blob: 6049c17be04e0193b1ca0bae1b7c1861d74640bf [file] [log] [blame]
Serge Bazanski42e61c62021-03-18 15:07:18 +01001// Copyright 2020 The Monogon Project Authors.
2//
3// SPDX-License-Identifier: Apache-2.0
4//
5// Licensed under the Apache License, Version 2.0 (the "License");
6// you may not use this file except in compliance with the License.
7// You may obtain a copy of the License at
8//
9// http://www.apache.org/licenses/LICENSE-2.0
10//
11// Unless required by applicable law or agreed to in writing, software
12// distributed under the License is distributed on an "AS IS" BASIS,
13// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
14// See the License for the specific language governing permissions and
15// limitations under the License.
16
Serge Bazanski37110c32023-03-01 13:57:27 +000017// Package cluster implements low-level clustering logic, especially logic
18// regarding to bootstrapping, registering into and joining a cluster. Its goal
19// is to provide the rest of the node code with the following:
20// - A mounted plaintext storage.
21// - Node credentials/identity.
22// - A locally running etcd server if the node is supposed to run one, and a
23// client connection to that etcd cluster if so.
24// - The state of the cluster as seen by the node, to enable code to respond to
25// node lifecycle changes.
Serge Bazanski42e61c62021-03-18 15:07:18 +010026package cluster
27
28import (
Serge Bazanskia959cbd2021-06-17 15:56:51 +020029 "context"
30 "errors"
Serge Bazanski42e61c62021-03-18 15:07:18 +010031 "fmt"
32
Serge Bazanskia959cbd2021-06-17 15:56:51 +020033 "source.monogon.dev/metropolis/node/core/localstorage"
34 "source.monogon.dev/metropolis/node/core/network"
Serge Bazanski6dff6d62022-01-28 18:15:14 +010035 "source.monogon.dev/metropolis/node/core/roleserve"
Serge Bazanskia959cbd2021-06-17 15:56:51 +020036 "source.monogon.dev/metropolis/pkg/supervisor"
37 apb "source.monogon.dev/metropolis/proto/api"
Mateusz Zalega2930e992022-04-25 12:52:35 +020038 cpb "source.monogon.dev/metropolis/proto/common"
Serge Bazanski42e61c62021-03-18 15:07:18 +010039)
40
Serge Bazanskia959cbd2021-06-17 15:56:51 +020041type Manager struct {
42 storageRoot *localstorage.Root
43 networkService *network.Service
Serge Bazanski6dff6d62022-01-28 18:15:14 +010044 roleServer *roleserve.Service
Lorenz Brun85ad26a2023-03-27 17:00:00 +020045 nodeParams *apb.NodeParameters
Serge Bazanski5df62ba2023-03-22 17:56:46 +010046 haveTPM bool
Serge Bazanskia959cbd2021-06-17 15:56:51 +020047
Serge Bazanskife5192d2023-03-16 11:33:56 +010048 oneway chan struct{}
Serge Bazanskia959cbd2021-06-17 15:56:51 +020049}
50
51// NewManager creates a new cluster Manager. The given localstorage Root must
52// be places, but not yet started (and will be started as the Manager makes
53// progress). The given network Service must already be running.
Serge Bazanski5df62ba2023-03-22 17:56:46 +010054func NewManager(storageRoot *localstorage.Root, networkService *network.Service, rs *roleserve.Service, nodeParams *apb.NodeParameters, haveTPM bool) *Manager {
Serge Bazanskia959cbd2021-06-17 15:56:51 +020055 return &Manager{
56 storageRoot: storageRoot,
57 networkService: networkService,
Serge Bazanski6dff6d62022-01-28 18:15:14 +010058 roleServer: rs,
Lorenz Brun85ad26a2023-03-27 17:00:00 +020059 nodeParams: nodeParams,
Serge Bazanski5df62ba2023-03-22 17:56:46 +010060 haveTPM: haveTPM,
Serge Bazanskife5192d2023-03-16 11:33:56 +010061 oneway: make(chan struct{}),
Serge Bazanskia959cbd2021-06-17 15:56:51 +020062 }
63}
64
Serge Bazanskia959cbd2021-06-17 15:56:51 +020065// Run is the runnable of the Manager, to be started using the Supervisor. It
66// is one-shot, and should not be restarted.
67func (m *Manager) Run(ctx context.Context) error {
Serge Bazanskife5192d2023-03-16 11:33:56 +010068 select {
69 case <-m.oneway:
Serge Bazanskia959cbd2021-06-17 15:56:51 +020070 return fmt.Errorf("cannot restart cluster manager")
Serge Bazanskife5192d2023-03-16 11:33:56 +010071 default:
Serge Bazanskia959cbd2021-06-17 15:56:51 +020072 }
Serge Bazanskife5192d2023-03-16 11:33:56 +010073 close(m.oneway)
Serge Bazanskia959cbd2021-06-17 15:56:51 +020074
Serge Bazanskie4a4ce12023-03-22 18:29:54 +010075 // Try sealed configuration first.
Serge Bazanski98054a12023-06-14 18:16:21 +020076 configuration, err := m.storageRoot.ESP.Metropolis.SealedConfiguration.Unseal(cpb.NodeTPMUsage_NODE_TPM_PRESENT_AND_USED)
Serge Bazanskia959cbd2021-06-17 15:56:51 +020077 if err == nil {
78 supervisor.Logger(ctx).Info("Sealed configuration present. attempting to join cluster")
Mateusz Zalega2930e992022-04-25 12:52:35 +020079
80 // Read Cluster Directory and unmarshal it. Since the node is already
81 // registered with the cluster, the directory won't be bootstrapped from
82 // Node Parameters.
83 cd, err := m.storageRoot.ESP.Metropolis.ClusterDirectory.Unmarshal()
84 if err != nil {
85 return fmt.Errorf("while reading cluster directory: %w", err)
86 }
Serge Bazanskie4a4ce12023-03-22 18:29:54 +010087 return m.join(ctx, configuration, cd, true)
Serge Bazanskia959cbd2021-06-17 15:56:51 +020088 }
89
Serge Bazanski98054a12023-06-14 18:16:21 +020090 if !errors.Is(err, localstorage.ErrNoSealed) && !errors.Is(err, localstorage.ErrSealedCorrupted) {
Serge Bazanskia959cbd2021-06-17 15:56:51 +020091 return fmt.Errorf("unexpected sealed config error: %w", err)
92 }
93
Serge Bazanski98054a12023-06-14 18:16:21 +020094 configuration, err = m.storageRoot.ESP.Metropolis.SealedConfiguration.Unseal(cpb.NodeTPMUsage_NODE_TPM_NOT_PRESENT)
Serge Bazanskie4a4ce12023-03-22 18:29:54 +010095 if err == nil {
96 supervisor.Logger(ctx).Info("Non-sealed configuration present. attempting to join cluster")
97
98 // Read Cluster Directory and unmarshal it. Since the node is already
99 // registered with the cluster, the directory won't be bootstrapped from
100 // Node Parameters.
101 cd, err := m.storageRoot.ESP.Metropolis.ClusterDirectory.Unmarshal()
102 if err != nil {
103 return fmt.Errorf("while reading cluster directory: %w", err)
104 }
105 return m.join(ctx, configuration, cd, false)
106 }
107
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200108 supervisor.Logger(ctx).Info("No sealed configuration, looking for node parameters")
109
Lorenz Brun85ad26a2023-03-27 17:00:00 +0200110 switch inner := m.nodeParams.Cluster.(type) {
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200111 case *apb.NodeParameters_ClusterBootstrap_:
Serge Bazanski5839e972021-11-16 15:46:19 +0100112 err = m.bootstrap(ctx, inner.ClusterBootstrap)
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200113 case *apb.NodeParameters_ClusterRegister_:
Serge Bazanski5839e972021-11-16 15:46:19 +0100114 err = m.register(ctx, inner.ClusterRegister)
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200115 default:
Serge Bazanski5839e972021-11-16 15:46:19 +0100116 err = fmt.Errorf("node parameters misconfigured: neither cluster_bootstrap nor cluster_register set")
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200117 }
Serge Bazanski5839e972021-11-16 15:46:19 +0100118
119 if err == nil {
120 supervisor.Logger(ctx).Info("Cluster enrolment done.")
Serge Bazanskife5192d2023-03-16 11:33:56 +0100121 return nil
Serge Bazanski5839e972021-11-16 15:46:19 +0100122 }
123 return err
Serge Bazanskia959cbd2021-06-17 15:56:51 +0200124}