Files
kea-operator/internal/kea/agent.go
T
unkinben e95e5437a2
ci/woodpecker/pr/pre-commit Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/build Pipeline was successful
Harden kea socket dir to 0750 in the rendered entrypoints
After v0.1.1 moved the socket dir to /var/run/kea, kea-dhcp4 and
kea-ctrl-agent still crash-loop:

  DHCP4_PARSER_COMMIT_FAIL ... 'socket-name' is invalid: socket path:/var/run/kea
  does not exist or has more relaxed permissions than 750

Kea 2.6+ refuses a unix-socket directory whose mode is more relaxed than
0750. The shared emptyDir is mounted at /var/run/kea with the default 0777,
so kea rejects it. The kea containers run as root, so the entrypoints can
tighten it.

- chmod 0750 the RunDir in both rendered entrypoints after mkdir.
- Assert both entrypoints chmod the socket dir to 0750.

Needs a v0.1.2 release so argocd-apps can bump the operator image.

Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
2026-08-08 20:12:17 +10:00

54 lines
1.6 KiB
Go

package kea
import "fmt"
type ctrlAgentRoot struct {
ControlAgent controlAgent `json:"Control-agent"`
}
type controlAgent struct {
HTTPHost string `json:"http-host"`
HTTPPort int `json:"http-port"`
ControlSockets map[string]map[string]any `json:"control-sockets"`
Loggers []logger `json:"loggers"`
}
// RenderCtrlAgent renders the deterministic kea-ctrl-agent.conf JSON. The
// control agent exposes the HA/REST control channel on CtrlAgentPort and
// forwards to kea-dhcp4 over the shared unix socket.
func RenderCtrlAgent() (string, error) {
return marshal(ctrlAgentRoot{ControlAgent: controlAgent{
HTTPHost: "0.0.0.0",
HTTPPort: CtrlAgentPort,
ControlSockets: map[string]map[string]any{
"dhcp4": {"socket-type": "unix", "socket-name": CtrlSocketPath},
},
Loggers: loggers("kea-ctrl-agent"),
}})
}
// EntrypointDHCP4 is the kea-dhcp4 container entrypoint. It derives this pod's
// HA peer name from the StatefulSet ordinal, substitutes the placeholder in the
// projected config, and execs the server.
func EntrypointDHCP4() string {
return fmt.Sprintf(`#!/bin/sh
set -e
ORD="${HOSTNAME##*-}"
mkdir -p %[1]s
chmod 0750 %[1]s
sed "s/%[2]s/server${ORD}/g" %[3]s/kea-dhcp4.conf > %[4]s
exec %[5]s -c %[4]s
`, RunDir, ThisServerPlaceholder, ConfigDir, DHCP4ConfPath, DHCP4Bin)
}
// EntrypointCtrlAgent is the kea-ctrl-agent container entrypoint.
func EntrypointCtrlAgent() string {
return fmt.Sprintf(`#!/bin/sh
set -e
mkdir -p %[1]s
chmod 0750 %[1]s
cp %[2]s/kea-ctrl-agent.conf %[3]s
exec %[4]s -c %[3]s
`, RunDir, ConfigDir, CtrlAgentConfPath, CtrlAgentBin)
}