registration

package
v0.16.2 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 29, 2026 License: Apache-2.0 Imports: 13 Imported by: 0

Documentation

Index

Constants

View Source
const (
	// StatusPendingApproval means a human still has to approve this
	// registration in a browser. This is the interactive path.
	StatusPendingApproval = "pending_approval"

	// StatusRegistered means a valid enroll token was presented and the cluster
	// already exists. Only the unattended path returns this, and there is
	// nothing to poll for.
	StatusRegistered = "registered"
)

Registration status values returned by the initiate endpoint. A response that predates unattended enrollment carries no status field at all, which decodes to the empty string and is treated as StatusPendingApproval — the only behavior those older responses ever had.

View Source
const (
	AnchorCluster = "cluster"
	AnchorCloud   = "cloud"
)

Workload identity anchors. See pkg/workloadidentity for what the choice means; in short, both keep the signing key on the cluster, and this decides only who serves discovery and what goes in the iss claim.

Variables

View Source
var RegistrationFiles = []string{
	"registration.json",
	"service-account.key",
}

RegistrationFiles are the files SaveRegistration writes, and the complete set that has to go for a cluster to stop considering itself registered.

Nothing else in the server directory belongs to cloud registration, which is easy to get wrong by eye: ca.crt/ca.key and api.crt/api.key secure CLI-to-cluster authentication, oidc-signing.key signs end-user session cookies for OIDC-protected routes, and workload-identity.key anchors the cluster's own service identities. Removing any of those breaks something unrelated to the cloud.

Functions

func ClearRegistration added in v0.14.0

func ClearRegistration(dir string) error

ClearRegistration removes the registration data from the specified directory, leaving the rest of the server directory alone. Missing files are not an error, so a partially cleared directory can be finished off by running again.

func GenerateKeyPair

func GenerateKeyPair() (privateKey string, publicKey string, err error)

GenerateKeyPair generates a new ED25519 key pair for registration

func PublicKeyFromPrivateKeyPEM added in v0.15.0

func PublicKeyFromPrivateKeyPEM(privPEM string) (string, error)

PublicKeyFromPrivateKeyPEM derives the PEM-encoded public key from a PEM-encoded ED25519 private key. It exists so an interrupted enrollment can retry with the keypair it already saved to disk — presenting the same public key is what lets cloud replay the original registration instead of refusing a spent token.

func SaveRegistration

func SaveRegistration(dir string, reg *StoredRegistration) error

SaveRegistration saves the registration data to the specified directory

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client handles the cluster registration flow

func NewClient

func NewClient(managementURL string, config Config) *Client

NewClient creates a new registration client

func (*Client) PollForApproval

func (c *Client) PollForApproval(ctx context.Context, pollURL string, pollInterval time.Duration, progressCallback func()) (*Status, error)

PollForApproval polls the registration status with optional progress callback

func (*Client) StartRegistration

func (c *Client) StartRegistration(ctx context.Context) (*Result, error)

StartRegistration initiates the registration process

type Config

type Config struct {
	ClusterName    string            `json:"cluster_name"`
	OrganizationID string            `json:"organization_id,omitempty"` // Optional - user will select in UI
	Tags           map[string]string `json:"tags,omitempty"`
	PublicKey      string            `json:"public_key,omitempty"` // PEM encoded public key

	// EnrollToken, when set, requests the unattended path: cloud spends the
	// token and creates the cluster in the same request instead of handing back
	// an auth_url for a human to approve. An org admin already made the decision
	// when they minted the token, so there is nothing to poll for.
	EnrollToken string `json:"enroll_token,omitempty"`
}

Config contains the configuration for cluster registration

type Result

type Result struct {
	Status         string    `json:"status"`
	RegistrationID string    `json:"registration_id"`
	AuthURL        string    `json:"auth_url"`
	PollURL        string    `json:"poll_url"`
	ExpiresAt      time.Time `json:"expires_at"`

	// Set only on the unattended (StatusRegistered) response. There is no
	// credential here: service-account auth is a challenge-response against the
	// public key the node supplied, so the private key it already holds is the
	// whole secret.
	ClusterID         string            `json:"cluster_id,omitempty"`
	OrganizationID    string            `json:"organization_id,omitempty"`
	ServiceAccountID  string            `json:"service_account_id,omitempty"`
	DNSHostname       string            `json:"dns_hostname,omitempty"`
	IdentityIssuerURL string            `json:"identity_issuer_url,omitempty"`
	Tags              map[string]string `json:"tags,omitempty"`
}

Result contains the result of registration initiation. It covers both shapes the initiate endpoint can return: the interactive response populates AuthURL/PollURL and leaves the registered fields empty, while the unattended (enroll-token) response sets Status to StatusRegistered and fills in the cluster identity directly with no auth_url to visit.

type Status

type Status struct {
	Status           string `json:"status"`
	ClusterID        string `json:"cluster_id,omitempty"`
	OrganizationID   string `json:"organization_id,omitempty"`
	ServiceAccountID string `json:"service_account_id,omitempty"`
	DNSHostname      string `json:"dns_hostname,omitempty"`
	// IdentityIssuerURL is where cloud will anchor this cluster's workload
	// identity if the cluster asks it to. Advertised at registration rather
	// than only on first key publication so a cluster can adopt the anchor on
	// the boot it registers, instead of minting a boot's worth of tokens under
	// one iss and then switching. Empty when cloud has no anchor configured.
	IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
}

Status represents the status of a registration during polling

type StoredRegistration

type StoredRegistration struct {
	ClusterID        string `json:"cluster_id"`
	ClusterName      string `json:"cluster_name"`
	OrganizationID   string `json:"organization_id"`
	ServiceAccountID string `json:"service_account_id"`
	DNSHostname      string `json:"dns_hostname,omitempty"` // Auto-provisioned DNS hostname from cloud
	// IdentityIssuerURL is the workload identity anchor cloud assigned this
	// cluster. Persisted because the iss claim it produces gets pinned in
	// external trust configurations, so it has to survive restarts unchanged
	// rather than being recomputed from whatever cloud reports today.
	IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
	// IdentityAnchor records which anchor this cluster registered with:
	// AnchorCloud or AnchorCluster. The choice is made at registration, so it
	// lives with the registration rather than in server config — a cluster that
	// registered before this existed finds no value here and keeps the cluster
	// anchor, which is what stops an upgrade from silently moving anyone's iss.
	IdentityAnchor string            `json:"identity_anchor,omitempty"`
	PrivateKey     string            `json:"private_key"` // PEM encoded private key
	CloudURL       string            `json:"cloud_url"`
	RegisteredAt   time.Time         `json:"registered_at"`
	Tags           map[string]string `json:"tags,omitempty"`

	// Pending registration fields
	Status         string    `json:"status,omitempty"` // "pending" or "approved"
	RegistrationID string    `json:"registration_id,omitempty"`
	PollURL        string    `json:"poll_url,omitempty"`
	ExpiresAt      time.Time `json:"expires_at"`
}

StoredRegistration contains the registration data stored on disk

func LoadRegistration

func LoadRegistration(dir string) (*StoredRegistration, error)

LoadRegistration loads the registration data from the specified directory

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL