Run from the jump host: on each validator it updates the git clone in /opt/cloud-ip-validator, builds the image there, stops and removes the current container and starts a new one from the new image. Run parameters live in an env file (deploy/ansible/env/validator-agent.env, git-ignored, template committed). The image is built before the running container is touched, so a failed build leaves the old container running. Hosts are updated in waves (1, 4, rest) and any failure stops the run. validator_id comes from the inventory and is checked against the running container before it is replaced. Only ansible.builtin modules are used, so the validators need no extra packages. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
41 lines
1.3 KiB
YAML
41 lines
1.3 KiB
YAML
---
|
|
# Dockerfile ничего не компилирует: в образ копируется закоммиченный
|
|
# bin/validator-agent. Не даём выкатить бинарник, не совпадающий с суммой.
|
|
- name: Check bin/validator-agent against SHA256SUMS
|
|
ansible.builtin.shell: |
|
|
set -o pipefail
|
|
grep -E '[[:space:]]validator-agent$' SHA256SUMS | sha256sum -c -
|
|
args:
|
|
chdir: "{{ repo_dir }}/bin"
|
|
executable: /bin/bash
|
|
changed_when: false
|
|
|
|
# Контекст сборки — корень репозитория (так и в SETUP.md). Слои кэшируются,
|
|
# при смене bin/ образ пересобирается сам.
|
|
- name: Build the image
|
|
ansible.builtin.command:
|
|
argv:
|
|
- docker
|
|
- build
|
|
- --platform
|
|
- "{{ platform }}"
|
|
- --label
|
|
- "git.rev={{ rev_after.stdout }}"
|
|
- --label
|
|
- deployed.by=ansible
|
|
- -t
|
|
- "{{ image_ref }}"
|
|
- -f
|
|
- "{{ dockerfile }}"
|
|
- .
|
|
chdir: "{{ repo_dir }}"
|
|
|
|
- name: Tag the image as latest
|
|
ansible.builtin.command: "docker tag {{ image_ref }} {{ image_name }}:latest"
|
|
|
|
- name: Read the image id
|
|
ansible.builtin.command:
|
|
argv: [docker, image, inspect, --format, "{% raw %}{{.Id}}{% endraw %}", "{{ image_ref }}"]
|
|
changed_when: false
|
|
register: built_image
|