Files
felhom.eu/hub/internal/api/wg.go
T
admin fbeeacb124 hub: S1 wgsync (pinned-SSH push + declarative reconciler) + /admin/wg API + env wiring
internal/wgsync: x/crypto/ssh client with ssh.FixedHostKey pin (no insecure
fallback), forced-command exec, ok/applied response contract; Reconciler pushes
the FULL peer list on Trigger or 5-min tick (drift repair by construction).
internal/api/wg.go: PUT/GET /admin/wg/endpoint + POST/DELETE/GET /admin/wg/peers,
global-key-only, pubkey in body (base64 vs URL), sync ok|deferred|disabled.
main.go: WG_ENDPOINT_SSH_* env wiring, disabled-with-INFO when unconfigured.
Groups B/C/D tests incl. in-process SSH server; red-proofs b/c/d run + reverted.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PSK5g6qYLknKj8u3QAFEr6
2026-07-03 23:40:22 +02:00

265 lines
9.4 KiB
Go

package api
// S1 offsite connectivity (doc 06 §3.2/§5): the operator admin surface for the WG endpoint
// record + peer registry. GLOBAL key ONLY on every route (the handleAdminSetDesiredState gate) —
// a per-host key must never author the peer list; the box-facing registration path is S2.
// DELETE takes the pubkey in the JSON body: WG pubkeys are std base64 ('/' and '+'), so a pubkey
// NEVER appears in a URL path — and no, URL-escaping is not the fix (see the S1 spec §8).
import (
"context"
"database/sql"
"encoding/base64"
"encoding/json"
"fmt"
"io"
"net/http"
"net/netip"
"time"
"gitea.dooplex.hu/admin/felhom-hub/internal/store"
)
// WGSyncer is the reconciler seam (satisfied by *wgsync.Reconciler; tests inject a fake). nil =
// peer-sync disabled: mutations still hit the DB (the source of truth) and report sync:"disabled".
type WGSyncer interface {
SyncNow(ctx context.Context) error
Trigger()
}
// SetWGSyncer wires the wgsync reconciler (mirror of SetLatestVersionProvider; nil-safe).
func (h *Handler) SetWGSyncer(s WGSyncer) {
h.wgSyncer = s
}
// validateWGPubkey enforces the exact WG public-key shape: 44 chars of std base64 decoding to
// 32 bytes. Anything else is rejected before any allocation.
func validateWGPubkey(pk string) error {
if len(pk) != 44 {
return fmt.Errorf("pubkey must be 44 base64 chars, got %d", len(pk))
}
raw, err := base64.StdEncoding.DecodeString(pk)
if err != nil {
return fmt.Errorf("pubkey is not valid base64: %v", err)
}
if len(raw) != 32 {
return fmt.Errorf("pubkey must decode to 32 bytes, got %d", len(raw))
}
return nil
}
// syncAfterMutation runs an inline sync after a peer mutation. The DB write already happened —
// it is the source of truth — so a push failure is REPORTED, not rolled back: the reconciler's
// next tick converges the endpoint (Scenario D).
func (h *Handler) syncAfterMutation(ctx context.Context) string {
if h.wgSyncer == nil {
return "disabled"
}
syncCtx, cancel := context.WithTimeout(ctx, 10*time.Second)
defer cancel()
if err := h.wgSyncer.SyncNow(syncCtx); err != nil {
h.logger.Printf("[ERROR] wgsync: inline push after mutation failed: %v (reconciler will retry)", err)
h.wgSyncer.Trigger()
return "deferred: " + err.Error()
}
return "ok"
}
// handleAdminSetWGEndpoint — PUT /admin/wg/endpoint. Upserts the endpoint record.
func (h *Handler) handleAdminSetWGEndpoint(w http.ResponseWriter, r *http.Request) {
_, _, isGlobal, ok := h.checkAuthHost(r)
if !ok || !isGlobal {
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
return
}
body, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
if err != nil {
http.Error(w, "Bad request", http.StatusBadRequest)
return
}
var req struct {
EndpointID string `json:"endpoint_id"`
DNSName string `json:"dns_name"`
WGPort int `json:"wg_port"`
ServerPubkey string `json:"server_pubkey"`
TunnelSubnet string `json:"tunnel_subnet"`
PBSTunnelIP string `json:"pbs_tunnel_ip"`
}
if err := json.Unmarshal(body, &req); err != nil {
http.Error(w, "Invalid payload: body must be JSON", http.StatusBadRequest)
return
}
if req.DNSName == "" {
http.Error(w, "Invalid payload: dns_name required", http.StatusBadRequest)
return
}
if req.WGPort < 1 || req.WGPort > 65535 {
http.Error(w, "Invalid payload: wg_port must be 1-65535", http.StatusBadRequest)
return
}
if err := validateWGPubkey(req.ServerPubkey); err != nil {
http.Error(w, "Invalid payload: server_pubkey: "+err.Error(), http.StatusBadRequest)
return
}
prefix, err := netip.ParsePrefix(req.TunnelSubnet)
if err != nil {
http.Error(w, "Invalid payload: tunnel_subnet must be CIDR", http.StatusBadRequest)
return
}
pbsAddr, err := netip.ParseAddr(req.PBSTunnelIP)
if err != nil || !prefix.Contains(pbsAddr) {
http.Error(w, "Invalid payload: pbs_tunnel_ip must be an address inside tunnel_subnet", http.StatusBadRequest)
return
}
if err := h.store.SetWGEndpoint(&store.WGEndpoint{
EndpointID: req.EndpointID, DNSName: req.DNSName, WGPort: req.WGPort,
ServerPubkey: req.ServerPubkey, TunnelSubnet: req.TunnelSubnet, PBSTunnelIP: req.PBSTunnelIP,
}); err != nil {
h.logger.Printf("[ERROR] set wg endpoint: %v", err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
h.logger.Printf("[INFO] wg endpoint set: %s (%s:%d, subnet %s)", req.DNSName, req.DNSName, req.WGPort, req.TunnelSubnet)
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
w.Write([]byte(`{"status":"ok"}`))
}
// handleAdminGetWGEndpoint — GET /admin/wg/endpoint.
func (h *Handler) handleAdminGetWGEndpoint(w http.ResponseWriter, r *http.Request) {
_, _, isGlobal, ok := h.checkAuthHost(r)
if !ok || !isGlobal {
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
return
}
e, err := h.store.GetWGEndpoint()
if err == sql.ErrNoRows {
http.Error(w, "wg endpoint not configured", http.StatusNotFound)
return
}
if err != nil {
h.logger.Printf("[ERROR] get wg endpoint: %v", err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]interface{}{
"endpoint_id": e.EndpointID, "dns_name": e.DNSName, "wg_port": e.WGPort,
"server_pubkey": e.ServerPubkey, "tunnel_subnet": e.TunnelSubnet, "pbs_tunnel_ip": e.PBSTunnelIP,
})
}
// handleAdminAddWGPeer — POST /admin/wg/peers. Allocates a /32 (idempotent on pubkey) and
// pushes the full list inline (sync semantics: ok | deferred | disabled).
func (h *Handler) handleAdminAddWGPeer(w http.ResponseWriter, r *http.Request) {
_, _, isGlobal, ok := h.checkAuthHost(r)
if !ok || !isGlobal {
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
return
}
body, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
if err != nil {
http.Error(w, "Bad request", http.StatusBadRequest)
return
}
var req struct {
Pubkey string `json:"pubkey"`
HostID string `json:"host_id"`
Note string `json:"note"`
}
if err := json.Unmarshal(body, &req); err != nil {
http.Error(w, "Invalid payload: body must be JSON", http.StatusBadRequest)
return
}
if err := validateWGPubkey(req.Pubkey); err != nil {
http.Error(w, "Invalid payload: "+err.Error(), http.StatusBadRequest)
return
}
ip, existed, err := h.store.AddWGPeer(req.Pubkey, req.HostID, req.Note)
if err == store.ErrWGEndpointUnset {
http.Error(w, "wg endpoint not configured", http.StatusConflict)
return
}
if err == store.ErrWGSubnetExhausted {
http.Error(w, "tunnel subnet exhausted", http.StatusConflict)
return
}
if err != nil {
h.logger.Printf("[ERROR] add wg peer: %v", err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
syncStatus := h.syncAfterMutation(r.Context())
h.logger.Printf("[INFO] wg peer added: %s -> %s/32 (existed=%v, sync=%s)", req.Pubkey, ip, existed, syncStatus)
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(map[string]interface{}{
"pubkey": req.Pubkey, "assigned_ip": ip + "/32", "existed": existed, "sync": syncStatus,
})
}
// handleAdminDeleteWGPeer — DELETE /admin/wg/peers, pubkey in the JSON body (never the URL).
// Unknown pubkey → 404 with NO sync (nothing changed). Known → delete + inline push: the pushed
// full list no longer contains the peer, so revocation lands with the push (Scenario B).
func (h *Handler) handleAdminDeleteWGPeer(w http.ResponseWriter, r *http.Request) {
_, _, isGlobal, ok := h.checkAuthHost(r)
if !ok || !isGlobal {
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
return
}
body, err := io.ReadAll(io.LimitReader(r.Body, 1<<20))
if err != nil {
http.Error(w, "Bad request", http.StatusBadRequest)
return
}
var req struct {
Pubkey string `json:"pubkey"`
}
if err := json.Unmarshal(body, &req); err != nil {
http.Error(w, "Invalid payload: body must be JSON", http.StatusBadRequest)
return
}
if err := validateWGPubkey(req.Pubkey); err != nil {
http.Error(w, "Invalid payload: "+err.Error(), http.StatusBadRequest)
return
}
err = h.store.RemoveWGPeer(req.Pubkey)
if err == sql.ErrNoRows {
http.Error(w, "Unknown pubkey", http.StatusNotFound)
return
}
if err != nil {
h.logger.Printf("[ERROR] remove wg peer: %v", err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
syncStatus := h.syncAfterMutation(r.Context())
h.logger.Printf("[INFO] wg peer removed: %s (sync=%s)", req.Pubkey, syncStatus)
w.Header().Set("Content-Type", "application/json")
w.WriteHeader(http.StatusOK)
json.NewEncoder(w).Encode(map[string]interface{}{"status": "ok", "sync": syncStatus})
}
// handleAdminListWGPeers — GET /admin/wg/peers. The verification surface (S2 builds UI on top).
func (h *Handler) handleAdminListWGPeers(w http.ResponseWriter, r *http.Request) {
_, _, isGlobal, ok := h.checkAuthHost(r)
if !ok || !isGlobal {
http.Error(w, "Forbidden: global key required", http.StatusForbidden)
return
}
peers, err := h.store.ListWGPeers()
if err != nil {
h.logger.Printf("[ERROR] list wg peers: %v", err)
http.Error(w, "Internal error", http.StatusInternalServerError)
return
}
out := make([]map[string]interface{}, 0, len(peers))
for _, p := range peers {
out = append(out, map[string]interface{}{
"pubkey": p.Pubkey, "assigned_ip": p.AssignedIP + "/32", "host_id": p.HostID, "note": p.Note,
})
}
w.Header().Set("Content-Type", "application/json")
json.NewEncoder(w).Encode(map[string]interface{}{"peers": out})
}