685-line playbook becomes 33 lines plus a 426-line role (install/service/healthcheck phases, six templates, one handler). fulcrum_vars.yml is deleted; its content is the role's defaults. Verified: fulcrum untouched - active since 2026-07-29 (no restart), 192G datadir, height 966842, bitcoind and db_mem unchanged on disk. Second run changed=1 (the arming run, changed_when: false aside). vipy changed=0. THREE PRE-EXISTING LANDMINES the check-mode diff caught, any of which a faithful extraction would have detonated: - bitcoin_rpc_host was "192.168.1.140", commented "IP of knots_box_local". But .140 is fulcrum-box ITSELF; knots-box is .135. The DHCP leases had reshuffled - the fifth instance of this same disease in this estate. The live config had been hand-corrected to knots-box; running the playbook would have reverted it and pointed Fulcrum at itself. Now addressed by Tailscale name. - The `Restart fulcrum` handler was guarded by uptime_kuma_enabled, so the three tasks that notify it (SSL cert, fulcrum.conf, systemd unit) could not restart anything. A config change applied to disk, reported success, and silently never took effect. That is worse than the other banner casualties: it makes the deployment itself lie. Ungated. - db_mem was about to go 2048 -> 4448 (75% of 5931MB RAM), leaving ~1.4GB for the OS and Fulcrum's non-cache memory. The live value had been hand-tuned down. fulcrum_db_mem_mb_override pins it. Note set_fact outranks role defaults, so the calculation itself has to honour the override. MY OWN ERROR, third instance: retyping `copy:` as `template:` lost `owner:` on the banner and on fulcrum.conf. Rather than keep catching these by eye, every managed path's owner/group/mode is now compared against `git show HEAD:` mechanically - 12/12 match. The health check timer had not fired since 2026-02-17 while reporting `active` and `enabled`. It is OnBootSec + OnUnitActiveSec with no OnCalendar: OnBootSec elapses once, and OnUnitActiveSec needs the SERVICE to have run this boot to have anything to schedule from. Restarting the timer does not supply that; running the service does, so the role now runs the check once after enabling. Also dropped `Requires=fulcrum.service` from the timer - on a timer that means "stop watching when the watched thing stops". Diagnostic note: NextElapseUSecRealtime is always empty for a monotonic timer, so it reads as broken even when healthy. I misread it once and wrongly called the timer dead. Use NextElapseUSecMonotonic or systemctl list-timers. fulcrum_ssl_port and fulcrum_tailscale_hostname moved to services_config.yml - the socket-proxy play on the edge host needs them and a role default cannot reach a second play. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
54 lines
1.7 KiB
YAML
54 lines
1.7 KiB
YAML
# Centralized Services Configuration
|
|
# Subdomains and Caddy settings for all services
|
|
|
|
# Edit these subdomains to match your preferences
|
|
subdomains:
|
|
# Monitoring Services (on watchtower)
|
|
ntfy: ntfy
|
|
# DEPRECATED 2026-09-11 — Uptime Kuma is decommissioned and this subdomain no
|
|
# longer resolves to anything. Kept only because the deprecated monitoring
|
|
# blocks still template it into uptime_kuma_api_url. See archive/uptime_kuma/.
|
|
uptime_kuma: uptime
|
|
|
|
# VPN Infrastructure (on spacey)
|
|
headscale: headscale
|
|
|
|
# Core Services (on vipy)
|
|
vaultwarden: vault
|
|
forgejo: forgejo
|
|
lnbits: wallet
|
|
|
|
# Secondary Services (on vipy)
|
|
ntfy_emergency_app: avisame
|
|
personal_blog: pablohere
|
|
|
|
# Memos (on memos-box)
|
|
memos: memos
|
|
|
|
# Mempool Block Explorer (on mempool_box, proxied via vipy)
|
|
mempool: mempool
|
|
|
|
# DATUM Gateway dashboard (on knots_box, proxied via vipy)
|
|
datum_gateway: datum
|
|
|
|
# Caddy configuration
|
|
caddy_sites_dir: /etc/caddy/sites-enabled
|
|
|
|
# Service-specific settings shared across playbooks
|
|
service_settings:
|
|
ntfy:
|
|
topic: alerts
|
|
headscale:
|
|
namespace: counter-net
|
|
mempool:
|
|
# The frontend port is needed in two places on two different hosts: the
|
|
# mempool role deploys it on mempool-box, and the Caddy play proxies to it
|
|
# from the edge host. A role default cannot serve the second play, so it
|
|
# lives here rather than in roles/mempool/defaults.
|
|
frontend_port: 8080
|
|
fulcrum:
|
|
# Same shape as mempool: the fulcrum role deploys on fulcrum-box, and the
|
|
# socket-proxy play publishes the SSL port from the edge host. A role default
|
|
# is invisible to that second play.
|
|
ssl_port: 50002
|
|
tailscale_hostname: fulcrum-box
|