From e115dad8857a6e18daec5ffc0d44e1867ef22abe Mon Sep 17 00:00:00 2001 From: navigator Date: Wed, 7 Oct 2026 14:43:57 +0000 Subject: [PATCH 1/4] feat: keel-overlay-vip, the units of keel's service VIP (0049) The VIP of a replicated pair on the WireGuard mesh is keel's code (keel vip, handbook decision 0049, third round, point 1); this package ships only its units and the overlay manifest. keel-vip.service runs the controller with etcd, sandboxed with CAP_NET_ADMIN alone, writing only /var/lib/keel/vip and /etc/wireguard, installed disabled for keel spec apply to enable with the overlay; ExecStopPost drops every VIP the node carries. keel-vip-check.timer runs keel vip check at boot and every minute in every mode. --- packages/README.md | 1 + packages/vip/debian/changelog | 10 ++++++ packages/vip/debian/control | 30 +++++++++++++++++ packages/vip/debian/copyright | 25 +++++++++++++++ packages/vip/debian/rules | 29 +++++++++++++++++ packages/vip/debian/source/format | 1 + packages/vip/keel-overlay-vip.preset | 5 +++ packages/vip/keel-vip-check.service | 35 ++++++++++++++++++++ packages/vip/keel-vip-check.timer | 13 ++++++++ packages/vip/keel-vip.service | 48 ++++++++++++++++++++++++++++ packages/vip/manifest.yaml | 12 +++++++ 11 files changed, 209 insertions(+) create mode 100644 packages/vip/debian/changelog create mode 100644 packages/vip/debian/control create mode 100644 packages/vip/debian/copyright create mode 100755 packages/vip/debian/rules create mode 100644 packages/vip/debian/source/format create mode 100644 packages/vip/keel-overlay-vip.preset create mode 100644 packages/vip/keel-vip-check.service create mode 100644 packages/vip/keel-vip-check.timer create mode 100644 packages/vip/keel-vip.service create mode 100644 packages/vip/manifest.yaml diff --git a/packages/README.md b/packages/README.md index 28573c42..d6a07aa2 100644 --- a/packages/README.md +++ b/packages/README.md @@ -12,6 +12,7 @@ directory each, with its own changelog and version, released on its own | `installer/` | `keel-overlay-installer` | Keel's `inithooks` (>= 2.3.6+keel14), `confconsole` (>= 2.2.3+keel8), `keel` (>= 0.12.0) | none; its manifest names the first boot hooks the three ship | | `wireguard/` | `keel-overlay-wireguard` | trixie's `wireguard-tools` 1.0.20210914 | none; the interface is the instance spec's | | `etcd/` | `keel-overlay-etcd` | trixie's `etcd-server` 3.5.16, and `keel-overlay-wireguard`, which its manifest `requires` | `etcd.service` | +| `vip/` | `keel-overlay-vip` | `keel` (>= 0.20.0), whose `keel vip` the units run, and `keel-overlay-wireguard`, which its manifest `requires` | `keel-vip.service`, the controller with etcd; and `keel-vip-check.timer`, enabled in every mode | | `crowdsec/` | `keel-overlay-crowdsec` | trixie's `crowdsec` 1.4.6-10 and `crowdsec-firewall-bouncer` 0.0.25 | `crowdsec.service`, `crowdsec-firewall-bouncer.service` | | `nginx/` | `keel-overlay-nginx` | trixie's `nginx` 1.26.3 and `libnginx-mod-stream` | `nginx.service`, enabled in every mode | | `coraza/` | `keel-overlay-coraza` | Keel's `libnginx-mod-http-coraza` 0.21.0 and `coreruleset` 4.25.1 (step 5), and `keel-overlay-nginx` | none: an Nginx module; `/usr/lib/keel/overlays/coraza/state` turns it on and off | diff --git a/packages/vip/debian/changelog b/packages/vip/debian/changelog new file mode 100644 index 00000000..40fb21f0 --- /dev/null +++ b/packages/vip/debian/changelog @@ -0,0 +1,10 @@ +keel-overlay-vip (0.1.0) trixie; urgency=medium + + * First release: the units of keel's service VIP on the WireGuard mesh + (handbook decision 0049, third round). keel-vip.service runs keel vip + tend, the controller with etcd, sandboxed with CAP_NET_ADMIN alone + and writing only /var/lib/keel/vip and /etc/wireguard, and drops every + VIP the node carries once it stops; installed disabled. + keel-vip-check.timer runs keel vip check at boot and every minute. + + -- Marcos Mendez Wed, 07 Oct 2026 12:00:00 +0000 diff --git a/packages/vip/debian/control b/packages/vip/debian/control new file mode 100644 index 00000000..905ed335 --- /dev/null +++ b/packages/vip/debian/control @@ -0,0 +1,30 @@ +Source: keel-overlay-vip +Section: admin +Priority: optional +Maintainer: KeelLinux maintainers +Uploaders: Marcos Mendez +Build-Depends: + debhelper-compat (= 13), +Standards-Version: 4.7.2 +Rules-Requires-Root: no +Vcs-Git: https://github.com/Keel-Linux/common.git -b 19.x [packages/vip] +Vcs-Browser: https://github.com/Keel-Linux/common/tree/19.x/packages/vip + +Package: keel-overlay-vip +Architecture: all +Depends: + iproute2, + keel (>= 0.20.0), + keel-overlay-wireguard, + wireguard-tools, + ${misc:Depends}, +Description: Keel overlay: the service VIP of a replicated pair + The VIP overlay of Keel Linux (handbook decision 0049): the units of + keel's VIP on the WireGuard mesh, and the overlay manifest keel reads, + installed as /usr/share/keel/overlays/vip.yaml (decision 0041). The code + is keel's (keel vip); this package ships only the units. + . + keel-vip.service is the controller with etcd, installed disabled and + stopped: keel spec apply enables it with the overlay. keel-vip-check.timer + runs keel vip check at boot and every minute in every mode; a node that + knows no VIP skips it. diff --git a/packages/vip/debian/copyright b/packages/vip/debian/copyright new file mode 100644 index 00000000..d1f5eef0 --- /dev/null +++ b/packages/vip/debian/copyright @@ -0,0 +1,25 @@ +Format: https://www.debian.org/doc/packaging-manuals/copyright-format/1.0/ +Upstream-Name: keel-overlay-vip +Upstream-Contact: KeelLinux maintainers +Source: https://github.com/Keel-Linux/common + +Files: * +Copyright: 2026 Keel Linux maintainers +License: GPL-3+ + +License: GPL-3+ + This program is free software; you can redistribute it and/or modify + it under the terms of the GNU General Public License as published by + the Free Software Foundation; either version 3 of the License, or + (at your option) any later version. + . + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU General Public License for more details. + . + You should have received a copy of the GNU General Public License + along with this program. If not, see . + . + On Debian systems, the complete text of the GNU General Public License + version 3 can be found in /usr/share/common-licenses/GPL-3. diff --git a/packages/vip/debian/rules b/packages/vip/debian/rules new file mode 100755 index 00000000..bd90e57c --- /dev/null +++ b/packages/vip/debian/rules @@ -0,0 +1,29 @@ +#!/usr/bin/make -f +# The overlay manifest, the units and the systemd preset sit beside +# debian/ (docs/manifest-v1.md, "Kinds, and where each file lives") and +# are installed under the names keel and systemd look them up by. The +# code they run is keel's (keel vip); this package ships only the units +# (handbook decision 0049, third round, point 1). + +PKG = debian/keel-overlay-vip + +%: + dh $@ + +execute_after_dh_auto_install: + install -D -m 0644 manifest.yaml $(PKG)/usr/share/keel/overlays/vip.yaml + install -D -m 0644 keel-vip.service \ + $(PKG)/usr/lib/systemd/system/keel-vip.service + install -D -m 0644 keel-vip-check.service \ + $(PKG)/usr/lib/systemd/system/keel-vip-check.service + install -D -m 0644 keel-vip-check.timer \ + $(PKG)/usr/lib/systemd/system/keel-vip-check.timer + install -D -m 0644 keel-overlay-vip.preset \ + $(PKG)/usr/lib/systemd/system-preset/20-keel-overlay-vip.preset + +# The controller is installed disabled and stopped, the state of a simple +# installation: keel spec apply enables it with the overlay. The check's +# timer runs in every mode. +override_dh_installsystemd: + dh_installsystemd --no-enable --no-start keel-vip.service + dh_installsystemd keel-vip-check.timer diff --git a/packages/vip/debian/source/format b/packages/vip/debian/source/format new file mode 100644 index 00000000..89ae9db8 --- /dev/null +++ b/packages/vip/debian/source/format @@ -0,0 +1 @@ +3.0 (native) diff --git a/packages/vip/keel-overlay-vip.preset b/packages/vip/keel-overlay-vip.preset new file mode 100644 index 00000000..d411fd9b --- /dev/null +++ b/packages/vip/keel-overlay-vip.preset @@ -0,0 +1,5 @@ +# keel-overlay-vip: the controller is off until keel spec apply enables +# the overlay (handbook decision 0041): Debian's presets enable every unit +# they do not name, on a first boot and on `systemctl preset-all`. The +# check's timer stays enabled; its service skips a node that knows no VIP. +disable keel-vip.service diff --git a/packages/vip/keel-vip-check.service b/packages/vip/keel-vip-check.service new file mode 100644 index 00000000..a889560e --- /dev/null +++ b/packages/vip/keel-vip-check.service @@ -0,0 +1,35 @@ +# keel-overlay-vip: keel vip check (handbook decision 0049): every peer +# asked the epoch of each VIP this node knows, a newer claim taken (an +# old primary that comes back drops the VIP at once), the VIP dropped +# where it is not held, and WireGuard's table and wg0.conf set again from +# what this node holds. Run at boot and every minute by +# keel-vip-check.timer; a node that knows no VIP has nothing to check. +[Unit] +Description=keel vip: learn newer claims of the VIPs this node knows +Documentation=https://github.com/Keel-Linux/keel/blob/main/docs/vip.md +After=network-online.target wg-quick@wg0.service +Wants=network-online.target +ConditionDirectoryNotEmpty=/var/lib/keel/vip + +[Service] +Type=oneshot +ExecStart=/usr/bin/keel vip check +CapabilityBoundingSet=CAP_NET_ADMIN +NoNewPrivileges=yes +PrivateTmp=yes +PrivateDevices=yes +ProtectSystem=strict +ReadWritePaths=/var/lib/keel/vip /etc/wireguard +ProtectHome=yes +ProtectKernelTunables=yes +ProtectKernelModules=yes +ProtectKernelLogs=yes +ProtectControlGroups=yes +ProtectClock=yes +ProtectHostname=yes +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK +RestrictNamespaces=yes +RestrictRealtime=yes +LockPersonality=yes +SystemCallArchitectures=native +SystemCallFilter=@system-service diff --git a/packages/vip/keel-vip-check.timer b/packages/vip/keel-vip-check.timer new file mode 100644 index 00000000..6b351436 --- /dev/null +++ b/packages/vip/keel-vip-check.timer @@ -0,0 +1,13 @@ +# keel-overlay-vip: keel vip check at boot and every minute (handbook +# decision 0049: "at boot and on a timer"). It runs in every mode: on a +# node that knows no VIP the service's condition skips it. +[Unit] +Description=keel vip: check the VIPs at boot and every minute + +[Timer] +OnBootSec=30s +OnUnitActiveSec=1min +AccuracySec=5s + +[Install] +WantedBy=timers.target diff --git a/packages/vip/keel-vip.service b/packages/vip/keel-vip.service new file mode 100644 index 00000000..6defd88b --- /dev/null +++ b/packages/vip/keel-vip.service @@ -0,0 +1,48 @@ +# keel-overlay-vip: the VIP's controller with etcd (handbook decision +# 0049, third round; keel's docs/vip.md). The holder renews its etcd +# lease (TTL 20 s) every 2 s and drops the VIP from wg0 after 10 s +# without a renewal; every member follows the claims in etcd and routes +# the VIP to its holder; the other node of the pair claims once the +# holder's lease expired. It changes wg0's addresses and WireGuard's +# allowed-ips, so it holds CAP_NET_ADMIN and nothing else, and writes +# only /var/lib/keel/vip and /etc/wireguard. ExecStopPost drops every VIP +# this node carries, however the controller stopped, so no VIP outlives +# the process that renews its lease. +[Unit] +Description=keel vip: the VIP's controller with etcd +Documentation=https://github.com/Keel-Linux/keel/blob/main/docs/vip.md +After=network-online.target etcd.service wg-quick@wg0.service +Wants=network-online.target +ConditionPathExists=/var/lib/keel/etcd/cluster.json + +[Service] +ExecStart=/usr/bin/keel vip tend +ExecStopPost=/usr/bin/keel vip tend --stopped +Restart=always +RestartSec=2 +CapabilityBoundingSet=CAP_NET_ADMIN +NoNewPrivileges=yes +PrivateTmp=yes +PrivateDevices=yes +ProtectSystem=strict +ReadWritePaths=/var/lib/keel/vip /etc/wireguard +StateDirectory=keel/vip +StateDirectoryMode=0700 +ProtectHome=yes +ProtectKernelTunables=yes +ProtectKernelModules=yes +ProtectKernelLogs=yes +ProtectControlGroups=yes +ProtectClock=yes +ProtectHostname=yes +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK +RestrictNamespaces=yes +RestrictRealtime=yes +LockPersonality=yes +SystemCallArchitectures=native +SystemCallFilter=@system-service +MemoryMax=128M +TasksMax=64 + +[Install] +WantedBy=multi-user.target diff --git a/packages/vip/manifest.yaml b/packages/vip/manifest.yaml new file mode 100644 index 00000000..9faf83af --- /dev/null +++ b/packages/vip/manifest.yaml @@ -0,0 +1,12 @@ +manifest_version: 1 +kind: overlay +name: vip +title: Service VIP +summary: The replicated pair's VIP on the mesh (0049); moved by keel vip +requires: [wireguard] +processes: + # the controller with etcd (keel vip tend): renews the holder's lease, + # drops the VIP 10 s after its last renewal, follows the claims and + # fails over; it runs only on a member of a formed etcd cluster + - name: keel-vip + unit: keel-vip.service From 95caca2f9193becdfc8a6a9a09ea960a8325bf1a Mon Sep 17 00:00:00 2001 From: navigator Date: Wed, 7 Oct 2026 18:30:49 +0000 Subject: [PATCH 2/4] fix: keel-vip.service is the root helper of the split controller From keel#81's security review: keel vip tend is now the root helper, which starts the unprivileged controller as its own transient unit. The helper keeps CAP_NET_ADMIN, takes CAP_DAC_OVERRIDE to reach the controller's 0600 socket, and reaches only AF_UNIX and AF_NETLINK. The unit has StartLimitIntervalSec=0, so a crash loop never leaves it stopped for good. --- packages/README.md | 2 +- packages/vip/debian/changelog | 10 ++++++--- packages/vip/debian/control | 3 ++- packages/vip/keel-vip-check.service | 1 + packages/vip/keel-vip.service | 35 +++++++++++++++++------------ 5 files changed, 32 insertions(+), 19 deletions(-) diff --git a/packages/README.md b/packages/README.md index d6a07aa2..7336c3ff 100644 --- a/packages/README.md +++ b/packages/README.md @@ -12,7 +12,7 @@ directory each, with its own changelog and version, released on its own | `installer/` | `keel-overlay-installer` | Keel's `inithooks` (>= 2.3.6+keel14), `confconsole` (>= 2.2.3+keel8), `keel` (>= 0.12.0) | none; its manifest names the first boot hooks the three ship | | `wireguard/` | `keel-overlay-wireguard` | trixie's `wireguard-tools` 1.0.20210914 | none; the interface is the instance spec's | | `etcd/` | `keel-overlay-etcd` | trixie's `etcd-server` 3.5.16, and `keel-overlay-wireguard`, which its manifest `requires` | `etcd.service` | -| `vip/` | `keel-overlay-vip` | `keel` (>= 0.20.0), whose `keel vip` the units run, and `keel-overlay-wireguard`, which its manifest `requires` | `keel-vip.service`, the controller with etcd; and `keel-vip-check.timer`, enabled in every mode | +| `vip/` | `keel-overlay-vip` | `keel` (>= 0.20.0), whose `keel vip` the units run, and `keel-overlay-wireguard`, which its manifest `requires` | `keel-vip.service`, the VIP's root helper with etcd, which starts its unprivileged controller as the transient `keel-vip-control`; and `keel-vip-check.timer`, enabled in every mode | | `crowdsec/` | `keel-overlay-crowdsec` | trixie's `crowdsec` 1.4.6-10 and `crowdsec-firewall-bouncer` 0.0.25 | `crowdsec.service`, `crowdsec-firewall-bouncer.service` | | `nginx/` | `keel-overlay-nginx` | trixie's `nginx` 1.26.3 and `libnginx-mod-stream` | `nginx.service`, enabled in every mode | | `coraza/` | `keel-overlay-coraza` | Keel's `libnginx-mod-http-coraza` 0.21.0 and `coreruleset` 4.25.1 (step 5), and `keel-overlay-nginx` | none: an Nginx module; `/usr/lib/keel/overlays/coraza/state` turns it on and off | diff --git a/packages/vip/debian/changelog b/packages/vip/debian/changelog index 40fb21f0..279fc3ca 100644 --- a/packages/vip/debian/changelog +++ b/packages/vip/debian/changelog @@ -2,9 +2,13 @@ keel-overlay-vip (0.1.0) trixie; urgency=medium * First release: the units of keel's service VIP on the WireGuard mesh (handbook decision 0049, third round). keel-vip.service runs keel vip - tend, the controller with etcd, sandboxed with CAP_NET_ADMIN alone - and writing only /var/lib/keel/vip and /etc/wireguard, and drops every - VIP the node carries once it stops; installed disabled. + tend, the root helper, with CAP_NET_ADMIN and CAP_DAC_OVERRIDE (to + reach the controller's 0600 socket) alone, AF_UNIX and + AF_NETLINK only, writing only /var/lib/keel/vip and /etc/wireguard; + it starts the controller as a transient unit with a dynamic user and + no capability, and drops every VIP the node carries once it stops; + StartLimitIntervalSec=0, so a crash loop never leaves it stopped for + good; installed disabled. keel-vip-check.timer runs keel vip check at boot and every minute. -- Marcos Mendez Wed, 07 Oct 2026 12:00:00 +0000 diff --git a/packages/vip/debian/control b/packages/vip/debian/control index 905ed335..e77eed1c 100644 --- a/packages/vip/debian/control +++ b/packages/vip/debian/control @@ -24,7 +24,8 @@ Description: Keel overlay: the service VIP of a replicated pair installed as /usr/share/keel/overlays/vip.yaml (decision 0041). The code is keel's (keel vip); this package ships only the units. . - keel-vip.service is the controller with etcd, installed disabled and + keel-vip.service is the VIP's root helper with etcd, which starts the + unprivileged controller as its own transient unit; installed disabled and stopped: keel spec apply enables it with the overlay. keel-vip-check.timer runs keel vip check at boot and every minute in every mode; a node that knows no VIP skips it. diff --git a/packages/vip/keel-vip-check.service b/packages/vip/keel-vip-check.service index a889560e..55c53c7c 100644 --- a/packages/vip/keel-vip-check.service +++ b/packages/vip/keel-vip-check.service @@ -4,6 +4,7 @@ # where it is not held, and WireGuard's table and wg0.conf set again from # what this node holds. Run at boot and every minute by # keel-vip-check.timer; a node that knows no VIP has nothing to check. +# It is a client of the members' channel only: it opens no port. [Unit] Description=keel vip: learn newer claims of the VIPs this node knows Documentation=https://github.com/Keel-Linux/keel/blob/main/docs/vip.md diff --git a/packages/vip/keel-vip.service b/packages/vip/keel-vip.service index 6defd88b..06463303 100644 --- a/packages/vip/keel-vip.service +++ b/packages/vip/keel-vip.service @@ -1,26 +1,33 @@ -# keel-overlay-vip: the VIP's controller with etcd (handbook decision -# 0049, third round; keel's docs/vip.md). The holder renews its etcd -# lease (TTL 20 s) every 2 s and drops the VIP from wg0 after 10 s -# without a renewal; every member follows the claims in etcd and routes -# the VIP to its holder; the other node of the pair claims once the -# holder's lease expired. It changes wg0's addresses and WireGuard's -# allowed-ips, so it holds CAP_NET_ADMIN and nothing else, and writes -# only /var/lib/keel/vip and /etc/wireguard. ExecStopPost drops every VIP -# this node carries, however the controller stopped, so no VIP outlives -# the process that renews its lease. +# keel-overlay-vip: the VIP's root helper with etcd (handbook decision +# 0049, third round; keel's docs/vip.md), split as keel#75 splits an +# invite. This unit is the root helper: it alone changes wg0's addresses +# and WireGuard's allowed-ips, each checked against the pair record, so +# it holds CAP_NET_ADMIN, and CAP_DAC_OVERRIDE to connect to the +# controller's 0600 socket, which the controller's dynamic user owns; +# nothing else. It reaches nothing but systemd and the kernel (AF_UNIX, +# AF_NETLINK), and writes only /var/lib/keel/vip and /etc/wireguard. It starts the controller, which faces etcd and the +# overlay, as the transient unit keel-vip-control: a dynamic user, no +# capability at all, its socket 0600 in a 0700 runtime directory, its +# peer checked by SO_PEERCRED against the unit's MainPID; it sends it the +# etcd client certificate's key as a memfd. The holder renews its etcd +# lease (TTL 20 s) every 2 s and carries the VIP only while the last +# renewal the majority confirmed is under 10 s old. ExecStopPost drops +# every VIP this node carries, however the helper stopped, and the unit +# is never left stopped for good: a crash loop is retried. [Unit] -Description=keel vip: the VIP's controller with etcd +Description=keel vip: the VIP's root helper with etcd Documentation=https://github.com/Keel-Linux/keel/blob/main/docs/vip.md After=network-online.target etcd.service wg-quick@wg0.service Wants=network-online.target ConditionPathExists=/var/lib/keel/etcd/cluster.json +StartLimitIntervalSec=0 [Service] ExecStart=/usr/bin/keel vip tend ExecStopPost=/usr/bin/keel vip tend --stopped Restart=always -RestartSec=2 -CapabilityBoundingSet=CAP_NET_ADMIN +RestartSec=5 +CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE NoNewPrivileges=yes PrivateTmp=yes PrivateDevices=yes @@ -35,7 +42,7 @@ ProtectKernelLogs=yes ProtectControlGroups=yes ProtectClock=yes ProtectHostname=yes -RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK +RestrictAddressFamilies=AF_UNIX AF_NETLINK RestrictNamespaces=yes RestrictRealtime=yes LockPersonality=yes From 10bb8601ec815b95f759973c6cb11d51b1a13efa Mon Sep 17 00:00:00 2001 From: navigator Date: Wed, 7 Oct 2026 20:55:20 +0000 Subject: [PATCH 3/4] fix: keel-vip.service holds CAP_NET_ADMIN alone keel#81's re-review: the helper and the controller meet on an abstract unix socket of the network namespace they share, each end checked by SO_PEERCRED (the helper's against the controller's unit's MainPID), so the helper needs no CAP_DAC_OVERRIDE to reach a socket the controller's dynamic user owns. --- packages/vip/debian/changelog | 3 +-- packages/vip/keel-vip.service | 24 ++++++++++++------------ 2 files changed, 13 insertions(+), 14 deletions(-) diff --git a/packages/vip/debian/changelog b/packages/vip/debian/changelog index 279fc3ca..1a7f6a3d 100644 --- a/packages/vip/debian/changelog +++ b/packages/vip/debian/changelog @@ -2,8 +2,7 @@ keel-overlay-vip (0.1.0) trixie; urgency=medium * First release: the units of keel's service VIP on the WireGuard mesh (handbook decision 0049, third round). keel-vip.service runs keel vip - tend, the root helper, with CAP_NET_ADMIN and CAP_DAC_OVERRIDE (to - reach the controller's 0600 socket) alone, AF_UNIX and + tend, the root helper, with CAP_NET_ADMIN alone, AF_UNIX and AF_NETLINK only, writing only /var/lib/keel/vip and /etc/wireguard; it starts the controller as a transient unit with a dynamic user and no capability, and drops every VIP the node carries once it stops; diff --git a/packages/vip/keel-vip.service b/packages/vip/keel-vip.service index 06463303..01d3b711 100644 --- a/packages/vip/keel-vip.service +++ b/packages/vip/keel-vip.service @@ -2,18 +2,18 @@ # 0049, third round; keel's docs/vip.md), split as keel#75 splits an # invite. This unit is the root helper: it alone changes wg0's addresses # and WireGuard's allowed-ips, each checked against the pair record, so -# it holds CAP_NET_ADMIN, and CAP_DAC_OVERRIDE to connect to the -# controller's 0600 socket, which the controller's dynamic user owns; -# nothing else. It reaches nothing but systemd and the kernel (AF_UNIX, -# AF_NETLINK), and writes only /var/lib/keel/vip and /etc/wireguard. It starts the controller, which faces etcd and the +# it holds CAP_NET_ADMIN and nothing else. It reaches nothing but systemd +# and the kernel (AF_UNIX, AF_NETLINK), and writes only /var/lib/keel/vip +# and /etc/wireguard. It starts the controller, which faces etcd and the # overlay, as the transient unit keel-vip-control: a dynamic user, no -# capability at all, its socket 0600 in a 0700 runtime directory, its -# peer checked by SO_PEERCRED against the unit's MainPID; it sends it the -# etcd client certificate's key as a memfd. The holder renews its etcd -# lease (TTL 20 s) every 2 s and carries the VIP only while the last -# renewal the majority confirmed is under 10 s old. ExecStopPost drops -# every VIP this node carries, however the helper stopped, and the unit -# is never left stopped for good: a crash loop is retried. +# capability at all, on an abstract unix socket of the namespace they +# share, each end checked by SO_PEERCRED (the helper's against the +# unit's MainPID); it sends it the etcd client certificate's key as a +# memfd. The holder renews its etcd lease (TTL 20 s) every 2 s and +# carries the VIP only while the last renewal the majority confirmed is +# under 10 s old. ExecStopPost drops every VIP this node carries, however +# the helper stopped, and the unit is never left stopped for good: a +# crash loop is retried. [Unit] Description=keel vip: the VIP's root helper with etcd Documentation=https://github.com/Keel-Linux/keel/blob/main/docs/vip.md @@ -27,7 +27,7 @@ ExecStart=/usr/bin/keel vip tend ExecStopPost=/usr/bin/keel vip tend --stopped Restart=always RestartSec=5 -CapabilityBoundingSet=CAP_NET_ADMIN CAP_DAC_OVERRIDE +CapabilityBoundingSet=CAP_NET_ADMIN NoNewPrivileges=yes PrivateTmp=yes PrivateDevices=yes From 7bef31817360aca244fffef98edab7ab05d1425f Mon Sep 17 00:00:00 2001 From: navigator Date: Wed, 7 Oct 2026 22:21:30 +0000 Subject: [PATCH 4/4] docs: keel-vip.service's helper binds a fresh socket name first --- packages/vip/keel-vip.service | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/packages/vip/keel-vip.service b/packages/vip/keel-vip.service index 01d3b711..9caa1f60 100644 --- a/packages/vip/keel-vip.service +++ b/packages/vip/keel-vip.service @@ -7,7 +7,8 @@ # and /etc/wireguard. It starts the controller, which faces etcd and the # overlay, as the transient unit keel-vip-control: a dynamic user, no # capability at all, on an abstract unix socket of the namespace they -# share, each end checked by SO_PEERCRED (the helper's against the +# share, under a fresh random name the helper binds before it starts the +# controller, each end checked by SO_PEERCRED (the helper's against the # unit's MainPID); it sends it the etcd client certificate's key as a # memfd. The holder renews its etcd lease (TTL 20 s) every 2 s and # carries the VIP only while the last renewal the majority confirmed is