swarm-bao: don't let the viewer restart enqueue fail the granter
ExecStartPost (not postStart, which can't take a prefix) with a leading -: a failed enqueue -- an already-running viewer unit, or systemctl itself failing -- must not mark the granter failed or trigger its own Restart=on-failure.
This commit is contained in:
parent
22c96282b9
commit
8fb7751da9
2 changed files with 22 additions and 13 deletions
|
|
@ -2652,6 +2652,22 @@ in
|
|||
RemainAfterExit = true;
|
||||
Restart = "on-failure";
|
||||
RestartSec = 30;
|
||||
# Runs only once the script above exits 0, which is when the
|
||||
# granter may first configure `auth/oidc`; the viewer unit exits 0
|
||||
# without doing so before then, and nothing else re-runs it. A
|
||||
# restart because it is `RemainAfterExit`, where a start is a
|
||||
# no-op.
|
||||
#
|
||||
# `--no-block`: the viewer unit is ordered after this one, so a
|
||||
# blocking restart waits on a job that cannot run until this unit
|
||||
# is active, which it is not until this command returns.
|
||||
#
|
||||
# `postStart` can't carry the leading `-`, which is why this is
|
||||
# `ExecStartPost` directly: without it, a viewer unit that is
|
||||
# already running (or a `systemctl` that itself fails to enqueue
|
||||
# the job) would mark the granter failed and trigger its own
|
||||
# `Restart=on-failure` for a problem that isn't the granter's.
|
||||
ExecStartPost = "-${pkgs.systemd}/bin/systemctl restart --no-block swarm-bao-operator-viewer-policy.service";
|
||||
};
|
||||
script = ''
|
||||
set -euo pipefail
|
||||
|
|
@ -2717,17 +2733,6 @@ in
|
|||
token_ttl=15m \
|
||||
token_max_ttl=15m
|
||||
'';
|
||||
# Runs only once the script above exits 0, which is when the granter
|
||||
# may first configure `auth/oidc`; the viewer unit exits 0 without
|
||||
# doing so before then, and nothing else re-runs it. A restart because
|
||||
# it is `RemainAfterExit`, where a start is a no-op.
|
||||
#
|
||||
# `--no-block`: the viewer unit is ordered after this one, so a
|
||||
# blocking restart waits on a job that cannot run until this unit is
|
||||
# active, which it is not until this command returns.
|
||||
postStart = ''
|
||||
systemctl restart --no-block swarm-bao-operator-viewer-policy.service
|
||||
'';
|
||||
};
|
||||
|
||||
# The swarm's first grant, written from the HOST. Every API listener but
|
||||
|
|
|
|||
Loading…
Reference in a new issue