57 lines
2.3 KiB
Markdown
57 lines
2.3 KiB
Markdown
|
|
# `phoenixd`
|
||
|
|
|
||
|
|
Deploys and runs [phoenixd](https://phoenix.acinq.co/server), an ACINQ Lightning
|
||
|
|
node, on the edge host. LNBits uses it as a wallet backend. The HTTP API stays on
|
||
|
|
loopback — phoenixd is never published through Caddy.
|
||
|
|
|
||
|
|
Converted from `deploy_phoenixd_playbook.yml` (552 lines) under Plan 6. The
|
||
|
|
playbook is now 18 lines.
|
||
|
|
|
||
|
|
## Phases
|
||
|
|
|
||
|
|
| | |
|
||
|
|
|---|---|
|
||
|
|
| `install.yml` | packages, system user, directories, versioned download and install |
|
||
|
|
| `service.yml` | systemd unit, start, then first-boot checks (config written, seed created) |
|
||
|
|
| `healthcheck.yml` | check script, unit, timer |
|
||
|
|
|
||
|
|
## The seed
|
||
|
|
|
||
|
|
`{{ phoenixd_data_dir }}/seed.dat` **is** the funds. phoenixd is deliberately
|
||
|
|
excluded from the automated backups (Plan 5, Model C): the seed is twelve fixed
|
||
|
|
words that never change, so an automated job would only manufacture more copies
|
||
|
|
of a static secret on more machines. Write them down offline, once.
|
||
|
|
|
||
|
|
Note the live file is mode `0644`. That is phoenixd's own doing, not this role's,
|
||
|
|
and it is worth tightening.
|
||
|
|
|
||
|
|
## Monitoring: one variable, no product knowledge
|
||
|
|
|
||
|
|
The check asks the node itself — the service must be active **and**
|
||
|
|
`phoenix-cli getinfo` must return a `nodeId` — and records the answer in its exit
|
||
|
|
code, which systemd keeps:
|
||
|
|
|
||
|
|
```bash
|
||
|
|
systemctl is-failed phoenixd-healthcheck.service
|
||
|
|
```
|
||
|
|
|
||
|
|
That is a complete answer with no monitoring system involved. To report
|
||
|
|
elsewhere, set `healthcheck_push_url` to anything accepting an HTTP ping. Gone
|
||
|
|
from this role: the embedded Python that created monitors over the Uptime Kuma
|
||
|
|
API, the `/tmp` credentials file, the push-URL file written and parsed back, and
|
||
|
|
the systemd `Environment=` rewrite.
|
||
|
|
|
||
|
|
### Two things the conversion fixed
|
||
|
|
|
||
|
|
**The check used to log an error once a minute.** Its `Environment=` push URL had
|
||
|
|
been empty since the decommissioning, and the script printed
|
||
|
|
`ERROR: UPTIME_KUMA_PUSH_URL not set` on every fire — roughly 1,400 times a day.
|
||
|
|
The exit code was still correct, so nothing was broken; it was pure noise, and
|
||
|
|
noise that trains you to ignore the log. An unset push URL is now normal and
|
||
|
|
silent.
|
||
|
|
|
||
|
|
**`Enable and start phoenixd health check timer` was guarded by
|
||
|
|
`uptime_kuma_enabled`** and so had not run since the decommissioning — while the
|
||
|
|
timer itself was still live on the host from before. Ansible had quietly stopped
|
||
|
|
managing something that was still running. Ungated.
|