What is storagenode tag?
Node tags are arbitrary key=value pairs about a storagenode, signed by an authority. A storagenode presents them to the satellite when it checks in.
If the satellite trusts the signer, it stores the tags and can use them in placement rules.
For example: “only store this data on nodes tagged datacenter=true”.
Who can sign these tags?
tag-signer is the command-line tool that creates and inspects these signed tags.
satellite can sign the tags, a different identity can sign the tags, storagenode can also sign the tags.
What?
If the tag signed using satellite identity, it work out of the box.
If signed by a different entity, satellite could choose to trust it using --tag-authorities flag.
If signed by storagenode identity, when storagenode run, instead of using --contact.tags, storagenode would use --contact.self-signed-tags.
But - there is a different between satellite/another entity signed tag versus storagenode self signed tags:
If storagenode self signed tags, you list the key/value directly, eg:
--contact.self-signed-tags="datacenter=true,region=eu,storage_price=1.5"
But when satellite sign, it should look like this:
--contact.tags="Cs4BCmAKIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAEhIKCmRhdGFjZW50ZXISBHRydWUSDAoGcmVnaW9uEgJldRIUCgdzb21la2V5Eglzb21ldmFsdWUY+MOP1gYaIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAIkgwRgIhAOzXiooze55EsDaujM9MyqYBtH192EJzlaQWJUfVlavvAiEA+9LLg7ppcCyH5hS0EqosYd78q713KbJOBBy0R09cco0="
# --contact.tags="<base64_signer_A>,<another_base64_signer_A>,<base64_signer_B>"
Satellite sign tags workflow
./tag-signer sign --identity-dir id/satellite --node-id <base58_of_storagenode_id> datacenter=true region=eu somekey=somevalue
# result
# Cs4BCmAKIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAEhIKCmRhdGFjZW50ZXISBHRydWUSDAoGcmVnaW9uEgJldRIUCgdzb21la2V5Eglzb21ldmFsdWUY+MOP1gYaIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAIkgwRgIhAOzXiooze55EsDaujM9MyqYBtH192EJzlaQWJUfVlavvAiEA+9LLg7ppcCyH5hS0EqosYd78q713KbJOBBy0R09cco0=
# inspect using tag-signer
./tag-signer inspect Cs4BCmAKIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAEhIKCmRhdGFjZW50ZXISBHRydWUSDAoGcmVnaW9uEgJldRIUCgdzb21la2V5Eglzb21ldmFsdWUY+MOP1gYaIOYKvLjsBGyMDltCUARcqM0Cq7b6QN/IUx0+P3AAAAAAIkgwRgIhAOzXiooze55EsDaujM9MyqYBtH192EJzlaQWJUfVlavvAiEA+9LLg7ppcCyH5hS0EqosYd78q713KbJOBBy0R09cco0=
Trusted Node
trusted_node=true is special flag, it lets a brand-new node skip the node ID difficulty check when it first registers with the satellite - will not work with self signed tags.
This is probably for Commercial Selected Node.
Placement
Not sure if it just me but I’d got confused with this string 12Q8q2PofHPwycSwAVCpjNxxzWiDJhi8UV4ceZBo4hmNARpYcR7 in placement templates.
templates:
SIGNER: 12Q8q2PofHPwycSwAVCpjNxxzWiDJhi8UV4ceZBo4hmNARpYcR7
SIGNER is just a variable name.
12Q8q2PofHPwycSwAVCpjNxxzWiDJhi8UV4ceZBo4hmNARpYcR7 is the base58 of satellite id (if you use satellite identity to sign for storagenode).