Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Show and modify routing rules from the UI #433

Open
wants to merge 15 commits into
base: main
Choose a base branch
from

Conversation

prakhar10
Copy link
Member

Description

  1. Adding a way to display routing rules and also modify them from the UI
  2. Minor change to show a user icon with a gear if user is ADMIN or a regular user icon if its a regular USER on the top right corner of the UI

Screenshot 2024-08-08 at 8 22 16 PM

Screenshot 2024-08-08 at 8 22 35 PM

Screenshot 2024-08-08 at 8 23 06 PM

Additional context and related issues

Release notes

( ) This is not user-visible or is docs only, and no release notes are required.
(X) Release notes are required. Please propose a release note for me.
( ) Release notes are required, with the following suggested text:

* 

@cla-bot cla-bot bot added the cla-signed label Aug 9, 2024
Copy link
Contributor

@willmostly willmostly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This looks like a nice improvement, thank you! I reviewed the Java half, and will try to find someone for the typescript.

My biggest concern here is not with the code, but with allowing users to supply input that will be written to disk on the server, then executed by the jeasy rules engine. We should take a close look at jeasy and mvel to understand what security vulnerabilities we might be introducing. At minimum we should log all of the updates so that they can be audited. @wendigo and @ebyhr wdyt?

Comment on lines 483 to 486
for (int i = 0; i < routingRulesList.size(); i++) {
if (routingRulesList.get(i).name().equals(routingRules.name())) {
routingRulesList.set(i, routingRules);
break;
}
}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

as the name of this method suggests, this updates an existing rule. It does not appear that this change adds support for deleting an existing rule or adding a new one. I guess this may be due to the UI changes required, but would it be difficult to add this functionality?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't think it would be difficult. I thought of initially going with only updates and in a separate PR i will put Add and Delete functionality. Will that be ok? Or should I add it in this PR itself?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

that plan sounds fine to me, thanks!

@prakhar10
Copy link
Member Author

prakhar10 commented Aug 16, 2024

This looks like a nice improvement, thank you! I reviewed the Java half, and will try to find someone for the typescript.

My biggest concern here is not with the code, but with allowing users to supply input that will be written to disk on the server, then executed by the jeasy rules engine. We should take a close look at jeasy and mvel to understand what security vulnerabilities we might be introducing. At minimum we should log all of the updates so that they can be audited. @wendigo and @ebyhr wdyt?

This functionality will be accessible only for users with ADMIN privileges. Regular users will have this as Read-Only. I also have a functionality implemented in our internal repo where we are auditing changes being made to the Clusters from the UI. I can raise a PR for that as well and will add functionality to audit routing rules as well. I was thinking of getting this reviewed first and then from comments and suggestions I will raise the Audit logs PR.

Copy link
Contributor

@willmostly willmostly left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

this is looking good, we're almost there. @mosabua and I discussed the need to support this for clustered deployments. We should also provide a way to disable this feature in case someone doesn't want to bother setting up a shared filesystem

docs/gateway-api.md Show resolved Hide resolved
@willmostly
Copy link
Contributor

@prakhar10 please squash these commits

@prakhar10
Copy link
Member Author

this is looking good, we're almost there. @mosabua and I discussed the need to support this for clustered deployments. We should also provide a way to disable this feature in case someone doesn't want to bother setting up a shared filesystem

So this means provide an option or a config to show/disable the Routing Rules option in the left panel of the UI right?

@mosabua
Copy link
Member

mosabua commented Sep 3, 2024

this is looking good, we're almost there. @mosabua and I discussed the need to support this for clustered deployments. We should also provide a way to disable this feature in case someone doesn't want to bother setting up a shared filesystem

So this means provide an option or a config to show/disable the Routing Rules option in the left panel of the UI right?

I think for now we can just say in the docs that you must provide shared storage for that feature to work and in terms of disabling it could be just a config option option .. I think over time we will need various config options for the UI anyway

Remove console logs and renamed api

Add api documentation and changes related to PR comments
@prakhar10
Copy link
Member Author

@mosabua @willmostly can you please review?

@mosabua
Copy link
Member

mosabua commented Oct 3, 2024

I assume that @prakhar10 and @willmostly are collaborating on this currently .. ping me if review or anything else is needed.

@prakhar10
Copy link
Member Author

I need to make changes according to @ebyhr 's comments. So i will get that done by this weekend.

@prakhar10
Copy link
Member Author

@ebyhr can you review now please?

@prakhar10
Copy link
Member Author

@mosabua can you please review?

@prakhar10
Copy link
Member Author

@ebyhr can you take a look now?

@prakhar10
Copy link
Member Author

@willmostly @ebyhr can you review now please?

For this feature to work with multiple replicas of the Trino Gateway, you will need to provide a shared storage for the routing rules file. If multiple replicas are used with local storage, then rules will get out of sync when updated.

```shell
curl -X POST http://localhost:8080/webapp/updateRoutingRules \
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The method definition includes

@Consumes(MediaType.APPLICATION_JSON)

Does this curl command work without

-H 'Content-Type: application/json'

?

@RolesAllowed("USER")
@Produces(MediaType.APPLICATION_JSON)
@Path("/getRoutingRules")
public Response getRoutingRules()
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Should these methods return the bare type instead of wrapping them in a Response, similar to the Trino UI? E.g. https://github.com/trinodb/trino/blob/bb80ff8be6073bc970501825e2e7f304b3b9d643/core/trino-main/src/main/java/io/trino/server/ui/ClusterResource.java#L51

This API can be used to programmatically update the Routing Rules.
Rule will be updated based on the rule name.

For this feature to work with multiple replicas of the Trino Gateway, you will need to provide a shared storage for the routing rules file. If multiple replicas are used with local storage, then rules will get out of sync when updated.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
For this feature to work with multiple replicas of the Trino Gateway, you will need to provide a shared storage for the routing rules file. If multiple replicas are used with local storage, then rules will get out of sync when updated.
For this feature to work with multiple replicas of the Trino Gateway, you will need to provide a shared storage that supports file locking for the routing rules file. If multiple replicas are used with local storage, then rules will get out of sync when updated.

throws IOException
{
ImmutableList.Builder<RoutingRule> updatedRoutingRulesBuilder = ImmutableList.builder();
List<RoutingRule> currentRoutingRulesList = new ArrayList<>();
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
List<RoutingRule> currentRoutingRulesList = new ArrayList<>();
List<RoutingRule> currentRoutingRulesList = getRoutingRules();

also remove the the logic below to read rules

yamlContent.append(yamlWriter.writeValueAsString(rule));
updatedRoutingRulesBuilder.add(rule);
}
try (FileChannel fileChannel = FileChannel.open(Paths.get(rulesConfigPath), StandardOpenOption.WRITE, StandardOpenOption.READ);
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Lock the file before it is read. Otherwise you allow a sequence like

  1. Gateway 1 reads rules
  2. Gateway 2 reads rules
  3. Gateway 1 locks rules, writes rules, releases lock.
  4. Gateway 2 locks rules, writes rules, releases lock.

Which results in the changes by Gateway 1 being lost.

import static org.assertj.core.api.Assertions.assertThat;
import static org.assertj.core.api.Assertions.assertThatThrownBy;

final class TestRoutingRulesManager
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please add tests that use the REST API

public record RoutingRule(
String name,
@Nullable String description,
@Nullable Integer priority,
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

priority should not be nullable. It may be defaulted to 0.

requireNonNull(name, "name is null");
actions = ImmutableList.copyOf(actions);
requireNonNull(condition, "condition is null");
}
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Set description to "" if it is null

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Development

Successfully merging this pull request may close these issues.

7 participants