ansible: fix container name and git user, refuse to start a second agent

The real container on the validators is named validator-agent (the image
is cloud-ip-validator-validator-agent); the playbook used the image name
as the container name, so it would have started a second agent next to
the old one with the same validator_id. The clone on the validators is
owned by root, so git must run as root (git_user), otherwise fetch fails
with "cannot open .git/FETCH_HEAD: Permission denied".

Preflight now stops when the host has another container of this agent
(by name or image) besides container_name.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
ayurishchevandClaude Sonnet 5.5 committed 2026-10-02 10:01:05 +03:00
1 parent 49890ff5de
commit cf4a883363
3 files changed
+42 -9

No files matched your search

@@ -85,6 +85,34 @@
failed_when: false
check_mode: false
# Защита от второго агента: если на хосте уже есть другой контейнер этого
# агента (по имени или по образу), сценарий остановится, а не запустит
# рядом ещё один с тем же validator_id.
- name: List containers on the validator
ansible.builtin.command: docker ps -a --format {% raw %}'{{.Names}}|{{.Image}}'{% endraw %}
register: all_containers
changed_when: false
check_mode: false
- name: Check that there is no other agent container
ansible.builtin.assert:
that: (other_agents | from_json) | length == 0
fail_msg: >-
{{ inventory_hostname }}: найден другой контейнер агента: {{ (other_agents | from_json) | join(', ') }}.
Сценарий заменяет только контейнер {{ container_name }}. Проверьте container_name в
inventory/group_vars/validators.yml или удалите лишний контейнер вручную.
quiet: true
vars:
other_agents: >-
{%- set found = [] -%}
{%- for line in all_containers.stdout_lines -%}
{%- set row = line.split('|') -%}
{%- if row[0] != container_name and ('validator-agent' in row[0] or row[1] == image_name or row[1].startswith(image_name ~ ':')) -%}
{%- set _ = found.append(row[0] ~ ' (' ~ row[1] ~ ')') -%}
{%- endif -%}
{%- endfor -%}
{{- found | to_json -}}
# validator_id работающего контейнера — эталон: если он отличается от
# inventory, заменять контейнер нельзя (агент зарегистрировался бы под чужим
# именем, адреса привязывались бы к порту другой ВМ). Выводится только он,