Run from the jump host: on each validator it updates the git clone in /opt/cloud-ip-validator, builds the image there, stops and removes the current container and starts a new one from the new image. Run parameters live in an env file (deploy/ansible/env/validator-agent.env, git-ignored, template committed). The image is built before the running container is touched, so a failed build leaves the old container running. Hosts are updated in waves (1, 4, rest) and any failure stops the run. validator_id comes from the inventory and is checked against the running container before it is replaced. Only ansible.builtin modules are used, so the validators need no extra packages. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
46 lines
1.7 KiB
YAML
46 lines
1.7 KiB
YAML
---
|
|
# Образ уже собран: простой валидатора — только stop + rm + run.
|
|
- name: Copy the env file to the validator
|
|
ansible.builtin.copy:
|
|
src: "{{ local_env_file }}"
|
|
dest: "{{ remote_env_file }}"
|
|
owner: root
|
|
group: root
|
|
mode: "0600"
|
|
no_log: true
|
|
|
|
- name: Check whether the container exists
|
|
ansible.builtin.command: "docker container inspect {{ container_name }}"
|
|
register: container_exists
|
|
changed_when: false
|
|
failed_when: false
|
|
|
|
- name: Stop the current container
|
|
ansible.builtin.command: "docker stop -t {{ stop_timeout }} {{ container_name }}"
|
|
when: container_exists.rc == 0
|
|
|
|
- name: Remove the current container
|
|
ansible.builtin.command: "docker rm -f {{ container_name }}"
|
|
when: container_exists.rc == 0
|
|
|
|
# --restart нужен: агент завершается, если регистрация в control-api не
|
|
# удалась, и должен подняться снова. validator_id берётся из inventory
|
|
# (validator_id) и перекрывает env-файл.
|
|
- name: Start the new container
|
|
ansible.builtin.command:
|
|
argv: >-
|
|
{{ ['docker', 'run', '-d',
|
|
'--name', container_name,
|
|
'--restart', restart_policy,
|
|
'--platform', platform,
|
|
'--env-file', remote_env_file,
|
|
'-e', 'VALIDATOR_AGENT_VALIDATOR_ID=' ~ effective_validator_id,
|
|
'--log-driver', 'json-file',
|
|
'--log-opt', 'max-size=' ~ log_max_size,
|
|
'--log-opt', 'max-file=' ~ log_max_file,
|
|
'--label', 'git.rev=' ~ rev_after.stdout,
|
|
'--label', 'deployed.by=ansible']
|
|
+ (capabilities | map('regex_replace', '^(.*)$', '--cap-add=\1') | list)
|
|
+ [image_ref] }}
|
|
register: started
|