S6 – Skarnet's small supervision suite
skarnet.org
skarnet.org
The coding style is a little terse and is clearly influenced by djb. The author has some (justified) mistrust of the C standard library, so you'll need to get used to the alternatives in their "skalibs" library, but I'd feel much more comfortable debugging a problem with this suite than I would with systemd.
Also, the related tool, execline, is a trip: https://skarnet.org/software/execline/ .
Could you elaborate on this? I'm curious about using s6 as a container runner.
But s6 is excellent as well.
And this looks really good: https://wiki.gentoo.org/wiki/Comparison_of_init_systems
Handling those daemons by jailing them with Linux-centric cgroups is the one thing systemd allows you to "get away with".
Couldn’t be happier with the decision.
You can see how we provision s6 files here https://github.com/upmaru/pakman
There's a huge community https://www.linuxserver.io/ for people building "home server" containers that all use the s6-overlay, hundreds of examples there. They have a lot of tutorials and a very busy Discord, Reddit, etc with all levels of experience from container developers to people who don't program and are just getting into Docker. I run a bunch of these containers myself and am pretty happy with how adaptable they are.
I'm still missing some corner bits, but I'm quite happy with it for this rather exotic use case.
This was interesting to read. I wonder if Bercot wrote anything in detail about what this entails; if this is referring to per-package edge-cases, or the complexity of the logic required to facilitate interactions between services.
Your services might want to change user (if they're system services), or save data to $HOME (if they're user services). That's purely determined by the service definition itself.
I've been using s6 for user services for over a year now quite happily. I'm using my frontend tool to manage them, and it basically just invokes s6 commands and provides a high-level interface for me to use.
I can "crontab -e" as any user without privilege and edit my own crontab, separate from the root one, that's what I meant.
Then, also, separately from the pid1 S6, unprivileged users can have their own supervision trees independent of the pid1 instance, but that can depend upon things started by pid1.
Example:
pid1 S6 launches root-configured service, S as part of its supervision tree.
Unprivileged user, U, has a discrete instance of S6, which I'll refer to as pidN S6 with a supervision tree that U controls (e.g. in each user's $HOME). pidN S6 launches a service T which depends on S.
Is there a way for pidN S6 to wait on pid1 S6 to note that S is ready, blocking the launch of T until that notification.
The separate supervision trees part seems trivial based on my understanding of S6.
I also see in the docs that a daemon can signal its own supervising S6 that it is ready, so that S6 can manage the dependencies among multiple services in its supervision tree. The part that seems unclear to me (and the original question-asker) is if there can be cross-supervision-tree dependencies.
The brute-force way to do this would be to have the PID1 S6 launch a pidN S6 process for each user, with the supervision tree defined in that user's $HOME. Then the pid1 S6 can ensure that each pidN instance is dependent upon all PID1 services, so that the user instances only launch after all possible dependencies are initialized. This would still depend on an implicit contract between root and users so that root does in fact launch all upstream dependencies.
Alternatively, I guess you could give fine-grained sudo privileges to each user that gets a pidN S6, so that they can check the status of running daemons under the pid1 S6.
I pray that, in the future, *nix/POSIX adds process management programmable<->declarative (congruent) supervisor coprocesses and lifecycle hooks such that running a system becomes more like the Erlang BEAM runtime.
> without having to commit to an entire init system.
And many are small modular tools that integrate with other pieces.
Having tried similar things myself, I concur. One way to add a bit of sanity is to mandate running dnsmasq which has reasonable control interfaces, but it's overkill.
I'm happy that s6 is so beloved, but I am not amongst that crowd.