Skip to content

feat(service): render systemd unit with configurable User, Group and WorkingDirectory - #174

Merged
yanksyoon merged 3 commits into
feat/agent-user-configfrom
feat/systemd-user-directive
Aug 11, 2026
Merged

feat(service): render systemd unit with configurable User, Group and WorkingDirectory#174
yanksyoon merged 3 commits into
feat/agent-user-configfrom
feat/systemd-user-directive

Conversation

@yanksyoon

Copy link
Copy Markdown
Member

Overview

Make the systemd unit template honor the new agent_user and jenkins_home config options by adding User=, Group=, WorkingDirectory= and an explicit Environment="JENKINS_HOME=..." directive.

Rationale

Rev 18 of this charm ran the agent as the jenkins user. The current charm's systemd unit has no user directive and always launches as root. This PR, building on the config added in #173, lets operators opt into the historical jenkins user while keeping root the default for backward compatibility.

Juju Events Changes

None.

Module Changes

  • templates/jenkins_agent.service: now a Jinja template with {{ agent_user }} and {{ jenkins_home }}.
  • src/service.py: renders the unit with state values; also updates is_active and environments to use the configured jenkins_home.
  • tests/unit/conftest.py: updates the expected override.conf fixture to include JENKINS_HOME.
  • tests/unit/test_service.py: adds tests for default and custom user/workdir rendering.

Library Changes

None.

Checklist

  • The charm style guide was applied
  • The contributing guide was applied
  • The changes are compliant with ISD054 - Managing Charm Complexity
  • The documentation is updated
  • The PR is tagged with appropriate label (trivial, senior-review-required)
  • The changelog has been updated

…WorkingDirectory

Uses the agent_user and jenkins_home values added in the previous commit to

render the systemd unit template. The unit now runs the launcher script as the

configured user and exports JENKINS_HOME for the launcher and agent process.

Defaults remain root and /var/lib/jenkins for backward compatibility.
@yanksyoon
yanksyoon requested a review from a team as a code owner July 23, 2026 16:59
@yanksyoon
yanksyoon requested review from florentianayuwono and javierdelapuente and removed request for a team July 23, 2026 16:59
yanksyoon and others added 2 commits August 11, 2026 13:26
* feat(launcher): honor configured JENKINS_HOME in agent script

Removes the hardcoded /var/lib/jenkins path in the launcher script and uses

the JENKINS_HOME environment variable. The unit already exports the configured

home. The script still falls back to /var/lib/jenkins if invoked directly,

preserving backward compatibility.

* feat(service): ensure agent user exists and owns JENKINS_HOME (#176)

* feat(service): ensure agent user exists and owns JENKINS_HOME

When agent_user is non-root, the charm now creates the user if missing and

ensures JENKINS_HOME is owned by that user. Failures are logged as warnings

so that pre-created users/homes do not block reconcile, matching the

warn-and-continue preference.

* feat(service): ensure agent user exists and owns JENKINS_HOME

Adds _ensure_user_and_home() to create the configured agent_user and chown

jenkins_home on every reconcile. Failures are logged and continue, honoring

the warn-and-continue preference. Unit tests use a fake useradd/pwd lookup

and assert os.chown arguments so they pass on macOS and in CI.

* feat(service): parameterize file ownership in _render_file (#177)

* feat(service): parameterize file ownership in _render_file

The previous implementation always chowned rendered files to root. This is

correct for systemd unit files and the launcher script (systemd runs as root),

but made it impossible for user-owned files to keep their owner. The helper

now accepts an optional owner argument so future code paths can render files

as the configured agent user while the service files remain root-owned.

* ci: debug

* feat: jenkins user w/ passwordless sudo

* ci: debug

* ci: revert debug

* ci(workflow): disable tmate debugging sessions

Tmate creates interactive tmux sessions that cannot be driven by automation.
Rely on captured Juju and pytest logs for diagnostics instead.

* test(integration): add diagnostics to traefik ingress test

Capture Jenkins client URL, Juju status, model debug logs and traefik
proxied endpoints when the Jenkins API connection drops during the
agent job-execution assertion. This helps identify whether the failure
is the server pod IP, ingress routing, or agent connectivity.

* test: log Jenkins queue state before waiting

* test: capture Jenkins API diagnostics on status failures

* test: capture wrapped Jenkins API failures

* test: use fresh client in traefik test to avoid stale pod IP

* test: route traefik client via ingress with retry

* fix: lint
@yanksyoon
yanksyoon requested a review from yhaliaw August 11, 2026 06:20
@yanksyoon
yanksyoon merged commit 554af72 into feat/agent-user-config Aug 11, 2026
36 checks passed
@yanksyoon
yanksyoon deleted the feat/systemd-user-directive branch August 11, 2026 06:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant