Module: Fluent::Plugin::Opentelemetry::GrpcTLS

Defined in:
lib/fluent/plugin/opentelemetry/grpc_tls.rb

Class Method Summary collapse

Class Method Details

.channel_credentials(transport_config) ⇒ Object



27
28
29
30
31
32
33
34
35
# File 'lib/fluent/plugin/opentelemetry/grpc_tls.rb', line 27

def channel_credentials(transport_config)
  return :this_channel_is_insecure unless tls?(transport_config)

  GRPC::Core::ChannelCredentials.new(
    read_pem(transport_config.ca_path),
    read_private_key(transport_config),
    read_pem(transport_config.cert_path)
  )
end

.server_credentials(transport_config) ⇒ Object



37
38
39
40
41
42
43
44
45
# File 'lib/fluent/plugin/opentelemetry/grpc_tls.rb', line 37

def server_credentials(transport_config)
  return :this_port_is_insecure unless tls?(transport_config)

  GRPC::Core::ServerCredentials.new(
    read_pem(transport_config.ca_path),
    [{ private_key: read_private_key(transport_config), cert_chain: read_pem(transport_config.cert_path) }],
    transport_config.client_cert_auth
  )
end

.validate_server!(transport_config) ⇒ Object



11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
# File 'lib/fluent/plugin/opentelemetry/grpc_tls.rb', line 11

def validate_server!(transport_config)
  return unless tls?(transport_config)

  if transport_config.cert_path.nil? || transport_config.private_key_path.nil?
    raise Fluent::ConfigError, "<transport tls> cert_path and private_key_path are required when <grpc> is used"
  end

  if transport_config.client_cert_auth && transport_config.ca_path.nil?
    raise Fluent::ConfigError, "<transport tls> client_cert_auth requires ca_path when <grpc> is used"
  end

  [transport_config.ca_path, transport_config.cert_path, transport_config.private_key_path].compact.each do |path|
    raise Fluent::ConfigError, "<transport tls> cannot read '#{path}'" unless File.readable?(path)
  end
end