swarm-bao: say "run the bootstrap step" when the bootstrap token is dead, not "sealed"
swarm-bao-granter-role used its token for `bao auth list` with no check,
so an expired, revoked or policy-less token in bootstrapTokenFile exited
2 with a raw 403 and no hint. It now checks whether the store is up when
that call fails: if it is, the token is at fault, and the unit prints the
one-time bootstrap step and exits 4. A missing token file is still a
ConditionPathExists skip, so the two read differently in the journal.
The twelve granterLogin units printed "the store is sealed or
unreachable" on a healthy store, because `bao status` exited 1 there:
the CLI resolves a token helper under $HOME before asking, systemd sets
no HOME for a unit without User=, and the fallback shells out to
`getent`/`sh`, neither of which is on the unit's PATH ("failed to get
token helper: error expanding config path "": exec: "sh": executable
file not found in $PATH"). The check now runs with HOME=/var/empty and
keeps its stderr, so a genuinely unreachable store says why. When the
store is up and the login is refused, the units now name
swarm-bao-granter-role as the unit that writes the missing role.
setup.md's post-step restart used 'swarm-bao-*-policy.service', which
misses swarm-bao-agent-pki. It now names that unit too, and a
module-eval case fails when the restart misses any unit that logs in as
the granter.
Refs #4704
This commit is contained in:
parent
3fc7a785fa
commit
a2b4acfb6a
3 changed files with 80 additions and 8 deletions
|
|
@ -123,11 +123,13 @@ the side that has one.
|
|||
|
||||
**Confirm with `systemctl status swarm-bao-granter-role`**, which should log
|
||||
`Uploaded policy: bao-granter` and `Data written to: auth/cert/certs/bao-granter`.
|
||||
Then restart the granting units that failed while they waited:
|
||||
Then restart the granting units that failed while they waited. These two
|
||||
names cover every unit that logs in as the granter, and CI fails when one
|
||||
doesn't:
|
||||
|
||||
```bash
|
||||
systemctl reset-failed 'swarm-bao-*-policy.service'
|
||||
systemctl restart 'swarm-bao-*-policy.service'
|
||||
systemctl reset-failed 'swarm-bao-*-policy.service' swarm-bao-agent-pki.service
|
||||
systemctl restart 'swarm-bao-*-policy.service' swarm-bao-agent-pki.service
|
||||
systemctl status swarm-bao-controller-policy # Uploaded policy, Data written to: auth/cert/certs/swarm-controller
|
||||
rm /var/lib/swarm-bao-bootstrap/grant.token
|
||||
```
|
||||
|
|
|
|||
Loading…
Reference in a new issue