# `mempool` Deploys the [Mempool](https://mempool.space) block explorer as a three-container Docker Compose stack — MariaDB, backend, frontend — on `mempool-box`, and keeps a health check on each. Converted from `deploy_mempool_playbook.yml` (745 lines) under Plan 6. The playbook is now 37 lines: this role, plus a second play that publishes the frontend through Caddy on the edge host. ## Phases | | | |---|---| | `docker.yml` | Docker engine: repo, key, packages, service | | `deploy.yml` | directories, `docker-compose.yml`, pull, up, wait-for-healthy | | `healthcheck.yml` | three check scripts, three services, three timers | ## Three health checks, not one Mempool is three moving parts and knowing *which* one is down is the point, so each gets its own check, unit and timer, driven by the `mempool_healthchecks` list: | | checks | |---|---| | `mariadb` | `docker inspect` health status of `mempool-db` | | `backend` | `GET /api/v1/backend-info` | | `frontend` | `GET /` | Each records its answer in its exit code, which systemd keeps: `systemctl is-failed mempool-backend-healthcheck.service`. Reporting elsewhere is one field per check, `push_url`, and is the plug-in point for whatever monitoring exists. Empty means check, exit honestly, report nowhere. The URLs are credentials, so callers pass them from the vault. Nothing here is specific to a monitoring product. The embedded Python that created monitors over the Uptime Kuma API, the `/tmp` credentials file, the push-URL file read back and parsed, and three systemd `Environment=` rewrites are gone. ## MariaDB owns its own data directory `{{ mempool_mysql_dir }}` is bind-mounted into the container, which runs as uid **999** and must create files there. The playbook this replaced declared `owner: "{{ ansible_user }}"` (1000) on it, which had drifted from reality ever since the containers were created — unnoticed, because the playbook had not been run since. That was not academic. The first real run of this role pulled a newer `mariadb:10.11` and recreated `mempool-db`; had the chown still been in place, MariaDB would have come back to a directory it could not write. The role now ensures the directory exists and leaves ownership to the container. ## `mempool_frontend_port` lives in `services_config.yml` Two hosts need it: this role deploys the frontend on `mempool-box`, and the Caddy play proxies to it from the edge host. A role default is invisible to the second play, so the value lives in `service_settings.mempool.frontend_port` and the role default derives from it. ## Expect `changed=2` on a converged host `Pull Mempool images` and `Deploy Mempool containers with docker compose` are bare `command:` tasks with no `changed_when`, so they always report changed. That is the idempotent floor, not drift. Everything else reports `ok`. **`mariadb:10.11` is a moving tag**, so a run can pull a newer patch release and recreate the database container. Pin it if that is not what you want.