Files
worker/docs/changelog.md
Gleb Tv cb23f123ae
Все проверки выполнены успешно
CI / test (push) Successful in 10m15s
Docker / Build and publish worker image (push) Successful in 34m59s
feat(worker): adopt canonical public URL
2026-08-12 20:48:01 +03:00

4.5 KiB

Changelog

2026-08-12

Public endpoint configuration (milestone 1 of public-endpoint-and-identity)

  • PUBLIC_URL is now the canonical advertised public origin; the legacy WORKER_URL is accepted only for the bounded migration and logs a startup deprecation warning. PUBLIC_URL wins whenever both are set, and the installer drops WORKER_URL from freshly written env files when PUBLIC_URL is present.
  • Startup and install validate the origin shape: absolute http/https URL with scheme and authority only; userinfo, query, fragment, and any path other than / are rejected.
  • Plain-HTTP PUBLIC_URL on a non-loopback host is rejected in an explicitly production environment (DEPLOY_ENV, RSMON_ENV, or GO_ENV = production); other environments keep the historical warning.
  • internal/wire adds public_url to WorkerInit (control plane to worker), keeping the legacy url field for old control planes; the worker prefers public_url and rejects unusable values, keeping the previous accepted URL. RegisterRequest.public_url is the registration contract for the pending RSMon counterpart (the worker does not currently transmit the URL during registration; it consumes the accepted endpoint from WorkerInit).
  • The legacy WORKER_URL is held only to the tolerant absolute-URL check (no newly rejected legacy shapes); PUBLIC_URL is held to the strict scheme-and-authority origin shape. Both reject a missing hostname, e.g. https://:27401.

2026-07-19

Standalone installation and deployment

  • Added rsmon-worker install for installing the current binary, a mode-0600 environment file, and a root-owned systemd service.
  • Added rsmon-worker deploy for installing workers over SSH with key or password authentication, optional secret files, and host-key verification through known_hosts or a pinned fingerprint.
  • Added --token-file, --url, --api-key, and --no-start deployment options.
  • Added optional --docker deployment using a prebuilt image. Docker install and deploy now require an immutable repository@sha256:... reference before any Docker or remote-host mutation; the former mutable latest default is no longer accepted.
  • Simplified the default systemd service to Type=simple, User=root, and Restart=on-failure.
  • Reworked the legacy scripts/install-systemd.sh script as a compatibility wrapper around the built-in installer.

Standalone repository cleanup

  • Removed the remaining certificate-bundle fallback under /data/rsmon and updated its documentation.
  • Changed Docker build and runtime bases to public Go and Debian images.
  • Documented binary, systemd, Docker, and SSH deployment workflows.
  • Added installer and SSH host-verification tests.

Verification

  • Passed make test, make build, go vet, and go mod verify.
  • Validated systemd units, Compose configuration, Docker image pull and execution, and production worker job reporting.
  • Published the changes as commit 3256dcd (feat: add worker install and deploy) on master, triggering the Docker image workflow.

Task protocol and local audit hardening

  • Required one task-envelope branch, matching outer/inner job IDs, and a non-empty lease token before local execution.
  • Added structured terminal failures for unsupported check kinds and safely attributable malformed envelopes.
  • Recorded delegated notification outcomes in the bounded /notifications view using only job ID, method, status, duration, and time.
  • Added static permanent handling for invalid deadlines and recovered notification executor panics without retaining secret-bearing text.
  • Removed the critical-cluster test-config endpoint, CLI flag, environment switch, and production helper; hardcoded config application is test-only.
  • Made runner token rotation connection-scoped and in-memory: it reconnects without stopping web, inventory, metrics, or cluster subsystems. Durable token storage, bootstrap exchange, rotation acknowledgement, and revocation remain unimplemented.
  • Added bounded resend of dequeued check and notification result envelopes after websocket reconnect; control-plane application remains at-least-once and must deduplicate by leased job and lease token. Failed metric snapshots are dropped and replaced by the next periodic tick, not replayed.
  • SIGTERM stops new dispatch and waits for active work, but stale-lease acknowledgement, bounded graceful final-result drain, and duplicate-frame coverage remain open.