Skip to content

Restart services in deploy-certs only when their TLS material changed - #411

Merged
vincent10400094 merged 1 commit into
mainfrom
fix/certs-restart-only-on-change
Oct 7, 2026
Merged

vincent10400094 merged 1 commit into
mainfrom
fix/certs-restart-only-on-change

Conversation

@vincent10400094

Copy link
Copy Markdown
Member

deploy/debuglet-deploy runs deploy-certs.yml before every action, on every host. That playbook restarted the dispatcher and each executor unconditionally. As a result, ./deploy/debuglet-deploy prod dispatcher restarted all six prod executors even though no certificate had changed: every copy task reported ok, yet every "Restart executor" reported changed.

That matters for verification. An executor restart starts a new TESLA chain, and the old chain's last d keys are never disclosed (see #378). Each needless restart therefore left about 15 minutes of probes unverifiable.

Each copy task now registers its result, and the dispatcher or executor is restarted only if one of its own certificate, key or CA files changed. A first deployment is unchanged: there is no unit yet, so there is still no restart.

Tested: deploy/test/provisioner-check.sh passes locally ("all deployment render checks passed"). The render checks don't exercise service restarts.

🤖 Generated with Claude Code

Every deployment runs deploy-certs.yml first, and it restarted the
dispatcher and every executor unconditionally, so even a dispatcher-only
deploy restarted the whole fleet. An executor restart starts a new TESLA
chain and never discloses the old chain's last disclosure delay of keys,
so each needless restart left about 15 minutes of probes unverifiable.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vincent10400094
vincent10400094 merged commit 87ce14d into main Oct 7, 2026
10 checks passed
@vincent10400094
vincent10400094 deleted the fix/certs-restart-only-on-change branch October 8, 2026 00:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant