-
Notifications
You must be signed in to change notification settings - Fork 464
/
main.go
82 lines (71 loc) · 2.01 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
package main
import (
"flag"
"log"
"github.com/autonomy/dianemo/src/initramfs/cmd/osd/pkg/gen"
"github.com/autonomy/dianemo/src/initramfs/cmd/osd/pkg/reg"
"github.com/autonomy/dianemo/src/initramfs/pkg/grpc/factory"
"github.com/autonomy/dianemo/src/initramfs/pkg/grpc/middleware/auth/basic"
"github.com/autonomy/dianemo/src/initramfs/pkg/grpc/tls"
"github.com/autonomy/dianemo/src/initramfs/pkg/userdata"
"google.golang.org/grpc"
"google.golang.org/grpc/credentials"
)
var (
dataPath *string
generate *bool
port *int
rotPort *int
)
func init() {
log.SetFlags(log.Lshortfile | log.Ldate | log.Lmicroseconds | log.Ltime)
dataPath = flag.String("userdata", "", "the path to the user data")
port = flag.Int("port", 50000, "the port to listen on")
rotPort = flag.Int("rot-port", 50001, "the port to listen on")
generate = flag.Bool("generate", false, "generate the TLS certificate using one of the Root of Trusts")
flag.Parse()
}
func main() {
var err error
data, err := userdata.Open(*dataPath)
if err != nil {
log.Fatalf("open user data: %v", err)
}
if *generate {
if len(data.Services.ROTD.Endpoints) == 0 {
log.Fatalf("at least one root of trust endpoint is required")
}
creds := basic.NewCredentials(
data.Security.OS.CA.Crt,
data.Services.ROTD.Username,
data.Services.ROTD.Password,
)
// TODO: In the case of failure, attempt to generate the identity from
// another RoT.
var conn *grpc.ClientConn
conn, err = basic.NewConnection(data.Services.ROTD.Endpoints[0], *rotPort, creds)
if err != nil {
return
}
generator := gen.NewGenerator(conn)
if err = generator.Identity(data.Security); err != nil {
log.Fatalf("generate identity: %v", err)
}
}
config, err := tls.NewConfig(tls.Mutual, data.Security.OS)
if err != nil {
log.Fatalf("credentials: %v", err)
}
err = factory.Listen(
®.Registrator{data},
factory.Port(*port),
factory.ServerOptions(
grpc.Creds(
credentials.NewTLS(config),
),
),
)
if err != nil {
log.Fatalf("listen: %v", err)
}
}