blob: c40c9ed77815cf54f0ee030bd6afeddb4f61c3ac [file] [log] [blame]
Lorenz Brune6573102021-11-02 14:15:37 +01001package main
2
3import (
Serge Bazanski97783222021-12-14 16:04:26 +01004 "bytes"
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +02005 "context"
Lorenz Brune6573102021-11-02 14:15:37 +01006 "crypto/ed25519"
Lorenz Brun7a510192022-07-04 15:31:38 +00007 _ "embed"
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +02008 "fmt"
Lorenz Brune6573102021-11-02 14:15:37 +01009 "os"
Tim Windelschmidtb765f242024-05-08 01:40:02 +020010 "os/signal"
Lorenz Brune6573102021-11-02 14:15:37 +010011
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010012 "github.com/bazelbuild/rules_go/go/runfiles"
Lorenz Brune6573102021-11-02 14:15:37 +010013 "github.com/spf13/cobra"
14
Tim Windelschmidt2a1d1b22024-02-06 07:07:42 +010015 "source.monogon.dev/metropolis/proto/api"
16 cpb "source.monogon.dev/metropolis/proto/common"
17
Jan Schära9b060b2024-08-07 10:42:29 +020018 "source.monogon.dev/metropolis/cli/flagdefs"
Lorenz Brune6573102021-11-02 14:15:37 +010019 "source.monogon.dev/metropolis/cli/metroctl/core"
Jan Schär39f4f5c2024-10-29 09:41:50 +010020 common "source.monogon.dev/metropolis/node"
Tim Windelschmidt9f21f532024-05-07 15:14:20 +020021 "source.monogon.dev/osbase/blkio"
22 "source.monogon.dev/osbase/fat32"
Lorenz Brune6573102021-11-02 14:15:37 +010023)
24
25var installCmd = &cobra.Command{
Lorenz Brun7a510192022-07-04 15:31:38 +000026 Short: "Contains subcommands to install Metropolis via different media.",
Lorenz Brune6573102021-11-02 14:15:37 +010027 Use: "install",
28}
29
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020030// bootstrap is a flag controlling node parameters included in the installer
31// image. If set, the installed node will bootstrap a new cluster. Otherwise,
32// it will try to connect to the cluster which endpoints were provided with
33// the --endpoints flag.
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010034var bootstrap = installCmd.PersistentFlags().Bool("bootstrap", false, "Create a bootstrap installer image.")
Jan Schära9b060b2024-08-07 10:42:29 +020035var bootstrapTPMMode = flagdefs.TPMModePflag(installCmd.PersistentFlags(), "bootstrap-tpm-mode", cpb.ClusterConfiguration_TPM_MODE_REQUIRED, "TPM mode to set on cluster")
36var bootstrapStorageSecurityPolicy = flagdefs.StorageSecurityPolicyPflag(installCmd.PersistentFlags(), "bootstrap-storage-security", cpb.ClusterConfiguration_STORAGE_SECURITY_POLICY_NEEDS_ENCRYPTION_AND_AUTHENTICATION, "Storage security policy to set on cluster")
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010037var bundlePath = installCmd.PersistentFlags().StringP("bundle", "b", "", "Path to the Metropolis bundle to be installed")
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020038
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020039func makeNodeParams() (*api.NodeParameters, error) {
Tim Windelschmidtb765f242024-05-08 01:40:02 +020040 ctx, _ := signal.NotifyContext(context.Background(), os.Interrupt)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020041
Mateusz Zalega8234c162022-07-08 17:05:50 +020042 if err := os.MkdirAll(flags.configPath, 0700); err != nil && !os.IsExist(err) {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020043 return nil, fmt.Errorf("failed to create config directory: %w", err)
Lorenz Brune6573102021-11-02 14:15:37 +010044 }
Lorenz Brune6573102021-11-02 14:15:37 +010045
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020046 var params *api.NodeParameters
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010047 if *bootstrap {
Jan Schär39f4f5c2024-10-29 09:41:50 +010048 if flags.cluster == "" {
49 return nil, fmt.Errorf("when bootstrapping a cluster, the --cluster parameter is required")
50 }
51 if err := common.ValidateClusterDomain(flags.cluster); err != nil {
52 return nil, fmt.Errorf("invalid cluster domain: %w", err)
53 }
54
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010055 // TODO(lorenz): Have a key management story for this
Serge Bazanskicf23ebc2023-03-14 17:02:04 +010056 priv, err := core.GetOrMakeOwnerKey(flags.configPath)
57 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020058 return nil, fmt.Errorf("failed to generate or get owner key: %w", err)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020059 }
Serge Bazanskicf23ebc2023-03-14 17:02:04 +010060 pub := priv.Public().(ed25519.PublicKey)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020061 params = &api.NodeParameters{
62 Cluster: &api.NodeParameters_ClusterBootstrap_{
63 ClusterBootstrap: &api.NodeParameters_ClusterBootstrap{
Serge Bazanskicf23ebc2023-03-14 17:02:04 +010064 OwnerPublicKey: pub,
Serge Bazanskibdc803b2023-03-27 10:55:09 +020065 InitialClusterConfiguration: &cpb.ClusterConfiguration{
Jan Schär39f4f5c2024-10-29 09:41:50 +010066 ClusterDomain: flags.cluster,
Jan Schära9b060b2024-08-07 10:42:29 +020067 StorageSecurityPolicy: *bootstrapStorageSecurityPolicy,
68 TpmMode: *bootstrapTPMMode,
Serge Bazanskibdc803b2023-03-27 10:55:09 +020069 },
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020070 },
Lorenz Brune6573102021-11-02 14:15:37 +010071 },
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020072 }
73 } else {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020074 cc, err := dialAuthenticated(ctx)
75 if err != nil {
76 return nil, fmt.Errorf("while dialing node: %w", err)
77 }
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020078 mgmt := api.NewManagementClient(cc)
79 resT, err := mgmt.GetRegisterTicket(ctx, &api.GetRegisterTicketRequest{})
80 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020081 return nil, fmt.Errorf("while receiving register ticket: %w", err)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020082 }
83 resI, err := mgmt.GetClusterInfo(ctx, &api.GetClusterInfoRequest{})
84 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020085 return nil, fmt.Errorf("while receiving cluster directory: %w", err)
Mateusz Zalegad5f2f7a2022-07-05 18:48:56 +020086 }
87
88 params = &api.NodeParameters{
89 Cluster: &api.NodeParameters_ClusterRegister_{
90 ClusterRegister: &api.NodeParameters_ClusterRegister{
91 RegisterTicket: resT.Ticket,
92 ClusterDirectory: resI.ClusterDirectory,
93 CaCertificate: resI.CaCertificate,
94 },
95 },
96 }
Lorenz Brune6573102021-11-02 14:15:37 +010097 }
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +020098 return params, nil
Tim Windelschmidt7006caf2024-02-27 16:49:39 +010099}
Lorenz Brune6573102021-11-02 14:15:37 +0100100
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200101func external(name, datafilePath string, flag *string) (fat32.SizedReader, error) {
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100102 if flag == nil || *flag == "" {
103 rPath, err := runfiles.Rlocation(datafilePath)
104 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200105 return nil, fmt.Errorf("no %s specified", name)
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100106 }
107 df, err := os.ReadFile(rPath)
108 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200109 return nil, fmt.Errorf("can't read file: %w", err)
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100110 }
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200111 return bytes.NewReader(df), nil
Lorenz Brune6573102021-11-02 14:15:37 +0100112 }
113
Tim Windelschmidt9ded9942024-04-08 21:30:17 +0200114 f, err := blkio.NewFileReader(*flag)
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100115 if err != nil {
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200116 return nil, fmt.Errorf("failed to open specified %s: %w", name, err)
Lorenz Brune6573102021-11-02 14:15:37 +0100117 }
Tim Windelschmidt7006caf2024-02-27 16:49:39 +0100118
Tim Windelschmidt0b4fb8c2024-09-18 17:34:23 +0200119 return f, nil
Lorenz Brune6573102021-11-02 14:15:37 +0100120}
121
122func init() {
123 rootCmd.AddCommand(installCmd)
Lorenz Brune6573102021-11-02 14:15:37 +0100124}