2023-05-25 12:43:44 -04:00
|
|
|
/*
|
|
|
|
Copyright (c) Edgeless Systems GmbH
|
|
|
|
|
|
|
|
SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
*/
|
2023-06-02 03:19:23 -04:00
|
|
|
package client
|
2023-05-25 12:43:44 -04:00
|
|
|
|
|
|
|
import (
|
2023-06-01 07:55:46 -04:00
|
|
|
"bytes"
|
2023-05-25 12:43:44 -04:00
|
|
|
"context"
|
|
|
|
"encoding/json"
|
|
|
|
"errors"
|
|
|
|
"fmt"
|
2023-06-01 07:55:46 -04:00
|
|
|
"io"
|
2023-05-25 12:43:44 -04:00
|
|
|
"path"
|
|
|
|
"sort"
|
|
|
|
"time"
|
|
|
|
|
2023-06-02 05:20:01 -04:00
|
|
|
s3manager "github.com/aws/aws-sdk-go-v2/feature/s3/manager"
|
2023-06-01 07:55:46 -04:00
|
|
|
"github.com/aws/aws-sdk-go-v2/service/s3"
|
2023-06-02 03:19:23 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/api/attestationconfig"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/constants"
|
2023-05-25 12:43:44 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/kms/storage"
|
2023-06-01 07:55:46 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/sigstore"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/staticupload"
|
2023-05-25 12:43:44 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/variant"
|
|
|
|
)
|
|
|
|
|
2023-06-02 03:19:23 -04:00
|
|
|
// Client manages (modifies) the version information for the attestation variants.
|
|
|
|
type Client struct {
|
2023-06-02 05:20:01 -04:00
|
|
|
s3Client
|
|
|
|
s3ClientClose func(ctx context.Context) error
|
|
|
|
bucketID string
|
|
|
|
cosignPwd []byte // used to decrypt the cosign private key
|
|
|
|
privKey []byte // used to sign
|
2023-05-25 12:43:44 -04:00
|
|
|
}
|
|
|
|
|
2023-06-02 03:19:23 -04:00
|
|
|
// New returns a new Client.
|
2023-06-02 05:20:01 -04:00
|
|
|
func New(ctx context.Context, cfg staticupload.Config, cosignPwd, privateKey []byte) (*Client, CloseFunc, error) {
|
|
|
|
client, clientClose, err := staticupload.New(ctx, cfg)
|
2023-05-25 12:43:44 -04:00
|
|
|
if err != nil {
|
2023-06-02 05:20:01 -04:00
|
|
|
return nil, nil, fmt.Errorf("failed to create s3 storage: %w", err)
|
2023-05-25 12:43:44 -04:00
|
|
|
}
|
2023-06-02 05:20:01 -04:00
|
|
|
repo := &Client{
|
|
|
|
s3Client: client,
|
|
|
|
s3ClientClose: clientClose,
|
|
|
|
bucketID: cfg.Bucket,
|
|
|
|
cosignPwd: cosignPwd,
|
|
|
|
privKey: privateKey,
|
|
|
|
}
|
|
|
|
repoClose := func(ctx context.Context) error {
|
|
|
|
return repo.Close(ctx)
|
|
|
|
}
|
|
|
|
return repo, repoClose, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Close closes the Client.
|
|
|
|
func (a Client) Close(ctx context.Context) error {
|
|
|
|
if a.s3ClientClose == nil {
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
return a.s3ClientClose(ctx)
|
2023-05-25 12:43:44 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
// UploadAzureSEVSNP uploads the latest version numbers of the Azure SEVSNP.
|
2023-06-02 03:19:23 -04:00
|
|
|
func (a Client) UploadAzureSEVSNP(ctx context.Context, versions attestationconfig.AzureSEVSNPVersion, date time.Time) error {
|
2023-06-01 07:55:46 -04:00
|
|
|
versionBytes, err := json.Marshal(versions)
|
2023-05-25 12:43:44 -04:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
variant := variant.AzureSEVSNP{}
|
|
|
|
fname := date.Format("2006-01-02-15-04") + ".json"
|
|
|
|
|
2023-06-02 03:19:23 -04:00
|
|
|
filePath := fmt.Sprintf("%s/%s/%s", constants.CDNAttestationConfigPrefixV1, variant.String(), fname)
|
2023-06-02 05:20:01 -04:00
|
|
|
err = put(ctx, a.s3Client, a.bucketID, filePath, versionBytes)
|
2023-06-01 07:55:46 -04:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
err = a.createAndUploadSignature(ctx, versionBytes, filePath)
|
2023-05-25 12:43:44 -04:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
return a.addVersionToList(ctx, variant, fname)
|
|
|
|
}
|
|
|
|
|
2023-06-01 07:55:46 -04:00
|
|
|
// createAndUploadSignature signs the given content and uploads the signature to the given filePath with the .sig suffix.
|
2023-06-02 03:19:23 -04:00
|
|
|
func (a Client) createAndUploadSignature(ctx context.Context, content []byte, filePath string) error {
|
2023-06-01 07:55:46 -04:00
|
|
|
signature, err := sigstore.SignContent(a.cosignPwd, a.privKey, content)
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("sign version file: %w", err)
|
|
|
|
}
|
2023-06-02 05:20:01 -04:00
|
|
|
err = put(ctx, a.s3Client, a.bucketID, filePath+".sig", signature)
|
2023-06-01 07:55:46 -04:00
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("upload signature: %w", err)
|
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2023-05-25 12:43:44 -04:00
|
|
|
// List returns the list of versions for the given attestation type.
|
2023-06-02 03:19:23 -04:00
|
|
|
func (a Client) List(ctx context.Context, attestation variant.Variant) ([]string, error) {
|
|
|
|
key := path.Join(constants.CDNAttestationConfigPrefixV1, attestation.String(), "list")
|
2023-06-02 05:20:01 -04:00
|
|
|
bt, err := get(ctx, a.s3Client, a.bucketID, key)
|
2023-05-25 12:43:44 -04:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
var versions []string
|
|
|
|
if err := json.Unmarshal(bt, &versions); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
return versions, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// DeleteList empties the list of versions for the given attestation type.
|
2023-06-02 03:19:23 -04:00
|
|
|
func (a Client) DeleteList(ctx context.Context, attestation variant.Variant) error {
|
2023-05-25 12:43:44 -04:00
|
|
|
versions := []string{}
|
|
|
|
bt, err := json.Marshal(&versions)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2023-06-02 05:20:01 -04:00
|
|
|
return put(ctx, a.s3Client, a.bucketID, path.Join(constants.CDNAttestationConfigPrefixV1, attestation.String(), "list"), bt)
|
2023-05-25 12:43:44 -04:00
|
|
|
}
|
|
|
|
|
2023-06-02 03:19:23 -04:00
|
|
|
func (a Client) addVersionToList(ctx context.Context, attestation variant.Variant, fname string) error {
|
2023-05-25 12:43:44 -04:00
|
|
|
versions := []string{}
|
2023-06-02 03:19:23 -04:00
|
|
|
key := path.Join(constants.CDNAttestationConfigPrefixV1, attestation.String(), "list")
|
2023-06-02 05:20:01 -04:00
|
|
|
bt, err := get(ctx, a.s3Client, a.bucketID, key)
|
2023-05-25 12:43:44 -04:00
|
|
|
if err == nil {
|
|
|
|
if err := json.Unmarshal(bt, &versions); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
} else if !errors.Is(err, storage.ErrDEKUnset) {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
versions = append(versions, fname)
|
|
|
|
versions = variant.RemoveDuplicate(versions)
|
|
|
|
sort.Sort(sort.Reverse(sort.StringSlice(versions)))
|
|
|
|
json, err := json.Marshal(versions)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2023-06-02 05:20:01 -04:00
|
|
|
return put(ctx, a.s3Client, a.bucketID, key, json)
|
2023-06-01 07:55:46 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
// get is a convenience method.
|
2023-06-02 05:20:01 -04:00
|
|
|
func get(ctx context.Context, client s3Client, bucket, path string) ([]byte, error) {
|
2023-06-01 07:55:46 -04:00
|
|
|
getObjectInput := &s3.GetObjectInput{
|
2023-06-02 05:20:01 -04:00
|
|
|
Bucket: &bucket,
|
2023-06-01 07:55:46 -04:00
|
|
|
Key: &path,
|
|
|
|
}
|
|
|
|
output, err := client.GetObject(ctx, getObjectInput)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("getting object: %w", err)
|
|
|
|
}
|
|
|
|
return io.ReadAll(output.Body)
|
|
|
|
}
|
|
|
|
|
|
|
|
// put is a convenience method.
|
2023-06-02 05:20:01 -04:00
|
|
|
func put(ctx context.Context, client s3Client, bucket, path string, data []byte) error {
|
2023-06-01 07:55:46 -04:00
|
|
|
putObjectInput := &s3.PutObjectInput{
|
2023-06-02 05:20:01 -04:00
|
|
|
Bucket: &bucket,
|
2023-06-01 07:55:46 -04:00
|
|
|
Key: &path,
|
|
|
|
Body: bytes.NewReader(data),
|
|
|
|
}
|
|
|
|
_, err := client.Upload(ctx, putObjectInput)
|
|
|
|
return err
|
2023-05-25 12:43:44 -04:00
|
|
|
}
|
2023-06-02 05:20:01 -04:00
|
|
|
|
|
|
|
type s3Client interface {
|
|
|
|
GetObject(
|
|
|
|
ctx context.Context, params *s3.GetObjectInput, optFns ...func(*s3.Options),
|
|
|
|
) (*s3.GetObjectOutput, error)
|
|
|
|
Upload(
|
|
|
|
ctx context.Context, input *s3.PutObjectInput, opts ...func(*s3manager.Uploader),
|
|
|
|
) (*s3manager.UploadOutput, error)
|
|
|
|
}
|
|
|
|
|
|
|
|
// CloseFunc is a function that closes the client.
|
|
|
|
type CloseFunc func(ctx context.Context) error
|