talos/internal/pkg/encryption/keys/options.go
Andrey Smirnov a5f3000f2e
feat: implement encryption locking to STATE
Fixes #10676

Signed-off-by: Andrey Smirnov <andrey.smirnov@siderolabs.com>
2025-08-01 18:24:56 +04:00

69 lines
1.7 KiB
Go

// This Source Code Form is subject to the terms of the Mozilla Public
// License, v. 2.0. If a copy of the MPL was not distributed with this
// file, You can obtain one at http://mozilla.org/MPL/2.0/.
package keys
import "github.com/siderolabs/talos/internal/pkg/encryption/helpers"
// KeyOption represents key option callback used in KeyHandler.GetKey func.
type KeyOption func(o *KeyOptions) error
// KeyOptions set of options to be used in KeyHandler.GetKey func.
type KeyOptions struct {
VolumeID string
GetSystemInformation helpers.SystemInformationGetter
TPMLocker helpers.TPMLockFunc
SaltGetter helpers.SaltGetter
}
// WithVolumeID passes the partition label to the key handler.
func WithVolumeID(label string) KeyOption {
return func(o *KeyOptions) error {
o.VolumeID = label
return nil
}
}
// WithSystemInformationGetter passes the node UUID to the key handler.
func WithSystemInformationGetter(getter helpers.SystemInformationGetter) KeyOption {
return func(o *KeyOptions) error {
o.GetSystemInformation = getter
return nil
}
}
// WithTPMLocker passes the TPM locker to the key handler.
func WithTPMLocker(locker helpers.TPMLockFunc) KeyOption {
return func(o *KeyOptions) error {
o.TPMLocker = locker
return nil
}
}
// WithSaltGetter passes the salt getter to the key handler.
func WithSaltGetter(getter helpers.SaltGetter) KeyOption {
return func(o *KeyOptions) error {
o.SaltGetter = getter
return nil
}
}
// NewDefaultOptions creates new KeyOptions.
func NewDefaultOptions(options []KeyOption) (*KeyOptions, error) {
var opts KeyOptions
for _, o := range options {
err := o(&opts)
if err != nil {
return nil, err
}
}
return &opts, nil
}