Repository navigation
feat(install): OpenRC 下 agent 也以 monitor-agent 运行 - #49
Merged
Merged
Conversation
stqfdyr
force-pushed
the
feat/openrc-agent-user
branch
from
September 23, 2026 03:26
5f043a1 to
742dcce
Compare
没有 useradd 的系统(Alpine)用 BusyBox adduser 建用户;服务脚本加 command_user,启动前用 checkpath 把日志交给该用户(supervise-daemon 降权之后才打开日志)。supervise-daemon 在 agent 反复退出时仍报告 started,重启后改看进程是否存在。卸载补 deluser。
stqfdyr
force-pushed
the
feat/openrc-agent-user
branch
from
September 23, 2026 03:46
742dcce to
1aa54e8
Compare
stqfdyr
added a commit
to monitor-probe/monitor-document
that referenced
this pull request
Sep 24, 2026
- 设计哲学:OpenRC 的提示框改为「同样以专用用户运行,但 systemd 那几行隔离项没有对应物」 - 卸载:OpenRC 的手动步骤补上删用户(Alpine 用 `deluser`,其它系统用 `userdel`,较早版本装的没有这个用户时静默跳过),删掉「不建系统用户」那句 - 设计哲学、FAQ、AI 部署提示词里「下载的二进制会以 root 跑起来」改为按实际写:以 root 执行的是安装脚本;GitHub 代理返回的内容会作为 agent 在每台节点上运行。systemd 自 monitor-probe/monitor#8 起、OpenRC 自 monitor-probe/monitor#49 起,agent 都不以 root 运行,警示的对象换成真正以 root 执行的那一环,力度不变
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
OpenRC(Alpine 等)下 agent 也改为以
monitor-agent用户运行,不再是 root。systemd 下它早已如此(#8)。useradd用它,没有的(Alpine)用 BusyBoxadduser -S -D -Hcommand_user="monitor-agent"。supervise-daemon降权之后才打开日志文件,所以start_pre里用checkpath把/var/log/monitor-agent.log交给该用户(0600),此前安装留下的 root 所有的日志也一并改过来;不改的话 agent 起不来pidof),不在就报错退出,不再打印installed。supervise-daemon在 agent 反复退出时rc-service status仍报告started,看状态看不出来;BusyBox 的pgrep -x按完整路径匹配,所以用pidof。不在时与 systemd 一样换回原来的二进制(fix(install): 从 DynamicUser 版本原地升级时补建用户;新版没起来时报错并换回原来的版本 #48)userdel不存在就用deluser与 systemd 相比仍然缺的是那套沙箱(
ProtectSystem=等),OpenRC 没有对应物。基于 #48(同一段建用户的代码),请在 #48 之后合并;与 #37、#39、#47 合并无冲突。
测试:Alpine 3.22 + OpenRC 容器:
monitor-agent后,hub 收到的disk_total相同,procs相同,其余指标只有正常波动monitor-agent运行,日志归属改正,连上 hub,退出码 0--iface):打出did not start,退出码 1,日志里是 agent 自己的报错monitor-agent运行,退出码 1systemd 回归(Ubuntu 24.04,
passwd: files systemd):全新安装、v1.0.0 DynamicUser 原地升级(NRestarts=0)、卸载删用户,均正常。sh -n、shellcheck -S warning通过。