Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 554e2e4f9c | |||
| 245a46aa5d | |||
| e86b24f493 | |||
| 749059d235 | |||
| 17f043d856 | |||
| 4d8ec0f54c | |||
| 1dc02ce5cf | |||
| 2946db9b49 | |||
| 7e9fec60d4 |
+4
-2
@@ -2,5 +2,7 @@
|
|||||||
/dist/
|
/dist/
|
||||||
*.rpm
|
*.rpm
|
||||||
*.zip
|
*.zip
|
||||||
encapi
|
# Root-level dev binaries only — anchored so cmd/encapi and cmd/encapi-cli
|
||||||
encapi-cli
|
# (the source packages) are NOT ignored.
|
||||||
|
/encapi
|
||||||
|
/encapi-cli
|
||||||
|
|||||||
+13
-1
@@ -6,10 +6,22 @@ repos:
|
|||||||
- id: end-of-file-fixer
|
- id: end-of-file-fixer
|
||||||
- id: check-yaml
|
- id: check-yaml
|
||||||
- id: check-added-large-files
|
- id: check-added-large-files
|
||||||
|
- id: check-merge-conflict
|
||||||
|
|
||||||
- repo: https://github.com/dnephin/pre-commit-golang
|
- repo: https://github.com/dnephin/pre-commit-golang
|
||||||
rev: v0.5.1
|
rev: v0.5.1
|
||||||
hooks:
|
hooks:
|
||||||
- id: go-fmt
|
- id: go-fmt
|
||||||
- id: go-vet
|
|
||||||
- id: go-mod-tidy
|
- id: go-mod-tidy
|
||||||
|
|
||||||
|
# encapi has no root-level Go files (all under cmd/, internal/, pkg/), so the
|
||||||
|
# dnephin go-vet hook (which runs `go vet` at the repo root) fails with
|
||||||
|
# "no Go files". Vet the whole module instead, mirroring artifactapi.
|
||||||
|
- repo: local
|
||||||
|
hooks:
|
||||||
|
- id: go-vet
|
||||||
|
name: go vet
|
||||||
|
entry: go vet ./...
|
||||||
|
language: system
|
||||||
|
types: [go]
|
||||||
|
pass_filenames: false
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ when:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: docker-build
|
- name: docker-build
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest
|
||||||
settings:
|
settings:
|
||||||
repo: git.unkin.net/unkin/encapi
|
repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi
|
||||||
dry_run: true
|
dry_run: true
|
||||||
|
|||||||
@@ -4,15 +4,15 @@ when:
|
|||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: docker-encapi
|
- name: docker-encapi
|
||||||
image: woodpeckerci/plugin-docker-buildx
|
image: artifactapi.k8s.syd1.au.unkin.net/docker-internal/plugin-docker-buildx:latest
|
||||||
settings:
|
settings:
|
||||||
registry: git.unkin.net
|
registry: artifactapi.k8s.syd1.au.unkin.net
|
||||||
repo: git.unkin.net/unkin/encapi
|
repo: artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi
|
||||||
build_args:
|
build_args:
|
||||||
VERSION: ${CI_COMMIT_TAG}
|
VERSION: ${CI_COMMIT_TAG}
|
||||||
username: droneci
|
buildkit_config: |
|
||||||
password:
|
[registry."artifactapi.k8s.syd1.au.unkin.net"]
|
||||||
from_secret: DRONECI_PASSWORD
|
ca = ["/etc/docker/certs.d/artifactapi.k8s.syd1.au.unkin.net/ca.crt"]
|
||||||
tags:
|
tags:
|
||||||
- ${CI_COMMIT_TAG}
|
- ${CI_COMMIT_TAG}
|
||||||
- latest
|
- latest
|
||||||
|
|||||||
@@ -93,7 +93,7 @@ make test-short # skip container-backed DB tests
|
|||||||
## Releases
|
## Releases
|
||||||
|
|
||||||
- **`encapi` server image** — tagging `vX.Y.Z` builds and pushes
|
- **`encapi` server image** — tagging `vX.Y.Z` builds and pushes
|
||||||
`git.unkin.net/unkin/encapi:{tag,latest}` (distroless).
|
`artifactapi.k8s.syd1.au.unkin.net/docker-internal/encapi:{tag,latest}` (distroless).
|
||||||
- **`encapi-cli` RPM** — the same tag builds an RPM (nfpm) and publishes it to
|
- **`encapi-cli` RPM** — the same tag builds an RPM (nfpm) and publishes it to
|
||||||
the ArtifactAPI `rpm-internal` repo. Installs `encapi-cli`, the `encapi-enc`
|
the ArtifactAPI `rpm-internal` repo. Installs `encapi-cli`, the `encapi-enc`
|
||||||
Puppet wrapper, and `/etc/encapi/enc.conf`.
|
Puppet wrapper, and `/etc/encapi/enc.conf`.
|
||||||
|
|||||||
@@ -0,0 +1,13 @@
|
|||||||
|
// Command encapi-cli manages the Puppet ENC via the encapi HTTP API. Puppet's
|
||||||
|
// exec node_terminus calls `encapi-cli classify <certname>`.
|
||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"os"
|
||||||
|
|
||||||
|
"git.unkin.net/unkin/encapi/internal/cli"
|
||||||
|
)
|
||||||
|
|
||||||
|
func main() {
|
||||||
|
os.Exit(cli.Run(os.Args[1:], cli.LoadEnv(), os.Stdout, os.Stderr))
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
// Command encapi is the ENC HTTP server: it serves Puppet's node classification
|
||||||
|
// documents and the read/write API backing the CLI and Terraform provider.
|
||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"context"
|
||||||
|
"log/slog"
|
||||||
|
"os"
|
||||||
|
"os/signal"
|
||||||
|
"syscall"
|
||||||
|
|
||||||
|
"git.unkin.net/unkin/encapi/internal/config"
|
||||||
|
"git.unkin.net/unkin/encapi/internal/database"
|
||||||
|
"git.unkin.net/unkin/encapi/internal/distro"
|
||||||
|
"git.unkin.net/unkin/encapi/internal/server"
|
||||||
|
)
|
||||||
|
|
||||||
|
var version = "dev"
|
||||||
|
|
||||||
|
func main() {
|
||||||
|
slog.SetDefault(slog.New(slog.NewJSONHandler(os.Stdout, nil)))
|
||||||
|
slog.Info("starting encapi", "version", version)
|
||||||
|
|
||||||
|
cfg, err := config.Load()
|
||||||
|
if err != nil {
|
||||||
|
slog.Error("load config", "err", err)
|
||||||
|
os.Exit(1)
|
||||||
|
}
|
||||||
|
|
||||||
|
db, err := database.New(cfg.DatabaseDSN())
|
||||||
|
if err != nil {
|
||||||
|
slog.Error("connect database", "err", err)
|
||||||
|
os.Exit(1)
|
||||||
|
}
|
||||||
|
defer db.Close()
|
||||||
|
|
||||||
|
if cfg.WriteToken == "" {
|
||||||
|
slog.Warn("ENCAPI_WRITE_TOKEN is not set; write endpoints are disabled")
|
||||||
|
}
|
||||||
|
|
||||||
|
srv := server.New(db, distro.New(cfg.DistroAPIURL), cfg.WriteToken)
|
||||||
|
|
||||||
|
ctx, stop := signal.NotifyContext(context.Background(), syscall.SIGINT, syscall.SIGTERM)
|
||||||
|
defer stop()
|
||||||
|
|
||||||
|
if err := srv.ListenAndServe(ctx, cfg.ListenAddr); err != nil {
|
||||||
|
slog.Error("server", "err", err)
|
||||||
|
os.Exit(1)
|
||||||
|
}
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user