2022-09-05 03:06:08 -04:00
|
|
|
/*
|
|
|
|
Copyright (c) Edgeless Systems GmbH
|
|
|
|
|
|
|
|
SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
*/
|
|
|
|
|
2022-04-05 09:12:20 -04:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
2022-04-11 08:25:19 -04:00
|
|
|
"context"
|
2022-04-05 09:12:20 -04:00
|
|
|
"flag"
|
2024-02-08 09:20:01 -05:00
|
|
|
"fmt"
|
2023-03-14 09:17:36 -04:00
|
|
|
"io"
|
2024-02-08 09:20:01 -05:00
|
|
|
"log/slog"
|
2024-03-06 05:01:13 -05:00
|
|
|
"log/syslog"
|
2022-09-08 08:45:27 -04:00
|
|
|
"net"
|
2023-03-09 03:47:28 -05:00
|
|
|
"os"
|
2022-04-05 09:12:20 -04:00
|
|
|
"path/filepath"
|
2024-03-06 05:01:13 -05:00
|
|
|
"time"
|
2022-04-05 09:12:20 -04:00
|
|
|
|
2023-07-17 07:55:31 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/disk-mapper/internal/diskencryption"
|
2022-09-21 07:47:57 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/disk-mapper/internal/recoveryserver"
|
|
|
|
"github.com/edgelesssys/constellation/v2/disk-mapper/internal/rejoinclient"
|
|
|
|
"github.com/edgelesssys/constellation/v2/disk-mapper/internal/setup"
|
2023-03-09 03:47:28 -05:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/attestation/choose"
|
2023-03-14 09:17:36 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/attestation/tdx"
|
2023-06-09 09:41:02 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/attestation/variant"
|
2022-09-21 07:47:57 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/attestation/vtpm"
|
2022-10-21 09:04:34 -04:00
|
|
|
awscloud "github.com/edgelesssys/constellation/v2/internal/cloud/aws"
|
2022-09-21 07:47:57 -04:00
|
|
|
azurecloud "github.com/edgelesssys/constellation/v2/internal/cloud/azure"
|
2022-10-21 09:04:34 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/cloud/cloudprovider"
|
2022-09-21 07:47:57 -04:00
|
|
|
gcpcloud "github.com/edgelesssys/constellation/v2/internal/cloud/gcp"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/cloud/metadata"
|
2023-03-07 05:58:33 -05:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/cloud/openstack"
|
2022-09-21 07:47:57 -04:00
|
|
|
qemucloud "github.com/edgelesssys/constellation/v2/internal/cloud/qemu"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/constants"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/grpc/dialer"
|
2023-01-16 05:19:03 -05:00
|
|
|
kmssetup "github.com/edgelesssys/constellation/v2/internal/kms/setup"
|
2022-09-21 07:47:57 -04:00
|
|
|
"github.com/edgelesssys/constellation/v2/internal/logger"
|
|
|
|
"github.com/edgelesssys/constellation/v2/internal/role"
|
2022-04-11 08:25:19 -04:00
|
|
|
"github.com/spf13/afero"
|
2022-04-05 09:12:20 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
2023-02-27 12:19:52 -05:00
|
|
|
gcpStateDiskPath = "/dev/disk/by-id/google-state-disk"
|
|
|
|
azureStateDiskPath = "/dev/disk/azure/scsi1/lun0"
|
|
|
|
awsStateDiskPath = "/dev/sdb"
|
2023-02-21 05:24:04 -05:00
|
|
|
qemuStateDiskPath = "/dev/vdb"
|
2023-02-27 12:19:52 -05:00
|
|
|
openstackStateDiskPath = "/dev/vdb"
|
2022-04-05 09:12:20 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
func main() {
|
2024-03-06 05:01:13 -05:00
|
|
|
runErr := run()
|
|
|
|
if runErr == nil {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
syslogWriter, err := syslog.New(syslog.LOG_EMERG|syslog.LOG_KERN, "disk-mapper")
|
|
|
|
if err != nil {
|
|
|
|
os.Exit(1)
|
|
|
|
}
|
|
|
|
_ = syslogWriter.Err(runErr.Error())
|
|
|
|
_ = syslogWriter.Emerg("disk-mapper has failed. In most cases, this is due to a misconfiguration or transient error with the infrastructure.")
|
|
|
|
time.Sleep(time.Minute) // sleep to allow the message to be written to syslog and seen by the user
|
|
|
|
os.Exit(1)
|
|
|
|
}
|
|
|
|
|
|
|
|
func run() error {
|
2022-07-01 10:17:06 -04:00
|
|
|
csp := flag.String("csp", "", "Cloud Service Provider the image is running on")
|
2022-11-14 03:02:56 -05:00
|
|
|
verbosity := flag.Int("v", 0, logger.CmdLineVerbosityDescription)
|
2022-04-11 08:25:19 -04:00
|
|
|
|
2022-07-01 10:17:06 -04:00
|
|
|
flag.Parse()
|
2024-02-08 09:20:01 -05:00
|
|
|
log := logger.NewJSONLogger(logger.VerbosityFromInt(*verbosity))
|
|
|
|
log.With(slog.String("version", constants.BinaryVersion().String()), slog.String("cloudProvider", *csp)).
|
|
|
|
Info("Starting disk-mapper")
|
2022-04-21 10:28:47 -04:00
|
|
|
|
2023-03-09 03:47:28 -05:00
|
|
|
// set up quote issuer for aTLS connections
|
2023-03-29 03:30:13 -04:00
|
|
|
attestVariant, err := variant.FromString(os.Getenv(constants.AttestationVariant))
|
2023-03-09 03:47:28 -05:00
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Failed to parse attestation variant")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2023-03-09 03:47:28 -05:00
|
|
|
}
|
|
|
|
issuer, err := choose.Issuer(attestVariant, log)
|
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Failed to select issuer")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2023-03-09 03:47:28 -05:00
|
|
|
}
|
|
|
|
|
|
|
|
// set up metadata API
|
2022-04-11 08:25:19 -04:00
|
|
|
var diskPath string
|
2023-03-07 05:58:33 -05:00
|
|
|
var metadataClient setup.MetadataAPI
|
2022-10-21 09:04:34 -04:00
|
|
|
switch cloudprovider.FromString(*csp) {
|
|
|
|
case cloudprovider.AWS:
|
|
|
|
// on AWS Nitro platform, disks are attached over NVMe
|
|
|
|
// using udev rules, a symlink for our disk is created at /dev/sdb
|
|
|
|
diskPath, err = filepath.EvalSymlinks(awsStateDiskPath)
|
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Unable to resolve Azure state disk path")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-10-21 09:04:34 -04:00
|
|
|
}
|
2023-03-07 05:58:33 -05:00
|
|
|
metadataClient, err = awscloud.New(context.Background())
|
2022-10-21 09:04:34 -04:00
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Failed to set up AWS metadata client")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-10-21 09:04:34 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
case cloudprovider.Azure:
|
2022-07-04 06:59:43 -04:00
|
|
|
diskPath, err = filepath.EvalSymlinks(azureStateDiskPath)
|
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Unable to resolve Azure state disk path")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-07-04 06:59:43 -04:00
|
|
|
}
|
2023-03-07 05:58:33 -05:00
|
|
|
metadataClient, err = azurecloud.New(context.Background())
|
2022-04-11 08:25:19 -04:00
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Failed to set up Azure metadata client")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
2022-08-31 14:10:49 -04:00
|
|
|
|
2022-10-21 09:04:34 -04:00
|
|
|
case cloudprovider.GCP:
|
2022-07-04 06:59:43 -04:00
|
|
|
diskPath, err = filepath.EvalSymlinks(gcpStateDiskPath)
|
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error("Unable to resolve GCP state disk path")
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-07-04 06:59:43 -04:00
|
|
|
}
|
2022-11-09 08:43:48 -05:00
|
|
|
gcpMeta, err := gcpcloud.New(context.Background())
|
2022-04-11 08:25:19 -04:00
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error(("Failed to create GCP metadata client"))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
2022-11-09 08:43:48 -05:00
|
|
|
defer gcpMeta.Close()
|
2023-03-07 05:58:33 -05:00
|
|
|
metadataClient = gcpMeta
|
2022-04-11 08:25:19 -04:00
|
|
|
|
2023-02-27 12:19:52 -05:00
|
|
|
case cloudprovider.OpenStack:
|
|
|
|
diskPath = openstackStateDiskPath
|
2023-03-07 05:58:33 -05:00
|
|
|
metadataClient, err = openstack.New(context.Background())
|
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error(("Failed to create OpenStack metadata client"))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2023-03-07 05:58:33 -05:00
|
|
|
}
|
2023-03-01 04:39:32 -05:00
|
|
|
|
2022-10-21 09:04:34 -04:00
|
|
|
case cloudprovider.QEMU:
|
2022-04-21 10:28:47 -04:00
|
|
|
diskPath = qemuStateDiskPath
|
2023-03-07 05:58:33 -05:00
|
|
|
metadataClient = qemucloud.New()
|
2022-04-21 10:28:47 -04:00
|
|
|
|
|
|
|
default:
|
2024-02-08 09:20:01 -05:00
|
|
|
log.Error(fmt.Sprintf("CSP %s is not supported by Constellation", *csp))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-04-05 09:12:20 -04:00
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
// initialize device mapper
|
2023-07-17 07:55:31 -04:00
|
|
|
mapper, free, err := diskencryption.New(diskPath, log)
|
2022-04-05 09:12:20 -04:00
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error(("Failed to initialize device mapper"))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-04-05 09:12:20 -04:00
|
|
|
}
|
2023-07-17 07:55:31 -04:00
|
|
|
defer free()
|
2022-04-05 09:12:20 -04:00
|
|
|
|
2023-03-14 09:17:36 -04:00
|
|
|
// Use TDX if available
|
|
|
|
openDevice := vtpm.OpenVTPM
|
2023-03-20 06:15:57 -04:00
|
|
|
if attestVariant.OID().Equal(variant.QEMUTDX{}.OID()) {
|
2023-03-14 09:17:36 -04:00
|
|
|
openDevice = func() (io.ReadWriteCloser, error) {
|
|
|
|
return tdx.Open()
|
|
|
|
}
|
|
|
|
}
|
2022-04-11 08:25:19 -04:00
|
|
|
setupManger := setup.New(
|
2024-02-08 09:20:01 -05:00
|
|
|
log.WithGroup("setupManager"),
|
2022-04-11 08:25:19 -04:00
|
|
|
*csp,
|
2022-08-15 08:50:03 -04:00
|
|
|
diskPath,
|
2022-04-11 08:25:19 -04:00
|
|
|
afero.Afero{Fs: afero.NewOsFs()},
|
|
|
|
mapper,
|
|
|
|
setup.DiskMounter{},
|
2023-03-14 09:17:36 -04:00
|
|
|
openDevice,
|
2022-04-11 08:25:19 -04:00
|
|
|
)
|
|
|
|
|
2023-02-24 08:25:39 -05:00
|
|
|
if err := setupManger.LogDevices(); err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error(("Failed to log devices"))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2023-02-24 08:25:39 -05:00
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
// prepare the state disk
|
2023-07-18 10:20:03 -04:00
|
|
|
if mapper.IsInitialized() {
|
2022-09-08 08:45:27 -04:00
|
|
|
// set up rejoin client
|
|
|
|
var self metadata.InstanceMetadata
|
2023-03-07 05:58:33 -05:00
|
|
|
self, err = metadataClient.Self(context.Background())
|
2022-09-08 08:45:27 -04:00
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error(("Failed to get self metadata"))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-09-08 08:45:27 -04:00
|
|
|
}
|
|
|
|
rejoinClient := rejoinclient.New(
|
|
|
|
dialer.New(issuer, nil, &net.Dialer{}),
|
|
|
|
self,
|
2023-03-07 05:58:33 -05:00
|
|
|
metadataClient,
|
2024-02-08 09:20:01 -05:00
|
|
|
log.WithGroup("rejoinClient"),
|
2022-09-08 08:45:27 -04:00
|
|
|
)
|
|
|
|
|
2022-09-14 07:25:42 -04:00
|
|
|
// set up recovery server if control-plane node
|
|
|
|
var recoveryServer setup.RecoveryServer
|
|
|
|
if self.Role == role.ControlPlane {
|
2024-02-08 09:20:01 -05:00
|
|
|
recoveryServer = recoveryserver.New(issuer, kmssetup.KMS, log.WithGroup("recoveryServer"))
|
2022-09-14 07:25:42 -04:00
|
|
|
} else {
|
2024-02-08 09:20:01 -05:00
|
|
|
recoveryServer = recoveryserver.NewStub(log.WithGroup("recoveryServer"))
|
2022-09-14 07:25:42 -04:00
|
|
|
}
|
2022-09-08 08:45:27 -04:00
|
|
|
|
|
|
|
err = setupManger.PrepareExistingDisk(setup.NewNodeRecoverer(recoveryServer, rejoinClient))
|
2022-04-12 08:24:36 -04:00
|
|
|
} else {
|
2022-04-11 08:25:19 -04:00
|
|
|
err = setupManger.PrepareNewDisk()
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
|
|
|
if err != nil {
|
2024-02-08 09:20:01 -05:00
|
|
|
log.With(slog.Any("error", err)).Error(("Failed to prepare state disk"))
|
2024-03-06 05:01:13 -05:00
|
|
|
return err
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
2024-03-06 05:01:13 -05:00
|
|
|
return nil
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|