feat(plc): ephemeral soft-PLC provisioning + program load (#183)
CI / Check (pull_request) Failing after 1m31s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
CI / Check (pull_request) Failing after 1m31s
CI / Detect Changes (pull_request) Has been skipped
CI / Deploy Agent (pull_request) Has been skipped
CI / Deploy Dashboard (pull_request) Has been skipped
CI / Deploy Docs (pull_request) Has been skipped
CI / Deploy MCP (pull_request) Has been skipped
Dynamic PLC testing without reaching the customer's device: when a PLC/SPS target ships control logic but no reachable live URL, instantiate that logic ourselves on a throwaway OpenPLC container in-cluster, load + start it, probe the provisioned Modbus endpoint, and tear it down. No customer network access, sandboxed, and reproducible. This is the phase-1 foundation of epic #183 (OpenPLC substrate). It covers: - provision: ephemeral container lifecycle (docker CLI). Resource-capped (memory/cpus/pids), hardened (no-new-privileges), labelled, joined to the agent's own network with no host port exposure, and swept by a stale reaper for anything a crashed run leaks. The `docker` argv is built by pure functions so it is unit-tested without a daemon. - openplc: drives the OpenPLC web UI to load a program — login → upload → save → compile (MatIEC) → start_plc (which opens Modbus/TCP 502). - runtime::provision_and_test: composes them under a hard deadline with guaranteed teardown on every path (success / error / timeout), then runs the existing ICS probe against the provisioned endpoint. extract_program picks the best loadable program (complete ST > largest ST > PLCopen XML). - orchestrator: for a PlcSps target with control logic and no live URL, run provision-and-test after the static PLC scan. Gated by PlcRuntimeConfig (PLC_RUNTIME_ENABLED, default off — needs Docker access in the agent). DAST-against-WebVisu and CODESYS-runtime fidelity are follow-ups. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5
parent
1aba85b28e
commit
1ae6025286
@@ -49,6 +49,57 @@ pub struct AgentConfig {
|
||||
/// of tenants to iterate. When `None` or unreachable, scheduler
|
||||
/// falls back to `SCHEDULER_TENANT_IDS` env (M7.2-C).
|
||||
pub tenant_registry_url: Option<String>,
|
||||
/// Ephemeral soft-PLC provisioning for dynamic PLC testing (#183). Off by
|
||||
/// default: it needs Docker access in the agent's runtime, which is a
|
||||
/// deployment opt-in.
|
||||
pub plc_runtime: PlcRuntimeConfig,
|
||||
}
|
||||
|
||||
/// Configuration for the ephemeral soft-PLC "provision-and-test" path (#183).
|
||||
///
|
||||
/// When a PLC/SPS target ships control logic but no reachable live device, the
|
||||
/// agent can instantiate that logic itself: spin up a throwaway soft-PLC
|
||||
/// (OpenPLC) container in-cluster, load the program, start the runtime, probe it
|
||||
/// over industrial protocols, then tear it down. This struct carries the knobs
|
||||
/// for that container's lifecycle and the OpenPLC web-UI credentials used to
|
||||
/// upload the program.
|
||||
#[derive(Clone, Debug)]
|
||||
pub struct PlcRuntimeConfig {
|
||||
/// Master switch. Provision-and-test does nothing unless this is set — it
|
||||
/// shells out to `docker`, which requires the agent container to have Docker
|
||||
/// access (socket mount), an explicit deployment decision.
|
||||
pub enabled: bool,
|
||||
/// Container image for the ephemeral soft-PLC (OpenPLC).
|
||||
pub image: String,
|
||||
/// Docker network the instance joins. Must be the agent's own network so it
|
||||
/// is reachable in-cluster by container name and never published to the host.
|
||||
pub network: String,
|
||||
/// Memory cap passed to `docker run --memory` (e.g. `512m`).
|
||||
pub memory: String,
|
||||
/// CPU cap passed to `docker run --cpus` (e.g. `0.5`).
|
||||
pub cpus: String,
|
||||
/// Hard ceiling on a provisioned instance's lifetime. Teardown is guaranteed
|
||||
/// no later than this even if a load/probe step hangs.
|
||||
pub max_lifetime_secs: u64,
|
||||
/// OpenPLC web-UI username for the program upload (image default `openplc`).
|
||||
pub openplc_user: String,
|
||||
/// OpenPLC web-UI password (image default `openplc`).
|
||||
pub openplc_password: SecretString,
|
||||
}
|
||||
|
||||
impl Default for PlcRuntimeConfig {
|
||||
fn default() -> Self {
|
||||
Self {
|
||||
enabled: false,
|
||||
image: "registry.meghsakha.com/openplc:latest".to_string(),
|
||||
network: "certifai".to_string(),
|
||||
memory: "512m".to_string(),
|
||||
cpus: "0.5".to_string(),
|
||||
max_lifetime_secs: 180,
|
||||
openplc_user: "openplc".to_string(),
|
||||
openplc_password: SecretString::from("openplc".to_string()),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
#[derive(Clone, Debug, Serialize, Deserialize)]
|
||||
|
||||
@@ -13,6 +13,6 @@ pub mod auth;
|
||||
#[cfg(feature = "axum")]
|
||||
pub mod tenant_ctx;
|
||||
|
||||
pub use config::{AgentConfig, DashboardConfig};
|
||||
pub use config::{AgentConfig, DashboardConfig, PlcRuntimeConfig};
|
||||
pub use error::CoreError;
|
||||
pub use tenant::{OrgRole, TenantContext, TenantStatus};
|
||||
|
||||
Reference in New Issue
Block a user