enroll

package
v1.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 10 Imported by: 0

Documentation

Overview

Package enroll owns the enrollment token: its format, how it is made and read back, and the command an operator runs on a new edge. The admin API, the CLI and the gateway all go through it.

A token is "<id>.<secret>": 16 hex digits, a dot, then 32 random bytes in base64url. Only the sha256 of the secret is stored.

Index

Constants

View Source
const (
	DefaultTTL = 24 * time.Hour
	MaxTTL     = 7 * 24 * time.Hour
)

Variables

View Source
var ErrMalformed = errors.New("malformed token")

ErrMalformed is returned by Parse for anything that is not a token.

Functions

func Command

func Command(publicURL, caFingerprint, token string) string

Command is what to run on the edge to enroll it. The token goes through stdin (printf is a shell builtin): it never shows in the process list.

func New

func New(name string, labels map[string]string, ttl time.Duration, replace bool, now time.Time) (string, store.Token, error)

New returns the token to hand out and the record to store. A ttl of zero means DefaultTTL.

func Parse

func Parse(token string) (id string, secretHash []byte, err error)

Parse splits a token into its id and the hash of its secret, as stored.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL