Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
da09d22b47 |
@@ -1,36 +0,0 @@
|
||||
---
|
||||
name: Bug Report
|
||||
about: Create a report to help us improve
|
||||
title: "[BUG] "
|
||||
labels: bug
|
||||
assignees: ""
|
||||
---
|
||||
|
||||
**Describe the bug**
|
||||
|
||||
<!-- A clear and concise description of what the bug is. -->
|
||||
|
||||
**How to reproduce**
|
||||
|
||||
<!-- Steps to reproduce the behavior:
|
||||
|
||||
1. Run ...
|
||||
2. Do ...
|
||||
-->
|
||||
|
||||
**Expected behavior**
|
||||
|
||||
<!-- A clear and concise description of what you expected to happen. -->
|
||||
|
||||
**Environment:**
|
||||
|
||||
- Uncloud versions:
|
||||
- Control (client) node (`uc --version`):
|
||||
- Uncloud daemon (from the server) (`uncloudd --version`):
|
||||
- OS version (`uname -a`):
|
||||
- Client (control node):
|
||||
- Server:
|
||||
|
||||
**Additional context**
|
||||
|
||||
<!-- Add any other context about the problem here. -->
|
||||
@@ -1 +0,0 @@
|
||||
../AI.md
|
||||
@@ -37,9 +37,7 @@ jobs:
|
||||
(echo "go.mod or go.sum has changed. Please run 'go mod tidy' and commit the changes." && exit 1)
|
||||
|
||||
- name: Run tests
|
||||
run: |
|
||||
make ucind-image
|
||||
make test
|
||||
run: make test
|
||||
timeout-minutes: 10
|
||||
|
||||
check-protobuf:
|
||||
|
||||
@@ -1,39 +0,0 @@
|
||||
name: Lint
|
||||
on:
|
||||
push:
|
||||
branches:
|
||||
- "main"
|
||||
- "test/**"
|
||||
- "release/**"
|
||||
pull_request:
|
||||
branches:
|
||||
- main
|
||||
paths:
|
||||
- "**.go"
|
||||
- "go.*"
|
||||
permissions:
|
||||
contents: read
|
||||
jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
|
||||
|
||||
- name: Set up Go
|
||||
uses: actions/setup-go@d35c59abb061a4a6fb18e82ac0862c26744d6ab5 # v5.5.0
|
||||
with:
|
||||
go-version: "1.23.2"
|
||||
|
||||
- name: golangci-lint
|
||||
uses: golangci/golangci-lint-action@4afd733a84b1f43292c63897423277bb7f4313a9 # v8.0.0
|
||||
with:
|
||||
version: v2.2.2
|
||||
|
||||
- name: Format code
|
||||
run: |
|
||||
make format
|
||||
git diff --exit-code ||
|
||||
(echo "Code is not formatted. Please run 'make format' and commit the changes." && exit 1)
|
||||
|
||||
timeout-minutes: 10
|
||||
@@ -1,42 +0,0 @@
|
||||
version: "2"
|
||||
|
||||
run:
|
||||
concurrency: 4
|
||||
tests: true
|
||||
timeout: 5m
|
||||
|
||||
linters:
|
||||
default: none
|
||||
enable:
|
||||
- bodyclose
|
||||
# - dogsled
|
||||
- dupl
|
||||
# - errcheck
|
||||
- gochecknoinits
|
||||
- goconst
|
||||
# - gocritic
|
||||
# - gocyclo
|
||||
# - godot
|
||||
# - gosec
|
||||
# - govet
|
||||
- ineffassign
|
||||
- misspell
|
||||
- nakedret
|
||||
# - prealloc
|
||||
# - revive
|
||||
# - staticcheck
|
||||
- unconvert
|
||||
# - unparam
|
||||
# - unused
|
||||
- whitespace
|
||||
exclusions:
|
||||
rules:
|
||||
- path: ^test/e2e
|
||||
linters:
|
||||
- goconst # constants here add no value, so we skip goconst only for test/e2e.
|
||||
|
||||
formatters:
|
||||
enable:
|
||||
- gofumpt
|
||||
- goimports
|
||||
|
||||
@@ -1,11 +1,3 @@
|
||||
[tools."aqua:vektra/mockery"]
|
||||
version = "3.5.3"
|
||||
backend = "aqua:vektra/mockery"
|
||||
|
||||
[tools."aqua:vektra/mockery".checksums]
|
||||
"mockery_3.5.3_Darwin_arm64.tar.gz" = "sha256:a3a94b14c7414e148f2252199ffc4a0108d311358f3d336cbe05bb73cb203704"
|
||||
"mockery_3.5.3_Linux_x86_64.tar.gz" = "sha256:ebce416b0175338525246c376885a1579ca6cd4d4015140ba0c70e6b5339a39c"
|
||||
|
||||
[tools.go]
|
||||
version = "1.23.10"
|
||||
backend = "core:go"
|
||||
@@ -14,14 +6,6 @@ backend = "core:go"
|
||||
"go1.23.10.darwin-arm64.tar.gz" = "sha256:25c64bfa8a8fd8e7f62fb54afa4354af8409a4bb2358c2699a1003b733e6fce5"
|
||||
"go1.23.10.linux-amd64.tar.gz" = "sha256:535f9f81802499f2a7dbfa70abb8fda3793725fcc29460f719815f6e10b5fd60"
|
||||
|
||||
[tools.golangci-lint]
|
||||
version = "2.2.2"
|
||||
backend = "aqua:golangci/golangci-lint"
|
||||
|
||||
[tools.golangci-lint.checksums]
|
||||
"golangci-lint-2.2.2-darwin-arm64.tar.gz" = "sha256:d84d94d042c0d495fd1746f3d18948a75de163b17a14e8de3ef840928dd2df74"
|
||||
"golangci-lint-2.2.2-linux-amd64.tar.gz" = "sha256:c27fbde948a87d326feacd21df2f61a9c54dbd2e3bfa185c0a1cd6917a6f964f"
|
||||
|
||||
[tools.protoc]
|
||||
version = "27.3"
|
||||
backend = "aqua:protocolbuffers/protobuf/protoc"
|
||||
|
||||
@@ -2,9 +2,7 @@
|
||||
experimental = true
|
||||
|
||||
[tools]
|
||||
"aqua:vektra/mockery" = "3.5.3"
|
||||
go = "1.23"
|
||||
golangci-lint = "2.2.2"
|
||||
protoc = "27.3"
|
||||
protoc-gen-go = "1.34.2"
|
||||
protoc-gen-go-grpc = "1.5.1"
|
||||
|
||||
@@ -1,4 +0,0 @@
|
||||
packages:
|
||||
github.com/psviderski/uncloud/internal/machine/caddyconfig:
|
||||
interfaces:
|
||||
CaddyfileValidator:
|
||||
@@ -1,244 +0,0 @@
|
||||
# AI.md - Uncloud Project Guide
|
||||
|
||||
This document provides comprehensive information about the Uncloud project for AI assistants to understand the codebase, architecture, and development practices.
|
||||
|
||||
## Project Overview
|
||||
|
||||
**Uncloud** is a lightweight clustering and container orchestration tool that enables deployment and management of web applications across cloud VMs and bare metal servers. It creates a secure WireGuard mesh network between Docker hosts and provides automatic service discovery, load balancing, HTTPS ingress, and simple CLI commands for application management.
|
||||
|
||||
### Key Characteristics
|
||||
|
||||
- **Language**: Go
|
||||
- **Architecture**: Decentralized, no control plane
|
||||
- **Target**: Self-hosted infrastructure without Kubernetes complexity
|
||||
- **License**: View LICENSE file for details
|
||||
- **Status**: Active development, not yet ready for production
|
||||
|
||||
## Core Features
|
||||
|
||||
### 🏗️ Infrastructure
|
||||
|
||||
- **Multi-machine deployment**: Combine cloud VMs, dedicated servers, and bare metal
|
||||
- **Zero-config networking**: Automatic WireGuard mesh with NAT traversal
|
||||
- **Decentralized design**: No central control plane, all machines are equal
|
||||
- **Service discovery**: Built-in DNS server resolves service names to container IPs
|
||||
|
||||
### 🚀 Application Management
|
||||
|
||||
- **Docker Compose compatibility**: Uses familiar Docker Compose format
|
||||
- **Zero-downtime deployments**: Rolling updates without service interruption
|
||||
- **Automatic HTTPS**: Caddy reverse proxy with Let's Encrypt integration
|
||||
- **Managed DNS**: Free `*.cluster.uncloud.run` subdomains via Uncloud DNS service
|
||||
- **Cross-machine scaling**: Run containers across multiple machines
|
||||
|
||||
### 🔧 Developer Experience
|
||||
|
||||
- **Docker-like CLI**: Familiar commands (`uc` binary)
|
||||
- **Imperative operations**: Direct commands vs. declarative state reconciliation
|
||||
- **Remote management**: Control entire infrastructure via SSH to any machine
|
||||
- **Minimal overhead**: ~150MB RAM footprint per machine
|
||||
|
||||
## Architecture
|
||||
|
||||
### Core Components
|
||||
|
||||
1. **CLI (`uc`)** - Main user interface for cluster management
|
||||
2. **Daemon (`uncloudd`)** - Machine daemon running on each node
|
||||
3. **Corrosion** - Distributed SQLite database for cluster state (Fly.io project)
|
||||
4. **Caddy** - Reverse proxy for HTTPS termination and routing
|
||||
5. **WireGuard** - Secure mesh networking between machines
|
||||
|
||||
### Network Architecture
|
||||
|
||||
- Each machine gets unique subnet (e.g., `10.210.0.0/24`, `10.210.1.0/24`)
|
||||
- Containers get cluster-unique IPs for direct communication
|
||||
- Automatic peer discovery and key management
|
||||
- NAT traversal for machines behind firewalls
|
||||
|
||||
### State Management
|
||||
|
||||
- **CRDT-based distributed storage** using Corrosion
|
||||
- **Eventually consistent** state across all machines
|
||||
- **Gossip protocol** (Serf) for state propagation
|
||||
- **No quorum requirements** - partial network splits remain functional
|
||||
|
||||
## Project Structure
|
||||
|
||||
### Key Directories
|
||||
|
||||
- **`cmd/`**: Contains main applications
|
||||
|
||||
- `uncloud/`: CLI tool with subcommands for machine, service, volume management
|
||||
- `uncloudd/`: Daemon that runs on each machine
|
||||
- `ucind/`: Development cluster management for testing
|
||||
|
||||
- **`internal/`**: Internal implementation packages
|
||||
|
||||
- `cli/`: Command-line interface logic
|
||||
- `machine/`: Machine lifecycle and state management
|
||||
- `daemon/`: Daemon implementation and gRPC services
|
||||
- `dns/`: Internal DNS server for service discovery
|
||||
|
||||
- **`pkg/`**: Public API packages for external use
|
||||
|
||||
- `api/`: Core API types and definitions
|
||||
- `client/`: Client libraries for interacting with Uncloud
|
||||
|
||||
- **`experiment/`**: Experimental features and prototypes
|
||||
- **`scripts/`**: Installation and utility scripts
|
||||
- **`test/`**: Test suites and test infrastructure
|
||||
- **`website/`**: Documentation website (Docusaurus)
|
||||
- **`misc/`**: Design documents and guides
|
||||
|
||||
## Key Technologies
|
||||
|
||||
### Core Dependencies
|
||||
|
||||
```go
|
||||
// Networking and orchestration
|
||||
github.com/docker/docker // Docker API client
|
||||
github.com/docker/compose/v2 // Docker Compose integration
|
||||
golang.zx2c4.com/wireguard // WireGuard implementation
|
||||
github.com/hashicorp/serf // Gossip protocol
|
||||
|
||||
// State management
|
||||
github.com/ipfs/go-ds-crdt // CRDT distributed storage
|
||||
github.com/dgraph-io/badger/v3 // Embedded database
|
||||
|
||||
// Web proxy
|
||||
github.com/caddyserver/caddy/v2 // HTTP server and reverse proxy
|
||||
|
||||
// CLI and UX
|
||||
github.com/spf13/cobra // CLI framework
|
||||
github.com/charmbracelet/huh // Interactive forms
|
||||
|
||||
// gRPC and networking
|
||||
google.golang.org/grpc // gRPC framework
|
||||
github.com/siderolabs/grpc-proxy // gRPC proxy for forwarding
|
||||
```
|
||||
|
||||
## Development Workflow
|
||||
|
||||
### Build and Development
|
||||
|
||||
```bash
|
||||
# Build binaries
|
||||
go build -o uncloud ./cmd/uncloud
|
||||
go build -o uncloudd ./cmd/uncloudd
|
||||
```
|
||||
|
||||
### Key Make Targets
|
||||
|
||||
- `proto`: Generate protobuf code
|
||||
- `ucind-cluster`: Create development cluster
|
||||
- `update-dev`: Deploy to development machines
|
||||
- `demo-reset`: Reset demo environment
|
||||
- `fmt`: Format code
|
||||
- `test`: Run all tests
|
||||
- `lint`: Lint the code using golangci-lint
|
||||
- `lint-and-fix`: Lint the code and fix issues whenever possible
|
||||
|
||||
## CLI Commands Structure
|
||||
|
||||
The `uc` CLI provides these main command groups:
|
||||
|
||||
### Machine Management
|
||||
|
||||
```bash
|
||||
uc machine init <user@host> # Initialize new cluster
|
||||
uc machine add <user@host> # Add machine to cluster
|
||||
uc machine ls # List machines
|
||||
uc machine rm <name> # Remove machine
|
||||
```
|
||||
|
||||
### Service Management
|
||||
|
||||
```bash
|
||||
uc run <image> # Run container from image
|
||||
uc deploy # Deploy from compose.yaml
|
||||
uc scale <service> <count> # Scale service replicas
|
||||
uc ls # List services
|
||||
uc rm <service> # Remove service
|
||||
```
|
||||
|
||||
### Context and Connectivity
|
||||
|
||||
```bash
|
||||
uc context ls # List available contexts
|
||||
uc context use <name> # Switch context
|
||||
```
|
||||
|
||||
### Global Flags
|
||||
|
||||
- `--connect`: Connect to remote machine directly, without a config file
|
||||
- `--uncloud-config`: Override config file path
|
||||
|
||||
## Development Guidelines
|
||||
|
||||
### Code Organization
|
||||
|
||||
- **Package naming**: Use clear, descriptive names
|
||||
- **Error handling**: Wrap errors with context using `fmt.Errorf`
|
||||
- **Logging**: Use structured logging with levels
|
||||
- **gRPC**: Services defined in `internal/machine/api/pb/`
|
||||
|
||||
### Testing
|
||||
|
||||
- Unit tests alongside source files (`*_test.go`)
|
||||
- Integration tests in `test/e2e/`
|
||||
- Test fixtures in `test/fixtures/`
|
||||
|
||||
### Dependencies
|
||||
|
||||
- Prefer standard library when possible
|
||||
- Pin versions in `go.mod`
|
||||
- Document rationale for external dependencies
|
||||
|
||||
### Configuration
|
||||
|
||||
- Support environment variables for key settings
|
||||
- Validate configuration early
|
||||
- Provide sensible defaults
|
||||
|
||||
## Troubleshooting and Debugging
|
||||
|
||||
### Common Issues
|
||||
|
||||
- **Networking**: Check WireGuard status, iptables rules
|
||||
- **DNS**: Verify service discovery resolution
|
||||
- **Containers**: Use standard Docker debugging tools
|
||||
- **State sync**: Check Corrosion logs for replication issues
|
||||
|
||||
### Debugging Tools
|
||||
|
||||
- Standard Linux networking tools (`ping`, `traceroute`, `wireshark`)
|
||||
- Docker commands (`docker ps`, `docker logs`)
|
||||
- SSH access to machines for direct inspection
|
||||
- gRPC debugging tools
|
||||
|
||||
### Logs and Monitoring
|
||||
|
||||
- Systemd services (getting logs via `journalctl -u SERVICE_NAME`)
|
||||
- `uncloud` -- Uncloud daemon
|
||||
- `uncloud-corrosion` -- Corrosion process
|
||||
- Machine daemon logs
|
||||
- Container logs via Docker
|
||||
|
||||
## File Patterns and Conventions
|
||||
|
||||
### Important Files to Understand
|
||||
|
||||
- `cmd/uncloud/main.go`: CLI entry point and command structure
|
||||
- `internal/cli/cli.go`: CLI implementation and configuration
|
||||
- `internal/machine/machine.go`: Core machine management
|
||||
- `pkg/api/`: Public API definitions
|
||||
- `misc/design.md`: Architecture and design philosophy
|
||||
- `README.md`: User-facing documentation
|
||||
|
||||
### Configuration Files
|
||||
|
||||
- `go.mod/go.sum`: Go dependency management
|
||||
- `Makefile`: Build and development tasks
|
||||
- `Dockerfile`: Container build instructions forUncloud-in-Docker (used for testing)
|
||||
|
||||
This document should help AI assistants understand the project structure, make informed suggestions, and contribute effectively to the Uncloud codebase.
|
||||
@@ -1,5 +1,6 @@
|
||||
CORROSION_IMAGE ?= ghcr.io/psviderski/corrosion:latest
|
||||
UCIND_IMAGE ?= ghcr.io/psviderski/ucind:latest
|
||||
DOCS_IMAGE ?= ghcr.io/psviderski/uncloud-docs:latest
|
||||
|
||||
update-dev:
|
||||
GOOS=linux GOARCH=amd64 go build -o uncloudd-linux-amd64 ./cmd/uncloudd && \
|
||||
@@ -45,11 +46,6 @@ proto:
|
||||
protoc --go_out=. --go_opt=paths=source_relative --go-grpc_out=. --go-grpc_opt=paths=source_relative \
|
||||
--proto_path=. --proto_path=internal/machine/api/vendor internal/machine/api/pb/*.proto
|
||||
|
||||
.PHONY: proto-mise
|
||||
proto-mise:
|
||||
mise exec -- protoc --go_out=. --go_opt=paths=source_relative --go-grpc_out=. --go-grpc_opt=paths=source_relative \
|
||||
--proto_path=. --proto_path=internal/machine/api/vendor internal/machine/api/pb/*.proto
|
||||
|
||||
.PHONY: corrosion-image
|
||||
corrosion-image:
|
||||
docker build -t "$(CORROSION_IMAGE)" --target corrosion .
|
||||
@@ -66,22 +62,14 @@ ucind-image:
|
||||
ucind-multiarch-image-push:
|
||||
docker buildx build --push --platform linux/amd64,linux/arm64 -t "$(UCIND_IMAGE)" --target ucind .
|
||||
|
||||
.PHONY: mocks
|
||||
mocks:
|
||||
@mockery
|
||||
|
||||
.PHONY: test
|
||||
test:
|
||||
ifeq ($(TEST_NAME),)
|
||||
go test -count=1 -v ./...
|
||||
else
|
||||
go test -race -count=1 -v -run ^$(TEST_NAME)$$ ./...
|
||||
go test -count=1 -v -run ^$(TEST_NAME)$$ ./...
|
||||
endif
|
||||
|
||||
.PHONY: test-e2e
|
||||
test-e2e:
|
||||
go test -race -count=1 -v ./test/e2e
|
||||
|
||||
.PHONY: test-clean
|
||||
test-clean:
|
||||
@CONTAINERS=$$(docker ps --filter "name=ucind-test" -q); \
|
||||
@@ -101,20 +89,6 @@ test-clean:
|
||||
vet:
|
||||
go vet ./...
|
||||
|
||||
.PHONY: format fmt
|
||||
format fmt:
|
||||
GOOS=linux golangci-lint fmt
|
||||
|
||||
LINT_TARGETS := lint lint-and-fix
|
||||
.PHONY: $(LINT_TARGETS) _lint
|
||||
$(LINT_TARGETS): _lint
|
||||
lint: ARGS=
|
||||
lint-and-fix: ARGS=--fix
|
||||
_lint:
|
||||
# Explicitly set OS to Linux to not skip *_linux.go files when running on macOS.
|
||||
# Uncloud daemon won't likely support OS other than Linux anytime soon, so for now we can rely on that.
|
||||
GOOS=linux golangci-lint run $(ARGS)
|
||||
|
||||
.PHONY: cli-docs
|
||||
cli-docs:
|
||||
go run ./cmd/uncloud docs
|
||||
.PHONY: docs-image-push
|
||||
docs-image:
|
||||
docker buildx build --push --platform linux/amd64,linux/arm64 -t "$(DOCS_IMAGE)" ./docs
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
<div align="center">
|
||||
<img src="./website/landing/images/logo.svg" height="100" width="100" alt="Uncloud logo"/>
|
||||
<img src="./website/images/logo.svg" height="100" width="100" alt="Uncloud logo"/>
|
||||
<h1>Uncloud</h1>
|
||||
<p><strong>Docker simplicity. Multi-machine power.</strong></p>
|
||||
|
||||
<p>
|
||||
<a href="https://uncloud.run/docs"><img src="https://img.shields.io/badge/Docs-blue.svg?style=for-the-badge&logo=gitbook&logoColor=white" alt="Documentation"></a>
|
||||
<a href="https://docs.uncloud.run"><img src="https://img.shields.io/badge/Docs-blue.svg?style=for-the-badge&logo=gitbook&logoColor=white" alt="Documentation"></a>
|
||||
<a href="https://discord.gg/eR35KQJhPu"><img src="https://img.shields.io/badge/discord-5865F2.svg?style=for-the-badge&logo=discord&logoColor=white" alt="Join Discord"></a>
|
||||
<a href="https://x.com/psviderski"><img src="https://img.shields.io/badge/follow-black?style=for-the-badge&logo=X&logoColor=while" alt="Follow on X"></a>
|
||||
<a href="https://github.com/sponsors/psviderski"><img src="https://img.shields.io/badge/Donate-EA4AAA.svg?style=for-the-badge&logo=githubsponsors&logoColor=white" alt="Donate"></a>
|
||||
@@ -52,11 +52,11 @@ complexity of Kubernetes.
|
||||
|
||||
## 🎬 Quick demo
|
||||
|
||||
The screenshot below demonstrates how I use Uncloud to deploy https://uncloud.run website to 2 remote machines from
|
||||
the [`compose.yaml`](website/compose.yaml) file on my local machine.
|
||||
The screenshot below demonstrates how I use Uncloud to deploy the [Uncloud Documentation](https://docs.uncloud.run)
|
||||
website to 2 remote machines (why not?) from the [`compose.yaml`](docs/compose.yaml) file on my local machine.
|
||||
|
||||
It exposes the container port `8000/tcp` as HTTPS on the domain `uncloud.run`, served by the Caddy reverse proxy on the
|
||||
remote machines. All managed by Uncloud.
|
||||
It exposes the container port `8000/tcp` as HTTPS on the domain `docs.uncloud.run`, served by the Caddy reverse proxy on
|
||||
the remote machines. All managed by Uncloud.
|
||||
|
||||

|
||||
|
||||
@@ -97,7 +97,7 @@ platform, whether you're running on a $5 VPS, a spare Mac mini, or a rack of bar
|
||||
curl -fsS https://get.uncloud.run/install.sh | sh
|
||||
```
|
||||
|
||||
See [Installation](https://uncloud.run/docs/getting-started/install-cli) for more options.
|
||||
See [Installation](https://docs.uncloud.run/getting-started/install-cli) for more options.
|
||||
|
||||
2. Initialise your first machine:
|
||||
|
||||
@@ -130,15 +130,15 @@ platform, whether you're running on a $5 VPS, a spare Mac mini, or a rack of bar
|
||||
uncloud-uninstall
|
||||
```
|
||||
|
||||
View the [Documentation](https://uncloud.run/docs) for more information.
|
||||
View the [Documentation](https://docs.uncloud.run) for more information.
|
||||
|
||||
## ⚙️ How it works
|
||||
|
||||
Check out the [design document](misc/design.md) to understand Uncloud's design philosophy and goals.
|
||||
Check out the [design document](docs/design.md) to understand Uncloud's design philosophy and goals.
|
||||
|
||||
Here is a diagram of an Uncloud multi-provider cluster of 3 machines:
|
||||
|
||||

|
||||

|
||||
|
||||
<details>
|
||||
<summary>Peek under the hood to see what happens when you run certain commands.</summary>
|
||||
@@ -323,15 +323,6 @@ SQLite database used to share Uncloud's cluster state.
|
||||
features, and be the first to know when it's ready for production use.
|
||||
* Watch this repository for releases.
|
||||
|
||||
## 💖 Sponsors
|
||||
|
||||
These companies and projects are helping Uncloud with their generous sponsorship and/or services:
|
||||
|
||||
<!-- Sentry -->
|
||||
<a href="https://sentry.io/welcome/">
|
||||
<img height="100" alt="Sentry" src="https://github.com/user-attachments/assets/6c1439c0-d20d-40dc-a669-c9aa94651dfa" />
|
||||
</a>
|
||||
|
||||
## ❤️ Contributors
|
||||
|
||||
Thank you [@cedws](https://github.com/cedws) for being the first contributor to Uncloud! 🎉
|
||||
|
||||
@@ -2,9 +2,8 @@ package cluster
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/ucind"
|
||||
"github.com/spf13/cobra"
|
||||
"github.com/psviderski/uncloud/internal/ucind"
|
||||
)
|
||||
|
||||
func NewCreateCommand() *cobra.Command {
|
||||
|
||||
@@ -2,9 +2,8 @@ package cluster
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/ucind"
|
||||
"github.com/spf13/cobra"
|
||||
"github.com/psviderski/uncloud/internal/ucind"
|
||||
)
|
||||
|
||||
func NewRemoveCommand() *cobra.Command {
|
||||
|
||||
@@ -1,76 +0,0 @@
|
||||
package caddy
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"os"
|
||||
|
||||
"github.com/alecthomas/chroma/v2/quick"
|
||||
"github.com/psviderski/uncloud/internal/cli"
|
||||
"github.com/psviderski/uncloud/pkg/api"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
type configOptions struct {
|
||||
machine string
|
||||
noColor bool
|
||||
context string
|
||||
}
|
||||
|
||||
func NewConfigCommand() *cobra.Command {
|
||||
opts := configOptions{}
|
||||
|
||||
cmd := &cobra.Command{
|
||||
Use: "config",
|
||||
Short: "Show the current Caddy configuration (Caddyfile).",
|
||||
Long: "Display the current Caddy configuration (Caddyfile) from the connected machine or a specified one.",
|
||||
RunE: func(cmd *cobra.Command, args []string) error {
|
||||
uncli := cmd.Context().Value("cli").(*cli.CLI)
|
||||
return runConfig(cmd.Context(), uncli, opts)
|
||||
},
|
||||
}
|
||||
|
||||
cmd.Flags().StringVarP(&opts.machine, "machine", "m", "",
|
||||
"Name or ID of the machine to get the configuration from. (default is connected machine)")
|
||||
cmd.Flags().BoolVar(&opts.noColor, "no-color", false,
|
||||
"Disable syntax highlighting for the output.")
|
||||
cmd.Flags().StringVarP(
|
||||
&opts.context, "context", "c", "",
|
||||
"Name of the cluster context. (default is the current context)",
|
||||
)
|
||||
|
||||
return cmd
|
||||
}
|
||||
|
||||
func runConfig(ctx context.Context, uncli *cli.CLI, opts configOptions) error {
|
||||
clusterClient, err := uncli.ConnectCluster(ctx, opts.context)
|
||||
if err != nil {
|
||||
return fmt.Errorf("connect to cluster: %w", err)
|
||||
}
|
||||
defer clusterClient.Close()
|
||||
|
||||
if opts.machine != "" {
|
||||
// If a specific machine is requested, use it to get the Caddy configuration.
|
||||
ctx, _, err = api.ProxyMachinesContext(ctx, clusterClient, []string{opts.machine})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
config, err := clusterClient.Caddy.GetConfig(ctx, nil)
|
||||
if err != nil {
|
||||
return fmt.Errorf("get Caddy config: %w", err)
|
||||
}
|
||||
|
||||
// Print the Caddyfile with syntax highlighting.
|
||||
if opts.noColor {
|
||||
fmt.Print(config.Caddyfile)
|
||||
} else {
|
||||
if err = quick.Highlight(os.Stdout, config.Caddyfile, "caddy", "terminal256", "monokai"); err != nil {
|
||||
// If highlighting fails, fall back to plain output.
|
||||
fmt.Print(config.Caddyfile)
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -5,7 +5,6 @@ import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"maps"
|
||||
"os"
|
||||
"slices"
|
||||
"strings"
|
||||
|
||||
@@ -19,7 +18,6 @@ import (
|
||||
)
|
||||
|
||||
type deployOptions struct {
|
||||
caddyfile string
|
||||
image string
|
||||
machines []string
|
||||
context string
|
||||
@@ -39,8 +37,6 @@ func NewDeployCommand() *cobra.Command {
|
||||
},
|
||||
}
|
||||
|
||||
cmd.Flags().StringVar(&opts.caddyfile, "caddyfile", "",
|
||||
"Path to a custom global Caddy config (Caddyfile) that will be prepended to the auto-generated Caddy config.")
|
||||
cmd.Flags().StringVar(&opts.image, "image", "",
|
||||
"Caddy Docker image to deploy. (default caddy:LATEST_VERSION)")
|
||||
cmd.Flags().StringSliceVarP(&opts.machines, "machine", "m", nil,
|
||||
@@ -55,15 +51,6 @@ func NewDeployCommand() *cobra.Command {
|
||||
}
|
||||
|
||||
func runDeploy(ctx context.Context, uncli *cli.CLI, opts deployOptions) error {
|
||||
caddyfile := ""
|
||||
if opts.caddyfile != "" {
|
||||
data, err := os.ReadFile(opts.caddyfile)
|
||||
if err != nil {
|
||||
return fmt.Errorf("read Caddyfile: %w", err)
|
||||
}
|
||||
caddyfile = strings.TrimSpace(string(data))
|
||||
}
|
||||
|
||||
clusterClient, err := uncli.ConnectCluster(ctx, opts.context)
|
||||
if err != nil {
|
||||
return fmt.Errorf("connect to cluster: %w", err)
|
||||
@@ -104,7 +91,7 @@ func runDeploy(ctx context.Context, uncli *cli.CLI, opts deployOptions) error {
|
||||
placement := api.Placement{
|
||||
Machines: cli.ExpandCommaSeparatedValues(opts.machines),
|
||||
}
|
||||
d, err := clusterClient.NewCaddyDeployment(opts.image, caddyfile, placement)
|
||||
d, err := clusterClient.NewCaddyDeployment(opts.image, placement)
|
||||
if err != nil {
|
||||
return fmt.Errorf("create caddy deployment: %w", err)
|
||||
}
|
||||
|
||||
@@ -10,7 +10,6 @@ func NewRootCommand() *cobra.Command {
|
||||
Short: "Manage Caddy reverse proxy service.",
|
||||
}
|
||||
cmd.AddCommand(
|
||||
NewConfigCommand(),
|
||||
NewDeployCommand(),
|
||||
)
|
||||
return cmd
|
||||
|
||||
@@ -21,7 +21,6 @@ type deployOptions struct {
|
||||
profiles []string
|
||||
services []string
|
||||
noBuild bool
|
||||
recreate bool
|
||||
|
||||
context string
|
||||
}
|
||||
@@ -51,8 +50,6 @@ func NewDeployCommand() *cobra.Command {
|
||||
"Name of the cluster context to deploy to (default is the current context)")
|
||||
cmd.Flags().BoolVarP(&opts.noBuild, "no-build", "n", false,
|
||||
"Do not build images before deploying services. (default false)")
|
||||
cmd.Flags().BoolVar(&opts.recreate, "recreate", false,
|
||||
"Recreate containers even if their configuration and image haven't changed.")
|
||||
|
||||
// TODO: Consider adding a filter flag to specify which machines to deploy to but keep the rest running.
|
||||
// Could be useful to test a new version on a subset of machines before rolling out to all.
|
||||
@@ -111,11 +108,7 @@ func runDeploy(ctx context.Context, uncli *cli.CLI, opts deployOptions) error {
|
||||
}
|
||||
defer clusterClient.Close()
|
||||
|
||||
var strategy deploy.Strategy
|
||||
if opts.recreate {
|
||||
strategy = &deploy.RollingStrategy{ForceRecreate: true}
|
||||
}
|
||||
composeDeploy, err := compose.NewDeploymentWithStrategy(ctx, clusterClient, project, strategy)
|
||||
composeDeploy, err := compose.NewDeployment(ctx, clusterClient, project)
|
||||
if err != nil {
|
||||
return fmt.Errorf("create compose deployment: %w", err)
|
||||
}
|
||||
|
||||
@@ -1,122 +0,0 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"regexp"
|
||||
"strings"
|
||||
|
||||
"github.com/spf13/cobra"
|
||||
"github.com/spf13/cobra/doc"
|
||||
)
|
||||
|
||||
const docsDir = "website/docs/9-cli-reference"
|
||||
|
||||
type cmdWrapper struct {
|
||||
cmd *cobra.Command
|
||||
}
|
||||
|
||||
// NewDocsCommand creates a new hidden command to generate CLI reference docs.
|
||||
func NewDocsCommand() *cobra.Command {
|
||||
wrapper := &cmdWrapper{}
|
||||
cmd := &cobra.Command{
|
||||
Use: "docs",
|
||||
Short: "Generate Uncloud CLI reference docs",
|
||||
SilenceUsage: true,
|
||||
DisableFlagsInUseLine: true,
|
||||
Hidden: true,
|
||||
Args: cobra.NoArgs,
|
||||
ValidArgsFunction: cobra.NoFileCompletions,
|
||||
RunE: func(cmd *cobra.Command, _ []string) error {
|
||||
// Remove existing markdown files.
|
||||
mdFiles, err := filepath.Glob(filepath.Join(docsDir, "*.md"))
|
||||
if err != nil {
|
||||
return fmt.Errorf("list existing CLI docs: %w", err)
|
||||
}
|
||||
for _, f := range mdFiles {
|
||||
if err = os.Remove(f); err != nil {
|
||||
return fmt.Errorf("remove '%s': %w", f, err)
|
||||
}
|
||||
}
|
||||
|
||||
// Generate new CLI reference docs.
|
||||
wrapper.cmd.Root().DisableAutoGenTag = true
|
||||
if err := doc.GenMarkdownTree(cmd.Root(), docsDir); err != nil {
|
||||
return fmt.Errorf("generate CLI docs: %w", err)
|
||||
}
|
||||
|
||||
// Remove *completion*.md files that contain malformatted code blocks that break Docusaurus.
|
||||
mdFiles, err = filepath.Glob(filepath.Join(docsDir, "*completion*.md"))
|
||||
if err != nil {
|
||||
return fmt.Errorf("list generated CLI docs: %w", err)
|
||||
}
|
||||
for _, f := range mdFiles {
|
||||
if err = os.Remove(f); err != nil {
|
||||
return fmt.Errorf("remove '%s': %w", f, err)
|
||||
}
|
||||
}
|
||||
|
||||
// Post-process generated markdown files.
|
||||
mdFiles, err = filepath.Glob(filepath.Join(docsDir, "*.md"))
|
||||
if err != nil {
|
||||
return fmt.Errorf("list generated CLI docs: %w", err)
|
||||
}
|
||||
|
||||
for _, f := range mdFiles {
|
||||
if err = postProcessMarkdown(f); err != nil {
|
||||
return fmt.Errorf("post-process '%s': %w", f, err)
|
||||
}
|
||||
}
|
||||
|
||||
return nil
|
||||
},
|
||||
}
|
||||
|
||||
wrapper.cmd = cmd
|
||||
return cmd
|
||||
}
|
||||
|
||||
// postProcessMarkdown applies transformations to generated markdown files.
|
||||
func postProcessMarkdown(filename string) error {
|
||||
data, err := os.ReadFile(filename)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
content := string(data)
|
||||
|
||||
// Replace "SEE ALSO" with "See also".
|
||||
content = strings.ReplaceAll(content, "SEE ALSO", "See also")
|
||||
// Escape <id> to avoid Docusaurus treating it as an HTML tag.
|
||||
content = strings.ReplaceAll(content, "<id>", "\\<id>")
|
||||
|
||||
// Remove broken links to completion docs.
|
||||
if strings.Contains(content, "[uc completion") {
|
||||
lines := strings.Split(content, "\n")
|
||||
var filteredLines []string
|
||||
for _, line := range lines {
|
||||
if !strings.Contains(line, "[uc completion") {
|
||||
filteredLines = append(filteredLines, line)
|
||||
}
|
||||
}
|
||||
content = strings.Join(filteredLines, "\n")
|
||||
}
|
||||
|
||||
// Adjust heading levels. Process from shortest to longest to avoid double replacements.
|
||||
replacements := []struct {
|
||||
old, new string
|
||||
}{
|
||||
{`(?m)^## `, `# `},
|
||||
{`(?m)^### `, `## `},
|
||||
{`(?m)^#### `, `### `},
|
||||
{`(?m)^##### `, `#### `},
|
||||
}
|
||||
|
||||
for _, r := range replacements {
|
||||
re := regexp.MustCompile(r.old)
|
||||
content = re.ReplaceAllString(content, r.new)
|
||||
}
|
||||
|
||||
return os.WriteFile(filename, []byte(content), 0o644)
|
||||
}
|
||||
@@ -41,7 +41,7 @@ func NewAddCommand() *cobra.Command {
|
||||
if err != nil {
|
||||
return fmt.Errorf("parse remote machine: %w", err)
|
||||
}
|
||||
remoteMachine := &cli.RemoteMachine{
|
||||
remoteMachine := cli.RemoteMachine{
|
||||
User: user,
|
||||
Host: host,
|
||||
Port: port,
|
||||
@@ -59,12 +59,11 @@ func NewAddCommand() *cobra.Command {
|
||||
cmd.Flags().StringVar(
|
||||
&opts.publicIP, "public-ip", "auto",
|
||||
"Public IP address of the machine for ingress configuration. Use 'auto' for automatic detection, "+
|
||||
fmt.Sprintf("blank '' or '%s' to disable ingress on this machine, or specify an IP address.", PublicIPNone),
|
||||
"blank '' or 'none' to disable ingress on this machine, or specify an IP address.",
|
||||
)
|
||||
cmd.Flags().StringVarP(
|
||||
&opts.sshKey, "ssh-key", "i", "",
|
||||
fmt.Sprintf("Path to SSH private key for remote login (if not already added to SSH agent). (default %q)",
|
||||
cli.DefaultSSHKeyPath),
|
||||
&opts.sshKey, "ssh-key", "i", "~/.ssh/id_ed25519",
|
||||
"Path to SSH private key for remote login (if not already added to SSH agent).",
|
||||
)
|
||||
cmd.Flags().StringVar(
|
||||
&opts.version, "version", "latest",
|
||||
@@ -78,12 +77,12 @@ func NewAddCommand() *cobra.Command {
|
||||
return cmd
|
||||
}
|
||||
|
||||
func add(ctx context.Context, uncli *cli.CLI, remoteMachine *cli.RemoteMachine, opts addOptions) error {
|
||||
func add(ctx context.Context, uncli *cli.CLI, remoteMachine cli.RemoteMachine, opts addOptions) error {
|
||||
var publicIP *netip.Addr
|
||||
switch opts.publicIP {
|
||||
case "auto":
|
||||
publicIP = &netip.Addr{}
|
||||
case "", PublicIPNone:
|
||||
case "", "none":
|
||||
publicIP = nil
|
||||
default:
|
||||
ip, err := netip.ParseAddr(opts.publicIP)
|
||||
@@ -146,7 +145,7 @@ func add(ctx context.Context, uncli *cli.CLI, remoteMachine *cli.RemoteMachine,
|
||||
|
||||
// TODO: scale the existing Caddy service to the new machine instead of running a new deployment
|
||||
// that may cause a small downtime.
|
||||
d, err := clusterClient.NewCaddyDeployment(caddyImage, "", api.Placement{})
|
||||
d, err := clusterClient.NewCaddyDeployment(caddyImage, api.Placement{})
|
||||
if err != nil {
|
||||
return fmt.Errorf("create caddy deployment: %w", err)
|
||||
}
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
package machine
|
||||
|
||||
const (
|
||||
// PublicIPNone is the value used to indicate removal of public IP
|
||||
PublicIPNone = "none"
|
||||
)
|
||||
@@ -77,19 +77,18 @@ func NewInitCommand() *cobra.Command {
|
||||
cmd.Flags().StringVar(
|
||||
&opts.publicIP, "public-ip", "auto",
|
||||
"Public IP address of the machine for ingress configuration. Use 'auto' for automatic detection, "+
|
||||
fmt.Sprintf("blank '' or '%s' to disable ingress on this machine, or specify an IP address.", PublicIPNone),
|
||||
"blank '' or 'none' to disable ingress on this machine, or specify an IP address.",
|
||||
)
|
||||
cmd.Flags().StringVarP(
|
||||
&opts.sshKey, "ssh-key", "i", "",
|
||||
fmt.Sprintf("Path to SSH private key for remote login (if not already added to SSH agent). (default %q)",
|
||||
cli.DefaultSSHKeyPath),
|
||||
&opts.sshKey, "ssh-key", "i", "~/.ssh/id_ed25519",
|
||||
"Path to SSH private key for remote login (if not already added to SSH agent).",
|
||||
)
|
||||
cmd.Flags().StringVar(
|
||||
&opts.version, "version", "latest",
|
||||
"Version of the Uncloud daemon to install on the machine.",
|
||||
)
|
||||
cmd.Flags().StringVarP(
|
||||
&opts.context, "context", "c", cli.DefaultContextName,
|
||||
&opts.context, "context", "c", "default",
|
||||
"Name of the created context for the initialised cluster in the Uncloud config.",
|
||||
)
|
||||
|
||||
@@ -106,7 +105,7 @@ func initCluster(ctx context.Context, uncli *cli.CLI, remoteMachine *cli.RemoteM
|
||||
switch opts.publicIP {
|
||||
case "auto":
|
||||
publicIP = &netip.Addr{}
|
||||
case "", PublicIPNone:
|
||||
case "", "none":
|
||||
publicIP = nil
|
||||
default:
|
||||
ip, err := netip.ParseAddr(opts.publicIP)
|
||||
@@ -147,7 +146,7 @@ func initCluster(ctx context.Context, uncli *cli.CLI, remoteMachine *cli.RemoteM
|
||||
}
|
||||
|
||||
if !opts.noCaddy {
|
||||
d, err := client.NewCaddyDeployment("", "", api.Placement{})
|
||||
d, err := client.NewCaddyDeployment("", api.Placement{})
|
||||
if err != nil {
|
||||
return fmt.Errorf("create caddy deployment: %w", err)
|
||||
}
|
||||
|
||||
@@ -1,47 +0,0 @@
|
||||
package machine
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/cli"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
func NewRenameCommand() *cobra.Command {
|
||||
var contextName string
|
||||
cmd := &cobra.Command{
|
||||
Use: "rename OLD_NAME NEW_NAME",
|
||||
Short: "Rename a machine in the cluster.",
|
||||
Long: `Rename a machine in the cluster.
|
||||
|
||||
This command changes the name of an existing machine while preserving all other
|
||||
configuration including network settings, public IP, and cluster membership.`,
|
||||
Args: cobra.ExactArgs(2),
|
||||
RunE: func(cmd *cobra.Command, args []string) error {
|
||||
uncli := cmd.Context().Value("cli").(*cli.CLI)
|
||||
return rename(cmd.Context(), uncli, contextName, args[0], args[1])
|
||||
},
|
||||
}
|
||||
cmd.Flags().StringVarP(
|
||||
&contextName, "context", "c", "",
|
||||
"Name of the cluster context. (default is the current context)",
|
||||
)
|
||||
return cmd
|
||||
}
|
||||
|
||||
func rename(ctx context.Context, uncli *cli.CLI, contextName, oldName, newName string) error {
|
||||
client, err := uncli.ConnectCluster(ctx, contextName)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer client.Close()
|
||||
|
||||
machine, err := client.RenameMachine(ctx, oldName, newName)
|
||||
if err != nil {
|
||||
return fmt.Errorf("rename machine: %w", err)
|
||||
}
|
||||
|
||||
fmt.Printf("Machine %q renamed to %q (ID: %s)\n", oldName, machine.Name, machine.Id)
|
||||
return nil
|
||||
}
|
||||
@@ -14,13 +14,12 @@ import (
|
||||
"github.com/docker/compose/v2/pkg/progress"
|
||||
"github.com/docker/docker/api/types/container"
|
||||
"github.com/psviderski/uncloud/internal/cli"
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
"github.com/psviderski/uncloud/pkg/api"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
type removeOptions struct {
|
||||
noReset bool
|
||||
force bool
|
||||
yes bool
|
||||
context string
|
||||
}
|
||||
@@ -31,7 +30,7 @@ func NewRmCommand() *cobra.Command {
|
||||
cmd := &cobra.Command{
|
||||
Use: "rm MACHINE",
|
||||
Aliases: []string{"remove", "delete"},
|
||||
Short: "Remove a machine from a cluster and reset it.",
|
||||
Short: "Remove a machine from a cluster.",
|
||||
Args: cobra.ExactArgs(1),
|
||||
RunE: func(cmd *cobra.Command, args []string) error {
|
||||
uncli := cmd.Context().Value("cli").(*cli.CLI)
|
||||
@@ -43,14 +42,11 @@ func NewRmCommand() *cobra.Command {
|
||||
"Name of the cluster context. (default is the current context)")
|
||||
cmd.Flags().BoolVarP(&opts.yes, "yes", "y", false,
|
||||
"Do not prompt for confirmation before removing the machine.")
|
||||
cmd.Flags().BoolVar(&opts.noReset, "no-reset", false,
|
||||
"Do not reset the machine after removing it from the cluster. This will leave all containers and data intact.")
|
||||
|
||||
return cmd
|
||||
}
|
||||
|
||||
func remove(ctx context.Context, uncli *cli.CLI, nameOrID string, opts removeOptions) error {
|
||||
// TODO: automatically choose a connection to the machine that is not being removed.
|
||||
func remove(ctx context.Context, uncli *cli.CLI, machineName string, opts removeOptions) error {
|
||||
client, err := uncli.ConnectCluster(ctx, opts.context)
|
||||
if err != nil {
|
||||
return fmt.Errorf("connect to cluster: %w", err)
|
||||
@@ -58,46 +54,22 @@ func remove(ctx context.Context, uncli *cli.CLI, nameOrID string, opts removeOpt
|
||||
defer client.Close()
|
||||
|
||||
// Verify the machine exists and list all service containers on it including stopped ones.
|
||||
mctx, machines, err := api.ProxyMachinesContext(ctx, client, []string{nameOrID})
|
||||
listCtx, machines, err := api.ProxyMachinesContext(ctx, client, []string{machineName})
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if len(machines) == 0 {
|
||||
return fmt.Errorf("machine '%s' not found in the cluster", nameOrID)
|
||||
return fmt.Errorf("machine '%s' not found in the cluster", machineName)
|
||||
}
|
||||
m := machines[0].Machine
|
||||
|
||||
// Verify if the machine being removed is the proxy machine we're connected to.
|
||||
proxyMachine, err := client.MachineClient.Inspect(ctx, nil)
|
||||
if err != nil {
|
||||
return fmt.Errorf("inspect proxy machine: %w", err)
|
||||
}
|
||||
if proxyMachine.Id == m.Id {
|
||||
allMachines, err := client.ListMachines(ctx, nil)
|
||||
if err != nil {
|
||||
return fmt.Errorf("list machines: %w", err)
|
||||
}
|
||||
if len(allMachines) > 1 {
|
||||
return errors.New("cannot remove the machine you are currently connected to. " +
|
||||
"Please connect to another machine in the cluster and try again. " +
|
||||
"Use --connect flag or update 'connections' for the cluster context in your Uncloud config")
|
||||
// It's ok to remove the proxy machine if it's the last one in the cluster.
|
||||
}
|
||||
}
|
||||
|
||||
// TODO: mark the machine as being removed and unschedulable when this is possible to prevent new containers
|
||||
// from being scheduled on it while the removal is in progress.
|
||||
|
||||
reset := !opts.noReset
|
||||
var containers []api.ServiceContainer
|
||||
reachable := false
|
||||
if reset {
|
||||
// Check if the machine is up and has service containers.
|
||||
listOpts := container.ListOptions{All: true}
|
||||
machineContainers, err := client.Docker.ListServiceContainers(mctx, "", listOpts)
|
||||
if err == nil {
|
||||
reachable = true
|
||||
containers = machineContainers[0].Containers
|
||||
machineContainers, err := client.Docker.ListServiceContainers(listCtx, "", listOpts)
|
||||
if err != nil {
|
||||
return fmt.Errorf("list containers: %w", err)
|
||||
}
|
||||
containers := machineContainers[0].Containers
|
||||
|
||||
if len(containers) > 0 {
|
||||
plural := ""
|
||||
if len(containers) > 1 {
|
||||
@@ -106,18 +78,11 @@ func remove(ctx context.Context, uncli *cli.CLI, nameOrID string, opts removeOpt
|
||||
fmt.Printf("Found %d service container%s on machine '%s':\n", len(containers), plural, m.Name)
|
||||
fmt.Println(formatContainerTree(containers))
|
||||
fmt.Println()
|
||||
fmt.Println("This will remove all service containers from the machine, remove it from the cluster, " +
|
||||
"and reset it to the uninitialised state.")
|
||||
fmt.Println("This will remove all service containers on the machine, reset it to the uninitialised state, " +
|
||||
"and remove it from the cluster.")
|
||||
} else {
|
||||
fmt.Printf("No service containers found on machine '%s'.\n", m.Name)
|
||||
fmt.Println("This will remove the machine from the cluster and reset it to the uninitialised state.")
|
||||
}
|
||||
} else {
|
||||
fmt.Printf("This will remove machine '%s' from the cluster without resetting it as it's unreachable.\n",
|
||||
m.Name)
|
||||
}
|
||||
} else {
|
||||
fmt.Printf("This will remove machine '%s' from the cluster without resetting it.\n", m.Name)
|
||||
fmt.Println("This will reset the machine to the uninitialised state and remove it from the cluster.")
|
||||
}
|
||||
|
||||
if !opts.yes {
|
||||
@@ -131,37 +96,23 @@ func remove(ctx context.Context, uncli *cli.CLI, nameOrID string, opts removeOpt
|
||||
}
|
||||
}
|
||||
|
||||
if reset && len(containers) > 0 {
|
||||
if len(containers) > 0 {
|
||||
err = progress.RunWithTitle(ctx, func(ctx context.Context) error {
|
||||
return removeContainers(ctx, client, containers)
|
||||
}, uncli.ProgressOut(), "Removing containers")
|
||||
|
||||
if err != nil {
|
||||
return fmt.Errorf("remove containers: %w", err)
|
||||
}
|
||||
fmt.Println()
|
||||
}
|
||||
|
||||
if _, err = client.RemoveMachine(ctx, &pb.RemoveMachineRequest{Id: m.Id}); err != nil {
|
||||
return fmt.Errorf("remove machine from cluster: %w", err)
|
||||
}
|
||||
fmt.Printf("Machine '%s' removed from the cluster.\n", m.Name)
|
||||
// TODO: 4. Implement and call Reset via Machine API to reset the machine state to uninitialised.
|
||||
// TODO: 5. Remove the machine from the cluster store.
|
||||
|
||||
if reset && reachable {
|
||||
_, err = client.MachineClient.Reset(mctx, &pb.ResetRequest{})
|
||||
if err != nil {
|
||||
fmt.Printf("WARNING: Failed to reset machine: %v\n", err)
|
||||
} else {
|
||||
fmt.Println("Machine reset initiated and will complete in the background.")
|
||||
}
|
||||
}
|
||||
|
||||
// TODO: remove the connection to the machine from the uncloud config if it exists. We need a way to associate
|
||||
// the machine with its connection in the config, e.g. by storing the machine name in the connection metadata.
|
||||
|
||||
// TODO: If Caddy was running on this machine and a cluster domain is reserved,
|
||||
// let the user know that the DNS records should be updated.
|
||||
|
||||
return nil
|
||||
return fmt.Errorf("resetting machine is not fully implemented yet")
|
||||
//fmt.Printf("Machine '%s' removed from the cluster.\n", m.Name)
|
||||
//return nil
|
||||
}
|
||||
|
||||
// formatContainerTree formats a list of containers grouped by service as a tree structure.
|
||||
|
||||
@@ -14,9 +14,7 @@ func NewRootCommand() *cobra.Command {
|
||||
NewAddCommand(),
|
||||
NewInitCommand(),
|
||||
NewListCommand(),
|
||||
NewRenameCommand(),
|
||||
NewRmCommand(),
|
||||
NewUpdateCommand(),
|
||||
NewTokenCommand(),
|
||||
)
|
||||
return cmd
|
||||
|
||||
@@ -2,10 +2,9 @@ package machine
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/spf13/cobra"
|
||||
"github.com/psviderski/uncloud/internal/daemon"
|
||||
"github.com/psviderski/uncloud/internal/machine"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
type tokenOptions struct {
|
||||
|
||||
@@ -1,128 +0,0 @@
|
||||
package machine
|
||||
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/cli"
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
type updateOptions struct {
|
||||
name string
|
||||
publicIP string
|
||||
context string
|
||||
}
|
||||
|
||||
func NewUpdateCommand() *cobra.Command {
|
||||
opts := updateOptions{}
|
||||
cmd := &cobra.Command{
|
||||
Use: "update",
|
||||
Short: "Update machine configuration in the cluster.",
|
||||
Long: `Update machine configuration in the cluster.
|
||||
|
||||
This command allows setting various machine properties including:
|
||||
- Machine name (--name)
|
||||
- Public IP address (--public-ip)
|
||||
|
||||
At least one flag must be specified to perform an update operation.`,
|
||||
Args: cobra.ExactArgs(1),
|
||||
RunE: func(cmd *cobra.Command, args []string) error {
|
||||
uncli := cmd.Context().Value("cli").(*cli.CLI)
|
||||
return update(cmd.Context(), uncli, cmd, opts, args[0])
|
||||
},
|
||||
}
|
||||
|
||||
cmd.Flags().StringVar(
|
||||
&opts.name, "name", "",
|
||||
"New name for the machine",
|
||||
)
|
||||
cmd.Flags().StringVar(
|
||||
&opts.publicIP, "public-ip", "",
|
||||
fmt.Sprintf("Public IP address of the machine for ingress configuration. Use '%s' or '' to remove the public IP.", PublicIPNone),
|
||||
)
|
||||
cmd.Flags().StringVarP(
|
||||
&opts.context, "context", "c", "",
|
||||
"Name of the cluster context. (default is the current context)",
|
||||
)
|
||||
|
||||
return cmd
|
||||
}
|
||||
|
||||
func update(ctx context.Context, uncli *cli.CLI, cmd *cobra.Command, opts updateOptions, machineNameOrID string) error {
|
||||
// Check if at least one flag was explicitly set
|
||||
if !cmd.Flags().Changed("name") && !cmd.Flags().Changed("public-ip") {
|
||||
return fmt.Errorf("at least one update flag must be specified (--name, --public-ip)")
|
||||
}
|
||||
|
||||
client, err := uncli.ConnectCluster(ctx, opts.context)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
defer client.Close()
|
||||
|
||||
// First, resolve the machine to get its ID
|
||||
machine, err := client.InspectMachine(ctx, machineNameOrID)
|
||||
if err != nil {
|
||||
return fmt.Errorf("find machine: %w", err)
|
||||
}
|
||||
|
||||
// Build the update request
|
||||
req := &pb.UpdateMachineRequest{
|
||||
MachineId: machine.Machine.Id,
|
||||
}
|
||||
|
||||
if opts.name != "" {
|
||||
req.Name = &opts.name
|
||||
}
|
||||
|
||||
// Check if --public-ip flag was explicitly provided
|
||||
if cmd.Flags().Changed("public-ip") {
|
||||
if opts.publicIP == "" || opts.publicIP == PublicIPNone {
|
||||
req.PublicIp = &pb.IP{} // Empty IP to signal removal
|
||||
} else {
|
||||
// Parse and validate the public IP
|
||||
ip, err := netip.ParseAddr(opts.publicIP)
|
||||
if err != nil {
|
||||
return fmt.Errorf("invalid public IP address %q: %w", opts.publicIP, err)
|
||||
}
|
||||
req.PublicIp = pb.NewIP(ip)
|
||||
}
|
||||
}
|
||||
|
||||
// Perform the update operation
|
||||
updatedMachine, err := client.UpdateMachine(ctx, req)
|
||||
if err != nil {
|
||||
return fmt.Errorf("update machine: %w", err)
|
||||
}
|
||||
|
||||
// Report what was changed
|
||||
changes := make([]string, 0)
|
||||
if opts.name != "" {
|
||||
changes = append(changes, fmt.Sprintf("name: %q -> %q", machine.Machine.Name, updatedMachine.Name))
|
||||
}
|
||||
if cmd.Flags().Changed("public-ip") {
|
||||
oldIP := PublicIPNone
|
||||
if machine.Machine.PublicIp != nil {
|
||||
if addr, err := machine.Machine.PublicIp.ToAddr(); err == nil {
|
||||
oldIP = addr.String()
|
||||
}
|
||||
}
|
||||
newIP := PublicIPNone
|
||||
if updatedMachine.PublicIp != nil {
|
||||
if addr, err := updatedMachine.PublicIp.ToAddr(); err == nil {
|
||||
newIP = addr.String()
|
||||
}
|
||||
}
|
||||
changes = append(changes, fmt.Sprintf("public IP: %s -> %s", oldIP, newIP))
|
||||
}
|
||||
|
||||
fmt.Printf("Machine %q (ID: %s) configuration updated:\n", updatedMachine.Name, updatedMachine.Id)
|
||||
for _, change := range changes {
|
||||
fmt.Printf(" %s\n", change)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
@@ -27,7 +27,7 @@ type globalOptions struct {
|
||||
func main() {
|
||||
opts := globalOptions{}
|
||||
cmd := &cobra.Command{
|
||||
Use: "uc",
|
||||
Use: "uncloud",
|
||||
Short: "A CLI tool for managing Uncloud resources such as clusters, machines, and services.",
|
||||
Version: version.String(),
|
||||
SilenceUsage: true,
|
||||
@@ -75,7 +75,6 @@ func main() {
|
||||
|
||||
cmd.AddCommand(
|
||||
NewDeployCommand(),
|
||||
NewDocsCommand(),
|
||||
NewBuildCommand(),
|
||||
caddy.NewRootCommand(),
|
||||
cmdcontext.NewRootCommand(),
|
||||
|
||||
@@ -9,6 +9,7 @@ import (
|
||||
|
||||
"github.com/docker/docker/pkg/stringid"
|
||||
"github.com/docker/go-units"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/cli"
|
||||
"github.com/spf13/cobra"
|
||||
)
|
||||
|
||||
@@ -17,7 +17,6 @@ import (
|
||||
)
|
||||
|
||||
type runOptions struct {
|
||||
caddyfile string
|
||||
command []string
|
||||
cpu dockeropts.NanoCPUs
|
||||
entrypoint string
|
||||
@@ -58,9 +57,6 @@ func NewRunCommand() *cobra.Command {
|
||||
},
|
||||
}
|
||||
|
||||
cmd.Flags().StringVar(&opts.caddyfile, "caddyfile", "",
|
||||
"Path to a custom Caddy config (Caddyfile) for the service. "+
|
||||
"Cannot be used together with non-@host published ports.")
|
||||
cmd.Flags().VarP(&opts.cpu, "cpu", "",
|
||||
"Maximum number of CPU cores a service container can use. Fractional values are allowed: "+
|
||||
"0.5 for half a core or 2.25 for two and a quarter cores.")
|
||||
@@ -86,7 +82,7 @@ func NewRunCommand() *cobra.Command {
|
||||
"Give extended privileges to service containers. This is a security risk and should be used with caution.")
|
||||
cmd.Flags().StringSliceVarP(&opts.publish, "publish", "p", nil,
|
||||
"Publish a service port to make it accessible outside the cluster. Can be specified multiple times.\n"+
|
||||
"Format: [hostname:]container_port[/protocol] or [host_ip:]host_port:container_port[/protocol]@host\n"+
|
||||
"Format: [hostname:][load_balancer_port:]container_port[/protocol] or [host_ip:]:host_port:container_port[/protocol]@host\n"+
|
||||
"Supported protocols: tcp, udp, http, https (default is tcp). If a hostname for http(s) port is not specified\n"+
|
||||
"and a cluster domain is reserved, service-name.cluster-domain will be used as the hostname.\n"+
|
||||
"Examples:\n"+
|
||||
@@ -165,15 +161,6 @@ func run(ctx context.Context, uncli *cli.CLI, opts runOptions) error {
|
||||
func prepareServiceSpec(opts runOptions) (api.ServiceSpec, error) {
|
||||
var spec api.ServiceSpec
|
||||
|
||||
caddyfile := ""
|
||||
if opts.caddyfile != "" {
|
||||
data, err := os.ReadFile(opts.caddyfile)
|
||||
if err != nil {
|
||||
return spec, fmt.Errorf("read Caddyfile: %w", err)
|
||||
}
|
||||
caddyfile = strings.TrimSpace(string(data))
|
||||
}
|
||||
|
||||
env, err := parseEnv(opts.env)
|
||||
if err != nil {
|
||||
return spec, err
|
||||
@@ -231,12 +218,6 @@ func prepareServiceSpec(opts runOptions) (api.ServiceSpec, error) {
|
||||
Volumes: volumes,
|
||||
}
|
||||
|
||||
if caddyfile != "" {
|
||||
spec.Caddy = &api.CaddySpec{
|
||||
Config: caddyfile,
|
||||
}
|
||||
}
|
||||
|
||||
// Overwrite the default ENTRYPOINT of the image or reset it if an empty string is passed.
|
||||
if opts.entrypoint != "" {
|
||||
spec.Container.Entrypoint = []string{opts.entrypoint}
|
||||
|
||||
@@ -2,9 +2,7 @@
|
||||
*
|
||||
|
||||
# Allow files and directories.
|
||||
!blog/
|
||||
!docs/
|
||||
!landing/
|
||||
!src/
|
||||
!static/
|
||||
!pkg/
|
||||
@@ -5,5 +5,5 @@
|
||||
:8000 {
|
||||
root * /usr/share/caddy
|
||||
file_server
|
||||
log
|
||||
try_files {path} /index.html
|
||||
}
|
||||
@@ -19,12 +19,9 @@ RUN npm ci
|
||||
## Build the static site.
|
||||
RUN npm run build
|
||||
|
||||
# Stage 3: Serve static Docusaurus site and landing page with Caddy.
|
||||
# Stage 3: Serve static site with Caddy.
|
||||
FROM caddy:2.10.0-alpine AS caddy
|
||||
## Copy the Caddyfile.
|
||||
COPY ./Caddyfile /etc/caddy/Caddyfile
|
||||
## Copy the Docusaurus build output.
|
||||
COPY --from=prod /opt/docusaurus/build /usr/share/caddy
|
||||
# Copy the landing page assets.
|
||||
COPY landing/images /usr/share/caddy/images
|
||||
COPY landing/index.html landing/style.css /usr/share/caddy/
|
||||
@@ -0,0 +1,41 @@
|
||||
# Website
|
||||
|
||||
This website is built using [Docusaurus](https://docusaurus.io/), a modern static website generator.
|
||||
|
||||
### Installation
|
||||
|
||||
```
|
||||
$ yarn
|
||||
```
|
||||
|
||||
### Local Development
|
||||
|
||||
```
|
||||
$ yarn start
|
||||
```
|
||||
|
||||
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
|
||||
|
||||
### Build
|
||||
|
||||
```
|
||||
$ yarn build
|
||||
```
|
||||
|
||||
This command generates static content into the `build` directory and can be served using any static contents hosting service.
|
||||
|
||||
### Deployment
|
||||
|
||||
Using SSH:
|
||||
|
||||
```
|
||||
$ USE_SSH=true yarn deploy
|
||||
```
|
||||
|
||||
Not using SSH:
|
||||
|
||||
```
|
||||
$ GIT_USER=<Your GitHub username> yarn deploy
|
||||
```
|
||||
|
||||
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the `gh-pages` branch.
|
||||
@@ -1,31 +1,39 @@
|
||||
---
|
||||
title: How to connect Docker containers across multiple hosts with WireGuard
|
||||
description: Learn how to configure a WireGuard overlay network that lets Docker containers securely communicate
|
||||
across multiple hosts. No exposed ports needed.
|
||||
slug: connect-docker-containers-across-hosts-wireguard
|
||||
image: ./wireguard-overlay.png
|
||||
authors: psviderski
|
||||
tags: [ docker, wireguard, networking, vpn ]
|
||||
---
|
||||
# WireGuard overlay network for Docker containers
|
||||
|
||||
You want your Docker containers to talk to each other, but they're running on different machines. Perhaps across
|
||||
different cloud providers or mixing cloud with on-prem. The usual approach of mapping services to host ports quickly
|
||||
becomes a pain. Worse, if they're on the public internet, you need to secure every exposed endpoint with TLS and auth.
|
||||
# How to connect Docker containers across multiple hosts using WireGuard
|
||||
|
||||
What if your containers on different machines could communicate directly without exposing any ports? Using their private
|
||||
Docker IPs, as if they were on the same machine. Here's how you can use pure WireGuard and some clever networking tricks
|
||||
to make this work.
|
||||
# Connect Docker containers across multiple hosts with WireGuard
|
||||
|
||||
You have Docker containers running on different Linux machines. You want container A on one machine to talk directly to
|
||||
container B on another machine using their private IPs. For example, to run your application and database containers on
|
||||
separate machines without exposing them publicly. Here's how you can use pure WireGuard and some networking tricks to
|
||||
make this work.
|
||||
|
||||
I implemented this technique to enable cross-machine container communication in
|
||||
[Uncloud](https://github.com/psviderski/uncloud), an open source clustering and deployment tool for Docker.
|
||||
|
||||
* [What we're building](#what-were-building)
|
||||
* [Prequisites](#prerequisites)
|
||||
* [Step 1: Configure Docker networks](#step-1-configure-docker-networks)
|
||||
* [Step 2: Connect Docker networks with WireGuard](#step-2-connect-docker-networks-with-wireguard)
|
||||
* [Step 3: Configure IP routing](#step-3-configure-ip-routing)
|
||||
* [Step 4: Testing](#step-4-testing)
|
||||
* [Step 5: Make the configuration persistent](#step-5-make-the-configuration-persistent)
|
||||
* [Scaling beyond two machines and limitations](#scaling-beyond-two-machines-and-limitations)
|
||||
* [Automating with Uncloud](#automating-with-uncloud)
|
||||
* [Alternative solutions](#alternative-solutions)
|
||||
* [Conclusion](#conclusion)
|
||||
|
||||
## What we're building
|
||||
|
||||
Docker containers are typically connected to a [bridge network](https://docs.docker.com/engine/network/drivers/bridge/)
|
||||
on their host machine, which allows them to communicate with each other. A bridge network also provides isolation from
|
||||
containers not connected to it and other networks on the host. What we want to achieve is connecting these bridge
|
||||
containers not connected to it and other networks on the host. What we want to achieve is to connect these bridge
|
||||
networks across machines so that containers on different machines can communicate as if they were connected to the same
|
||||
local bridge network.
|
||||
|
||||
The incantation we need is called a site-to-site VPN. Any solution would work. Moreover, if the machines are on the same
|
||||
local network, they're already connected and only lack the appropriate routing configuration. But I'll describe a more
|
||||
local network, they're already connected and only miss the appropriate routing configuration. But I'll describe a more
|
||||
versatile approach that works even when the machines are on different continents or behind NAT. WireGuard is the ideal
|
||||
solution for this use case: it's lightweight, [fast](https://www.wireguard.com/performance/), simple to configure,
|
||||
provides [strong security](https://www.wireguard.com/protocol/) and NAT traversal.
|
||||
@@ -37,21 +45,19 @@ communicate with each other using their private IPs.
|
||||
|
||||
I will use these two machines:
|
||||
|
||||
* Machine 1: Debian 12 virtual machine in my homelab network in Australia, which is behind NAT
|
||||
* Machine 1: Debian 12 virtual machine in my homelab network in Australia which is behind NAT
|
||||
* Machine 2: Ubuntu 24.04 server from Hetzner in Finland that has a public IP
|
||||
|
||||

|
||||
|
||||
<!-- truncate -->
|
||||

|
||||
|
||||
## Prerequisites
|
||||
|
||||
- Basic knowledge of [Docker networking](https://docs.docker.com/network/) and [WireGuard](https://www.wireguard.com/).
|
||||
* Basic knowledge of [Docker networking](https://docs.docker.com/network/) and [WireGuard](https://www.wireguard.com/).
|
||||
If you're new to these topics, you might want to read up on them first.
|
||||
- At least two Linux machines with root access and Docker installed. They should be on the same network or be able to
|
||||
communicate over the internet.
|
||||
* At least two Linux machines with root access and Docker installed. They should be on the same network or reachable
|
||||
over the internet.
|
||||
|
||||
## Step 1: Configure Docker networks
|
||||
# Step 1: Configure Docker networks
|
||||
|
||||
Most of the commands in this guide require root privileges. You can run them with `sudo` or log in as root. I'll start
|
||||
root shells on both machines with `sudo -i` for convenience.
|
||||
@@ -64,7 +70,7 @@ Therefore, let's create new Docker bridge networks on each machine with manually
|
||||
choose any subnets from
|
||||
the [private IPv4 address ranges](https://en.wikipedia.org/wiki/Private_network#Private_IPv4_addresses)
|
||||
that do not overlap with each other or with your existing networks. I'll use `10.200.1.0/24` and `10.200.2.0/24`
|
||||
for Machine 1 and Machine 2, respectively. They don't even need to be sequential or be part of the same larger network.
|
||||
for Machine 1 and Machine 2 respectively. They don't even need to be sequential or be part of the same larger network.
|
||||
However, using a common parent network (like `10.200.0.0/16` in my case) can simplify firewall rules and make it easier
|
||||
to manage more machines later.
|
||||
|
||||
@@ -81,16 +87,16 @@ Starting with Docker 28.2.0 ([PR](https://github.com/moby/moby/pull/49832)), you
|
||||
host interfaces you
|
||||
allow [direct routing](https://docs.docker.com/engine/network/packet-filtering-firewalls/#direct-routing) to containers
|
||||
in bridge networks. This is done by specifying the `com.docker.network.bridge.trusted_host_interfaces` option when
|
||||
creating the network. In our case, we want to allow routing via the WireGuard interface `wg0` that will be created in
|
||||
the next step.
|
||||
creating the network. In our case, we want to allow routing via the WireGuard interface `wg0` that we be created in the
|
||||
next step.
|
||||
|
||||
Provide this option even if you're using an older Docker version, as it'll be required if you upgrade Docker in the
|
||||
Provide this option even if you're using an older Docker version as it'll be required if you upgrade Docker in the
|
||||
future.
|
||||
|
||||
## Step 2: Connect Docker networks with WireGuard
|
||||
|
||||
By default, WireGuard uses the UDP port 51820 for communication. To establish a tunnel, at least one of the machines
|
||||
needs to be able to reach the other's port over the internet or local network. Please make sure it's not blocked by a
|
||||
By default, WireGuard uses the UDP port 51280 for communication. To establish a tunnel, at least one of the machines
|
||||
need to be able to reach the other's port over the internet or local network. Please make sure it's not blocked by a
|
||||
firewall on both machines.
|
||||
|
||||
For example, when using `iptables`, you can allow incoming UDP traffic on port 51820 with the following command:
|
||||
@@ -122,7 +128,7 @@ PrivateKey = <replace with 'privatekey' file content from Machine 1>
|
||||
|
||||
[Peer]
|
||||
PublicKey = <replace with 'publickey' file content from Machine 2>
|
||||
# IP ranges for which a peer will route traffic: Docker subnet on Machine 2
|
||||
# IP ranges for which a peer will route traffic - Docker subnet on Machine 2
|
||||
AllowedIPs = 10.200.2.0/24
|
||||
# Public IP of Machine 2
|
||||
Endpoint = 157.180.72.195:51820
|
||||
@@ -139,7 +145,7 @@ PrivateKey = <replace with 'privatekey' file content from Machine 2>
|
||||
|
||||
[Peer]
|
||||
PublicKey = <replace with 'publickey' file content from Machine 1>
|
||||
# IP ranges for which a peer will route traffic: Docker subnet on Machine 1
|
||||
# IP ranges for which a peer will route traffic - Docker subnet on Machine 1
|
||||
AllowedIPs = 10.200.1.0/24
|
||||
# Reachable endpoint of Machine 1
|
||||
# Endpoint =
|
||||
@@ -156,14 +162,14 @@ In my case, Machine 1 is behind NAT in my private homelab network which is not r
|
||||
server (Machine 2). The bidirectional tunnel can still be established in this case but Machine 1 must initiate the
|
||||
connection.
|
||||
|
||||
If both of your machines are reachable from each other, you should specify the `Endpoint` option in both configs which
|
||||
If both of your machine are reachable from each other, you should specify the `Endpoint` option in both configs which
|
||||
will allow them to establish the connection without waiting for the other side to initiate it. If both of your machines
|
||||
are behind NAT, see [NAT to NAT Connections](https://github.com/pirate/wireguard-docs#NAT-to-NAT-Connections) for more
|
||||
information.
|
||||
|
||||
Note also that we don't set the `Address` option in the configs because we don't want to assign any IP addresses to the
|
||||
Note also that we don't set `Address` option in the configs because we don't want to assign any IP addresses to the
|
||||
WireGuard interfaces. We want the tunnel to only encapsulate and transfer packets from the `multi-host` bridge networks
|
||||
and don't want either end of it to be the destination for the packets.
|
||||
and don't want any end of it to be the destination for the packets.
|
||||
|
||||
As the key pairs are now specified in the configuration files, you can remove the `privatekey` and `publickey` files on
|
||||
both machines:
|
||||
@@ -199,19 +205,14 @@ If you see the `latest handshake` time updating, it means the tunnel is working
|
||||
|
||||
## Step 3: Configure IP routing
|
||||
|
||||
You've established the WireGuard tunnel, but packets between containers won't flow yet. You need to configure IP routing
|
||||
between the tunnel and the container networks.
|
||||
|
||||
Docker daemon automatically enables IP forwarding in the kernel when it starts, so you don't need to manually configure
|
||||
`net.ipv4.ip_forward` with `sysctl`.
|
||||
|
||||
The challenge is that Docker blocks traffic between external interfaces and container networks by default for security
|
||||
reasons. You need to explicitly allow WireGuard traffic from `wg0` interface to reach your containers via the
|
||||
`multi-host` bridge interface. Docker uses iptables, so you can allow this traffic by adding a rule to the `FORWARD`
|
||||
chain before any other Docker-managed rules that would drop it.
|
||||
|
||||
Fortunately, Docker creates a special `DOCKER-USER` chain exactly for this purpose. It's processed before other
|
||||
Docker-managed chains, allowing you to add custom rules that won't be overridden by Docker.
|
||||
However, Docker blocks traffic between external interfaces and container networks by default for security. You need to
|
||||
explicitly allow WireGuard traffic from `wg0` interface to reach your containers via the `multi-host` bridge interface.
|
||||
Docker uses iptables, so you can allow this traffic by adding a rule to the `FORWARD` chain before any other
|
||||
Docker-managed rules that would drop it. Luckily, Docker creates a special `DOCKER-USER` chain exactly for this purpose
|
||||
that the `FORWARD` chain jumps to before jumping to any other Docker-managed chains.
|
||||
|
||||
To create the required iptables rule, you need to find the bridge interface name for the `multi-host` network you
|
||||
created earlier. It's named `br-<short-network-id>`, where `<short-network-id>` is the first 12 characters of the
|
||||
@@ -219,7 +220,7 @@ network ID.
|
||||
|
||||
Add the iptables rule to allow traffic from `wg0` to `multi-host` bridge on Machine 1:
|
||||
|
||||
```shell
|
||||
```bash
|
||||
$ docker network ls -f name=multi-host
|
||||
NETWORK ID NAME DRIVER SCOPE
|
||||
661096b2a5d9 multi-host bridge local
|
||||
@@ -228,14 +229,14 @@ $ iptables -I DOCKER-USER -i wg0 -o br-661096b2a5d9 -j ACCEPT
|
||||
|
||||
Add the iptables rule to allow traffic from `wg0` to `multi-host` bridge on Machine 2:
|
||||
|
||||
```shell
|
||||
```bash
|
||||
$ docker network ls -f name=multi-host
|
||||
NETWORK ID NAME DRIVER SCOPE
|
||||
48f808048e7c multi-host bridge local
|
||||
$ iptables -I DOCKER-USER -i wg0 -o br-48f808048e7c -j ACCEPT
|
||||
```
|
||||
|
||||
The traffic in the other direction (from `multi-host` bridge to `wg0`) is not blocked by Docker by default. But it still
|
||||
The traffic the other way around (from `multi-host` bridge to `wg0`) is not blocked by Docker by default. But it still
|
||||
won't be able to make it through the tunnel. The reason is that Docker creates a `MASQUERADE` rule in the `nat` table
|
||||
for every bridge network with option
|
||||
[`com.docker.network.bridge.enable_ip_masquerade`](https://docs.docker.com/engine/network/drivers/bridge/#options) set
|
||||
@@ -245,13 +246,13 @@ to `true` (which is the default). In my case, the rule looks like this on Machin
|
||||
POSTROUTING -s 10.200.1.0/24 ! -o br-661096b2a5d9 -j MASQUERADE
|
||||
```
|
||||
|
||||
This essentially configures NAT for all external traffic coming from containers which is necessary for allowing them to
|
||||
This essentially configures NAT for all external traffic coming from containers which is necessary to allow them to
|
||||
access the internet and other external networks. However, it equally applies to the traffic going through the `wg0`
|
||||
interface. It tries to masquerade the source IP address of the packets with the IP address of the `wg0` interface and
|
||||
fails because the `wg0` interface doesn't have an IP. This results in the packets being
|
||||
[dropped](https://elixir.bootlin.com/linux/v6.15.5/source/net/netfilter/nf_nat_masquerade.c#L54-L58).
|
||||
|
||||
You could assign an IP address to `wg0` but this would cause the following unwanted side effects:
|
||||
You cloud assign an IP address to `wg0` but this would cause the following unwanted side effects:
|
||||
|
||||
- Containers from other Docker networks on the same machine could route through the tunnel to reach remote `multi-host`
|
||||
containers, violating Docker's network isolation model.
|
||||
@@ -321,7 +322,7 @@ PING 10.200.2.2 (10.200.2.2): 56 data bytes
|
||||
64 bytes from 10.200.2.2: seq=2 ttl=62 time=297.285 ms
|
||||
```
|
||||
|
||||
Both hosts have IPs assigned to the `multi-host` bridges, `10.200.1.1` and `10.200.2.1` respectively, which should also
|
||||
Both hosts have IPs assigned to the `multi-host` bridges, `10.200.1.1` and `10.200.2.1` respectively which should aslo
|
||||
be reachable from the containers or hosts on both machines.
|
||||
|
||||
You can see from the `ping` command the latency is quite high (~300 ms) in my case because the packets have to travel
|
||||
@@ -343,12 +344,12 @@ be to use `PostUp` and `PostDown` options in the WireGuard configs to automatica
|
||||
starts/stops.
|
||||
|
||||
Append the following lines to the `[Interface]` section in `/etc/wireguard/wg0.conf`. Make sure to replace
|
||||
`<network-id>` with your actual Docker network ID from [Step 3](#step-3-configure-ip-routing). The `%i` is replaced by
|
||||
WireGuard with the interface name (`wg0`).
|
||||
`<network-id>` with your actual Docker network ID from Step 3. The `%i` is replaced by WireGuard with the interface
|
||||
name (`wg0`).
|
||||
|
||||
On Machine 1:
|
||||
|
||||
```ini
|
||||
```shell
|
||||
[Interface]
|
||||
...
|
||||
PostUp = iptables -I DOCKER-USER -i %i -o br-<network-id> -j ACCEPT; iptables -t nat -I POSTROUTING -s 10.200.1.0/24 -o %i -j RETURN
|
||||
@@ -357,7 +358,7 @@ PostDown = iptables -D DOCKER-USER -i %i -o br-<network-id> -j ACCEPT; iptables
|
||||
|
||||
On Machine 2:
|
||||
|
||||
```ini
|
||||
```shell
|
||||
[Interface]
|
||||
...
|
||||
PostUp = iptables -I DOCKER-USER -i %i -o br-<network-id> -j ACCEPT; iptables -t nat -I POSTROUTING -s 10.200.2.0/24 -o %i -j RETURN
|
||||
@@ -367,7 +368,7 @@ PostDown = iptables -D DOCKER-USER -i %i -o br-<network-id> -j ACCEPT; iptables
|
||||
### Start WireGuard on boot
|
||||
|
||||
The `wireguard-tools` package provides a convenient systemd service to manage WireGuard interfaces. Since our iptables
|
||||
rules should have priority over Docker's rules, WireGuard must start after Docker.
|
||||
rules should have a priority over Docker's rules, WireGuard must start after Docker.
|
||||
|
||||
Create a systemd drop-in configuration for this:
|
||||
|
||||
@@ -385,135 +386,54 @@ Then enable the WireGuard service to start on boot:
|
||||
```shell
|
||||
systemctl enable wg-quick@wg0.service
|
||||
systemctl daemon-reload
|
||||
# Verify the unit includes the drop-in configuration
|
||||
# Verify the unit includes the drop-in configuration.
|
||||
systemctl cat wg-quick@wg0.service
|
||||
```
|
||||
|
||||
## Scaling beyond two machines
|
||||
## Scaling beyond two machines and limitations
|
||||
|
||||
Adding a third machine means following the same steps as above on it and updating WireGuard configs on *all* existing
|
||||
machines. Each machine needs a `[Peer]` section for every other machine in the network. With 5 machines, that's 4 peer
|
||||
entries per config file or 20 peer configurations total that establish a full mesh topology.
|
||||
|
||||

|
||||
|
||||
## Limitations
|
||||
|
||||
### DNS resolution
|
||||
|
||||
The main limitation of this setup is that containers can't find each other by name across machines. You need to use
|
||||
their IP addresses directly or implement a service discovery solution like Consul or CoreDNS.
|
||||
|
||||
For small deployments, you can assign static IPs to containers and use those IPs in your app configuration. But service
|
||||
discovery is essential for larger and more dynamic deployments.
|
||||
|
||||
### NAT traversal constraints
|
||||
|
||||
For WireGuard connections to work, at least one machine in each pair must be publicly reachable. The connection fails if
|
||||
both machines are behind NAT. While solutions exist (STUN/TURN servers, UDP hole punching), they're beyond the scope of
|
||||
this guide.
|
||||
|
||||
Common scenarios that work:
|
||||
|
||||
- ✅ Cloud VPS (public or private IP) ↔ Cloud VPS (public or private IP). Both can use private IPs only if they're in the
|
||||
same cloud provider's network
|
||||
- ✅ Homelab (behind NAT) ↔ Cloud VPS (public IP)
|
||||
- ✅ Homelab (private IP) ↔ Homelab (private IP on the same local network)
|
||||
- ❌ Homelab (behind NAT) ↔ Friend's homelab (behind NAT) — requires a relay server
|
||||
//Adding a third machine requires updating configs on all existing machines. This gets tedious fast... //WireGuard mesh
|
||||
and challenges to manually manage key pairs and distribute configs //Requirements for NAT traversal: at least one
|
||||
machine in each pair must be reachable by the other. The wireguard will fail to establish a connection if both machines
|
||||
are behind NAT without special tricks that are beyond the scope of this post. DNS resolution for container names across
|
||||
machines is not covered here, but you can use a service discovery tool like Consul.
|
||||
|
||||
## Automating with Uncloud
|
||||
|
||||
As your setup grows, managing subnet allocation for Docker networks (ensuring each gets a unique range like
|
||||
`10.200.1.0/24`, `10.200.2.0/24`) and updating WireGuard configs manually may become tedious quickly.
|
||||
//I built Uncloud to handle all the heavy lifting automatically.
|
||||
|
||||
I built [Uncloud](https://github.com/psviderski/uncloud), an open source clustering and deployment tool for Docker, to
|
||||
handle all the heavy lifting automatically. You can get the same result and much more with just a few commands.
|
||||
|
||||
Initialise a new cluster on your first machine:
|
||||
You can initialise a cluster of machines by running the following commands:
|
||||
|
||||
```shell
|
||||
uc machine init user@machine1
|
||||
uc machine init user@machine1-ip
|
||||
uc machine add user@machine2-ip
|
||||
...
|
||||
uc machine add user@machineN-ip
|
||||
```
|
||||
|
||||
Add more machines to the cluster:
|
||||
//This will create `uncloud` Docker bridge network on each machine with `10.210.N.0/24` subnet by default and set up
|
||||
//WireGuard mesh network between them and make persistent across reboots.
|
||||
|
||||
```shell
|
||||
uc machine add user@machine2
|
||||
uc machine add user@machine3
|
||||
```
|
||||
|
||||
This is what these commands do:
|
||||
|
||||
- Create the `uncloud` Docker network on each machine with unique subnets (`10.210.0.0/24`, `10.210.1.0/24`, etc.).
|
||||
- Generate WireGuard key pairs and distribute public keys across machines.
|
||||
- Start a full mesh WireGuard network.
|
||||
- Configure iptables rules for container communication.
|
||||
- Make everything persistent across reboots.
|
||||
|
||||
Beyond the network setup, you also get:
|
||||
|
||||
- Multi-machine [Docker Compose](https://docs.docker.com/reference/compose-file/) deployments with zero downtime.
|
||||
- Built-in DNS server that resolves container IPs by their service names.
|
||||
- Automatic HTTPS and reverse proxy configuration.
|
||||
|
||||
Check out the [documentation](https://uncloud.run/docs) for more information.
|
||||
//Mention embedded DNS that resolves container IPs by their service names and multi-machine Docker Compose support.
|
||||
|
||||
## Alternative solutions
|
||||
|
||||
Before settling on the WireGuard approach, I evaluated several alternatives. Note that I only considered lightweight
|
||||
solutions suitable for Docker. Kubernetes and its CNI ecosystem deserve a separate discussion.
|
||||
//I wanted to explore only lightweight solutions for Docker so not talking about Kubernetes and a numerous CNI
|
||||
//drivers. Let's leave this beast for another time.
|
||||
|
||||
### Docker Swarm overlay network
|
||||
|
||||
Docker Swarm includes built-in [overlay networking](https://docs.docker.com/engine/network/drivers/overlay/). However,
|
||||
to use an overlay network, you need to run a [Swarm cluster](https://docs.docker.com/engine/swarm/) on all machines.
|
||||
This introduces additional complexity:
|
||||
|
||||
- Cluster nodes must
|
||||
[maintain the quorum](https://docs.docker.com/engine/swarm/admin_guide/#maintain-the-quorum-of-managers). Losing
|
||||
quorum impacts the functionality of overlay networks.
|
||||
- Ports 2377, 7946, and 4789 must be exposed to untrusted networks (if connecting machines over the internet) for
|
||||
cluster management, node communication, and VXLAN overlay traffic.
|
||||
- VXLAN traffic is unencrypted by default, requiring additional
|
||||
[hardening](https://docs.docker.com/engine/swarm/swarm-tutorial/#open-protocols-and-ports-between-the-hosts) with
|
||||
IPSec and firewalls.
|
||||
- Every node must be publicly reachable. VXLAN fails if machines are behind NAT.
|
||||
|
||||
If these limitations are acceptable, an overlay network is a great option. Note that you can use an overlay network with
|
||||
regular containers without using any other Swarm features.
|
||||
|
||||
### Flannel
|
||||
|
||||
[Flannel](https://github.com/flannel-io/flannel) is battle-tested in Kubernetes but can also be used with Docker. It
|
||||
supports multiple [backends](https://github.com/flannel-io/flannel/blob/master/Documentation/backends.md) including
|
||||
VXLAN and WireGuard.
|
||||
|
||||
The main caveat is that Flannel requires running etcd as the datastore for coordination. Depending on your availability
|
||||
requirements, you may need to set up an etcd cluster with multiple nodes. This is not a problem if you're already using
|
||||
Kubernetes. But if you're just running a few Docker hosts, it might seem like overkill.
|
||||
|
||||
### Tailscale
|
||||
|
||||
[Tailscale](https://tailscale.com/) makes WireGuard easy with automatic NAT traversal and key management, but it's not
|
||||
designed as a generic site-to-site VPN for connecting networks. Instead, it connects individual devices and provides
|
||||
identity-based access controls.
|
||||
|
||||
The recommended approach for using [Tailscale with Docker](https://tailscale.com/kb/1282/docker) is to connect each
|
||||
individual container to a Tailscale network. This means deploying an additional Tailscale container alongside every
|
||||
application container.
|
||||
|
||||
Tailscale's [subnet router](https://tailscale.com/kb/1019/subnets) feature might work to expose Docker networks similar
|
||||
to our setup, but I haven't tested this approach.
|
||||
//Not a generic site-to-site VPN, so the recommended approach is to use Tailscale on the container level. This way a
|
||||
//container that needs to talk across machines is configured as a Tailscale machine so it can connect to other Tailscale
|
||||
//machines. Maybe the subnet router feature can be used to connect Docker networks in a similar I described here, but
|
||||
//I haven't tested it.
|
||||
|
||||
## Conclusion
|
||||
|
||||
That's it! Now you know how to securely connect Docker containers across multiple machines using WireGuard. The manual
|
||||
setup works great for a handful of machines that you don't need to change often, but configuration management becomes
|
||||
tedious as you scale.
|
||||
//Summarise what we've done.?
|
||||
|
||||
If you don't want to mess with manual configuration, consider automation tools like Uncloud or evaluate if you need a
|
||||
full orchestration platform.
|
||||
|
||||
Feel free to reach out if you have any questions or suggestions. You can find me on X
|
||||
at [@psviderski](https://x.com/psviderski) or check my GitHub profile [psviderski](https://github.com/psviderski/)
|
||||
for other contacts.
|
||||
If you like this article and my work, you can follow me on X [@psviderski](https://x.com/psviderski).
|
||||
|
Before Width: | Height: | Size: 897 KiB After Width: | Height: | Size: 897 KiB |
@@ -0,0 +1,8 @@
|
||||
services:
|
||||
uncloud-docs:
|
||||
image: ghcr.io/psviderski/uncloud-docs:latest
|
||||
pull_policy: always
|
||||
user: nobody
|
||||
x-ports:
|
||||
- docs.uncloud.run:8000/https
|
||||
scale: 2
|
||||
@@ -67,7 +67,7 @@ Docker containers running on different machines get **unique IP addresses** from
|
||||
The design and implementation were highly inspired by
|
||||
Talos [KubeSpan](https://www.talos.dev/v1.10/talos-guides/network/kubespan/).
|
||||
|
||||
### Managed DNS service (optional)
|
||||
### Managed DNS service
|
||||
|
||||
Uncloud can provide **managed DNS records** like `<service-name>.<cluster-id>.cluster.uncloud.run` for your public
|
||||
services through free [Uncloud DNS](https://github.com/psviderski/uncloud-dns) service. You can deploy a service and
|
||||
@@ -99,7 +99,7 @@ containers by their service names, `curl` service endpoints, or analyse traffic
|
||||
|
||||
## Getting started
|
||||
|
||||
Install Uncloud CLI and deploy your first app:
|
||||
Install Uncloud CLI and deploy your first app in minutes:
|
||||
|
||||
* [Install Uncloud CLI](./2-getting-started/1-install-cli.md)
|
||||
* [Deploy demo app](./2-getting-started/2-deploy-demo-app.md)
|
||||
@@ -89,23 +89,6 @@ For example, move it to `/usr/local/bin` which is a common location for user-ins
|
||||
sudo mv ./uc /usr/local/bin
|
||||
```
|
||||
|
||||
Follow the same steps to upgrade to the latest version in the future.
|
||||
|
||||
## Debian
|
||||
|
||||
On a Debian system, you can install Uncloud CLI from an unofficial
|
||||
[repository](https://debian.griffo.io/) maintained by
|
||||
[@dariogriffo](https://github.com/dariogriffo):
|
||||
|
||||
```shell
|
||||
curl -sS https://debian.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | sudo gpg --dearmor --yes -o /etc/apt/trusted.gpg.d/debian.griffo.io.gpg
|
||||
echo "deb https://debian.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | sudo tee /etc/apt/sources.list.d/debian.griffo.io.list
|
||||
apt install -y uncloud
|
||||
```
|
||||
|
||||
Alternatively, you can download `.deb` packages directly from the repository
|
||||
[releases](https://github.com/dariogriffo/uncloud-debian/releases) page.
|
||||
|
||||
## Verify installation
|
||||
|
||||
After installation, verify that `uc` command is working:
|
||||
@@ -114,6 +97,22 @@ After installation, verify that `uc` command is working:
|
||||
uc --version
|
||||
```
|
||||
|
||||
## Linux (via package managers)
|
||||
|
||||
### Debian
|
||||
|
||||
Via unofficial repository packages created and maintained at [uncloud-debian](https://github.com/dariogriffo/uncloud-debian/) by @dariogriffo
|
||||
|
||||
You can install uncloud the debian way by running:
|
||||
|
||||
```sh
|
||||
curl -sS https://debian.griffo.io/EA0F721D231FDD3A0A17B9AC7808B4DD62C41256.asc | sudo gpg --dearmor --yes -o /etc/apt/trusted.gpg.d/debian.griffo.io.gpg
|
||||
echo "deb https://debian.griffo.io/apt $(lsb_release -sc 2>/dev/null) main" | sudo tee /etc/apt/sources.list.d/debian.griffo.io.list
|
||||
apt install -y uncloud
|
||||
```
|
||||
|
||||
or in the releases page of the repository [here](https://github.com/dariogriffo/uncloud-debian/releases)
|
||||
|
||||
## Next steps
|
||||
|
||||
Now that you have `uc` installed, you're ready to:
|
||||
@@ -9,8 +9,8 @@ infrastructure with secure internet access.
|
||||
Before you begin, you'll need:
|
||||
|
||||
- **Uncloud CLI** [installed](1-install-cli.md) on your local machine
|
||||
- A **Ubuntu or Debian server** with **public IP address** and **SSH access** using a **private key** (as `root` or a
|
||||
user with **passwordless** `sudo` privileges).
|
||||
- A **Ubuntu or Debian server** with **public IP address** and **SSH access** (as `root` or a user with `sudo`
|
||||
privileges) using a **private key**.
|
||||
|
||||
:::tip Need a server?
|
||||
|
||||
@@ -271,16 +271,6 @@ Want to use your own domain, for example, `excalidraw.example.com` instead of `e
|
||||
Add a CNAME record `excalidraw.example.com` in your DNS provider (Cloudflare, Namecheap, etc.) pointing to
|
||||
`excalidraw.7za6s7.cluster.uncloud.run`. Alternatively, you can add an A record pointing to your server's IP.
|
||||
|
||||
:::info note
|
||||
|
||||
These instructions set up your own domain **in addition to** the Uncloud managed DNS name
|
||||
`excalidraw.7za6s7.cluster.uncloud.run`.
|
||||
|
||||
If you want to avoid the managed service altogether, add `--no-dns` to your `uc machine init` command, and point an A
|
||||
DNS record to your server(s)'s IP(s).
|
||||
|
||||
:::
|
||||
|
||||
Then update the published port `80/https` in `compose.yaml` to use your domain:
|
||||
|
||||
```yaml title="compose.yaml"
|
||||
@@ -318,126 +308,8 @@ Give it a moment for Caddy to obtain a TLS certificate, then visit https://excal
|
||||
|
||||
## Clean up
|
||||
|
||||
When you're done experimenting, you can remove the `excalidraw` service or uninstall Uncloud completely.
|
||||
TBD
|
||||
|
||||
### Remove the service
|
||||
## Next steps
|
||||
|
||||
Remove the `excalidraw` service while keeping your Uncloud machine running for future deployments:
|
||||
|
||||
```shell
|
||||
uc rm excalidraw
|
||||
```
|
||||
|
||||
### Uninstall Uncloud
|
||||
|
||||
If you want to completely uninstall Uncloud from your server and clean up everything it created, SSH into your server
|
||||
and run:
|
||||
|
||||
```shell
|
||||
sudo uncloud-uninstall
|
||||
```
|
||||
|
||||
This command will:
|
||||
|
||||
- Remove all Uncloud-managed containers (including Caddy)
|
||||
- Remove the Uncloud-managed Docker and WireGuard networks
|
||||
- Uninstall the Uncloud daemon from the server
|
||||
|
||||
<details>
|
||||
<summary>💡 Expand to see example output</summary>
|
||||
|
||||
```
|
||||
⚠️This script will uninstall Uncloud and remove ALL Uncloud managed containers on this machine.
|
||||
The following actions will be performed:
|
||||
- Remove Uncloud systemd services
|
||||
- Remove Uncloud binaries and data
|
||||
- Remove Uncloud user and group
|
||||
- Remove all Docker containers managed by Uncloud
|
||||
- Remove Uncloud Docker network
|
||||
- Remove Uncloud WireGuard interface
|
||||
Do you want to proceed with uninstallation? [y/N] y
|
||||
⏳ Stopping systemd services...
|
||||
Removed "/etc/systemd/system/multi-user.target.wants/uncloud.service".
|
||||
The unit files have no installation config (WantedBy=, RequiredBy=, UpheldBy=,
|
||||
Also=, or Alias= settings in the [Install] section, and DefaultInstance= for
|
||||
template units). This means they are not meant to be enabled or disabled using systemctl.
|
||||
|
||||
Possible reasons for having these kinds of units are:
|
||||
• A unit may be statically enabled by being symlinked from another unit's
|
||||
.wants/, .requires/, or .upholds/ directory.
|
||||
• A unit's purpose may be to act as a helper for some other unit which has
|
||||
a requirement dependency on it.
|
||||
• A unit may be started when needed via activation (socket, path, timer,
|
||||
D-Bus, udev, scripted systemctl call, ...).
|
||||
• In case of template units, the unit is meant to be enabled with some
|
||||
instance name specified.
|
||||
✓ Systemd services stopped.
|
||||
⏳ Removing systemd service files...
|
||||
removed '/etc/systemd/system/uncloud.service'
|
||||
removed '/etc/systemd/system/uncloud-corrosion.service'
|
||||
✓ Systemd service files removed.
|
||||
⏳ Removing binaries...
|
||||
removed '/usr/local/bin/uncloudd'
|
||||
removed '/usr/local/bin/uncloud-corrosion'
|
||||
✓ Binaries removed.
|
||||
⏳ Removing data and run directories...
|
||||
removed '/var/lib/uncloud/machine.db-wal'
|
||||
removed '/var/lib/uncloud/caddy/caddy/autosave.json'
|
||||
removed directory '/var/lib/uncloud/caddy/caddy'
|
||||
removed '/var/lib/uncloud/caddy/caddy.json'
|
||||
removed directory '/var/lib/uncloud/caddy'
|
||||
removed '/var/lib/uncloud/machine.json'
|
||||
removed '/var/lib/uncloud/machine.db-shm'
|
||||
removed '/var/lib/uncloud/corrosion/admin.sock'
|
||||
removed '/var/lib/uncloud/corrosion/config.toml'
|
||||
removed '/var/lib/uncloud/corrosion/subscriptions/b4e825113f1143e5b27715b62193a9f8/sub.sqlite-wal'
|
||||
removed '/var/lib/uncloud/corrosion/subscriptions/b4e825113f1143e5b27715b62193a9f8/sub.sqlite-shm'
|
||||
removed '/var/lib/uncloud/corrosion/subscriptions/b4e825113f1143e5b27715b62193a9f8/sub.sqlite'
|
||||
removed directory '/var/lib/uncloud/corrosion/subscriptions/b4e825113f1143e5b27715b62193a9f8'
|
||||
removed '/var/lib/uncloud/corrosion/subscriptions/5e04cbb20a2743c382cfbd4949922351/sub.sqlite'
|
||||
removed directory '/var/lib/uncloud/corrosion/subscriptions/5e04cbb20a2743c382cfbd4949922351'
|
||||
removed directory '/var/lib/uncloud/corrosion/subscriptions'
|
||||
removed '/var/lib/uncloud/corrosion/schema.sql'
|
||||
removed '/var/lib/uncloud/corrosion/store.db'
|
||||
removed directory '/var/lib/uncloud/corrosion'
|
||||
removed '/var/lib/uncloud/machine.db'
|
||||
removed directory '/var/lib/uncloud'
|
||||
removed directory '/run/uncloud'
|
||||
✓ Data and run directories removed.
|
||||
⏳ Removing Linux user and group...
|
||||
✓ Linux user 'uncloud' removed.
|
||||
Linux group 'uncloud' does not exist or was already removed.
|
||||
⏳ Looking for Docker containers and network created by Uncloud...
|
||||
Found 4 Uncloud managed containers.
|
||||
⏳ Stopping Uncloud managed containers...
|
||||
20613f6046d0
|
||||
1f1a65b78e93
|
||||
4300bde4a2b0
|
||||
053fdd57ec56
|
||||
⏳ Removing Uncloud managed containers...
|
||||
20613f6046d0
|
||||
1f1a65b78e93
|
||||
4300bde4a2b0
|
||||
053fdd57ec56
|
||||
✓ Uncloud managed containers stopped and removed.
|
||||
⏳ Removing Docker network uncloud...
|
||||
uncloud
|
||||
✓ Docker network uncloud removed.
|
||||
⏳ Removing WireGuard interface uncloud...
|
||||
✓ WireGuard interface uncloud removed.
|
||||
⏳ Removing uninstall script...
|
||||
removed '/usr/local/bin/uncloud-uninstall'
|
||||
✓ Uninstall script removed.
|
||||
|
||||
✅ Uncloud has been uninstalled successfully!
|
||||
Note: Docker installation was preserved. If you want to completely remove Docker as well, follow https://docs.docker.com/engine/install/ubuntu/#uninstall-docker-engine
|
||||
```
|
||||
|
||||
</details>
|
||||
|
||||
## Further reading
|
||||
|
||||
- **[Add more machines](../9-cli-reference/uc_machine_add.md)**: Scale horizontally by creating a cluster of machines
|
||||
- **[Ingress & HTTP](../3-concepts/1-ingress/1-overview.md)**: Learn how Uncloud handles incoming traffic and how to
|
||||
expose your services to the internet
|
||||
- **[CLI reference](../9-cli-reference/uc.md)**: Explore all available commands and options
|
||||
TBD
|
||||
|
Before Width: | Height: | Size: 389 KiB After Width: | Height: | Size: 389 KiB |
@@ -10,12 +10,12 @@ import {themes as prismThemes} from 'prism-react-renderer';
|
||||
|
||||
/** @type {import('@docusaurus/types').Config} */
|
||||
const config = {
|
||||
title: 'Uncloud',
|
||||
tagline: 'Self-host and scale web apps without Kubernetes complexity',
|
||||
title: 'Uncloud Docs',
|
||||
tagline: 'Dinosaurs are cool',
|
||||
favicon: 'img/favicon.png',
|
||||
|
||||
// Set the production url of your site here
|
||||
url: 'https://uncloud.run',
|
||||
url: 'https://docs.uncloud.run',
|
||||
// Set the /<baseUrl>/ pathname under which your site is served
|
||||
// For GitHub pages deployment, it is often '/<projectName>/'
|
||||
baseUrl: '/',
|
||||
@@ -54,30 +54,27 @@ const config = {
|
||||
({
|
||||
docs: {
|
||||
// Remove this to remove the "edit this page" links.
|
||||
editUrl: 'https://github.com/psviderski/uncloud/edit/main/website/',
|
||||
editUrl: 'https://github.com/psviderski/uncloud/edit/main/docs/',
|
||||
// Serve the docs at the site's root.
|
||||
// routeBasePath: '/',
|
||||
routeBasePath: '/',
|
||||
showLastUpdateTime: true,
|
||||
sidebarPath: './sidebars.js',
|
||||
},
|
||||
blog: {
|
||||
blogDescription: 'Blog posts from the Uncloud team and community',
|
||||
blogSidebarTitle: 'All posts',
|
||||
blogSidebarCount: 'ALL',
|
||||
showReadingTime: true,
|
||||
feedOptions: {
|
||||
type: ['rss', 'atom'],
|
||||
xslt: true,
|
||||
},
|
||||
// Please change this to your repo.
|
||||
// Remove this to remove the "edit this page" links.
|
||||
// blog: {
|
||||
// showReadingTime: true,
|
||||
// feedOptions: {
|
||||
// type: ['rss', 'atom'],
|
||||
// xslt: true,
|
||||
// },
|
||||
// // Please change this to your repo.
|
||||
// // Remove this to remove the "edit this page" links.
|
||||
// editUrl:
|
||||
// 'https://github.com/facebook/docusaurus/tree/main/packages/create-docusaurus/templates/shared/',
|
||||
// Useful options to enforce blogging best practices
|
||||
onInlineTags: 'warn',
|
||||
onInlineAuthors: 'warn',
|
||||
onUntruncatedBlogPosts: 'warn',
|
||||
},
|
||||
// // Useful options to enforce blogging best practices
|
||||
// onInlineTags: 'warn',
|
||||
// onInlineAuthors: 'warn',
|
||||
// onUntruncatedBlogPosts: 'warn',
|
||||
// },
|
||||
theme: {
|
||||
customCss: './src/css/custom.css',
|
||||
},
|
||||
@@ -99,24 +96,12 @@ const config = {
|
||||
// Relative to your site's "static" directory. Cannot be SVGs. Can be external URLs too.
|
||||
image: 'img/social-card.png',
|
||||
navbar: {
|
||||
title: 'Uncloud',
|
||||
title: 'Uncloud Docs',
|
||||
logo: {
|
||||
alt: 'Uncloud Logo',
|
||||
src: 'img/logo.svg',
|
||||
href: 'https://uncloud.run',
|
||||
},
|
||||
items: [
|
||||
{
|
||||
type: 'doc',
|
||||
docId: 'overview',
|
||||
label: 'Docs',
|
||||
position: 'left',
|
||||
},
|
||||
{
|
||||
to: 'blog',
|
||||
label: 'Blog',
|
||||
position: 'left',
|
||||
},
|
||||
{
|
||||
type: 'search',
|
||||
position: 'right',
|
||||
@@ -0,0 +1,45 @@
|
||||
{
|
||||
"name": "docs",
|
||||
"version": "0.0.0",
|
||||
"private": true,
|
||||
"scripts": {
|
||||
"docusaurus": "docusaurus",
|
||||
"start": "docusaurus start",
|
||||
"build": "docusaurus build",
|
||||
"swizzle": "docusaurus swizzle",
|
||||
"deploy": "docusaurus deploy",
|
||||
"clear": "docusaurus clear",
|
||||
"serve": "docusaurus serve",
|
||||
"write-translations": "docusaurus write-translations",
|
||||
"write-heading-ids": "docusaurus write-heading-ids"
|
||||
},
|
||||
"dependencies": {
|
||||
"@docusaurus/core": "3.7.0",
|
||||
"@docusaurus/preset-classic": "3.7.0",
|
||||
"@easyops-cn/docusaurus-search-local": "^0.49.2",
|
||||
"@mdx-js/react": "^3.0.0",
|
||||
"clsx": "^2.0.0",
|
||||
"prism-react-renderer": "^2.3.0",
|
||||
"react": "^19.0.0",
|
||||
"react-dom": "^19.0.0"
|
||||
},
|
||||
"devDependencies": {
|
||||
"@docusaurus/module-type-aliases": "3.7.0",
|
||||
"@docusaurus/types": "3.7.0"
|
||||
},
|
||||
"browserslist": {
|
||||
"production": [
|
||||
">0.5%",
|
||||
"not dead",
|
||||
"not op_mini all"
|
||||
],
|
||||
"development": [
|
||||
"last 3 chrome version",
|
||||
"last 3 firefox version",
|
||||
"last 5 safari version"
|
||||
]
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18.0"
|
||||
}
|
||||
}
|
||||
|
Before Width: | Height: | Size: 1.2 KiB After Width: | Height: | Size: 1.2 KiB |
|
Before Width: | Height: | Size: 341 B After Width: | Height: | Size: 341 B |
|
Before Width: | Height: | Size: 88 KiB After Width: | Height: | Size: 88 KiB |
@@ -20,7 +20,7 @@ Uncloud stores its configuration in `~/.config/uncloud/config.yaml`. If you wish
|
||||
|
||||
### Initialisation
|
||||
|
||||
Begin by initialising the first node in your cluster with `uc machine init [USER@HOST:PORT]`. If you do not have a need for Caddy reverse proxy, you may disable this feature with `--no-caddy`. If you want to avoid using uncloud's managed DNS service, add the `--no-dns` flag.
|
||||
Begin by initialising the first node in your cluster with `uc machine init [USER@HOST:PORT]`. If you do not have a need for Caddy reverse proxy, you may disable this feature with `--no-caddy`.
|
||||
|
||||
This command will idempotently install Docker, uncloudd, uncloud-corrosion. If Caddy is enabled, it will set up a reverse proxy. If Uncloud DNS is enabled, it will create a DNS A record for the machine's public IP address under `*.[CLUSTER ID].cluster.uncloud.run`.
|
||||
|
||||
@@ -37,7 +37,6 @@ Uncloud (uncloud.run) DNS can be managed with the `uc dns` subcommand.
|
||||
* To reserve a domain name, run `uc dns reserve`
|
||||
* To release a domain name, run `uc dns release`.
|
||||
* To see the domain name, run `uc dns show`
|
||||
* To avoid using the Uncloud managed DNS service, use the `--no-dns` flag on your `uc machine init` command.
|
||||
|
||||
### Running a service
|
||||
|
||||
@@ -3,11 +3,10 @@ package main
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"time"
|
||||
|
||||
"github.com/hashicorp/serf/serf"
|
||||
crdt "github.com/ipfs/go-ds-crdt"
|
||||
"log/slog"
|
||||
"time"
|
||||
)
|
||||
|
||||
// Implements the Broadcaster interface.
|
||||
|
||||
@@ -2,10 +2,9 @@ package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"github.com/dgraph-io/badger/v3"
|
||||
"log"
|
||||
"time"
|
||||
|
||||
"github.com/dgraph-io/badger/v3"
|
||||
)
|
||||
|
||||
func customTimeEncoder(t time.Time) string {
|
||||
|
||||
@@ -2,10 +2,9 @@ package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"github.com/ipfs/go-log/v2"
|
||||
"log/slog"
|
||||
"os"
|
||||
|
||||
"github.com/ipfs/go-log/v2"
|
||||
)
|
||||
|
||||
// ipfsLogger is an slog logger that implements the IPFS go-log StandardLogger interface.
|
||||
|
||||
@@ -2,13 +2,12 @@ package main
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"github.com/docker/docker/libnetwork/networkdb"
|
||||
"log/slog"
|
||||
"os"
|
||||
"os/signal"
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/docker/docker/libnetwork/networkdb"
|
||||
)
|
||||
|
||||
func main() {
|
||||
|
||||
@@ -4,13 +4,6 @@ import (
|
||||
"context"
|
||||
"flag"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"net"
|
||||
"os"
|
||||
"os/signal"
|
||||
"syscall"
|
||||
"time"
|
||||
|
||||
"github.com/hashicorp/memberlist"
|
||||
"github.com/hashicorp/serf/cmd/serf/command/agent"
|
||||
"github.com/hashicorp/serf/serf"
|
||||
@@ -18,6 +11,12 @@ import (
|
||||
badger "github.com/ipfs/go-ds-badger3"
|
||||
crdt "github.com/ipfs/go-ds-crdt"
|
||||
"github.com/lmittmann/tint"
|
||||
"log/slog"
|
||||
"net"
|
||||
"os"
|
||||
"os/signal"
|
||||
"syscall"
|
||||
"time"
|
||||
)
|
||||
|
||||
func createSerfAgentConfig(name, bindAddr, rpcAddr, profile string) *agent.Config {
|
||||
|
||||
@@ -4,19 +4,18 @@ import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
|
||||
"github.com/hashicorp/serf/serf"
|
||||
"github.com/ipfs/boxo/datastore/dshelp"
|
||||
dag "github.com/ipfs/boxo/ipld/merkledag"
|
||||
"github.com/ipfs/go-cid"
|
||||
ds "github.com/ipfs/go-datastore"
|
||||
ipld "github.com/ipfs/go-ipld-format"
|
||||
"log/slog"
|
||||
)
|
||||
|
||||
// Implements the DAGService interface.
|
||||
// TODO: implement SessionDAGService to optimize node fetching.
|
||||
// TODO: persistentSerfDAG?
|
||||
// TOOD: persistentSerfDAG?
|
||||
type dagSyncer struct {
|
||||
// Persistent storage for the nodes.
|
||||
store ds.Datastore
|
||||
@@ -51,7 +50,8 @@ func (d *dagSyncer) Get(ctx context.Context, cid cid.Cid) (ipld.Node, error) {
|
||||
}
|
||||
slog.Debug("Queried node from peers", "cid", cid, "deadline", query.Deadline())
|
||||
|
||||
for {
|
||||
responded := false
|
||||
for !responded {
|
||||
select {
|
||||
case resp, ok := <-query.ResponseCh():
|
||||
if !ok {
|
||||
@@ -63,6 +63,7 @@ func (d *dagSyncer) Get(ctx context.Context, cid cid.Cid) (ipld.Node, error) {
|
||||
continue
|
||||
}
|
||||
slog.Debug("Received node from peer", "cid", cid, "peer", resp.From)
|
||||
responded = true
|
||||
query.Close()
|
||||
|
||||
node, err = nodeFromBytes(resp.Payload)
|
||||
|
||||
@@ -6,13 +6,12 @@ import (
|
||||
"crypto/cipher"
|
||||
"encoding/hex"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"time"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/machine/network"
|
||||
"github.com/siderolabs/discovery-api/api/v1alpha1/client/pb"
|
||||
discovery "github.com/siderolabs/discovery-client/pkg/client"
|
||||
"go.uber.org/zap"
|
||||
"net/netip"
|
||||
"time"
|
||||
"github.com/psviderski/uncloud/internal/machine/network"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
@@ -6,7 +6,6 @@ require (
|
||||
github.com/BurntSushi/toml v1.4.0
|
||||
github.com/Masterminds/semver v1.5.0
|
||||
github.com/Masterminds/squirrel v1.5.4
|
||||
github.com/alecthomas/chroma/v2 v2.20.0
|
||||
github.com/caddyserver/caddy/v2 v2.8.4
|
||||
github.com/cenkalti/backoff/v4 v4.3.0
|
||||
github.com/charmbracelet/huh v0.6.0
|
||||
@@ -36,7 +35,6 @@ require (
|
||||
github.com/jmoiron/sqlx v1.4.0
|
||||
github.com/lmittmann/tint v1.0.5
|
||||
github.com/miekg/dns v1.1.65
|
||||
github.com/mitchellh/mapstructure v1.5.0
|
||||
github.com/moby/term v0.5.0
|
||||
github.com/opencontainers/go-digest v1.0.0
|
||||
github.com/opencontainers/image-spec v1.1.0
|
||||
@@ -109,7 +107,6 @@ require (
|
||||
github.com/dgraph-io/badger/v2 v2.2007.4 // indirect
|
||||
github.com/dgraph-io/ristretto v0.1.1 // indirect
|
||||
github.com/dgryski/go-farm v0.0.0-20200201041132-a6ae2369ad13 // indirect
|
||||
github.com/dlclark/regexp2 v1.11.5 // indirect
|
||||
github.com/docker/buildx v0.18.0 // indirect
|
||||
github.com/docker/distribution v2.8.3+incompatible // indirect
|
||||
github.com/docker/docker-credential-helpers v0.8.2 // indirect
|
||||
@@ -207,6 +204,7 @@ require (
|
||||
github.com/mitchellh/go-homedir v1.1.0 // indirect
|
||||
github.com/mitchellh/go-ps v1.0.0 // indirect
|
||||
github.com/mitchellh/hashstructure/v2 v2.0.2 // indirect
|
||||
github.com/mitchellh/mapstructure v1.5.0 // indirect
|
||||
github.com/mitchellh/reflectwalk v1.0.2 // indirect
|
||||
github.com/moby/buildkit v0.17.2 // indirect
|
||||
github.com/moby/docker-image-spec v1.3.1 // indirect
|
||||
@@ -267,7 +265,6 @@ require (
|
||||
github.com/spf13/cast v1.7.0 // indirect
|
||||
github.com/spf13/pflag v1.0.5 // indirect
|
||||
github.com/stoewer/go-strcase v1.2.0 // indirect
|
||||
github.com/stretchr/objx v0.5.2 // indirect
|
||||
github.com/tailscale/tscert v0.0.0-20240517230440-bbccfbf48933 // indirect
|
||||
github.com/theupdateframework/notary v0.7.0 // indirect
|
||||
github.com/tonistiigi/dchapes-mode v0.0.0-20241001053921-ca0759fec205 // indirect
|
||||
|
||||
@@ -53,12 +53,6 @@ github.com/OneOfOne/xxhash v1.2.8/go.mod h1:eZbhyaAYD41SGSSsnmcpxVoRiQ/MPUTjUdII
|
||||
github.com/Shopify/logrus-bugsnag v0.0.0-20170309145241-6dbc35f2c30d/go.mod h1:HI8ITrYtUY+O+ZhtlqUnD8+KwNPOyugEhfP9fdUIaEQ=
|
||||
github.com/Shopify/logrus-bugsnag v0.0.0-20171204204709-577dee27f20d h1:UrqY+r/OJnIp5u0s1SbQ8dVfLCZJsnvazdBP5hS4iRs=
|
||||
github.com/Shopify/logrus-bugsnag v0.0.0-20171204204709-577dee27f20d/go.mod h1:HI8ITrYtUY+O+ZhtlqUnD8+KwNPOyugEhfP9fdUIaEQ=
|
||||
github.com/alecthomas/assert/v2 v2.11.0 h1:2Q9r3ki8+JYXvGsDyBXwH3LcJ+WK5D0gc5E8vS6K3D0=
|
||||
github.com/alecthomas/assert/v2 v2.11.0/go.mod h1:Bze95FyfUr7x34QZrjL+XP+0qgp/zg8yS+TtBj1WA3k=
|
||||
github.com/alecthomas/chroma/v2 v2.20.0 h1:sfIHpxPyR07/Oylvmcai3X/exDlE8+FA820NTz+9sGw=
|
||||
github.com/alecthomas/chroma/v2 v2.20.0/go.mod h1:e7tViK0xh/Nf4BYHl00ycY6rV7b8iXBksI9E359yNmA=
|
||||
github.com/alecthomas/repr v0.5.1 h1:E3G4t2QbHTSNpPKBgMTln5KLkZHLOcU7r37J4pXBuIg=
|
||||
github.com/alecthomas/repr v0.5.1/go.mod h1:Fr0507jx4eOXV7AlPV6AVZLYrLIuIeSOWtW57eE/O/4=
|
||||
github.com/alecthomas/template v0.0.0-20160405071501-a0175ee3bccc/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
|
||||
github.com/alecthomas/template v0.0.0-20190718012654-fb15b899a751/go.mod h1:LOuyumcjzFXgccqObfd/Ljyb9UuFJ6TxHnclSeseNhc=
|
||||
github.com/alecthomas/units v0.0.0-20151022065526-2efee857e7cf/go.mod h1:ybxpYRFXyAe+OPACYpWeL0wqObRcbAqCMya13uyzqw0=
|
||||
@@ -265,8 +259,6 @@ github.com/dgryski/go-farm v0.0.0-20200201041132-a6ae2369ad13 h1:fAjc9m62+UWV/WA
|
||||
github.com/dgryski/go-farm v0.0.0-20200201041132-a6ae2369ad13/go.mod h1:SqUrOPUnsFjfmXRMNPybcSiG0BgUW2AuFH8PAnS2iTw=
|
||||
github.com/distribution/reference v0.6.0 h1:0IXCQ5g4/QMHHkarYzh5l+u8T3t73zM5QvfrDyIgxBk=
|
||||
github.com/distribution/reference v0.6.0/go.mod h1:BbU0aIcezP1/5jX/8MP0YiH4SdvB5Y4f/wlDRiLyi3E=
|
||||
github.com/dlclark/regexp2 v1.11.5 h1:Q/sSnsKerHeCkc/jSTNq1oCm7KiVgUMZRDUoRu0JQZQ=
|
||||
github.com/dlclark/regexp2 v1.11.5/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
|
||||
github.com/docker/buildx v0.18.0 h1:rSauXHeJt90NvtXrLK5J992Eb0UPJZs2vV3u1zTf1nE=
|
||||
github.com/docker/buildx v0.18.0/go.mod h1:JGNSshOhHs5FhG3u51jXUf4lLOeD2QBIlJ2vaRB67p4=
|
||||
github.com/docker/cli v27.5.0+incompatible h1:aMphQkcGtpHixwwhAXJT1rrK/detk2JIvDaFkLctbGM=
|
||||
@@ -495,8 +487,6 @@ github.com/hashicorp/memberlist v0.5.1 h1:mk5dRuzeDNis2bi6LLoQIXfMH7JQvAzt3mQD0v
|
||||
github.com/hashicorp/memberlist v0.5.1/go.mod h1:zGDXV6AqbDTKTM6yxW0I4+JtFzZAJVoIPvss4hV8F24=
|
||||
github.com/hashicorp/serf v0.10.1 h1:Z1H2J60yRKvfDYAOZLd2MU0ND4AH/WDz7xYHDWQsIPY=
|
||||
github.com/hashicorp/serf v0.10.1/go.mod h1:yL2t6BqATOLGc5HF7qbFkTfXoPIY0WZdWHfEvMqbG+4=
|
||||
github.com/hexops/gotextdiff v1.0.3 h1:gitA9+qJrrTCsiCl7+kh75nPqQt1cx4ZkudSTLoUqJM=
|
||||
github.com/hexops/gotextdiff v1.0.3/go.mod h1:pSWU5MAI3yDq+fZBTazCSJysOMbxWL1BSow5/V2vxeg=
|
||||
github.com/hpcloud/tail v1.0.0/go.mod h1:ab1qPbhIpdTxEkNHXyeSf5vhxWSCs/tWer42PpOxQnU=
|
||||
github.com/huandu/xstrings v1.3.1/go.mod h1:y5/lhBue+AyNmUVz9RLU9xbLR0o4KIIExikq4ovT0aE=
|
||||
github.com/huandu/xstrings v1.3.2/go.mod h1:y5/lhBue+AyNmUVz9RLU9xbLR0o4KIIExikq4ovT0aE=
|
||||
@@ -1049,7 +1039,6 @@ github.com/stretchr/objx v0.1.1/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+
|
||||
github.com/stretchr/objx v0.2.0/go.mod h1:qt09Ya8vawLte6SNmTgCsAVtYtaKzEcn8ATUoHMkEqE=
|
||||
github.com/stretchr/objx v0.4.0/go.mod h1:YvHI0jy2hoMjB+UWwv71VJQ9isScKT/TqJzVSSt89Yw=
|
||||
github.com/stretchr/objx v0.5.0/go.mod h1:Yh+to48EsGEfYuaHDzXPcE3xhTkx73EhmCGUpEOglKo=
|
||||
github.com/stretchr/objx v0.5.2 h1:xuMeJ0Sdp5ZMRXx/aWO6RZxdr3beISkG5/G/aIRr3pY=
|
||||
github.com/stretchr/objx v0.5.2/go.mod h1:FRsXN1f5AsAjCGJKqEizvkpNtU+EGNCLh3NxZ/8L+MA=
|
||||
github.com/stretchr/testify v1.2.2/go.mod h1:a8OnRcib4nhh0OaRAV+Yts87kKdq0PP7pXfy6kDkUVs=
|
||||
github.com/stretchr/testify v1.3.0/go.mod h1:M5WIy9Dh21IEIfnGCwXGc5bZfKNJtfHm1UVUgZn+9EI=
|
||||
|
||||
@@ -6,8 +6,8 @@ import (
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"os"
|
||||
"slices"
|
||||
|
||||
"github.com/charmbracelet/huh"
|
||||
"github.com/docker/cli/cli/streams"
|
||||
"github.com/psviderski/uncloud/internal/cli/config"
|
||||
"github.com/psviderski/uncloud/internal/fs"
|
||||
@@ -22,12 +22,7 @@ import (
|
||||
"google.golang.org/protobuf/types/known/emptypb"
|
||||
)
|
||||
|
||||
const (
|
||||
// DefaultSSHKeyPath is the fallback location for the SSH private key when provisioning remote machines.
|
||||
// Used when no key is explicitly provided and SSH agent authentication fails.
|
||||
DefaultSSHKeyPath = "~/.ssh/id_ed25519"
|
||||
DefaultContextName = "default"
|
||||
)
|
||||
const defaultContextName = "default"
|
||||
|
||||
type CLI struct {
|
||||
Config *config.Config
|
||||
@@ -170,12 +165,15 @@ func (cli *CLI) InitCluster(ctx context.Context, opts InitClusterOptions) (*clie
|
||||
}
|
||||
|
||||
func (cli *CLI) initRemoteMachine(ctx context.Context, opts InitClusterOptions) (*client.Client, error) {
|
||||
contextName, err := cli.newContextName(opts.Context)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
contextName := opts.Context
|
||||
if contextName == "" {
|
||||
contextName = defaultContextName
|
||||
}
|
||||
if _, ok := cli.Config.Contexts[contextName]; ok {
|
||||
return nil, fmt.Errorf("cluster context '%s' already exists", contextName)
|
||||
}
|
||||
|
||||
machineClient, err := provisionRemoteMachine(ctx, opts.RemoteMachine, opts.Version)
|
||||
machineClient, err := cli.provisionRemoteMachine(ctx, *opts.RemoteMachine, opts.Version)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -192,7 +190,7 @@ func (cli *CLI) initRemoteMachine(ctx context.Context, opts InitClusterOptions)
|
||||
return nil, fmt.Errorf("inspect machine: %w", err)
|
||||
}
|
||||
if minfo.Id != "" {
|
||||
if err = promptResetMachine(ctx, machineClient.MachineClient); err != nil {
|
||||
if err = cli.promptResetMachine(); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
}
|
||||
@@ -247,37 +245,11 @@ func (cli *CLI) initRemoteMachine(ctx context.Context, opts InitClusterOptions)
|
||||
return machineClient, nil
|
||||
}
|
||||
|
||||
// newContextName returns a unique name for a new cluster context. If the provided name is not DefaultContextName,
|
||||
// and it's already taken, an error is returned. If the name is not provided or is DefaultContextName, the first
|
||||
// available name "default[-N]" is returned.
|
||||
func (cli *CLI) newContextName(name string) (string, error) {
|
||||
if name == "" {
|
||||
name = DefaultContextName
|
||||
}
|
||||
|
||||
if _, exists := cli.Config.Contexts[name]; !exists {
|
||||
return name, nil
|
||||
}
|
||||
|
||||
// If non-default context already exists, error out.
|
||||
if name != DefaultContextName {
|
||||
return "", fmt.Errorf("cluster context '%s' already exists", name)
|
||||
}
|
||||
|
||||
// The default context already exists, generate a numbered suffix to make it unique.
|
||||
for i := 1; ; i++ {
|
||||
name = fmt.Sprintf("%s-%d", DefaultContextName, i)
|
||||
if _, exists := cli.Config.Contexts[name]; !exists {
|
||||
return name, nil
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
type AddMachineOptions struct {
|
||||
Context string
|
||||
MachineName string
|
||||
PublicIP *netip.Addr
|
||||
RemoteMachine *RemoteMachine
|
||||
RemoteMachine RemoteMachine
|
||||
Version string
|
||||
}
|
||||
|
||||
@@ -300,7 +272,7 @@ func (cli *CLI) AddMachine(ctx context.Context, opts AddMachineOptions) (*client
|
||||
}
|
||||
}()
|
||||
|
||||
machineClient, err := provisionRemoteMachine(ctx, opts.RemoteMachine, opts.Version)
|
||||
machineClient, err := cli.provisionRemoteMachine(ctx, opts.RemoteMachine, opts.Version)
|
||||
if err != nil {
|
||||
return nil, nil, err
|
||||
}
|
||||
@@ -316,18 +288,7 @@ func (cli *CLI) AddMachine(ctx context.Context, opts AddMachineOptions) (*client
|
||||
return nil, nil, fmt.Errorf("inspect machine: %w", err)
|
||||
}
|
||||
if minfo.Id != "" {
|
||||
// Check if the machine is already a member of this cluster.
|
||||
machines, err := c.ListMachines(ctx, nil)
|
||||
if err != nil {
|
||||
return nil, nil, fmt.Errorf("list cluster machines: %w", err)
|
||||
}
|
||||
if slices.ContainsFunc(machines, func(m *pb.MachineMember) bool {
|
||||
return m.Machine.Id == minfo.Id
|
||||
}) {
|
||||
return nil, nil, fmt.Errorf("machine is already a member of this cluster (%s)", minfo.Name)
|
||||
}
|
||||
|
||||
if err = promptResetMachine(ctx, machineClient.MachineClient); err != nil {
|
||||
if err = cli.promptResetMachine(); err != nil {
|
||||
return nil, nil, err
|
||||
}
|
||||
}
|
||||
@@ -378,7 +339,7 @@ func (cli *CLI) AddMachine(ctx context.Context, opts AddMachineOptions) (*client
|
||||
return nil, nil, fmt.Errorf("add machine to cluster (context '%s'): %w", contextName, err)
|
||||
}
|
||||
|
||||
// Get the most up-to-date list of other machines in the cluster to include them in the join request.
|
||||
// List other machines in the cluster to include them in the join request.
|
||||
machines, err := c.ListMachines(ctx, nil)
|
||||
if err != nil {
|
||||
return nil, nil, fmt.Errorf("list cluster machines: %w", err)
|
||||
@@ -421,20 +382,11 @@ func (cli *CLI) AddMachine(ctx context.Context, opts AddMachineOptions) (*client
|
||||
// provisionRemoteMachine installs the Uncloud daemon and dependencies on the remote machine over SSH and returns
|
||||
// a machine API client to interact with the machine. The client should be closed after use by the caller.
|
||||
// The version parameter specifies the version of the Uncloud daemon to install. If empty, the latest version is used.
|
||||
// The remoteMachine.SSHKeyPath could be updated to the default SSH key path if it is not set and the SSH agent
|
||||
// authentication fails.
|
||||
func provisionRemoteMachine(
|
||||
ctx context.Context, remoteMachine *RemoteMachine, version string,
|
||||
func (cli *CLI) provisionRemoteMachine(
|
||||
ctx context.Context, remoteMachine RemoteMachine, version string,
|
||||
) (*client.Client, error) {
|
||||
// Provision the remote machine by installing the Uncloud daemon and dependencies over SSH.
|
||||
sshClient, err := sshexec.Connect(remoteMachine.User, remoteMachine.Host, remoteMachine.Port, remoteMachine.KeyPath)
|
||||
// If the SSH connection using SSH agent fails and no key path is provided, try to use the default SSH key.
|
||||
if err != nil && remoteMachine.KeyPath == "" {
|
||||
remoteMachine.KeyPath = DefaultSSHKeyPath
|
||||
sshClient, err = sshexec.Connect(
|
||||
remoteMachine.User, remoteMachine.Host, remoteMachine.Port, remoteMachine.KeyPath,
|
||||
)
|
||||
}
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf(
|
||||
"SSH login to remote machine %s: %w",
|
||||
@@ -468,6 +420,31 @@ func provisionRemoteMachine(
|
||||
return machineClient, nil
|
||||
}
|
||||
|
||||
func (cli *CLI) promptResetMachine() error {
|
||||
var confirm bool
|
||||
form := huh.NewForm(
|
||||
huh.NewGroup(
|
||||
huh.NewConfirm().
|
||||
Title(
|
||||
"The remote machine is already initialised as a cluster member. Do you want to reset it first?",
|
||||
).
|
||||
Affirmative("Yes!").
|
||||
Negative("No").
|
||||
Value(&confirm),
|
||||
),
|
||||
).WithAccessible(true)
|
||||
if err := form.Run(); err != nil {
|
||||
return fmt.Errorf("prompt user to confirm: %w", err)
|
||||
}
|
||||
|
||||
if !confirm {
|
||||
return fmt.Errorf("remote machine is already initialised as a cluster member")
|
||||
}
|
||||
// TODO: implement resetting the remote machine.
|
||||
return fmt.Errorf("resetting the remote machine is not implemented yet. " +
|
||||
"Please manually run 'uncloud-uninstall' on the remote machine to fully uninstall Uncloud from it")
|
||||
}
|
||||
|
||||
// ProgressOut returns an output stream for progress writer.
|
||||
func (cli *CLI) ProgressOut() *streams.Out {
|
||||
return streams.NewOut(os.Stdout)
|
||||
|
||||
@@ -53,15 +53,11 @@ func (c *Config) Read() error {
|
||||
|
||||
func (c *Config) Save() error {
|
||||
dir, _ := filepath.Split(c.path)
|
||||
// If dir is empty (e.g., when path is just a filename), use current directory
|
||||
if dir == "" {
|
||||
dir = "."
|
||||
}
|
||||
if err := os.MkdirAll(dir, 0o700); err != nil {
|
||||
if err := os.MkdirAll(dir, 0700); err != nil {
|
||||
return fmt.Errorf("create config directory '%s': %w", dir, err)
|
||||
}
|
||||
|
||||
f, err := os.OpenFile(c.path, os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0o600)
|
||||
f, err := os.OpenFile(c.path, os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0600)
|
||||
if err != nil {
|
||||
return fmt.Errorf("write config file '%s': %w", c.path, err)
|
||||
}
|
||||
|
||||
@@ -1,80 +0,0 @@
|
||||
package config
|
||||
|
||||
import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestConfig_Save(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
// Create a temporary directory for the test
|
||||
tmpDir := t.TempDir()
|
||||
|
||||
// Change to temp directory so relative paths resolve correctly
|
||||
originalDir, err := os.Getwd()
|
||||
if err != nil {
|
||||
t.Fatalf("Failed to get current directory: %v", err)
|
||||
}
|
||||
defer func() {
|
||||
if err := os.Chdir(originalDir); err != nil {
|
||||
t.Logf("Failed to restore original directory: %v", err)
|
||||
}
|
||||
}()
|
||||
|
||||
tests := []struct {
|
||||
name string
|
||||
configPath string
|
||||
contextName string
|
||||
expectFileAt string // Expected file location for verification
|
||||
useAbsolutePath bool // Whether to use absolute path for expectFileAt
|
||||
}{
|
||||
{
|
||||
name: "relative path without prefix",
|
||||
configPath: "test-config.yaml",
|
||||
contextName: "test",
|
||||
},
|
||||
{
|
||||
name: "relative path with prefix",
|
||||
configPath: "./test-config-2.yaml",
|
||||
contextName: "test2",
|
||||
},
|
||||
{
|
||||
name: "absolute path",
|
||||
configPath: filepath.Join(tmpDir, "absolute-config.yaml"),
|
||||
contextName: "test3",
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
if err := os.Chdir(tmpDir); err != nil {
|
||||
t.Fatalf("Failed to change to temp directory: %v", err)
|
||||
}
|
||||
|
||||
cfg := &Config{
|
||||
CurrentContext: tt.contextName,
|
||||
Contexts: map[string]*Context{
|
||||
tt.contextName: {
|
||||
Name: tt.contextName,
|
||||
},
|
||||
},
|
||||
path: tt.configPath,
|
||||
}
|
||||
|
||||
// This should not fail when saving the config
|
||||
err := cfg.Save()
|
||||
if err != nil {
|
||||
t.Errorf("Expected no error when saving config, got: %v", err)
|
||||
}
|
||||
|
||||
// Verify the file was created
|
||||
if _, err := os.Stat(tt.configPath); os.IsNotExist(err) {
|
||||
t.Errorf("Config file was not created at expected path: %s", tt.configPath)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -5,20 +5,12 @@ import (
|
||||
"fmt"
|
||||
"os"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/cenkalti/backoff/v4"
|
||||
"github.com/charmbracelet/huh"
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
"github.com/psviderski/uncloud/internal/sshexec"
|
||||
"google.golang.org/protobuf/types/known/emptypb"
|
||||
)
|
||||
|
||||
const (
|
||||
// TODO: support pinning the script version to the CLI version.
|
||||
installScriptURL = "https://raw.githubusercontent.com/psviderski/uncloud/refs/heads/main/scripts/install.sh"
|
||||
rootUser = "root"
|
||||
)
|
||||
const installScriptURL = "https://raw.githubusercontent.com/psviderski/uncloud/refs/heads/main/scripts/install.sh"
|
||||
|
||||
type RemoteMachine struct {
|
||||
User string
|
||||
@@ -32,7 +24,7 @@ func installCmd(user string, version string) string {
|
||||
var env []string
|
||||
|
||||
// Add the SSH user (non-root) to the uncloud group to allow access to the Uncloud daemon unix socket.
|
||||
if user != rootUser {
|
||||
if user != "root" {
|
||||
sudoPrefix = "sudo"
|
||||
env = append(env, "UNCLOUD_GROUP_ADD_USER="+sshexec.Quote(user))
|
||||
}
|
||||
@@ -54,26 +46,6 @@ func provisionMachine(ctx context.Context, exec sshexec.Executor, version string
|
||||
return fmt.Errorf("run whoami: %w", err)
|
||||
}
|
||||
|
||||
if user != rootUser {
|
||||
// 'sudo -n' is not used because it fails with 'sudo: a password is required' when the user has no password
|
||||
// in /etc/shadow even though it may have valid sudo access.
|
||||
out, err := exec.Run(ctx, "sudo true")
|
||||
if err != nil {
|
||||
if strings.Contains(out, "password is required") {
|
||||
return fmt.Errorf(
|
||||
"user '%[1]s' requires a password for sudo, but Uncloud needs passwordless sudo or root access "+
|
||||
"to install and configure the uncloudd daemon on the remote machine.\n\n"+
|
||||
"Possible solutions:\n"+
|
||||
"1. Use root user or a user with passwordless sudo instead.\n"+
|
||||
"2. Configure passwordless sudo for the user '%[1]s' by running on the remote machine:\n"+
|
||||
" echo '%[1]s ALL=(ALL) NOPASSWD:ALL' | sudo tee /etc/sudoers.d/%[1]s",
|
||||
user)
|
||||
}
|
||||
return fmt.Errorf("sudo command failed for user '%s': %w. "+
|
||||
"Please ensure the user has sudo privileges or use root user instead", user, err)
|
||||
}
|
||||
}
|
||||
|
||||
cmd := installCmd(user, version)
|
||||
|
||||
fmt.Println("Downloading Uncloud install script:", installScriptURL)
|
||||
@@ -84,56 +56,3 @@ func provisionMachine(ctx context.Context, exec sshexec.Executor, version string
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func promptResetMachine(ctx context.Context, machineClient pb.MachineClient) error {
|
||||
var confirm bool
|
||||
form := huh.NewForm(
|
||||
huh.NewGroup(
|
||||
huh.NewConfirm().
|
||||
Title(
|
||||
"The remote machine is already initialised as a cluster member. Do you want to reset it first?\n" +
|
||||
"This will:\n" +
|
||||
"- Remove all service containers from the machine\n" +
|
||||
"- Reset the machine to the uninitialised state",
|
||||
).
|
||||
Affirmative("Yes!").
|
||||
Negative("No").
|
||||
Value(&confirm),
|
||||
),
|
||||
).WithAccessible(true)
|
||||
if err := form.Run(); err != nil {
|
||||
return fmt.Errorf("prompt user to confirm: %w", err)
|
||||
}
|
||||
|
||||
if !confirm {
|
||||
return fmt.Errorf("remote machine is already initialised as a cluster member")
|
||||
}
|
||||
|
||||
if _, err := machineClient.Reset(ctx, &pb.ResetRequest{}); err != nil {
|
||||
return fmt.Errorf("reset remote machine: %w. You can also manually run 'uncloud-uninstall' "+
|
||||
"on the remote machine to fully uninstall Uncloud from it", err)
|
||||
}
|
||||
fmt.Println("Resetting the remote machine...")
|
||||
if err := waitMachineReady(ctx, machineClient, 1*time.Minute); err != nil {
|
||||
return fmt.Errorf("wait for machine to be ready after reset: %w", err)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
// waitMachineReady waits for the machine to be ready to serve requests.
|
||||
func waitMachineReady(ctx context.Context, machineClient pb.MachineClient, timeout time.Duration) error {
|
||||
boff := backoff.WithContext(backoff.NewExponentialBackOff(
|
||||
backoff.WithMaxInterval(1*time.Second),
|
||||
backoff.WithMaxElapsedTime(timeout),
|
||||
), ctx)
|
||||
|
||||
inspect := func() error {
|
||||
_, err := machineClient.Inspect(ctx, &emptypb.Empty{})
|
||||
if err != nil {
|
||||
return fmt.Errorf("inspect machine: %w", err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
return backoff.Retry(inspect, boff)
|
||||
}
|
||||
|
||||
@@ -5,15 +5,14 @@ import (
|
||||
"crypto/tls"
|
||||
"errors"
|
||||
"fmt"
|
||||
"github.com/cenkalti/backoff/v4"
|
||||
"golang.org/x/net/http2"
|
||||
"log/slog"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/netip"
|
||||
"net/url"
|
||||
"time"
|
||||
|
||||
"github.com/cenkalti/backoff/v4"
|
||||
"golang.org/x/net/http2"
|
||||
)
|
||||
|
||||
const (
|
||||
|
||||
@@ -6,12 +6,11 @@ import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"github.com/cenkalti/backoff/v4"
|
||||
"io"
|
||||
"log/slog"
|
||||
"net/http"
|
||||
"strconv"
|
||||
|
||||
"github.com/cenkalti/backoff/v4"
|
||||
)
|
||||
|
||||
type ChangeType string
|
||||
|
||||
@@ -3,9 +3,8 @@ package daemon
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
|
||||
systemd "github.com/coreos/go-systemd/daemon"
|
||||
"log/slog"
|
||||
"github.com/psviderski/uncloud/internal/machine"
|
||||
)
|
||||
|
||||
|
||||
@@ -3,11 +3,10 @@ package daemon
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"os"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/machine"
|
||||
"github.com/psviderski/uncloud/internal/machine/network"
|
||||
"net/netip"
|
||||
"os"
|
||||
)
|
||||
|
||||
// MachineToken returns the local machine's token that can be used for adding the machine to a cluster.
|
||||
|
||||
@@ -4,11 +4,10 @@ import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"time"
|
||||
|
||||
"github.com/cenkalti/backoff/v4"
|
||||
"github.com/docker/docker/client"
|
||||
"log/slog"
|
||||
"time"
|
||||
)
|
||||
|
||||
// WaitDaemonReady waits for the Docker daemon to start and be ready to serve requests.
|
||||
|
||||
@@ -1,176 +0,0 @@
|
||||
// Code generated by protoc-gen-go. DO NOT EDIT.
|
||||
// versions:
|
||||
// protoc-gen-go v1.34.2
|
||||
// protoc v5.27.3
|
||||
// source: internal/machine/api/pb/caddy.proto
|
||||
|
||||
package pb
|
||||
|
||||
import (
|
||||
protoreflect "google.golang.org/protobuf/reflect/protoreflect"
|
||||
protoimpl "google.golang.org/protobuf/runtime/protoimpl"
|
||||
emptypb "google.golang.org/protobuf/types/known/emptypb"
|
||||
timestamppb "google.golang.org/protobuf/types/known/timestamppb"
|
||||
reflect "reflect"
|
||||
sync "sync"
|
||||
)
|
||||
|
||||
const (
|
||||
// Verify that this generated code is sufficiently up-to-date.
|
||||
_ = protoimpl.EnforceVersion(20 - protoimpl.MinVersion)
|
||||
// Verify that runtime/protoimpl is sufficiently up-to-date.
|
||||
_ = protoimpl.EnforceVersion(protoimpl.MaxVersion - 20)
|
||||
)
|
||||
|
||||
type GetCaddyConfigResponse struct {
|
||||
state protoimpl.MessageState
|
||||
sizeCache protoimpl.SizeCache
|
||||
unknownFields protoimpl.UnknownFields
|
||||
|
||||
// The generated Caddyfile content.
|
||||
Caddyfile string `protobuf:"bytes,1,opt,name=caddyfile,proto3" json:"caddyfile,omitempty"`
|
||||
// Timestamp when the config was last modified.
|
||||
ModifiedAt *timestamppb.Timestamp `protobuf:"bytes,2,opt,name=modified_at,json=modifiedAt,proto3" json:"modified_at,omitempty"`
|
||||
}
|
||||
|
||||
func (x *GetCaddyConfigResponse) Reset() {
|
||||
*x = GetCaddyConfigResponse{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_caddy_proto_msgTypes[0]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
}
|
||||
|
||||
func (x *GetCaddyConfigResponse) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*GetCaddyConfigResponse) ProtoMessage() {}
|
||||
|
||||
func (x *GetCaddyConfigResponse) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_caddy_proto_msgTypes[0]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
// Deprecated: Use GetCaddyConfigResponse.ProtoReflect.Descriptor instead.
|
||||
func (*GetCaddyConfigResponse) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_caddy_proto_rawDescGZIP(), []int{0}
|
||||
}
|
||||
|
||||
func (x *GetCaddyConfigResponse) GetCaddyfile() string {
|
||||
if x != nil {
|
||||
return x.Caddyfile
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *GetCaddyConfigResponse) GetModifiedAt() *timestamppb.Timestamp {
|
||||
if x != nil {
|
||||
return x.ModifiedAt
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
var File_internal_machine_api_pb_caddy_proto protoreflect.FileDescriptor
|
||||
|
||||
var file_internal_machine_api_pb_caddy_proto_rawDesc = []byte{
|
||||
0x0a, 0x23, 0x69, 0x6e, 0x74, 0x65, 0x72, 0x6e, 0x61, 0x6c, 0x2f, 0x6d, 0x61, 0x63, 0x68, 0x69,
|
||||
0x6e, 0x65, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x70, 0x62, 0x2f, 0x63, 0x61, 0x64, 0x64, 0x79, 0x2e,
|
||||
0x70, 0x72, 0x6f, 0x74, 0x6f, 0x12, 0x03, 0x61, 0x70, 0x69, 0x1a, 0x1b, 0x67, 0x6f, 0x6f, 0x67,
|
||||
0x6c, 0x65, 0x2f, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2f, 0x65, 0x6d, 0x70, 0x74,
|
||||
0x79, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x1a, 0x1f, 0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2f,
|
||||
0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2f, 0x74, 0x69, 0x6d, 0x65, 0x73, 0x74, 0x61,
|
||||
0x6d, 0x70, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x22, 0x73, 0x0a, 0x16, 0x47, 0x65, 0x74, 0x43,
|
||||
0x61, 0x64, 0x64, 0x79, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e,
|
||||
0x73, 0x65, 0x12, 0x1c, 0x0a, 0x09, 0x63, 0x61, 0x64, 0x64, 0x79, 0x66, 0x69, 0x6c, 0x65, 0x18,
|
||||
0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x09, 0x63, 0x61, 0x64, 0x64, 0x79, 0x66, 0x69, 0x6c, 0x65,
|
||||
0x12, 0x3b, 0x0a, 0x0b, 0x6d, 0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x5f, 0x61, 0x74, 0x18,
|
||||
0x02, 0x20, 0x01, 0x28, 0x0b, 0x32, 0x1a, 0x2e, 0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2e, 0x70,
|
||||
0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x54, 0x69, 0x6d, 0x65, 0x73, 0x74, 0x61, 0x6d,
|
||||
0x70, 0x52, 0x0a, 0x6d, 0x6f, 0x64, 0x69, 0x66, 0x69, 0x65, 0x64, 0x41, 0x74, 0x32, 0x49, 0x0a,
|
||||
0x05, 0x43, 0x61, 0x64, 0x64, 0x79, 0x12, 0x40, 0x0a, 0x09, 0x47, 0x65, 0x74, 0x43, 0x6f, 0x6e,
|
||||
0x66, 0x69, 0x67, 0x12, 0x16, 0x2e, 0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72, 0x6f,
|
||||
0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d, 0x70, 0x74, 0x79, 0x1a, 0x1b, 0x2e, 0x61, 0x70,
|
||||
0x69, 0x2e, 0x47, 0x65, 0x74, 0x43, 0x61, 0x64, 0x64, 0x79, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67,
|
||||
0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x42, 0x37, 0x5a, 0x35, 0x67, 0x69, 0x74, 0x68,
|
||||
0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x73, 0x76, 0x69, 0x64, 0x65, 0x72, 0x73, 0x6b,
|
||||
0x69, 0x2f, 0x75, 0x6e, 0x63, 0x6c, 0x6f, 0x75, 0x64, 0x2f, 0x69, 0x6e, 0x74, 0x65, 0x72, 0x6e,
|
||||
0x61, 0x6c, 0x2f, 0x6d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x70,
|
||||
0x62, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33,
|
||||
}
|
||||
|
||||
var (
|
||||
file_internal_machine_api_pb_caddy_proto_rawDescOnce sync.Once
|
||||
file_internal_machine_api_pb_caddy_proto_rawDescData = file_internal_machine_api_pb_caddy_proto_rawDesc
|
||||
)
|
||||
|
||||
func file_internal_machine_api_pb_caddy_proto_rawDescGZIP() []byte {
|
||||
file_internal_machine_api_pb_caddy_proto_rawDescOnce.Do(func() {
|
||||
file_internal_machine_api_pb_caddy_proto_rawDescData = protoimpl.X.CompressGZIP(file_internal_machine_api_pb_caddy_proto_rawDescData)
|
||||
})
|
||||
return file_internal_machine_api_pb_caddy_proto_rawDescData
|
||||
}
|
||||
|
||||
var file_internal_machine_api_pb_caddy_proto_msgTypes = make([]protoimpl.MessageInfo, 1)
|
||||
var file_internal_machine_api_pb_caddy_proto_goTypes = []any{
|
||||
(*GetCaddyConfigResponse)(nil), // 0: api.GetCaddyConfigResponse
|
||||
(*timestamppb.Timestamp)(nil), // 1: google.protobuf.Timestamp
|
||||
(*emptypb.Empty)(nil), // 2: google.protobuf.Empty
|
||||
}
|
||||
var file_internal_machine_api_pb_caddy_proto_depIdxs = []int32{
|
||||
1, // 0: api.GetCaddyConfigResponse.modified_at:type_name -> google.protobuf.Timestamp
|
||||
2, // 1: api.Caddy.GetConfig:input_type -> google.protobuf.Empty
|
||||
0, // 2: api.Caddy.GetConfig:output_type -> api.GetCaddyConfigResponse
|
||||
2, // [2:3] is the sub-list for method output_type
|
||||
1, // [1:2] is the sub-list for method input_type
|
||||
1, // [1:1] is the sub-list for extension type_name
|
||||
1, // [1:1] is the sub-list for extension extendee
|
||||
0, // [0:1] is the sub-list for field type_name
|
||||
}
|
||||
|
||||
func init() { file_internal_machine_api_pb_caddy_proto_init() }
|
||||
func file_internal_machine_api_pb_caddy_proto_init() {
|
||||
if File_internal_machine_api_pb_caddy_proto != nil {
|
||||
return
|
||||
}
|
||||
if !protoimpl.UnsafeEnabled {
|
||||
file_internal_machine_api_pb_caddy_proto_msgTypes[0].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*GetCaddyConfigResponse); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
case 1:
|
||||
return &v.sizeCache
|
||||
case 2:
|
||||
return &v.unknownFields
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
}
|
||||
type x struct{}
|
||||
out := protoimpl.TypeBuilder{
|
||||
File: protoimpl.DescBuilder{
|
||||
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
||||
RawDescriptor: file_internal_machine_api_pb_caddy_proto_rawDesc,
|
||||
NumEnums: 0,
|
||||
NumMessages: 1,
|
||||
NumExtensions: 0,
|
||||
NumServices: 1,
|
||||
},
|
||||
GoTypes: file_internal_machine_api_pb_caddy_proto_goTypes,
|
||||
DependencyIndexes: file_internal_machine_api_pb_caddy_proto_depIdxs,
|
||||
MessageInfos: file_internal_machine_api_pb_caddy_proto_msgTypes,
|
||||
}.Build()
|
||||
File_internal_machine_api_pb_caddy_proto = out.File
|
||||
file_internal_machine_api_pb_caddy_proto_rawDesc = nil
|
||||
file_internal_machine_api_pb_caddy_proto_goTypes = nil
|
||||
file_internal_machine_api_pb_caddy_proto_depIdxs = nil
|
||||
}
|
||||
@@ -1,20 +0,0 @@
|
||||
syntax = "proto3";
|
||||
|
||||
package api;
|
||||
|
||||
option go_package = "github.com/psviderski/uncloud/internal/machine/api/pb";
|
||||
|
||||
import "google/protobuf/empty.proto";
|
||||
import "google/protobuf/timestamp.proto";
|
||||
|
||||
service Caddy {
|
||||
// GetConfig retrieves the current Caddy configuration from the machine.
|
||||
rpc GetConfig(google.protobuf.Empty) returns (GetCaddyConfigResponse);
|
||||
}
|
||||
|
||||
message GetCaddyConfigResponse {
|
||||
// The generated Caddyfile content.
|
||||
string caddyfile = 1;
|
||||
// Timestamp when the config was last modified.
|
||||
google.protobuf.Timestamp modified_at = 2;
|
||||
}
|
||||
@@ -1,124 +0,0 @@
|
||||
// Code generated by protoc-gen-go-grpc. DO NOT EDIT.
|
||||
// versions:
|
||||
// - protoc-gen-go-grpc v1.5.1
|
||||
// - protoc v5.27.3
|
||||
// source: internal/machine/api/pb/caddy.proto
|
||||
|
||||
package pb
|
||||
|
||||
import (
|
||||
context "context"
|
||||
grpc "google.golang.org/grpc"
|
||||
codes "google.golang.org/grpc/codes"
|
||||
status "google.golang.org/grpc/status"
|
||||
emptypb "google.golang.org/protobuf/types/known/emptypb"
|
||||
)
|
||||
|
||||
// This is a compile-time assertion to ensure that this generated file
|
||||
// is compatible with the grpc package it is being compiled against.
|
||||
// Requires gRPC-Go v1.64.0 or later.
|
||||
const _ = grpc.SupportPackageIsVersion9
|
||||
|
||||
const (
|
||||
Caddy_GetConfig_FullMethodName = "/api.Caddy/GetConfig"
|
||||
)
|
||||
|
||||
// CaddyClient is the client API for Caddy service.
|
||||
//
|
||||
// For semantics around ctx use and closing/ending streaming RPCs, please refer to https://pkg.go.dev/google.golang.org/grpc/?tab=doc#ClientConn.NewStream.
|
||||
type CaddyClient interface {
|
||||
// GetConfig retrieves the current Caddy configuration from the machine.
|
||||
GetConfig(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*GetCaddyConfigResponse, error)
|
||||
}
|
||||
|
||||
type caddyClient struct {
|
||||
cc grpc.ClientConnInterface
|
||||
}
|
||||
|
||||
func NewCaddyClient(cc grpc.ClientConnInterface) CaddyClient {
|
||||
return &caddyClient{cc}
|
||||
}
|
||||
|
||||
func (c *caddyClient) GetConfig(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*GetCaddyConfigResponse, error) {
|
||||
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
||||
out := new(GetCaddyConfigResponse)
|
||||
err := c.cc.Invoke(ctx, Caddy_GetConfig_FullMethodName, in, out, cOpts...)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// CaddyServer is the server API for Caddy service.
|
||||
// All implementations must embed UnimplementedCaddyServer
|
||||
// for forward compatibility.
|
||||
type CaddyServer interface {
|
||||
// GetConfig retrieves the current Caddy configuration from the machine.
|
||||
GetConfig(context.Context, *emptypb.Empty) (*GetCaddyConfigResponse, error)
|
||||
mustEmbedUnimplementedCaddyServer()
|
||||
}
|
||||
|
||||
// UnimplementedCaddyServer must be embedded to have
|
||||
// forward compatible implementations.
|
||||
//
|
||||
// NOTE: this should be embedded by value instead of pointer to avoid a nil
|
||||
// pointer dereference when methods are called.
|
||||
type UnimplementedCaddyServer struct{}
|
||||
|
||||
func (UnimplementedCaddyServer) GetConfig(context.Context, *emptypb.Empty) (*GetCaddyConfigResponse, error) {
|
||||
return nil, status.Errorf(codes.Unimplemented, "method GetConfig not implemented")
|
||||
}
|
||||
func (UnimplementedCaddyServer) mustEmbedUnimplementedCaddyServer() {}
|
||||
func (UnimplementedCaddyServer) testEmbeddedByValue() {}
|
||||
|
||||
// UnsafeCaddyServer may be embedded to opt out of forward compatibility for this service.
|
||||
// Use of this interface is not recommended, as added methods to CaddyServer will
|
||||
// result in compilation errors.
|
||||
type UnsafeCaddyServer interface {
|
||||
mustEmbedUnimplementedCaddyServer()
|
||||
}
|
||||
|
||||
func RegisterCaddyServer(s grpc.ServiceRegistrar, srv CaddyServer) {
|
||||
// If the following call pancis, it indicates UnimplementedCaddyServer was
|
||||
// embedded by pointer and is nil. This will cause panics if an
|
||||
// unimplemented method is ever invoked, so we test this at initialization
|
||||
// time to prevent it from happening at runtime later due to I/O.
|
||||
if t, ok := srv.(interface{ testEmbeddedByValue() }); ok {
|
||||
t.testEmbeddedByValue()
|
||||
}
|
||||
s.RegisterService(&Caddy_ServiceDesc, srv)
|
||||
}
|
||||
|
||||
func _Caddy_GetConfig_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
|
||||
in := new(emptypb.Empty)
|
||||
if err := dec(in); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if interceptor == nil {
|
||||
return srv.(CaddyServer).GetConfig(ctx, in)
|
||||
}
|
||||
info := &grpc.UnaryServerInfo{
|
||||
Server: srv,
|
||||
FullMethod: Caddy_GetConfig_FullMethodName,
|
||||
}
|
||||
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
|
||||
return srv.(CaddyServer).GetConfig(ctx, req.(*emptypb.Empty))
|
||||
}
|
||||
return interceptor(ctx, in, info, handler)
|
||||
}
|
||||
|
||||
// Caddy_ServiceDesc is the grpc.ServiceDesc for Caddy service.
|
||||
// It's only intended for direct use with grpc.RegisterService,
|
||||
// and not to be introspected or modified (even as a copy)
|
||||
var Caddy_ServiceDesc = grpc.ServiceDesc{
|
||||
ServiceName: "api.Caddy",
|
||||
HandlerType: (*CaddyServer)(nil),
|
||||
Methods: []grpc.MethodDesc{
|
||||
{
|
||||
MethodName: "GetConfig",
|
||||
Handler: _Caddy_GetConfig_Handler,
|
||||
},
|
||||
},
|
||||
Streams: []grpc.StreamDesc{},
|
||||
Metadata: "internal/machine/api/pb/caddy.proto",
|
||||
}
|
||||
@@ -124,7 +124,7 @@ func (x DNSRecord_RecordType) Number() protoreflect.EnumNumber {
|
||||
|
||||
// Deprecated: Use DNSRecord_RecordType.Descriptor instead.
|
||||
func (DNSRecord_RecordType) EnumDescriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{11, 0}
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{8, 0}
|
||||
}
|
||||
|
||||
type AddMachineRequest struct {
|
||||
@@ -339,173 +339,6 @@ func (x *ListMachinesResponse) GetMachines() []*MachineMember {
|
||||
return nil
|
||||
}
|
||||
|
||||
type UpdateMachineRequest struct {
|
||||
state protoimpl.MessageState
|
||||
sizeCache protoimpl.SizeCache
|
||||
unknownFields protoimpl.UnknownFields
|
||||
|
||||
// Machine to update
|
||||
MachineId string `protobuf:"bytes,1,opt,name=machine_id,json=machineId,proto3" json:"machine_id,omitempty"`
|
||||
// Updated machine information
|
||||
Name *string `protobuf:"bytes,2,opt,name=name,proto3,oneof" json:"name,omitempty"`
|
||||
PublicIp *IP `protobuf:"bytes,3,opt,name=public_ip,json=publicIp,proto3,oneof" json:"public_ip,omitempty"`
|
||||
Endpoints []*IPPort `protobuf:"bytes,4,rep,name=endpoints,proto3" json:"endpoints,omitempty"`
|
||||
}
|
||||
|
||||
func (x *UpdateMachineRequest) Reset() {
|
||||
*x = UpdateMachineRequest{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[4]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
}
|
||||
|
||||
func (x *UpdateMachineRequest) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*UpdateMachineRequest) ProtoMessage() {}
|
||||
|
||||
func (x *UpdateMachineRequest) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[4]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
// Deprecated: Use UpdateMachineRequest.ProtoReflect.Descriptor instead.
|
||||
func (*UpdateMachineRequest) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{4}
|
||||
}
|
||||
|
||||
func (x *UpdateMachineRequest) GetMachineId() string {
|
||||
if x != nil {
|
||||
return x.MachineId
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *UpdateMachineRequest) GetName() string {
|
||||
if x != nil && x.Name != nil {
|
||||
return *x.Name
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func (x *UpdateMachineRequest) GetPublicIp() *IP {
|
||||
if x != nil {
|
||||
return x.PublicIp
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (x *UpdateMachineRequest) GetEndpoints() []*IPPort {
|
||||
if x != nil {
|
||||
return x.Endpoints
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type UpdateMachineResponse struct {
|
||||
state protoimpl.MessageState
|
||||
sizeCache protoimpl.SizeCache
|
||||
unknownFields protoimpl.UnknownFields
|
||||
|
||||
Machine *MachineInfo `protobuf:"bytes,1,opt,name=machine,proto3" json:"machine,omitempty"`
|
||||
}
|
||||
|
||||
func (x *UpdateMachineResponse) Reset() {
|
||||
*x = UpdateMachineResponse{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[5]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
}
|
||||
|
||||
func (x *UpdateMachineResponse) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*UpdateMachineResponse) ProtoMessage() {}
|
||||
|
||||
func (x *UpdateMachineResponse) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[5]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
// Deprecated: Use UpdateMachineResponse.ProtoReflect.Descriptor instead.
|
||||
func (*UpdateMachineResponse) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{5}
|
||||
}
|
||||
|
||||
func (x *UpdateMachineResponse) GetMachine() *MachineInfo {
|
||||
if x != nil {
|
||||
return x.Machine
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
type RemoveMachineRequest struct {
|
||||
state protoimpl.MessageState
|
||||
sizeCache protoimpl.SizeCache
|
||||
unknownFields protoimpl.UnknownFields
|
||||
|
||||
Id string `protobuf:"bytes,1,opt,name=id,proto3" json:"id,omitempty"`
|
||||
}
|
||||
|
||||
func (x *RemoveMachineRequest) Reset() {
|
||||
*x = RemoveMachineRequest{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[6]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
}
|
||||
|
||||
func (x *RemoveMachineRequest) String() string {
|
||||
return protoimpl.X.MessageStringOf(x)
|
||||
}
|
||||
|
||||
func (*RemoveMachineRequest) ProtoMessage() {}
|
||||
|
||||
func (x *RemoveMachineRequest) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[6]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
return ms
|
||||
}
|
||||
return mi.MessageOf(x)
|
||||
}
|
||||
|
||||
// Deprecated: Use RemoveMachineRequest.ProtoReflect.Descriptor instead.
|
||||
func (*RemoveMachineRequest) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{6}
|
||||
}
|
||||
|
||||
func (x *RemoveMachineRequest) GetId() string {
|
||||
if x != nil {
|
||||
return x.Id
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
type Domain struct {
|
||||
state protoimpl.MessageState
|
||||
sizeCache protoimpl.SizeCache
|
||||
@@ -517,7 +350,7 @@ type Domain struct {
|
||||
func (x *Domain) Reset() {
|
||||
*x = Domain{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[7]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[4]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -530,7 +363,7 @@ func (x *Domain) String() string {
|
||||
func (*Domain) ProtoMessage() {}
|
||||
|
||||
func (x *Domain) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[7]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[4]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -543,7 +376,7 @@ func (x *Domain) ProtoReflect() protoreflect.Message {
|
||||
|
||||
// Deprecated: Use Domain.ProtoReflect.Descriptor instead.
|
||||
func (*Domain) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{7}
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{4}
|
||||
}
|
||||
|
||||
func (x *Domain) GetName() string {
|
||||
@@ -564,7 +397,7 @@ type ReserveDomainRequest struct {
|
||||
func (x *ReserveDomainRequest) Reset() {
|
||||
*x = ReserveDomainRequest{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[8]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[5]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -577,7 +410,7 @@ func (x *ReserveDomainRequest) String() string {
|
||||
func (*ReserveDomainRequest) ProtoMessage() {}
|
||||
|
||||
func (x *ReserveDomainRequest) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[8]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[5]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -590,7 +423,7 @@ func (x *ReserveDomainRequest) ProtoReflect() protoreflect.Message {
|
||||
|
||||
// Deprecated: Use ReserveDomainRequest.ProtoReflect.Descriptor instead.
|
||||
func (*ReserveDomainRequest) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{8}
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{5}
|
||||
}
|
||||
|
||||
func (x *ReserveDomainRequest) GetEndpoint() string {
|
||||
@@ -611,7 +444,7 @@ type CreateDomainRecordsRequest struct {
|
||||
func (x *CreateDomainRecordsRequest) Reset() {
|
||||
*x = CreateDomainRecordsRequest{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[9]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[6]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -624,7 +457,7 @@ func (x *CreateDomainRecordsRequest) String() string {
|
||||
func (*CreateDomainRecordsRequest) ProtoMessage() {}
|
||||
|
||||
func (x *CreateDomainRecordsRequest) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[9]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[6]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -637,7 +470,7 @@ func (x *CreateDomainRecordsRequest) ProtoReflect() protoreflect.Message {
|
||||
|
||||
// Deprecated: Use CreateDomainRecordsRequest.ProtoReflect.Descriptor instead.
|
||||
func (*CreateDomainRecordsRequest) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{9}
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{6}
|
||||
}
|
||||
|
||||
func (x *CreateDomainRecordsRequest) GetRecords() []*DNSRecord {
|
||||
@@ -658,7 +491,7 @@ type CreateDomainRecordsResponse struct {
|
||||
func (x *CreateDomainRecordsResponse) Reset() {
|
||||
*x = CreateDomainRecordsResponse{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[10]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[7]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -671,7 +504,7 @@ func (x *CreateDomainRecordsResponse) String() string {
|
||||
func (*CreateDomainRecordsResponse) ProtoMessage() {}
|
||||
|
||||
func (x *CreateDomainRecordsResponse) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[10]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[7]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -684,7 +517,7 @@ func (x *CreateDomainRecordsResponse) ProtoReflect() protoreflect.Message {
|
||||
|
||||
// Deprecated: Use CreateDomainRecordsResponse.ProtoReflect.Descriptor instead.
|
||||
func (*CreateDomainRecordsResponse) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{10}
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{7}
|
||||
}
|
||||
|
||||
func (x *CreateDomainRecordsResponse) GetRecords() []*DNSRecord {
|
||||
@@ -707,7 +540,7 @@ type DNSRecord struct {
|
||||
func (x *DNSRecord) Reset() {
|
||||
*x = DNSRecord{}
|
||||
if protoimpl.UnsafeEnabled {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[11]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[8]
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
ms.StoreMessageInfo(mi)
|
||||
}
|
||||
@@ -720,7 +553,7 @@ func (x *DNSRecord) String() string {
|
||||
func (*DNSRecord) ProtoMessage() {}
|
||||
|
||||
func (x *DNSRecord) ProtoReflect() protoreflect.Message {
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[11]
|
||||
mi := &file_internal_machine_api_pb_cluster_proto_msgTypes[8]
|
||||
if protoimpl.UnsafeEnabled && x != nil {
|
||||
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
|
||||
if ms.LoadMessageInfo() == nil {
|
||||
@@ -733,7 +566,7 @@ func (x *DNSRecord) ProtoReflect() protoreflect.Message {
|
||||
|
||||
// Deprecated: Use DNSRecord.ProtoReflect.Descriptor instead.
|
||||
func (*DNSRecord) Descriptor() ([]byte, []int) {
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{11}
|
||||
return file_internal_machine_api_pb_cluster_proto_rawDescGZIP(), []int{8}
|
||||
}
|
||||
|
||||
func (x *DNSRecord) GetName() string {
|
||||
@@ -797,87 +630,59 @@ var file_internal_machine_api_pb_cluster_proto_rawDesc = []byte{
|
||||
0x6f, 0x6e, 0x73, 0x65, 0x12, 0x2e, 0x0a, 0x08, 0x6d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x73,
|
||||
0x18, 0x01, 0x20, 0x03, 0x28, 0x0b, 0x32, 0x12, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x4d, 0x61, 0x63,
|
||||
0x68, 0x69, 0x6e, 0x65, 0x4d, 0x65, 0x6d, 0x62, 0x65, 0x72, 0x52, 0x08, 0x6d, 0x61, 0x63, 0x68,
|
||||
0x69, 0x6e, 0x65, 0x73, 0x22, 0xbb, 0x01, 0x0a, 0x14, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x4d,
|
||||
0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x1d, 0x0a,
|
||||
0x0a, 0x6d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x5f, 0x69, 0x64, 0x18, 0x01, 0x20, 0x01, 0x28,
|
||||
0x09, 0x52, 0x09, 0x6d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x49, 0x64, 0x12, 0x17, 0x0a, 0x04,
|
||||
0x6e, 0x61, 0x6d, 0x65, 0x18, 0x02, 0x20, 0x01, 0x28, 0x09, 0x48, 0x00, 0x52, 0x04, 0x6e, 0x61,
|
||||
0x6d, 0x65, 0x88, 0x01, 0x01, 0x12, 0x29, 0x0a, 0x09, 0x70, 0x75, 0x62, 0x6c, 0x69, 0x63, 0x5f,
|
||||
0x69, 0x70, 0x18, 0x03, 0x20, 0x01, 0x28, 0x0b, 0x32, 0x07, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x49,
|
||||
0x50, 0x48, 0x01, 0x52, 0x08, 0x70, 0x75, 0x62, 0x6c, 0x69, 0x63, 0x49, 0x70, 0x88, 0x01, 0x01,
|
||||
0x12, 0x29, 0x0a, 0x09, 0x65, 0x6e, 0x64, 0x70, 0x6f, 0x69, 0x6e, 0x74, 0x73, 0x18, 0x04, 0x20,
|
||||
0x03, 0x28, 0x0b, 0x32, 0x0b, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x49, 0x50, 0x50, 0x6f, 0x72, 0x74,
|
||||
0x52, 0x09, 0x65, 0x6e, 0x64, 0x70, 0x6f, 0x69, 0x6e, 0x74, 0x73, 0x42, 0x07, 0x0a, 0x05, 0x5f,
|
||||
0x6e, 0x61, 0x6d, 0x65, 0x42, 0x0c, 0x0a, 0x0a, 0x5f, 0x70, 0x75, 0x62, 0x6c, 0x69, 0x63, 0x5f,
|
||||
0x69, 0x70, 0x22, 0x43, 0x0a, 0x15, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x4d, 0x61, 0x63, 0x68,
|
||||
0x69, 0x6e, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x2a, 0x0a, 0x07, 0x6d,
|
||||
0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x0b, 0x32, 0x10, 0x2e, 0x61,
|
||||
0x70, 0x69, 0x2e, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x49, 0x6e, 0x66, 0x6f, 0x52, 0x07,
|
||||
0x6d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x22, 0x26, 0x0a, 0x14, 0x52, 0x65, 0x6d, 0x6f, 0x76,
|
||||
0x65, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12,
|
||||
0x0e, 0x0a, 0x02, 0x69, 0x64, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x02, 0x69, 0x64, 0x22,
|
||||
0x1c, 0x0a, 0x06, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x12, 0x0a, 0x04, 0x6e, 0x61, 0x6d,
|
||||
0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x22, 0x32, 0x0a,
|
||||
0x14, 0x52, 0x65, 0x73, 0x65, 0x72, 0x76, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65,
|
||||
0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x1a, 0x0a, 0x08, 0x65, 0x6e, 0x64, 0x70, 0x6f, 0x69, 0x6e,
|
||||
0x74, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x08, 0x65, 0x6e, 0x64, 0x70, 0x6f, 0x69, 0x6e,
|
||||
0x74, 0x22, 0x46, 0x0a, 0x1a, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69,
|
||||
0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12,
|
||||
0x28, 0x0a, 0x07, 0x72, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x18, 0x01, 0x20, 0x03, 0x28, 0x0b,
|
||||
0x32, 0x0e, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x4e, 0x53, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64,
|
||||
0x52, 0x07, 0x72, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x22, 0x47, 0x0a, 0x1b, 0x43, 0x72, 0x65,
|
||||
0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73,
|
||||
0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x28, 0x0a, 0x07, 0x72, 0x65, 0x63, 0x6f,
|
||||
0x72, 0x64, 0x73, 0x18, 0x01, 0x20, 0x03, 0x28, 0x0b, 0x32, 0x0e, 0x2e, 0x61, 0x70, 0x69, 0x2e,
|
||||
0x44, 0x4e, 0x53, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x52, 0x07, 0x72, 0x65, 0x63, 0x6f, 0x72,
|
||||
0x64, 0x73, 0x22, 0x96, 0x01, 0x0a, 0x09, 0x44, 0x4e, 0x53, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64,
|
||||
0x12, 0x12, 0x0a, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x04,
|
||||
0x6e, 0x61, 0x6d, 0x65, 0x12, 0x2d, 0x0a, 0x04, 0x74, 0x79, 0x70, 0x65, 0x18, 0x02, 0x20, 0x01,
|
||||
0x28, 0x0e, 0x32, 0x19, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x4e, 0x53, 0x52, 0x65, 0x63, 0x6f,
|
||||
0x72, 0x64, 0x2e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x54, 0x79, 0x70, 0x65, 0x52, 0x04, 0x74,
|
||||
0x79, 0x70, 0x65, 0x12, 0x16, 0x0a, 0x06, 0x76, 0x61, 0x6c, 0x75, 0x65, 0x73, 0x18, 0x03, 0x20,
|
||||
0x03, 0x28, 0x09, 0x52, 0x06, 0x76, 0x61, 0x6c, 0x75, 0x65, 0x73, 0x22, 0x2e, 0x0a, 0x0a, 0x52,
|
||||
0x65, 0x63, 0x6f, 0x72, 0x64, 0x54, 0x79, 0x70, 0x65, 0x12, 0x0f, 0x0a, 0x0b, 0x55, 0x4e, 0x53,
|
||||
0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x05, 0x0a, 0x01, 0x41, 0x10,
|
||||
0x01, 0x12, 0x08, 0x0a, 0x04, 0x41, 0x41, 0x41, 0x41, 0x10, 0x02, 0x32, 0x92, 0x04, 0x0a, 0x07,
|
||||
0x43, 0x6c, 0x75, 0x73, 0x74, 0x65, 0x72, 0x12, 0x3d, 0x0a, 0x0a, 0x41, 0x64, 0x64, 0x4d, 0x61,
|
||||
0x63, 0x68, 0x69, 0x6e, 0x65, 0x12, 0x16, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x41, 0x64, 0x64, 0x4d,
|
||||
0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x17, 0x2e,
|
||||
0x61, 0x70, 0x69, 0x2e, 0x41, 0x64, 0x64, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65,
|
||||
0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x41, 0x0a, 0x0c, 0x4c, 0x69, 0x73, 0x74, 0x4d, 0x61,
|
||||
0x63, 0x68, 0x69, 0x6e, 0x65, 0x73, 0x12, 0x16, 0x2e, 0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2e,
|
||||
0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d, 0x70, 0x74, 0x79, 0x1a, 0x19,
|
||||
0x2e, 0x61, 0x70, 0x69, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65,
|
||||
0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x46, 0x0a, 0x0d, 0x55, 0x70, 0x64,
|
||||
0x61, 0x74, 0x65, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x12, 0x19, 0x2e, 0x61, 0x70, 0x69,
|
||||
0x2e, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65,
|
||||
0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x1a, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x55, 0x70, 0x64, 0x61,
|
||||
0x74, 0x65, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73,
|
||||
0x65, 0x12, 0x42, 0x0a, 0x0d, 0x52, 0x65, 0x6d, 0x6f, 0x76, 0x65, 0x4d, 0x61, 0x63, 0x68, 0x69,
|
||||
0x6e, 0x65, 0x12, 0x19, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x52, 0x65, 0x6d, 0x6f, 0x76, 0x65, 0x4d,
|
||||
0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x16, 0x2e,
|
||||
0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e,
|
||||
0x45, 0x6d, 0x70, 0x74, 0x79, 0x12, 0x37, 0x0a, 0x0d, 0x52, 0x65, 0x73, 0x65, 0x72, 0x76, 0x65,
|
||||
0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x19, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x52, 0x65, 0x73,
|
||||
0x65, 0x72, 0x76, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73,
|
||||
0x74, 0x1a, 0x0b, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x30,
|
||||
0x0a, 0x09, 0x47, 0x65, 0x74, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x16, 0x2e, 0x67, 0x6f,
|
||||
0x69, 0x6e, 0x65, 0x73, 0x22, 0x1c, 0x0a, 0x06, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x12,
|
||||
0x0a, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x04, 0x6e, 0x61,
|
||||
0x6d, 0x65, 0x22, 0x32, 0x0a, 0x14, 0x52, 0x65, 0x73, 0x65, 0x72, 0x76, 0x65, 0x44, 0x6f, 0x6d,
|
||||
0x61, 0x69, 0x6e, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x1a, 0x0a, 0x08, 0x65, 0x6e,
|
||||
0x64, 0x70, 0x6f, 0x69, 0x6e, 0x74, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x08, 0x65, 0x6e,
|
||||
0x64, 0x70, 0x6f, 0x69, 0x6e, 0x74, 0x22, 0x46, 0x0a, 0x1a, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65,
|
||||
0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x52, 0x65, 0x71,
|
||||
0x75, 0x65, 0x73, 0x74, 0x12, 0x28, 0x0a, 0x07, 0x72, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x18,
|
||||
0x01, 0x20, 0x03, 0x28, 0x0b, 0x32, 0x0e, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x4e, 0x53, 0x52,
|
||||
0x65, 0x63, 0x6f, 0x72, 0x64, 0x52, 0x07, 0x72, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x22, 0x47,
|
||||
0x0a, 0x1b, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65,
|
||||
0x63, 0x6f, 0x72, 0x64, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x28, 0x0a,
|
||||
0x07, 0x72, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x18, 0x01, 0x20, 0x03, 0x28, 0x0b, 0x32, 0x0e,
|
||||
0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x4e, 0x53, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x52, 0x07,
|
||||
0x72, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x22, 0x96, 0x01, 0x0a, 0x09, 0x44, 0x4e, 0x53, 0x52,
|
||||
0x65, 0x63, 0x6f, 0x72, 0x64, 0x12, 0x12, 0x0a, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x18, 0x01, 0x20,
|
||||
0x01, 0x28, 0x09, 0x52, 0x04, 0x6e, 0x61, 0x6d, 0x65, 0x12, 0x2d, 0x0a, 0x04, 0x74, 0x79, 0x70,
|
||||
0x65, 0x18, 0x02, 0x20, 0x01, 0x28, 0x0e, 0x32, 0x19, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x4e,
|
||||
0x53, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x2e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x54, 0x79,
|
||||
0x70, 0x65, 0x52, 0x04, 0x74, 0x79, 0x70, 0x65, 0x12, 0x16, 0x0a, 0x06, 0x76, 0x61, 0x6c, 0x75,
|
||||
0x65, 0x73, 0x18, 0x03, 0x20, 0x03, 0x28, 0x09, 0x52, 0x06, 0x76, 0x61, 0x6c, 0x75, 0x65, 0x73,
|
||||
0x22, 0x2e, 0x0a, 0x0a, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x54, 0x79, 0x70, 0x65, 0x12, 0x0f,
|
||||
0x0a, 0x0b, 0x55, 0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12,
|
||||
0x05, 0x0a, 0x01, 0x41, 0x10, 0x01, 0x12, 0x08, 0x0a, 0x04, 0x41, 0x41, 0x41, 0x41, 0x10, 0x02,
|
||||
0x32, 0x86, 0x03, 0x0a, 0x07, 0x43, 0x6c, 0x75, 0x73, 0x74, 0x65, 0x72, 0x12, 0x3d, 0x0a, 0x0a,
|
||||
0x41, 0x64, 0x64, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x12, 0x16, 0x2e, 0x61, 0x70, 0x69,
|
||||
0x2e, 0x41, 0x64, 0x64, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65,
|
||||
0x73, 0x74, 0x1a, 0x17, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x41, 0x64, 0x64, 0x4d, 0x61, 0x63, 0x68,
|
||||
0x69, 0x6e, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x41, 0x0a, 0x0c, 0x4c,
|
||||
0x69, 0x73, 0x74, 0x4d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x73, 0x12, 0x16, 0x2e, 0x67, 0x6f,
|
||||
0x6f, 0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d,
|
||||
0x70, 0x74, 0x79, 0x1a, 0x0b, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e,
|
||||
0x12, 0x34, 0x0a, 0x0d, 0x52, 0x65, 0x6c, 0x65, 0x61, 0x73, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69,
|
||||
0x6e, 0x12, 0x16, 0x2e, 0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f,
|
||||
0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d, 0x70, 0x74, 0x79, 0x1a, 0x0b, 0x2e, 0x61, 0x70, 0x69, 0x2e,
|
||||
0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x58, 0x0a, 0x13, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65,
|
||||
0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x12, 0x1f, 0x2e,
|
||||
0x61, 0x70, 0x69, 0x2e, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e,
|
||||
0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x20,
|
||||
0x2e, 0x61, 0x70, 0x69, 0x2e, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69,
|
||||
0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65,
|
||||
0x42, 0x37, 0x5a, 0x35, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70,
|
||||
0x73, 0x76, 0x69, 0x64, 0x65, 0x72, 0x73, 0x6b, 0x69, 0x2f, 0x75, 0x6e, 0x63, 0x6c, 0x6f, 0x75,
|
||||
0x64, 0x2f, 0x69, 0x6e, 0x74, 0x65, 0x72, 0x6e, 0x61, 0x6c, 0x2f, 0x6d, 0x61, 0x63, 0x68, 0x69,
|
||||
0x6e, 0x65, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x70, 0x62, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f,
|
||||
0x33,
|
||||
0x70, 0x74, 0x79, 0x1a, 0x19, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x4d, 0x61,
|
||||
0x63, 0x68, 0x69, 0x6e, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x37,
|
||||
0x0a, 0x0d, 0x52, 0x65, 0x73, 0x65, 0x72, 0x76, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12,
|
||||
0x19, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x52, 0x65, 0x73, 0x65, 0x72, 0x76, 0x65, 0x44, 0x6f, 0x6d,
|
||||
0x61, 0x69, 0x6e, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x0b, 0x2e, 0x61, 0x70, 0x69,
|
||||
0x2e, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x30, 0x0a, 0x09, 0x47, 0x65, 0x74, 0x44, 0x6f,
|
||||
0x6d, 0x61, 0x69, 0x6e, 0x12, 0x16, 0x2e, 0x67, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72,
|
||||
0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d, 0x70, 0x74, 0x79, 0x1a, 0x0b, 0x2e, 0x61,
|
||||
0x70, 0x69, 0x2e, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x34, 0x0a, 0x0d, 0x52, 0x65, 0x6c,
|
||||
0x65, 0x61, 0x73, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12, 0x16, 0x2e, 0x67, 0x6f, 0x6f,
|
||||
0x67, 0x6c, 0x65, 0x2e, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x62, 0x75, 0x66, 0x2e, 0x45, 0x6d, 0x70,
|
||||
0x74, 0x79, 0x1a, 0x0b, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x12,
|
||||
0x58, 0x0a, 0x13, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52,
|
||||
0x65, 0x63, 0x6f, 0x72, 0x64, 0x73, 0x12, 0x1f, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x43, 0x72, 0x65,
|
||||
0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64, 0x73,
|
||||
0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x20, 0x2e, 0x61, 0x70, 0x69, 0x2e, 0x43, 0x72,
|
||||
0x65, 0x61, 0x74, 0x65, 0x44, 0x6f, 0x6d, 0x61, 0x69, 0x6e, 0x52, 0x65, 0x63, 0x6f, 0x72, 0x64,
|
||||
0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x42, 0x37, 0x5a, 0x35, 0x67, 0x69, 0x74,
|
||||
0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x70, 0x73, 0x76, 0x69, 0x64, 0x65, 0x72, 0x73,
|
||||
0x6b, 0x69, 0x2f, 0x75, 0x6e, 0x63, 0x6c, 0x6f, 0x75, 0x64, 0x2f, 0x69, 0x6e, 0x74, 0x65, 0x72,
|
||||
0x6e, 0x61, 0x6c, 0x2f, 0x6d, 0x61, 0x63, 0x68, 0x69, 0x6e, 0x65, 0x2f, 0x61, 0x70, 0x69, 0x2f,
|
||||
0x70, 0x62, 0x62, 0x06, 0x70, 0x72, 0x6f, 0x74, 0x6f, 0x33,
|
||||
}
|
||||
|
||||
var (
|
||||
@@ -893,7 +698,7 @@ func file_internal_machine_api_pb_cluster_proto_rawDescGZIP() []byte {
|
||||
}
|
||||
|
||||
var file_internal_machine_api_pb_cluster_proto_enumTypes = make([]protoimpl.EnumInfo, 2)
|
||||
var file_internal_machine_api_pb_cluster_proto_msgTypes = make([]protoimpl.MessageInfo, 12)
|
||||
var file_internal_machine_api_pb_cluster_proto_msgTypes = make([]protoimpl.MessageInfo, 9)
|
||||
var file_internal_machine_api_pb_cluster_proto_goTypes = []any{
|
||||
(MachineMember_MembershipState)(0), // 0: api.MachineMember.MembershipState
|
||||
(DNSRecord_RecordType)(0), // 1: api.DNSRecord.RecordType
|
||||
@@ -901,54 +706,43 @@ var file_internal_machine_api_pb_cluster_proto_goTypes = []any{
|
||||
(*AddMachineResponse)(nil), // 3: api.AddMachineResponse
|
||||
(*MachineMember)(nil), // 4: api.MachineMember
|
||||
(*ListMachinesResponse)(nil), // 5: api.ListMachinesResponse
|
||||
(*UpdateMachineRequest)(nil), // 6: api.UpdateMachineRequest
|
||||
(*UpdateMachineResponse)(nil), // 7: api.UpdateMachineResponse
|
||||
(*RemoveMachineRequest)(nil), // 8: api.RemoveMachineRequest
|
||||
(*Domain)(nil), // 9: api.Domain
|
||||
(*ReserveDomainRequest)(nil), // 10: api.ReserveDomainRequest
|
||||
(*CreateDomainRecordsRequest)(nil), // 11: api.CreateDomainRecordsRequest
|
||||
(*CreateDomainRecordsResponse)(nil), // 12: api.CreateDomainRecordsResponse
|
||||
(*DNSRecord)(nil), // 13: api.DNSRecord
|
||||
(*NetworkConfig)(nil), // 14: api.NetworkConfig
|
||||
(*IP)(nil), // 15: api.IP
|
||||
(*MachineInfo)(nil), // 16: api.MachineInfo
|
||||
(*IPPort)(nil), // 17: api.IPPort
|
||||
(*emptypb.Empty)(nil), // 18: google.protobuf.Empty
|
||||
(*Domain)(nil), // 6: api.Domain
|
||||
(*ReserveDomainRequest)(nil), // 7: api.ReserveDomainRequest
|
||||
(*CreateDomainRecordsRequest)(nil), // 8: api.CreateDomainRecordsRequest
|
||||
(*CreateDomainRecordsResponse)(nil), // 9: api.CreateDomainRecordsResponse
|
||||
(*DNSRecord)(nil), // 10: api.DNSRecord
|
||||
(*NetworkConfig)(nil), // 11: api.NetworkConfig
|
||||
(*IP)(nil), // 12: api.IP
|
||||
(*MachineInfo)(nil), // 13: api.MachineInfo
|
||||
(*emptypb.Empty)(nil), // 14: google.protobuf.Empty
|
||||
}
|
||||
var file_internal_machine_api_pb_cluster_proto_depIdxs = []int32{
|
||||
14, // 0: api.AddMachineRequest.network:type_name -> api.NetworkConfig
|
||||
15, // 1: api.AddMachineRequest.public_ip:type_name -> api.IP
|
||||
16, // 2: api.AddMachineResponse.machine:type_name -> api.MachineInfo
|
||||
16, // 3: api.MachineMember.machine:type_name -> api.MachineInfo
|
||||
11, // 0: api.AddMachineRequest.network:type_name -> api.NetworkConfig
|
||||
12, // 1: api.AddMachineRequest.public_ip:type_name -> api.IP
|
||||
13, // 2: api.AddMachineResponse.machine:type_name -> api.MachineInfo
|
||||
13, // 3: api.MachineMember.machine:type_name -> api.MachineInfo
|
||||
0, // 4: api.MachineMember.state:type_name -> api.MachineMember.MembershipState
|
||||
4, // 5: api.ListMachinesResponse.machines:type_name -> api.MachineMember
|
||||
15, // 6: api.UpdateMachineRequest.public_ip:type_name -> api.IP
|
||||
17, // 7: api.UpdateMachineRequest.endpoints:type_name -> api.IPPort
|
||||
16, // 8: api.UpdateMachineResponse.machine:type_name -> api.MachineInfo
|
||||
13, // 9: api.CreateDomainRecordsRequest.records:type_name -> api.DNSRecord
|
||||
13, // 10: api.CreateDomainRecordsResponse.records:type_name -> api.DNSRecord
|
||||
1, // 11: api.DNSRecord.type:type_name -> api.DNSRecord.RecordType
|
||||
2, // 12: api.Cluster.AddMachine:input_type -> api.AddMachineRequest
|
||||
18, // 13: api.Cluster.ListMachines:input_type -> google.protobuf.Empty
|
||||
6, // 14: api.Cluster.UpdateMachine:input_type -> api.UpdateMachineRequest
|
||||
8, // 15: api.Cluster.RemoveMachine:input_type -> api.RemoveMachineRequest
|
||||
10, // 16: api.Cluster.ReserveDomain:input_type -> api.ReserveDomainRequest
|
||||
18, // 17: api.Cluster.GetDomain:input_type -> google.protobuf.Empty
|
||||
18, // 18: api.Cluster.ReleaseDomain:input_type -> google.protobuf.Empty
|
||||
11, // 19: api.Cluster.CreateDomainRecords:input_type -> api.CreateDomainRecordsRequest
|
||||
3, // 20: api.Cluster.AddMachine:output_type -> api.AddMachineResponse
|
||||
5, // 21: api.Cluster.ListMachines:output_type -> api.ListMachinesResponse
|
||||
7, // 22: api.Cluster.UpdateMachine:output_type -> api.UpdateMachineResponse
|
||||
18, // 23: api.Cluster.RemoveMachine:output_type -> google.protobuf.Empty
|
||||
9, // 24: api.Cluster.ReserveDomain:output_type -> api.Domain
|
||||
9, // 25: api.Cluster.GetDomain:output_type -> api.Domain
|
||||
9, // 26: api.Cluster.ReleaseDomain:output_type -> api.Domain
|
||||
12, // 27: api.Cluster.CreateDomainRecords:output_type -> api.CreateDomainRecordsResponse
|
||||
20, // [20:28] is the sub-list for method output_type
|
||||
12, // [12:20] is the sub-list for method input_type
|
||||
12, // [12:12] is the sub-list for extension type_name
|
||||
12, // [12:12] is the sub-list for extension extendee
|
||||
0, // [0:12] is the sub-list for field type_name
|
||||
10, // 6: api.CreateDomainRecordsRequest.records:type_name -> api.DNSRecord
|
||||
10, // 7: api.CreateDomainRecordsResponse.records:type_name -> api.DNSRecord
|
||||
1, // 8: api.DNSRecord.type:type_name -> api.DNSRecord.RecordType
|
||||
2, // 9: api.Cluster.AddMachine:input_type -> api.AddMachineRequest
|
||||
14, // 10: api.Cluster.ListMachines:input_type -> google.protobuf.Empty
|
||||
7, // 11: api.Cluster.ReserveDomain:input_type -> api.ReserveDomainRequest
|
||||
14, // 12: api.Cluster.GetDomain:input_type -> google.protobuf.Empty
|
||||
14, // 13: api.Cluster.ReleaseDomain:input_type -> google.protobuf.Empty
|
||||
8, // 14: api.Cluster.CreateDomainRecords:input_type -> api.CreateDomainRecordsRequest
|
||||
3, // 15: api.Cluster.AddMachine:output_type -> api.AddMachineResponse
|
||||
5, // 16: api.Cluster.ListMachines:output_type -> api.ListMachinesResponse
|
||||
6, // 17: api.Cluster.ReserveDomain:output_type -> api.Domain
|
||||
6, // 18: api.Cluster.GetDomain:output_type -> api.Domain
|
||||
6, // 19: api.Cluster.ReleaseDomain:output_type -> api.Domain
|
||||
9, // 20: api.Cluster.CreateDomainRecords:output_type -> api.CreateDomainRecordsResponse
|
||||
15, // [15:21] is the sub-list for method output_type
|
||||
9, // [9:15] is the sub-list for method input_type
|
||||
9, // [9:9] is the sub-list for extension type_name
|
||||
9, // [9:9] is the sub-list for extension extendee
|
||||
0, // [0:9] is the sub-list for field type_name
|
||||
}
|
||||
|
||||
func init() { file_internal_machine_api_pb_cluster_proto_init() }
|
||||
@@ -1008,42 +802,6 @@ func file_internal_machine_api_pb_cluster_proto_init() {
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[4].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*UpdateMachineRequest); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
case 1:
|
||||
return &v.sizeCache
|
||||
case 2:
|
||||
return &v.unknownFields
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[5].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*UpdateMachineResponse); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
case 1:
|
||||
return &v.sizeCache
|
||||
case 2:
|
||||
return &v.unknownFields
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[6].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*RemoveMachineRequest); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
case 1:
|
||||
return &v.sizeCache
|
||||
case 2:
|
||||
return &v.unknownFields
|
||||
default:
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[7].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*Domain); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
@@ -1055,7 +813,7 @@ func file_internal_machine_api_pb_cluster_proto_init() {
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[8].Exporter = func(v any, i int) any {
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[5].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*ReserveDomainRequest); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
@@ -1067,7 +825,7 @@ func file_internal_machine_api_pb_cluster_proto_init() {
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[9].Exporter = func(v any, i int) any {
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[6].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*CreateDomainRecordsRequest); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
@@ -1079,7 +837,7 @@ func file_internal_machine_api_pb_cluster_proto_init() {
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[10].Exporter = func(v any, i int) any {
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[7].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*CreateDomainRecordsResponse); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
@@ -1091,7 +849,7 @@ func file_internal_machine_api_pb_cluster_proto_init() {
|
||||
return nil
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[11].Exporter = func(v any, i int) any {
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[8].Exporter = func(v any, i int) any {
|
||||
switch v := v.(*DNSRecord); i {
|
||||
case 0:
|
||||
return &v.state
|
||||
@@ -1104,14 +862,13 @@ func file_internal_machine_api_pb_cluster_proto_init() {
|
||||
}
|
||||
}
|
||||
}
|
||||
file_internal_machine_api_pb_cluster_proto_msgTypes[4].OneofWrappers = []any{}
|
||||
type x struct{}
|
||||
out := protoimpl.TypeBuilder{
|
||||
File: protoimpl.DescBuilder{
|
||||
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
|
||||
RawDescriptor: file_internal_machine_api_pb_cluster_proto_rawDesc,
|
||||
NumEnums: 2,
|
||||
NumMessages: 12,
|
||||
NumMessages: 9,
|
||||
NumExtensions: 0,
|
||||
NumServices: 1,
|
||||
},
|
||||
|
||||
@@ -11,8 +11,6 @@ import "internal/machine/api/pb/machine.proto";
|
||||
service Cluster {
|
||||
rpc AddMachine(AddMachineRequest) returns (AddMachineResponse);
|
||||
rpc ListMachines(google.protobuf.Empty) returns (ListMachinesResponse);
|
||||
rpc UpdateMachine(UpdateMachineRequest) returns (UpdateMachineResponse);
|
||||
rpc RemoveMachine(RemoveMachineRequest) returns (google.protobuf.Empty);
|
||||
|
||||
rpc ReserveDomain(ReserveDomainRequest) returns (Domain);
|
||||
rpc GetDomain(google.protobuf.Empty) returns (Domain);
|
||||
@@ -51,24 +49,6 @@ message ListMachinesResponse {
|
||||
repeated MachineMember machines = 1;
|
||||
}
|
||||
|
||||
message UpdateMachineRequest {
|
||||
// Machine to update
|
||||
string machine_id = 1;
|
||||
|
||||
// Updated machine information
|
||||
optional string name = 2;
|
||||
optional IP public_ip = 3;
|
||||
repeated IPPort endpoints = 4;
|
||||
}
|
||||
|
||||
message UpdateMachineResponse {
|
||||
MachineInfo machine = 1;
|
||||
}
|
||||
|
||||
message RemoveMachineRequest {
|
||||
string id = 1;
|
||||
}
|
||||
|
||||
message Domain {
|
||||
string name = 1;
|
||||
}
|
||||
|
||||
@@ -22,8 +22,6 @@ const _ = grpc.SupportPackageIsVersion9
|
||||
const (
|
||||
Cluster_AddMachine_FullMethodName = "/api.Cluster/AddMachine"
|
||||
Cluster_ListMachines_FullMethodName = "/api.Cluster/ListMachines"
|
||||
Cluster_UpdateMachine_FullMethodName = "/api.Cluster/UpdateMachine"
|
||||
Cluster_RemoveMachine_FullMethodName = "/api.Cluster/RemoveMachine"
|
||||
Cluster_ReserveDomain_FullMethodName = "/api.Cluster/ReserveDomain"
|
||||
Cluster_GetDomain_FullMethodName = "/api.Cluster/GetDomain"
|
||||
Cluster_ReleaseDomain_FullMethodName = "/api.Cluster/ReleaseDomain"
|
||||
@@ -36,8 +34,6 @@ const (
|
||||
type ClusterClient interface {
|
||||
AddMachine(ctx context.Context, in *AddMachineRequest, opts ...grpc.CallOption) (*AddMachineResponse, error)
|
||||
ListMachines(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*ListMachinesResponse, error)
|
||||
UpdateMachine(ctx context.Context, in *UpdateMachineRequest, opts ...grpc.CallOption) (*UpdateMachineResponse, error)
|
||||
RemoveMachine(ctx context.Context, in *RemoveMachineRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||
ReserveDomain(ctx context.Context, in *ReserveDomainRequest, opts ...grpc.CallOption) (*Domain, error)
|
||||
GetDomain(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*Domain, error)
|
||||
ReleaseDomain(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*Domain, error)
|
||||
@@ -72,26 +68,6 @@ func (c *clusterClient) ListMachines(ctx context.Context, in *emptypb.Empty, opt
|
||||
return out, nil
|
||||
}
|
||||
|
||||
func (c *clusterClient) UpdateMachine(ctx context.Context, in *UpdateMachineRequest, opts ...grpc.CallOption) (*UpdateMachineResponse, error) {
|
||||
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
||||
out := new(UpdateMachineResponse)
|
||||
err := c.cc.Invoke(ctx, Cluster_UpdateMachine_FullMethodName, in, out, cOpts...)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
func (c *clusterClient) RemoveMachine(ctx context.Context, in *RemoveMachineRequest, opts ...grpc.CallOption) (*emptypb.Empty, error) {
|
||||
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
||||
out := new(emptypb.Empty)
|
||||
err := c.cc.Invoke(ctx, Cluster_RemoveMachine_FullMethodName, in, out, cOpts...)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
func (c *clusterClient) ReserveDomain(ctx context.Context, in *ReserveDomainRequest, opts ...grpc.CallOption) (*Domain, error) {
|
||||
cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...)
|
||||
out := new(Domain)
|
||||
@@ -138,8 +114,6 @@ func (c *clusterClient) CreateDomainRecords(ctx context.Context, in *CreateDomai
|
||||
type ClusterServer interface {
|
||||
AddMachine(context.Context, *AddMachineRequest) (*AddMachineResponse, error)
|
||||
ListMachines(context.Context, *emptypb.Empty) (*ListMachinesResponse, error)
|
||||
UpdateMachine(context.Context, *UpdateMachineRequest) (*UpdateMachineResponse, error)
|
||||
RemoveMachine(context.Context, *RemoveMachineRequest) (*emptypb.Empty, error)
|
||||
ReserveDomain(context.Context, *ReserveDomainRequest) (*Domain, error)
|
||||
GetDomain(context.Context, *emptypb.Empty) (*Domain, error)
|
||||
ReleaseDomain(context.Context, *emptypb.Empty) (*Domain, error)
|
||||
@@ -160,12 +134,6 @@ func (UnimplementedClusterServer) AddMachine(context.Context, *AddMachineRequest
|
||||
func (UnimplementedClusterServer) ListMachines(context.Context, *emptypb.Empty) (*ListMachinesResponse, error) {
|
||||
return nil, status.Errorf(codes.Unimplemented, "method ListMachines not implemented")
|
||||
}
|
||||
func (UnimplementedClusterServer) UpdateMachine(context.Context, *UpdateMachineRequest) (*UpdateMachineResponse, error) {
|
||||
return nil, status.Errorf(codes.Unimplemented, "method UpdateMachine not implemented")
|
||||
}
|
||||
func (UnimplementedClusterServer) RemoveMachine(context.Context, *RemoveMachineRequest) (*emptypb.Empty, error) {
|
||||
return nil, status.Errorf(codes.Unimplemented, "method RemoveMachine not implemented")
|
||||
}
|
||||
func (UnimplementedClusterServer) ReserveDomain(context.Context, *ReserveDomainRequest) (*Domain, error) {
|
||||
return nil, status.Errorf(codes.Unimplemented, "method ReserveDomain not implemented")
|
||||
}
|
||||
@@ -235,42 +203,6 @@ func _Cluster_ListMachines_Handler(srv interface{}, ctx context.Context, dec fun
|
||||
return interceptor(ctx, in, info, handler)
|
||||
}
|
||||
|
||||
func _Cluster_UpdateMachine_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
|
||||
in := new(UpdateMachineRequest)
|
||||
if err := dec(in); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if interceptor == nil {
|
||||
return srv.(ClusterServer).UpdateMachine(ctx, in)
|
||||
}
|
||||
info := &grpc.UnaryServerInfo{
|
||||
Server: srv,
|
||||
FullMethod: Cluster_UpdateMachine_FullMethodName,
|
||||
}
|
||||
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
|
||||
return srv.(ClusterServer).UpdateMachine(ctx, req.(*UpdateMachineRequest))
|
||||
}
|
||||
return interceptor(ctx, in, info, handler)
|
||||
}
|
||||
|
||||
func _Cluster_RemoveMachine_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
|
||||
in := new(RemoveMachineRequest)
|
||||
if err := dec(in); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if interceptor == nil {
|
||||
return srv.(ClusterServer).RemoveMachine(ctx, in)
|
||||
}
|
||||
info := &grpc.UnaryServerInfo{
|
||||
Server: srv,
|
||||
FullMethod: Cluster_RemoveMachine_FullMethodName,
|
||||
}
|
||||
handler := func(ctx context.Context, req interface{}) (interface{}, error) {
|
||||
return srv.(ClusterServer).RemoveMachine(ctx, req.(*RemoveMachineRequest))
|
||||
}
|
||||
return interceptor(ctx, in, info, handler)
|
||||
}
|
||||
|
||||
func _Cluster_ReserveDomain_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) {
|
||||
in := new(ReserveDomainRequest)
|
||||
if err := dec(in); err != nil {
|
||||
@@ -358,14 +290,6 @@ var Cluster_ServiceDesc = grpc.ServiceDesc{
|
||||
MethodName: "ListMachines",
|
||||
Handler: _Cluster_ListMachines_Handler,
|
||||
},
|
||||
{
|
||||
MethodName: "UpdateMachine",
|
||||
Handler: _Cluster_UpdateMachine_Handler,
|
||||
},
|
||||
{
|
||||
MethodName: "RemoveMachine",
|
||||
Handler: _Cluster_RemoveMachine_Handler,
|
||||
},
|
||||
{
|
||||
MethodName: "ReserveDomain",
|
||||
Handler: _Cluster_ReserveDomain_Handler,
|
||||
|
||||
@@ -14,7 +14,7 @@ service Machine {
|
||||
rpc JoinCluster(JoinClusterRequest) returns (google.protobuf.Empty);
|
||||
rpc Token(google.protobuf.Empty) returns (TokenResponse);
|
||||
rpc Inspect(google.protobuf.Empty) returns (MachineInfo);
|
||||
// Reset restores the machine to a clean state, removing all cluster-related configuration and data.
|
||||
// Reset restores the machine to a clean state, removing all cluster-related сonfiguration and data.
|
||||
rpc Reset(ResetRequest) returns (google.protobuf.Empty);
|
||||
|
||||
rpc InspectService(InspectServiceRequest) returns (InspectServiceResponse);
|
||||
|
||||
@@ -39,7 +39,7 @@ type MachineClient interface {
|
||||
JoinCluster(ctx context.Context, in *JoinClusterRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||
Token(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*TokenResponse, error)
|
||||
Inspect(ctx context.Context, in *emptypb.Empty, opts ...grpc.CallOption) (*MachineInfo, error)
|
||||
// Reset restores the machine to a clean state, removing all cluster-related configuration and data.
|
||||
// Reset restores the machine to a clean state, removing all cluster-related сonfiguration and data.
|
||||
Reset(ctx context.Context, in *ResetRequest, opts ...grpc.CallOption) (*emptypb.Empty, error)
|
||||
InspectService(ctx context.Context, in *InspectServiceRequest, opts ...grpc.CallOption) (*InspectServiceResponse, error)
|
||||
}
|
||||
@@ -132,7 +132,7 @@ type MachineServer interface {
|
||||
JoinCluster(context.Context, *JoinClusterRequest) (*emptypb.Empty, error)
|
||||
Token(context.Context, *emptypb.Empty) (*TokenResponse, error)
|
||||
Inspect(context.Context, *emptypb.Empty) (*MachineInfo, error)
|
||||
// Reset restores the machine to a clean state, removing all cluster-related configuration and data.
|
||||
// Reset restores the machine to a clean state, removing all cluster-related сonfiguration and data.
|
||||
Reset(context.Context, *ResetRequest) (*emptypb.Empty, error)
|
||||
InspectService(context.Context, *InspectServiceRequest) (*InspectServiceResponse, error)
|
||||
mustEmbedUnimplementedMachineServer()
|
||||
|
||||
@@ -2,11 +2,10 @@ package proxy
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
"google.golang.org/grpc/status"
|
||||
"google.golang.org/protobuf/encoding/protowire"
|
||||
"google.golang.org/protobuf/proto"
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
)
|
||||
|
||||
// One2ManyResponder converts upstream responses into messages from upstreams, so that multiple
|
||||
|
||||
@@ -2,12 +2,11 @@ package proxy
|
||||
|
||||
import (
|
||||
"context"
|
||||
"sync"
|
||||
|
||||
"github.com/siderolabs/grpc-proxy/proxy"
|
||||
"google.golang.org/grpc/codes"
|
||||
"google.golang.org/grpc/metadata"
|
||||
"google.golang.org/grpc/status"
|
||||
"sync"
|
||||
)
|
||||
|
||||
// Director manages routing of gRPC requests between local and remote backends.
|
||||
|
||||
@@ -2,12 +2,11 @@ package proxy
|
||||
|
||||
import (
|
||||
"context"
|
||||
"sync"
|
||||
|
||||
"github.com/siderolabs/grpc-proxy/proxy"
|
||||
"google.golang.org/grpc"
|
||||
"google.golang.org/grpc/credentials/insecure"
|
||||
"google.golang.org/grpc/metadata"
|
||||
"sync"
|
||||
)
|
||||
|
||||
// LocalBackend is a proxy.One2ManyResponder implementation that proxies to a local gRPC server listening on a Unix socket.
|
||||
|
||||
@@ -3,15 +3,14 @@ package proxy
|
||||
import (
|
||||
"context"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/siderolabs/grpc-proxy/proxy"
|
||||
"google.golang.org/grpc"
|
||||
"google.golang.org/grpc/backoff"
|
||||
"google.golang.org/grpc/credentials/insecure"
|
||||
"google.golang.org/grpc/metadata"
|
||||
"net/netip"
|
||||
"sync"
|
||||
"time"
|
||||
)
|
||||
|
||||
// RemoteBackend is a proxy.One2ManyResponder implementation that proxies to a remote gRPC server, injecting machine metadata
|
||||
|
||||
@@ -1,342 +0,0 @@
|
||||
package caddyconfig
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"cmp"
|
||||
"context"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"maps"
|
||||
"net"
|
||||
"slices"
|
||||
"strconv"
|
||||
"strings"
|
||||
"text/template"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/machine/store"
|
||||
"github.com/psviderski/uncloud/pkg/api"
|
||||
)
|
||||
|
||||
const (
|
||||
caddyfileHeader = `# This file is autogenerated by Uncloud based on the configuration of running services.
|
||||
# Do not edit manually. Any manual changes will be overwritten on the next update.
|
||||
`
|
||||
caddyfileTemplate = `# Health check endpoint to verify Caddy reachability on this machine.
|
||||
http:// {
|
||||
handle {{.VerifyPath}} {
|
||||
respond "{{.VerifyResponse}}" 200
|
||||
}
|
||||
log
|
||||
}
|
||||
|
||||
(common_proxy) {
|
||||
# Retry failed requests up to lb_retries times against other available upstreams.
|
||||
lb_retries 3
|
||||
# Upstreams are marked unhealthy for fail_duration after a failed request (passive health checking).
|
||||
fail_duration 30s
|
||||
}
|
||||
{{- if or .HTTPHostUpstreams .HTTPSHostUpstreams }}
|
||||
|
||||
# Sites generated from service ports.{{end}}
|
||||
{{- range $hostname, $upstreams := .HTTPHostUpstreams}}
|
||||
|
||||
http://{{$hostname}} {
|
||||
reverse_proxy {{join $upstreams " "}} {
|
||||
import common_proxy
|
||||
}
|
||||
log
|
||||
}{{end}}
|
||||
{{- range $hostname, $upstreams := .HTTPSHostUpstreams}}
|
||||
|
||||
https://{{$hostname}} {
|
||||
reverse_proxy {{join $upstreams " "}} {
|
||||
import common_proxy
|
||||
}
|
||||
log
|
||||
}{{end}}
|
||||
`
|
||||
caddyfileUnavailabeFooter = `# NOTE: User-defined configs for services were skipped because Caddy is not running on this machine
|
||||
# or the latest generated config is invalid. Please check the Caddy logs if it's running.
|
||||
`
|
||||
)
|
||||
|
||||
// CaddyfileGenerator generates a Caddyfile configuration for the Caddy reverse proxy.
|
||||
type CaddyfileGenerator struct {
|
||||
// machineID is the unique identifier of the machine where the controller is running.
|
||||
machineID string
|
||||
validator CaddyfileValidator
|
||||
log *slog.Logger
|
||||
}
|
||||
|
||||
// CaddyfileValidator is an interface for validating Caddyfile configurations.
|
||||
type CaddyfileValidator interface {
|
||||
Validate(ctx context.Context, caddyfile string) error
|
||||
}
|
||||
|
||||
func NewCaddyfileGenerator(machineID string, validator CaddyfileValidator, log *slog.Logger) *CaddyfileGenerator {
|
||||
if log == nil {
|
||||
log = slog.Default()
|
||||
}
|
||||
return &CaddyfileGenerator{
|
||||
machineID: machineID,
|
||||
validator: validator,
|
||||
log: log,
|
||||
}
|
||||
}
|
||||
|
||||
// Generate creates a Caddyfile configuration based on the provided service containers.
|
||||
// The Caddyfile is generated from the service ports of the healthy containers.
|
||||
// If a 'caddy' service container is running on this machine and defines a custom Caddy config (x-caddy) in its service
|
||||
// spec, it will be validated and prepended to the generated Caddyfile. Custom Caddy configs (x-caddy) defined in other
|
||||
// service specs are validated and appended to the generated Caddyfile. Invalid configs are logged and skipped to ensure
|
||||
// the generated Caddyfile remains valid.
|
||||
//
|
||||
// The final Caddyfile structure includes:
|
||||
//
|
||||
// [caddy x-caddy (global config)]
|
||||
// [generated Caddyfile from all service ports]
|
||||
// [service-a x-caddy]
|
||||
// ...
|
||||
// [service-z x-caddy]
|
||||
//
|
||||
// If includeCustom is false, custom Caddy configs (x-caddy) are not included in the generated Caddyfile.
|
||||
func (g *CaddyfileGenerator) Generate(
|
||||
ctx context.Context, records []store.ContainerRecord, includeCustom bool,
|
||||
) (string, error) {
|
||||
containers := make([]api.ServiceContainer, len(records))
|
||||
for i, cr := range records {
|
||||
containers[i] = cr.Container
|
||||
}
|
||||
// Sort containers by service name and creation time to generate a stable Caddyfile.
|
||||
slices.SortStableFunc(containers, func(a, b api.ServiceContainer) int {
|
||||
return cmp.Or(
|
||||
strings.Compare(a.ServiceName(), b.ServiceName()),
|
||||
a.CreatedTime().Compare(b.CreatedTime()),
|
||||
)
|
||||
})
|
||||
|
||||
caddyfile, err := g.generateBaseFromPorts(containers)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("generate base Caddyfile from service ports: %w", err)
|
||||
}
|
||||
|
||||
if !includeCustom {
|
||||
return fmt.Sprintf("%s\n%s\n%s", caddyfileHeader, caddyfile, caddyfileUnavailabeFooter), nil
|
||||
}
|
||||
|
||||
upstreams := serviceUpstreams(containers)
|
||||
// Track validation errors for reporting.
|
||||
var configErrors []string
|
||||
|
||||
// Find the 'caddy' service container on this machine. Use the most recent one if multiple exist.
|
||||
var caddyCtr *api.ServiceContainer
|
||||
for _, cr := range records {
|
||||
if cr.MachineID == g.machineID && cr.Container.ServiceName() == CaddyServiceName &&
|
||||
(caddyCtr == nil || cr.Container.CreatedTime().Compare(caddyCtr.CreatedTime()) > 0) {
|
||||
caddyCtr = &cr.Container
|
||||
}
|
||||
}
|
||||
|
||||
// If the caddy container is running on this machine and has a custom Caddy config (global),
|
||||
// prepend it to the generated Caddyfile and validate it.
|
||||
if caddyCtr != nil && caddyCtr.ServiceSpec.CaddyConfig() != "" {
|
||||
// Render the custom global Caddy config as a Go template with the upstreams.
|
||||
tmplCtx := templateContext{
|
||||
Name: caddyCtr.ServiceName(),
|
||||
Upstreams: upstreams,
|
||||
}
|
||||
renderedConfig, err := renderCaddyfile(tmplCtx, caddyCtr.ServiceSpec.CaddyConfig())
|
||||
if err != nil {
|
||||
g.log.Error("Failed to render template directives in user-defined global Caddy config, skipping it.",
|
||||
"service", caddyCtr.ServiceName(), "container", caddyCtr.ID, "err", err)
|
||||
configErrors = append(configErrors,
|
||||
fmt.Sprintf("service '%s': failed to render template: %v", caddyCtr.ServiceName(), err))
|
||||
} else {
|
||||
caddyfileCandidate := fmt.Sprintf("# User-defined global config from service '%s'.\n%s\n\n%s",
|
||||
caddyCtr.ServiceName(), renderedConfig, caddyfile)
|
||||
|
||||
if err = g.validator.Validate(ctx, caddyfileCandidate); err != nil {
|
||||
g.log.Error("User-defined global Caddy config is invalid, skipping it.",
|
||||
"service", caddyCtr.ServiceName(), "container", caddyCtr.ID, "err", err)
|
||||
configErrors = append(configErrors,
|
||||
fmt.Sprintf("service '%s': validation failed: %v", caddyCtr.ServiceName(), err))
|
||||
} else {
|
||||
caddyfile = caddyfileCandidate
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// There could be multiple service containers for the same service with different custom Caddy configs, for example,
|
||||
// if the service has been partially updated. The most recent container for each service defines the current custom
|
||||
// Caddy config for that service.
|
||||
latestServiceContainers := make(map[string]api.ServiceContainer, len(containers))
|
||||
for _, ctr := range containers {
|
||||
if latest, ok := latestServiceContainers[ctr.ServiceName()]; ok {
|
||||
if ctr.CreatedTime().Compare(latest.CreatedTime()) > 0 {
|
||||
latestServiceContainers[ctr.ServiceName()] = ctr
|
||||
}
|
||||
} else {
|
||||
latestServiceContainers[ctr.ServiceName()] = ctr
|
||||
}
|
||||
}
|
||||
sortedServiceNames := slices.Sorted(maps.Keys(latestServiceContainers))
|
||||
|
||||
// Append a custom Caddy config for each service to the Caddyfile and validate it. If the config for a service
|
||||
// is invalid, skip it but continue processing other services to ensure the Caddyfile remains valid.
|
||||
for _, serviceName := range sortedServiceNames {
|
||||
// Skip the caddy container as we already processed it.
|
||||
if serviceName == CaddyServiceName {
|
||||
continue
|
||||
}
|
||||
|
||||
ctr := latestServiceContainers[serviceName]
|
||||
if ctr.ServiceSpec.CaddyConfig() == "" {
|
||||
continue
|
||||
}
|
||||
|
||||
// Render the template actions in the service's Caddy config.
|
||||
tmplCtx := templateContext{
|
||||
Name: serviceName,
|
||||
Upstreams: upstreams,
|
||||
}
|
||||
renderedConfig, err := renderCaddyfile(tmplCtx, ctr.ServiceSpec.CaddyConfig())
|
||||
if err != nil {
|
||||
g.log.Error("Failed to render template directives in user-defined Caddy config for service, skipping it.",
|
||||
"service", serviceName, "err", err)
|
||||
configErrors = append(configErrors,
|
||||
fmt.Sprintf("service '%s': failed to render template: %v", serviceName, err))
|
||||
continue
|
||||
}
|
||||
|
||||
caddyfileCandidate := fmt.Sprintf("%s\n# User-defined config for service '%s'.\n%s\n",
|
||||
caddyfile, serviceName, renderedConfig)
|
||||
if err = g.validator.Validate(ctx, caddyfileCandidate); err != nil {
|
||||
g.log.Error("User-defined Caddy config for service is invalid, skipping it.",
|
||||
"service", serviceName, "err", err)
|
||||
configErrors = append(configErrors, fmt.Sprintf("service '%s': validation failed: %v", serviceName, err))
|
||||
} else {
|
||||
caddyfile = caddyfileCandidate
|
||||
}
|
||||
}
|
||||
|
||||
// Append error summary as comment if there were any invalid configs.
|
||||
if len(configErrors) > 0 {
|
||||
errorsComment := "# Skipped invalid user-defined configs:\n"
|
||||
for _, e := range configErrors {
|
||||
errorsComment += fmt.Sprintf("# - %s\n", e)
|
||||
}
|
||||
|
||||
caddyfile += "\n" + errorsComment
|
||||
}
|
||||
|
||||
return caddyfileHeader + "\n" + caddyfile, nil
|
||||
}
|
||||
|
||||
func (g *CaddyfileGenerator) generateBaseFromPorts(containers []api.ServiceContainer) (string, error) {
|
||||
httpHostUpstreams, httpsHostUpstreams := httpUpstreamsFromPorts(containers)
|
||||
|
||||
funcs := template.FuncMap{"join": strings.Join}
|
||||
tmpl, err := template.New("Caddyfile").Funcs(funcs).Parse(caddyfileTemplate)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("parse Caddyfile template: %w", err)
|
||||
}
|
||||
|
||||
data := struct {
|
||||
VerifyPath string
|
||||
VerifyResponse string
|
||||
HTTPHostUpstreams map[string][]string
|
||||
HTTPSHostUpstreams map[string][]string
|
||||
}{
|
||||
VerifyPath: VerifyPath,
|
||||
VerifyResponse: g.machineID,
|
||||
HTTPHostUpstreams: httpHostUpstreams,
|
||||
HTTPSHostUpstreams: httpsHostUpstreams,
|
||||
}
|
||||
|
||||
var buf bytes.Buffer
|
||||
if err = tmpl.Execute(&buf, data); err != nil {
|
||||
return "", fmt.Errorf("execute Caddyfile template: %w", err)
|
||||
}
|
||||
|
||||
return buf.String(), nil
|
||||
}
|
||||
|
||||
// httpUpstreamsFromPorts extracts upstreams for HTTP and HTTPS protocols from the published ports of the provided
|
||||
// service containers. It's expected that all containers are healthy.
|
||||
func httpUpstreamsFromPorts(containers []api.ServiceContainer) (map[string][]string, map[string][]string) {
|
||||
// Maps hostnames to lists of upstreams (container IP:port pairs).
|
||||
httpHostUpstreams := make(map[string][]string)
|
||||
httpsHostUpstreams := make(map[string][]string)
|
||||
for _, ctr := range containers {
|
||||
ip := ctr.UncloudNetworkIP()
|
||||
if !ip.IsValid() {
|
||||
// Container is not connected to the uncloud Docker network (could be host network).
|
||||
continue
|
||||
}
|
||||
log := slog.With("container", ctr.ID)
|
||||
|
||||
ports, err := ctr.ServicePorts()
|
||||
if err != nil {
|
||||
log.Error("Failed to parse service ports for container.", "err", err)
|
||||
continue
|
||||
}
|
||||
|
||||
for _, port := range ports {
|
||||
if port.Mode != api.PortModeIngress {
|
||||
continue
|
||||
}
|
||||
|
||||
switch port.Protocol {
|
||||
case api.ProtocolHTTP:
|
||||
upstream := net.JoinHostPort(ip.String(), strconv.Itoa(int(port.ContainerPort)))
|
||||
httpHostUpstreams[port.Hostname] = append(httpHostUpstreams[port.Hostname], upstream)
|
||||
case api.ProtocolHTTPS:
|
||||
upstream := net.JoinHostPort(ip.String(), strconv.Itoa(int(port.ContainerPort)))
|
||||
httpsHostUpstreams[port.Hostname] = append(httpsHostUpstreams[port.Hostname], upstream)
|
||||
default:
|
||||
// TODO: implement L4 ingress routing for TCP and UDP.
|
||||
log.Error("Unsupported protocol for ingress port.", "port", port)
|
||||
continue
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
return httpHostUpstreams, httpsHostUpstreams
|
||||
}
|
||||
|
||||
// serviceUpstreams creates a map of service names to their container IPs.
|
||||
// Only includes containers connected to the uncloud Docker network.
|
||||
func serviceUpstreams(containers []api.ServiceContainer) map[string][]string {
|
||||
upstreams := make(map[string][]string)
|
||||
for _, ctr := range containers {
|
||||
ip := ctr.UncloudNetworkIP()
|
||||
if !ip.IsValid() {
|
||||
// Container is not connected to the uncloud Docker network (could be host network).
|
||||
continue
|
||||
}
|
||||
|
||||
serviceName := ctr.ServiceName()
|
||||
upstreams[serviceName] = append(upstreams[serviceName], ip.String())
|
||||
}
|
||||
|
||||
return upstreams
|
||||
}
|
||||
|
||||
// renderCaddyfile renders a Caddyfile template with the upstreams function and data.
|
||||
func renderCaddyfile(tmplCtx templateContext, caddyfile string) (string, error) {
|
||||
funcs := template.FuncMap{
|
||||
"upstreams": upstreamsTemplateFn(tmplCtx),
|
||||
}
|
||||
|
||||
tmpl, err := template.New("Caddyfile").Funcs(funcs).Parse(caddyfile)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("parse config as Go template: %w", err)
|
||||
}
|
||||
|
||||
var buf bytes.Buffer
|
||||
if err = tmpl.Execute(&buf, tmplCtx); err != nil {
|
||||
return "", fmt.Errorf("execute template: %w", err)
|
||||
}
|
||||
|
||||
return buf.String(), nil
|
||||
}
|
||||
@@ -1,142 +0,0 @@
|
||||
package caddyconfig
|
||||
|
||||
import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
"net/http"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"github.com/caddyserver/caddy/v2"
|
||||
)
|
||||
|
||||
// CaddyAdminClient is a client for interacting with the Caddy admin API over a Unix socket.
|
||||
type CaddyAdminClient struct {
|
||||
socketPath string
|
||||
client *http.Client
|
||||
}
|
||||
|
||||
func NewCaddyAdminClient(socketPath string) *CaddyAdminClient {
|
||||
return &CaddyAdminClient{
|
||||
socketPath: socketPath,
|
||||
client: &http.Client{
|
||||
Timeout: 5 * time.Second,
|
||||
Transport: &http.Transport{
|
||||
DialContext: func(_ context.Context, _, _ string) (net.Conn, error) {
|
||||
return net.Dial("unix", socketPath)
|
||||
},
|
||||
},
|
||||
},
|
||||
}
|
||||
}
|
||||
|
||||
// IsAvailable checks if the local Caddy instance is running and responding to admin API requests.
|
||||
func (c *CaddyAdminClient) IsAvailable(ctx context.Context) bool {
|
||||
// Caddy doesn't serve a /ping endpoint. It's a random endpoint we can use to check if Caddy is running.
|
||||
req, err := http.NewRequestWithContext(ctx, "GET", "http://localhost/ping", nil)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
|
||||
resp, err := c.client.Do(req)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
|
||||
// Any HTTP response means Caddy is running and accessible.
|
||||
return true
|
||||
}
|
||||
|
||||
// Adapt converts a Caddyfile to JSON configuration without loading or running it.
|
||||
func (c *CaddyAdminClient) Adapt(ctx context.Context, caddyfile string) (string, error) {
|
||||
req, err := http.NewRequestWithContext(ctx, "POST", "http://localhost/adapt", strings.NewReader(caddyfile))
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("create adapt request: %w", err)
|
||||
}
|
||||
req.Header.Set("Content-Type", "text/caddyfile")
|
||||
|
||||
resp, err := c.client.Do(req)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("send adapt request: %w", err)
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
|
||||
body, err := io.ReadAll(resp.Body)
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("read response body: %w", err)
|
||||
}
|
||||
|
||||
if resp.StatusCode == http.StatusOK {
|
||||
// Parse the response body to extract the result field.
|
||||
var msg struct {
|
||||
Result json.RawMessage `json:"result"`
|
||||
}
|
||||
if err = json.Unmarshal(body, &msg); err != nil {
|
||||
return "", fmt.Errorf("parse adapt response: %w", err)
|
||||
}
|
||||
return string(msg.Result), nil
|
||||
}
|
||||
|
||||
// If the response is a 400 Bad Request, try to parse the error message from it.
|
||||
if resp.StatusCode == http.StatusBadRequest {
|
||||
var apiError caddy.APIError
|
||||
if err = json.Unmarshal(body, &apiError); err == nil {
|
||||
return "", errors.New(apiError.Message)
|
||||
}
|
||||
}
|
||||
|
||||
return "", errors.New(string(body))
|
||||
}
|
||||
|
||||
// Load loads a Caddyfile configuration into the Caddy instance running on the machine.
|
||||
// Due to a Caddy bug (https://github.com/caddyserver/caddy/issues/7246), we first adapt the Caddyfile to JSON
|
||||
// and then load the JSON config to get proper error handling.
|
||||
func (c *CaddyAdminClient) Load(ctx context.Context, caddyfile string) error {
|
||||
jsonConfig, err := c.Adapt(ctx, caddyfile)
|
||||
if err != nil {
|
||||
return fmt.Errorf("adapt Caddyfile to JSON config: %w", err)
|
||||
}
|
||||
|
||||
req, err := http.NewRequestWithContext(ctx, "POST", "http://localhost/load", strings.NewReader(jsonConfig))
|
||||
if err != nil {
|
||||
return fmt.Errorf("create load request: %w", err)
|
||||
}
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
|
||||
resp, err := c.client.Do(req)
|
||||
if err != nil {
|
||||
return fmt.Errorf("send load request: %w", err)
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
|
||||
if resp.StatusCode == http.StatusOK {
|
||||
return nil
|
||||
}
|
||||
|
||||
body, _ := io.ReadAll(resp.Body)
|
||||
// If the response is a 400 Bad Request, try to parse the error message from it.
|
||||
if resp.StatusCode == http.StatusBadRequest {
|
||||
var apiError caddy.APIError
|
||||
if err = json.Unmarshal(body, &apiError); err == nil {
|
||||
return fmt.Errorf("caddy responded with error: %s", apiError.Message)
|
||||
}
|
||||
}
|
||||
|
||||
return fmt.Errorf("caddy responded with error: HTTP %d: %s", resp.StatusCode, string(body))
|
||||
}
|
||||
|
||||
// Validate checks if the provided Caddyfile can be adapted to Caddy JSON config using the running Caddy instance via
|
||||
// its admin API. It doesn't guarantee that the Caddyfile is actually valid and can be loaded. For example, a tls
|
||||
// directive with a missing certificate will pass the adaptation but will fail when Caddy tries to load it.
|
||||
// But this is the best we can do over the admin API.
|
||||
// TODO: run 'docker exec caddy-container caddy validate' to do proper validation or implement a Caddy module that
|
||||
// exposes a validation endpoint.
|
||||
func (c *CaddyAdminClient) Validate(ctx context.Context, caddyfile string) error {
|
||||
_, err := c.Adapt(ctx, caddyfile)
|
||||
return err
|
||||
}
|
||||
@@ -4,7 +4,9 @@ import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"log/slog"
|
||||
"maps"
|
||||
"net"
|
||||
"net/http"
|
||||
"slices"
|
||||
"strconv"
|
||||
@@ -17,8 +19,47 @@ import (
|
||||
"github.com/psviderski/uncloud/pkg/api"
|
||||
)
|
||||
|
||||
func GenerateJSONConfig(containers []api.ServiceContainer, verifyResponse string) (*caddy.Config, error) {
|
||||
httpHostUpstreams, httpsHostUpstreams := httpUpstreamsFromPorts(containers)
|
||||
func GenerateConfig(containers []api.ServiceContainer, verifyResponse string) (*caddy.Config, error) {
|
||||
// Maps hostnames to lists of upstreams (container IP:port pairs).
|
||||
httpHostUpstreams := make(map[string][]string)
|
||||
httpsHostUpstreams := make(map[string][]string)
|
||||
for _, ctr := range containers {
|
||||
if !ctr.Healthy() {
|
||||
continue
|
||||
}
|
||||
|
||||
ip := ctr.UncloudNetworkIP()
|
||||
if !ip.IsValid() {
|
||||
// Container is not connected to the uncloud Docker network (could be host network).
|
||||
continue
|
||||
}
|
||||
log := slog.With("container", ctr.ID)
|
||||
|
||||
ports, err := ctr.ServicePorts()
|
||||
if err != nil {
|
||||
log.Error("Failed to parse service ports for container.", "err", err)
|
||||
continue
|
||||
}
|
||||
|
||||
for _, port := range ports {
|
||||
if port.Mode != api.PortModeIngress {
|
||||
continue
|
||||
}
|
||||
|
||||
switch port.Protocol {
|
||||
case api.ProtocolHTTP:
|
||||
upstream := net.JoinHostPort(ip.String(), strconv.Itoa(int(port.ContainerPort)))
|
||||
httpHostUpstreams[port.Hostname] = append(httpHostUpstreams[port.Hostname], upstream)
|
||||
case api.ProtocolHTTPS:
|
||||
upstream := net.JoinHostPort(ip.String(), strconv.Itoa(int(port.ContainerPort)))
|
||||
httpsHostUpstreams[port.Hostname] = append(httpsHostUpstreams[port.Hostname], upstream)
|
||||
default:
|
||||
// TODO: implement L4 ingress routing for TCP and UDP.
|
||||
log.Error("Unsupported protocol for ingress port.", "port", port)
|
||||
continue
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
var warnings []caddyconfig.Warning
|
||||
servers := make(map[string]*caddyhttp.Server)
|
||||
@@ -13,7 +13,7 @@ import (
|
||||
"github.com/stretchr/testify/require"
|
||||
)
|
||||
|
||||
func TestGenerateJSONConfig(t *testing.T) {
|
||||
func TestGenerateConfig(t *testing.T) {
|
||||
configWithoutServices := `{
|
||||
"servers": {
|
||||
"http": {
|
||||
@@ -312,11 +312,73 @@ func TestGenerateJSONConfig(t *testing.T) {
|
||||
want: configWithoutServices,
|
||||
wantErr: false,
|
||||
},
|
||||
{
|
||||
name: "restarting container ignored",
|
||||
containers: []api.ServiceContainer{
|
||||
newRestartingContainer("10.210.0.2", "app.example.com:8080/http"),
|
||||
},
|
||||
want: configWithoutServices,
|
||||
wantErr: false,
|
||||
},
|
||||
{
|
||||
name: "stopped container ignored",
|
||||
containers: []api.ServiceContainer{
|
||||
newStoppedContainer("10.210.0.2", "app.example.com:8080/http"),
|
||||
},
|
||||
want: configWithoutServices,
|
||||
wantErr: false,
|
||||
},
|
||||
{
|
||||
name: "mix of running, restarting, and stopped containers",
|
||||
containers: []api.ServiceContainer{
|
||||
newContainer("10.210.0.2", "app.example.com:8080/http"),
|
||||
newRestartingContainer("10.210.0.3", "app.example.com:8080/http"),
|
||||
newStoppedContainer("10.210.0.4", "app.example.com:8080/http"),
|
||||
},
|
||||
want: `{
|
||||
"servers": {
|
||||
"http": {
|
||||
"listen": [":80"],
|
||||
"routes": [
|
||||
{
|
||||
"match": [{"host": ["app.example.com"]}],
|
||||
"handle": [{
|
||||
"handler": "reverse_proxy",
|
||||
"health_checks": {
|
||||
"passive": {
|
||||
"fail_duration": 30000000000
|
||||
}
|
||||
},
|
||||
"load_balancing": {
|
||||
"retries": 3
|
||||
},
|
||||
"upstreams": [{"dial": "10.210.0.2:8080"}]
|
||||
}]
|
||||
},
|
||||
{
|
||||
"match": [{"path": ["/.uncloud-verify"]}],
|
||||
"handle": [{
|
||||
"body": "verification-response-body",
|
||||
"handler": "static_response",
|
||||
"status_code": 200
|
||||
}]
|
||||
}
|
||||
],
|
||||
"logs": {}
|
||||
},
|
||||
"https": {
|
||||
"listen": [":443"],
|
||||
"logs": {}
|
||||
}
|
||||
}
|
||||
}`,
|
||||
wantErr: false,
|
||||
},
|
||||
}
|
||||
|
||||
for _, tt := range tests {
|
||||
t.Run(tt.name, func(t *testing.T) {
|
||||
config, err := GenerateJSONConfig(tt.containers, "verification-response-body")
|
||||
config, err := GenerateConfig(tt.containers, "verification-response-body")
|
||||
|
||||
if tt.wantErr {
|
||||
assert.Error(t, err)
|
||||
@@ -377,3 +439,15 @@ func newContainerWithoutNetwork(ports ...string) api.ServiceContainer {
|
||||
},
|
||||
}}}
|
||||
}
|
||||
|
||||
func newRestartingContainer(ip string, ports ...string) api.ServiceContainer {
|
||||
ctr := newContainer(ip, ports...)
|
||||
ctr.Container.State.Restarting = true
|
||||
return ctr
|
||||
}
|
||||
|
||||
func newStoppedContainer(ip string, ports ...string) api.ServiceContainer {
|
||||
ctr := newContainer(ip, ports...)
|
||||
ctr.Container.State.Running = false
|
||||
return ctr
|
||||
}
|
||||
@@ -14,7 +14,6 @@ import (
|
||||
)
|
||||
|
||||
const (
|
||||
CaddyServiceName = "caddy"
|
||||
CaddyGroup = "uncloud"
|
||||
VerifyPath = "/.uncloud-verify"
|
||||
)
|
||||
@@ -23,49 +22,40 @@ const (
|
||||
// proxy. The generated configuration allows Caddy to route external traffic to service containers across the internal
|
||||
// network.
|
||||
type Controller struct {
|
||||
machineID string
|
||||
caddyfilePath string
|
||||
generator *CaddyfileGenerator
|
||||
client *CaddyAdminClient
|
||||
store *store.Store
|
||||
log *slog.Logger
|
||||
path string
|
||||
verifyResponse string
|
||||
}
|
||||
|
||||
func NewController(machineID, configDir, adminSock string, store *store.Store) (*Controller, error) {
|
||||
if err := os.MkdirAll(configDir, 0o750); err != nil {
|
||||
return nil, fmt.Errorf("create directory for Caddy configuration '%s': %w", configDir, err)
|
||||
func NewController(store *store.Store, path string, verifyResponse string) (*Controller, error) {
|
||||
dir := filepath.Dir(path)
|
||||
if err := os.MkdirAll(dir, 0750); err != nil {
|
||||
return nil, fmt.Errorf("create parent directory for Caddy configuration '%s': %w", dir, err)
|
||||
}
|
||||
if err := fs.Chown(configDir, "", CaddyGroup); err != nil {
|
||||
return nil, fmt.Errorf("change owner of directory for Caddy configuration '%s': %w", configDir, err)
|
||||
if err := fs.Chown(dir, "", CaddyGroup); err != nil {
|
||||
return nil, fmt.Errorf("change owner of parent directory for Caddy configuration '%s': %w", dir, err)
|
||||
}
|
||||
|
||||
log := slog.With("component", "caddy-controller")
|
||||
client := NewCaddyAdminClient(adminSock)
|
||||
generator := NewCaddyfileGenerator(machineID, client, log)
|
||||
|
||||
return &Controller{
|
||||
machineID: machineID,
|
||||
caddyfilePath: filepath.Join(configDir, "Caddyfile"),
|
||||
generator: generator,
|
||||
client: client,
|
||||
store: store,
|
||||
log: log,
|
||||
path: path,
|
||||
verifyResponse: verifyResponse,
|
||||
}, nil
|
||||
}
|
||||
|
||||
func (c *Controller) Run(ctx context.Context) error {
|
||||
containers, changes, err := c.store.SubscribeContainers(ctx)
|
||||
containerRecords, changes, err := c.store.SubscribeContainers(ctx)
|
||||
if err != nil {
|
||||
return fmt.Errorf("subscribe to container changes: %w", err)
|
||||
}
|
||||
c.log.Info("Subscribed to container changes in the cluster to generate Caddy configuration.")
|
||||
slog.Info("Subscribed to container changes in the cluster to generate Caddy configuration.")
|
||||
|
||||
containers = filterHealthyContainers(containers)
|
||||
c.generateAndLoadCaddyfile(ctx, containers)
|
||||
|
||||
// TODO: left for backward compatibility, remove later.
|
||||
if err = c.generateJSONConfig(containers); err != nil {
|
||||
c.log.Error("Failed to generate Caddy JSON configuration to disk.", "err", err)
|
||||
containers, err := c.filterAvailableContainers(containerRecords)
|
||||
if err != nil {
|
||||
return fmt.Errorf("filter available containers: %w", err)
|
||||
}
|
||||
if err = c.generateConfig(containers); err != nil {
|
||||
return fmt.Errorf("generate Caddy configuration: %w", err)
|
||||
}
|
||||
|
||||
for {
|
||||
@@ -74,97 +64,47 @@ func (c *Controller) Run(ctx context.Context) error {
|
||||
if !ok {
|
||||
return fmt.Errorf("containers subscription failed")
|
||||
}
|
||||
c.log.Info("Cluster containers changed, updating Caddy configuration.")
|
||||
slog.Debug("Cluster containers changed, updating Caddy configuration.")
|
||||
|
||||
containers, err = c.store.ListContainers(ctx, store.ListOptions{})
|
||||
containerRecords, err = c.store.ListContainers(ctx, store.ListOptions{})
|
||||
if err != nil {
|
||||
c.log.Error("Failed to list containers.", "err", err)
|
||||
slog.Error("Failed to list containers.", "err", err)
|
||||
continue
|
||||
}
|
||||
containers = filterHealthyContainers(containers)
|
||||
c.generateAndLoadCaddyfile(ctx, containers)
|
||||
|
||||
// TODO: left for backward compatibility, remove later.
|
||||
if err = c.generateJSONConfig(containers); err != nil {
|
||||
c.log.Error("Failed to generate Caddy JSON configuration to disk.", "err", err)
|
||||
containers, err = c.filterAvailableContainers(containerRecords)
|
||||
if err != nil {
|
||||
slog.Error("Failed to filter available containers.", "err", err)
|
||||
continue
|
||||
}
|
||||
if err = c.generateConfig(containers); err != nil {
|
||||
slog.Error("Failed to generate Caddy configuration.", "err", err)
|
||||
}
|
||||
|
||||
slog.Debug("Updated Caddy configuration.", "path", c.path)
|
||||
case <-ctx.Done():
|
||||
return nil
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// filterHealthyContainers filters out containers that are not healthy.
|
||||
// TODO: Filters out containers from this machine that are likely unavailable. The availability can be determined
|
||||
// by the cluster membership state of the machine that the container is running on. Implement machine membership
|
||||
// check using Corrossion Admin client.
|
||||
func filterHealthyContainers(containers []store.ContainerRecord) []store.ContainerRecord {
|
||||
healthy := make([]store.ContainerRecord, 0, len(containers))
|
||||
for _, cr := range containers {
|
||||
if cr.Container.Healthy() {
|
||||
healthy = append(healthy, cr)
|
||||
// filterAvailableContainers filters out containers from this machine that are likely unavailable. The availability
|
||||
// is determined by the cluster membership state of the machine that the container is running on.
|
||||
// TODO: implement machine membership check using Corrossion Admin client.
|
||||
func (c *Controller) filterAvailableContainers(
|
||||
containerRecords []store.ContainerRecord,
|
||||
) ([]api.ServiceContainer, error) {
|
||||
containers := make([]api.ServiceContainer, len(containerRecords))
|
||||
for i, cr := range containerRecords {
|
||||
containers[i] = api.ServiceContainer{
|
||||
Container: cr.Container,
|
||||
// TODO: restore ServiceSpec from the container record once it's saved in the store.
|
||||
}
|
||||
}
|
||||
return healthy
|
||||
return containers, nil
|
||||
}
|
||||
|
||||
func (c *Controller) generateAndLoadCaddyfile(ctx context.Context, containers []store.ContainerRecord) {
|
||||
// Check if Caddy is available before attempting to generate and load config.
|
||||
caddyAvailable := c.client.IsAvailable(ctx)
|
||||
caddyfile, err := c.generator.Generate(ctx, containers, caddyAvailable)
|
||||
if err != nil {
|
||||
c.log.Error("Failed to generate Caddyfile configuration.", "err", err)
|
||||
return
|
||||
}
|
||||
|
||||
if !caddyAvailable {
|
||||
// Caddy is not running so the generated Caddyfile should not include user-defined configs thus must be valid.
|
||||
// It's safe to write the config to disk so that when Caddy is deployed on this machine, it can pick it up.
|
||||
if err = c.writeCaddyfile(caddyfile); err != nil {
|
||||
c.log.Error("Failed to write Caddyfile to disk.", "err", err)
|
||||
return
|
||||
}
|
||||
c.log.Debug("Caddy is not running on this machine, skipping configuration load.", "path", c.caddyfilePath)
|
||||
return
|
||||
}
|
||||
|
||||
// Caddy is available, try to load the config which may fail if the config is invalid. Generally, a config can
|
||||
// pass the adaptation/validation step but still fail to load, for example, if it references resources that are
|
||||
// not available.
|
||||
if err = c.client.Load(ctx, caddyfile); err != nil {
|
||||
c.log.Error("Failed to load new Caddy configuration into local Caddy instance.",
|
||||
"err", err, "path", c.caddyfilePath)
|
||||
// Don't write invalid config to disk.
|
||||
return
|
||||
}
|
||||
|
||||
// Config loaded successfully, now write it to disk.
|
||||
if err = c.writeCaddyfile(caddyfile); err != nil {
|
||||
c.log.Error("Failed to write Caddyfile to disk after successful load.", "err", err)
|
||||
// Config is already loaded in Caddy, so this is not critical.
|
||||
}
|
||||
|
||||
c.log.Info("New Caddy configuration loaded into local Caddy instance.", "path", c.caddyfilePath)
|
||||
}
|
||||
|
||||
// writeCaddyfile writes the Caddyfile content to disk with proper permissions.
|
||||
func (c *Controller) writeCaddyfile(caddyfile string) error {
|
||||
if err := os.WriteFile(c.caddyfilePath, []byte(caddyfile), 0o640); err != nil {
|
||||
return fmt.Errorf("write Caddyfile to file '%s': %w", c.caddyfilePath, err)
|
||||
}
|
||||
if err := fs.Chown(c.caddyfilePath, "", CaddyGroup); err != nil {
|
||||
return fmt.Errorf("change owner of Caddyfile '%s': %w", c.caddyfilePath, err)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (c *Controller) generateJSONConfig(containers []store.ContainerRecord) error {
|
||||
serviceContainers := make([]api.ServiceContainer, len(containers))
|
||||
for i, cr := range containers {
|
||||
serviceContainers[i] = cr.Container
|
||||
}
|
||||
|
||||
config, err := GenerateJSONConfig(serviceContainers, c.machineID)
|
||||
func (c *Controller) generateConfig(containers []api.ServiceContainer) error {
|
||||
config, err := GenerateConfig(containers, c.verifyResponse)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -173,13 +113,12 @@ func (c *Controller) generateJSONConfig(containers []store.ContainerRecord) erro
|
||||
if err != nil {
|
||||
return fmt.Errorf("marshal Caddy configuration: %w", err)
|
||||
}
|
||||
configPath := filepath.Join(filepath.Dir(c.caddyfilePath), "caddy.json")
|
||||
|
||||
if err = os.WriteFile(configPath, configBytes, 0o640); err != nil {
|
||||
return fmt.Errorf("write Caddy configuration to file '%s': %w", configPath, err)
|
||||
if err = os.WriteFile(c.path, configBytes, 0640); err != nil {
|
||||
return fmt.Errorf("write Caddy configuration to file '%s': %w", c.path, err)
|
||||
}
|
||||
if err = fs.Chown(configPath, "", CaddyGroup); err != nil {
|
||||
return fmt.Errorf("change owner of Caddy configuration file '%s': %w", configPath, err)
|
||||
if err = fs.Chown(c.path, "", CaddyGroup); err != nil {
|
||||
return fmt.Errorf("change owner of Caddy configuration file '%s': %w", c.path, err)
|
||||
}
|
||||
|
||||
return nil
|
||||
|
||||
@@ -1,95 +0,0 @@
|
||||
// Code generated by mockery; DO NOT EDIT.
|
||||
// github.com/vektra/mockery
|
||||
// template: testify
|
||||
|
||||
package caddyconfig
|
||||
|
||||
import (
|
||||
"context"
|
||||
|
||||
mock "github.com/stretchr/testify/mock"
|
||||
)
|
||||
|
||||
// NewMockCaddyfileValidator creates a new instance of MockCaddyfileValidator. It also registers a testing interface on the mock and a cleanup function to assert the mocks expectations.
|
||||
// The first argument is typically a *testing.T value.
|
||||
func NewMockCaddyfileValidator(t interface {
|
||||
mock.TestingT
|
||||
Cleanup(func())
|
||||
}) *MockCaddyfileValidator {
|
||||
mock := &MockCaddyfileValidator{}
|
||||
mock.Mock.Test(t)
|
||||
|
||||
t.Cleanup(func() { mock.AssertExpectations(t) })
|
||||
|
||||
return mock
|
||||
}
|
||||
|
||||
// MockCaddyfileValidator is an autogenerated mock type for the CaddyfileValidator type
|
||||
type MockCaddyfileValidator struct {
|
||||
mock.Mock
|
||||
}
|
||||
|
||||
type MockCaddyfileValidator_Expecter struct {
|
||||
mock *mock.Mock
|
||||
}
|
||||
|
||||
func (_m *MockCaddyfileValidator) EXPECT() *MockCaddyfileValidator_Expecter {
|
||||
return &MockCaddyfileValidator_Expecter{mock: &_m.Mock}
|
||||
}
|
||||
|
||||
// Validate provides a mock function for the type MockCaddyfileValidator
|
||||
func (_mock *MockCaddyfileValidator) Validate(ctx context.Context, caddyfile string) error {
|
||||
ret := _mock.Called(ctx, caddyfile)
|
||||
|
||||
if len(ret) == 0 {
|
||||
panic("no return value specified for Validate")
|
||||
}
|
||||
|
||||
var r0 error
|
||||
if returnFunc, ok := ret.Get(0).(func(context.Context, string) error); ok {
|
||||
r0 = returnFunc(ctx, caddyfile)
|
||||
} else {
|
||||
r0 = ret.Error(0)
|
||||
}
|
||||
return r0
|
||||
}
|
||||
|
||||
// MockCaddyfileValidator_Validate_Call is a *mock.Call that shadows Run/Return methods with type explicit version for method 'Validate'
|
||||
type MockCaddyfileValidator_Validate_Call struct {
|
||||
*mock.Call
|
||||
}
|
||||
|
||||
// Validate is a helper method to define mock.On call
|
||||
// - ctx context.Context
|
||||
// - caddyfile string
|
||||
func (_e *MockCaddyfileValidator_Expecter) Validate(ctx interface{}, caddyfile interface{}) *MockCaddyfileValidator_Validate_Call {
|
||||
return &MockCaddyfileValidator_Validate_Call{Call: _e.mock.On("Validate", ctx, caddyfile)}
|
||||
}
|
||||
|
||||
func (_c *MockCaddyfileValidator_Validate_Call) Run(run func(ctx context.Context, caddyfile string)) *MockCaddyfileValidator_Validate_Call {
|
||||
_c.Call.Run(func(args mock.Arguments) {
|
||||
var arg0 context.Context
|
||||
if args[0] != nil {
|
||||
arg0 = args[0].(context.Context)
|
||||
}
|
||||
var arg1 string
|
||||
if args[1] != nil {
|
||||
arg1 = args[1].(string)
|
||||
}
|
||||
run(
|
||||
arg0,
|
||||
arg1,
|
||||
)
|
||||
})
|
||||
return _c
|
||||
}
|
||||
|
||||
func (_c *MockCaddyfileValidator_Validate_Call) Return(err error) *MockCaddyfileValidator_Validate_Call {
|
||||
_c.Call.Return(err)
|
||||
return _c
|
||||
}
|
||||
|
||||
func (_c *MockCaddyfileValidator_Validate_Call) RunAndReturn(run func(ctx context.Context, caddyfile string) error) *MockCaddyfileValidator_Validate_Call {
|
||||
_c.Call.Return(run)
|
||||
return _c
|
||||
}
|
||||
@@ -1,39 +0,0 @@
|
||||
package caddyconfig
|
||||
|
||||
import (
|
||||
"context"
|
||||
"os"
|
||||
|
||||
"google.golang.org/grpc/codes"
|
||||
"google.golang.org/grpc/status"
|
||||
"google.golang.org/protobuf/types/known/emptypb"
|
||||
"google.golang.org/protobuf/types/known/timestamppb"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
)
|
||||
|
||||
// Server implements the gRPC Caddy service.
|
||||
type Server struct {
|
||||
pb.UnimplementedCaddyServer
|
||||
service *Service
|
||||
}
|
||||
|
||||
func NewServer(service *Service) *Server {
|
||||
return &Server{service: service}
|
||||
}
|
||||
|
||||
// GetConfig retrieves the current Caddy configuration from the machine.
|
||||
func (s *Server) GetConfig(ctx context.Context, _ *emptypb.Empty) (*pb.GetCaddyConfigResponse, error) {
|
||||
caddyfile, modifiedAt, err := s.service.Caddyfile()
|
||||
if err != nil {
|
||||
if os.IsNotExist(err) {
|
||||
return nil, status.Errorf(codes.NotFound, err.Error())
|
||||
}
|
||||
return nil, status.Errorf(codes.Internal, err.Error())
|
||||
}
|
||||
|
||||
return &pb.GetCaddyConfigResponse{
|
||||
Caddyfile: caddyfile,
|
||||
ModifiedAt: timestamppb.New(modifiedAt),
|
||||
}, nil
|
||||
}
|
||||
@@ -1,35 +0,0 @@
|
||||
package caddyconfig
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"time"
|
||||
)
|
||||
|
||||
// Service provides methods to interact with the Caddy configuration on the machine.
|
||||
type Service struct {
|
||||
configDir string
|
||||
}
|
||||
|
||||
// NewService creates a new Service instance with the specified Caddy configuration directory.
|
||||
func NewService(configDir string) *Service {
|
||||
return &Service{configDir: configDir}
|
||||
}
|
||||
|
||||
// Caddyfile retrieves the current Caddy configuration (Caddyfile) from the machine's config directory.
|
||||
func (s *Service) Caddyfile() (string, time.Time, error) {
|
||||
path := filepath.Join(s.configDir, "Caddyfile")
|
||||
content, err := os.ReadFile(path)
|
||||
if err != nil {
|
||||
return "", time.Time{}, fmt.Errorf("read Caddyfile from file '%s': %w", path, err)
|
||||
}
|
||||
|
||||
// Get the file modification time.
|
||||
fileInfo, err := os.Stat(path)
|
||||
if err != nil {
|
||||
return "", time.Time{}, fmt.Errorf("get Caddyfile file info '%s': %w", path, err)
|
||||
}
|
||||
|
||||
return string(content), fileInfo.ModTime(), nil
|
||||
}
|
||||
@@ -1,77 +0,0 @@
|
||||
package caddyconfig
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net"
|
||||
"strconv"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// templateContext holds the data available to Caddyfile templates.
|
||||
type templateContext struct {
|
||||
// Name is the current service name.
|
||||
Name string
|
||||
// Upstreams maps service names to their container IPs.
|
||||
Upstreams map[string][]string
|
||||
}
|
||||
|
||||
// upstreamsTemplateFn returns a template function that generates a space separated string of upstreams for the service.
|
||||
// It optionally accepts a service name and a port number: {{upstreams [service-name] [port]}}.
|
||||
func upstreamsTemplateFn(tmplCtx templateContext) func(args ...any) (string, error) {
|
||||
return func(args ...any) (string, error) {
|
||||
var serviceName string
|
||||
var port int
|
||||
|
||||
// Parse arguments.
|
||||
switch len(args) {
|
||||
case 0:
|
||||
// Current service, default port.
|
||||
serviceName = tmplCtx.Name
|
||||
case 1:
|
||||
// Either port (int) for current service or service name (string).
|
||||
switch arg := args[0].(type) {
|
||||
case int:
|
||||
serviceName = tmplCtx.Name
|
||||
port = arg
|
||||
case string:
|
||||
serviceName = arg
|
||||
port = 0
|
||||
default:
|
||||
return "", fmt.Errorf("upstreams function: invalid argument type: %T", arg)
|
||||
}
|
||||
case 2:
|
||||
// Service name and port.
|
||||
name, ok := args[0].(string)
|
||||
if !ok {
|
||||
return "", fmt.Errorf("upstreams function: first argument must be service name (string)")
|
||||
}
|
||||
serviceName = name
|
||||
|
||||
p, ok := args[1].(int)
|
||||
if !ok {
|
||||
return "", fmt.Errorf("upstreams function: second argument must be port (int)")
|
||||
}
|
||||
port = p
|
||||
default:
|
||||
return "", fmt.Errorf("upstreams function: too many arguments; expected 0-2, got %d", len(args))
|
||||
}
|
||||
|
||||
ips, ok := tmplCtx.Upstreams[serviceName]
|
||||
if !ok || len(ips) == 0 {
|
||||
// No upstreams available.
|
||||
return "", nil
|
||||
}
|
||||
|
||||
// Build the space separated upstreams string.
|
||||
var upstreams []string
|
||||
for _, ip := range ips {
|
||||
if port > 0 {
|
||||
upstreams = append(upstreams, net.JoinHostPort(ip, strconv.Itoa(port)))
|
||||
} else {
|
||||
upstreams = append(upstreams, ip)
|
||||
}
|
||||
}
|
||||
|
||||
return strings.Join(upstreams, " "), nil
|
||||
}
|
||||
}
|
||||
@@ -5,18 +5,17 @@ import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"google.golang.org/grpc/codes"
|
||||
"google.golang.org/grpc/status"
|
||||
"google.golang.org/protobuf/types/known/emptypb"
|
||||
"log/slog"
|
||||
"net/netip"
|
||||
"time"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/corrosion"
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
"github.com/psviderski/uncloud/internal/machine/network"
|
||||
"github.com/psviderski/uncloud/internal/machine/store"
|
||||
"github.com/psviderski/uncloud/internal/secret"
|
||||
"google.golang.org/grpc/codes"
|
||||
"google.golang.org/grpc/status"
|
||||
"google.golang.org/protobuf/types/known/emptypb"
|
||||
)
|
||||
|
||||
type Cluster struct {
|
||||
@@ -198,89 +197,6 @@ func (c *Cluster) AddMachine(ctx context.Context, req *pb.AddMachineRequest) (*p
|
||||
return resp, nil
|
||||
}
|
||||
|
||||
// UpdateMachine updates machine configuration in the cluster.
|
||||
func (c *Cluster) UpdateMachine(ctx context.Context, req *pb.UpdateMachineRequest) (*pb.UpdateMachineResponse, error) {
|
||||
if err := c.checkInitialised(ctx); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if req.MachineId == "" {
|
||||
return nil, status.Error(codes.InvalidArgument, "machine_id not set")
|
||||
}
|
||||
|
||||
// Get the current machine info
|
||||
currentMachine, err := c.store.GetMachine(ctx, req.MachineId)
|
||||
if err != nil {
|
||||
if errors.Is(err, store.ErrMachineNotFound) {
|
||||
return nil, status.Errorf(codes.NotFound, "machine not found: %s", req.MachineId)
|
||||
}
|
||||
return nil, status.Errorf(codes.Internal, "failed to get machine: %v", err)
|
||||
}
|
||||
|
||||
// Create a copy of the current machine for updating
|
||||
updatedMachine := &pb.MachineInfo{
|
||||
Id: currentMachine.Id,
|
||||
Name: currentMachine.Name,
|
||||
Network: currentMachine.Network,
|
||||
PublicIp: currentMachine.PublicIp,
|
||||
}
|
||||
|
||||
// Apply updates from the request
|
||||
if req.Name != nil {
|
||||
// Check for empty name
|
||||
if *req.Name == "" {
|
||||
return nil, status.Error(codes.InvalidArgument, "machine name cannot be empty")
|
||||
}
|
||||
// Check for duplicate names (excluding the current machine)
|
||||
if *req.Name != currentMachine.Name {
|
||||
machines, err := c.store.ListMachines(ctx)
|
||||
if err != nil {
|
||||
return nil, status.Errorf(codes.Internal, "list machines: %v", err)
|
||||
}
|
||||
for _, m := range machines {
|
||||
if m.Id != req.MachineId && m.Name == *req.Name {
|
||||
return nil, status.Errorf(codes.AlreadyExists, "machine with name %q already exists", *req.Name)
|
||||
}
|
||||
}
|
||||
}
|
||||
updatedMachine.Name = *req.Name
|
||||
}
|
||||
if req.PublicIp != nil {
|
||||
// Check if this is an empty IP (used to signal removal)
|
||||
if len(req.PublicIp.Ip) == 0 {
|
||||
// User wants to remove public IP
|
||||
updatedMachine.PublicIp = nil
|
||||
} else {
|
||||
// Validate and set the new IP
|
||||
ip, err := req.PublicIp.ToAddr()
|
||||
if err != nil {
|
||||
return nil, status.Errorf(codes.InvalidArgument, "invalid public IP: %v", err)
|
||||
}
|
||||
if !ip.IsValid() {
|
||||
return nil, status.Error(codes.InvalidArgument, "invalid public IP")
|
||||
}
|
||||
updatedMachine.PublicIp = req.PublicIp
|
||||
}
|
||||
}
|
||||
if req.Endpoints != nil {
|
||||
updatedMachine.Network.Endpoints = req.Endpoints
|
||||
}
|
||||
|
||||
// Update the machine in the store
|
||||
if err = c.store.UpdateMachine(ctx, updatedMachine); err != nil {
|
||||
if errors.Is(err, store.ErrMachineNotFound) {
|
||||
return nil, status.Errorf(codes.NotFound, "machine not found: %s", req.MachineId)
|
||||
}
|
||||
return nil, status.Errorf(codes.Internal, "update machine: %v", err)
|
||||
}
|
||||
|
||||
slog.Info("Machine configuration updated in the cluster.",
|
||||
"id", updatedMachine.Id, "name", updatedMachine.Name)
|
||||
|
||||
resp := &pb.UpdateMachineResponse{Machine: updatedMachine}
|
||||
return resp, nil
|
||||
}
|
||||
|
||||
// ListMachines lists all machines in the cluster including their membership states.
|
||||
func (c *Cluster) ListMachines(ctx context.Context, _ *emptypb.Empty) (*pb.ListMachinesResponse, error) {
|
||||
if err := c.checkInitialised(ctx); err != nil {
|
||||
@@ -326,24 +242,3 @@ func (c *Cluster) ListMachines(ctx context.Context, _ *emptypb.Empty) (*pb.ListM
|
||||
|
||||
return &pb.ListMachinesResponse{Machines: members}, nil
|
||||
}
|
||||
|
||||
// RemoveMachine removes a machine from the cluster.
|
||||
func (c *Cluster) RemoveMachine(ctx context.Context, req *pb.RemoveMachineRequest) (*emptypb.Empty, error) {
|
||||
if err := c.checkInitialised(ctx); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
if req.Id == "" {
|
||||
return nil, status.Error(codes.InvalidArgument, "machine ID not set")
|
||||
}
|
||||
|
||||
if err := c.store.DeleteMachine(ctx, req.Id); err != nil {
|
||||
if errors.Is(err, store.ErrMachineNotFound) {
|
||||
return nil, status.Errorf(codes.NotFound, "machine not found: %s", req.Id)
|
||||
}
|
||||
return nil, status.Errorf(codes.Internal, "delete machine from store: %v", err)
|
||||
}
|
||||
slog.Info("Machine removed from the cluster.", "id", req.Id)
|
||||
|
||||
return &emptypb.Empty{}, nil
|
||||
}
|
||||
|
||||
@@ -4,7 +4,6 @@ import (
|
||||
"context"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/dns"
|
||||
"github.com/psviderski/uncloud/internal/machine/api/pb"
|
||||
"github.com/psviderski/uncloud/internal/machine/store"
|
||||
|
||||
@@ -3,9 +3,8 @@ package cluster
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
"net/netip"
|
||||
|
||||
"go4.org/netipx"
|
||||
"net/netip"
|
||||
)
|
||||
|
||||
const DefaultSubnetBits = 24
|
||||
|
||||
@@ -2,7 +2,6 @@ package cluster
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
|
||||
"github.com/psviderski/uncloud/internal/secret"
|
||||
)
|
||||
|
||||
|
||||
@@ -1,6 +0,0 @@
|
||||
package constants
|
||||
|
||||
const (
|
||||
// MachineAPIPort is the port for the Machine API service on the management WireGuard network.
|
||||
MachineAPIPort = 51000
|
||||
)
|
||||
@@ -3,11 +3,10 @@ package corroservice
|
||||
import (
|
||||
"bytes"
|
||||
"fmt"
|
||||
"github.com/BurntSushi/toml"
|
||||
"net/netip"
|
||||
"os"
|
||||
"path/filepath"
|
||||
|
||||
"github.com/BurntSushi/toml"
|
||||
"github.com/psviderski/uncloud/internal/fs"
|
||||
)
|
||||
|
||||
@@ -51,7 +50,7 @@ func (c *Config) Write(path, owner string) error {
|
||||
if err := encoder.Encode(c); err != nil {
|
||||
return fmt.Errorf("encode config: %w", err)
|
||||
}
|
||||
if err := os.WriteFile(path, data.Bytes(), 0o600); err != nil {
|
||||
if err := os.WriteFile(path, data.Bytes(), 0600); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := fs.Chown(path, owner, owner); err != nil {
|
||||
@@ -63,10 +62,10 @@ func (c *Config) Write(path, owner string) error {
|
||||
func MkDataDir(dir, owner string) error {
|
||||
parent, _ := filepath.Split(dir)
|
||||
// Use 0711 for parent directories to allow `owner` to access its nested data directory.
|
||||
if err := os.MkdirAll(parent, 0o711); err != nil {
|
||||
if err := os.MkdirAll(parent, 0711); err != nil {
|
||||
return fmt.Errorf("create directory %q: %w", parent, err)
|
||||
}
|
||||
if err := os.Mkdir(dir, 0o700); err != nil {
|
||||
if err := os.Mkdir(dir, 0700); err != nil {
|
||||
if !os.IsExist(err) {
|
||||
return fmt.Errorf("create directory %q: %w", dir, err)
|
||||
}
|
||||
|
||||