Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Inject TLS ca cert into IPA ramdisk #491

Merged
merged 3 commits into from
Nov 27, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions controllers/ironicconductor_controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -837,6 +837,7 @@ func (r *IronicConductorReconciler) generateServiceConfigMaps(
"common.sh": "/common/bin/common.sh",
"get_net_ip": "/common/bin/get_net_ip",
"runlogwatch.sh": "/common/bin/runlogwatch.sh",
"pxe-init.sh": "/common/bin/pxe-init.sh",
},
Labels: cmLabels,
},
Expand Down
1 change: 1 addition & 0 deletions controllers/ironicinspector_controller.go
Original file line number Diff line number Diff line change
Expand Up @@ -1462,6 +1462,7 @@ func (r *IronicInspectorReconciler) generateServiceConfigMaps(
"common.sh": "/common/bin/common.sh",
"get_net_ip": "/common/bin/get_net_ip",
"runlogwatch.sh": "/common/bin/runlogwatch.sh",
"pxe-init.sh": "/common/bin/pxe-init.sh",
},
Labels: cmLabels,
},
Expand Down
41 changes: 21 additions & 20 deletions pkg/ironic/initcontainer.go
Original file line number Diff line number Diff line change
Expand Up @@ -116,26 +116,6 @@ func InitContainer(init APIDetails) []corev1.Container {

var containers []corev1.Container

if init.PxeInit {
pxeInit := corev1.Container{
Name: "pxe-init",
Image: init.PxeContainerImage,
SecurityContext: &corev1.SecurityContext{
RunAsUser: &runAsUser,
},
Command: []string{
"/bin/bash",
},
Args: []string{
"-c",
PxeInitContainerCommand,
},
Env: envs,
VolumeMounts: init.VolumeMounts,
}
containers = append(containers, pxeInit)
}

initContainer := corev1.Container{
Name: "init",
Image: init.ContainerImage,
Expand Down Expand Up @@ -167,5 +147,26 @@ func InitContainer(init APIDetails) []corev1.Container {
containers = append(containers, ipaInit)
}

if init.PxeInit {
pxeInit := corev1.Container{
Name: "pxe-init",
Image: init.PxeContainerImage,
SecurityContext: &corev1.SecurityContext{
RunAsUser: &runAsUser,
Privileged: &init.Privileged,
},
Command: []string{
"/bin/bash",
},
Args: []string{
"-c",
PxeInitContainerCommand,
},
Env: envs,
VolumeMounts: init.VolumeMounts,
}
containers = append(containers, pxeInit)
}

return containers
}
1 change: 1 addition & 0 deletions pkg/ironicconductor/statefulset.go
Original file line number Diff line number Diff line change
Expand Up @@ -340,6 +340,7 @@ func StatefulSet(
VolumeMounts: initVolumeMounts,
PxeInit: true,
ConductorInit: true,
Privileged: true,
DeployHTTPURL: deployHTTPURL,
IngressDomain: ingressDomain,
ProvisionNetwork: instance.Spec.ProvisionNetwork,
Expand Down
34 changes: 20 additions & 14 deletions pkg/ironicinspector/initcontainer.go
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ const (
InitContainerCommand = "/usr/local/bin/container-scripts/init.sh"

// PxeInitContainerCommand -
PxeInitContainerCommand = "/usr/local/bin/container-scripts/pxe-init.sh"
PxeInitContainerCommand = "/usr/local/bin/container-scripts/inspector-pxe-init.sh"
)

// InitContainer - init container for Ironic Inspector pods
Expand Down Expand Up @@ -128,12 +128,31 @@ func InitContainer(init APIDetails) []corev1.Container {
}
containers = append(containers, inspectorInit)

if init.IpaInit {
ipaInit := corev1.Container{
Name: "ironic-python-agent-init",
Image: init.IronicPythonAgentImage,
SecurityContext: &corev1.SecurityContext{
Privileged: &init.Privileged,
},
Env: imageCopyEnvs,
VolumeMounts: init.VolumeMounts,
}
containers = append(containers, ipaInit)
}

if init.PxeInit {
pxeInit := corev1.Container{
Name: "inspector-pxe-init",
Image: init.PxeContainerImage,
SecurityContext: &corev1.SecurityContext{
RunAsUser: &runAsUser,
Capabilities: &corev1.Capabilities{
Add: []corev1.Capability{
"SYS_CHROOT",
"SETFCAP",
},
},
},
Command: []string{
"/bin/bash",
Expand All @@ -145,18 +164,5 @@ func InitContainer(init APIDetails) []corev1.Container {
containers = append(containers, pxeInit)
}

if init.IpaInit {
ipaInit := corev1.Container{
Name: "ironic-python-agent-init",
Image: init.IronicPythonAgentImage,
SecurityContext: &corev1.SecurityContext{
Privileged: &init.Privileged,
},
Env: imageCopyEnvs,
VolumeMounts: init.VolumeMounts,
}
containers = append(containers, ipaInit)
}

return containers
}
1 change: 1 addition & 0 deletions pkg/ironicinspector/statefulset.go
Original file line number Diff line number Diff line change
Expand Up @@ -351,6 +351,7 @@ func StatefulSet(
VolumeMounts: initVolumeMounts,
PxeInit: true,
IpaInit: true,
Privileged: true,
InspectorHTTPURL: inspectorHTTPURL,
IngressDomain: ingressDomain,
InspectionNetwork: instance.Spec.InspectionNetwork,
Expand Down
2 changes: 1 addition & 1 deletion templates/common/bin/common.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/bin//bash
#!/bin/bash
#
# Copyright 2022 Red Hat Inc.
#
Expand Down
2 changes: 1 addition & 1 deletion templates/common/bin/ironic-init.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/bin//bash
#!/bin/bash
#
# Copyright 2023 Red Hat Inc.
#
Expand Down
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/bin//bash
#!/bin/bash
#
# Copyright 2020 Red Hat Inc.
#
Expand All @@ -15,12 +15,14 @@
# under the License.
set -ex


# Create TFTP, HTTP serving directories
mkdir -p /var/lib/ironic/tftpboot/pxelinux.cfg
if [ ! -d "/var/lib/ironic/tftpboot/pxelinux.cfg" ]; then
mkdir -p /var/lib/ironic/tftpboot/pxelinux.cfg
fi
if [ ! -d "/var/lib/ironic/httpboot" ]; then
mkdir /var/lib/ironic/httpboot
mkdir -p /var/lib/ironic/httpboot
fi

# Check for expected EFI directories
if [ -d "/boot/efi/EFI/centos" ]; then
efi_dir=centos
Expand All @@ -41,3 +43,35 @@ for dir in httpboot tftpboot; do
# Ensure all files are readable
chmod -R +r /var/lib/ironic/$dir
done

# Patch ironic-python-agent with custom CA certificates
if [ -f "/etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem" ] && [ -f "/var/lib/ironic/httpboot/ironic-python-agent.initramfs" ]; then
# Extract the initramfs
cd /
mkdir initramfs
pushd initramfs
zcat /var/lib/ironic/httpboot/ironic-python-agent.initramfs | cpio -idmV
popd

# Copy the CA certificates
cp /etc/pki/ca-trust/extracted/pem/tls-ca-bundle.pem /initramfs/etc/pki/ca-trust/extracted/pem/
echo update-ca-trust | unshare -r chroot ./initramfs

# Repack the initramfs
pushd initramfs
find . | cpio -o -c --quiet -R root:root | gzip -1 > /var/lib/ironic/httpboot/ironic-python-agent.initramfs
fi

# Build an ESP image
pushd /var/lib/ironic/httpboot
if [ ! -a "esp.img" ]; then
dd if=/dev/zero of=esp.img bs=4096 count=1024
mkfs.msdos -F 12 -n 'ESP_IMAGE' esp.img

mmd -i esp.img EFI
mmd -i esp.img EFI/BOOT
mcopy -i esp.img -v bootx64.efi ::EFI/BOOT
mcopy -i esp.img -v grubx64.efi ::EFI/BOOT
mdir -i esp.img ::EFI/BOOT;
fi
popd
2 changes: 1 addition & 1 deletion templates/common/bin/runlogwatch.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/usr/bin/bash
#!/bin/bash

# Ramdisk logs path
LOG_DIR=${LOG_DIR:-/var/lib/ironic/ramdisk-logs}
Expand Down
15 changes: 1 addition & 14 deletions templates/ironicconductor/bin/init.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/bin//bash
#!/bin/bash
#
# Copyright 2020 Red Hat Inc.
#
Expand Down Expand Up @@ -54,16 +54,3 @@ fi
if [ ! -d "/var/lib/ironic/ramdisk-logs" ]; then
mkdir /var/lib/ironic/ramdisk-logs
fi
# Build an ESP image
pushd /var/lib/ironic/httpboot
if [ ! -a "esp.img" ]; then
dd if=/dev/zero of=esp.img bs=4096 count=1024
mkfs.msdos -F 12 -n 'ESP_IMAGE' esp.img

mmd -i esp.img EFI
mmd -i esp.img EFI/BOOT
mcopy -i esp.img -v bootx64.efi ::EFI/BOOT
mcopy -i esp.img -v grubx64.efi ::EFI/BOOT
mdir -i esp.img ::EFI/BOOT;
fi
popd
5 changes: 4 additions & 1 deletion templates/ironicinspector/bin/init.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
#!/bin//bash
#!/bin/bash
#
# Copyright 2023 Red Hat Inc.
#
Expand All @@ -20,6 +20,9 @@ export TRANSPORTURL=${TransportURL:-""}

export CUSTOMCONF=${CustomConf:-""}

if [ ! -d "/var/lib/ironic/httpboot" ]; then
mkdir /var/lib/ironic/httpboot
fi
if [ ! -d "/var/lib/ironic/ramdisk-logs" ]; then
mkdir /var/lib/ironic/ramdisk-logs
fi
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -18,10 +18,6 @@ set -ex
# Get the statefulset pod index
export PODINDEX=$(echo ${HOSTNAME##*-})

# Create TFTP, HTTP serving directories
mkdir -p /var/lib/ironic/tftpboot/pxelinux.cfg
mkdir -p /var/lib/ironic/httpboot

# DHCP server configuration
export InspectorNetworkIP=$(/usr/local/bin/container-scripts/get_net_ip ${InspectionNetwork})
export INSPECTOR_HTTP_URL=$(python3 -c 'import os; print(os.environ["InspectorHTTPURL"] % os.environ)')
Expand All @@ -38,23 +34,5 @@ envsubst < ${DNSMASQ_CFG} | tee ${DNSMASQ_CFG}
export INSPECTOR_IPXE=/var/lib/config-data/merged/inspector.ipxe
envsubst < ${INSPECTOR_IPXE} | tee ${INSPECTOR_IPXE}

# Check for expected EFI directories
if [ -d "/boot/efi/EFI/centos" ]; then
efi_dir=centos
elif [ -d "/boot/efi/EFI/redhat" ]; then
efi_dir=redhat
else
echo "No EFI directory detected"
exit 1
fi

# Copy iPXE and grub files to tftpboot, httpboot
for dir in httpboot tftpboot; do
cp /usr/share/ipxe/ipxe-snponly-x86_64.efi /var/lib/ironic/$dir/snponly.efi
cp /usr/share/ipxe/undionly.kpxe /var/lib/ironic/$dir/undionly.kpxe
cp /usr/share/ipxe/ipxe.lkrn /var/lib/ironic/$dir/ipxe.lkrn
cp /boot/efi/EFI/$efi_dir/shimx64.efi /var/lib/ironic/$dir/bootx64.efi
cp /boot/efi/EFI/$efi_dir/grubx64.efi /var/lib/ironic/$dir/grubx64.efi
# Ensure all files are readable
chmod -R +r /var/lib/ironic/$dir
done
# run common pxe-init script
/usr/local/bin/container-scripts/pxe-init.sh