diff --git a/openflare_agent/internal/nginx/manager.go b/openflare_agent/internal/nginx/manager.go index e5188667..a93ad5b3 100644 --- a/openflare_agent/internal/nginx/manager.go +++ b/openflare_agent/internal/nginx/manager.go @@ -393,6 +393,8 @@ func (m *Manager) CurrentChecksum() (string, error) { } if accessLogPath := m.accessLogRuntimePath(); accessLogPath != "" { normalizedMain = strings.ReplaceAll(normalizedMain, accessLogPath, openrestyrender.AccessLogPlaceholder) + errorLogPath := filepath.Join(filepath.Dir(accessLogPath), "error.log") + normalizedMain = strings.ReplaceAll(normalizedMain, filepath.ToSlash(errorLogPath), openrestyrender.ErrorLogPlaceholder) } if luaDir := m.luaRuntimePath(); luaDir != "" { normalizedMain = strings.ReplaceAll(normalizedMain, luaDir, openrestyrender.LuaDirPlaceholder) @@ -1061,6 +1063,8 @@ func (m *Manager) renderMainConfig(content string) string { } if accessLogPath := m.accessLogRuntimePath(); accessLogPath != "" { rendered = strings.ReplaceAll(rendered, openrestyrender.AccessLogPlaceholder, accessLogPath) + errorLogPath := filepath.Join(filepath.Dir(accessLogPath), "error.log") + rendered = strings.ReplaceAll(rendered, openrestyrender.ErrorLogPlaceholder, filepath.ToSlash(errorLogPath)) } if luaDir := m.luaRuntimePath(); luaDir != "" { rendered = strings.ReplaceAll(rendered, openrestyrender.LuaDirPlaceholder, luaDir) diff --git a/openflare_server/common/constants.go b/openflare_server/common/constants.go index ee7e90db..ece6f3c1 100644 --- a/openflare_server/common/constants.go +++ b/openflare_server/common/constants.go @@ -97,6 +97,7 @@ var OpenRestyMainConfigTemplate = `# This file is generated by OpenFlare. Do not worker_processes {{OpenRestyWorkerProcesses}}; worker_rlimit_nofile {{OpenRestyWorkerRlimitNofile}}; pid logs/nginx.pid; +error_log {{OpenRestyErrorLogPath}} warn; events { worker_connections {{OpenRestyWorkerConnections}}; diff --git a/openflare_server/service/https_phase1_test.go b/openflare_server/service/https_phase1_test.go index a12937f9..ecfdd23e 100644 --- a/openflare_server/service/https_phase1_test.go +++ b/openflare_server/service/https_phase1_test.go @@ -58,6 +58,9 @@ func TestCreateTLSCertificateAndRenderHTTPSConfig(t *testing.T) { if !strings.Contains(result.Version.MainConfig, "access_log __OPENFLARE_ACCESS_LOG__ openflare_json;") { t.Fatal("expected main config to include managed access log placeholder") } + if !strings.Contains(result.Version.MainConfig, "error_log __OPENFLARE_ERROR_LOG__ warn;") { + t.Fatal("expected main config to include managed error log placeholder") + } if !strings.Contains(result.Version.MainConfig, "log_by_lua_file __OPENFLARE_LUA_DIR__/log.lua;") { t.Fatal("expected main config to include managed openresty lua log hook") } @@ -1242,6 +1245,9 @@ func TestOpenRestyMainConfigTemplateRenderAndValidate(t *testing.T) { if !strings.Contains(preview.MainConfig, "access_log __OPENFLARE_ACCESS_LOG__ openflare_json;") { t.Fatal("expected preview main config to preserve managed access log placeholder") } + if !strings.Contains(preview.MainConfig, "error_log __OPENFLARE_ERROR_LOG__ warn;") { + t.Fatal("expected preview main config to preserve managed error log placeholder") + } if !strings.Contains(preview.MainConfig, "map $http_upgrade $connection_upgrade {") { t.Fatal("expected preview main config to preserve managed websocket upgrade map") } @@ -1281,6 +1287,15 @@ func TestOpenRestyMainConfigTemplateRenderAndValidate(t *testing.T) { if err := ValidateOpenRestyMainConfigTemplate(invalidTemplate); err == nil { t.Fatal("expected template without managed websocket upgrade map placeholder to fail validation") } + + invalidTemplate = strings.ReplaceAll( + common.OpenRestyMainConfigTemplate, + "{{OpenRestyErrorLogPath}}", + "", + ) + if err := ValidateOpenRestyMainConfigTemplate(invalidTemplate); err == nil { + t.Fatal("expected template without managed error log placeholder to fail validation") + } } func TestOpenRestyCommonRequestOptionsRender(t *testing.T) { diff --git a/openflare_server/utils/render/openresty/render.go b/openflare_server/utils/render/openresty/render.go index bdb5521d..8adab7d6 100644 --- a/openflare_server/utils/render/openresty/render.go +++ b/openflare_server/utils/render/openresty/render.go @@ -278,6 +278,7 @@ func renderMainConfigTemplate(templateText string, cfg ConfigSnapshot) string { "{{OpenRestyConnectionUpgradeMap}}", renderConnectionUpgradeMap(), "{{OpenRestyDefaultServerBlock}}", renderDefaultServerBlock(), "{{OpenRestyAccessLogPath}}", AccessLogPlaceholder, + "{{OpenRestyErrorLogPath}}", ErrorLogPlaceholder, "{{OpenRestyEventsUseDirective}}", renderTemplateDirective(cfg.EventsUse != "", fmt.Sprintf("use %s;", cfg.EventsUse)), "{{OpenRestyEventsMultiAcceptDirective}}", renderTemplateDirective(cfg.EventsMultiAcceptEnabled, "multi_accept on;"), "{{OpenRestyKeepaliveTimeout}}", fmt.Sprintf("%d", cfg.KeepaliveTimeout), diff --git a/openflare_server/utils/render/openresty/types.go b/openflare_server/utils/render/openresty/types.go index c3e04d6a..0ea8bc09 100644 --- a/openflare_server/utils/render/openresty/types.go +++ b/openflare_server/utils/render/openresty/types.go @@ -4,6 +4,7 @@ const ( CertDirPlaceholder = "__OPENFLARE_CERT_DIR__" RouteConfigPlaceholder = "__OPENFLARE_ROUTE_CONFIG__" AccessLogPlaceholder = "__OPENFLARE_ACCESS_LOG__" + ErrorLogPlaceholder = "__OPENFLARE_ERROR_LOG__" LuaDirPlaceholder = "__OPENFLARE_LUA_DIR__" ObservabilityListenPlaceholder = "__OPENFLARE_OBSERVABILITY_LISTEN__" ObservabilityPortPlaceholder = "__OPENFLARE_OBSERVABILITY_PORT__" @@ -25,6 +26,7 @@ const defaultMainConfigTemplate = `# This file is generated by OpenFlare. Do not worker_processes {{OpenRestyWorkerProcesses}}; worker_rlimit_nofile {{OpenRestyWorkerRlimitNofile}}; pid logs/nginx.pid; +error_log {{OpenRestyErrorLogPath}} warn; events { worker_connections {{OpenRestyWorkerConnections}}; @@ -222,6 +224,7 @@ var requiredMainConfigTemplatePlaceholders = []string{ "{{OpenRestyConnectionUpgradeMap}}", "{{OpenRestyDefaultServerBlock}}", "{{OpenRestyAccessLogPath}}", + "{{OpenRestyErrorLogPath}}", "{{OpenRestyEventsUseDirective}}", "{{OpenRestyEventsMultiAcceptDirective}}", "{{OpenRestyKeepaliveTimeout}}",