Find a file
Andrei Kvapil 1436fee2dd
[hack] Add host runtime preflight check for standalone containerd/docker (#2371)
## What this PR does

Adds a host preflight diagnostic script (`hack/check-host-runtime.sh`)
that warns operators when a standalone `containerd.service` or
`docker.service` is running on the host alongside the embedded k3s
runtime used by the cozystack `generic` variant (k3s / kubeadm on
Ubuntu).

**Why it matters.** K3s ships its own containerd at
`/run/k3s/containerd/containerd.sock` and
`/var/lib/rancher/k3s/agent/containerd`, while a system-package
containerd or docker uses `/run/containerd/containerd.sock` and
`/var/lib/containerd`. The two runtimes do not fight over sockets, so
both keep running silently. Over time the standalone one accumulates
unpruned images and build cache in `/var/lib/containerd` — enough to
fill the root disk, trigger `DiskPressure`, and put `cozystack-api` into
an eviction loop. This is silent on day zero and surfaces as a
mysterious production incident weeks later. The script exists to warn
the next operator before the failure mode surfaces.

The script is warning-only — it always exits 0 and never blocks the
install. It detects:

- `containerd.service` or `docker.service` active via `systemctl
is-active`
- Standalone runtime sockets at well-known paths, with a fallback that
works on hosts without systemd
- Standalone data directory sizes via `du -sh`

When a warning fires, the HINT names only the detected services and
instructs the operator to disable them with `sudo systemctl disable
--now <service>`. Reclaiming the data directory is called out separately
with an explicit note not to delete it blindly — the data may still be
in use.

**Entry points.**

- `make preflight` runs the script directly (for operators preparing a
generic-variant host)
- `make unit-tests` now runs `bats-unit-tests` alongside
`helm-unit-tests`, auto-discovering every `hack/*.bats` file that is not
an e2e test

**Test coverage.** `hack/check-host-runtime.bats` (11 cases, run via
`hack/cozytest.sh`) covers clean hosts with and without systemd,
single-service detection, both services simultaneously, socket-only
fallback for both runtimes, glob-expansion regression guard, explicit
exit-code-0 assertion, `sudo` prefix assertion, `du` failure robustness,
and the "service + socket = exactly one warning" de-duplication
invariant. Every test is self-contained with `trap 'rm -rf $STUB_DIR'
EXIT` for clean recovery on assertion failure, and has no runtime
dependencies beyond bash and core utilities — no python3, no real
systemd.

Irrelevant on Talos where the container runtime lifecycle is fully
managed by the distribution.

### Release note

```release-note
[hack] Add `check-host-runtime.sh` and `make preflight` target that warn when a standalone containerd or docker runtime is running alongside the embedded k3s runtime on the cozystack generic variant.
```


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a non-blocking preflight check that detects standalone container
runtimes, reports disk-usage estimates, and displays an actionable hint
to disable detected services.

* **Tests**
* Added BATS-based unit tests with comprehensive coverage for the
preflight validations and various host scenarios.

* **Chores**
* Build updated to run the BATS unit tests alongside the existing test
suite.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-12 11:39:23 +02:00
.github chore: replace cozystack-bot PAT with cozystack-ci GitHub App 2026-04-07 01:43:04 +05:00
api feat(backups): restore vmi to copy in another namespace 2026-04-09 14:06:33 +04:00
cmd feat(backup): no manual actions required to perform restorejob for 2026-03-31 12:01:04 +04:00
dashboards feat(monitoring): add MongoDB Grafana dashboards 2026-03-05 22:47:53 +03:00
docs docs(changelog): fix v1.2.1 link in v1.2.0 deprecation warning 2026-04-02 19:00:43 +02:00
examples/backups/vmi feat(backups): restore vmi to copy in another namespace 2026-04-09 14:06:33 +04:00
hack fix(hack): wrap du in 'timeout 5s' to prevent preflight stall 2026-04-11 17:07:35 +03:00
img Cozystack logo for dark GitHub theme (#9) 2024-02-09 11:02:41 +01:00
internal feat(backups): restore vmi to copy in another namespace 2026-04-09 14:06:33 +04:00
packages [cilium] Move AppArmor podAnnotations to a non-Talos-only values file 2026-04-11 16:39:58 +03:00
pkg [platform] Validate computed tenant namespace length in cozystack-api 2026-04-12 03:29:25 +03:00
tools/openapi-gen [docs] Added openapi generation tool 2026-03-25 15:57:25 +05:00
.gitignore fix(installer): add build revision marker to trigger platform reconciliation 2026-03-18 21:37:23 +05:00
.pre-commit-config.yaml [cozystack-api] Implement TenantNamespace, TenantModules, TenantSecret and TenantSecretsTable resources 2025-09-24 18:27:54 +02:00
ADOPTERS.md Update ADOPTERS.md by adding new adopter 2025-12-18 16:45:06 +03:00
AGENTS.md [agents] Add instructions for working with unresolved code review comments 2025-12-10 21:10:56 +01:00
CODE_OF_CONDUCT.md Update CODE_OF_CONDUCT.md 2025-10-08 09:43:34 +05:00
CONTRIBUTING.md [docs] Proofread the readme and contributing 2025-04-09 11:09:19 +03:00
CONTRIBUTOR_LADDER.md Update CONTRIBUTOR_LADDER.md 2025-10-08 09:28:27 +05:00
go.mod feat(lineage-webhook): import scheduling constants from cozystack-scheduler 2026-03-18 14:08:29 +03:00
go.sum feat(lineage-webhook): import scheduling constants from cozystack-scheduler 2026-03-18 14:08:29 +03:00
GOVERNANCE.md Create GOVERNANCE.md (#733) 2025-04-01 18:48:14 +02:00
LICENSE Preapare release v0.0.1 2024-02-08 12:04:32 +01:00
MAINTAINERS.md Update MAINTAINERS.md 2025-10-08 09:16:26 +05:00
Makefile docs(hack): note whitespace caveat on BATS_UNIT_FILES wildcard 2026-04-11 14:37:06 +03:00
README.md docs: add OpenSSF Best Practices badge to README 2026-04-01 22:32:08 +02:00
SECURITY.md docs: add SECURITY.md 2026-03-17 02:57:52 +05:00

Cozystack Cozystack

Open Source Apache-2.0 License Support Active GitHub Release GitHub Commit OpenSSF Best Practices

Cozystack

Cozystack is a free PaaS platform and framework for building clouds.

Cozystack is a CNCF Sandbox Level Project that was originally built and sponsored by Ænix.

With Cozystack, you can transform a bunch of servers into an intelligent system with a simple REST API for spawning Kubernetes clusters, Database-as-a-Service, virtual machines, load balancers, HTTP caching services, and other services with ease.

Use Cozystack to build your own cloud or provide a cost-effective development environment.

Cozystack user interface

Use-Cases

Documentation

The documentation is located on the cozystack.io website.

Read the Getting Started section for a quick start.

If you encounter any difficulties, start with the troubleshooting guide and work your way through the process that we've outlined.

Versioning

Versioning adheres to the Semantic Versioning principles.
A full list of the available releases is available in the GitHub repository's Release section.

Contributions

Contributions are highly appreciated and very welcomed!

In case of bugs, please check if the issue has already been opened by checking the GitHub Issues section. If it isn't, you can open a new one. A detailed report will help us replicate it, assess it, and work on a fix.

You can express your intention to on the fix on your own. Commits are used to generate the changelog, and their author will be referenced in it.

If you have Feature Requests please use the Discussion's Feature Request section.

Community

You are welcome to join our Telegram group and come to our weekly community meetings. Add them to your Google Calendar or iCal for convenience.

License

Cozystack is licensed under Apache 2.0.
The code is provided as-is with no warranties.

Commercial Support

A list of companies providing commercial support for this project can be found on official site.