Run from the jump host: on each validator it updates the git clone in /opt/cloud-ip-validator, builds the image there, stops and removes the current container and starts a new one from the new image. Run parameters live in an env file (deploy/ansible/env/validator-agent.env, git-ignored, template committed). The image is built before the running container is touched, so a failed build leaves the old container running. Hosts are updated in waves (1, 4, rest) and any failure stops the run. validator_id comes from the inventory and is checked against the running container before it is replaced. Only ansible.builtin modules are used, so the validators need no extra packages. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
34 lines
1.1 KiB
YAML
34 lines
1.1 KiB
YAML
---
|
|
# Порядок важен: сначала всё, что не трогает работающий контейнер (проверки,
|
|
# обновление кода, сборка образа), и только потом замена контейнера. Если
|
|
# что-то упало до replace, старый контейнер продолжает работать.
|
|
- name: Preflight checks
|
|
ansible.builtin.import_tasks: preflight.yml
|
|
tags: [preflight]
|
|
|
|
- name: Dry run stops after preflight
|
|
ansible.builtin.debug:
|
|
msg: "check mode: git, build, replace and verify are skipped"
|
|
when: ansible_check_mode
|
|
tags: [always]
|
|
|
|
- name: Update the git clone
|
|
ansible.builtin.import_tasks: git.yml
|
|
when: not ansible_check_mode
|
|
tags: [git]
|
|
|
|
- name: Build the image
|
|
ansible.builtin.import_tasks: build.yml
|
|
when: not ansible_check_mode
|
|
tags: [build]
|
|
|
|
- name: Replace the container
|
|
ansible.builtin.import_tasks: replace.yml
|
|
when: not ansible_check_mode
|
|
tags: [replace]
|
|
|
|
- name: Verify the new container
|
|
ansible.builtin.import_tasks: verify.yml
|
|
when: not ansible_check_mode
|
|
tags: [verify]
|