Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add stale lockfile removal mechanism for confd critical sections #370

Open
wants to merge 3 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 26 additions & 2 deletions src/configure-balena.sh
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,7 @@ CONF=${CONF:-/balena/${TLD}.env}
CERTS=${CERTS:-/certs}
HOSTS_CONFIG=${HOSTS_CONFIG:-ALERTMANAGER_HOST:alertmanager,ADMIN_HOST:admin,API_HOST:api,BUILDER_HOST:builder,DATA_HOST:data,DELTA_HOST:delta,DELTA_S3_HOST:s3,DEVICE_URLS_BASE:devices,FILES_HOST:files,GIT_HOST:git,GIT_HOSTNAME:git,IMAGE_MAKER_HOST:img,IMAGE_MAKER_S3_HOST:s3,LOKI_HOST:loki,MONITOR_HOST:monitor,PROXY_HOST:devices,REDIS_HOST:redis,REGISTRY2_HOST:registry2,REGISTRY_PROXY_HOST:registry-proxy,TOKEN_AUTH_CERT_ISSUER:api,REGISTRY2_TOKEN_AUTH_ISSUER:api,REGISTRY2_TOKEN_AUTH_REALM:api,UI_HOST:dashboard,VPN_HOST:cloudlink,WEBRESOURCES_S3_HOST:s3}
TOKENS_CONFIG=${TOKENS_CONFIG:-API_SERVICE_API_KEY:hex,AUTH_RESINOS_REGISTRY_CODE:hex,BUILDER_SERVICE_API_KEY:hex,COOKIE_SESSION_SECRET:hex,DELTA_SERVICE_API_KEY:hex,DIGITIZER_API_KEY:hex,GEOIP_LICENCE_KEY:hex,GEOIP_USER_ID:hex,GIT_API_KEY:hex,IMG_S3_ACCESS_KEY:hex,IMG_S3_SECRET_KEY:hex,JF_OAUTH_APP_SECRET:hex,JSON_WEB_TOKEN_SECRET:hex,MAPS_API_KEY:hex,MIXPANEL_TOKEN:hex,MONITOR_OAUTH_COOKIE_SECRET:hex,MONITOR_SECRET_TOKEN:hex,PROXY_SERVICE_API_KEY:hex,REGISTRY2_SECRETKEY:hex,TOKEN_AUTH_BUILDER_TOKEN:hex,VPN_GUEST_API_KEY:hex,VPN_SERVICE_API_KEY:hex,API_VPN_SERVICE_API_KEY:API_SERVICE_API_KEY,DELTA_API_KEY:DELTA_SERVICE_API_KEY,DELTA_S3_KEY:IMG_S3_ACCESS_KEY,DELTA_S3_SECRET:IMG_S3_SECRET_KEY,GIT_SERVICE_API_KEY:GIT_API_KEY,MDNS_API_TOKEN:PROXY_SERVICE_API_KEY,REGISTRY2_TOKEN:TOKEN_AUTH_BUILDER_TOKEN,S3_MINIO_ACCESS_KEY:IMG_S3_ACCESS_KEY,S3_MINIO_SECRET_KEY:IMG_S3_SECRET_KEY,S3_MINIO_ACCESS_KEY:REGISTRY2_S3_KEY,S3_MINIO_SECRET_KEY:REGISTRY2_S3_SECRET,WEBRESOURCES_S3_ACCESS_KEY:IMG_S3_ACCESS_KEY,WEBRESOURCES_S3_SECRET_KEY:IMG_S3_SECRET_KEY}
LOCK_TIMEOUT=${LOCK_TIMEOUT:-300}

declare -A HOST_ENVVARS
hosts_config=($(echo "${HOSTS_CONFIG}" | tr ',' ' '))
Expand Down Expand Up @@ -65,20 +66,43 @@ function cleanup() {
}
trap 'cleanup' EXIT

function get_lock_age {
if [[ -d "$(dirname "${CONF}")" ]]; then
if [[ -f "${CONF}.lock" ]]; then
echo "$(( $(date +%s) - $(date -r "${CONF}.lock" +%s) ))"
fi
fi
}

function set_update_lock {
if [[ -d "$(dirname "${CONF}")" ]]; then
echo "create lockfile ${CONF}.lock with ${LOCK_TIMEOUT}s age timeout"

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
echo "create lockfile ${CONF}.lock with ${LOCK_TIMEOUT}s age timeout"
echo "creating lockfile ${CONF}.lock with ${LOCK_TIMEOUT}s age timeout"

Nit just to match the other log message

lockfile "${CONF}.lock"
fi
}

function check_update_lock() {
if [[ -d "$(dirname "${CONF}")" ]]; then
[[ -f "${CONF}.lock" ]] || return 0
! test -f "${CONF}.lock"
if [[ -f "${CONF}.lock" ]]; then
# remove stale lockfile
if [[ $(get_lock_age) -gt $LOCK_TIMEOUT ]]; then
remove_update_lock
return 0
fi
return 1

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What's the reasoning for returning 1 here? I thought even in bash script returning anything other than 0 indicates an error.

else
return 0
fi
fi
}

function remove_update_lock() {
if [[ -d "$(dirname "${CONF}")" ]]; then
if [[ -f "${CONF}.lock" ]]; then
lock_age="$(get_lock_age)"
echo "removing lockfile ${CONF}.lock, aged ${lock_age}s"
fi
fi
rm -f "${CONF}.lock"
}

Expand Down
Loading