Repository navigation
fix: apache2ctl configtest at first boot, not in the build - #15
Open
marcos-mendez wants to merge 2 commits into
Open
marcos-mendez wants to merge 2 commits into
marcos-mendez wants to merge 2 commits into
Conversation
added 2 commits
September 30, 2026 11:10
On common 19.x no layer carries /etc/ssl/private/cert.pem: removelists-final takes every private key out of the image and the machine makes its own at the first boot (keel-core#8). wordpress.conf and mods-available/ssl.conf both name that file, and the parent layer arrives without it, so the configtest in conf.d/main could only fail, and the layer no longer built. The check moves to firstboot.d/40wordpress, after 15regen-sslcert and before Apache is restarted, the way keel-nodebb runs nginx -t in its own hook and keel-lamp runs configtest in its boot test. A failing configtest is fatal there and Apache is not restarted. conf.d/main asserts that it left no cert.pem or cert.key, and the boot test reads the assembled image before it boots and fails on any certificate or private key from the list common removes.
A failed apache2ctl configtest is fatal to 40wordpress, not to the first boot: inithooks logs the failure and runs the next hook. The changelog says so now, and the hook logs a line when configtest passes, which the boot test's new bt_configtest_verdict reads in the inithooks log. bt_shared_keys_verdict also names a dangling symlink where a key would be, and passes ca-certificates.crt and ssh_config beside the keys.
2 of 4 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On common 19.x
conf.d/mainfailed atapache2ctl configtest:wordpress.conf(443 vhost) andmods-available/ssl.confname/etc/ssl/private/cert.pem, which common'sremovelists-finalnow takes out of every layer (keel-core#8). The parent layer arrives without it, so the check could only fail.firstboot.d/40wordpressrunsapache2ctl configtestafter 15regen-sslcert and before restarting Apache. A failure is fatal to 40wordpress, which then does not restart Apache; inithooks logs it and runs the next hook. Same place keel-nodebb runsnginx -t(its 40nodebb hook); keel-lamp runs configtest in its boot test.conf.d/maindrops the build time configtest and asserts it left nocert.pemorcert.key.bt_shared_keys_verdictreads the assembled rootfs before the first boot and fails on any certificate or private key from common's removelist (TLS pair, snakeoil, miniserv.pem, turnkey-ssl copies, SSH host keys), dangling symlinks included;bt_configtest_verdictreads the inithooks log for the passing configtest line.Required check expected to fail:
appliance / boot-published-layeris required by branch protection, and it boots the layer the mirror publishes, not this branch. That layer carries 8 private keys (cert.pem,cert.key,miniserv.pem, the turnkey-ssl pair, 3 SSH host keys) plus 3 SSH host.pubfiles, which the new verdict names. It clears only once a layer built from this fix is published, which is an attended release by the maintainer.Test plan
bats tests/all pass,COVERAGE_THRESHOLD=97 tests/coverage.shpasses🤖 Generated with Claude Code
https://claude.ai/code/session_01CPHHkPGkk3tgjomjB1bq4p