From e9e7b3a61e19506772f11338e1e4d3e7396b62c1 Mon Sep 17 00:00:00 2001 From: Pasha Sviderski Date: Mon, 14 Sep 2026 19:22:42 +1000 Subject: [PATCH] chore: move legacy unused WG tunnel and client connector to experiment/wg --- experiment/go.mod | 11 ++++-- experiment/go.sum | 10 ++++++ .../wg/connector.go | 36 +++++++++++-------- .../tunnel => experiment/wg}/tunnel.go | 4 +-- go.mod | 5 +-- go.sum | 4 --- internal/cli/config/connection.go | 8 ++--- 7 files changed, 45 insertions(+), 33 deletions(-) rename pkg/client/connector/wireguard.go => experiment/wg/connector.go (78%) rename {internal/machine/network/tunnel => experiment/wg}/tunnel.go (94%) diff --git a/experiment/go.mod b/experiment/go.mod index 24c6d72f..e8149581 100644 --- a/experiment/go.mod +++ b/experiment/go.mod @@ -19,16 +19,21 @@ require ( github.com/siderolabs/discovery-api v0.1.4 github.com/siderolabs/discovery-client v0.1.9 go.uber.org/zap v1.27.0 + golang.org/x/net v0.43.0 + golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173 + google.golang.org/grpc v1.74.2 ) require ( github.com/Masterminds/goutils v1.1.1 // indirect + github.com/Masterminds/semver v1.5.0 // indirect github.com/Masterminds/semver/v3 v3.4.0 // indirect github.com/Masterminds/sprig/v3 v3.2.3 // indirect github.com/armon/circbuf v0.0.0-20190214190532-5111143e8da2 // indirect github.com/armon/go-metrics v0.4.1 // indirect github.com/armon/go-radix v1.0.0 // indirect github.com/bgentry/speakeasy v0.2.0 // indirect + github.com/caarlos0/go-version v0.2.2 // indirect github.com/cenkalti/backoff/v4 v4.3.0 // indirect github.com/cespare/xxhash v1.1.0 // indirect github.com/cespare/xxhash/v2 v2.3.0 // indirect @@ -123,17 +128,17 @@ require ( golang.org/x/crypto v0.41.0 // indirect golang.org/x/exp v0.0.0-20250408133849-7e4ce0ab07d0 // indirect golang.org/x/mod v0.27.0 // indirect - golang.org/x/net v0.43.0 // indirect golang.org/x/sync v0.20.0 // indirect golang.org/x/sys v0.45.0 // indirect golang.org/x/text v0.28.0 // indirect + golang.org/x/time v0.11.0 // indirect golang.org/x/tools v0.36.0 // indirect - golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173 // indirect + golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 // indirect golang.zx2c4.com/wireguard/wgctrl v0.0.0-20230429144221-925a1e7659e6 // indirect google.golang.org/genproto/googleapis/rpc v0.0.0-20250528174236-200df99c418a // indirect - google.golang.org/grpc v1.74.2 // indirect google.golang.org/protobuf v1.36.9 // indirect gotest.tools/v3 v3.5.2 // indirect + gvisor.dev/gvisor v0.0.0-20230927004350-cbd86285d259 // indirect lukechampine.com/blake3 v1.3.0 // indirect ) diff --git a/experiment/go.sum b/experiment/go.sum index 35fd503d..d962b9c7 100644 --- a/experiment/go.sum +++ b/experiment/go.sum @@ -5,6 +5,8 @@ github.com/BurntSushi/toml v0.3.1/go.mod h1:xHWCNGjB5oqiDr8zfno3MHue2Ht5sIBksp03 github.com/DataDog/datadog-go v3.2.0+incompatible/go.mod h1:LButxg5PwREeZtORoXG3tL4fMGNddJ+vMq1mwgfaqoQ= github.com/Masterminds/goutils v1.1.1 h1:5nUrii3FMTL5diU80unEVvNevw1nH4+ZV4DSLVJLSYI= github.com/Masterminds/goutils v1.1.1/go.mod h1:8cTjp+g8YejhMuvIA5y2vz3BpJxksy863GQaJW2MFNU= +github.com/Masterminds/semver v1.5.0 h1:H65muMkzWKEuNDnfl9d70GUjFniHKHRbFPGBuZ3QEww= +github.com/Masterminds/semver v1.5.0/go.mod h1:MB6lktGJrhw8PrUyiEoblNEGEQ+RzHPF078ddwwvV3Y= github.com/Masterminds/semver/v3 v3.1.1/go.mod h1:VPu/7SZ7ePZ3QOrcuXROw5FAcLl4a0cBrbBpGY/8hQs= github.com/Masterminds/semver/v3 v3.2.0/go.mod h1:qvl/7zhW3nngYb5+80sSMF+FG2BjYrf8m9wsX0PNOMQ= github.com/Masterminds/semver/v3 v3.4.0 h1:Zog+i5UMtVoCU8oKka5P7i9q9HgrJeGzI9SA1Xbatp0= @@ -38,6 +40,8 @@ github.com/beorn7/perks v1.0.1/go.mod h1:G2ZrVWU2WbWT9wwq4/hrbKbnv/1ERSJQ0ibhJ6r github.com/bgentry/speakeasy v0.1.0/go.mod h1:+zsyZBPWlz7T6j88CTgSN5bM796AkVf0kBD4zp0CCIs= github.com/bgentry/speakeasy v0.2.0 h1:tgObeVOf8WAvtuAX6DhJ4xks4CFNwPDZiqzGqIHE51E= github.com/bgentry/speakeasy v0.2.0/go.mod h1:+zsyZBPWlz7T6j88CTgSN5bM796AkVf0kBD4zp0CCIs= +github.com/caarlos0/go-version v0.2.2 h1:5r+nlrg4H2wOVwWjqRqRRIRbZ7ytRmjC9xoMIP0a5kQ= +github.com/caarlos0/go-version v0.2.2/go.mod h1:X+rI5VAtJDpcjCjeEIXpxGa5+rTcgur1FK66wS0/944= github.com/cenkalti/backoff/v4 v4.3.0 h1:MyRJ/UdXutAwSAT+s3wNd7MfTIcy71VQueUuFK343L8= github.com/cenkalti/backoff/v4 v4.3.0/go.mod h1:Y3VNntkOUPxTVeUxJ/G5vcM//AlwfmyYozVcomhLiZE= github.com/census-instrumentation/opencensus-proto v0.2.1/go.mod h1:f6KPmirojxKA12rnyqOA5BBL4O983OfeGPqjHWSTneU= @@ -707,6 +711,8 @@ golang.org/x/text v0.3.7/go.mod h1:u+2+/6zg+i71rQMx5EYifcz6MCKuco9NR6JIITiCfzQ= golang.org/x/text v0.4.0/go.mod h1:mrYo+phRRbMaCq/xk9113O4dZlRixOauAjOtrjsXDZ8= golang.org/x/text v0.28.0 h1:rhazDwis8INMIwQ4tpjLDzUhx6RlXqZNPEM0huQojng= golang.org/x/text v0.28.0/go.mod h1:U8nCwOR8jO/marOQ0QbDiOngZVEBB7MAiitBuMjXiNU= +golang.org/x/time v0.11.0 h1:/bpjEDfN9tkoN/ryeYHnv5hcMlc8ncjMcM4XBk5NWV0= +golang.org/x/time v0.11.0/go.mod h1:CDIdPxbZBQxdj6cxyCIdrNogrJKMJ7pr37NYpMcMDSg= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20190114222345-bf090417da8b/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20190226205152-f727befe758c/go.mod h1:9Yl7xja0Znq3iFh3HoIrodX9oNMXvdceNzlUR8zjMvY= @@ -725,6 +731,8 @@ golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8T golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= +golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 h1:B82qJJgjvYKsXS9jeunTOisW56dUokqW/FOteYJJ/yg= +golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2/go.mod h1:deeaetjYA+DHMHg+sMSMI58GrEteJUUzzw7en6TJQcI= golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173 h1:/jFs0duh4rdb8uIfPMv78iAJGcPKDeqAFnaLBropIC4= golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173/go.mod h1:tkCQ4FQXmpAgYVh++1cq16/dH4QJtmvpRv19DWGAHSA= golang.zx2c4.com/wireguard/wgctrl v0.0.0-20230429144221-925a1e7659e6 h1:CawjfCvYQH2OU3/TnxLx97WDSUDRABfT18pCOYwc2GE= @@ -776,6 +784,8 @@ gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gotest.tools/v3 v3.5.2 h1:7koQfIKdy+I8UTetycgUqXWSDwpgv193Ka+qRsmBY8Q= gotest.tools/v3 v3.5.2/go.mod h1:LtdLGcnqToBH83WByAAi/wiwSFCArdFIUV/xxN4pcjA= +gvisor.dev/gvisor v0.0.0-20230927004350-cbd86285d259 h1:TbRPT0HtzFP3Cno1zZo7yPzEEnfu8EjLfl6IU9VfqkQ= +gvisor.dev/gvisor v0.0.0-20230927004350-cbd86285d259/go.mod h1:AVgIgHMwK63XvmAzWG9vLQ41YnVHN0du0tEC46fI7yY= honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= lukechampine.com/blake3 v1.3.0 h1:sJ3XhFINmHSrYCgl958hscfIa3bw8x4DqMP3u1YvoYE= diff --git a/pkg/client/connector/wireguard.go b/experiment/wg/connector.go similarity index 78% rename from pkg/client/connector/wireguard.go rename to experiment/wg/connector.go index f95d299c..3fe0f418 100644 --- a/pkg/client/connector/wireguard.go +++ b/experiment/wg/connector.go @@ -1,4 +1,4 @@ -package connector +package wg import ( "context" @@ -7,39 +7,48 @@ import ( "net/netip" "strconv" - "github.com/psviderski/uncloud/internal/cli/config" "github.com/psviderski/uncloud/internal/grpcversion" "github.com/psviderski/uncloud/internal/machine/constants" "github.com/psviderski/uncloud/internal/machine/network" - "github.com/psviderski/uncloud/internal/machine/network/tunnel" - "github.com/psviderski/uncloud/pkg/client" + "github.com/psviderski/uncloud/internal/secret" "golang.org/x/net/proxy" "google.golang.org/grpc" "google.golang.org/grpc/credentials/insecure" ) +// Machine describes a remote machine that the experimental connector can reach. +type Machine struct { + Host string + PublicKey secret.Secret +} + +type User interface { + ManagementIP() netip.Addr + PrivateKey() secret.Secret +} + // WireGuardConnector establishes a connection to the cluster API through a WireGuard tunnel // to one of the cluster machines. type WireGuardConnector struct { - user *client.User - machines []config.MachineConnection - tun *tunnel.Tunnel + user User + machines []Machine + tun *Tunnel } -func NewWireGuardConnector(user *client.User, machines []config.MachineConnection) *WireGuardConnector { +func NewWireGuardConnector(user User, machines []Machine) *WireGuardConnector { return &WireGuardConnector{ user: user, machines: machines, } } -// TODO: handle context cancelation. +// TODO: handle context cancellation. func (c *WireGuardConnector) Connect(ctx context.Context) (*grpc.ClientConn, error) { if len(c.machines) == 0 { return nil, fmt.Errorf("no machines to connect to") } // TODO: iterate over machines and try to connect to each one until successful. - // For now, try to connect to only the first machine. + // For now, try to connect to only the first machine. machine := c.machines[0] endpointIPs, err := net.LookupIP(machine.Host) if err != nil { @@ -49,25 +58,24 @@ func (c *WireGuardConnector) Connect(ctx context.Context) (*grpc.ClientConn, err if err != nil { return nil, fmt.Errorf("parse IP address %q: %w", endpointIPs[0].String(), err) } - endpoint := netip.AddrPortFrom(endpointAddr, tunnel.DefaultEndpointPort) + endpoint := netip.AddrPortFrom(endpointAddr, DefaultEndpointPort) machineManagementIP := network.ManagementIP(machine.PublicKey) machineAPIAddr := net.JoinHostPort(machineManagementIP.String(), strconv.Itoa(constants.MachineAPIPort)) - tunCfg := &tunnel.Config{ + tunCfg := &Config{ LocalAddress: c.user.ManagementIP(), LocalPrivateKey: c.user.PrivateKey(), RemotePublicKey: machine.PublicKey, RemoteNetwork: netip.PrefixFrom(machineManagementIP, 128), Endpoint: endpoint, } - if c.tun, err = tunnel.Connect(tunCfg); err != nil { + if c.tun, err = Connect(tunCfg); err != nil { return nil, fmt.Errorf("establish WireGuard tunnel to %q: %w", endpoint, err) } conn, err := grpc.NewClient( machineAPIAddr, grpc.WithTransportCredentials(insecure.NewCredentials()), - grpc.WithDefaultServiceConfig(defaultServiceConfig), grpc.WithContextDialer(func(ctx context.Context, addr string) (net.Conn, error) { return c.tun.DialContext(ctx, "tcp", addr) }), diff --git a/internal/machine/network/tunnel/tunnel.go b/experiment/wg/tunnel.go similarity index 94% rename from internal/machine/network/tunnel/tunnel.go rename to experiment/wg/tunnel.go index cb6fd7ef..298c3bf1 100644 --- a/internal/machine/network/tunnel/tunnel.go +++ b/experiment/wg/tunnel.go @@ -1,4 +1,4 @@ -package tunnel +package wg import ( "context" @@ -15,7 +15,7 @@ import ( const ( DefaultEndpointPort = 51820 - // DefaultKeepaliveInterval is sensible interval that works with a wide variety of firewalls. + // DefaultKeepaliveInterval is a sensible interval that works with a wide variety of firewalls. DefaultKeepaliveInterval = 25 * time.Second ) diff --git a/go.mod b/go.mod index fd99484c..7ffe81ef 100644 --- a/go.mod +++ b/go.mod @@ -52,7 +52,6 @@ require ( golang.org/x/sync v0.20.0 golang.org/x/sys v0.45.0 golang.org/x/term v0.34.0 - golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173 golang.zx2c4.com/wireguard/wgctrl v0.0.0-20230429144221-925a1e7659e6 google.golang.org/genproto/googleapis/rpc v0.0.0-20250528174236-200df99c418a google.golang.org/grpc v1.74.2 @@ -162,7 +161,6 @@ require ( github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da // indirect github.com/golang/protobuf v1.5.4 // indirect github.com/golang/snappy v0.0.4 // indirect - github.com/google/btree v1.1.2 // indirect github.com/google/cel-go v0.20.1 // indirect github.com/google/gnostic-models v0.6.8 // indirect github.com/google/gofuzz v1.2.0 // indirect @@ -336,14 +334,13 @@ require ( golang.org/x/text v0.28.0 // indirect golang.org/x/time v0.11.0 // indirect golang.org/x/tools v0.36.0 // indirect - golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 // indirect + golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173 // indirect google.golang.org/genproto/googleapis/api v0.0.0-20250528174236-200df99c418a // indirect gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect gopkg.in/inf.v0 v0.9.1 // indirect gopkg.in/ini.v1 v1.67.0 // indirect gopkg.in/yaml.v2 v2.4.0 // indirect gopkg.in/yaml.v3 v3.0.1 // indirect - gvisor.dev/gvisor v0.0.0-20230927004350-cbd86285d259 // indirect howett.net/plist v1.0.0 // indirect k8s.io/api v0.32.3 // indirect k8s.io/apimachinery v0.32.3 // indirect diff --git a/go.sum b/go.sum index f806b83d..42728be9 100644 --- a/go.sum +++ b/go.sum @@ -1210,8 +1210,6 @@ golang.org/x/xerrors v0.0.0-20190717185122-a985d3407aa7/go.mod h1:I/5z698sn9Ka8T golang.org/x/xerrors v0.0.0-20191011141410-1b5146add898/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20191204190536-9bdfabe68543/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1/go.mod h1:I/5z698sn9Ka8TeJc9MKroUUfqBBauWjQqLJ2OPfmY0= -golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2 h1:B82qJJgjvYKsXS9jeunTOisW56dUokqW/FOteYJJ/yg= -golang.zx2c4.com/wintun v0.0.0-20230126152724-0fa3db229ce2/go.mod h1:deeaetjYA+DHMHg+sMSMI58GrEteJUUzzw7en6TJQcI= golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173 h1:/jFs0duh4rdb8uIfPMv78iAJGcPKDeqAFnaLBropIC4= golang.zx2c4.com/wireguard v0.0.0-20231211153847-12269c276173/go.mod h1:tkCQ4FQXmpAgYVh++1cq16/dH4QJtmvpRv19DWGAHSA= golang.zx2c4.com/wireguard/wgctrl v0.0.0-20230429144221-925a1e7659e6 h1:CawjfCvYQH2OU3/TnxLx97WDSUDRABfT18pCOYwc2GE= @@ -1286,8 +1284,6 @@ gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA= gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= gotest.tools/v3 v3.5.2 h1:7koQfIKdy+I8UTetycgUqXWSDwpgv193Ka+qRsmBY8Q= gotest.tools/v3 v3.5.2/go.mod h1:LtdLGcnqToBH83WByAAi/wiwSFCArdFIUV/xxN4pcjA= -gvisor.dev/gvisor v0.0.0-20230927004350-cbd86285d259 h1:TbRPT0HtzFP3Cno1zZo7yPzEEnfu8EjLfl6IU9VfqkQ= -gvisor.dev/gvisor v0.0.0-20230927004350-cbd86285d259/go.mod h1:AVgIgHMwK63XvmAzWG9vLQ41YnVHN0du0tEC46fI7yY= honnef.co/go/tools v0.0.0-20190102054323-c2f93a96b099/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= honnef.co/go/tools v0.0.0-20190523083050-ea95bdfd59fc/go.mod h1:rf3lG4BRIbNafJWhAfAdb/ePZxsR/4RtNHQocxwk9r4= honnef.co/go/tools v0.0.1-2019.2.3/go.mod h1:a3bituU0lyd329TUQxRnasdCoJDkEUEAqEt0JzvZhAg= diff --git a/internal/cli/config/connection.go b/internal/cli/config/connection.go index 4762be99..ae9206a2 100644 --- a/internal/cli/config/connection.go +++ b/internal/cli/config/connection.go @@ -7,8 +7,6 @@ import ( "net/netip" "strconv" "strings" - - "github.com/psviderski/uncloud/internal/secret" ) type MachineConnection struct { @@ -23,10 +21,8 @@ type MachineConnection struct { // The pointer is used to omit the field when not set. Otherwise, yaml marshalling includes an empty object. TCP *netip.AddrPort `yaml:"tcp,omitempty"` // Unix is the path to the machine's API unix socket. - Unix string `yaml:"unix,omitempty"` - Host string `yaml:"host,omitempty"` - PublicKey secret.Secret `yaml:"public_key,omitempty"` - MachineID string `yaml:"machine_id,omitempty"` + Unix string `yaml:"unix,omitempty"` + MachineID string `yaml:"machine_id,omitempty"` } func (c *MachineConnection) String() string {