Repository navigation
fix: inspect, confirm and monit on a Keel Core (keel#60, keel#61) - #64
Merged
Merged
Conversation
The bugs of the maintainer's screenshots of the Core image (2026-10-02): - inspect reads keel-<name>-<version>-<codename>-<arch> in /etc/turnkey_version, as a Keel image writes it; - instance.fqdn is no longer required: no hook asks for it, so inspect exited 13 on every new appliance; - hub.api_key references the Keel Cloud key's file when the first boot stored one, found by its presence alone; - an allow-hotplug interface the live machine does not have is left out (the image's eth1 placeholder); - security.updates_at_first_boot is read from the line 95secupdates now leaves before the update posture, which said force after Skip; - keel network confirm with nothing waiting says how the last change ended, from /var/lib/keel/network/last.json: already confirmed (exit 0) or reverted; - keel.conf sets monit's interface to a root-only Unix socket, so monit summary and status work, with no network listener. keel#60: inspect reads the monitor's channels back from monitor.json, tokens and URL files by reference; diff withholds observed channel values too. keel#61 item 1: a comment-only CrowdSec online_api_credentials.yaml counts as absent. Closes #60
This was referenced Oct 2, 2026
Merged
Review of #64. The outcome of a confirmation or a revert is recorded after the marker is cleared and the timers disarmed, and a record that cannot be written (a full disk) is reported as a note instead of crashing: before, it could leave the marker and let the timer revert a change the operator had confirmed. Arming a change removes the previous record, so an older confirmation never answers for a change whose end recorded nothing; a record that cannot be removed refuses the change before anything moves. The keelcore fixture's cloud_api_key is committed: a global *_key ignore rule had left it out, and the repository's .gitignore now excepts it. inithooks' record ships in 2.3.6+keel16, not keel15.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The keel bugs in the maintainer's screenshots of the Core image (2026-10-02), plus keel#60 and item 1 of keel#61. keel 0.15.1.
Root causes
appliance: not inferred, header "unknown appliance"probe_applianceaccepted only theturnkey-prefix; a Keel image writeskeel-core-19.0-trixie-amd64keel-read liketurnkey-inspectexits 13 on a fresh Coreinstance.fqdnwas inREQUIRED, whose rule is "a hook prompts when unset"; no hook asks for it, apply skips/etc/hostswithout it, and no appliance has one out of the boxREQUIRED(still reported as not inferred)hub.api_key: skipwith a Keel Cloud key savedprobe_hublooked only for a TurnKey Hub registration/etc/keel/secrets/cloud_api_keygives{file: <secrets-dir>/cloud_api_key}, never readeth1the container does not haveallow-hotplug eth1placeholder stanza, and inspect reported every stanza/sys/class/netis left out with a report line;autoones and offline roots unchangedupdates_at_first_boot: forceafter Skip/var/lib/inithooks/sec-updates, which inithooks' 95secupdates now writes (Keel-Linux/inithooks#33, keel16)/var/lib/keel/network/last.json(0600); already confirmed exits 0 and says so, reverted is called revertedmonit summaryalways failskeel.confsetsset httpd unixsocket /run/monit.sock uid root gid root permission 0600+allow localhost: root-only socket, no network listener (decision 0021). monit 5.34.3 supports it; checked withmonit -t -v/etc/keel/monitor.jsononline_api_credentials.yamlread as registeredkeel#61 item 2 (monit's first cycle) is fixed in keel-core (a monit drop-in ordered after Core's units); its PR links here.
Tests
Tests written first, then the code. 2308 pass, 8 skip; coverage 99% (same 12 lines missed as on main, all new code covered). The real-monit tests ran against monit 5.34.3 via
KEEL_MONIT. New fixturetests/fixtures/inspect/keelcoreis a fresh Core after first boot.Real test
LXC container from
debian-13-keel-core_19.0-3+step7b-20261001_amd64.tar.zston the test VM, with keel 0.15.1 and the inithooks, confconsole and keel-core packages of their PRs (built before the renumbering to keel16 and keel11) installed before the first boot. The review fixes (record last, forget on arm) are covered by unit tests:inspect:
core 19.0 (trixie, amd64), exit 0, no eth1,updates_at_first_boot: skip,hub.api_key: {file: ...cloud_api_key},monitor.notifyread back;emitted spec (with the overlay states inspect cannot infer added) re-applied: 0 changes;
overlay confirmed from
lxc-attach, then from the console: "already confirmed ... it stays", exit 0;monit summaryworks;/run/monit.sockissrw------- root root; no TCP listener;container destroyed afterwards.
CI green
Review
Closes #60. Refs #61.