blob: fff13e9b6b6adb1b095d1702ec111cb2919fa5cb [file] [log] [blame]
Lorenz Brune6573102021-11-02 14:15:37 +01001package main
2
3import (
Serge Bazanski97783222021-12-14 16:04:26 +01004 "bytes"
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +02005 "context"
Lorenz Brune6573102021-11-02 14:15:37 +01006 "crypto/ed25519"
Lorenz Brun7a510192022-07-04 15:31:38 +00007 _ "embed"
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +02008 "fmt"
Lorenz Brune6573102021-11-02 14:15:37 +01009 "os"
Tim Windelschmidtb765f242024-05-08 01:40:02 +020010 "os/signal"
Lorenz Brune6573102021-11-02 14:15:37 +010011
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010012 "github.com/bazelbuild/rules_go/go/runfiles"
Lorenz Brune6573102021-11-02 14:15:37 +010013 "github.com/spf13/cobra"
14
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010015 "source.monogon.dev/metropolis/proto/api"
16 cpb "source.monogon.dev/metropolis/proto/common"
17
Jan Schära9b060b2024-08-07 10:42:29 +020018 "source.monogon.dev/metropolis/cli/flagdefs"
Lorenz Brune6573102021-11-02 14:15:37 +010019 "source.monogon.dev/metropolis/cli/metroctl/core"
Tim Windelschmidt9f21f532024-05-07 15:14:20 +020020 "source.monogon.dev/osbase/blkio"
21 "source.monogon.dev/osbase/fat32"
Lorenz Brune6573102021-11-02 14:15:37 +010022)
23
24var installCmd = &cobra.Command{
Lorenz Brun7a510192022-07-04 15:31:38 +000025 Short: "Contains subcommands to install Metropolis via different media.",
Lorenz Brune6573102021-11-02 14:15:37 +010026 Use: "install",
27}
28
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020029// bootstrap is a flag controlling node parameters included in the installer
30// image. If set, the installed node will bootstrap a new cluster. Otherwise,
31// it will try to connect to the cluster which endpoints were provided with
32// the --endpoints flag.
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010033var bootstrap = installCmd.PersistentFlags().Bool("bootstrap", false, "Create a bootstrap installer image.")
Jan Schära9b060b2024-08-07 10:42:29 +020034var bootstrapTPMMode = flagdefs.TPMModePflag(installCmd.PersistentFlags(), "bootstrap-tpm-mode", cpb.ClusterConfiguration_TPM_MODE_REQUIRED, "TPM mode to set on cluster")
35var bootstrapStorageSecurityPolicy = flagdefs.StorageSecurityPolicyPflag(installCmd.PersistentFlags(), "bootstrap-storage-security", cpb.ClusterConfiguration_STORAGE_SECURITY_POLICY_NEEDS_ENCRYPTION_AND_AUTHENTICATION, "Storage security policy to set on cluster")
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010036var bundlePath = installCmd.PersistentFlags().StringP("bundle", "b", "", "Path to the Metropolis bundle to be installed")
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020037
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020038func makeNodeParams() (*api.NodeParameters, error) {
Tim Windelschmidtb765f242024-05-08 01:40:02 +020039 ctx, _ := signal.NotifyContext(context.Background(), os.Interrupt)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020040
Mateusz Zalega8234c162022-07-08 17:05:50 +020041 if err := os.MkdirAll(flags.configPath, 0700); err != nil && !os.IsExist(err) {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020042 return nil, fmt.Errorf("failed to create config directory: %w", err)
Lorenz Brune6573102021-11-02 14:15:37 +010043 }
Lorenz Brune6573102021-11-02 14:15:37 +010044
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020045 var params *api.NodeParameters
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010046 if *bootstrap {
47 // TODO(lorenz): Have a key management story for this
Serge Bazanskicf23ebc2023-03-14 17:02:04 +010048 priv, err := core.GetOrMakeOwnerKey(flags.configPath)
49 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020050 return nil, fmt.Errorf("failed to generate or get owner key: %w", err)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020051 }
Serge Bazanskicf23ebc2023-03-14 17:02:04 +010052 pub := priv.Public().(ed25519.PublicKey)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020053 params = &api.NodeParameters{
54 Cluster: &api.NodeParameters_ClusterBootstrap_{
55 ClusterBootstrap: &api.NodeParameters_ClusterBootstrap{
Serge Bazanskicf23ebc2023-03-14 17:02:04 +010056 OwnerPublicKey: pub,
Serge Bazanskibdc803b2023-03-27 10:55:09 +020057 InitialClusterConfiguration: &cpb.ClusterConfiguration{
Jan Schära9b060b2024-08-07 10:42:29 +020058 StorageSecurityPolicy: *bootstrapStorageSecurityPolicy,
59 TpmMode: *bootstrapTPMMode,
Serge Bazanskibdc803b2023-03-27 10:55:09 +020060 },
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020061 },
Lorenz Brune6573102021-11-02 14:15:37 +010062 },
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020063 }
64 } else {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020065 cc, err := dialAuthenticated(ctx)
66 if err != nil {
67 return nil, fmt.Errorf("while dialing node: %w", err)
68 }
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020069 mgmt := api.NewManagementClient(cc)
70 resT, err := mgmt.GetRegisterTicket(ctx, &api.GetRegisterTicketRequest{})
71 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020072 return nil, fmt.Errorf("while receiving register ticket: %w", err)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020073 }
74 resI, err := mgmt.GetClusterInfo(ctx, &api.GetClusterInfoRequest{})
75 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020076 return nil, fmt.Errorf("while receiving cluster directory: %w", err)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020077 }
78
79 params = &api.NodeParameters{
80 Cluster: &api.NodeParameters_ClusterRegister_{
81 ClusterRegister: &api.NodeParameters_ClusterRegister{
82 RegisterTicket: resT.Ticket,
83 ClusterDirectory: resI.ClusterDirectory,
84 CaCertificate: resI.CaCertificate,
85 },
86 },
87 }
Lorenz Brune6573102021-11-02 14:15:37 +010088 }
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020089 return params, nil
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010090}
Lorenz Brune6573102021-11-02 14:15:37 +010091
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020092func external(name, datafilePath string, flag *string) (fat32.SizedReader, error) {
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010093 if flag == nil || *flag == "" {
94 rPath, err := runfiles.Rlocation(datafilePath)
95 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020096 return nil, fmt.Errorf("no %s specified", name)
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010097 }
98 df, err := os.ReadFile(rPath)
99 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200100 return nil, fmt.Errorf("can't read file: %w", err)
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100101 }
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200102 return bytes.NewReader(df), nil
Lorenz Brune6573102021-11-02 14:15:37 +0100103 }
104
Tim Windelschmidt9ded9942024-04-08 21:30:17 +0200105 f, err := blkio.NewFileReader(*flag)
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100106 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200107 return nil, fmt.Errorf("failed to open specified %s: %w", name, err)
Lorenz Brune6573102021-11-02 14:15:37 +0100108 }
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100109
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200110 return f, nil
Lorenz Brune6573102021-11-02 14:15:37 +0100111}
112
113func init() {
114 rootCmd.AddCommand(installCmd)
Lorenz Brune6573102021-11-02 14:15:37 +0100115}