add uncloud machine token command to print machine token to add machine to cluster

This commit is contained in:
Pavel Sviderski
2024-09-05 16:13:27 +10:00
parent 4656bdd132
commit 945eff471b
9 changed files with 327 additions and 42 deletions
+5 -1
View File
@@ -41,12 +41,16 @@ func ConfigPath(dataDir string) string {
func ParseConfig(path string) (*Config, error) {
data, err := os.ReadFile(path)
if err != nil {
return nil, fmt.Errorf("read config file %q: %w", path, err)
return nil, fmt.Errorf("read config file: %w", err)
}
var config Config
if err = json.Unmarshal(data, &config); err != nil {
return nil, fmt.Errorf("parse config file %q: %w", path, err)
}
if config.Network == nil {
return nil, fmt.Errorf("missing network configuration in config file %q", path)
}
return &config, nil
}
+76 -40
View File
@@ -38,7 +38,7 @@ func InitCluster(dataDir, machineName string, netPrefix netip.Prefix, users []*p
}
// Use all routable addresses as endpoints.
addrs, err := network.ListRoutableAddresses()
addrs, err := network.ListRoutableIPs()
if err != nil {
return fmt.Errorf("list routable addresses: %w", err)
}
@@ -112,9 +112,30 @@ type Daemon struct {
}
func New(dataDir string) (*Daemon, error) {
cfg, err := machine.ParseConfig(machine.ConfigPath(dataDir))
cfgPath := machine.ConfigPath(dataDir)
cfg, err := machine.ParseConfig(cfgPath)
if err != nil {
return nil, fmt.Errorf("load machine config: %w", err)
if !errors.Is(err, os.ErrNotExist) {
return nil, fmt.Errorf("load machine config: %w", err)
}
// Generate an empty machine config with a new key pair.
slog.Info("Machine config not found, creating a new one.", "path", cfgPath)
privKey, pubKey, kErr := network.NewMachineKeys()
if kErr != nil {
return nil, fmt.Errorf("generate machine keys: %w", kErr)
}
slog.Info("Generated machine key pair.", "pubkey", pubKey)
cfg = &machine.Config{
Network: &network.Config{
PrivateKey: privKey,
PublicKey: pubKey,
},
}
cfg.SetPath(cfgPath)
if err = cfg.Save(); err != nil {
return nil, fmt.Errorf("save machine config: %w", err)
}
}
statePath := cluster.StatePath(dataDir)
@@ -123,59 +144,74 @@ func New(dataDir string) (*Daemon, error) {
if !errors.Is(err, os.ErrNotExist) {
return nil, fmt.Errorf("load cluster state: %w", err)
}
slog.Info("No cluster state found, creating a new one.", "path", statePath)
slog.Info("Cluster state not found, creating a new one.", "path", statePath)
if err = state.Save(); err != nil {
return nil, fmt.Errorf("save cluster state: %w", err)
}
}
apiAddr := net.JoinHostPort(cfg.Network.ManagementIP.String(), strconv.Itoa(machine.APIPort))
c := cluster.NewCluster(state, apiAddr)
d := &Daemon{
config: cfg,
}
if cfg.Network.IsConfigured() {
apiAddr := net.JoinHostPort(cfg.Network.ManagementIP.String(), strconv.Itoa(machine.APIPort))
d.cluster = cluster.NewCluster(state, apiAddr)
}
return &Daemon{
config: cfg,
cluster: c,
}, nil
return d, nil
}
func (d *Daemon) Run(ctx context.Context) error {
wgnet, err := network.NewWireGuardNetwork()
if err != nil {
return fmt.Errorf("create WireGuard network: %w", err)
}
if err = wgnet.Configure(*d.config.Network); err != nil {
return fmt.Errorf("configure WireGuard network: %w", err)
}
//ctx, cancel := context.WithCancel(context.Background())
//go wgnet.WatchEndpoints(ctx, peerEndpointChangeNotifier)
//addrs, err := network.ListRoutableAddresses()
//if err != nil {
// return err
//}
//fmt.Println("Addresses:", addrs)
// Use an errgroup to coordinate error handling and graceful shutdown of multiple daemon components.
errGroup, ctx := errgroup.WithContext(ctx)
errGroup.Go(func() error {
slog.Info("Starting cluster.")
if err = d.cluster.Run(); err != nil {
return fmt.Errorf("cluster failed: %w", err)
// Start the network only if it is configured.
if d.config.Network.IsConfigured() {
wgnet, err := network.NewWireGuardNetwork()
if err != nil {
return fmt.Errorf("create WireGuard network: %w", err)
}
return nil
})
errGroup.Go(func() error {
if err = wgnet.Run(ctx); err != nil {
return fmt.Errorf("WireGuard network failed: %w", err)
if err = wgnet.Configure(*d.config.Network); err != nil {
return fmt.Errorf("configure WireGuard network: %w", err)
}
return nil
})
//ctx, cancel := context.WithCancel(context.Background())
//go wgnet.WatchEndpoints(ctx, peerEndpointChangeNotifier)
//addrs, err := network.ListRoutableIPs()
//if err != nil {
// return err
//}
//fmt.Println("Addresses:", addrs)
errGroup.Go(func() error {
if err = wgnet.Run(ctx); err != nil {
return fmt.Errorf("WireGuard network failed: %w", err)
}
return nil
})
} else {
slog.Info("Waiting for network configuration to start WireGuard network.")
}
if d.cluster != nil {
errGroup.Go(func() error {
slog.Info("Starting cluster.")
if err := d.cluster.Run(); err != nil {
return fmt.Errorf("cluster failed: %w", err)
}
return nil
})
}
// Shutdown goroutine.
errGroup.Go(func() error {
<-ctx.Done()
slog.Info("Stopping cluster.")
d.cluster.Stop()
slog.Info("Cluster stopped.")
if d.cluster != nil {
slog.Info("Stopping cluster.")
d.cluster.Stop()
slog.Info("Cluster stopped.")
}
return nil
})
+41
View File
@@ -0,0 +1,41 @@
package daemon
import (
"errors"
"fmt"
"net/netip"
"os"
"uncloud/internal/machine"
"uncloud/internal/machine/network"
)
// MachineToken returns the local machine's token that can be used for adding the machine to a cluster.
// TODO: ideally, this should be an RPC call to the daemon API to ensure the config is created and up-to-date.
func MachineToken(dataDir string) (machine.Token, error) {
cfg, err := machine.ParseConfig(machine.ConfigPath(dataDir))
if err != nil {
if errors.Is(err, os.ErrNotExist) {
return machine.Token{}, fmt.Errorf("load machine config (is uncloudd daemon running?): %w", err)
}
return machine.Token{}, fmt.Errorf("load machine config: %w", err)
}
if len(cfg.Network.PublicKey) == 0 {
return machine.Token{}, errors.New("public key is not set in machine config")
}
ips, err := network.ListRoutableIPs()
if err != nil {
return machine.Token{}, fmt.Errorf("list routable addresses: %w", err)
}
publicIP, err := network.GetPublicIP()
// Ignore the error if failed to get the public IP using API services.
if err == nil {
ips = append([]netip.Addr{publicIP}, ips...)
}
endpoints := make([]netip.AddrPort, len(ips))
for i, ip := range ips {
endpoints[i] = netip.AddrPortFrom(ip, network.WireGuardPort)
}
return machine.NewToken(cfg.Network.PublicKey, endpoints), nil
}
+106
View File
@@ -0,0 +1,106 @@
package network
import (
"context"
"fmt"
"io"
"net"
"net/http"
"net/netip"
"strings"
"time"
)
// ListRoutableIPs returns a list of routable unicast IP addresses.
func ListRoutableIPs() ([]netip.Addr, error) {
interfaces, err := net.Interfaces()
if err != nil {
return nil, fmt.Errorf("list network interfaces: %w", err)
}
var routable []netip.Addr
for _, iface := range interfaces {
if iface.Name == WireGuardInterfaceName || strings.HasPrefix(iface.Name, "docker") {
// Skip the Uncloud WireGuard and Docker interfaces.
continue
}
if iface.Flags&net.FlagUp == 0 || iface.Flags&net.FlagRunning == 0 || iface.Flags&net.FlagLoopback != 0 {
// Skip interfaces:
// * Not administratively UP.
// * The operational status is not RUNNING. This is the closest equivalent to checking for NO-CARRIER.
// * Loopback.
continue
}
// TODO: check for link/ether ifaces?
addrs, aErr := iface.Addrs()
if aErr != nil {
return nil, fmt.Errorf("list unicast addresses for interface %q: %w", iface.Name, err)
}
for _, addr := range addrs {
ipNet, ok := addr.(*net.IPNet)
if !ok {
continue
}
// Includes IPv4 private address space and local IPv6 unicast address space.
if ipNet.IP.IsGlobalUnicast() {
ip, pErr := netip.ParseAddr(ipNet.IP.String())
if pErr != nil {
return nil, fmt.Errorf("parse IP address %q: %w", ipNet.IP, err)
}
routable = append(routable, ip)
}
}
}
return routable, nil
}
func GetPublicIP() (netip.Addr, error) {
services := []struct {
URL string
Parser func([]byte) (netip.Addr, error)
}{
{"https://api.ipify.org", parsePlaintextIP},
{"https://ipinfo.io/ip", parsePlaintextIP},
{"http://ip-api.com/line/?fields=query", parsePlaintextIP},
}
for _, service := range services {
if ip, err := queryIP(service.URL, service.Parser); err == nil {
return ip, nil
}
}
return netip.Addr{}, fmt.Errorf("failed to get public IP from all services")
}
func queryIP(service string, parser func([]byte) (netip.Addr, error)) (netip.Addr, error) {
ctx, cancel := context.WithTimeout(context.Background(), 5*time.Second)
defer cancel()
req, err := http.NewRequestWithContext(ctx, http.MethodGet, service, nil)
if err != nil {
return netip.Addr{}, fmt.Errorf("create request: %w", err)
}
resp, err := http.DefaultClient.Do(req)
if err != nil {
return netip.Addr{}, fmt.Errorf("send request: %w", err)
}
defer func() {
_ = resp.Body.Close()
}()
if resp.StatusCode != http.StatusOK {
return netip.Addr{}, fmt.Errorf("unexpected status code: %d", resp.StatusCode)
}
body, err := io.ReadAll(resp.Body)
if err != nil {
return netip.Addr{}, fmt.Errorf("read response body: %w", err)
}
return parser(body)
}
func parsePlaintextIP(data []byte) (netip.Addr, error) {
return netip.ParseAddr(string(data))
}
+5
View File
@@ -35,6 +35,11 @@ type PeerConfig struct {
PublicKey secret.Secret
}
func (c Config) IsConfigured() bool {
return c.Subnet != (netip.Prefix{}) && c.ManagementIP != (netip.Addr{}) &&
c.PrivateKey != nil && c.PublicKey != nil
}
func (c Config) toDeviceConfig() (wgtypes.Config, error) {
privateKey, err := wgtypes.NewKey(c.PrivateKey)
if err != nil {
+54
View File
@@ -0,0 +1,54 @@
package machine
import (
"encoding/base64"
"encoding/json"
"fmt"
"net/netip"
"strings"
"uncloud/internal/secret"
)
const (
TokenPrefix = "mtkn:"
)
// Token represents the machine's token for joining a cluster.
type Token struct {
PublicKey secret.Secret
Endpoints []netip.AddrPort
}
// NewToken creates a new machine token with the given public key and endpoints.
func NewToken(publicKey secret.Secret, endpoints []netip.AddrPort) Token {
return Token{
PublicKey: publicKey,
Endpoints: endpoints,
}
}
// ParseToken decodes a machine token from the given string.
func ParseToken(s string) (Token, error) {
if strings.HasPrefix(s, TokenPrefix) {
return Token{}, fmt.Errorf("invalid token prefix")
}
decoded, err := base64.StdEncoding.DecodeString(s[len(TokenPrefix):])
if err != nil {
return Token{}, fmt.Errorf("decode token: %w", err)
}
var token Token
if err = json.Unmarshal(decoded, &token); err != nil {
return Token{}, fmt.Errorf("unmarshal token: %w", err)
}
return token, nil
}
// String returns the machine token encoded as a string.
func (t Token) String() (string, error) {
js, err := json.Marshal(t)
if err != nil {
return "", fmt.Errorf("marshal token: %w", err)
}
encoded := base64.StdEncoding.EncodeToString(js)
return TokenPrefix + encoded, nil
}