Repository navigation
feat: keel-overlay-vip, the units of keel's service VIP (0049) - #40
Open
marcos-mendez wants to merge 2 commits into
Open
marcos-mendez wants to merge 2 commits into
marcos-mendez wants to merge 2 commits into
Conversation
added 2 commits
October 7, 2026 14:43
The VIP of a replicated pair on the WireGuard mesh is keel's code (keel vip, handbook decision 0049, third round, point 1); this package ships only its units and the overlay manifest. keel-vip.service runs the controller with etcd, sandboxed with CAP_NET_ADMIN alone, writing only /var/lib/keel/vip and /etc/wireguard, installed disabled for keel spec apply to enable with the overlay; ExecStopPost drops every VIP the node carries. keel-vip-check.timer runs keel vip check at boot and every minute in every mode.
From keel#81's security review: keel vip tend is now the root helper, which starts the unprivileged controller as its own transient unit. The helper keeps CAP_NET_ADMIN, takes CAP_DAC_OVERRIDE to reach the controller's 0600 socket, and reaches only AF_UNIX and AF_NETLINK. The unit has StartLimitIntervalSec=0, so a crash loop never leaves it stopped for good.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The companion of Keel-Linux/keel#81: the units of keel's service VIP and its overlay manifest (handbook decision 0049, third round, point 1: the code lives in keel, this package ships only the units, as the etcd overlay does).
keel-vip.service:keel vip tend, the controller with etcd (lease TTL 20 s, released 10 s after the last renewal),ConditionPathExists=/var/lib/keel/etcd/cluster.json,CapabilityBoundingSet=CAP_NET_ADMINonly,ProtectSystem=strictwithReadWritePaths=/var/lib/keel/vip /etc/wireguard,RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK,SystemCallFilter=@system-service;ExecStopPost=keel vip tend --stoppeddrops every VIP the node carries however the controller stopped. Installed disabled (--no-enable --no-start, and a preset), for keel spec apply to enable with the overlay; it is the manifest's process.keel-vip-check.timer:keel vip checkat boot and every minute, in every mode; the service skips a node that knows no VIP (ConditionDirectoryNotEmpty=/var/lib/keel/vip).keel (>= 0.20.0), the first withkeel vip.Built and linted locally with
packages/build vip(lintian clean); the manifest validates with keel 0.20.0'skeel manifest validate, andsystemd-analyze verifyfinds nothing in the units. Merge after keel#81.