refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226) #227
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!227
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "chore/226-retire-bash-reconciler"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
Retires the bash entitlement reconciler now that the
bitborg-auth-reconcilercontainer is the sole applier (ADR 0035 cutover, #221). Closes the last open item on #226.What this does
gitborg-reconciler.sh.j2,.service.j2,.timer.j2,reconciler.env.j2.tasks/main.yml: replaces the bash install with astate: absentremoval of the orphaned on-host artifacts (gitborg-reconciler.service/.timer, the script,reconciler.env) + adaemon-reload, then includes the container tasks. (Deleting the tasks alone would leave the units on the host forever — Ansible only converges what it declares.) They're already stopped+disabled from #221, so removal is clean.defaults: drops the bash-only varsreconciler_enabled,reconciler_apply,reconciler_packages,reconciler_bin,reconciler_env_file; keeps the sharedreconciler_systemd_user_dir/reconciler_on_calendar; rewrites the ADR 0035 comment block (no longer a "parallel-run rehearsal").next-container.yml: removes the double-reconcile guard (moot without bash); ensures the systemd user dir exists (the bash role used to create it); drops "dry-run parallel run" from task names/comments.-nextcontainer/timerDescription=and env comment (no longer a dry-run rehearsal).Verification (read-only
--check --diffagainst prod)Converges cleanly: the bash units/script/env go
absent,failed=0, health gates intact. Full apply is deferred to after burn-in.Open question for review
I kept the
gitborg-reconciler-nextunit + var names (only dropped the stale wording) to bound the diff and avoid a host unit-name transition. Should a follow-up (or this PR) renamegitborg-reconciler-next→gitborg-reconcilernow that it's the only reconciler? That means renaming the unit files +reconciler_next_*vars and handling the on-host unit rename at apply. Happy to fold it in if preferred.Apply (when burn-in is signed off)
site.yml --tags reconciler→ verify the timer still fires, a run applies with sane projections, andreconciler.promstays fresh (noReconcilerStale).Refs #226, ADR 0035.
WIP: refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226)till refactor(reconciler): retire the bash reconciler after ADR 0035 cutover (#226)