mirror of
https://github.com/immich-app/yucca.git
synced 2026-09-30 13:33:00 +08:00
* feat: introduce partition/region/ceph-cluster model across the stack
Formalize partition -> region -> {one k8s cluster, many ceph clusters} and
thread it through every layer plus a new yuctl ops CLI.
- tf: deployment/<partition>/<region>/<stack> layout; terragrunt path-parse +
state key yucca/<partition>/<region>/<stack>; per-region region.hcl (role,
site_id, datacenter, provider_code, domain); env->partition / site->region
renames (NetBird object names byte-identical); standardized per-stack
`discovery` output contract (secrets as op:// refs).
- k8s: clusters/<partition>/<region>/ (staging/austin, prod/htz-fsn1, dev/local);
role-based kustomize components (primary/secondary); hybrid cluster-settings
(TF-rendered identity + human fragment); dev-mirror folded into dev/local;
charts regrouped into charts/{apps,platform,lib,dev}.
- ci: infra.yml partition/region discovery matrix; partition-keyed path filters;
<partition>-<region> environment gates; image-versions path moves.
- ansible: inventories under <partition>-<region>/<cluster>.
- yuctl: Go/cobra CLI reading the discovery contract from TF state.
- Retire the sietch-talos libvirt VM cluster (dev@local is the k3d cluster);
ceph inventory_dirname -> <partition>-<region>/<cluster>.
Verified: mise k8s:validate green (3 clusters); yuctl go build/vet; tofu
validate pre-merge (all 9 stacks). Live-staging state migration NOT run.
* fix typo
* commit
106 lines
3.3 KiB
TOML
106 lines
3.3 KiB
TOML
[tools]
|
|
python = "3.12"
|
|
|
|
[env]
|
|
# Project-local virtualenv for all Python tooling
|
|
VIRTUAL_ENV = "{{config_root}}/.venv"
|
|
PATH = "{{config_root}}/.venv/bin:{{env.PATH}}"
|
|
# Note: TALOS_ENV is intentionally NOT declared here. mise's [env] block
|
|
# overrides shell-exported values, which silently sends operators to the
|
|
# wrong cluster. Operators must export TALOS_ENV once per shell session:
|
|
# export TALOS_ENV=inventories/staging-austin/inventory.ini
|
|
# Inventory file is TF-rendered — `TF_STACK_DIR=tf/deployment/staging/austin/talos mise run tf:apply`
|
|
# (from yucca root) if missing.
|
|
|
|
[tasks.setup]
|
|
description = "Bootstrap development environment"
|
|
run = """
|
|
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
echo "=== Creating virtualenv ==="
|
|
python -m venv .venv
|
|
source .venv/bin/activate
|
|
|
|
echo "=== Installing Python dependencies ==="
|
|
pip install -q -r requirements.txt
|
|
|
|
echo "=== Installing Ansible collections ==="
|
|
ansible-galaxy collection install -r requirements.yml
|
|
|
|
echo "=== Verifying ==="
|
|
ansible --version | head -1
|
|
ansible-lint --version | head -1
|
|
yamllint --version
|
|
|
|
echo ""
|
|
echo "Environment ready. Run 'mise trust' if prompted."
|
|
echo "Next: 'TF_STACK_DIR=tf/deployment/staging/austin/talos mise run tf:apply' from yucca root to render inventory."
|
|
"""
|
|
|
|
[tasks.lint]
|
|
description = "Run all linters (yamllint + ansible-lint + shellcheck)"
|
|
run = """
|
|
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
echo "=== yamllint ==="
|
|
yamllint roles/ *.yml
|
|
echo ""
|
|
echo "=== ansible-lint ==="
|
|
ansible-lint
|
|
echo ""
|
|
echo "=== shellcheck ==="
|
|
if command -v shellcheck &>/dev/null; then
|
|
shellcheck scripts/*.sh && echo "All scripts pass"
|
|
else
|
|
echo "shellcheck not installed — skipping (install: pacman -S shellcheck)"
|
|
fi
|
|
"""
|
|
|
|
[tasks.check]
|
|
description = "Syntax-check all playbooks (no 1P access required)"
|
|
run = """
|
|
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
# Syntax-check only parses YAML — any valid inventory works. Default to
|
|
# sietch-talos when TALOS_ENV isn't inline-prefixed; the parse is identical.
|
|
TALOS_ENV="${TALOS_ENV:-inventories/staging-austin/inventory.ini}"
|
|
# Fall back to inventory.example.ini before tf:apply has rendered the runtime one.
|
|
if [ ! -f "$TALOS_ENV" ]; then
|
|
EXAMPLE="$(dirname "$TALOS_ENV")/inventory.example.ini"
|
|
if [ -f "$EXAMPLE" ]; then
|
|
echo "(runtime inventory.ini not yet rendered; falling back to inventory.example.ini)"
|
|
TALOS_ENV="$EXAMPLE"
|
|
fi
|
|
fi
|
|
for pb in *.yml; do
|
|
case "$pb" in
|
|
requirements.yml) continue ;;
|
|
*)
|
|
echo "Checking $pb..."
|
|
ansible-playbook -i "$TALOS_ENV" --syntax-check "$pb" 2>&1 | tail -1
|
|
;;
|
|
esac
|
|
done
|
|
"""
|
|
|
|
[tasks.preflight]
|
|
description = "Pre-flight: cluster health + hypervisor readiness (read-only)"
|
|
run = "scripts/ansible-play.sh preflight.yml"
|
|
|
|
[tasks."prepare-hypervisors"]
|
|
description = "Idempotent infra prep (bridges + libvirt + nftables + base image)"
|
|
run = "scripts/ansible-play.sh prepare-hypervisors.yml"
|
|
|
|
[tasks.provision]
|
|
description = "Provision Talos VMs (default profile=full; pass -- -e profile=smoke for smoke)"
|
|
run = "scripts/ansible-play.sh provision-vms.yml"
|
|
|
|
[tasks."destroy-vms"]
|
|
description = "Tear down Talos VMs + overlays (lab cleanup; leaves bridges + libvirt intact)"
|
|
run = "scripts/ansible-play.sh destroy-vms.yml"
|
|
|
|
[tasks."rollback-nftables-bridges"]
|
|
description = "Revert bridge-nf-call sysctls to kernel defaults (paired with nftables_bridges role)"
|
|
run = "scripts/ansible-play.sh rollback-nftables-bridges.yml"
|