Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 1 | load("@io_bazel_rules_go//go:def.bzl", "go_library") |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 2 | load("//metropolis/node/build:def.bzl", "erofs_image") |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 3 | |
| 4 | go_library( |
| 5 | name = "go_default_library", |
| 6 | srcs = ["ports.go"], |
Serge Bazanski | 31370b0 | 2021-01-07 16:31:14 +0100 | [diff] [blame] | 7 | importpath = "source.monogon.dev/metropolis/node", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 8 | visibility = ["//metropolis:__subpackages__"], |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 9 | ) |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 10 | |
Lorenz Brun | 313816f | 2020-12-22 16:52:26 +0100 | [diff] [blame] | 11 | # debug_build checks if we're building in debug mode and enables various debug features for the image. |
Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 12 | config_setting( |
| 13 | name = "debug_build", |
| 14 | values = { |
| 15 | "compilation_mode": "dbg", |
| 16 | }, |
| 17 | ) |
| 18 | |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 19 | erofs_image( |
| 20 | name = "rootfs", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 21 | extra_dirs = [ |
| 22 | "/kubernetes/conf/flexvolume-plugins", |
Lorenz Brun | 74e8e5c | 2021-01-26 14:00:50 +0100 | [diff] [blame] | 23 | "/containerd/plugins", |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 24 | "/sys", |
| 25 | "/proc", |
| 26 | "/dev", |
| 27 | "/esp", |
| 28 | "/tmp", |
| 29 | "/run", |
| 30 | "/ephemeral", |
| 31 | "/data", |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 32 | ], |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 33 | files = { |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 34 | "//metropolis/node/core": "/init", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 35 | |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 36 | # CA Certificate bundle & os-release & resolv.conf |
| 37 | # These should not be explicitly used by Metropolis code and are only here for compatibility with |
| 38 | # paths hardcoded by standard libraries (like Go's). |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 39 | "@cacerts//file": "/etc/ssl/cert.pem", |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 40 | "//metropolis/node/core/network/dns:resolv.conf": "/etc/resolv.conf", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 41 | ":os-release-info": "/etc/os-release", |
| 42 | |
| 43 | # Hyperkube |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 44 | "//metropolis/node/kubernetes/hyperkube": "/kubernetes/bin/kube", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 45 | |
Lorenz Brun | 339582b | 2020-07-29 18:13:35 +0200 | [diff] [blame] | 46 | # CoreDNS |
| 47 | "@com_github_coredns_coredns//:coredns": "/kubernetes/bin/coredns", |
| 48 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 49 | # runsc/gVisor |
| 50 | "@com_github_google_gvisor//runsc": "/containerd/bin/runsc", |
Serge Bazanski | f12bedf | 2021-01-15 16:58:50 +0100 | [diff] [blame] | 51 | "@com_github_google_gvisor//shim/v2:containerd-shim-runsc-v1": "/containerd/bin/containerd-shim-runsc-v1", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 52 | |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 53 | # runc (runtime in files_cc because of cgo) |
| 54 | "@com_github_containerd_containerd//cmd/containerd-shim-runc-v2": "/containerd/bin/containerd-shim-runc-v2", |
| 55 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 56 | # Containerd |
| 57 | "@com_github_containerd_containerd//cmd/containerd": "/containerd/bin/containerd", |
| 58 | |
| 59 | # Containerd config files |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 60 | "//metropolis/node/kubernetes/containerd:runsc.toml": "/containerd/conf/runsc.toml", |
| 61 | "//metropolis/node/kubernetes/containerd:config.toml": "/containerd/conf/config.toml", |
| 62 | "//metropolis/node/kubernetes/containerd:cnispec.gojson": "/containerd/conf/cnispec.gojson", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 63 | |
Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 64 | # Containerd preseed bundles |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 65 | "//metropolis/test/e2e/preseedtest:preseedtest.tar": "/containerd/preseed/k8s.io/preseedtest.tar", |
| 66 | "//metropolis/test/e2e/k8s_cts:k8s_cts_image.tar": "/containerd/preseed/k8s.io/k8s_cts.tar", |
Lorenz Brun | 30167f5 | 2021-03-17 17:49:01 +0100 | [diff] [blame] | 67 | "//metropolis/vm/smoketest:smoketest_container.tar": "/containerd/preseed/k8s.io/smoketest.tar", |
Lorenz Brun | 8b0431a | 2020-07-13 16:56:36 +0200 | [diff] [blame] | 68 | |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 69 | # CNI Plugins |
| 70 | "@com_github_containernetworking_plugins//plugins/main/loopback": "/containerd/bin/cni/loopback", |
| 71 | "@com_github_containernetworking_plugins//plugins/main/ptp": "/containerd/bin/cni/ptp", |
| 72 | "@com_github_containernetworking_plugins//plugins/ipam/host-local": "/containerd/bin/cni/host-local", |
Serge Bazanski | c3ae758 | 2020-06-08 17:15:26 +0200 | [diff] [blame] | 73 | |
Lorenz Brun | 70f65b2 | 2020-07-08 17:02:47 +0200 | [diff] [blame] | 74 | # Delve |
| 75 | "@com_github_go_delve_delve//cmd/dlv:dlv": "/dlv", |
Serge Bazanski | 140bddc | 2020-06-05 21:01:19 +0200 | [diff] [blame] | 76 | }, |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 77 | files_cc = { |
| 78 | # runc runtime, with cgo |
| 79 | "@com_github_opencontainers_runc//:runc": "/containerd/bin/runc", |
Lorenz Brun | ddd6caf | 2021-03-04 17:16:04 +0100 | [diff] [blame] | 80 | "@xfsprogs//:mkfs": "/bin/mkfs.xfs", |
Lorenz Brun | 5e4fc2d | 2020-09-22 18:35:15 +0200 | [diff] [blame] | 81 | }, |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 82 | symlinks = { |
| 83 | "/ephemeral/machine-id": "/etc/machine-id", |
| 84 | "/ephemeral/hosts": "/etc/hosts", |
| 85 | }, |
Serge Bazanski | 731d00a | 2020-02-03 19:08:07 +0100 | [diff] [blame] | 86 | ) |
| 87 | |
| 88 | genrule( |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 89 | name = "image", |
| 90 | srcs = [ |
Serge Bazanski | f055a7f | 2021-04-13 16:22:33 +0200 | [diff] [blame^] | 91 | "//third_party/linux", |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 92 | ":rootfs", |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 93 | ], |
| 94 | outs = [ |
Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 95 | "node.img", |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 96 | ], |
| 97 | cmd = """ |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 98 | $(location //metropolis/node/build/mkimage) \ |
Serge Bazanski | f055a7f | 2021-04-13 16:22:33 +0200 | [diff] [blame^] | 99 | -efi $(location //third_party/linux) \ |
Lorenz Brun | 3a99c59 | 2021-01-26 19:57:21 +0100 | [diff] [blame] | 100 | -system $(location :rootfs) \ |
Leopold Schabel | 6549307 | 2019-11-06 13:40:44 +0000 | [diff] [blame] | 101 | -out $@ |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 102 | """, |
Lorenz Brun | 0bcaaee | 2019-11-06 12:42:39 +0100 | [diff] [blame] | 103 | tools = [ |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 104 | "//metropolis/node/build/mkimage", |
Lorenz Brun | 0bcaaee | 2019-11-06 12:42:39 +0100 | [diff] [blame] | 105 | ], |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 106 | visibility = [ |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 107 | "//metropolis/test/e2e:__subpackages__", |
Serge Bazanski | f12bedf | 2021-01-15 16:58:50 +0100 | [diff] [blame] | 108 | "//metropolis/test/launch:__subpackages__", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 109 | ], |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 110 | ) |
| 111 | |
| 112 | genrule( |
| 113 | name = "swtpm_data", |
| 114 | outs = [ |
| 115 | "tpm/tpm2-00.permall", |
| 116 | "tpm/signkey.pem", |
| 117 | "tpm/issuercert.pem", |
| 118 | ], |
| 119 | cmd = """ |
| 120 | mkdir -p tpm/ca |
| 121 | |
| 122 | cat <<EOF > tpm/swtpm.conf |
| 123 | create_certs_tool= /usr/share/swtpm/swtpm-localca |
| 124 | create_certs_tool_config = tpm/swtpm-localca.conf |
| 125 | create_certs_tool_options = /etc/swtpm-localca.options |
| 126 | EOF |
| 127 | |
| 128 | cat <<EOF > tpm/swtpm-localca.conf |
| 129 | statedir = tpm/ca |
| 130 | signingkey = tpm/ca/signkey.pem |
| 131 | issuercert = tpm/ca/issuercert.pem |
| 132 | certserial = tpm/ca/certserial |
| 133 | EOF |
| 134 | |
| 135 | swtpm_setup \ |
| 136 | --tpmstate tpm \ |
| 137 | --create-ek-cert \ |
| 138 | --create-platform-cert \ |
| 139 | --allow-signing \ |
| 140 | --tpm2 \ |
| 141 | --display \ |
| 142 | --pcr-banks sha1,sha256,sha384,sha512 \ |
| 143 | --config tpm/swtpm.conf |
| 144 | |
| 145 | cp tpm/tpm2-00.permall $(location tpm/tpm2-00.permall) |
| 146 | cp tpm/ca/issuercert.pem $(location tpm/issuercert.pem) |
| 147 | cp tpm/ca/signkey.pem $(location tpm/signkey.pem) |
| 148 | """, |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 149 | visibility = [ |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 150 | "//metropolis/test/e2e:__subpackages__", |
Serge Bazanski | f12bedf | 2021-01-15 16:58:50 +0100 | [diff] [blame] | 151 | "//metropolis/test/launch:__subpackages__", |
Serge Bazanski | 0be9be8 | 2021-01-07 15:23:44 +0100 | [diff] [blame] | 152 | ], |
Hendrik Hofstadt | 0d7c91e | 2019-10-23 21:44:47 +0200 | [diff] [blame] | 153 | ) |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 154 | |
Serge Bazanski | 77cb6c5 | 2020-12-19 00:09:22 +0100 | [diff] [blame] | 155 | load("//metropolis/node/build/genosrelease:defs.bzl", "os_release") |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 156 | |
| 157 | os_release( |
| 158 | name = "os-release-info", |
Serge Bazanski | 662b5b3 | 2020-12-21 13:49:00 +0100 | [diff] [blame] | 159 | os_id = "metropolis-node", |
| 160 | os_name = "Metropolis Node", |
| 161 | stamp_var = "STABLE_METROPOLIS_version", |
Lorenz Brun | 878f5f9 | 2020-05-12 16:15:39 +0200 | [diff] [blame] | 162 | ) |