Files
edgeguard-native/internal/chrony/chrony.go
Debian 02096c8ad8 chore(lint): golangci-lint --fix — misspell + staticcheck-Autofixes (Backlog 142→~98)
Erster Schritt des golangci-lint-Rollouts (non-blocking): 44 misspell + 4
staticcheck automatisch behoben (32 Dateien, nur Tippfehler/mechanisch).
build+test grün. Kein Runtime-Change → kein Deploy.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-05 23:25:22 +02:00

135 lines
3.7 KiB
Go

// Package chrony renders /etc/chrony/conf.d/edgeguard.conf from
// ntp_settings + ntp_pools and reloads chrony.service. Distro
// /etc/chrony/chrony.conf includes conf.d/* automatically — wir
// schreiben nur unseren drop-in.
package chrony
import (
"bytes"
"context"
_ "embed"
"fmt"
"os"
"strings"
"text/template"
"github.com/jackc/pgx/v5/pgxpool"
"git.netcell-it.de/projekte/edgeguard-native/internal/configgen"
"git.netcell-it.de/projekte/edgeguard-native/internal/models"
ntpsvc "git.netcell-it.de/projekte/edgeguard-native/internal/services/ntp"
)
// ConfPath: distro chrony.conf includes /etc/chrony/conf.d/*.conf.
// Wir schreiben direkt rein. postinst legt die Datei initial mit
// chown edgeguard:edgeguard 0644 an damit der Renderer schreibt.
const ConfPath = "/etc/chrony/conf.d/edgeguard.conf"
//go:embed chrony.cfg.tpl
var cfgTpl string
var tpl = template.Must(template.New("chrony").Parse(cfgTpl))
type View struct {
Settings *models.NTPSettings
Pools []models.NTPPool
ListenAddresses []string
AllowACLs []string
}
type Generator struct {
Pool *pgxpool.Pool
Repo *ntpsvc.Repo
SkipReload bool
}
func New(pool *pgxpool.Pool) *Generator {
return &Generator{Pool: pool, Repo: ntpsvc.New(pool)}
}
func (g *Generator) Name() string { return "chrony" }
// RenderToString renders the chrony config to a string without writing
// to disk or reloading the service. Used by the config-preview endpoint.
func (g *Generator) RenderToString(ctx context.Context) (string, error) {
settings, err := g.Repo.GetSettings(ctx)
if err != nil {
return "", fmt.Errorf("settings: %w", err)
}
pools, err := g.Repo.ListPools(ctx)
if err != nil {
return "", fmt.Errorf("pools: %w", err)
}
view := View{
Settings: settings,
Pools: pools,
ListenAddresses: filterNonLoopback(splitCSV(settings.ListenAddresses)),
AllowACLs: splitCSV(settings.AllowACL),
}
var body bytes.Buffer
if err := tpl.Execute(&body, view); err != nil {
return "", fmt.Errorf("template: %w", err)
}
return body.String(), nil
}
func (g *Generator) Render(ctx context.Context) error {
settings, err := g.Repo.GetSettings(ctx)
if err != nil {
return fmt.Errorf("settings: %w", err)
}
pools, err := g.Repo.ListPools(ctx)
if err != nil {
return fmt.Errorf("pools: %w", err)
}
view := View{
Settings: settings,
Pools: pools,
ListenAddresses: filterNonLoopback(splitCSV(settings.ListenAddresses)),
AllowACLs: splitCSV(settings.AllowACL),
}
var body bytes.Buffer
if err := tpl.Execute(&body, view); err != nil {
return fmt.Errorf("template: %w", err)
}
// Direct write (kein tmp+rename) — analog unbound, weil
// /etc/chrony/conf.d/ root-owned ist und edgeguard nur die eine
// Datei überschreiben darf (postinst chown).
if err := os.WriteFile(ConfPath, body.Bytes(), 0o644); err != nil {
return fmt.Errorf("write %s: %w", ConfPath, err)
}
if g.SkipReload {
return nil
}
// chrony.service kennt kein 'systemctl reload' — nur restart.
// ~200ms ohne NTP-Antworten beim Save, dafür neue conf wirksam.
return configgen.RestartService("chrony")
}
func splitCSV(s string) []string {
out := []string{}
for _, part := range strings.Split(s, ",") {
p := strings.TrimSpace(part)
if p != "" {
out = append(out, p)
}
}
return out
}
// filterNonLoopback wirft 127.x / ::1 raus — wenn NUR localhost im
// listen_addresses ist, lassen wir den bindaddress-Block weg und
// chrony bindet auf alle Interfaces (default), was für eine reine
// Client-Configuration nicht stört.
func filterNonLoopback(in []string) []string {
out := []string{}
for _, ip := range in {
if ip == "::1" || ip == "localhost" || strings.HasPrefix(ip, "127.") {
continue
}
out = append(out, ip)
}
return out
}