fix(caddy): keep NET_BIND_SERVICE so the file-cap binary can exec (#81 hotfix) #102
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!102
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/caddy-net-bind-service-filecap"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Hotfix for a prod outage caused by #94 (already applied to prod; this lands the fix on
mainso it isn't lost / re-broken on the next apply).What happened
Applying #94 (socket activation) crash-looped Caddy with
exec container process /usr/bin/caddy: Operation not permitted, taking all four hosts down for ~4 min (14:47–14:51 UTC, 2026-07-18).Root cause
#94 dropped
AddCapability=NET_BIND_SERVICEon the (correct) theory that with socket activation Caddy no longer binds ports. But the officialcaddyimage ships/usr/bin/caddywithcap_net_bind_serviceas a file capability, and withNoNewPrivileges=truethe kernel refuses toexecvea file-capability binary unless that cap is in the bounding set →EPERM→ crash loop. The dropped cap was never about binding; it's required just to exec the image's binary.Fix
Restore
AddCapability=NET_BIND_SERVICE(with a comment explaining it's for the exec, not for binding).PublishPortstays gone — the #81 win is intact; sockets are still host-bound and passed as fds.Verified on prod (post-fix apply)
10.89.0.x).alt-svc: h3=":443"advertised; QUIC listener up (only a non-fatal UDP-buffer info note).probe_success=1for all endpoints; no new firing alerts.Follow-up for reviewers
The lesson generalises: any Quadlet with
NoNewPrivileges=true+DropCapability=ALLfronting an image whose binary carries file caps needs the matchingAddCapability. Worth a note in the caddy/ADR-0005 hardening rationale.