Defaults
Defaults for download_host
alwaldend.main.download_host configures download hosts using the existing
host, nginx, and traefik roles. It checks that the selected content device
is a block device before configuring the host, creates Btrfs without
forcing replacement of an existing filesystem, and mounts by UUID. This role
is intended for the Fedora hosts used by infra/download.
The role creates only the publication roots: projects/, sites/, and private
staging/, owned by the download publisher account. Publishers create individual projects,
sites, and releases. The mount root and service state remain root-owned;
privileged ownership changes never traverse per-site directories. Shared Nginx
and Traefik roles own their service units. Traefik uses its standard system-disk
location. A daily systemd timer runs incremental duperemove over projects
and sites with resource limits and private hash state. Uploading files,
extracting sites, and switching the current-release symlink are separate
publisher operations. Administrators authenticate with existing SSH access and
run publication as this account through sudo. The role does not manage its
authorized_keys and requires no publisher key input. It installs rsync for
SSH transfers.
On SELinux-enabled hosts, the role persists httpd_sys_content_t labels for
static content and applies them with restorecon. This permits confined Nginx
to read the custom document root; ordinary Unix permissions alone do not grant
that access. See Red Hat’s Nginx configuration guide.
Filesystem creation, UUID-based mounting, directories, SELinux labels, and daily
maintenance live in tasks/filesystem.yaml. The pinned
community.general.btrfs_info
module discovers filesystem UUIDs; selection uses the canonical device path so
both direct device paths and by-id symlinks work. Attachment checks remain in
tasks/main.yaml before base-host setup.
force_handlers: true on the play so completed configuration changes run
their notified handlers even if a later task fails.download_content_device. Administrator SSH and sudo access come
from the shared host roles; no dedicated upload key is configured.download_root and download_publisher as needed. The content mount
must be under root-owned, non-publisher-writable parent directories./opt/traefik) so content-disk failure does not stop the proxy.nginx_config_template,
Traefik static/dynamic templates, ACME settings, and base-host variables.
The caller owns inventory, firewall policy, Vault references, and routing.- name: Configure the selected download VM
hosts: download
become: true
force_handlers: true
roles:
- alwaldend.main.download_host
The collection packages the role automatically through its existing role aggregation. Domain-specific serving templates stay with the deployment.
Defaults for download_host