (
|
||||
"strconv"
|
||||
"sync"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestCaptureClientAccessCanRaceReplacement(t *testing.T) {
|
||||
captureDevice := &Capture{}
|
||||
captureDevice.SetMainClient("rtsp://main/0")
|
||||
captureDevice.SetSubClient("rtsp://sub/0")
|
||||
|
||||
var workers sync.WaitGroup
|
||||
workers.Add(2)
|
||||
go func() {
|
||||
defer workers.Done()
|
||||
for replacement := 1; replacement <= 1000; replacement++ {
|
||||
suffix := strconv.Itoa(replacement)
|
||||
captureDevice.SetMainClient("rtsp://main/" + suffix)
|
||||
captureDevice.SetSubClient("rtsp://sub/" + suffix)
|
||||
}
|
||||
}()
|
||||
go func() {
|
||||
defer workers.Done()
|
||||
for snapshot := 0; snapshot < 1000; snapshot++ {
|
||||
if captureDevice.MainClient() == nil {
|
||||
t.Error("MainClient() returned nil")
|
||||
return
|
||||
}
|
||||
if captureDevice.SubClient() == nil {
|
||||
t.Error("SubClient() returned nil")
|
||||
return
|
||||
}
|
||||
}
|
||||
}()
|
||||
workers.Wait()
|
||||
}
|
||||
|
||||
func TestCaptureClearClientsOnlyClearsMatchingRun(t *testing.T) {
|
||||
captureDevice := &Capture{}
|
||||
oldMain := captureDevice.SetMainClient("rtsp://main/old")
|
||||
oldSub := captureDevice.SetSubClient("rtsp://sub/old")
|
||||
oldBackchannel := captureDevice.SetBackChannelClient("rtsp://back/old")
|
||||
|
||||
newMain := captureDevice.SetMainClient("rtsp://main/new")
|
||||
newSub := captureDevice.SetSubClient("rtsp://sub/new")
|
||||
newBackchannel := captureDevice.SetBackChannelClient("rtsp://back/new")
|
||||
|
||||
captureDevice.ClearClients(oldMain, oldSub, oldBackchannel)
|
||||
if captureDevice.MainClient() != newMain {
|
||||
t.Fatal("stale cleanup cleared the new main client")
|
||||
}
|
||||
if captureDevice.SubClient() != newSub {
|
||||
t.Fatal("stale cleanup cleared the new sub client")
|
||||
}
|
||||
|
||||
captureDevice.ClearClients(newMain, newSub, newBackchannel)
|
||||
if captureDevice.MainClient() != nil || captureDevice.SubClient() != nil {
|
||||
t.Fatal("matching cleanup did not clear current clients")
|
||||
}
|
||||
}
|
||||
@@ -1,594 +0,0 @@
|
||||
package cloud
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"crypto/tls"
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"io/ioutil"
|
||||
"os"
|
||||
"sync"
|
||||
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/kerberos-io/joy4/av/pubsub"
|
||||
"github.com/minio/minio-go/v6"
|
||||
|
||||
mqtt "github.com/eclipse/paho.mqtt.golang"
|
||||
av "github.com/kerberos-io/joy4/av"
|
||||
"github.com/kerberos-io/joy4/cgo/ffmpeg"
|
||||
"gocv.io/x/gocv"
|
||||
|
||||
"net/http"
|
||||
"net/url"
|
||||
"runtime"
|
||||
"runtime/debug"
|
||||
"strconv"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/computervision"
|
||||
"github.com/kerberos-io/agent/machinery/src/log"
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
"github.com/kerberos-io/agent/machinery/src/utils"
|
||||
"github.com/kerberos-io/agent/machinery/src/webrtc"
|
||||
"github.com/shirou/gopsutil/disk"
|
||||
"github.com/shirou/gopsutil/host"
|
||||
)
|
||||
|
||||
func PendingUpload() {
|
||||
ff, err := utils.ReadDirectory("./data/cloud/")
|
||||
if err == nil {
|
||||
for _, f := range ff {
|
||||
log.Log.Info(f.Name())
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func HandleUpload(configuration *models.Configuration, communication *models.Communication) {
|
||||
|
||||
log.Log.Debug("HandleUpload: started")
|
||||
|
||||
config := configuration.Config
|
||||
watchDirectory := "./data/cloud/"
|
||||
|
||||
if config.Offline == "true" {
|
||||
log.Log.Debug("HandleUpload: stopping as Offline is enabled.")
|
||||
} else {
|
||||
|
||||
loop:
|
||||
for {
|
||||
ff, err := utils.ReadDirectory(watchDirectory)
|
||||
|
||||
// This will check if we need to stop the thread,
|
||||
// because of a reconfiguration.
|
||||
select {
|
||||
case <-communication.HandleUpload:
|
||||
break loop
|
||||
case <-time.After(2 * time.Second):
|
||||
}
|
||||
|
||||
if err == nil {
|
||||
for _, f := range ff {
|
||||
|
||||
// This will check if we need to stop the thread,
|
||||
// because of a reconfiguration.
|
||||
select {
|
||||
case <-communication.HandleUpload:
|
||||
break loop
|
||||
default:
|
||||
}
|
||||
|
||||
fileName := f.Name()
|
||||
if config.Cloud == "s3" {
|
||||
UploadS3(configuration, fileName, watchDirectory)
|
||||
} else if config.Cloud == "kstorage" {
|
||||
UploadKerberosVault(configuration, fileName, watchDirectory)
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
log.Log.Debug("HandleUpload: finished")
|
||||
}
|
||||
|
||||
func HandleHeartBeat(configuration *models.Configuration, communication *models.Communication) {
|
||||
|
||||
log.Log.Debug("HandleHeartBeat: started")
|
||||
|
||||
config := configuration.Config
|
||||
|
||||
if config.Offline == "true" {
|
||||
log.Log.Debug("HandleHeartBeat: stopping as Offline is enabled.")
|
||||
} else {
|
||||
|
||||
url := config.HeartbeatURI
|
||||
key := ""
|
||||
username := ""
|
||||
vaultURI := ""
|
||||
|
||||
if config.Cloud == "s3" && config.S3 != nil && config.S3.Publickey != "" {
|
||||
username = config.S3.Username
|
||||
key = config.S3.Publickey
|
||||
} else if config.Cloud == "kstorage" && config.KStorage != nil && config.KStorage.CloudKey != "" {
|
||||
key = config.KStorage.CloudKey
|
||||
username = config.KStorage.Directory
|
||||
vaultURI = config.KStorage.URI
|
||||
}
|
||||
|
||||
// This is the new way ;)
|
||||
if config.HubURI != "" {
|
||||
url = config.HubURI + "/devices/heartbeat"
|
||||
}
|
||||
if config.HubKey != "" {
|
||||
key = config.HubKey
|
||||
}
|
||||
|
||||
loop:
|
||||
for {
|
||||
|
||||
uptime, _ := host.Uptime()
|
||||
days := strconv.Itoa(int(uptime / (60 * 60 * 24)))
|
||||
//12:11:48 up 11 days
|
||||
|
||||
//partitions, _ := disk.Partitions(false)
|
||||
usage, _ := disk.Usage("/")
|
||||
diskPercentUsed := strconv.Itoa(int(usage.UsedPercent))
|
||||
|
||||
onvifEnabled := "false"
|
||||
if config.Capture.IPCamera.ONVIFXAddr != "" {
|
||||
onvifEnabled = "true"
|
||||
}
|
||||
|
||||
// Check if the agent is running inside a cluster (Kerberos Factory) or as
|
||||
// an open source agent
|
||||
isEnterprise := false
|
||||
if os.Getenv("DEPLOYMENT") == "factory" || os.Getenv("MACHINERY_ENVIRONMENT") == "kubernetes" {
|
||||
isEnterprise = true
|
||||
}
|
||||
|
||||
var object = fmt.Sprintf(`{
|
||||
"key" : "%s",
|
||||
"hash" : "826133658",
|
||||
"version" : "3.0.0",
|
||||
"cpuid" : "Serial: xxx",
|
||||
"clouduser" : "%s",
|
||||
"cloudpublickey" : "%s",
|
||||
"cameraname" : "%s",
|
||||
"cameratype" : "IPCamera",
|
||||
"docker" : true,
|
||||
"kios" : false,
|
||||
"raspberrypi" : false,
|
||||
"enterprise" : %t,
|
||||
"board" : "",
|
||||
"disk1size" : "%s",
|
||||
"disk3size" : "%s",
|
||||
"diskvdasize" : "%s",
|
||||
"numberoffiles" : "33",
|
||||
"temperature" : "sh: 1: vcgencmd: not found",
|
||||
"wifissid" : "",
|
||||
"wifistrength" : "",
|
||||
"uptime" : "up %s days,",
|
||||
"timestamp" : 1564747908,
|
||||
"siteID" : "%s",
|
||||
"onvif" : "%s"
|
||||
}`, config.Key, username, key, config.Name, isEnterprise, "0", "0", diskPercentUsed, days, config.HubSite, onvifEnabled)
|
||||
|
||||
var jsonStr = []byte(object)
|
||||
buffy := bytes.NewBuffer(jsonStr)
|
||||
req, _ := http.NewRequest("POST", url, buffy)
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
|
||||
client := &http.Client{}
|
||||
resp, err := client.Do(req)
|
||||
if resp != nil {
|
||||
resp.Body.Close()
|
||||
}
|
||||
if err == nil && resp.StatusCode == 200 {
|
||||
communication.CloudTimestamp.Store(time.Now().Unix())
|
||||
log.Log.Info("HandleHeartBeat: (200) Heartbeat received by Kerberos Hub.")
|
||||
} else {
|
||||
log.Log.Error("HandleHeartBeat: (400) Something went wrong while sending to Kerberos Hub.")
|
||||
}
|
||||
|
||||
// If we have a vault connect, we will also send some analytics
|
||||
// to that service.
|
||||
if vaultURI != "" {
|
||||
buffy = bytes.NewBuffer(jsonStr)
|
||||
req, _ = http.NewRequest("POST", vaultURI+"/devices/heartbeat", buffy)
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
|
||||
client = &http.Client{}
|
||||
resp, err = client.Do(req)
|
||||
if resp != nil {
|
||||
resp.Body.Close()
|
||||
}
|
||||
if err == nil && resp.StatusCode == 200 {
|
||||
log.Log.Info("HandleHeartBeat: (200) Heartbeat received by Kerberos Vault.")
|
||||
} else {
|
||||
log.Log.Error("HandleHeartBeat: (400) Something went wrong while sending to Kerberos Vault.")
|
||||
}
|
||||
}
|
||||
|
||||
// This will check if we need to stop the thread,
|
||||
// because of a reconfiguration.
|
||||
select {
|
||||
case <-communication.HandleHeartBeat:
|
||||
break loop
|
||||
case <-time.After(15 * time.Second):
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
log.Log.Debug("HandleHeartBeat: finished")
|
||||
}
|
||||
|
||||
func HandleLiveStreamSD(livestreamCursor *pubsub.QueueCursor, configuration *models.Configuration, communication *models.Communication, mqttClient mqtt.Client, decoder *ffmpeg.VideoDecoder, decoderMutex *sync.Mutex) {
|
||||
|
||||
log.Log.Debug("HandleLiveStreamSD: started")
|
||||
|
||||
config := configuration.Config
|
||||
|
||||
if config.Offline == "true" {
|
||||
log.Log.Debug("HandleLiveStreamSD: stopping as Offline is enabled.")
|
||||
} else {
|
||||
|
||||
key := ""
|
||||
if config.Cloud == "s3" && config.S3 != nil && config.S3.Publickey != "" {
|
||||
key = config.S3.Publickey
|
||||
} else if config.Cloud == "kstorage" && config.KStorage != nil && config.KStorage.CloudKey != "" {
|
||||
key = config.KStorage.CloudKey
|
||||
}
|
||||
// This is the new way ;)
|
||||
if config.HubKey != "" {
|
||||
key = config.HubKey
|
||||
}
|
||||
|
||||
topic := "kerberos/" + key + "/device/" + config.Key + "/live"
|
||||
|
||||
lastLivestreamRequest := int64(0)
|
||||
|
||||
var cursorError error
|
||||
var pkt av.Packet
|
||||
|
||||
for cursorError == nil {
|
||||
pkt, cursorError = livestreamCursor.ReadPacket()
|
||||
if len(pkt.Data) == 0 || !pkt.IsKeyFrame {
|
||||
continue
|
||||
}
|
||||
now := time.Now().Unix()
|
||||
select {
|
||||
case <-communication.HandleLiveSD:
|
||||
lastLivestreamRequest = now
|
||||
default:
|
||||
}
|
||||
if now-lastLivestreamRequest > 3 {
|
||||
continue
|
||||
}
|
||||
log.Log.Info("HandleLiveStreamSD: Sending base64 encoded images to MQTT.")
|
||||
sendImage(topic, mqttClient, pkt, decoder, decoderMutex)
|
||||
}
|
||||
}
|
||||
|
||||
log.Log.Debug("HandleLiveStreamSD: finished")
|
||||
}
|
||||
|
||||
func sendImage(topic string, mqttClient mqtt.Client, pkt av.Packet, decoder *ffmpeg.VideoDecoder, decoderMutex *sync.Mutex) {
|
||||
mat := computervision.GetRGBImage(pkt, decoder, decoderMutex)
|
||||
buffer, err := gocv.IMEncode(gocv.JPEGFileExt, mat)
|
||||
mat.Close()
|
||||
if err == nil {
|
||||
encoded := base64.StdEncoding.EncodeToString(buffer.GetBytes())
|
||||
mqttClient.Publish(topic, 0, false, encoded)
|
||||
}
|
||||
runtime.GC()
|
||||
debug.FreeOSMemory()
|
||||
}
|
||||
|
||||
func HandleLiveStreamHD(livestreamCursor *pubsub.QueueCursor, configuration *models.Configuration, communication *models.Communication, mqttClient mqtt.Client, codecs []av.CodecData, decoder *ffmpeg.VideoDecoder, decoderMutex *sync.Mutex) {
|
||||
|
||||
config := configuration.Config
|
||||
|
||||
if config.Offline == "true" {
|
||||
log.Log.Debug("HandleLiveStreamHD: stopping as Offline is enabled.")
|
||||
} else {
|
||||
|
||||
// Should create a track here.
|
||||
track := webrtc.NewVideoTrack()
|
||||
go webrtc.WriteToTrack(livestreamCursor, configuration, communication, mqttClient, track, codecs, decoder, decoderMutex)
|
||||
|
||||
if config.Capture.ForwardWebRTC == "true" {
|
||||
// We get a request with an offer, but we'll forward it.
|
||||
for m := range communication.HandleLiveHDHandshake {
|
||||
// Forward SDP
|
||||
m.CloudKey = config.Key
|
||||
request, err := json.Marshal(m)
|
||||
if err == nil {
|
||||
mqttClient.Publish("kerberos/webrtc/request", 2, false, request)
|
||||
}
|
||||
}
|
||||
} else {
|
||||
log.Log.Info("HandleLiveStreamHD: Waiting for peer connections.")
|
||||
for handshake := range communication.HandleLiveHDHandshake {
|
||||
log.Log.Info("HandleLiveStreamHD: setting up a peer connection.")
|
||||
key := config.Key + "/" + handshake.Cuuid
|
||||
webrtc.CandidatesMutex.Lock()
|
||||
_, ok := webrtc.CandidateArrays[key]
|
||||
if !ok {
|
||||
webrtc.CandidateArrays[key] = make(chan string, 30)
|
||||
}
|
||||
webrtc.CandidatesMutex.Unlock()
|
||||
webrtc.InitializeWebRTCConnection(configuration, communication, mqttClient, track, handshake, webrtc.CandidateArrays[key])
|
||||
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// VerifyHub godoc
|
||||
// @Router /api/hub/verify [post]
|
||||
// @ID verify-hub
|
||||
// @Security Bearer
|
||||
// @securityDefinitions.apikey Bearer
|
||||
// @in header
|
||||
// @name Authorization
|
||||
// @Tags config
|
||||
// @Param config body models.Config true "Config"
|
||||
// @Summary Will verify the hub connectivity.
|
||||
// @Description Will verify the hub connectivity.
|
||||
// @Success 200 {object} models.APIResponse
|
||||
func VerifyHub(c *gin.Context) {
|
||||
|
||||
var config models.Config
|
||||
err := c.BindJSON(&config)
|
||||
|
||||
if err == nil {
|
||||
hubKey := config.HubKey
|
||||
//hubPrivateKey := config.HubPrivateKey
|
||||
//hubSite := config.HubSite
|
||||
hubURI := config.HubURI
|
||||
|
||||
content := []byte(`{"message": "fake-message"}`)
|
||||
body := bytes.NewReader(content)
|
||||
req, err := http.NewRequest("POST", hubURI+"/queue/test", body)
|
||||
if err == nil {
|
||||
req.Header.Set("X-Kerberos-Cloud-Key", hubKey)
|
||||
client := &http.Client{}
|
||||
|
||||
resp, err := client.Do(req)
|
||||
if err == nil {
|
||||
body, err := ioutil.ReadAll(resp.Body)
|
||||
defer resp.Body.Close()
|
||||
if err == nil {
|
||||
if resp.StatusCode == 200 {
|
||||
c.JSON(200, body)
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while reaching the Kerberos Hub API: " + string(body),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while ready the response body: " + err.Error(),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while reaching to the Kerberos Hub API: " + hubURI,
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while creating the HTTP request: " + err.Error(),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while receiving the config " + err.Error(),
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// VerifyPersistence godoc
|
||||
// @Router /api/persistence/verify [post]
|
||||
// @ID verify-persistence
|
||||
// @Security Bearer
|
||||
// @securityDefinitions.apikey Bearer
|
||||
// @in header
|
||||
// @name Authorization
|
||||
// @Tags config
|
||||
// @Param config body models.Config true "Config"
|
||||
// @Summary Will verify the persistence.
|
||||
// @Description Will verify the persistence.
|
||||
// @Success 200 {object} models.APIResponse
|
||||
func VerifyPersistence(c *gin.Context) {
|
||||
|
||||
var config models.Config
|
||||
err := c.BindJSON(&config)
|
||||
if err != nil || config.Cloud != "" {
|
||||
|
||||
if config.Cloud == "s3" {
|
||||
|
||||
//fmt.Println("Uploading...")
|
||||
// timestamp_microseconds_instanceName_regionCoordinates_numberOfChanges_token
|
||||
// 1564859471_6-474162_oprit_577-283-727-375_1153_27.mp4
|
||||
// - Timestamp
|
||||
// - Size + - + microseconds
|
||||
// - device
|
||||
// - Region
|
||||
// - Number of changes
|
||||
// - Token
|
||||
|
||||
aws_access_key_id := config.S3.Publickey
|
||||
aws_secret_access_key := config.S3.Secretkey
|
||||
aws_region := config.S3.Region
|
||||
|
||||
// This is the new way ;)
|
||||
if config.HubKey != "" {
|
||||
aws_access_key_id = config.HubKey
|
||||
}
|
||||
if config.HubPrivateKey != "" {
|
||||
aws_secret_access_key = config.HubPrivateKey
|
||||
}
|
||||
|
||||
s3Client, err := minio.NewWithRegion("s3.amazonaws.com", aws_access_key_id, aws_secret_access_key, true, aws_region)
|
||||
if err != nil {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Creation of Kerberos Hub connection failed: " + err.Error(),
|
||||
})
|
||||
} else {
|
||||
|
||||
// Check if we need to use the proxy.
|
||||
if config.S3.ProxyURI != "" {
|
||||
var transport http.RoundTripper = &http.Transport{
|
||||
Proxy: func(*http.Request) (*url.URL, error) {
|
||||
return url.Parse(config.S3.ProxyURI)
|
||||
},
|
||||
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
|
||||
}
|
||||
s3Client.SetCustomTransport(transport)
|
||||
}
|
||||
|
||||
deviceKey := "fake-key"
|
||||
devicename := "justatest"
|
||||
coordinates := "200-200-400-400"
|
||||
eventToken := "769"
|
||||
|
||||
timestamp := time.Now().Unix()
|
||||
fileName := strconv.FormatInt(timestamp, 10) + "_6-967003_justatest_200-200-400-400_24_769.mp4"
|
||||
content := []byte("test-file")
|
||||
body := bytes.NewReader(content)
|
||||
|
||||
n, err := s3Client.PutObject(config.S3.Bucket,
|
||||
config.S3.Username+"/"+fileName,
|
||||
body,
|
||||
body.Size(),
|
||||
minio.PutObjectOptions{
|
||||
ContentType: "video/mp4",
|
||||
StorageClass: "ONEZONE_IA",
|
||||
UserMetadata: map[string]string{
|
||||
"event-timestamp": strconv.FormatInt(timestamp, 10),
|
||||
"event-microseconds": deviceKey,
|
||||
"event-instancename": devicename,
|
||||
"event-regioncoordinates": coordinates,
|
||||
"event-numberofchanges": deviceKey,
|
||||
"event-token": eventToken,
|
||||
"productid": deviceKey,
|
||||
"publickey": aws_access_key_id,
|
||||
"uploadtime": "now",
|
||||
},
|
||||
})
|
||||
|
||||
if err != nil {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Upload of fake recording failed: " + err.Error(),
|
||||
})
|
||||
} else {
|
||||
c.JSON(200, models.APIResponse{
|
||||
Data: "Upload Finished: file has been uploaded to bucket: " + strconv.FormatInt(n, 10),
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if config.Cloud == "kstorage" {
|
||||
|
||||
uri := config.KStorage.URI
|
||||
accessKey := config.KStorage.AccessKey
|
||||
secretAccessKey := config.KStorage.SecretAccessKey
|
||||
directory := config.KStorage.Directory
|
||||
provider := config.KStorage.Provider
|
||||
|
||||
if err == nil && uri != "" && accessKey != "" && secretAccessKey != "" {
|
||||
var postData = []byte(`{"title":"Buy cheese and bread for breakfast."}`)
|
||||
client := &http.Client{}
|
||||
req, err := http.NewRequest("POST", uri+"/ping", bytes.NewReader(postData))
|
||||
|
||||
req.Header.Add("X-Kerberos-Storage-AccessKey", accessKey)
|
||||
req.Header.Add("X-Kerberos-Storage-SecretAccessKey", secretAccessKey)
|
||||
resp, err := client.Do(req)
|
||||
|
||||
if err == nil {
|
||||
body, err := ioutil.ReadAll(resp.Body)
|
||||
defer resp.Body.Close()
|
||||
if err == nil && resp.StatusCode == http.StatusOK {
|
||||
|
||||
if provider != "" || directory != "" {
|
||||
|
||||
hubKey := config.KStorage.CloudKey
|
||||
// This is the new way ;)
|
||||
if config.HubKey != "" {
|
||||
hubKey = config.HubKey
|
||||
}
|
||||
|
||||
// Generate a random name.
|
||||
timestamp := time.Now().Unix()
|
||||
fileName := strconv.FormatInt(timestamp, 10) +
|
||||
"_6-967003_justatest_200-200-400-400_24_769.mp4"
|
||||
content := []byte("test-file")
|
||||
body := bytes.NewReader(content)
|
||||
//fileSize := int64(len(content))
|
||||
|
||||
req, err := http.NewRequest("POST", uri+"/storage", body)
|
||||
if err == nil {
|
||||
|
||||
req.Header.Set("Content-Type", "video/mp4")
|
||||
req.Header.Set("X-Kerberos-Storage-CloudKey", hubKey)
|
||||
req.Header.Set("X-Kerberos-Storage-AccessKey", accessKey)
|
||||
req.Header.Set("X-Kerberos-Storage-SecretAccessKey", secretAccessKey)
|
||||
req.Header.Set("X-Kerberos-Storage-Provider", provider)
|
||||
req.Header.Set("X-Kerberos-Storage-FileName", fileName)
|
||||
req.Header.Set("X-Kerberos-Storage-Device", "test")
|
||||
req.Header.Set("X-Kerberos-Storage-Capture", "IPCamera")
|
||||
req.Header.Set("X-Kerberos-Storage-Directory", directory)
|
||||
client := &http.Client{}
|
||||
|
||||
resp, err := client.Do(req)
|
||||
|
||||
if err == nil {
|
||||
if resp != nil {
|
||||
body, err := ioutil.ReadAll(resp.Body)
|
||||
defer resp.Body.Close()
|
||||
if err == nil {
|
||||
if resp.StatusCode == 200 {
|
||||
c.JSON(200, body)
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while verifying your persistence settings. Make sure your provider is the same as the storage provider in your Kerberos Vault, and the relevant storage provider is configured properly.",
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Upload of fake recording failed: " + err.Error(),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while creating /storage POST request." + err.Error(),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Provider and/or directory is missing from the request.",
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while verifying storage credentials: " + string(body),
|
||||
})
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while verifying storage credentials:" + err.Error(),
|
||||
})
|
||||
}
|
||||
}
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "No persistence was specified, so do not know what to verify:" + err.Error(),
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -1,96 +0,0 @@
|
||||
package cloud
|
||||
|
||||
import (
|
||||
"io/ioutil"
|
||||
"net/http"
|
||||
"os"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/log"
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
)
|
||||
|
||||
func UploadKerberosVault(configuration *models.Configuration, fileName string, directory string) bool {
|
||||
|
||||
config := configuration.Config
|
||||
|
||||
if config.KStorage.AccessKey == "" ||
|
||||
config.KStorage.SecretAccessKey == "" ||
|
||||
config.KStorage.Provider == "" ||
|
||||
config.KStorage.Directory == "" ||
|
||||
config.KStorage.URI == "" {
|
||||
log.Log.Info("UploadKerberosVault: Kerberos Vault not properly configured.")
|
||||
}
|
||||
|
||||
//fmt.Println("Uploading...")
|
||||
// timestamp_microseconds_instanceName_regionCoordinates_numberOfChanges_token
|
||||
// 1564859471_6-474162_oprit_577-283-727-375_1153_27.mp4
|
||||
// - Timestamp
|
||||
// - Size + - + microseconds
|
||||
// - device
|
||||
// - Region
|
||||
// - Number of changes
|
||||
// - Token
|
||||
|
||||
// KerberosCloud, this means storage is disabled and proxy enabled.
|
||||
log.Log.Info("UploadKerberosVault: Uploading to Kerberos Vault (" + config.KStorage.URI + ")")
|
||||
|
||||
log.Log.Info("UploadKerberosVault: Upload started for " + fileName)
|
||||
fullname := "data/recordings/" + fileName
|
||||
|
||||
file, err := os.OpenFile(fullname, os.O_RDWR, 0755)
|
||||
if err != nil {
|
||||
log.Log.Info("UploadKerberosVault: Upload Failed, file doesn't exists anymore.")
|
||||
os.Remove(directory + "/" + fileName)
|
||||
return false
|
||||
}
|
||||
|
||||
defer file.Close()
|
||||
|
||||
publicKey := config.KStorage.CloudKey
|
||||
// This is the new way ;)
|
||||
if config.HubKey != "" {
|
||||
publicKey = config.HubKey
|
||||
}
|
||||
|
||||
req, err := http.NewRequest("POST", config.KStorage.URI+"/storage", file)
|
||||
if err != nil {
|
||||
log.Log.Error("Error reading request. " + err.Error())
|
||||
}
|
||||
req.Header.Set("Content-Type", "video/mp4")
|
||||
req.Header.Set("X-Kerberos-Storage-CloudKey", publicKey)
|
||||
req.Header.Set("X-Kerberos-Storage-AccessKey", config.KStorage.AccessKey)
|
||||
req.Header.Set("X-Kerberos-Storage-SecretAccessKey", config.KStorage.SecretAccessKey)
|
||||
req.Header.Set("X-Kerberos-Storage-Provider", config.KStorage.Provider)
|
||||
req.Header.Set("X-Kerberos-Storage-FileName", fileName)
|
||||
req.Header.Set("X-Kerberos-Storage-Device", config.Key)
|
||||
req.Header.Set("X-Kerberos-Storage-Capture", "IPCamera")
|
||||
req.Header.Set("X-Kerberos-Storage-Directory", config.KStorage.Directory)
|
||||
//client := &http.Client{Timeout: time.Second * 30}
|
||||
client := &http.Client{}
|
||||
|
||||
resp, err := client.Do(req)
|
||||
|
||||
if resp != nil {
|
||||
defer resp.Body.Close()
|
||||
}
|
||||
|
||||
if err == nil {
|
||||
if resp != nil {
|
||||
body, err := ioutil.ReadAll(resp.Body)
|
||||
if err == nil {
|
||||
if resp.StatusCode == 200 {
|
||||
log.Log.Info("UploadKerberosVault: Upload Finished, " + resp.Status + ", " + string(body))
|
||||
// We will remove the file from disk as well
|
||||
os.Remove(fullname)
|
||||
os.Remove(directory + "/" + fileName)
|
||||
} else {
|
||||
log.Log.Info("UploadKerberosVault: Upload Failed, " + resp.Status + ", " + string(body))
|
||||
}
|
||||
resp.Body.Close()
|
||||
}
|
||||
}
|
||||
} else {
|
||||
log.Log.Info("UploadKerberosVault: Upload Failed, " + err.Error())
|
||||
}
|
||||
return true
|
||||
}
|
||||
1954
machinery/src/cloud/cloud.go
Normal file
592
machinery/src/cloud/cloud_test.go
Normal file
@@ -0,0 +1,592 @@
|
||||
package cloud
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net/http"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
agentonvif "github.com/kerberos-io/agent/machinery/src/onvif"
|
||||
goonvif "github.com/kerberos-io/onvif"
|
||||
goonvifdevice "github.com/kerberos-io/onvif/device"
|
||||
goonvifptz "github.com/kerberos-io/onvif/ptz"
|
||||
)
|
||||
|
||||
func TestHeartbeatFailureLogOmitsHubResponseBody(t *testing.T) {
|
||||
response := &http.Response{
|
||||
StatusCode: http.StatusBadRequest,
|
||||
Status: "400 Bad Request",
|
||||
Body: io.NopCloser(strings.NewReader(`{"error":"invalid heartbeat"}`)),
|
||||
}
|
||||
|
||||
responseBody, truncated, err := readHeartbeatResponseBody(response)
|
||||
if err != nil {
|
||||
t.Fatalf("readHeartbeatResponseBody() error = %v", err)
|
||||
}
|
||||
fields := heartbeatFailureLogFields(response, responseBody, truncated, 125*time.Millisecond)
|
||||
|
||||
for key, want := range map[string]interface{}{
|
||||
"duration_ms": int64(125),
|
||||
"response_body_bytes": len(responseBody),
|
||||
"response_body_truncated": false,
|
||||
"status_code": http.StatusBadRequest,
|
||||
} {
|
||||
if got := fields[key]; got != want {
|
||||
t.Errorf("%s = %v, want %v", key, got, want)
|
||||
}
|
||||
}
|
||||
for key, value := range fields {
|
||||
if strings.Contains(key, "response_body") && key != "response_body_bytes" && key != "response_body_truncated" {
|
||||
t.Fatalf("unexpected response body field %q=%v", key, value)
|
||||
}
|
||||
if strings.Contains(fmt.Sprint(value), "invalid heartbeat") {
|
||||
t.Fatalf("heartbeat log fields exposed response body in %q=%v", key, value)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestReadHeartbeatResponseBodyTruncatesLargeBody(t *testing.T) {
|
||||
response := &http.Response{
|
||||
Body: io.NopCloser(strings.NewReader(strings.Repeat("x", heartbeatResponseBodyLogLimit+1))),
|
||||
}
|
||||
|
||||
body, truncated, err := readHeartbeatResponseBody(response)
|
||||
if err != nil {
|
||||
t.Fatalf("readHeartbeatResponseBody() error = %v", err)
|
||||
}
|
||||
if !truncated {
|
||||
t.Fatal("readHeartbeatResponseBody() truncated = false, want true")
|
||||
}
|
||||
if len(body) != heartbeatResponseBodyLogLimit {
|
||||
t.Fatalf("len(body) = %d, want %d", len(body), heartbeatResponseBodyLogLimit)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFPayloadCachesStaticAndReusesLoopSubscription(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
device := newTestONVIFDevice()
|
||||
camera := models.IPCamera{
|
||||
ONVIFXAddr: "http://camera/onvif",
|
||||
ONVIFUsername: "operator",
|
||||
ONVIFPassword: "secret",
|
||||
}
|
||||
initialEvents := []agentonvif.ONVIFEvents{{Key: "input-1", Type: "input", Value: "true", Timestamp: 1}}
|
||||
loopEvents := []agentonvif.ONVIFEvents{{Key: "output-1", Type: "output", Value: "false", Timestamp: 2}}
|
||||
wantPresets := mustJSONMarshal(t, []models.OnvifActionPreset{{Name: "Lobby", Token: "1"}})
|
||||
wantInitialEvents := mustJSONMarshal(t, initialEvents)
|
||||
wantLoopEvents := mustJSONMarshal(t, loopEvents)
|
||||
|
||||
var connectCalls, ptzConfigCalls, ptzFunctionCalls, presetCalls, createCalls, eventCalls, unsubscribeCalls int
|
||||
|
||||
heartbeatConnectToONVIFDevice = func(*models.IPCamera) (*goonvif.Device, goonvifdevice.GetCapabilitiesResponse, error) {
|
||||
connectCalls++
|
||||
return device, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
}
|
||||
heartbeatGetPTZConfigurationsFromDevice = func(*goonvif.Device) (goonvifptz.GetConfigurationsResponse, error) {
|
||||
ptzConfigCalls++
|
||||
return goonvifptz.GetConfigurationsResponse{}, nil
|
||||
}
|
||||
heartbeatGetPTZFunctionsFromDevice = func(goonvifptz.GetConfigurationsResponse) ([]string, bool, bool) {
|
||||
ptzFunctionCalls++
|
||||
return nil, true, true
|
||||
}
|
||||
heartbeatGetPresetsFromDevice = func(*goonvif.Device) ([]models.OnvifActionPreset, error) {
|
||||
presetCalls++
|
||||
return []models.OnvifActionPreset{{Name: "Lobby", Token: "1"}}, nil
|
||||
}
|
||||
heartbeatCreatePullPointSubscription = func(*goonvif.Device) (string, error) {
|
||||
createCalls++
|
||||
switch createCalls {
|
||||
case 1:
|
||||
return "initial-1", nil
|
||||
case 2:
|
||||
return "loop", nil
|
||||
case 3:
|
||||
return "initial-2", nil
|
||||
default:
|
||||
t.Fatalf("unexpected create pull point call %d", createCalls)
|
||||
return "", nil
|
||||
}
|
||||
}
|
||||
heartbeatGetEventMessages = func(_ *goonvif.Device, pullPointAddress string) ([]agentonvif.ONVIFEvents, error) {
|
||||
eventCalls++
|
||||
switch pullPointAddress {
|
||||
case "initial-1", "initial-2":
|
||||
return initialEvents, nil
|
||||
case "loop":
|
||||
return loopEvents, nil
|
||||
default:
|
||||
t.Fatalf("unexpected pull point address %q", pullPointAddress)
|
||||
return nil, nil
|
||||
}
|
||||
}
|
||||
heartbeatUnsubscribePullPoint = func(_ *goonvif.Device, pullPointAddress string) error {
|
||||
unsubscribeCalls++
|
||||
if pullPointAddress != "initial-1" && pullPointAddress != "initial-2" {
|
||||
t.Fatalf("unexpected unsubscribe pull point %q", pullPointAddress)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
state := newHeartbeatONVIFState()
|
||||
|
||||
payload := getHeartbeatONVIFPayload(camera, state)
|
||||
if payload.enabled != "true" || payload.zoom != "true" || payload.panTilt != "true" || payload.presets != "true" {
|
||||
t.Fatalf("unexpected static payload: %+v", payload)
|
||||
}
|
||||
if string(payload.presetsList) != string(wantPresets) {
|
||||
t.Fatalf("payload.presetsList = %s, want %s", payload.presetsList, wantPresets)
|
||||
}
|
||||
if string(payload.eventsList) != string(wantInitialEvents) {
|
||||
t.Fatalf("payload.eventsList = %s, want %s", payload.eventsList, wantInitialEvents)
|
||||
}
|
||||
if connectCalls != 1 || ptzConfigCalls != 1 || ptzFunctionCalls != 1 || presetCalls != 1 {
|
||||
t.Fatalf("unexpected static call counts after first cycle: connect=%d ptzConfig=%d ptzFunctions=%d presets=%d", connectCalls, ptzConfigCalls, ptzFunctionCalls, presetCalls)
|
||||
}
|
||||
if createCalls != 2 || eventCalls != 1 || unsubscribeCalls != 1 {
|
||||
t.Fatalf("unexpected event call counts after first cycle: create=%d events=%d unsubscribe=%d", createCalls, eventCalls, unsubscribeCalls)
|
||||
}
|
||||
|
||||
payload = getHeartbeatONVIFPayload(camera, state)
|
||||
if string(payload.eventsList) != string(wantLoopEvents) {
|
||||
t.Fatalf("second payload.eventsList = %s, want %s", payload.eventsList, wantLoopEvents)
|
||||
}
|
||||
if connectCalls != 1 {
|
||||
t.Fatalf("connectCalls = %d, want 1", connectCalls)
|
||||
}
|
||||
if ptzConfigCalls != 1 || ptzFunctionCalls != 1 || presetCalls != 1 {
|
||||
t.Fatalf("static calls were not cached: ptzConfig=%d ptzFunctions=%d presets=%d", ptzConfigCalls, ptzFunctionCalls, presetCalls)
|
||||
}
|
||||
if createCalls != 3 || eventCalls != 3 || unsubscribeCalls != 2 {
|
||||
t.Fatalf("temporary state subscription was not refreshed or loop subscription was not reused: create=%d events=%d unsubscribe=%d", createCalls, eventCalls, unsubscribeCalls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFPayloadRefreshesAfterCameraConfigChange(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
deviceA := newTestONVIFDevice()
|
||||
deviceB := newTestONVIFDevice()
|
||||
cameraA := models.IPCamera{ONVIFXAddr: "http://camera-a/onvif", ONVIFUsername: "user", ONVIFPassword: "secret-a"}
|
||||
cameraB := models.IPCamera{ONVIFXAddr: "http://camera-b/onvif", ONVIFUsername: "user", ONVIFPassword: "secret-b"}
|
||||
var connectCalls, ptzConfigCalls, presetCalls, createCalls int
|
||||
var unsubscribed []string
|
||||
|
||||
heartbeatConnectToONVIFDevice = func(camera *models.IPCamera) (*goonvif.Device, goonvifdevice.GetCapabilitiesResponse, error) {
|
||||
connectCalls++
|
||||
switch camera.ONVIFXAddr {
|
||||
case cameraA.ONVIFXAddr:
|
||||
return deviceA, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
case cameraB.ONVIFXAddr:
|
||||
return deviceB, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
default:
|
||||
t.Fatalf("unexpected camera address %q", camera.ONVIFXAddr)
|
||||
return nil, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
}
|
||||
}
|
||||
heartbeatGetPTZConfigurationsFromDevice = func(*goonvif.Device) (goonvifptz.GetConfigurationsResponse, error) {
|
||||
ptzConfigCalls++
|
||||
return goonvifptz.GetConfigurationsResponse{}, nil
|
||||
}
|
||||
heartbeatGetPTZFunctionsFromDevice = func(goonvifptz.GetConfigurationsResponse) ([]string, bool, bool) {
|
||||
return nil, false, true
|
||||
}
|
||||
heartbeatGetPresetsFromDevice = func(*goonvif.Device) ([]models.OnvifActionPreset, error) {
|
||||
presetCalls++
|
||||
return nil, nil
|
||||
}
|
||||
heartbeatCreatePullPointSubscription = func(*goonvif.Device) (string, error) {
|
||||
createCalls++
|
||||
switch createCalls {
|
||||
case 1:
|
||||
return "initial-a", nil
|
||||
case 2:
|
||||
return "loop-a", nil
|
||||
case 3:
|
||||
return "initial-b", nil
|
||||
case 4:
|
||||
return "loop-b", nil
|
||||
default:
|
||||
t.Fatalf("unexpected create pull point call %d", createCalls)
|
||||
return "", nil
|
||||
}
|
||||
}
|
||||
heartbeatGetEventMessages = func(_ *goonvif.Device, pullPointAddress string) ([]agentonvif.ONVIFEvents, error) {
|
||||
switch pullPointAddress {
|
||||
case "initial-a":
|
||||
return []agentonvif.ONVIFEvents{{Key: "a", Type: "input", Value: "true", Timestamp: 1}}, nil
|
||||
case "initial-b":
|
||||
return []agentonvif.ONVIFEvents{{Key: "b", Type: "input", Value: "false", Timestamp: 2}}, nil
|
||||
default:
|
||||
t.Fatalf("unexpected pull point address %q", pullPointAddress)
|
||||
return nil, nil
|
||||
}
|
||||
}
|
||||
heartbeatUnsubscribePullPoint = func(_ *goonvif.Device, pullPointAddress string) error {
|
||||
unsubscribed = append(unsubscribed, pullPointAddress)
|
||||
return nil
|
||||
}
|
||||
|
||||
state := newHeartbeatONVIFState()
|
||||
_ = getHeartbeatONVIFPayload(cameraA, state)
|
||||
payload := getHeartbeatONVIFPayload(cameraB, state)
|
||||
|
||||
if connectCalls != 2 {
|
||||
t.Fatalf("connectCalls = %d, want 2", connectCalls)
|
||||
}
|
||||
if ptzConfigCalls != 2 || presetCalls != 2 {
|
||||
t.Fatalf("camera config change did not refresh static state: ptzConfig=%d presets=%d", ptzConfigCalls, presetCalls)
|
||||
}
|
||||
if createCalls != 4 {
|
||||
t.Fatalf("camera config change did not recreate subscriptions: create=%d", createCalls)
|
||||
}
|
||||
if countString(unsubscribed, "loop-a") != 1 {
|
||||
t.Fatalf("unsubscribed loop-a %d times, want 1; unsubscribed=%v", countString(unsubscribed, "loop-a"), unsubscribed)
|
||||
}
|
||||
wantEvents := mustJSONMarshal(t, []agentonvif.ONVIFEvents{{Key: "b", Type: "input", Value: "false", Timestamp: 2}})
|
||||
if string(payload.eventsList) != string(wantEvents) {
|
||||
t.Fatalf("payload.eventsList = %s, want %s", payload.eventsList, wantEvents)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFPayloadRetriesStaticFetchFailuresWithoutReconnect(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
device := newTestONVIFDevice()
|
||||
camera := models.IPCamera{
|
||||
ONVIFXAddr: "http://camera/onvif",
|
||||
ONVIFUsername: "operator",
|
||||
ONVIFPassword: "secret",
|
||||
}
|
||||
var connectCalls, ptzConfigCalls, presetCalls, createCalls, eventCalls int
|
||||
|
||||
heartbeatConnectToONVIFDevice = func(*models.IPCamera) (*goonvif.Device, goonvifdevice.GetCapabilitiesResponse, error) {
|
||||
connectCalls++
|
||||
return device, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
}
|
||||
heartbeatGetPTZConfigurationsFromDevice = func(*goonvif.Device) (goonvifptz.GetConfigurationsResponse, error) {
|
||||
ptzConfigCalls++
|
||||
return goonvifptz.GetConfigurationsResponse{}, nil
|
||||
}
|
||||
heartbeatGetPTZFunctionsFromDevice = func(goonvifptz.GetConfigurationsResponse) ([]string, bool, bool) {
|
||||
return nil, true, true
|
||||
}
|
||||
heartbeatGetPresetsFromDevice = func(*goonvif.Device) ([]models.OnvifActionPreset, error) {
|
||||
presetCalls++
|
||||
if presetCalls == 1 {
|
||||
return nil, errors.New("temporary preset failure")
|
||||
}
|
||||
return []models.OnvifActionPreset{{Name: "Lobby", Token: "1"}}, nil
|
||||
}
|
||||
heartbeatCreatePullPointSubscription = func(*goonvif.Device) (string, error) {
|
||||
createCalls++
|
||||
switch createCalls {
|
||||
case 1:
|
||||
return "initial-1", nil
|
||||
case 2:
|
||||
return "loop", nil
|
||||
case 3:
|
||||
return "initial-2", nil
|
||||
default:
|
||||
t.Fatalf("unexpected create pull point call %d", createCalls)
|
||||
return "", nil
|
||||
}
|
||||
}
|
||||
heartbeatGetEventMessages = func(_ *goonvif.Device, pullPointAddress string) ([]agentonvif.ONVIFEvents, error) {
|
||||
eventCalls++
|
||||
switch pullPointAddress {
|
||||
case "initial-1", "initial-2":
|
||||
return []agentonvif.ONVIFEvents{{Key: "one", Type: "input", Value: "true", Timestamp: 1}}, nil
|
||||
case "loop":
|
||||
return []agentonvif.ONVIFEvents{{Key: "two", Type: "output", Value: "false", Timestamp: 2}}, nil
|
||||
default:
|
||||
t.Fatalf("unexpected pull point address %q", pullPointAddress)
|
||||
return nil, nil
|
||||
}
|
||||
}
|
||||
heartbeatUnsubscribePullPoint = func(*goonvif.Device, string) error { return nil }
|
||||
|
||||
state := newHeartbeatONVIFState()
|
||||
payload := getHeartbeatONVIFPayload(camera, state)
|
||||
if payload.presets != "false" {
|
||||
t.Fatalf("payload.presets = %q, want false on transient preset failure", payload.presets)
|
||||
}
|
||||
payload = getHeartbeatONVIFPayload(camera, state)
|
||||
if payload.presets != "true" {
|
||||
t.Fatalf("payload.presets = %q, want true after retry", payload.presets)
|
||||
}
|
||||
if connectCalls != 1 {
|
||||
t.Fatalf("connectCalls = %d, want 1", connectCalls)
|
||||
}
|
||||
if ptzConfigCalls != 2 || presetCalls != 2 {
|
||||
t.Fatalf("static failures were not retried on heartbeat cadence: ptzConfig=%d presets=%d", ptzConfigCalls, presetCalls)
|
||||
}
|
||||
if createCalls != 3 || eventCalls != 3 {
|
||||
t.Fatalf("unexpected event behavior during retry: create=%d events=%d", createCalls, eventCalls)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFStateReleasesSubscriptionWhenDisabled(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
device := newTestONVIFDevice()
|
||||
state := newHeartbeatONVIFState()
|
||||
state.cameraConfiguration = models.IPCamera{ONVIFXAddr: "http://camera/onvif"}
|
||||
state.cameraKey = heartbeatONVIFCameraKey(state.cameraConfiguration)
|
||||
state.device = device
|
||||
state.loopPullPoint = "loop"
|
||||
|
||||
var unsubscribed []string
|
||||
heartbeatUnsubscribePullPoint = func(gotDevice *goonvif.Device, pullPointAddress string) error {
|
||||
if gotDevice != device {
|
||||
t.Fatal("unsubscribe used a different ONVIF device")
|
||||
}
|
||||
unsubscribed = append(unsubscribed, pullPointAddress)
|
||||
return nil
|
||||
}
|
||||
|
||||
state.prepare(models.IPCamera{})
|
||||
|
||||
if len(unsubscribed) != 1 || unsubscribed[0] != "loop" {
|
||||
t.Fatalf("unsubscribed = %v, want [loop]", unsubscribed)
|
||||
}
|
||||
if state.device != nil || state.loopPullPoint != "" {
|
||||
t.Fatalf("disabled state retained device or pull point: %+v", state)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFPayloadDoesNotCreateSubscriptionsWhenConnectFails(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
var createCalls int
|
||||
|
||||
heartbeatConnectToONVIFDevice = func(*models.IPCamera) (*goonvif.Device, goonvifdevice.GetCapabilitiesResponse, error) {
|
||||
return nil, goonvifdevice.GetCapabilitiesResponse{}, errors.New("connect failed")
|
||||
}
|
||||
heartbeatCreatePullPointSubscription = func(*goonvif.Device) (string, error) {
|
||||
createCalls++
|
||||
return "unexpected", nil
|
||||
}
|
||||
|
||||
payload := getHeartbeatONVIFPayload(models.IPCamera{
|
||||
ONVIFXAddr: "http://camera/onvif",
|
||||
ONVIFUsername: "operator",
|
||||
ONVIFPassword: "secret",
|
||||
}, newHeartbeatONVIFState())
|
||||
|
||||
if createCalls != 0 {
|
||||
t.Fatalf("createCalls = %d, want 0", createCalls)
|
||||
}
|
||||
assertDefaultHeartbeatONVIFPayload(t, payload)
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFPayloadReconnectFailureInvalidatesCache(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
device1 := newTestONVIFDevice()
|
||||
device2 := newTestONVIFDevice()
|
||||
camera := models.IPCamera{
|
||||
ONVIFXAddr: "http://camera/onvif",
|
||||
ONVIFUsername: "operator",
|
||||
ONVIFPassword: "secret",
|
||||
}
|
||||
var connectCalls, ptzConfigCalls, presetCalls, createCalls int
|
||||
var unsubscribed []string
|
||||
|
||||
heartbeatConnectToONVIFDevice = func(*models.IPCamera) (*goonvif.Device, goonvifdevice.GetCapabilitiesResponse, error) {
|
||||
connectCalls++
|
||||
switch connectCalls {
|
||||
case 1:
|
||||
return device1, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
case 2:
|
||||
return device2, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
default:
|
||||
t.Fatalf("unexpected connect call %d", connectCalls)
|
||||
return nil, goonvifdevice.GetCapabilitiesResponse{}, nil
|
||||
}
|
||||
}
|
||||
heartbeatGetPTZConfigurationsFromDevice = func(*goonvif.Device) (goonvifptz.GetConfigurationsResponse, error) {
|
||||
ptzConfigCalls++
|
||||
return goonvifptz.GetConfigurationsResponse{}, nil
|
||||
}
|
||||
heartbeatGetPTZFunctionsFromDevice = func(goonvifptz.GetConfigurationsResponse) ([]string, bool, bool) {
|
||||
return nil, true, false
|
||||
}
|
||||
heartbeatGetPresetsFromDevice = func(*goonvif.Device) ([]models.OnvifActionPreset, error) {
|
||||
presetCalls++
|
||||
return []models.OnvifActionPreset{{Name: "Preset", Token: "1"}}, nil
|
||||
}
|
||||
heartbeatCreatePullPointSubscription = func(*goonvif.Device) (string, error) {
|
||||
createCalls++
|
||||
switch createCalls {
|
||||
case 1:
|
||||
return "initial-1", nil
|
||||
case 2:
|
||||
return "loop-1", nil
|
||||
case 3:
|
||||
return "initial-2", nil
|
||||
case 4:
|
||||
return "initial-3", nil
|
||||
case 5:
|
||||
return "loop-3", nil
|
||||
default:
|
||||
t.Fatalf("unexpected create pull point call %d", createCalls)
|
||||
return "", nil
|
||||
}
|
||||
}
|
||||
heartbeatGetEventMessages = func(_ *goonvif.Device, pullPointAddress string) ([]agentonvif.ONVIFEvents, error) {
|
||||
switch pullPointAddress {
|
||||
case "initial-1":
|
||||
return []agentonvif.ONVIFEvents{{Key: "before", Type: "input", Value: "true", Timestamp: 1}}, nil
|
||||
case "initial-2":
|
||||
return []agentonvif.ONVIFEvents{{Key: "during", Type: "input", Value: "true", Timestamp: 2}}, nil
|
||||
case "loop-1":
|
||||
return nil, errors.New("pull failed")
|
||||
case "initial-3":
|
||||
return []agentonvif.ONVIFEvents{{Key: "after", Type: "input", Value: "false", Timestamp: 2}}, nil
|
||||
default:
|
||||
t.Fatalf("unexpected pull point address %q", pullPointAddress)
|
||||
return nil, nil
|
||||
}
|
||||
}
|
||||
heartbeatUnsubscribePullPoint = func(_ *goonvif.Device, pullPointAddress string) error {
|
||||
unsubscribed = append(unsubscribed, pullPointAddress)
|
||||
return nil
|
||||
}
|
||||
|
||||
state := newHeartbeatONVIFState()
|
||||
_ = getHeartbeatONVIFPayload(camera, state)
|
||||
payload := getHeartbeatONVIFPayload(camera, state)
|
||||
wantEventsDuringFailure := mustJSONMarshal(t, []agentonvif.ONVIFEvents{{Key: "during", Type: "input", Value: "true", Timestamp: 2}})
|
||||
if string(payload.eventsList) != string(wantEventsDuringFailure) {
|
||||
t.Fatalf("payload.eventsList after operation failure = %s, want %s", payload.eventsList, wantEventsDuringFailure)
|
||||
}
|
||||
payload = getHeartbeatONVIFPayload(camera, state)
|
||||
|
||||
if ptzConfigCalls != 2 || presetCalls != 2 {
|
||||
t.Fatalf("reconnect did not refresh static state: ptzConfig=%d presets=%d", ptzConfigCalls, presetCalls)
|
||||
}
|
||||
if connectCalls != 2 {
|
||||
t.Fatalf("connectCalls = %d, want 2 after reconnect", connectCalls)
|
||||
}
|
||||
if createCalls != 5 {
|
||||
t.Fatalf("reconnect did not recreate subscriptions: create=%d", createCalls)
|
||||
}
|
||||
if countString(unsubscribed, "loop-1") != 1 {
|
||||
t.Fatalf("operation failure cleanup mismatch, unsubscribed=%v", unsubscribed)
|
||||
}
|
||||
wantEvents := mustJSONMarshal(t, []agentonvif.ONVIFEvents{{Key: "after", Type: "input", Value: "false", Timestamp: 2}})
|
||||
if string(payload.eventsList) != string(wantEvents) {
|
||||
t.Fatalf("payload.eventsList = %s, want %s", payload.eventsList, wantEvents)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHeartbeatONVIFPayloadKeepsCachedConnectionWhenInitialStateFetchFails(t *testing.T) {
|
||||
restoreHeartbeatONVIFStubs(t)
|
||||
|
||||
device := newTestONVIFDevice()
|
||||
camera := models.IPCamera{
|
||||
ONVIFXAddr: "http://camera/onvif",
|
||||
ONVIFUsername: "operator",
|
||||
ONVIFPassword: "secret",
|
||||
}
|
||||
loopEvents := []agentonvif.ONVIFEvents{{Key: "input-1", Type: "input", Value: "true", Timestamp: 1}}
|
||||
|
||||
state := newHeartbeatONVIFState()
|
||||
state.cameraConfiguration = camera
|
||||
state.cameraKey = heartbeatONVIFCameraKey(camera)
|
||||
state.device = device
|
||||
state.loopPullPoint = "loop"
|
||||
state.staticLoaded = true
|
||||
state.staticPayload.enabled = "true"
|
||||
|
||||
heartbeatCreatePullPointSubscription = func(*goonvif.Device) (string, error) {
|
||||
return "", errors.New("temporary initial-state failure")
|
||||
}
|
||||
heartbeatGetEventMessages = func(_ *goonvif.Device, pullPointAddress string) ([]agentonvif.ONVIFEvents, error) {
|
||||
if pullPointAddress != "loop" {
|
||||
t.Fatalf("unexpected pull point address %q", pullPointAddress)
|
||||
}
|
||||
return loopEvents, nil
|
||||
}
|
||||
|
||||
payload := getHeartbeatONVIFPayload(camera, state)
|
||||
|
||||
wantEvents := mustJSONMarshal(t, loopEvents)
|
||||
if string(payload.eventsList) != string(wantEvents) {
|
||||
t.Fatalf("payload.eventsList = %s, want %s", payload.eventsList, wantEvents)
|
||||
}
|
||||
if state.device != device || state.loopPullPoint != "loop" || !state.staticLoaded {
|
||||
t.Fatalf("temporary failure invalidated healthy cached state: %+v", state)
|
||||
}
|
||||
}
|
||||
|
||||
func restoreHeartbeatONVIFStubs(t *testing.T) {
|
||||
t.Helper()
|
||||
|
||||
originalConnect := heartbeatConnectToONVIFDevice
|
||||
originalCreate := heartbeatCreatePullPointSubscription
|
||||
originalDigitalInputs := heartbeatGetDigitalInputs
|
||||
originalEvents := heartbeatGetEventMessages
|
||||
originalPresets := heartbeatGetPresetsFromDevice
|
||||
originalPTZConfigurations := heartbeatGetPTZConfigurationsFromDevice
|
||||
originalPTZFunctions := heartbeatGetPTZFunctionsFromDevice
|
||||
originalRelayOutputs := heartbeatGetRelayOutputs
|
||||
originalUnsubscribe := heartbeatUnsubscribePullPoint
|
||||
|
||||
t.Cleanup(func() {
|
||||
heartbeatConnectToONVIFDevice = originalConnect
|
||||
heartbeatCreatePullPointSubscription = originalCreate
|
||||
heartbeatGetDigitalInputs = originalDigitalInputs
|
||||
heartbeatGetEventMessages = originalEvents
|
||||
heartbeatGetPresetsFromDevice = originalPresets
|
||||
heartbeatGetPTZConfigurationsFromDevice = originalPTZConfigurations
|
||||
heartbeatGetPTZFunctionsFromDevice = originalPTZFunctions
|
||||
heartbeatGetRelayOutputs = originalRelayOutputs
|
||||
heartbeatUnsubscribePullPoint = originalUnsubscribe
|
||||
})
|
||||
}
|
||||
|
||||
func mustJSONMarshal(t *testing.T, v interface{}) []byte {
|
||||
t.Helper()
|
||||
|
||||
b, err := json.Marshal(v)
|
||||
if err != nil {
|
||||
t.Fatalf("json.Marshal() error = %v", err)
|
||||
}
|
||||
return b
|
||||
}
|
||||
|
||||
func assertDefaultHeartbeatONVIFPayload(t *testing.T, payload heartbeatONVIFPayload) {
|
||||
t.Helper()
|
||||
|
||||
defaultPayload := defaultHeartbeatONVIFPayload()
|
||||
if payload.enabled != defaultPayload.enabled ||
|
||||
payload.zoom != defaultPayload.zoom ||
|
||||
payload.panTilt != defaultPayload.panTilt ||
|
||||
payload.presets != defaultPayload.presets ||
|
||||
string(payload.presetsList) != string(defaultPayload.presetsList) ||
|
||||
string(payload.eventsList) != string(defaultPayload.eventsList) {
|
||||
t.Fatalf("payload = %+v, want default payload", payload)
|
||||
}
|
||||
}
|
||||
|
||||
func newTestONVIFDevice() *goonvif.Device {
|
||||
return &goonvif.Device{}
|
||||
}
|
||||
|
||||
func countString(values []string, want string) int {
|
||||
count := 0
|
||||
for _, value := range values {
|
||||
if value == want {
|
||||
count++
|
||||
}
|
||||
}
|
||||
return count
|
||||
}
|
||||
139
machinery/src/cloud/dropbox.go
Normal file
@@ -0,0 +1,139 @@
|
||||
// Package cloud contains the Dropbox implementation of the Cloud interface.
|
||||
// It uses the Dropbox SDK to upload files to Dropbox.
|
||||
package cloud
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"errors"
|
||||
"os"
|
||||
|
||||
"github.com/dropbox/dropbox-sdk-go-unofficial/v6/dropbox"
|
||||
"github.com/dropbox/dropbox-sdk-go-unofficial/v6/dropbox/files"
|
||||
"github.com/dropbox/dropbox-sdk-go-unofficial/v6/dropbox/users"
|
||||
"github.com/gin-gonic/gin"
|
||||
"github.com/kerberos-io/agent/machinery/src/models"
|
||||
log "github.com/sirupsen/logrus"
|
||||
)
|
||||
|
||||
// UploadDropbox uploads the file to your Dropbox account using the access token and directory.
|
||||
func UploadDropbox(configuration *models.Configuration, fileName string) (bool, bool, error) {
|
||||
|
||||
config := configuration.Config
|
||||
token := config.Dropbox.AccessToken
|
||||
directory := config.Dropbox.Directory
|
||||
if directory != "" {
|
||||
// Check if trailing slash if not we'll add one.
|
||||
if directory[len(directory)-1:] != "/" {
|
||||
directory = directory + "/"
|
||||
}
|
||||
}
|
||||
|
||||
if token == "" {
|
||||
err := "UploadDropbox: Dropbox not properly configured"
|
||||
log.Info(err)
|
||||
return false, true, errors.New(err)
|
||||
}
|
||||
|
||||
// Upload to Dropbox
|
||||
log.Info("UploadDropbox: Uploading to Dropbox")
|
||||
log.Info("UploadDropbox: Upload started for " + fileName)
|
||||
fullname := "data/recordings/" + fileName
|
||||
|
||||
dConfig := dropbox.Config{
|
||||
Token: token,
|
||||
LogLevel: dropbox.LogInfo, // if needed, set the desired logging level. Default is off
|
||||
}
|
||||
|
||||
file, err := os.OpenFile(fullname, os.O_RDWR, 0755)
|
||||
if file != nil {
|
||||
defer func() {
|
||||
if cerr := file.Close(); cerr != nil {
|
||||
log.Error("UploadDropbox: Error closing file: " + cerr.Error())
|
||||
}
|
||||
}()
|
||||
}
|
||||
|
||||
if err == nil {
|
||||
// Upload the file
|
||||
dbf := files.New(dConfig)
|
||||
res, err := dbf.Upload(&files.UploadArg{
|
||||
CommitInfo: files.CommitInfo{
|
||||
Path: "/" + directory + fileName,
|
||||
Mode: &files.WriteMode{
|
||||
Tagged: dropbox.Tagged{
|
||||
Tag: "overwrite",
|
||||
},
|
||||
},
|
||||
},
|
||||
}, file)
|
||||
|
||||
if err != nil {
|
||||
log.Error("UploadDropbox: Error uploading file: " + err.Error())
|
||||
return false, false, err
|
||||
}
|
||||
|
||||
log.Info("UploadDropbox: File uploaded successfully, " + res.Name)
|
||||
return true, true, nil
|
||||
}
|
||||
|
||||
log.Error("UploadDropbox: Error opening file: " + err.Error())
|
||||
return false, true, err
|
||||
}
|
||||
|
||||
// VerifyDropbox verifies if the Dropbox token is valid and it is able to upload a file.
|
||||
func VerifyDropbox(config models.Config, c *gin.Context) {
|
||||
|
||||
token := config.Dropbox.AccessToken
|
||||
directory := config.Dropbox.Directory
|
||||
if directory != "" {
|
||||
// Check if trailing slash if not we'll add one.
|
||||
if directory[len(directory)-1:] != "/" {
|
||||
directory = directory + "/"
|
||||
}
|
||||
}
|
||||
|
||||
if token != "" {
|
||||
dConfig := dropbox.Config{
|
||||
Token: token,
|
||||
LogLevel: dropbox.LogInfo, // if needed, set the desired logging level. Default is off
|
||||
}
|
||||
dbx := users.New(dConfig)
|
||||
_, err := dbx.GetCurrentAccount()
|
||||
if err != nil {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while reaching the Dropbox API: " + err.Error(),
|
||||
})
|
||||
} else {
|
||||
|
||||
// Upload the file
|
||||
content := TestFile
|
||||
file := bytes.NewReader(content)
|
||||
|
||||
dbf := files.New(dConfig)
|
||||
_, err := dbf.Upload(&files.UploadArg{
|
||||
CommitInfo: files.CommitInfo{
|
||||
Path: "/" + directory + "kerbers-agent-test.mp4",
|
||||
Mode: &files.WriteMode{
|
||||
Tagged: dropbox.Tagged{
|
||||
Tag: "overwrite",
|
||||
},
|
||||
},
|
||||
},
|
||||
}, file)
|
||||
|
||||
if err != nil {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Something went wrong while reaching the Dropbox API: " + err.Error(),
|
||||
})
|
||||
} else {
|
||||
c.JSON(200, models.APIResponse{
|
||||
Data: "Dropbox is working fine.",
|
||||
})
|
||||
}
|
||||
}
|
||||
} else {
|
||||
c.JSON(400, models.APIResponse{
|
||||
Data: "Dropbox token is not set.",
|
||||
})
|
||||
}
|
||||
}
|
||||