Refactor run-once orchestration and bootstrap Mailu/Mastodon in a single deploy

- Replace legacy utils/run_once.yml with the new helpers utils/once_flag.yml and utils/once_finalize.yml
- Introduce utils/compose_up.yml to ensure docker-compose stacks are up and to flush handlers safely without coupling to run-once flags
- Migrate all affected roles (desk-*, dev-*, sys-ctl-*, sys-svc-*, web-app-*, web-svc-*, util-*) to the new run-once helpers
- Rework sys-svc-msmtp to auto-load Mailu once per deploy, check reachability, and reuse the running stack instead of requiring multiple playbook passes
- Adjust web-app-mailu to integrate cert deployment, handler flushing, and run-once handling so Mailu is fully initialized in a single deploy
- Improve Matomo, CDN, logout and CSP/health-check related roles to cooperate with the new compose_up / once_* pattern
- Simplify alarm/backup/timer/service orchestration (sys-ctl-alm-*, sys-bkp-provider, sys-timer-cln-bkps, etc.) by moving run-once logic into dedicated 01_core.yml files
- Update integration tests so utils/once_flag.yml and utils/once_finalize.yml are recognised as valid run-once providers, keeping the global run_once_* guarantees consistent
- Align frontend injection and service dependencies so Mastodon- and Mailu-related services can be brought up coherently within a single deployment cycle rather than several iterations
This commit is contained in:
2025-12-01 13:30:50 +01:00
parent 72ede9414b
commit e09f561f0b
128 changed files with 291 additions and 243 deletions

View File

@@ -19,7 +19,7 @@ class RunOnceInclusionTest(unittest.TestCase):
Ensure that every Ansible block in roles/*/tasks with a when condition matching
either the dynamic Jinja scheme or a literal run_once_<role_name> is not defined,
and containing an include_role/import_role also ends with
include_tasks: utils/run_once.yml as its last task.
include_tasks: utils/once_finalize.yml as its last task.
"""
WHEN_PATTERN = re.compile(
r"(?:run_once_\+\s*\(role_name\s*\|\s*lower\s*\|\s*replace\('\-','\_'\)\)\s*is\s*(?:not\s+)?defined"
@@ -64,16 +64,16 @@ class RunOnceInclusionTest(unittest.TestCase):
isinstance(t, dict) and ('include_role' in t or 'import_role' in t)
for t in block
)
# Check that last task is include_tasks: utils/run_once.yml
# Check that last task is include_tasks: utils/once_finalize.yml
last_task = block[-1] if block else None
has_run_once_include = (
isinstance(last_task, dict)
and last_task.get('include_tasks') == 'utils/run_once.yml'
and last_task.get('include_tasks') == 'utils/once_finalize.yml'
)
if has_role_include and not has_run_once_include:
violations.append(
f"{filepath}: block with when='{when}' missing final include_tasks: utils/run_once.yml"
f"{filepath}: block with when='{when}' missing final include_tasks: utils/once_finalize.yml"
)
if violations: