go.temporal.io/server/common/config/config.go

879 LOC · 27 covered · 852 uncovered · 9 ranges · 65 concepts · 4 introducers · 22 tests

File neighbourhood

The centred file is linked to every concept that introduces one of its ranges, every test that runs code from the file, and the gray connector concepts standing between those tests and the file's own introducer concepts. Undirected links join concepts to every file where they introduce source and concepts to the tests they introduce; arrows show specialization between the displayed concepts and bridge only concepts omitted from this view. Concept colors match the source ranges below; connector concepts have no source color and are shown in gray.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the file

In the embedded map, ordinary wheel input scrolls the page; use the visible controls to zoom and drag to pan. Open the full-screen map for canvas navigation: wheel pans, Ctrl/Command plus wheel zooms, and arrow keys pan when this region is focused. On touch screens, open the full-screen map to pan or pinch. If JavaScript or WebGL is unavailable, use the related-file, concept, and source links on this page.

Focused file, its introducer and connector concepts, their introduced files, and tests that run code from the filego.temporal.io/server/client/clientfactory.go · 245 LOCclient/clientfactory.gogo.temporal.io/server/client/matching/client.go · 535 LOCmatching/client.gogo.temporal.io/server/client/matching/client_gen.go · 702 LOCmatching/client_gen.gogo.temporal.io/server/client/matching/metric_client.go · 263 LOCmatching/metric_client.g…go.temporal.io/server/common/authorization/claim_mapper.go · 89 LOCauthorization/claim_mapp…go.temporal.io/server/common/authorization/default_token_key_provider.go · 191 LOCauthorization/default_to…go.temporal.io/server/common/config/archival.go · 42 LOCconfig/archival.gogo.temporal.io/server/common/config/fx.go · 34 LOCconfig/fx.gogo.temporal.io/server/common/config/persistence.go · 323 LOCconfig/persistence.gogo.temporal.io/server/common/dynamicconfig/collection.go · 779 LOCdynamicconfig/collection…go.temporal.io/server/common/membership/ringpop/factory.go · 270 LOCringpop/factory.gogo.temporal.io/server/common/membership/ringpop/fx.go · 32 LOCringpop/fx.gogo.temporal.io/server/common/membership/ringpop/monitor.go · 484 LOCringpop/monitor.gogo.temporal.io/server/common/membership/ringpop/service_resolver.go · 533 LOCringpop/service_resolver…go.temporal.io/server/common/persistence/cassandra/version_checker.go · 62 LOCcassandra/version_checke…go.temporal.io/server/common/persistence/persistence_rate_limited_clients.go · 1186 LOCpersistence/persistence_…go.temporal.io/server/common/persistence/sql/sqlplugin/sqlite/db.go · 125 LOCsqlite/db.gogo.temporal.io/server/common/pprof/fx.go · 31 LOCpprof/fx.gogo.temporal.io/server/common/pprof/pprof.go · 66 LOCpprof/pprof.gogo.temporal.io/server/common/resource/fx.go · 533 LOCresource/fx.gogo.temporal.io/server/common/rpc/encryption/local_store_tls_provider.go · 506 LOCencryption/local_store_t…go.temporal.io/server/common/rpc/interceptor/dc_redirection_policy.go · 221 LOCinterceptor/dc_redirecti…go.temporal.io/server/common/rpc/rpc.go · 413 LOCrpc/rpc.gogo.temporal.io/server/service/frontend/fx.go · 1057 LOCfrontend/fx.gogo.temporal.io/server/service/history/fx.go · 529 LOChistory/fx.gogo.temporal.io/server/service/matching/fx.go · 268 LOCmatching/fx.gogo.temporal.io/server/service/worker/fx.go · 231 LOCworker/fx.gogo.temporal.io/server/temporal/fx.go · 1273 LOCtemporal/fx.gogo.temporal.io/server/temporal/server.go · 46 LOCtemporal/server.gogo.temporal.io/server/temporal/server_impl.go · 198 LOCtemporal/server_impl.gogo.temporal.io/server/temporal/server_option.go · 227 LOCtemporal/server_option.g…go.temporal.io/server/temporal/server_options.go · 139 LOCtemporal/server_options.…workflow_handler.go ×11 · 117 introduced LOCworkflow_handler.go ×11common.go ×1 · 11 introduced LOCcommon.go ×1request_response.pb.go ×6 · 246 introduced LOCrequest_response.pb.go ×…visibility_store.go ×17 · 171 introduced LOCvisibility_store.go ×17telemetry.go ×2 · 15 introduced LOCtelemetry.go ×2fx.go ×1 · 4 introduced LOCfx.go ×1collector.go ×7 · 33 introduced LOCcollector.go ×7data_store_factory.go ×29 · 703 introduced LOCdata_store_factory.go ×2…TestNewServer · 0 introduced LOCTestNewServerpri_matcher.go ×1 · 2 introduced LOCpri_matcher.go ×1timer_queue_active_task_executor.go ×1 · 3 introduced LOCtimer_queue_active_task_…TestNewServer · 0 introduced LOCTestNewServermetric_client.go ×3 · 18 introduced LOCmetric_client.go ×3request_response.pb.go ×12 · 137 introduced LOCrequest_response.pb.go ×…workflow_task_completed_handler.go ×9 · 75 introduced LOCworkflow_task_completed_…pri_forwarder.go ×2 · 4 introduced LOCpri_forwarder.go ×2request_response.pb.go ×1 · 7 introduced LOCrequest_response.pb.go ×…logger.go ×1 · 5 introduced LOClogger.go ×1connections.go ×1 · 9 introduced LOCconnections.go ×1persistence_rate_limited_clients.go ×2 · 17 introduced LOCpersistence_rate_limited…logger.go ×1 · 2 introduced LOClogger.go ×1metric_client.go ×2 · 7 introduced LOCmetric_client.go ×2pri_matcher.go ×1 · 4 introduced LOCpri_matcher.go ×1task_queue_partition_manager.go ×2 · 10 introduced LOCtask_queue_partition_man…connections.go ×2 · 12 introduced LOCconnections.go ×2workflow_handler.go ×8 · 144 introduced LOCworkflow_handler.go ×8pri_matcher.go ×1 · 2 introduced LOCpri_matcher.go ×1handler.go ×1 · 20 introduced LOChandler.go ×1pri_matcher.go ×8 · 55 introduced LOCpri_matcher.go ×8matching_engine.go ×1 · 8 introduced LOCmatching_engine.go ×1server.go ×1 · 3 introduced LOCserver.go ×1logger.go ×2 · 21 introduced LOClogger.go ×2queue_scheduled.go ×1 · 2 introduced LOCqueue_scheduled.go ×1handler.go ×25 · 728 introduced LOChandler.go ×25endpoint_registry.go ×2 · 26 introduced LOCendpoint_registry.go ×2server.go ×3 · 13 introduced LOCserver.go ×3scanner.go ×1 · 2 introduced LOCscanner.go ×1mask_internal_error.go ×1 · 2 introduced LOCmask_internal_error.go ×…matching_engine.go ×2 · 5 introduced LOCmatching_engine.go ×2service_resolver.go ×4 · 49 introduced LOCservice_resolver.go ×4lite_server.go ×25 · 303 introduced LOClite_server.go ×25fx.go ×44 · 705 introduced LOCfx.go ×44local_store_cert_provider.go ×11 · 47 introduced LOClocal_store_cert_provide…tls_config_helper.go ×1 · 2 introduced LOCtls_config_helper.go ×1TestRingpopInvalidTLS · 0 introduced LOCTestRingpopInvalidTLSlocal_store_tls_provider.go ×4 · 17 introduced LOClocal_store_tls_provider…local_store_cert_provider.go ×5 · 12 introduced LOClocal_store_cert_provide…local_store_cert_provider.go ×51 · 202 introduced LOClocal_store_cert_provide…factory.go ×5 · 9 introduced LOCfactory.go ×5local_store_tls_provider.go ×1 · 6 introduced LOClocal_store_tls_provider…factory.go ×1 · 5 introduced LOCfactory.go ×1factory.go ×6 · 20 introduced LOCfactory.go ×6TestGetRemoteClusterClientConfig_ExactOverStar · 0 introduced LOCTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_MoreSpecificWildcardWins · 0 introduced LOCTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_ThreeTierPriority · 0 introduced LOCTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_WildcardSubdomainMatch · 0 introduced LOCTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_ExactMatch · 0 introduced LOCTestGetRemoteClusterClie…local_store_tls_provider.go ×1 · 2 introduced LOClocal_store_tls_provider…local_store_tls_provider.go ×1 · 5 introduced LOClocal_store_tls_provider…local_store_tls_provider.go ×2 · 5 introduced LOClocal_store_tls_provider…local_store_tls_provider.go ×6 · 25 introduced LOClocal_store_tls_provider…local_store_tls_provider.go ×3 · 21 introduced LOClocal_store_tls_provider…default_token_key_provider.go ×3 · 16 introduced LOCdefault_token_key_provid…config.go ×1 · 3 introduced LOCconfig.go ×1config.go ×1 · 4 introduced LOCconfig.go ×1TestGetClaimMapperFromConfigDefault · introduced test · go.temporal.io/server/common/authorization/TestDefaultClaimMapperSuite/TestGetClaimMapperFromConfigDefaultTestGetClaimMapperFromCo…TestRingpopInvalidTLS · introduced test · go.temporal.io/server/common/membership/ringpop/TestRingpopSuite/TestRingpopInvalidTLSTestRingpopInvalidTLSTestRingpopMutualTLS · introduced test · go.temporal.io/server/common/membership/ringpop/TestRingpopSuite/TestRingpopMutualTLSTestRingpopMutualTLSTestRingpopServerTLS · introduced test · go.temporal.io/server/common/membership/ringpop/TestRingpopSuite/TestRingpopServerTLSTestRingpopServerTLSTestGetRemoteClusterClientConfig_ExactMatch · introduced test · go.temporal.io/server/common/rpc/encryption/TestGetRemoteClusterClientConfig_ExactMatchTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_ExactOverStar · introduced test · go.temporal.io/server/common/rpc/encryption/TestGetRemoteClusterClientConfig_ExactOverStarTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_MoreSpecificWildcardWins · introduced test · go.temporal.io/server/common/rpc/encryption/TestGetRemoteClusterClientConfig_MoreSpecificWildcardWinsTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_StarFallback · introduced test · go.temporal.io/server/common/rpc/encryption/TestGetRemoteClusterClientConfig_StarFallbackTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_ThreeTierPriority · introduced test · go.temporal.io/server/common/rpc/encryption/TestGetRemoteClusterClientConfig_ThreeTierPriorityTestGetRemoteClusterClie…TestGetRemoteClusterClientConfig_WildcardSubdomainMatch · introduced test · go.temporal.io/server/common/rpc/encryption/TestGetRemoteClusterClientConfig_WildcardSubdomainMatchTestGetRemoteClusterClie…TestIsEnabled · introduced test · go.temporal.io/server/common/rpc/encryption/TestTLSConfigSuite/TestIsEnabledTestIsEnabledTestNewServer · introduced test · go.temporal.io/server/temporal/TestNewServerTestNewServerTestNewServerWithJSONEncoding · introduced test · go.temporal.io/server/temporal/TestNewServerWithJSONEncodingTestNewServerWithJSONEnc…with_OTEL_Collector_running · introduced test · go.temporal.io/server/temporal/TestNewServerWithOTEL/with_OTEL_Collector_runningwith_OTEL_Collector_runn…without_OTEL_Collector_running · introduced test · go.temporal.io/server/temporal/TestNewServerWithOTEL/without_OTEL_Collector_runningwithout_OTEL_Collector_r…ExampleNewServer · introduced test · go.temporal.io/server/temporaltest/ExampleNewServerExampleNewServerTestBaseServerOptions · introduced test · go.temporal.io/server/temporaltest/TestBaseServerOptionsTestBaseServerOptionsTestClientWithCustomInterceptor · introduced test · go.temporal.io/server/temporaltest/TestClientWithCustomInterceptorTestClientWithCustomInte…TestDefaultWorkerOptions · introduced test · go.temporal.io/server/temporaltest/TestDefaultWorkerOptionsTestDefaultWorkerOptionsTestNewServer · introduced test · go.temporal.io/server/temporaltest/TestNewServerTestNewServerTestNewWorkerWithOptions · introduced test · go.temporal.io/server/temporaltest/TestNewWorkerWithOptionsTestNewWorkerWithOptionsTestSearchAttributeRegistration · introduced test · go.temporal.io/server/temporaltest/TestSearchAttributeRegistrationTestSearchAttributeRegis…Focused file · go.temporal.io/server/common/config/config.go · 879 LOCconfig/config.go

Graph controls are ready.

Interactive rendering requires JavaScript and WebGL. Use the related-file, concept, and source links on this page while the interactive map is unavailable.

1 package config
2
3 import (
4 "bytes"
5 "fmt"
6 "math"
7 "strings"
8 "time"
9
10 "github.com/jmoiron/sqlx"
11 "go.temporal.io/server/common/auth"
12 "go.temporal.io/server/common/cluster"
13 "go.temporal.io/server/common/dynamicconfig"
14 "go.temporal.io/server/common/log"
15 "go.temporal.io/server/common/masker"
16 "go.temporal.io/server/common/metrics"
17 "go.temporal.io/server/common/persistence/visibility/store/elasticsearch/client"
18 "go.temporal.io/server/common/primitives"
19 "go.temporal.io/server/common/telemetry"
20 "google.golang.org/grpc/keepalive"
21 "gopkg.in/yaml.v3"
22 )
23
24 const (
25 infinity = time.Duration(math.MaxInt64)
26 )
27
28 type (
29 // Config contains the configuration for a set of temporal services
30 Config struct {
31 // Global is process-wide service-related configuration
32 Global Global `yaml:"global"`
33 // Persistence contains the configuration for temporal datastores
34 Persistence Persistence `yaml:"persistence"`
35 // Log is the logging config
36 Log log.Config `yaml:"log"`
37 // ClusterMetadata is the config containing all valid clusters and active cluster
38 ClusterMetadata *cluster.Config `yaml:"clusterMetadata"`
39 // DCRedirectionPolicy contains the frontend datacenter redirection policy
40 DCRedirectionPolicy DCRedirectionPolicy `yaml:"dcRedirectionPolicy"`
41 // Services is a map of service name to service config items
42 Services map[string]Service `yaml:"services"`
43 // Archival is the config for archival
44 Archival Archival `yaml:"archival"`
45 // PublicClient is config for connecting to temporal frontend
46 PublicClient PublicClient `yaml:"publicClient"`
47 // DynamicConfigClient is the config for setting up the file based dynamic config client
48 // Filepath should be relative to the root directory
49 DynamicConfigClient *dynamicconfig.FileBasedClientConfig `yaml:"dynamicConfigClient"`
50 // NamespaceDefaults is the default config for every namespace
51 NamespaceDefaults NamespaceDefaults `yaml:"namespaceDefaults"`
52 // ExporterConfig allows the specification of process-wide OTEL exporters
53 ExporterConfig telemetry.ExportConfig `yaml:"otel"`
54 // Visibility related config
55 Visibility Visibility `yaml:"visibility"`
56 }
57
58 // Service contains the service specific config items
59 Service struct {
60 // RPC is the rpc configuration
61 RPC RPC `yaml:"rpc"`
62 }
63
64 // PProf contains the config items for the pprof utility
65 PProf struct {
66 // Port is the port on which the PProf will bind to
67 Port int `yaml:"port"`
68 // Host defaults to `localhost` but can be overriden
69 // for instance in the case of dual stack IPv4/IPv6
70 Host string `yaml:"host"`
71 }
72
73 // RPC contains the rpc config items
74 RPC struct {
75 // GRPCPort is the port on which gRPC will listen
76 GRPCPort int `yaml:"grpcPort"`
77 // Port used for membership listener
78 MembershipPort int `yaml:"membershipPort"`
79 // BindOnLocalHost is true if localhost is the bind address
80 // if neither BindOnLocalHost nor BindOnIP are set then an
81 // an attempt to discover an address is made
82 BindOnLocalHost bool `yaml:"bindOnLocalHost"`
83 // BindOnIP can be used to bind service on specific ip (eg. `0.0.0.0` or `::`)
84 // check net.ParseIP for supported syntax
85 // mutually exclusive with `BindOnLocalHost` option
86 BindOnIP string `yaml:"bindOnIP"`
87 // HTTPPort is the port on which HTTP will listen. If unset/0, HTTP will be
88 // disabled. This setting only applies to the frontend service.
89 HTTPPort int `yaml:"httpPort"`
90 // HTTPAdditionalForwardedHeaders adds additional headers to the default set
91 // forwarded from HTTP to gRPC. Any value with a trailing * will match the prefix before
92 // the asterisk (eg. `x-internal-*`)
93 HTTPAdditionalForwardedHeaders []string `yaml:"httpAdditionalForwardedHeaders"`
94 // KeepAliveServerConfig keep alive configuration for the server
95 KeepAliveServerConfig KeepAliveServerConfig `yaml:"keepAliveServerConfig"`
96 // ClientConnectionConfig defines the connection config used by other services
97 // when they create a gRPC client connection to this service.
98 ClientConnectionConfig ClientConnectionConfig `yaml:"clientConnectionConfig"`
99 }
100
101 KeepAliveServerParameters struct {
102 MaxConnectionIdle *time.Duration `yaml:"maxConnectionIdle"`
103 MaxConnectionAge *time.Duration `yaml:"maxConnectionAge"`
104 MaxConnectionAgeGrace *time.Duration `yaml:"maxConnectionAgeGrace"`
105 Time *time.Duration `yaml:"keepAliveTime"`
106 Timeout *time.Duration `yaml:"keepAliveTimeout"`
107 }
108
109 KeepAliveClientParameters struct {
110 Time *time.Duration `yaml:"keepAliveTime"`
111 Timeout *time.Duration `yaml:"keepAliveTimeout"`
112 PermitWithoutStream *bool `yaml:"keepAlivePermitWithoutStream"`
113 }
114
115 ClientConnectionConfig struct {
116 KeepAliveClientConfig *KeepAliveClientParameters `yaml:"keepAliveClientParameters"`
117 }
118
119 KeepAliveServerEnforcementPolicy struct {
120 MinTime *time.Duration `yaml:"minTime"`
121 PermitWithoutStream *bool `yaml:"permitWithoutStream"`
122 }
123
124 KeepAliveServerConfig struct {
125 KeepAliveServerParameters *KeepAliveServerParameters `yaml:"keepAliveServerParameters"`
126 KeepAliveEnforcementPolicy *KeepAliveServerEnforcementPolicy `yaml:"keepAliveEnforcementPolicy"`
127 }
128
129 // Global contains config items that apply process-wide to all services
130 Global struct {
131 // Membership is the ringpop related configuration
132 Membership Membership `yaml:"membership"`
133 // PProf is the PProf configuration
134 PProf PProf `yaml:"pprof"`
135 // TLS controls the communication encryption configuration
136 TLS RootTLS `yaml:"tls"`
137 // Metrics is the metrics subsystem configuration
138 Metrics *metrics.Config `yaml:"metrics"`
139 // Settings for authentication and authorization
140 Authorization Authorization `yaml:"authorization"`
141 }
142
143 // RootTLS contains all TLS settings for the Temporal server
144 RootTLS struct {
145 // Internode controls backend service (history, matching, internal-frontend)
146 // communication TLS settings.
147 Internode GroupTLS `yaml:"internode"`
148 // Frontend controls frontend server TLS settings. To control system worker -> frontend
149 // TLS, use the SystemWorker field. (Frontend.Client is accepted for backwards
150 // compatibility.)
151 Frontend GroupTLS `yaml:"frontend"`
152 // SystemWorker controls TLS setting for System Workers connecting to Frontend.
153 SystemWorker WorkerTLS `yaml:"systemWorker"`
154 // RemoteFrontendClients controls TLS setting for talking to remote cluster.
155 RemoteClusters map[string]GroupTLS `yaml:"remoteClusters"`
156 // ExpirationChecks defines settings for periodic checks for expiration of certificates
157 ExpirationChecks CertExpirationValidation `yaml:"expirationChecks"`
158 // Interval between refreshes of certificates loaded from files
159 RefreshInterval time.Duration `yaml:"refreshInterval"`
160 }
161
162 // GroupTLS contains an instance client and server TLS settings
163 GroupTLS struct {
164 // Client handles client TLS settings
165 Client ClientTLS `yaml:"client"`
166 // Server handles the server (listener) TLS settings
167 Server ServerTLS `yaml:"server"`
168
169 // PerHostOverrides contains per-hostname TLS settings that
170 // are used for external clients connecting to the Temporal Cluster on that
171 // specific hostname. Host names are case insensitive. Optional. If not present,
172 // uses configuration supplied by Server field.
173 PerHostOverrides map[string]ServerTLS `yaml:"hostOverrides"`
174 }
175
176 // ServerTLS contains items to load server TLS configuration
177 ServerTLS struct {
178 // The path to the file containing the PEM-encoded public key of the certificate to use.
179 CertFile string `yaml:"certFile"`
180 // The path to the file containing the PEM-encoded private key of the certificate to use.
181 KeyFile string `yaml:"keyFile"`
182 // A list of paths to files containing the PEM-encoded public key of the Certificate Authorities you wish to trust for client authentication.
183 // This value is ignored if `requireClientAuth` is not enabled. Cannot specify both ClientCAFiles and ClientCAData
184 ClientCAFiles []string `yaml:"clientCaFiles"`
185
186 // Base64 equivalents of the above artifacts.
187 // You cannot specify both a Data and a File for the same artifact (e.g. setting CertFile and CertData)
188 CertData string `yaml:"certData"`
189 KeyData string `yaml:"keyData"`
190 ClientCAData []string `yaml:"clientCaData"`
191
192 // Requires clients to authenticate with a certificate when connecting, otherwise known as mutual TLS.
193 RequireClientAuth bool `yaml:"requireClientAuth"`
194 }
195
196 // ClientTLS contains TLS configuration for clients within the Temporal Cluster to connect to Temporal nodes.
197 ClientTLS struct {
198 // DNS name to validate against for server to server connections.
199 // Required when TLS is enabled in a multi-host cluster.
200 // This name should be referenced by the certificate specified in the ServerTLS section.
201 ServerName string `yaml:"serverName"`
202
203 // If you want to verify the temporal server hostname and server cert, then you should turn this on
204 // This option is basically equivalent to InSecureSkipVerify
205 // See InSecureSkipVerify in http://golang.org/pkg/crypto/tls/ for more info
206 DisableHostVerification bool `yaml:"disableHostVerification"`
207
208 // Optional - A list of paths to files containing the PEM-encoded public key of the Certificate Authorities that are used to validate the server's TLS certificate
209 // You cannot specify both RootCAFiles and RootCAData
210 RootCAFiles []string `yaml:"rootCaFiles"`
211
212 // Optional - A list of base64 PEM-encoded public keys of the Certificate Authorities that are used to validate the server's TLS certificate.
213 // You cannot specify both RootCAFiles and RootCAData
214 RootCAData []string `yaml:"rootCaData"`
215
216 // Optional - Use TLS even is neither client certificate nor root CAs are configured
217 // This is for non-mTLS cases when client validates serve against a set of trusted CA certificates configured in the environment
218 ForceTLS bool `yaml:"forceTLS"`
219 }
220
221 // WorkerTLS contains TLS configuration for system workers within the Temporal Cluster to connect to Temporal frontend.
222 WorkerTLS struct {
223 // The path to the file containing the PEM-encoded public key of the client certificate to use by system workers.
224 CertFile string `yaml:"certFile"`
225 // The path to the file containing the PEM-encoded private key of the client certificate to use by system workers.
226 KeyFile string `yaml:"keyFile"`
227 // Base64 equivalents of the above artifacts.
228 // You cannot specify both a Data and a File for the same artifact (e.g. setting CertFile and CertData)
229 CertData string `yaml:"certData"`
230 KeyData string `yaml:"keyData"`
231
232 // Client TLS settings for system workers
233 Client ClientTLS `yaml:"client"`
234 }
235
236 // CertExpirationValidation contains settings for periodic checks of TLS certificate expiration
237 CertExpirationValidation struct {
238 // Log warnings for certificates expiring during this time window from now
239 WarningWindow time.Duration `yaml:"warningWindow"`
240 // Log error for certificates expiring during this time window from now
241 ErrorWindow time.Duration `yaml:"errorWindow"`
242 // Interval between checks for certificate expiration
243 CheckInterval time.Duration `yaml:"checkInterval"`
244 }
245
246 // Membership contains config items related to the membership layer of temporal
247 Membership struct {
248 // MaxJoinDuration is the max wait time to join the gossip ring
249 MaxJoinDuration time.Duration `yaml:"maxJoinDuration"`
250 // BroadcastAddress is used as the address that is communicated to remote nodes to connect on.
251 // This is generally used when BindOnIP would be the same across several nodes (ie: `0.0.0.0` or `::`)
252 // and for nat traversal scenarios. Check net.ParseIP for supported syntax
253 BroadcastAddress string `yaml:"broadcastAddress"`
254 }
255
256 // Persistence contains the configuration for data store / persistence layer
257 Persistence struct {
258 // DefaultStore is the name of the default data store to use
259 DefaultStore string `yaml:"defaultStore" validate:"nonzero"`
260 // VisibilityStore is the name of the datastore to be used for visibility records
261 VisibilityStore string `yaml:"visibilityStore"`
262 // SecondaryVisibilityStore is the name of the secondary datastore to be used for visibility records
263 SecondaryVisibilityStore string `yaml:"secondaryVisibilityStore"`
264 // NumHistoryShards is the desired number of history shards. This config doesn't
265 // belong here, needs refactoring
266 NumHistoryShards int32 `yaml:"numHistoryShards" validate:"nonzero"`
267 // DataStores contains the configuration for all datastores
268 DataStores map[string]DataStore `yaml:"datastores"`
269 // TransactionSizeLimit is the largest allowed transaction size
270 TransactionSizeLimit dynamicconfig.IntPropertyFn `yaml:"-" json:"-"`
271 }
272
273 // DataStore is the configuration for a single datastore
274 DataStore struct {
275 // FaultInjection contains the config for fault injector wrapper.
276 FaultInjection *FaultInjection `yaml:"faultInjection"`
277 // Cassandra contains the config for a cassandra datastore
278 Cassandra *Cassandra `yaml:"cassandra"`
279 // SQL contains the config for a SQL based datastore
280 SQL *SQL `yaml:"sql"`
281 // Custom contains the config for custom datastore implementation
282 CustomDataStoreConfig *CustomDatastoreConfig `yaml:"customDatastore"`
283 // ElasticSearch contains the config for a ElasticSearch datastore
284 Elasticsearch *client.Config `yaml:"elasticsearch"`
285 }
286
287 FaultInjection struct {
288 // Targets is a mapping of data store name to a targeted fault injection config for that data store.
289 // Here is an example config for targeted fault injection. This config will inject errors into the
290 // UpdateShard method of the ShardStore at a rate of 100%. No other methods will be affected.
291 /*
292 targets:
293 dataStores:
294 ShardStore:
295 methods:
296 UpdateShard:
297 seed: 42
298 errors:
299 ShardOwnershipLostError: 1.0 # all UpdateShard calls will fail with ShardOwnershipLostError
300 */
301 // This will cause the UpdateShard method of the ShardStore to always return ShardOwnershipLostError.
302 // See config/development-cass-es-fi.yaml for a more detailed example.
303 Targets FaultInjectionTargets `yaml:"targets"`
304
305 // Injector optionally injects faults using runtime code instead of static YAML config.
306 Injector FaultInjector `yaml:"-" json:"-"`
307 }
308
309 FaultInjector func(FaultInjectionTarget) error
310
311 FaultInjectionTarget struct {
312 Store DataStoreName
313 Method string
314 // Request is optionally populated by fault injection wrappers for request-aware faults.
315 Request any
316 }
317
318 // FaultInjectionTargets is the set of targets for fault injection. A target is a method of a data store.
319 FaultInjectionTargets struct {
320 // DataStores is a map of datastore name to fault injection config.
321 // Use this to configure fault injection for specific datastores. The key is the name of the datastore,
322 // e.g. "ShardStore". See DataStoreName for the list of valid datastore names.
323 DataStores map[DataStoreName]FaultInjectionDataStoreConfig `yaml:"dataStores"`
324 }
325
326 // DataStoreName is the name of a datastore, e.g. "ShardStore". The full list is defined later in this file.
327 DataStoreName string
328
329 // FaultInjectionDataStoreConfig is the fault injection config for a single datastore, e.g., the ShardStore.
330 FaultInjectionDataStoreConfig struct {
331 // Methods is a map of data store method name to a fault injection config for that method.
332 // We create an error generator that infers the method name from the call stack using reflection.
333 // For example, if a test with targeted fault injection enabled calls ShardStore.UpdateShard, then
334 // we fetch the error generator from this map using the key "UpdateShard".
335 // The key is the name of the method to inject faults for.
336 // The value is the config for that method.
337 Methods map[string]FaultInjectionMethodConfig `yaml:"methods"`
338 }
339
340 // FaultInjectionMethodConfig is the fault injection config for a single method of a data store.
341 FaultInjectionMethodConfig struct {
342 // Errors is a map of error type to probability of returning that error.
343 // For example: `ShardOwnershipLostError: 0.1` will cause the method to return a ShardOwnershipLostError 10% of
344 // the time.
345 // The other 90% of the time, the method will call the underlying datastore.
346 // If there are multiple errors for a method, the probability of each error is independent of the others.
347 // For example, if there are two errors with probabilities 0.1 and 0.2, then the first error will be returned
348 // 10% of the time, the second error will be returned 20% of the time,
349 // and the underlying method will be called 70% of the time.
350 Errors map[string]float64 `yaml:"errors"`
351
352 // Seed is the seed for the random number generator used to sample faults from the Errors map. You can use this
353 // to make the fault injection deterministic.
354 // If the test config does not set this to a non-zero number, the fault injector will set it to the current time
355 // in nanoseconds.
356 Seed int64 `yaml:"seed"`
357 }
358
359 // Cassandra contains configuration to connect to Cassandra cluster
360 Cassandra struct {
361 // Hosts is a csv of cassandra endpoints
362 Hosts string `yaml:"hosts" validate:"nonzero"`
363 // Port is the cassandra port used for connection by gocql client
364 Port int `yaml:"port"`
365 // User is the cassandra user used for authentication by gocql client
366 User string `yaml:"user"`
367 // Password is the cassandra password used for authentication by gocql client
368 Password string `yaml:"password"`
369 // AllowedAuthenticators is the optional list of authenticators the gocql client checks before approving the challenge request from the server.
370 AllowedAuthenticators []string `yaml:"allowedAuthenticators"`
371 // keyspace is the cassandra keyspace
372 Keyspace string `yaml:"keyspace" validate:"nonzero"`
373 // Datacenter is the data center filter arg for cassandra
374 Datacenter string `yaml:"datacenter"`
375 // MaxConns is the max number of connections to this datastore for a single keyspace
376 MaxConns int `yaml:"maxConns"`
377 // ConnectTimeout is a timeout for initial dial to cassandra server (default: 600 milliseconds)
378 ConnectTimeout time.Duration `yaml:"connectTimeout"`
379 // Timeout is a timeout for reads and, unless otherwise specified, writes. If not specified, ConnectTimeout is used.
380 Timeout time.Duration `yaml:"timeout"`
381 // WriteTimeout is a timeout for writing a query. If not specified, Timeout is used.
382 WriteTimeout time.Duration `yaml:"writeTimeout"`
383 // TLS configuration
384 TLS *auth.TLS `yaml:"tls"`
385 // Consistency configuration (defaults to LOCAL_QUORUM / LOCAL_SERIAL for all stores if this field not set)
386 Consistency *CassandraStoreConsistency `yaml:"consistency"`
387 // DisableInitialHostLookup instructs the gocql client to connect only using the supplied hosts
388 DisableInitialHostLookup bool `yaml:"disableInitialHostLookup"`
389 // AddressTranslator translates Cassandra IP addresses, used for cases when IP addresses gocql driver returns are not accessible from the server
390 AddressTranslator *CassandraAddressTranslator `yaml:"addressTranslator"`
391 }
392
393 // CassandraStoreConsistency enables you to set the consistency settings for each Cassandra Persistence Store for Temporal
394 CassandraStoreConsistency struct {
395 // Default defines the consistency level for ALL stores.
396 // Defaults to LOCAL_QUORUM and LOCAL_SERIAL if not set
397 Default *CassandraConsistencySettings `yaml:"default"`
398 }
399
400 CassandraAddressTranslator struct {
401 // Translator defines name of translator implementation to use for Cassandra address translation
402 Translator string `yaml:"translator"`
403 // Options map of options for address translator implementation
404 Options map[string]string `yaml:"options"`
405 }
406
407 // CassandraConsistencySettings sets the default consistency level for regular & serial queries to Cassandra.
408 CassandraConsistencySettings struct {
409 // Consistency sets the default consistency level. Values identical to gocql Consistency values. (defaults to LOCAL_QUORUM if not set).
410 Consistency string `yaml:"consistency"`
411 // SerialConsistency sets the consistency for the serial prtion of queries. Values identical to gocql SerialConsistency values. (defaults to LOCAL_SERIAL if not set)
412 SerialConsistency string `yaml:"serialConsistency"`
413 }
414
415 // PasswordCommandConfig configures an external command to fetch the datastore password.
416 // The command's stdout is used as the password.
417 PasswordCommandConfig struct {
418 // Command is the path to the executable to run.
419 Command string `yaml:"command"`
420 // Args is the list of arguments to pass to the command.
421 Args []string `yaml:"args"`
422 // Timeout is the maximum duration to wait for the command to complete.
423 // Defaults to 30 seconds if unset.
424 Timeout time.Duration `yaml:"timeout"`
425 }
426
427 // SQL is the configuration for connecting to a SQL backed datastore
428 SQL struct {
429 // Connect is a function that returns a sql db connection. String based configuration is ignored if this is provided.
430 Connect func(sqlConfig *SQL) (*sqlx.DB, error) `yaml:"-" json:"-"`
431 // User is the username to be used for the conn
432 User string `yaml:"user"`
433 // Password is the password corresponding to the user name
434 Password string `yaml:"password"`
435 // PasswordCommand executes an external command and uses its stdout as the password.
436 // Mutually exclusive with Password.
437 // If the command returns an expiring token (e.g. cloud IAM), set MaxConnLifetime
438 // to ensure connections are recycled before the token expires.
439 PasswordCommand *PasswordCommandConfig `yaml:"passwordCommand"`
440 // PluginName is the name of SQL plugin
441 PluginName string `yaml:"pluginName" validate:"nonzero"`
442 // DatabaseName is the name of SQL database to connect to
443 DatabaseName string `yaml:"databaseName" validate:"nonzero"`
444 // ConnectAddr is the remote addr of the database
445 ConnectAddr string `yaml:"connectAddr" validate:"nonzero"`
446 // ConnectProtocol is the protocol that goes with the ConnectAddr ex - tcp, unix
447 ConnectProtocol string `yaml:"connectProtocol" validate:"nonzero"`
448 // ConnectAttributes is a set of key-value attributes to be sent as part of connect data_source_name url.
449 // For the postgres12_pgx plugin, "require_auth" restricts which authentication methods the client
450 // accepts from the server (e.g. "scram-sha-256", or "!none" to negate), hardening against auth
451 // downgrade. Unset means all methods are accepted.
452 ConnectAttributes map[string]string `yaml:"connectAttributes"`
453 // MaxConns the max number of connections to this datastore
454 MaxConns int `yaml:"maxConns"`
455 // MaxIdleConns is the max number of idle connections to this datastore
456 MaxIdleConns int `yaml:"maxIdleConns"`
457 // MaxConnLifetime is the maximum time a connection can be alive
458 MaxConnLifetime time.Duration `yaml:"maxConnLifetime"`
459 // EXPERIMENTAL - TaskScanPartitions is the number of partitions to sequentially scan during ListTaskQueue operations.
460 // This is used for in a sharded sql database such as Vitess for heavy task workloads to minimize scatter gather.
461 // The default value for this param is 1, and should not be configured without a thorough understanding of what this does.
462 TaskScanPartitions int `yaml:"taskScanPartitions"`
463 // TLS is the configuration for TLS connections
464 TLS *auth.TLS `yaml:"tls"`
465 }
466
467 // CustomDatastoreConfig is the configuration for connecting to a custom datastore that is not supported by temporal core
468 CustomDatastoreConfig struct {
469 // Name of the custom datastore
470 Name string `yaml:"name"`
471 // IndexName represents a unique identifier for the data store.
472 // The name "IndexName" inherits from the Elasticsearch config and refers to the index name.
473 // In SQL, it refers to the database name.
474 // For custom data store, you may pick any name as long as it's unique across custom data
475 // stores (Elasticsearch index names and SQL database names).
476 IndexName string `yaml:"indexName"`
477 // Options to be used by AbstractDatastoreFactory implementation
478 Options map[string]any `yaml:"options"`
479 }
480
481 // Replicator describes the configuration of replicator
482 Replicator struct{}
483
484 // ReplicationTaskProcessorConfig is the config for replication task processor.
485 ReplicationTaskProcessorConfig struct {
486 NoTaskInitialWaitIntervalSecs int `yaml:"noTaskInitialWaitIntervalSecs"`
487 NoTaskWaitBackoffCoefficient float64 `yaml:"noTaskWaitBackoffCoefficient"`
488 NoTaskMaxWaitIntervalSecs int `yaml:"noTaskMaxWaitIntervalSecs"`
489 }
490
491 // DCRedirectionPolicy contains the frontend datacenter redirection policy
492 DCRedirectionPolicy struct {
493 Policy string `yaml:"policy"`
494 }
495
496 // Archival contains the config for archival
497 Archival struct {
498 // History is the config for the history archival
499 History HistoryArchival `yaml:"history"`
500 // Visibility is the config for visibility archival
501 Visibility VisibilityArchival `yaml:"visibility"`
502 }
503
504 // HistoryArchival contains the config for history archival
505 HistoryArchival struct {
506 // State is the state of history archival either: enabled, disabled, or paused
507 State string `yaml:"state"`
508 // EnableRead whether history can be read from archival
509 EnableRead bool `yaml:"enableRead"`
510 // Provider contains the config for all history archivers
511 Provider *HistoryArchiverProvider `yaml:"provider"`
512 }
513
514 // HistoryArchiverProvider contains the config for all history archivers
515 HistoryArchiverProvider struct {
516 Filestore *FilestoreArchiver `yaml:"filestore"`
517 Gstorage *GstorageArchiver `yaml:"gstorage"`
518 S3store *S3Archiver `yaml:"s3store"`
519 // CustomStores contains the config for all custom history archivers
520 // The structure is a map of archiver name (scheme) to a map of config key-values
521 CustomStores map[string]map[string]any `yaml:"customStores"`
522 }
523
524 // VisibilityArchival contains the config for visibility archival
525 VisibilityArchival struct {
526 // State is the state of visibility archival either: enabled, disabled, or paused
527 State string `yaml:"state"`
528 // EnableRead whether visibility can be read from archival
529 EnableRead bool `yaml:"enableRead"`
530 // Provider contains the config for all visibility archivers
531 Provider *VisibilityArchiverProvider `yaml:"provider"`
532 }
533
534 // VisibilityArchiverProvider contains the config for all visibility archivers
535 VisibilityArchiverProvider struct {
536 Filestore *FilestoreArchiver `yaml:"filestore"`
537 S3store *S3Archiver `yaml:"s3store"`
538 Gstorage *GstorageArchiver `yaml:"gstorage"`
539 // CustomStores contains the config for all custom visibility archivers
540 // The structure is a map of archiver name (scheme) to a map of config key-values
541 CustomStores map[string]map[string]any `yaml:"customStores"`
542 }
543
544 // FilestoreArchiver contain the config for filestore archiver
545 FilestoreArchiver struct {
546 FileMode string `yaml:"fileMode"`
547 DirMode string `yaml:"dirMode"`
548 }
549
550 // GstorageArchiver contain the config for google storage archiver
551 GstorageArchiver struct {
552 CredentialsPath string `yaml:"credentialsPath"`
553 }
554
555 // S3Archiver contains the config for S3 archiver
556 S3Archiver struct {
557 Region string `yaml:"region"`
558 Endpoint *string `yaml:"endpoint"`
559 S3ForcePathStyle bool `yaml:"s3ForcePathStyle"`
560 LogLevel uint `yaml:"logLevel"`
561 }
562
563 // PublicClient is the config for internal nodes (history/matching/worker) connecting to
564 // frontend. There are three methods of connecting:
565 // 1. Use membership to locate "internal-frontend" and connect to them using the Internode
566 // TLS config (which can be "no TLS"). This is recommended for deployments that use an
567 // Authorizer and ClaimMapper. To use this, leave this section out of your config, and
568 // make sure there is an "internal-frontend" section in Services.
569 // 2. Use membership to locate "frontend" and connect to them using the Frontend TLS config
570 // (which can be "no TLS"). This is recommended for deployments that don't use an
571 // Authorizer or ClaimMapper, or have implemented a custom ClaimMapper that correctly
572 // identifies the system worker using mTLS and assigns it an Admin-level claim.
573 // To use this, leave this section out of your config and make sure there is _no_
574 // "internal-frontend" section in Services.
575 // 3. Connect to an explicit endpoint using the SystemWorker (falling back to Frontend) TLS
576 // config (which can be "no TLS"). You can use this if you want to force frontend
577 // connections to go through an external load balancer. If you use this with a
578 // ClaimMapper+Authorizer, you need to ensure that your ClaimMapper assigns Admin
579 // claims to worker nodes, and your Authorizer correctly handles those claims.
580 PublicClient struct {
581 // HostPort is the host port to connect on. Host can be DNS name. See the above
582 // comment: in many situations you can leave this empty.
583 HostPort string `yaml:"hostPort"`
584 // HTTPHostPort is the HTTP host port to connect on. Host can be DNS name. See the above
585 // comment: in many situations you can leave this empty.
586 HTTPHostPort string `yaml:"httpHostPort"`
587 // Force selection of either the "internode" or "frontend" TLS configs for these
588 // connections (only those two strings are valid).
589 ForceTLSConfig string `yaml:"forceTLSConfig"`
590 }
591
592 // NamespaceDefaults is the default config for each namespace
593 NamespaceDefaults struct {
594 // Archival is the default archival config for each namespace
595 Archival ArchivalNamespaceDefaults `yaml:"archival"`
596 }
597
598 // ArchivalNamespaceDefaults is the default archival config for each namespace
599 ArchivalNamespaceDefaults struct {
600 // History is the namespace default history archival config for each namespace
601 History HistoryArchivalNamespaceDefaults `yaml:"history"`
602 // Visibility is the namespace default visibility archival config for each namespace
603 Visibility VisibilityArchivalNamespaceDefaults `yaml:"visibility"`
604 }
605
606 // HistoryArchivalNamespaceDefaults is the default history archival config for each namespace
607 HistoryArchivalNamespaceDefaults struct {
608 // State is the namespace default state of history archival: enabled or disabled
609 State string `yaml:"state"`
610 // URI is the namespace default URI for history archiver
611 URI string `yaml:"URI"`
612 }
613
614 // VisibilityArchivalNamespaceDefaults is the default visibility archival config for each namespace
615 VisibilityArchivalNamespaceDefaults struct {
616 // State is the namespace default state of visibility archival: enabled or disabled
617 State string `yaml:"state"`
618 // URI is the namespace default URI for visibility archiver
619 URI string `yaml:"URI"`
620 }
621
622 Visibility struct {
623 // PersistenceCustomSearchAttributes is a set of key-value pairs specifying the number of
624 // pre-allocated custom search attributes for each type. Pre-allocated custom search attributes
625 // are named following the convention `<type><seq>` (eg. Keyword01) and are expected to exist in
626 // the data store (eg. SQL DB table column Keyword01 must exist). The pre-allocated custom search
627 // attributes serves as a limit for the number of custom search attributes you can create per
628 // namespace.
629 // If any type is not specified, it will pre-allocate the default number of custom search
630 // attributes for the type defined in the map defaultNumDbCustomSearchAttributes in
631 // common/searchattribute/sadefs.go.
632 // Modifying the number of pre-allocated custom search attributes:
633 // - if you increase a number, it will pre-allocate additional custom search attributes to match
634 // the desired number;
635 // - if you decrease a number, it will not delete the existing custom search attributes, ie., it
636 // is no-op.
637 // This config only applies to SQL or custom Visibility stores.
638 PersistenceCustomSearchAttributes map[string]int `yaml:"persistenceCustomSearchAttributes" validate:"persistence_custom_search_attributes"`
639 }
640
641 Authorization struct {
642 // Signing key provider for validating JWT tokens
643 JWTKeyProvider JWTKeyProvider `yaml:"jwtKeyProvider"`
644 PermissionsClaimName string `yaml:"permissionsClaimName"`
645 // Regular expression to parse permissions claim value. The regex should contain named groups "namespace" and "role", for example
646 // `^(?P<role>\w+):(?P<namespace>\w+)$` will match `admin:default` and extract `default` as namespace and `admin` as role.
647 PermissionsRegex string `yaml:"permissionsRegex"`
648 // Empty string for noopAuthorizer or "default" for defaultAuthorizer
649 Authorizer string `yaml:"authorizer"`
650 // Empty string for noopClaimMapper or "default" for defaultJWTClaimMapper
651 ClaimMapper string `yaml:"claimMapper"`
652 // Name of main auth header to pass to ClaimMapper (as `AuthToken`). Defaults to `authorization`.
653 AuthHeaderName string `yaml:"authHeaderName"`
654 // Name of extra auth header to pass to ClaimMapper (as `ExtraData`). Defaults to `authorization-extras`.
655 AuthExtraHeaderName string `yaml:"authExtraHeaderName"`
656 // JWT audience for validating tokens
657 Audience string `yaml:"audience"`
658 // RemoteClusterAuth controls outbound credentials carried on cross-cluster RPCs.
659 RemoteClusterAuth RemoteClusterAuth `yaml:"remoteClusterAuth"`
660 }
661
662 // RemoteClusterAuth controls outbound auth on cross-cluster RPCs.
663 RemoteClusterAuth struct {
664 // Require fails outbound remote-cluster RPCs that have no token (and fails server boot if no TokenProvider is set).
665 Require bool `yaml:"require"`
666 }
667
668 // @@@SNIPSTART temporal-common-service-config-jwtkeyprovider
669 // Contains the config for signing key provider for validating JWT tokens
670 JWTKeyProvider struct {
671 KeySourceURIs []string `yaml:"keySourceURIs"`
672 RefreshInterval time.Duration `yaml:"refreshInterval"`
673 }
674 // @@@SNIPEND
675 )
676
677 const (
678 ShardStoreName DataStoreName = "ShardStore"
679 TaskStoreName DataStoreName = "TaskStore"
680 MetadataStoreName DataStoreName = "MetadataStore"
681 ExecutionStoreName DataStoreName = "ExecutionStore"
682 QueueName DataStoreName = "Queue"
683 QueueV2Name DataStoreName = "QueueV2"
684 ClusterMDStoreName DataStoreName = "ClusterMDStore"
685 NexusEndpointStoreName DataStoreName = "NexusEndpointStore"
686 )
687
688 const (
689 ForceTLSConfigAuto = ""
690 ForceTLSConfigInternode = "internode"
691 ForceTLSConfigFrontend = "frontend"
692 )
693
694 // Validate validates this config
695 > func (c *Config) Validate() error { fx.go ×44
696 > if err := c.Persistence.Validate(); err != nil {
697 return err
698 }
699
700 > if err := c.Archival.Validate(&c.NamespaceDefaults.Archival); err != nil { fx.go ×44
701 return err
702 }
703
704 > _, hasIFE := c.Services[string(primitives.InternalFrontendService)] fx.go ×44
705 > if hasIFE && (c.PublicClient.HostPort != "" || c.PublicClient.ForceTLSConfig != "" || c.PublicClient.HTTPHostPort != "") {
706 return fmt.Errorf("when using internal-frontend, publicClient must be empty")
707 }
708
709 > switch c.PublicClient.ForceTLSConfig { fx.go ×44
710 > case ForceTLSConfigAuto, ForceTLSConfigInternode, ForceTLSConfigFrontend:
711 default:
712 return fmt.Errorf("invalid value for publicClient.forceTLSConfig: %q", c.PublicClient.ForceTLSConfig)
713 }
714
715 > return nil fx.go ×44
716 }
717
718 // String converts the config object into a string
719 > func (c *Config) String() string { fx.go ×44
720 > var buf bytes.Buffer
721 > encoder := yaml.NewEncoder(&buf)
722 > encoder.SetIndent(2)
723 > _ = encoder.Encode(c)
724 > maskedYaml, _ := masker.MaskYaml(buf.String(), masker.DefaultYAMLFieldNames)
725 > return maskedYaml
726 > }
727
728 > func (r *GroupTLS) IsServerEnabled() bool { config.go ×1
729 > return r.Server.KeyFile != "" || r.Server.KeyData != ""
730 > }
731
732 > func (r *GroupTLS) IsClientEnabled() bool { config.go ×1
733 > return len(r.Client.RootCAFiles) > 0 || len(r.Client.RootCAData) > 0 ||
734 > r.Client.ForceTLS
735 > }
736
737 > func (p *JWTKeyProvider) HasSourceURIsConfigured() bool { default_token_key_provider.go ×3
738 > if len(p.KeySourceURIs) == 0 {
739 > return false
740 > }
741 for _, uri := range p.KeySourceURIs {
742 if strings.TrimSpace(uri) != "" {
743 return true
744 }
745 }
746 return false
747 }
748
749 func (k *KeepAliveServerConfig) GetKeepAliveServerParameters() keepalive.ServerParameters {
750 // the default config is same as grpc default config, same for the below client config and enforcement policy
751 defaultConfig := keepalive.ServerParameters{
752 MaxConnectionIdle: infinity,
753 MaxConnectionAge: infinity,
754 MaxConnectionAgeGrace: infinity,
755 Time: 2 * time.Hour,
756 Timeout: 20 * time.Second,
757 }
758 if k == nil || k.KeepAliveServerParameters == nil {
759 return defaultConfig
760 }
761 kp := k.KeepAliveServerParameters
762 if kp.MaxConnectionIdle != nil {
763 defaultConfig.MaxConnectionIdle = *kp.MaxConnectionIdle
764 }
765 if kp.MaxConnectionAge != nil {
766 defaultConfig.MaxConnectionAge = *kp.MaxConnectionAge
767 }
768 if kp.MaxConnectionAgeGrace != nil {
769 defaultConfig.MaxConnectionAgeGrace = *kp.MaxConnectionAgeGrace
770 }
771 if kp.Time != nil {
772 defaultConfig.Time = *kp.Time
773 }
774 if kp.Timeout != nil {
775 defaultConfig.Timeout = *kp.Timeout
776 }
777 return defaultConfig
778 }
779
780 func (c *ClientConnectionConfig) GetKeepAliveClientParameters() keepalive.ClientParameters {
781 defaultConfig := keepalive.ClientParameters{
782 Time: infinity,
783 Timeout: 20 * time.Second,
784 PermitWithoutStream: false,
785 }
786
787 if c == nil || c.KeepAliveClientConfig == nil {
788 return defaultConfig
789 }
790
791 if c.KeepAliveClientConfig.Time != nil {
792 defaultConfig.Time = *c.KeepAliveClientConfig.Time
793 }
794 if c.KeepAliveClientConfig.Timeout != nil {
795 defaultConfig.Timeout = *c.KeepAliveClientConfig.Timeout
796 }
797 if c.KeepAliveClientConfig.PermitWithoutStream != nil {
798 defaultConfig.PermitWithoutStream = *c.KeepAliveClientConfig.PermitWithoutStream
799 }
800
801 return defaultConfig
802 }
803
804 func (k *KeepAliveServerConfig) GetKeepAliveEnforcementPolicy() keepalive.EnforcementPolicy {
805 defaultConfig := keepalive.EnforcementPolicy{
806 MinTime: 5 * time.Minute,
807 PermitWithoutStream: false,
808 }
809
810 if k == nil || k.KeepAliveEnforcementPolicy == nil {
811 return defaultConfig
812 }
813
814 if k.KeepAliveEnforcementPolicy.MinTime != nil {
815 defaultConfig.MinTime = *k.KeepAliveEnforcementPolicy.MinTime
816 }
817 if k.KeepAliveEnforcementPolicy.PermitWithoutStream != nil {
818 defaultConfig.PermitWithoutStream = *k.KeepAliveEnforcementPolicy.PermitWithoutStream
819 }
820
821 return defaultConfig
822 }
823
824 func (fi *FaultInjection) WithError(storeName DataStoreName, methodName, errorName string, probability float64) *FaultInjection {
825 if fi == nil {
826 return nil
827 }
828 m := fi.method(storeName, methodName)
829 m.Errors[errorName] = probability
830 fi.Targets.DataStores[storeName].Methods[methodName] = m
831 return fi
832 }
833
834 func (fi *FaultInjection) WithMethodSeed(storeName DataStoreName, methodName string, seed int64) *FaultInjection {
835 if fi == nil {
836 return nil
837 }
838 m := fi.method(storeName, methodName)
839 m.Seed = seed
840 fi.Targets.DataStores[storeName].Methods[methodName] = m
841 return fi
842 }
843
844 func (fi *FaultInjection) method(storeName DataStoreName, methodName string) FaultInjectionMethodConfig {
845 if fi.Targets.DataStores == nil {
846 fi.Targets.DataStores = map[DataStoreName]FaultInjectionDataStoreConfig{}
847 }
848 store, ok := fi.Targets.DataStores[storeName]
849 if !ok {
850 store = FaultInjectionDataStoreConfig{Methods: map[string]FaultInjectionMethodConfig{}}
851 }
852 method, ok := store.Methods[methodName]
853 if !ok {
854 method = FaultInjectionMethodConfig{Errors: map[string]float64{}}
855 }
856 store.Methods[methodName] = method
857 fi.Targets.DataStores[storeName] = store
858 return method
859 }
860
861 func DefaultFaultInjection() *FaultInjection {
862 fiCfg := &FaultInjection{}
863 return fiCfg.
864 WithError(ExecutionStoreName, "CreateWorkflowExecution", "ResourceExhausted", 0.01).
865 WithError(ExecutionStoreName, "CreateWorkflowExecution", "Timeout", 0.01).
866 WithError(ExecutionStoreName, "CreateWorkflowExecution", "ExecuteAndTimeout", 0.01).
867 WithError(ExecutionStoreName, "UpdateWorkflowExecution", "ResourceExhausted", 0.01).
868 WithError(ExecutionStoreName, "UpdateWorkflowExecution", "Timeout", 0.01).
869 WithError(ExecutionStoreName, "UpdateWorkflowExecution", "ExecuteAndTimeout", 0.01).
870 WithError(ExecutionStoreName, "GetWorkflowExecution", "ResourceExhausted", 0.01).
871 WithError(ExecutionStoreName, "GetWorkflowExecution", "Timeout", 0.01).
872 WithError(ExecutionStoreName, "GetCurrentExecution", "ResourceExhausted", 0.01).
873 WithError(ExecutionStoreName, "GetCurrentExecution", "Timeout", 0.01).
874 WithError(ExecutionStoreName, "AppendHistoryNodes", "ResourceExhausted", 0.01).
875 WithError(ExecutionStoreName, "AppendHistoryNodes", "Timeout", 0.01).
876 WithError(ExecutionStoreName, "AppendHistoryNodes", "ExecuteAndTimeout", 0.01).
877 WithError(ExecutionStoreName, "ReadHistoryBranch", "ResourceExhausted", 0.01).
878 WithError(ExecutionStoreName, "ReadHistoryBranch", "Timeout", 0.01)
879 }