Watch
0
0
Fork
You've already forked hyperhive
0
hyperhive/nix/host-modules/lib
Repository files (latest commit first)
Filename Latest commit message Latest commit date
atlas b68fd7306e refresh-consumer: key the restart on the file's mtime, not a pre-write compare
The restart decision was a shell variable set by comparing the fetched
value with the file just before overwriting it. A run that wrote the
file and then failed before the restart (the matrix unit's registration
render, or `systemctl --machine` finding no bus yet) left a retry that
saw an unchanged file and never restarted the consumer.

The file is now written only when the value differs, so its mtime marks
the last real change, and `refresh_consumer <machine> <unit> <path>`
compares that mtime with the consumer's ActiveEnterTimestamp on every
run, the shape the openbao client-CA refresh in swarm-bao.nix already
uses. A consumer that started after the last change is left alone; a
running one is try-restarted, a failed one reset and started, all with
--no-block, and nothing happens while the container is down.

The helper's comment block also exceeded the 30-line limit
(`comment-block lint` failed on d871467d); its per-function notes now
sit beside the functions.

module-eval-bao-grants asserts the gated write, the path the refresh is
keyed on, and the mtime-vs-start comparison for each consumer.

Refs #4662
2026-09-30 07:45:47 +02:00
..
atomic-write-secret.nix lint: tighten atomic-write-secret.nix's header comment; fix vale contractions in persistence.md 2026-09-26 21:50:03 +02:00
hive-ca-trust.nix deploy: move the hive CA's knobs to deploy.hive-controller.tls 2026-08-30 20:52:00 +02:00
name-guards.nix swarm: extract the name guards, so the module just says what is forbidden 2026-08-31 18:50:15 +02:00
refresh-consumer.nix refresh-consumer: key the restart on the file's mtime, not a pre-write compare 2026-09-30 07:45:47 +02:00
store-retry.nix credential units: restart consumers on a changed credential; fix the ordering claim 2026-09-30 07:45:47 +02:00