Configure gateway limits and encrypted storage
This commit is contained in:
1 parent
43987bbadb
commit
510e519bd1
23 files changed
+480
-17
No files matched your search
@@ -0,0 +1,69 @@
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
|
||||
mode=${1:-}
|
||||
case "$mode" in
|
||||
single) directories='single' ;;
|
||||
cluster) directories='cluster/gateway-staging cluster/metadata cluster/metadata-recovery cluster/repair-staging cluster/gc-staging cluster/maintenance-staging cluster/node-a cluster/node-b cluster/node-c cluster/node-d' ;;
|
||||
*) echo 'Usage: prepare-encrypted-storage.sh single|cluster [environment-file]' >&2; exit 2 ;;
|
||||
esac
|
||||
|
||||
if [ "$#" -gt 2 ]; then
|
||||
echo 'Too many arguments' >&2
|
||||
exit 2
|
||||
fi
|
||||
if [ "$#" -eq 2 ]; then
|
||||
[ -r "$2" ] || { echo 'Environment file is not readable' >&2; exit 2; }
|
||||
while IFS='=' read -r name value || [ -n "${name:-}" ]; do
|
||||
case "$name" in
|
||||
ENCRYPTED_STORAGE_ROOT) ENCRYPTED_STORAGE_ROOT=$value ;;
|
||||
ENCRYPTED_VOLUME_ID) ENCRYPTED_VOLUME_ID=$value ;;
|
||||
esac
|
||||
done < "$2"
|
||||
fi
|
||||
|
||||
root=${ENCRYPTED_STORAGE_ROOT:?Set ENCRYPTED_STORAGE_ROOT to an existing mounted LUKS directory}
|
||||
id=${ENCRYPTED_VOLUME_ID:?Set ENCRYPTED_VOLUME_ID to 32 lowercase hex characters}
|
||||
case "$id" in *[!0-9a-f]*|'') echo 'ENCRYPTED_VOLUME_ID must be lowercase hex' >&2; exit 2 ;; esac
|
||||
[ "${#id}" -eq 32 ] || { echo 'ENCRYPTED_VOLUME_ID must be 32 characters' >&2; exit 2; }
|
||||
[ -d "$root" ] && [ ! -L "$root" ] || { echo 'Encrypted root is missing or a symlink' >&2; exit 1; }
|
||||
root=$(realpath -e "$root")
|
||||
source=$(findmnt -n -M "$root" -o SOURCE) || { echo 'Encrypted root is not a mount point' >&2; exit 1; }
|
||||
device=$(printf '%s\n' "$source" | sed 's/\[.*$//')
|
||||
case "$device" in /dev/*) ;; *) echo 'Encrypted root must be backed by a block device' >&2; exit 1 ;; esac
|
||||
lsblk -s -n -r -o TYPE "$device" | grep -Fxq crypt || {
|
||||
echo 'Encrypted root is not backed by an active dm-crypt mapping' >&2
|
||||
exit 1
|
||||
}
|
||||
|
||||
for relative in $directories; do
|
||||
path=$root/$relative
|
||||
[ ! -L "$root/cluster" ] || { echo 'Refusing symlink under encrypted root' >&2; exit 1; }
|
||||
[ ! -L "$path" ] || { echo "Refusing symlink: $path" >&2; exit 1; }
|
||||
if [ -d "$path" ] && [ ! -e "$path/.objectstore-encrypted" ] &&
|
||||
[ -n "$(find "$path" -mindepth 1 -maxdepth 1 -print -quit)" ]; then
|
||||
echo "Refusing to mark nonempty directory: $path" >&2
|
||||
exit 1
|
||||
fi
|
||||
install -d -m 0700 "$path"
|
||||
[ "$(findmnt -n -T "$path" -o TARGET)" = "$root" ] || {
|
||||
echo "Directory is not on the encrypted mount: $path" >&2
|
||||
exit 1
|
||||
}
|
||||
marker=$path/.objectstore-encrypted
|
||||
if [ -e "$marker" ]; then
|
||||
[ ! -L "$marker" ] && [ "$(cat "$marker")" = "$id" ] || {
|
||||
echo "Encrypted volume marker mismatch: $path" >&2
|
||||
exit 1
|
||||
}
|
||||
else
|
||||
printf '%s\n' "$id" > "$marker"
|
||||
fi
|
||||
chmod 0600 "$marker"
|
||||
case "$relative" in
|
||||
cluster/metadata|cluster/metadata-recovery) chown 70:70 "$path" "$marker" ;;
|
||||
*) chown 10001:10001 "$path" "$marker" ;;
|
||||
esac
|
||||
done
|
||||
|
||||
echo "Prepared $mode paths on the active encrypted mount: $root"
|
||||
@@ -8,6 +8,7 @@ java --add-modules jdk.httpserver -cp out/classes:lib/hash4j-0.30.0.jar cloud.lu
|
||||
java --add-modules jdk.httpserver -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.ConcurrencyTest
|
||||
java --add-modules jdk.httpserver,java.net.http -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.HttpTest
|
||||
java --add-modules jdk.httpserver,java.net.http -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.ClientLimitsTest
|
||||
java -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.EncryptedVolumeTest
|
||||
java --add-modules jdk.httpserver,java.net.http -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.ClusterNodeTest
|
||||
java --add-modules jdk.httpserver,java.net.http -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.ClusterTlsTest
|
||||
java -cp out/classes:lib/hash4j-0.30.0.jar cloud.lunarsky.store.CliTest
|
||||
|
||||
Reference in new issue
Block a user