2022-05-10 06:35:17 -04:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
2022-04-12 10:07:17 -04:00
|
|
|
"errors"
|
2022-05-10 06:35:17 -04:00
|
|
|
"flag"
|
2022-04-12 10:07:17 -04:00
|
|
|
"fmt"
|
2022-05-10 06:35:17 -04:00
|
|
|
"net"
|
|
|
|
|
2022-04-12 10:07:17 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/constants"
|
|
|
|
"github.com/edgelesssys/constellation/internal/file"
|
2022-06-28 10:51:30 -04:00
|
|
|
"github.com/edgelesssys/constellation/internal/logger"
|
2022-05-10 06:35:17 -04:00
|
|
|
"github.com/edgelesssys/constellation/kms/server/kmsapi"
|
|
|
|
"github.com/edgelesssys/constellation/kms/server/kmsapi/kmsproto"
|
|
|
|
"github.com/edgelesssys/constellation/kms/server/setup"
|
2022-04-12 10:07:17 -04:00
|
|
|
"github.com/spf13/afero"
|
2022-05-10 06:35:17 -04:00
|
|
|
"go.uber.org/zap"
|
2022-06-28 10:51:30 -04:00
|
|
|
"go.uber.org/zap/zapcore"
|
2022-05-10 06:35:17 -04:00
|
|
|
|
|
|
|
"google.golang.org/grpc"
|
|
|
|
)
|
|
|
|
|
|
|
|
func main() {
|
2022-06-15 10:00:48 -04:00
|
|
|
port := flag.String("port", "9000", "Port gRPC server listens on")
|
2022-04-12 10:07:17 -04:00
|
|
|
masterSecretPath := flag.String("master-secret", "/constellation/constellation-mastersecret.base64", "Path to the Constellation master secret")
|
2022-06-15 10:00:48 -04:00
|
|
|
|
2022-05-10 06:35:17 -04:00
|
|
|
flag.Parse()
|
2022-06-15 10:00:48 -04:00
|
|
|
|
2022-06-28 10:51:30 -04:00
|
|
|
log := logger.New(logger.JSONLog, zapcore.InfoLevel)
|
|
|
|
|
|
|
|
log.With(zap.String("version", constants.VersionInfo)).Infof("Constellation Key Management Service")
|
2022-05-10 06:35:17 -04:00
|
|
|
|
2022-04-12 10:07:17 -04:00
|
|
|
masterKey, err := readMainSecret(*masterSecretPath)
|
2022-05-10 06:35:17 -04:00
|
|
|
if err != nil {
|
2022-06-28 10:51:30 -04:00
|
|
|
log.With(zap.Error(err)).Fatalf("Failed to read master secret")
|
2022-05-10 06:35:17 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
conKMS, err := setup.SetUpKMS(context.Background(), setup.NoStoreURI, setup.ClusterKMSURI)
|
|
|
|
if err != nil {
|
2022-06-28 10:51:30 -04:00
|
|
|
log.With(zap.Error(err)).Fatalf("Failed to setup KMS")
|
2022-05-10 06:35:17 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
if err := conKMS.CreateKEK(context.Background(), "Constellation", masterKey); err != nil {
|
2022-06-28 10:51:30 -04:00
|
|
|
log.With(zap.Error(err)).Fatalf("Failed to create KMS KEK from MasterKey")
|
2022-05-10 06:35:17 -04:00
|
|
|
}
|
|
|
|
|
2022-06-15 10:00:48 -04:00
|
|
|
lis, err := net.Listen("tcp", net.JoinHostPort("", *port))
|
2022-05-10 06:35:17 -04:00
|
|
|
if err != nil {
|
2022-06-28 10:51:30 -04:00
|
|
|
log.With(zap.Error(err)).Fatalf("Failed to listen")
|
2022-05-10 06:35:17 -04:00
|
|
|
}
|
|
|
|
|
2022-06-28 10:51:30 -04:00
|
|
|
srv := kmsapi.New(log.Named("server"), conKMS)
|
2022-05-10 06:35:17 -04:00
|
|
|
|
2022-06-28 10:51:30 -04:00
|
|
|
log.Named("gRPC").WithIncreasedLevel(zapcore.WarnLevel).ReplaceGRPCLogger()
|
2022-05-10 06:35:17 -04:00
|
|
|
// TODO: Launch server with aTLS to allow attestation for clients.
|
2022-06-28 10:51:30 -04:00
|
|
|
grpcServer := grpc.NewServer(log.Named("gRPC").GetServerUnaryInterceptor())
|
2022-05-10 06:35:17 -04:00
|
|
|
|
|
|
|
kmsproto.RegisterAPIServer(grpcServer, srv)
|
|
|
|
|
2022-06-28 10:51:30 -04:00
|
|
|
log.Infof("Starting key management service on %s", lis.Addr().String())
|
2022-05-10 06:35:17 -04:00
|
|
|
if err := grpcServer.Serve(lis); err != nil {
|
2022-06-28 10:51:30 -04:00
|
|
|
log.With(zap.Error(err)).Fatalf("Failed to serve")
|
2022-05-10 06:35:17 -04:00
|
|
|
}
|
|
|
|
}
|
2022-04-12 10:07:17 -04:00
|
|
|
|
|
|
|
// readMainSecret reads the base64 encoded main secret file from specified path and returns the secret as bytes.
|
|
|
|
func readMainSecret(fileName string) ([]byte, error) {
|
|
|
|
if fileName == "" {
|
|
|
|
return nil, errors.New("no filename to master secret provided")
|
|
|
|
}
|
|
|
|
|
|
|
|
fileHandler := file.NewHandler(afero.NewOsFs())
|
|
|
|
|
|
|
|
secretBytes, err := fileHandler.Read(fileName)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
if len(secretBytes) < constants.MasterSecretLengthMin {
|
|
|
|
return nil, fmt.Errorf("provided master secret is smaller than the required minimum of %d bytes", constants.MasterSecretLengthMin)
|
|
|
|
}
|
|
|
|
|
|
|
|
return secretBytes, nil
|
|
|
|
}
|