Uh oh!
There was an error while loading. Please reload this page.
Add read-only Keep status display on the physical console - #103
Add read-only Keep status display on the physical console#103wksantiago wants to merge 4 commits into
Conversation
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
🚧 Files skipped from review as they are similar to previous changes (2)
WalkthroughAdds an optional branded, read-only console status display. A root collector publishes JSON health snapshots, while a sandboxed unprivileged renderer displays sanitized, stale-aware status data. NixOS assertions, VM coverage, brand validation, appliance wiring, and documentation are included. ChangesConsole status display
Estimated code review effort: 4 (Complex) | ~60 minutes Sequence Diagram(s)sequenceDiagram
participant systemd_timer
participant keep_node_status_collect
participant status_json
participant keep_node_status_render
participant virtual_console
systemd_timer->>keep_node_status_collect: trigger periodic collection
keep_node_status_collect->>status_json: publish atomic JSON snapshot
keep_node_status_render->>status_json: read and validate snapshot
keep_node_status_render->>virtual_console: render sanitized status frame
Possibly related PRs
Suggested labels: Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 3
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@docs/hardware.md`:
- Around line 111-115: Update the anti-lockout recovery guidance in the
documented sections to reference the configured statusDisplay.tty rather than
assuming tty1, instruct operators to use any other available VT, and qualify
that /dev/console may not be the configured renderer VT.
- Around line 123-125: Update the shell code fence around the systemctl command
to specify the bash language identifier, using ```bash instead of an untyped
fence.
- Around line 101-109: Update the stale-state documentation to consistently
describe the renderer’s identity behavior: since nodeLabel defaults to
networking.hostName, clarify whether the hostname/node label is replaced with ??
or remains visible, and ensure the surviving identity statement names only the
elements that actually remain displayed.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: 8f40e73b-6b7d-4427-89d5-7708925973bf
📒 Files selected for processing (9)
README.mddocs/SECURITY.mddocs/hardware.mdflake.nixnixos/installer.nixnixos/keep-node.nixnixos/lib/brand.nixnixos/status-display.nixtests/status-display.nix
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
wksantiago
commented
Jul 20, 2026
@coderabbitai review |
✅ Action performedReview finished.
|
Read-only, Keep-branded status screen on the physical console. Off by default.
An installed node boots to a bare kernel log dump and a login prompt where every account is password-locked, so an operator standing at the box learns nothing about why the vault did not unlock or the mesh did not form.
A root collector writes
/run/keep-node-status/status.json; an unprivilegedkeep-statusrenderer paints tty1 withStandardInput=null, so it holds no descriptor on the keyboard. Physical console access grants nothing today and still grants nothing.New:
nixos/lib/brand.nix,nixos/status-display.nix,tests/status-display.nix. Checks:status-display,statusdisplay-assertions,brand-shapes. Installer MOTD shares the same mark.Closes#101
Summary by CodeRabbit
New Features
keepNode.statusDisplay(VT/refresh/staleness, node label) with mesh address visibility as a separate opt-in.Documentation
Tests