Repository navigation
feat(doctor): report whether the running proxy has the docker socket mounted - #101
Merged
Merged
Conversation
…mounted ## Summary The config-time sleep/docker_socket pairing check covers the *current* config, but the running container keeps whatever it was booted with: a proxy from before run.docker_socket was added silently lacks the mount (the failure mode is one hung request when a sleeping service never wakes), and one from before it was removed keeps root-equivalent host access. kamal doctor now inspects the running kamal-proxy's mount destinations per host (Commands::Proxy#mount_destinations) and reports a "Proxy docker socket" row: OK when the configured socket is mounted (or arrives on boot, or nothing is configured), FAIL with a `kamal proxy reboot` remedy when sleep is configured and the mount is missing, WARN when the socket is configured without sleep (drift, nothing hangs yet) or when a docker.sock mount lingers that the config no longer asks for. Also fixes a latent bug the new test surfaced: the doctor's catch-all named SSHKit::Runner::MultipleExecuteError, which does not exist in sshkit 1.25 - a host whose checks failed wholesale became a NameError instead of a recorded SSH failure, the opposite of the doctor's never-crash contract. ## Test Coverage - mounted / missing-with-sleep (fail) / missing-without-sleep (warn) / stray-unconfigured (warn) / boot-time (ok) / quiet-when-absent (ok) - mount_destinations command shape ## Verification - [x] bundle exec rubocop --parallel passes - [x] unit suite passes Closes #98
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
kamal doctornow inspects what the running kamal-proxy was actually booted with, not just what the config says. The config-time sleep/docker_socketpairing check can't see a proxy booted before the socket was added (sleeping services never wake — one hung request) or after it was removed (root-equivalent host access lingers).Kamal::Commands::Proxy#mount_destinations—docker inspect, one mount destination per linesleep:configured somewhere and the running proxy lacks the mount →kamal proxy rebootsleep:and not mounted (drift, nothing hangs yet); or adocker.sockmount the config no longer asks for; or the inspection itself failed (the doctor never crashes)SSHKit::Runner::MultipleExecuteError, which doesn't exist in sshkit 1.25 — a host whose checks failed wholesale became aNameErrorinstead of a recorded SSH failure. The new test was the first thing to trip it.Closes #98
Test plan
test/cli/doctor_test.rb(two new fixtures: sleep+socket, socket-only)mount_destinationscommand shape intest/commands/proxy_test.rbbundle exec rubocop --parallelclean; full unit suite greenDeviations & judgment calls
sleep:configured —docker_socketalone is a legal one-key convenience, and a missing mount then breaks nothing yet, so it warns as drift instead. The issue didn't specify; erring toward "FAIL means something is broken right now".docker.sock$on mount destinations) — the gem always mounts the socket at its host path, so this catches every gem-made mount; an operator-mounted socket viarun.optionswith an exotic name would not warn. Deliberate: better to under-warn than false-alarm on custom mounts.stub_proxy_versionnow also stubs mounts to empty — every running-proxy doctor test hits the new inspection, and per-test boilerplate in eight places was worse than one documented default in the shared helper.dashper request (themainmirror is never a valid root — "latest main" for this fork meansdash).