Documentation
¶
Overview ¶
Package distrocfg defines the standard interface that all distro config settings
Index ¶
- Constants
- Variables
- func NodeLabelsMapToList(m map[string]string) []string
- func RemoveStaleFiles(h *cluster.ZarfHost, dirs []string, desired map[string]DesiredFile) error
- func StaleFiles(h *cluster.ZarfHost, dirs []string, desired map[string]DesiredFile) []string
- type AdminCredentials
- type Common
- func (r *Common) BinaryName() string
- func (r *Common) BinaryPath() string
- func (r *Common) ConfigPath() string
- func (r *Common) DataDirPath() string
- func (r *Common) GetControllerService() string
- func (r *Common) GetWorkerService() string
- func (r *Common) JoinTokenPath() string
- func (r *Common) SetPath(key string, value string) error
- type DesiredFile
- type Distro
- type K3S
- func (d *K3S) AdminCredentials(host cluster.ZarfHost, dataDir string) (AdminCredentials, error)
- func (d *K3S) KubeconfigPath(_ cluster.ZarfHost, _ string) string
- func (d *K3S) KubectlCmdf(host cluster.ZarfHost, dataDir string, s string, args ...any) string
- func (d *K3S) StopControllerService(h *cluster.ZarfHost) error
- func (d *K3S) StopWorkerService(h *cluster.ZarfHost) error
- type RKE2
- func (d *RKE2) AdminCredentials(host cluster.ZarfHost, dataDir string) (AdminCredentials, error)
- func (d *RKE2) KubeconfigPath(_ cluster.ZarfHost, _ string) string
- func (d *RKE2) KubectlCmdf(host cluster.ZarfHost, dataDir string, s string, args ...any) string
- func (d *RKE2) StopControllerService(h *cluster.ZarfHost) error
- func (d *RKE2) StopWorkerService(h *cluster.ZarfHost) error
- type RancherCommon
- func (d *RancherCommon) CleanupPaths() []string
- func (d *RancherCommon) ConfigureEngine(ctx context.Context, host cluster.ZarfHost, run cluster.ZarfRuntimeMeta, ...) error
- func (d *RancherCommon) DesiredFiles(_ cluster.ZarfHost, run cluster.ZarfRuntimeMeta, dis distro.ZarfDistro) (map[string]DesiredFile, error)
- func (d *RancherCommon) DistroCmdf(template string, args ...any) string
- func (d *RancherCommon) GetClusterCIDR(dis distro.ZarfDistro) []string
- func (d *RancherCommon) JoinTokenPathAgent() string
- func (d *RancherCommon) ManagedDirs() []string
- func (d *RancherCommon) RunningVersion(host cluster.ZarfHost) (string, error)
Constants ¶
const ( // Binary id string Binary = "Binary" // BinaryDir id string BinaryDir = "BinDir" // Config id string Config = "Config" // Token id string Token = "Token" // Data id string Data = "DataDir" // WorkerService id string WorkerService = "Worker" // ControllerService id string ControllerService = "Control" )
const (
// DistroK3S id
DistroK3S = "k3s"
)
const (
// DistroRKE2 id
DistroRKE2 = "rke2"
)
const DistroReleaseFile = "/etc/cargoship/distro-release.json"
DistroReleaseFile is the metadata file tracking the installed distro package on the host.
const StateDir = "/etc/cargoship"
StateDir is where cargoship records state files describing the applied distro package.
Variables ¶
var ( // ErrVersionNotDetected if a version is not detected ErrVersionNotDetected = errors.New("failed to get version from the distro binary") // ErrPathKey if a path key is not used ErrPathKey = errors.New("key for set path does not exist") )
var ErrNoAdminCredentials = errors.New("admin kubeconfig has no admin credentials")
ErrNoAdminCredentials if the admin kubeconfig on the host does not carry a usable CA certificate and admin client key pair
Functions ¶
func NodeLabelsMapToList ¶
NodeLabelsMapToList takes a map and returns a string array for used by Kubernetes labels
func RemoveStaleFiles ¶ added in v0.20.1
RemoveStaleFiles deletes the files StaleFiles finds. It reports the first deletion error, so a file that cannot be removed is surfaced rather than left to be rediscovered on every run.
func StaleFiles ¶ added in v0.20.1
StaleFiles returns the files under dirs that desired no longer names, sorted by path.
A managed directory holds only files cargoship put there, so a file in one that is not in the desired set was written for something the cluster configuration has since dropped -- a registry that no longer has an inline CA, say. Such a file is harmless while it sits there, since nothing references it, but it also never goes away on its own, and a certificate left behind on every node long after the registry is gone is the kind of thing that turns up in an audit rather than in a log.
A directory that does not exist, or that cannot be listed, contributes nothing: pruning is cleanup, and there is no point failing an apply over it.
Types ¶
type AdminCredentials ¶ added in v0.20.0
type AdminCredentials struct {
// CertificateAuthority is the CA certificate the API server's serving cert is signed with
CertificateAuthority []byte
// ClientCertificate is the admin client certificate
ClientCertificate []byte
// ClientKey is the key for ClientCertificate
ClientKey []byte
}
AdminCredentials is the CA certificate and admin client key pair an engine writes on a controller host, in PEM form.
type Common ¶
type Common struct {
//keep-sorted start
// Binary name of the engine binary
Binary string
// BinaryDir where the engine binary is stored in
BinaryDir string
// Config where the engine config is located
Config string
// Data where the engine data is located
Data string
// ID the id used to identify the distro
ID string
// ServiceController the controller service
ServiceController string
// ServiceWorker the worker service
ServiceWorker string
// Token the token path
Token string
}
Common for all the distro's
func (*Common) BinaryName ¶
BinaryName returns the engine binary name
func (*Common) BinaryPath ¶
BinaryPath returns the full path to the engine binary
func (*Common) ConfigPath ¶
ConfigPath returns the full path for the config directory used by the engine
func (*Common) DataDirPath ¶
DataDirPath returns the full path for the data directory used by the engine
func (*Common) GetControllerService ¶
GetControllerService returns the name of the controller service
func (*Common) GetWorkerService ¶
GetWorkerService returns the name of the worker service
func (*Common) JoinTokenPath ¶
JoinTokenPath returns the path of the token to join the cluster
type DesiredFile ¶ added in v0.20.1
type DesiredFile struct {
// Content is the full desired content of the file.
Content []byte
// Mode is the file mode as chmod spells it, e.g. "0600".
Mode string
// NoRestart indicates changes to this file do not require draining or restarting the engine.
NoRestart bool
}
DesiredFile is one engine config file a distro wants on a host: its content, and the mode it is written with. The mode travels with the content because it varies per file -- a file the engine reads as a group member is not written like one holding credentials.
func DistroReleaseDesiredFile ¶ added in v0.23.0
func DistroReleaseDesiredFile(dis distro.ZarfDistro, managedFiles map[string]DesiredFile) (string, DesiredFile, bool, error)
DistroReleaseDesiredFile generates the DesiredFile for the installed distro package metadata and managed files tracking.
type Distro ¶
type Distro interface {
// AdminCredentials returns the cluster CA certificate and the admin client key pair
// for a given controller host and data directory
AdminCredentials(cluster.ZarfHost, string) (AdminCredentials, error)
// BinaryName returns the engine binary name
BinaryName() string
// BinaryPath returns the full path to the engine binary
BinaryPath() string
// CleanupPaths returns every path on a host the engine owns outright, for an uninstall
// to remove recursively. Paths that are unset or too broad to safely remove are left out.
CleanupPaths() []string
// ConfigPath returns the full path for the config directory used by the engine
ConfigPath() string
// ConfigureEngine does distro specific configuration on a host
ConfigureEngine(context.Context, cluster.ZarfHost, cluster.ZarfRuntimeMeta, distro.ZarfDistro) error
// DataDirPath returns the full path for the data directory used by the engine
DataDirPath() string
// DesiredFiles returns the full set of engine config files (path -> desired file) this
// distro would write for the given host/run/dis state -- e.g. registries.yaml, audit.yaml,
// pss.yaml -- used both to pre-seed a fresh host and, by the engine-config-sync phases, to
// detect drift on an already-running host.
DesiredFiles(cluster.ZarfHost, cluster.ZarfRuntimeMeta, distro.ZarfDistro) (map[string]DesiredFile, error)
// ManagedDirs returns the directories on a host whose contents cargoship writes and owns
// outright, so that a file in one of them that DesiredFiles no longer names can be removed
// rather than left behind. A distro that keeps no such directory returns nil.
ManagedDirs() []string
// DistroCmdf returns a string that can be used to execute commands on the core engine binary
DistroCmdf(string, ...any) string
// GetClusterCIDR returns a string array with the all the known cluster cidr blocks
GetClusterCIDR(distro.ZarfDistro) []string
// GetControllerService returns the name of the controller service
GetControllerService() string
// GetWorkerService returns the name of the worker service
GetWorkerService() string
// JoinTokenPath returns the path of the token to join the cluster
JoinTokenPath() string
// JoinTokenPathAgent returns the path of the token to join the cluster.
// Distro's like RKE2 and K3S allow for agent tokens, so this allows for some level of access control if a node is allowed to be a controller or an agent.
JoinTokenPathAgent() string
// KubeconfigPath returns the path to the admin config for a given
KubeconfigPath(cluster.ZarfHost, string) string
// KubectlCmdf returns a string with that can be executed to interact with the kubernetes cluster
KubectlCmdf(cluster.ZarfHost, string, string, ...any) string
// RunningVersion returns the version of the distro being ran, if the engine is not running it throws an "ErrVersionNotDetected" error
RunningVersion(cluster.ZarfHost) (string, error)
// SetPath takes in a key value pair to change how the distro values are configured, if a key is not valid it will throw an "ErrPathKey" error
SetPath(key string, value string) error
// StopControllerService stops the controller service on the host
StopControllerService(*cluster.ZarfHost) error
// StopWorkerService stops the controller service on the host
StopWorkerService(*cluster.ZarfHost) error
}
Distro interface for any distro object
type K3S ¶
type K3S struct {
RancherCommon
}
K3S distro struct
func (*K3S) AdminCredentials ¶ added in v0.20.0
AdminCredentials returns the cluster CA certificate and the admin client key pair, read out of the admin kubeconfig k3s writes on a controller host.
func (*K3S) KubeconfigPath ¶
KubeconfigPath returns the path to the admin config for a given
func (*K3S) KubectlCmdf ¶
KubectlCmdf returns a string with that can be executed to interact with the kubernetes cluster
func (*K3S) StopControllerService ¶
StopControllerService stops the controller service on the host
type RKE2 ¶
type RKE2 struct {
RancherCommon
}
RKE2 distro struct
func (*RKE2) AdminCredentials ¶ added in v0.20.0
AdminCredentials returns the cluster CA certificate and the admin client key pair, read out of the admin kubeconfig rke2 writes on a controller host.
func (*RKE2) KubeconfigPath ¶
KubeconfigPath returns the path to the admin config for a given distro
func (*RKE2) KubectlCmdf ¶
KubectlCmdf returns a string with that can be executed to interact with the kubernetes cluster
func (*RKE2) StopControllerService ¶
StopControllerService implements Distro.
type RancherCommon ¶
type RancherCommon struct {
Common
}
RancherCommon is a parent object for both RKE2 and k3s distros
func (*RancherCommon) CleanupPaths ¶ added in v0.20.0
func (d *RancherCommon) CleanupPaths() []string
CleanupPaths returns the paths an uninstall removes from a host: the engine data directory and the config directory, both of which rke2 and k3s own outright.
func (*RancherCommon) ConfigureEngine ¶
func (d *RancherCommon) ConfigureEngine(ctx context.Context, host cluster.ZarfHost, run cluster.ZarfRuntimeMeta, dis distro.ZarfDistro) error
ConfigureEngine does distro specific configuration on a host
func (*RancherCommon) DesiredFiles ¶ added in v0.15.0
func (d *RancherCommon) DesiredFiles(_ cluster.ZarfHost, run cluster.ZarfRuntimeMeta, dis distro.ZarfDistro) (map[string]DesiredFile, error)
DesiredFiles returns the desired content of registries.yaml, audit.yaml, and pss.yaml for the given host/run/dis, keyed by their full destination path. Content is identical across hosts of the same run (no host-varying fields are involved), unlike config.yaml.
func (*RancherCommon) DistroCmdf ¶
func (d *RancherCommon) DistroCmdf(template string, args ...any) string
DistroCmdf returns a string that can be used to execute commands on the core engine binary
func (*RancherCommon) GetClusterCIDR ¶
func (d *RancherCommon) GetClusterCIDR(dis distro.ZarfDistro) []string
GetClusterCIDR returns a string array with the all the known cluster cidr blocks
func (*RancherCommon) JoinTokenPathAgent ¶
func (d *RancherCommon) JoinTokenPathAgent() string
JoinTokenPathAgent returns the path of the token to join the cluster. Distro's like RKE2 and K3S allow for agent tokens, so this allows for some level of access control if a node is allowed to be a controller or an agent.
func (*RancherCommon) ManagedDirs ¶ added in v0.20.1
func (d *RancherCommon) ManagedDirs() []string
ManagedDirs returns the directories on a host whose contents cargoship owns outright. For rke2 and k3s that includes the directory holding CA certificates and state metadata: every file in it was put there by cargoship, so a file with no entry left behind it can go.
func (*RancherCommon) RunningVersion ¶
func (d *RancherCommon) RunningVersion(host cluster.ZarfHost) (string, error)
RunningVersion returns the version of the distro being ran, if the engine is not running it throws an "ErrVersionNotDetected" error