fix(quadlet): pull pinned images + restart on unit change (#63) #93

Sammanfogat
supernaut sammanfogade 1 incheckning från fix/63-image-bump-pull-restart in i main 2026-07-18 12:56:25 +00:00
Ägare

PR: fix/63-image-bump-pull-restart → main

Title: fix(quadlet): pull pinned images + restart on unit change (#63)

Fixes #63 — image-tag bumps silently no-op'd on prod because nothing pulled the new tag and the started-only path never restarted onto a re-rendered unit.

Changes

  • postgres / forgejo / caddy roles: explicit podman_image pull of the pinned image before (re)start — pull: true is a no-op when the tag is already local, so routine applies stay fast.
  • postgres / caddy: register the container-unit install and restarted-when-changed (the monitoring role's "restart any whose unit changed" pattern). The daemon-reload happens at the role's flush_handlers; the restart is a plain task after it, so ordering is guaranteed.
  • forgejo: daemon_reload: true folded into the Restart Forgejo handler and the container-unit install now notifies it. This kills the stale-unit mechanism pinned during the v16 upgrade: at flush, handlers run in definition order, and under --tags forgejo the in-scope Reload bitborg user systemd definition sorted after the restart — so the restart used the old generated unit. Reloading inside the handler is ordering-proof in every tag scope. Also dropped the handler's failed_when: false (the folded reload guarantees the unit exists by restart time, so real restart failures now surface).
  • verification: each role asserts post-start that the running container's ImageName equals the pinned image:tag — a silent no-op now fails the play instead of reporting green. Skipped under --check (a pending bump legitimately differs there).
  • runbook: upgrade §4 rewritten — the apply now pulls, restarts, and self-verifies.

Verification

  • ansible-playbook site.yml --syntax-check clean
  • ansible-lint on the three roles: 0 failures, 0 warnings (production profile)
  • Not applied to prod. First post-merge apply should be all no-ops (this PR changes no units); the new assert tasks make every future tag bump self-checking.
# PR: fix/63-image-bump-pull-restart → main Title: fix(quadlet): pull pinned images + restart on unit change (#63) Fixes #63 — image-tag bumps silently no-op'd on prod because nothing pulled the new tag and the started-only path never restarted onto a re-rendered unit. ## Changes - **postgres / forgejo / caddy roles**: explicit `podman_image` pull of the pinned image before (re)start — `pull: true` is a no-op when the tag is already local, so routine applies stay fast. - **postgres / caddy**: register the container-unit install and `restarted`-when-changed (the monitoring role's "restart any whose unit changed" pattern). The daemon-reload happens at the role's `flush_handlers`; the restart is a plain task after it, so ordering is guaranteed. - **forgejo**: `daemon_reload: true` folded into the `Restart Forgejo` handler and the container-unit install now notifies it. This kills the stale-unit mechanism pinned during the v16 upgrade: at flush, handlers run in *definition* order, and under `--tags forgejo` the in-scope `Reload bitborg user systemd` definition sorted after the restart — so the restart used the old generated unit. Reloading inside the handler is ordering-proof in every tag scope. Also dropped the handler's `failed_when: false` (the folded reload guarantees the unit exists by restart time, so real restart failures now surface). - **verification**: each role asserts post-start that the running container's `ImageName` equals the pinned `image:tag` — a silent no-op now fails the play instead of reporting green. Skipped under `--check` (a pending bump legitimately differs there). - **runbook**: upgrade §4 rewritten — the apply now pulls, restarts, and self-verifies. ## Verification - `ansible-playbook site.yml --syntax-check` clean - `ansible-lint` on the three roles: 0 failures, 0 warnings (production profile) - Not applied to prod. First post-merge apply should be all no-ops (this PR changes no units); the new assert tasks make every future tag bump self-checking.
supernaut lade till 1 incheckning 2026-07-18 07:17:05 +00:00
fix(quadlet): pull pinned images + restart on unit change (#63)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 1m40s
48b3f5731c
postgres/forgejo/caddy roles now:

- pull the pinned image explicitly before (re)starting, so a tag bump
  actually has the new image on the host (previously nothing pulled it)
- restart the container when its .container unit changed (monitoring
  role's pattern); forgejo folds daemon-reload into the Restart handler
  so the restart can never use a stale generated unit under --tags
- verify post-start that the running container is on the pinned tag,
  failing the play instead of green-lighting a silent no-op

Closes #63
supernaut sammanfogade incheckning 11c81880ec till main 2026-07-18 12:56:25 +00:00
supernaut tog bort grenen fix/63-image-bump-pull-restart 2026-07-18 12:56:25 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!93
Ingen beskrivning angiven.