swarm-bao: say "run the bootstrap step" when the bootstrap token is dead, not "sealed"
swarm-bao-granter-role used its token for `bao auth list` with no check,
so an expired, revoked or policy-less token in bootstrapTokenFile exited
2 with a raw 403 and no hint. It now checks whether the store is up when
that call fails: if it is, the token is at fault, and the unit prints the
one-time bootstrap step and exits 4. A missing token file is still a
ConditionPathExists skip, so the two read differently in the journal.
The twelve granterLogin units printed "the store is sealed or
unreachable" on a healthy store, because `bao status` exited 1 there:
the CLI resolves a token helper under $HOME before asking, systemd sets
no HOME for a unit without User=, and the fallback shells out to
`getent`/`sh`, neither of which is on the unit's PATH ("failed to get
token helper: error expanding config path "": exec: "sh": executable
file not found in $PATH"). The check now runs with HOME=/var/empty and
keeps its stderr, so a genuinely unreachable store says why. When the
store is up and the login is refused, the units now name
swarm-bao-granter-role as the unit that writes the missing role.
setup.md's post-step restart used 'swarm-bao-*-policy.service', which
misses swarm-bao-agent-pki. It now names that unit too, and a
module-eval case fails when the restart misses any unit that logs in as
the granter.
Refs #4704
This commit is contained in:
parent
3fc7a785fa
commit
a2b4acfb6a
3 changed files with 80 additions and 8 deletions
|
|
@ -821,6 +821,23 @@ let
|
|||
&& lib.hasInfix "systemctl restart swarm-bao-granter-role" sc
|
||||
) grantingUnitNames;
|
||||
}
|
||||
{
|
||||
# A token the store refuses gets the same step, under an exit status of
|
||||
# its own. Both store checks run with a HOME: without one `bao status`
|
||||
# exits 1 on a healthy store and every refusal reads as "sealed".
|
||||
name = "a refused bootstrap token prints the one-time step and exits 4, and every store check has a HOME";
|
||||
ok =
|
||||
let
|
||||
s = baoGrantHere.systemd.services;
|
||||
g = s.swarm-bao-granter-role.script;
|
||||
in
|
||||
lib.hasInfix "refused the bootstrap token in /run/secrets/bao-bootstrap.token" g
|
||||
&& lib.hasInfix "bao policy write bao-bootstrap /etc/hyperhive/bao-bootstrap-policy.hcl" g
|
||||
&& lib.hasInfix "exit 4" g
|
||||
&& lib.all (unit: lib.hasInfix "HOME=/var/empty bao status" s.${unit}.script) (
|
||||
[ "swarm-bao-granter-role" ] ++ grantingUnitNames
|
||||
);
|
||||
}
|
||||
{
|
||||
# Every granting unit retries a sealed or late store for a day, in the
|
||||
# `[Unit]` section systemd reads it from, and waits for the unit that
|
||||
|
|
@ -1164,6 +1181,34 @@ let
|
|||
&& lib.all (u: baoCalls u.script != [ ]) (lib.attrValues granterUnits)
|
||||
&& lib.all (u: baoCalls u.script != [ ]) (lib.attrValues bootstrapUnits);
|
||||
}
|
||||
{
|
||||
# setup.md's restart after the one-time step: a granting unit it misses
|
||||
# stays failed once its start limit is hit.
|
||||
name = "setup.md's reset-failed and restart after the one-time step reach every granting unit";
|
||||
ok =
|
||||
let
|
||||
lines = lib.splitString "\n" (builtins.readFile ../../docs/getting-started/setup.md);
|
||||
# The unit patterns on the one `systemctl <verb> 'swarm-bao-…` line.
|
||||
argsOf =
|
||||
verb:
|
||||
map (l: map (lib.replaceStrings [ "'" ] [ "" ]) (lib.drop 2 (lib.splitString " " l))) (
|
||||
lib.filter (lib.hasPrefix "systemctl ${verb} 'swarm-bao-") lines
|
||||
);
|
||||
covers =
|
||||
pats:
|
||||
lib.all (
|
||||
unit:
|
||||
lib.any (
|
||||
p: builtins.match (lib.replaceStrings [ "." "*" ] [ "[.]" ".*" ] p) "${unit}.service" != null
|
||||
) pats
|
||||
) (lib.attrNames granterUnits);
|
||||
in
|
||||
lib.length (argsOf "restart") == 1
|
||||
&& argsOf "reset-failed" == argsOf "restart"
|
||||
&& covers (lib.head (argsOf "restart"))
|
||||
# The control: the policy glob alone misses one.
|
||||
&& !(covers [ "swarm-bao-*-policy.service" ]);
|
||||
}
|
||||
{
|
||||
# And the grants side: a stanza the parser skipped would read as a
|
||||
# grant that is not there.
|
||||
|
|
|
|||
Loading…
Reference in a new issue