Skip to content

fix: apache2ctl configtest at first boot, not in the build - #15

Open
marcos-mendez wants to merge 2 commits into
masterfrom
fix/configtest-at-first-boot
Open

marcos-mendez wants to merge 2 commits into
masterfrom
fix/configtest-at-first-boot

Conversation

@marcos-mendez

@marcos-mendez marcos-mendez commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

On common 19.x conf.d/main failed at apache2ctl configtest: wordpress.conf (443 vhost) and mods-available/ssl.conf name /etc/ssl/private/cert.pem, which common's removelists-final now takes out of every layer (keel-core#8). The parent layer arrives without it, so the check could only fail.

  • firstboot.d/40wordpress runs apache2ctl configtest after 15regen-sslcert and before restarting Apache. A failure is fatal to 40wordpress, which then does not restart Apache; inithooks logs it and runs the next hook. Same place keel-nodebb runs nginx -t (its 40nodebb hook); keel-lamp runs configtest in its boot test.
  • conf.d/main drops the build time configtest and asserts it left no cert.pem or cert.key.
  • Boot test: bt_shared_keys_verdict reads the assembled rootfs before the first boot and fails on any certificate or private key from common's removelist (TLS pair, snakeoil, miniserv.pem, turnkey-ssl copies, SSH host keys), dangling symlinks included; bt_configtest_verdict reads the inithooks log for the passing configtest line.
  • Changelog 19.0 (6); COVERAGE.md updated (238 bats tests, 99.16 percent, lowest file 97.83, gate stays 97).

Required check expected to fail: appliance / boot-published-layer is required by branch protection, and it boots the layer the mirror publishes, not this branch. That layer carries 8 private keys (cert.pem, cert.key, miniserv.pem, the turnkey-ssl pair, 3 SSH host keys) plus 3 SSH host .pub files, which the new verdict names. It clears only once a layer built from this fix is published, which is an attended release by the maintainer.

Test plan

  • bats tests/ all pass, COVERAGE_THRESHOLD=97 tests/coverage.sh passes
  • layer builds on common 19.x
  • boot test on the rebuilt layer: no key in the assembled image, configtest passing in the inithooks log

🤖 Generated with Claude Code

https://claude.ai/code/session_01CPHHkPGkk3tgjomjB1bq4p

navigator added 2 commits September 30, 2026 11:10
On common 19.x no layer carries /etc/ssl/private/cert.pem: removelists-final
takes every private key out of the image and the machine makes its own at
the first boot (keel-core#8). wordpress.conf and mods-available/ssl.conf both
name that file, and the parent layer arrives without it, so the configtest in
conf.d/main could only fail, and the layer no longer built.

The check moves to firstboot.d/40wordpress, after 15regen-sslcert and before
Apache is restarted, the way keel-nodebb runs nginx -t in its own hook and
keel-lamp runs configtest in its boot test. A failing configtest is fatal
there and Apache is not restarted.

conf.d/main asserts that it left no cert.pem or cert.key, and the boot test
reads the assembled image before it boots and fails on any certificate or
private key from the list common removes.
A failed apache2ctl configtest is fatal to 40wordpress, not to the first
boot: inithooks logs the failure and runs the next hook. The changelog says
so now, and the hook logs a line when configtest passes, which the boot
test's new bt_configtest_verdict reads in the inithooks log.

bt_shared_keys_verdict also names a dangling symlink where a key would be,
and passes ca-certificates.crt and ssh_config beside the keys.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant