Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 554e2e4f9c | |||
| 245a46aa5d | |||
| e86b24f493 | |||
| 749059d235 | |||
| 17f043d856 | |||
| 4d8ec0f54c | |||
| 1dc02ce5cf | |||
| 2946db9b49 | |||
| 7e9fec60d4 |
+4
-2
@@ -2,5 +2,7 @@
|
||||
/dist/
|
||||
*.rpm
|
||||
*.zip
|
||||
encapi
|
||||
encapi-cli
|
||||
# Root-level dev binaries only — anchored so cmd/encapi and cmd/encapi-cli
|
||||
# (the source packages) are NOT ignored.
|
||||
/encapi
|
||||
/encapi-cli
|
||||
|
||||
+13
-1
@@ -6,10 +6,22 @@ repos:
|
||||
- id: end-of-file-fixer
|
||||
- id: check-yaml
|
||||
- id: check-added-large-files
|
||||
- id: check-merge-conflict
|
||||
|
||||
- repo: https://github.com/dnephin/pre-commit-golang
|
||||
rev: v0.5.1
|
||||
hooks:
|
||||
- id: go-fmt
|
||||
- id: go-vet
|
||||
- id: go-mod-tidy
|
||||
|
||||
# encapi has no root-level Go files (all under cmd/, internal/, pkg/), so the
|
||||
# dnephin go-vet hook (which runs `go vet` at the repo root) fails with
|
||||
# "no Go files". Vet the whole module instead, mirroring artifactapi.
|
||||
- repo: local
|
||||
hooks:
|
||||
- id: go-vet
|
||||
name: go vet
|
||||
entry: go vet ./...
|
||||
language: system
|
||||
types: [go]
|
||||
pass_filenames: false
|
||||
|
||||
@@ -3,7 +3,7 @@ when:
|
||||
|
||||
steps:
|
||||
- name: docker-build
|
||||
image: woodpeckerci/plugin-docker-buildx
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest
|
||||
settings:
|
||||
repo: git.unkin.net/unkin/encapi
|
||||
repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi
|
||||
dry_run: true
|
||||
|
||||
@@ -4,15 +4,15 @@ when:
|
||||
|
||||
steps:
|
||||
- name: docker-encapi
|
||||
image: woodpeckerci/plugin-docker-buildx
|
||||
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest
|
||||
settings:
|
||||
registry: git.unkin.net
|
||||
repo: git.unkin.net/unkin/encapi
|
||||
registry: artifactapi.k8s.syd1.au.unkin.net
|
||||
repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi
|
||||
build_args:
|
||||
VERSION: ${CI_COMMIT_TAG}
|
||||
username: droneci
|
||||
password:
|
||||
from_secret: DRONECI_PASSWORD
|
||||
buildkit_config: |
|
||||
[registry."artifactapi.k8s.syd1.au.unkin.net"]
|
||||
ca = ["/etc/docker/certs.d/artifactapi.k8s.syd1.au.unkin.net/ca.crt"]
|
||||
tags:
|
||||
- ${CI_COMMIT_TAG}
|
||||
- latest
|
||||
|
||||
@@ -93,7 +93,7 @@ make test-short # skip container-backed DB tests
|
||||
## Releases
|
||||
|
||||
- **`encapi` server image** — tagging `vX.Y.Z` builds and pushes
|
||||
`git.unkin.net/unkin/encapi:{tag,latest}` (distroless).
|
||||
`artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi:{tag,latest}` (distroless).
|
||||
- **`encapi-cli` RPM** — the same tag builds an RPM (nfpm) and publishes it to
|
||||
the ArtifactAPI `rpm-internal` repo. Installs `encapi-cli`, the `encapi-enc`
|
||||
Puppet wrapper, and `/etc/encapi/enc.conf`.
|
||||
|
||||
@@ -0,0 +1,13 @@
|
||||
// Command encapi-cli manages the Puppet ENC via the encapi HTTP API. Puppet's
|
||||
// exec node_terminus calls `encapi-cli classify <certname>`.
|
||||
package main
|
||||
|
||||
import (
|
||||
"os"
|
||||
|
||||
"git.unkin.net/unkin/encapi/internal/cli"
|
||||
)
|
||||
|
||||
func main() {
|
||||
os.Exit(cli.Run(os.Args[1:], cli.LoadEnv(), os.Stdout, os.Stderr))
|
||||
}
|
||||
@@ -0,0 +1,50 @@
|
||||
// Command encapi is the ENC HTTP server: it serves Puppet's node classification
|
||||
// documents and the read/write API backing the CLI and Terraform provider.
|
||||
package main
|
||||
|
||||
import (
|
||||
"context"
|
||||
"log/slog"
|
||||
"os"
|
||||
"os/signal"
|
||||
"syscall"
|
||||
|
||||
"git.unkin.net/unkin/encapi/internal/config"
|
||||
"git.unkin.net/unkin/encapi/internal/database"
|
||||
"git.unkin.net/unkin/encapi/internal/distro"
|
||||
"git.unkin.net/unkin/encapi/internal/server"
|
||||
)
|
||||
|
||||
var version = "dev"
|
||||
|
||||
func main() {
|
||||
slog.SetDefault(slog.New(slog.NewJSONHandler(os.Stdout, nil)))
|
||||
slog.Info("starting encapi", "version", version)
|
||||
|
||||
cfg, err := config.Load()
|
||||
if err != nil {
|
||||
slog.Error("load config", "err", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
|
||||
db, err := database.New(cfg.DatabaseDSN())
|
||||
if err != nil {
|
||||
slog.Error("connect database", "err", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
defer db.Close()
|
||||
|
||||
if cfg.WriteToken == "" {
|
||||
slog.Warn("ENCAPI_WRITE_TOKEN is not set; write endpoints are disabled")
|
||||
}
|
||||
|
||||
srv := server.New(db, distro.New(cfg.DistroAPIURL), cfg.WriteToken)
|
||||
|
||||
ctx, stop := signal.NotifyContext(context.Background(), syscall.SIGINT, syscall.SIGTERM)
|
||||
defer stop()
|
||||
|
||||
if err := srv.ListenAndServe(ctx, cfg.ListenAddr); err != nil {
|
||||
slog.Error("server", "err", err)
|
||||
os.Exit(1)
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user