Skip to content

fix: Keel screens follow the appliance manifest, and fit 80x24 - #19

Merged
marcos-mendez merged 3 commits into
masterfrom
fix/menus-from-the-manifest
Oct 2, 2026
Merged

marcos-mendez merged 3 commits into
masterfrom
fix/menus-from-the-manifest

Conversation

@marcos-mendez

@marcos-mendez marcos-mendez commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

The maintainer's review of the Keel Web step 8 image on Proxmox: Database mode on an appliance with no database, WireGuard in the first menu of a simple installation, a Keel Cloud screen asking for a key nobody can generate yet, and menu descriptions cut at the box edge.

What changes

Menus from the manifest (decision 0041). keelmenu.py reads appliance.name and installation.mode from the spec and asks keel to resolve the chain (keel.manifest.facts.gather, the resolution behind keel manifest show --resolved and keel spec validate), so confconsole holds no second copy of the rules.

Entry Offered when
View, Apply, Show drift, Export spec always
Database mode a mariadb or postgresql data service is in the chain (an overlay that provides it, or an application service). Not on Keel Core or Keel Web
Overlay network wireguard is in the chain; in the Instance menu in cloud_simple/cloud_advanced or once the spec enables or configures the overlay, otherwise behind a new Advanced entry
Keel Cloud only when /etc/keel/cloud-endpoint holds an endpoint; hidden by default

A chain that cannot be read (no keel, no manifests as on pre-0041 images such as the WordPress templates, no appliance.name) keeps the screens as before, the overlay behind Advanced.

Keel Cloud gated. The Instance entry is hidden, run by name it says Keel Cloud is not available, and keelfirstboot.py cloud, which inithooks' 80keel-cloud runs, asks and stores nothing (keel-init and a preseeded HUB_APIKEY included). The screen, its tests and the first boot step stay; writing /etc/keel/cloud-endpoint turns them on. inithooks is not changed: 80keel-cloud only calls keelfirstboot.py cloud, which carries the gate, so there is nothing to merge after inithooks keel17.

Nothing cut at 80x24. keelfit.py: a menu is as wide as its widest choice or text line, a message box as its text, both up to what the terminal leaves (keelbanner.available), so no box is drawn over the backtitle; an item is shortened with an ellipsis only past the full width. Show drift stacks its table two lines a field when it is wider than the box (every row wrapped in two at 80 columns). The overlay screen lists one line a peer, at most three, so its menu keeps its rows (two peers drew the menu over its buttons). The Keel descriptions were shortened and a test holds every Instance menu to 80 columns.

Overlay address wording. The Address form says the suggestion is this node's address on Keel's private mesh, randomly generated, not a LAN address; the first node keeps it, the others take ::2, ::3 on the same /64; the port is the UDP port the other nodes reach.

Found, not changed here

The installed overlay manifests name screens confconsole does not ship: wireguard.yaml has screen: /usr/lib/confconsole/plugins.d/Networking/wireguard.py (the screen is Instance/Overlay_network.py) and crowdsec.yaml has Security/crowdsec.py (no CrowdSec screen exists). The rules here key on the overlay and the engine, not on that path.

Test plan

  • set -o pipefail; coverage run --branch -m pytest tests: 789 passed, 7 skipped; 100 percent lines and branches over the measured package, which gains keelfit and keelmenu; with keel's library on the path 796 passed (the real-resolution tests run)
  • confconsole 2.2.3+keel12 built and installed with dpkg on the step 8 Keel Web and Keel Core images in LXC on the test VM; keelmenu.machine() resolves web (core, web) and core with no data engine; keelfirstboot.py cloud skips with and without _TURNKEY_INIT
  • Every Keel menu and screen captured at 80x24 and 100x30: Advanced Menu, Instance (Web and Core, no Database mode), Advanced, Overlay network with no address and with two peers, Address, Add peer, Remove peer, Apply/Export/Show drift/View spec, Core in cloud_simple (Overlay in the menu), Keel Cloud with the flag on, and run by name with it off
  • Database mode screens on a MariaDB or WordPress image built with manifests (none of the step 8 images carries a database)

Review follow-ups (9d80eda, 1f96eb9)

  • /etc/keel/cloud-endpoint must hold one https URL with a host (bracketed IPv6 allowed), in a root-owned regular file not writable by group or others; anything else keeps Keel Cloud hidden and is logged. Format in docs/Instance.rst.
  • keelfit never passes dialog a size of 0 (tested at 8 columns).
  • Database mode also shows where the description declares database.server, and for Redis: the engines are one set, keelmenu.DATA_ENGINES = {"mariadb", "postgresql", "redis"}.
  • Gap, not faked: keel validates primary/replica for Redis (and PostgreSQL) but keel spec apply converges MariaDB only (system/database.py returns a note for any other engine), and keel-redis's boot test expects standalone only. So Redis gets Database mode > Standalone, no Cloud submenu, and the first boot asks it no role. PostgreSQL loses the Cloud submenu for the same reason. Adding an engine to REPLICATING_ENGINES turns it on once keel applies it.

navigator added 3 commits October 2, 2026 13:47
The maintainer's screenshots of the Keel Web step 8 image on Proxmox
showed Database mode on an appliance with no database, WireGuard in the
first menu of a simple installation, a Keel Cloud screen asking for a
key nobody can generate, and descriptions cut at the box edge.

keelmenu.py reads the appliance the spec names, resolved along its chain
by keel itself (keel.manifest.facts.gather, decision 0041), and the
installation mode: Database mode only with a mariadb or postgresql data
service in the chain; Overlay network in the menu in the cloud modes or
once the overlay is in use, behind a new Advanced entry otherwise; Keel
Cloud only once /etc/keel/cloud-endpoint names the service, which also
gates the first boot step 80keel-cloud runs. A chain that cannot be read
keeps the screens a machine had.

keelfit.py sizes the boxes: a menu as wide as its widest choice or line,
a message box as its text, both up to what the terminal leaves, so
nothing is cut and nothing is drawn over the backtitle. Show drift
stacks its table when it is wider than the box, the overlay screen lists
one line a peer, and the Keel descriptions fit 80 columns, held by a
test. The overlay address text says it is this node's address on Keel's
private mesh, randomly generated, not a LAN address.
On a terminal of 8 columns the box had 0 columns for its text, so
text_rows was asked to wrap at 0, and a box height of 0 is dialog's own
autosize, which draws over the backtitle. The text gets at least one
column and box() at least one row and one column; text_box goes through
box(). Review of confconsole#19.
…gine

Review of confconsole#19 and the maintainer's Redis request.

/etc/keel/cloud-endpoint turns Keel Cloud on only when it holds one
https URL with a host (a bracketed IPv6 literal allowed), in a regular
file root owns that neither group nor others can write. Anything else
keeps the screens hidden and logs why; no file stays quiet.
docs/Instance.rst gives the format.

Database mode shows for a mariadb, postgresql or redis data service,
one set (keelmenu.DATA_ENGINES), and wherever the description declares
database.server, even when the chain resolves with no engine. Its
Cloud roles are offered only for an engine whose replication keel
applies: keel validates a Redis or PostgreSQL primary and replica but
converges MariaDB's alone (system/database.py notes the others and
changes nothing), so those engines get Standalone, and the first boot
asks them no role instead of writing one nothing makes.
@marcos-mendez
marcos-mendez merged commit 1ef7a9e into master Oct 2, 2026
2 checks passed
marcos-mendez pushed a commit that referenced this pull request Oct 2, 2026
The role screen change moves to keel13: master's keel12 is the Instance
menu from the appliance manifest (#19).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant