lint: fix pre-existing failures so the self-test pipeline passes
continuous-integration/drone/push Build is passing
continuous-integration/drone/push Build is passing
Push build #33 (this branch) failed at the lint gate on failures inherited from main, which block this PR from merging: - runner/harness/warm.py: ruff format (long regex line — no code change) - nix/modules/acme-dns.nix: statix W201 'avoid repeated keys' — fold the three service definitions (acme-dns, cc-ci-acme-storage-seed, cc-ci-acme-traefik-handoff) into one services = { ... } attrset. Pure restructure: systemd.services eval of all three units is byte-identical to main (nix eval --json diff, all three IDENTICAL). scripts/lint.sh now: PASS.
This commit is contained in:
+78
-71
@@ -111,82 +111,89 @@ in
|
|||||||
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
|
"f /var/lib/ci-certs/acme-production-enabled 0600 root root -"
|
||||||
];
|
];
|
||||||
|
|
||||||
services.acme-dns = {
|
# Three systemd units (W201 statix): one attrset, distinct unit names — avoids
|
||||||
description = "Restricted authoritative DNS for cc-ci ACME DNS-01";
|
# `services = { ... }` attribute sets repeating the `services` key.
|
||||||
wantedBy = [ "multi-user.target" ];
|
services = {
|
||||||
after = [ "network-online.target" ];
|
acme-dns = {
|
||||||
wants = [ "network-online.target" ];
|
description = "Restricted authoritative DNS for cc-ci ACME DNS-01";
|
||||||
serviceConfig = {
|
wantedBy = [ "multi-user.target" ];
|
||||||
User = "acme-dns";
|
after = [ "network-online.target" ];
|
||||||
Group = "acme-dns";
|
wants = [ "network-online.target" ];
|
||||||
StateDirectory = "acme-dns";
|
serviceConfig = {
|
||||||
StateDirectoryMode = "0700";
|
User = "acme-dns";
|
||||||
WorkingDirectory = "/var/lib/acme-dns";
|
Group = "acme-dns";
|
||||||
ExecStart = "${pkgs.acme-dns}/bin/acme-dns -c ${acmeDnsConfig}";
|
StateDirectory = "acme-dns";
|
||||||
Restart = "on-failure";
|
StateDirectoryMode = "0700";
|
||||||
RestartSec = "5s";
|
WorkingDirectory = "/var/lib/acme-dns";
|
||||||
AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
|
ExecStart = "${pkgs.acme-dns}/bin/acme-dns -c ${acmeDnsConfig}";
|
||||||
CapabilityBoundingSet = [ "CAP_NET_BIND_SERVICE" ];
|
Restart = "on-failure";
|
||||||
NoNewPrivileges = true;
|
RestartSec = "5s";
|
||||||
PrivateTmp = true;
|
AmbientCapabilities = [ "CAP_NET_BIND_SERVICE" ];
|
||||||
PrivateDevices = true;
|
CapabilityBoundingSet = [ "CAP_NET_BIND_SERVICE" ];
|
||||||
ProtectHome = true;
|
NoNewPrivileges = true;
|
||||||
ProtectSystem = "strict";
|
PrivateTmp = true;
|
||||||
ReadWritePaths = [ "/var/lib/acme-dns" ];
|
PrivateDevices = true;
|
||||||
RestrictAddressFamilies = [ "AF_INET" "AF_UNIX" ];
|
ProtectHome = true;
|
||||||
|
ProtectSystem = "strict";
|
||||||
|
ReadWritePaths = [ "/var/lib/acme-dns" ];
|
||||||
|
RestrictAddressFamilies = [ "AF_INET" "AF_UNIX" ];
|
||||||
|
};
|
||||||
};
|
};
|
||||||
};
|
|
||||||
|
|
||||||
# Seed the new cert's acmedns storage before the ACME unit first runs (see
|
# Seed the new cert's acmedns storage before the ACME unit first runs (see
|
||||||
# acmeStorageSeed above). Ordering via the generated acme unit name.
|
# acmeStorageSeed above). Ordering via the generated acme unit name.
|
||||||
services.cc-ci-acme-storage-seed = {
|
cc-ci-acme-storage-seed = {
|
||||||
description = "Seed ci.autonomic.zone acme-dns storage from the legacy account";
|
description = "Seed ci.autonomic.zone acme-dns storage from the legacy account";
|
||||||
after = [ "acme-dns.service" ];
|
after = [ "acme-dns.service" ];
|
||||||
wantedBy = [ "acme-ci.autonomic.zone.service" ];
|
wantedBy = [ "acme-ci.autonomic.zone.service" ];
|
||||||
before = [ "acme-ci.autonomic.zone.service" ];
|
before = [ "acme-ci.autonomic.zone.service" ];
|
||||||
serviceConfig = {
|
serviceConfig = {
|
||||||
Type = "oneshot";
|
Type = "oneshot";
|
||||||
UMask = "0077";
|
UMask = "0077";
|
||||||
|
};
|
||||||
|
script = "${acmeStorageSeed}/bin/cc-ci-acme-storage-seed";
|
||||||
};
|
};
|
||||||
script = "${acmeStorageSeed}/bin/cc-ci-acme-storage-seed";
|
|
||||||
};
|
|
||||||
|
|
||||||
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
|
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
|
||||||
# host certificate must be copied and reconciled rather than merely reloaded.
|
# host certificate must be copied and reconciled rather than merely reloaded.
|
||||||
# This service is started only by the production-mode ACME postRun hook.
|
# This service is started only by the production-mode ACME postRun hook.
|
||||||
services.cc-ci-acme-traefik-handoff = {
|
# Traefik consumes its wildcard as immutable Swarm secrets, so a renewed
|
||||||
description = "Install renewed cc-ci wildcard into Traefik Swarm secrets";
|
# host certificate must be copied and reconciled rather than merely reloaded.
|
||||||
after = [ "docker.service" "deploy-proxy.service" ];
|
# This service is started only by the production-mode ACME postRun hook.
|
||||||
requires = [ "docker.service" ];
|
cc-ci-acme-traefik-handoff = {
|
||||||
path = [ pkgs.coreutils pkgs.docker pkgs.systemd pkgs.gnugrep ];
|
description = "Install renewed cc-ci wildcard into Traefik Swarm secrets";
|
||||||
serviceConfig = {
|
after = [ "docker.service" "deploy-proxy.service" ];
|
||||||
Type = "oneshot";
|
requires = [ "docker.service" ];
|
||||||
UMask = "0077";
|
path = [ pkgs.coreutils pkgs.docker pkgs.systemd pkgs.gnugrep ];
|
||||||
|
serviceConfig = {
|
||||||
|
Type = "oneshot";
|
||||||
|
UMask = "0077";
|
||||||
|
};
|
||||||
|
script = ''
|
||||||
|
src=/var/lib/acme/ci.autonomic.zone
|
||||||
|
dst=/var/lib/ci-certs/live
|
||||||
|
test -s "$src/fullchain.pem"
|
||||||
|
test -s "$src/key.pem"
|
||||||
|
install -d -m 0700 "$dst"
|
||||||
|
install -m 0444 "$src/fullchain.pem" "$dst/fullchain.pem.new"
|
||||||
|
install -m 0400 "$src/key.pem" "$dst/privkey.pem.new"
|
||||||
|
mv -f "$dst/fullchain.pem.new" "$dst/fullchain.pem"
|
||||||
|
mv -f "$dst/privkey.pem.new" "$dst/privkey.pem"
|
||||||
|
|
||||||
|
# deploy-proxy performs the health-gated Swarm rollout. Its reconciler
|
||||||
|
# derives a fresh version from the public certificate chain and inserts
|
||||||
|
# the matching ssl_cert/ssl_key secrets before deploying Traefik.
|
||||||
|
systemctl restart deploy-proxy.service
|
||||||
|
|
||||||
|
# A successful rollout no longer references old wildcard versions. Best
|
||||||
|
# effort removal retains any secret Docker still reports as in use.
|
||||||
|
keep="v$(sha256sum "$dst/fullchain.pem" | cut -c1-16)"
|
||||||
|
docker secret ls --format '{{.Name}}' | \
|
||||||
|
grep -E '^traefik_ci_commoninternet_net_ssl_(cert|key)_v' | \
|
||||||
|
grep -v -E "_(ssl_cert|ssl_key)_$keep\$" | \
|
||||||
|
while IFS= read -r stale; do docker secret rm "$stale" || true; done
|
||||||
|
'';
|
||||||
};
|
};
|
||||||
script = ''
|
|
||||||
src=/var/lib/acme/ci.autonomic.zone
|
|
||||||
dst=/var/lib/ci-certs/live
|
|
||||||
test -s "$src/fullchain.pem"
|
|
||||||
test -s "$src/key.pem"
|
|
||||||
install -d -m 0700 "$dst"
|
|
||||||
install -m 0444 "$src/fullchain.pem" "$dst/fullchain.pem.new"
|
|
||||||
install -m 0400 "$src/key.pem" "$dst/privkey.pem.new"
|
|
||||||
mv -f "$dst/fullchain.pem.new" "$dst/fullchain.pem"
|
|
||||||
mv -f "$dst/privkey.pem.new" "$dst/privkey.pem"
|
|
||||||
|
|
||||||
# deploy-proxy performs the health-gated Swarm rollout. Its reconciler
|
|
||||||
# derives a fresh version from the public certificate chain and inserts
|
|
||||||
# the matching ssl_cert/ssl_key secrets before deploying Traefik.
|
|
||||||
systemctl restart deploy-proxy.service
|
|
||||||
|
|
||||||
# A successful rollout no longer references old wildcard versions. Best
|
|
||||||
# effort removal retains any secret Docker still reports as in use.
|
|
||||||
keep="v$(sha256sum "$dst/fullchain.pem" | cut -c1-16)"
|
|
||||||
docker secret ls --format '{{.Name}}' | \
|
|
||||||
grep -E '^traefik_ci_commoninternet_net_ssl_(cert|key)_v' | \
|
|
||||||
grep -v -E "_(ssl_cert|ssl_key)_$keep\$" | \
|
|
||||||
while IFS= read -r stale; do docker secret rm "$stale" || true; done
|
|
||||||
'';
|
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
@@ -41,7 +41,9 @@ _CTX.check_hostname = False
|
|||||||
_CTX.verify_mode = ssl.CERT_NONE
|
_CTX.verify_mode = ssl.CERT_NONE
|
||||||
|
|
||||||
# A cold per-run stack name looks like "<tag>-<6hex>_ci_commoninternet_net_<svc>"; extract the hex.
|
# A cold per-run stack name looks like "<tag>-<6hex>_ci_commoninternet_net_<svc>"; extract the hex.
|
||||||
_STACK_HEX_RE = re.compile(r"^[a-z0-9]{1,4}-([0-9a-f]{6})_ci_(?:autonomic_zone|commoninternet_net)_")
|
_STACK_HEX_RE = re.compile(
|
||||||
|
r"^[a-z0-9]{1,4}-([0-9a-f]{6})_ci_(?:autonomic_zone|commoninternet_net)_"
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
def stable_domain(recipe: str) -> str:
|
def stable_domain(recipe: str) -> str:
|
||||||
|
|||||||
Reference in New Issue
Block a user