Conversation
… slowly Map every rejection to a sentence naming the fix and the dashboard page that applies it, include the agent's protocol version on a mismatch, and repeat the explanation every 30 minutes, including while the collector is stopped. A revoked or unknown key (HTTP 401 / invalid_key) still stops until the container is recreated with a new key. A blocked host, a protocol mismatch and an HTTP 403 from something in front of Cloud can all clear without touching the agent, so they now re-check about every 15 minutes for up to 24 hours before stopping. Over-cap rejections retry at the same calm 30-60 s pace as a closed enrollment window. Refs marvinvr/docktail-cloud#39
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
When DockTail Cloud refuses the agent's connection, the agent used to log one line with the raw reason code, for example
cloud: hello rejected (terminal) — stopping, and then stop for the life of the process. The log gave no remediation and no hint that a restart was needed.What changes
Every rejection gets a sentence that says what to do. Each reason code maps to one or two sentences naming the fix and the dashboard page where you apply it:
/settings/agent-keys/hosts/settings/billing/settings/agent-keysA protocol mismatch also logs the agent's version and protocol version and says to pull a newer image. The classification lives in the new
cloud/reject.go.The explanation repeats. The full hint is logged on the first rejection and then every 30 minutes, including while the collector is stopped, so it stays near the end of
docker logs. Retries in between log one short line.Retry behaviour now depends on the reason:
http_401,invalid_keyblocked,protocol_mismatch,http_403over_capenrollment_closed.Docs:
docs/06-cloud.mdgains a "Connection Problems" table covering each reason, what it means, what the agent does and how to fix it.The wire protocol is unchanged.
Not included
The mismatch message does not show the protocol version the server expects, because
hello_ackdoes not carry it and adding it would need a protocol change.Refs marvinvr/docktail-cloud#39