Summary
VyOS runs /config/scripts/vyos-postconfig-bootup.script after boot config apply. The stock file is empty (comment header only). /config/scripts/post-config.d/ is not executed.
This is inconsistent with /config/scripts/post-upgrade.d/, which vyos-router already runs via run-parts after an upgrade.
Operators who drop executable hooks in post-config.d/ (Debian-style drop-ins, same idea as post-upgrade.d) find they never run unless they replace the stock bootup script with a runner.
Why it matters
Anything that lives only as a post-config.d hook is silently skipped on a stock image: extra systemd units installed from /config, neigh pins, GeoIP/AbuseIPDB refresh, qemu-guest-agent, and similar. The box looks configured; those jobs never start until something else enables them.
We run six production routers that all ship an 8-line runner in vyos-postconfig-bootup.script because the stock one is a no-op.
Reproduction
On a stock 1.5 rolling image:
ls -l /config/scripts/vyos-postconfig-bootup.script # empty aside from the comment header mkdir -p /config/scripts/post-config.d cat >/config/scripts/post-config.d/zz-marker.sh <<'EOF' #!/bin/sh logger -t post-config-d "ran zz-marker" EOF chmod +x /config/scripts/post-config.d/zz-marker.sh reboot
After boot: no post-config-d line in the journal. Contrast: the same script in post-upgrade.d does run on upgrade (run-parts in run_postupgrade_script).
Expected
Either of:
- Docs (docs/automation/command-scripting.md and the troubleshooting boot sequence): state that post-config.d/ is not automatic; only vyos-postconfig-bootup.script runs. Mention the contrast with post-upgrade.d.
- Default runner in the stock vyos-postconfig-bootup.script created by debian/vyos-1x.postinst (and the copy restored by restore_if_missing_postconfig_script in src/init/vyos-router): iterate executable files in /config/scripts/post-config.d/ (or run-parts), log failures, do not fail the boot.
(2) matches run_postupgrade_script already in vyos-router. Existing custom vyos-postconfig-bootup.script files are left untouched (if [ ! -x $POSTCONFIG_SCRIPT ] in postinst; restore only if missing).
Suggested runner (stock script body)
#!/bin/sh # This script is executed at boot time after VyOS configuration is fully applied. # Any modifications required to work around unfixed bugs # or use services not available through the VyOS CLI system can be placed here. # # Executable files in /config/scripts/post-config.d/ are run in name order # (same idea as post-upgrade.d / run-parts). Failures are logged; boot continues. DIR=/config/scripts/post-config.d [ -d "$DIR" ] || exit 0 for script in "$DIR"/*; do [ -f "$script" ] && [ -x "$script" ] || continue "$script" || logger -t vyos-postconfig "post-config.d/$(basename "$script") failed (exit $?)" done
Environment
- VyOS 1.5 Circinus rolling
- src/init/vyos-router: run_postconfig_scripts vs run_postupgrade_script (run-parts post-upgrade.d)
- debian/vyos-1x.postinst creates the empty stock script
- Docs: command-scripting "Postconfig script on boot"