mirror of
https://scm.tikali.ai/tikali/applications/monky/monky-deployd.git
synced 2026-09-18 06:16:16 +00:00
a30014a096
Every apply requested a new lease, so a failing deploy retried by the 60 s timer burned tenancy's 5-leases-per-hour budget and then failed on LEASE_RATE_LIMITED forever (env-qa-02 pilot). Now: reuse a lease-derived token while lookup-self says it is valid; swap the bootstrap token for a lease once; if tenancy rate-limits the lease while a working token exists, apply with it and defer the swap. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KLB7jieMNRkTsJ2epr4Ds1
41 lines
2.4 KiB
Markdown
41 lines
2.4 KiB
Markdown
# role `monky_deployd`
|
|
|
|
Installs and configures [monky-deployd](https://scm.tikali.ai/tikali/applications/monky/monky-deployd)
|
|
(the Monky backend pull agent, MONKY-ADR-0028) on a docker host that already carries an enrolled
|
|
host identity (`roles/ziti_tunneler`, run-host mode). Skeleton for **osg1-07**; copy it there.
|
|
|
|
What it does: pin + download the `.deb` from the scm.tikali.ai package registry (sha256 verified; the
|
|
project is **private**, so the fetches send the read-only deploy token `monky_deployd_download_token`
|
|
as `DEPLOY-TOKEN`, `no_log`; `monky_deployd_base_url`/`_deb_url` switch to the Gitea release off-estate) → ACL
|
|
`u:monky-deployd:r` on the identity (`rx` on the dir) → `/etc/monky-deployd/config.yaml` from the
|
|
template → optional openbao-ca PEM → optional `monky-deployd-proxy.service` (`transport: proxy`)
|
|
→ the **one-time bootstrap deploy grant** from a vault var (0600, `no_log`) → `monky-deployd.timer`
|
|
→ first tick via handler (inside the grant's hour) → `monky-deployd status`.
|
|
|
|
## Variables (see `defaults/main.yml`)
|
|
|
|
| var | note |
|
|
|---|---|
|
|
| `monky_deployd_version` | pinned release, e.g. `0.1.6` |
|
|
| `monky_deployd_download_token` | **vaulted**: GitLab deploy token, scope `read_package_registry` only (revocable) — the registry is private; seeded in OpenBao at `monky/monky-tenancy/deployd-download` key `token` (path/key are the operator's choice). Empty = no header (only works with the Gitea `base_url`) |
|
|
| `monky_deployd_env_id` / `_site` / `_transport` | per host (`env-dev-06`, `cbs`, `sdk`) |
|
|
| `monky_deployd_bootstrap_grant` | tenancy-minted deploy grant (1 h) — `ansible-vault` or a lookup at play time; empty keeps the existing token |
|
|
| `monky_deployd_bao_ca_pem` | the `openbao-ca` certificate (PEM) |
|
|
| `monky_deployd_volumes_on_absent` | `keep` (default) or `purge` (never applied on prod by the agent) |
|
|
|
|
## Example play
|
|
|
|
```yaml
|
|
- hosts: env-dev-06:env-dev-07:env-dev-08:env-dev-09
|
|
become: true
|
|
roles:
|
|
- role: ziti_tunneler # enrol/verify monky-host.<env>; gains the ACL var + name assertion
|
|
- role: monky_deployd
|
|
vars:
|
|
monky_deployd_bootstrap_grant: "{{ lookup('pipe', 'tenancy-mint-grant ' ~ inventory_hostname) }}"
|
|
monky_deployd_download_token: "{{ vault_monky_deployd_download_token }}" # ansible-vault / OpenBao lookup
|
|
```
|
|
|
|
Rollout order (plan §E): pilot env-qa-02 → env-dev-06..09 → env-dev-01 last (after its live key moves into Bao).
|
|
Verified on Ubuntu 26.04.
|