Files
esh-pfi-infrastructure/playbooks/albok-service-host.yaml
T
vh d3958655c1 feat(albok-service): deploy the fleet knowledgebase service on nh3-docker
albok-service 0.1.0 (vh/albok 0b37431), image pfi/albok-service pinned by
digest, published on host port 8392 because 8390 is the post office.
Host prep playbook creates the fixed ids (albok 1500, albok-read 1510,
albok-personal 1511) and the local store/private roots; the container
gets a mounted /etc/group and group_add so the service can resolve and
chgrp its wing dirs. The config carries a LiteLLM key scoped to
qwen3-embedding and lives outside the deploy-synced conf dir. DNS name
albok.nh3.internal.
2026-10-02 17:56:34 -07:00

42 lines
2.0 KiB
YAML

# Host preparation for albok-service on nh3-docker (2026-10-02). Idempotent.
# scripts/elway infra-ops@10.100.50.40 --playbook playbooks/albok-service-host.yaml
# Creates the service identity and read groups with FIXED numeric ids (the contract requires them),
# and the two local roots owned by uid 1500. The config file itself (it carries the embedder key)
# is uploaded separately to /srv/albok/etc/albok.yaml: see stacks/albok-service/README.md.
steps:
- name: group albok (gid 1500)
sudo: true
shell: groupadd --gid 1500 albok
when: "! getent group albok >/dev/null"
- name: user albok (uid 1500, no login, no home)
sudo: true
shell: useradd --system --uid 1500 --gid 1500 --no-create-home --home-dir /nonexistent --shell /usr/sbin/nologin albok
when: "! getent passwd albok >/dev/null"
- name: read group albok-read (gid 1510) — building `fleet`
sudo: true
shell: groupadd --gid 1510 albok-read
when: "! getent group albok-read >/dev/null"
- name: read group albok-personal (gid 1511) — building `personal`
sudo: true
shell: groupadd --gid 1511 albok-personal
when: "! getent group albok-personal >/dev/null"
- name: store root, private root and config dir (local ext4, never NFS)
sudo: true
shell: |
set -e
install -d -o 1500 -g 1500 -m 0711 /srv/albok/store
install -d -o 1500 -g 1500 -m 0700 /srv/albok/private
install -d -o root -g 1500 -m 0750 /srv/albok/etc
changed_when: "false"
verify:
- name: ids are the fixed numbers
shell: |
test "$(getent passwd albok | cut -d: -f3,4)" = "1500:1500" && test "$(getent group albok-read | cut -d: -f3)" = 1510 && test "$(getent group albok-personal | cut -d: -f3)" = 1511
changed_when: "false"
- name: roots are local (not NFS) and owned by 1500
sudo: true
shell: |
test "$(findmnt -T /srv/albok/store -no FSTYPE)" = ext4 && test "$(stat -c %u /srv/albok/store)" = 1500 && test "$(stat -c %u /srv/albok/private)" = 1500
changed_when: "false"