diff --git a/gen/ts/cryptos/fleet/v1/fleet_pb.ts b/gen/ts/cryptos/fleet/v1/fleet_pb.ts index bd1cf5f..85cf1e0 100644 --- a/gen/ts/cryptos/fleet/v1/fleet_pb.ts +++ b/gen/ts/cryptos/fleet/v1/fleet_pb.ts @@ -12,7 +12,7 @@ import type { Message } from "@bufbuild/protobuf"; * Describes the file cryptos/fleet/v1/fleet.proto. */ export const file_cryptos_fleet_v1_fleet: GenFile = /*@__PURE__*/ - fileDesc("ChxjcnlwdG9zL2ZsZWV0L3YxL2ZsZWV0LnByb3RvEhBjcnlwdG9zLmZsZWV0LnYxIhIKEExpc3ROb2Rlc1JlcXVlc3QiQQoRTGlzdE5vZGVzUmVzcG9uc2USLAoFbm9kZXMYASADKAsyHS5jcnlwdG9zLmZsZWV0LnYxLk5vZGVTdW1tYXJ5Ih4KDkdldE5vZGVSZXF1ZXN0EgwKBG5hbWUYASABKAkiPQoPR2V0Tm9kZVJlc3BvbnNlEioKBG5vZGUYASABKAsyHC5jcnlwdG9zLmZsZWV0LnYxLk5vZGVEZXRhaWwiJwoXTGlzdENlcnRpZmljYXRlc1JlcXVlc3QSDAoEbm9kZRgBIAEoCSJPChhMaXN0Q2VydGlmaWNhdGVzUmVzcG9uc2USMwoMY2VydGlmaWNhdGVzGAEgAygLMh0uY3J5cHRvcy5mbGVldC52MS5DZXJ0aWZpY2F0ZSIVChNMaXN0UHJvZmlsZXNSZXF1ZXN0IkUKFExpc3RQcm9maWxlc1Jlc3BvbnNlEi0KBWl0ZW1zGAEgAygLMh4uY3J5cHRvcy52MS5DZXJ0aWZpY2F0ZVByb2ZpbGUiRwoUQ3JlYXRlUHJvZmlsZVJlcXVlc3QSLwoHcHJvZmlsZRgBIAEoCzIeLmNyeXB0b3MudjEuQ2VydGlmaWNhdGVQcm9maWxlIhcKFUNyZWF0ZVByb2ZpbGVSZXNwb25zZSJHChRVcGRhdGVQcm9maWxlUmVxdWVzdBIvCgdwcm9maWxlGAEgASgLMh4uY3J5cHRvcy52MS5DZXJ0aWZpY2F0ZVByb2ZpbGUiFwoVVXBkYXRlUHJvZmlsZVJlc3BvbnNlIiQKFERlbGV0ZVByb2ZpbGVSZXF1ZXN0EgwKBG5hbWUYASABKAkiFwoVRGVsZXRlUHJvZmlsZVJlc3BvbnNlIkQKGUFwcGx5UHJvZmlsZVRvTm9kZVJlcXVlc3QSEQoJbm9kZV9uYW1lGAEgASgJEhQKDHByb2ZpbGVfbmFtZRgCIAEoCSJJChpBcHBseVByb2ZpbGVUb05vZGVSZXNwb25zZRISCgpnZW5lcmF0aW9uGAEgASgEEhcKD3JlcXVpcmVzX3JlYm9vdBgCIAEoCCIVChNMaXN0QWRhcHRlcnNSZXF1ZXN0IkoKFExpc3RBZGFwdGVyc1Jlc3BvbnNlEjIKBWl0ZW1zGAEgAygLMiMuY3J5cHRvcy5mbGVldC52MS5FbnJvbGxtZW50QWRhcHRlciI5ChhTZXRBZGFwdGVyRW5hYmxlZFJlcXVlc3QSDAoEbmFtZRgBIAEoCRIPCgdlbmFibGVkGAIgASgIIlEKGVNldEFkYXB0ZXJFbmFibGVkUmVzcG9uc2USNAoHYWRhcHRlchgBIAEoCzIjLmNyeXB0b3MuZmxlZXQudjEuRW5yb2xsbWVudEFkYXB0ZXIiEgoQTGlzdEF1ZGl0UmVxdWVzdCJAChFMaXN0QXVkaXRSZXNwb25zZRIrCgVpdGVtcxgBIAMoCzIcLmNyeXB0b3MuZmxlZXQudjEuQXVkaXRFdmVudCIYChZMaXN0RW5yb2xsbWVudHNSZXF1ZXN0Ik0KF0xpc3RFbnJvbGxtZW50c1Jlc3BvbnNlEjIKBWl0ZW1zGAEgAygLMiMuY3J5cHRvcy5mbGVldC52MS5FbnJvbGxtZW50UmVxdWVzdCKvAQoLTm9kZVN1bW1hcnkSDAoEbmFtZRgBIAEoCRIPCgdhZGRyZXNzGAIgASgJEgwKBHJvbGUYAyABKAkSFgoOaWRlbnRpdHlfc3RhdGUYBCABKAkSCgoCY24YBSABKAkSDgoGaXNzdWVyGAYgASgJEigKBmhlYWx0aBgHIAEoDjIYLmNyeXB0b3MuZmxlZXQudjEuSGVhbHRoEhUKDWhlYWx0aF9kZXRhaWwYCCABKAkiSQoMTm9kZUlkZW50aXR5EhEKCWNoYWluX3BlbRgBIAEoCRIRCgljaGFpbl9kZXIYAiADKAwSEwoLbGVhZl9zaGEyNTYYAyABKAkiqQEKCk5vZGVEZXRhaWwSLgoHc3VtbWFyeRgBIAEoCzIdLmNyeXB0b3MuZmxlZXQudjEuTm9kZVN1bW1hcnkSMAoIaWRlbnRpdHkYAiABKAsyHi5jcnlwdG9zLmZsZWV0LnYxLk5vZGVJZGVudGl0eRIVCg10cG1fYXZhaWxhYmxlGAMgASgIEhIKCmJvb3RfY291bnQYBCABKAQSDgoGdXB0aW1lGAUgASgJIsABCgtDZXJ0aWZpY2F0ZRIOCgZzZXJpYWwYASABKAkSEgoKc3ViamVjdF9jbhgCIAEoCRITCgtpc3N1ZXJfbm9kZRgDIAEoCRIMCgRraW5kGAQgASgJEg4KBnN0YXR1cxgFIAEoCRISCgpub3RfYmVmb3JlGAYgASgJEhEKCW5vdF9hZnRlchgHIAEoCRIPCgdwcm9maWxlGAggASgJEhIKCnJldm9rZWRfYXQYCSABKAkSDgoGcmVhc29uGAogASgJIo0BChFFbnJvbGxtZW50QWRhcHRlchIMCgRraW5kGAEgASgJEgwKBG5hbWUYAiABKAkSEAoIZW5kcG9pbnQYAyABKAkSDwoHcHJvZmlsZRgEIAEoCRIPCgdlbmFibGVkGAUgASgIEhIKCmNoYWxsZW5nZXMYBiADKAkSFAoMZ3BvX3RlbXBsYXRlGAcgASgJIm0KCkF1ZGl0RXZlbnQSCgoCaWQYASABKAkSCgoCYXQYAiABKAkSDAoEa2luZBgDIAEoCRIPCgdzdW1tYXJ5GAQgASgJEhMKC3RhcmdldF9raW5kGAUgASgJEhMKC3RhcmdldF9wYXRoGAYgASgJItUCChFFbnJvbGxtZW50UmVxdWVzdBIKCgJpZBgBIAEoCRIVCg1wcm9wb3NlZF9uYW1lGAIgASgJEgwKBHJvbGUYAyABKAkSEQoJcGFyZW50X2NuGAQgASgJEg8KB2FkZHJlc3MYBSABKAkSDgoGc3RhdHVzGAYgASgJEhsKE2F0dGVzdGF0aW9uX3N1bW1hcnkYByABKAkSGwoTYXR0ZXN0YXRpb25fbm9kZV9pZBgIIAEoCRIUCgxjc3Jfa2V5X3R5cGUYCSABKAkSFgoOY3NyX3N1YmplY3RfY24YCiABKAkSFAoMcmVxdWVzdGVkX2F0GAsgASgJEhgKEHJlamVjdGlvbl9yZWFzb24YDCABKAkSGgoSYWRtaXR0ZWRfbm9kZV9uYW1lGA0gASgJEgwKBGtpbmQYDiABKAkSGQoRcGlubmVkX2tleV9zaGEyNTYYDyABKAkitQEKF0NyZWF0ZUVucm9sbG1lbnRSZXF1ZXN0EgwKBGtpbmQYASABKAkSFQoNbm9kZV9lbmRwb2ludBgCIAEoCRIWCg5hZG1pbl9jZXJ0X3BlbRgDIAEoCRIVCg1hZG1pbl9rZXlfcGVtGAQgASgJEg4KBmNhX3BlbRgFIAEoCRISCgpjaGlsZF9ub2RlGAYgASgJEhEKCXBhcmVudF9jbhgHIAEoCRIPCgdwcm9maWxlGAggASgJIlMKGENyZWF0ZUVucm9sbG1lbnRSZXNwb25zZRI3CgplbnJvbGxtZW50GAEgASgLMiMuY3J5cHRvcy5mbGVldC52MS5FbnJvbGxtZW50UmVxdWVzdCJ8ChhBcHByb3ZlRW5yb2xsbWVudFJlcXVlc3QSCgoCaWQYASABKAkSFQoNbm9kZV9lbmRwb2ludBgCIAEoCRIWCg5hZG1pbl9jZXJ0X3BlbRgDIAEoCRIVCg1hZG1pbl9rZXlfcGVtGAQgASgJEg4KBmNhX3BlbRgFIAEoCSJUChlBcHByb3ZlRW5yb2xsbWVudFJlc3BvbnNlEjcKCmVucm9sbG1lbnQYASABKAsyIy5jcnlwdG9zLmZsZWV0LnYxLkVucm9sbG1lbnRSZXF1ZXN0IjUKF1JlamVjdEVucm9sbG1lbnRSZXF1ZXN0EgoKAmlkGAEgASgJEg4KBnJlYXNvbhgCIAEoCSJTChhSZWplY3RFbnJvbGxtZW50UmVzcG9uc2USNwoKZW5yb2xsbWVudBgBIAEoCzIjLmNyeXB0b3MuZmxlZXQudjEuRW5yb2xsbWVudFJlcXVlc3QiDwoNV2hvQW1JUmVxdWVzdCI9ChBPcGVyYXRvcklkZW50aXR5EgoKAmNuGAEgASgJEg4KBnNlcmlhbBgCIAEoCRINCgVsZXZlbBgDIAEoCSJGCg5XaG9BbUlSZXNwb25zZRI0CghvcGVyYXRvchgBIAEoCzIiLmNyeXB0b3MuZmxlZXQudjEuT3BlcmF0b3JJZGVudGl0eSJWChhSZXZva2VDZXJ0aWZpY2F0ZVJlcXVlc3QSEQoJbm9kZV9uYW1lGAEgASgJEhIKCnNlcmlhbF9oZXgYAiABKAkSEwoLcmVhc29uX2NvZGUYAyABKAUiWAoZUmV2b2tlQ2VydGlmaWNhdGVSZXNwb25zZRISCgpzZXJpYWxfaGV4GAEgASgJEhIKCnJldm9rZWRfYXQYAiABKAkSEwoLcmVhc29uX2NvZGUYAyABKAUiTAoQSXNzdWVMZWFmUmVxdWVzdBIRCglub2RlX25hbWUYASABKAkSDwoHY3NyX2RlchgCIAEoDBIUCgxwcm9maWxlX25hbWUYAyABKAkiJQoRSXNzdWVMZWFmUmVzcG9uc2USEAoIY2VydF9kZXIYASABKAwiOwoQUmVrZXlOb2RlUmVxdWVzdBIRCglub2RlX25hbWUYASABKAkSFAoMcHJvZmlsZV9uYW1lGAIgASgJIk0KEVJla2V5Tm9kZVJlc3BvbnNlEhIKCnN1YmplY3RfY24YASABKAkSEQoJaXNzdWVyX2NuGAIgASgJEhEKCWNoYWluX2xlbhgDIAEoBSIpChRHZXROb2RlQ29uZmlnUmVxdWVzdBIRCglub2RlX25hbWUYASABKAkiQgoVR2V0Tm9kZUNvbmZpZ1Jlc3BvbnNlEikKBmNvbmZpZxgBIAEoCzIZLmNyeXB0b3MudjEuTWFjaGluZUNvbmZpZyJWChZBcHBseU5vZGVDb25maWdSZXF1ZXN0EhEKCW5vZGVfbmFtZRgBIAEoCRIpCgZjb25maWcYAiABKAsyGS5jcnlwdG9zLnYxLk1hY2hpbmVDb25maWciRgoXQXBwbHlOb2RlQ29uZmlnUmVzcG9uc2USEgoKZ2VuZXJhdGlvbhgBIAEoBBIXCg9yZXF1aXJlc19yZWJvb3QYAiABKAgqUgoGSGVhbHRoEhYKEkhFQUxUSF9VTlNQRUNJRklFRBAAEg0KCUhFQUxUSF9VUBABEg8KC0hFQUxUSF9ET1dOEAISEAoMSEVBTFRIX0VSUk9SEAMylRAKDEZsZWV0U2VydmljZRJUCglMaXN0Tm9kZXMSIi5jcnlwdG9zLmZsZWV0LnYxLkxpc3ROb2Rlc1JlcXVlc3QaIy5jcnlwdG9zLmZsZWV0LnYxLkxpc3ROb2Rlc1Jlc3BvbnNlEk4KB0dldE5vZGUSIC5jcnlwdG9zLmZsZWV0LnYxLkdldE5vZGVSZXF1ZXN0GiEuY3J5cHRvcy5mbGVldC52MS5HZXROb2RlUmVzcG9uc2USaQoQTGlzdENlcnRpZmljYXRlcxIpLmNyeXB0b3MuZmxlZXQudjEuTGlzdENlcnRpZmljYXRlc1JlcXVlc3QaKi5jcnlwdG9zLmZsZWV0LnYxLkxpc3RDZXJ0aWZpY2F0ZXNSZXNwb25zZRJdCgxMaXN0UHJvZmlsZXMSJS5jcnlwdG9zLmZsZWV0LnYxLkxpc3RQcm9maWxlc1JlcXVlc3QaJi5jcnlwdG9zLmZsZWV0LnYxLkxpc3RQcm9maWxlc1Jlc3BvbnNlEmAKDUNyZWF0ZVByb2ZpbGUSJi5jcnlwdG9zLmZsZWV0LnYxLkNyZWF0ZVByb2ZpbGVSZXF1ZXN0GicuY3J5cHRvcy5mbGVldC52MS5DcmVhdGVQcm9maWxlUmVzcG9uc2USYAoNVXBkYXRlUHJvZmlsZRImLmNyeXB0b3MuZmxlZXQudjEuVXBkYXRlUHJvZmlsZVJlcXVlc3QaJy5jcnlwdG9zLmZsZWV0LnYxLlVwZGF0ZVByb2ZpbGVSZXNwb25zZRJgCg1EZWxldGVQcm9maWxlEiYuY3J5cHRvcy5mbGVldC52MS5EZWxldGVQcm9maWxlUmVxdWVzdBonLmNyeXB0b3MuZmxlZXQudjEuRGVsZXRlUHJvZmlsZVJlc3BvbnNlEm8KEkFwcGx5UHJvZmlsZVRvTm9kZRIrLmNyeXB0b3MuZmxlZXQudjEuQXBwbHlQcm9maWxlVG9Ob2RlUmVxdWVzdBosLmNyeXB0b3MuZmxlZXQudjEuQXBwbHlQcm9maWxlVG9Ob2RlUmVzcG9uc2USXQoMTGlzdEFkYXB0ZXJzEiUuY3J5cHRvcy5mbGVldC52MS5MaXN0QWRhcHRlcnNSZXF1ZXN0GiYuY3J5cHRvcy5mbGVldC52MS5MaXN0QWRhcHRlcnNSZXNwb25zZRJsChFTZXRBZGFwdGVyRW5hYmxlZBIqLmNyeXB0b3MuZmxlZXQudjEuU2V0QWRhcHRlckVuYWJsZWRSZXF1ZXN0GisuY3J5cHRvcy5mbGVldC52MS5TZXRBZGFwdGVyRW5hYmxlZFJlc3BvbnNlElQKCUxpc3RBdWRpdBIiLmNyeXB0b3MuZmxlZXQudjEuTGlzdEF1ZGl0UmVxdWVzdBojLmNyeXB0b3MuZmxlZXQudjEuTGlzdEF1ZGl0UmVzcG9uc2USZgoPTGlzdEVucm9sbG1lbnRzEiguY3J5cHRvcy5mbGVldC52MS5MaXN0RW5yb2xsbWVudHNSZXF1ZXN0GikuY3J5cHRvcy5mbGVldC52MS5MaXN0RW5yb2xsbWVudHNSZXNwb25zZRJpChBDcmVhdGVFbnJvbGxtZW50EikuY3J5cHRvcy5mbGVldC52MS5DcmVhdGVFbnJvbGxtZW50UmVxdWVzdBoqLmNyeXB0b3MuZmxlZXQudjEuQ3JlYXRlRW5yb2xsbWVudFJlc3BvbnNlEmwKEUFwcHJvdmVFbnJvbGxtZW50EiouY3J5cHRvcy5mbGVldC52MS5BcHByb3ZlRW5yb2xsbWVudFJlcXVlc3QaKy5jcnlwdG9zLmZsZWV0LnYxLkFwcHJvdmVFbnJvbGxtZW50UmVzcG9uc2USaQoQUmVqZWN0RW5yb2xsbWVudBIpLmNyeXB0b3MuZmxlZXQudjEuUmVqZWN0RW5yb2xsbWVudFJlcXVlc3QaKi5jcnlwdG9zLmZsZWV0LnYxLlJlamVjdEVucm9sbG1lbnRSZXNwb25zZRJLCgZXaG9BbUkSHy5jcnlwdG9zLmZsZWV0LnYxLldob0FtSVJlcXVlc3QaIC5jcnlwdG9zLmZsZWV0LnYxLldob0FtSVJlc3BvbnNlEmwKEVJldm9rZUNlcnRpZmljYXRlEiouY3J5cHRvcy5mbGVldC52MS5SZXZva2VDZXJ0aWZpY2F0ZVJlcXVlc3QaKy5jcnlwdG9zLmZsZWV0LnYxLlJldm9rZUNlcnRpZmljYXRlUmVzcG9uc2USVAoJSXNzdWVMZWFmEiIuY3J5cHRvcy5mbGVldC52MS5Jc3N1ZUxlYWZSZXF1ZXN0GiMuY3J5cHRvcy5mbGVldC52MS5Jc3N1ZUxlYWZSZXNwb25zZRJUCglSZWtleU5vZGUSIi5jcnlwdG9zLmZsZWV0LnYxLlJla2V5Tm9kZVJlcXVlc3QaIy5jcnlwdG9zLmZsZWV0LnYxLlJla2V5Tm9kZVJlc3BvbnNlEmAKDUdldE5vZGVDb25maWcSJi5jcnlwdG9zLmZsZWV0LnYxLkdldE5vZGVDb25maWdSZXF1ZXN0GicuY3J5cHRvcy5mbGVldC52MS5HZXROb2RlQ29uZmlnUmVzcG9uc2USZgoPQXBwbHlOb2RlQ29uZmlnEiguY3J5cHRvcy5mbGVldC52MS5BcHBseU5vZGVDb25maWdSZXF1ZXN0GikuY3J5cHRvcy5mbGVldC52MS5BcHBseU5vZGVDb25maWdSZXNwb25zZUI4WjZnaXRodWIuY29tL0NyeXB0T1MtUEtJL2FwaS9nby9jcnlwdG9zL2ZsZWV0L3YxO2ZsZWV0djFiBnByb3RvMw", [file_cryptos_v1_config]); + fileDesc("ChxjcnlwdG9zL2ZsZWV0L3YxL2ZsZWV0LnByb3RvEhBjcnlwdG9zLmZsZWV0LnYxIhIKEExpc3ROb2Rlc1JlcXVlc3QiQQoRTGlzdE5vZGVzUmVzcG9uc2USLAoFbm9kZXMYASADKAsyHS5jcnlwdG9zLmZsZWV0LnYxLk5vZGVTdW1tYXJ5Ih4KDkdldE5vZGVSZXF1ZXN0EgwKBG5hbWUYASABKAkiPQoPR2V0Tm9kZVJlc3BvbnNlEioKBG5vZGUYASABKAsyHC5jcnlwdG9zLmZsZWV0LnYxLk5vZGVEZXRhaWwiJwoXTGlzdENlcnRpZmljYXRlc1JlcXVlc3QSDAoEbm9kZRgBIAEoCSJPChhMaXN0Q2VydGlmaWNhdGVzUmVzcG9uc2USMwoMY2VydGlmaWNhdGVzGAEgAygLMh0uY3J5cHRvcy5mbGVldC52MS5DZXJ0aWZpY2F0ZSIVChNMaXN0UHJvZmlsZXNSZXF1ZXN0IkUKFExpc3RQcm9maWxlc1Jlc3BvbnNlEi0KBWl0ZW1zGAEgAygLMh4uY3J5cHRvcy52MS5DZXJ0aWZpY2F0ZVByb2ZpbGUiRwoUQ3JlYXRlUHJvZmlsZVJlcXVlc3QSLwoHcHJvZmlsZRgBIAEoCzIeLmNyeXB0b3MudjEuQ2VydGlmaWNhdGVQcm9maWxlIhcKFUNyZWF0ZVByb2ZpbGVSZXNwb25zZSJHChRVcGRhdGVQcm9maWxlUmVxdWVzdBIvCgdwcm9maWxlGAEgASgLMh4uY3J5cHRvcy52MS5DZXJ0aWZpY2F0ZVByb2ZpbGUiFwoVVXBkYXRlUHJvZmlsZVJlc3BvbnNlIiQKFERlbGV0ZVByb2ZpbGVSZXF1ZXN0EgwKBG5hbWUYASABKAkiFwoVRGVsZXRlUHJvZmlsZVJlc3BvbnNlIkQKGUFwcGx5UHJvZmlsZVRvTm9kZVJlcXVlc3QSEQoJbm9kZV9uYW1lGAEgASgJEhQKDHByb2ZpbGVfbmFtZRgCIAEoCSJJChpBcHBseVByb2ZpbGVUb05vZGVSZXNwb25zZRISCgpnZW5lcmF0aW9uGAEgASgEEhcKD3JlcXVpcmVzX3JlYm9vdBgCIAEoCCIVChNMaXN0QWRhcHRlcnNSZXF1ZXN0IkoKFExpc3RBZGFwdGVyc1Jlc3BvbnNlEjIKBWl0ZW1zGAEgAygLMiMuY3J5cHRvcy5mbGVldC52MS5FbnJvbGxtZW50QWRhcHRlciI5ChhTZXRBZGFwdGVyRW5hYmxlZFJlcXVlc3QSDAoEbmFtZRgBIAEoCRIPCgdlbmFibGVkGAIgASgIIlEKGVNldEFkYXB0ZXJFbmFibGVkUmVzcG9uc2USNAoHYWRhcHRlchgBIAEoCzIjLmNyeXB0b3MuZmxlZXQudjEuRW5yb2xsbWVudEFkYXB0ZXIiEgoQTGlzdEF1ZGl0UmVxdWVzdCJAChFMaXN0QXVkaXRSZXNwb25zZRIrCgVpdGVtcxgBIAMoCzIcLmNyeXB0b3MuZmxlZXQudjEuQXVkaXRFdmVudCIYChZMaXN0RW5yb2xsbWVudHNSZXF1ZXN0Ik0KF0xpc3RFbnJvbGxtZW50c1Jlc3BvbnNlEjIKBWl0ZW1zGAEgAygLMiMuY3J5cHRvcy5mbGVldC52MS5FbnJvbGxtZW50UmVxdWVzdCKvAQoLTm9kZVN1bW1hcnkSDAoEbmFtZRgBIAEoCRIPCgdhZGRyZXNzGAIgASgJEgwKBHJvbGUYAyABKAkSFgoOaWRlbnRpdHlfc3RhdGUYBCABKAkSCgoCY24YBSABKAkSDgoGaXNzdWVyGAYgASgJEigKBmhlYWx0aBgHIAEoDjIYLmNyeXB0b3MuZmxlZXQudjEuSGVhbHRoEhUKDWhlYWx0aF9kZXRhaWwYCCABKAkiSQoMTm9kZUlkZW50aXR5EhEKCWNoYWluX3BlbRgBIAEoCRIRCgljaGFpbl9kZXIYAiADKAwSEwoLbGVhZl9zaGEyNTYYAyABKAkiqQEKCk5vZGVEZXRhaWwSLgoHc3VtbWFyeRgBIAEoCzIdLmNyeXB0b3MuZmxlZXQudjEuTm9kZVN1bW1hcnkSMAoIaWRlbnRpdHkYAiABKAsyHi5jcnlwdG9zLmZsZWV0LnYxLk5vZGVJZGVudGl0eRIVCg10cG1fYXZhaWxhYmxlGAMgASgIEhIKCmJvb3RfY291bnQYBCABKAQSDgoGdXB0aW1lGAUgASgJIsABCgtDZXJ0aWZpY2F0ZRIOCgZzZXJpYWwYASABKAkSEgoKc3ViamVjdF9jbhgCIAEoCRITCgtpc3N1ZXJfbm9kZRgDIAEoCRIMCgRraW5kGAQgASgJEg4KBnN0YXR1cxgFIAEoCRISCgpub3RfYmVmb3JlGAYgASgJEhEKCW5vdF9hZnRlchgHIAEoCRIPCgdwcm9maWxlGAggASgJEhIKCnJldm9rZWRfYXQYCSABKAkSDgoGcmVhc29uGAogASgJIo0BChFFbnJvbGxtZW50QWRhcHRlchIMCgRraW5kGAEgASgJEgwKBG5hbWUYAiABKAkSEAoIZW5kcG9pbnQYAyABKAkSDwoHcHJvZmlsZRgEIAEoCRIPCgdlbmFibGVkGAUgASgIEhIKCmNoYWxsZW5nZXMYBiADKAkSFAoMZ3BvX3RlbXBsYXRlGAcgASgJIm0KCkF1ZGl0RXZlbnQSCgoCaWQYASABKAkSCgoCYXQYAiABKAkSDAoEa2luZBgDIAEoCRIPCgdzdW1tYXJ5GAQgASgJEhMKC3RhcmdldF9raW5kGAUgASgJEhMKC3RhcmdldF9wYXRoGAYgASgJItUCChFFbnJvbGxtZW50UmVxdWVzdBIKCgJpZBgBIAEoCRIVCg1wcm9wb3NlZF9uYW1lGAIgASgJEgwKBHJvbGUYAyABKAkSEQoJcGFyZW50X2NuGAQgASgJEg8KB2FkZHJlc3MYBSABKAkSDgoGc3RhdHVzGAYgASgJEhsKE2F0dGVzdGF0aW9uX3N1bW1hcnkYByABKAkSGwoTYXR0ZXN0YXRpb25fbm9kZV9pZBgIIAEoCRIUCgxjc3Jfa2V5X3R5cGUYCSABKAkSFgoOY3NyX3N1YmplY3RfY24YCiABKAkSFAoMcmVxdWVzdGVkX2F0GAsgASgJEhgKEHJlamVjdGlvbl9yZWFzb24YDCABKAkSGgoSYWRtaXR0ZWRfbm9kZV9uYW1lGA0gASgJEgwKBGtpbmQYDiABKAkSGQoRcGlubmVkX2tleV9zaGEyNTYYDyABKAkitQEKF0NyZWF0ZUVucm9sbG1lbnRSZXF1ZXN0EgwKBGtpbmQYASABKAkSFQoNbm9kZV9lbmRwb2ludBgCIAEoCRIWCg5hZG1pbl9jZXJ0X3BlbRgDIAEoCRIVCg1hZG1pbl9rZXlfcGVtGAQgASgJEg4KBmNhX3BlbRgFIAEoCRISCgpjaGlsZF9ub2RlGAYgASgJEhEKCXBhcmVudF9jbhgHIAEoCRIPCgdwcm9maWxlGAggASgJIlMKGENyZWF0ZUVucm9sbG1lbnRSZXNwb25zZRI3CgplbnJvbGxtZW50GAEgASgLMiMuY3J5cHRvcy5mbGVldC52MS5FbnJvbGxtZW50UmVxdWVzdCJ8ChhBcHByb3ZlRW5yb2xsbWVudFJlcXVlc3QSCgoCaWQYASABKAkSFQoNbm9kZV9lbmRwb2ludBgCIAEoCRIWCg5hZG1pbl9jZXJ0X3BlbRgDIAEoCRIVCg1hZG1pbl9rZXlfcGVtGAQgASgJEg4KBmNhX3BlbRgFIAEoCSJUChlBcHByb3ZlRW5yb2xsbWVudFJlc3BvbnNlEjcKCmVucm9sbG1lbnQYASABKAsyIy5jcnlwdG9zLmZsZWV0LnYxLkVucm9sbG1lbnRSZXF1ZXN0IjUKF1JlamVjdEVucm9sbG1lbnRSZXF1ZXN0EgoKAmlkGAEgASgJEg4KBnJlYXNvbhgCIAEoCSJTChhSZWplY3RFbnJvbGxtZW50UmVzcG9uc2USNwoKZW5yb2xsbWVudBgBIAEoCzIjLmNyeXB0b3MuZmxlZXQudjEuRW5yb2xsbWVudFJlcXVlc3QiDwoNV2hvQW1JUmVxdWVzdCI9ChBPcGVyYXRvcklkZW50aXR5EgoKAmNuGAEgASgJEg4KBnNlcmlhbBgCIAEoCRINCgVsZXZlbBgDIAEoCSJGCg5XaG9BbUlSZXNwb25zZRI0CghvcGVyYXRvchgBIAEoCzIiLmNyeXB0b3MuZmxlZXQudjEuT3BlcmF0b3JJZGVudGl0eSJWChhSZXZva2VDZXJ0aWZpY2F0ZVJlcXVlc3QSEQoJbm9kZV9uYW1lGAEgASgJEhIKCnNlcmlhbF9oZXgYAiABKAkSEwoLcmVhc29uX2NvZGUYAyABKAUiWAoZUmV2b2tlQ2VydGlmaWNhdGVSZXNwb25zZRISCgpzZXJpYWxfaGV4GAEgASgJEhIKCnJldm9rZWRfYXQYAiABKAkSEwoLcmVhc29uX2NvZGUYAyABKAUiTAoQSXNzdWVMZWFmUmVxdWVzdBIRCglub2RlX25hbWUYASABKAkSDwoHY3NyX2RlchgCIAEoDBIUCgxwcm9maWxlX25hbWUYAyABKAkiJQoRSXNzdWVMZWFmUmVzcG9uc2USEAoIY2VydF9kZXIYASABKAwiOwoQUmVrZXlOb2RlUmVxdWVzdBIRCglub2RlX25hbWUYASABKAkSFAoMcHJvZmlsZV9uYW1lGAIgASgJIk0KEVJla2V5Tm9kZVJlc3BvbnNlEhIKCnN1YmplY3RfY24YASABKAkSEQoJaXNzdWVyX2NuGAIgASgJEhEKCWNoYWluX2xlbhgDIAEoBSIpChRHZXROb2RlQ29uZmlnUmVxdWVzdBIRCglub2RlX25hbWUYASABKAkiQgoVR2V0Tm9kZUNvbmZpZ1Jlc3BvbnNlEikKBmNvbmZpZxgBIAEoCzIZLmNyeXB0b3MudjEuTWFjaGluZUNvbmZpZyJWChZBcHBseU5vZGVDb25maWdSZXF1ZXN0EhEKCW5vZGVfbmFtZRgBIAEoCRIpCgZjb25maWcYAiABKAsyGS5jcnlwdG9zLnYxLk1hY2hpbmVDb25maWciRgoXQXBwbHlOb2RlQ29uZmlnUmVzcG9uc2USEgoKZ2VuZXJhdGlvbhgBIAEoBBIXCg9yZXF1aXJlc19yZWJvb3QYAiABKAgiOwoSRXhwb3J0Q0FLZXlSZXF1ZXN0EhEKCW5vZGVfbmFtZRgBIAEoCRISCgpwYXNzcGhyYXNlGAIgASgMIicKE0V4cG9ydENBS2V5UmVzcG9uc2USEAoIZW52ZWxvcGUYASABKAwiTQoSSW1wb3J0Q0FLZXlSZXF1ZXN0EhEKCW5vZGVfbmFtZRgBIAEoCRIQCghlbnZlbG9wZRgCIAEoDBISCgpwYXNzcGhyYXNlGAMgASgMIjwKE0ltcG9ydENBS2V5UmVzcG9uc2USEgoKc3ViamVjdF9jbhgBIAEoCRIRCglpc3N1ZXJfY24YAiABKAkqUgoGSGVhbHRoEhYKEkhFQUxUSF9VTlNQRUNJRklFRBAAEg0KCUhFQUxUSF9VUBABEg8KC0hFQUxUSF9ET1dOEAISEAoMSEVBTFRIX0VSUk9SEAMyzREKDEZsZWV0U2VydmljZRJUCglMaXN0Tm9kZXMSIi5jcnlwdG9zLmZsZWV0LnYxLkxpc3ROb2Rlc1JlcXVlc3QaIy5jcnlwdG9zLmZsZWV0LnYxLkxpc3ROb2Rlc1Jlc3BvbnNlEk4KB0dldE5vZGUSIC5jcnlwdG9zLmZsZWV0LnYxLkdldE5vZGVSZXF1ZXN0GiEuY3J5cHRvcy5mbGVldC52MS5HZXROb2RlUmVzcG9uc2USaQoQTGlzdENlcnRpZmljYXRlcxIpLmNyeXB0b3MuZmxlZXQudjEuTGlzdENlcnRpZmljYXRlc1JlcXVlc3QaKi5jcnlwdG9zLmZsZWV0LnYxLkxpc3RDZXJ0aWZpY2F0ZXNSZXNwb25zZRJdCgxMaXN0UHJvZmlsZXMSJS5jcnlwdG9zLmZsZWV0LnYxLkxpc3RQcm9maWxlc1JlcXVlc3QaJi5jcnlwdG9zLmZsZWV0LnYxLkxpc3RQcm9maWxlc1Jlc3BvbnNlEmAKDUNyZWF0ZVByb2ZpbGUSJi5jcnlwdG9zLmZsZWV0LnYxLkNyZWF0ZVByb2ZpbGVSZXF1ZXN0GicuY3J5cHRvcy5mbGVldC52MS5DcmVhdGVQcm9maWxlUmVzcG9uc2USYAoNVXBkYXRlUHJvZmlsZRImLmNyeXB0b3MuZmxlZXQudjEuVXBkYXRlUHJvZmlsZVJlcXVlc3QaJy5jcnlwdG9zLmZsZWV0LnYxLlVwZGF0ZVByb2ZpbGVSZXNwb25zZRJgCg1EZWxldGVQcm9maWxlEiYuY3J5cHRvcy5mbGVldC52MS5EZWxldGVQcm9maWxlUmVxdWVzdBonLmNyeXB0b3MuZmxlZXQudjEuRGVsZXRlUHJvZmlsZVJlc3BvbnNlEm8KEkFwcGx5UHJvZmlsZVRvTm9kZRIrLmNyeXB0b3MuZmxlZXQudjEuQXBwbHlQcm9maWxlVG9Ob2RlUmVxdWVzdBosLmNyeXB0b3MuZmxlZXQudjEuQXBwbHlQcm9maWxlVG9Ob2RlUmVzcG9uc2USXQoMTGlzdEFkYXB0ZXJzEiUuY3J5cHRvcy5mbGVldC52MS5MaXN0QWRhcHRlcnNSZXF1ZXN0GiYuY3J5cHRvcy5mbGVldC52MS5MaXN0QWRhcHRlcnNSZXNwb25zZRJsChFTZXRBZGFwdGVyRW5hYmxlZBIqLmNyeXB0b3MuZmxlZXQudjEuU2V0QWRhcHRlckVuYWJsZWRSZXF1ZXN0GisuY3J5cHRvcy5mbGVldC52MS5TZXRBZGFwdGVyRW5hYmxlZFJlc3BvbnNlElQKCUxpc3RBdWRpdBIiLmNyeXB0b3MuZmxlZXQudjEuTGlzdEF1ZGl0UmVxdWVzdBojLmNyeXB0b3MuZmxlZXQudjEuTGlzdEF1ZGl0UmVzcG9uc2USZgoPTGlzdEVucm9sbG1lbnRzEiguY3J5cHRvcy5mbGVldC52MS5MaXN0RW5yb2xsbWVudHNSZXF1ZXN0GikuY3J5cHRvcy5mbGVldC52MS5MaXN0RW5yb2xsbWVudHNSZXNwb25zZRJpChBDcmVhdGVFbnJvbGxtZW50EikuY3J5cHRvcy5mbGVldC52MS5DcmVhdGVFbnJvbGxtZW50UmVxdWVzdBoqLmNyeXB0b3MuZmxlZXQudjEuQ3JlYXRlRW5yb2xsbWVudFJlc3BvbnNlEmwKEUFwcHJvdmVFbnJvbGxtZW50EiouY3J5cHRvcy5mbGVldC52MS5BcHByb3ZlRW5yb2xsbWVudFJlcXVlc3QaKy5jcnlwdG9zLmZsZWV0LnYxLkFwcHJvdmVFbnJvbGxtZW50UmVzcG9uc2USaQoQUmVqZWN0RW5yb2xsbWVudBIpLmNyeXB0b3MuZmxlZXQudjEuUmVqZWN0RW5yb2xsbWVudFJlcXVlc3QaKi5jcnlwdG9zLmZsZWV0LnYxLlJlamVjdEVucm9sbG1lbnRSZXNwb25zZRJLCgZXaG9BbUkSHy5jcnlwdG9zLmZsZWV0LnYxLldob0FtSVJlcXVlc3QaIC5jcnlwdG9zLmZsZWV0LnYxLldob0FtSVJlc3BvbnNlEmwKEVJldm9rZUNlcnRpZmljYXRlEiouY3J5cHRvcy5mbGVldC52MS5SZXZva2VDZXJ0aWZpY2F0ZVJlcXVlc3QaKy5jcnlwdG9zLmZsZWV0LnYxLlJldm9rZUNlcnRpZmljYXRlUmVzcG9uc2USVAoJSXNzdWVMZWFmEiIuY3J5cHRvcy5mbGVldC52MS5Jc3N1ZUxlYWZSZXF1ZXN0GiMuY3J5cHRvcy5mbGVldC52MS5Jc3N1ZUxlYWZSZXNwb25zZRJUCglSZWtleU5vZGUSIi5jcnlwdG9zLmZsZWV0LnYxLlJla2V5Tm9kZVJlcXVlc3QaIy5jcnlwdG9zLmZsZWV0LnYxLlJla2V5Tm9kZVJlc3BvbnNlEmAKDUdldE5vZGVDb25maWcSJi5jcnlwdG9zLmZsZWV0LnYxLkdldE5vZGVDb25maWdSZXF1ZXN0GicuY3J5cHRvcy5mbGVldC52MS5HZXROb2RlQ29uZmlnUmVzcG9uc2USZgoPQXBwbHlOb2RlQ29uZmlnEiguY3J5cHRvcy5mbGVldC52MS5BcHBseU5vZGVDb25maWdSZXF1ZXN0GikuY3J5cHRvcy5mbGVldC52MS5BcHBseU5vZGVDb25maWdSZXNwb25zZRJaCgtFeHBvcnRDQUtleRIkLmNyeXB0b3MuZmxlZXQudjEuRXhwb3J0Q0FLZXlSZXF1ZXN0GiUuY3J5cHRvcy5mbGVldC52MS5FeHBvcnRDQUtleVJlc3BvbnNlEloKC0ltcG9ydENBS2V5EiQuY3J5cHRvcy5mbGVldC52MS5JbXBvcnRDQUtleVJlcXVlc3QaJS5jcnlwdG9zLmZsZWV0LnYxLkltcG9ydENBS2V5UmVzcG9uc2VCOFo2Z2l0aHViLmNvbS9DcnlwdE9TLVBLSS9hcGkvZ28vY3J5cHRvcy9mbGVldC92MTtmbGVldHYxYgZwcm90bzM", [file_cryptos_v1_config]); /** * @generated from message cryptos.fleet.v1.ListNodesRequest @@ -1340,6 +1340,124 @@ export type ApplyNodeConfigResponse = Message<"cryptos.fleet.v1.ApplyNodeConfigR export const ApplyNodeConfigResponseSchema: GenMessage = /*@__PURE__*/ messageDesc(file_cryptos_fleet_v1_fleet, 49); +/** + * ExportCAKeyRequest names the managed node to back up and carries the operator + * passphrase the node seals the backup with. The passphrase is relayed to the + * node in transit and is never persisted by the manager. + * + * @generated from message cryptos.fleet.v1.ExportCAKeyRequest + */ +export type ExportCAKeyRequest = Message<"cryptos.fleet.v1.ExportCAKeyRequest"> & { + /** + * node_name is the managed node whose CA key to export. + * + * @generated from field: string node_name = 1; + */ + nodeName: string; + + /** + * passphrase seals the backup node-side; it is never persisted. + * + * @generated from field: bytes passphrase = 2; + */ + passphrase: Uint8Array; +}; + +/** + * Describes the message cryptos.fleet.v1.ExportCAKeyRequest. + * Use `create(ExportCAKeyRequestSchema)` to create a new message. + */ +export const ExportCAKeyRequestSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_cryptos_fleet_v1_fleet, 50); + +/** + * ExportCAKeyResponse carries the encrypted backup envelope (Argon2id + + * AES-256-GCM over the node's CA key material). It is opaque to the manager. + * + * @generated from message cryptos.fleet.v1.ExportCAKeyResponse + */ +export type ExportCAKeyResponse = Message<"cryptos.fleet.v1.ExportCAKeyResponse"> & { + /** + * envelope is the encrypted CA key backup. + * + * @generated from field: bytes envelope = 1; + */ + envelope: Uint8Array; +}; + +/** + * Describes the message cryptos.fleet.v1.ExportCAKeyResponse. + * Use `create(ExportCAKeyResponseSchema)` to create a new message. + */ +export const ExportCAKeyResponseSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_cryptos_fleet_v1_fleet, 51); + +/** + * ImportCAKeyRequest names the fresh target node, the encrypted envelope to + * restore, and the passphrase that unseals it. The passphrase is relayed to + * the node in transit and is never persisted by the manager. + * + * @generated from message cryptos.fleet.v1.ImportCAKeyRequest + */ +export type ImportCAKeyRequest = Message<"cryptos.fleet.v1.ImportCAKeyRequest"> & { + /** + * node_name is the fresh managed node to restore the identity onto. + * + * @generated from field: string node_name = 1; + */ + nodeName: string; + + /** + * envelope is the encrypted CA key backup produced by ExportCAKey. + * + * @generated from field: bytes envelope = 2; + */ + envelope: Uint8Array; + + /** + * passphrase unseals the envelope node-side; it is never persisted. + * + * @generated from field: bytes passphrase = 3; + */ + passphrase: Uint8Array; +}; + +/** + * Describes the message cryptos.fleet.v1.ImportCAKeyRequest. + * Use `create(ImportCAKeyRequestSchema)` to create a new message. + */ +export const ImportCAKeyRequestSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_cryptos_fleet_v1_fleet, 52); + +/** + * ImportCAKeyResponse summarizes the restored identity so the web can confirm + * what was imported, without returning the full identity chain. + * + * @generated from message cryptos.fleet.v1.ImportCAKeyResponse + */ +export type ImportCAKeyResponse = Message<"cryptos.fleet.v1.ImportCAKeyResponse"> & { + /** + * subject_cn is the restored identity's subject common name. + * + * @generated from field: string subject_cn = 1; + */ + subjectCn: string; + + /** + * issuer_cn is the restored identity's issuer common name. + * + * @generated from field: string issuer_cn = 2; + */ + issuerCn: string; +}; + +/** + * Describes the message cryptos.fleet.v1.ImportCAKeyResponse. + * Use `create(ImportCAKeyResponseSchema)` to create a new message. + */ +export const ImportCAKeyResponseSchema: GenMessage = /*@__PURE__*/ + messageDesc(file_cryptos_fleet_v1_fleet, 53); + /** * Health reports the manager's view of node reachability, independent of * the node's own reported identity state. @@ -1623,6 +1741,36 @@ export const FleetService: GenService<{ input: typeof ApplyNodeConfigRequestSchema; output: typeof ApplyNodeConfigResponseSchema; }, + /** + * ExportCAKey backs up a managed node's CA private key to an encrypted + * envelope. The node seals the backup with the operator passphrase + * (Argon2id + AES-256-GCM) so the plaintext key never leaves the node; the + * manager only relays the envelope through to the caller. The passphrase is + * used in transit and is never persisted. A TPM-backed node refuses export. + * Admin-gated and audited (the audit names the node only, never the secret). + * + * @generated from rpc cryptos.fleet.v1.FleetService.ExportCAKey + */ + exportCAKey: { + methodKind: "unary"; + input: typeof ExportCAKeyRequestSchema; + output: typeof ExportCAKeyResponseSchema; + }, + /** + * ImportCAKey restores a CA identity onto a fresh managed node from an + * encrypted envelope produced by ExportCAKey. The node decrypts the envelope + * with the operator passphrase and adopts the key; it refuses the import if + * it already holds an identity. The passphrase transits the manager only to + * reach the node and is never persisted. Admin-gated and audited (the audit + * names the node and restored subject only, never the secret or envelope). + * + * @generated from rpc cryptos.fleet.v1.FleetService.ImportCAKey + */ + importCAKey: { + methodKind: "unary"; + input: typeof ImportCAKeyRequestSchema; + output: typeof ImportCAKeyResponseSchema; + }, }> = /*@__PURE__*/ serviceDesc(file_cryptos_fleet_v1_fleet, 0); diff --git a/go/cryptos/fleet/v1/fleet.pb.go b/go/cryptos/fleet/v1/fleet.pb.go index 1270b63..d52fef9 100644 --- a/go/cryptos/fleet/v1/fleet.pb.go +++ b/go/cryptos/fleet/v1/fleet.pb.go @@ -3023,6 +3023,244 @@ func (x *ApplyNodeConfigResponse) GetRequiresReboot() bool { return false } +// ExportCAKeyRequest names the managed node to back up and carries the operator +// passphrase the node seals the backup with. The passphrase is relayed to the +// node in transit and is never persisted by the manager. +type ExportCAKeyRequest struct { + state protoimpl.MessageState + sizeCache protoimpl.SizeCache + unknownFields protoimpl.UnknownFields + + // node_name is the managed node whose CA key to export. + NodeName string `protobuf:"bytes,1,opt,name=node_name,json=nodeName,proto3" json:"node_name,omitempty"` + // passphrase seals the backup node-side; it is never persisted. + Passphrase []byte `protobuf:"bytes,2,opt,name=passphrase,proto3" json:"passphrase,omitempty"` +} + +func (x *ExportCAKeyRequest) Reset() { + *x = ExportCAKeyRequest{} + if protoimpl.UnsafeEnabled { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[50] + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + ms.StoreMessageInfo(mi) + } +} + +func (x *ExportCAKeyRequest) String() string { + return protoimpl.X.MessageStringOf(x) +} + +func (*ExportCAKeyRequest) ProtoMessage() {} + +func (x *ExportCAKeyRequest) ProtoReflect() protoreflect.Message { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[50] + if protoimpl.UnsafeEnabled && x != nil { + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + if ms.LoadMessageInfo() == nil { + ms.StoreMessageInfo(mi) + } + return ms + } + return mi.MessageOf(x) +} + +// Deprecated: Use ExportCAKeyRequest.ProtoReflect.Descriptor instead. +func (*ExportCAKeyRequest) Descriptor() ([]byte, []int) { + return file_cryptos_fleet_v1_fleet_proto_rawDescGZIP(), []int{50} +} + +func (x *ExportCAKeyRequest) GetNodeName() string { + if x != nil { + return x.NodeName + } + return "" +} + +func (x *ExportCAKeyRequest) GetPassphrase() []byte { + if x != nil { + return x.Passphrase + } + return nil +} + +// ExportCAKeyResponse carries the encrypted backup envelope (Argon2id + +// AES-256-GCM over the node's CA key material). It is opaque to the manager. +type ExportCAKeyResponse struct { + state protoimpl.MessageState + sizeCache protoimpl.SizeCache + unknownFields protoimpl.UnknownFields + + // envelope is the encrypted CA key backup. + Envelope []byte `protobuf:"bytes,1,opt,name=envelope,proto3" json:"envelope,omitempty"` +} + +func (x *ExportCAKeyResponse) Reset() { + *x = ExportCAKeyResponse{} + if protoimpl.UnsafeEnabled { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[51] + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + ms.StoreMessageInfo(mi) + } +} + +func (x *ExportCAKeyResponse) String() string { + return protoimpl.X.MessageStringOf(x) +} + +func (*ExportCAKeyResponse) ProtoMessage() {} + +func (x *ExportCAKeyResponse) ProtoReflect() protoreflect.Message { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[51] + if protoimpl.UnsafeEnabled && x != nil { + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + if ms.LoadMessageInfo() == nil { + ms.StoreMessageInfo(mi) + } + return ms + } + return mi.MessageOf(x) +} + +// Deprecated: Use ExportCAKeyResponse.ProtoReflect.Descriptor instead. +func (*ExportCAKeyResponse) Descriptor() ([]byte, []int) { + return file_cryptos_fleet_v1_fleet_proto_rawDescGZIP(), []int{51} +} + +func (x *ExportCAKeyResponse) GetEnvelope() []byte { + if x != nil { + return x.Envelope + } + return nil +} + +// ImportCAKeyRequest names the fresh target node, the encrypted envelope to +// restore, and the passphrase that unseals it. The passphrase is relayed to +// the node in transit and is never persisted by the manager. +type ImportCAKeyRequest struct { + state protoimpl.MessageState + sizeCache protoimpl.SizeCache + unknownFields protoimpl.UnknownFields + + // node_name is the fresh managed node to restore the identity onto. + NodeName string `protobuf:"bytes,1,opt,name=node_name,json=nodeName,proto3" json:"node_name,omitempty"` + // envelope is the encrypted CA key backup produced by ExportCAKey. + Envelope []byte `protobuf:"bytes,2,opt,name=envelope,proto3" json:"envelope,omitempty"` + // passphrase unseals the envelope node-side; it is never persisted. + Passphrase []byte `protobuf:"bytes,3,opt,name=passphrase,proto3" json:"passphrase,omitempty"` +} + +func (x *ImportCAKeyRequest) Reset() { + *x = ImportCAKeyRequest{} + if protoimpl.UnsafeEnabled { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[52] + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + ms.StoreMessageInfo(mi) + } +} + +func (x *ImportCAKeyRequest) String() string { + return protoimpl.X.MessageStringOf(x) +} + +func (*ImportCAKeyRequest) ProtoMessage() {} + +func (x *ImportCAKeyRequest) ProtoReflect() protoreflect.Message { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[52] + if protoimpl.UnsafeEnabled && x != nil { + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + if ms.LoadMessageInfo() == nil { + ms.StoreMessageInfo(mi) + } + return ms + } + return mi.MessageOf(x) +} + +// Deprecated: Use ImportCAKeyRequest.ProtoReflect.Descriptor instead. +func (*ImportCAKeyRequest) Descriptor() ([]byte, []int) { + return file_cryptos_fleet_v1_fleet_proto_rawDescGZIP(), []int{52} +} + +func (x *ImportCAKeyRequest) GetNodeName() string { + if x != nil { + return x.NodeName + } + return "" +} + +func (x *ImportCAKeyRequest) GetEnvelope() []byte { + if x != nil { + return x.Envelope + } + return nil +} + +func (x *ImportCAKeyRequest) GetPassphrase() []byte { + if x != nil { + return x.Passphrase + } + return nil +} + +// ImportCAKeyResponse summarizes the restored identity so the web can confirm +// what was imported, without returning the full identity chain. +type ImportCAKeyResponse struct { + state protoimpl.MessageState + sizeCache protoimpl.SizeCache + unknownFields protoimpl.UnknownFields + + // subject_cn is the restored identity's subject common name. + SubjectCn string `protobuf:"bytes,1,opt,name=subject_cn,json=subjectCn,proto3" json:"subject_cn,omitempty"` + // issuer_cn is the restored identity's issuer common name. + IssuerCn string `protobuf:"bytes,2,opt,name=issuer_cn,json=issuerCn,proto3" json:"issuer_cn,omitempty"` +} + +func (x *ImportCAKeyResponse) Reset() { + *x = ImportCAKeyResponse{} + if protoimpl.UnsafeEnabled { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[53] + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + ms.StoreMessageInfo(mi) + } +} + +func (x *ImportCAKeyResponse) String() string { + return protoimpl.X.MessageStringOf(x) +} + +func (*ImportCAKeyResponse) ProtoMessage() {} + +func (x *ImportCAKeyResponse) ProtoReflect() protoreflect.Message { + mi := &file_cryptos_fleet_v1_fleet_proto_msgTypes[53] + if protoimpl.UnsafeEnabled && x != nil { + ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x)) + if ms.LoadMessageInfo() == nil { + ms.StoreMessageInfo(mi) + } + return ms + } + return mi.MessageOf(x) +} + +// Deprecated: Use ImportCAKeyResponse.ProtoReflect.Descriptor instead. +func (*ImportCAKeyResponse) Descriptor() ([]byte, []int) { + return file_cryptos_fleet_v1_fleet_proto_rawDescGZIP(), []int{53} +} + +func (x *ImportCAKeyResponse) GetSubjectCn() string { + if x != nil { + return x.SubjectCn + } + return "" +} + +func (x *ImportCAKeyResponse) GetIssuerCn() string { + if x != nil { + return x.IssuerCn + } + return "" +} + var File_cryptos_fleet_v1_fleet_proto protoreflect.FileDescriptor var file_cryptos_fleet_v1_fleet_proto_rawDesc = []byte{ @@ -3348,141 +3586,173 @@ var file_cryptos_fleet_v1_fleet_proto_rawDesc = []byte{ 0x04, 0x52, 0x0a, 0x67, 0x65, 0x6e, 0x65, 0x72, 0x61, 0x74, 0x69, 0x6f, 0x6e, 0x12, 0x27, 0x0a, 0x0f, 0x72, 0x65, 0x71, 0x75, 0x69, 0x72, 0x65, 0x73, 0x5f, 0x72, 0x65, 0x62, 0x6f, 0x6f, 0x74, 0x18, 0x02, 0x20, 0x01, 0x28, 0x08, 0x52, 0x0e, 0x72, 0x65, 0x71, 0x75, 0x69, 0x72, 0x65, 0x73, - 0x52, 0x65, 0x62, 0x6f, 0x6f, 0x74, 0x2a, 0x52, 0x0a, 0x06, 0x48, 0x65, 0x61, 0x6c, 0x74, 0x68, - 0x12, 0x16, 0x0a, 0x12, 0x48, 0x45, 0x41, 0x4c, 0x54, 0x48, 0x5f, 0x55, 0x4e, 0x53, 0x50, 0x45, - 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, 0x12, 0x0d, 0x0a, 0x09, 0x48, 0x45, 0x41, 0x4c, - 0x54, 0x48, 0x5f, 0x55, 0x50, 0x10, 0x01, 0x12, 0x0f, 0x0a, 0x0b, 0x48, 0x45, 0x41, 0x4c, 0x54, - 0x48, 0x5f, 0x44, 0x4f, 0x57, 0x4e, 0x10, 0x02, 0x12, 0x10, 0x0a, 0x0c, 0x48, 0x45, 0x41, 0x4c, - 0x54, 0x48, 0x5f, 0x45, 0x52, 0x52, 0x4f, 0x52, 0x10, 0x03, 0x32, 0x95, 0x10, 0x0a, 0x0c, 0x46, - 0x6c, 0x65, 0x65, 0x74, 0x53, 0x65, 0x72, 0x76, 0x69, 0x63, 0x65, 0x12, 0x54, 0x0a, 0x09, 0x4c, - 0x69, 0x73, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x73, 0x12, 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, + 0x52, 0x65, 0x62, 0x6f, 0x6f, 0x74, 0x22, 0x51, 0x0a, 0x12, 0x45, 0x78, 0x70, 0x6f, 0x72, 0x74, + 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x12, 0x1b, 0x0a, 0x09, + 0x6e, 0x6f, 0x64, 0x65, 0x5f, 0x6e, 0x61, 0x6d, 0x65, 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, + 0x08, 0x6e, 0x6f, 0x64, 0x65, 0x4e, 0x61, 0x6d, 0x65, 0x12, 0x1e, 0x0a, 0x0a, 0x70, 0x61, 0x73, + 0x73, 0x70, 0x68, 0x72, 0x61, 0x73, 0x65, 0x18, 0x02, 0x20, 0x01, 0x28, 0x0c, 0x52, 0x0a, 0x70, + 0x61, 0x73, 0x73, 0x70, 0x68, 0x72, 0x61, 0x73, 0x65, 0x22, 0x31, 0x0a, 0x13, 0x45, 0x78, 0x70, + 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, + 0x12, 0x1a, 0x0a, 0x08, 0x65, 0x6e, 0x76, 0x65, 0x6c, 0x6f, 0x70, 0x65, 0x18, 0x01, 0x20, 0x01, + 0x28, 0x0c, 0x52, 0x08, 0x65, 0x6e, 0x76, 0x65, 0x6c, 0x6f, 0x70, 0x65, 0x22, 0x6d, 0x0a, 0x12, + 0x49, 0x6d, 0x70, 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x71, 0x75, 0x65, + 0x73, 0x74, 0x12, 0x1b, 0x0a, 0x09, 0x6e, 0x6f, 0x64, 0x65, 0x5f, 0x6e, 0x61, 0x6d, 0x65, 0x18, + 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x08, 0x6e, 0x6f, 0x64, 0x65, 0x4e, 0x61, 0x6d, 0x65, 0x12, + 0x1a, 0x0a, 0x08, 0x65, 0x6e, 0x76, 0x65, 0x6c, 0x6f, 0x70, 0x65, 0x18, 0x02, 0x20, 0x01, 0x28, + 0x0c, 0x52, 0x08, 0x65, 0x6e, 0x76, 0x65, 0x6c, 0x6f, 0x70, 0x65, 0x12, 0x1e, 0x0a, 0x0a, 0x70, + 0x61, 0x73, 0x73, 0x70, 0x68, 0x72, 0x61, 0x73, 0x65, 0x18, 0x03, 0x20, 0x01, 0x28, 0x0c, 0x52, + 0x0a, 0x70, 0x61, 0x73, 0x73, 0x70, 0x68, 0x72, 0x61, 0x73, 0x65, 0x22, 0x51, 0x0a, 0x13, 0x49, + 0x6d, 0x70, 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, + 0x73, 0x65, 0x12, 0x1d, 0x0a, 0x0a, 0x73, 0x75, 0x62, 0x6a, 0x65, 0x63, 0x74, 0x5f, 0x63, 0x6e, + 0x18, 0x01, 0x20, 0x01, 0x28, 0x09, 0x52, 0x09, 0x73, 0x75, 0x62, 0x6a, 0x65, 0x63, 0x74, 0x43, + 0x6e, 0x12, 0x1b, 0x0a, 0x09, 0x69, 0x73, 0x73, 0x75, 0x65, 0x72, 0x5f, 0x63, 0x6e, 0x18, 0x02, + 0x20, 0x01, 0x28, 0x09, 0x52, 0x08, 0x69, 0x73, 0x73, 0x75, 0x65, 0x72, 0x43, 0x6e, 0x2a, 0x52, + 0x0a, 0x06, 0x48, 0x65, 0x61, 0x6c, 0x74, 0x68, 0x12, 0x16, 0x0a, 0x12, 0x48, 0x45, 0x41, 0x4c, + 0x54, 0x48, 0x5f, 0x55, 0x4e, 0x53, 0x50, 0x45, 0x43, 0x49, 0x46, 0x49, 0x45, 0x44, 0x10, 0x00, + 0x12, 0x0d, 0x0a, 0x09, 0x48, 0x45, 0x41, 0x4c, 0x54, 0x48, 0x5f, 0x55, 0x50, 0x10, 0x01, 0x12, + 0x0f, 0x0a, 0x0b, 0x48, 0x45, 0x41, 0x4c, 0x54, 0x48, 0x5f, 0x44, 0x4f, 0x57, 0x4e, 0x10, 0x02, + 0x12, 0x10, 0x0a, 0x0c, 0x48, 0x45, 0x41, 0x4c, 0x54, 0x48, 0x5f, 0x45, 0x52, 0x52, 0x4f, 0x52, + 0x10, 0x03, 0x32, 0xcd, 0x11, 0x0a, 0x0c, 0x46, 0x6c, 0x65, 0x65, 0x74, 0x53, 0x65, 0x72, 0x76, + 0x69, 0x63, 0x65, 0x12, 0x54, 0x0a, 0x09, 0x4c, 0x69, 0x73, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x73, + 0x12, 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, + 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x73, 0x52, 0x65, 0x71, + 0x75, 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x4e, 0x6f, 0x64, 0x65, + 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x4e, 0x0a, 0x07, 0x47, 0x65, 0x74, + 0x4e, 0x6f, 0x64, 0x65, 0x12, 0x20, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x52, + 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x21, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, + 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, + 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x69, 0x0a, 0x10, 0x4c, 0x69, 0x73, + 0x74, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x73, 0x12, 0x29, 0x2e, + 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, + 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, + 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, - 0x4e, 0x6f, 0x64, 0x65, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, 0x63, - 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x4c, 0x69, 0x73, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, - 0x65, 0x12, 0x4e, 0x0a, 0x07, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x12, 0x20, 0x2e, 0x63, - 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x21, - 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, - 0x31, 0x2e, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, - 0x65, 0x12, 0x69, 0x0a, 0x10, 0x4c, 0x69, 0x73, 0x74, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, - 0x63, 0x61, 0x74, 0x65, 0x73, 0x12, 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, - 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x43, 0x65, 0x72, - 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, - 0x1a, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, - 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, - 0x61, 0x74, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x5d, 0x0a, 0x0c, - 0x4c, 0x69, 0x73, 0x74, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x73, 0x12, 0x25, 0x2e, 0x63, - 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x4c, 0x69, 0x73, 0x74, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x73, 0x52, 0x65, 0x71, 0x75, - 0x65, 0x73, 0x74, 0x1a, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, - 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x50, 0x72, 0x6f, 0x66, 0x69, - 0x6c, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x60, 0x0a, 0x0d, 0x43, - 0x72, 0x65, 0x61, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x12, 0x26, 0x2e, 0x63, - 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x71, - 0x75, 0x65, 0x73, 0x74, 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, + 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x5d, 0x0a, 0x0c, 0x4c, 0x69, 0x73, 0x74, 0x50, 0x72, 0x6f, 0x66, + 0x69, 0x6c, 0x65, 0x73, 0x12, 0x25, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x50, 0x72, 0x6f, 0x66, + 0x69, 0x6c, 0x65, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x26, 0x2e, 0x63, 0x72, + 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, + 0x69, 0x73, 0x74, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, + 0x6e, 0x73, 0x65, 0x12, 0x60, 0x0a, 0x0d, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x50, 0x72, 0x6f, + 0x66, 0x69, 0x6c, 0x65, 0x12, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x50, 0x72, - 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x60, 0x0a, - 0x0d, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x12, 0x26, + 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x27, 0x2e, 0x63, + 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, + 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x73, + 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x60, 0x0a, 0x0d, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x50, + 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x12, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, + 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, + 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, - 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, - 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x55, 0x70, 0x64, 0x61, 0x74, 0x65, - 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, - 0x60, 0x0a, 0x0d, 0x44, 0x65, 0x6c, 0x65, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, - 0x12, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, - 0x2e, 0x76, 0x31, 0x2e, 0x44, 0x65, 0x6c, 0x65, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, - 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, + 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x60, 0x0a, 0x0d, 0x44, 0x65, 0x6c, 0x65, 0x74, + 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x12, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x44, 0x65, 0x6c, 0x65, - 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, - 0x65, 0x12, 0x6f, 0x0a, 0x12, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, - 0x65, 0x54, 0x6f, 0x4e, 0x6f, 0x64, 0x65, 0x12, 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, - 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, - 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x54, 0x6f, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x71, - 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2c, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, - 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x50, 0x72, 0x6f, - 0x66, 0x69, 0x6c, 0x65, 0x54, 0x6f, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, - 0x73, 0x65, 0x12, 0x5d, 0x0a, 0x0c, 0x4c, 0x69, 0x73, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, - 0x72, 0x73, 0x12, 0x25, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, - 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, - 0x72, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, - 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, - 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, - 0x65, 0x12, 0x6c, 0x0a, 0x11, 0x53, 0x65, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x45, - 0x6e, 0x61, 0x62, 0x6c, 0x65, 0x64, 0x12, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, - 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x53, 0x65, 0x74, 0x41, 0x64, 0x61, - 0x70, 0x74, 0x65, 0x72, 0x45, 0x6e, 0x61, 0x62, 0x6c, 0x65, 0x64, 0x52, 0x65, 0x71, 0x75, 0x65, - 0x73, 0x74, 0x1a, 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, - 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x53, 0x65, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, - 0x45, 0x6e, 0x61, 0x62, 0x6c, 0x65, 0x64, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, - 0x54, 0x0a, 0x09, 0x4c, 0x69, 0x73, 0x74, 0x41, 0x75, 0x64, 0x69, 0x74, 0x12, 0x22, 0x2e, 0x63, + 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, + 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, + 0x2e, 0x76, 0x31, 0x2e, 0x44, 0x65, 0x6c, 0x65, 0x74, 0x65, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, + 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x6f, 0x0a, 0x12, 0x41, 0x70, 0x70, + 0x6c, 0x79, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x54, 0x6f, 0x4e, 0x6f, 0x64, 0x65, 0x12, + 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, + 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x54, + 0x6f, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2c, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x4c, 0x69, 0x73, 0x74, 0x41, 0x75, 0x64, 0x69, 0x74, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, - 0x1a, 0x23, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, - 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x41, 0x75, 0x64, 0x69, 0x74, 0x52, 0x65, 0x73, - 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x66, 0x0a, 0x0f, 0x4c, 0x69, 0x73, 0x74, 0x45, 0x6e, 0x72, - 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x12, 0x28, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, + 0x41, 0x70, 0x70, 0x6c, 0x79, 0x50, 0x72, 0x6f, 0x66, 0x69, 0x6c, 0x65, 0x54, 0x6f, 0x4e, 0x6f, + 0x64, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x5d, 0x0a, 0x0c, 0x4c, 0x69, + 0x73, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x73, 0x12, 0x25, 0x2e, 0x63, 0x72, 0x79, + 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, + 0x73, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, + 0x74, 0x1a, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, + 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, + 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x6c, 0x0a, 0x11, 0x53, 0x65, 0x74, + 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x45, 0x6e, 0x61, 0x62, 0x6c, 0x65, 0x64, 0x12, 0x2a, + 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, + 0x31, 0x2e, 0x53, 0x65, 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x45, 0x6e, 0x61, 0x62, + 0x6c, 0x65, 0x64, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2b, 0x2e, 0x63, 0x72, 0x79, + 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x53, 0x65, + 0x74, 0x41, 0x64, 0x61, 0x70, 0x74, 0x65, 0x72, 0x45, 0x6e, 0x61, 0x62, 0x6c, 0x65, 0x64, 0x52, + 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x54, 0x0a, 0x09, 0x4c, 0x69, 0x73, 0x74, 0x41, + 0x75, 0x64, 0x69, 0x74, 0x12, 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x41, 0x75, 0x64, 0x69, + 0x74, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, - 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, - 0x73, 0x74, 0x1a, 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, - 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, - 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x69, 0x0a, - 0x10, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, - 0x74, 0x12, 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, - 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, - 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2a, 0x2e, 0x63, - 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, - 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x6c, 0x0a, 0x11, 0x41, 0x70, 0x70, 0x72, - 0x6f, 0x76, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x12, 0x2a, 0x2e, - 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, - 0x2e, 0x41, 0x70, 0x70, 0x72, 0x6f, 0x76, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, - 0x6e, 0x74, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, - 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, - 0x72, 0x6f, 0x76, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, - 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x69, 0x0a, 0x10, 0x52, 0x65, 0x6a, 0x65, 0x63, 0x74, - 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x12, 0x29, 0x2e, 0x63, 0x72, 0x79, - 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, - 0x6a, 0x65, 0x63, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, - 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, - 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, 0x6a, 0x65, 0x63, 0x74, 0x45, - 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, - 0x65, 0x12, 0x4b, 0x0a, 0x06, 0x57, 0x68, 0x6f, 0x41, 0x6d, 0x49, 0x12, 0x1f, 0x2e, 0x63, 0x72, - 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x57, - 0x68, 0x6f, 0x41, 0x6d, 0x49, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x20, 0x2e, 0x63, - 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, - 0x57, 0x68, 0x6f, 0x41, 0x6d, 0x49, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x6c, - 0x0a, 0x11, 0x52, 0x65, 0x76, 0x6f, 0x6b, 0x65, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, - 0x61, 0x74, 0x65, 0x12, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, - 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, 0x76, 0x6f, 0x6b, 0x65, 0x43, 0x65, 0x72, - 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, - 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, - 0x76, 0x31, 0x2e, 0x52, 0x65, 0x76, 0x6f, 0x6b, 0x65, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, - 0x63, 0x61, 0x74, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x54, 0x0a, 0x09, - 0x49, 0x73, 0x73, 0x75, 0x65, 0x4c, 0x65, 0x61, 0x66, 0x12, 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, - 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x49, 0x73, 0x73, - 0x75, 0x65, 0x4c, 0x65, 0x61, 0x66, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, + 0x41, 0x75, 0x64, 0x69, 0x74, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x66, 0x0a, + 0x0f, 0x4c, 0x69, 0x73, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x73, + 0x12, 0x28, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, + 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, 0x73, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, + 0x6e, 0x74, 0x73, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x29, 0x2e, 0x63, 0x72, 0x79, + 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x4c, 0x69, + 0x73, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x73, 0x52, 0x65, 0x73, + 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x69, 0x0a, 0x10, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x45, + 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x12, 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, + 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x43, 0x72, 0x65, + 0x61, 0x74, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x71, + 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x43, 0x72, 0x65, 0x61, 0x74, 0x65, 0x45, 0x6e, + 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, + 0x12, 0x6c, 0x0a, 0x11, 0x41, 0x70, 0x70, 0x72, 0x6f, 0x76, 0x65, 0x45, 0x6e, 0x72, 0x6f, 0x6c, + 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x12, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, + 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x72, 0x6f, 0x76, 0x65, + 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, + 0x74, 0x1a, 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, + 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x72, 0x6f, 0x76, 0x65, 0x45, 0x6e, 0x72, 0x6f, + 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x69, + 0x0a, 0x10, 0x52, 0x65, 0x6a, 0x65, 0x63, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, + 0x6e, 0x74, 0x12, 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, + 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, 0x6a, 0x65, 0x63, 0x74, 0x45, 0x6e, 0x72, 0x6f, + 0x6c, 0x6c, 0x6d, 0x65, 0x6e, 0x74, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2a, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, - 0x2e, 0x49, 0x73, 0x73, 0x75, 0x65, 0x4c, 0x65, 0x61, 0x66, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, - 0x73, 0x65, 0x12, 0x54, 0x0a, 0x09, 0x52, 0x65, 0x6b, 0x65, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x12, - 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, - 0x76, 0x31, 0x2e, 0x52, 0x65, 0x6b, 0x65, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, - 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, - 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, 0x6b, 0x65, 0x79, 0x4e, 0x6f, 0x64, 0x65, - 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x60, 0x0a, 0x0d, 0x47, 0x65, 0x74, 0x4e, - 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x12, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, - 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x47, 0x65, 0x74, - 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, - 0x74, 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, + 0x2e, 0x52, 0x65, 0x6a, 0x65, 0x63, 0x74, 0x45, 0x6e, 0x72, 0x6f, 0x6c, 0x6c, 0x6d, 0x65, 0x6e, + 0x74, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x4b, 0x0a, 0x06, 0x57, 0x68, 0x6f, + 0x41, 0x6d, 0x49, 0x12, 0x1f, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, + 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x57, 0x68, 0x6f, 0x41, 0x6d, 0x49, 0x52, 0x65, 0x71, + 0x75, 0x65, 0x73, 0x74, 0x1a, 0x20, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, + 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x57, 0x68, 0x6f, 0x41, 0x6d, 0x49, 0x52, 0x65, + 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x6c, 0x0a, 0x11, 0x52, 0x65, 0x76, 0x6f, 0x6b, 0x65, + 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x12, 0x2a, 0x2e, 0x63, 0x72, + 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, + 0x65, 0x76, 0x6f, 0x6b, 0x65, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, + 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x2b, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, + 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, 0x76, 0x6f, 0x6b, + 0x65, 0x43, 0x65, 0x72, 0x74, 0x69, 0x66, 0x69, 0x63, 0x61, 0x74, 0x65, 0x52, 0x65, 0x73, 0x70, + 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x54, 0x0a, 0x09, 0x49, 0x73, 0x73, 0x75, 0x65, 0x4c, 0x65, 0x61, + 0x66, 0x12, 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, + 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x49, 0x73, 0x73, 0x75, 0x65, 0x4c, 0x65, 0x61, 0x66, 0x52, 0x65, + 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, + 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x49, 0x73, 0x73, 0x75, 0x65, 0x4c, 0x65, + 0x61, 0x66, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x54, 0x0a, 0x09, 0x52, 0x65, + 0x6b, 0x65, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x12, 0x22, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, + 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, 0x65, 0x6b, 0x65, 0x79, + 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x23, 0x2e, 0x63, 0x72, + 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x52, + 0x65, 0x6b, 0x65, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, + 0x12, 0x60, 0x0a, 0x0d, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, + 0x67, 0x12, 0x26, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, - 0x69, 0x67, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x66, 0x0a, 0x0f, 0x41, 0x70, - 0x70, 0x6c, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x12, 0x28, 0x2e, - 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, - 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, - 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, - 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, + 0x69, 0x67, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x27, 0x2e, 0x63, 0x72, 0x79, 0x70, + 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x47, 0x65, 0x74, 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, + 0x73, 0x65, 0x12, 0x66, 0x0a, 0x0f, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x43, + 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x12, 0x28, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, + 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x4e, 0x6f, + 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, 0x69, 0x67, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, + 0x29, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, + 0x76, 0x31, 0x2e, 0x41, 0x70, 0x70, 0x6c, 0x79, 0x4e, 0x6f, 0x64, 0x65, 0x43, 0x6f, 0x6e, 0x66, + 0x69, 0x67, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x5a, 0x0a, 0x0b, 0x45, 0x78, + 0x70, 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x12, 0x24, 0x2e, 0x63, 0x72, 0x79, 0x70, + 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x45, 0x78, 0x70, + 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, + 0x25, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, + 0x76, 0x31, 0x2e, 0x45, 0x78, 0x70, 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, + 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x12, 0x5a, 0x0a, 0x0b, 0x49, 0x6d, 0x70, 0x6f, 0x72, 0x74, + 0x43, 0x41, 0x4b, 0x65, 0x79, 0x12, 0x24, 0x2e, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, + 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x49, 0x6d, 0x70, 0x6f, 0x72, 0x74, 0x43, + 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x71, 0x75, 0x65, 0x73, 0x74, 0x1a, 0x25, 0x2e, 0x63, 0x72, + 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2e, 0x66, 0x6c, 0x65, 0x65, 0x74, 0x2e, 0x76, 0x31, 0x2e, 0x49, + 0x6d, 0x70, 0x6f, 0x72, 0x74, 0x43, 0x41, 0x4b, 0x65, 0x79, 0x52, 0x65, 0x73, 0x70, 0x6f, 0x6e, 0x73, 0x65, 0x42, 0x38, 0x5a, 0x36, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f, 0x6d, 0x2f, 0x43, 0x72, 0x79, 0x70, 0x74, 0x4f, 0x53, 0x2d, 0x50, 0x4b, 0x49, 0x2f, 0x61, 0x70, 0x69, 0x2f, 0x67, 0x6f, 0x2f, 0x63, 0x72, 0x79, 0x70, 0x74, 0x6f, 0x73, 0x2f, 0x66, 0x6c, 0x65, 0x65, @@ -3503,7 +3773,7 @@ func file_cryptos_fleet_v1_fleet_proto_rawDescGZIP() []byte { } var file_cryptos_fleet_v1_fleet_proto_enumTypes = make([]protoimpl.EnumInfo, 1) -var file_cryptos_fleet_v1_fleet_proto_msgTypes = make([]protoimpl.MessageInfo, 50) +var file_cryptos_fleet_v1_fleet_proto_msgTypes = make([]protoimpl.MessageInfo, 54) var file_cryptos_fleet_v1_fleet_proto_goTypes = []any{ (Health)(0), // 0: cryptos.fleet.v1.Health (*ListNodesRequest)(nil), // 1: cryptos.fleet.v1.ListNodesRequest @@ -3556,16 +3826,20 @@ var file_cryptos_fleet_v1_fleet_proto_goTypes = []any{ (*GetNodeConfigResponse)(nil), // 48: cryptos.fleet.v1.GetNodeConfigResponse (*ApplyNodeConfigRequest)(nil), // 49: cryptos.fleet.v1.ApplyNodeConfigRequest (*ApplyNodeConfigResponse)(nil), // 50: cryptos.fleet.v1.ApplyNodeConfigResponse - (*v1.CertificateProfile)(nil), // 51: cryptos.v1.CertificateProfile - (*v1.MachineConfig)(nil), // 52: cryptos.v1.MachineConfig + (*ExportCAKeyRequest)(nil), // 51: cryptos.fleet.v1.ExportCAKeyRequest + (*ExportCAKeyResponse)(nil), // 52: cryptos.fleet.v1.ExportCAKeyResponse + (*ImportCAKeyRequest)(nil), // 53: cryptos.fleet.v1.ImportCAKeyRequest + (*ImportCAKeyResponse)(nil), // 54: cryptos.fleet.v1.ImportCAKeyResponse + (*v1.CertificateProfile)(nil), // 55: cryptos.v1.CertificateProfile + (*v1.MachineConfig)(nil), // 56: cryptos.v1.MachineConfig } var file_cryptos_fleet_v1_fleet_proto_depIdxs = []int32{ 25, // 0: cryptos.fleet.v1.ListNodesResponse.nodes:type_name -> cryptos.fleet.v1.NodeSummary 27, // 1: cryptos.fleet.v1.GetNodeResponse.node:type_name -> cryptos.fleet.v1.NodeDetail 28, // 2: cryptos.fleet.v1.ListCertificatesResponse.certificates:type_name -> cryptos.fleet.v1.Certificate - 51, // 3: cryptos.fleet.v1.ListProfilesResponse.items:type_name -> cryptos.v1.CertificateProfile - 51, // 4: cryptos.fleet.v1.CreateProfileRequest.profile:type_name -> cryptos.v1.CertificateProfile - 51, // 5: cryptos.fleet.v1.UpdateProfileRequest.profile:type_name -> cryptos.v1.CertificateProfile + 55, // 3: cryptos.fleet.v1.ListProfilesResponse.items:type_name -> cryptos.v1.CertificateProfile + 55, // 4: cryptos.fleet.v1.CreateProfileRequest.profile:type_name -> cryptos.v1.CertificateProfile + 55, // 5: cryptos.fleet.v1.UpdateProfileRequest.profile:type_name -> cryptos.v1.CertificateProfile 29, // 6: cryptos.fleet.v1.ListAdaptersResponse.items:type_name -> cryptos.fleet.v1.EnrollmentAdapter 29, // 7: cryptos.fleet.v1.SetAdapterEnabledResponse.adapter:type_name -> cryptos.fleet.v1.EnrollmentAdapter 30, // 8: cryptos.fleet.v1.ListAuditResponse.items:type_name -> cryptos.fleet.v1.AuditEvent @@ -3577,8 +3851,8 @@ var file_cryptos_fleet_v1_fleet_proto_depIdxs = []int32{ 31, // 14: cryptos.fleet.v1.ApproveEnrollmentResponse.enrollment:type_name -> cryptos.fleet.v1.EnrollmentRequest 31, // 15: cryptos.fleet.v1.RejectEnrollmentResponse.enrollment:type_name -> cryptos.fleet.v1.EnrollmentRequest 39, // 16: cryptos.fleet.v1.WhoAmIResponse.operator:type_name -> cryptos.fleet.v1.OperatorIdentity - 52, // 17: cryptos.fleet.v1.GetNodeConfigResponse.config:type_name -> cryptos.v1.MachineConfig - 52, // 18: cryptos.fleet.v1.ApplyNodeConfigRequest.config:type_name -> cryptos.v1.MachineConfig + 56, // 17: cryptos.fleet.v1.GetNodeConfigResponse.config:type_name -> cryptos.v1.MachineConfig + 56, // 18: cryptos.fleet.v1.ApplyNodeConfigRequest.config:type_name -> cryptos.v1.MachineConfig 1, // 19: cryptos.fleet.v1.FleetService.ListNodes:input_type -> cryptos.fleet.v1.ListNodesRequest 3, // 20: cryptos.fleet.v1.FleetService.GetNode:input_type -> cryptos.fleet.v1.GetNodeRequest 5, // 21: cryptos.fleet.v1.FleetService.ListCertificates:input_type -> cryptos.fleet.v1.ListCertificatesRequest @@ -3600,29 +3874,33 @@ var file_cryptos_fleet_v1_fleet_proto_depIdxs = []int32{ 45, // 37: cryptos.fleet.v1.FleetService.RekeyNode:input_type -> cryptos.fleet.v1.RekeyNodeRequest 47, // 38: cryptos.fleet.v1.FleetService.GetNodeConfig:input_type -> cryptos.fleet.v1.GetNodeConfigRequest 49, // 39: cryptos.fleet.v1.FleetService.ApplyNodeConfig:input_type -> cryptos.fleet.v1.ApplyNodeConfigRequest - 2, // 40: cryptos.fleet.v1.FleetService.ListNodes:output_type -> cryptos.fleet.v1.ListNodesResponse - 4, // 41: cryptos.fleet.v1.FleetService.GetNode:output_type -> cryptos.fleet.v1.GetNodeResponse - 6, // 42: cryptos.fleet.v1.FleetService.ListCertificates:output_type -> cryptos.fleet.v1.ListCertificatesResponse - 8, // 43: cryptos.fleet.v1.FleetService.ListProfiles:output_type -> cryptos.fleet.v1.ListProfilesResponse - 10, // 44: cryptos.fleet.v1.FleetService.CreateProfile:output_type -> cryptos.fleet.v1.CreateProfileResponse - 12, // 45: cryptos.fleet.v1.FleetService.UpdateProfile:output_type -> cryptos.fleet.v1.UpdateProfileResponse - 14, // 46: cryptos.fleet.v1.FleetService.DeleteProfile:output_type -> cryptos.fleet.v1.DeleteProfileResponse - 16, // 47: cryptos.fleet.v1.FleetService.ApplyProfileToNode:output_type -> cryptos.fleet.v1.ApplyProfileToNodeResponse - 18, // 48: cryptos.fleet.v1.FleetService.ListAdapters:output_type -> cryptos.fleet.v1.ListAdaptersResponse - 20, // 49: cryptos.fleet.v1.FleetService.SetAdapterEnabled:output_type -> cryptos.fleet.v1.SetAdapterEnabledResponse - 22, // 50: cryptos.fleet.v1.FleetService.ListAudit:output_type -> cryptos.fleet.v1.ListAuditResponse - 24, // 51: cryptos.fleet.v1.FleetService.ListEnrollments:output_type -> cryptos.fleet.v1.ListEnrollmentsResponse - 33, // 52: cryptos.fleet.v1.FleetService.CreateEnrollment:output_type -> cryptos.fleet.v1.CreateEnrollmentResponse - 35, // 53: cryptos.fleet.v1.FleetService.ApproveEnrollment:output_type -> cryptos.fleet.v1.ApproveEnrollmentResponse - 37, // 54: cryptos.fleet.v1.FleetService.RejectEnrollment:output_type -> cryptos.fleet.v1.RejectEnrollmentResponse - 40, // 55: cryptos.fleet.v1.FleetService.WhoAmI:output_type -> cryptos.fleet.v1.WhoAmIResponse - 42, // 56: cryptos.fleet.v1.FleetService.RevokeCertificate:output_type -> cryptos.fleet.v1.RevokeCertificateResponse - 44, // 57: cryptos.fleet.v1.FleetService.IssueLeaf:output_type -> cryptos.fleet.v1.IssueLeafResponse - 46, // 58: cryptos.fleet.v1.FleetService.RekeyNode:output_type -> cryptos.fleet.v1.RekeyNodeResponse - 48, // 59: cryptos.fleet.v1.FleetService.GetNodeConfig:output_type -> cryptos.fleet.v1.GetNodeConfigResponse - 50, // 60: cryptos.fleet.v1.FleetService.ApplyNodeConfig:output_type -> cryptos.fleet.v1.ApplyNodeConfigResponse - 40, // [40:61] is the sub-list for method output_type - 19, // [19:40] is the sub-list for method input_type + 51, // 40: cryptos.fleet.v1.FleetService.ExportCAKey:input_type -> cryptos.fleet.v1.ExportCAKeyRequest + 53, // 41: cryptos.fleet.v1.FleetService.ImportCAKey:input_type -> cryptos.fleet.v1.ImportCAKeyRequest + 2, // 42: cryptos.fleet.v1.FleetService.ListNodes:output_type -> cryptos.fleet.v1.ListNodesResponse + 4, // 43: cryptos.fleet.v1.FleetService.GetNode:output_type -> cryptos.fleet.v1.GetNodeResponse + 6, // 44: cryptos.fleet.v1.FleetService.ListCertificates:output_type -> cryptos.fleet.v1.ListCertificatesResponse + 8, // 45: cryptos.fleet.v1.FleetService.ListProfiles:output_type -> cryptos.fleet.v1.ListProfilesResponse + 10, // 46: cryptos.fleet.v1.FleetService.CreateProfile:output_type -> cryptos.fleet.v1.CreateProfileResponse + 12, // 47: cryptos.fleet.v1.FleetService.UpdateProfile:output_type -> cryptos.fleet.v1.UpdateProfileResponse + 14, // 48: cryptos.fleet.v1.FleetService.DeleteProfile:output_type -> cryptos.fleet.v1.DeleteProfileResponse + 16, // 49: cryptos.fleet.v1.FleetService.ApplyProfileToNode:output_type -> cryptos.fleet.v1.ApplyProfileToNodeResponse + 18, // 50: cryptos.fleet.v1.FleetService.ListAdapters:output_type -> cryptos.fleet.v1.ListAdaptersResponse + 20, // 51: cryptos.fleet.v1.FleetService.SetAdapterEnabled:output_type -> cryptos.fleet.v1.SetAdapterEnabledResponse + 22, // 52: cryptos.fleet.v1.FleetService.ListAudit:output_type -> cryptos.fleet.v1.ListAuditResponse + 24, // 53: cryptos.fleet.v1.FleetService.ListEnrollments:output_type -> cryptos.fleet.v1.ListEnrollmentsResponse + 33, // 54: cryptos.fleet.v1.FleetService.CreateEnrollment:output_type -> cryptos.fleet.v1.CreateEnrollmentResponse + 35, // 55: cryptos.fleet.v1.FleetService.ApproveEnrollment:output_type -> cryptos.fleet.v1.ApproveEnrollmentResponse + 37, // 56: cryptos.fleet.v1.FleetService.RejectEnrollment:output_type -> cryptos.fleet.v1.RejectEnrollmentResponse + 40, // 57: cryptos.fleet.v1.FleetService.WhoAmI:output_type -> cryptos.fleet.v1.WhoAmIResponse + 42, // 58: cryptos.fleet.v1.FleetService.RevokeCertificate:output_type -> cryptos.fleet.v1.RevokeCertificateResponse + 44, // 59: cryptos.fleet.v1.FleetService.IssueLeaf:output_type -> cryptos.fleet.v1.IssueLeafResponse + 46, // 60: cryptos.fleet.v1.FleetService.RekeyNode:output_type -> cryptos.fleet.v1.RekeyNodeResponse + 48, // 61: cryptos.fleet.v1.FleetService.GetNodeConfig:output_type -> cryptos.fleet.v1.GetNodeConfigResponse + 50, // 62: cryptos.fleet.v1.FleetService.ApplyNodeConfig:output_type -> cryptos.fleet.v1.ApplyNodeConfigResponse + 52, // 63: cryptos.fleet.v1.FleetService.ExportCAKey:output_type -> cryptos.fleet.v1.ExportCAKeyResponse + 54, // 64: cryptos.fleet.v1.FleetService.ImportCAKey:output_type -> cryptos.fleet.v1.ImportCAKeyResponse + 42, // [42:65] is the sub-list for method output_type + 19, // [19:42] is the sub-list for method input_type 19, // [19:19] is the sub-list for extension type_name 19, // [19:19] is the sub-list for extension extendee 0, // [0:19] is the sub-list for field type_name @@ -4234,6 +4512,54 @@ func file_cryptos_fleet_v1_fleet_proto_init() { return nil } } + file_cryptos_fleet_v1_fleet_proto_msgTypes[50].Exporter = func(v any, i int) any { + switch v := v.(*ExportCAKeyRequest); i { + case 0: + return &v.state + case 1: + return &v.sizeCache + case 2: + return &v.unknownFields + default: + return nil + } + } + file_cryptos_fleet_v1_fleet_proto_msgTypes[51].Exporter = func(v any, i int) any { + switch v := v.(*ExportCAKeyResponse); i { + case 0: + return &v.state + case 1: + return &v.sizeCache + case 2: + return &v.unknownFields + default: + return nil + } + } + file_cryptos_fleet_v1_fleet_proto_msgTypes[52].Exporter = func(v any, i int) any { + switch v := v.(*ImportCAKeyRequest); i { + case 0: + return &v.state + case 1: + return &v.sizeCache + case 2: + return &v.unknownFields + default: + return nil + } + } + file_cryptos_fleet_v1_fleet_proto_msgTypes[53].Exporter = func(v any, i int) any { + switch v := v.(*ImportCAKeyResponse); i { + case 0: + return &v.state + case 1: + return &v.sizeCache + case 2: + return &v.unknownFields + default: + return nil + } + } } type x struct{} out := protoimpl.TypeBuilder{ @@ -4241,7 +4567,7 @@ func file_cryptos_fleet_v1_fleet_proto_init() { GoPackagePath: reflect.TypeOf(x{}).PkgPath(), RawDescriptor: file_cryptos_fleet_v1_fleet_proto_rawDesc, NumEnums: 1, - NumMessages: 50, + NumMessages: 54, NumExtensions: 0, NumServices: 1, }, diff --git a/go/cryptos/fleet/v1/fleet_grpc.pb.go b/go/cryptos/fleet/v1/fleet_grpc.pb.go index fccea33..b72e961 100644 --- a/go/cryptos/fleet/v1/fleet_grpc.pb.go +++ b/go/cryptos/fleet/v1/fleet_grpc.pb.go @@ -40,6 +40,8 @@ const ( FleetService_RekeyNode_FullMethodName = "/cryptos.fleet.v1.FleetService/RekeyNode" FleetService_GetNodeConfig_FullMethodName = "/cryptos.fleet.v1.FleetService/GetNodeConfig" FleetService_ApplyNodeConfig_FullMethodName = "/cryptos.fleet.v1.FleetService/ApplyNodeConfig" + FleetService_ExportCAKey_FullMethodName = "/cryptos.fleet.v1.FleetService/ExportCAKey" + FleetService_ImportCAKey_FullMethodName = "/cryptos.fleet.v1.FleetService/ImportCAKey" ) // FleetServiceClient is the client API for FleetService service. @@ -123,6 +125,20 @@ type FleetServiceClient interface { // node's ApplyConfig is a whole-config replace, so the caller must send the // complete config, never a partial one. Admin-gated and audited. ApplyNodeConfig(ctx context.Context, in *ApplyNodeConfigRequest, opts ...grpc.CallOption) (*ApplyNodeConfigResponse, error) + // ExportCAKey backs up a managed node's CA private key to an encrypted + // envelope. The node seals the backup with the operator passphrase + // (Argon2id + AES-256-GCM) so the plaintext key never leaves the node; the + // manager only relays the envelope through to the caller. The passphrase is + // used in transit and is never persisted. A TPM-backed node refuses export. + // Admin-gated and audited (the audit names the node only, never the secret). + ExportCAKey(ctx context.Context, in *ExportCAKeyRequest, opts ...grpc.CallOption) (*ExportCAKeyResponse, error) + // ImportCAKey restores a CA identity onto a fresh managed node from an + // encrypted envelope produced by ExportCAKey. The node decrypts the envelope + // with the operator passphrase and adopts the key; it refuses the import if + // it already holds an identity. The passphrase transits the manager only to + // reach the node and is never persisted. Admin-gated and audited (the audit + // names the node and restored subject only, never the secret or envelope). + ImportCAKey(ctx context.Context, in *ImportCAKeyRequest, opts ...grpc.CallOption) (*ImportCAKeyResponse, error) } type fleetServiceClient struct { @@ -343,6 +359,26 @@ func (c *fleetServiceClient) ApplyNodeConfig(ctx context.Context, in *ApplyNodeC return out, nil } +func (c *fleetServiceClient) ExportCAKey(ctx context.Context, in *ExportCAKeyRequest, opts ...grpc.CallOption) (*ExportCAKeyResponse, error) { + cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...) + out := new(ExportCAKeyResponse) + err := c.cc.Invoke(ctx, FleetService_ExportCAKey_FullMethodName, in, out, cOpts...) + if err != nil { + return nil, err + } + return out, nil +} + +func (c *fleetServiceClient) ImportCAKey(ctx context.Context, in *ImportCAKeyRequest, opts ...grpc.CallOption) (*ImportCAKeyResponse, error) { + cOpts := append([]grpc.CallOption{grpc.StaticMethod()}, opts...) + out := new(ImportCAKeyResponse) + err := c.cc.Invoke(ctx, FleetService_ImportCAKey_FullMethodName, in, out, cOpts...) + if err != nil { + return nil, err + } + return out, nil +} + // FleetServiceServer is the server API for FleetService service. // All implementations should embed UnimplementedFleetServiceServer // for forward compatibility. @@ -424,6 +460,20 @@ type FleetServiceServer interface { // node's ApplyConfig is a whole-config replace, so the caller must send the // complete config, never a partial one. Admin-gated and audited. ApplyNodeConfig(context.Context, *ApplyNodeConfigRequest) (*ApplyNodeConfigResponse, error) + // ExportCAKey backs up a managed node's CA private key to an encrypted + // envelope. The node seals the backup with the operator passphrase + // (Argon2id + AES-256-GCM) so the plaintext key never leaves the node; the + // manager only relays the envelope through to the caller. The passphrase is + // used in transit and is never persisted. A TPM-backed node refuses export. + // Admin-gated and audited (the audit names the node only, never the secret). + ExportCAKey(context.Context, *ExportCAKeyRequest) (*ExportCAKeyResponse, error) + // ImportCAKey restores a CA identity onto a fresh managed node from an + // encrypted envelope produced by ExportCAKey. The node decrypts the envelope + // with the operator passphrase and adopts the key; it refuses the import if + // it already holds an identity. The passphrase transits the manager only to + // reach the node and is never persisted. Admin-gated and audited (the audit + // names the node and restored subject only, never the secret or envelope). + ImportCAKey(context.Context, *ImportCAKeyRequest) (*ImportCAKeyResponse, error) } // UnimplementedFleetServiceServer should be embedded to have @@ -496,6 +546,12 @@ func (UnimplementedFleetServiceServer) GetNodeConfig(context.Context, *GetNodeCo func (UnimplementedFleetServiceServer) ApplyNodeConfig(context.Context, *ApplyNodeConfigRequest) (*ApplyNodeConfigResponse, error) { return nil, status.Errorf(codes.Unimplemented, "method ApplyNodeConfig not implemented") } +func (UnimplementedFleetServiceServer) ExportCAKey(context.Context, *ExportCAKeyRequest) (*ExportCAKeyResponse, error) { + return nil, status.Errorf(codes.Unimplemented, "method ExportCAKey not implemented") +} +func (UnimplementedFleetServiceServer) ImportCAKey(context.Context, *ImportCAKeyRequest) (*ImportCAKeyResponse, error) { + return nil, status.Errorf(codes.Unimplemented, "method ImportCAKey not implemented") +} func (UnimplementedFleetServiceServer) testEmbeddedByValue() {} // UnsafeFleetServiceServer may be embedded to opt out of forward compatibility for this service. @@ -894,6 +950,42 @@ func _FleetService_ApplyNodeConfig_Handler(srv interface{}, ctx context.Context, return interceptor(ctx, in, info, handler) } +func _FleetService_ExportCAKey_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) { + in := new(ExportCAKeyRequest) + if err := dec(in); err != nil { + return nil, err + } + if interceptor == nil { + return srv.(FleetServiceServer).ExportCAKey(ctx, in) + } + info := &grpc.UnaryServerInfo{ + Server: srv, + FullMethod: FleetService_ExportCAKey_FullMethodName, + } + handler := func(ctx context.Context, req interface{}) (interface{}, error) { + return srv.(FleetServiceServer).ExportCAKey(ctx, req.(*ExportCAKeyRequest)) + } + return interceptor(ctx, in, info, handler) +} + +func _FleetService_ImportCAKey_Handler(srv interface{}, ctx context.Context, dec func(interface{}) error, interceptor grpc.UnaryServerInterceptor) (interface{}, error) { + in := new(ImportCAKeyRequest) + if err := dec(in); err != nil { + return nil, err + } + if interceptor == nil { + return srv.(FleetServiceServer).ImportCAKey(ctx, in) + } + info := &grpc.UnaryServerInfo{ + Server: srv, + FullMethod: FleetService_ImportCAKey_FullMethodName, + } + handler := func(ctx context.Context, req interface{}) (interface{}, error) { + return srv.(FleetServiceServer).ImportCAKey(ctx, req.(*ImportCAKeyRequest)) + } + return interceptor(ctx, in, info, handler) +} + // FleetService_ServiceDesc is the grpc.ServiceDesc for FleetService service. // It's only intended for direct use with grpc.RegisterService, // and not to be introspected or modified (even as a copy) @@ -985,6 +1077,14 @@ var FleetService_ServiceDesc = grpc.ServiceDesc{ MethodName: "ApplyNodeConfig", Handler: _FleetService_ApplyNodeConfig_Handler, }, + { + MethodName: "ExportCAKey", + Handler: _FleetService_ExportCAKey_Handler, + }, + { + MethodName: "ImportCAKey", + Handler: _FleetService_ImportCAKey_Handler, + }, }, Streams: []grpc.StreamDesc{}, Metadata: "cryptos/fleet/v1/fleet.proto", diff --git a/go/cryptos/fleet/v1/fleetv1connect/fleet.connect.go b/go/cryptos/fleet/v1/fleetv1connect/fleet.connect.go index ba8217b..13eb3ef 100644 --- a/go/cryptos/fleet/v1/fleetv1connect/fleet.connect.go +++ b/go/cryptos/fleet/v1/fleetv1connect/fleet.connect.go @@ -90,6 +90,12 @@ const ( // FleetServiceApplyNodeConfigProcedure is the fully-qualified name of the FleetService's // ApplyNodeConfig RPC. FleetServiceApplyNodeConfigProcedure = "/cryptos.fleet.v1.FleetService/ApplyNodeConfig" + // FleetServiceExportCAKeyProcedure is the fully-qualified name of the FleetService's ExportCAKey + // RPC. + FleetServiceExportCAKeyProcedure = "/cryptos.fleet.v1.FleetService/ExportCAKey" + // FleetServiceImportCAKeyProcedure is the fully-qualified name of the FleetService's ImportCAKey + // RPC. + FleetServiceImportCAKeyProcedure = "/cryptos.fleet.v1.FleetService/ImportCAKey" ) // FleetServiceClient is a client for the cryptos.fleet.v1.FleetService service. @@ -166,6 +172,20 @@ type FleetServiceClient interface { // node's ApplyConfig is a whole-config replace, so the caller must send the // complete config, never a partial one. Admin-gated and audited. ApplyNodeConfig(context.Context, *connect.Request[v1.ApplyNodeConfigRequest]) (*connect.Response[v1.ApplyNodeConfigResponse], error) + // ExportCAKey backs up a managed node's CA private key to an encrypted + // envelope. The node seals the backup with the operator passphrase + // (Argon2id + AES-256-GCM) so the plaintext key never leaves the node; the + // manager only relays the envelope through to the caller. The passphrase is + // used in transit and is never persisted. A TPM-backed node refuses export. + // Admin-gated and audited (the audit names the node only, never the secret). + ExportCAKey(context.Context, *connect.Request[v1.ExportCAKeyRequest]) (*connect.Response[v1.ExportCAKeyResponse], error) + // ImportCAKey restores a CA identity onto a fresh managed node from an + // encrypted envelope produced by ExportCAKey. The node decrypts the envelope + // with the operator passphrase and adopts the key; it refuses the import if + // it already holds an identity. The passphrase transits the manager only to + // reach the node and is never persisted. Admin-gated and audited (the audit + // names the node and restored subject only, never the secret or envelope). + ImportCAKey(context.Context, *connect.Request[v1.ImportCAKeyRequest]) (*connect.Response[v1.ImportCAKeyResponse], error) } // NewFleetServiceClient constructs a client for the cryptos.fleet.v1.FleetService service. By @@ -305,6 +325,18 @@ func NewFleetServiceClient(httpClient connect.HTTPClient, baseURL string, opts . connect.WithSchema(fleetServiceMethods.ByName("ApplyNodeConfig")), connect.WithClientOptions(opts...), ), + exportCAKey: connect.NewClient[v1.ExportCAKeyRequest, v1.ExportCAKeyResponse]( + httpClient, + baseURL+FleetServiceExportCAKeyProcedure, + connect.WithSchema(fleetServiceMethods.ByName("ExportCAKey")), + connect.WithClientOptions(opts...), + ), + importCAKey: connect.NewClient[v1.ImportCAKeyRequest, v1.ImportCAKeyResponse]( + httpClient, + baseURL+FleetServiceImportCAKeyProcedure, + connect.WithSchema(fleetServiceMethods.ByName("ImportCAKey")), + connect.WithClientOptions(opts...), + ), } } @@ -331,6 +363,8 @@ type fleetServiceClient struct { rekeyNode *connect.Client[v1.RekeyNodeRequest, v1.RekeyNodeResponse] getNodeConfig *connect.Client[v1.GetNodeConfigRequest, v1.GetNodeConfigResponse] applyNodeConfig *connect.Client[v1.ApplyNodeConfigRequest, v1.ApplyNodeConfigResponse] + exportCAKey *connect.Client[v1.ExportCAKeyRequest, v1.ExportCAKeyResponse] + importCAKey *connect.Client[v1.ImportCAKeyRequest, v1.ImportCAKeyResponse] } // ListNodes calls cryptos.fleet.v1.FleetService.ListNodes. @@ -438,6 +472,16 @@ func (c *fleetServiceClient) ApplyNodeConfig(ctx context.Context, req *connect.R return c.applyNodeConfig.CallUnary(ctx, req) } +// ExportCAKey calls cryptos.fleet.v1.FleetService.ExportCAKey. +func (c *fleetServiceClient) ExportCAKey(ctx context.Context, req *connect.Request[v1.ExportCAKeyRequest]) (*connect.Response[v1.ExportCAKeyResponse], error) { + return c.exportCAKey.CallUnary(ctx, req) +} + +// ImportCAKey calls cryptos.fleet.v1.FleetService.ImportCAKey. +func (c *fleetServiceClient) ImportCAKey(ctx context.Context, req *connect.Request[v1.ImportCAKeyRequest]) (*connect.Response[v1.ImportCAKeyResponse], error) { + return c.importCAKey.CallUnary(ctx, req) +} + // FleetServiceHandler is an implementation of the cryptos.fleet.v1.FleetService service. type FleetServiceHandler interface { // ListNodes returns a summary for every node the manager knows about. @@ -512,6 +556,20 @@ type FleetServiceHandler interface { // node's ApplyConfig is a whole-config replace, so the caller must send the // complete config, never a partial one. Admin-gated and audited. ApplyNodeConfig(context.Context, *connect.Request[v1.ApplyNodeConfigRequest]) (*connect.Response[v1.ApplyNodeConfigResponse], error) + // ExportCAKey backs up a managed node's CA private key to an encrypted + // envelope. The node seals the backup with the operator passphrase + // (Argon2id + AES-256-GCM) so the plaintext key never leaves the node; the + // manager only relays the envelope through to the caller. The passphrase is + // used in transit and is never persisted. A TPM-backed node refuses export. + // Admin-gated and audited (the audit names the node only, never the secret). + ExportCAKey(context.Context, *connect.Request[v1.ExportCAKeyRequest]) (*connect.Response[v1.ExportCAKeyResponse], error) + // ImportCAKey restores a CA identity onto a fresh managed node from an + // encrypted envelope produced by ExportCAKey. The node decrypts the envelope + // with the operator passphrase and adopts the key; it refuses the import if + // it already holds an identity. The passphrase transits the manager only to + // reach the node and is never persisted. Admin-gated and audited (the audit + // names the node and restored subject only, never the secret or envelope). + ImportCAKey(context.Context, *connect.Request[v1.ImportCAKeyRequest]) (*connect.Response[v1.ImportCAKeyResponse], error) } // NewFleetServiceHandler builds an HTTP handler from the service implementation. It returns the @@ -647,6 +705,18 @@ func NewFleetServiceHandler(svc FleetServiceHandler, opts ...connect.HandlerOpti connect.WithSchema(fleetServiceMethods.ByName("ApplyNodeConfig")), connect.WithHandlerOptions(opts...), ) + fleetServiceExportCAKeyHandler := connect.NewUnaryHandler( + FleetServiceExportCAKeyProcedure, + svc.ExportCAKey, + connect.WithSchema(fleetServiceMethods.ByName("ExportCAKey")), + connect.WithHandlerOptions(opts...), + ) + fleetServiceImportCAKeyHandler := connect.NewUnaryHandler( + FleetServiceImportCAKeyProcedure, + svc.ImportCAKey, + connect.WithSchema(fleetServiceMethods.ByName("ImportCAKey")), + connect.WithHandlerOptions(opts...), + ) return "/cryptos.fleet.v1.FleetService/", http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { switch r.URL.Path { case FleetServiceListNodesProcedure: @@ -691,6 +761,10 @@ func NewFleetServiceHandler(svc FleetServiceHandler, opts ...connect.HandlerOpti fleetServiceGetNodeConfigHandler.ServeHTTP(w, r) case FleetServiceApplyNodeConfigProcedure: fleetServiceApplyNodeConfigHandler.ServeHTTP(w, r) + case FleetServiceExportCAKeyProcedure: + fleetServiceExportCAKeyHandler.ServeHTTP(w, r) + case FleetServiceImportCAKeyProcedure: + fleetServiceImportCAKeyHandler.ServeHTTP(w, r) default: http.NotFound(w, r) } @@ -783,3 +857,11 @@ func (UnimplementedFleetServiceHandler) GetNodeConfig(context.Context, *connect. func (UnimplementedFleetServiceHandler) ApplyNodeConfig(context.Context, *connect.Request[v1.ApplyNodeConfigRequest]) (*connect.Response[v1.ApplyNodeConfigResponse], error) { return nil, connect.NewError(connect.CodeUnimplemented, errors.New("cryptos.fleet.v1.FleetService.ApplyNodeConfig is not implemented")) } + +func (UnimplementedFleetServiceHandler) ExportCAKey(context.Context, *connect.Request[v1.ExportCAKeyRequest]) (*connect.Response[v1.ExportCAKeyResponse], error) { + return nil, connect.NewError(connect.CodeUnimplemented, errors.New("cryptos.fleet.v1.FleetService.ExportCAKey is not implemented")) +} + +func (UnimplementedFleetServiceHandler) ImportCAKey(context.Context, *connect.Request[v1.ImportCAKeyRequest]) (*connect.Response[v1.ImportCAKeyResponse], error) { + return nil, connect.NewError(connect.CodeUnimplemented, errors.New("cryptos.fleet.v1.FleetService.ImportCAKey is not implemented")) +} diff --git a/proto/cryptos/fleet/v1/fleet.proto b/proto/cryptos/fleet/v1/fleet.proto index 74e816b..0e0a9b9 100644 --- a/proto/cryptos/fleet/v1/fleet.proto +++ b/proto/cryptos/fleet/v1/fleet.proto @@ -120,6 +120,22 @@ service FleetService { // node's ApplyConfig is a whole-config replace, so the caller must send the // complete config, never a partial one. Admin-gated and audited. rpc ApplyNodeConfig(ApplyNodeConfigRequest) returns (ApplyNodeConfigResponse); + + // ExportCAKey backs up a managed node's CA private key to an encrypted + // envelope. The node seals the backup with the operator passphrase + // (Argon2id + AES-256-GCM) so the plaintext key never leaves the node; the + // manager only relays the envelope through to the caller. The passphrase is + // used in transit and is never persisted. A TPM-backed node refuses export. + // Admin-gated and audited (the audit names the node only, never the secret). + rpc ExportCAKey(ExportCAKeyRequest) returns (ExportCAKeyResponse); + + // ImportCAKey restores a CA identity onto a fresh managed node from an + // encrypted envelope produced by ExportCAKey. The node decrypts the envelope + // with the operator passphrase and adopts the key; it refuses the import if + // it already holds an identity. The passphrase transits the manager only to + // reach the node and is never persisted. Admin-gated and audited (the audit + // names the node and restored subject only, never the secret or envelope). + rpc ImportCAKey(ImportCAKeyRequest) returns (ImportCAKeyResponse); } message ListNodesRequest {} @@ -466,3 +482,41 @@ message ApplyNodeConfigResponse { // requires_reboot is true when the applied change takes effect only on reboot. bool requires_reboot = 2; } + +// ExportCAKeyRequest names the managed node to back up and carries the operator +// passphrase the node seals the backup with. The passphrase is relayed to the +// node in transit and is never persisted by the manager. +message ExportCAKeyRequest { + // node_name is the managed node whose CA key to export. + string node_name = 1; + // passphrase seals the backup node-side; it is never persisted. + bytes passphrase = 2; +} + +// ExportCAKeyResponse carries the encrypted backup envelope (Argon2id + +// AES-256-GCM over the node's CA key material). It is opaque to the manager. +message ExportCAKeyResponse { + // envelope is the encrypted CA key backup. + bytes envelope = 1; +} + +// ImportCAKeyRequest names the fresh target node, the encrypted envelope to +// restore, and the passphrase that unseals it. The passphrase is relayed to +// the node in transit and is never persisted by the manager. +message ImportCAKeyRequest { + // node_name is the fresh managed node to restore the identity onto. + string node_name = 1; + // envelope is the encrypted CA key backup produced by ExportCAKey. + bytes envelope = 2; + // passphrase unseals the envelope node-side; it is never persisted. + bytes passphrase = 3; +} + +// ImportCAKeyResponse summarizes the restored identity so the web can confirm +// what was imported, without returning the full identity chain. +message ImportCAKeyResponse { + // subject_cn is the restored identity's subject common name. + string subject_cn = 1; + // issuer_cn is the restored identity's issuer common name. + string issuer_cn = 2; +}