diff --git a/deploy/fleetd.service b/deploy/fleetd.service index beb09e2..6d4e4eb 100644 --- a/deploy/fleetd.service +++ b/deploy/fleetd.service @@ -42,8 +42,16 @@ Environment=PATH=/usr/lib/jvm/temurin-25-jdk/bin:/usr/share/maven/bin:/usr/local # AI_GATEWAY_TOKEN authenticates gateway profiles; if it is missing, fleetd still starts, but a # gateway profile later returns HTTP 401. Or, put the same three variables in a 0600 file and add: # EnvironmentFile=%h/.config/fleetd/env -# After starting, check `journalctl --user -u fleetd` for Fleetd.reportRequiredSecrets. It lists -# the required secret names that resolved, without printing their values. +# After starting, check which of them actually resolved. The daemon reports every secret a +# configured profile references, by name, never by value: +# journalctl --user -u fleetd | grep 'startup secret' +# A resolved one logs "startup secret NAME: set (profile 'x' tokenEnv)". A missing one logs +# "startup secret NAME: MISSING" at WARN — and the daemon starts anyway, which is the whole +# problem: without this grep the first sign is a member that cannot open a pull request, hours +# later and in a different component. +# Note what the report can and cannot tell you. It lists only names some profile actually +# references (tokenEnv, gitTokenEnv, and the broker uriEnv). A secret nothing references is never +# reported, because nothing needs it. Restart=on-failure RestartSec=10s