swarm-controller: first credential-renewal pass waits for the queue connection
The renewal pass ran the moment swarm-controller started, before its queue client had connected, so `WantedWriter::view` refused with "client state Pending" and the pass logged `agent credential renewal: pass failed; retrying next tick`. That fired twice in 24h on muede-lpt2, both under a second after start, and would trip a Grafana rule on that WARN on ordinary restarts. The first pass now waits until the queue client is connected, polling `swarm_queue_client::ensure_connected` every 5s the way `AgentIconReader::create_when_connected` does. The wait is bounded by one RECONCILE_INTERVAL (5 min): the old code's retry after a false start also came one interval later, so a queue that never connects gets its first pass no later than before. Hitting the bound logs one WARN and runs the pass anyway. Only startup waits; a later disconnect still fails a pass and logs the WARN. Refs #4717
This commit is contained in:
parent
b9667d5975
commit
9e06e191a3
3 changed files with 151 additions and 39 deletions
|
|
@ -120,5 +120,10 @@ utoipa-axum.workspace = true
|
|||
# `agent_renewal.rs` reads an agent certificate's validity window.
|
||||
x509-cert.workspace = true
|
||||
|
||||
# `test-util` for `#[tokio::test(start_paused = true)]`: `agent_renewal`'s
|
||||
# tests wait out its five-minute bound on paused time.
|
||||
[dev-dependencies]
|
||||
tokio = { workspace = true, features = ["test-util"] }
|
||||
|
||||
[lints]
|
||||
workspace = true
|
||||
|
|
|
|||
Loading…
Reference in a new issue