deploy.sh:
- never rsync into /; stage to /tmp on the remote and install at final
paths via sudo bash heredoc, closing the parent-dir attribute leak
that broke three hosts in the earlier rsync incident
- shell-quote heredoc args via ${var@Q}
- drop -A -X on the remaining (web) rsyncs
- generic worker.secrets loop reads (env-var → pass path) from manifest;
GITEA_TOKEN now flows through automatically
- in-memory bash substitution for templates (secrets never on argv)
- simplify semanage port labelling: --add 2>/dev/null || --modify (the
old grep pre-check matched only the first listed port)
- restorecon back to short flags (Fedora policycoreutils has no long
forms; --recursive errored at deploy time)
- quieter health probe loop: curl diagnostics only on final failure
manifest as source of truth:
- api.config.bind drives BIND_ADDR, firewalld port, semanage label,
health-probe URL
- web.config.{server_name,root,api_upstream} drives nginx render,
rsync targets, restorecon scope
- nginx config renamed to site.conf.tmpl; firewalld svc to
moments-api.xml.tmpl; both rendered at deploy time
- topology flip: api → nikola, worker → frootmig (anjie freed)
new scripts:
- script/teardown.sh: idempotent component teardown, never rsyncs,
shared-state cleanup gated on absence of remaining env files,
--remove-docroot guard against shallow / system paths
- script/db-perms.sh: rewritten — fixes grep/append role mismatch that
appended duplicates on re-run, adds postgres reload, hits primary +
standby in a single invocation
readme: genericized; deployment topology no longer carries real host
or site names.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
37 lines
1.1 KiB
YAML
37 lines
1.1 KiB
YAML
app: moments
|
|
environments:
|
|
prod:
|
|
components:
|
|
api:
|
|
hosts: [nikola.kosherinata.internal]
|
|
config:
|
|
bind: 0.0.0.0:42424
|
|
db_role: moments_ro
|
|
db_host: magrathea.kosherinata.internal
|
|
db_port: 5432
|
|
db_name: moments
|
|
worker:
|
|
hosts: [frootmig.kosherinata.internal]
|
|
config:
|
|
db_role: moments_rw
|
|
db_host: magrathea.kosherinata.internal
|
|
db_port: 5432
|
|
db_name: moments
|
|
github_user: grenade
|
|
gitea_host: git.lair.cafe
|
|
gitea_user: grenade
|
|
hg_host: hg-edge.mozilla.org
|
|
hg_repos: build/puppet,build/tools,build/buildbot-configs
|
|
hg_author_terms: thijssen,grenade
|
|
bugzilla_host: bugzilla.mozilla.org
|
|
bugzilla_email: rthijssen@mozilla.com
|
|
secrets:
|
|
GITHUB_TOKEN: github.com/grenade/admin-token
|
|
GITEA_TOKEN: git.lair.cafe/grenade/admin-token
|
|
web:
|
|
hosts: [oolon.kosherinata.internal]
|
|
config:
|
|
server_name: rob.tn
|
|
root: /var/www/rob.tn
|
|
api_upstream: http://nikola.kosherinata.internal:42424
|