Documentation
¶
Index ¶
- Constants
- Variables
- func AddOperatorToWeaverGroupStep() *automa.StepBuilder
- func AutoRemoveOrphanedPackages() *automa.StepBuilder
- func CheckClusterCRDs(id string, crds []string, timeout time.Duration, ...) *automa.StepBuilder
- func CheckClusterConfigMaps(id string, configMaps []string, timeout time.Duration, ...) *automa.StepBuilder
- func CheckClusterHealth() *automa.WorkflowBuilder
- func CheckClusterNamespaces(id string, namespaces []string, timeout time.Duration, ...) *automa.StepBuilder
- func CheckClusterNodesReady(id string, provider kube.ClientProviderFromContext) *automa.StepBuilder
- func CheckClusterPodsReady(id string, podNames []string, timeout time.Duration, ...) *automa.StepBuilder
- func CheckClusterServices(id string, services []string, timeout time.Duration, ...) *automa.StepBuilder
- func CheckClusterStep() *automa.StepBuilder
- func CheckDaemonComponentPrerequisites(sockPath string) string
- func CheckDaemonComponentPrerequisitesStep(sockPath string) *automa.StepBuilder
- func CheckDaemonServiceStep(paths models.WeaverPaths, sockPath string) *automa.StepBuilder
- func CheckNoProvisionedCluster() *automa.StepBuilder
- func CheckWeaverInstallation(binDir string) *automa.StepBuilder
- func CleanupWeaverFiles() *automa.StepBuilder
- func ConfigureSysctlForKubernetes() *automa.WorkflowBuilder
- func CreateDaemonRBACStep(specs []DaemonComponentSpec) *automa.StepBuilder
- func CreateTeleportNamespace() automa.Builder
- func DeleteBlockNodePersistentVolumes(inputs models.BlockNodeInputs) automa.Builder
- func DeleteDaemonRBACStep(specs []DaemonComponentSpec) *automa.StepBuilder
- func DeployMetricsServer(valueOptions *values.Options) *automa.WorkflowBuilder
- func DisableSwap() *automa.StepBuilder
- func EnsureHederaOwnerStep() *automa.StepBuilder
- func EnsureWeaverOwnerStep() *automa.StepBuilder
- func FetchDaemonStatus(sockPath string) *daemon.StatusResponse
- func InitializeCluster() *automa.StepBuilder
- func InstallColocatedDaemonBinary(binDir string) *automa.StepBuilder
- func InstallDaemonBinaryStep(src DaemonBinarySource, paths models.WeaverPaths) *automa.StepBuilder
- func InstallDaemonServiceStep(paths models.WeaverPaths, extraReadWritePaths []string) *automa.StepBuilder
- func InstallKernelModule(name string) *automa.StepBuilder
- func InstallSoloOperator() automa.Builder
- func InstallSudoersStep() *automa.StepBuilder
- func InstallSystemPackage(name string, installer func() (software.Package, error)) *automa.StepBuilder
- func InstallTeleportKubeAgent() automa.Builder
- func InstallWeaver(binDir string) *automa.StepBuilder
- func IsTeleportPodsReady() automa.Builder
- func NetworkFirewallCreate(reconcile bool) *automa.StepBuilder
- func NetworkFirewallDelete() *automa.StepBuilder
- func NetworkPolicyCreate(force bool, healthPort string) *automa.StepBuilder
- func NetworkPolicyDeleteAll() *automa.StepBuilder
- func NftServiceTeardown() *automa.StepBuilder
- func NftWeaverPersist() *automa.StepBuilder
- func PreflightAlloy() *automa.WorkflowBuilder
- func PurgeBlockNodeStorage(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func RecordProvisionerVersion() *automa.StepBuilder
- func RecreateBlockNodeStorage(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func RefreshSystemPackageIndex() *automa.StepBuilder
- func RemoveConfigDirectories() *automa.StepBuilder
- func RemoveDaemonBinaryStep(paths models.WeaverPaths) *automa.StepBuilder
- func RemoveDaemonConfigStep(paths models.WeaverPaths) *automa.StepBuilder
- func RemoveDaemonKubeconfigStep(specs []DaemonComponentSpec) *automa.StepBuilder
- func RemoveDaemonServiceStep(paths models.WeaverPaths) *automa.StepBuilder
- func RemoveNetworkConfig() *automa.StepBuilder
- func RemoveSudoersStep() *automa.StepBuilder
- func RemoveSystemPackage(name string, installer func() (software.Package, error)) *automa.StepBuilder
- func RemoveSystemdServiceFiles() *automa.StepBuilder
- func ResetBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func ResetCluster() *automa.StepBuilder
- func RestartDaemonServiceStep() *automa.StepBuilder
- func RolloutRestartBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func SetupAlloy() *automa.WorkflowBuilder
- func SetupAlloyStack() *automa.WorkflowBuilder
- func SetupBindMounts() *automa.WorkflowBuilder
- func SetupBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func SetupCilium(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupCrio(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupESOSecret(opts ESOSecretOptions) *automa.WorkflowBuilder
- func SetupExternalSecrets(namespace string) *automa.WorkflowBuilder
- func SetupHelm(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupHomeDirectoryStructure(pp models.WeaverPaths) *automa.StepBuilder
- func SetupK9s(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupKubeadm(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupKubectl(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupKubelet(mr software.MachineRuntime) *automa.WorkflowBuilder
- func SetupMetalLB() *automa.WorkflowBuilder
- func SetupPrometheusOperatorCRDs() *automa.WorkflowBuilder
- func SetupSystemdService(serviceName string) *automa.StepBuilder
- func SetupTeleportClusterAgent() *automa.WorkflowBuilder
- func SetupTeleportNodeAgent(mr software.MachineRuntime) *automa.WorkflowBuilder
- func Sleep(ctx context.Context, d time.Duration) error
- func SoakStart(sockPath string, req consensus.SoakStartRequest) (*consensus.SoakStartResponse, error)
- func SoakStartStep(sockPath string, req consensus.SoakStartRequest) *automa.StepBuilder
- func SoakStatus(sockPath string) *consensus.SoakStatusResponse
- func SoakStop(sockPath string, keepState bool) error
- func SoakStopStep(sockPath string, keepState bool) *automa.StepBuilder
- func StartCilium() *automa.WorkflowBuilder
- func StartDaemonServiceStep() *automa.StepBuilder
- func StopDaemonServiceStep() *automa.StepBuilder
- func TcEgressPersist(nicName string, trunkRate string, overrides map[string]shape.ClassOverride) *automa.StepBuilder
- func TcEgressServiceTeardown() *automa.StepBuilder
- func TcEgressTeardown() *automa.StepBuilder
- func TcIngressRecord(nicName string, linkRate string, overrides map[string]shape.ClassOverride) *automa.StepBuilder
- func TcIngressTeardown() *automa.StepBuilder
- func TeardownAlloyStack() *automa.WorkflowBuilder
- func TeardownBindMounts() *automa.WorkflowBuilder
- func TeardownExternalSecrets(namespace string) *automa.WorkflowBuilder
- func TeardownPrometheusOperatorCRDs() *automa.WorkflowBuilder
- func TeardownSystemdService(serviceName string) *automa.StepBuilder
- func TeardownTeleportClusterAgent() *automa.WorkflowBuilder
- func TeardownTeleportNodeAgent(mr software.MachineRuntime) *automa.WorkflowBuilder
- func UninstallBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func UninstallWeaver(binDir string) *automa.StepBuilder
- func UpgradeBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
- func VerifyExecutablesStep(artifactName string) *automa.StepBuilder
- func WriteBlockNodeDaemonConfigStep(paths models.WeaverPaths, orbit string, statusz daemon.StatuszConfig, ...) *automa.StepBuilder
- func WriteDaemonKubeconfigStep(specs []DaemonComponentSpec) *automa.StepBuilder
- type DaemonBinarySource
- type DaemonComponentSpec
- type ESOSecretOptions
Constants ¶
const ( LoadedByThisStep = automa.Key("loadedByThisStep") ConfigurationFile = "configurationFile" AlreadyInstalled = "alreadyInstalled" AlreadyConfigured = "alreadyConfigured" ServiceAlreadyEnabled = "serviceAlreadyEnabled" ServiceAlreadyRunning = "serviceAlreadyRunning" ServiceEnabledByThisStep = "serviceEnabled" ServiceStartedByThisStep = "serviceStarted" DownloadedByThisStep = "downloaded" ExtractedByThisStep = "extracted" InstalledByThisStep = "installed" CleanedUpByThisStep = "cleanedUp" ConfiguredByThisStep = "configured" // FirewallCreatedByThisStep records whether NetworkFirewallCreate actually // created the inet weaver-host-firewall table (true) or found it already present (false), so // rollback only deletes a table this step introduced. FirewallCreatedByThisStep = "firewallCreated" IsReady = "isReady" IsPending = "isPending" // BandwidthManagerStatus reports the raw Cilium "enable-bandwidth-manager" // cilium-config ConfigMap value ("true"/"false"/"" when unset) recorded by // the guard step in StartCilium. BandwidthManagerStatus = "bandwidthManagerStatus" )
const ( SetupAlloyStepId = "setup-alloy" PreflightAlloyPhaseId = "preflight-alloy" PreCheckAlloyStepId = "precheck-alloy" InstallAlloyStepId = "install-alloy" InstallNodeExporterStepId = "install-node-exporter" DeployAlloyConfigStepId = "deploy-alloy-config" DeployBlockNodeMonitoringStepId = "deploy-block-node-monitoring" CreateAlloyNamespaceStepId = "create-alloy-namespace" IsAlloyReadyStepId = "is-alloy-ready" IsNodeExporterReadyStepId = "is-node-exporter-ready" )
const ( KeyModifiedByThisStep = "modifiedByThisStep" KeyBindTarget = "bindTarget" KeyBindMount = "bindMount" KeyAlreadyMounted = "alreadyMounted" KeyAlreadyInFstab = "alreadyInFstab" )
const ( SetupBlockNodeStepId = "setup-block-node" SetupBlockNodeStorageStepId = "setup-block-node-storage" CreateBlockNodeNamespaceStepId = "create-block-node-namespace" CreateBlockNodePVsStepId = "create-block-node-pvs" DeleteBlockNodePVsStepId = "delete-block-node-pvs" RecreateBlockNodeStorageStepId = "recreate-block-node-storage" InstallBlockNodeStepId = "install-block-node" UninstallBlockNodeStepId = "uninstall-block-node" UpgradeBlockNodeStepId = "upgrade-block-node" WaitForBlockNodeStepId = "wait-for-block-node" ResetBlockNodeStepId = "reset-block-node" PurgeBlockNodeStorageStepId = "purge-block-node-storage" ScaleDownBlockNodeStepId = "scale-down-block-node" ClearBlockNodeStorageStepId = "clear-block-node-storage" ScaleUpBlockNodeStepId = "scale-up-block-node" WaitForBlockNodeTerminatedStepId = "wait-for-block-node-terminated" RolloutRestartBlockNodeStepId = "rollout-restart-block-node" VerifyBlockNodeReachableStepId = "verify-block-node-reachable" )
const ( SetupESOSecretStepId = "setup-eso-secret" CreateESOSecretStepId = "create-eso-secret" )
const ( SetupExternalSecretsStepId = "setup-external-secrets" InstallExternalSecretsStepId = "install-external-secrets" IsExternalSecretsReadyStepId = "is-external-secrets-ready" TeardownExternalSecretsStepId = "teardown-external-secrets" UninstallExternalSecretsStepId = "uninstall-external-secrets" )
const ( CheckClusterNodesStepId = "check_cluster_nodes" CheckClusterNamespacesStepId = "check_cluster_namespaces" CheckClusterConfigMapsStepId = "check_cluster_configmaps" CheckClusterPodsStepId = "check_cluster_pods" CheckClusterServicesStepId = "check_cluster_services" CheckClusterCRDsStepId = "check_cluster_crds" )
const ( SetupMetalLBStepId = "setup-metallb" InstallMetalLBStepId = "install-metallb" MetalLBTemplatePath = "files/metallb/metallb.yaml" ConfigureMetalLbConfigStepId = "configure-metallb-config" PrepareMetalLbConfigStepId = "prepare-metallb-config" DeployMetalLbConfigStepId = "deploy-metallb-config" IsMetalLBReadyStepId = "is-metallb-ready" )
const ( SetupPrometheusCRDsStepId = "setup-prometheus-crds" InstallPrometheusCRDsStepId = "install-prometheus-crds" IsPrometheusCRDsReadyStepId = "is-prometheus-crds-ready" )
const ( ConfigureSysctlForKubernetesStepId = "configure-sysctl-for-kubernetes" SysCtlBackupFilename = "sysctl.conf" KeyBackupFile = "backup_file" KeyReloadedFiles = "reloaded_files" KeyCopiedFiles = "copied_files" KeyRemovedFiles = "removed_files" KeyWarnings = "warnings" )
const ( SetupTeleportStepId = "setup-teleport" TeardownTeleportClusterAgentStepId = "teardown-teleport-cluster-agent" TeardownTeleportNodeAgentStepId = "teardown-teleport-node-agent" InstallTeleportStepId = "install-teleport" UninstallTeleportKubeAgentStepId = "uninstall-teleport-kube-agent" UninstallTeleportNodeAgentStepId = "uninstall-teleport-node-agent" UnconfigureTeleportNodeAgentStepId = "unconfigure-teleport-node-agent" CreateTeleportNamespaceStepId = "create-teleport-namespace" IsTeleportReadyStepId = "is-teleport-ready" )
const BlockNodeDaemonConfigStepId = "write-block-node-daemon-config"
BlockNodeDaemonConfigStepId is the step ID for WriteBlockNodeDaemonConfigStep.
const CheckNoProvisionedClusterStepId = "check-no-provisioned-cluster"
CheckNoProvisionedClusterStepId is the step ID for CheckNoProvisionedCluster.
const (
DisableSwapStepId = "disable-swap"
)
const (
InstallSoloOperatorStepId = "install-solo-operator"
)
const NetworkFirewallCreateStepId = "network-firewall-create"
NetworkFirewallCreateStepId is the step ID for NetworkFirewallCreate, so callers building/inspecting a workflow (e.g. handler tests asserting the step list) can reference it instead of the literal string.
const NetworkFirewallDeleteStepId = "network-firewall-delete"
NetworkFirewallDeleteStepId is the step ID for NetworkFirewallDelete.
const NetworkPolicyCreateStepId = "network-policy-create"
NetworkPolicyCreateStepId is the step ID for NetworkPolicyCreate.
const NetworkPolicyDeleteAllStepId = "network-policy-delete-all"
NetworkPolicyDeleteAllStepId is the step ID for NetworkPolicyDeleteAll.
const NftServiceTeardownStepId = "nft-service-teardown"
NftServiceTeardownStepId is the step ID for NftServiceTeardown.
const NftWeaverPersistStepId = "nft-weaver-persist"
NftWeaverPersistStepId is the step ID for NftWeaverPersist.
const RemoveNetworkConfigStepId = "remove-network-config"
RemoveNetworkConfigStepId is the step ID for RemoveNetworkConfig.
const RestartDaemonServiceStepId = "restart-daemon-service"
RestartDaemonServiceStepId is the step ID for RestartDaemonServiceStep.
const TcEgressPersistStepId = "bandwidth-shaper-persist"
TcEgressPersistStepId is the step ID for TcEgressPersist.
const TcEgressServiceTeardownStepId = "bandwidth-shaper-service-teardown"
TcEgressServiceTeardownStepId is the step ID for TcEgressServiceTeardown.
const TcEgressTeardownStepId = "bandwidth-shaper-teardown"
TcEgressTeardownStepId is the step ID for TcEgressTeardown.
const TcIngressRecordStepId = "tc-ingress-record"
TcIngressRecordStepId is the step ID for TcIngressRecord.
const TcIngressTeardownStepId = "tc-ingress-teardown"
TcIngressTeardownStepId is the step ID for TcIngressTeardown.
Variables ¶
var PrintWorkflowReport = func(report *automa.Report, fileName string) error { b, err := yaml.Marshal(report) if err != nil { return errorx.IllegalFormat.Wrap(err, "failed to marshal workflow report") } if fileName != "" { if err := os.WriteFile(fileName, b, models.DefaultFilePerm); err != nil { return errorx.ExternalError.Wrap(err, "failed to write workflow report to %s", fileName) } return nil } fmt.Printf("Workflow Execution Report:%s\n", b) return nil }
PrintWorkflowReport serializes the workflow execution report as YAML. If fileName is provided the report is written to that file; otherwise it is printed to standard output. It returns a non-nil error when the report cannot be marshaled or written so callers can avoid reporting a successful save that never happened.
Functions ¶
func AddOperatorToWeaverGroupStep ¶ added in v0.20.0
func AddOperatorToWeaverGroupStep() *automa.StepBuilder
AddOperatorToWeaverGroupStep adds the invoking operator (SUDO_USER) to the weaver group so they can reach the daemon socket without sudo. The step is idempotent — if the user is already a member it logs and succeeds. If SUDO_USER is unset or is "root" the step is skipped silently.
func AutoRemoveOrphanedPackages ¶
func AutoRemoveOrphanedPackages() *automa.StepBuilder
AutoRemoveOrphanedPackages removes orphaned dependencies and frees disk space. Essentially this is equivalent to running `apt autoremove -y` on Debian-based systems
func CheckClusterCRDs ¶
func CheckClusterCRDs(id string, crds []string, timeout time.Duration, provider kube.ClientProviderFromContext) *automa.StepBuilder
CheckClusterCRDs checks if the specified CRDs are installed in the cluster crds is a list of CRD names
func CheckClusterConfigMaps ¶
func CheckClusterConfigMaps(id string, configMaps []string, timeout time.Duration, provider kube.ClientProviderFromContext) *automa.StepBuilder
CheckClusterConfigMaps checks if the specified config maps exist in the cluster
func CheckClusterHealth ¶
func CheckClusterHealth() *automa.WorkflowBuilder
CheckClusterHealth performs a series of checks to ensure the cluster is healthy and operational
func CheckClusterNamespaces ¶
func CheckClusterNamespaces(id string, namespaces []string, timeout time.Duration, provider kube.ClientProviderFromContext) *automa.StepBuilder
CheckClusterNamespaces checks if the specified namespaces exist in the cluster namespaces is a list of namespace names
func CheckClusterNodesReady ¶
func CheckClusterNodesReady(id string, provider kube.ClientProviderFromContext) *automa.StepBuilder
CheckClusterNodesReady checks if all nodes in the cluster are ready
func CheckClusterPodsReady ¶
func CheckClusterPodsReady(id string, podNames []string, timeout time.Duration, provider kube.ClientProviderFromContext) *automa.StepBuilder
CheckClusterPodsReady checks if the specified pods are running in the cluster podNames is a list of strings in the format 'namespace/pod-name-prefix'
func CheckClusterServices ¶
func CheckClusterServices(id string, services []string, timeout time.Duration, provider kube.ClientProviderFromContext) *automa.StepBuilder
CheckClusterServices checks if the specified services are running in the cluster services is a list of strings in the format 'namespace/service-name'
func CheckClusterStep ¶ added in v0.20.0
func CheckClusterStep() *automa.StepBuilder
CheckClusterStep verifies the K8s API is reachable via the admin kubeconfig before attempting any provisioning.
func CheckDaemonComponentPrerequisites ¶ added in v0.20.0
CheckDaemonComponentPrerequisites queries GET /status on the daemon socket at sockPath and returns a human-readable warning string when any component probe errors or degraded monitor states are present, or an empty string when everything is healthy.
Two classes of issue are reported:
- Probe errors (disk prerequisites): the component's required directories are missing, wrongly owned, or not writable. Operator must act.
- Degraded monitors: a monitor's last watch/list cycle failed (e.g. RBAC revoked). The monitor retries automatically; operator should investigate.
It is called by `daemon service check` after the main health workflow passes.
func CheckDaemonComponentPrerequisitesStep ¶ added in v0.20.0
func CheckDaemonComponentPrerequisitesStep(sockPath string) *automa.StepBuilder
CheckDaemonComponentPrerequisitesStep wraps CheckDaemonComponentPrerequisites as a workflow step so that install (and any future workflow) can surface probe failures in the TUI without post-workflow logic in the command RunE. The step succeeds immediately when no probe errors are present.
func CheckDaemonServiceStep ¶ added in v0.20.0
func CheckDaemonServiceStep(paths models.WeaverPaths, sockPath string) *automa.StepBuilder
CheckDaemonServiceStep verifies the daemon installation and runtime health:
- Sandbox unit file exists at $home/sandbox/usr/lib/systemd/system/solo-provisioner-daemon.service
- System symlink exists at /usr/lib/systemd/system/solo-provisioner-daemon.service → sandbox file
- Service is enabled (systemctl is-enabled)
- Service is active/running (systemctl is-active)
- Daemon binary exists at /opt/solo/weaver/bin/solo-provisioner-daemon
- Sudoers entry exists at /etc/sudoers.d/solo-provisioner
- Unix socket responds to GET /health → HTTP 200
func CheckNoProvisionedCluster ¶ added in v0.28.0
func CheckNoProvisionedCluster() *automa.StepBuilder
CheckNoProvisionedCluster fails the self-uninstall when a Kubernetes cluster is still provisioned here. Removing the CLI first strands the operator: every teardown command lives in the binary about to be deleted, and the daemon would keep reconciling a block node with nothing left to manage it.
This deliberately reads the host rather than the recorded state file, which can disagree with reality after a partial teardown.
func CheckWeaverInstallation ¶
func CheckWeaverInstallation(binDir string) *automa.StepBuilder
CheckWeaverInstallation checks if solo-provisioner is installed at the given binDir.
func CleanupWeaverFiles ¶ added in v0.7.0
func CleanupWeaverFiles() *automa.StepBuilder
CleanupWeaverFiles removes weaver installation files while preserving downloads, bin, and logs folders
func ConfigureSysctlForKubernetes ¶
func ConfigureSysctlForKubernetes() *automa.WorkflowBuilder
func CreateDaemonRBACStep ¶ added in v0.20.0
func CreateDaemonRBACStep(specs []DaemonComponentSpec) *automa.StepBuilder
CreateDaemonRBACStep idempotently creates, for each component in specs, one ServiceAccount, ClusterRole, ClusterRoleBinding, and long-lived token Secret. Resources that already exist are left unchanged. The rollback only removes resources that were actually created on this run so a failed re-install does not invalidate a prior working installation.
Resource names follow the convention solo-provisioner-daemon-<shortName> so that components are isolated and independently upgradeable.
func CreateTeleportNamespace ¶ added in v0.7.0
func DeleteBlockNodePersistentVolumes ¶ added in v0.18.0
func DeleteBlockNodePersistentVolumes(inputs models.BlockNodeInputs) automa.Builder
DeleteBlockNodePersistentVolumes returns the step that deletes the block node's PVCs and PVs by label selector. Used by the uninstall --purge-storage workflow after the data directories have been wiped.
This is a thin public facade over the package-private deleteBlockNodePVs helper; handlers in internal/bll/blocknode/ cannot reach the helper directly. The inner step already carries its own DeleteBlockNodePVsStepId and notify hooks (StepStart/StepFailure/StepCompletion), so no wrapper workflow is added here — wrapping would either collide on the step id or duplicate the notifications.
func DeleteDaemonRBACStep ¶ added in v0.20.0
func DeleteDaemonRBACStep(specs []DaemonComponentSpec) *automa.StepBuilder
DeleteDaemonRBACStep deletes the ClusterRoleBinding, ClusterRole, token Secret, and ServiceAccount for every component in specs. All deletions are best-effort — missing resources are silently ignored, other errors are logged as warnings. The step always succeeds so uninstall can continue past partial state.
func DeployMetricsServer ¶ added in v0.7.0
func DeployMetricsServer(valueOptions *values.Options) *automa.WorkflowBuilder
func DisableSwap ¶
func DisableSwap() *automa.StepBuilder
DisableSwap disables swap on the system On execute, it runs the swapoff and ensures fstab is updated to prevent swap from being re-enabled on reboot On rollback, it runs the swapon and ensures fstab is updated to re-enable swap on reboot
func EnsureHederaOwnerStep ¶ added in v0.17.0
func EnsureHederaOwnerStep() *automa.StepBuilder
EnsureHederaOwnerStep idempotently creates the hedera:2000 user and group when they do not exist, then adds the weaver service account to the hedera group so it can write to block-node storage directories (which are setgid hedera:hedera 2775).
func EnsureWeaverOwnerStep ¶ added in v0.17.0
func EnsureWeaverOwnerStep() *automa.StepBuilder
EnsureWeaverOwnerStep idempotently creates the weaver:2500 user and group when they do not exist. This runs as the first step of self-install so that SetupHomeDirectoryStructure can chown the provisioner home dirs to weaver:weaver.
func FetchDaemonStatus ¶ added in v0.20.0
func FetchDaemonStatus(sockPath string) *daemon.StatusResponse
FetchDaemonStatus fetches GET /status from the daemon socket and returns the decoded response. Returns nil if the endpoint is unreachable or returns a non-200 status — callers treat nil as "status unavailable, skip".
func InitializeCluster ¶
func InitializeCluster() *automa.StepBuilder
InitializeCluster checks cluster status and performs initialization only if needed
func InstallColocatedDaemonBinary ¶ added in v0.28.0
func InstallColocatedDaemonBinary(binDir string) *automa.StepBuilder
InstallColocatedDaemonBinary installs a solo-provisioner-daemon binary found beside the running executable into binDir, so that a block-node install with traffic shaping enabled has a daemon binary to use without the operator supplying a path.
Self-install is the only command that runs from outside binDir — every other command is pinned there by CheckWeaverInstallation — so it is also the only point at which the CLI can still see the daemon binary that was built next to it. `task build` emits both binaries into the same bin/, so after `sudo bin/solo-provisioner-<os>-<arch> install` the CLI and the daemon on the host are always a matching pair, and rebuilding refreshes both.
The step is best-effort: an official install downloads the CLI on its own and has no sibling daemon binary to find, in which case this is a no-op and the daemon is obtained later from the infrastructure catalog. Nothing here can fail the self-install.
func InstallDaemonBinaryStep ¶ added in v0.20.0
func InstallDaemonBinaryStep(src DaemonBinarySource, paths models.WeaverPaths) *automa.StepBuilder
InstallDaemonBinaryStep obtains, verifies, and installs the solo-provisioner-daemon binary at paths.BinDir/solo-provisioner-daemon.
Resolution order:
- src.BinPath == "": auto-download via the infrastructure catalog, verify the release's detached signature against the embedded release GPG key.
- src.BinPath set + src.Checksum set: verify sha256 of BinPath before installing.
- src.BinPath set (no checksum): copy as-is after confirming the file exists.
Rollback removes the installed binary.
func InstallDaemonServiceStep ¶ added in v0.20.0
func InstallDaemonServiceStep(paths models.WeaverPaths, extraReadWritePaths []string) *automa.StepBuilder
InstallDaemonServiceStep installs the solo-provisioner-daemon systemd service unit file into the weaver sandbox, creates a symlink at /usr/lib/systemd/system/solo-provisioner-daemon.service, runs daemon-reload, enables, and starts the service. extraReadWritePaths lists any additional paths beyond /opt/solo that the service unit must be allowed to write; each path is created with MkdirAll before the unit is rendered so the mount namespace setup does not fail with status=226/NAMESPACE for an absent directory.
func InstallKernelModule ¶
func InstallKernelModule(name string) *automa.StepBuilder
InstallKernelModule ensures that a specific kernel module is loaded and persisted. If the module is already loaded, it skips the loading process. On rollback, it unloads the module only if it was loaded by this step.
func InstallSoloOperator ¶ added in v0.17.0
func InstallSudoersStep ¶ added in v0.17.0
func InstallSudoersStep() *automa.StepBuilder
InstallSudoersStep writes the weaver sudoers entry to /etc/sudoers.d/solo-provisioner.
func InstallSystemPackage ¶
func InstallSystemPackage(name string, installer func() (software.Package, error)) *automa.StepBuilder
InstallSystemPackage installs a system package using the provided installer function. The installer function should return a software.Package instance that knows how to install the package. If the package is already installed, it will skip the installation.
func InstallTeleportKubeAgent ¶ added in v0.7.0
func InstallWeaver ¶
func InstallWeaver(binDir string) *automa.StepBuilder
InstallWeaver installs the currently running executable as the `solo-provisioner` binary into the provided `binDir` and attempts to create a convenience symlink in `/usr/local/bin`.
Behavior
- The step locates the currently running executable (source).
- It ensures `binDir` exists and then copies the source executable into a temporary file created inside `binDir` (pattern `solo-provisioner.tmp.*`).
- After the copy completes the temp file is closed, its mode is set to executable (`0o755`), and the temp file is atomically renamed to the final destination `binDir/solo-provisioner`.
Why a temp file + rename
- Atomic replacement: renaming a file within the same filesystem is atomic on POSIX. This guarantees other processes see either the old binary or the fully-written new one, never a half-written file.
- Crash/failure safety: if the copy fails (disk full, interrupt, etc.) the existing installed binary is not touched; the incomplete temp file can be removed without corrupting the installation.
- Running processes remain valid: on Unix, processes holding the old inode continue to run unaffected after the file at the destination is replaced.
- Correct final state: permissions and any finalization (e.g. fsync if added) can be applied to the temp file before it becomes visible at the final path.
Implementation notes
- The temp file is created inside `binDir` to ensure the rename is a same- filesystem move (required for atomicity).
- If creating a symlink at `/usr/local/bin/solo-provisioner` fails the step logs a warning but does not treat this as a hard error (installation can still succeed without the symlink).
- The step returns an automa success or failure report describing the outcome.
- Elevated permissions (e.g. `sudo`) are typically required to write to the system `binDir` or create the symlink in `/usr/local/bin`.
Usage
- Intended to be executed as part of an installation workflow; callers should ensure the process has the required permissions when calling this step.
func IsTeleportPodsReady ¶ added in v0.7.0
func NetworkFirewallCreate ¶ added in v0.22.0
func NetworkFirewallCreate(reconcile bool) *automa.StepBuilder
NetworkFirewallCreate lays down the node-level `inet weaver-host-firewall` nftables table (SSH/management allowlist, ICMP policy, in-cluster host-service ports) by invoking the same logic as `network firewall create`. It is wired into the block-node workflow (`block node install` / `reconfigure` / `upgrade`) — not the generic `kube cluster install`, which provisions a cluster independent of any specific node type and should not unconditionally apply node-specific firewall rules.
reconcile selects the convergence behaviour:
- reconcile=false (install / upgrade): create-if-missing. When the table already exists the supplied flags are NOT applied, so re-running is a no-op. This is the "re-assert the install decision, never regress" mode.
- reconcile=true (reconfigure): force re-render the table from the resolved flags even when it already exists, so an operator changing firewall settings via `block node reconfigure` actually sees them take effect. Only the branch that already knows teardown is permitted passes this.
The table's input chain is default-drop and the only SSH allow rule matches the management allowlist (`ip saddr @mgmt_addrs tcp dport <ssh> accept`). Applying it with an empty allowlist would drop every new SSH connection and lock the host out, so when no management CIDRs are configured this step SKIPS with a warning rather than rendering a lock-out ruleset. The allowlist is supplied via `--mgmt-cidrs` or the host.managementCidrs config value. An operator can also opt out entirely via `--firewall-enabled=false`.
func NetworkFirewallDelete ¶ added in v0.27.0
func NetworkFirewallDelete() *automa.StepBuilder
NetworkFirewallDelete removes the node-level `inet weaver-host-firewall` nftables table (the same teardown as `network firewall delete`). It is the disable counterpart to NetworkFirewallCreate, wired into `block node reconfigure` when the operator turns the host firewall off on an already-provisioned host.
The delete is idempotent (firewall.Manager.Delete existence-checks before removing), so running it when no table is present is a no-op. It deliberately does NOT disable the shared solo-provisioner-network-nft.service — that unit is also used by the `inet weaver-workload-policy` plane and is only torn down by a full cluster uninstall.
func NetworkPolicyCreate ¶ added in v0.25.0
func NetworkPolicyCreate(force bool, healthPort string) *automa.StepBuilder
NetworkPolicyCreate lays down the BN workload classification plane (the `inet weaver` table) by running the create-if-missing equivalent of `network policy create` for each canonical BN category. It must run before NftWeaverPersist so the policy registry is populated when that step re-renders and persists network-weaver-workload-policy.nft (an empty registry persists no file at all).
Every create is idempotent: a re-run leaves existing policies and their operator-mutated set membership untouched. When force is set, each policy's static rules are re-rendered from these definitions (membership is preserved by the manager). The one operator-curated set, bn-mgmt-in/out, receives its initial membership here from the host management allowlist (--mgmt-cidrs). bn-restricted starts empty and is left entirely to the daemon's statusz poll loop — see canonicalPolicy.curated. healthPort is the resolved block-node health/statusz port (from blocknode.ResolveHealthPort against the operator's effective values), used to seed the bn-mgmt sets so the port solo-weaver allows tracks the port the BN actually listens on rather than a value baked into solo-weaver.
func NetworkPolicyDeleteAll ¶ added in v0.27.0
func NetworkPolicyDeleteAll() *automa.StepBuilder
NetworkPolicyDeleteAll tears down the BN workload classification plane (the `inet weaver-workload-policy` table) by deleting every canonical BN policy. It is the disable counterpart to NetworkPolicyCreate, wired into `block node reconfigure` when the operator turns traffic shaping off on an already-provisioned block node.
It walks canonicalBNPolicies and deletes only those that currently exist (Manager.Delete errors on a missing policy, so each is Exists-checked first), making the step idempotent. Each delete re-renders the live weaver chain without that policy; deleting the last remaining policy tears the whole `inet weaver` table down and removes the persisted network-weaver-workload-policy.nft, so no separate NftWeaverPersist is needed on the disable path.
func NftServiceTeardown ¶ added in v0.28.0
func NftServiceTeardown() *automa.StepBuilder
NftServiceTeardown disables and removes the shared solo-provisioner-network-nft.service unit when neither the host-firewall artifact (network-weaver-host-firewall.nft) nor the workload-policy artifact (network-weaver-workload-policy.nft) are present — i.e. both planes have been torn down and nothing is left for the service to replay at boot.
If the host-firewall file still exists (HostNftPath), the service is needed to replay it; the step skips so the firewall survives reboot until `kube cluster uninstall` removes it.
It is wired into `block node uninstall` after NetworkPolicyDeleteAll (which removes the weaver-workload-policy.nft artifact when the last policy is deleted) and before the shape teardown steps. The step is idempotent: it skips gracefully when the unit file is already absent.
func NftWeaverPersist ¶ added in v0.23.0
func NftWeaverPersist() *automa.StepBuilder
NftWeaverPersist re-renders /etc/solo-provisioner/network-weaver-workload-policy.nft from the policy registry and restarts the shared solo-provisioner-network-nft.service oneshot so the kernel loads both network-weaver-host-firewall.nft and network-weaver-workload-policy.nft via systemd — bringing the service's RemainAfterExit state in sync with the full static plane installed by `network policy create`.
Set elements are deliberately NOT persisted; the daemon's poll loop rehydrates them within one ~5 s cycle after reboot.
func PreflightAlloy ¶ added in v0.23.0
func PreflightAlloy() *automa.WorkflowBuilder
PreflightAlloy returns the preflight phase for the Alloy install workflow. It wraps the preCheckAlloy prerequisite check as a top-level, phase-level builder so the TUI renders it as a named phase boundary (mirrors SetupBlockNode's phase pattern).
func PurgeBlockNodeStorage ¶ added in v0.8.0
func PurgeBlockNodeStorage(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
PurgeBlockNodeStorage scales down the block node and clears all storage. This does NOT scale back up - use ResetBlockNode if you need to restart the pod after clearing.
func RecordProvisionerVersion ¶ added in v0.27.0
func RecordProvisionerVersion() *automa.StepBuilder
RecordProvisionerVersion persists the running CLI version to state.yaml at the end of cluster install. `kube cluster install` does not flush state via the BaseHandler path (unlike `block node install`), so without this a fresh cluster has no state.yaml and the next invocation synthesises the 0.0.0 baseline and re-runs historical migrations.
func RecreateBlockNodeStorage ¶ added in v0.17.0
func RecreateBlockNodeStorage(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
RecreateBlockNodeStorage deletes existing PVs/PVCs, creates storage directories at the new paths, then creates fresh PVs/PVCs bound to those directories. It is used in the reconfigure --with-reset workflow to apply storage path changes.
func RefreshSystemPackageIndex ¶
func RefreshSystemPackageIndex() *automa.StepBuilder
RefreshSystemPackageIndex refreshes the system package index. Essentially this is equivalent to running `apt-get update` on Debian-based systems
func RemoveConfigDirectories ¶ added in v0.7.0
func RemoveConfigDirectories() *automa.StepBuilder
RemoveConfigDirectories removes configuration directories created during cluster setup
func RemoveDaemonBinaryStep ¶ added in v0.20.0
func RemoveDaemonBinaryStep(paths models.WeaverPaths) *automa.StepBuilder
RemoveDaemonBinaryStep removes the solo-provisioner-daemon binary from paths.BinDir. This is a best-effort step — a missing binary is not an error.
func RemoveDaemonConfigStep ¶ added in v0.20.0
func RemoveDaemonConfigStep(paths models.WeaverPaths) *automa.StepBuilder
RemoveDaemonConfigStep removes daemon.yaml from the config directory. Deleted on uninstall so a subsequent install with different --components starts from a clean slate rather than inheriting stale component entries.
func RemoveDaemonKubeconfigStep ¶ added in v0.20.0
func RemoveDaemonKubeconfigStep(specs []DaemonComponentSpec) *automa.StepBuilder
RemoveDaemonKubeconfigStep removes the kubeconfig file for every component in specs. Removal is best-effort: a missing file is noted at Info level, a real removal error is logged as a warning and the step still succeeds so uninstall can continue past partial state.
func RemoveDaemonServiceStep ¶ added in v0.20.0
func RemoveDaemonServiceStep(paths models.WeaverPaths) *automa.StepBuilder
RemoveDaemonServiceStep stops, disables, and removes the solo-provisioner-daemon systemd service — both the system symlink and the sandbox unit file.
func RemoveNetworkConfig ¶ added in v0.28.0
func RemoveNetworkConfig() *automa.StepBuilder
RemoveNetworkConfig deletes the operator-facing config tree that the network planes persist outside the weaver home — the rendered .nft files, the policy registry, and the tc device/class configs.
It runs before the two boot-unit teardown steps: NftServiceTeardown retains the shared unit while the host-firewall .nft file is still present, so removing the files first is what lets that step take the unit with it.
Live kernel state (the loaded nft tables, the tc qdiscs) is deliberately left alone — this removes the boot-replay inputs, so the host comes up clean, but nothing here touches packet handling on a running machine.
func RemoveSudoersStep ¶ added in v0.17.0
func RemoveSudoersStep() *automa.StepBuilder
RemoveSudoersStep removes the weaver sudoers entry from /etc/sudoers.d/solo-provisioner.
func RemoveSystemPackage ¶
func RemoveSystemPackage(name string, installer func() (software.Package, error)) *automa.StepBuilder
RemoveSystemPackage removes a system package using the provided installer function. The installer function should return a software.Package instance that knows how to uninstall the package. If the package is not installed, it will skip the removal.
func RemoveSystemdServiceFiles ¶ added in v0.7.0
func RemoveSystemdServiceFiles() *automa.StepBuilder
RemoveSystemdServiceFiles removes systemd service files created during cluster setup
func ResetBlockNode ¶ added in v0.8.0
func ResetBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
ResetBlockNode resets the block node by clearing all storage and restarting the pod
func ResetCluster ¶ added in v0.7.0
func ResetCluster() *automa.StepBuilder
ResetCluster runs kubeadm reset to tear down the Kubernetes cluster
func RestartDaemonServiceStep ¶ added in v0.27.0
func RestartDaemonServiceStep() *automa.StepBuilder
RestartDaemonServiceStep restarts the solo-provisioner-daemon systemd service so it re-reads daemon.yaml. The daemon loads its component config (including whether the block-node traffic-shaper monitor runs) only at startup — there is no hot-reload — so a config change such as disabling the traffic-shaper monitor only takes effect after a restart. Restart (not stop) is used deliberately: the daemon is shared, so co-located components must keep running; the now-disabled block-node monitor simply is not rebuilt.
It is best-effort with respect to installation state: when the service is not running (e.g. the daemon was never installed) there is nothing to reload, so the step is skipped rather than failing.
func RolloutRestartBlockNode ¶ added in v0.17.0
func RolloutRestartBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
RolloutRestartBlockNode restarts the block node pod by scaling the StatefulSet down to 0, waiting for termination, scaling back up to 1, and waiting for readiness. This reuses the existing ScaleStatefulSet infrastructure and guarantees the pod picks up any configuration changes (including ConfigMap-only updates) that Helm did not propagate via a pod-spec diff.
func SetupAlloy ¶ added in v0.7.0
func SetupAlloy() *automa.WorkflowBuilder
SetupAlloy returns a workflow builder that sets up Grafana Alloy for observability.
func SetupAlloyStack ¶ added in v0.7.0
func SetupAlloyStack() *automa.WorkflowBuilder
SetupAlloyStack returns a workflow builder that sets up the complete Alloy observability stack. This includes Prometheus Operator CRDs and Grafana Alloy. K8s secrets containing passwords for remote endpoints must be pre-created before running this. Secrets can be created manually, via ESO/Vault, Terraform, or any other mechanism.
It is a bare container that composes three top-level phases, each of which emits phase-level TUI progress (see PreflightAlloy, SetupPrometheusOperatorCRDs, SetupAlloy). Mirrors InstallClusterWorkflow in internal/workflows/cluster.go.
func SetupBindMounts ¶
func SetupBindMounts() *automa.WorkflowBuilder
func SetupBlockNode ¶
func SetupBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
SetupBlockNode sets up the block node on the cluster
func SetupCilium ¶
func SetupCilium(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupCrio ¶
func SetupCrio(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupESOSecret ¶ added in v0.28.0
func SetupESOSecret(opts ESOSecretOptions) *automa.WorkflowBuilder
SetupESOSecret returns a workflow builder that applies an ExternalSecret to the cluster from the given options.
func SetupExternalSecrets ¶ added in v0.7.0
func SetupExternalSecrets(namespace string) *automa.WorkflowBuilder
SetupExternalSecrets returns a workflow builder that installs the External Secrets Operator at the catalog default version. An empty namespace selects the catalog default namespace.
func SetupHelm ¶
func SetupHelm(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupHomeDirectoryStructure ¶
func SetupHomeDirectoryStructure(pp models.WeaverPaths) *automa.StepBuilder
func SetupK9s ¶
func SetupK9s(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupKubeadm ¶
func SetupKubeadm(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupKubectl ¶
func SetupKubectl(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupKubelet ¶
func SetupKubelet(mr software.MachineRuntime) *automa.WorkflowBuilder
func SetupMetalLB ¶
func SetupMetalLB() *automa.WorkflowBuilder
func SetupPrometheusOperatorCRDs ¶ added in v0.7.0
func SetupPrometheusOperatorCRDs() *automa.WorkflowBuilder
SetupPrometheusOperatorCRDs returns a workflow builder that sets up Prometheus Operator CRDs. These CRDs are required for ServiceMonitor and PodMonitor support in Alloy.
func SetupSystemdService ¶
func SetupSystemdService(serviceName string) *automa.StepBuilder
SetupSystemdService enables and starts a systemd service by name It also reloads the systemd daemon to apply any changes Example: SetupSystemdService("kubelet")
func SetupTeleportClusterAgent ¶ added in v0.7.0
func SetupTeleportClusterAgent() *automa.WorkflowBuilder
SetupTeleportClusterAgent returns a workflow builder that sets up the Teleport Kubernetes agent. This provides secure, identity-aware access to the Kubernetes cluster with full audit logging. All configuration including RBAC is provided via the Helm values file. Used by 'solol-provisioner teleport cluster install' command.
func SetupTeleportNodeAgent ¶ added in v0.7.0
func SetupTeleportNodeAgent(mr software.MachineRuntime) *automa.WorkflowBuilder
SetupTeleportNodeAgent returns a workflow builder that sets up the Teleport node agent. This provides SSH access to the node via Teleport with full session recording. Used by 'solo-provisioner teleport node install' command.
func Sleep ¶
Sleep sleeps for the given duration or returns early if the context is canceled or its deadline expires. Returns nil on success or ctx.Err() on cancellation.
func SoakStart ¶ added in v0.20.0
func SoakStart(sockPath string, req consensus.SoakStartRequest) (*consensus.SoakStartResponse, error)
SoakStart sends POST /consensus_node/migration/soak/start to the daemon socket and returns the accepted response. Returns an error if the daemon rejects the request (e.g. 409 Conflict when a soak is already active).
func SoakStartStep ¶ added in v0.20.0
func SoakStartStep(sockPath string, req consensus.SoakStartRequest) *automa.StepBuilder
SoakStartStep sends POST /consensus_node/migration/soak/start to the daemon socket and surfaces TUI / non-interactive output via the notify layer.
func SoakStatus ¶ added in v0.20.0
func SoakStatus(sockPath string) *consensus.SoakStatusResponse
SoakStatus fetches GET /consensus_node/migration/soak/status from the daemon socket. Returns nil if the daemon is unreachable or returns a non-200 status.
func SoakStop ¶ added in v0.20.0
SoakStop sends DELETE /consensus_node/migration/soak to the daemon socket. When keepState is true the query param delete_state=false is appended so cutover-state.jsonl is preserved and the daemon will resume on next restart. Returns an error if no soak is active (409) or the daemon is unreachable.
func SoakStopStep ¶ added in v0.20.0
func SoakStopStep(sockPath string, keepState bool) *automa.StepBuilder
SoakStopStep sends DELETE /consensus_node/migration/soak to the daemon socket and surfaces TUI / non-interactive output via the notify layer. When keepState is true the soak state file is preserved so the daemon resumes the soak on the next restart.
func StartCilium ¶
func StartCilium() *automa.WorkflowBuilder
func StartDaemonServiceStep ¶ added in v0.20.0
func StartDaemonServiceStep() *automa.StepBuilder
StartDaemonServiceStep starts the solo-provisioner-daemon systemd service.
func StopDaemonServiceStep ¶ added in v0.20.0
func StopDaemonServiceStep() *automa.StepBuilder
StopDaemonServiceStep stops the solo-provisioner-daemon systemd service and verifies the service is no longer running.
func TcEgressPersist ¶ added in v0.22.0
func TcEgressPersist(nicName string, trunkRate string, overrides map[string]shape.ClassOverride) *automa.StepBuilder
TcEgressPersist provisions the egress tc HTB hierarchy for reboot persistence. It writes the egress device root and three default classes (partner/public/reserve-egress) into the shape registry — either at the operator-supplied trunkRate/overrides, or, when neither was supplied and no egress registry entry exists yet (a fresh install), at auto-detected defaults. This mirrors TcIngressRecord's unconditional provisioning so `network shape show` always reports all six classes after install, not just the three from TcIngressRecord.
When trunkRate/overrides are empty and an egress registry entry already exists (a reconfigure/upgrade re-run that didn't pass --link-rate/--shape), it re-renders the boot script from that existing config instead, so it never clobbers operator-applied `network shape set` adjustments.
When nicName is empty the NIC is auto-detected from the default route via DetectEgressInterface. Pass --egress-interface to override on multi-NIC hosts or when the default route does not identify the correct physical interface.
func TcEgressServiceTeardown ¶ added in v0.28.0
func TcEgressServiceTeardown() *automa.StepBuilder
TcEgressServiceTeardown stops, disables and removes the solo-provisioner-bandwidth-shaper.service unit along with the boot script it executes. Unlike the shared network-nft unit — which replays the host firewall too and so outlives the block node — this unit exists only to replay the $EGRESS HTB hierarchy that block node install lays down, so it is removed here rather than deferred to kube cluster uninstall.
It must run after TcEgressTeardown, which drops the live hierarchy and resets the boot script; this step then removes the boot-replay machinery itself. The step is idempotent: an already-absent unit or script is not an error.
func TcEgressTeardown ¶ added in v0.27.0
func TcEgressTeardown() *automa.StepBuilder
TcEgressTeardown removes the egress tc HTB hierarchy (device root + all egress classes) and re-renders the boot script to its empty default, dropping the live shaping on the physical NIC. It is the disable counterpart to TcEgressPersist, wired into `block node reconfigure` when traffic shaping is turned off.
It must run after NetworkPolicyDeleteAll: the policy plane's --stamp rules reference these classes, and the underlying shape teardown assumes those references are already gone. The teardown is idempotent — with no egress config present it re-renders the empty script and succeeds.
func TcIngressRecord ¶ added in v0.25.0
func TcIngressRecord(nicName string, linkRate string, overrides map[string]shape.ClassOverride) *automa.StepBuilder
TcIngressRecord records the ingress ($VETH) HTB shape config so the daemon pod-lifecycle watcher can replay it on each block-node pod create. It writes the ingress device root and the three default classes (publisher/backfill- response/reserve-ingress) at proportional rates into the shape registry, but — unlike TcEgressPersist — renders NO boot script: the $VETH qdisc is ephemeral (Cilium recreates the veth per pod) and is deliberately not persisted across reboot.
Ingress bandwidth defaults to egress: linkRate is the operator's --link-rate (the $EGRESS trunk). When empty it resolves "auto" — the NIC's detected link speed at install time — so the recorded class rates are always concrete, since the per-pod replay has no sysfs fallback. nicName pins auto-resolution to the operator-chosen NIC on multi-NIC hosts.
func TcIngressTeardown ¶ added in v0.28.0
func TcIngressTeardown() *automa.StepBuilder
TcIngressTeardown removes the ingress tc shape config (device root + all ingress classes) from the shape registry. There is no boot script to re-render: the $VETH HTB is ephemeral (Cilium recreates the veth on each pod create) and was deliberately not persisted for boot replay. It is the teardown counterpart to TcIngressRecord, wired into `block node uninstall`.
It must run after NetworkPolicyDeleteAll: the policy plane's --reply-stamp rules reference these classes, and the underlying shape teardown assumes those references are already gone. The teardown is idempotent — with no ingress config present it succeeds immediately.
func TeardownAlloyStack ¶ added in v0.7.0
func TeardownAlloyStack() *automa.WorkflowBuilder
TeardownAlloyStack returns a workflow builder that tears down the complete Alloy observability stack. This removes Grafana Alloy, Node Exporter, and Prometheus Operator CRDs.
func TeardownBindMounts ¶ added in v0.7.0
func TeardownBindMounts() *automa.WorkflowBuilder
TeardownBindMounts removes bind mounts and their fstab entries
func TeardownExternalSecrets ¶ added in v0.25.0
func TeardownExternalSecrets(namespace string) *automa.WorkflowBuilder
TeardownExternalSecrets returns a workflow builder that uninstalls the External Secrets Operator. An empty namespace selects the catalog default namespace.
func TeardownPrometheusOperatorCRDs ¶ added in v0.7.0
func TeardownPrometheusOperatorCRDs() *automa.WorkflowBuilder
TeardownPrometheusOperatorCRDs returns a workflow builder that tears down Prometheus Operator CRDs.
func TeardownSystemdService ¶ added in v0.7.0
func TeardownSystemdService(serviceName string) *automa.StepBuilder
TeardownSystemdService stops and disables a systemd service Used during cluster uninstall/teardown
func TeardownTeleportClusterAgent ¶ added in v0.16.0
func TeardownTeleportClusterAgent() *automa.WorkflowBuilder
TeardownTeleportClusterAgent creates a workflow to uninstall the Teleport Kubernetes cluster agent. It detects whether the Helm release is installed and removes it if present.
func TeardownTeleportNodeAgent ¶ added in v0.16.0
func TeardownTeleportNodeAgent(mr software.MachineRuntime) *automa.WorkflowBuilder
TeardownTeleportNodeAgent creates a workflow to uninstall the Teleport node agent. It stops the systemd service, removes configuration, and uninstalls binaries (reverse of install).
func UninstallBlockNode ¶ added in v0.12.0
func UninstallBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
func UninstallWeaver ¶ added in v0.7.0
func UninstallWeaver(binDir string) *automa.StepBuilder
func UpgradeBlockNode ¶ added in v0.5.0
func UpgradeBlockNode(inputs models.BlockNodeInputs) *automa.WorkflowBuilder
UpgradeBlockNode upgrades the block node on the cluster.
The upgradeBlockNode step deletes the helm-owned Services immediately before calling helm so that helm recreates them as fresh CREATE events. Cilium's eBPF service reconciler drops the `spec.type` transition UPDATE event (the root cause of #619) but handles CREATE cleanly, so the topology flip heals itself without any kube-system-wide Cilium DaemonSet restart. The delete is placed AFTER preflight (migration discovery, values-file rendering) so a preflight failure leaves the Services intact — the failure window between delete and helm shrinks to a function call. The post-upgrade reachability probe converts any remaining failure mode (Cilium, MetalLB, chart, firewall) into a loud workflow error. See #644.
func VerifyExecutablesStep ¶ added in v0.22.0
func VerifyExecutablesStep(artifactName string) *automa.StepBuilder
VerifyExecutablesStep verifies the named artifact's installed binaries against their catalog checksums. Insert it before SetupSystemdService for systemd-launched binaries (kubelet, cri-o + runtimes, teleport): it is their only time-of-use check, so tampering blocks the service start.
func WriteBlockNodeDaemonConfigStep ¶ added in v0.24.0
func WriteBlockNodeDaemonConfigStep(paths models.WeaverPaths, orbit string, statusz daemon.StatuszConfig, enabled bool) *automa.StepBuilder
WriteBlockNodeDaemonConfigStep records the block-node component's enablement in daemon.yaml. It loads the existing config (or starts a fresh one), merges in the block_node component block — enabled/monitors.traffic_shaper set to the requested state, the scoped daemon-bn.kubeconfig, and the BN orbit (namespace) — merges the operator-owned statusz block (see below), preserves the consensus_node block, then writes it back.
enabled drives both Components.BlockNode.Enabled and Monitors.TrafficShaper:
- true (install / reconfigure enable): the traffic-shaper monitor runs once the daemon is up.
- false (reconfigure disable): the block-node component and its traffic-shaper monitor are turned off WITHOUT uninstalling the daemon binary/service, so a co-located component (e.g. consensus-node monitoring) that shares the same daemon keeps running.
statusz carries the operator-supplied overrides (from `block node install`/ `reconfigure`'s --statusz-base-url / --statusz-poll-interval). The provisioner-owned fields above always win; the statusz block is merged per-field: starting from any block already on disk, each non-empty override overlays its field, and an empty override preserves the existing on-disk value. So a bare reconfigure/upgrade (a zero-value statusz) never clobbers a hand-edited statusz block, while an explicit flag updates just that field.
The daemon binary and systemd service are installed separately by `daemon service install`; this step only records the enablement. The write is fully reversed on rollback (the file is restored to its prior content, or removed if it did not exist).
func WriteDaemonKubeconfigStep ¶ added in v0.20.0
func WriteDaemonKubeconfigStep(specs []DaemonComponentSpec) *automa.StepBuilder
WriteDaemonKubeconfigStep waits for each component's SA token Secret to be populated, then writes a scoped kubeconfig to spec.KubeconfigPath using the SA token and cluster CA from the admin kubeconfig. Files are written with mode 0640 (root:weaver) so the daemon process (running as the weaver group) can read them. Rollback removes all kubeconfig files written by this step.
Types ¶
type DaemonBinarySource ¶ added in v0.20.0
type DaemonBinarySource struct {
// BinPath is the local path to the binary. Empty means auto-download.
BinPath string
// Checksum is an optional sha256 hex digest to verify BinPath.
// Ignored when BinPath is empty (the auto-download path verifies the
// release signature instead).
Checksum string
// Version selects which catalog version to auto-download. Ignored when
// BinPath is set (no version resolution needed for a locally-supplied
// binary). Empty means the catalog's own default version.
Version string
}
DaemonBinarySource describes where to obtain the daemon binary. When BinPath is empty the binary is auto-downloaded from the release URL embedded in the infrastructure catalog (pkg/software/infrastructure-catalog.yaml) and verified against the embedded release GPG key (pkg/codesign) using the release's detached signature. When BinPath is set, Checksum (sha256 hex) may be supplied to verify the binary before it is installed.
type DaemonComponentSpec ¶ added in v0.20.0
type DaemonComponentSpec struct {
// ShortName is the suffix appended to all K8s resource names created for
// this component (e.g. "cn" → SA solo-provisioner-daemon-cn, ClusterRole
// solo-provisioner-daemon-cn, token secret solo-provisioner-daemon-cn-token).
ShortName string
// Namespace is the orbit namespace where the SA and token Secret live.
Namespace string
// KubeconfigPath is the absolute path where the component's scoped
// kubeconfig is written (e.g. /opt/solo/weaver/config/daemon-cn.kubeconfig).
KubeconfigPath string
// PolicyRules are the RBAC permissions granted to the component's
// ClusterRole. Each component declares only the rules it needs so that
// the principle of least privilege is maintained per component.
PolicyRules []rbacv1.PolicyRule
}
DaemonComponentSpec describes the K8s resources the daemon install workflow must create for one K8s-dependent daemon component. The workflow builds one spec per enabled component from the DaemonConfig and passes the slice to the generic RBAC and kubeconfig steps — adding a new component (e.g. block-node) therefore requires only a new spec entry, no step code changes.
type ESOSecretOptions ¶ added in v0.28.0
type ESOSecretOptions struct {
Name string
Namespace string
StoreName string
RefreshInterval string
Data []models.ESOSecretDataEntry
}
ESOSecretOptions parameterizes the ExternalSecret create workflow. Its exported fields are consumed directly by the manifest template.
Source Files
¶
- catalog.go
- consensus_migration_client.go
- const.go
- helpers.go
- report.go
- step_alloy.go
- step_bind_mounts.go
- step_block_node.go
- step_cilium.go
- step_cluster_configmaps.go
- step_cluster_crds.go
- step_cluster_namespace.go
- step_cluster_node_ready.go
- step_cluster_pod_ready.go
- step_cluster_services.go
- step_cluster_uninstall.go
- step_consensus_migration.go
- step_crio.go
- step_daemon.go
- step_daemon_block_node.go
- step_daemon_provision.go
- step_disable_swap.go
- step_ensure_hedera_owner.go
- step_ensure_weaver_owner.go
- step_eso_secret.go
- step_external_secrets.go
- step_health.go
- step_helm.go
- step_k9s.go
- step_kubeadm.go
- step_kubectl.go
- step_kubelet.go
- step_metallb.go
- step_metrics_server.go
- step_network_firewall.go
- step_network_firewall_delete.go
- step_network_nft_service_teardown.go
- step_network_nft_weaver.go
- step_network_policy.go
- step_network_policy_delete.go
- step_network_tc_egress.go
- step_network_tc_egress_service_teardown.go
- step_network_tc_egress_teardown.go
- step_network_tc_ingress.go
- step_network_tc_ingress_teardown.go
- step_prometheus_operator_crds.go
- step_provisioner_version.go
- step_setup_directories.go
- step_solo_operator.go
- step_sysctl.go
- step_system_module.go
- step_system_package.go
- step_systemd_service.go
- step_teleport.go
- step_verify_executables.go
- step_weaver.go
- step_weaver_purge.go