quietPath:=fs.String("quiet-file","/run/felis/watchdog-quiet-until","Unix time before which nothing is mailed; the installer writes it while it restarts things on purpose")
backupDir:=fs.String("backup-dir","/var/lib/felis/db-backups",`control-plane database backups to check for freshness ("" skips the check)`)
diskPaths:=fs.String("disk-paths","/,/var/lib/rancher/k3s,/var/lib/felis","comma-separated paths whose filesystems must keep free space")
certDirs:=fs.String("k3s-cert-dirs",strings.Join(watchdog.K3sCertDirs,","),`k3s certificate directories whose *.crt files must not be near expiry ("" skips the check)`)
proxyAddr:=fs.String("proxy-addr","",`game proxy address to dial, e.g. 127.0.0.1:25565 ("" skips the check)`)
nodeIP:=fs.String("node-ip","",`the node address the install was made on, which must stay on this host ("" skips the check)`)
controlNS:=fs.String("control-namespace",platform.DefaultControlNamespace,"namespace of the control plane")
f.SummaryEN=fmt.Sprintf("the k3s certificate %s (%s) expired at %s: the k3s components can no longer authenticate to each other, so the cluster API, the node and the panel's server management stop working",
f.SummaryEN=fmt.Sprintf("the k3s certificate %s (%s) expires at %s (%d days left): once it does, the k3s components can no longer authenticate to each other, so the cluster API, the node and the panel's server management stop working",
file,soonest.Subject.CommonName,when,days)
}
ifsoonest.IsCA{
f.Hint="a k3s CA certificate, which no restart renews: rotate it with `k3s certificate rotate-ca` (docs/troubleshooting.md §13d)"
}else{
f.Hint="sudo systemctl restart k3s: k3s renews its certificates near expiry as it starts, and running game servers keep running; check with sudo k3s certificate check (docs/troubleshooting.md §13d)"