| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 1 | load("@io_bazel_rules_go//go:def.bzl", "go_library", "go_test") |
| Tim Windelschmidt | c2290c2 | 2024-08-15 19:56:00 +0200 | [diff] [blame] | 2 | load("//osbase/build:def.bzl", "erofs_image", "verity_image") |
| 3 | load("//osbase/build:efi.bzl", "efi_unified_kernel_image") |
| 4 | load("//osbase/build/mkimage:def.bzl", "node_image") |
| Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 5 | load("@rules_pkg//:pkg.bzl", "pkg_zip") |
| Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 6 | |
| 7 | go_library( |
| Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 8 | name = "node", |
| Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 9 | srcs = [ |
| 10 | "ids.go", |
| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 11 | "labels.go", |
| Lorenz Brun | 0e291a1 | 2023-06-01 12:22:45 +0200 | [diff] [blame] | 12 | "net_ips.go", |
| Serge Bazanski | 93d593b | 2023-03-28 16:43:47 +0200 | [diff] [blame] | 13 | "net_protocols.go", |
| Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 14 | "ports.go", |
| 15 | ], |
| Serge Bazanski | 31370b0 | 2021-01-07 16:31:14 +0100 | [diff] [blame] | 16 | importpath = "source.monogon.dev/metropolis/node", |
| Tim Windelschmidt | 0300077 | 2023-07-03 02:19:28 +0200 | [diff] [blame] | 17 | visibility = [ |
| 18 | "//metropolis:__subpackages__", |
| 19 | "@io_k8s_kubernetes//pkg/registry:__subpackages__", |
| 20 | ], |
| Serge Bazanski | 53458ba | 2024-06-18 09:56:46 +0000 | [diff] [blame] | 21 | deps = [ |
| 22 | "//metropolis/proto/common", |
| 23 | "@com_github_vishvananda_netlink//:netlink", |
| 24 | ], |
| Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 25 | ) |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 26 | |
| Lorenz Brun | 313816f | 2020-12-22 16:52:26 +0100 | [diff] [blame] | 27 | # debug_build checks if we're building in debug mode and enables various debug features for the image. |
| Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 28 | config_setting( |
| 29 | name = "debug_build", |
| 30 | values = { |
| 31 | "compilation_mode": "dbg", |
| 32 | }, |
| 33 | ) |
| 34 | |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 35 | erofs_image( |
| 36 | name = "rootfs", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 37 | files = { |
| Serge Bazanski | eac8f73 | 2021-10-05 23:30:37 +0200 | [diff] [blame] | 38 | "//metropolis/node/core": "/core", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 39 | |
| Jan Schär | 91bf1c8 | 2024-07-29 17:31:33 +0200 | [diff] [blame^] | 40 | # CA Certificate bundle & os-release & resolv.conf & hosts |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 41 | # These should not be explicitly used by Metropolis code and are only here for compatibility with |
| 42 | # paths hardcoded by standard libraries (like Go's). |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 43 | "@cacerts//file": "/etc/ssl/cert.pem", |
| Jan Schär | 91bf1c8 | 2024-07-29 17:31:33 +0200 | [diff] [blame^] | 44 | "//osbase/net/dns:resolv.conf": "/etc/resolv.conf", |
| 45 | "//osbase/net/dns:hosts": "/etc/hosts", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 46 | ":os-release-info": "/etc/os-release", |
| 47 | |
| Serge Bazanski | 6d563ca | 2023-06-14 13:44:20 +0200 | [diff] [blame] | 48 | # Metrics exporters |
| 49 | "@com_github_prometheus_node_exporter//:node_exporter": "/metrics/bin/node_exporter", |
| 50 | |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 51 | # Hyperkube |
| Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 52 | "//metropolis/node/kubernetes/hyperkube": "/kubernetes/bin/kube", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 53 | |
| 54 | # runsc/gVisor |
| Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 55 | "@dev_gvisor_gvisor//runsc": "/containerd/bin/runsc", |
| 56 | "@dev_gvisor_gvisor//shim": "/containerd/bin/containerd-shim-runsc-v1", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 57 | |
| Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 58 | # runc (runtime in files_cc because of cgo) |
| 59 | "@com_github_containerd_containerd//cmd/containerd-shim-runc-v2": "/containerd/bin/containerd-shim-runc-v2", |
| 60 | |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 61 | # Containerd |
| 62 | "@com_github_containerd_containerd//cmd/containerd": "/containerd/bin/containerd", |
| 63 | |
| 64 | # Containerd config files |
| Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 65 | "//metropolis/node/kubernetes/containerd:runsc.toml": "/containerd/conf/runsc.toml", |
| 66 | "//metropolis/node/kubernetes/containerd:config.toml": "/containerd/conf/config.toml", |
| 67 | "//metropolis/node/kubernetes/containerd:cnispec.gojson": "/containerd/conf/cnispec.gojson", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 68 | |
| Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 69 | # Containerd preseed bundles |
| Tim Windelschmidt | 0974b22 | 2024-01-16 14:04:15 +0100 | [diff] [blame] | 70 | "//metropolis/test/e2e/preseedtest:preseedtest_tarball": "/containerd/preseed/k8s.io/preseedtest.tar", |
| Tim Windelschmidt | 93020d7 | 2024-02-13 18:13:07 +0100 | [diff] [blame] | 71 | "//metropolis/node/kubernetes/pause:pause_tarball": "/containerd/preseed/k8s.io/pause.tar", |
| Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 72 | |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 73 | # CNI Plugins |
| 74 | "@com_github_containernetworking_plugins//plugins/main/loopback": "/containerd/bin/cni/loopback", |
| 75 | "@com_github_containernetworking_plugins//plugins/main/ptp": "/containerd/bin/cni/ptp", |
| 76 | "@com_github_containernetworking_plugins//plugins/ipam/host-local": "/containerd/bin/cni/host-local", |
| Serge Bazanski | c3ae758 | 2020-06-08 17:15:26 +0200 | [diff] [blame] | 77 | |
| Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 78 | # Delve |
| 79 | "@com_github_go_delve_delve//cmd/dlv:dlv": "/dlv", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 80 | }, |
| Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 81 | files_cc = { |
| Serge Bazanski | eac8f73 | 2021-10-05 23:30:37 +0200 | [diff] [blame] | 82 | "//metropolis/node/core/minit": "/init", |
| Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 83 | # runc runtime, with cgo |
| 84 | "@com_github_opencontainers_runc//:runc": "/containerd/bin/runc", |
| Lorenz Brun | ddd6caf | 2021-03-04 17:16:04 +0100 | [diff] [blame] | 85 | "@xfsprogs//:mkfs": "/bin/mkfs.xfs", |
| Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 86 | "@chrony//:chrony": "/time/chrony", |
| Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 87 | }, |
| Serge Bazanski | a393814 | 2022-04-04 17:04:47 +0200 | [diff] [blame] | 88 | fsspecs = [ |
| 89 | ":erofs-layout.fsspec", |
| Tim Windelschmidt | c2290c2 | 2024-08-15 19:56:00 +0200 | [diff] [blame] | 90 | "//osbase/build:earlydev.fsspec", |
| Tim Windelschmidt | 65bf311 | 2024-04-08 21:32:14 +0200 | [diff] [blame] | 91 | "//third_party:firmware", |
| Serge Bazanski | a393814 | 2022-04-04 17:04:47 +0200 | [diff] [blame] | 92 | ], |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 93 | symlinks = { |
| 94 | "/ephemeral/machine-id": "/etc/machine-id", |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 95 | }, |
| Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 96 | ) |
| 97 | |
| Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 98 | verity_image( |
| 99 | name = "verity_rootfs", |
| 100 | source = ":rootfs", |
| 101 | ) |
| 102 | |
| Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 103 | efi_unified_kernel_image( |
| 104 | name = "kernel_efi", |
| Lorenz Brun | 6cb00ed | 2024-02-08 17:49:19 +0100 | [diff] [blame] | 105 | cmdline = "console=ttyS0,115200 console=ttyS1,115200 console=tty0 quiet rootfstype=erofs init=/init loadpin.exclude=kexec-image,kexec-initramfs kernel.unknown_nmi_panic=1", |
| Tim Windelschmidt | 65bf311 | 2024-04-08 21:32:14 +0200 | [diff] [blame] | 106 | initrd = ["//third_party:ucode"], |
| Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 107 | kernel = "//third_party/linux", |
| 108 | os_release = ":os-release-info", |
| Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 109 | verity = ":verity_rootfs", |
| Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 110 | ) |
| 111 | |
| Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 112 | # An intermediary "bundle" format until we finalize the actual bundle format. This is NOT stable until migrated |
| 113 | # to the actual bundle format. |
| 114 | # TODO(lorenz): Replace this |
| 115 | pkg_zip( |
| Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 116 | name = "bundle", |
| Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 117 | srcs = [ |
| 118 | ":kernel_efi", |
| Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 119 | ":verity_rootfs", |
| Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 120 | ], |
| Lorenz Brun | f8ede09 | 2021-11-08 20:50:57 +0100 | [diff] [blame] | 121 | visibility = ["//visibility:public"], |
| Lorenz Brun | f758ce4 | 2021-11-09 03:40:43 +0100 | [diff] [blame] | 122 | ) |
| 123 | |
| Lorenz Brun | 1dc60af | 2023-10-03 15:40:09 +0200 | [diff] [blame] | 124 | node_image( |
| Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 125 | name = "image", |
| Lorenz Brun | 1dc60af | 2023-10-03 15:40:09 +0200 | [diff] [blame] | 126 | kernel = ":kernel_efi", |
| 127 | system = ":verity_rootfs", |
| Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 128 | visibility = [ |
| Mateusz Zalega | fed8fe5 | 2022-07-14 16:19:35 +0200 | [diff] [blame] | 129 | "//metropolis/cli/metroctl/test:__subpackages__", |
| Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 130 | "//metropolis/test/e2e:__subpackages__", |
| Serge Bazanski | f12bedf | 2021-01-15 16:58:50 +0100 | [diff] [blame] | 131 | "//metropolis/test/launch:__subpackages__", |
| Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 132 | ], |
| Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 133 | ) |
| 134 | |
| Tim Windelschmidt | c2290c2 | 2024-08-15 19:56:00 +0200 | [diff] [blame] | 135 | load("//osbase/build/genosrelease:defs.bzl", "os_release") |
| Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 136 | |
| 137 | os_release( |
| 138 | name = "os-release-info", |
| Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 139 | os_id = "metropolis-node", |
| 140 | os_name = "Metropolis Node", |
| Serge Bazanski | 30494c1 | 2023-11-28 16:27:24 +0100 | [diff] [blame] | 141 | stamp_var = "STABLE_MONOGON_metropolis_version", |
| Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 142 | ) |
| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 143 | |
| 144 | go_test( |
| 145 | name = "node_test", |
| 146 | srcs = ["labels_test.go"], |
| 147 | embed = [":node"], |
| 148 | ) |