talos/internal/pkg/encryption/keys/nodeid.go
Philipp Sauter 2deff6b6e1
feat: add support for variable substitution in talos.config kernel parameter
The URL to fetch the configuration for a talos node is given by the
talos.config kernel parameter. We add support for 4 variables ${uuid},
${serial}, ${mac} and ${hostname} which substitute the device UUID,
DMI-sourced serial number, MAC address of the first network interface to
be up and the hostname respectively.

Fixes #3272

Signed-off-by: Philipp Sauter <philipp.sauter@siderolabs.com>
2022-06-24 12:38:08 +02:00

51 lines
1.2 KiB
Go

// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this
// file, You can obtain one at http://mozilla.org/MPL/2.0/.
package keys
import (
"fmt"
"github.com/talos-systems/talos/internal/pkg/smbios"
)
// NodeIDKeyHandler generates the key based on current node information
// and provided template string.
type NodeIDKeyHandler struct{}
// NewNodeIDKeyHandler creates new NodeIDKeyHandler.
func NewNodeIDKeyHandler() (*NodeIDKeyHandler, error) {
return &NodeIDKeyHandler{}, nil
}
// GetKey implements KeyHandler interface.
func (h *NodeIDKeyHandler) GetKey(options ...KeyOption) ([]byte, error) {
opts, err := NewDefaultOptions(options)
if err != nil {
return nil, err
}
s, err := smbios.GetSMBIOSInfo()
if err != nil {
return nil, err
}
machineUUID := s.SystemInformation.UUID
if machineUUID == "" {
return nil, fmt.Errorf("machine UUID is not populated %s", machineUUID)
}
// primitive entropy check
counts := map[rune]int{}
for _, s := range machineUUID {
counts[s]++
if counts[s] > len(machineUUID)/2 {
return nil, fmt.Errorf("machine UUID %s entropy check failed", machineUUID)
}
}
return []byte(machineUUID + opts.PartitionLabel), nil
}