fix: PVE role/user idempotency + init pre-staging instructions

- createPVERole: use grep -qF + fallback to pveum role mod (was broken
  by single-quote-in-grep pattern: grep -q '^'OrcaOperator'')
- createPVEUser: same idempotency fix (grep -qF + fallback to mod)
- orca init: prints ssh-copy-id instructions with the orca public key
  path after generating the SSH keypair
- docs/uat.md: removed manual pre-staging (ssh-keygen, ssh-copy-id
  with operator key, host-key fingerprint pinning). orca init handles
  key generation; node join uses the orca key by default; TOFU is
  automatic. Updated node join examples to not pass --ssh-key or
  --host-key-fingerprint.

---ci---
project: orca
status: fix
---/ci---
This commit is contained in:
Jon Chery
2026-08-10 17:07:30 +00:00
parent 00efe25ce4
commit d324939699
3 changed files with 36 additions and 42 deletions
+26 -35
View File
@@ -21,52 +21,45 @@ Use `--type linux` for all remote nodes. Proxmox-specific claims
(`doctor proxmox`, PVE role, sudoers) are **skipped** in this path.
The signoff script reports exercised vs. skipped claims.
### Pre-staging
1. Build orca from the v0.13 tag:
```sh
git clone https://git.cloudinit.dev/coreci/orca.git
cd orca && git checkout v0.12.13
make build
# binary is at bin/orca
```
2. Generate the orca SSH keypair on the lead:
```sh
ssh-keygen -t ed25519 -f ~/.ssh/orca_ed25519 -N ""
```
3. Pre-stage the orca public key on pve01 and worker01:
```sh
ssh-copy-id -i ~/.ssh/orca_ed25519.pub root@pve01
ssh-copy-id -i ~/.ssh/orca_ed25519.pub root@worker01
```
4. Pin host-key fingerprints (optional but recommended):
```sh
ssh-keyscan pve01 | ssh-keygen -lf -
ssh-keyscan worker01 | ssh-keygen -lf -
```
## Step-by-step UAT
### Step 1: Initialize the cluster
### Step 1: Install orca + initialize the cluster
Install orca (1-liner):
```sh
curl -fsSL https://git.cloudinit.dev/coreci/orca/raw/branch/main/scripts/install.sh | bash
```
Initialize the cluster:
```sh
export ORCA_HOME=~/orca-uat
orca init
```
**Expected**: cluster directory created, CA cert generated, localhost node registered.
**Expected**: orca init creates:
- CA cert + server cert
- SSH keypair (orca_ssh_key + orca_ssh_key.pub)
- known_hosts file (empty, for TOFU capture)
- Master key (for secrets encryption)
- Traefik data-plane ingress (binary + systemd unit + config)
- Localhost node registered
**Pre-staging remote nodes**: `orca init` prints the orca public key path.
Deploy it to each remote host before joining:
```sh
ssh-copy-id -i $ORCA_HOME/orca_ssh_key.pub root@pve01
ssh-copy-id -i $ORCA_HOME/orca_ssh_key.pub root@worker01
```
The TOFU host-key capture is automatic — no manual fingerprint pinning needed.
The first SSH connection captures and stores the remote host key.
### Step 2: Onboard the Proxmox host
```sh
orca node join --type proxmox \
--host pve01 \
--ssh-user root \
--ssh-key ~/.ssh/orca_ed25519 \
--host-key-fingerprint SHA256:<fingerprint>
--ssh-user root
```
**Expected**: SSH bootstrap succeeds, orca user created, PVE role assigned, node registered as `ready` with `kind=proxmox`.
@@ -76,9 +69,7 @@ orca node join --type proxmox \
```sh
orca node join --type linux \
--host worker01 \
--ssh-user root \
--ssh-key ~/.ssh/orca_ed25519 \
--host-key-fingerprint SHA256:<fingerprint>
--ssh-user root
```
**Expected**: SSH bootstrap succeeds, orca user created, drift-events dir created, node registered as `ready` with `kind=linux`.