diff --git a/packages/keel-core/debian/changelog b/packages/keel-core/debian/changelog index c6bce52..ffd56c5 100644 --- a/packages/keel-core/debian/changelog +++ b/packages/keel-core/debian/changelog @@ -1,3 +1,15 @@ +keel-core (0.1.1) trixie; urgency=medium + + * Monit starts after the units of Core's processes, ssh.service, + webmin.service and postfix.service: a drop-in, + /usr/lib/systemd/system/monit.service.d/keel-core.conf, ordering only. + Started beside them, monit's first cycle after a boot found webmin and + postfix inactive (Keel-Linux/keel#61, item 2). keel writes no + `set daemon ... with start delay` instead: that line is global, and + keel leaves the operator's cycle alone (decision 0021). + + -- Marcos Mendez Fri, 02 Oct 2026 06:00:00 +0000 + keel-core (0.1.0) trixie; urgency=medium * First release (handbook decision 0041, first implementation, step 4). diff --git a/packages/keel-core/debian/control b/packages/keel-core/debian/control index 6f8f1ff..2370ea2 100644 --- a/packages/keel-core/debian/control +++ b/packages/keel-core/debian/control @@ -23,7 +23,9 @@ Description: Keel Core, the appliance every Keel appliance is built on The appliance manifest of Keel Core (handbook decisions 0036 and 0041), installed as /usr/share/keel/appliances/core.yaml: the four overlays Core carries with their state in each installation mode, and Core's own - processes (sshd, Webmin and postfix) with their ports and checks. + processes (sshd, Webmin and postfix) with their ports and checks. A + systemd drop-in starts monit after those three units, so its first cycle + does not find them still starting. . It depends on the four overlay packages, installer, wireguard, etcd and crowdsec, and on keel 0.13.0, the first keel that converges the overlays' diff --git a/packages/keel-core/debian/rules b/packages/keel-core/debian/rules index bf9a692..dd791b2 100755 --- a/packages/keel-core/debian/rules +++ b/packages/keel-core/debian/rules @@ -9,3 +9,5 @@ execute_after_dh_auto_install: install -D -m 0644 manifest.yaml \ debian/keel-core/usr/share/keel/appliances/core.yaml + install -D -m 0644 monit-after-core.conf \ + debian/keel-core/usr/lib/systemd/system/monit.service.d/keel-core.conf diff --git a/packages/keel-core/monit-after-core.conf b/packages/keel-core/monit-after-core.conf new file mode 100644 index 0000000..c26205f --- /dev/null +++ b/packages/keel-core/monit-after-core.conf @@ -0,0 +1,8 @@ +# Installed by keel-core as /usr/lib/systemd/system/monit.service.d/. +# Monit's checks of Keel Core are the units of the manifest's processes +# (manifest.yaml, beside debian/). Started beside them, monit's first +# cycle after a boot found webmin and postfix inactive (keel#61), so +# monit starts after them. Ordering only: a unit that fails does not +# keep monit from starting, and monit then reports it. +[Unit] +After=ssh.service webmin.service postfix.service diff --git a/tests/README.md b/tests/README.md index 970998d..b539732 100644 --- a/tests/README.md +++ b/tests/README.md @@ -70,9 +70,10 @@ container: keel inspect --output /root/emitted.yaml keel spec apply --system --spec /root/emitted.yaml # 0 change(s) -`inspect` cannot read the monitor's channels back (they are in -`/etc/keel/monitor.json`, which it does not repeat), so the channel is -added to the emitted file before it is applied, as its report says. And +Before keel 0.15.1, `inspect` could not read the monitor's channels back +(they are in `/etc/keel/monitor.json`), so the channel was added to the +emitted file before it was applied; keel 0.15.1 reads them back, tokens +by file (keel#60), and the emitted file applies as it is. And Monit's `/etc/keel/monit/keel-manifest.conf` checks sshd, webmin and postfix and nothing else. Core has no web shell: TurnKey removed shellinabox in 18.0, so the manifest does not declare the `webshell` of diff --git a/tests/package.bats b/tests/package.bats index 487617a..468baf6 100644 --- a/tests/package.bats +++ b/tests/package.bats @@ -53,10 +53,43 @@ print(eval(sys.argv[2]))' "$PACKAGE_DIR/manifest.yaml" "$1" [[ "$output" == "-rw-r--r-- root/root "* ]] } -@test "it installs nothing but the manifest and its documentation" { +@test "it installs the manifest, monit's ordering and its documentation" { run bash -c "dpkg-deb -c '$DEB' | awk '{print \$6}' | grep -v '/\$' | sort" [ "$status" -eq 0 ] - [ "$output" = $'./usr/share/doc/keel-core/changelog.gz\n./usr/share/doc/keel-core/copyright\n./usr/share/keel/appliances/core.yaml' ] + [ "$output" = $'./usr/lib/systemd/system/monit.service.d/keel-core.conf\n./usr/share/doc/keel-core/changelog.gz\n./usr/share/doc/keel-core/copyright\n./usr/share/keel/appliances/core.yaml' ] +} + +# keel#61: monit's first cycle after boot found webmin and postfix +# inactive, because monit started beside them; its checks are the units +# of the manifest's processes, so monit starts after those units +@test "monit starts after the units of Core's processes, and only that" { + dpkg-deb -x "$DEB" "$BUILD/root" + dropin="$BUILD/root/usr/lib/systemd/system/monit.service.d/keel-core.conf" + run grep -v '^#' "$dropin" + [ "$status" -eq 0 ] + [ "$output" = $'[Unit]\nAfter=ssh.service webmin.service postfix.service' ] + units=$(manifest '" ".join(p["unit"] for p in m["processes"])') + [ "$(sed -n 's/^After=//p' "$dropin")" = "$units" ] +} + +@test "monit's ordering is a plain file of mode 0644, owned by root" { + run bash -c "dpkg-deb -c '$DEB' | grep ' ./usr/lib/systemd/system/monit.service.d/keel-core.conf$'" + [ "$status" -eq 0 ] + [[ "$output" == "-rw-r--r-- root/root "* ]] +} + +@test "systemd reads the ordering without a complaint" { + if ! command -v systemd-analyze >/dev/null; then + skip "systemd-analyze is not installed" + fi + dpkg-deb -x "$DEB" "$BUILD/root" + mkdir -p "$BUILD/units" + printf '[Service]\nExecStart=/bin/true\n' > "$BUILD/units/monit.service" + mkdir -p "$BUILD/units/monit.service.d" + cp "$BUILD/root/usr/lib/systemd/system/monit.service.d/keel-core.conf" \ + "$BUILD/units/monit.service.d/" + run systemd-analyze verify --man=no "$BUILD/units/monit.service" + [[ "$output" != *"keel-core.conf"* ]] } # the manifest: the Core table of decision 0041