Watcher
Watcher 让多个 enforcer 实例之间的 policy 保持同步。当某个 enforcer 更新 policy 时,它会通知其他实例(通过 etcd、Redis 或 Kafka 等消息总线),其他实例随之重新加载或更新自己内存中的 policy。这样你就可以在负载均衡后面运行多个 enforcer,而不会出现权限过期的问题。
Watcher 与 adapter 一样,也在独立的包中实现。下面的列表列出了支持的后端。要新增一个,请提交 issue 或 PR。
| Watcher | Type | Author | Description |
|---|---|---|---|
| PostgreSQL WatcherEx | Database | @IguteChung | WatcherEx for PostgreSQL |
| Redis WatcherEx | KV store | Casbin | WatcherEx for Redis |
| Redis Watcher | KV store | @billcobbler | Watcher for Redis |
| Etcd Watcher | KV store | Casbin | Watcher for etcd |
| TiKV Watcher | KV store | Casbin | Watcher for TiKV |
| Kafka Watcher | Messaging system | @wgarunap | Watcher for Apache Kafka |
| NATS Watcher | Messaging system | Soluto | Watcher for NATS |
| ZooKeeper Watcher | Messaging system | Grepsr | Watcher for Apache ZooKeeper |
| NATS, RabbitMQ, GCP Pub/Sub, AWS SNS & SQS, Kafka, InMemory | Messaging System | @rusenask | Watcher based on Go Cloud Dev Kit that works with leading cloud providers and self-hosted infrastructure |
| NATS, RabbitMQ, GCP Pub/Sub, AWS SNS & SQS, Kafka, InMemory | Messaging System | @bartventer | WatcherEx based on Go Cloud Dev Kit that works with leading cloud providers and self-hosted infrastructure |
| RocketMQ Watcher | Messaging system | @fmyxyz | Watcher for Apache RocketMQ |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Etcd Adapter | KV store | @mapleafgo | Watcher for etcd |
| Redis Watcher | KV store | Casbin | Watcher for Redis |
| Redis WatcherEx | KV store | Casbin | WatcherEx for Redis |
| Lettuce-Based Redis Watcher | KV store | Casbin | Watcher for Redis based on Lettuce) |
| PostgreSQL Watcher | Database | Casbin | Watcher for PostgreSQL |
| Kafka Watcher | Messaging system | Casbin | Watcher for Apache Kafka |
| ZooKeeper Watcher | Messaging system | Casbin | Watcher for Apache ZooKeeper |
| RabbitMQ Watcher | Messaging system | Casbin | Watcher for RabbitMQ |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Etcd Watcher | KV store | Casbin | Watcher for etcd |
| Redis Watcher | KV store | Casbin | Watcher for Redis |
| Pub/Sub Watcher | Messaging system | Casbin | Watcher for Google Cloud Pub/Sub |
| MongoDB Change Streams Watcher | Database | Casbin | Watcher for MongoDB Change Streams |
| Postgres Watcher | Database | @mcollina | Watcher for PostgreSQL |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Etcd Watcher | KV store | Casbin | Watcher for etcd |
| Redis Watcher | KV store | Casbin | Watcher for Redis |
| Redis Watcher | KV store | ScienceLogic | Watcher for Redis |
| Redis Async Watcher | KV store | @kevinkelin | Watcher for Redis |
| PostgreSQL Watcher | Database | Casbin | Watcher for PostgreSQL |
| RabbitMQ Watcher | Messaging system | Casbin | Watcher for RabbitMQ |
| MongoDB Watcher | Database | @sanguinedab | Watcher for MongoDB |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Redis Watcher | KV store | @Sbou | Watcher for Redis |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Redis Watcher | KV store | CasbinRuby | Watcher for Redis |
| RabbitMQ Watcher | Messaging system | CasbinRuby | Watcher for RabbitMQ |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Redis Watcher | KV store | @Tinywan | Watcher for Redis |
| Watcher | Type | Author | Description |
|---|---|---|---|
| Redis Watcher | KV store | Casbin | Watcher for Redis |
WatcherEx
为了支持多个实例之间的增量同步,我们提供了 WatcherEx 接口。该接口可以在 policy 变更时通知其他实例,不过目前还没有 WatcherEx 的实现。我们建议使用 dispatcher 来实现这一功能。
与 Watcher 接口相比,WatcherEx 能够区分收到的更新操作类型,例如 AddPolicy 与 RemovePolicy。
WatcherEx API:
| API | Description |
|---|---|
| SetUpdateCallback(func(string)) error | SetUpdateCallback 配置 watcher 在数据库中的 policy 被其他实例更改时调用的回调函数。经典的回调是 Enforcer.LoadPolicy()。 |
| Update() error | Update 调用其他 实例的更新回调来同步它们的 policy。通常在更改数据库中的 policy 之后调用,例如在 Enforcer.SavePolicy()、Enforcer.AddPolicy()、Enforcer.RemovePolicy() 等之后。 |
| Close() | Close 停止并释放 watcher。此后回调函数将不再被调用。 |
| UpdateForAddPolicy(sec, ptype string, params ...string) error | UpdateForAddPolicy 调用其他实例的更新回调来同步它们的 policy。在通过 Enforcer.AddPolicy()、Enforcer.AddNamedPolicy()、Enforcer.AddGroupingPolicy() 和 Enforcer.AddNamedGroupingPolicy() 添加 policy 之后调用。 |
| UpdateForRemovePolicy(sec, ptype string, params ...string) error | UpdateForRemovePolicy 调用其他实例的更新回调来同步它们的 policy。在通过 Enforcer.RemovePolicy()、Enforcer.RemoveNamedPolicy()、Enforcer.RemoveGroupingPolicy() 和 Enforcer.RemoveNamedGroupingPolicy() 移除 policy 之后调用。 |
| UpdateForRemoveFilteredPolicy(sec, ptype string, fieldIndex int, fieldValues ...string) error | UpdateForRemoveFilteredPolicy 调用其他实例的更新回调来同步它们的 policy。在 Enforcer.RemoveFilteredPolicy()、Enforcer.RemoveFilteredNamedPolicy()、Enforcer.RemoveFilteredGroupingPolicy() 和 Enforcer.RemoveFilteredNamedGroupingPolicy() 之后调用。 |
| UpdateForSavePolicy(model model.Model) error | UpdateForSavePolicy 调用其他实例的更新回调来同步它们的 policy。在 Enforcer.SavePolicy() 之后调用。 |
| UpdateForAddPolicies(sec string, ptype string, rules ...[]string) error | UpdateForAddPolicies 调用其他实例的更新回调来同步它们的 policy。在 Enforcer.AddPolicies()、Enforcer.AddNamedPolicies()、Enforcer.AddGroupingPolicies() 和 Enforcer.AddNamedGroupingPolicies() 之后调用。 |
| UpdateForRemovePolicies(sec string, ptype string, rules ...[]string) error | UpdateForRemovePolicies 调用其他实例的更新回调来同步它们的 policy。在 Enforcer.RemovePolicies()、Enforcer.RemoveNamedPolicies()、Enforcer.RemoveGroupingPolicies() 和 Enforcer.RemoveNamedGroupingPolicies() 之后调用。 |