|
| 1 | +package app |
| 2 | + |
| 3 | +import ( |
| 4 | + "context" |
| 5 | + "errors" |
| 6 | + "fmt" |
| 7 | + "strings" |
| 8 | +) |
| 9 | + |
| 10 | +// The host software Onebox requires and deliberately never installs. Declaring |
| 11 | +// the set in one place is what keeps the three gates that assert it — |
| 12 | +// `ob bootstrap`, `ob preflight` and the deploy preflight step — from each |
| 13 | +// checking a different subset, which let a host pass bootstrap and fail two |
| 14 | +// commands later. `ob doctor` is deliberately not among them: it reports local |
| 15 | +// runner provenance and contacts no server. |
| 16 | +const ( |
| 17 | + dockerVersionCommand = "docker version --format '{{.Server.Version}}'" |
| 18 | + composeVersionCommand = "docker compose version --short" |
| 19 | + buildxVersionCommand = "docker buildx version" |
| 20 | +) |
| 21 | + |
| 22 | +// Prerequisite names are stable: they appear in `ob preflight` output and in |
| 23 | +// the refusals bootstrap and the deploy step raise, so an operator reading any |
| 24 | +// of them sees the same vocabulary. |
| 25 | +const ( |
| 26 | + PrerequisiteRuntime = "container runtime" |
| 27 | + PrerequisiteCompose = "compose plugin" |
| 28 | + PrerequisiteResolver = "image resolver" |
| 29 | +) |
| 30 | + |
| 31 | +// A refusal that names no command is a dead end at the worst moment: first |
| 32 | +// contact with a fresh host. Each remedy is an action, and the three causes a |
| 33 | +// failing `docker version` actually has are distinguished, because "install |
| 34 | +// Docker" is the wrong advice for the common case where Docker is installed and |
| 35 | +// the deploy account simply cannot reach its socket. |
| 36 | +const ( |
| 37 | + prerequisiteDocs = "https://onebox.run/start/install" |
| 38 | + |
| 39 | + runtimeAbsentRemedy = "install Docker Engine, the Compose plugin and Buildx on the server (" + prerequisiteDocs + "), then rerun ob preflight" |
| 40 | + runtimeDeniedRemedy = "add the deploy account to the docker group on the server and reconnect so the new membership applies, then rerun ob preflight" |
| 41 | + runtimeUnreachableRemedy = "start the Docker daemon on the server, then rerun ob preflight" |
| 42 | + composeRemedy = "install the Docker Compose plugin on the server (" + prerequisiteDocs + "), then rerun ob preflight" |
| 43 | +) |
| 44 | + |
| 45 | +// runResultDetail is what the command itself said. Stderr is preferred and |
| 46 | +// stdout is the fallback, because some clients report a failure on stdout — but |
| 47 | +// the join has to be trimmed before the first line is taken, or an empty stderr |
| 48 | +// leaves a leading newline and firstLine returns "", discarding the very |
| 49 | +// fallback this exists for. An empty detail is worse than verbose: it strands |
| 50 | +// the refusal with no reason, and for the runtime it also loses the cause that |
| 51 | +// selects the remedy. |
| 52 | +// |
| 53 | +// It takes the streams rather than the result value so this file keeps naming |
| 54 | +// no transport type, the same way buildx.go does: the package's purity test |
| 55 | +// permits exactly one file to import the transport, and this is not it. |
| 56 | +func runResultDetail(stderr, stdout, command string, exitCode int) string { |
| 57 | + detail := strings.TrimSpace(firstLine(strings.TrimSpace(stderr + "\n" + stdout))) |
| 58 | + if detail != "" { |
| 59 | + return detail |
| 60 | + } |
| 61 | + return fmt.Sprintf("%s exited with status %d", command, exitCode) |
| 62 | +} |
| 63 | + |
| 64 | +// runtimeRemedyFor reads the cause out of what the runtime said. Docker reports |
| 65 | +// all three through the same non-zero exit, and only the text separates them. |
| 66 | +func runtimeRemedyFor(detail string) string { |
| 67 | + lowered := strings.ToLower(detail) |
| 68 | + switch { |
| 69 | + case strings.Contains(lowered, "permission denied"): |
| 70 | + return runtimeDeniedRemedy |
| 71 | + case strings.Contains(lowered, "cannot connect to the docker daemon"), |
| 72 | + strings.Contains(lowered, "is the docker daemon running"): |
| 73 | + return runtimeUnreachableRemedy |
| 74 | + default: |
| 75 | + return runtimeAbsentRemedy |
| 76 | + } |
| 77 | +} |
| 78 | + |
| 79 | +// CheckHostPrerequisites asks the server for every piece of host software a |
| 80 | +// deploy needs, and reports each as a Check rather than as an error, so a |
| 81 | +// caller sees the whole set at once. |
| 82 | +// |
| 83 | +// An error is returned only when the server cannot be reached at all, and the |
| 84 | +// checks answered before that point come back with it rather than being |
| 85 | +// discarded: a connection that drops on the third probe has not invalidated the |
| 86 | +// first two. A container runtime that is absent or unusable short-circuits the |
| 87 | +// rest — without it the remaining answers are noise, not diagnosis. |
| 88 | +// |
| 89 | +// Nothing here mutates, and nothing contacts a registry. |
| 90 | +func CheckHostPrerequisites(ctx context.Context, run Runner) ([]Check, error) { |
| 91 | + return checkHostPrerequisites(ctx, run, true) |
| 92 | +} |
| 93 | + |
| 94 | +// checkHostPrerequisites takes reportVersions because only a caller rendering a |
| 95 | +// report reads the version of a prerequisite that passed. The refusing path |
| 96 | +// discards a satisfied check's detail entirely, so fetching the Buildx version |
| 97 | +// for it spends an SSH round trip on a string nobody sees — on every deploy. |
| 98 | +// A failing check always gets the version, which is where it earns its cost. |
| 99 | +func checkHostPrerequisites(ctx context.Context, run Runner, reportVersions bool) ([]Check, error) { |
| 100 | + res, err := run.Run(ctx, dockerVersionCommand) |
| 101 | + if err != nil { |
| 102 | + return nil, err |
| 103 | + } |
| 104 | + if res.ExitCode != 0 { |
| 105 | + detail := runResultDetail(res.Stderr, res.Stdout, dockerVersionCommand, res.ExitCode) |
| 106 | + return []Check{{ |
| 107 | + Name: PrerequisiteRuntime, |
| 108 | + Detail: detail, |
| 109 | + Remedy: runtimeRemedyFor(detail), |
| 110 | + }}, nil |
| 111 | + } |
| 112 | + checks := []Check{{ |
| 113 | + Name: PrerequisiteRuntime, OK: true, |
| 114 | + Detail: "docker " + strings.TrimSpace(res.Stdout), |
| 115 | + }} |
| 116 | + |
| 117 | + // Compose is what actually applies a release. It was previously asserted |
| 118 | + // only by the deploy step, so `ob preflight` reported a host ready that |
| 119 | + // `ob deploy` then refused. |
| 120 | + res, err = run.Run(ctx, composeVersionCommand) |
| 121 | + if err != nil { |
| 122 | + return checks, err |
| 123 | + } |
| 124 | + if res.ExitCode != 0 { |
| 125 | + checks = append(checks, Check{ |
| 126 | + Name: PrerequisiteCompose, |
| 127 | + Detail: runResultDetail(res.Stderr, res.Stdout, composeVersionCommand, res.ExitCode), |
| 128 | + Remedy: composeRemedy, |
| 129 | + }) |
| 130 | + } else { |
| 131 | + checks = append(checks, Check{ |
| 132 | + Name: PrerequisiteCompose, OK: true, |
| 133 | + Detail: "compose " + strings.TrimSpace(res.Stdout), |
| 134 | + }) |
| 135 | + } |
| 136 | + |
| 137 | + detail, err := CheckBuildxDigestSupport(ctx, run) |
| 138 | + if err != nil { |
| 139 | + var capabilityErr *BuildxCapabilityError |
| 140 | + if !errors.As(err, &capabilityErr) { |
| 141 | + return checks, err |
| 142 | + } |
| 143 | + return append(checks, Check{ |
| 144 | + Name: PrerequisiteResolver, |
| 145 | + Detail: withBuildxVersion(ctx, run, capabilityErr.Error()), |
| 146 | + Remedy: BuildxRemedy, |
| 147 | + }), nil |
| 148 | + } |
| 149 | + if reportVersions { |
| 150 | + detail = withBuildxVersion(ctx, run, detail) |
| 151 | + } |
| 152 | + return append(checks, Check{ |
| 153 | + Name: PrerequisiteResolver, OK: true, Detail: detail, |
| 154 | + }), nil |
| 155 | +} |
| 156 | + |
| 157 | +// withBuildxVersion appends the client version to a capability result. The |
| 158 | +// capability probe is the authority — a client that advertises `--format` and |
| 159 | +// ignores it passes a version comparison — but the version is what makes a bug |
| 160 | +// report actionable, so both are reported. |
| 161 | +func withBuildxVersion(ctx context.Context, run Runner, detail string) string { |
| 162 | + res, err := run.Run(ctx, buildxVersionCommand) |
| 163 | + if err != nil || res.ExitCode != 0 { |
| 164 | + return detail |
| 165 | + } |
| 166 | + version := strings.TrimSpace(firstLine(res.Stdout)) |
| 167 | + if version == "" { |
| 168 | + return detail |
| 169 | + } |
| 170 | + return fmt.Sprintf("%s (%s)", detail, version) |
| 171 | +} |
| 172 | + |
| 173 | +// RequireHostPrerequisites is the refusing form of CheckHostPrerequisites, for |
| 174 | +// bootstrap and the deploy preflight step, which stop at the first problem |
| 175 | +// instead of rendering a report. |
| 176 | +// |
| 177 | +// The refusal is typed rather than prose, so a structured caller reads a code |
| 178 | +// and a command rather than parsing a sentence, and `ob preflight` is the |
| 179 | +// honest next step: it is read-only and reports every unmet prerequisite at |
| 180 | +// once, where this path stops at the first. It is never circular — the only |
| 181 | +// callers are bootstrap and the deploy step, not `ob preflight` itself. |
| 182 | +func RequireHostPrerequisites(ctx context.Context, run Runner) error { |
| 183 | + checks, err := checkHostPrerequisites(ctx, run, false) |
| 184 | + if err != nil { |
| 185 | + return err |
| 186 | + } |
| 187 | + for _, check := range checks { |
| 188 | + if check.OK { |
| 189 | + continue |
| 190 | + } |
| 191 | + // Every failing check carries a remedy — that is the point of the |
| 192 | + // remedy constants — so this needs no branch for the empty case. A |
| 193 | + // check added without one would produce a dangling em dash, which a |
| 194 | + // test asserting every remedy names an action catches. |
| 195 | + return errf("host_prerequisite_unmet", "", "ob preflight", |
| 196 | + "%s unavailable: %s — %s", check.Name, check.Detail, check.Remedy) |
| 197 | + } |
| 198 | + return nil |
| 199 | +} |
| 200 | + |
| 201 | +// HostPrerequisiteRefusal restates an unmet prerequisite with the caller's own |
| 202 | +// framing, as one typed error rather than prose wrapped around a rendered one. |
| 203 | +// Wrapping with %w renders `Error()`, which carries the code, so the caller's |
| 204 | +// sentence ended up with `host_prerequisite_unmet:` buried in the middle of it. |
| 205 | +// Every typed failure prints its code first; this keeps that shape. |
| 206 | +func HostPrerequisiteRefusal(format string, args ...any) error { |
| 207 | + return errf("host_prerequisite_unmet", "", "ob preflight", format, args...) |
| 208 | +} |
0 commit comments