fix(update): say that setup cannot move felis-api to a newer release
`felis update` offers `sudo felis setup` for every planner-backed target and closed with a trailer calling setup idempotent. That is true for velocity -- install_velocity re-resolves the newest build of the pinned minor on each run -- and misleading for felis-api, which both --panel and --plugins resolve to. setup hands bootstrap the binary it is itself running and takes the bootstrap_from_tui arm, which skips the release lookup. The run rebuilds the image and rolls the deployment off that SAME binary: it reports success and leaves the version exactly where it was. An operator following this guidance to apply a felis-api update would watch it appear to work and then see the same version reported again. Only the bootstrap installer moves felis-api, and naming it is where this gets dangerous, so the warning ships with it. The installer is not an updater. Every run re-derives FELIS_ROOT_DOMAIN through detect_node_ip and defaults it to <node-ip>.nip.io; nothing reads the domain back out of the felis.toml an earlier run wrote. A bare re-run -- which is exactly what README documents, with no environment at all -- rewrites root-domain, panel-hostname and admin-hostname to nip.io names, while ensure_panel_tls_cert returns early on the certificate it already wrote and keeps serving the old hostnames. The console then fails to match its own certificate, and there is no re-domain flow to recover with. Persisted secrets are not at risk: load_or_make_secrets sources secrets.env before it generates anything. felis update stays report-only, so no command changed; only the claim about what the offered one accomplishes, and the conditions under which the alternative is safe to run. Tested four ways, because the scoping and the warning are both the point: --panel carries the caveat AND names FELIS_ROOT_DOMAIN, --velocity keeps the ordinary trailer without either, and --mc, which offers no command at all, gets neither.
This commit is contained in:
2 files changed
+18
-3
No files matched your search
+10
-3
@@ -260,10 +260,17 @@ func renderApplyGuidance(res updater.Result, selected map[string]bool, force boo
|
||||
// on every run. But setup hands deploy/bootstrap.sh the binary it is itself running
|
||||
// (FELIS_BOOTSTRAP_BINARY), and that arm skips the release lookup entirely, so it
|
||||
// rebuilds the image and rolls the deployment from the SAME binary -- a run that looks
|
||||
// like a successful update and leaves the version unchanged. Only the installer, which
|
||||
// resolves and downloads a release, actually moves felis-api.
|
||||
// like a successful update and leaves the version unchanged.
|
||||
//
|
||||
// The installer is the only thing that moves felis-api, but it is NOT an updater and
|
||||
// must not be recommended as one without this warning. detect_node_ip re-derives
|
||||
// FELIS_ROOT_DOMAIN on every run and defaults it to <node-ip>.nip.io -- nothing reads
|
||||
// the domain back out of the felis.toml a previous run wrote. A bare re-run therefore
|
||||
// rewrites root-domain/panel-hostname/admin-hostname to nip.io names while
|
||||
// ensure_panel_tls_cert, which is write-once, keeps serving the old ones: the console
|
||||
// stops matching its own certificate. There is no re-domain flow to recover with.
|
||||
if offeredFelisAPI {
|
||||
b.WriteString("\nfelis-api (panel, plugins) is the exception: setup re-images it from the felis binary\nalready on this host, so it cannot install a NEWER felis-api. To move to a newer\nrelease, re-run the bootstrap installer (see README).\n")
|
||||
b.WriteString("\nfelis-api (panel, plugins) is the exception: setup re-images it from the felis binary\nalready on this host, so it cannot install a NEWER felis-api. Only re-running the\nbootstrap installer does that, and it is a full install run, not an update: give it the\nSAME environment as the original install, FELIS_ROOT_DOMAIN above all. It defaults to\n<node-ip>.nip.io, and a bare re-run re-domains this install while the write-once panel\ncertificate keeps the old hostnames.\n")
|
||||
}
|
||||
return b.String()
|
||||
}
|
||||
@@ -148,6 +148,14 @@ func TestApplyGuidanceScopesTheFelisAPICaveat(t *testing.T) {
|
||||
if !strings.Contains(api, caveat) {
|
||||
t.Fatalf("--panel resolves to felis-api and must carry the caveat:\n%s", api)
|
||||
}
|
||||
// Naming the installer without naming this is worse than saying nothing: the README
|
||||
// invocation carries no environment, detect_node_ip then defaults FELIS_ROOT_DOMAIN
|
||||
// to <node-ip>.nip.io, and the operator re-domains a live install by following our
|
||||
// own advice. Nothing reads the previous domain back, and the write-once panel cert
|
||||
// keeps the old hostnames, so there is no recovery path either.
|
||||
if !strings.Contains(api, "FELIS_ROOT_DOMAIN") {
|
||||
t.Fatalf("pointing at the installer without the re-domain warning is a footgun:\n%s", api)
|
||||
}
|
||||
|
||||
vel := renderApplyGuidance(
|
||||
planResult([]updates.Action{{Component: "velocity", Kind: updates.ActionNotify, LatestKnown: true}}),
|
||||
|
||||
Reference in new issue
Block a user