|
| 1 | +import { Processor, Process, InjectQueue } from '@nestjs/bull' |
| 2 | +import { Logger } from '@nestjs/common' |
| 3 | +import { Job, Queue } from 'bull' |
| 4 | +import { ImageDescriptor } from '../kubernetes/k8s.service' |
| 5 | +import { getManifest, contentTypes } from '@snyk/docker-registry-v2-client' |
| 6 | +@Processor('analyzer.check.updates') |
| 7 | +export class ImageDescriptorWorker { |
| 8 | + private readonly logger = new Logger(ImageDescriptorWorker.name) |
| 9 | + private readonly patchQueue: Queue |
| 10 | + |
| 11 | + constructor(@InjectQueue('patcher.update') queue: Queue) { |
| 12 | + this.patchQueue = queue |
| 13 | + } |
| 14 | + |
| 15 | + @Process() |
| 16 | + async fetchImageList(job: Job<ImageDescriptor>) { |
| 17 | + try { |
| 18 | + this.logger.debug( |
| 19 | + `Checking for updates of ${job.data.repository}:${ |
| 20 | + job.data.tag |
| 21 | + } used by ${ |
| 22 | + job.data.owner.namespace |
| 23 | + }/${job.data.owner.type.toString()}/${job.data.owner.name}` |
| 24 | + ) |
| 25 | + // split on / check for a . in the first snippet |
| 26 | + const parts = job.data.repository.split('/') |
| 27 | + // this may not be universarlly true |
| 28 | + const isDockerIo = parts[0].indexOf('.') === -1 |
| 29 | + const dockerIoRegistryDomain = 'registry-1.docker.io' |
| 30 | + const dockerIo = 'docker.io' |
| 31 | + const registry = isDockerIo |
| 32 | + ? 'registry-1.docker.io' |
| 33 | + : parts[0] === dockerIo |
| 34 | + ? dockerIoRegistryDomain |
| 35 | + : parts[0] |
| 36 | + const repo = isDockerIo |
| 37 | + ? parts.length === 1 |
| 38 | + ? `library/${job.data.repository}` |
| 39 | + : job.data.repository |
| 40 | + : parts[0] === dockerIo |
| 41 | + ? job.data.repository.substring(dockerIo.length + 1) |
| 42 | + : job.data.repository.substring(registry.length + 1) |
| 43 | + this.logger.debug( |
| 44 | + `Fetching manifest for registry = ${registry}, repo = ${repo}, tag = ${job.data.tag}` |
| 45 | + ) |
| 46 | + const reqOptions = |
| 47 | + registry === 'ghcr.io' |
| 48 | + ? { |
| 49 | + acceptManifest: `${contentTypes.MANIFEST_V2}, ${contentTypes.MANIFEST_LIST_V2}, ${contentTypes.OCI_INDEX_V1}, ${contentTypes.OCI_MANIFEST_V1}`, |
| 50 | + } |
| 51 | + : undefined |
| 52 | + const manifest = await getManifest( |
| 53 | + registry, |
| 54 | + repo, |
| 55 | + job.data.tag, |
| 56 | + undefined, |
| 57 | + undefined, |
| 58 | + reqOptions, |
| 59 | + { |
| 60 | + os: 'linux', |
| 61 | + architecture: job.data.arch, |
| 62 | + } |
| 63 | + ) |
| 64 | + if (manifest == null || manifest?.indexDigest == null) { |
| 65 | + this.logger.warn( |
| 66 | + 'Failed to get a workable manifest for %s with tag %s from registry %s', |
| 67 | + repo, |
| 68 | + job.data.tag, |
| 69 | + registry |
| 70 | + ) |
| 71 | + } |
| 72 | + this.logger.debug( |
| 73 | + `Fetched manifest digest = ${manifest?.indexDigest}, running hash = ${job.data.hash}, repo = ${job.data.repository}`, |
| 74 | + manifest |
| 75 | + ) |
| 76 | + if ( |
| 77 | + manifest.indexDigest !== job.data.hash && |
| 78 | + manifest.indexDigest != null |
| 79 | + ) { |
| 80 | + this.logger.warn( |
| 81 | + `Found an update for ${registry}/${repo}:${job.data.tag}` |
| 82 | + ) |
| 83 | + // queueu work for the patcher |
| 84 | + await this.patchQueue.add({ |
| 85 | + ...job.data, |
| 86 | + ...{ |
| 87 | + currentSha: job.data.hash, |
| 88 | + targetSha: manifest.indexDigest, |
| 89 | + }, |
| 90 | + }) |
| 91 | + return { |
| 92 | + detectedUpdate: true, |
| 93 | + current: job.data.hash, |
| 94 | + detectedLatest: manifest.indexDigest, |
| 95 | + } |
| 96 | + } else { |
| 97 | + return { |
| 98 | + detectedUpdate: false, |
| 99 | + current: job.data.hash, |
| 100 | + detectedLatest: manifest.indexDigest, |
| 101 | + } |
| 102 | + } |
| 103 | + } catch (err) { |
| 104 | + this.logger.error( |
| 105 | + `Error while checking for updates for ${job.data.repository}:${job.data.tag}: ${err.message}`, |
| 106 | + null, |
| 107 | + err |
| 108 | + ) |
| 109 | + throw err |
| 110 | + } |
| 111 | + } |
| 112 | +} |
0 commit comments