Files
kubesolo-os/cloud-init/cmd/main.go
Adolfo Delorenzo 49a37e30e8 feat: add production hardening — Ed25519 signing, Portainer Edge, SSH extension (Phase 4)
Image signing:
- Ed25519 sign/verify package (pure Go stdlib, zero deps)
- genkey and sign CLI subcommands for build system
- Optional --pubkey flag for verifying updates on apply
- Signature URLs in update metadata (latest.json)

Portainer Edge Agent:
- cloud-init portainer.go module writes K8s manifest
- Auto-deploys Edge Agent when portainer.edge-agent.enabled
- Full RBAC (ServiceAccount, ClusterRoleBinding, Deployment)
- 5 Portainer tests in portainer_test.go

Production tooling:
- SSH debug extension builder (hack/build-ssh-extension.sh)
- Boot performance benchmark (test/benchmark/bench-boot.sh)
- Resource usage benchmark (test/benchmark/bench-resources.sh)
- Deployment guide (docs/deployment-guide.md)

Test results: 50 update agent tests + 22 cloud-init tests passing.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-11 11:26:23 -06:00

138 lines
3.3 KiB
Go

// kubesolo-cloudinit is a lightweight cloud-init parser for KubeSolo OS.
//
// It reads a YAML configuration file and applies hostname, network, and
// KubeSolo settings during the init sequence. Designed to run as a static
// binary on BusyBox-based systems.
//
// Usage:
//
// kubesolo-cloudinit apply <config.yaml>
// kubesolo-cloudinit validate <config.yaml>
// kubesolo-cloudinit dump <config.yaml>
package main
import (
"encoding/json"
"fmt"
"log/slog"
"os"
cloudinit "github.com/portainer/kubesolo-os/cloud-init"
)
const (
defaultConfigPath = "/mnt/data/etc-kubesolo/cloud-init.yaml"
persistDataDir = "/mnt/data"
configDir = "/etc/kubesolo"
)
func main() {
// Set up structured logging to stderr (captured by init)
slog.SetDefault(slog.New(slog.NewTextHandler(os.Stderr, &slog.HandlerOptions{
Level: slog.LevelInfo,
})))
if len(os.Args) < 2 {
usage()
os.Exit(1)
}
cmd := os.Args[1]
// Determine config path
configPath := defaultConfigPath
if len(os.Args) >= 3 {
configPath = os.Args[2]
}
switch cmd {
case "apply":
if err := cmdApply(configPath); err != nil {
slog.Error("cloud-init apply failed", "error", err)
os.Exit(1)
}
case "validate":
if err := cmdValidate(configPath); err != nil {
fmt.Fprintf(os.Stderr, "validation failed: %s\n", err)
os.Exit(1)
}
fmt.Println("OK")
case "dump":
if err := cmdDump(configPath); err != nil {
fmt.Fprintf(os.Stderr, "error: %s\n", err)
os.Exit(1)
}
default:
fmt.Fprintf(os.Stderr, "unknown command: %s\n", cmd)
usage()
os.Exit(1)
}
}
func cmdApply(configPath string) error {
slog.Info("applying cloud-init", "config", configPath)
cfg, err := cloudinit.Parse(configPath)
if err != nil {
return err
}
// 1. Apply hostname
if err := cloudinit.ApplyHostname(cfg); err != nil {
return fmt.Errorf("hostname: %w", err)
}
// 2. Apply network configuration
if err := cloudinit.ApplyNetwork(cfg); err != nil {
return fmt.Errorf("network: %w", err)
}
// 3. Apply KubeSolo settings
if err := cloudinit.ApplyKubeSolo(cfg, configDir); err != nil {
return fmt.Errorf("kubesolo config: %w", err)
}
// 4. Apply Portainer Edge Agent manifest (if enabled)
if err := cloudinit.ApplyPortainer(cfg, "/var/lib/kubesolo/server/manifests"); err != nil {
return fmt.Errorf("portainer edge agent: %w", err)
}
// 5. Save persistent configs for next boot
if err := cloudinit.SaveHostname(cfg, persistDataDir+"/etc-kubesolo"); err != nil {
slog.Warn("failed to save hostname", "error", err)
}
if err := cloudinit.SaveNetworkConfig(cfg, persistDataDir+"/network"); err != nil {
slog.Warn("failed to save network config", "error", err)
}
slog.Info("cloud-init applied successfully")
return nil
}
func cmdValidate(configPath string) error {
_, err := cloudinit.Parse(configPath)
return err
}
func cmdDump(configPath string) error {
cfg, err := cloudinit.Parse(configPath)
if err != nil {
return err
}
enc := json.NewEncoder(os.Stdout)
enc.SetIndent("", " ")
return enc.Encode(cfg)
}
func usage() {
fmt.Fprintf(os.Stderr, `Usage: kubesolo-cloudinit <command> [config.yaml]
Commands:
apply Parse and apply cloud-init configuration
validate Check config file for errors
dump Parse and print config as JSON
If config path is omitted, defaults to %s
`, defaultConfigPath)
}