2022-09-05 09:06:08 +02:00
/ *
Copyright ( c ) Edgeless Systems GmbH
SPDX - License - Identifier : AGPL - 3.0 - only
* /
2022-08-01 09:37:05 +02:00
package cmd
import (
"context"
2023-02-07 12:56:25 +01:00
"errors"
2022-08-01 09:37:05 +02:00
"fmt"
"net/http"
"net/url"
"time"
2023-06-07 16:16:32 +02:00
"github.com/edgelesssys/constellation/v2/internal/api/attestationconfigapi"
"github.com/edgelesssys/constellation/v2/internal/api/versionsapi"
2022-11-15 15:40:49 +01:00
"github.com/edgelesssys/constellation/v2/internal/attestation/measurements"
2023-11-28 17:30:11 +01:00
"github.com/edgelesssys/constellation/v2/internal/attestation/variant"
"github.com/edgelesssys/constellation/v2/internal/cloud/cloudprovider"
2022-09-21 13:47:57 +02:00
"github.com/edgelesssys/constellation/v2/internal/config"
2023-08-04 13:53:51 +02:00
"github.com/edgelesssys/constellation/v2/internal/constants"
2023-12-08 16:27:04 +01:00
"github.com/edgelesssys/constellation/v2/internal/constellation/featureset"
2022-09-21 13:47:57 +02:00
"github.com/edgelesssys/constellation/v2/internal/file"
2022-10-11 13:57:52 +02:00
"github.com/edgelesssys/constellation/v2/internal/sigstore"
2022-08-01 09:37:05 +02:00
"github.com/spf13/afero"
"github.com/spf13/cobra"
2023-10-16 15:05:29 +02:00
"github.com/spf13/pflag"
2022-08-01 09:37:05 +02:00
)
func newConfigFetchMeasurementsCmd ( ) * cobra . Command {
cmd := & cobra . Command {
Use : "fetch-measurements" ,
Short : "Fetch measurements for configured cloud provider and image" ,
2023-01-17 14:01:56 +01:00
Long : "Fetch measurements for configured cloud provider and image.\n\n" +
"A config needs to be generated first." ,
Args : cobra . ExactArgs ( 0 ) ,
RunE : runConfigFetchMeasurements ,
2022-08-01 09:37:05 +02:00
}
cmd . Flags ( ) . StringP ( "url" , "u" , "" , "alternative URL to fetch measurements from" )
cmd . Flags ( ) . StringP ( "signature-url" , "s" , "" , "alternative URL to fetch measurements' signature from" )
2023-06-06 10:32:22 +02:00
cmd . Flags ( ) . Bool ( "insecure" , false , "skip the measurement signature verification" )
2023-06-09 10:49:28 +02:00
must ( cmd . Flags ( ) . MarkHidden ( "insecure" ) )
2022-08-01 09:37:05 +02:00
return cmd
}
type fetchMeasurementsFlags struct {
2023-10-16 15:05:29 +02:00
rootFlags
2022-08-01 09:37:05 +02:00
measurementsURL * url . URL
signatureURL * url . URL
2023-06-06 10:32:22 +02:00
insecure bool
2023-10-16 15:05:29 +02:00
}
func ( f * fetchMeasurementsFlags ) parse ( flags * pflag . FlagSet ) error {
var err error
if err := f . rootFlags . parse ( flags ) ; err != nil {
return err
}
f . measurementsURL , err = parseURLFlag ( flags , "url" )
if err != nil {
return err
}
f . signatureURL , err = parseURLFlag ( flags , "signature-url" )
if err != nil {
return err
}
f . insecure , err = flags . GetBool ( "insecure" )
if err != nil {
return fmt . Errorf ( "getting 'insecure' flag: %w" , err )
}
return nil
2022-08-01 09:37:05 +02:00
}
2023-11-28 17:30:11 +01:00
type verifyFetcher interface {
FetchAndVerifyMeasurements ( ctx context . Context ,
image string , csp cloudprovider . Provider , attestationVariant variant . Variant ,
noVerify bool ,
) ( measurements . M , error )
}
2023-01-04 09:46:29 +00:00
type configFetchMeasurementsCmd struct {
2023-10-16 15:05:29 +02:00
flags fetchMeasurementsFlags
2023-05-26 17:50:55 +02:00
canFetchMeasurements bool
log debugLog
2023-11-28 17:30:11 +01:00
verifyFetcher verifyFetcher
2023-01-04 09:46:29 +00:00
}
2023-03-20 11:03:36 +01:00
func runConfigFetchMeasurements ( cmd * cobra . Command , _ [ ] string ) error {
2023-01-04 09:46:29 +00:00
log , err := newCLILogger ( cmd )
if err != nil {
return fmt . Errorf ( "creating logger: %w" , err )
}
2022-08-01 09:37:05 +02:00
fileHandler := file . NewHandler ( afero . NewOsFs ( ) )
2022-10-11 13:57:52 +02:00
rekor , err := sigstore . NewRekor ( )
if err != nil {
return fmt . Errorf ( "constructing Rekor client: %w" , err )
}
2023-11-28 17:30:11 +01:00
verifyFetcher := measurements . NewVerifyFetcher ( sigstore . NewCosignVerifier , rekor , http . DefaultClient )
cfm := & configFetchMeasurementsCmd { log : log , canFetchMeasurements : featureset . CanFetchMeasurements , verifyFetcher : verifyFetcher }
2023-10-16 15:05:29 +02:00
if err := cfm . flags . parse ( cmd . Flags ( ) ) ; err != nil {
return fmt . Errorf ( "parsing flags: %w" , err )
}
2024-04-03 13:49:03 +00:00
cfm . log . Debug ( "Using flags" , "insecure" , cfm . flags . insecure , "measurementsURL" , cfm . flags . measurementsURL , "signatureURL" , cfm . flags . signatureURL )
2023-01-04 09:46:29 +00:00
2023-09-25 11:53:02 +02:00
fetcher := attestationconfigapi . NewFetcherWithClient ( http . DefaultClient , constants . CDNRepositoryURL )
2023-11-28 17:30:11 +01:00
return cfm . configFetchMeasurements ( cmd , fileHandler , fetcher )
2022-08-01 09:37:05 +02:00
}
2023-01-04 09:46:29 +00:00
func ( cfm * configFetchMeasurementsCmd ) configFetchMeasurements (
2023-11-28 17:30:11 +01:00
cmd * cobra . Command , fileHandler file . Handler , fetcher attestationconfigapi . Fetcher ,
2022-11-28 10:27:33 +01:00
) error {
2023-05-26 17:50:55 +02:00
if ! cfm . canFetchMeasurements {
cmd . PrintErrln ( "Fetching measurements is not supported in the OSS build of the Constellation CLI. Consult the documentation for instructions on where to download the enterprise version." )
return errors . New ( "fetching measurements is not supported" )
}
2024-02-08 14:20:01 +00:00
cfm . log . Debug ( fmt . Sprintf ( "Loading configuration file from %q" , cfm . flags . pathPrefixer . PrefixPrintablePath ( constants . ConfigFilename ) ) )
2023-06-01 13:55:46 +02:00
2023-10-16 15:05:29 +02:00
conf , err := config . New ( fileHandler , constants . ConfigFilename , fetcher , cfm . flags . force )
2023-02-07 12:56:25 +01:00
var configValidationErr * config . ValidationError
if errors . As ( err , & configValidationErr ) {
cmd . PrintErrln ( configValidationErr . LongMessage ( ) )
}
2022-08-01 09:37:05 +02:00
if err != nil {
2023-02-07 12:56:25 +01:00
return err
2022-08-01 09:37:05 +02:00
}
2022-11-22 18:47:08 +01:00
if ! conf . IsReleaseImage ( ) {
2022-11-10 10:27:24 +01:00
cmd . PrintErrln ( "Configured image doesn't look like a released production image. Double check image before deploying to production." )
2022-08-16 15:53:54 +02:00
}
2024-02-08 14:20:01 +00:00
cfm . log . Debug ( "Creating context" )
2022-11-22 18:47:08 +01:00
ctx , cancel := context . WithTimeout ( context . Background ( ) , time . Minute )
defer cancel ( )
2024-02-08 14:20:01 +00:00
cfm . log . Debug ( "Updating URLs" )
2023-10-16 15:05:29 +02:00
if err := cfm . flags . updateURLs ( conf ) ; err != nil {
2022-08-01 09:37:05 +02:00
return err
}
2023-11-28 17:30:11 +01:00
fetchedMeasurements , err := cfm . verifyFetcher . FetchAndVerifyMeasurements ( ctx , conf . Image , conf . GetProvider ( ) ,
conf . GetAttestationConfig ( ) . GetVariant ( ) , cfm . flags . insecure )
2023-05-22 14:59:28 +02:00
if err != nil {
2023-11-28 17:30:11 +01:00
var rekorErr * measurements . RekorError
if errors . As ( err , & rekorErr ) {
2023-06-06 10:32:22 +02:00
cmd . PrintErrf ( "Ignoring Rekor related error: %v\n" , err )
cmd . PrintErrln ( "Make sure the downloaded measurements are trustworthy!" )
2023-11-28 17:30:11 +01:00
} else {
return fmt . Errorf ( "fetching and verifying measurements: %w" , err )
2023-06-06 10:32:22 +02:00
}
}
2024-04-03 13:49:03 +00:00
cfm . log . Debug ( fmt . Sprintf ( "Measurements: %s" , fetchedMeasurements . String ( ) ) )
2023-06-06 10:32:22 +02:00
2024-02-08 14:20:01 +00:00
cfm . log . Debug ( "Updating measurements in configuration" )
2022-08-01 09:37:05 +02:00
conf . UpdateMeasurements ( fetchedMeasurements )
2023-08-04 13:53:51 +02:00
if err := fileHandler . WriteYAML ( constants . ConfigFilename , conf , file . OptOverwrite ) ; err != nil {
2022-08-01 09:37:05 +02:00
return err
}
2024-04-03 13:49:03 +00:00
cfm . log . Debug ( fmt . Sprintf ( "Configuration written to %q" , cfm . flags . pathPrefixer . PrefixPrintablePath ( constants . ConfigFilename ) ) )
2023-06-19 16:51:39 +02:00
cmd . Print ( "Successfully fetched measurements and updated Configuration\n" )
2022-08-01 09:37:05 +02:00
return nil
}
2022-11-28 10:27:33 +01:00
func ( f * fetchMeasurementsFlags ) updateURLs ( conf * config . Config ) error {
2023-02-03 10:05:42 +00:00
ver , err := versionsapi . NewVersionFromShortPath ( conf . Image , versionsapi . VersionKindImage )
if err != nil {
return fmt . Errorf ( "creating version from image name: %w" , err )
}
2023-05-22 14:59:28 +02:00
measurementsURL , signatureURL , err := versionsapi . MeasurementURL ( ver )
2023-02-03 10:05:42 +00:00
if err != nil {
return err
}
2022-08-01 09:37:05 +02:00
if f . measurementsURL == nil {
2023-02-03 10:05:42 +00:00
f . measurementsURL = measurementsURL
2022-08-01 09:37:05 +02:00
}
if f . signatureURL == nil {
2023-02-03 10:05:42 +00:00
f . signatureURL = signatureURL
2022-08-01 09:37:05 +02:00
}
return nil
}
2023-05-26 17:49:46 +02:00
2023-10-16 15:05:29 +02:00
// parseURLFlag checks that flag can be parsed as URL.
// If no value was provided for flag, nil is returned.
func parseURLFlag ( flags * pflag . FlagSet , flag string ) ( * url . URL , error ) {
rawURL , err := flags . GetString ( flag )
if err != nil {
return nil , fmt . Errorf ( "getting '%s' flag: %w" , flag , err )
}
if rawURL != "" {
return url . Parse ( rawURL )
}
return nil , nil
}
2023-05-26 17:49:46 +02:00
type rekorVerifier interface {
SearchByHash ( context . Context , string ) ( [ ] string , error )
VerifyEntry ( context . Context , string , string ) error
}