mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-20 11:32:19 +00:00
3b5164032a
A RustFS cluster device needs a durable identity before it can exchange a one-time registration token for a certificate. This adds the device-side half of that exchange, which rustfs/connect already verifies. `connect::identity` builds the canonical registration transcript frozen by protocol/agent/v1/registration-proof.md, signs it as low-S ES256, and emits the PKCS#10 certificate request Connect consumes for its SubjectPublicKeyInfo. `connect::identity_store` seals the P-256 key at mode 0600 and publishes it through a no-clobber link, so a retry or a concurrent start returns the original identity rather than minting a second one, and a corrupt or widened key is refused rather than silently replaced. The protocol fixture set is copied here byte-identically because fixture-sets.json names this repository as the consumer copy; the tests verify it against its own manifests and cross-verify Connect-produced ECDSA proofs against transcripts rebuilt locally. Nothing starts a task or touches the S3 data path: an unenrolled deployment generates no key and holds no identity.
35 lines
1.2 KiB
JSON
35 lines
1.2 KiB
JSON
{
|
|
"protocolVersion": "v1",
|
|
"fixtureSet": "version",
|
|
"fixture": "field-registry",
|
|
"description": "The frozen v1 negotiation envelope. Registration and heartbeat both carry it. Any top-level field not listed here is unknown and is discarded after acceptance.",
|
|
"envelope": "AgentProtocolNegotiation",
|
|
"supportedMajorVersions": [1],
|
|
"protocolVersionPattern": "^v[1-9][0-9]{0,3}$",
|
|
"unknownFieldPolicy": "accept-and-discard",
|
|
"unknownCapabilityPolicy": "discard",
|
|
"fields": [
|
|
{
|
|
"name": "protocolVersion",
|
|
"requiredness": "required",
|
|
"type": "string",
|
|
"default": null,
|
|
"note": "Major version only. The minor and patch level of an agent is not negotiated."
|
|
},
|
|
{
|
|
"name": "agentVersion",
|
|
"requiredness": "optional",
|
|
"type": "string",
|
|
"default": null,
|
|
"note": "Informational. Connect never compares it for equality with its own version and never gates behavior on it."
|
|
},
|
|
{
|
|
"name": "capabilities",
|
|
"requiredness": "optional",
|
|
"type": "array",
|
|
"default": [],
|
|
"note": "Unordered token set. A capability an operation requires but the device did not report fails that operation with a structured result, not the connection."
|
|
}
|
|
]
|
|
}
|