Files
2026-09-06 13:51:11 +00:00

2.1 KiB

Silent no_agent watchdog cron pattern (cert expiry & similar)

The user does NOT want confirmation/status messages when there is nothing to act on ("лишний шум"). Replace one-shot "remind me on date X" cron prompts with a silent no_agent watchdog that only speaks at a threshold.

Pattern (used 2026-08-29 for the nixg.ru LE cert)

  • cron job: no_agent: true, daily schedule (0 10 * * *), deliver to Telegram DM.
  • script (e.g. check_icq_cert.sh): while healthy → print NOTHING (empty stdout). no_agent contract: empty stdout = silent tick, nothing delivered; non-empty stdout is delivered verbatim; non-zero exit sends an error alert.
  • Only when the condition crosses the threshold (e.g. days_left <= 45) print the actionable instructions (with the exact commands), which then arrive as the message.
#!/bin/bash
CERT=/opt/icq/certs/nixg.ru.crt
THRESHOLD=${THRESHOLD:-45}
[ -f "$CERT" ] || { echo "⚠️ Отсутствует сертификат $CERT"; exit 0; }
END=$(openssl x509 -enddate -noout -in "$CERT" | cut -d= -f2)
DAYS=$(( ( $(date -d "$END" +%s) - $(date +%s) ) / 86400 ))
[ "$DAYS" -gt "$THRESHOLD" ] && exit 0        # silence while healthy
echo "🔐 Сертификат nixg.ru истекает через ${DAYS} дн. (${END}) — продлить вручную..."
echo "1. sudo certbot renew --manual-auth-hook /bin/true --manual-cleanup-hook /bin/true"
echo "2. Добавить TXT _acme-challenge.nixg.ru / _acme-challenge.xmpp.nixg.ru в панели Jino"
echo "3. dig @1.1.1.1 _acme-challenge.nixg.ru TXT +short"
echo "4. Повторить certbot renew; 5. cp -L полный серт в /opt/icq/certs/; 6. docker compose restart prosody"

Lessons

  • cron jobs created from a CLI session have no live delivery channel — set deliver to a gateway platform (e.g. telegram:<chat_id>) or they vanish into the log.
  • Testing: run the script directly with a forced threshold (THRESHOLD=100 ./check_icq_cert.sh) to see the noise branch; the normal run must be silent.
  • Status reminder cron job (agent-based, deliver origin) = noise generator; the watchdog shape is what this user wants.