| Jan Schär | 7c38e78 | 2025-04-29 09:23:37 +0000 | [diff] [blame] | 1 | load("@io_bazel_rules_go//go:def.bzl", "go_binary", "go_library", "go_test") |
| Jan Schär | e6c0c32 | 2025-05-12 16:14:25 +0000 | [diff] [blame] | 2 | load("//osbase/build/genproductinfo:defs.bzl", "product_info") |
| Tim Windelschmidt | bed76d9 | 2025-02-18 03:04:14 +0100 | [diff] [blame] | 3 | load("//osbase/build/mkerofs:def.bzl", "erofs_image") |
| Jan Schär | 5fdca56 | 2025-04-14 11:33:29 +0000 | [diff] [blame] | 4 | load("//osbase/build/mkoci:def.bzl", "oci_os_image") |
| Tim Windelschmidt | bed76d9 | 2025-02-18 03:04:14 +0100 | [diff] [blame] | 5 | load("//osbase/build/mkpayload:def.bzl", "efi_unified_kernel_image") |
| 6 | load("//osbase/build/mkverity:def.bzl", "verity_image") |
| Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 7 | |
| 8 | go_library( |
| Lorenz Brun | d13c1c6 | 2022-03-30 19:58:58 +0200 | [diff] [blame] | 9 | name = "node", |
| Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 10 | srcs = [ |
| 11 | "ids.go", |
| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 12 | "labels.go", |
| Lorenz Brun | 0e291a1 | 2023-06-01 12:22:45 +0200 | [diff] [blame] | 13 | "net_ips.go", |
| Serge Bazanski | 93d593b | 2023-03-28 16:43:47 +0200 | [diff] [blame] | 14 | "net_protocols.go", |
| Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 15 | "ports.go", |
| Jan Schär | 39f4f5c | 2024-10-29 09:41:50 +0100 | [diff] [blame] | 16 | "validation.go", |
| Lorenz Brun | e306d78 | 2021-09-01 13:01:06 +0200 | [diff] [blame] | 17 | ], |
| Serge Bazanski | 31370b0 | 2021-01-07 16:31:14 +0100 | [diff] [blame] | 18 | importpath = "source.monogon.dev/metropolis/node", |
| Tim Windelschmidt | 0300077 | 2023-07-03 02:19:28 +0200 | [diff] [blame] | 19 | visibility = [ |
| 20 | "//metropolis:__subpackages__", |
| 21 | "@io_k8s_kubernetes//pkg/registry:__subpackages__", |
| 22 | ], |
| Timon Stampfli | 91bcf46 | 2024-12-15 16:57:05 +0100 | [diff] [blame] | 23 | deps = ["//metropolis/proto/common"], |
| Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 24 | ) |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 25 | |
| Lorenz Brun | 313816f | 2020-12-22 16:52:26 +0100 | [diff] [blame] | 26 | # debug_build checks if we're building in debug mode and enables various debug features for the image. |
| Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 27 | config_setting( |
| 28 | name = "debug_build", |
| 29 | values = { |
| 30 | "compilation_mode": "dbg", |
| 31 | }, |
| 32 | ) |
| 33 | |
| Lorenz Brun | 2ecccae | 2024-11-27 22:03:35 +0100 | [diff] [blame] | 34 | exports_files([ |
| 35 | "passwd", |
| 36 | ]) |
| 37 | |
| Jan Schär | 7c38e78 | 2025-04-29 09:23:37 +0000 | [diff] [blame] | 38 | go_binary( |
| Tim Windelschmidt | 25e0d8f | 2024-12-02 23:46:24 +0100 | [diff] [blame] | 39 | name = "runc", |
| Jan Schär | 7c38e78 | 2025-04-29 09:23:37 +0000 | [diff] [blame] | 40 | embed = ["@com_github_opencontainers_runc//:runc_lib"], |
| 41 | gotags = [ |
| 42 | "osusergo", |
| 43 | "netgo", |
| 44 | "seccomp", |
| 45 | ], |
| Jan Schär | 0fd36f4 | 2025-04-29 10:26:03 +0000 | [diff] [blame] | 46 | pure = "off", |
| Tim Windelschmidt | 25e0d8f | 2024-12-02 23:46:24 +0100 | [diff] [blame] | 47 | ) |
| 48 | |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 49 | erofs_image( |
| 50 | name = "rootfs", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 51 | files = { |
| Jan Schär | 69b7687 | 2025-05-14 16:39:47 +0000 | [diff] [blame] | 52 | "/init": "//metropolis/node/minit", |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 53 | "/core": "//metropolis/node/core", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 54 | |
| Jan Schär | b86917b | 2025-05-14 16:31:08 +0000 | [diff] [blame] | 55 | # Product info |
| 56 | "/etc/product-info.json": ":product_info", |
| 57 | |
| Jan Schär | 91bf1c8 | 2024-07-29 17:31:33 +0200 | [diff] [blame] | 58 | # CA Certificate bundle & os-release & resolv.conf & hosts |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 59 | # These should not be explicitly used by Metropolis code and are only here for compatibility with |
| 60 | # paths hardcoded by standard libraries (like Go's). |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 61 | "/etc/ssl/cert.pem": "@cacerts//file", |
| 62 | "/etc/passwd": ":passwd", |
| 63 | "/etc/resolv.conf": "//osbase/net/dns:resolv.conf", |
| 64 | "/etc/hosts": "//osbase/net/dns:hosts", |
| Jan Schär | e6c0c32 | 2025-05-12 16:14:25 +0000 | [diff] [blame] | 65 | "/etc/os-release": ":product_info_os_release", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 66 | |
| Serge Bazanski | 6d563ca | 2023-06-14 13:44:20 +0200 | [diff] [blame] | 67 | # Metrics exporters |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 68 | "/metrics/bin/node_exporter": "@com_github_prometheus_node_exporter//:node_exporter", |
| Serge Bazanski | 6d563ca | 2023-06-14 13:44:20 +0200 | [diff] [blame] | 69 | |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 70 | # Hyperkube |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 71 | "/kubernetes/bin/kube": "//metropolis/node/kubernetes/hyperkube", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 72 | |
| 73 | # runsc/gVisor |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 74 | "/containerd/bin/runsc": "@dev_gvisor_gvisor//runsc", |
| 75 | "/containerd/bin/containerd-shim-runsc-v1": "@dev_gvisor_gvisor//shim", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 76 | |
| Jan Schär | 0fd36f4 | 2025-04-29 10:26:03 +0000 | [diff] [blame] | 77 | # runc |
| 78 | "/containerd/bin/runc": ":runc", |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 79 | "/containerd/bin/containerd-shim-runc-v2": "@com_github_containerd_containerd_v2//cmd/containerd-shim-runc-v2", |
| Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 80 | |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 81 | # Containerd |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 82 | "/containerd/bin/containerd": "@com_github_containerd_containerd_v2//cmd/containerd", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 83 | |
| 84 | # Containerd config files |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 85 | "/containerd/conf/runsc.toml": "//metropolis/node/kubernetes/containerd:runsc.toml", |
| 86 | "/containerd/conf/config.toml": "//metropolis/node/kubernetes/containerd:config.toml", |
| 87 | "/containerd/conf/cnispec.gojson": "//metropolis/node/kubernetes/containerd:cnispec.gojson", |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 88 | |
| Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 89 | # Containerd preseed bundles |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 90 | "/containerd/preseed/k8s.io/preseedtest.tar": "//metropolis/test/e2e/preseedtest:preseedtest_tarball", |
| 91 | "/containerd/preseed/k8s.io/pause.tar": "//metropolis/node/kubernetes/pause:pause_tarball", |
| Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 92 | |
| Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 93 | # CNI Plugins |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 94 | "/containerd/bin/cni/loopback": "@com_github_containernetworking_plugins//plugins/main/loopback", |
| 95 | "/containerd/bin/cni/ptp": "@com_github_containernetworking_plugins//plugins/main/ptp", |
| 96 | "/containerd/bin/cni/host-local": "@com_github_containernetworking_plugins//plugins/ipam/host-local", |
| Serge Bazanski | c3ae758 | 2020-06-08 17:15:26 +0200 | [diff] [blame] | 97 | |
| Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 98 | # Delve |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 99 | "/dlv": "@com_github_go_delve_delve//cmd/dlv:dlv", |
| Jan Schär | 0fd36f4 | 2025-04-29 10:26:03 +0000 | [diff] [blame] | 100 | |
| 101 | # file system tools |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 102 | "/bin/mkfs.xfs": "@xfsprogs//:mkfs", |
| Jan Schär | 0fd36f4 | 2025-04-29 10:26:03 +0000 | [diff] [blame] | 103 | |
| 104 | # time |
| Tim Windelschmidt | 24bf6fd | 2025-02-12 04:48:24 +0100 | [diff] [blame] | 105 | "/time/chrony": "@chrony//:chrony", |
| Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 106 | }, |
| Serge Bazanski | a393814 | 2022-04-04 17:04:47 +0200 | [diff] [blame] | 107 | fsspecs = [ |
| 108 | ":erofs-layout.fsspec", |
| Tim Windelschmidt | c2290c2 | 2024-08-15 19:56:00 +0200 | [diff] [blame] | 109 | "//osbase/build:earlydev.fsspec", |
| Tim Windelschmidt | 65bf311 | 2024-04-08 21:32:14 +0200 | [diff] [blame] | 110 | "//third_party:firmware", |
| Serge Bazanski | a393814 | 2022-04-04 17:04:47 +0200 | [diff] [blame] | 111 | ], |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 112 | symlinks = { |
| Tim Windelschmidt | ad4d954 | 2025-03-24 20:20:13 +0100 | [diff] [blame] | 113 | "/etc/machine-id": "/ephemeral/machine-id", |
| Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 114 | }, |
| Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 115 | ) |
| 116 | |
| Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 117 | verity_image( |
| 118 | name = "verity_rootfs", |
| Jan Schär | 2add1cb | 2025-07-14 09:26:18 +0000 | [diff] [blame] | 119 | salt = ":product_info", |
| Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 120 | source = ":rootfs", |
| 121 | ) |
| 122 | |
| Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 123 | efi_unified_kernel_image( |
| 124 | name = "kernel_efi", |
| Tim Windelschmidt | 4ebbc5f | 2025-07-16 16:04:35 +0200 | [diff] [blame] | 125 | cmdline = "console=ttyS0,115200 console=ttyS1,115200 console=ttyAMA0 quiet rootfstype=erofs init=/init loadpin.exclude=kexec-image,kexec-initramfs kernel.unknown_nmi_panic=1", |
| Tim Windelschmidt | 65bf311 | 2024-04-08 21:32:14 +0200 | [diff] [blame] | 126 | initrd = ["//third_party:ucode"], |
| Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 127 | kernel = "//third_party/linux", |
| Jan Schär | e6c0c32 | 2025-05-12 16:14:25 +0000 | [diff] [blame] | 128 | os_release = ":product_info_os_release", |
| Mateusz Zalega | 8c2c771 | 2022-01-25 19:42:21 +0100 | [diff] [blame] | 129 | verity = ":verity_rootfs", |
| Lorenz Brun | 2f9f387 | 2021-09-29 19:48:08 +0200 | [diff] [blame] | 130 | ) |
| 131 | |
| Jan Schär | 5fdca56 | 2025-04-14 11:33:29 +0000 | [diff] [blame] | 132 | oci_os_image( |
| 133 | name = "oci_image", |
| 134 | srcs = { |
| 135 | "system": ":verity_rootfs", |
| 136 | "kernel.efi": ":kernel_efi", |
| 137 | }, |
| Jan Schär | 07e6905 | 2025-05-12 16:34:15 +0000 | [diff] [blame] | 138 | product_info = ":product_info", |
| Jan Schär | 5fdca56 | 2025-04-14 11:33:29 +0000 | [diff] [blame] | 139 | visibility = ["//visibility:public"], |
| 140 | ) |
| 141 | |
| Jan Schär | 3b0c8dd | 2025-06-23 10:32:07 +0000 | [diff] [blame] | 142 | oci_os_image( |
| 143 | name = "oci_image_uncompressed", |
| 144 | srcs = { |
| 145 | "system": ":verity_rootfs", |
| 146 | "kernel.efi": ":kernel_efi", |
| 147 | }, |
| 148 | compression_level = 0, |
| 149 | product_info = ":product_info", |
| 150 | visibility = ["//metropolis/test/launch:__pkg__"], |
| 151 | ) |
| 152 | |
| Jan Schär | e6c0c32 | 2025-05-12 16:14:25 +0000 | [diff] [blame] | 153 | product_info( |
| 154 | name = "product_info", |
| 155 | components = [ |
| 156 | "linux", |
| 157 | "kubernetes", |
| 158 | ], |
| Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 159 | os_id = "metropolis-node", |
| 160 | os_name = "Metropolis Node", |
| Jan Schär | e6c0c32 | 2025-05-12 16:14:25 +0000 | [diff] [blame] | 161 | out_os_release = ":product_info_os_release", |
| Serge Bazanski | 30494c1 | 2023-11-28 16:27:24 +0100 | [diff] [blame] | 162 | stamp_var = "STABLE_MONOGON_metropolis_version", |
| Jan Schär | b86917b | 2025-05-14 16:31:08 +0000 | [diff] [blame] | 163 | visibility = [":__subpackages__"], |
| Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 164 | ) |
| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 165 | |
| 166 | go_test( |
| 167 | name = "node_test", |
| Jan Schär | 39f4f5c | 2024-10-29 09:41:50 +0100 | [diff] [blame] | 168 | srcs = [ |
| 169 | "labels_test.go", |
| 170 | "validation_test.go", |
| 171 | ], |
| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 172 | embed = [":node"], |
| Serge Bazanski | dd2b80f | 2024-09-24 13:06:27 +0000 | [diff] [blame] | 173 | deps = ["@io_k8s_apimachinery//pkg/util/validation"], |
| Serge Bazanski | 1f78954 | 2024-05-22 14:01:50 +0200 | [diff] [blame] | 174 | ) |