fix(deploy): nightly auto-upgrade failed on both ATMs, for different reasons #101

Merged
padreug merged 2 commits from fix/autoupgrade-known-hosts-and-wg into dev 2026-09-22 18:28:38 +00:00
Showing only changes of commit 71b2691f8c - Show all commits

fix(deploy): don't fail activation over an unprovisioned WireGuard tunnel

wg0.key is written per machine after flashing. Until it is, the unit's
`wg set … private-key` exits 1 with 'fopen: No such file or directory',
and one failed unit makes switch-to-configuration exit 4 — which marks
the whole nightly system.autoUpgrade run as failed even though the new
generation applied. sintra has reported a broken updater on that basis
alone; its tunnel was never provisioned and wg0 has never existed.

Skip the unit when there is no key rather than failing activation over
an interface that was never set up. A provisioned machine is unaffected.
Guarded on wg0 still being declared so the live image, which mkForce's
the interfaces away, doesn't inherit a unit with no ExecStart.

Refs #98

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Padreug 2026-09-22 20:14:46 +02:00

View file

@ -181,6 +181,20 @@
fi fi
''; '';
# The tunnel is operator-provisioned: wg0.key is written per machine after
# flashing, and until it is, `wg set … private-key` exits 1 with
# "fopen: No such file or directory". One failed unit makes
# switch-to-configuration exit 4, which marks the entire nightly
# system.autoUpgrade run as failed — so an ATM that simply never had its
# tunnel provisioned reports a broken updater for the life of the machine
# (sintra, #98). Skip the unit when there is no key instead of failing
# activation over an interface that was never set up; a provisioned machine
# is unaffected. Guarded on wg0 still being declared so the live image,
# which mkForce's the interfaces away, doesn't get a unit with no ExecStart.
systemd.services = lib.mkIf (config.networking.wireguard.interfaces ? wg0) {
wireguard-wg0.unitConfig.ConditionPathExists = "/var/lib/wireguard/wg0.key";
};
# In-place rename migration: lamassu user → bitspire user. # In-place rename migration: lamassu user → bitspire user.
# Runs after `users` activation so the bitspire user exists with its UID. # Runs after `users` activation so the bitspire user exists with its UID.
# Idempotent: re-running on an already-migrated system is a chown no-op. # Idempotent: re-running on an already-migrated system is a chown no-op.