20260928 - Read the CARTO key the OS image now carries - #101
Merged
Merged
Conversation
owl-os#63 writes /etc/retina-gui/carto.env into the image from a CI secret, and nothing reads it. This adds that path to the unit, above the existing /data one. The order is the point rather than an accident. systemd applies EnvironmentFile lines in sequence and a later assignment wins, so /etc is the fleet's copy and /data, listed second, is one node's own. Reversed, an OS update carrying the fleet key would silently overwrite a key set on that node by hand. Why two paths at all: /etc lives on the rootfs, which every A/B update replaces wholesale, so it reaches existing nodes and rotates with each release. /data survives an update untouched, which is exactly why the image cannot seed it -- a file written there only ever reaches a freshly flashed node. Both lines keep the leading "-". A node with neither file still boots and the only consequence is the watermark it already has. Three tests: both paths are read, /etc comes first, and neither line has lost its dash. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
owl-os#63 (merged) writes
/etc/retina-gui/carto.envinto the OS image from a CI secret, and nothing reads it. This adds that path to the unit, above the existing/dataone.The order is the point
systemd applies
EnvironmentFile=lines in sequence and a later assignment wins. So/etcis the fleet's copy and/data, listed second, is one node's own.Reversed, an OS update carrying the fleet key would silently overwrite a key set on that node by hand. There's a test asserting the ordering, and I checked it fires by swapping the two lines and watching it go red.
Why two paths at all
/etc/retina-gui/carto.env/data/retina-gui/carto.env/etcis on the rootfs, which every A/B update replaces wholesale, so it reaches existing nodes and rotates with each release./datasurvives an update untouched, which is exactly why the image cannot seed it: a file written there only ever reaches a freshly flashed node.Both lines keep the leading
-. A node with neither file still boots, and the only consequence is the watermark it already has. A missing key must never decide whether the GUI starts.Verification
Three tests: both paths are read,
/etccomes first, and neither line has lost its dash. Full suite green (1012), ruff clean.README updated — it documented only
/dataand was wrong as of owl-os#63.Not verified: the live tile layer drawing on hardware with a real key. The key is verified against CARTO and the mechanism is unit-tested, but the two have never been put together on a node.
After this
Still needed before a node shows a real map, none of it in this PR: a
CARTO_API_KEYsecret on owl-os, a new retina-gui tag (v0.10.1predates all of this work), an owl-os pin bump, and an OS release.🤖 Generated with Claude Code