Run from the jump host: on each validator it updates the git clone in /opt/cloud-ip-validator, builds the image there, stops and removes the current container and starts a new one from the new image. Run parameters live in an env file (deploy/ansible/env/validator-agent.env, git-ignored, template committed). The image is built before the running container is touched, so a failed build leaves the old container running. Hosts are updated in waves (1, 4, rest) and any failure stops the run. validator_id comes from the inventory and is checked against the running container before it is replaced. Only ansible.builtin modules are used, so the validators need no extra packages. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
81 lines
3.1 KiB
YAML
81 lines
3.1 KiB
YAML
---
|
|
# Команды git вместо модуля git: модуль переписывает URL remote и может
|
|
# затереть учётные данные, уже настроенные в клоне. Работаем от git_user
|
|
# (или от SSH-пользователя, если он не задан).
|
|
- name: Remember the current revision
|
|
ansible.builtin.command: "{{ git_cmd }} rev-parse HEAD"
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
changed_when: false
|
|
register: rev_before
|
|
|
|
- name: Fetch the remote
|
|
ansible.builtin.command: "{{ git_cmd }} fetch --prune --tags {{ repo_remote }}"
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
changed_when: false
|
|
|
|
# deploy_ref — ветка, тег или коммит. Ветка берётся из remote (свежая),
|
|
# тег и коммит — как есть.
|
|
- name: Resolve deploy_ref as a remote branch
|
|
ansible.builtin.command: >-
|
|
{{ git_cmd }} rev-parse --verify --quiet
|
|
refs/remotes/{{ repo_remote }}/{{ deploy_ref }}^{commit}
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
changed_when: false
|
|
failed_when: false
|
|
register: ref_branch
|
|
|
|
- name: Resolve deploy_ref as a tag or commit
|
|
ansible.builtin.command: "{{ git_cmd }} rev-parse --verify --quiet {{ deploy_ref }}^{commit}"
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
changed_when: false
|
|
failed_when: false
|
|
register: ref_other
|
|
when: ref_branch.rc != 0
|
|
|
|
- name: Fail if deploy_ref does not exist
|
|
ansible.builtin.assert:
|
|
that: ref_branch.rc == 0 or (ref_other.rc | default(1)) == 0
|
|
fail_msg: "deploy_ref={{ deploy_ref }} не найден в {{ repo_dir }} ({{ repo_remote }})."
|
|
quiet: true
|
|
|
|
- name: Fix the target revision
|
|
ansible.builtin.set_fact:
|
|
target_rev: "{{ ref_branch.stdout if ref_branch.rc == 0 else ref_other.stdout }}"
|
|
|
|
# Ветка: остаёмся на локальной ветке (клон не уходит в detached HEAD),
|
|
# сброс на remote. Тег или коммит: detached HEAD.
|
|
- name: Check out the branch
|
|
ansible.builtin.command: "{{ git_cmd }} checkout --force -B {{ deploy_ref }} {{ target_rev }}"
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
when: ref_branch.rc == 0
|
|
changed_when: rev_before.stdout != target_rev
|
|
|
|
- name: Check out the tag or commit
|
|
ansible.builtin.command: "{{ git_cmd }} checkout --force --detach {{ target_rev }}"
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
when: ref_branch.rc != 0
|
|
changed_when: rev_before.stdout != target_rev
|
|
|
|
- name: Read the deployed revision
|
|
ansible.builtin.command: "{{ git_cmd }} rev-parse HEAD"
|
|
become: "{{ git_user | length > 0 }}"
|
|
become_user: "{{ git_user }}"
|
|
changed_when: false
|
|
register: rev_after
|
|
|
|
- name: Check that the clone is at the target revision
|
|
ansible.builtin.assert:
|
|
that: rev_after.stdout == target_rev
|
|
fail_msg: "Клон на {{ rev_after.stdout }}, ожидалось {{ target_rev }}."
|
|
quiet: true
|
|
|
|
- name: Remember the short revision
|
|
ansible.builtin.set_fact:
|
|
deploy_rev: "{{ rev_after.stdout[:12] }}"
|