mirror of
https://github.com/siderolabs/talos.git
synced 2025-08-12 01:27:07 +02:00
This PR introduces the first part of disk encryption support. New config section `systemDiskEncryption` was added into MachineConfig. For now it contains only Ephemeral partition encryption. Encryption itself supports two kinds of keys for now: - node id deterministic key. - static key which is hardcoded in the config and mainly used for test purposes. Talosctl cluster create can now be told to encrypt ephemeral partition by using `--encrypt-ephemeral` flag. Additionally: - updated pkgs library version. - changed Dockefile to copy cryptsetup deps from pkgs. Signed-off-by: Artem Chernyshev <artem.0xD2@gmail.com>
37 lines
905 B
Go
37 lines
905 B
Go
// This Source Code Form is subject to the terms of the Mozilla Public
|
|
// License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
// file, You can obtain one at http://mozilla.org/MPL/2.0/.
|
|
|
|
package keys
|
|
|
|
// KeyOption represents key option callback used in KeyHandler.GetKey func.
|
|
type KeyOption func(o *KeyOptions) error
|
|
|
|
// KeyOptions set of options to be used in KeyHandler.GetKey func.
|
|
type KeyOptions struct {
|
|
PartitionLabel string
|
|
}
|
|
|
|
// WithPartitionLabel passes the partition label in to GetKey function.
|
|
func WithPartitionLabel(label string) KeyOption {
|
|
return func(o *KeyOptions) error {
|
|
o.PartitionLabel = label
|
|
|
|
return nil
|
|
}
|
|
}
|
|
|
|
// NewDefaultOptions creates new KeyOptions.
|
|
func NewDefaultOptions(options []KeyOption) (*KeyOptions, error) {
|
|
var opts KeyOptions
|
|
|
|
for _, o := range options {
|
|
err := o(&opts)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
}
|
|
|
|
return &opts, nil
|
|
}
|