31ccb52114
Wave B/C/D of P01 mTLS implementation.
- internal/audit/audit.go — thin wrapper around engine.Audit for
cert/handshake events (Action* and Result* constants; REQ-038).
- internal/certpaths/ — extracted path constants out of cli to break
the cli<->doctor import cycle; cli re-exports the helpers for
backward compat.
- internal/security/ca.go — public WriteCert/WriteKey helpers (0600
for keys, 0644 for certs; REQ-033); used by the cert CLI and
integration test.
- internal/daemon/tls.go — mTLS server with GetCertificate hot-swap
callback. Plaintext HTTP remains the default for v0.1 compat;
StartMTLS() flips the server into mTLS mode.
- internal/daemon/server.go — adds mtls *MTLSState field; MTLSActive()
getter for health endpoints.
- internal/transport/mtls.go — mTLS client with VerifyPeerCertificate
for pinned peer identity; DialContext for raw TLS.
- internal/transport/handshake_log.go — structured slog helpers for
handshake ok/fail (REQ-038 fields: event, result, peer, cert_fp).
- internal/cli/cert.go — orca cert {ca-init,gen,show,renew,fingerprint}
subcommands; file mode enforcement at every entry; redacted cert
show (REQ-035).
- internal/cli/doctor.go — orca doctor {cert,network,db} subcommands
(REQ-032); --json output supported.
- internal/cli/node.go — adds --ca-fingerprint to orca node join
(REQ-026); fails fast on mismatch.
- internal/doctor/doctor.go — 6 checks: cert.ca, cert.server,
cert.expiry, cert.fingerprint, network stub, db stub.
- internal/doctor/doctor_test.go — happy + sad path coverage.
- internal/security/integration_test.go — end-to-end: CA-init, CSR
generation, mTLS handshake, mismatch failure, rotation alarm,
redaction, file mode enforcement.
All tests pass with -race; gofmt -l . clean; go vet ./... clean.
---ci---
project: orca
phase: 8
milestone: v0.2
status: execute
---/ci---
76 lines
1.9 KiB
Go
76 lines
1.9 KiB
Go
package cli
|
|
|
|
import (
|
|
"fmt"
|
|
|
|
"github.com/spf13/cobra"
|
|
|
|
"git.cloudinit.dev/coreci/orca/internal/doctor"
|
|
)
|
|
|
|
var doctorCmd = &cobra.Command{
|
|
Use: "doctor",
|
|
Short: "Run self-checks on the orca installation",
|
|
Long: "Verify CA, server cert, expiry, fingerprint, network, and DB. Reports PASS/WARN/FAIL per check.",
|
|
RunE: func(cmd *cobra.Command, args []string) error {
|
|
report := doctor.Run(cmd.Context())
|
|
if jsonOutput {
|
|
return printJSON(report.Checks)
|
|
}
|
|
fmt.Fprint(cmd.OutOrStdout(), report.Print())
|
|
return nil
|
|
},
|
|
}
|
|
|
|
var doctorCertCmd = &cobra.Command{
|
|
Use: "cert",
|
|
Short: "Run only the cert self-checks",
|
|
RunE: func(cmd *cobra.Command, args []string) error {
|
|
checks := []doctor.Check{
|
|
doctor.CertCA(),
|
|
doctor.CertServer(),
|
|
doctor.CertExpiry(),
|
|
doctor.CertFingerprint(),
|
|
}
|
|
results := make([]doctor.CheckResult, 0, len(checks))
|
|
for _, c := range checks {
|
|
r, msg := c.Run(cmd.Context())
|
|
results = append(results, doctor.CheckResult{Name: c.Name, Result: r, Message: msg})
|
|
}
|
|
if jsonOutput {
|
|
return printJSON(results)
|
|
}
|
|
for _, r := range results {
|
|
fmt.Fprintf(cmd.OutOrStdout(), "%-20s %-5s %s\n", r.Name, r.Result, r.Message)
|
|
}
|
|
return nil
|
|
},
|
|
}
|
|
|
|
var doctorNetworkCmd = &cobra.Command{
|
|
Use: "network",
|
|
Short: "Run the network self-check (P02 impl)",
|
|
RunE: func(cmd *cobra.Command, args []string) error {
|
|
c := doctor.NetworkStub()
|
|
r, msg := c.Run(cmd.Context())
|
|
fmt.Fprintf(cmd.OutOrStdout(), "%-20s %-5s %s\n", c.Name, r, msg)
|
|
return nil
|
|
},
|
|
}
|
|
|
|
var doctorDBCmd = &cobra.Command{
|
|
Use: "db",
|
|
Short: "Run the database self-check (P02 impl)",
|
|
RunE: func(cmd *cobra.Command, args []string) error {
|
|
c := doctor.DBStub()
|
|
r, msg := c.Run(cmd.Context())
|
|
fmt.Fprintf(cmd.OutOrStdout(), "%-20s %-5s %s\n", c.Name, r, msg)
|
|
return nil
|
|
},
|
|
}
|
|
|
|
func init() {
|
|
doctorCmd.AddCommand(doctorCertCmd, doctorNetworkCmd, doctorDBCmd)
|
|
rootCmd.AddCommand(doctorCmd)
|
|
}
|