Delete the lab's registry, and bootstrap the anchor through the installer #19
@@ -370,6 +370,15 @@ async function deliverCaRoot(): Promise<boolean> {
|
||||
"rm -f root.unenc",
|
||||
"openssl req -x509 -new -key root.key -passin file:key-password -sha256 -days 3650" +
|
||||
` -out root.crt -subj "/CN=Mesh Internal CA/O=Novox Mesh Lab"`,
|
||||
// Readable by the control plane, which is not root. Its image is FROM scratch and runs as
|
||||
// 65534, and `docker cp` keeps the ownership and mode a file had outside — openssl writes a
|
||||
// private key 0600 root-owned, so the copy landed unreadable and `secret accept` failed with
|
||||
// `open /ca-root-key: permission denied`. The CA then crash-looped on a root it never got.
|
||||
// Chowning it inside the container is not available: there is no shell in there to do it with.
|
||||
//
|
||||
// Safe here and nowhere else: these three exist for the seconds between being written and
|
||||
// being sealed to the machine, on a lab node, for a CA thrown away with the scenario.
|
||||
"chmod 0644 /tmp/ca/root.crt /tmp/ca/root.key /tmp/ca/key-password",
|
||||
"docker cp /tmp/ca/root.crt mesh-control:/ca-root-cert",
|
||||
"docker cp /tmp/ca/root.key mesh-control:/ca-root-key",
|
||||
"docker cp /tmp/ca/key-password mesh-control:/ca-root-key-password",
|
||||
|
||||
Reference in New Issue
Block a user