70 lines
2.9 KiB
Markdown
70 lines
2.9 KiB
Markdown
|
|
# `mempool`
|
||
|
|
|
||
|
|
Deploys the [Mempool](https://mempool.space) block explorer as a three-container
|
||
|
|
Docker Compose stack — MariaDB, backend, frontend — on `mempool-box`, and keeps a
|
||
|
|
health check on each.
|
||
|
|
|
||
|
|
Converted from `deploy_mempool_playbook.yml` (745 lines) under Plan 6. The
|
||
|
|
playbook is now 37 lines: this role, plus a second play that publishes the
|
||
|
|
frontend through Caddy on the edge host.
|
||
|
|
|
||
|
|
## Phases
|
||
|
|
|
||
|
|
| | |
|
||
|
|
|---|---|
|
||
|
|
| `docker.yml` | Docker engine: repo, key, packages, service |
|
||
|
|
| `deploy.yml` | directories, `docker-compose.yml`, pull, up, wait-for-healthy |
|
||
|
|
| `healthcheck.yml` | three check scripts, three services, three timers |
|
||
|
|
|
||
|
|
## Three health checks, not one
|
||
|
|
|
||
|
|
Mempool is three moving parts and knowing *which* one is down is the point, so
|
||
|
|
each gets its own check, unit and timer, driven by the `mempool_healthchecks`
|
||
|
|
list:
|
||
|
|
|
||
|
|
| | checks |
|
||
|
|
|---|---|
|
||
|
|
| `mariadb` | `docker inspect` health status of `mempool-db` |
|
||
|
|
| `backend` | `GET /api/v1/backend-info` |
|
||
|
|
| `frontend` | `GET /` |
|
||
|
|
|
||
|
|
Each records its answer in its exit code, which systemd keeps:
|
||
|
|
`systemctl is-failed mempool-backend-healthcheck.service`. Reporting elsewhere
|
||
|
|
is one field per check, `push_url`, and is the plug-in point for whatever
|
||
|
|
monitoring exists. Empty means check, exit honestly, report nowhere. The URLs
|
||
|
|
are credentials, so callers pass them from the vault.
|
||
|
|
|
||
|
|
Nothing here is specific to a monitoring product. The embedded Python that
|
||
|
|
created monitors over the Uptime Kuma API, the `/tmp` credentials file, the
|
||
|
|
push-URL file read back and parsed, and three systemd `Environment=` rewrites
|
||
|
|
are gone.
|
||
|
|
|
||
|
|
## MariaDB owns its own data directory
|
||
|
|
|
||
|
|
`{{ mempool_mysql_dir }}` is bind-mounted into the container, which runs as uid
|
||
|
|
**999** and must create files there. The playbook this replaced declared
|
||
|
|
`owner: "{{ ansible_user }}"` (1000) on it, which had drifted from reality ever
|
||
|
|
since the containers were created — unnoticed, because the playbook had not been
|
||
|
|
run since.
|
||
|
|
|
||
|
|
That was not academic. The first real run of this role pulled a newer
|
||
|
|
`mariadb:10.11` and recreated `mempool-db`; had the chown still been in place,
|
||
|
|
MariaDB would have come back to a directory it could not write. The role now
|
||
|
|
ensures the directory exists and leaves ownership to the container.
|
||
|
|
|
||
|
|
## `mempool_frontend_port` lives in `services_config.yml`
|
||
|
|
|
||
|
|
Two hosts need it: this role deploys the frontend on `mempool-box`, and the Caddy
|
||
|
|
play proxies to it from the edge host. A role default is invisible to the second
|
||
|
|
play, so the value lives in `service_settings.mempool.frontend_port` and the role
|
||
|
|
default derives from it.
|
||
|
|
|
||
|
|
## Expect `changed=2` on a converged host
|
||
|
|
|
||
|
|
`Pull Mempool images` and `Deploy Mempool containers with docker compose` are
|
||
|
|
bare `command:` tasks with no `changed_when`, so they always report changed.
|
||
|
|
That is the idempotent floor, not drift. Everything else reports `ok`.
|
||
|
|
|
||
|
|
**`mariadb:10.11` is a moving tag**, so a run can pull a newer patch release and
|
||
|
|
recreate the database container. Pin it if that is not what you want.
|