clixon/apps/restconf
2021-09-21 11:22:40 +02:00
..
clixon_restconf.h First working prototype 2021-09-21 11:22:40 +02:00
Makefile.in - Moved yang patch code to new files restconf_methods_patch.[ch] 2021-08-15 20:43:52 +02:00
README.md * Changed config and install options for Restconf 2021-05-23 17:14:18 +02:00
restconf_api.c Copyright 2021 2021-01-13 14:40:34 +01:00
restconf_api.h fixed another rebase error 2021-08-05 15:39:27 +03:00
restconf_api_fcgi.c restconf fcgi mem leak in indata 2021-06-27 16:40:27 +02:00
restconf_api_native.c implement yang-patch 2021-08-05 15:15:28 +03:00
restconf_err.c First working prototype 2021-09-21 11:22:40 +02:00
restconf_err.h - Added Restconf-style xml/json message bodies everywhere 2021-05-08 20:20:01 +02:00
restconf_evhtp.c - Restconf error: added special case for translating from netconf invalid-value to 400 vs 404 2021-08-27 15:12:50 +02:00
restconf_evhtp.h - Restconf nghttp2 compiles 2021-06-03 22:47:54 +02:00
restconf_handle.c * Restconf authentication callback (ca_auth) signature changed 2021-02-09 21:26:35 +01:00
restconf_handle.h * Restconf authentication callback (ca_auth) signature changed 2021-02-09 21:26:35 +01:00
restconf_lib.c First working prototype 2021-09-21 11:22:40 +02:00
restconf_lib.h First working prototype 2021-09-21 11:22:40 +02:00
restconf_main_fcgi.c implement yang-patch 2021-08-05 15:15:28 +03:00
restconf_main_native.c Native restconf: SSL client certs failures are returned as http 405 errors, not fail during SSL negotiation 2021-08-27 09:33:59 +02:00
restconf_methods.c - Refactor yang patch code according to Clixon coding style 2021-09-08 10:38:49 +02:00
restconf_methods.h - Moved yang patch code to new files restconf_methods_patch.[ch] 2021-08-15 20:43:52 +02:00
restconf_methods_get.c cli pagination 2021-09-21 11:22:40 +02:00
restconf_methods_get.h Copyright 2021 2021-01-13 14:40:34 +01:00
restconf_methods_patch.c * JSON errors are now labelled with JSON and not XML 2021-09-20 21:35:01 +02:00
restconf_methods_patch.h - Refactor yang patch code according to Clixon coding style 2021-09-08 10:38:49 +02:00
restconf_methods_post.c - Refactor yang patch code according to Clixon coding style 2021-09-08 10:38:49 +02:00
restconf_methods_post.h implement yang-patch 2021-08-05 15:15:28 +03:00
restconf_native.c - Restconf error: added special case for translating from netconf invalid-value to 400 vs 404 2021-08-27 15:12:50 +02:00
restconf_native.h - Restconf error: added special case for translating from netconf invalid-value to 400 vs 404 2021-08-27 15:12:50 +02:00
restconf_nghttp2.c - Restconf error: added special case for translating from netconf invalid-value to 400 vs 404 2021-08-27 15:12:50 +02:00
restconf_nghttp2.h - Restconf native http/1 to http/2 upgrade (non-tls) 2021-06-13 12:43:19 +02:00
restconf_root.c First working prototype 2021-09-21 11:22:40 +02:00
restconf_root.h Copyright 2021 2021-01-13 14:40:34 +01:00
restconf_stream.h Copyright 2021 2021-01-13 14:40:34 +01:00
restconf_stream_fcgi.c * Netconf message-id attribute changed from optional to mandatory 2021-06-30 10:59:10 +02:00

Clixon Restconf

There are two installation instructions: for libevhtp and nginx.

Native

Download, build and install libevhtp from source. Prereqs: libevent and ssl

   sudo git clone https://github.com/clicon/clixon-libevhtp.git
   cd clixon-libevhtp
   ./configure --libdir=/usr/lib
   make
   sudo make install

Configure clixon with native restconf:

  ./configure --with-restconf=native

Ensure www-data is member of the CLICON_SOCK_GROUP (default clicon). If not, add it:

  sudo usermod -a -G clicon www-data

Nginx

Installation instruction for Nginx. Other reverse proxies should work but are not verified.

Ensure www-data is member of the CLICON_SOCK_GROUP (default clicon). If not, add it:

  sudo usermod -a -G clicon www-data

This implementation uses FastCGI, see http://www.mit.edu/~yandros/doc/specs/fcgi-spec.html.

Download and start nginx. For example on ubuntu:

  sudo apt install ngnix

on FreeBSD:

  sudo pkg install ngnix

Edit the nginx config file. (On Ubuntu: /etc/nginx/sites-available/default, on FreeBSD: /usr/local/etc/nginx/sites-available/default)

  server {
    ...
    location / {
      fastcgi_pass unix:/www-data/fastcgi_restconf.sock;
      include fastcgi_params;
    }
  }

Start nginx daemon

  sudo /etc/init.d nginx start

Alternatively, start it via systemd:

  sudo systemctl start nginx.service

Or on FreeBSD:

  sudo service nginx start

Run

Start clixon backend daemon (if not already started)

  sudo clixon_backend -s init -f /usr/local/etc/example.xml

Start clixon restconf daemon

  sudo clixon_restconf -f /usr/local/etc/example.xml

On FreeBSD:

  sudo clixon_restconf -f /usr/local/etc/example.xml

Make restconf calls with curl (or other http client). Example of writing a new interface specification:

  curl -sX PUT http://localhost/restconf/data/ietf-interfaces:interfaces -H 'Content-Type: application/yang-data+json' -d '{"ietf-interfaces:interfaces":{"interface":{"name":"eth1","type":"clixon-example:eth","enabled":true}}}'

Get the data

  curl -X GET http://127.0.0.1/restconf/data/ietf-interfaces:interfaces
  {
    "ietf-interfaces:interfaces": {
      "interface": [
        {
          "name": "eth1",
          "type": "clixon-example:eth",
          "enabled": true
        }
      ]
    }
  }

Get the type of a specific interface:

  curl -X GET http://127.0.0.1/restconf/data/ietf-interfacesinterfaces/interface=eth1/type
  {
    "ietf-interfaces:type": "clixon-example:eth" 
  }

Streams

Clixon have two experimental restconf event stream implementations following RFC8040 Section 6 using SSE. One native and one using Nginx nchan. The Nchan alternaitve is described in the next section.

The example creates an EXAMPLE stream.

Set the Clixon configuration options:

<CLICON_STREAM_PATH>streams</CLICON_STREAM_PATH>
<CLICON_STREAM_URL>https://example.com</CLICON_STREAM_URL>
<CLICON_STREAM_RETENTION>3600</CLICON_STREAM_RETENTION>

In this example, the stream EXAMPLE would be accessed with https://example.com/streams/EXAMPLE.

The retention is configured as 1 hour, i.e., the stream replay function will only save timeseries one hour.

Clixon defines an internal in-memory (not persistent) replay function controlled by the configure option above.

You may access a restconf streams using curl.

Add the following to extend the nginx configuration file with the following statements (for example):

	location /streams {
	    fastcgi_pass unix:/www-data/fastcgi_restconf.sock;
	    include fastcgi_params;
 	    proxy_http_version 1.1;
	    proxy_set_header Connection "";
        }

An example of a stream access is as follows:

> curl -H "Accept: text/event-stream" -s -X GET http://localhost/streams/EXAMPLE
data: <notification xmlns="urn:ietf:params:xml:ns:netconf:notification:1.0"><eventTime>2018-11-04T14:47:11.373124</eventTime><event><event-class>fault</event-class><reportingEntity><card>Ethernet0</card></reportingEntity><severity>major</severity></event></notification>

data: <notification xmlns="urn:ietf:params:xml:ns:netconf:notification:1.0"><eventTime>2018-11-04T14:47:16.375265</eventTime><event><event-class>fault</event-class><reportingEntity><card>Ethernet0</card></reportingEntity><severity>major</severity></event></notification>

You can also specify start and stop time. Start-time enables replay of existing samples, while stop-time is used both for replay, but also for stopping a stream at some future time.

   curl -H "Accept: text/event-stream" -s -X GET http://localhost/streams/EXAMPLE?start-time=2014-10-25T10:02:00&stop-time=2014-10-25T12:31:00

See (stream tests)[../test/test_streams.sh] for more examples.

Nchan

As an alternative streams implementation, Nginx/Nchan can be used. Nginx uses pub/sub channels and can be configured in a variety of ways. The following uses a simple variant with one generic subscription channel (streams) and one publication channel (pub).

The advantage with Nchan is the large eco-system around Nginx and Nchan.

Native mode and Nchan mode can co-exist, but the publish URL of Nchan should be different from the streams URL of the native streams.

Nchan mode does not use Clixon retention, since it uses its own replay mechanism.

Download and install nchan, see (https://nchan.io/#install).

Add the following to extend the Nginx configuration file with the following statements (example):

        location ~ /sub/(\w+)$ {
            nchan_subscriber;
            nchan_channel_id $1; #first capture of the location match
        }
        location ~ /pub/(\w+)$ {
            nchan_publisher;
            nchan_channel_id $1; #first capture of the location match
        }        

Configure clixon with --enable-publish which enables curl code for publishing streams to nchan.

You also need to configure CLICON_STREAM_PUB to enable pushing notifications to Nginx/Nchan. Example:

<CLICON_STREAM_PUB>http://localhost/pub</CLICON_STREAM_PUB>

Clicon will then publish events from stream EXAMPLE to `http://localhost/pub/EXAMPLE

Access the event stream EXAMPLE using curl:

   curl -H "Accept: text/event-stream" -s -X GET http://localhost/streams/EXAMPLE
: hi

id: 1541344320:0
data: <notification xmlns="urn:ietf:params:xml:ns:netconf:notification:1.0"><eventTime>2018-11-04T15:12:00.435769</eventTime><event><event-class>fault</event-class><reportingEntity><card>Ethernet0</card></reportingEntity><severity>major</severity></event></notification>

id: 1541344325:0
data: <notification xmlns="urn:ietf:params:xml:ns:netconf:notification:1.0"><eventTime>2018-11-04T15:12:05.446425</eventTime><event><event-class>fault</event-class><reportingEntity><card>Ethernet0</card></reportingEntity><severity>major</severity></event></notification>

Note that the SSE stream output is different than for native streams, and that Last-Event-Id is used for replay:

curl -H "Accept: text/event-stream" -H "Last-Event-ID: 1539961709:0" -s -X GET http://localhost/streams/EXAMPLE

See (https://nchan.io/#eventsource) on more info on how to access an SSE sub endpoint.

Debugging

Start the restconf fastcgi program with debug flag:

sudo clixon_restconf -D 1 -f /usr/local/etc/example.xml

Look at syslog:

tail -f /var/log/syslog | grep clixon_restconf

Send command:

curl -G http://127.0.0.1/restconf/data/*

You can also run restconf in a debugger.

sudo gdb clixon_restconf
(gdb) run -D 1 -f /usr/local/etc/example.xml

but you need to ensure /www-data/fastcgi_restconf.sock has the following access (may need to be done after restconf has started)

rwxr-xr-x 1 www-data www-data 0 sep 22 11:46 /www-data/fastcgi_restconf.sock

You can set debug level of the backend via restconf:

   curl -is -X POST -H "Content-Type: application/yang-data+json" -d '{"clixon-lib:input":{"level":1}}' http://localhost/restconf/operations/clixon-lib:debug