Fix prod compose port collision and make ansible deploy re-runnable
Build & Deploy / Build & push images (push) Successful in 4m24s
Build & Deploy / Deploy to VM (push) Failing after 2m11s

docker-compose.prod.yml: compose merges `ports` by appending, so the prod
override left the base file's 8888:8000 and 3000:3000 in place next to the
127.0.0.1-scoped ones. Each container tried to bind its port twice and the
second bind failed with "address already in use", so c2-core and frontend
could never start. It also meant the localhost-only binding never applied —
both ports were published on every interface. Marked both `!override`, the
same way mosquitto already used `!reset`.

infra/ansible:
- add the missing "Reload Caddy" handler; the Deploy Caddyfile task notified
  a handler that did not exist, which aborts the play
- guard mkswap/swapon on whether /swapfile is already active, so a second run
  does not fail on "mounted" / "Device or resource busy"
- git task now updates instead of clone-once, otherwise a re-run redeploys
  whatever code was on the VM at first clone
- vault.yml.example: correct the registry token comment to read-only scope

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
Logan Cusano
2026-08-09 21:19:03 -04:00
parent 2e3fde2448
commit 6140dd7b9c
5 changed files with 56 additions and 7 deletions
+7 -2
View File
@@ -12,9 +12,14 @@ services:
restart: always restart: always
ports: !reset [] # Remove the dev 1883:1883 mapping — internal only ports: !reset [] # Remove the dev 1883:1883 mapping — internal only
# !override, not a plain list: compose MERGES `ports` by appending, so a plain
# list leaves the base file's "8888:8000" in place alongside this one. The
# container then tries to bind 8888 twice — 0.0.0.0 and 127.0.0.1 — and the
# second bind fails with "address already in use". It also silently defeated
# the whole point of this override, publishing the port on every interface.
c2-core: c2-core:
restart: always restart: always
ports: ports: !override
- "127.0.0.1:8888:8000" # Caddy proxies, not exposed publicly - "127.0.0.1:8888:8000" # Caddy proxies, not exposed publicly
discord-bot: discord-bot:
@@ -22,5 +27,5 @@ services:
frontend: frontend:
restart: always restart: always
ports: ports: !override
- "127.0.0.1:3000:3000" # Caddy proxies, not exposed publicly - "127.0.0.1:3000:3000" # Caddy proxies, not exposed publicly
@@ -0,0 +1,13 @@
---
# The "Deploy Caddyfile" task notifies this. Without this file the play aborts
# with "The requested handler 'Reload Caddy' was not found" — notify does not
# tolerate a missing handler.
#
# reloaded, not restarted: caddy reload swaps config with zero downtime and
# keeps existing TLS certs/connections; a restart drops every in-flight request.
- name: Reload Caddy
ansible.builtin.systemd_service:
name: caddy
state: reloaded
enabled: true
+9 -2
View File
@@ -2,12 +2,19 @@
# First-time setup: clone repo, write secrets, pull pre-built images and start stack. # First-time setup: clone repo, write secrets, pull pre-built images and start stack.
# Images are built and pushed by Gitea CI — this role never builds on the VM. # Images are built and pushed by Gitea CI — this role never builds on the VM.
- name: Clone repo (skipped if already present) # update: true (was false) — with update disabled, every re-run of this playbook
# redeployed the code that happened to be on the VM at first clone, so any fix
# pushed to main was invisible here and the only way to ship one was CI or a
# manual pull. force: true discards local edits made on the VM; the templated
# .env files and Caddyfile live outside git tracking, so nothing generated by
# this role is at risk.
- name: Clone or update repo
git: git:
repo: "{{ repo_url }}" repo: "{{ repo_url }}"
dest: "{{ app_dir }}" dest: "{{ app_dir }}"
version: main version: main
update: false update: true
force: true
become: false become: false
- name: Set ownership of app directory - name: Set ownership of app directory
+19 -2
View File
@@ -36,16 +36,33 @@
path: /swapfile path: /swapfile
mode: "0600" mode: "0600"
# mkswap refuses to touch a file that is already active as swap, so a
# re-run would fail here without this guard. The swap file survives
# reboots via the fstab entry below, so on any second run it IS active.
- name: Check whether the swap file is already active
command: swapon --show=NAME --noheadings
register: _active_swaps
changed_when: false
failed_when: false
- name: Format swap file - name: Format swap file
command: mkswap /swapfile command: mkswap /swapfile
when: "'/swapfile' not in _active_swaps.stdout"
register: _mkswap register: _mkswap
changed_when: _mkswap.rc == 0 changed_when: _mkswap.rc == 0
# Guarded by the same check as mkswap above. The stderr test alone was not
# enough: an already-active swap file reports "Device or resource busy",
# not "already", so the original failed_when never matched it.
- name: Enable swap - name: Enable swap
command: swapon /swapfile command: swapon /swapfile
when: "'/swapfile' not in _active_swaps.stdout"
register: _swapon register: _swapon
failed_when: _swapon.rc != 0 and 'already' not in _swapon.stderr failed_when: >
changed_when: _swapon.rc == 0 _swapon.rc is defined and _swapon.rc != 0
and 'already' not in _swapon.stderr
and 'busy' not in _swapon.stderr
changed_when: _swapon.rc is defined and _swapon.rc == 0
- name: Persist swap in fstab - name: Persist swap in fstab
lineinfile: lineinfile:
+8 -1
View File
@@ -22,7 +22,14 @@ vault_firestore_database: "c2-server"
# ── Gitea Container Registry ────────────────────────────────────────────────── # ── Gitea Container Registry ──────────────────────────────────────────────────
vault_registry_host: "git.vpn.cusano.net" vault_registry_host: "git.vpn.cusano.net"
vault_registry_user: "logan" vault_registry_user: "logan"
vault_registry_token: "" # Gitea access token with package:write scope vault_registry_token: "" # Gitea access token, READ-ONLY package scope.
# The VM only pulls (roles/deploy/tasks/main.yml:62-72);
# nothing here pushes. Pushing is CI's job and uses a
# separate write-scoped token (BUILD_TOKEN in Gitea
# repo secrets). Keep them separate: this token sits on
# an internet-facing VM, and a write-scoped one there
# would let an attacker publish a poisoned image that
# every future deploy and edge node would install.
vault_registry: "git.vpn.cusano.net/logan" # full image prefix vault_registry: "git.vpn.cusano.net/logan" # full image prefix
# ── Discord Bot ─────────────────────────────────────────────────────────────── # ── Discord Bot ───────────────────────────────────────────────────────────────