f03d2dc8a6
与控制面同仓同 go.mod,新增节点 agent 实现:
- proto/agent/v1/agent.proto + internal/pb/agentv1:冻结的控制面↔agent gRPC 契约
(Enroll/Register/Heartbeat/Subscribe/Ack/ReportUsage)。仓库尚无 protoc 流水线,
暂以手写 Go 类型 + JSON gRPC codec 实现,与 proto 1:1 对应,待 protoc 接入即可替换。
- internal/agentd:
- enroll.go:首启生成 EC 密钥+CSR,持 bootstrap token 调 Enroll 换 90d 节点证书
(CN=node_uuid),落 /etc/pangolin-agent/,此后 mTLS。
- conn.go(agent.go)+creds.go:mTLS 主动拨号 + 指数退避重连;重连携带 last_command_id;
Register 取 ConfigSnapshot 全量配置覆盖本地。
- heartbeat.go:30s 上报 peer/带宽/CPU + config_version;need_full_resync→全量同步。
- command.go:消费 Subscribe,Upsert/Revoke/Rotate/ApplyConfig/Lifecycle 幂等处理后
Ack(at-least-once,按 command_id 去重)。
- singbox.go+render.go:内存用户表 + 落盘 state.json(仅 dp_uuid+expires_at);任何变更
渲染完整 sing-box 配置(REALITY users[uuid,flow] + Hy2 users[派生口令])→ 500ms 去抖
合并 → systemd 重启。
- ttl.go:凭证 TTL 定时移除并上报。
- usage.go:按 dp_uuid 聚合上报,绝无 user_id/email/目的地址。
- derive.go:Hy2 口令 = HMAC-SHA256(key, dp_uuid),与控制面同源派生。
- cmd/agent:入口(flag/env 配置)。
- infra/cloud-init/{node.yaml.tmpl,install-node.sh,README.md}:一段式安装,下载锁定版本
二进制并校验 SHA-256,systemd 拉管,首启即 Enroll/Register。shellcheck -S warning 通过。
测试(bufconn mock 控制面,无需 docker):Enroll→Register→Heartbeat 全流转;Upsert/Revoke
渲染正确;Rotate 宽限期新旧并存到点移除;TTL 自动移除并上报;断流重连 last_command_id
续发不丢不重;need_full_resync 触发重注册;state.json 恢复;去抖合并;扫描确认无身份字段。
go test -race ./internal/agentd/... ./internal/pb/... 通过;go vet ./... 通过。
落实 doc/04 §2 节点无状态化与 doc/06 §3 数据面红线(节点仅见 dp_uuid)。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
96 lines
2.8 KiB
Go
96 lines
2.8 KiB
Go
package agentd
|
|
|
|
import (
|
|
"encoding/json"
|
|
|
|
agentv1 "github.com/wangjia/pangolin/server/internal/pb/agentv1"
|
|
)
|
|
|
|
// renderSingboxConfig produces a complete sing-box SERVER config JSON for the node:
|
|
// a VLESS+REALITY inbound and a Hysteria2 inbound, each carrying one user per
|
|
// provisioned credential. REALITY users key on the dp_uuid; Hy2 users key on the
|
|
// derived password (DeriveHy2Password) — both from the same dp_uuid source.
|
|
//
|
|
// Only the opaque dp_uuid is ever written; no account identity touches the node.
|
|
func renderSingboxConfig(creds []Cred, reality *agentv1.RealityInbound, hy2 *agentv1.Hy2Inbound, deriveKey string) ([]byte, error) {
|
|
cfg := map[string]any{
|
|
"log": map[string]any{"level": "warn", "timestamp": true},
|
|
"inbounds": buildInbounds(creds, reality, hy2, deriveKey),
|
|
"outbounds": []any{map[string]any{"type": "direct", "tag": "direct"}},
|
|
}
|
|
return json.MarshalIndent(cfg, "", " ")
|
|
}
|
|
|
|
func buildInbounds(creds []Cred, reality *agentv1.RealityInbound, hy2 *agentv1.Hy2Inbound, deriveKey string) []any {
|
|
inbounds := make([]any, 0, 2)
|
|
|
|
if reality != nil {
|
|
users := make([]any, 0, len(creds))
|
|
for _, c := range creds {
|
|
if c.Protocol == agentv1.ProtocolReality || c.Protocol == agentv1.ProtocolBoth {
|
|
flow := c.Flow
|
|
if flow == "" {
|
|
flow = DefaultFlow
|
|
}
|
|
users = append(users, map[string]any{
|
|
"name": c.DpUUID,
|
|
"uuid": c.DpUUID,
|
|
"flow": flow,
|
|
})
|
|
}
|
|
}
|
|
realityTLS := map[string]any{
|
|
"enabled": true,
|
|
"server_name": reality.ServerName,
|
|
"reality": map[string]any{
|
|
"enabled": true,
|
|
"private_key": reality.PrivateKey,
|
|
"short_id": []string{reality.ShortID},
|
|
"handshake": map[string]any{
|
|
"server": reality.HandshakeServer,
|
|
"server_port": reality.HandshakePort,
|
|
},
|
|
},
|
|
}
|
|
inbounds = append(inbounds, map[string]any{
|
|
"type": "vless",
|
|
"tag": "reality-in",
|
|
"listen": "::",
|
|
"listen_port": reality.ListenPort,
|
|
"users": users,
|
|
"tls": realityTLS,
|
|
})
|
|
}
|
|
|
|
if hy2 != nil {
|
|
users := make([]any, 0, len(creds))
|
|
for _, c := range creds {
|
|
if c.Protocol == agentv1.ProtocolHy2 || c.Protocol == agentv1.ProtocolBoth {
|
|
users = append(users, map[string]any{
|
|
"name": c.DpUUID,
|
|
"password": DeriveHy2Password(c.DpUUID, deriveKey),
|
|
})
|
|
}
|
|
}
|
|
hy2In := map[string]any{
|
|
"type": "hysteria2",
|
|
"tag": "hy2-in",
|
|
"listen": "::",
|
|
"listen_port": hy2.ListenPort,
|
|
"users": users,
|
|
"tls": map[string]any{
|
|
"enabled": true,
|
|
"alpn": []string{"h3"},
|
|
"certificate_path": hy2.CertPath,
|
|
"key_path": hy2.KeyPath,
|
|
},
|
|
}
|
|
if hy2.Masquerade != "" {
|
|
hy2In["masquerade"] = hy2.Masquerade
|
|
}
|
|
inbounds = append(inbounds, hy2In)
|
|
}
|
|
|
|
return inbounds
|
|
}
|