personal_infra/ansible/roles/socket_proxy/tasks/main.yml

55 lines
1.9 KiB
YAML
Raw Permalink Normal View History

bitcoin-knots, fulcrum, datum-gateway: add and use the socket_proxy role Three near-identical hosts: edge plays become one role plus three short calls. 183 lines removed, 34 added, plus a 111-line role. Verified before touching any playbook: all six live units on vipy reproduced byte-identically. Then --limit edge --check per playbook - bitcoin-knots and fulcrum changed=0; datum-gateway changed=2, both attributable to the already known caddy_site comment line and the Reload caddy handler it triggers. The 6 units and 14 Caddy files on the hosts are byte-identical afterwards. PLAN_4 claimed these three plays had "no behavioural drift at all". That was wrong - it came from a diff truncated by head -60. The live bitcoin-p2p-proxy units carry four settings this playbook never wrote: .socket Documentation=, FreeBind=true .service Documentation=, TimeoutStopSec=5, StandardOutput=journal, StandardError=journal FreeBind is the one that matters: it lets the socket bind to an address that is not up yet, so without it the socket can fail to start on boot. Running the bitcoin-knots playbook would have stripped it. Same class of hazard as headscale. The role expresses all four; bitcoin-p2p is the only caller that passes any. Also: UFW treats the rule comment as part of the rule. datum-stratum's live comment is "DATUM Gateway Stratum public access" but the role's derived default produced "DATUM Stratum public access", which rewrote the rule. Caught in the dry-run; datum now passes the comment explicitly. Two deliberate differences from the original, both documented in the README: ignore_errors: yes on the upstream check became failed_when: false, and the handler restarts the .socket, which drops connections open through it - it fires only when a unit file actually changes. The inert Uptime Kuma TCP monitor blocks stay in the playbooks rather than being pulled into a new role (12/12/18 guarded tasks). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-11 23:50:15 +02:00
---
- name: Assert socket_proxy parameters are sane
ansible.builtin.assert:
that:
- socket_proxy_name | length > 0
- socket_proxy_description | length > 0
- socket_proxy_listen_port | int > 0
- socket_proxy_upstream_host | length > 0
fail_msg: >-
socket_proxy: '{{ socket_proxy_name | default("<unnamed>") }}' needs a name,
a description, a listen port and an upstream host.
quiet: true
- name: "Create the {{ socket_proxy_name }}-proxy socket unit"
ansible.builtin.template:
src: proxy.socket.j2
dest: "/etc/systemd/system/{{ socket_proxy_name }}-proxy.socket"
owner: root
group: root
mode: '0644'
notify: Restart socket proxy
- name: "Create the {{ socket_proxy_name }}-proxy service unit"
ansible.builtin.template:
src: proxy.service.j2
dest: "/etc/systemd/system/{{ socket_proxy_name }}-proxy.service"
owner: root
group: root
mode: '0644'
notify: Restart socket proxy
- name: "Enable and start the {{ socket_proxy_name }}-proxy socket"
ansible.builtin.systemd:
name: "{{ socket_proxy_name }}-proxy.socket"
enabled: yes
state: started
daemon_reload: yes
- name: "Allow the {{ socket_proxy_name }} port through UFW"
community.general.ufw:
rule: allow
port: "{{ socket_proxy_listen_port | string }}"
proto: "{{ socket_proxy_ufw_proto }}"
comment: "{{ socket_proxy_ufw_comment | default(socket_proxy_description ~ ' public access', true) }}"
# Reachability of the upstream over Tailscale. Deliberately non-fatal: the proxy
# is still correctly configured if the backend happens to be down, and this is
# the one check that depends on another machine being up.
- name: "Verify {{ socket_proxy_upstream_host }} is reachable over Tailscale"
ansible.builtin.wait_for:
host: "{{ socket_proxy_upstream_host }}"
port: "{{ socket_proxy_upstream_port | default(socket_proxy_listen_port, true) }}"
timeout: 10
failed_when: false