Skip to content

fix(docker): flush config.json to the KSM record on container shutdown - #2405

Open
mani-muon wants to merge 1 commit into
Keeper-Security:masterfrom
mani-muon:docker-entrypoint-flush-config-on-stop
Open

mani-muon wants to merge 1 commit into
Keeper-Security:masterfrom
mani-muon:docker-entrypoint-flush-config-on-stop

Conversation

@mani-muon

Copy link
Copy Markdown

Problem

When the entrypoint runs with --ksm-config/--ksm-token and --record, it starts docker_ksm_utility.py monitor in the background to push changes to config.json back to the KSM record. The monitor only uploads on its 30-second tick (MONITOR_INTERVAL=30). On container stop, cleanup_on_exit -> stop_config_monitor kills the monitor without a final upload, so anything written to config.json since the last tick is lost. Commander rotates clone_code on every login, so the next container start resumes from a stale config.

Fix

In stop_config_monitor, call the existing upload_config_to_ksm helper once before killing the monitor PID. The call only runs when KSM mode is active (KSM_CONFIG or KSM_TOKEN set, RECORD set, config.json present), and a failing upload is logged but does not block shutdown.

  • No new helpers; reuses upload_config_to_ksm as it stands.
  • MONITOR_INTERVAL is unchanged; this only adds a flush on shutdown.
  • The config-file and user/password auth paths are untouched: the guard skips when no monitor was started.

Testing

Local harness with a stubbed python3 on PATH that records its argv and sleeps for monitor subcommands:

  1. KSM mode, config present: stop_config_monitor invokes upload exactly once, then kills the monitor PID.
  2. Same, with the upload stub exiting non-zero: a warning is logged and shutdown completes with rc 0.
  3. Non-KSM path (no monitor started): no-op, no upload.
  4. Monitor PID file present but KSM variables unset: the PID is still killed, no upload.

bash -n docker-entrypoint.sh is clean.

The background config monitor only uploads config.json back to the KSM
record on its 30s interval tick, so stopping the container between ticks
dropped any change written since the last tick -- notably the clone_code
Commander rotates on each login -- and the next start served a stale
config. Perform one final upload via the existing upload_config_to_ksm
helper from stop_config_monitor before killing the monitor PID, guarded
so it only runs when KSM mode is active and config.json exists and so a
failed upload is logged but does not block shutdown.
@mani-muon
mani-muon marked this pull request as ready for review October 1, 2026 23:30
@mani-muon

mani-muon commented Oct 1, 2026 •

Copy link
Copy Markdown
Author

Hey @sk-keeper 👋🏽 -- May I please get a review on this PR? 🙇🏽

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant