# Retry shape for a oneshot that fetches a credential or certificate from # the secret store: every 30s for 24h. Under `seal = "shamir"` an operator # unseals BY HAND, and a fetch fails for as long as that takes, or for as # long as the store or the gateway in front of it is down. `start-limit-hit` # does not clear when the store comes back, so a budget shorter than the # outage leaves the unit failed until something starts it again. # # `StartLimit*` are `[Unit]` settings — systemd ignores them under # `[Service]` — and the window must exceed `RestartSec × burst` or it closes # between attempts and the burst is never reached: 2880 × 30s is 24h inside # a 25h window. # # Under the default `RestartMode=normal` each failed attempt passes through # `failed`, which ends that attempt's start job: a unit ordered `After=` it # waits for ONE attempt, a unit that `Requires=` it fails with `dependency`, # and the retries continue in the background as fresh start jobs. A consumer # that loaded the credential before it landed does not see it without a # restart — ./refresh-consumer.nix. # # Pure attrset — NOT a NixOS module. Use from a unit definition: # # storeRetry = import ./lib/store-retry.nix { }; # systemd.services.foo = { # inherit (storeRetry) startLimitBurst startLimitIntervalSec; # serviceConfig = storeRetry.serviceConfig // { Type = "oneshot"; }; # }; { }: { startLimitBurst = 2880; startLimitIntervalSec = 90000; serviceConfig = { Restart = "on-failure"; RestartSec = 30; }; }