Repository navigation
Restart services in deploy-certs only when their TLS material changed - #411
Merged
Merged
Conversation
Every deployment runs deploy-certs.yml first, and it restarted the dispatcher and every executor unconditionally, so even a dispatcher-only deploy restarted the whole fleet. An executor restart starts a new TESLA chain and never discloses the old chain's last disclosure delay of keys, so each needless restart left about 15 minutes of probes unverifiable. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
deploy/debuglet-deployrunsdeploy-certs.ymlbefore every action, on every host. That playbook restarted the dispatcher and each executor unconditionally. As a result,./deploy/debuglet-deploy prod dispatcherrestarted all six prod executors even though no certificate had changed: every copy task reportedok, yet every "Restart executor" reportedchanged.That matters for verification. An executor restart starts a new TESLA chain, and the old chain's last d keys are never disclosed (see #378). Each needless restart therefore left about 15 minutes of probes unverifiable.
Each copy task now registers its result, and the dispatcher or executor is restarted only if one of its own certificate, key or CA files changed. A first deployment is unchanged: there is no unit yet, so there is still no restart.
Tested:
deploy/test/provisioner-check.shpasses locally ("all deployment render checks passed"). The render checks don't exercise service restarts.🤖 Generated with Claude Code