hub v0.130.0: OS updates, guest fast lane — rings, per-box switch, OS releases approved from ring 0, os-report, os_update desired block

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
This commit is contained in:
2026-10-04 10:56:39 +02:00
parent 6ed79cd2e9
commit c5f91174f6
25 changed files with 1338 additions and 2 deletions
+52
View File
@@ -0,0 +1,52 @@
package web
import (
"encoding/json"
"net/http"
"strconv"
"strings"
)
// handleOSAdmin serves the operator's OS-update controls (behind the operator login, like every route here):
//
// POST /os/ring/<host_id> ring=0|1
// POST /os/enabled/<host_id> on=1|0
// POST /os/approve-now approve the current ring-0 set at once (an operator event)
// GET /os/fleet one line per box (JSON)
func (s *Server) handleOSAdmin(w http.ResponseWriter, r *http.Request, path string) {
if s.osUpdates == nil {
http.Error(w, "os updates not configured", http.StatusServiceUnavailable)
return
}
reply := func(v any, err error) {
if err != nil {
http.Error(w, err.Error(), http.StatusBadRequest)
return
}
w.Header().Set("Content-Type", "application/json")
_ = json.NewEncoder(w).Encode(v)
}
switch {
case r.Method == http.MethodGet && path == "/os/fleet":
reply(s.osUpdates.FleetJSON())
case r.Method == http.MethodPost && strings.HasPrefix(path, "/os/ring/"):
n, err := strconv.Atoi(r.FormValue("ring"))
if err != nil {
http.Error(w, "ring must be 0 or 1", http.StatusBadRequest)
return
}
reply(map[string]bool{"ok": true}, s.osUpdates.SetRing(strings.TrimPrefix(path, "/os/ring/"), n))
case r.Method == http.MethodPost && strings.HasPrefix(path, "/os/enabled/"):
on := r.FormValue("on")
if on != "0" && on != "1" {
http.Error(w, "on must be 0 or 1", http.StatusBadRequest)
return
}
reply(map[string]bool{"ok": true}, s.osUpdates.SetEnabled(strings.TrimPrefix(path, "/os/enabled/"), on == "1"))
case r.Method == http.MethodPost && path == "/os/approve-now":
id, err := s.osUpdates.ApproveNow()
reply(map[string]string{"release_id": id}, err)
default:
http.Error(w, "not found", http.StatusNotFound)
}
}
+15
View File
@@ -73,6 +73,7 @@ type Server struct {
// offsiteWindowAdmin: operator one-shot grant / weekly switch (decision 68). nil → 503.
offsiteWindowGrant func(customerID string) error
offsiteWindowGrantMax func(customerID string, maxRemove int) error
osUpdates OSUpdateAdmin
offsiteWindowSwitch func(on bool) error
// operator key-file clean-up (decision 72) and abandonment cancel (decision 74). nil → 503.
offsiteRemoveUnpinned func(ctx context.Context, customerID string) (int, error)
@@ -212,6 +213,17 @@ func (s *Server) SetOffsiteKeyAdmin(remove func(context.Context, string) (int, e
s.offsiteRemoveUnpinned, s.offsiteAbandonCancel = remove, cancel
}
// OSUpdateAdmin is the operator side of the guest fast lane (hub v0.130.0).
type OSUpdateAdmin interface {
SetRing(hostID string, ring int) error
SetEnabled(hostID string, on bool) error
ApproveNow() (string, error)
FleetJSON() (any, error)
}
// SetOSUpdateAdmin wires the OS-update operator routes.
func (s *Server) SetOSUpdateAdmin(a OSUpdateAdmin) { s.osUpdates = a }
// SetOffsiteWindowLargeGrant wires the operator's one-window raised cap (R-833).
func (s *Server) SetOffsiteWindowLargeGrant(fn func(string, int) error) { s.offsiteWindowGrantMax = fn }
@@ -681,6 +693,9 @@ func (s *Server) ServeHTTP(w http.ResponseWriter, r *http.Request) {
}
w.Header().Set("Content-Type", "application/json")
_, _ = w.Write([]byte("{\"ok\":true}\n"))
case strings.HasPrefix(path, "/os/"):
// Operator (hub v0.130.0, `11` §8 step 2): per-box ring and switch, approve now, the fleet lines.
s.handleOSAdmin(w, r, path)
case path == "/offsite/key-audit":
// Operator: run the daily off-site key check now (decision 69). Same code path as the 07:10 job.
if r.Method != http.MethodPost {