puppetserver: auto-restart JVM when its binaries are replaced by an upgrade #499

Merged
benvin merged 1 commits from benvin/puppetserver-jvm-restart-on-upgrade into develop 2026-07-30 20:50:31 +10:00

1 Commits

Author SHA1 Message Date
unkinben 85a5afda6b profiles::puppet::server: restart puppetserver when its JVM binary is replaced
ci/woodpecker/pr/puppet-lint Pipeline was successful
ci/woodpecker/pr/ruby-validate Pipeline was successful
ci/woodpecker/pr/yamllint Pipeline was successful
ci/woodpecker/pr/erb-validate Pipeline was successful
ci/woodpecker/pr/bolt-validate Pipeline was successful
ci/woodpecker/pr/epp-validate Pipeline was successful
ci/woodpecker/pr/puppet-validate Pipeline was successful
ci/woodpecker/pr/ruby-check Pipeline was successful
An out-of-band OpenJDK upgrade (java-17-openjdk 17.0.18 -> 17.0.19, delivered
by the AlmaLinux repo migration in #496) removed the old versioned JAVA_HOME
while the puppetserver JVMs kept running against the now-deleted files. The
running JVM re-execs jspawnhelper from its original (deleted) JAVA_HOME on every
posix_spawn, so ProcessBuilder fails with "error=2, No such file or directory".
That broke the exec ENC (/opt/cobbler-enc/cobbler-enc) and 500'd every catalog
compile across all 6 masters, failing 136/143 nodes. The masters could not
self-heal because nothing restarts the JVM on a java upgrade.

Add a puppetserver-jvm-guard systemd timer (every 5 min) that detects a
puppetserver JVM executing from deleted binaries and restarts the service,
so any future JVM/library upgrade recovers automatically.

Claude-Session: https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv
2026-07-30 00:46:32 +10:00