2022-04-05 09:12:20 -04:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
2022-04-11 08:25:19 -04:00
|
|
|
"context"
|
2022-04-05 09:12:20 -04:00
|
|
|
"flag"
|
2022-04-11 08:25:19 -04:00
|
|
|
"fmt"
|
2022-04-21 10:28:47 -04:00
|
|
|
"log"
|
2022-04-05 09:12:20 -04:00
|
|
|
"os"
|
|
|
|
"path/filepath"
|
2022-04-11 08:25:19 -04:00
|
|
|
"strings"
|
|
|
|
"time"
|
2022-04-05 09:12:20 -04:00
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
"github.com/edgelesssys/constellation/coordinator/attestation/azure"
|
|
|
|
"github.com/edgelesssys/constellation/coordinator/attestation/gcp"
|
2022-04-21 10:28:47 -04:00
|
|
|
"github.com/edgelesssys/constellation/coordinator/attestation/qemu"
|
2022-04-11 08:25:19 -04:00
|
|
|
"github.com/edgelesssys/constellation/coordinator/attestation/vtpm"
|
|
|
|
azurecloud "github.com/edgelesssys/constellation/coordinator/cloudprovider/azure"
|
|
|
|
gcpcloud "github.com/edgelesssys/constellation/coordinator/cloudprovider/gcp"
|
|
|
|
"github.com/edgelesssys/constellation/coordinator/core"
|
2022-04-12 08:24:36 -04:00
|
|
|
"github.com/edgelesssys/constellation/state/keyservice"
|
2022-04-05 09:12:20 -04:00
|
|
|
"github.com/edgelesssys/constellation/state/mapper"
|
2022-04-11 08:25:19 -04:00
|
|
|
"github.com/edgelesssys/constellation/state/setup"
|
|
|
|
"github.com/spf13/afero"
|
2022-04-05 09:12:20 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
const (
|
2022-04-11 08:25:19 -04:00
|
|
|
gcpStateDiskPath = "/dev/disk/by-id/google-state-disk"
|
|
|
|
azureStateDiskPath = "/dev/disk/azure/scsi1/lun0"
|
2022-04-21 10:28:47 -04:00
|
|
|
qemuStateDiskPath = "/dev/vda"
|
2022-04-05 09:12:20 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
var csp = flag.String("csp", "", "Cloud Service Provider the image is running on")
|
|
|
|
|
|
|
|
func main() {
|
|
|
|
flag.Parse()
|
2022-04-11 08:25:19 -04:00
|
|
|
|
2022-04-21 10:28:47 -04:00
|
|
|
log.Printf("Starting disk-mapper for csp %q\n", *csp)
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
// set up metadata API and quote issuer for aTLS connections
|
|
|
|
var err error
|
|
|
|
var diskPathErr error
|
|
|
|
var diskPath string
|
|
|
|
var issuer core.QuoteIssuer
|
|
|
|
var metadata core.ProviderMetadata
|
|
|
|
switch strings.ToLower(*csp) {
|
|
|
|
case "azure":
|
|
|
|
diskPath, diskPathErr = filepath.EvalSymlinks(azureStateDiskPath)
|
|
|
|
metadata, err = azurecloud.NewMetadata(context.Background())
|
|
|
|
if err != nil {
|
2022-04-28 08:44:09 -04:00
|
|
|
exit(err)
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
|
|
|
issuer = azure.NewIssuer()
|
|
|
|
|
|
|
|
case "gcp":
|
|
|
|
diskPath, diskPathErr = filepath.EvalSymlinks(gcpStateDiskPath)
|
|
|
|
issuer = gcp.NewIssuer()
|
|
|
|
gcpClient, err := gcpcloud.NewClient(context.Background())
|
|
|
|
if err != nil {
|
2022-04-28 08:44:09 -04:00
|
|
|
exit(err)
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
|
|
|
metadata = gcpcloud.New(gcpClient)
|
|
|
|
|
2022-04-21 10:28:47 -04:00
|
|
|
case "qemu":
|
|
|
|
diskPath = qemuStateDiskPath
|
|
|
|
issuer = qemu.NewIssuer()
|
|
|
|
fmt.Fprintf(os.Stderr, "warning: cloud services are not supported for csp %q\n", *csp)
|
2022-04-11 08:25:19 -04:00
|
|
|
metadata = &core.ProviderMetadataFake{}
|
2022-04-21 10:28:47 -04:00
|
|
|
|
|
|
|
default:
|
|
|
|
diskPathErr = fmt.Errorf("csp %q is not supported by Constellation", *csp)
|
2022-04-11 08:25:19 -04:00
|
|
|
}
|
|
|
|
if diskPathErr != nil {
|
2022-04-28 08:44:09 -04:00
|
|
|
exit(fmt.Errorf("unable to determine state disk path: %w", diskPathErr))
|
2022-04-05 09:12:20 -04:00
|
|
|
}
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
// initialize device mapper
|
2022-04-05 09:12:20 -04:00
|
|
|
mapper, err := mapper.New(diskPath)
|
|
|
|
if err != nil {
|
2022-04-28 08:44:09 -04:00
|
|
|
exit(err)
|
2022-04-05 09:12:20 -04:00
|
|
|
}
|
|
|
|
defer mapper.Close()
|
|
|
|
|
2022-04-11 08:25:19 -04:00
|
|
|
setupManger := setup.New(
|
|
|
|
*csp,
|
|
|
|
afero.Afero{Fs: afero.NewOsFs()},
|
|
|
|
keyservice.New(issuer, metadata, 20*time.Second), // try to request a key every 20 seconds
|
|
|
|
mapper,
|
|
|
|
setup.DiskMounter{},
|
|
|
|
vtpm.OpenVTPM,
|
|
|
|
)
|
|
|
|
|
|
|
|
// prepare the state disk
|
2022-04-12 08:24:36 -04:00
|
|
|
if mapper.IsLUKSDevice() {
|
2022-04-11 08:25:19 -04:00
|
|
|
err = setupManger.PrepareExistingDisk()
|
2022-04-12 08:24:36 -04:00
|
|
|
} else {
|
2022-04-11 08:25:19 -04:00
|
|
|
err = setupManger.PrepareNewDisk()
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
2022-04-28 08:44:09 -04:00
|
|
|
exit(err)
|
|
|
|
}
|
2022-04-12 08:24:36 -04:00
|
|
|
|
2022-04-28 08:44:09 -04:00
|
|
|
func exit(err error) {
|
2022-04-12 08:24:36 -04:00
|
|
|
if err != nil {
|
2022-05-10 04:47:22 -04:00
|
|
|
fmt.Fprintln(os.Stderr, err.Error())
|
2022-04-28 08:44:09 -04:00
|
|
|
os.Exit(1)
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|
2022-04-28 08:44:09 -04:00
|
|
|
os.Exit(0)
|
2022-04-12 08:24:36 -04:00
|
|
|
}
|