Skip to content

fix: etcd's health on its metrics listener, and no lone member kept - #39

Merged
marcos-mendez merged 3 commits into
19.xfrom
fix/etcd-health-and-stray-member
Oct 4, 2026
Merged

marcos-mendez merged 3 commits into
19.xfrom
fix/etcd-health-and-stray-member

Conversation

@marcos-mendez

@marcos-mendez marcos-mendez commented Oct 4, 2026 •

Copy link
Copy Markdown
Collaborator

Companion of Keel-Linux/keel#78; merge this first.

  • Monit's etcd-health asks /health on etcd's plain metrics listener http://[::1]:2381 (keel renders ETCD_LISTEN_METRICS_URLS). The client port is TLS with client certificates now, so the old plain probe of 2379 failed every cycle and restarted etcd forever.
  • The first installation removes /var/lib/etcd/default when etcd-server's own postinst made it in the same transaction (preinst notes whether a member existed before). That start leaves a lone cluster of one. Data that was there before is never touched, and keel refuses to start etcd over a member it never started.
  • packages/README.md documents both; overlay-install.bats checks the member is gone.

keel now runs etcd over the mesh with TLS and client certificates on
2379, so Monit's plain probe of /health there failed every cycle and
restarted etcd forever. The check asks /health on the plain metrics
listener keel renders on http://[::1]:2381.

etcd-server's postinst starts etcd, which leaves a member of a cluster
of one in /var/lib/etcd/default. The overlay's first installation now
removes it when it was not there before (preinst notes it), so the
node keeps no lone cluster before keel joins it to the mesh's. Data
that was there before is never touched; keel refuses to start etcd over
a member it did not start.
marcos-mendez pushed a commit to Keel-Linux/keel that referenced this pull request Oct 4, 2026
…a CRL

From the security review of keel#78:

- only the node that holds the mesh's root CA forms the cluster, once
  (keel.mesh.etcdca): it signs a formation record (cluster token,
  members, root fingerprint) with the root and reserves the formation
  under its lock; a member takes a cluster, from a join's answer or a
  cluster message, only with that record, and a member in a cluster
  takes no other. Two concurrent invites can no longer start two
  clusters; another inviter of the third member admits it and names the
  holder; keel mesh etcd form runs only on the holder, and on a mesh
  with no CA makes the root where the operator runs it (a trust root);
- leaves last 30 days and are renewed by their member; intermediates a
  year, renewed by the holder, which signs them with the root (an
  inviter relays the request; only when the holder is unreachable does
  it sign one level deeper, re-anchored at the first renewal);
- every intermediate is name constrained to the mesh's /64 and ::1;
- the holder keeps a CRL signed by the root, written to etcd's
  --peer-crl-file and --client-crl-file and carried by grants and
  rosters; keel mesh remove has the holder revoke the removed node's
  intermediates, and so its leaves and what it issued;
- etcd serves /health on a plain metrics listener on [::1]:2381 for
  Monit (Keel-Linux/common#39);
- apply refuses a member in /var/lib/etcd/default that keel never
  started, and the join or form that starts etcd removes it first.
trixie-backports replaced golang-1.26-go with golang-1.27-go, so the
step 5 packages pinned in the web job, which build with 1.26, could no
longer have their build dependencies installed (mk-build-deps exited
1 for libcoraza). The job takes 1.26.8-1~bpo13+1 from
snapshot.debian.org as of 2026-10-01, pinned.
@marcos-mendez
marcos-mendez force-pushed the fix/etcd-health-and-stray-member branch from 2d8d0e8 to 6c1a787 Compare October 4, 2026 12:11
keel removes a member directory only when it can prove it is the lone
member etcd-server's own start made at the overlay's installation: the
overlay's postinst now marks it in /var/lib/keel-overlay-etcd/
package-member rather than removing it, and never marks a member that
was there before.
marcos-mendez pushed a commit to Keel-Linux/keel that referenced this pull request Oct 4, 2026
From the third review of keel#78:

- a revocation names no serial: the holder revokes the intermediates
  it recorded for that address and WireGuard key, and only for the
  node's admitter, a trust root or the node itself; it signs an
  intermediate for an address only with that address's own key;
- records carry etcd's cluster ID, an epoch that only grows, a nonce
  and an expiry, name exactly the cluster's members for `new` and
  `existing` alike, and a member takes none no newer than the last;
  only the holder adds a learner, so every record is the root's;
- only the root signs intermediates, relayed by the inviter (0048's
  third round, point 1, narrowed): one intermediate deep, path length
  0, name constrained to its member's own /128 and ::1, each recorded.
  When the holder cannot be reached the join completes without etcd,
  the request is queued, keel-mesh-etcd.timer asks again, and keel
  mesh status says so;
- a member directory keel never started is removed only when
  keel-overlay-etcd marked it as etcd-server's own (Keel-Linux/common#39);
  any other is refused, named;
- a renewal that fails is alerted through the monitor's channels and
  shown by keel mesh status and keel diff (etcd.certificates), as is a
  certificate within seven days of its expiry.
@marcos-mendez
marcos-mendez merged commit 5c891bb into 19.x Oct 4, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant