Skip to content

feat: keel-overlay-vip, the units of keel's service VIP (0049) - #40

Open
marcos-mendez wants to merge 2 commits into
19.xfrom
feat/overlay-vip
Open

marcos-mendez wants to merge 2 commits into
19.xfrom
feat/overlay-vip

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

The companion of Keel-Linux/keel#81: the units of keel's service VIP and its overlay manifest (handbook decision 0049, third round, point 1: the code lives in keel, this package ships only the units, as the etcd overlay does).

  • keel-vip.service: keel vip tend, the controller with etcd (lease TTL 20 s, released 10 s after the last renewal), ConditionPathExists=/var/lib/keel/etcd/cluster.json, CapabilityBoundingSet=CAP_NET_ADMIN only, ProtectSystem=strict with ReadWritePaths=/var/lib/keel/vip /etc/wireguard, RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK, SystemCallFilter=@system-service; ExecStopPost=keel vip tend --stopped drops every VIP the node carries however the controller stopped. Installed disabled (--no-enable --no-start, and a preset), for keel spec apply to enable with the overlay; it is the manifest's process.
  • keel-vip-check.timer: keel vip check at boot and every minute, in every mode; the service skips a node that knows no VIP (ConditionDirectoryNotEmpty=/var/lib/keel/vip).
  • Depends on keel (>= 0.20.0), the first with keel vip.

Built and linted locally with packages/build vip (lintian clean); the manifest validates with keel 0.20.0's keel manifest validate, and systemd-analyze verify finds nothing in the units. Merge after keel#81.

navigator added 2 commits October 7, 2026 14:43
The VIP of a replicated pair on the WireGuard mesh is keel's code (keel
vip, handbook decision 0049, third round, point 1); this package ships
only its units and the overlay manifest. keel-vip.service runs the
controller with etcd, sandboxed with CAP_NET_ADMIN alone, writing only
/var/lib/keel/vip and /etc/wireguard, installed disabled for keel spec
apply to enable with the overlay; ExecStopPost drops every VIP the node
carries. keel-vip-check.timer runs keel vip check at boot and every
minute in every mode.
From keel#81's security review: keel vip tend is now the root helper,
which starts the unprivileged controller as its own transient unit. The
helper keeps CAP_NET_ADMIN, takes CAP_DAC_OVERRIDE to reach the
controller's 0600 socket, and reaches only AF_UNIX and AF_NETLINK. The
unit has StartLimitIntervalSec=0, so a crash loop never leaves it stopped
for good.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant