Define the collector, service, and CLI lifecycle #8

Closed
opened 2026-08-31 08:03:03 +00:00 by xavierk · 1 comment
Owner

Parent map: Chart Fenris’s persistent TUI monitoring redesign

Question

What is the exact lifecycle contract among the systemd collector, on-demand TUI, and non-interactive CLI? Decide service states and ownership, enable/disable versus start/stop semantics, sampling while the TUI is closed, configuration reloads, stale detection, explicit privilege prompts, and compatibility behavior for status, sample, and fenris.sh.

Parent map: [Chart Fenris’s persistent TUI monitoring redesign](https://git.bongbetic.com/xavierk/Fenris/issues/1) ## Question What is the exact lifecycle contract among the systemd collector, on-demand TUI, and non-interactive CLI? Decide service states and ownership, enable/disable versus start/stop semantics, sampling while the TUI is closed, configuration reloads, stale detection, explicit privilege prompts, and compatibility behavior for status, sample, and fenris.sh.
xavierk added this to the Wayfinder: Fenris persistent TUI monitoring redesign milestone 2026-08-31 08:03:03 +00:00
xavierk added the wayfinder:grilling label 2026-08-31 08:03:03 +00:00
xavierk added a new dependency 2026-08-31 08:03:19 +00:00
xavierk added a new dependency 2026-08-31 08:03:19 +00:00
xavierk added a new dependency 2026-08-31 08:03:19 +00:00
xavierk added a new dependency 2026-08-31 09:19:28 +00:00
xavierk self-assigned this 2026-08-31 10:21:20 +00:00
Author
Owner

Resolved Define the collector, service, and CLI lifecycle — full contract in ADR 0003.

Answer:

  • Units: two system units only — fenris-collect.timer (OnBootSec=2min, OnUnitInactiveSec=5min, AccuracySec=30s, Persistent=no, TimeoutStartSec=90s, WantedBy=timers.target) and root oneshot fenris-collect.service. No /run/fenris surface; journal holds failures.
  • Config: /etc/fenris/fenris.conf holds only the device selector (by-id preferred, node warned), re-read each run; invalid config = bounded failed run, surfaced as a fact by status/TUI. Interval changes live in a documented timer drop-in.
  • Privilege: crosses at exactly two binaries — /usr/libexec/fenris/fenris-collect (ExecStart) and /usr/libexec/fenris/fenris-monitor (enable/disable/collect trigger + period rows; the only polkit-authorized binary, action com.bongbetic.fenris.monitor, auth_admin). Root invokes helpers directly; no-agent environments fail cleanly with the root equivalent.
  • Sanctioned toggle: Pause = disable --now, Resume = enable --now, via the helper, which records monitoring-period rows idempotently (first enable opens at the enable moment; resume over a raw-stop gap keeps the gap inside as unknown seconds; only the sanctioned path writes user_disabled). This amends Verify systemd lifecycle and privilege constraints's direct-systemctl toggle — a period boundary cannot be recorded by systemctl; the research's spirit is intact.
  • On-demand: fenris sample and TUI collect-now trigger the oneshot through the helper and report the synchronous outcome; no sampling outside the collector; TUI Pause confirms, Resume doesn't.
  • Compatibility: status retained (read-only: store + allow-listed systemctl show, journal hint, never auto-samples); sample retained (helper path); --device, start, stop, run rejected with migration pointers; fenris.sh retired.
  • Freshness: shared constants — fresh ≤ 2× cadence + AccuracySec + 60 s; missed until 48 h; stale ≥ 48 h (matches ADR 0002's gate); empty store says "no observations yet" with an enable hint.

Glossary gained Collection run and Deliberate disable in CONTEXT.md. Unblocks the TUI prototype, installation, and failure-behavior tickets.

Resolved [Define the collector, service, and CLI lifecycle](https://git.bongbetic.com/xavierk/Fenris/issues/8) — full contract in [ADR 0003](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/docs/adr/0003-service-lifecycle-and-sanctioned-toggle.md). **Answer:** - **Units**: two system units only — `fenris-collect.timer` (`OnBootSec=2min`, `OnUnitInactiveSec=5min`, `AccuracySec=30s`, `Persistent=no`, `TimeoutStartSec=90s`, `WantedBy=timers.target`) and root oneshot `fenris-collect.service`. No `/run/fenris` surface; journal holds failures. - **Config**: `/etc/fenris/fenris.conf` holds only the device selector (by-id preferred, node warned), re-read each run; invalid config = bounded failed run, surfaced as a fact by `status`/TUI. Interval changes live in a documented timer drop-in. - **Privilege**: crosses at exactly two binaries — `/usr/libexec/fenris/fenris-collect` (ExecStart) and `/usr/libexec/fenris/fenris-monitor` (enable/disable/collect trigger + period rows; the only polkit-authorized binary, action `com.bongbetic.fenris.monitor`, `auth_admin`). Root invokes helpers directly; no-agent environments fail cleanly with the root equivalent. - **Sanctioned toggle**: Pause = `disable --now`, Resume = `enable --now`, via the helper, which records monitoring-period rows idempotently (first enable opens at the enable moment; resume over a raw-stop gap keeps the gap inside as unknown seconds; only the sanctioned path writes `user_disabled`). This amends [Verify systemd lifecycle and privilege constraints](https://git.bongbetic.com/xavierk/Fenris/issues/7)'s direct-systemctl toggle — a period boundary cannot be recorded by systemctl; the research's spirit is intact. - **On-demand**: `fenris sample` and TUI collect-now trigger the oneshot through the helper and report the synchronous outcome; no sampling outside the collector; TUI Pause confirms, Resume doesn't. - **Compatibility**: `status` retained (read-only: store + allow-listed `systemctl show`, journal hint, never auto-samples); `sample` retained (helper path); `--device`, `start`, `stop`, `run` rejected with migration pointers; `fenris.sh` retired. - **Freshness**: shared constants — fresh ≤ 2× cadence + `AccuracySec` + 60 s; missed until 48 h; stale ≥ 48 h (matches ADR 0002's gate); empty store says "no observations yet" with an enable hint. Glossary gained **Collection run** and **Deliberate disable** in [CONTEXT.md](https://git.bongbetic.com/xavierk/Fenris/src/branch/main/CONTEXT.md). Unblocks the TUI prototype, installation, and failure-behavior tickets.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Reference: xavierk/Fenris#8