A service can be declared to reflect a file
Because a running service does not re-read its configuration. Replace the file, find the service running, do nothing -- and the machine keeps behaving as it did while every check passes, because the file is right and the service is up. That is not hypothetical. It is how a third node joining a mesh left the first two carrying a private network that no longer existed, with every part of it reporting success. Declared state rather than a command: the declaration says the running service must reflect these files, and the host works out that it does not. A command to restart would be an action, and the link may not carry one -- the host refused precisely that when I tried it, correctly, which is how this shape was arrived at rather than the other. Scoped to one apply. A change from an earlier one has already been reflected, and restarting for it every time would make a steady machine bounce its services for ever. Also: the node generates its overlay key at enrolment and reports the public half, and the store waits three minutes rather than one for the database -- sixty seconds is not enough for a cold machine running initdb, and it failed that way three times, which is the worst kind of flake because a second run always fixed it.
This commit is contained in:
@@ -113,6 +113,20 @@ type Service struct {
|
||||
// Without this the host could start a unit and not make it survive a reboot, which is a
|
||||
// declaration that reports success and stops being true at the next power cut.
|
||||
Boot string `json:"boot,omitempty"`
|
||||
|
||||
// RestartOn names resources whose change means this service must be restarted.
|
||||
//
|
||||
// Because a running service does not re-read its configuration. Replace the file, find the
|
||||
// service already running, do nothing, and the machine keeps behaving the way it did before —
|
||||
// while every check passes, because the file is right and the service is up. That is not
|
||||
// hypothetical: it is how a third node joining a mesh left the first two carrying a network
|
||||
// that no longer existed, and every part of it reported success.
|
||||
//
|
||||
// This is declared state rather than a command. The declaration says the running service must
|
||||
// reflect these files; the host works out that it does not and acts. A *command* to restart
|
||||
// would be an action, and the link may not carry one (novox/hq ADR 0005) — so this is not a
|
||||
// way around that rule, it is the shape the rule leaves.
|
||||
RestartOn []string `json:"restart-on,omitempty"`
|
||||
}
|
||||
|
||||
func (s *Service) Identity() string { return s.ID }
|
||||
|
||||
Reference in New Issue
Block a user