ansible: fix container name and git user, refuse to start a second agent

The real container on the validators is named validator-agent (the image
is cloud-ip-validator-validator-agent); the playbook used the image name
as the container name, so it would have started a second agent next to
the old one with the same validator_id. The clone on the validators is
owned by root, so git must run as root (git_user), otherwise fetch fails
with "cannot open .git/FETCH_HEAD: Permission denied".

Preflight now stops when the host has another container of this agent
(by name or image) besides container_name.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
ayurishchevandClaude Sonnet 5.5 committed 2026-10-02 10:01:05 +03:00
1 parent 49890ff5de
commit cf4a883363
3 files changed
+42 -9

No files matched your search

@@ -15,13 +15,15 @@ repo_dir: /opt/cloud-ip-validator
repo_remote: origin
# Ветка, тег или коммит, который нужно выкатить (откат: -e deploy_ref=<коммит>).
deploy_ref: main
# Пользователь, у которого в клоне настроен доступ к репозиторию (git fetch).
# Пусто — git работает от SSH-пользователя без sudo.
git_user: ""
# Пользователь, от имени которого выполняется git в клоне (через sudo): владелец
# клона. На валидаторах клон принадлежит root, репозиторий читается без учётных
# данных. Пусто — git работает от SSH-пользователя без sudo.
git_user: root
# --- образ и контейнер --------------------------------------------------
image_name: cloud-ip-validator-validator-agent
container_name: cloud-ip-validator-validator-agent
# Имя контейнера на валидаторах (имя образа — другое, см. image_name).
container_name: validator-agent
platform: linux/amd64
dockerfile: deploy/docker/validator-agent/Dockerfile
# Сколько образов с метками ревизий хранить (кроме latest); старые удаляются.