ops: host systemd units in git; windy-pro tags never reach Windy Git
All checks were successful
check / gate (push) Successful in 22s
All checks were successful
check / gate (push) Successful in 22s
- deploy/systemd/: sync/backup timers+services, tunnel, and the windy-job heartbeat drop-ins (silent-failure audit). They existed only on Veron, the same drift that left the runbook wrong. GITHUB_TOKEN is stripped (repo is public); it stays in the root-only unit on the host. - sync: SYNC_NO_TAGS (default windy-pro). build-electron fires on v* tags and targets ubuntu/macos/windows-latest, labels no runner has, so it would queue forever, invisibly. Desktop releases are built elsewhere. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
13
deploy/systemd/windygit-backup.service
Normal file
13
deploy/systemd/windygit-backup.service
Normal file
@@ -0,0 +1,13 @@
|
||||
[Unit]
|
||||
Description=Windy Git nightly backup (git bundles + windgit schema -> R2)
|
||||
After=network-online.target docker.service
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
WorkingDirectory=/srv/windygit/src
|
||||
# The .env holds the R2 credentials. The script refuses to run without them
|
||||
# rather than reporting a backup that did not happen.
|
||||
EnvironmentFile=/srv/windygit/src/.env
|
||||
ExecStart=/bin/bash /srv/windygit/src/scripts/backup.sh
|
||||
Nice=10
|
||||
IOSchedulingClass=idle
|
||||
3
deploy/systemd/windygit-backup.service.d/windy-job.conf
Normal file
3
deploy/systemd/windygit-backup.service.d/windy-job.conf
Normal file
@@ -0,0 +1,3 @@
|
||||
[Service]
|
||||
ExecStart=
|
||||
ExecStart=/usr/local/bin/windy-job windygit-backup 26h --expect "ok — [0-9]+ repos" --owner 13 -- /bin/bash /srv/windygit/src/scripts/backup.sh
|
||||
12
deploy/systemd/windygit-backup.timer
Normal file
12
deploy/systemd/windygit-backup.timer
Normal file
@@ -0,0 +1,12 @@
|
||||
[Unit]
|
||||
Description=Nightly Windy Git backup
|
||||
|
||||
[Timer]
|
||||
OnCalendar=*-*-* 04:17:00
|
||||
# Grant's workstation is not always on at 04:17. Without this a missed window
|
||||
# is simply skipped and the backup silently never runs.
|
||||
Persistent=true
|
||||
RandomizedDelaySec=600
|
||||
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
@@ -0,0 +1,3 @@
|
||||
[Service]
|
||||
ExecStart=
|
||||
ExecStart=/usr/local/bin/windy-job windygit-ci-prune 7h --expect "ci storage [0-9]+G" --owner 13 -- /srv/windygit/src/deploy/runner/prune.sh
|
||||
12
deploy/systemd/windygit-sync.service
Normal file
12
deploy/systemd/windygit-sync.service
Normal file
@@ -0,0 +1,12 @@
|
||||
[Unit]
|
||||
Description=Sync GitHub -> Windy Git (Phase 1: GitHub is the source of truth)
|
||||
After=network-online.target docker.service
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
WorkingDirectory=/srv/windygit/src
|
||||
EnvironmentFile=/srv/windygit/src/.env
|
||||
# GITHUB_TOKEN is set on the host only (root-only unit file / .env) — NEVER commit it.
|
||||
Environment=GITHUB_OWNER=sneakyfree
|
||||
ExecStart=/bin/bash /srv/windygit/src/scripts/sync_from_github.sh
|
||||
Nice=10
|
||||
3
deploy/systemd/windygit-sync.service.d/windy-job.conf
Normal file
3
deploy/systemd/windygit-sync.service.d/windy-job.conf
Normal file
@@ -0,0 +1,3 @@
|
||||
[Service]
|
||||
ExecStart=
|
||||
ExecStart=/usr/local/bin/windy-job windygit-sync 20m --expect "all repos in step with GitHub" --owner 13 -- /bin/bash /srv/windygit/src/scripts/sync_from_github.sh
|
||||
10
deploy/systemd/windygit-sync.timer
Normal file
10
deploy/systemd/windygit-sync.timer
Normal file
@@ -0,0 +1,10 @@
|
||||
[Unit]
|
||||
Description=Keep Windy Git in step with GitHub every 5 minutes
|
||||
|
||||
[Timer]
|
||||
OnBootSec=3min
|
||||
OnUnitActiveSec=5min
|
||||
Persistent=true
|
||||
|
||||
[Install]
|
||||
WantedBy=timers.target
|
||||
16
deploy/systemd/windygit-tunnel.service
Normal file
16
deploy/systemd/windygit-tunnel.service
Normal file
@@ -0,0 +1,16 @@
|
||||
[Unit]
|
||||
Description=Windy Git - Cloudflare Tunnel (the only ingress; no inbound port is opened)
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=notify
|
||||
ExecStart=/usr/bin/cloudflared --no-autoupdate --config /etc/cloudflared/config.yml tunnel run
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
# G1.4 - bounded, so a misbehaving ingress can never starve Grant's workstation.
|
||||
MemoryMax=512M
|
||||
CPUQuota=100%
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -40,6 +40,12 @@ FAILED=0
|
||||
# it flips to Windy-Git-first, or the sync will fight its authors and win.
|
||||
REPOS="${SYNC_REPOS:-windy-calendar windy-search windy-registry Windy-Clone WindyCloud windy-cloud-sites windy-mind eternitas windy-agent windy-git windy-chat windy-mail windy-connect windy-drops windy-code-web windy-code windy-traveler windy-translate windytranslate-site windytraveler-site windy-hand windy-cloud-domains windy-cloud-vps windytalk windy-pro}"
|
||||
|
||||
# Repos whose TAGS must not reach Windy Git. A tag push fires `on: push: tags`
|
||||
# workflows; windy-pro's build-electron is a matrix over ubuntu/macos/windows-
|
||||
# latest, labels no runner here has, so every leg would queue forever (and
|
||||
# queued jobs are invisible in /actions/tasks). Releases are built elsewhere.
|
||||
NO_TAGS="${SYNC_NO_TAGS:-windy-pro}"
|
||||
|
||||
mkdir -p "$WORK"
|
||||
log() { printf '[sync %s] %s\n' "$(date -u +%H:%M:%SZ)" "$*"; }
|
||||
|
||||
@@ -63,7 +69,7 @@ for r in $REPOS; do
|
||||
|
||||
if git --git-dir="$bare" push --quiet --force \
|
||||
"https://${WG_OWNER}:${GITEA_ADMIN_TOKEN}@${WG}/${WG_OWNER}/${r}.git" \
|
||||
'+refs/heads/*:refs/heads/*' '+refs/tags/*:refs/tags/*' 2>/dev/null; then
|
||||
'+refs/heads/*:refs/heads/*' $([[ " $NO_TAGS " == *" $r "* ]] || echo '+refs/tags/*:refs/tags/*') 2>/dev/null; then
|
||||
log "$r ok (${before:0:7})"
|
||||
else
|
||||
log "FAILED push $r -> windy git"; FAILED=1
|
||||
|
||||
Reference in New Issue
Block a user