Skip to main content

build_request

Function build_request 

Source
pub fn build_request(
    workspace_root: &Path,
    machine: &MachineConfig,
    yubaba_url: String,
    yubaba_sha256: String,
    yubaba_channel: String,
    headscale_preauth_key: Option<String>,
    mesh_url: Option<String>,
    cloudflared_token: Option<String>,
    yubaba_cosign_identity_regexp: Option<String>,
) -> Result<ProvisionRequest>
Expand description

Build a provision request: load the cloud-init template for the workspace and substitute per-machine values. The yubaba binary is fetched on the machine at first boot from yubaba_url and verified against yubaba_sha256 (R040-F11) — base64-embedding it would blow past Hetzner’s 32 KiB cap.

headscale_preauth_key decides mesh membership (R330-F28). Some ⟺ this machine is JOINING an existing mesh: the rendered cloud-init emits the tailscaled install + tailscale up --auth-key=<key> join block. None ⟺ STANDALONE / coordinator-to-be — no mesh exists yet, so no join block is emitted; the node comes up as bare yubaba and becomes the coordinator later via yah mesh bootstrap. Membership is gated purely on this key’s presence, independent of machine.hosts_operator_bridge.

mesh_url is the stable Headscale coordinator URL (R040-F18). When present (only meaningful alongside a preauth key), the rendered cloud-init passes --login-server <url> to tailscale up so the machine joins the camp’s Headscale instead of Tailscale SaaS. When None, a joining machine uses the default Tailscale SaaS coordinator.

yubaba_channel selects the release channel ("stable" or "beta"); use cloud_init::DEFAULT_YUBABA_CHANNEL for Phase 1. containerd is installed unpinned (R330-T9 — an exact apt pin matched no Debian repo).