CB-594: make supervision and a working fleet possible at the same time #86
Reference in New Issue
Block a user
Delete Branch "worker/cb594-96bead-8"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes #80.
What changed
scripts/bridged-launchd-wrapper.sh (new) — launchd execs this instead of java directly. It execs a login shell (
zsh -l), which sources ${SHARED_ENV}/tools/secrets.sh, and that shell execs the real command in its place (one process throughout). Verified empirically: run from a stripped env (env -i, no login-shell vars at all) it still resolves both WORKER_GITEA_TOKEN and AI_GATEWAY_TOKEN.Bridged.java — logs at startup which required secret env vars resolved and which are MISSING, by name only (never a value/prefix/length). The required set (
Bridged.requiredSecretEnvVars, package-private + pure, unit tested in RequiredSecretEnvVarsTest) is derived from the loaded config: every non-subscription profile'stokenEnv, plus every profile'sgitTokenEnvwhere set — not a hard-coded list. A missing var only warns; the daemon still boots.deploy/dev.ltms.bridged.plist — every CHANGEME replaced with this host's real paths (JAVA_HOME resolved via jenv's actual JDK 25.0.3 home, not /usr/libexec/java_home which reported the unrelated Applet-plugin JVM). ProgramArguments now points at the wrapper. StandardOut/ErrorPath both point at bridged/bridged.out, the same file scripts/redeploy-bridged.sh already tails, instead of an orphaned logs/ path nothing else referenced.
scripts/redeploy-bridged.sh — detects whether the launchd agent is loaded (
launchctl list) and reports it in --check (installed vs loaded are reported separately; --check stays read-only). When loaded, stop/start uselaunchctl unload/loadinstead of a raw kill + manual nohup, so only one supervisor ever touches the process. Reason: a bare SIGTERM makes this JVM exit 143 even with its shutdown hook running to completion (measured with a throwaway Java process carrying an equivalent shutdown hook, SIGTERM'd from a shell that couldwaiton it directly — exit 143, every time). KeepAlive.SuccessfulExit=false reads any nonzero exit as a crash and would restart the OLD jar before the script's own start step runs.Verification
mvn -f bridged/pom.xml clean install: BUILD SUCCESS, Tests run: 813, Failures: 0, Errors: 0, Skipped: 0 (unpiped).scripts/redeploy-bridged.sh --checkrun live: correctly reports the agent as not installed / not loaded (it has never been installed on this host, per the ticket), tokens resolve in a login shell, read-only confirmed (nothing changed).launchctl load/bootstrap, did not touch ~/Library/LaunchAgents, did not stop/restart the live daemon, did not edit secrets.sh — all out of scope per the ticket's hard limits.Install command for the operator (not yet run)
Out of scope, noticed but not touched