fix(caddy): tmpfiles Z field order — Mode comes before User/Group #10

Merged
Faris merged 2 commits from fix/caddy-local-tmpfiles-mode into main 2026-10-02 21:47:04 +01:00
Owner

Z /data caddy caddy - - parses as mode caddy and is silently skipped on every boot — that error came straight from the running container (00-nixos.conf:4: Invalid mode 'caddy'). Correct tmpfiles order is Type Path Mode User Group Age: Z /data - caddy caddy - -.

Both caddies get the corrected rule (the vlan50 one had the same silently-dead line; its tree was caddy-owned only because caddy re-issued certs itself). After merge + deploy: the old admin-owned 0600 keys get chowned at boot, certs load, and the TLS handshakes recover — no re-issue storm.

`Z /data caddy caddy - -` parses as mode `caddy` and is silently skipped on every boot — that error came straight from the running container (`00-nixos.conf:4: Invalid mode 'caddy'`). Correct tmpfiles order is `Type Path Mode User Group Age`: `Z /data - caddy caddy - -`. Both caddies get the corrected rule (the vlan50 one had the same silently-dead line; its tree was caddy-owned only because caddy re-issued certs itself). After merge + deploy: the old admin-owned 0600 keys get chowned at boot, certs load, and the TLS handshakes recover — no re-issue storm.
'Z /data caddy caddy - -' parsed as mode 'caddy' and was silently
skipped on every boot (both caddies); the correct order is
'Z /data - caddy caddy - -' so the 0600 keys of the pre-existing
cert storage actually become readable by uid 239.
chore: sync with merged main
All checks were successful
eval / eval (pull_request) Successful in 22s
6ed990e963
Faris merged commit a89f48dd60 into main 2026-10-02 21:47:04 +01:00
Faris deleted branch fix/caddy-local-tmpfiles-mode 2026-10-02 21:47:04 +01:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Faris/nixos!10
No description provided.