feat(billing): prompt the reconcile shim after tier_pro changes #533
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-infra!533
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "feat/billing-reconcile-trigger"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
What
billing.env.j2rendersRECONCILE_TRIGGER_URLandRECONCILE_TRIGGER_TOKENonly whenvault_payments_webhook_tokenis non-empty. The billing service then prompts the reconcile shim after eachtier_prochange, so a grant applies at once instead of on the next 5-minute tick.How
payment=<token>from the samevault_payments_webhook_token(reconcile-shim.env.j2). One vault value serves both ends.reconcile_shim_internal_urlis areconcilerrole default.site.ymllists all roles in one play, so the default resolves in a--tags billingrun (the forgejo role already relies on this). No copy added.bitborgpodman network on one host.Tested
ansible-playbook site.yml --check --diff --limit bitborg-prod --tags billing,reconciler:ok=27 changed=0 failed=0 skipped=17, empty diff. Inert today:billing_enabled: falseskips the role, and the token is empty.trim_blocks): empty token gives the file as before, with no new lines. A non-empty token appends the comment and the two lines at the end.pnpm format:check,pnpm mdlint,pnpm ansible:check(syntax),ansible-lint roles/billing: clean. Pre-commit hooks passed.Operator steps
Set the vault value:
pnpm ansible-vault:edit,vault_payments_webhook_token: <openssl rand -hex 32>.Dry-run, then apply (shim first, so it accepts the source before billing sends it):
Expect the shim env file to change and the shim to restart. If
billing_enabledis true, expect the billing env file to change and the service to restart. Tag order does not set role order:site.ymlruns billing before reconciler. Run--tags reconcilerfirst, then--tags billing, if the order matters to you.Verify: grant a test
tier_promembership through the billing service. The shim log (podman logs bitborg-reconcile-trigger, or Loki) showskick reason=payment. The reconciler runs within seconds, not 5 minutes.Alerting gap
ReconcileEventPathSilentcounts only[reconcile-trigger] kicklines from the web container, then expectsbitborg-reconcile-kick.serviceto start. Kicks from the billing service are not counted, so a dead billing-to-shim path raises no alert. The 5-minute timer still applies every change. Not built here: it needs a decision on which log to count (the shim logskick reason=<source>).Open questions
ReconcileEventPathSilentalso countkick reason=paymentshim lines? Follow-up issue if yes.Visa kommandoradsinstruktioner
Checka ut
Checka ut en ny gren från din projektkatalog och testa ändringarna.