HydraIssues

hydraperforcewatcher has one global perforce.port, so one process cannot serve two Perforce scales
open bug Project: hydraperforcewatcher Reporter: cederik 31 Aug 2026 21:19

Description

Found during hydragon reconnaissance (#615) on 2026-08-31.

The problem

hydraperforcewatcher has a single global perforce.port in its configuration. The Watches struct carries no per-watch port and no per-watch user (internal/cli/serve.go).

So one watcher process can only ever serve one p4d server.

Why it matters

We now run one Perforce scale for each organization. galloromeinsmuseum is on port 1666, p4scale-visitflanders is on 1667, and hydragon will be on 1668. Adding a //hydragon/main entry to the running watcher's watches: list does not work. Worse, editing that live configuration repoints Cyborn's watcher, because the port is global.

The workaround today is a second watcher instance for each scale: its own configuration file, its own state directory, its own systemd unit and its own agent identifier. That is one more process for every organization we onboard, and each one is a separate thing to monitor, update and get wrong.

What to do

Move port and user from the global perforce block onto each watch entry, and keep the global as the default when a watch omits them. One process then serves every scale on the node.

Until that lands, the runbook must say plainly that a new scale needs a new watcher instance, and must never say "add a watch".

Related: #615, #623 hydragon Phase 1, #543 ensure-server hardening.