fix: deduplicate sidecars/systemd, block system-critical stops, filter runtime paths
This commit is contained in:
+10
-2
@@ -72,10 +72,12 @@ def find_listeners_on_host(port):
|
||||
def find_sidecar_processes(cid, container_ports):
|
||||
"""
|
||||
Ищет sidecar-процессы на хосте, к которым контейнер стучится через loopback.
|
||||
Дедуплицирует по (host_process, container_port_target).
|
||||
"""
|
||||
info("Ищем loopback-соединения контейнера (sidecar / proxy / WARP) ...")
|
||||
conns = get_container_host_connections(cid)
|
||||
sidecars = []
|
||||
seen = set()
|
||||
|
||||
for c in conns:
|
||||
local = c.get("local", "")
|
||||
@@ -87,11 +89,16 @@ def find_sidecar_processes(cid, container_ports):
|
||||
listeners = find_listeners_on_host(port)
|
||||
if listeners:
|
||||
for l in listeners:
|
||||
info(f" Контейнер подключается к {local} → процесс на хосте: {l.get('process', '?')} (pid={l.get('pid', '?')})")
|
||||
proc = l.get("process", "?")
|
||||
key = (proc, port)
|
||||
if key in seen:
|
||||
continue
|
||||
seen.add(key)
|
||||
info(f" Контейнер подключается к {local} → процесс на хосте: {proc} (pid={l.get('pid', '?')})")
|
||||
sidecars.append({
|
||||
"type": "loopback_listener",
|
||||
"container_port_target": port,
|
||||
"host_process": l.get("process"),
|
||||
"host_process": proc,
|
||||
"host_pid": l.get("pid"),
|
||||
"method": "ss_lsof",
|
||||
})
|
||||
@@ -176,6 +183,7 @@ def gather_host_network_info():
|
||||
def find_systemd_units_related(procs):
|
||||
"""
|
||||
Ищет systemd unit-файлы для процессов (sidecar и других).
|
||||
Дедуплицирует по имени unit.
|
||||
"""
|
||||
units = []
|
||||
seen = set()
|
||||
|
||||
+4
-2
@@ -205,8 +205,9 @@ def discover_nginx(service_ports, service_domain_hints):
|
||||
|
||||
|
||||
def get_nginx_systemd_unit():
|
||||
"""Ищет unit-файл nginx"""
|
||||
"""Ищет unit-файл nginx, возвращает уникальные (deduplicated по пути)"""
|
||||
units = []
|
||||
seen_paths = set()
|
||||
for unit in ("nginx.service", "nginx"):
|
||||
out = run(f"systemctl is-active {unit}", check=False)
|
||||
if out.returncode == 0 or out.stdout.strip() in ("active", "inactive"):
|
||||
@@ -214,7 +215,8 @@ def get_nginx_systemd_unit():
|
||||
try:
|
||||
uout = run(f"systemctl show {unit} -p FragmentPath --value", check=False)
|
||||
path = uout.stdout.strip()
|
||||
if path:
|
||||
if path and path not in seen_paths:
|
||||
seen_paths.add(path)
|
||||
units.append({"unit": unit, "path": path})
|
||||
except Exception:
|
||||
pass
|
||||
|
||||
Reference in New Issue
Block a user