Support storing image encryption keys in Vault

This commit is contained in:
Vitaliy Filippov
2026-04-27 15:24:44 +03:00
parent 62b29b03c5
commit 8225b37f53
15 changed files with 594 additions and 213 deletions
+9 -29
View File
@@ -98,32 +98,15 @@ http_context_t *etcd_state_client_t::get_http_ctx()
void etcd_state_client_t::etcd_call_oneshot(const std::string & etcd_url, const std::string & api, json11::Json payload,
int timeout, std::function<void(std::string, json11::Json)> callback)
{
std::string etcd_api_path;
bool ssl = etcd_url.substr(0, 8) == "https://";
auto etcd_address = etcd_url.substr(ssl ? 8 : 7);
int pos = etcd_address.find('/');
if (pos >= 0)
{
etcd_api_path = etcd_address.substr(pos);
etcd_address = etcd_address.substr(0, pos);
}
std::string req = payload.dump();
req = "POST "+etcd_api_path+api+" HTTP/1.1\r\n"
"Host: "+etcd_address+"\r\n"
"Content-Type: application/json\r\n"
"Content-Length: "+std::to_string(req.size())+"\r\n"
"Connection: close\r\n"
"\r\n"+req;
auto http_cli = http_init(get_http_ctx());
auto cb = [http_cli, callback](http_message_t *response)
http_json_post(http_cli, etcd_url+api, payload, "", { .timeout = timeout }, [http_cli, callback](http_message_t *response)
{
std::string err;
json11::Json data;
response->parse_json_response(err, data);
callback(err, data);
http_destroy(http_cli);
};
http_request(http_cli, etcd_address, req, { .timeout = timeout, .ssl = ssl }, cb);
});
}
void etcd_state_client_t::etcd_call(const std::string & api, json11::Json payload, int timeout,
@@ -1448,7 +1431,7 @@ json11::Json::object etcd_state_client_t::serialize_inode_cfg(inode_config_t *cf
}
if (!cfg->enc_key.empty())
{
new_cfg["enc_key"] = tohexstr(cfg->enc_key.data(), cfg->enc_key.size());
new_cfg["enc_key"] = cfg->enc_key;
}
if (cfg->readonly)
{
@@ -1484,18 +1467,15 @@ inode_config_t etcd_state_client_t::deserialize_inode_cfg(uint64_t inode_num, js
else
parent_inode_num |= parent_pool_id << (64-POOL_ID_BITS);
}
std::vector<uint8_t> enc_key;
std::string enc_key;
if (!value["enc_key"].is_null())
{
if (value["enc_key"].string_value().size() == 2*AES_256_XTS_KEY_SIZE)
enc_key = value["enc_key"].string_value();
if (enc_key.substr(0, strlen(VAULT_KEY_PREFIX)) != VAULT_KEY_PREFIX &&
(enc_key.size() != 2*AES_256_XTS_KEY_SIZE || !ishexstr(enc_key)))
{
enc_key.resize(AES_256_XTS_KEY_SIZE);
if (fromhexstr(value["enc_key"].string_value(), AES_256_XTS_KEY_SIZE, enc_key.data()) < AES_256_XTS_KEY_SIZE)
enc_key.clear();
}
if (enc_key.empty())
{
fprintf(stderr, "Inode %u/%ju has invalid enc_key, should be %u bit hex string\n",
enc_key = "";
fprintf(stderr, "Inode %u/%ju has invalid enc_key, should be %u bit hex string or Vault key reference\n",
INODE_POOL(inode_num), INODE_NO_POOL(inode_num), AES_256_XTS_KEY_SIZE);
}
}