Documentation
¶
Index ¶
- Constants
- Variables
- func AgentEnrol(api, token, apiHost string, deviceKeys []string, forget bool) string
- func AgentInstall(stamp, version string) string
- func AgentUnenrol() string
- func RolloutProvisionScript(profile []byte, runtime string) string
- func RolloutRuntimeInstall(staged, destination, sha256 string) string
- func ShQuote(s string) string
Constants ¶
const AgentInterval = "60s"
AgentInterval is how often the agent probes.
A minute, because the history it writes is charted per minute and a slower timer would draw gaps into every chart. The report being up to a minute stale is what design/appify.md §3 already accepted as the price of the reporting account having no privileges.
const StagedAgent = "/tmp/.komizo-box.staged"
StagedAgent is where the agent binary is written before agent-install.sh moves it into place.
Under /tmp rather than beside its destination, so a transfer that dies half way leaves a stray file somewhere harmless rather than a truncated komizo-box in /usr/local/bin that the next boot would try to run.
Variables ¶
var AlpineInitScript string
var AlpineProxyScript string
var AlpineReloadSSHDScript string
AlpineReloadSSHDScript applies the sshd config every app in an update wrote.
Separate from alpine.sh because it runs ONCE per update rather than once per app -- komizo#65. alpine.sh validates its own edit and defers; this is what makes the deferral safe to have.
var AlpineRemoveScript string
var AlpineScript string
Functions ¶
func AgentEnrol ¶ added in v0.0.15
AgentEnrol exchanges an enrolment token for this box's credential.
Every value is SHELL-QUOTED: they come from a caller rather than from a constant in this file, and the token in particular is an opaque string from a service. The app package validates the URL too, which is the same belt-and-braces argument ShQuote carries everywhere else here. deviceKeys are the devices the box will take orders from, and they are the one input here the SERVICE did not produce -- see box/operator.go. Rendered as repeated flags rather than one delimited value so the box parses exactly what was passed, with no separator to disagree about.
func AgentInstall ¶ added in v0.0.13
AgentInstall installs komizo-box and starts it under OpenRC.
The BINARY is not in here. It is several megabytes of ELF, staged over its own connection at StagedAgent, and this moves it into place -- see agent-install.sh.
version is the komizo release doing the installing and stamp is the content hash of the agents it carries. Both are recorded so the interface can answer two different questions: which komizo set this box up, and would running the update change anything.
func AgentUnenrol ¶ added in v0.0.15
func AgentUnenrol() string
AgentUnenrol stops the agent and removes the credential.
func RolloutProvisionScript ¶ added in v0.0.30
RolloutProvisionScript carries a locally validated canonical profile inside the root-only streamed script. Base64 keeps profile bytes out of the remote process arguments and has no shell metacharacters.
func RolloutRuntimeInstall ¶ added in v0.0.31
RolloutRuntimeInstall atomically installs a separately transferred runtime at one fixed app-scoped destination after authenticating its bytes.
func ShQuote ¶ added in v0.0.12
ShQuote wraps a value for a shell command line.
Single quotes, with any single quote in the value closed, escaped and reopened -- the one form that is safe for arbitrary text in POSIX sh.
Exported and living HERE because this is the package that builds shell. The app package had its own copy; it now calls this one, so there is a single definition of the rule that makes every quoted value in this tool safe.
Types ¶
This section is empty.