Files
yucca/ansible/talos/.mise.toml
T
Antoine Lecompte c6985d902c feat(all): introduce partition/region/ceph-cluster model across the stack (#222)
* feat: introduce partition/region/ceph-cluster model across the stack

Formalize partition -> region -> {one k8s cluster, many ceph clusters} and
thread it through every layer plus a new yuctl ops CLI.

- tf: deployment/<partition>/<region>/<stack> layout; terragrunt path-parse +
  state key yucca/<partition>/<region>/<stack>; per-region region.hcl (role,
  site_id, datacenter, provider_code, domain); env->partition / site->region
  renames (NetBird object names byte-identical); standardized per-stack
  `discovery` output contract (secrets as op:// refs).
- k8s: clusters/<partition>/<region>/ (staging/austin, prod/htz-fsn1, dev/local);
  role-based kustomize components (primary/secondary); hybrid cluster-settings
  (TF-rendered identity + human fragment); dev-mirror folded into dev/local;
  charts regrouped into charts/{apps,platform,lib,dev}.
- ci: infra.yml partition/region discovery matrix; partition-keyed path filters;
  <partition>-<region> environment gates; image-versions path moves.
- ansible: inventories under <partition>-<region>/<cluster>.
- yuctl: Go/cobra CLI reading the discovery contract from TF state.
- Retire the sietch-talos libvirt VM cluster (dev@local is the k3d cluster);
  ceph inventory_dirname -> <partition>-<region>/<cluster>.

Verified: mise k8s:validate green (3 clusters); yuctl go build/vet; tofu
validate pre-merge (all 9 stacks). Live-staging state migration NOT run.

* fix typo

* commit
2026-06-29 08:40:29 -04:00

106 lines
3.3 KiB
TOML

[tools]
python = "3.12"
[env]
# Project-local virtualenv for all Python tooling
VIRTUAL_ENV = "{{config_root}}/.venv"
PATH = "{{config_root}}/.venv/bin:{{env.PATH}}"
# Note: TALOS_ENV is intentionally NOT declared here. mise's [env] block
# overrides shell-exported values, which silently sends operators to the
# wrong cluster. Operators must export TALOS_ENV once per shell session:
# export TALOS_ENV=inventories/staging-austin/inventory.ini
# Inventory file is TF-rendered — `TF_STACK_DIR=tf/deployment/staging/austin/talos mise run tf:apply`
# (from yucca root) if missing.
[tasks.setup]
description = "Bootstrap development environment"
run = """
#!/usr/bin/env bash
set -euo pipefail
echo "=== Creating virtualenv ==="
python -m venv .venv
source .venv/bin/activate
echo "=== Installing Python dependencies ==="
pip install -q -r requirements.txt
echo "=== Installing Ansible collections ==="
ansible-galaxy collection install -r requirements.yml
echo "=== Verifying ==="
ansible --version | head -1
ansible-lint --version | head -1
yamllint --version
echo ""
echo "Environment ready. Run 'mise trust' if prompted."
echo "Next: 'TF_STACK_DIR=tf/deployment/staging/austin/talos mise run tf:apply' from yucca root to render inventory."
"""
[tasks.lint]
description = "Run all linters (yamllint + ansible-lint + shellcheck)"
run = """
#!/usr/bin/env bash
set -euo pipefail
echo "=== yamllint ==="
yamllint roles/ *.yml
echo ""
echo "=== ansible-lint ==="
ansible-lint
echo ""
echo "=== shellcheck ==="
if command -v shellcheck &>/dev/null; then
shellcheck scripts/*.sh && echo "All scripts pass"
else
echo "shellcheck not installed — skipping (install: pacman -S shellcheck)"
fi
"""
[tasks.check]
description = "Syntax-check all playbooks (no 1P access required)"
run = """
#!/usr/bin/env bash
set -euo pipefail
# Syntax-check only parses YAML — any valid inventory works. Default to
# sietch-talos when TALOS_ENV isn't inline-prefixed; the parse is identical.
TALOS_ENV="${TALOS_ENV:-inventories/staging-austin/inventory.ini}"
# Fall back to inventory.example.ini before tf:apply has rendered the runtime one.
if [ ! -f "$TALOS_ENV" ]; then
EXAMPLE="$(dirname "$TALOS_ENV")/inventory.example.ini"
if [ -f "$EXAMPLE" ]; then
echo "(runtime inventory.ini not yet rendered; falling back to inventory.example.ini)"
TALOS_ENV="$EXAMPLE"
fi
fi
for pb in *.yml; do
case "$pb" in
requirements.yml) continue ;;
*)
echo "Checking $pb..."
ansible-playbook -i "$TALOS_ENV" --syntax-check "$pb" 2>&1 | tail -1
;;
esac
done
"""
[tasks.preflight]
description = "Pre-flight: cluster health + hypervisor readiness (read-only)"
run = "scripts/ansible-play.sh preflight.yml"
[tasks."prepare-hypervisors"]
description = "Idempotent infra prep (bridges + libvirt + nftables + base image)"
run = "scripts/ansible-play.sh prepare-hypervisors.yml"
[tasks.provision]
description = "Provision Talos VMs (default profile=full; pass -- -e profile=smoke for smoke)"
run = "scripts/ansible-play.sh provision-vms.yml"
[tasks."destroy-vms"]
description = "Tear down Talos VMs + overlays (lab cleanup; leaves bridges + libvirt intact)"
run = "scripts/ansible-play.sh destroy-vms.yml"
[tasks."rollback-nftables-bridges"]
description = "Revert bridge-nf-call sysctls to kernel defaults (paired with nftables_bridges role)"
run = "scripts/ansible-play.sh rollback-nftables-bridges.yml"