Documentation
¶
Overview ¶
Package kapmtls manages credentials for the node-local KAP mTLS agent.
Index ¶
Constants ¶
View Source
const ( PackageName = "kap-mtls-agent" DefaultAgentBinaryPath = "/usr/local/bin/kaproxy-mtls-agent" DefaultAgentUnitPath = "/etc/systemd/system/kaproxy-mtls-agent.service" AgentService = "kaproxy-mtls-agent.service" AgentReadyURL = "http://127.0.0.1:8440/readyz" ReleasesDirectoryName = "releases" CurrentSymlinkName = "current" AgentEnvironmentFileName = "agent.env" ClientCertificateFileName = "client.crt" ClientPrivateKeyFileName = "client.key" GatewayCAFileName = "gateway-ca.crt" )
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Credentials ¶
type Credentials struct {
CertificatePEM []byte
PrivateKeyPEM []byte
GatewayCAPEM []byte
GatewayEndpoint string
ServerName string
ClientCAFingerprint string
GatewayCAFingerprint string
}
Credentials is one complete agent credential generation. Certificate and key bytes are sensitive and must not be logged.
type Manager ¶
type Manager struct {
// contains filtered or unexported fields
}
func NewManager ¶
func (*Manager) Activate ¶
Activate retries a pending reload notification. Agent startup and recovery remain the package controller's responsibility.
func (*Manager) UpdateCredentials ¶
func (m *Manager) UpdateCredentials(ctx context.Context, machineID string, credentials Credentials) error
UpdateCredentials atomically selects an immutable generation and reloads only leaf credentials. Agent startup and recovery belong to the package controller.
type Paths ¶
type Paths struct {
StateDir string
AgentBinary string
AgentUnitFile string
AgentVersionFile string
}
func DefaultPaths ¶
type Status ¶
type Status struct {
CredentialsInstalled bool
CertificateSerial string
CertificateNotAfter time.Time
AgentInstalled bool
AgentActive bool
AgentReady bool
AgentVersion string
GatewayEndpoint string
ServerName string
ClientCAFingerprint string
GatewayCAFingerprint string
}
Status contains only non-secret state used by gpud-manager reconciliation.
Click to show internal directories.
Click to hide internal directories.