Skip to content

20260928 - Read the CARTO key the OS image now carries - #101

Merged
Purple10101 merged 1 commit into
mainfrom
20260928-carto-key-from-os-image
Sep 28, 2026
Merged

Purple10101 merged 1 commit into
mainfrom
20260928-carto-key-from-os-image

Conversation

@Purple10101

Copy link
Copy Markdown
Collaborator

What

owl-os#63 (merged) writes /etc/retina-gui/carto.env into the OS image from a CI secret, and nothing reads it. This adds that path to the unit, above the existing /data one.

EnvironmentFile=-/etc/retina-gui/carto.env
EnvironmentFile=-/data/retina-gui/carto.env

The order is the point

systemd applies EnvironmentFile= lines in sequence and a later assignment wins. So /etc is the fleet's copy and /data, listed second, is one node's own.

Reversed, an OS update carrying the fleet key would silently overwrite a key set on that node by hand. There's a test asserting the ordering, and I checked it fires by swapping the two lines and watching it go red.

Why two paths at all

Path Whose Survives an OS update?
/etc/retina-gui/carto.env the fleet's, from the image No, and that is what makes it useful
/data/retina-gui/carto.env this one node's Yes

/etc is on the rootfs, which every A/B update replaces wholesale, so it reaches existing nodes and rotates with each release. /data survives an update untouched, which is exactly why the image cannot seed it: a file written there only ever reaches a freshly flashed node.

Both lines keep the leading -. A node with neither file still boots, and the only consequence is the watermark it already has. A missing key must never decide whether the GUI starts.

Verification

Three tests: both paths are read, /etc comes first, and neither line has lost its dash. Full suite green (1012), ruff clean.

README updated — it documented only /data and was wrong as of owl-os#63.

Not verified: the live tile layer drawing on hardware with a real key. The key is verified against CARTO and the mechanism is unit-tested, but the two have never been put together on a node.

After this

Still needed before a node shows a real map, none of it in this PR: a CARTO_API_KEY secret on owl-os, a new retina-gui tag (v0.10.1 predates all of this work), an owl-os pin bump, and an OS release.

🤖 Generated with Claude Code

owl-os#63 writes /etc/retina-gui/carto.env into the image from a CI secret,
and nothing reads it. This adds that path to the unit, above the existing
/data one.

The order is the point rather than an accident. systemd applies
EnvironmentFile lines in sequence and a later assignment wins, so /etc is
the fleet's copy and /data, listed second, is one node's own. Reversed, an
OS update carrying the fleet key would silently overwrite a key set on that
node by hand.

Why two paths at all: /etc lives on the rootfs, which every A/B update
replaces wholesale, so it reaches existing nodes and rotates with each
release. /data survives an update untouched, which is exactly why the image
cannot seed it -- a file written there only ever reaches a freshly flashed
node.

Both lines keep the leading "-". A node with neither file still boots and
the only consequence is the watermark it already has.

Three tests: both paths are read, /etc comes first, and neither line has
lost its dash.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Purple10101
Purple10101 merged commit abda430 into main Sep 28, 2026
3 checks passed
@Purple10101
Purple10101 deleted the 20260928-carto-key-from-os-image branch September 28, 2026 13:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant