platform

package
v0.0.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 5, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package platform implements the setup workflow for MCP Runtime platform components.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func BuildOperatorArgs

func BuildOperatorArgs(metricsAddr, probeAddr string, leaderElect, leaderElectChanged bool) []string

buildOperatorArgs constructs operator command-line arguments from flags. Only includes flags that were explicitly set.

func DefaultMCPAuthIssuerURL

func DefaultMCPAuthIssuerURL() string

DefaultMCPAuthIssuerURL derives the bundled server's fixed public route from the platform domain, returning empty when no public domain is configured.

func SetupPlatform

func SetupPlatform(logger *zap.Logger, plan setupplan.Plan, clusterMgr ClusterManagerAPI) error

func ValidateMTLSSetupCLIFlags

func ValidateMTLSSetupCLIFlags(testMode, tlsEnabled bool, mtlsClusterIssuer string) error

ValidateMTLSSetupCLIFlags enforces the mTLS setup flag contract. The mTLS auth path is enabled by naming a workload issuer with --mtls-cluster-issuer (test mode defaults it to the bundled mcp-runtime-ca). It requires --with-tls because Traefik terminates the caller's mTLS on the websecure (TLS) entrypoint; test mode is exempt (it serves the bundled self-signed default certificate there).

func ValidatePlatformMode

func ValidatePlatformMode(mode string) error

func ValidatePublicPlatformAuthConfig

func ValidatePublicPlatformAuthConfig(platformMode string, tlsEnabled, testMode bool, existingData map[string]string) error

func ValidatePublicPlatformAuthEnv

func ValidatePublicPlatformAuthEnv(platformMode string, tlsEnabled, testMode bool) error

func ValidateRegistryMode

func ValidateRegistryMode(mode string) error

func ValidateRegistryTLSMode

func ValidateRegistryTLSMode(mode string, tlsEnabled bool, acmeEmail string) error

func ValidateStorageMode

func ValidateStorageMode(mode string) error

func ValidateTLSSetupCLIFlags

func ValidateTLSSetupCLIFlags(
	tlsEnabled bool,
	providedTLSSecrets bool, acmeEmailResolved, tlsCIResolved string,
	acmeStagingResolved, skipCertManagerInstall bool,
) error

validateTLSSetupCLIFlags enforces ACME / internal-issuer mutual exclusion and requires --with-tls when any TLS or cert-manager-related options are set.

Types

type AnalyticsImageSet

type AnalyticsImageSet struct {
	Ingest        string
	PlatformAPI   string
	RuntimeAPI    string
	AnalyticsAPI  string
	Processor     string
	UI            string
	DoctorSmoke   string
	Traefik       string
	ClickHouse    string
	Kafka         string
	Prometheus    string
	OTelCollector string
	Tempo         string
	Loki          string
	Promtail      string
	Grafana       string
}

type ClusterManagerAPI

type ClusterManagerAPI interface {
	InitCluster(kubeconfig, context string) error
	ConfigureCluster(opts cluster.IngressOptions) error
}

type RegistryManagerAPI

type RegistryManagerAPI interface {
	ShowRegistryInfo() error
	PushInCluster(source, target, helperNS string) error
}

type SetupContext

type SetupContext struct {
	Plan                  setupplan.Plan
	ExternalRegistry      *config.ExternalRegistryConfig
	UsingExternalRegistry bool
	RegistryAuthStaged    bool
	RegistrySecretName    string
	OperatorImage         string
	GatewayProxyImage     string
	AnalyticsImages       AnalyticsImageSet
}

SetupContext carries state shared across setup steps.

type SetupDeps

type SetupDeps struct {
	ResolveExternalRegistryConfig   func(*config.ExternalRegistryConfig) (*config.ExternalRegistryConfig, error)
	ClusterManager                  ClusterManagerAPI
	RegistryManager                 RegistryManagerAPI
	LoginRegistry                   func(logger *zap.Logger, registryURL, username, password string) error
	DeployRegistry                  func(logger *zap.Logger, namespace string, port int, registryType, registryStorageSize, manifestPath string) error
	WaitForDeploymentAvailable      func(logger *zap.Logger, name, namespace, selector string, timeout time.Duration) error
	WaitForDeploymentRolledOut      func(logger *zap.Logger, name, namespace, selector string, timeout time.Duration) error
	PrintDeploymentDiagnostics      func(deploy, namespace, selector string)
	SetupTLS                        func(logger *zap.Logger, plan setupplan.Plan) error
	BuildOperatorImage              func(image string) error
	PushOperatorImage               func(image string) error
	BuildGatewayProxyImage          func(image string) error
	PushGatewayProxyImage           func(image string) error
	BuildAnalyticsImage             func(image, dockerfilePath, buildContext string) error
	PushAnalyticsImage              func(image string) error
	EnsureNamespace                 func(namespace string) error
	EnsureCatalogNamespace          func(namespace string, labels map[string]string) error
	ResolvePlatformRegistryURL      func(logger *zap.Logger) string
	PushOperatorImageToInternal     func(logger *zap.Logger, sourceImage, targetImage, helperNamespace string) error
	PushGatewayProxyImageToInternal func(logger *zap.Logger, sourceImage, targetImage, helperNamespace string) error
	PushAnalyticsImageToInternal    func(logger *zap.Logger, sourceImage, targetImage, helperNamespace string) error
	DeployOperatorManifests         func(logger *zap.Logger, operatorImage, gatewayProxyImage string, operatorArgs []string, imagePullSecretName string) error
	DeployAnalyticsManifests        func(logger *zap.Logger, images AnalyticsImageSet, storageMode, platformMode string) error
	EnsureImagePullSecret           func(namespace, name, registry, username, password string) error
	DisableRegistryIngressAuth      func() error
	EnableRegistryIngressAuth       func() error
	ConfigureProvisionedRegistryEnv func(ext *config.ExternalRegistryConfig, secretName string) error
	RestartDeployment               func(name, namespace string) error
	CheckCRDInstalled               func(name string) error
	GetDeploymentTimeout            func() time.Duration
	GetRegistryPort                 func() int
	OperatorImageFor                func(ext *config.ExternalRegistryConfig) string
	GatewayProxyImageFor            func(ext *config.ExternalRegistryConfig) string
	// StampPlatformVersion records the installed platform version on platform
	// Deployment metadata after a successful setup. Nil skips stamping (tests).
	StampPlatformVersion func(version string) error
	// RunPostSetupSmoke runs a short operational gate after registry/operator/CRD
	// checks. Nil skips the smoke (tests); production defaults fail setup when
	// nodes, Postgres, platform-api, Sentinel rollouts, or auth probes are bad.
	RunPostSetupSmoke func() error
}

type SetupPipeline

type SetupPipeline struct {
	// contains filtered or unexported fields
}

SetupPipeline provides a fluent API for building step sequences.

func NewSetupPipeline

func NewSetupPipeline() *SetupPipeline

func (*SetupPipeline) Build

func (p *SetupPipeline) Build() []SetupStep

func (*SetupPipeline) With

func (p *SetupPipeline) With(step SetupStep) *SetupPipeline

func (*SetupPipeline) WithIf

func (p *SetupPipeline) WithIf(condition bool, step SetupStep) *SetupPipeline

type SetupStep

type SetupStep interface {
	Name() string
	Run(logger *zap.Logger, deps SetupDeps, ctx *SetupContext) error
}

SetupStep models a single setup phase.

Directories

Path Synopsis
Package imagecache provides content-hash based GHCR reuse for QA E2E and setup platform images.
Package imagecache provides content-hash based GHCR reuse for QA E2E and setup platform images.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL