# role `monky_deployd` Installs and configures [monky-deployd](https://scm.tikali.ai/tikali/applications/monky/monky-deployd) (the Monky backend pull agent, MONKY-ADR-0028) on a docker host that already carries an enrolled host identity (`roles/ziti_tunneler`, run-host mode). Skeleton for **osg1-07**; copy it there. What it does: pin + download the `.deb` from the scm.tikali.ai package registry (sha256 verified; the project is **private**, so the fetches send the read-only deploy token `monky_deployd_download_token` as `DEPLOY-TOKEN`, `no_log`; `monky_deployd_base_url`/`_deb_url` switch to the Gitea release off-estate) → ACL `u:monky-deployd:r` on the identity (`rx` on the dir) → `/etc/monky-deployd/config.yaml` from the template → optional openbao-ca PEM → optional `monky-deployd-proxy.service` (`transport: proxy`) → the **one-time bootstrap deploy grant** from a vault var (0600, `no_log`) → `monky-deployd.timer` → first tick via handler (inside the grant's hour) → `monky-deployd status`. ## Variables (see `defaults/main.yml`) | var | note | |---|---| | `monky_deployd_version` | pinned release, e.g. `0.1.3` | | `monky_deployd_download_token` | **vaulted**: GitLab deploy token, scope `read_package_registry` only (revocable) — the registry is private; seeded in OpenBao at `monky/monky-tenancy/deployd-download` key `token` (path/key are the operator's choice). Empty = no header (only works with the Gitea `base_url`) | | `monky_deployd_env_id` / `_site` / `_transport` | per host (`env-dev-06`, `cbs`, `sdk`) | | `monky_deployd_bootstrap_grant` | tenancy-minted deploy grant (1 h) — `ansible-vault` or a lookup at play time; empty keeps the existing token | | `monky_deployd_bao_ca_pem` | the `openbao-ca` certificate (PEM) | | `monky_deployd_volumes_on_absent` | `keep` (default) or `purge` (never applied on prod by the agent) | ## Example play ```yaml - hosts: env-dev-06:env-dev-07:env-dev-08:env-dev-09 become: true roles: - role: ziti_tunneler # enrol/verify monky-host.; gains the ACL var + name assertion - role: monky_deployd vars: monky_deployd_bootstrap_grant: "{{ lookup('pipe', 'tenancy-mint-grant ' ~ inventory_hostname) }}" monky_deployd_download_token: "{{ vault_monky_deployd_download_token }}" # ansible-vault / OpenBao lookup ``` Rollout order (plan §E): pilot env-qa-02 → env-dev-06..09 → env-dev-01 last (after its live key moves into Bao). Verified on Ubuntu 26.04.