Skip to content

feat: the spec's cloud section and keel cloud (0046) - #68

Draft
marcos-mendez wants to merge 3 commits into
mainfrom
feat/spec-cloud-section
Draft

marcos-mendez wants to merge 3 commits into
mainfrom
feat/spec-cloud-section

Conversation

@marcos-mendez

Copy link
Copy Markdown
Collaborator

The spec gains a cloud section for Keel Cloud (handbook decision 0046, proposed in handbook#39), additive under version: 1, and keel cloud runs Keel Cloud's node agent from the keel-overlay-cloud package of Keel-Linux/keel-cloud.

  • cloud.endpoint (https only, no path), cloud.api_key (skip or a file reference), cloud.entry_secret (a file reference), cloud.set (a DNS label, required with a key), cloud.ca_file. Secrets are file references only, never generate.
  • keel only validates it; diff reports cloud: not compared. The agent writes network.overlay.wireguard.peers, which spec apply --system converges and diff compares as before.
  • keel cloud ... execs keel-cloud-node ...; without the package it says which package and exits 9.
  • 0.16.0, changelog, docs/spec.md "cloud", README.

Tests: tests/test_spec_cloud.py; the full suite passes locally at 99.8 percent. Used in the real test of keel-cloud's Phase A on the test VM (two Keel Core containers with this keel brought the overlay up through Keel Cloud).

Test plan

  • CI green
  • Merged before keel-overlay-cloud is published, which depends on keel >= 0.16.0

The spec gains a cloud section, additive under version 1: endpoint (an
https URL), api_key (skip or a file reference), entry_secret (a file
reference), set (a lower case DNS label, required with a key) and
ca_file. Secrets are file references only, never generate: the key is
made by Keel Cloud and the entry secret by the set's first node. keel
validates the section and diff never compares it; the peers Keel
Cloud's node agent writes are compared under network.overlay as
before.

keel cloud runs keel-cloud-node of the keel-overlay-cloud package with
the same arguments, and names the package when it is missing (exit 9).

Proven on the test VM with Keel-Linux/keel-cloud: two Keel Core
containers with this keel enrolled, gained each other as peers and
brought the overlay up with spec apply --system and network confirm.
navigator added 2 commits October 2, 2026 14:13
# Conflicts:
#	debian/changelog
#	keel/__init__.py
#	pyproject.toml
A trailing newline passed the anchored patterns, so "shop\n" was a
valid set name. Found in the security review of keel-cloud's Phase A.
@marcos-mendez

Copy link
Copy Markdown
Collaborator Author

Paused by the maintainer (2026-10-02) until the etcd mesh (Phase 5 of tracker#46: registry, install by discovery, three nodes without Keel Cloud) is stable. Then the node-side client ships in images, small and disabled, and is enabled later through apt update and apt upgrade. Needs an independent security review before merge.

@marcos-mendez
marcos-mendez marked this pull request as draft October 2, 2026 14:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant