Host configuration
Categories:
Build :ansible_bin to package the playbook and shared collection. The play
uses alwaldend.main.download_host
for storage, the publisher account, rsync, service setup, and deduplication.
The role does not configure publisher authorized keys; administrators use their
existing SSH access and run publication through sudo as download. Inventory,
Vault injection, and routing templates belong to this deployment. Both inventories connect
using their unique host FQDNs, with the same names for SSH host-key checks.
Host DNS must resolve before configuration; no IP override or HostKeyAlias
is configured. Run :ansible.local or :ansible.yandex only with explicit live
authorization. Before configuring the host, Ansible requires the content path
to resolve to a block device. The role creates the filesystem without forcing
an overwrite and mounts it before enabling the services. The shared roles
manage the service units. Traefik keeps its configuration and ACME data on the
system disk at /opt/traefik and has no content-mount dependency. The role creates
publication roots; publishers create individual project/site directories and
select releases. It never uploads or selects releases.
nginx_config_template supplies the complete configuration to the reusable
Nginx role. JSON listings allow credential-free cross-origin reads and normal
HEAD/range downloads. Site requests follow the current link. Port 8008 is
loopback-only and uses the Fedora SELinux HTTP port type. Public content has
read-only HTTP labels; the SSH publisher needs readable file modes and must
preserve those labels when activating staged content.
Yandex uses Let’s Encrypt HTTP-01 without EAB; XCP-ng uses the existing Vault HTTP-01 directory with EAB generated by the shared Traefik role. Local browsers need the repository CA. Neither host stores a DNS provider credential.
For public ACME staging, override both download_acme_directory and
traefik_data_dir (for example a separate acme-staging directory under the
Traefik root). Switching back preserves separate staging/production accounts
and prevents staging certificates from becoming the production selection.
The content filesystem is Btrfs. The native duperemove package and daily
systemd timer share duplicate extents across published files and extracted
sites. Its private hash database lives outside both scan roots. The maintenance
service waits for the mount and has bounded CPU/memory and low I/O priority;
a failed run leaves the release layout and active website selection intact.
The play forces notified handlers after later task failures. Successfully installed configuration therefore still triggers its pending handlers if a later task fails. Unreachable hosts can still prevent handler execution. Nginx configuration validation before installation is unchanged. See Ansible’s handler failure behavior.