# Silent no_agent watchdog cron pattern (cert expiry & similar) The user does NOT want confirmation/status messages when there is nothing to act on ("лишний шум"). Replace one-shot "remind me on date X" cron prompts with a silent no_agent watchdog that only speaks at a threshold. ## Pattern (used 2026-08-29 for the nixg.ru LE cert) - cron job: `no_agent: true`, daily schedule (`0 10 * * *`), deliver to Telegram DM. - `script` (e.g. `check_icq_cert.sh`): while healthy → print NOTHING (empty stdout). no_agent contract: empty stdout = silent tick, nothing delivered; non-empty stdout is delivered verbatim; non-zero exit sends an error alert. - Only when the condition crosses the threshold (e.g. `days_left <= 45`) print the actionable instructions (with the exact commands), which then arrive as the message. ```bash #!/bin/bash CERT=/opt/icq/certs/nixg.ru.crt THRESHOLD=${THRESHOLD:-45} [ -f "$CERT" ] || { echo "⚠️ Отсутствует сертификат $CERT"; exit 0; } END=$(openssl x509 -enddate -noout -in "$CERT" | cut -d= -f2) DAYS=$(( ( $(date -d "$END" +%s) - $(date +%s) ) / 86400 )) [ "$DAYS" -gt "$THRESHOLD" ] && exit 0 # silence while healthy echo "🔐 Сертификат nixg.ru истекает через ${DAYS} дн. (${END}) — продлить вручную..." echo "1. sudo certbot renew --manual-auth-hook /bin/true --manual-cleanup-hook /bin/true" echo "2. Добавить TXT _acme-challenge.nixg.ru / _acme-challenge.xmpp.nixg.ru в панели Jino" echo "3. dig @1.1.1.1 _acme-challenge.nixg.ru TXT +short" echo "4. Повторить certbot renew; 5. cp -L полный серт в /opt/icq/certs/; 6. docker compose restart prosody" ``` ## Lessons - cron jobs created from a CLI session have no live delivery channel — set `deliver` to a gateway platform (e.g. `telegram:`) or they vanish into the log. - Testing: run the script directly with a forced threshold (`THRESHOLD=100 ./check_icq_cert.sh`) to see the noise branch; the normal run must be silent. - Status reminder cron job (agent-based, deliver origin) = noise generator; the watchdog shape is what this user wants.