refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226) #227

Sammanfogat
supernaut sammanfogade 1 incheckning från chore/226-retire-bash-reconciler in i main 2026-07-28 06:41:00 +00:00
Ägare

⚠️ WIP — do NOT merge/apply until the post-cutover burn-in is signed off. The container has been sole applier since the #221 cutover; this removes the now-dead bash reconciler. Merging is gated on an agreed burn-in with the container applying cleanly.

Retires the bash entitlement reconciler now that the bitborg-auth-reconciler container is the sole applier (ADR 0035 cutover, #221). Closes the last open item on #226.

What this does

  • Deletes the bash templates: gitborg-reconciler.sh.j2, .service.j2, .timer.j2, reconciler.env.j2.
  • tasks/main.yml: replaces the bash install with a state: absent removal of the orphaned on-host artifacts (gitborg-reconciler.service/.timer, the script, reconciler.env) + a daemon-reload, then includes the container tasks. (Deleting the tasks alone would leave the units on the host forever — Ansible only converges what it declares.) They're already stopped+disabled from #221, so removal is clean.
  • defaults: drops the bash-only vars reconciler_enabled, reconciler_apply, reconciler_packages, reconciler_bin, reconciler_env_file; keeps the shared reconciler_systemd_user_dir / reconciler_on_calendar; rewrites the ADR 0035 comment block (no longer a "parallel-run rehearsal").
  • next-container.yml: removes the double-reconcile guard (moot without bash); ensures the systemd user dir exists (the bash role used to create it); drops "dry-run parallel run" from task names/comments.
  • Relabels the -next container/timer Description= and env comment (no longer a dry-run rehearsal).
  • runbook: the reconciler section now describes the container; the parallel-run cutover is recorded as history.

Verification (read-only --check --diff against prod)

Converges cleanly: the bash units/script/env go absent, failed=0, health gates intact. Full apply is deferred to after burn-in.

Open question for review

I kept the gitborg-reconciler-next unit + var names (only dropped the stale wording) to bound the diff and avoid a host unit-name transition. Should a follow-up (or this PR) rename gitborg-reconciler-next → gitborg-reconciler now that it's the only reconciler? That means renaming the unit files + reconciler_next_* vars and handling the on-host unit rename at apply. Happy to fold it in if preferred.

Apply (when burn-in is signed off)

site.yml --tags reconciler → verify the timer still fires, a run applies with sane projections, and reconciler.prom stays fresh (no ReconcilerStale).

Refs #226, ADR 0035.

> ⚠️ **WIP — do NOT merge/apply until the post-cutover burn-in is signed off.** The container has been sole applier since the #221 cutover; this removes the now-dead bash reconciler. Merging is gated on an agreed burn-in with the container applying cleanly. Retires the bash entitlement reconciler now that the `bitborg-auth-reconciler` container is the sole applier (ADR 0035 cutover, #221). Closes the last open item on #226. ## What this does - **Deletes** the bash templates: `gitborg-reconciler.sh.j2`, `.service.j2`, `.timer.j2`, `reconciler.env.j2`. - **`tasks/main.yml`:** replaces the bash install with a `state: absent` removal of the orphaned on-host artifacts (`gitborg-reconciler.service`/`.timer`, the script, `reconciler.env`) + a `daemon-reload`, then includes the container tasks. *(Deleting the tasks alone would leave the units on the host forever — Ansible only converges what it declares.)* They're already stopped+disabled from #221, so removal is clean. - **`defaults`:** drops the bash-only vars `reconciler_enabled`, `reconciler_apply`, `reconciler_packages`, `reconciler_bin`, `reconciler_env_file`; keeps the shared `reconciler_systemd_user_dir` / `reconciler_on_calendar`; rewrites the ADR 0035 comment block (no longer a "parallel-run rehearsal"). - **`next-container.yml`:** removes the double-reconcile guard (moot without bash); ensures the systemd user dir exists (the bash role used to create it); drops "dry-run parallel run" from task names/comments. - **Relabels** the `-next` container/timer `Description=` and env comment (no longer a dry-run rehearsal). - **runbook:** the reconciler section now describes the container; the parallel-run cutover is recorded as history. ## Verification (read-only `--check --diff` against prod) Converges cleanly: the bash units/script/env go `absent`, `failed=0`, health gates intact. Full apply is **deferred to after burn-in**. ## Open question for review I **kept the `gitborg-reconciler-next` unit + var names** (only dropped the stale wording) to bound the diff and avoid a host unit-name transition. Should a follow-up (or this PR) rename `gitborg-reconciler-next` → `gitborg-reconciler` now that it's the only reconciler? That means renaming the unit files + `reconciler_next_*` vars and handling the on-host unit rename at apply. Happy to fold it in if preferred. ## Apply (when burn-in is signed off) `site.yml --tags reconciler` → verify the timer still fires, a run applies with sane projections, and `reconciler.prom` stays fresh (no `ReconcilerStale`). Refs #226, ADR 0035.
supernaut lade till 1 incheckning 2026-07-27 19:05:34 +00:00
refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m24s
1dcab24639
The gitborg-auth-reconciler container has been the sole applier since the cutover
(#221). Remove the now-dead bash implementation and de-rehearsal the container role:

- Delete the bash templates (script, .service, .timer, reconciler.env).
- tasks/main.yml: replace the bash install with a state:absent removal of the
  orphaned on-host units/script/env (+ daemon-reload); keep the container include.
- defaults: drop reconciler_enabled / reconciler_apply / reconciler_packages /
  reconciler_bin / reconciler_env_file; rewrite the ADR 0035 comment block.
- next-container.yml: drop the double-reconcile guard (moot without bash); ensure the
  systemd user dir exists (the bash role used to); drop 'dry-run parallel run' wording.
- Relabel the -next unit descriptions + env comment (no longer a dry-run rehearsal).
- runbook: reconciler section now describes the container; cutover recorded as history.

Kept the gitborg-reconciler-next unit/var names to bound the diff + apply risk — the
rename to gitborg-reconciler is an open question for review (see the PR body).

Do NOT apply until the post-cutover burn-in is signed off.
supernaut ändrade titeln från WIP: refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226) till refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226) 2026-07-28 06:38:07 +00:00
supernaut sammanfogade incheckning b678dd818e till main 2026-07-28 06:41:00 +00:00
supernaut tog bort grenen chore/226-retire-bash-reconciler 2026-07-28 06:41:00 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!227
Ingen beskrivning angiven.