Documentation
¶
Overview ¶
Package clustercfg is used to parse an byte array and returns a ZarfCluster
Index ¶
- Constants
- func DecryptRegistryAuth(dis *cluster.ZarfCluster, password string) error
- func EncryptValue(value, password string) (string, error)
- func Parse(_ context.Context, b []byte) (cluster.ZarfCluster, error)
- func ResolveVaultPassword(passwordFile string) (string, error)
- func VerifyRegistryAuth(dis *cluster.ZarfCluster, password string) error
Constants ¶
const AnsibleVaultPasswordEnvVar = "ANSIBLE_VAULT_PASSWORD"
AnsibleVaultPasswordEnvVar is a secondary environment variable checked for the Ansible Vault password, used by ansible-vault itself. VaultPasswordEnvVar takes precedence when both are set.
const VaultPasswordEnvVar = "CARGOSHIP_VAULT_PASSWORD"
VaultPasswordEnvVar is the environment variable checked for the Ansible Vault password when no --vault-password-file flag is given.
Variables ¶
This section is empty.
Functions ¶
func DecryptRegistryAuth ¶ added in v0.15.0
func DecryptRegistryAuth(dis *cluster.ZarfCluster, password string) error
DecryptRegistryAuth decrypts any Ansible Vault-encrypted Username, Password, or Token fields on dis.Spec.Config.Registries in place, along with an inline TLS CA certificate given the same way. Fields that don't carry the $ANSIBLE_VAULT header are left untouched.
A CA certificate is public and does not need encrypting, but accepting one encrypted means a document can be vaulted as a whole without cargoship rejecting the parts that did not have to be. The decrypted TLS settings are validated here, since load time saw only ciphertext.
func EncryptValue ¶ added in v0.15.0
EncryptValue encrypts value with the given Ansible Vault password, producing a string suitable for use as a registry auth field (see DecryptRegistryAuth).
func ResolveVaultPassword ¶ added in v0.15.0
ResolveVaultPassword returns the Ansible Vault password to use for decrypting registry credentials. If passwordFile is set, its contents are read and used. Otherwise it falls back to the CARGOSHIP_VAULT_PASSWORD environment variable, then to ANSIBLE_VAULT_PASSWORD. An empty return value with a nil error means no password was configured.
func VerifyRegistryAuth ¶ added in v0.20.1
func VerifyRegistryAuth(dis *cluster.ZarfCluster, password string) error
VerifyRegistryAuth reports whether every Ansible Vault-encrypted registry value in dis can be decrypted with password, and whether what comes out is usable, leaving dis unchanged.
The values are only needed once the engine configuration is written, which is several phases into an apply -- long after cargoship has connected to every host, and on a sync, after it has started draining nodes. A password that was never supplied, or one that does not match the document, is worth finding out about before any of that happens rather than partway through it, so a command calls this as soon as it has resolved the password.
Types ¶
This section is empty.