mirror of
https://github.com/psviderski/uncloud.git
synced 2026-08-26 11:03:34 +00:00
add uncloud machine token command to print machine token to add machine to cluster
This commit is contained in:
@@ -41,12 +41,16 @@ func ConfigPath(dataDir string) string {
|
||||
func ParseConfig(path string) (*Config, error) {
|
||||
data, err := os.ReadFile(path)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("read config file %q: %w", path, err)
|
||||
return nil, fmt.Errorf("read config file: %w", err)
|
||||
}
|
||||
var config Config
|
||||
if err = json.Unmarshal(data, &config); err != nil {
|
||||
return nil, fmt.Errorf("parse config file %q: %w", path, err)
|
||||
}
|
||||
|
||||
if config.Network == nil {
|
||||
return nil, fmt.Errorf("missing network configuration in config file %q", path)
|
||||
}
|
||||
return &config, nil
|
||||
}
|
||||
|
||||
|
||||
@@ -38,7 +38,7 @@ func InitCluster(dataDir, machineName string, netPrefix netip.Prefix, users []*p
|
||||
}
|
||||
|
||||
// Use all routable addresses as endpoints.
|
||||
addrs, err := network.ListRoutableAddresses()
|
||||
addrs, err := network.ListRoutableIPs()
|
||||
if err != nil {
|
||||
return fmt.Errorf("list routable addresses: %w", err)
|
||||
}
|
||||
@@ -112,9 +112,30 @@ type Daemon struct {
|
||||
}
|
||||
|
||||
func New(dataDir string) (*Daemon, error) {
|
||||
cfg, err := machine.ParseConfig(machine.ConfigPath(dataDir))
|
||||
cfgPath := machine.ConfigPath(dataDir)
|
||||
cfg, err := machine.ParseConfig(cfgPath)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("load machine config: %w", err)
|
||||
if !errors.Is(err, os.ErrNotExist) {
|
||||
return nil, fmt.Errorf("load machine config: %w", err)
|
||||
}
|
||||
// Generate an empty machine config with a new key pair.
|
||||
slog.Info("Machine config not found, creating a new one.", "path", cfgPath)
|
||||
privKey, pubKey, kErr := network.NewMachineKeys()
|
||||
if kErr != nil {
|
||||
return nil, fmt.Errorf("generate machine keys: %w", kErr)
|
||||
}
|
||||
slog.Info("Generated machine key pair.", "pubkey", pubKey)
|
||||
|
||||
cfg = &machine.Config{
|
||||
Network: &network.Config{
|
||||
PrivateKey: privKey,
|
||||
PublicKey: pubKey,
|
||||
},
|
||||
}
|
||||
cfg.SetPath(cfgPath)
|
||||
if err = cfg.Save(); err != nil {
|
||||
return nil, fmt.Errorf("save machine config: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
statePath := cluster.StatePath(dataDir)
|
||||
@@ -123,59 +144,74 @@ func New(dataDir string) (*Daemon, error) {
|
||||
if !errors.Is(err, os.ErrNotExist) {
|
||||
return nil, fmt.Errorf("load cluster state: %w", err)
|
||||
}
|
||||
slog.Info("No cluster state found, creating a new one.", "path", statePath)
|
||||
slog.Info("Cluster state not found, creating a new one.", "path", statePath)
|
||||
if err = state.Save(); err != nil {
|
||||
return nil, fmt.Errorf("save cluster state: %w", err)
|
||||
}
|
||||
}
|
||||
|
||||
apiAddr := net.JoinHostPort(cfg.Network.ManagementIP.String(), strconv.Itoa(machine.APIPort))
|
||||
c := cluster.NewCluster(state, apiAddr)
|
||||
d := &Daemon{
|
||||
config: cfg,
|
||||
}
|
||||
if cfg.Network.IsConfigured() {
|
||||
apiAddr := net.JoinHostPort(cfg.Network.ManagementIP.String(), strconv.Itoa(machine.APIPort))
|
||||
d.cluster = cluster.NewCluster(state, apiAddr)
|
||||
}
|
||||
|
||||
return &Daemon{
|
||||
config: cfg,
|
||||
cluster: c,
|
||||
}, nil
|
||||
return d, nil
|
||||
}
|
||||
|
||||
func (d *Daemon) Run(ctx context.Context) error {
|
||||
wgnet, err := network.NewWireGuardNetwork()
|
||||
if err != nil {
|
||||
return fmt.Errorf("create WireGuard network: %w", err)
|
||||
}
|
||||
if err = wgnet.Configure(*d.config.Network); err != nil {
|
||||
return fmt.Errorf("configure WireGuard network: %w", err)
|
||||
}
|
||||
//ctx, cancel := context.WithCancel(context.Background())
|
||||
//go wgnet.WatchEndpoints(ctx, peerEndpointChangeNotifier)
|
||||
|
||||
//addrs, err := network.ListRoutableAddresses()
|
||||
//if err != nil {
|
||||
// return err
|
||||
//}
|
||||
//fmt.Println("Addresses:", addrs)
|
||||
|
||||
// Use an errgroup to coordinate error handling and graceful shutdown of multiple daemon components.
|
||||
errGroup, ctx := errgroup.WithContext(ctx)
|
||||
errGroup.Go(func() error {
|
||||
slog.Info("Starting cluster.")
|
||||
if err = d.cluster.Run(); err != nil {
|
||||
return fmt.Errorf("cluster failed: %w", err)
|
||||
|
||||
// Start the network only if it is configured.
|
||||
if d.config.Network.IsConfigured() {
|
||||
wgnet, err := network.NewWireGuardNetwork()
|
||||
if err != nil {
|
||||
return fmt.Errorf("create WireGuard network: %w", err)
|
||||
}
|
||||
return nil
|
||||
})
|
||||
errGroup.Go(func() error {
|
||||
if err = wgnet.Run(ctx); err != nil {
|
||||
return fmt.Errorf("WireGuard network failed: %w", err)
|
||||
if err = wgnet.Configure(*d.config.Network); err != nil {
|
||||
return fmt.Errorf("configure WireGuard network: %w", err)
|
||||
}
|
||||
return nil
|
||||
})
|
||||
|
||||
//ctx, cancel := context.WithCancel(context.Background())
|
||||
//go wgnet.WatchEndpoints(ctx, peerEndpointChangeNotifier)
|
||||
|
||||
//addrs, err := network.ListRoutableIPs()
|
||||
//if err != nil {
|
||||
// return err
|
||||
//}
|
||||
//fmt.Println("Addresses:", addrs)
|
||||
|
||||
errGroup.Go(func() error {
|
||||
if err = wgnet.Run(ctx); err != nil {
|
||||
return fmt.Errorf("WireGuard network failed: %w", err)
|
||||
}
|
||||
return nil
|
||||
})
|
||||
} else {
|
||||
slog.Info("Waiting for network configuration to start WireGuard network.")
|
||||
}
|
||||
|
||||
if d.cluster != nil {
|
||||
errGroup.Go(func() error {
|
||||
slog.Info("Starting cluster.")
|
||||
if err := d.cluster.Run(); err != nil {
|
||||
return fmt.Errorf("cluster failed: %w", err)
|
||||
}
|
||||
return nil
|
||||
})
|
||||
}
|
||||
|
||||
// Shutdown goroutine.
|
||||
errGroup.Go(func() error {
|
||||
<-ctx.Done()
|
||||
slog.Info("Stopping cluster.")
|
||||
d.cluster.Stop()
|
||||
slog.Info("Cluster stopped.")
|
||||
if d.cluster != nil {
|
||||
slog.Info("Stopping cluster.")
|
||||
d.cluster.Stop()
|
||||
slog.Info("Cluster stopped.")
|
||||
}
|
||||
return nil
|
||||
})
|
||||
|
||||
|
||||
@@ -0,0 +1,41 @@
|
||||
package daemon
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"os"
|
||||
"uncloud/internal/machine"
|
||||
"uncloud/internal/machine/network"
|
||||
)
|
||||
|
||||
// MachineToken returns the local machine's token that can be used for adding the machine to a cluster.
|
||||
// TODO: ideally, this should be an RPC call to the daemon API to ensure the config is created and up-to-date.
|
||||
func MachineToken(dataDir string) (machine.Token, error) {
|
||||
cfg, err := machine.ParseConfig(machine.ConfigPath(dataDir))
|
||||
if err != nil {
|
||||
if errors.Is(err, os.ErrNotExist) {
|
||||
return machine.Token{}, fmt.Errorf("load machine config (is uncloudd daemon running?): %w", err)
|
||||
}
|
||||
return machine.Token{}, fmt.Errorf("load machine config: %w", err)
|
||||
}
|
||||
if len(cfg.Network.PublicKey) == 0 {
|
||||
return machine.Token{}, errors.New("public key is not set in machine config")
|
||||
}
|
||||
|
||||
ips, err := network.ListRoutableIPs()
|
||||
if err != nil {
|
||||
return machine.Token{}, fmt.Errorf("list routable addresses: %w", err)
|
||||
}
|
||||
publicIP, err := network.GetPublicIP()
|
||||
// Ignore the error if failed to get the public IP using API services.
|
||||
if err == nil {
|
||||
ips = append([]netip.Addr{publicIP}, ips...)
|
||||
}
|
||||
|
||||
endpoints := make([]netip.AddrPort, len(ips))
|
||||
for i, ip := range ips {
|
||||
endpoints[i] = netip.AddrPortFrom(ip, network.WireGuardPort)
|
||||
}
|
||||
return machine.NewToken(cfg.Network.PublicKey, endpoints), nil
|
||||
}
|
||||
@@ -0,0 +1,106 @@
|
||||
package network
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/netip"
|
||||
"strings"
|
||||
"time"
|
||||
)
|
||||
|
||||
// ListRoutableIPs returns a list of routable unicast IP addresses.
|
||||
func ListRoutableIPs() ([]netip.Addr, error) {
|
||||
interfaces, err := net.Interfaces()
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("list network interfaces: %w", err)
|
||||
}
|
||||
|
||||
var routable []netip.Addr
|
||||
for _, iface := range interfaces {
|
||||
if iface.Name == WireGuardInterfaceName || strings.HasPrefix(iface.Name, "docker") {
|
||||
// Skip the Uncloud WireGuard and Docker interfaces.
|
||||
continue
|
||||
}
|
||||
if iface.Flags&net.FlagUp == 0 || iface.Flags&net.FlagRunning == 0 || iface.Flags&net.FlagLoopback != 0 {
|
||||
// Skip interfaces:
|
||||
// * Not administratively UP.
|
||||
// * The operational status is not RUNNING. This is the closest equivalent to checking for NO-CARRIER.
|
||||
// * Loopback.
|
||||
continue
|
||||
}
|
||||
// TODO: check for link/ether ifaces?
|
||||
|
||||
addrs, aErr := iface.Addrs()
|
||||
if aErr != nil {
|
||||
return nil, fmt.Errorf("list unicast addresses for interface %q: %w", iface.Name, err)
|
||||
}
|
||||
for _, addr := range addrs {
|
||||
ipNet, ok := addr.(*net.IPNet)
|
||||
if !ok {
|
||||
continue
|
||||
}
|
||||
// Includes IPv4 private address space and local IPv6 unicast address space.
|
||||
if ipNet.IP.IsGlobalUnicast() {
|
||||
ip, pErr := netip.ParseAddr(ipNet.IP.String())
|
||||
if pErr != nil {
|
||||
return nil, fmt.Errorf("parse IP address %q: %w", ipNet.IP, err)
|
||||
}
|
||||
routable = append(routable, ip)
|
||||
}
|
||||
}
|
||||
}
|
||||
return routable, nil
|
||||
}
|
||||
|
||||
func GetPublicIP() (netip.Addr, error) {
|
||||
services := []struct {
|
||||
URL string
|
||||
Parser func([]byte) (netip.Addr, error)
|
||||
}{
|
||||
{"https://api.ipify.org", parsePlaintextIP},
|
||||
{"https://ipinfo.io/ip", parsePlaintextIP},
|
||||
{"http://ip-api.com/line/?fields=query", parsePlaintextIP},
|
||||
}
|
||||
|
||||
for _, service := range services {
|
||||
if ip, err := queryIP(service.URL, service.Parser); err == nil {
|
||||
return ip, nil
|
||||
}
|
||||
}
|
||||
|
||||
return netip.Addr{}, fmt.Errorf("failed to get public IP from all services")
|
||||
}
|
||||
|
||||
func queryIP(service string, parser func([]byte) (netip.Addr, error)) (netip.Addr, error) {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
|
||||
defer cancel()
|
||||
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, service, nil)
|
||||
if err != nil {
|
||||
return netip.Addr{}, fmt.Errorf("create request: %w", err)
|
||||
}
|
||||
|
||||
resp, err := http.DefaultClient.Do(req)
|
||||
if err != nil {
|
||||
return netip.Addr{}, fmt.Errorf("send request: %w", err)
|
||||
}
|
||||
defer func() {
|
||||
_ = resp.Body.Close()
|
||||
}()
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
return netip.Addr{}, fmt.Errorf("unexpected status code: %d", resp.StatusCode)
|
||||
}
|
||||
|
||||
body, err := io.ReadAll(resp.Body)
|
||||
if err != nil {
|
||||
return netip.Addr{}, fmt.Errorf("read response body: %w", err)
|
||||
}
|
||||
return parser(body)
|
||||
}
|
||||
|
||||
func parsePlaintextIP(data []byte) (netip.Addr, error) {
|
||||
return netip.ParseAddr(string(data))
|
||||
}
|
||||
@@ -35,6 +35,11 @@ type PeerConfig struct {
|
||||
PublicKey secret.Secret
|
||||
}
|
||||
|
||||
func (c Config) IsConfigured() bool {
|
||||
return c.Subnet != (netip.Prefix{}) && c.ManagementIP != (netip.Addr{}) &&
|
||||
c.PrivateKey != nil && c.PublicKey != nil
|
||||
}
|
||||
|
||||
func (c Config) toDeviceConfig() (wgtypes.Config, error) {
|
||||
privateKey, err := wgtypes.NewKey(c.PrivateKey)
|
||||
if err != nil {
|
||||
|
||||
@@ -0,0 +1,54 @@
|
||||
package machine
|
||||
|
||||
import (
|
||||
"encoding/base64"
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"strings"
|
||||
"uncloud/internal/secret"
|
||||
)
|
||||
|
||||
const (
|
||||
TokenPrefix = "mtkn:"
|
||||
)
|
||||
|
||||
// Token represents the machine's token for joining a cluster.
|
||||
type Token struct {
|
||||
PublicKey secret.Secret
|
||||
Endpoints []netip.AddrPort
|
||||
}
|
||||
|
||||
// NewToken creates a new machine token with the given public key and endpoints.
|
||||
func NewToken(publicKey secret.Secret, endpoints []netip.AddrPort) Token {
|
||||
return Token{
|
||||
PublicKey: publicKey,
|
||||
Endpoints: endpoints,
|
||||
}
|
||||
}
|
||||
|
||||
// ParseToken decodes a machine token from the given string.
|
||||
func ParseToken(s string) (Token, error) {
|
||||
if strings.HasPrefix(s, TokenPrefix) {
|
||||
return Token{}, fmt.Errorf("invalid token prefix")
|
||||
}
|
||||
decoded, err := base64.StdEncoding.DecodeString(s[len(TokenPrefix):])
|
||||
if err != nil {
|
||||
return Token{}, fmt.Errorf("decode token: %w", err)
|
||||
}
|
||||
var token Token
|
||||
if err = json.Unmarshal(decoded, &token); err != nil {
|
||||
return Token{}, fmt.Errorf("unmarshal token: %w", err)
|
||||
}
|
||||
return token, nil
|
||||
}
|
||||
|
||||
// String returns the machine token encoded as a string.
|
||||
func (t Token) String() (string, error) {
|
||||
js, err := json.Marshal(t)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("marshal token: %w", err)
|
||||
}
|
||||
encoded := base64.StdEncoding.EncodeToString(js)
|
||||
return TokenPrefix + encoded, nil
|
||||
}
|
||||
Reference in New Issue
Block a user