diff --git a/cert/kube_certs.go b/cert/kube_certs.go index 5a36517b4..c7ace4e61 100644 --- a/cert/kube_certs.go +++ b/cert/kube_certs.go @@ -116,20 +116,20 @@ var certList = []Config{ Path: EtcdBasePath, BaseName: "server", CAName: "etcd-ca", - CommonName: "etcd", // TODO kubeadm using node name as common name cc.CommonName = mc.NodeRegistration.Name + CommonName: "etcd", // kubeadm using node name as common name cc.CommonName = mc.NodeRegistration.Name Organization: nil, Year: 100, - AltNames: AltNames{}, // TODO need set altNames + AltNames: AltNames{}, // need set altNames Usages: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth, x509.ExtKeyUsageClientAuth}, }, { Path: EtcdBasePath, BaseName: "peer", CAName: "etcd-ca", - CommonName: "etcd-peer", // TODO + CommonName: "etcd-peer", // change this in filter Organization: nil, Year: 100, - AltNames: AltNames{}, // TODO + AltNames: AltNames{}, // change this in filter Usages: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth, x509.ExtKeyUsageClientAuth}, }, { diff --git a/cmd/cert.go b/cmd/cert.go new file mode 100644 index 000000000..51f7fc144 --- /dev/null +++ b/cmd/cert.go @@ -0,0 +1,77 @@ +// Copyright © 2020 NAME HERE +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package cmd + +import ( + "github.com/fanux/sealos/cert" + "github.com/spf13/cobra" + "github.com/wonderivan/logger" + "net" +) + +type Flag struct { + DNS []string + IP []string + NodeName string + NodeIP string +} + +var config *Flag + +// certCmd represents the cert command +var certCmd = &cobra.Command{ + Use: "cert", + Short: "generate certs", + Long: `you can specify expire time`, + Run: func(cmd *cobra.Command, args []string) { + var ips []net.IP + for _,ip := range config.IP { + netip:=net.ParseIP(ip).To4() + if netip == nil { + logger.Warn("invalid altname : %s",ip) + continue + } + ips = append(ips, netip) + } + certConfig := &cert.SealosCertMetaData{ + APIServer: cert.AltNames{ + DNSNames: config.DNS, + IPs: ips, + }, + NodeName: config.NodeName, + NodeIP: config.NodeIP, + } + cert.GenerateAll(certConfig) + }, +} + +func init() { + config = &Flag{} + rootCmd.AddCommand(certCmd) + + cleanCmd.Flags().StringSliceVar(&config.DNS, "alt-dns", []string{}, "like sealyun.com") + cleanCmd.Flags().StringSliceVar(&config.IP, "alt-ip", []string{}, "like 10.103.97.2") + cleanCmd.Flags().StringVar(&config.NodeName, "node-name", "", "like 10.103.97.2") + cleanCmd.Flags().StringVar(&config.NodeIP, "node-ip", "", "like 10.103.97.2") + // Here you will define your flags and configuration settings. + + // Cobra supports Persistent Flags which will work for this command + // and all subcommands, e.g.: + // certCmd.PersistentFlags().String("foo", "", "A help for foo") + + // Cobra supports local flags which will only run when this command + // is called directly, e.g.: + // certCmd.Flags().BoolP("toggle", "t", false, "Help message for toggle") +}