refactor(deploy)!: TUI
This commit is contained in:
37 files changed
+3622
-1303
No files matched your search
+200
-36
@@ -8,60 +8,105 @@ import (
|
||||
"io"
|
||||
"os"
|
||||
"strings"
|
||||
"time"
|
||||
|
||||
"felis.lolicon.best/internal/api"
|
||||
"felis.lolicon.best/internal/config"
|
||||
"felis.lolicon.best/internal/store"
|
||||
)
|
||||
|
||||
const defaultSetupConfigPath = "/etc/felis/felis.toml"
|
||||
const hostSetupConfigPath = "/etc/felis/felis.host.toml"
|
||||
const hostBootstrapDonePath = "/etc/felis/bootstrap.done"
|
||||
const hostBootstrapBinPath = "/usr/local/bin/felis"
|
||||
const hostBootstrapKubeconfigPath = "/etc/rancher/k3s/k3s.yaml"
|
||||
|
||||
var errHostBootstrapCancelled = errors.New("host bootstrap cancelled")
|
||||
|
||||
// cmdSetup is the normal first-run operator console. It is intentionally separate
|
||||
// from breakGlass: setup creates the initial Owner and optional web edge; breakGlass
|
||||
// is reserved for emergency local recovery/reset.
|
||||
func cmdSetup(args []string, stdout, stderr io.Writer) int {
|
||||
fs := flag.NewFlagSet("setup", flag.ContinueOnError)
|
||||
fs.SetOutput(stderr)
|
||||
cfgPath := fs.String("config", "/etc/felis/felis.toml", "path to felis.toml")
|
||||
cfgPath := fs.String("config", defaultSetupConfigPath, "path to felis.toml")
|
||||
if err := fs.Parse(args); err != nil {
|
||||
if errors.Is(err, flag.ErrHelp) {
|
||||
return 0
|
||||
}
|
||||
return 2
|
||||
}
|
||||
configFlagSet := false
|
||||
fs.Visit(func(f *flag.Flag) {
|
||||
if f.Name == "config" {
|
||||
configFlagSet = true
|
||||
}
|
||||
})
|
||||
|
||||
if os.Geteuid() != 0 {
|
||||
fmt.Fprintln(stderr, "felis setup: refused — the setup console must run as root (try: sudo felis setup)")
|
||||
return 1
|
||||
}
|
||||
|
||||
cfg, err := config.Load(*cfgPath)
|
||||
if err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
|
||||
ctx := context.Background()
|
||||
drv, err := store.Open(ctx, cfg.Database.URL)
|
||||
if err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: open database: %v\n", err)
|
||||
bootstrapped := false
|
||||
if shouldRunHostBootstrapBeforeConfig(configFlagSet) {
|
||||
if err := runHostBootstrapForSetup(ctx); err != nil {
|
||||
return reportHostBootstrapError(err, stdout, stderr)
|
||||
}
|
||||
bootstrapped = true
|
||||
}
|
||||
if err := repairDefaultSetupConfig(configFlagSet); err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: repair default config: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
defer drv.Close()
|
||||
|
||||
repo := api.NewPGRepo(drv.DB())
|
||||
adminExists, err := repo.AdminExists(ctx)
|
||||
effectiveCfgPath := setupConfigPath(*cfgPath, configFlagSet)
|
||||
setup, err := openConfiguredSetup(ctx, effectiveCfgPath)
|
||||
if err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: detect existing admin: %v\n", err)
|
||||
return 1
|
||||
if bootstrapped || !shouldRunHostBootstrap(effectiveCfgPath, configFlagSet, err) {
|
||||
fmt.Fprintf(stderr, "felis setup: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
if err := runHostBootstrapForSetup(ctx); err != nil {
|
||||
return reportHostBootstrapError(err, stdout, stderr)
|
||||
}
|
||||
bootstrapped = true
|
||||
if err := repairDefaultSetupConfig(configFlagSet); err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: repair default config: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
effectiveCfgPath = setupConfigPath(*cfgPath, configFlagSet)
|
||||
setup, err = openConfiguredSetup(ctx, effectiveCfgPath)
|
||||
if err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: after bootstrap: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
}
|
||||
defer setup.drv.Close()
|
||||
|
||||
res, err := runSetupTUI(ctx, repo, cfg.Server.RootDomain, cfg.Auth.AdminHostname, cfg.Auth.PanelHostname, accountableOSUser(), adminExists)
|
||||
res, err := runSetupTUI(ctx, setup.repo, setup.cfg.Database.URL, setup.cfg.Server.RootDomain, setup.cfg.Auth.AdminHostname, setup.cfg.Auth.PanelHostname, accountableOSUser(), setup.adminExists)
|
||||
if err != nil {
|
||||
fmt.Fprintf(stderr, "felis setup: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
panelURL := res.panelURL
|
||||
if panelURL == "" {
|
||||
panelURL = localPanelURL(setup.cfg.Server.RootDomain)
|
||||
}
|
||||
|
||||
if !res.provisioned && !res.edgeConfigured {
|
||||
if bootstrapped {
|
||||
fmt.Fprintln(stdout, "felis setup: host bootstrap completed; Owner/edge setup skipped.")
|
||||
if panelURL != "" {
|
||||
fmt.Fprintf(stdout, "Panel: %s\n", panelURL)
|
||||
fmt.Fprintln(stdout, "The local HTTPS certificate is self-signed; your browser may ask for confirmation on first visit.")
|
||||
}
|
||||
return 0
|
||||
}
|
||||
fmt.Fprintln(stdout, "felis setup: cancelled — no changes made.")
|
||||
if panelURL != "" {
|
||||
fmt.Fprintf(stdout, "Panel: %s\n", panelURL)
|
||||
}
|
||||
return 0
|
||||
}
|
||||
|
||||
@@ -76,8 +121,9 @@ func cmdSetup(args []string, stdout, stderr io.Writer) int {
|
||||
if res.auditWarning != "" {
|
||||
fmt.Fprintf(stdout, "WARNING: the accountability audit row was NOT written: %s\n", res.auditWarning)
|
||||
}
|
||||
if url := adminLoginURL(res.rootDomain, res.adminHostname); url != "" {
|
||||
fmt.Fprintf(stdout, "Log in at %s with that username and password.\n", url)
|
||||
if panelURL != "" {
|
||||
fmt.Fprintf(stdout, "Log in at %s with that username and password.\n", panelURL)
|
||||
fmt.Fprintln(stdout, "The local HTTPS certificate is self-signed; your browser may ask for confirmation on first visit.")
|
||||
}
|
||||
}
|
||||
|
||||
@@ -89,27 +135,145 @@ func cmdSetup(args []string, stdout, stderr io.Writer) int {
|
||||
if res.edgeConfigPath != "" {
|
||||
fmt.Fprintf(stdout, "Wrote tunnel config: %s\n", res.edgeConfigPath)
|
||||
}
|
||||
fmt.Fprintf(stdout, "\nACTION REQUIRED — make felis-api trust the edge:\n")
|
||||
fmt.Fprintf(stdout, " in %s under [auth], set:\n", *cfgPath)
|
||||
if res.edgePanelHostname != "" {
|
||||
fmt.Fprintf(stdout, " panel_hostname = %q\n", res.edgePanelHostname)
|
||||
}
|
||||
if res.edgeAdminHostname != "" {
|
||||
fmt.Fprintf(stdout, " admin_hostname = %q\n", res.edgeAdminHostname)
|
||||
}
|
||||
fmt.Fprintf(stdout, " access_jwt_aud = %q\n", res.edgeAud)
|
||||
fmt.Fprintln(stdout, "Then start the tunnel: cloudflared tunnel run")
|
||||
fmt.Fprintln(stdout, "Verify the Access app actually guards the admin face before relying on it.")
|
||||
fmt.Fprintln(stdout, "Felis config, Kubernetes Secret, API rollout and cloudflared service were updated.")
|
||||
}
|
||||
return 0
|
||||
}
|
||||
|
||||
func adminLoginURL(rootDomain, adminHostname string) string {
|
||||
if h := strings.TrimSpace(adminHostname); h != "" {
|
||||
return "https://" + h
|
||||
type configuredSetup struct {
|
||||
cfg *config.Config
|
||||
drv *store.PostgresDriver
|
||||
repo *api.PGRepo
|
||||
adminExists bool
|
||||
}
|
||||
|
||||
type setupOpenError struct {
|
||||
stage string
|
||||
err error
|
||||
}
|
||||
|
||||
func (e *setupOpenError) Error() string {
|
||||
return e.stage + ": " + e.err.Error()
|
||||
}
|
||||
|
||||
func (e *setupOpenError) Unwrap() error {
|
||||
return e.err
|
||||
}
|
||||
|
||||
func openConfiguredSetup(ctx context.Context, cfgPath string) (*configuredSetup, error) {
|
||||
cfg, err := config.Load(cfgPath)
|
||||
if err != nil {
|
||||
return nil, &setupOpenError{stage: "load config", err: err}
|
||||
}
|
||||
if rootDomain != "" {
|
||||
return "https://op.console." + rootDomain
|
||||
drv, err := store.Open(ctx, cfg.Database.URL)
|
||||
if err != nil {
|
||||
return nil, &setupOpenError{stage: "open database", err: err}
|
||||
}
|
||||
return ""
|
||||
repo := api.NewPGRepo(drv.DB())
|
||||
adminExists, err := repo.AdminExists(ctx)
|
||||
if err != nil {
|
||||
drv.Close()
|
||||
return nil, &setupOpenError{stage: "detect existing admin", err: err}
|
||||
}
|
||||
return &configuredSetup{cfg: cfg, drv: drv, repo: repo, adminExists: adminExists}, nil
|
||||
}
|
||||
|
||||
func setupConfigPath(requested string, configFlagSet bool) string {
|
||||
return setupConfigPathFor(requested, hostSetupConfigPath, configFlagSet)
|
||||
}
|
||||
|
||||
func setupConfigPathFor(requested, host string, configFlagSet bool) string {
|
||||
if configFlagSet {
|
||||
return requested
|
||||
}
|
||||
if _, err := os.Stat(host); err == nil {
|
||||
return host
|
||||
}
|
||||
return requested
|
||||
}
|
||||
|
||||
func repairDefaultSetupConfig(configFlagSet bool) error {
|
||||
if configFlagSet {
|
||||
return nil
|
||||
}
|
||||
if _, err := os.Stat(hostSetupConfigPath); err != nil {
|
||||
return nil
|
||||
}
|
||||
return ensureDefaultConfigLink(defaultSetupConfigPath, hostSetupConfigPath)
|
||||
}
|
||||
|
||||
func ensureDefaultConfigLink(target, host string) error {
|
||||
if link, err := os.Readlink(target); err == nil && link == host {
|
||||
return nil
|
||||
}
|
||||
if _, err := os.Lstat(target); err != nil {
|
||||
if errors.Is(err, os.ErrNotExist) {
|
||||
return os.Symlink(host, target)
|
||||
}
|
||||
return err
|
||||
}
|
||||
backup := fmt.Sprintf("%s.bak.%s.%d", target, time.Now().UTC().Format("20060102150405"), os.Getpid())
|
||||
if err := os.Rename(target, backup); err != nil {
|
||||
return err
|
||||
}
|
||||
return os.Symlink(host, target)
|
||||
}
|
||||
|
||||
func shouldRunHostBootstrap(cfgPath string, configFlagSet bool, err error) bool {
|
||||
if configFlagSet {
|
||||
return false
|
||||
}
|
||||
var setupErr *setupOpenError
|
||||
if !errors.As(err, &setupErr) {
|
||||
return false
|
||||
}
|
||||
if setupErr.stage == "open database" {
|
||||
return true
|
||||
}
|
||||
if setupErr.stage != "load config" {
|
||||
return false
|
||||
}
|
||||
_, statErr := os.Stat(cfgPath)
|
||||
return errors.Is(statErr, os.ErrNotExist)
|
||||
}
|
||||
|
||||
func shouldRunHostBootstrapBeforeConfig(configFlagSet bool) bool {
|
||||
if configFlagSet {
|
||||
return false
|
||||
}
|
||||
return !hostBootstrapReady(hostBootstrapDonePath, hostSetupConfigPath, hostBootstrapBinPath, hostBootstrapKubeconfigPath)
|
||||
}
|
||||
|
||||
func hostBootstrapReady(marker, hostConfig, hostBin, kubeconfig string) bool {
|
||||
return fileExists(marker) && fileExists(hostConfig) && executableExists(hostBin) && fileExists(kubeconfig)
|
||||
}
|
||||
|
||||
func fileExists(path string) bool {
|
||||
info, err := os.Stat(path)
|
||||
return err == nil && !info.IsDir()
|
||||
}
|
||||
|
||||
func executableExists(path string) bool {
|
||||
info, err := os.Stat(path)
|
||||
return err == nil && !info.IsDir() && info.Mode()&0o111 != 0
|
||||
}
|
||||
|
||||
func runHostBootstrapForSetup(ctx context.Context) error {
|
||||
completed, err := runHostBootstrapTUI(ctx)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if !completed {
|
||||
return errHostBootstrapCancelled
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func reportHostBootstrapError(err error, stdout, stderr io.Writer) int {
|
||||
if errors.Is(err, errHostBootstrapCancelled) {
|
||||
fmt.Fprintln(stdout, "felis setup: cancelled — bootstrap not run.")
|
||||
return 0
|
||||
}
|
||||
fmt.Fprintf(stderr, "felis setup: bootstrap: %v\n", err)
|
||||
return 1
|
||||
}
|
||||
Reference in new issue
Block a user