mirror of
https://github.com/jcreek/CosmicClash.git
synced 2026-09-10 16:04:04 +00:00
feat(multiplayer): deliver signed workload tokens via Agones allocation annotation
Closes the remaining gap the previous two commits left open: WorkloadVerify itself worked, but nothing minted a real token at allocation time or handed it to a running pod, so it had no real caller yet. agones.Client gains WorkloadSecret/WorkloadTokenTTL. When set, Allocate mints a signed workload token for the allocation (allocation_id is known at request-construction time, before Agones has picked a server -- see the previous commit for why that's the only identifier the token can bind) and requests it as a third cosmic-clash.io/workload-token annotation, alongside the existing match-id/allocation-id ones. Left unset (the default), Allocate requests no such annotation, so a deployment not yet using this path is unaffected. cmd/allocator wires it from a new --workload-secret / COSMIC_CLASH_WORKLOAD_SECRET flag (must match cmd/control-plane's own), with a startup warning if left unset. supervisor.Supervisor.workloadToken() resolves the bearer credential for control-plane registration: an explicitly configured --workload-token-path always wins (kept for a future Kubernetes-projected-JWT WorkloadVerify path, not yet wired server-side), otherwise it falls back to the cosmic-clash.io/workload-token annotation on the allocated GameServer -- the same annotation-fallback pattern matchID already used for cosmic-clash.io/match-id. WorkloadTokenPath is accordingly no longer required at construction time when ControlPlaneURL is set. Verified: new agones test proves the annotation is requested (and parses/ verifies against the same secret, naming the right allocation) when WorkloadSecret is configured, and that it's absent when it isn't; new supervisor tests prove the annotation-sourced token is what's actually sent as the Authorization bearer, and that Start fails closed with neither a configured path nor an annotation present. Full `go build ./... && go vet ./... && gofmt -l . && go test ./... -race` and `go test -tags integration ./... -race` both clean.
This commit is contained in:
@@ -24,6 +24,7 @@ func main() {
|
||||
namespace := flag.String("agones-namespace", envOrDefault("COSMIC_CLASH_AGONES_NAMESPACE", "default"), "Agones namespace")
|
||||
transport := flag.String("transport", envOrDefault("COSMIC_CLASH_TRANSPORT", "enet"), "game transport: enet or steam_sdr")
|
||||
interval := flag.Duration("interval", time.Second, "allocation poll interval")
|
||||
workloadSecret := flag.String("workload-secret", os.Getenv("COSMIC_CLASH_WORKLOAD_SECRET"), "HMAC secret for control-plane-issued workload tokens (see workload/signed_token.go); must match cmd/control-plane's own --workload-secret. Unset skips minting a cosmic-clash.io/workload-token annotation entirely")
|
||||
flag.Parse()
|
||||
if *dsn == "" || *agonesURL == "" {
|
||||
fatalf("--dsn/COSMIC_CLASH_POSTGRES_DSN and --agones-url/COSMIC_CLASH_AGONES_URL are required")
|
||||
@@ -44,8 +45,11 @@ func main() {
|
||||
if err := migrations.Apply(startupCtx, db, *migrationDir); err != nil {
|
||||
fatalf("apply migrations: %v", err)
|
||||
}
|
||||
if *workloadSecret == "" {
|
||||
log.Printf("allocator: warning: --workload-secret / COSMIC_CLASH_WORKLOAD_SECRET is unset; allocated GameServers will receive no cosmic-clash.io/workload-token annotation, and control-plane registration will fail unless a --workload-token-path is separately configured on the supervisor")
|
||||
}
|
||||
now := func() time.Time { return time.Now().UTC() }
|
||||
client := agones.Client{BaseURL: *agonesURL, Namespace: *namespace}
|
||||
client := agones.Client{BaseURL: *agonesURL, Namespace: *namespace, WorkloadSecret: []byte(*workloadSecret)}
|
||||
worker := allocator.Worker{
|
||||
Claims: store.AllocatingMatchClaims{DB: db, Transport: *transport},
|
||||
Service: allocator.Service{
|
||||
|
||||
Reference in New Issue
Block a user