Simplified bootstrapping of a cluster (#40)

* Simplified bootstrapping of a cluster

Introduced a new convention about a pre-defined `bootstrap-admin` account for `orchard controller run`. Providing `ORCHARD_BOOTSTRAP_ADMIN_TOKEN` will auto-create such user for easier configuration. `bootstrap-admin` can be used for creating other service accounts on the first run and after that can be disposed.

Also change `orchard worker run` to expect controller URL as the only parameter and a bootstrap token passed via an argument instead of using a context that might not be created.

* Missing error check
This commit is contained in:
Fedor Korotkov
2023-03-22 23:43:37 +04:00
committed by GitHub
parent 9b5ad09841
commit cdf5c5eb00
8 changed files with 100 additions and 39 deletions
+15 -3
View File
@@ -1,6 +1,10 @@
package client
import "crypto/tls"
import (
"crypto/tls"
"crypto/x509"
"github.com/cirruslabs/orchard/internal/netconstants"
)
type Option func(*Client)
@@ -10,9 +14,17 @@ func WithAddress(address string) Option {
}
}
func WithTLSConfig(tlsConfig *tls.Config) Option {
func WithTrustedCertificate(cert *x509.Certificate) Option {
return func(client *Client) {
client.tlsConfig = tlsConfig
// Check that the API is accessible
privatePool := x509.NewCertPool()
privatePool.AddCert(cert)
client.tlsConfig = &tls.Config{
MinVersion: tls.VersionTLS13,
RootCAs: privatePool,
ServerName: netconstants.DefaultControllerServerName,
}
}
}