talos/internal/pkg/encryption/keys/nodeid.go
Artem Chernyshev 58ff2c9808 feat: implement ephemeral partition encryption
This PR introduces the first part of disk encryption support.
New config section `systemDiskEncryption` was added into MachineConfig.
For now it contains only Ephemeral partition encryption.

Encryption itself supports two kinds of keys for now:
- node id deterministic key.
- static key which is hardcoded in the config and mainly used for test
purposes.

Talosctl cluster create can now be told to encrypt ephemeral partition
by using `--encrypt-ephemeral` flag.

Additionally:
- updated pkgs library version.
- changed Dockefile to copy cryptsetup deps from pkgs.

Signed-off-by: Artem Chernyshev <artem.0xD2@gmail.com>
2021-02-17 13:39:04 -08:00

58 lines
1.3 KiB
Go

// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this
// file, You can obtain one at http://mozilla.org/MPL/2.0/.
package keys
import (
"fmt"
"github.com/google/uuid"
"github.com/talos-systems/go-smbios/smbios"
)
// NodeIDKeyHandler generates the key based on current node information
// and provided template string.
type NodeIDKeyHandler struct {
}
// NewNodeIDKeyHandler creates new NodeIDKeyHandler.
func NewNodeIDKeyHandler() (*NodeIDKeyHandler, error) {
return &NodeIDKeyHandler{}, nil
}
// GetKey implements KeyHandler interface.
func (h *NodeIDKeyHandler) GetKey(options ...KeyOption) ([]byte, error) {
opts, err := NewDefaultOptions(options)
if err != nil {
return nil, err
}
s, err := smbios.New()
if err != nil {
return nil, err
}
machineUUID, err := s.SystemInformation().UUID()
if err != nil {
return nil, err
}
if machineUUID == uuid.Nil {
return nil, fmt.Errorf("machine UUID is not populated %s", machineUUID)
}
id := machineUUID.String()
// primitive entropy check
counts := map[rune]int{}
for _, s := range id {
counts[s]++
if counts[s] > len(id)/2 {
return nil, fmt.Errorf("machine UUID %s entropy check failed", machineUUID)
}
}
return []byte(id + opts.PartitionLabel), nil
}