Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 1 | load("@io_bazel_rules_go//go:def.bzl", "go_library") |
Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 2 | load("//metropolis/node/build:def.bzl", "erofs_image", "verity_image") |
Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 3 | load("//metropolis/node/build:efi.bzl", "efi_unified_kernel_image") |
Lorenz Brun | 17c4c8b | 2022-02-01 12:59:47 +0100 | [diff] [blame] | 4 | load("//metropolis/node/build/fwprune:def.bzl", "fsspec_linux_firmware") |
Lorenz Brun | 80deba5 | 2022-02-24 17:07:13 +0100 | [diff] [blame] | 5 | load("//metropolis/node/build/mkucode:def.bzl", "cpio_ucode") |
Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 6 | load("@rules_pkg//:pkg.bzl", "pkg_zip") |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 7 | |
| 8 | go_library( |
Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 9 | name = "node", |
Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 10 | srcs = [ |
| 11 | "ids.go", |
Lorenz Brun | 0e291a1 | 2023-06-01 12:22:45 +0200 | [diff] [blame] | 12 | "net_ips.go", |
Serge Bazanski | 93d593b | 2023-03-28 16:43:47 +0200 | [diff] [blame] | 13 | "net_protocols.go", |
Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 14 | "ports.go", |
| 15 | ], |
Serge Bazanski | 31370b0 | 2021-01-07 16:31:14 +0100 | [diff] [blame] | 16 | importpath = "source.monogon.dev/metropolis/node", |
Tim Windelschmidt | 0300077 | 2023-07-03 02:19:28 +0200 | [diff] [blame^] | 17 | visibility = [ |
| 18 | "//metropolis:__subpackages__", |
| 19 | "@io_k8s_kubernetes//pkg/registry:__subpackages__", |
| 20 | ], |
Serge Bazanski | 93d593b | 2023-03-28 16:43:47 +0200 | [diff] [blame] | 21 | deps = ["@com_github_vishvananda_netlink//:netlink"], |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 22 | ) |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 23 | |
Lorenz Brun | 313816f | 2020-12-22 16:52:26 +0100 | [diff] [blame] | 24 | # debug_build checks if we're building in debug mode and enables various debug features for the image. |
Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 25 | config_setting( |
| 26 | name = "debug_build", |
| 27 | values = { |
| 28 | "compilation_mode": "dbg", |
| 29 | }, |
| 30 | ) |
| 31 | |
Lorenz Brun | 17c4c8b | 2022-02-01 12:59:47 +0100 | [diff] [blame] | 32 | fsspec_linux_firmware( |
| 33 | name = "firmware", |
| 34 | firmware_files = ["@linux-firmware//:all_files"], |
| 35 | kernel = "//third_party/linux", |
Lorenz Brun | d3ce0ac | 2022-03-03 12:51:21 +0100 | [diff] [blame] | 36 | metadata = "@linux-firmware//:metadata", |
Lorenz Brun | 17c4c8b | 2022-02-01 12:59:47 +0100 | [diff] [blame] | 37 | ) |
| 38 | |
Lorenz Brun | 80deba5 | 2022-02-24 17:07:13 +0100 | [diff] [blame] | 39 | cpio_ucode( |
| 40 | name = "ucode", |
| 41 | ucode = { |
| 42 | "@linux-firmware//:amd_ucode": "AuthenticAMD", |
| 43 | "@intel_ucode//:fam6h": "GenuineIntel", |
| 44 | }, |
| 45 | visibility = ["//metropolis:__subpackages__"], |
| 46 | ) |
| 47 | |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 48 | erofs_image( |
| 49 | name = "rootfs", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 50 | files = { |
Serge Bazanski | eac8f73 | 2021-10-05 23:30:37 +0200 | [diff] [blame] | 51 | "//metropolis/node/core": "/core", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 52 | |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 53 | # CA Certificate bundle & os-release & resolv.conf |
| 54 | # These should not be explicitly used by Metropolis code and are only here for compatibility with |
| 55 | # paths hardcoded by standard libraries (like Go's). |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 56 | "@cacerts//file": "/etc/ssl/cert.pem", |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 57 | "//metropolis/node/core/network/dns:resolv.conf": "/etc/resolv.conf", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 58 | ":os-release-info": "/etc/os-release", |
| 59 | |
Serge Bazanski | 6d563ca | 2023-06-14 13:44:20 +0200 | [diff] [blame] | 60 | # Metrics exporters |
| 61 | "@com_github_prometheus_node_exporter//:node_exporter": "/metrics/bin/node_exporter", |
| 62 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 63 | # Hyperkube |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 64 | "//metropolis/node/kubernetes/hyperkube": "/kubernetes/bin/kube", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 65 | |
Lorenz Brun | 339582b | 2020-07-29 18:13:35 +0200 | [diff] [blame] | 66 | # CoreDNS |
| 67 | "@com_github_coredns_coredns//:coredns": "/kubernetes/bin/coredns", |
| 68 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 69 | # runsc/gVisor |
Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 70 | "@dev_gvisor_gvisor//runsc": "/containerd/bin/runsc", |
| 71 | "@dev_gvisor_gvisor//shim": "/containerd/bin/containerd-shim-runsc-v1", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 72 | |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 73 | # runc (runtime in files_cc because of cgo) |
| 74 | "@com_github_containerd_containerd//cmd/containerd-shim-runc-v2": "/containerd/bin/containerd-shim-runc-v2", |
| 75 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 76 | # Containerd |
| 77 | "@com_github_containerd_containerd//cmd/containerd": "/containerd/bin/containerd", |
| 78 | |
| 79 | # Containerd config files |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 80 | "//metropolis/node/kubernetes/containerd:runsc.toml": "/containerd/conf/runsc.toml", |
| 81 | "//metropolis/node/kubernetes/containerd:config.toml": "/containerd/conf/config.toml", |
| 82 | "//metropolis/node/kubernetes/containerd:cnispec.gojson": "/containerd/conf/cnispec.gojson", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 83 | |
Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 84 | # Containerd preseed bundles |
Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 85 | "//metropolis/test/e2e/preseedtest:preseedtest_image.tar": "/containerd/preseed/k8s.io/preseedtest.tar", |
Serge Bazanski | 9104e38 | 2023-04-04 20:08:21 +0200 | [diff] [blame] | 86 | "//metropolis/test/e2e/selftest:selftest_image.tar": "/containerd/preseed/k8s.io/selftest.tar", |
Lorenz Brun | 30167f5 | 2021-03-17 17:49:01 +0100 | [diff] [blame] | 87 | "//metropolis/vm/smoketest:smoketest_container.tar": "/containerd/preseed/k8s.io/smoketest.tar", |
Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 88 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 89 | # CNI Plugins |
| 90 | "@com_github_containernetworking_plugins//plugins/main/loopback": "/containerd/bin/cni/loopback", |
| 91 | "@com_github_containernetworking_plugins//plugins/main/ptp": "/containerd/bin/cni/ptp", |
| 92 | "@com_github_containernetworking_plugins//plugins/ipam/host-local": "/containerd/bin/cni/host-local", |
Serge Bazanski | c3ae758 | 2020-06-08 17:15:26 +0200 | [diff] [blame] | 93 | |
Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 94 | # Delve |
| 95 | "@com_github_go_delve_delve//cmd/dlv:dlv": "/dlv", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 96 | }, |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 97 | files_cc = { |
Serge Bazanski | eac8f73 | 2021-10-05 23:30:37 +0200 | [diff] [blame] | 98 | "//metropolis/node/core/minit": "/init", |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 99 | # runc runtime, with cgo |
| 100 | "@com_github_opencontainers_runc//:runc": "/containerd/bin/runc", |
Lorenz Brun | ddd6caf | 2021-03-04 17:16:04 +0100 | [diff] [blame] | 101 | "@xfsprogs//:mkfs": "/bin/mkfs.xfs", |
Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 102 | "@chrony//:chrony": "/time/chrony", |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 103 | }, |
Serge Bazanski | a393814 | 2022-04-04 17:04:47 +0200 | [diff] [blame] | 104 | fsspecs = [ |
| 105 | ":erofs-layout.fsspec", |
| 106 | "//metropolis/node/build:earlydev.fsspec", |
| 107 | ":firmware", |
| 108 | ], |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 109 | symlinks = { |
| 110 | "/ephemeral/machine-id": "/etc/machine-id", |
| 111 | "/ephemeral/hosts": "/etc/hosts", |
| 112 | }, |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 113 | ) |
| 114 | |
Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 115 | verity_image( |
| 116 | name = "verity_rootfs", |
| 117 | source = ":rootfs", |
| 118 | ) |
| 119 | |
Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 120 | efi_unified_kernel_image( |
| 121 | name = "kernel_efi", |
Lorenz Brun | f0b22ff | 2023-05-02 16:04:20 +0200 | [diff] [blame] | 122 | cmdline = "console=ttyS0,115200 console=ttyS1,115200 console=tty0 quiet rootfstype=erofs init=/init", |
Lorenz Brun | b6c0aa9 | 2022-02-24 17:53:40 +0100 | [diff] [blame] | 123 | initrd = [":ucode"], |
Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 124 | kernel = "//third_party/linux", |
| 125 | os_release = ":os-release-info", |
Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 126 | verity = ":verity_rootfs", |
Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 127 | ) |
| 128 | |
Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 129 | # An intermediary "bundle" format until we finalize the actual bundle format. This is NOT stable until migrated |
| 130 | # to the actual bundle format. |
| 131 | # TODO(lorenz): Replace this |
| 132 | pkg_zip( |
Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 133 | name = "bundle", |
Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 134 | srcs = [ |
| 135 | ":kernel_efi", |
Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 136 | ":verity_rootfs", |
Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 137 | ], |
Lorenz Brun | f8ede09 | 2021-11-08 20:50:57 +0100 | [diff] [blame] | 138 | visibility = ["//visibility:public"], |
Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 139 | ) |
| 140 | |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 141 | genrule( |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 142 | name = "image", |
| 143 | srcs = [ |
Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 144 | ":kernel_efi", |
Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 145 | ":verity_rootfs", |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 146 | ], |
| 147 | outs = [ |
Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 148 | "node.img", |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 149 | ], |
| 150 | cmd = """ |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 151 | $(location //metropolis/node/build/mkimage) \ |
Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 152 | -efi $(location :kernel_efi) \ |
Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 153 | -system $(location :verity_rootfs) \ |
Leopold Schabel | 6549307 | 2019-11-06 13:40:44 +0000 | [diff] [blame] | 154 | -out $@ |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 155 | """, |
Lorenz Brun | 0bcaaee | 2019-11-06 12:42:39 +0100 | [diff] [blame] | 156 | tools = [ |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 157 | "//metropolis/node/build/mkimage", |
Lorenz Brun | 0bcaaee | 2019-11-06 12:42:39 +0100 | [diff] [blame] | 158 | ], |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 159 | visibility = [ |
Mateusz Zalega | fed8fe5 | 2022-07-14 16:19:35 +0200 | [diff] [blame] | 160 | "//metropolis/cli/metroctl/test:__subpackages__", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 161 | "//metropolis/test/e2e:__subpackages__", |
Serge Bazanski | f12bedf | 2021-01-15 16:58:50 +0100 | [diff] [blame] | 162 | "//metropolis/test/launch:__subpackages__", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 163 | ], |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 164 | ) |
| 165 | |
Leopold Schabel | 957c5b1 | 2021-12-04 01:34:40 +0100 | [diff] [blame] | 166 | # Create a tar.gz of the image, suitable for importing to GCP as a custom image. |
| 167 | # (see https://cloud.google.com/compute/docs/import/import-existing-image#create_image_file) |
| 168 | # |
| 169 | # We can't use Bazel's "pkg_tar" rule because it insists on adding a "./" prefix to the |
| 170 | # file name inside the archive, which is not compatible with GCP's importer. |
| 171 | genrule( |
| 172 | name = "image_gcp", |
| 173 | srcs = [ |
| 174 | ":image", |
| 175 | ], |
| 176 | outs = [ |
| 177 | "node.tar.gz", |
| 178 | ], |
| 179 | cmd = """ |
| 180 | # make it reproducible and fast (it doesn't compress well anyway) |
| 181 | export GZIP="--no-name --fast" |
| 182 | |
| 183 | ln -rs $< $(@D)/disk.raw # GCP insists it be called "disk.raw" |
| 184 | |
| 185 | cd $(@D) |
| 186 | tar --format=oldgnu --mtime='1970-01-01' -Sczhf node.tar.gz disk.raw |
| 187 | """, |
| 188 | ) |
| 189 | |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 190 | genrule( |
| 191 | name = "swtpm_data", |
| 192 | outs = [ |
| 193 | "tpm/tpm2-00.permall", |
| 194 | "tpm/signkey.pem", |
| 195 | "tpm/issuercert.pem", |
| 196 | ], |
| 197 | cmd = """ |
| 198 | mkdir -p tpm/ca |
| 199 | |
| 200 | cat <<EOF > tpm/swtpm.conf |
| 201 | create_certs_tool= /usr/share/swtpm/swtpm-localca |
| 202 | create_certs_tool_config = tpm/swtpm-localca.conf |
| 203 | create_certs_tool_options = /etc/swtpm-localca.options |
| 204 | EOF |
| 205 | |
| 206 | cat <<EOF > tpm/swtpm-localca.conf |
| 207 | statedir = tpm/ca |
| 208 | signingkey = tpm/ca/signkey.pem |
| 209 | issuercert = tpm/ca/issuercert.pem |
| 210 | certserial = tpm/ca/certserial |
| 211 | EOF |
| 212 | |
| 213 | swtpm_setup \ |
| 214 | --tpmstate tpm \ |
| 215 | --create-ek-cert \ |
| 216 | --create-platform-cert \ |
| 217 | --allow-signing \ |
| 218 | --tpm2 \ |
| 219 | --display \ |
| 220 | --pcr-banks sha1,sha256,sha384,sha512 \ |
| 221 | --config tpm/swtpm.conf |
| 222 | |
| 223 | cp tpm/tpm2-00.permall $(location tpm/tpm2-00.permall) |
| 224 | cp tpm/ca/issuercert.pem $(location tpm/issuercert.pem) |
| 225 | cp tpm/ca/signkey.pem $(location tpm/signkey.pem) |
| 226 | """, |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 227 | visibility = [ |
Mateusz Zalega | fed8fe5 | 2022-07-14 16:19:35 +0200 | [diff] [blame] | 228 | "//metropolis/cli/metroctl/test:__subpackages__", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 229 | "//metropolis/test/e2e:__subpackages__", |
Serge Bazanski | f12bedf | 2021-01-15 16:58:50 +0100 | [diff] [blame] | 230 | "//metropolis/test/launch:__subpackages__", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 231 | ], |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 232 | ) |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 233 | |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 234 | load("//metropolis/node/build/genosrelease:defs.bzl", "os_release") |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 235 | |
| 236 | os_release( |
| 237 | name = "os-release-info", |
Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 238 | os_id = "metropolis-node", |
| 239 | os_name = "Metropolis Node", |
| 240 | stamp_var = "STABLE_METROPOLIS_version", |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 241 | ) |