From 6c8b9dc166a7102feae5c0ec8726b3def7e1bbfa Mon Sep 17 00:00:00 2001 From: admin Date: Sun, 2 Aug 2026 07:20:43 +0000 Subject: [PATCH] fix: systemd ExecStartPre with - prefix, remove symlink dependency - ExecStartPre=- allows nginx start failure without blocking service - Removed shell constructs (|| true) incompatible with systemd - Removed env.list background goroutine (setup.sh no longer used) - Multi-instance needs per-instance ELF patching (WIP) --- internal/native/native.go | 26 ++++++-------------------- 1 file changed, 6 insertions(+), 20 deletions(-) diff --git a/internal/native/native.go b/internal/native/native.go index 852a320..6a55840 100644 --- a/internal/native/native.go +++ b/internal/native/native.go @@ -6,7 +6,6 @@ import ( "os/exec" "path/filepath" "strings" - "time" "git.sechpoint.app/customer-engineering/wallarm/internal/state" ) @@ -44,7 +43,6 @@ func InstallNode(node state.Node, apiToken, apiHost, labels string) error { } killPort(port) copyNginx(DeployTo) - startNginx(DeployTo, node, port) // 3. Download AIO once if _, err := os.Stat(installerPath); os.IsNotExist(err) { @@ -63,27 +61,15 @@ func InstallNode(node state.Node, apiToken, apiHost, labels string) error { return fmt.Errorf("extract: %w\n%s", err, string(out)) } - // 5. Fix: recreate env.list in background while setup.sh runs - done := make(chan struct{}) - go func() { - defer close(done) - for { - select { - case <-done: - return - default: - os.WriteFile(filepath.Join(DeployTo, "env.list"), - []byte("# wallarm env\n"), 0644) - time.Sleep(500 * time.Millisecond) - } - } - }() + // 5. Start NGINX (modules now available after extraction) + startNginx(DeployTo, node, port) // 6. Load Wallarm NGINX module + register node fmt.Printf("[%s] Configuring NGINX module...\n", node.Name) exec.Command("bash", filepath.Join(DeployTo, "pick-module.sh")).Run() - // 6. Register node + // 7. Kill stale wcli lock (from other instances) then register + exec.Command("rm", "-f", "/tmp/.wallarm.wcli.lock").Run() fmt.Printf("[%s] Registering node (this may take 30-60s)...\n", node.Name) registerCmd := exec.Command(filepath.Join(DeployTo, "register-node"), "job:register", @@ -182,11 +168,11 @@ After=network.target Type=simple WorkingDirectory=%s/%%i/wallarm EnvironmentFile=-%s/%%i/wallarm/env.list -ExecStartPre=%s/%%i/wallarm/nginx/sbin/nginx -c %s/%%i/wallarm/nginx/conf/nginx.conf -p %s/%%i/wallarm/nginx/ 2>/dev/null || true +ExecStartPre=-%s/%%i/wallarm/nginx/sbin/nginx -c %s/%%i/wallarm/nginx/conf/nginx.conf -p %s/%%i/wallarm/nginx/ ExecStartPre=/bin/sleep 2 ExecStart=%s/%%i/wallarm/usr/bin/python3.10 %s/%%i/wallarm/usr/bin/supervisord -c %s/%%i/wallarm/etc/supervisord.conf ExecStop=%s/%%i/wallarm/usr/bin/python3.10 %s/%%i/wallarm/usr/bin/supervisord -c %s/%%i/wallarm/etc/supervisord.conf shutdown -ExecStopPost=%s/%%i/wallarm/nginx/sbin/nginx -s quit -p %s/%%i/wallarm/nginx/ 2>/dev/null || true +ExecStopPost=-%s/%%i/wallarm/nginx/sbin/nginx -s quit -p %s/%%i/wallarm/nginx/ Restart=on-failure RestartSec=5 User=root