ansible: fix container name and git user, refuse to start a second agent
The real container on the validators is named validator-agent (the image is cloud-ip-validator-validator-agent); the playbook used the image name as the container name, so it would have started a second agent next to the old one with the same validator_id. The clone on the validators is owned by root, so git must run as root (git_user), otherwise fetch fails with "cannot open .git/FETCH_HEAD: Permission denied". Preflight now stops when the host has another container of this agent (by name or image) besides container_name. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
49890ff5de
commit
cf4a883363
3 files changed
+42
-9
No files matched your search
@@ -15,13 +15,15 @@ repo_dir: /opt/cloud-ip-validator
|
||||
repo_remote: origin
|
||||
# Ветка, тег или коммит, который нужно выкатить (откат: -e deploy_ref=<коммит>).
|
||||
deploy_ref: main
|
||||
# Пользователь, у которого в клоне настроен доступ к репозиторию (git fetch).
|
||||
# Пусто — git работает от SSH-пользователя без sudo.
|
||||
git_user: ""
|
||||
# Пользователь, от имени которого выполняется git в клоне (через sudo): владелец
|
||||
# клона. На валидаторах клон принадлежит root, репозиторий читается без учётных
|
||||
# данных. Пусто — git работает от SSH-пользователя без sudo.
|
||||
git_user: root
|
||||
|
||||
# --- образ и контейнер --------------------------------------------------
|
||||
image_name: cloud-ip-validator-validator-agent
|
||||
container_name: cloud-ip-validator-validator-agent
|
||||
# Имя контейнера на валидаторах (имя образа — другое, см. image_name).
|
||||
container_name: validator-agent
|
||||
platform: linux/amd64
|
||||
dockerfile: deploy/docker/validator-agent/Dockerfile
|
||||
# Сколько образов с метками ревизий хранить (кроме latest); старые удаляются.
|
||||
|
||||
Reference in new issue
Block a user