Add boot unit applying a local config #34

Merged
benvin merged 3 commits from benvin/boot-unit into main 2026-10-05 21:46:58 +11:00
Member

Hosts managed from a local config (e.g. -c /etc/shorewall) have no unit applying the ruleset at boot, so they come up unfiltered after a reboot; the RPM ships only the control-plane agent unit.

  • add tomswall.service: oneshot tomswall apply with DefaultDependencies=no, before network-pre.target, wanted by sysinit.target
  • retry on failure (Restart=on-failure, 5s); fails open once retries are exhausted
  • choose config via TOMSWALL_CONFIG in /etc/tomswall/tomswall.env (commented shorewall example)
  • omit ExecStop so stopping the unit never opens the firewall
  • conflict tomswall.service and tomswall-agent.service with each other
  • package the unit and env file (config|noreplace), not enabled by default
Hosts managed from a local config (e.g. `-c /etc/shorewall`) have no unit applying the ruleset at boot, so they come up unfiltered after a reboot; the RPM ships only the control-plane agent unit. - add `tomswall.service`: oneshot `tomswall apply` with `DefaultDependencies=no`, before `network-pre.target`, wanted by `sysinit.target` - retry on failure (`Restart=on-failure`, 5s); fails open once retries are exhausted - choose config via `TOMSWALL_CONFIG` in `/etc/tomswall/tomswall.env` (commented shorewall example) - omit ExecStop so stopping the unit never opens the firewall - conflict `tomswall.service` and `tomswall-agent.service` with each other - package the unit and env file (config|noreplace), not enabled by default
unkin-agent added 1 commit 2026-10-05 13:41:59 +11:00
Add boot unit applying a local config
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
dc406c4f56
Author
Member
  • packaging/tomswall.service:1 — missing DefaultDependencies=no; implicit After=sysinit.target basic.target makes the unit start after basic.target, so network-pre-ordered units (and anything early that is Before=basic.target) run unfiltered or can form an ordering cycle with Before=network-pre / WantedBy=basic.target → add DefaultDependencies=no plus Conflicts=shutdown.target and Before=shutdown.target (keep the explicit After=local-fs.target systemd-sysctl.service).
  • packaging/tomswall.service:14 — a failed apply leaves the unit failed and boot continues with no ruleset, which contradicts the PR intent of not coming up unfiltered → decide and state it: add Restart=on-failure (oneshot supports it on 244+) or a ExecStartPost/failure path that applies a default-drop ruleset; otherwise document that boot is fail-open.
  • nit: packaging/tomswall.service:12 — default tomswall.yaml is not shipped (only tomswall.example.yaml), so enabling the unit without editing the env file fails at boot → point the default at a shipped file or note it in tomswall.env.
- packaging/tomswall.service:1 — missing `DefaultDependencies=no`; implicit `After=sysinit.target basic.target` makes the unit start after basic.target, so network-pre-ordered units (and anything early that is Before=basic.target) run unfiltered or can form an ordering cycle with Before=network-pre / WantedBy=basic.target → add `DefaultDependencies=no` plus `Conflicts=shutdown.target` and `Before=shutdown.target` (keep the explicit After=local-fs.target systemd-sysctl.service). - packaging/tomswall.service:14 — a failed `apply` leaves the unit failed and boot continues with no ruleset, which contradicts the PR intent of not coming up unfiltered → decide and state it: add `Restart=on-failure` (oneshot supports it on 244+) or a `ExecStartPost`/failure path that applies a default-drop ruleset; otherwise document that boot is fail-open. - nit: packaging/tomswall.service:12 — default `tomswall.yaml` is not shipped (only `tomswall.example.yaml`), so enabling the unit without editing the env file fails at boot → point the default at a shipped file or note it in tomswall.env.
unkin-agent added 1 commit 2026-10-05 13:45:10 +11:00
Order boot unit before sysinit and retry on failure
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
7fcbb5fad8
Author
Member
  • packaging/tomswall.service:16 — Restart=on-failure + RestartSec=5 never exhausts: default StartLimit is 5 starts/10s, a 5s cadence gives at most 2-3 starts per window, so a bad config retries forever (every 5s, log spam) and the "fails open once restarts are exhausted" comment is false → add StartLimitIntervalSec=60/StartLimitBurst=5 under [Unit] (or drop Restart= and accept one-shot fail-open), and reword the comment.
- packaging/tomswall.service:16 — `Restart=on-failure` + `RestartSec=5` never exhausts: default StartLimit is 5 starts/10s, a 5s cadence gives at most 2-3 starts per window, so a bad config retries forever (every 5s, log spam) and the "fails open once restarts are exhausted" comment is false → add `StartLimitIntervalSec=60`/`StartLimitBurst=5` under [Unit] (or drop Restart= and accept one-shot fail-open), and reword the comment.
unkin-agent added 1 commit 2026-10-05 13:47:03 +11:00
Cap boot unit restarts so it fails open
ci/woodpecker/pr/build Pipeline was successful
ci/woodpecker/pr/test Pipeline was successful
ci/woodpecker/pr/pre-commit Pipeline was successful
502d06bdda
Author
Member

No findings.

No findings.
benvin merged commit afa056b454 into main 2026-10-05 21:46:58 +11:00
benvin deleted branch benvin/boot-unit 2026-10-05 21:46:59 +11:00
Sign in to join this conversation.