Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 6 additions & 6 deletions .github/workflows/seismic.yml
Original file line number Diff line number Diff line change
Expand Up @@ -93,15 +93,15 @@ jobs:
bash -n \
modules/seismic/mkosi.build \
modules/seismic/mkosi.postinst \
modules/seismic/mkosi.extra/usr/bin/setup-nginx-ssl \
modules/seismic/mkosi.extra/usr/bin/setup-persistent-luks \
modules/seismic/mkosi.extra/usr/bin/nginx-ssl-setup \
modules/seismic/mkosi.extra/usr/bin/persistent-luks-setup \
scripts/seismic/founding_inputs.sh \
scripts/seismic/image_json.sh
shellcheck -x \
modules/seismic/mkosi.build \
modules/seismic/mkosi.postinst \
modules/seismic/mkosi.extra/usr/bin/setup-nginx-ssl \
modules/seismic/mkosi.extra/usr/bin/setup-persistent-luks \
modules/seismic/mkosi.extra/usr/bin/nginx-ssl-setup \
modules/seismic/mkosi.extra/usr/bin/persistent-luks-setup \
scripts/seismic/founding_inputs.sh \
scripts/seismic/image_json.sh

Expand Down Expand Up @@ -183,11 +183,11 @@ jobs:
etc/systemd/system/minimal.target.wants/summit-key-holder.service
etc/systemd/system/minimal.target.wants/summit.service
etc/systemd/system/minimal.target.wants/tdx-init.service
usr/bin/nginx-ssl-setup
usr/bin/persistent-luks-setup
usr/bin/seismic-attestation-service
usr/bin/seismic-custodian-service
usr/bin/seismic-reth
usr/bin/setup-nginx-ssl
usr/bin/setup-persistent-luks
usr/bin/summit
usr/bin/summit-key-holder
usr/bin/tdx-init
Expand Down
2 changes: 1 addition & 1 deletion modules/seismic/kernel/config.d/10-seismic
Original file line number Diff line number Diff line change
Expand Up @@ -41,6 +41,6 @@ CONFIG_CRYPTO_USER_API_SKCIPHER=y
CONFIG_CRYPTO_USER_API_RNG=y
CONFIG_CRYPTO_USER_API_AEAD=y

# We use dm-integrity in setup-persistent-luks's authenticated FDE setup:
# We use dm-integrity in persistent-luks-setup's authenticated FDE setup:
# cryptsetup luksFormat --integrity hmac-sha256 ...
CONFIG_DM_INTEGRITY=y
2 changes: 1 addition & 1 deletion modules/seismic/mkosi.conf
Original file line number Diff line number Diff line change
Expand Up @@ -24,7 +24,7 @@ ImageId=seismic
#
# Prereqs before this is sane to land:
# 1. Signed-PCR-policy LUKS enrollment (the BLOCKER header in
# setup-persistent-luks) must land first — else every release
# persistent-luks-setup) must land first — else every release
# rebases roothash → PCR 11 → bricks unlock on first update.
# 2. Audit and relocate /usr/ writes from runtime scripts. Main
# offender is certbot's /etc/letsencrypt/; converges with
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ Requires=persistent-luks-setup.service tdx-init.service

[Service]
Type=oneshot
ExecStart=/usr/bin/setup-nginx-ssl
ExecStart=/usr/bin/nginx-ssl-setup
StandardOutput=journal
StandardError=journal

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@ Requires=custodian.service attestation.service
Type=oneshot
RemainAfterExit=yes

ExecStart=/usr/bin/setup-persistent-luks
ExecStart=/usr/bin/persistent-luks-setup
# Materialize per-service /persistent/<svc> ownership and mode now that /persistent is mounted.
ExecStartPost=/usr/bin/systemd-tmpfiles --create /etc/seismic/tmpfiles-persistent.conf

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ d /run/seismic 0755 root root -
# Custodian IPC namespace: the custodian's socket plus its LUKS-keyfile
# drop-zone. setgid makes the socket inherit custodian-ipc for authorized
# local clients (the keyfile itself is 0400, readable only by root's
# setup-persistent-luks).
# persistent-luks-setup).
d /run/seismic/custodian 2750 custodian custodian-ipc -
# tdx-init's config drop-zone — everything the operator POST fans out to:
# domain.env, custodian.env, attestation.env, network-manifest.json,
Expand All @@ -23,7 +23,7 @@ d /run/seismic/custodian 2750 custodian custodian-ipc -
# supplementary group (set in mkosi.postinst). Mirrors the /persistent/conf
# semantics from tmpfiles-persistent.conf.
d /run/seismic/conf 2750 tdx-init conf -
# LUKS-wipe progress drop-zone: setup-persistent-luks (runs as root) writes
# LUKS-wipe progress drop-zone: persistent-luks-setup (runs as root) writes
# luks.json here during the long first-boot wipe, and the attestation service
# serves it via getLuksProvisioningStatus for the operator CLI's progress bar.
# Only root writes; the attestation service reads the world-readable (0644)
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -44,7 +44,7 @@ set -Eeuo pipefail
# then retries per Restart=on-failure, overwriting this on the next attempt).
on_error() {
local rc=$?
write_status_json "$(jq -cn --arg e "setup-persistent-luks failed (rc=$rc); see journalctl -u persistent-luks-setup.service" \
write_status_json "$(jq -cn --arg e "persistent-luks-setup failed (rc=$rc); see journalctl -u persistent-luks-setup.service" \
'{state:"error", error:$e}' 2>/dev/null)"
return "$rc"
}
Expand Down Expand Up @@ -95,7 +95,7 @@ TOKEN_TYPE="seismic-header-mac"
DEFAULT_DISK_GLOB="/dev/disk/by-path/*10"
DISK_GLOB_OVERRIDE_FILE="/etc/seismic-images/persistent-disk-glob"

log() { echo "[setup-persistent-luks] $*" >&2; }
log() { echo "[persistent-luks-setup] $*" >&2; }

# True iff this boot runs in genesis launch mode (the custodian minted a
# fresh root_key locally instead of fetching one from a peer). Missing file
Expand Down
6 changes: 3 additions & 3 deletions modules/seismic/mkosi.postinst
Original file line number Diff line number Diff line change
Expand Up @@ -26,8 +26,8 @@ mkosi-chroot useradd -r -s /bin/false -G conf,engine-api,custodian-ipc reth
mkosi-chroot useradd -r -s /bin/false -G conf,engine-api,tpm summit

# Make scripts executable
chmod +x "$BUILDROOT/usr/bin/setup-nginx-ssl"
chmod +x "$BUILDROOT/usr/bin/setup-persistent-luks"
chmod +x "$BUILDROOT/usr/bin/nginx-ssl-setup"
chmod +x "$BUILDROOT/usr/bin/persistent-luks-setup"

# Enable services
mkdir -p "$BUILDROOT/etc/systemd/system/minimal.target.wants"
Expand All @@ -45,4 +45,4 @@ do
ln -sf "/etc/systemd/system/$service" "$BUILDROOT/etc/systemd/system/minimal.target.wants/"
done

# Note: certbot-renew.timer is enabled by setup-nginx-ssl after initial certbot run
# Note: certbot-renew.timer is enabled by nginx-ssl-setup after initial certbot run
12 changes: 6 additions & 6 deletions modules/seismic/readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ mkosi.extra/
│ ├── systemd/system/*.{service,timer} → /etc/systemd/system/...
│ └── udev/rules.d/60-tpm-permissions.rules → /etc/udev/rules.d/...
└── usr/
└── bin/{setup-nginx-ssl,setup-persistent-luks} → /usr/bin/...
└── bin/{nginx-ssl-setup,persistent-luks-setup} → /usr/bin/...
```

Module-root files that are **not** in the image: `mkosi.conf`,
Expand Down Expand Up @@ -129,9 +129,9 @@ provisioner POSTs the node's configuration (TOML: `[network]` with the
base64 network manifest + reth/summit geneses + bootnodes, and `[node]`
with external_ip, genesis_node, and the domain name/email) via HTTP. On
receipt tdx-init translates the payload into per-service config files
under `/run/seismic/conf/`: `domain.env` (for `setup-nginx-ssl`),
under `/run/seismic/conf/`: `domain.env` (for `nginx-ssl-setup`),
`custodian.env` (consumed by `custodian.service` via `EnvironmentFile=`,
and read by `setup-persistent-luks` for the genesis-mode guard),
and read by `persistent-luks-setup` for the genesis-mode guard),
`attestation.env` (likewise by `attestation.service`),
`network-manifest.json` (hashed by the attestation service into
`network_id`; its appearance also closes `summit-key-holder.service`'s
Expand All @@ -149,7 +149,7 @@ Runs as the `tdx-init` system user (group `conf`). The runtime dir is
materialized with `tdx-init:conf 2750` by systemd-tmpfiles at
sysinit.target, before any service starts.

`setup-nginx-ssl` sources `domain.env` for certbot. `custodian.service`
`nginx-ssl-setup` sources `domain.env` for certbot. `custodian.service`
reads `SEISMIC_CUSTODIAN_GENESIS_NODE` from `custodian.env` and
`attestation.service` reads `SEISMIC_ROOT_KEY_PEERS` from
`attestation.env`; the attestation service fails fast at startup if the
Expand Down Expand Up @@ -198,7 +198,7 @@ method. A genesis node generates `root_key` at startup
acquires it through the bootstrap methods driven by the attestation
service. Whenever the root key becomes present, the custodian drops the
LUKS keyfile at `/run/seismic/custodian/luks-keys` for
`setup-persistent-luks` (see boot diagram above).
`persistent-luks-setup` (see boot diagram above).

### `attestation.service`

Expand All @@ -219,7 +219,7 @@ restart; tight loops would hammer the TPM.
### `persistent-luks-setup.service`

Oneshot that runs
[`setup-persistent-luks`](mkosi.extra/usr/bin/setup-persistent-luks):
[`persistent-luks-setup`](mkosi.extra/usr/bin/persistent-luks-setup):
waits for the LUKS keys from the custodian, verifies the on-disk
header, opens the LUKS volume, and mounts it at `/persistent`. In
genesis mode it refuses to start over an already-provisioned volume
Expand Down