refactor(netbird): delete legacy Rust installer — #20 ph4 (manifest-driven only)
netbird is fully manifest-driven (apps/netbird-*/manifest.yml via the signed catalog): install_stack_via_orchestrator renders the 3-member stack with generated_certs (self-signed TLS for the #15 OIDC secure context), base64 generated_secrets, and templated config — and adopts the running stack by live container name. The hardcoded `podman run` fallback was therefore dead code on any node with the embedded catalog (verified live: .228 https:8087 -> 200). Removes the per-app Rust installer anti-pattern the master plan calls out: - install_netbird_stack: orchestrator -> adopt -> bail! (no in-Rust installer) - deletes 6 now-dead helpers (write_netbird_config_files, ensure_netbird_tls_cert, read_or_generate_b64_secret, netbird_net_resolver_ip, detect_netbird_public_host_ip, wait_for_netbird_oidc_ready), 3 NETBIRD_*_IMAGE consts, unused base64::Engine import - ~485 lines removed; prod_orchestrator doc-comments updated Behavioural parity: the manifest path already executed on the fleet, so this changes no live behavior. The legacy #10 OIDC-readiness wait was already bypassed by the manifest path; if that race resurfaces, add an OIDC-ready gate to the manifest rather than resurrecting the Rust fn. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
41e7f500f8
commit
89d397bb74
@@ -2964,7 +2964,8 @@ impl ProdContainerOrchestrator {
|
||||
}
|
||||
|
||||
/// The gateway IP of the app's podman network — aardvark's DNS resolver
|
||||
/// address. Mirrors the legacy `netbird_net_resolver_ip`; falls back to
|
||||
/// address. (Generalised from the old per-app netbird resolver helper,
|
||||
/// deleted in #20 ph4.) Falls back to
|
||||
/// podman's usual first-pool gateway if the inspect can't be parsed (the
|
||||
/// network was just ensured to exist, so this is a belt-and-braces default).
|
||||
async fn network_gateway(&self, manifest: &AppManifest) -> Result<String> {
|
||||
@@ -3004,8 +3005,8 @@ impl ProdContainerOrchestrator {
|
||||
/// entry whose crt+key already exist (idempotent / data-preserving). CN and
|
||||
/// SAN templates are rendered against host facts; when omitted they default
|
||||
/// to the node's host IP plus `127.0.0.1`/`localhost` so the cert is valid
|
||||
/// however the box is reached locally. Mirrors the legacy
|
||||
/// `ensure_netbird_tls_cert` (rsa:2048, 10-year, no per-app Rust).
|
||||
/// however the box is reached locally. (Generalised from the old per-app
|
||||
/// netbird TLS helper, deleted in #20 ph4: rsa:2048, 10-year, no per-app Rust.)
|
||||
async fn ensure_manifest_certs(&self, manifest: &AppManifest) -> Result<()> {
|
||||
let facts = self.detect_host_facts();
|
||||
let render = |s: &str| {
|
||||
|
||||
Reference in New Issue
Block a user