Skip to content

feat(update): keep the monitoring agent correct after fly update - #35

Merged
nabil1440 merged 2 commits into
agent/29-commandsfrom
agent/30-update
Sep 28, 2026
Merged

nabil1440 merged 2 commits into
agent/29-commandsfrom
agent/30-update

Conversation

@nabil1440

@nabil1440 nabil1440 commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Layer 5 of 7 of the monitoring agent (#31 → #37).

Summary

  • fly update stays. When the server has the latest release, it does nothing.
  • After an update, fly update restarts the agent, so the agent uses the new binary at once. If the agent still uses an old binary, fly update restarts it.
  • The new binary belongs to the server user, not to root.
  • A script without --yes and without a terminal gets an error, not a false success.

Change

  • internal/service: the unit of the agent (try-restart, and a check for a replaced binary).
  • internal/release: the new binary keeps the owner of the old binary.
  • cmd/version.go: the restart after an update, and the terminal check.
  • CI: the tests that need root run with sudo.

Adversarial review

The first version was refuted. These items are fixed in this PR:

  • The owner is given through the open file, not the path. The folder of the agent's binary belongs to the server user, who could put a link to a root file in place of the temporary file.
  • A systemctl failure shows its message. Before, fly update exited 1 with no message.
  • try-restart: an agent that an administrator stopped stays stopped.
  • An agent process that ends during the check is not stale. The timeout of systemctl is 2 minutes.

Tests

  • The restart decisions with a fake systemctl, the error messages through the exit code, and the terminal check.
  • As root (in CI): the owner is kept, and a link in place of the temporary file does not change the linked file.

Closes #30

@nabil1440
nabil1440 added this pull request to stack #38 September 22, 2026 10:40
@nabil1440 nabil1440 self-assigned this Sep 22, 2026
@nabil1440 nabil1440 changed the title agent/30 update feat(update): keep the monitoring agent correct after fly update Sep 22, 2026
- After fly update replaces the binary, restart fly-agent when the server
  has the agent. The agent then runs the new binary at once.
- When fly is already up to date but the agent still runs a replaced binary
  (the kernel shows it as "(deleted)"), restart the agent.
- Keep the owner of the old binary: sudo fly update no longer gives the
  agent's binary in ~fly/.fly/bin to root.
- Without --yes and without a terminal, stop with an error (exit 1). A
  script no longer reads "Update cancelled." as success.
- Add internal/service for the systemd unit of the agent.

Refs #30
…tl errors

Fixes from the adversarial review of this layer.

- Give the new binary its owner through the open file (fchown), not its
  path. The folder of the agent's binary belongs to the server user, who
  could put a link to a root file (for example /etc/shadow) in place of
  the temporary file, and root would then give that file to the user.
- A systemctl failure now shows its message. Before, fly update exited 1
  with no message, because the wrapped exit status looked like the error
  of a child process that had already reported it.
- Restart the agent with try-restart: an agent that an administrator
  stopped stays stopped.
- An agent process that ends during the check is not stale.
- Wait up to 2 minutes for systemctl, longer than the stop timeout of
  systemd.
- CI runs the tests that need root (the owner and the link attack).

Refs #30
@nabil1440
nabil1440 merged commit 656bc13 into develop Sep 28, 2026
1 of 2 checks passed
@nabil1440
nabil1440 deleted the agent/30-update branch September 28, 2026 03:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

enhancement: Keep the agent correct after fly update

1 participant