Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 1 | genrule( |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 2 | name = "initramfs", |
| 3 | srcs = [ |
| 4 | "//core/cmd/init", |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 5 | "//core/cmd/kube", |
Serge Bazanski | 2fb13a8 | 2020-02-11 12:41:37 +0100 | [diff] [blame] | 6 | "//third_party/xfsprogs:mkfs.xfs", |
Serge Bazanski | bb7db92 | 2020-04-30 12:43:10 +0200 | [diff] [blame] | 7 | "@io_k8s_kubernetes//cmd/kubelet:_kubelet-pure", |
| 8 | "@com_github_containerd_containerd//cmd/containerd", |
Serge Bazanski | bb7db92 | 2020-04-30 12:43:10 +0200 | [diff] [blame] | 9 | "@com_github_containerd_containerd//cmd/containerd-shim-runc-v2", |
| 10 | "@com_github_containernetworking_plugins//plugins/main/loopback", |
| 11 | "@com_github_containernetworking_plugins//plugins/main/ptp", |
| 12 | "@com_github_containernetworking_plugins//plugins/ipam/host-local", |
Serge Bazanski | bb7db92 | 2020-04-30 12:43:10 +0200 | [diff] [blame] | 13 | "@com_github_google_gvisor//runsc", |
Lorenz Brun | c88c82d | 2020-05-08 14:35:04 +0200 | [diff] [blame] | 14 | "@com_github_google_gvisor_containerd_shim//cmd/containerd-shim-runsc-v1", |
| 15 | "//core/internal/containerd:ptp.json", |
| 16 | "//core/internal/containerd:loopback.json", |
| 17 | "//core/internal/containerd:config.toml", |
| 18 | "//core/internal/containerd:runsc.toml", |
| 19 | "@cacerts//file", |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 20 | ":os-release-info", |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 21 | ], |
| 22 | outs = [ |
| 23 | "initramfs.cpio.lz4", |
| 24 | ], |
| 25 | cmd = """ |
| 26 | $(location @linux//:gen_init_cpio) - <<- 'EOF' | lz4 -l > \"$@\" |
| 27 | dir /dev 0755 0 0 |
| 28 | nod /dev/console 0600 0 0 c 5 1 |
| 29 | nod /dev/null 0644 0 0 c 1 3 |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 30 | nod /dev/kmsg 0644 0 0 c 1 11 |
Lorenz Brun | c88c82d | 2020-05-08 14:35:04 +0200 | [diff] [blame] | 31 | nod /dev/ptmx 0644 0 0 c 5 2 |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 32 | file /init $(location //core/cmd/init) 0755 0 0 |
Lorenz Brun | c88c82d | 2020-05-08 14:35:04 +0200 | [diff] [blame] | 33 | dir /etc 0755 0 0 |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 34 | file /etc/os-release $(location :os-release-info) 0644 0 0 |
Lorenz Brun | c88c82d | 2020-05-08 14:35:04 +0200 | [diff] [blame] | 35 | dir /etc/ssl 0755 0 0 |
| 36 | file /etc/ssl/cert.pem $(location @cacerts//file) 0444 0 0 |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 37 | dir /bin 0755 0 0 |
Serge Bazanski | 2fb13a8 | 2020-02-11 12:41:37 +0100 | [diff] [blame] | 38 | file /bin/mkfs.xfs $(location //third_party/xfsprogs:mkfs.xfs) 0755 0 0 |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 39 | dir /kubernetes 0755 0 0 |
| 40 | dir /kubernetes/bin 0755 0 0 |
| 41 | file /kubernetes/bin/kube $(location //core/cmd/kube) 0755 0 0 |
| 42 | dir /kubernetes/conf 0755 0 0 |
| 43 | dir /kubernetes/conf/flexvolume-plugins 0755 0 0 |
Serge Bazanski | bb7db92 | 2020-04-30 12:43:10 +0200 | [diff] [blame] | 44 | dir /containerd 0755 0 0 |
Lorenz Brun | c88c82d | 2020-05-08 14:35:04 +0200 | [diff] [blame] | 45 | dir /containerd/bin 0755 0 0 |
| 46 | file /containerd/bin/containerd $(location @com_github_containerd_containerd//cmd/containerd) 0755 0 0 |
| 47 | file /containerd/bin/containerd-shim-runsc-v1 $(location @com_github_google_gvisor_containerd_shim//cmd/containerd-shim-runsc-v1) 0755 0 0 |
| 48 | file /containerd/bin/runsc $(location @com_github_google_gvisor//runsc) 0755 0 0 |
| 49 | dir /containerd/bin/cni 0755 0 0 |
| 50 | file /containerd/bin/cni/loopback $(location @com_github_containernetworking_plugins//plugins/main/loopback) 0755 0 0 |
| 51 | file /containerd/bin/cni/ptp $(location @com_github_containernetworking_plugins//plugins/main/ptp) 0755 0 0 |
| 52 | file /containerd/bin/cni/host-local $(location @com_github_containernetworking_plugins//plugins/ipam/host-local) 0755 0 0 |
| 53 | dir /containerd/run 0755 0 0 |
| 54 | dir /containerd/conf 0755 0 0 |
| 55 | dir /containerd/conf/cni 0755 0 0 |
| 56 | file /containerd/conf/cni/10-ptp.conf $(location //core/internal/containerd:ptp.json) 0444 0 0 |
| 57 | file /containerd/conf/cni/99-loopback.conf $(location //core/internal/containerd:loopback.json) 0444 0 0 |
| 58 | file /containerd/conf/config.toml $(location //core/internal/containerd:config.toml) 0444 0 0 |
| 59 | file /containerd/conf/runsc.toml $(location //core/internal/containerd:runsc.toml) 0444 0 0 |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 60 | EOF |
| 61 | """, |
| 62 | tools = [ |
| 63 | "@linux//:gen_init_cpio", |
| 64 | ], |
| 65 | ) |
| 66 | |
| 67 | genrule( |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 68 | name = "image", |
| 69 | srcs = [ |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 70 | "//third_party/linux:bzImage", |
| 71 | ":initramfs", |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 72 | ], |
| 73 | outs = [ |
| 74 | "smalltown.img", |
| 75 | ], |
| 76 | cmd = """ |
Serge Bazanski | dcb3a56 | 2020-02-03 13:44:44 +0100 | [diff] [blame] | 77 | $(location //core/cmd/mkimage) \ |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 78 | -efi $(location //third_party/linux:bzImage) \ |
| 79 | -initramfs $(location :initramfs) \ |
Leopold Schabel | 6549307 | 2019-11-06 13:40:44 +0000 | [diff] [blame] | 80 | -out $@ |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 81 | """, |
Lorenz Brun | 0bcaaee | 2019-11-06 12:42:39 +0100 | [diff] [blame] | 82 | tools = [ |
Serge Bazanski | dcb3a56 | 2020-02-03 13:44:44 +0100 | [diff] [blame] | 83 | "//core/cmd/mkimage", |
Lorenz Brun | 0bcaaee | 2019-11-06 12:42:39 +0100 | [diff] [blame] | 84 | ], |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 85 | visibility = ["//visibility:public"], |
| 86 | ) |
| 87 | |
| 88 | genrule( |
| 89 | name = "swtpm_data", |
| 90 | outs = [ |
| 91 | "tpm/tpm2-00.permall", |
| 92 | "tpm/signkey.pem", |
| 93 | "tpm/issuercert.pem", |
| 94 | ], |
| 95 | cmd = """ |
| 96 | mkdir -p tpm/ca |
| 97 | |
| 98 | cat <<EOF > tpm/swtpm.conf |
| 99 | create_certs_tool= /usr/share/swtpm/swtpm-localca |
| 100 | create_certs_tool_config = tpm/swtpm-localca.conf |
| 101 | create_certs_tool_options = /etc/swtpm-localca.options |
| 102 | EOF |
| 103 | |
| 104 | cat <<EOF > tpm/swtpm-localca.conf |
| 105 | statedir = tpm/ca |
| 106 | signingkey = tpm/ca/signkey.pem |
| 107 | issuercert = tpm/ca/issuercert.pem |
| 108 | certserial = tpm/ca/certserial |
| 109 | EOF |
| 110 | |
| 111 | swtpm_setup \ |
| 112 | --tpmstate tpm \ |
| 113 | --create-ek-cert \ |
| 114 | --create-platform-cert \ |
| 115 | --allow-signing \ |
| 116 | --tpm2 \ |
| 117 | --display \ |
| 118 | --pcr-banks sha1,sha256,sha384,sha512 \ |
| 119 | --config tpm/swtpm.conf |
| 120 | |
| 121 | cp tpm/tpm2-00.permall $(location tpm/tpm2-00.permall) |
| 122 | cp tpm/ca/issuercert.pem $(location tpm/issuercert.pem) |
| 123 | cp tpm/ca/signkey.pem $(location tpm/signkey.pem) |
| 124 | """, |
| 125 | visibility = ["//visibility:public"], |
| 126 | ) |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 127 | |
| 128 | load("//core/build/genosrelease:defs.bzl", "os_release") |
| 129 | |
| 130 | os_release( |
| 131 | name = "os-release-info", |
| 132 | os_id = "smalltown", |
| 133 | os_name = "Smalltown", |
| 134 | stamp_var = "STABLE_SIGNOS_version", |
| 135 | ) |