|
server.shell( |
|
name="Generate root keys for validating DNSSEC", |
|
commands=[ |
|
"unbound-anchor -a /var/lib/unbound/root.key || true", |
|
"systemctl reset-failed unbound.service", |
|
], |
|
) |
This is redundant as the unbound service automatically calls this:
[Unit]
Description=Unbound DNS server
Documentation=man:unbound(8)
After=network.target
Before=nss-lookup.target
Wants=nss-lookup.target
[Service]
Type=notify
Restart=on-failure
EnvironmentFile=-/etc/default/unbound
ExecStartPre=-/usr/libexec/unbound-helper chroot_setup
ExecStartPre=-/usr/libexec/unbound-helper root_trust_anchor_update
ExecStart=/usr/sbin/unbound -d -p $DAEMON_OPTS
ExecStopPost=-/usr/libexec/unbound-helper chroot_teardown
ExecReload=+/bin/kill -HUP $MAINPID
[Install]
WantedBy=multi-user.target
It's handled by ExecStartPre in the systemd unit file
relay/cmdeploy/src/cmdeploy/__init__.py
Lines 595 to 601 in 5ba99dc
This is redundant as the unbound service automatically calls this:
It's handled by
ExecStartPrein the systemd unit file