mirror of
https://github.com/fscotto/infra.git
synced 2026-09-27 19:03:47 +00:00
Remove unsupported Aegis TPM storage
Co-authored-by: fscotto <17803710+fscotto@users.noreply.github.com>
This commit is contained in:
committed by
GitHub
parent
2004b48cf3
commit
bc9b381525
@@ -117,16 +117,13 @@ ansible-playbook ansible/site.yml --limit prometheus \
|
|||||||
## Aegis
|
## Aegis
|
||||||
|
|
||||||
`aegis` is a Raspberry Pi 4 running Fedora CoreOS. Provision it once with
|
`aegis` is a Raspberry Pi 4 running Fedora CoreOS. Provision it once with
|
||||||
`ansible/bootstrap/aegis.bu`, after replacing the SSH public-key placeholders:
|
`ansible/bootstrap/aegis.bu`, after replacing the SSH public-key placeholder:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
butane --strict --pretty --output aegis.ign ansible/bootstrap/aegis.bu
|
butane --strict --pretty --output aegis.ign ansible/bootstrap/aegis.bu
|
||||||
```
|
```
|
||||||
|
|
||||||
The bootstrap reserves partition 5 on `/dev/mmcblk0` for `/var/lib`. On the first boot it
|
The `core` and `pi` users both receive the configured SSH key.
|
||||||
generates a random LUKS2 key, enrolls it in the attached TPM2 device, and formats the unlocked
|
|
||||||
volume as btrfs. This is destructive for that partition and requires a TPM2 module/device; a
|
|
||||||
Raspberry Pi 4 has no TPM onboard. The `core` and `pi` users both receive the configured SSH key.
|
|
||||||
|
|
||||||
The controller then manages it remotely as `core@aegis`; unlike local desktop profiles, Aegis is
|
The controller then manages it remotely as `core@aegis`; unlike local desktop profiles, Aegis is
|
||||||
intentionally an SSH inventory target. `profile_aegis` manages rootful Podman Quadlets for AdGuard
|
intentionally an SSH inventory target. `profile_aegis` manages rootful Podman Quadlets for AdGuard
|
||||||
|
|||||||
@@ -11,81 +11,9 @@ passwd:
|
|||||||
ssh_authorized_keys:
|
ssh_authorized_keys:
|
||||||
- "ssh-ed25519 CHANGEME_AEGIS_SSH_PUBLIC_KEY"
|
- "ssh-ed25519 CHANGEME_AEGIS_SSH_PUBLIC_KEY"
|
||||||
storage:
|
storage:
|
||||||
disks:
|
|
||||||
- device: /dev/mmcblk0
|
|
||||||
wipe_table: false
|
|
||||||
partitions:
|
|
||||||
- label: aegis-data
|
|
||||||
number: 5
|
|
||||||
size_mib: 0
|
|
||||||
files:
|
files:
|
||||||
- path: /etc/hostname
|
- path: /etc/hostname
|
||||||
mode: 0644
|
mode: 0644
|
||||||
contents:
|
contents:
|
||||||
inline: |
|
inline: |
|
||||||
aegis
|
aegis
|
||||||
- path: /etc/crypttab
|
|
||||||
mode: 0644
|
|
||||||
contents:
|
|
||||||
append:
|
|
||||||
- inline: |
|
|
||||||
aegis-data /dev/disk/by-partlabel/aegis-data - tpm2-device=auto
|
|
||||||
- path: /etc/fstab
|
|
||||||
mode: 0644
|
|
||||||
contents:
|
|
||||||
append:
|
|
||||||
- inline: |
|
|
||||||
/dev/mapper/aegis-data /var/lib btrfs defaults,compress=zstd 0 0
|
|
||||||
- path: /usr/local/sbin/aegis-storage-init
|
|
||||||
mode: 0750
|
|
||||||
user:
|
|
||||||
name: root
|
|
||||||
group:
|
|
||||||
name: root
|
|
||||||
contents:
|
|
||||||
inline: |
|
|
||||||
#!/bin/bash
|
|
||||||
set -euo pipefail
|
|
||||||
|
|
||||||
device=/dev/disk/by-partlabel/aegis-data
|
|
||||||
mapper=aegis-data
|
|
||||||
key_file=/run/aegis-storage/key
|
|
||||||
marker=/etc/aegis-storage.initialized
|
|
||||||
|
|
||||||
if [[ -e "$marker" ]]; then
|
|
||||||
exit 0
|
|
||||||
fi
|
|
||||||
|
|
||||||
trap 'rm -f "$key_file"' EXIT
|
|
||||||
install -d -m 0700 /run/aegis-storage
|
|
||||||
dd if=/dev/urandom of="$key_file" bs=64 count=1 status=none
|
|
||||||
chmod 0600 "$key_file"
|
|
||||||
|
|
||||||
cryptsetup luksFormat --batch-mode --type luks2 --key-file="$key_file" "$device"
|
|
||||||
systemd-cryptenroll --tpm2-device=auto --unlock-key-file="$key_file" "$device"
|
|
||||||
cryptsetup open --key-file="$key_file" "$device" "$mapper"
|
|
||||||
mkfs.btrfs -L aegis-data "/dev/mapper/$mapper"
|
|
||||||
mount "/dev/mapper/$mapper" /var/lib
|
|
||||||
touch "$marker"
|
|
||||||
|
|
||||||
- path: /etc/systemd/system/aegis-storage-init.service
|
|
||||||
mode: 0644
|
|
||||||
contents:
|
|
||||||
inline: |
|
|
||||||
[Unit]
|
|
||||||
Description=Initialize the TPM-backed Aegis data volume
|
|
||||||
Wants=systemd-udev-settle.service
|
|
||||||
After=systemd-udev-settle.service
|
|
||||||
Before=local-fs.target
|
|
||||||
ConditionPathExists=!/etc/aegis-storage.initialized
|
|
||||||
|
|
||||||
[Service]
|
|
||||||
Type=oneshot
|
|
||||||
ExecStart=/usr/local/sbin/aegis-storage-init
|
|
||||||
|
|
||||||
[Install]
|
|
||||||
WantedBy=local-fs-pre.target
|
|
||||||
systemd:
|
|
||||||
units:
|
|
||||||
- name: aegis-storage-init.service
|
|
||||||
enabled: true
|
|
||||||
|
|||||||
Reference in New Issue
Block a user