mirror of
https://github.com/warmbly/warmbly.git
synced 2026-09-13 08:05:05 +00:00
feat: fix the eight defects the second review pass found, including three where the previous fix did not land: the bind-mounted state dir was root-owned so the node running as uid 1000 still could not write its update target, elevating the reserved-worker eviction did nothing because the rotation loop bailed on target-equals-current before the urgency was consulted, and the warmup-pool assertion was vacuous which hid that warmupPoolFor checked the subscription repo before the billing provider and answered free on a self-host install
This commit is contained in:
@@ -174,6 +174,12 @@ write_config() {
|
||||
fi
|
||||
|
||||
mkdir -p "$CONFIG_DIR" "$STATE_DIR"
|
||||
# The node container runs as uid 1000 (see deploy/docker/worker.Dockerfile),
|
||||
# so the bind-mounted state dir has to be writable by it. Without this the
|
||||
# agent's target-version write fails with EACCES, which it only logs, and
|
||||
# auto-update silently never happens.
|
||||
chown -R 1000:1000 "$STATE_DIR" 2>/dev/null || true
|
||||
chmod 0775 "$STATE_DIR"
|
||||
umask 077
|
||||
{
|
||||
printf '%s\n' "$NODE_ENV"
|
||||
@@ -256,6 +262,7 @@ fi
|
||||
|
||||
sed -i "s|^WARMBLY_VERSION=.*|WARMBLY_VERSION=$target|" "$CONFIG_DIR/node.env"
|
||||
printf 'WARMBLY_IMAGE_REF=%s:%s\n' "$image" "$target" > "$STATE_DIR/image-ref"
|
||||
chown -R 1000:1000 "$STATE_DIR" 2>/dev/null || true
|
||||
echo "warmbly-node-update: $current -> $target"
|
||||
systemctl restart "warmbly-$role"
|
||||
UPDATER
|
||||
|
||||
Reference in New Issue
Block a user