Skip to content

Protect a container

While you set things up, syslet removes anything you drop from the repository, which makes it easy to experiment. Once a setup works, an accidental deletion or a bad merge shouldn't take it down.

In this tutorial, you'll see what a removal looks like in the plan, then lock the site container from Deploy with CUE so syslet leaves it running.

Prerequisites

1. Preview a removal

enabled: false leaves an entry out of the spec without deleting it from web01.cue, so you can see what a removal would do. Add this line to web01.cue:

Text Only
sysdef: containers: site: enabled: false

Preview it, but don't apply:

Bash
cue cmd plan

syslet would stop the container and delete its unit file and config files:

Text Only
Unit files to delete:
  - site.container

Config directories to delete:
  - site/

Services to stop:
  - site.container

Systemd daemon-reload: required

Summary:
UNIT                                     STATUS     CHANGES
site.container                           removed    removed

syslet removes it because #SysdefDefaults set removalAllowed: true, which syslet recorded in the unit file as [X-Syslet] RemovalAllowed=true.

Remove the enabled: false line again.

2. Lock the container

Add the tools import below the package line of web01.cue, and the lock at the end:

web01.cue
package syslet

import syslettools "github.com/xchangeee/syslet/schema/tools@v0"

sysdef: containers: site: spec: {
    unit: Container: {
        Image: "docker.io/library/nginx:1.27"
        PublishPort: ["8080:80"]
    }
    configFiles: [{
        mountPath: "/etc/nginx/conf.d/default.conf"
        mode:      "0644"
        content: """
            server {
                listen 80;
                root /usr/share/nginx/html;
                location /healthz { return 200 "ok"; }
            }
            """
    }]
}

sysdef: (syslettools.#SysdefLock & {in: containers: ["site"]}).out

#SysdefLock sets removalAllowed: false on every container, network and volume listed. For volumes, it also sets reclaimPolicy: "Retain", so their data survives even when the unit is removed.

Preview it:

Bash
cue cmd plan

The plan only changes metadata in the unit file, so nothing is restarted:

Text Only
Unit file changes:

--- site.container
changed:
  [X-Syslet] RemovalAllowed
    old: true
    new: false

Systemd daemon-reload: required

Summary:
UNIT                                     STATUS     CHANGES
site.container                           updated    unit updated (desired: running)
Bash
cue cmd apply
git add -A && git commit -m "lock site"

3. Check the lock

Add sysdef: containers: site: enabled: false to web01.cue again and run:

Bash
cue cmd plan

This time syslet skips the container and leaves it running:

Text Only
1
2
3
4
5
Summary:
UNIT                                     STATUS     CHANGES
site.container                           skipped    protected (removalAllowed: false)

No changes detected. All units are up to date.

The lock is stored on the host, in the unit file. That's why it still protects the container once the spec is gone.

Remove the enabled: false line again.

To remove a locked container on purpose, first drop it from the #SysdefLock list and apply, then delete it from web01.cue and apply again. See Removing specs for details.

The site container is now safe from accidental removal. Every change goes through cue cmd plan, cue cmd apply and a commit.

Continue with Set up SOPS encryption.