Documentation
¶
Overview ¶
Package platform implements the setup workflow for MCP Runtime platform components.
Index ¶
- func BuildOperatorArgs(metricsAddr, probeAddr string, leaderElect, leaderElectChanged bool) []string
- func DefaultMCPAuthIssuerURL() string
- func SetupPlatform(logger *zap.Logger, plan setupplan.Plan, clusterMgr ClusterManagerAPI) error
- func ValidateMTLSSetupCLIFlags(testMode, tlsEnabled bool, mtlsClusterIssuer string) error
- func ValidatePlatformMode(mode string) error
- func ValidatePublicPlatformAuthConfig(platformMode string, tlsEnabled, testMode bool, existingData map[string]string) error
- func ValidatePublicPlatformAuthEnv(platformMode string, tlsEnabled, testMode bool) error
- func ValidateRegistryMode(mode string) error
- func ValidateRegistryTLSMode(mode string, tlsEnabled bool, acmeEmail string) error
- func ValidateStorageMode(mode string) error
- func ValidateTLSSetupCLIFlags(tlsEnabled bool, providedTLSSecrets bool, ...) error
- type AnalyticsImageSet
- type ClusterManagerAPI
- type RegistryManagerAPI
- type SetupContext
- type SetupDeps
- type SetupPipeline
- type SetupStep
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func BuildOperatorArgs ¶
func BuildOperatorArgs(metricsAddr, probeAddr string, leaderElect, leaderElectChanged bool) []string
buildOperatorArgs constructs operator command-line arguments from flags. Only includes flags that were explicitly set.
func DefaultMCPAuthIssuerURL ¶
func DefaultMCPAuthIssuerURL() string
DefaultMCPAuthIssuerURL derives the bundled server's fixed public route from the platform domain, returning empty when no public domain is configured.
func SetupPlatform ¶
func ValidateMTLSSetupCLIFlags ¶
ValidateMTLSSetupCLIFlags enforces the mTLS setup flag contract. The mTLS auth path is enabled by naming a workload issuer with --mtls-cluster-issuer (test mode defaults it to the bundled mcp-runtime-ca). It requires --with-tls because Traefik terminates the caller's mTLS on the websecure (TLS) entrypoint; test mode is exempt (it serves the bundled self-signed default certificate there).
func ValidatePlatformMode ¶
func ValidateRegistryMode ¶
func ValidateRegistryTLSMode ¶
func ValidateStorageMode ¶
func ValidateTLSSetupCLIFlags ¶
func ValidateTLSSetupCLIFlags( tlsEnabled bool, providedTLSSecrets bool, acmeEmailResolved, tlsCIResolved string, acmeStagingResolved, skipCertManagerInstall bool, ) error
validateTLSSetupCLIFlags enforces ACME / internal-issuer mutual exclusion and requires --with-tls when any TLS or cert-manager-related options are set.
Types ¶
type AnalyticsImageSet ¶
type ClusterManagerAPI ¶
type ClusterManagerAPI interface {
InitCluster(kubeconfig, context string) error
ConfigureCluster(opts cluster.IngressOptions) error
}
type RegistryManagerAPI ¶
type SetupContext ¶
type SetupContext struct {
Plan setupplan.Plan
ExternalRegistry *config.ExternalRegistryConfig
UsingExternalRegistry bool
RegistryAuthStaged bool
RegistrySecretName string
OperatorImage string
GatewayProxyImage string
AnalyticsImages AnalyticsImageSet
}
SetupContext carries state shared across setup steps.
type SetupDeps ¶
type SetupDeps struct {
ResolveExternalRegistryConfig func(*config.ExternalRegistryConfig) (*config.ExternalRegistryConfig, error)
ClusterManager ClusterManagerAPI
RegistryManager RegistryManagerAPI
LoginRegistry func(logger *zap.Logger, registryURL, username, password string) error
DeployRegistry func(logger *zap.Logger, namespace string, port int, registryType, registryStorageSize, manifestPath string) error
WaitForDeploymentAvailable func(logger *zap.Logger, name, namespace, selector string, timeout time.Duration) error
WaitForDeploymentRolledOut func(logger *zap.Logger, name, namespace, selector string, timeout time.Duration) error
PrintDeploymentDiagnostics func(deploy, namespace, selector string)
SetupTLS func(logger *zap.Logger, plan setupplan.Plan) error
BuildOperatorImage func(image string) error
PushOperatorImage func(image string) error
BuildGatewayProxyImage func(image string) error
PushGatewayProxyImage func(image string) error
BuildAnalyticsImage func(image, dockerfilePath, buildContext string) error
PushAnalyticsImage func(image string) error
EnsureNamespace func(namespace string) error
EnsureCatalogNamespace func(namespace string, labels map[string]string) error
ResolvePlatformRegistryURL func(logger *zap.Logger) string
PushOperatorImageToInternal func(logger *zap.Logger, sourceImage, targetImage, helperNamespace string) error
PushGatewayProxyImageToInternal func(logger *zap.Logger, sourceImage, targetImage, helperNamespace string) error
PushAnalyticsImageToInternal func(logger *zap.Logger, sourceImage, targetImage, helperNamespace string) error
DeployOperatorManifests func(logger *zap.Logger, operatorImage, gatewayProxyImage string, operatorArgs []string, imagePullSecretName string) error
DeployAnalyticsManifests func(logger *zap.Logger, images AnalyticsImageSet, storageMode, platformMode string) error
EnsureImagePullSecret func(namespace, name, registry, username, password string) error
DisableRegistryIngressAuth func() error
EnableRegistryIngressAuth func() error
ConfigureProvisionedRegistryEnv func(ext *config.ExternalRegistryConfig, secretName string) error
RestartDeployment func(name, namespace string) error
CheckCRDInstalled func(name string) error
GetDeploymentTimeout func() time.Duration
GetRegistryPort func() int
OperatorImageFor func(ext *config.ExternalRegistryConfig) string
GatewayProxyImageFor func(ext *config.ExternalRegistryConfig) string
// StampPlatformVersion records the installed platform version on platform
// Deployment metadata after a successful setup. Nil skips stamping (tests).
StampPlatformVersion func(version string) error
// RunPostSetupSmoke runs a short operational gate after registry/operator/CRD
// checks. Nil skips the smoke (tests); production defaults fail setup when
// nodes, Postgres, platform-api, Sentinel rollouts, or auth probes are bad.
RunPostSetupSmoke func() error
}
type SetupPipeline ¶
type SetupPipeline struct {
// contains filtered or unexported fields
}
SetupPipeline provides a fluent API for building step sequences.
func NewSetupPipeline ¶
func NewSetupPipeline() *SetupPipeline
func (*SetupPipeline) Build ¶
func (p *SetupPipeline) Build() []SetupStep
func (*SetupPipeline) With ¶
func (p *SetupPipeline) With(step SetupStep) *SetupPipeline
func (*SetupPipeline) WithIf ¶
func (p *SetupPipeline) WithIf(condition bool, step SetupStep) *SetupPipeline
Source Files
¶
- analytics.go
- credential_bundle.go
- dependency_rollouts.go
- deploy.go
- doc.go
- flow.go
- image_cache.go
- images.go
- ingress_controller.go
- kube_client.go
- mcp_auth_server.go
- placement.go
- platform.go
- platform_registry_deploy.go
- platform_registry_resolve.go
- preflight.go
- registry.go
- session_scaling.go
- steps.go
- tls.go
- traefik.go
- webhook.go
- workload_issuer_gate.go
Directories
¶
| Path | Synopsis |
|---|---|
|
Package imagecache provides content-hash based GHCR reuse for QA E2E and setup platform images.
|
Package imagecache provides content-hash based GHCR reuse for QA E2E and setup platform images. |