ops: host systemd units in git; windy-pro tags never reach Windy Git
All checks were successful
check / gate (push) Successful in 22s

- deploy/systemd/: sync/backup timers+services, tunnel, and the windy-job
  heartbeat drop-ins (silent-failure audit). They existed only on Veron,
  the same drift that left the runbook wrong. GITHUB_TOKEN is stripped
  (repo is public); it stays in the root-only unit on the host.
- sync: SYNC_NO_TAGS (default windy-pro). build-electron fires on v* tags
  and targets ubuntu/macos/windows-latest, labels no runner has, so it
  would queue forever, invisibly. Desktop releases are built elsewhere.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 09:51:51 -04:00
parent d5181f1c6d
commit 95c33c8004
9 changed files with 79 additions and 1 deletions

View File

@@ -0,0 +1,16 @@
[Unit]
Description=Windy Git - Cloudflare Tunnel (the only ingress; no inbound port is opened)
After=network-online.target
Wants=network-online.target
[Service]
Type=notify
ExecStart=/usr/bin/cloudflared --no-autoupdate --config /etc/cloudflared/config.yml tunnel run
Restart=always
RestartSec=5
# G1.4 - bounded, so a misbehaving ingress can never starve Grant's workstation.
MemoryMax=512M
CPUQuota=100%
[Install]
WantedBy=multi-user.target