Render kea unix socket paths under /var/run/kea
Kea 2.6.5 restricts control/HA unix socket paths to its compiled
runstatedir and rejects any other path by exact string match
("invalid path specified: '/run/kea', supported path is '/var/run/kea'"),
even though /var/run is a symlink to /run. The operator rendered sockets
under /run/kea, so kea-dhcp4 and kea-ctrl-agent crash-looped on startup.
- Point RunDir at /var/run/kea so all derived config/socket paths match.
- Pre-create /var/run/kea in the kea image.
- Assert rendered socket paths live under /var/run/kea.
Claude-Session: https://claude.ai/code/session_01JUoARVdmhxKQHyyyp1pxeT
This commit is contained in:
@@ -231,4 +231,21 @@ func TestRenderCtrlAgent(t *testing.T) {
|
||||
t.Errorf("ctrl-agent config missing %q", m)
|
||||
}
|
||||
}
|
||||
// Kea 2.6+ only accepts unix socket paths under /var/run/kea (exact string).
|
||||
if !strings.Contains(out, `"socket-name": "/var/run/kea/`) {
|
||||
t.Errorf("ctrl-agent socket-name must be under /var/run/kea, got: %s", out)
|
||||
}
|
||||
}
|
||||
|
||||
func TestControlSocketPathAllowedByKea(t *testing.T) {
|
||||
if !strings.HasPrefix(CtrlSocketPath, "/var/run/kea/") {
|
||||
t.Errorf("CtrlSocketPath %q must live under /var/run/kea (kea 2.6+ restriction)", CtrlSocketPath)
|
||||
}
|
||||
out, err := RenderDHCP4(referenceInput())
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.Contains(out, `"socket-name": "/var/run/kea/`) {
|
||||
t.Errorf("dhcp4 control-socket must be under /var/run/kea, got: %s", out)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -10,8 +10,11 @@ const (
|
||||
|
||||
// ConfigDir is where projected config is mounted read-only.
|
||||
ConfigDir = "/etc/kea-operator"
|
||||
// RunDir is a shared emptyDir for the config copy and control socket.
|
||||
RunDir = "/run/kea"
|
||||
// RunDir is a shared emptyDir for the config copy and control socket. Kea
|
||||
// 2.6+ restricts unix socket paths to its compiled runstatedir and rejects
|
||||
// anything else by exact string ("supported path is '/var/run/kea'"), even
|
||||
// though /var/run symlinks to /run, so this must be the literal /var/run/kea.
|
||||
RunDir = "/var/run/kea"
|
||||
|
||||
// DHCP4ConfPath is the runtime kea-dhcp4 config.
|
||||
DHCP4ConfPath = RunDir + "/kea-dhcp4.conf"
|
||||
|
||||
Reference in New Issue
Block a user