From f0e7ac73d6275af918299ae0abdde707a91957a0 Mon Sep 17 00:00:00 2001 From: Dai Ha Date: Thu, 3 Sep 2026 16:32:23 +0700 Subject: [PATCH] #103: give the operator the string that is actually in the log MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The merged fix told the operator to look in journalctl for "Fleetd.reportRequiredSecrets". That string never appears there — it is a method name. The logger is d.l.f.Fleetd and the lines read "startup secret NAME: set|MISSING", so the advice sent the operator looking for text that does not exist. Give the grep instead, and say what the report does not cover: it lists only names a configured profile references, so a secret nothing references is never reported. --- deploy/fleetd.service | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/deploy/fleetd.service b/deploy/fleetd.service index beb09e2..6d4e4eb 100644 --- a/deploy/fleetd.service +++ b/deploy/fleetd.service @@ -42,8 +42,16 @@ Environment=PATH=/usr/lib/jvm/temurin-25-jdk/bin:/usr/share/maven/bin:/usr/local # AI_GATEWAY_TOKEN authenticates gateway profiles; if it is missing, fleetd still starts, but a # gateway profile later returns HTTP 401. Or, put the same three variables in a 0600 file and add: # EnvironmentFile=%h/.config/fleetd/env -# After starting, check `journalctl --user -u fleetd` for Fleetd.reportRequiredSecrets. It lists -# the required secret names that resolved, without printing their values. +# After starting, check which of them actually resolved. The daemon reports every secret a +# configured profile references, by name, never by value: +# journalctl --user -u fleetd | grep 'startup secret' +# A resolved one logs "startup secret NAME: set (profile 'x' tokenEnv)". A missing one logs +# "startup secret NAME: MISSING" at WARN — and the daemon starts anyway, which is the whole +# problem: without this grep the first sign is a member that cannot open a pull request, hours +# later and in a different component. +# Note what the report can and cannot tell you. It lists only names some profile actually +# references (tokenEnv, gitTokenEnv, and the broker uriEnv). A secret nothing references is never +# reported, because nothing needs it. Restart=on-failure RestartSec=10s