Archived
Fix beszel-agent losing its hub-pairing fingerprint on every restart
services.beszel.agent runs under DynamicUser=true with ProtectSystem = "strict" and no StateDirectory, so /var/lib/beszel-agent -- where the agent persists the fingerprint that locks its hub pairing to this machine (github.com/henrygd/beszel/discussions/1542) -- was never actually writable. Every restart silently failed to persist it and regenerated a fresh one in memory, permanently desyncing from whatever the hub had on record after the very first successful pairing. Affects every host importing modules/beszel/enable-agent.nix (nix-cache, server), not just full container rebuilds. Found via nix-cache showing "fingerprint mismatch" after being rebuilt post-outage; confirmed server was silently exposed to the same bug, just hadn't restarted since its first pairing. Fixed by declaring StateDirectory so systemd gives the dynamic user real persistent storage. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,4 +6,13 @@
|
|||||||
#DOCKER_HOST = "tcp://docker-socket-proxy:2375";
|
#DOCKER_HOST = "tcp://docker-socket-proxy:2375";
|
||||||
HUB_URL = "http://${vars.dockerHost}.${vars.homeDomain}:${toString vars.ports.beszelHub}";
|
HUB_URL = "http://${vars.dockerHost}.${vars.homeDomain}:${toString vars.ports.beszelHub}";
|
||||||
};
|
};
|
||||||
|
|
||||||
|
# The upstream module runs beszel-agent under DynamicUser with
|
||||||
|
# ProtectSystem = "strict" and no StateDirectory, so /var/lib/beszel-agent
|
||||||
|
# (where the agent persists its hub-pairing fingerprint, per
|
||||||
|
# https://github.com/henrygd/beszel/discussions/1542) isn't writable --
|
||||||
|
# every restart silently fails to save it and regenerates a fresh one in
|
||||||
|
# memory, permanently desyncing from whatever the hub has on record after
|
||||||
|
# the very first successful pairing. Give it real persistent storage.
|
||||||
|
systemd.services.beszel-agent.serviceConfig.StateDirectory = "beszel-agent";
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user