registration

package
v0.14.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 27, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Index

Constants

View Source
const (
	AnchorCluster = "cluster"
	AnchorCloud   = "cloud"
)

Workload identity anchors. See pkg/workloadidentity for what the choice means; in short, both keep the signing key on the cluster, and this decides only who serves discovery and what goes in the iss claim.

Variables

View Source
var RegistrationFiles = []string{
	"registration.json",
	"service-account.key",
}

RegistrationFiles are the files SaveRegistration writes, and the complete set that has to go for a cluster to stop considering itself registered.

Nothing else in the server directory belongs to cloud registration, which is easy to get wrong by eye: ca.crt/ca.key and api.crt/api.key secure CLI-to-cluster authentication, oidc-signing.key signs end-user session cookies for OIDC-protected routes, and workload-identity.key anchors the cluster's own service identities. Removing any of those breaks something unrelated to the cloud.

Functions

func ClearRegistration added in v0.14.0

func ClearRegistration(dir string) error

ClearRegistration removes the registration data from the specified directory, leaving the rest of the server directory alone. Missing files are not an error, so a partially cleared directory can be finished off by running again.

func GenerateKeyPair

func GenerateKeyPair() (privateKey string, publicKey string, err error)

GenerateKeyPair generates a new ED25519 key pair for registration

func SaveRegistration

func SaveRegistration(dir string, reg *StoredRegistration) error

SaveRegistration saves the registration data to the specified directory

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client handles the cluster registration flow

func NewClient

func NewClient(managementURL string, config Config) *Client

NewClient creates a new registration client

func (*Client) PollForApproval

func (c *Client) PollForApproval(ctx context.Context, pollURL string, pollInterval time.Duration, progressCallback func()) (*Status, error)

PollForApproval polls the registration status with optional progress callback

func (*Client) StartRegistration

func (c *Client) StartRegistration(ctx context.Context) (*Result, error)

StartRegistration initiates the registration process

type Config

type Config struct {
	ClusterName    string            `json:"cluster_name"`
	OrganizationID string            `json:"organization_id,omitempty"` // Optional - user will select in UI
	Tags           map[string]string `json:"tags,omitempty"`
	PublicKey      string            `json:"public_key,omitempty"` // PEM encoded public key
}

Config contains the configuration for cluster registration

type Result

type Result struct {
	RegistrationID string    `json:"registration_id"`
	AuthURL        string    `json:"auth_url"`
	PollURL        string    `json:"poll_url"`
	ExpiresAt      time.Time `json:"expires_at"`
}

Result contains the result of registration initiation

type Status

type Status struct {
	Status           string `json:"status"`
	ClusterID        string `json:"cluster_id,omitempty"`
	OrganizationID   string `json:"organization_id,omitempty"`
	ServiceAccountID string `json:"service_account_id,omitempty"`
	DNSHostname      string `json:"dns_hostname,omitempty"`
	// IdentityIssuerURL is where cloud will anchor this cluster's workload
	// identity if the cluster asks it to. Advertised at registration rather
	// than only on first key publication so a cluster can adopt the anchor on
	// the boot it registers, instead of minting a boot's worth of tokens under
	// one iss and then switching. Empty when cloud has no anchor configured.
	IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
}

Status represents the status of a registration during polling

type StoredRegistration

type StoredRegistration struct {
	ClusterID        string `json:"cluster_id"`
	ClusterName      string `json:"cluster_name"`
	OrganizationID   string `json:"organization_id"`
	ServiceAccountID string `json:"service_account_id"`
	DNSHostname      string `json:"dns_hostname,omitempty"` // Auto-provisioned DNS hostname from cloud
	// IdentityIssuerURL is the workload identity anchor cloud assigned this
	// cluster. Persisted because the iss claim it produces gets pinned in
	// external trust configurations, so it has to survive restarts unchanged
	// rather than being recomputed from whatever cloud reports today.
	IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
	// IdentityAnchor records which anchor this cluster registered with:
	// AnchorCloud or AnchorCluster. The choice is made at registration, so it
	// lives with the registration rather than in server config — a cluster that
	// registered before this existed finds no value here and keeps the cluster
	// anchor, which is what stops an upgrade from silently moving anyone's iss.
	IdentityAnchor string            `json:"identity_anchor,omitempty"`
	PrivateKey     string            `json:"private_key"` // PEM encoded private key
	CloudURL       string            `json:"cloud_url"`
	RegisteredAt   time.Time         `json:"registered_at"`
	Tags           map[string]string `json:"tags,omitempty"`

	// Pending registration fields
	Status         string    `json:"status,omitempty"` // "pending" or "approved"
	RegistrationID string    `json:"registration_id,omitempty"`
	PollURL        string    `json:"poll_url,omitempty"`
	ExpiresAt      time.Time `json:"expires_at"`
}

StoredRegistration contains the registration data stored on disk

func LoadRegistration

func LoadRegistration(dir string) (*StoredRegistration, error)

LoadRegistration loads the registration data from the specified directory

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL