f03d2dc8a6
与控制面同仓同 go.mod,新增节点 agent 实现:
- proto/agent/v1/agent.proto + internal/pb/agentv1:冻结的控制面↔agent gRPC 契约
(Enroll/Register/Heartbeat/Subscribe/Ack/ReportUsage)。仓库尚无 protoc 流水线,
暂以手写 Go 类型 + JSON gRPC codec 实现,与 proto 1:1 对应,待 protoc 接入即可替换。
- internal/agentd:
- enroll.go:首启生成 EC 密钥+CSR,持 bootstrap token 调 Enroll 换 90d 节点证书
(CN=node_uuid),落 /etc/pangolin-agent/,此后 mTLS。
- conn.go(agent.go)+creds.go:mTLS 主动拨号 + 指数退避重连;重连携带 last_command_id;
Register 取 ConfigSnapshot 全量配置覆盖本地。
- heartbeat.go:30s 上报 peer/带宽/CPU + config_version;need_full_resync→全量同步。
- command.go:消费 Subscribe,Upsert/Revoke/Rotate/ApplyConfig/Lifecycle 幂等处理后
Ack(at-least-once,按 command_id 去重)。
- singbox.go+render.go:内存用户表 + 落盘 state.json(仅 dp_uuid+expires_at);任何变更
渲染完整 sing-box 配置(REALITY users[uuid,flow] + Hy2 users[派生口令])→ 500ms 去抖
合并 → systemd 重启。
- ttl.go:凭证 TTL 定时移除并上报。
- usage.go:按 dp_uuid 聚合上报,绝无 user_id/email/目的地址。
- derive.go:Hy2 口令 = HMAC-SHA256(key, dp_uuid),与控制面同源派生。
- cmd/agent:入口(flag/env 配置)。
- infra/cloud-init/{node.yaml.tmpl,install-node.sh,README.md}:一段式安装,下载锁定版本
二进制并校验 SHA-256,systemd 拉管,首启即 Enroll/Register。shellcheck -S warning 通过。
测试(bufconn mock 控制面,无需 docker):Enroll→Register→Heartbeat 全流转;Upsert/Revoke
渲染正确;Rotate 宽限期新旧并存到点移除;TTL 自动移除并上报;断流重连 last_command_id
续发不丢不重;need_full_resync 触发重注册;state.json 恢复;去抖合并;扫描确认无身份字段。
go test -race ./internal/agentd/... ./internal/pb/... 通过;go vet ./... 通过。
落实 doc/04 §2 节点无状态化与 doc/06 §3 数据面红线(节点仅见 dp_uuid)。
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
113 lines
3.8 KiB
Go
113 lines
3.8 KiB
Go
// Package agentd implements the Pangolin node agent: a lightweight daemon that
|
|
// runs on every acceleration node. It self-enrolls over mTLS, dials the control
|
|
// plane (the agent is always the dialer), keeps a long-lived gRPC connection with
|
|
// exponential-backoff reconnect, reports heartbeat/usage, and applies the streamed
|
|
// command feed by managing the local sing-box user table.
|
|
//
|
|
// No-state invariant (doc/04 §2, doc/06 §3): the agent persists ONLY the
|
|
// credential table (dp_uuid + expires_at) to disk. It keeps zero user identities,
|
|
// zero destination/DNS data and writes no access logs. A seized node leaks only
|
|
// opaque dp_uuids, never accounts.
|
|
package agentd
|
|
|
|
import (
|
|
"path/filepath"
|
|
"time"
|
|
)
|
|
|
|
// Default tuning values. The intervals match doc/06 (30s heartbeat) and the
|
|
// 500ms render debounce that batches bursts of credential changes into a single
|
|
// sing-box restart (sing-box has no hot-reload; a restart is a ~1-2s blip).
|
|
const (
|
|
DefaultHeartbeatInterval = 30 * time.Second
|
|
DefaultUsageInterval = 60 * time.Second
|
|
DefaultTTLScanInterval = 15 * time.Second
|
|
DefaultDebounceWindow = 500 * time.Millisecond
|
|
DefaultDialTimeout = 10 * time.Second
|
|
|
|
DefaultBackoffMin = 1 * time.Second
|
|
DefaultBackoffMax = 60 * time.Second
|
|
|
|
DefaultStateDir = "/etc/pangolin-agent"
|
|
DefaultSingboxCfg = "/etc/sing-box/config.json"
|
|
|
|
// DefaultFlow is the REALITY VLESS flow (doc/02 §3.1).
|
|
DefaultFlow = "xtls-rprx-vision"
|
|
)
|
|
|
|
// Config holds everything the agent needs. Most fields come from cloud-init
|
|
// (control-plane address + bootstrap token) or have safe defaults.
|
|
type Config struct {
|
|
// ControlPlaneAddr is the control plane gRPC endpoint (host:port).
|
|
ControlPlaneAddr string
|
|
// ServerName overrides the TLS SNI used when dialing (defaults to the host
|
|
// part of ControlPlaneAddr). The control plane cert must match it.
|
|
ServerName string
|
|
|
|
// BootstrapToken is the one-time cloud-init token consumed during Enroll.
|
|
// Ignored once the node already holds a certificate.
|
|
BootstrapToken string
|
|
|
|
// StateDir holds node.key/node.crt/ca.crt and state.json.
|
|
StateDir string
|
|
// SingboxConfigPath is where the rendered sing-box config is written.
|
|
SingboxConfigPath string
|
|
|
|
// DeriveKey keys the Hy2 password derivation (see DeriveHy2Password).
|
|
DeriveKey string
|
|
|
|
AgentVersion string
|
|
|
|
HeartbeatInterval time.Duration
|
|
UsageInterval time.Duration
|
|
TTLScanInterval time.Duration
|
|
DebounceWindow time.Duration
|
|
DialTimeout time.Duration
|
|
BackoffMin time.Duration
|
|
BackoffMax time.Duration
|
|
|
|
// Insecure dials without mTLS. ONLY for local dev / integration tests.
|
|
Insecure bool
|
|
}
|
|
|
|
// withDefaults returns a copy of c with zero-valued tunables filled in.
|
|
func (c Config) withDefaults() Config {
|
|
if c.StateDir == "" {
|
|
c.StateDir = DefaultStateDir
|
|
}
|
|
if c.SingboxConfigPath == "" {
|
|
c.SingboxConfigPath = DefaultSingboxCfg
|
|
}
|
|
if c.HeartbeatInterval == 0 {
|
|
c.HeartbeatInterval = DefaultHeartbeatInterval
|
|
}
|
|
if c.UsageInterval == 0 {
|
|
c.UsageInterval = DefaultUsageInterval
|
|
}
|
|
if c.TTLScanInterval == 0 {
|
|
c.TTLScanInterval = DefaultTTLScanInterval
|
|
}
|
|
if c.DebounceWindow == 0 {
|
|
c.DebounceWindow = DefaultDebounceWindow
|
|
}
|
|
if c.DialTimeout == 0 {
|
|
c.DialTimeout = DefaultDialTimeout
|
|
}
|
|
if c.BackoffMin == 0 {
|
|
c.BackoffMin = DefaultBackoffMin
|
|
}
|
|
if c.BackoffMax == 0 {
|
|
c.BackoffMax = DefaultBackoffMax
|
|
}
|
|
if c.AgentVersion == "" {
|
|
c.AgentVersion = "dev"
|
|
}
|
|
return c
|
|
}
|
|
|
|
// Paths to the on-disk PKI + state material.
|
|
func (c Config) KeyPath() string { return filepath.Join(c.StateDir, "node.key") }
|
|
func (c Config) CertPath() string { return filepath.Join(c.StateDir, "node.crt") }
|
|
func (c Config) CAPath() string { return filepath.Join(c.StateDir, "ca.crt") }
|
|
func (c Config) StatePath() string { return filepath.Join(c.StateDir, "state.json") }
|