mirror of
https://github.com/cirruslabs/orchard.git
synced 2026-09-30 03:51:43 +02:00
Simplified bootstrapping of a cluster (#40)
* Simplified bootstrapping of a cluster Introduced a new convention about a pre-defined `bootstrap-admin` account for `orchard controller run`. Providing `ORCHARD_BOOTSTRAP_ADMIN_TOKEN` will auto-create such user for easier configuration. `bootstrap-admin` can be used for creating other service accounts on the first run and after that can be disposed. Also change `orchard worker run` to expect controller URL as the only parameter and a bootstrap token passed via an argument instead of using a context that might not be created. * Missing error check
This commit is contained in:
+15
-3
@@ -1,6 +1,10 @@
|
||||
package client
|
||||
|
||||
import "crypto/tls"
|
||||
import (
|
||||
"crypto/tls"
|
||||
"crypto/x509"
|
||||
"github.com/cirruslabs/orchard/internal/netconstants"
|
||||
)
|
||||
|
||||
type Option func(*Client)
|
||||
|
||||
@@ -10,9 +14,17 @@ func WithAddress(address string) Option {
|
||||
}
|
||||
}
|
||||
|
||||
func WithTLSConfig(tlsConfig *tls.Config) Option {
|
||||
func WithTrustedCertificate(cert *x509.Certificate) Option {
|
||||
return func(client *Client) {
|
||||
client.tlsConfig = tlsConfig
|
||||
// Check that the API is accessible
|
||||
privatePool := x509.NewCertPool()
|
||||
privatePool.AddCert(cert)
|
||||
|
||||
client.tlsConfig = &tls.Config{
|
||||
MinVersion: tls.VersionTLS13,
|
||||
RootCAs: privatePool,
|
||||
ServerName: netconstants.DefaultControllerServerName,
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user