Add Ansible playbook to deliver validator-agent to the validators

Run from the jump host: on each validator it updates the git clone in
/opt/cloud-ip-validator, builds the image there, stops and removes the
current container and starts a new one from the new image. Run
parameters live in an env file (deploy/ansible/env/validator-agent.env,
git-ignored, template committed).

The image is built before the running container is touched, so a failed
build leaves the old container running. Hosts are updated in waves
(1, 4, rest) and any failure stops the run. validator_id comes from the
inventory and is checked against the running container before it is
replaced. Only ansible.builtin modules are used, so the validators need
no extra packages.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
ayurishchevandClaude Sonnet 5.5 committed 2026-10-02 09:23:39 +03:00
1 parent abbee9a08a
commit 49890ff5de
16 files changed
+684 -1

No files matched your search

@@ -0,0 +1,48 @@
---
# Параметры доставки validator-agent (не секреты). Любой из них можно
# переопределить в командной строке: -e deploy_ref=<коммит|тег>.
# Параметры запуска самого агента (адрес control-api, токен, способы
# самопроверки, таймауты) лежат в env-файле, см. local_env_file.
# SSH: пользователь и ключ одинаковы на jump-хосте и на валидаторах. Путь к
# ключу — на jump-хосте (ключ с правами 0600). Для docker и записи env-файла
# сценарий повышает права через sudo (become).
ansible_user: debian
ansible_ssh_private_key_file: ~/.ssh/vk_cloud_priv.key
# --- git-клон на валидаторе ---------------------------------------------
repo_dir: /opt/cloud-ip-validator
repo_remote: origin
# Ветка, тег или коммит, который нужно выкатить (откат: -e deploy_ref=<коммит>).
deploy_ref: main
# Пользователь, у которого в клоне настроен доступ к репозиторию (git fetch).
# Пусто — git работает от SSH-пользователя без sudo.
git_user: ""
# --- образ и контейнер --------------------------------------------------
image_name: cloud-ip-validator-validator-agent
container_name: cloud-ip-validator-validator-agent
platform: linux/amd64
dockerfile: deploy/docker/validator-agent/Dockerfile
# Сколько образов с метками ревизий хранить (кроме latest); старые удаляются.
keep_images: 3
# --- запуск контейнера (как в deploy/docker/RUN.txt) --------------------
restart_policy: unless-stopped
capabilities: [NET_RAW]
log_max_size: 10m
log_max_file: "3"
stop_timeout: 10
# --- проверка после запуска ---------------------------------------------
verify_retries: 10
verify_delay: 3
# --- env-файл на jump-хосте ---------------------------------------------
# Параметры запуска агента. Рабочий файл создаётся из validator-agent.env.example
# и в git не попадает. Файл можно зашифровать: ansible-vault encrypt <файл>
# (тогда запускайте с --ask-vault-pass или --vault-password-file).
local_env_file: "{{ playbook_dir }}/../env/validator-agent.env"
# Куда файл копируется на валидатор (путь закрыт .gitignore репозитория,
# переживает git reset).
remote_env_file: "{{ repo_dir }}/deploy/docker/.env.validator"