Watch
0
0
Fork
You've already forked hyperhive
0

swarm-bao: don't let the viewer restart enqueue fail the granter

ExecStartPost (not postStart, which can't take a prefix) with a
leading -: a failed enqueue -- an already-running viewer unit,
or systemctl itself failing -- must not mark the granter failed
or trigger its own Restart=on-failure.
This commit is contained in:
atlas 2026-09-29 18:09:53 +02:00
commit 8fb7751da9
2 changed files with 22 additions and 13 deletions

View file

@ -2652,6 +2652,22 @@ in
RemainAfterExit = true; RemainAfterExit = true;
Restart = "on-failure"; Restart = "on-failure";
RestartSec = 30; RestartSec = 30;
# Runs only once the script above exits 0, which is when the
# granter may first configure `auth/oidc`; the viewer unit exits 0
# without doing so before then, and nothing else re-runs it. A
# restart because it is `RemainAfterExit`, where a start is a
# no-op.
#
# `--no-block`: the viewer unit is ordered after this one, so a
# blocking restart waits on a job that cannot run until this unit
# is active, which it is not until this command returns.
#
# `postStart` can't carry the leading `-`, which is why this is
# `ExecStartPost` directly: without it, a viewer unit that is
# already running (or a `systemctl` that itself fails to enqueue
# the job) would mark the granter failed and trigger its own
# `Restart=on-failure` for a problem that isn't the granter's.
ExecStartPost = "-${pkgs.systemd}/bin/systemctl restart --no-block swarm-bao-operator-viewer-policy.service";
}; };
script = '' script = ''
set -euo pipefail set -euo pipefail
@ -2717,17 +2733,6 @@ in
token_ttl=15m \ token_ttl=15m \
token_max_ttl=15m token_max_ttl=15m
''; '';
# Runs only once the script above exits 0, which is when the granter
# may first configure `auth/oidc`; the viewer unit exits 0 without
# doing so before then, and nothing else re-runs it. A restart because
# it is `RemainAfterExit`, where a start is a no-op.
#
# `--no-block`: the viewer unit is ordered after this one, so a
# blocking restart waits on a job that cannot run until this unit is
# active, which it is not until this command returns.
postStart = ''
systemctl restart --no-block swarm-bao-operator-viewer-policy.service
'';
}; };
# The swarm's first grant, written from the HOST. Every API listener but # The swarm's first grant, written from the HOST. Every API listener but

View file

@ -1492,14 +1492,18 @@ let
# success restarts that unit: a restart since the unit is # success restarts that unit: a restart since the unit is
# `RemainAfterExit`, `--no-block` since it is ordered after the granter. # `RemainAfterExit`, `--no-block` since it is ordered after the granter.
# The ordering is one-way, so the viewer's retries never reach back. # The ordering is one-way, so the viewer's retries never reach back.
name = "a successful granter step restarts the viewer unit without blocking"; # `ExecStartPost` directly, not `postStart` (which can't carry a
# leading `-`), and the `-` is load-bearing: a failed enqueue must not
# mark the granter itself failed.
name = "a successful granter step restarts the viewer unit without blocking, and the enqueue can't fail the granter";
ok = ok =
let let
s = baoGrantHere.systemd.services; s = baoGrantHere.systemd.services;
g = s.swarm-bao-granter-role; g = s.swarm-bao-granter-role;
v = s.swarm-bao-operator-viewer-policy; v = s.swarm-bao-operator-viewer-policy;
in in
lib.hasInfix "systemctl restart --no-block swarm-bao-operator-viewer-policy.service" g.postStart lib.hasPrefix "-" g.serviceConfig.ExecStartPost
&& lib.hasInfix "systemctl restart --no-block swarm-bao-operator-viewer-policy.service" g.serviceConfig.ExecStartPost
&& lib.elem "swarm-bao-granter-role.service" v.after && lib.elem "swarm-bao-granter-role.service" v.after
&& !(lib.elem "swarm-bao-operator-viewer-policy.service" g.after) && !(lib.elem "swarm-bao-operator-viewer-policy.service" g.after)
&& !(v ? postStart && lib.hasInfix "swarm-bao-granter-role" v.postStart); && !(v ? postStart && lib.hasInfix "swarm-bao-granter-role" v.postStart);