diff --git a/deploy/020-statefulset.yaml b/deploy/020-statefulset.yaml index c0c1058..f5f203f 100644 --- a/deploy/020-statefulset.yaml +++ b/deploy/020-statefulset.yaml @@ -49,15 +49,19 @@ spec: limits: cpu: "4" memory: 8Gi + # startupProbe covers slow first boot (sshd after host-key/auth setup). + startupProbe: + tcpSocket: + port: ssh + failureThreshold: 60 + periodSeconds: 10 readinessProbe: tcpSocket: port: ssh - initialDelaySeconds: 5 periodSeconds: 10 livenessProbe: tcpSocket: port: ssh - initialDelaySeconds: 15 periodSeconds: 20 volumeMounts: - name: home diff --git a/entrypoint.sh b/entrypoint.sh index 18e4cf4..02de9cc 100755 --- a/entrypoint.sh +++ b/entrypoint.sh @@ -24,9 +24,12 @@ if [ -f "${AUTH_KEYS_SRC}" ]; then install -m 600 -o developer -g developer "${AUTH_KEYS_SRC}" "${HOME_DIR}/.ssh/authorized_keys" fi # sshd StrictModes rejects auth if $HOME is group/world-writable. +# Do not chown -R the whole PVC (tens of GB) — that blocks sshd past liveness and +# caused empty-home recovery restarts to loop. Ownership is uid 1000 (developer). chmod 755 "${HOME_DIR}" chmod 700 "${HOME_DIR}/.ssh" -chown -R developer:developer "${HOME_DIR}" +chown developer:developer "${HOME_DIR}" "${HOME_DIR}/.ssh" "${HOME_DIR}/workspace" 2>/dev/null || true +chown -R developer:developer "${HOME_DIR}/.ssh-host" 2>/dev/null || true # DinD sidecar listens on TCP; ensure SSH login shells see DOCKER_HOST. grep -q '^DOCKER_HOST=' /etc/environment 2>/dev/null \