blob: 323c8ca1133f16ef555663e31fd53cf34f37187f [file] [log] [blame]
Serge Bazanski42e61c62021-03-18 15:07:18 +01001// Copyright 2020 The Monogon Project Authors.
2//
3// SPDX-License-Identifier: Apache-2.0
4//
5// Licensed under the Apache License, Version 2.0 (the "License");
6// you may not use this file except in compliance with the License.
7// You may obtain a copy of the License at
8//
9// http://www.apache.org/licenses/LICENSE-2.0
10//
11// Unless required by applicable law or agreed to in writing, software
12// distributed under the License is distributed on an "AS IS" BASIS,
13// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14// See the License for the specific language governing permissions and
15// limitations under the License.
16
Serge Bazanski37110c32023-03-01 13:57:27 +000017// Package cluster implements low-level clustering logic, especially logic
18// regarding to bootstrapping, registering into and joining a cluster. Its goal
19// is to provide the rest of the node code with the following:
20// - A mounted plaintext storage.
21// - Node credentials/identity.
22// - A locally running etcd server if the node is supposed to run one, and a
23// client connection to that etcd cluster if so.
24// - The state of the cluster as seen by the node, to enable code to respond to
25// node lifecycle changes.
Serge Bazanski42e61c62021-03-18 15:07:18 +010026package cluster
27
28import (
Serge Bazanskia959cbd2021-06-17 15:56:51 +020029 "context"
30 "errors"
Serge Bazanski42e61c62021-03-18 15:07:18 +010031 "fmt"
32
Serge Bazanskia959cbd2021-06-17 15:56:51 +020033 "source.monogon.dev/metropolis/node/core/localstorage"
34 "source.monogon.dev/metropolis/node/core/network"
Serge Bazanski6dff6d62022-01-28 18:15:14 +010035 "source.monogon.dev/metropolis/node/core/roleserve"
Lorenz Brun35fcf032023-06-29 04:15:58 +020036 "source.monogon.dev/metropolis/node/core/update"
Serge Bazanskia959cbd2021-06-17 15:56:51 +020037 "source.monogon.dev/metropolis/pkg/supervisor"
38 apb "source.monogon.dev/metropolis/proto/api"
Mateusz Zalega2930e992022-04-25 12:52:35 +020039 cpb "source.monogon.dev/metropolis/proto/common"
Serge Bazanski42e61c62021-03-18 15:07:18 +010040)
41
Serge Bazanskia959cbd2021-06-17 15:56:51 +020042type Manager struct {
43 storageRoot *localstorage.Root
44 networkService *network.Service
Serge Bazanski6dff6d62022-01-28 18:15:14 +010045 roleServer *roleserve.Service
Lorenz Brun35fcf032023-06-29 04:15:58 +020046 updateService *update.Service
Lorenz Brun85ad26a2023-03-27 17:00:00 +020047 nodeParams *apb.NodeParameters
Serge Bazanski5df62ba2023-03-22 17:56:46 +010048 haveTPM bool
Serge Bazanskia959cbd2021-06-17 15:56:51 +020049
Serge Bazanskife5192d2023-03-16 11:33:56 +010050 oneway chan struct{}
Serge Bazanskia959cbd2021-06-17 15:56:51 +020051}
52
53// NewManager creates a new cluster Manager. The given localstorage Root must
54// be places, but not yet started (and will be started as the Manager makes
55// progress). The given network Service must already be running.
Lorenz Brun35fcf032023-06-29 04:15:58 +020056func NewManager(storageRoot *localstorage.Root, networkService *network.Service, rs *roleserve.Service, updateService *update.Service, nodeParams *apb.NodeParameters, haveTPM bool) *Manager {
Serge Bazanskia959cbd2021-06-17 15:56:51 +020057 return &Manager{
58 storageRoot: storageRoot,
59 networkService: networkService,
Serge Bazanski6dff6d62022-01-28 18:15:14 +010060 roleServer: rs,
Lorenz Brun35fcf032023-06-29 04:15:58 +020061 updateService: updateService,
Lorenz Brun85ad26a2023-03-27 17:00:00 +020062 nodeParams: nodeParams,
Serge Bazanski5df62ba2023-03-22 17:56:46 +010063 haveTPM: haveTPM,
Serge Bazanskife5192d2023-03-16 11:33:56 +010064 oneway: make(chan struct{}),
Serge Bazanskia959cbd2021-06-17 15:56:51 +020065 }
66}
67
Serge Bazanskia959cbd2021-06-17 15:56:51 +020068// Run is the runnable of the Manager, to be started using the Supervisor. It
69// is one-shot, and should not be restarted.
70func (m *Manager) Run(ctx context.Context) error {
Serge Bazanskife5192d2023-03-16 11:33:56 +010071 select {
72 case <-m.oneway:
Serge Bazanskia959cbd2021-06-17 15:56:51 +020073 return fmt.Errorf("cannot restart cluster manager")
Serge Bazanskife5192d2023-03-16 11:33:56 +010074 default:
Serge Bazanskia959cbd2021-06-17 15:56:51 +020075 }
Serge Bazanskife5192d2023-03-16 11:33:56 +010076 close(m.oneway)
Serge Bazanskia959cbd2021-06-17 15:56:51 +020077
Serge Bazanskie4a4ce12023-03-22 18:29:54 +010078 // Try sealed configuration first.
Serge Bazanski98054a12023-06-14 18:16:21 +020079 configuration, err := m.storageRoot.ESP.Metropolis.SealedConfiguration.Unseal(cpb.NodeTPMUsage_NODE_TPM_PRESENT_AND_USED)
Serge Bazanskia959cbd2021-06-17 15:56:51 +020080 if err == nil {
81 supervisor.Logger(ctx).Info("Sealed configuration present. attempting to join cluster")
Mateusz Zalega2930e992022-04-25 12:52:35 +020082
83 // Read Cluster Directory and unmarshal it. Since the node is already
84 // registered with the cluster, the directory won't be bootstrapped from
85 // Node Parameters.
86 cd, err := m.storageRoot.ESP.Metropolis.ClusterDirectory.Unmarshal()
87 if err != nil {
88 return fmt.Errorf("while reading cluster directory: %w", err)
89 }
Serge Bazanskie4a4ce12023-03-22 18:29:54 +010090 return m.join(ctx, configuration, cd, true)
Serge Bazanskia959cbd2021-06-17 15:56:51 +020091 }
92
Serge Bazanski98054a12023-06-14 18:16:21 +020093 if !errors.Is(err, localstorage.ErrNoSealed) && !errors.Is(err, localstorage.ErrSealedCorrupted) {
Serge Bazanskia959cbd2021-06-17 15:56:51 +020094 return fmt.Errorf("unexpected sealed config error: %w", err)
95 }
96
Serge Bazanski98054a12023-06-14 18:16:21 +020097 configuration, err = m.storageRoot.ESP.Metropolis.SealedConfiguration.Unseal(cpb.NodeTPMUsage_NODE_TPM_NOT_PRESENT)
Serge Bazanskie4a4ce12023-03-22 18:29:54 +010098 if err == nil {
99 supervisor.Logger(ctx).Info("Non-sealed configuration present. attempting to join cluster")
100
101 // Read Cluster Directory and unmarshal it. Since the node is already
102 // registered with the cluster, the directory won't be bootstrapped from
103 // Node Parameters.
104 cd, err := m.storageRoot.ESP.Metropolis.ClusterDirectory.Unmarshal()
105 if err != nil {
106 return fmt.Errorf("while reading cluster directory: %w", err)
107 }
108 return m.join(ctx, configuration, cd, false)
109 }
110
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200111 supervisor.Logger(ctx).Info("No sealed configuration, looking for node parameters")
112
Lorenz Brun85ad26a2023-03-27 17:00:00 +0200113 switch inner := m.nodeParams.Cluster.(type) {
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200114 case *apb.NodeParameters_ClusterBootstrap_:
Serge Bazanski5839e972021-11-16 15:46:19 +0100115 err = m.bootstrap(ctx, inner.ClusterBootstrap)
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200116 case *apb.NodeParameters_ClusterRegister_:
Serge Bazanski5839e972021-11-16 15:46:19 +0100117 err = m.register(ctx, inner.ClusterRegister)
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200118 default:
Serge Bazanski5839e972021-11-16 15:46:19 +0100119 err = fmt.Errorf("node parameters misconfigured: neither cluster_bootstrap nor cluster_register set")
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200120 }
Serge Bazanski5839e972021-11-16 15:46:19 +0100121
122 if err == nil {
123 supervisor.Logger(ctx).Info("Cluster enrolment done.")
Serge Bazanskife5192d2023-03-16 11:33:56 +0100124 return nil
Serge Bazanski5839e972021-11-16 15:46:19 +0100125 }
126 return err
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200127}