Protect a container¶
While you set things up, syslet removes anything you drop from the repository, which makes it easy to experiment. Once a setup works, an accidental deletion or a bad merge shouldn't take it down.
In this tutorial, you'll see what a removal looks like in the plan, then lock the site container from Deploy with CUE so syslet leaves it running.
Prerequisites¶
- The
infrarepository with thesitecontainer from Deploy with CUE.
1. Preview a removal¶
enabled: false leaves an entry out of the spec without deleting it from web01.cue, so you can see what a removal would do.
Add this line to web01.cue:
| Text Only | |
|---|---|
Preview it, but don't apply:
| Bash | |
|---|---|
syslet would stop the container and delete its unit file and config files:
| Text Only | |
|---|---|
syslet removes it because #SysdefDefaults set removalAllowed: true, which syslet recorded in the unit file as [X-Syslet] RemovalAllowed=true.
Remove the enabled: false line again.
2. Lock the container¶
Add the tools import below the package line of web01.cue, and the lock at the end:
#SysdefLock sets removalAllowed: false on every container, network and volume listed.
For volumes, it also sets reclaimPolicy: "Retain", so their data survives even when the unit is removed.
Preview it:
| Bash | |
|---|---|
The plan only changes metadata in the unit file, so nothing is restarted:
| Text Only | |
|---|---|
3. Check the lock¶
Add sysdef: containers: site: enabled: false to web01.cue again and run:
| Bash | |
|---|---|
This time syslet skips the container and leaves it running:
| Text Only | |
|---|---|
The lock is stored on the host, in the unit file. That's why it still protects the container once the spec is gone.
Remove the enabled: false line again.
To remove a locked container on purpose, first drop it from the #SysdefLock list and apply, then delete it from web01.cue and apply again.
See Removing specs for details.
The site container is now safe from accidental removal.
Every change goes through cue cmd plan, cue cmd apply and a commit.
Continue with Set up SOPS encryption.