Files
pangolin/server/internal/agentd/creds.go
wangjia f03d2dc8a6 feat(agent): node agent — enroll/mTLS, heartbeat, command stream, sing-box 用户表 (tsk__R8M4jEw43JR)
与控制面同仓同 go.mod,新增节点 agent 实现:

- proto/agent/v1/agent.proto + internal/pb/agentv1:冻结的控制面↔agent gRPC 契约
  (Enroll/Register/Heartbeat/Subscribe/Ack/ReportUsage)。仓库尚无 protoc 流水线,
  暂以手写 Go 类型 + JSON gRPC codec 实现,与 proto 1:1 对应,待 protoc 接入即可替换。
- internal/agentd:
  - enroll.go:首启生成 EC 密钥+CSR,持 bootstrap token 调 Enroll 换 90d 节点证书
    (CN=node_uuid),落 /etc/pangolin-agent/,此后 mTLS。
  - conn.go(agent.go)+creds.go:mTLS 主动拨号 + 指数退避重连;重连携带 last_command_id;
    Register 取 ConfigSnapshot 全量配置覆盖本地。
  - heartbeat.go:30s 上报 peer/带宽/CPU + config_version;need_full_resync→全量同步。
  - command.go:消费 Subscribe,Upsert/Revoke/Rotate/ApplyConfig/Lifecycle 幂等处理后
    Ack(at-least-once,按 command_id 去重)。
  - singbox.go+render.go:内存用户表 + 落盘 state.json(仅 dp_uuid+expires_at);任何变更
    渲染完整 sing-box 配置(REALITY users[uuid,flow] + Hy2 users[派生口令])→ 500ms 去抖
    合并 → systemd 重启。
  - ttl.go:凭证 TTL 定时移除并上报。
  - usage.go:按 dp_uuid 聚合上报,绝无 user_id/email/目的地址。
  - derive.go:Hy2 口令 = HMAC-SHA256(key, dp_uuid),与控制面同源派生。
- cmd/agent:入口(flag/env 配置)。
- infra/cloud-init/{node.yaml.tmpl,install-node.sh,README.md}:一段式安装,下载锁定版本
  二进制并校验 SHA-256,systemd 拉管,首启即 Enroll/Register。shellcheck -S warning 通过。

测试(bufconn mock 控制面,无需 docker):Enroll→Register→Heartbeat 全流转;Upsert/Revoke
渲染正确;Rotate 宽限期新旧并存到点移除;TTL 自动移除并上报;断流重连 last_command_id
续发不丢不重;need_full_resync 触发重注册;state.json 恢复;去抖合并;扫描确认无身份字段。
go test -race ./internal/agentd/... ./internal/pb/... 通过;go vet ./... 通过。

落实 doc/04 §2 节点无状态化与 doc/06 §3 数据面红线(节点仅见 dp_uuid)。

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 12:26:58 +08:00

102 lines
3.1 KiB
Go

package agentd
import (
"context"
"crypto/tls"
"crypto/x509"
"errors"
"fmt"
"net"
"os"
"google.golang.org/grpc"
"google.golang.org/grpc/credentials"
"google.golang.org/grpc/credentials/insecure"
)
// Dialer opens an authenticated long-lived connection to the control plane.
type Dialer func(ctx context.Context) (*grpc.ClientConn, error)
// mtlsClientConfig builds the client *tls.Config from the persisted node key/cert
// and pinned CA.
func mtlsClientConfig(cfg Config) (*tls.Config, error) {
cert, err := tls.LoadX509KeyPair(cfg.CertPath(), cfg.KeyPath())
if err != nil {
return nil, fmt.Errorf("agentd: load client keypair: %w", err)
}
caPEM, err := os.ReadFile(cfg.CAPath())
if err != nil {
return nil, fmt.Errorf("agentd: read CA: %w", err)
}
pool := x509.NewCertPool()
if !pool.AppendCertsFromPEM(caPEM) {
return nil, errors.New("agentd: CA file contains no certificate")
}
return &tls.Config{
Certificates: []tls.Certificate{cert},
RootCAs: pool,
ServerName: cfg.tlsServerName(),
MinVersion: tls.VersionTLS13,
}, nil
}
// tlsServerName returns the SNI to validate the control-plane cert against.
func (c Config) tlsServerName() string {
if c.ServerName != "" {
return c.ServerName
}
host, _, err := net.SplitHostPort(c.ControlPlaneAddr)
if err != nil {
return c.ControlPlaneAddr
}
return host
}
// NewMTLSDialer returns a Dialer that connects to the control plane over mTLS,
// presenting the node's client certificate.
func NewMTLSDialer(cfg Config) Dialer {
return func(ctx context.Context) (*grpc.ClientConn, error) {
tlsCfg, err := mtlsClientConfig(cfg)
if err != nil {
return nil, err
}
return grpc.NewClient(cfg.ControlPlaneAddr,
grpc.WithTransportCredentials(credentials.NewTLS(tlsCfg)),
)
}
}
// NewEnrollDialer returns an EnrollDialer for the bootstrap (pre-certificate)
// Enroll call. It pins the control-plane CA if ca.crt is already present
// (cloud-init may inject it); otherwise it falls back to a server-unauthenticated
// TLS handshake — the bootstrap token is the trust anchor for that single call.
func NewEnrollDialer(cfg Config) EnrollDialer {
return func(ctx context.Context) (*grpc.ClientConn, error) {
var creds credentials.TransportCredentials
if caPEM, err := os.ReadFile(cfg.CAPath()); err == nil {
pool := x509.NewCertPool()
if !pool.AppendCertsFromPEM(caPEM) {
return nil, errors.New("agentd: pinned CA file invalid")
}
creds = credentials.NewTLS(&tls.Config{
RootCAs: pool,
ServerName: cfg.tlsServerName(),
MinVersion: tls.VersionTLS13,
})
} else {
creds = credentials.NewTLS(&tls.Config{
InsecureSkipVerify: true, //nolint:gosec // bootstrap-token-authenticated enroll only
MinVersion: tls.VersionTLS13,
})
}
return grpc.NewClient(cfg.ControlPlaneAddr, grpc.WithTransportCredentials(creds))
}
}
// insecureDialer is used only by tests/dev (cfg.Insecure).
func insecureDialer(addr string) Dialer {
return func(ctx context.Context) (*grpc.ClientConn, error) {
return grpc.NewClient(addr, grpc.WithTransportCredentials(insecure.NewCredentials()))
}
}