fix(quadlet): pull pinned images + restart on unit change (#63) #93
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!93
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "fix/63-image-bump-pull-restart"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
PR: fix/63-image-bump-pull-restart → main
Title: fix(quadlet): pull pinned images + restart on unit change (#63)
Fixes #63 — image-tag bumps silently no-op'd on prod because nothing pulled the new tag and the started-only path never restarted onto a re-rendered unit.
Changes
podman_imagepull of the pinned image before (re)start —pull: trueis a no-op when the tag is already local, so routine applies stay fast.restarted-when-changed (the monitoring role's "restart any whose unit changed" pattern). The daemon-reload happens at the role'sflush_handlers; the restart is a plain task after it, so ordering is guaranteed.daemon_reload: truefolded into theRestart Forgejohandler and the container-unit install now notifies it. This kills the stale-unit mechanism pinned during the v16 upgrade: at flush, handlers run in definition order, and under--tags forgejothe in-scopeReload bitborg user systemddefinition sorted after the restart — so the restart used the old generated unit. Reloading inside the handler is ordering-proof in every tag scope. Also dropped the handler'sfailed_when: false(the folded reload guarantees the unit exists by restart time, so real restart failures now surface).ImageNameequals the pinnedimage:tag— a silent no-op now fails the play instead of reporting green. Skipped under--check(a pending bump legitimately differs there).Verification
ansible-playbook site.yml --syntax-checkcleanansible-linton the three roles: 0 failures, 0 warnings (production profile)