Documentation
¶
Index ¶
- Constants
- Variables
- func ClearRegistration(dir string) error
- func GenerateKeyPair() (privateKey string, publicKey string, err error)
- func PublicKeyFromPrivateKeyPEM(privPEM string) (string, error)
- func SaveRegistration(dir string, reg *StoredRegistration) error
- type Client
- type Config
- type Result
- type Status
- type StoredRegistration
Constants ¶
const ( // StatusPendingApproval means a human still has to approve this // registration in a browser. This is the interactive path. StatusPendingApproval = "pending_approval" // StatusRegistered means a valid enroll token was presented and the cluster // already exists. Only the unattended path returns this, and there is // nothing to poll for. StatusRegistered = "registered" )
Registration status values returned by the initiate endpoint. A response that predates unattended enrollment carries no status field at all, which decodes to the empty string and is treated as StatusPendingApproval — the only behavior those older responses ever had.
const ( AnchorCluster = "cluster" AnchorCloud = "cloud" )
Workload identity anchors. See pkg/workloadidentity for what the choice means; in short, both keep the signing key on the cluster, and this decides only who serves discovery and what goes in the iss claim.
Variables ¶
var RegistrationFiles = []string{
"registration.json",
"service-account.key",
}
RegistrationFiles are the files SaveRegistration writes, and the complete set that has to go for a cluster to stop considering itself registered.
Nothing else in the server directory belongs to cloud registration, which is easy to get wrong by eye: ca.crt/ca.key and api.crt/api.key secure CLI-to-cluster authentication, oidc-signing.key signs end-user session cookies for OIDC-protected routes, and workload-identity.key anchors the cluster's own service identities. Removing any of those breaks something unrelated to the cloud.
Functions ¶
func ClearRegistration ¶ added in v0.14.0
ClearRegistration removes the registration data from the specified directory, leaving the rest of the server directory alone. Missing files are not an error, so a partially cleared directory can be finished off by running again.
func GenerateKeyPair ¶
GenerateKeyPair generates a new ED25519 key pair for registration
func PublicKeyFromPrivateKeyPEM ¶ added in v0.15.0
PublicKeyFromPrivateKeyPEM derives the PEM-encoded public key from a PEM-encoded ED25519 private key. It exists so an interrupted enrollment can retry with the keypair it already saved to disk — presenting the same public key is what lets cloud replay the original registration instead of refusing a spent token.
func SaveRegistration ¶
func SaveRegistration(dir string, reg *StoredRegistration) error
SaveRegistration saves the registration data to the specified directory
Types ¶
type Client ¶
type Client struct {
// contains filtered or unexported fields
}
Client handles the cluster registration flow
type Config ¶
type Config struct {
ClusterName string `json:"cluster_name"`
OrganizationID string `json:"organization_id,omitempty"` // Optional - user will select in UI
Tags map[string]string `json:"tags,omitempty"`
PublicKey string `json:"public_key,omitempty"` // PEM encoded public key
// EnrollToken, when set, requests the unattended path: cloud spends the
// token and creates the cluster in the same request instead of handing back
// an auth_url for a human to approve. An org admin already made the decision
// when they minted the token, so there is nothing to poll for.
EnrollToken string `json:"enroll_token,omitempty"`
}
Config contains the configuration for cluster registration
type Result ¶
type Result struct {
Status string `json:"status"`
RegistrationID string `json:"registration_id"`
AuthURL string `json:"auth_url"`
PollURL string `json:"poll_url"`
ExpiresAt time.Time `json:"expires_at"`
// Set only on the unattended (StatusRegistered) response. There is no
// credential here: service-account auth is a challenge-response against the
// public key the node supplied, so the private key it already holds is the
// whole secret.
ClusterID string `json:"cluster_id,omitempty"`
OrganizationID string `json:"organization_id,omitempty"`
ServiceAccountID string `json:"service_account_id,omitempty"`
DNSHostname string `json:"dns_hostname,omitempty"`
IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
Tags map[string]string `json:"tags,omitempty"`
}
Result contains the result of registration initiation. It covers both shapes the initiate endpoint can return: the interactive response populates AuthURL/PollURL and leaves the registered fields empty, while the unattended (enroll-token) response sets Status to StatusRegistered and fills in the cluster identity directly with no auth_url to visit.
type Status ¶
type Status struct {
Status string `json:"status"`
ClusterID string `json:"cluster_id,omitempty"`
OrganizationID string `json:"organization_id,omitempty"`
ServiceAccountID string `json:"service_account_id,omitempty"`
DNSHostname string `json:"dns_hostname,omitempty"`
// IdentityIssuerURL is where cloud will anchor this cluster's workload
// identity if the cluster asks it to. Advertised at registration rather
// than only on first key publication so a cluster can adopt the anchor on
// the boot it registers, instead of minting a boot's worth of tokens under
// one iss and then switching. Empty when cloud has no anchor configured.
IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
}
Status represents the status of a registration during polling
type StoredRegistration ¶
type StoredRegistration struct {
ClusterID string `json:"cluster_id"`
ClusterName string `json:"cluster_name"`
OrganizationID string `json:"organization_id"`
ServiceAccountID string `json:"service_account_id"`
DNSHostname string `json:"dns_hostname,omitempty"` // Auto-provisioned DNS hostname from cloud
// IdentityIssuerURL is the workload identity anchor cloud assigned this
// cluster. Persisted because the iss claim it produces gets pinned in
// external trust configurations, so it has to survive restarts unchanged
// rather than being recomputed from whatever cloud reports today.
IdentityIssuerURL string `json:"identity_issuer_url,omitempty"`
// IdentityAnchor records which anchor this cluster registered with:
// AnchorCloud or AnchorCluster. The choice is made at registration, so it
// lives with the registration rather than in server config — a cluster that
// registered before this existed finds no value here and keeps the cluster
// anchor, which is what stops an upgrade from silently moving anyone's iss.
IdentityAnchor string `json:"identity_anchor,omitempty"`
PrivateKey string `json:"private_key"` // PEM encoded private key
CloudURL string `json:"cloud_url"`
RegisteredAt time.Time `json:"registered_at"`
Tags map[string]string `json:"tags,omitempty"`
// Pending registration fields
Status string `json:"status,omitempty"` // "pending" or "approved"
RegistrationID string `json:"registration_id,omitempty"`
PollURL string `json:"poll_url,omitempty"`
ExpiresAt time.Time `json:"expires_at"`
}
StoredRegistration contains the registration data stored on disk
func LoadRegistration ¶
func LoadRegistration(dir string) (*StoredRegistration, error)
LoadRegistration loads the registration data from the specified directory