Browse Source

Debounce LwM2M server reload to avoid double restart when both credentials change

pull/15301/head
Andrii Landiak 6 months ago
parent
commit
9ccf94f93b
  1. 4
      common/coap-server/src/main/java/org/thingsboard/server/coapserver/DefaultCoapServerService.java
  2. 42
      common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/config/LwM2MTransportServerConfig.java
  3. 106
      common/transport/lwm2m/src/test/java/org/thingsboard/server/transport/lwm2m/config/LwM2MTransportServerConfigDebounceTest.java
  4. 2
      transport/coap/src/main/resources/tb-coap-transport.yml
  5. 2
      transport/http/src/main/resources/tb-http-transport.yml
  6. 2
      transport/lwm2m/src/main/resources/tb-lwm2m-transport.yml
  7. 2
      transport/mqtt/src/main/resources/tb-mqtt-transport.yml

4
common/coap-server/src/main/java/org/thingsboard/server/coapserver/DefaultCoapServerService.java

@ -196,8 +196,8 @@ public class DefaultCoapServerService implements CoapServerService, SmartInitial
DTLSConnector newConnector = createDtlsConnector(dtlsConnectorConfig);
CoapEndpoint newEndpoint = buildDtlsEndpoint(networkConfig, newConnector);
// Californium binds the DTLS port at connector construction time, so we must stop the old
// endpoint first to release the port. This creates a brief window where the port is unbound;
// We must stop the old endpoint before starting the new one so they don't compete for the same DTLS port.
// This creates a brief window where the port is unbound;
// if the new endpoint fails to start, we attempt to restore the old one (see rollback below).
if (oldDtlsEndpoint != null) {
log.info("Stopping old DTLS endpoint to release the port...");

42
common/transport/lwm2m/src/main/java/org/thingsboard/server/transport/lwm2m/config/LwM2MTransportServerConfig.java

@ -16,6 +16,7 @@
package org.thingsboard.server.transport.lwm2m.config;
import jakarta.annotation.PostConstruct;
import jakarta.annotation.PreDestroy;
import lombok.Getter;
import lombok.Setter;
import lombok.extern.slf4j.Slf4j;
@ -27,12 +28,17 @@ import org.springframework.boot.autoconfigure.condition.ConditionalOnExpression;
import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.context.annotation.Bean;
import org.springframework.stereotype.Component;
import org.thingsboard.common.util.ThingsBoardThreadFactory;
import org.thingsboard.server.common.data.TbProperty;
import org.thingsboard.server.common.transport.config.ssl.SslCredentials;
import org.thingsboard.server.common.transport.config.ssl.SslCredentialsConfig;
import java.util.List;
import java.util.concurrent.CopyOnWriteArrayList;
import java.util.concurrent.Executors;
import java.util.concurrent.ScheduledExecutorService;
import java.util.concurrent.ScheduledFuture;
import java.util.concurrent.TimeUnit;
@Slf4j
@Component
@ -40,6 +46,13 @@ import java.util.concurrent.CopyOnWriteArrayList;
@ConfigurationProperties(prefix = "transport.lwm2m")
public class LwM2MTransportServerConfig implements LwM2MSecureServerConfig {
private static final long RELOAD_DEBOUNCE_SECONDS = 2;
private final List<Runnable> serverReloadCallbacks = new CopyOnWriteArrayList<>();
private final ScheduledExecutorService reloadDebouncer = Executors.newSingleThreadScheduledExecutor(ThingsBoardThreadFactory.forName("lwm2m-reload-debouncer"));
private volatile ScheduledFuture<?> pendingReload;
@Getter
@Value("${transport.lwm2m.dtls.retransmission_timeout:9000}")
private int dtlsRetransmissionTimeout;
@ -136,25 +149,42 @@ public class LwM2MTransportServerConfig implements LwM2MSecureServerConfig {
@Qualifier("lwm2mTrustCredentials")
private SslCredentialsConfig trustCredentialsConfig;
private final List<Runnable> serverReloadCallbacks = new CopyOnWriteArrayList<>();
@PostConstruct
public void init() {
credentialsConfig.registerReloadCallback(() -> {
log.info("LwM2M Server DTLS certificates reloaded. Triggering server reload...");
notifyServerReload();
log.info("LwM2M Server DTLS certificates reloaded. Scheduling debounced server reload...");
scheduleServerReload();
});
trustCredentialsConfig.registerReloadCallback(() -> {
log.info("LwM2M Trust certificates reloaded. Triggering server reload...");
notifyServerReload();
log.info("LwM2M Trust certificates reloaded. Scheduling debounced server reload...");
scheduleServerReload();
});
}
@PreDestroy
public void destroy() {
reloadDebouncer.shutdownNow();
}
public void registerServerReloadCallback(Runnable callback) {
serverReloadCallbacks.add(callback);
}
/**
* Debounces server reload so that if both server and trust credentials change in the same
* poll cycle, only the 'single server recreation' is triggered after both are reloaded.
*/
private synchronized void scheduleServerReload() {
if (pendingReload != null) {
pendingReload.cancel(false);
}
pendingReload = reloadDebouncer.schedule(() -> {
log.info("Debounce window elapsed. Triggering LwM2M server reload...");
notifyServerReload();
}, RELOAD_DEBOUNCE_SECONDS, TimeUnit.SECONDS);
}
private void notifyServerReload() {
for (Runnable callback : serverReloadCallbacks) {
try {

106
common/transport/lwm2m/src/test/java/org/thingsboard/server/transport/lwm2m/config/LwM2MTransportServerConfigDebounceTest.java

@ -0,0 +1,106 @@
/**
* Copyright © 2016-2026 The Thingsboard Authors
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package org.thingsboard.server.transport.lwm2m.config;
import org.junit.jupiter.api.AfterEach;
import org.junit.jupiter.api.BeforeEach;
import org.junit.jupiter.api.Test;
import org.junit.jupiter.api.extension.ExtendWith;
import org.mockito.Mock;
import org.mockito.junit.jupiter.MockitoExtension;
import org.springframework.test.util.ReflectionTestUtils;
import org.thingsboard.server.common.transport.config.ssl.SslCredentialsConfig;
import java.util.concurrent.atomic.AtomicInteger;
import static java.util.concurrent.TimeUnit.SECONDS;
import static org.assertj.core.api.Assertions.assertThat;
import static org.awaitility.Awaitility.await;
@ExtendWith(MockitoExtension.class)
public class LwM2MTransportServerConfigDebounceTest {
private static final long DEBOUNCE_SECONDS = 2; // matches LwM2MTransportServerConfig.RELOAD_DEBOUNCE_SECONDS
@Mock
private SslCredentialsConfig credentialsConfig;
@Mock
private SslCredentialsConfig trustCredentialsConfig;
private LwM2MTransportServerConfig config;
@BeforeEach
public void setup() {
config = new LwM2MTransportServerConfig();
ReflectionTestUtils.setField(config, "credentialsConfig", credentialsConfig);
ReflectionTestUtils.setField(config, "trustCredentialsConfig", trustCredentialsConfig);
}
@AfterEach
public void teardown() {
config.destroy();
}
@Test
public void givenSingleTrigger_whenScheduleServerReload_thenCallbackFiresOnce() {
AtomicInteger callCount = new AtomicInteger(0);
config.registerServerReloadCallback(callCount::incrementAndGet);
invokeScheduleServerReload();
await().atMost(DEBOUNCE_SECONDS + 2, SECONDS)
.untilAsserted(() -> assertThat(callCount.get()).isEqualTo(1));
}
@Test
public void givenTwoRapidTriggers_whenScheduleServerReload_thenCallbackFiresOnce() {
AtomicInteger callCount = new AtomicInteger(0);
config.registerServerReloadCallback(callCount::incrementAndGet);
invokeScheduleServerReload();
invokeScheduleServerReload();
await().atMost(DEBOUNCE_SECONDS + 2, SECONDS)
.untilAsserted(() -> assertThat(callCount.get()).isEqualTo(1));
// Wait extra to confirm no second invocation
await().during(DEBOUNCE_SECONDS + 1, SECONDS)
.atMost(DEBOUNCE_SECONDS + 2, SECONDS)
.untilAsserted(() -> assertThat(callCount.get()).isEqualTo(1));
}
@Test
public void givenTriggersOutsideDebounceWindow_whenScheduleServerReload_thenCallbackFiresTwice() {
AtomicInteger callCount = new AtomicInteger(0);
config.registerServerReloadCallback(callCount::incrementAndGet);
invokeScheduleServerReload();
await().atMost(DEBOUNCE_SECONDS + 2, SECONDS)
.untilAsserted(() -> assertThat(callCount.get()).isEqualTo(1));
invokeScheduleServerReload();
await().atMost(DEBOUNCE_SECONDS + 2, SECONDS)
.untilAsserted(() -> assertThat(callCount.get()).isEqualTo(2));
}
private void invokeScheduleServerReload() {
ReflectionTestUtils.invokeMethod(config, "scheduleServerReload");
}
}

2
transport/coap/src/main/resources/tb-coap-transport.yml

@ -176,7 +176,7 @@ transport:
# X.509 certificate configuration to auto-detect and reload certificate used by transport protocols in real-time (MQTT, CoAP, LwM2M, etc.)
reload:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:false}"
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"

2
transport/http/src/main/resources/tb-http-transport.yml

@ -207,7 +207,7 @@ transport:
# X.509 certificate configuration to auto-detect and reload certificate used by transport protocols in real-time (MQTT, CoAP, LwM2M, etc.)
reload:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:false}"
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"

2
transport/lwm2m/src/main/resources/tb-lwm2m-transport.yml

@ -307,7 +307,7 @@ transport:
# X.509 certificate configuration to auto-detect and reload certificate used by transport protocols in real-time (MQTT, CoAP, LwM2M, etc.)
reload:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:false}"
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"

2
transport/mqtt/src/main/resources/tb-mqtt-transport.yml

@ -240,7 +240,7 @@ transport:
# X.509 certificate configuration to auto-detect and reload certificate used by transport protocols in real-time (MQTT, CoAP, LwM2M, etc.)
reload:
# Enable/disable automatic SSL certificates reload
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:false}"
enabled: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_ENABLED:true}"
# Check interval in seconds for certificates reload
check_interval_seconds: "${TB_TRANSPORT_SSL_CERTIFICATE_RELOAD_CHECK_INTERVAL_SECONDS:60}"

Loading…
Cancel
Save