ops: host systemd units in git; windy-pro tags never reach Windy Git
All checks were successful
check / gate (push) Successful in 22s

- deploy/systemd/: sync/backup timers+services, tunnel, and the windy-job
  heartbeat drop-ins (silent-failure audit). They existed only on Veron,
  the same drift that left the runbook wrong. GITHUB_TOKEN is stripped
  (repo is public); it stays in the root-only unit on the host.
- sync: SYNC_NO_TAGS (default windy-pro). build-electron fires on v* tags
  and targets ubuntu/macos/windows-latest, labels no runner has, so it
  would queue forever, invisibly. Desktop releases are built elsewhere.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 09:51:51 -04:00
parent d5181f1c6d
commit 95c33c8004
9 changed files with 79 additions and 1 deletions

View File

@@ -0,0 +1,13 @@
[Unit]
Description=Windy Git nightly backup (git bundles + windgit schema -> R2)
After=network-online.target docker.service
[Service]
Type=oneshot
WorkingDirectory=/srv/windygit/src
# The .env holds the R2 credentials. The script refuses to run without them
# rather than reporting a backup that did not happen.
EnvironmentFile=/srv/windygit/src/.env
ExecStart=/bin/bash /srv/windygit/src/scripts/backup.sh
Nice=10
IOSchedulingClass=idle

View File

@@ -0,0 +1,3 @@
[Service]
ExecStart=
ExecStart=/usr/local/bin/windy-job windygit-backup 26h --expect "ok — [0-9]+ repos" --owner 13 -- /bin/bash /srv/windygit/src/scripts/backup.sh

View File

@@ -0,0 +1,12 @@
[Unit]
Description=Nightly Windy Git backup
[Timer]
OnCalendar=*-*-* 04:17:00
# Grant's workstation is not always on at 04:17. Without this a missed window
# is simply skipped and the backup silently never runs.
Persistent=true
RandomizedDelaySec=600
[Install]
WantedBy=timers.target

View File

@@ -0,0 +1,3 @@
[Service]
ExecStart=
ExecStart=/usr/local/bin/windy-job windygit-ci-prune 7h --expect "ci storage [0-9]+G" --owner 13 -- /srv/windygit/src/deploy/runner/prune.sh

View File

@@ -0,0 +1,12 @@
[Unit]
Description=Sync GitHub -> Windy Git (Phase 1: GitHub is the source of truth)
After=network-online.target docker.service
[Service]
Type=oneshot
WorkingDirectory=/srv/windygit/src
EnvironmentFile=/srv/windygit/src/.env
# GITHUB_TOKEN is set on the host only (root-only unit file / .env) — NEVER commit it.
Environment=GITHUB_OWNER=sneakyfree
ExecStart=/bin/bash /srv/windygit/src/scripts/sync_from_github.sh
Nice=10

View File

@@ -0,0 +1,3 @@
[Service]
ExecStart=
ExecStart=/usr/local/bin/windy-job windygit-sync 20m --expect "all repos in step with GitHub" --owner 13 -- /bin/bash /srv/windygit/src/scripts/sync_from_github.sh

View File

@@ -0,0 +1,10 @@
[Unit]
Description=Keep Windy Git in step with GitHub every 5 minutes
[Timer]
OnBootSec=3min
OnUnitActiveSec=5min
Persistent=true
[Install]
WantedBy=timers.target

View File

@@ -0,0 +1,16 @@
[Unit]
Description=Windy Git - Cloudflare Tunnel (the only ingress; no inbound port is opened)
After=network-online.target
Wants=network-online.target
[Service]
Type=notify
ExecStart=/usr/bin/cloudflared --no-autoupdate --config /etc/cloudflared/config.yml tunnel run
Restart=always
RestartSec=5
# G1.4 - bounded, so a misbehaving ingress can never starve Grant's workstation.
MemoryMax=512M
CPUQuota=100%
[Install]
WantedBy=multi-user.target